Hi,
We can ONLY encapsulate IPSec traffic into UDP for Client to LAN Implementation for the CVPN3000 at this time.
For Site to Site implementations we donot need to do that, as the NAT operation happens before the IPSec happens and you can do NAT and then IPSec that traffic on the Routers, Sample to clear this concept can be found at: http://www.cisco.com/warp/public/707/same-ip.html
Hope this helps,
Regards,
Aamir
-=-