Two problem in 1 please help

hi there, im new in the world of MIkrotik but i have 2 problems.

I have 2 offices that a i want to make an IPsec tunnel…in the first one i have a pfSense software in the ROuter and in the Other (where i have the problem)
i have a Mikrotik RB951G-2HnD.

My ISP left a Modem/Router but in BRIDGE mode, when i put the MIKROTIK in BRIDGE mode i have internet, but i think that i need ROUTER mode to make IPsec tunnel to work.

When i put the ROUTER mode i use the ISP data and then 172.21.4.254 as IP, 255.255.255.0 as subnet mask

DHCP Server Enabled and NAT Enabled with a DHCP Range of: 172.21.4.160-172.21.4.199

in the other hand i have an IPse configuration that say ESTABLISHED and also in the Peer i have two connections one with RESPONDER and the other in INITIATOR

please help

HERE A POST WITH PICTURES OF CONFIGURATIONS

https://imgur.com/a/x8lhy

Best Regards

Use bridge mode, find your public ip, change the ipsec peers and policies to match that.
You need a static public IP for ipsec.