You can create a rule under Access-Control Policy to allow ESP by choosing ESP(50) under the destination port. Picture attached:
This translates to the following rule on the CLI
access-list CSM_FW_ACL_ line 22 advanced permit esp ifc inside any any rule-id 268440576