IPSec förutsätter följande (wikipedia):
   In order for IPsec to work through a NAT, the following need to be allowed on the firewall:
    * Internet Key Exchange (IKE) - User Datagram Protocol (UDP) port 500
    * IPsec NAT-T - UDP port 4500
    * Encapsulating Security Payload (ESP) - Internet Protocol (IP) 50

  Often this is accomplished on home routers by enabling "IPsec Passthrough".
  

Detta är de förutsättningar som jag vet om dagens QuickVPN:

Referenser:
RFC 3715: IPsec-Network Address Translation (NAT) Compatibility Requirements
RFC 3947: Negotiation of NAT-Traversal in the IKE