IPSEC dynamic peer ip

Hello,

I have Mikrotik router on server side with static public IP. Other side have dynamic public IP and it is Edgerouter.
The traffic betwen clients works if I create ipsec policy with SA Src. Address and SA Dst. Address.

Because remote side have dynamic IP I like to have dynamic policy, that there is no need to change SA Dst. Address. I create template policy with 0.0.0.0 SA Dst. Address, IPSEC is enstablished but there is no traffic betwen?

Have can I correct set up the ipsec and policy template? Or is there some other configuration if remote peer have dynamic IP?

Firewall should allow traffic to/from tunnel:

;;; accept in ipsec policy
chain=forward action=accept ipsec-policy=in,ipsec

;;; accept out ipsec policy
chain=forward action=accept ipsec-policy=out,ipsec