Road-Warrior and Site-to-Site VPN-clients

Hi!
I’m setting up IKEv2 on hAP ac to be able to connect in both ways: [Road-Warrior][https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Road_Warrior_setup_using_IKEv2_with_RSA_authentication] and [Site-to-Site][https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Site_to_Site_IPsec_tunnel].
Both options separately work well, but when I’m trying to connect them simultaneously, for instance, when Site-to-Site is working and I’m connecting Road-warrior, log gets

killing ike2 SA

and tunnels stop working. Have read a lot of topics, but didn’t find a solution.

Here is the config:

/ip ipsec policy group add name="DH18-VPN_GROUP"
/ip ipsec profile \
	add name="DH18-VPN_PROFILE" dh-group=modp2048,modp1024 enc-algorithm=aes-128,3des hash-algorithm=sha1 
/ip ipsec proposal \
	add name="DH18-VPN_PROPOSAL" auth-algorithms=sha1 enc-algorithms=aes-128-cbc,aes-192-cbc,aes-256-cbc pfs-group=none
/ip ipsec peer \
	add name="DH18-VPN-IKE2-SERVER_PEER" profile=DH18-VPN_PROFILE passive=yes exchange-mode=ike2 send-initial-contact=no
	
/ip ipsec policy \
	add peer=DH18-VPN-IKE2-SERVER_PEER tunnel=yes src-address=192.168.69.0/24 dst-address=192.168.88.0/24 proposal=DH18-VPN_PROPOSAL action=encrypt comment="DH18 VPN Static Client"
/ip ipsec policy \
	add dst-address=172.16.18.0/24 group=DH18-VPN_GROUP proposal=DH18-VPN_PROPOSAL template=yes comment="DH18 VPN Road Warrior"
	
/ip ipsec mode-config \
	add name="DH18-VPN-RW-SERVER_MODE-CONFIG" responder=yes address-pool=VPN_DHCP-POOL address-prefix-length=32 static-dns=192.168.69.1 system-dns=no
	
/ip ipsec identity \
	add peer=DH18-VPN-IKE2-SERVER_PEER policy-template-group=DH18-VPN_GROUP generate-policy=port-strict auth-method=digital-signature certificate=Server_cert remote-certificate=Static-Client_cert match-by=cetrificate comment="DH18 VPN Static Client"
/ip ipsec identity \
	add peer=DH18-VPN-IKE2-SERVER_PEER policy-template-group=DH18-VPN_GROUP generate-policy=port-strict auth-method=digital-signature certificate=Server_cert mode-config=DH18-VPN-RW-SERVER_MODE-CONFIG remote-certificate=Road-Warrior_cert match-by=cetrificatecomment="DH18 VPN Road Warrior"