ROS 5.11 IPSEC issue - Will establish tunnel but no traffic

I’m running two Router board 450s and am trying to set up a IPSEC link between them. I followed Greg Sowell’s instructions to the letter and even deleted the policies and peers and re-did them several times just to make sure I’m not missing something but still come with the same result.

In the installed SAs window I see two of them on each side of the link, but when I click on the link under remote peers on the link it shows PH2 ACTIVE:0 and PH2 TOTAL:0

In the log I see where it says “IPsec-SA established: ESP/tunnel” and the IP addresses and shows a tunnel for both sides but no traffic can pass. Both sides logs show the same with two tunnels being established and after about a half hour is shows the link expired.

I’ve done everything from Greg’s tutorial to the T including the NAT modifications to send “interesting traffic” over the link. I’ve flushed the keys, rebooted the Router boards several times and even tried clearing the connection tracking.

But with all of this I can’t get any traffic to pass even trying to ping one router board from the other. Shouldn’t I see the PH2 active or PH2 total have something other than zero?

Any ideas ?

are you able to provide a config export to us?

Which config exports do I need to perform and post?

Hate to bump my own thread but this is driving me crazy. I’ve gone over the config and the mikrotik wiki a dozen times and can’t figure out what I’m missing.

Need config from both sides:

-Interfaces
-Firewall rules
-IPsec config
-Routing table