Well, i don't know the nortel, but what you need is to get all settings that say something about IPSEC, to run as standard and no proprietary settings like udp encapsulation or tcp encapsulation and then make sure that your IKE proposals are exactly matched in both ends, as well as the proxy src and dst ip networks that you wan't to encrypt.
And then you'll prolly still have to debug extensively to get it working :-(
But then it should work fine.
Jan