VPN with 1 to 1 nat

I have a basic quetion. We have a Mikrotik setup to manage a wireless network. We are using 10.15.x.x on the private side. For some customers that want to have a VPN we have created a 1 to 1 mapping
using dstnat and srcnat. I have tested the 1 to 1 by using a LINKSYS
with Private IP mapped to public and we can login from outside the network to the linksys. We have also tested the srcnat by setting up a laptop and assigning private ip then mapping to public. When we go to whatismyip.com it shows the correct Public address.

The problem is that the VPN will not connect up for the customers.
For example one customer is using a MULTITECH router on the private side and Nortel Contiity back at their remote office. They have the
VPN configured to use:
DES Encrpt, Tunnel IP SEc, TXT Pre shared Key

Since both sides are handling the VPN connections do we have to setup anything more than the 1 to 1 nat in the Mikrotik.

We used to use a AIRLOK box and we only had to configure 1 to 1 nat to allow both sides to connect.

What am I missing with the Mikrotik?

Thanks for any help I think I am missing something very easy.

Kevin

IPSec over NAT might not work correctly.
NAT-T traversal support that is added to RouterOS3 might help to accomplish IPSec over NAT scenario.

My Dear Friend:

Can you please help to understand how to did IP mapping. Its not working with me properly. I neend to know from you please. Just paste the examples here so that i can have it configured in my server.

Thanks

Vasi