ike2, letsencrypt and windows client

I set up ccr1016-12g as ike2 vpn server with radius auth and letsencrypt cert. Windows clients (may be linux too) can connect only if letsencrypt intermediante R3 cert present in machine cert store
I found this http://forum.mikrotik.com/t/ikev2-eap-radius-windows-10-not-working-but-working-on-apple-devices/121460/1 but execution of “ip ipsec peer set certificate=cert.crt,chain.crt” gives me “expected end of command (line 1 column 31)”
My routeros version is 7.1

How to make router send intermediate certificate?

Hello,
Read this topic, Please.
http://forum.mikrotik.com/t/ikev2-eap-mschapv2-authentication-with-user-manager/154279/1
For Linux I used this article https://protonvpn.com/support/linux-ikev2-protonvpn/ and it works except for one part pushing the DNS resolver to a loopback interface. However, this problem is due to the change in the Linux DNS system.
You can read my last replay in this post if you want to have more detail about this issue.
http://forum.mikrotik.com/t/ipsec-ike2-with-certificates-vpn-server-guide-for-remote-access/149434/1

Well, all the time i missed the whole point that in winbox i can choose not only one certificate

Can you guide me to install Ikev2 on mikrotik using lets encrypt to authenticate radius? or give me the link of the tutorial that you have followed successfully. i am not understanding where i am wrong.

https://help.mikrotik.com/docs/display/ROS/IPsec#IPsec-RoadWarriorsetupusingIKEv2withEAP-MSCHAPv2authenticationhandledbyUserManager(RouterOSv7)