How to configure a IPsec tunnel through dynamic IPv6 endpoints?

I have two routers (RB5009 v7.11.2) in different place and the carrier company provided these two routers with a CGNAT IPv4 address and some /60 IPv6 prefixes.

I want to create a tunnel between these two routers, in some reason, I want to use ESP encapsulation so I choosed IPsec to do this.

I setup IP/Cloud for dynamic domain (v4 and v6). But when I tried to connect one router to another, the ROS seems only wants to connect to the v4 address (which actually owned by CGNAT device, not my router), not v6 address.

So is there anyway to force ROS only connects to the AAAA record of the domain?

BR