/ip firewall filter
add action=jump chain=input dst-port=1111,2222,3333 jump-target=knock log=yes protocol=tcp
add action=add-src-to-address-list address-list=knock1 address-list-timeout=none-dynamic chain=\
knock dst-port=1111,2222,3333 log=yes protocol=tcp
add action=add-src-to-address-list address-list=knock2 address-list-timeout=none-dynamic chain=\
knock dst-port=1111,2222,3333 log=yes protocol=tcp src-address-list=knock1
add action=add-src-to-address-list address-list="allowed clients" address-list-timeout=\
none-dynamic chain=knock dst-port=1111,2222,3333 log=yes protocol=tcp src-address-list=knock2