Indeed, it was a surprise to me when with the original ACL of UDP500 and UDP4500, the IPSEC VPNs passed through the FTD and were NATed to the ASA where they all came up, but no traffic passed... Once I added ESP to the ACL all was well in the world. I double checked that NAT traversal was enabled on the VPNs, even though as they were using port 4500, it was pretty likely, so can only assume that if I'd had an MX instead of an FTD, it would either ignore ESP or you'd have to allow all ports 🤔