I made a other test:
I restored a working config (2.0 RC1) from a customer connected via PPPoE having a working IPSec Tunnel. Then i'd setup a Gateway as DefaultGW, switched from WAN PPPoE to WAN Static IP using the Gateway. Changed the LAN IP to my Testnet and the Phase 1 entry from Certs to PSK (PSK = 1234Test) and let the rules unchanged (Allow all incoming IPSec).
Same same: Tunnel comes up immediately … but passes NO traffic. This must be some kind of bug!
At the moment i have only the alternative to ship an old 1.2.3 to my customer, which is in a foreign country. I hope i can update it at a later time remotely, when 2.0 is released and the issue is solved. But of course i'm interested i a solution to that issue ...