I can’t tell you why your configuration is failing, but I had it working for a time, and I can tell you that I found IKEv2 so miserable to set up that when my prior VPN server (not a RouterOS box) ate its system disk and my VPN server configuration backups didn’t work with the new OS, I fell back to SSH as a limited sort of VPN for a time. (Port forwarding, SOCKS, etc.) I couldn’t stomach the idea of going through that process again atop the rebuilt server’s new OS.
Once RouterOS 7.1 became stable enough for my purposes, I got WireGuard working in the same role, and I don’t see myself ever going back to IKEv2. It has the simplicity of SSH with the power of a full VPN.
Do yourself a favor and stop throwing time at this problem. There’s a better solution now.