This blackhole trick seemed to work:
https://aacable.wordpress.com/2015/09/1 ... -approach/
/ip ipsec policy print detail where number=3
Are you saying I should just apply a second IP address to the existing VPN bridge interface I created?except the interface, there is none.