I mentioned this and NordVPN did come to me on this.
http://forum.mikrotik.com/t/nordvpn-troubles/151544/9
I have set to new-mss=1372 but you might start at 1232 and increase from there.
The line in /ip ipsec policy normally catches all ICMP 3-4 and convey them to the correct client. The problem is with NordVPN and some servers don’t let through the returnin ICMP 3-4 and we have to fore a fixed MTU in mangle.
After this I had no problems anymore but it was working before with out setting a fixed MTU.