@reschi1
Regarding the NAT/BINAT configuration in the phase #2 I found this one:
https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/phase-2-nat.html
I think this is what matches my case:
NAT - Overload/PAT Style
If the Local Network is a subnet, but the NAT/BINAT Translation address is set to a single IP address, then a 1:many NAT (PAT) translation is set up that works like an outbound NAT rule on WAN. All outbound traffic will be translated from the local network to the single IP address in the NAT field.
I think that my phase #2 configuration I posted above is clearly non-sense, isn't it? I'm talking about the translation configuration:
Local Network: Address 123.231.231.227
NAT/BINAT translation: Address 123.231.231.227
To me it would be logical to configure it this way:
Local Network: Network LAN subnet
NAT/BINAT translation: Address 123.231.231.227
Reconfigured it accordingly, but still no traffic. Leaves the previous question: Do I have to configure additional NAT settings apart from the phase #2 NAT/BINAT configuration?
What is more: I found this one https://forum.netgate.com/topic/140873/solved-inbound-traffic-with-nat-binat-translation-via-ipsec where it is claimed that not the site using a single IP address but the partner site has to configure NAT/BINAT settings. Now I'm rather confused.