How to IPSec with NAT-T ?

I have this configuration:

Site 1:
LAN1 192.168.1.0/24 — 192.168.1.1/24 (Router 1 - ROS 3.0) 195.xx.zz.145 ---- Internet

Site 2:

Internet — 88.yy.vv.20 (router with NAT) 10.0.0.138/24 —10.0.0.1/24 (Router 2 - ROS 3.0) 192.168.2.1/24 – 192.168.2.0/24 LAN2

I need build IPSec tunnel LAN1 - LAN2. How setup Router 1 and Router 2 (Policies, Peers, NAT-T …) ?

Thank you

NAT-T is supported at 3.0 version. Configuration examples,
http://www.mikrotik.com/testdocs/ros/2.9/ip/ipsec_content.php#5.44.8
Firewall NAT accept rule for local subnets is not required, since NAT-T is available at RouterOS 3.0.