self signed cert for IKE2

Can someone help me to create proper certificate on mikrotik to use with IKE2 on mikrotik and client.
The one i have created following mikrotik doesnt work
Thank you.

https://wiki.mikrotik.com/wiki/Manual:IP/IPsec

Very detailed info that I used and works on Blackberry OS10 and Win10 clients as well. Be careful with the settings for windows clients as Microsoft does not allow very tight security regarding Phase 1 (Peer) and Phase 2 (Proposal) proposal sets.
The above guide has info for both MT to MT and also MT to Road Warrior configuration.

have followed the link , created cert as shown it didnt work, cer problem

Have you imported the CA public cert to your Win machine?

no i have imported only the one signed with CA

Your Win PC needs to have the chain as trusted. Export the CA public key as described in the instructions and import it to the win PC. It has to be imported to the trusted root folder of the local machine repository.