You didnt read my post.it's because you haven't specified a filter to tell it only wan traffic. Either put in the in-interface or the dst-address (your public ip). You also don't really need to the to-ports. Action should be dst-nat with the to-address set to the internal ip.