It looks like you are using webfig
all should be disabled.
all enabled services should only be accessible from your lan (available from your lan subnet)and preferably only...
Sorry, copied and pasted and didn't check all the entries.
Try this line.
/ip firewall nat add action=dst-nat chain=dstnat dst-port=9881 in-interface-list=WAN protocol=tcp src-address-list=clients to-addresses=INTERNAL.HOST to-ports=9881 src-address-list=clients
You will need to move the...