I have a Cisco 3620 acting as VPN gateway IPSEC 3DES. My ACL only permits ESP and UDP500 inbound on the external interface. My VPN clients can initiate and establish the VPN connection, my router assigns an IP address from my IP local in the router...