When updating, did you leave the settings or set up the router again?
When I configure IPsec in Port Forwarding, a rule is created with these parameters.
config redirect
option proto 'any'
option name 'Exclude-IPsec-from-NAT'
option extra '-m policy --dir out --pol ipsec'
option vpn_type 'IPsec'
option target 'ACCEPT'
option dest 'wan'
option enabled '1'
And if you use localhost instead of IP? Can you also send a Troubleshoot file and your network topology to PM?
A Troubleshoot file contains a device's event logs, configuration files and other info useful for diagnostics. It can be downloaded from your device's WebUI, Troubleshoot page:
System → Administration → Troubleshoot
Regads.