Ok, I have set DMZ on one router to point to mikrotik and reset both routers once more. Now it works fine, but I guess it will fail down in 24hrs. Here what I did to make it work: [admin@BBBBBBBBBb] > ip ipsec peer print Flags: X - disabled, D - dynamic 0 address=aa.aa.aa.107/32 local-address=0.0.0....