RE: https://mastodon.au/@xrobau/117210850701587801
Hurrah, one of my Mikrotik routers was on a 7.12 release so it needed a couple of hops to reach 7.23.4, and the intermediate hop version evidently has a bug* that prevents it from negotiating a site-to-site VPN. This is why I still leave WAN SSH access unfirewalled, despite the risks, because the alternative risk is an overnight flight to another city.
* Edit: I think it might've been a misconfig on my part, which resulted in a race condition on startup. Now fixed.
Joy, two of our gateway routers were compromised by the vulnerability in 7.23.3, about two hours before I updated them all. Next job is to inspect all the config and rotate passwords. Fun!
(You can tell because of the disabled "ops" user that got created by the exploit.)