Hi,
The problem in masquerading VPN traffic is that Linux 7.0's IP masquerade has no awareness of IP protocols other than TCP, UDP and ICMP.!
IPsec over a VPN requires a change that adds support for the ISAKMP key exchange protocol.
You need to update to Redhat 7.1 or use the 7.0 Clarkconnect box as the VPN client without NAT from one of your windows boxes.
/Raz