/ip ipsec identity
add auth-method=pre-shared-key peer=Site1 secret="r8&#ym2*pufg" \
generate-policy=port-strict
add auth-method=pre-shared-key peer=Site2 secret="2j5%e5&@9z!7" \
generate-policy=port-strict
# identity for each client certificate
/ip ipsec identity
add peer=ClientVPN auth-method=digital-signature certificate=ServerCert \
generate-policy=port-strict match-by=certificate mode-config=vpn-client-ip \
policy-template-group=P2SVPN remote-certificate=ClientCert