You must configure NAT Transparency
The IPSec NAT Transparency feature introduces support for IPSec traffic to travel through NAT or Point Address Translation (PAT) points in the network by addressing many known incompatabilites between NAT and IPSec.
NAT Transparency uses User Datagram Protocol (UDP) port 4500 to encapsulate IPSec packets. By default, PIX drops all inbound connections coming from the outside. You must open this port for NAT Transparency to work.
Issue this command: for example
Pix#config t
Pix(config)#isakmp nat-traversal
For more information, refer to
http://www.cisco.com/en/US/products/sw/iosswrel/ps1839/products_feature_guide09186a0080110bca