If your MikroTik firewall is secure, you must explicitly allow the L2TP/IPsec traffic to pass. Go to > Firewall > Filter Rules . Add a new rule ( + ): Chain : input . Protocol : udp .
If your default policy is drop , you must also allow established/related traffic:
: Check mschap2 (uncheck weaker protocols like pap, chap, and mschap1 for better security). Use IPsec : Select yes (or required on RouterOS v7).