/ip firewall filter
add action=jump chain=forward dst-port=1111,2222,3333 jump-target=knock1 \
protocol=tcp
add action=jump chain=knock1 dst-port=1111,2222,3333 jump-target=knock2 \
protocol=tcp
add action=jump chain=knock2 dst-port=1111,2222,3333 jump-target=knock3 \
protocol=tcp
add action=add-src-to-address-list address-list="allowed clients" \
address-list-timeout=none-dynamic chain=knock3
add action=accept chain=forward src-address-list="allowed clients"