Try this:
1.enable isakmp nat-traversal.
Network Address Translation (NAT), including Port Address Translation (PAT), is used in many networks where IPSec is also used, but there are a number of incompatibilities that prevent IPSec packets from successfully traversing NAT devices. NAT traversal enables ESP packets to pass through one or more NAT devices.
2. upgrate VPN client to latest verion(4.8), if you have lower version.