IPSec through NAT a feature on VPN3000 can be used in this situation. It wraps the IKE and IPSEC packet in UDP packet, multiple clients behind a PAT device will work fine
check and verify your pre-shared keys. The message below tell keys are mismatching02:38:14: %CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from 192.168.10.253 failed its sanity check or is malformed