@freddy550
No. Your IPSec configuration has to be aware of the NAT, otherwise it will not connect.
Imagine, the remote site is 192.168.20.0/24 and it is natted to 10.227.56.0/24. So your phase 2 has to use 10.227.56.0/24 as remote network to connect to.