Your acl can reference just esp and udp/500.
access-list 101 permit esp any any
access-list 101 permit udp any any eq isakmp
If you're allowing clients on the inside out, you can try instead of adding the above to your public acl.
ip inspect name FW isakmp
HTH,
John
HTH,
John
*** Please rate all useful posts ***