Envió información Obtenida por CLI creo es mas claro que lo anterior. Les adiciono los comando utilizados para que puedan utilizar de referencia

-----------------------------------------------
Obtener informacion configuracion CLI -
-----------------------------------------------
1_ show system interface -
2_ show firewall address 2phase-name" -
3_ show vpn ipsec phase1-interface -
4_ show vpn ipsec phase2-interface -
5_ show firewall policy -
6_ show router static -
---------------------------------------------------------------------------------------------------------
Firewal address vpn-ipsec
-------------------------------
show firewall address IPsec-Clients-Addr-WAN1
config firewall address
edit "IPsec-Clients-Addr-WAN1"
set type iprange
set end-ip 192.168.4.254
set start-ip 192.168.4.1
---------------------------------------------------------------------
Interface virtual IPsec
-----------------------
edit "ipsec-wan1"
set vdom "root"
set ip 169.254.1.1 255.255.255.255
set type tunnel
set remote-ip 169.254.1.1
set snmp-index 7
set interface "wan1"
-----------------------------------------------------------------------
phase1
------
config vpn ipsec phase1-interface
edit "ipsec-wan1"
set type dynamic
set interface "wan1"
set mode aggressive
set xauthtype auto
set mode-cfg enable
set proposal 3des-sha1 aes128-sha1
set authusrgrp "VPN-IPSEC"
set ipv4-start-ip 192.168.4.2
set ipv4-end-ip 192.168.4.254
set ipv4-netmask 255.255.255.0
set dns-mode auto
set ipv4-split-include "192.168.0.0-network"
set save-password enable
set client-auto-negotiate enable
set client-keep-alive enable
set psksecret ENC IHRvb4uy+iNs4U0oo7OcUDYIYzP64zePst+oaNAIZmFBZHZjfJft59mW2e/LM4QoJs2tIxuubpNb4T7f7PMjPWm5tciAnt9dEVGBkCr6hs4ZKRv82/qLpibh5mF1xT1VhxyUNamuA4Uar7c6AmOx5cIexft/N6RI8TlCO22yZDi8vejvBUSytD5kk+IyISK3zUkLuw==
-------------------------------------------------------------------------------------------------------------------
Phase2
--------
config vpn ipsec phase2-interface
edit "ipsec-wan1"
set phase1name "ipsec-wan1"
set proposal 3des-sha1 aes128-sha1
------------------------------------------------------------------------------------------------------------------
Ruta estatica (vpn-ipsec)
-------------
set comment "IPsec-Wan1"
set device "ipsec-wan1"
set dst 192.168.4.0 255.255.255.0
------------------------------------------------------------------------------------------------------------------
Politicas de firewal (vpn-ipsec)
--------------------
edit 9
set srcintf "ipsec-wan1"
set dstintf "internal1"
set srcaddr "all"
set dstaddr "all"
set action accept
set schedule "always"
set service "ALL"
set logtraffic all
set comments "VPN-IPSEC"
edit 12
set srcintf "internal1"
set dstintf "ipsec-wan1"
set srcaddr "all"
set dstaddr "all"
set action accept
set schedule "always"
set service "ALL"
set logtraffic all
set comments "VPN-ipsec"
--------------------------------------------------------------------------------------------------------