It depends on your config but I assume you are using a 'default' SOHO config.
If so you are NAT-ting from your local LAN to the outside.
Only thing you need to do is create a NAT rule and a firewall filter allowance rule for each port
ros code
/ip firewall nat
add chain=dstnat action=dst-nat in-interface=<your WAN interface> protocol=udp dst-port=500 to-address=192.168.88.113 to-address=500
add chain=dstnat action=dst-nat in-interface=<your WAN interface> protocol=udp dst-port=4500 to-address=192.168.88.113 to-address=4500
If you have a static WAN ip, you could add dst-address=<your WAN IP> to each line
ros code
/ip firewall filter
add chain=forward action=accept protocol=udp dst-address=192.168.88.113 dst-address=500 in-interface=<your WAN interface>
add chain=forward action=accept protocol=udp dst-address=192.168.88.113 dst-address=4500 in-interface=<your WAN interface>