From the bits of information you've posted instead of the complete configuration, I assume that you didn't get the purpose of setting the connection-mark in the /ip ipsec mode-config row. You can use src-address-list , connection-mark , or both, but if you use both, packets need to match both to ge...