I have the same problem =((( no phase 2 on second policy... "unique" level doesn't help. Mikrotik hEX S on one side and Cisco FTD 2120 on the other. Oh, I have got the solution! After multiple days of experiments with Cisco FTD I got that you need to check box "Enable Perfect Forward...