This guy needs to read again the meaning of "out-interface" in the filter... And having a look to the packet flow would be useful, too... Especially knowing that the traffic is bidirectional and where it's placed the router in his network...
Hi! To have IPSec/L2TP working at layer 2 level, you should have the VPN address pool in the same broadcast domain of your LAN. Example: LAN: 192.168.1.0/24 VPN Pool: 192.168.1.10-192.168.1.20 Then in the PPP you should configure as termination address the same address of the Mikrotik (e.g. 192.168....