Confirm that you aren’t blocking and are forwarding the protocols involved. As I recall, they are 50 and 51 for ESP and AH, respectively. Since you’re going through NAT, you may need to forward the ISAKMP UDP on port 500 as well (though many devices, especially those intended for non-technical users, such as micro-cells and VOIP boxes, have ways of opening the UDP port when needed to the specific server and port associated with the IPSEC connection).