Invalid IPSEC Policy (ROS 7.6)

Hi all!

When I create an IPSEC policy, it goes into Invalid status. The subnet does not overlap, everything is exactly the same on the remote side and the policy has the correct status.
Invaild IPSEC Policy.jpg
I noticed that if you change the subnet mask, for example, to /26, then the policy immediately changes the status from Invalid to normal.
no Invaild IPSEC Policy.jpg
Why is that?

ROS Version 7.6

Same problem here in 7.9

x.x.x.x/24 ↔ y.y.y.y/29 invalid
x.x.x.x/24 ↔ y.y.y.y/28 valid

Did you resolve it?

i on ROS 7.9 use these subnets without problems /16 /21