IPSec + generate policy + multiple subnets

Hello everyone,

I have a LAN to LAN IPSec connection running, with one client having a dynamic IP. The setup worked like a charm for quite some time, the router with dynamic WAN-IP sends the initial connections, the router with static WAN-IP on the other side has “generate policy” enabled.
With 2 subnets from 2 different remote peers everything worked fine, but now one of the remote peers should connect 2 subnets, but only one policy is generated and therefore only one subnet works.

I already thought about some masq+routing rules to solve the issue, but perhabs there are better solutions.
Any ideas?
Thanks in advance,
sap

bump

It would seem you are using IPSec in Tunnel mode. Post the output of “/ip ipsec export compact” from the AC and the peers.