@TA3AS
ShrewSoft VPN Client is an obsolete software for many years, so we can't recommend it to be used at all.
But if you really want, try to follow this brief:
At first, install IPsec package on Keenetic, perform configuration and enable Virtual IP (XAuth) server on Applications page (don't forget about users and their passwords).
Next steps should be performed at VPN Access Manager app.
Press "Add".
Go to "General" tab, fill in the field "Remote Host / Hostname or IP Address" with Keeentic WAN IP address or assigned domain name. Leave other fields on the tab and on the "Client" and "Name Resolution" tabs default.
Go to "Authentication", and in combo "Authentication Method" choose "Mutual PSK + XAuth". On subtab "Local Identity" choose "Identification Type" - "IP Address", and make sure that the checkbox "Use a discovered local host address" is set.
Go to "Phase 1", then select "Exchange Type" - "main"; "DH Exchange" - "group 2"; "Cipher Algorithm" - "aes"; "Cipher Key Length" - "128"; "Hash Algorithm" - "sha1".
Go to "Phase 2", then select "Transform Algorithm" - "esp-aes"; "Transform Key Length" - "128"; "HMAC Algorithm" - "sha1", "PFS Exchange" - "disabled", "Compress Algorithm" - "disabled".
Leave settings on "Policy" tab unmodified.
Save, select the created connection and press "Connect".
Login and password you must know from Virtual IP configuration stage.
Here you are, message "tunnel enabled" will show you that everything works.