Hi
I need to reach a remote branch via IPSec but connecting before to a HQ (2 hops).
The connection works If use a Fortinet by my side (in the middle the VPN Ipsec Tunnel is the same, from my side to remote branch).
Using Mikrotik I realize the first VPN (my site > to HQ and it works - ping all the HQ subnet), but not to the second branch.
How I must set NAT/routes/Peers on my mkt?
My side: Mikrotik call HQ on ‘VPN1’
HQ: VPN IPsec DialUP incoming ‘VPN1’
Remote Branch: VPN Call HQ ‘VPN1’
Thank you
i realize the system with a fortigate and a zywall as client vpn to the HQ, then to the remote.
Still trying with Mirkotik 
I’m not a fan of using NATs on VPNs - simply a matter of choice.
Without seeing any of the configs:
Ensure that the routes are populated and correct. For instance MK should have a route to the Remote network pointing over the MK<->FGT VPN. You would need to ensure the FGT has a route to the Remote network as well, which I assume already exists. The Remote network will need a route to MK pointing over the Remote<->FGT VPN.
This should give you basic connectivity; that is again without knowing how your device/network is actually configured.
You can also setup a tunnel directly between MK and Remote - that is the route I would take.