Found that this is NAT-T enabled and then disabled again. during the change there is something weird going on, but the tunnel still does not get established.
Please look at the second log I sent.
This is looking at a similar problem. http://forum.pfsense.org/index.php/topic,5473.0.html
But I am using the IPSEC on the WAN interface so probably not a routing problem - problem with CARP?
-I don't think so because I have a different site with a m0n0wall connecting perfectly, only the Zyxel is bugging me!
I set the MTU on the zyxel to 1400 just to make sure it is not ADSL that is eliminating the reply and thus the timeout, but no result.
Any ideas?
Thanks!