Dears, I know that this is an old thread, but could save someone hours of testing. After hours of trying and trying and trying with the same problem, I've found that you have to ENABLE REPLAY DETECTION IN PHASE 2!!!!! (in the Fortigate ofcourse, Mikrotik is never wrong....:-) ) Hope it helps. Regard...