For firmware version 1.16.2 or lower
Check if your WAN1 is in passthrough mode and then verify the following checklist, pay special attention to interface binding section for IPSec:
Passthrough configuration checklist
If WAN1 is not in passthrough mode, then make sure NAT traversal is enabled for IPsec VPN traffic on Firewall originating IPSec traffic. Again make sure Interface binding is added for the destination IP endpoint on Mushroom (under Advanced tab).