The only thing I would suggest is opening UDP port 500 on the CP, which you already did.

Also make sure you are allowing IP 50 and 51 (ESP and AH). These are the three components required to...