/ip ipsec peer
add address=
95.170.XXX.XXX/32 exchange-mode=ike2 local-address=
62.168.XXX.XXX name=EKB<-->NSK
/ip ipsec profile
set [ find default=yes ] enc-algorithm=aes-256,aes-192,aes-128,3des hash-algorithm=sha256
/ip ipsec proposal
set [ find default=yes ] auth-algorithms=sha256,sha1
/ip ipsec identity
add peer=EKB<-->NSK secret="password"
/ip ipsec policy
add dst-address=172.20.20.0/30 peer=EKB<-->NSK sa-dst-address=
95.170.XXX.XXX sa-src-address=
62.168.XXX.XXX \
src-address=172.20.20.0/30 tunnel=yes