Today I had the same issue.
Port Forwarding UDP 500 and UDP 4500 to the inside LAN-adres of the hub will do.
Advise: test your Client VPN with a iPad or iPhone. This worked for me, immediately.
With the Apple clients you will see UDP 500 and UDP 4500 is okay.
MS Windows has problems with NAT-T (NAT Traversal) for ages.