IPsec cannot ping from HQ to Site

I have follow by this instruction for beginner IPec but the result I cannot ping from HQ to Site local IP.
https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Site_to_Site_IpSec_Tunnel

I also already open port 500,4500,1701 UDP but still cannot ping local PC from HQ to Site

Could anybody help?

Check the firewall in local PC.

Post the output of “/export hide-sensitive” from both ends of the tunnel. If there are any public IP addresses you don’t want to disclose, replace each of them systematically with a distinctive pattern (like “public.ip.1”). Otherwise no one without a crystal ball can help.

Dear all,

Now it work by this NAT rule.