I have configured an IPSec with 449 policies on Mikrotik CCR1036 with 6.37.5 OS.
Than I have exported the ipsec policy into file. After importing the file into other MikroTik with 6.43.8, from 110 to 449 policies are becomes inactive (red).
Or if I upgrade the 6.37.5 to 6.43.8 or 6.43.12 (stable) some policies becomes inactive (red) (See the screenshot).
After changing the sa-dst-address or dst-address prefix from /29 to /28, the policy becomes active. But after rebooting the result is the same, becomes inactive.