Broke my internet trying to ask why to do this. Then understood and found why. =)2 Allow forward traffic from WAN interface
3 Allow forward traffic to WAN interface
Gotcha! Default dynamic peer rule completely dissapear from time to time. And appers when l2tp restarts.Can you check '/ip ipsec peer print' when the issue is present?