Greg White,.
I have noted your comment on some documentation found on the web, "I have 
successfully (and repeatedly) used Nortel VPN client on a NATed host through a 
FreeBSD gateway."
Currently i have the same problem with a Nortel BCM Running M$ Windows VPN, the 
BCM sit's behind a FreeBSD Firewall / NATD.
---- Network ----
ADSL Modem
    |
FreeBSD Server / Gateway / HTTP etc.
    | 192.168.2.242      |    192.168.1.1
Nortel BCM            LAN
-----------------------------------------------------------------
Can you please provide me with any help (documentation) as to how you were able 
to successfully get IPSec Forwarding through the Nat'ed BSD Server without 
breaking IPSEC_AH
Thanks
Craigrm