/ip ipsec peer add address=2001:db8:be0:7501::1/128 exchange-mode=ike2 local-address=2001:db8:be1:6501::1 name=peer1 port=500 /ip ipsec profile add dh-group=modp1024 enc-algorithm=aes-128 name=profile1 /ip ipsec proposal set [ find default=yes ] disabled=yes add enc-algorithms=aes-128-cbc lifetime=1d name=proposal1 pfs-group=none /ip ipsec identity add peer=peer1 secret=12345678 /ip ipsec policy set 0 disabled=yes add dst-address=2001:db8:be0:7500::/64 peer=peer1 proposal=proposal1 sa-dst-address=2001:db8:be0:7501::1 \ sa-src-address=2001:db8:be1:6501::1 src-address=2001:db8:be1:6500::/64 tunnel=yes /ipv6 address add address=2001:db8:be1:6501::1 advertise=no interface=ether3 add address=2001:db8:be1:6500::1 advertise=no interface=ether4 /ipv6 route add distance=1 gateway=2001:db8:be1:6501::2