Symptom
When using NAT-T and UDP encapsulation of IPsec packets, the UDP length field is not computed properly.
Firewall devices typically block that type of traffic and the IPsec traffic might be dropped.
Workaround
Do not use NAT-T.
Create rules on Firewall to disable the UDP checks for this particular traffic.