Hi ALL
It seems that IPS somehow misdetects the first port-shifted IKE packet to udp/4500 after NAT detection.If I disable the IPS then I am able to connect fine via Ipsec
https://community.sophos.com/products/unified-threat-management/astaroorg/f/75/t/64144
Thanks