How did you test it, that you came to the conclusion that it doesn't work? Often enough it is the local firewall on the destination device that drops the traffic.
You can capture on the LAN side of the MX and look if you see the client originated traffic.
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.