Phase 2 / Data Plane is the Absolute Blocker Even if Phase 1 somehow succeeds, ESP (IP Protocol 50) cannot be NATted:
ESP has no TCP/UDP port numbers — NAT has nothing to track/translate The NAT device will drop ESP packets silently No data will flow; the tunnel stays non-functional