IPSec depends on the IP header on the packet being unchanged. NAT does change these, and so IPSec breaks.