Hi.
This is my test environment:
ssh server - firewall - mikrotik - ssh server
172.30.1.99/24 - 172.30.1.1/24, 10.1.1.1/24 - 10.1.1.2/24, 172.30.2.1/24 - 172.30.2.99/24
firewall ipsec ↔ mikrotik ipsec
From 172.30.1.99: telnet 172.30.2.99 22
INTERFACE TIME NUM DIR SRC-MAC DST-MAC VLAN SRC-ADDRESS DST-ADDRESS PROTOCOL SIZE CPU FP
ether1 7.875 1 ← 08:00:27:2E:6C:98 08:00:27:3A:34:7F 172.30.1.99:32890 172.30.2.99:22 (ssh) ip:tcp 74 0 no
ether2 7.875 2 → 08:00:27:F3:41:CF 08:00:27:EA:8A:10 172.30.1.99:32890 172.30.2.99:22 (ssh) ip:tcp 74 0 no
ether2 7.875 3 ← 08:00:27:EA:8A:10 08:00:27:F3:41:CF 172.30.2.99:22 (ssh) 172.30.1.99:32890 ip:tcp 74 0 no
Packet not shown outgoing by ether1 interface
ether1 7.877 4 ← 08:00:27:2E:6C:98 08:00:27:3A:34:7F 172.30.1.99:32890 172.30.2.99:22 (ssh) ip:tcp 66 0 no
ether2 7.877 5 → 08:00:27:F3:41:CF 08:00:27:EA:8A:10 172.30.1.99:32890 172.30.2.99:22 (ssh) ip:tcp 66 0 no
ether2 7.885 6 ← 08:00:27:EA:8A:10 08:00:27:F3:41:CF 172.30.2.99:22 (ssh) 172.30.1.99:32890 ip:tcp 98 0 no
Packet not shown outgoing by ether1 interface
ether1 7.886 7 ← 08:00:27:2E:6C:98 08:00:27:3A:34:7F 172.30.1.99:32890 172.30.2.99:22 (ssh) ip:tcp 66 0 no
ether2 7.886 8 → 08:00:27:F3:41:CF 08:00:27:EA:8A:10 172.30.1.99:32890 172.30.2.99:22 (ssh) ip:tcp 66 0 no
From 172.30.2.99: telnet 172.30.1.99 22
INTERFACE TIME NUM DIR SRC-MAC DST-MAC VLAN SRC-ADDRESS DST-ADDRESS PROTOCOL SIZE CPU FP
ether2 3.714 1 ← 08:00:27:EA:8A:10 08:00:27:F3:41:CF 172.30.2.99:33292 172.30.1.99:22 (ssh) ip:tcp 74 0 no
Packet not shown outgoing by ether1 interface
ether1 3.716 2 ← 08:00:27:2E:6C:98 08:00:27:3A:34:7F 172.30.1.99:22 (ssh) 172.30.2.99:33292 ip:tcp 74 0 no
ether2 3.716 3 → 08:00:27:F3:41:CF 08:00:27:EA:8A:10 172.30.1.99:22 (ssh) 172.30.2.99:33292 ip:tcp 74 0 no
ether2 3.716 4 ← 08:00:27:EA:8A:10 08:00:27:F3:41:CF 172.30.2.99:33292 172.30.1.99:22 (ssh) ip:tcp 66 0 no
Packet not shown outgoing by ether1 interface
ether1 3.726 5 ← 08:00:27:2E:6C:98 08:00:27:3A:34:7F 172.30.1.99:22 (ssh) 172.30.2.99:33292 ip:tcp 98 0 no
ether2 3.726 6 → 08:00:27:F3:41:CF 08:00:27:EA:8A:10 172.30.1.99:22 (ssh) 172.30.2.99:33292 ip:tcp 98 0 no
ether2 3.727 7 ← 08:00:27:EA:8A:10 08:00:27:F3:41:CF 172.30.2.99:33292 172.30.1.99:22 (ssh) ip:tcp 66 0 no
Packet not shown outgoing by ether1 interface
Why mikrotik sniffer not shown this packets?
Communication is OK