You are having here some MTU problems.
As the IPSec adds some overhead to the IP packets
the MTU decreases. The router informs the stations sending
1500Bytes packets and DF set via ICMP to decrease
the MTU.
At one end (based on your desription at remote site)
probably the station tries to send packets of 1500 octets size
and ignoes the router ICMP's.
You can control the behavior of DF bit in newer IOS's (12.2.T).