This can be acheived only if the VPN terminating device on the outside is capable of NAT Transparent mode. The NAT transparent mode solves this problem by encapsulating ESP within UDP and sending it to a negotiated port (in most cases end-user configurable port assignment.
-John