I've been using this config for a few years, but it happened already twice.
Between rb1 and rb2 is ospf. Suddenly ospf stopped and I've found, that I can ping rb1 from rb2 but not rb2 from rb1. Mac telnet was working correctly. I've downloaded config from rb1 and uploaded to new device and still no ping. Then I've found, that ping is working when i deactiveate all rules in NAT (all are touching another addresses and ports). When even one rule is active in NAT, ther's no ping. It's strange, because everything else works on this device.