Thanks dude.
Some of our customer set the device with internal ip(172.16.x.x,10.x.x.x), and use aggressive mode IKE with NAT traversal.
They don't like to change, so I am trying to figure it out. But NSX did not support aggressive mode.
Or does NSX IPsec VPN can process NAT traversal in main mode?