I have just enabled VPN remote access on an existing NG FP1 firewall (must be this version for E3 compliance reasons).
From a client (I have tried FP3 and R56, over broadband and dial-up) I can create a site, authenticate and download topology without any problem. SecureClient diagnostics show successful phase 1 and Xauth negotiations.
However, when attempting to contact the VPN domain, the client displays "exchanging keys with firewall" for a time before returning the error "communication with gateway x at site x failed". During this process, the firewall does not appear to receive ant traffic at all from the client (implied rules are being logged as well).
After the failure, SecureClient diagnostics shows a failed phase 2 due to "gateway not responding".
I have tried changing the MTU size on the client, and have confirmed that the ISP router does not have any access lists on it.
I don't know what else to try other than rebuilding the firewall.