nobody ever mentioned ECB, therefore AES-256-CBC would be my preferred cipher, I totally agree with you in that point.
I also agree with you that AES 128/256 is the same algorithm for IPsec and OpenVPN, but according to MikroTik's
datasheet for the hEX S, encrpytion offloading for IPsec is supported (by whatever mechanism) and encryption offloading vor OpenVPN (which uses OpenSSL)
Look at this page and you see that ECB in worse than CBC:
As written by mada3K the AES 128/256 for IPSEC is not different than AES128/256 for OpenSSL.