I am pretty sure mikrotik can do this but I am having a time with this. This what I got.
Remote Peer - xxx.xxx.136.10
Remote Secure Network/Encryption Domain - xxx.xxx.136.170/32
xxx.xxx.136.176/28
Local Peer - xxx.xxx.xxx.xxx
Local Secure Network/Encryption Domain - xxx.xxx.64.36/32
xxx.xxx.210.1/29
IPsec Phase 1
PSK
AES-256
SHA1
86,400
Group 2
Main
IPsec Phase 2
AES-256
SHA1
28,800
PFS Group 2
Thanks for any help.