Žiadne L2TP, to sa potom balia pakety dvakrát, a druhýkrát to vždy robí CPU.
Samotné IKEv2, takto nejako (site to site):
/ip ipsec profile
set [ find default=yes ] enc-algorithm=aes-256,aes-192,aes-128 hash-algorithm=sha256
add dh-group=modp2048 enc-algorithm=aes-256 name=profile2
/ip ipsec peer
add address=peer1.fqdn exchange-mode=ike2 name=peer1 profile=profile2
add address=peer2.fqdn exchange-mode=ike2 name=peer2 profile=profile2
add address=peer3.fqdn exchange-mode=ike2 name=peer3 profile=profile2
/ip ipsec proposal
set [ find default=yes ] auth-algorithms=sha256,sha1 enc-algorithms=aes-256-cbc,aes-256-ctr,aes-256-gcm,\
aes-192-cbc,aes-192-ctr,aes-192-gcm,aes-128-cbc,aes-128-ctr,aes-128-gcm pfs-group=modp2048
add enc-algorithms=aes-256-cbc,aes-256-ctr,aes-256-gcm name=proposal2 pfs-group=modp2048
/ip firewall filter
...
add action=accept chain=input comment="allow IPSEC IKE, NAT" dst-port=500,4500 protocol=udp
add action=accept chain=input comment="allow IPSec ESP" protocol=ipsec-esp
...
add action=accept chain=forward comment="accept in ipsec policy" ipsec-policy=in,ipsec
add action=accept chain=forward comment="accept out ipsec policy" ipsec-policy=out,ipsec
...
/ip firewall raw
add action=notrack chain=prerouting dst-address=peer1-subnet/24 src-address=local-subnet/24
add action=notrack chain=prerouting dst-address=local-subnet/24 src-address=peer1-subnet/24
add action=notrack chain=prerouting dst-address=peer2-subnet/24 src-address=local-subnet/24
add action=notrack chain=prerouting dst-address=local-subnet/24 src-address=peer2-subnet/24
add action=notrack chain=prerouting dst-address=peer3-subnet/24 src-address=local-subnet/24
add action=notrack chain=prerouting dst-address=local-subnet/24 src-address=peer3-subnet/24
/ip ipsec identity
add peer=peer1 remote-id=fqdn:peer1.fqdn secret=ABC
add peer=peer2 remote-id=fqdn:peer2.fqdn secret=DEF
add peer=peer3 remote-id=fqdn:peer3.fqdn secret=GHJ
/ip ipsec policy
add dst-address=peer1-subnet/24 peer=peer1 proposal=proposal2 src-address=local-subnet/24 tunnel=yes
add dst-address=peer2-subnet/24 peer=peer2 proposal=proposal2 src-address=local-subnet/24 tunnel=yes
add dst-address=peer3-subnet/24 peer=peer3 proposal=proposal2 src-address=local-subnet/24 tunnel=yes