I have TL-MR6400 v3 with LTE as WAN. My mobile operator gives me local IP behind NAT. As I see IPsec is the only type of VPN on this router that can be a client. I have a Strongswan as IPsec server with real static IP.
The problem is that Tunnel status is UP but no packet goes to port 4500. In dump I can see only requests to port 500 from high ports of NAT server and responces back. IKEv1 phases went well.