I manage a Mikrotik that sits in front of a customer's firewall in which we dstNAT all traffic from the router to their firewall. The client side of the IPSec site to site is on the customer's firewall. Even though all traffic is being forwarded it won't seem to establish. I even tried accepting anything going to 50, 500, and 4500 for good measure but still no dice.
Is there something simple I'm missing? Also tried an 'acc-fwd IPsec policy in' rule but nothing. Just trying to rule out our setup.
(I know people will ask why not just take the Mikrotik out but we monitor via The Dude)