For v7 and advanced setups, prefer aes-256-gcm if supported; adjust to your RouterOS version.
/ip firewall nat add chain=srcnat src-address=192.168.89.0/24 out-interface=ether1 action=masquerade comment="NAT VPN clients to internet" mikrotik l2tp server setup full