I have extended my post, with highlights of direct IP assignment limitation in HiLink. Huawei's NAT usually causes different problems with IPSec even with DMZ feature enabled ;(Can't you use HiLink mode? It works OK. Of course it has the disadvantage of an extra NAT layer.