Don't know what DSL modem you're using, but you're probably better to make that DSL modem work in bridge mode and have your MikroTik router working as a normal WAN router facing WAN and LAN sides. That way you'll have no issues with VPN, be able to forward traffic as you like and set up a good firewall. This is very typical and good setup. And this is how I'd do it.
If you haven't got enough control over your DSL modem, then sure, you can do chained NAT, forward everything to MT router or, as Benoit suggested, set up a DMZ feature. That way you'll still be able to bring the VPN tunnel up, but only as a client.