From my personal experience it looks like the other party did not send back a certificate as requested by this host, or the packet got lost on the network. IKE packets can be as large as 3,000 bytes, and China's Internet is known to have Path MTU "black holes" [1].

Please try ECDSA certificates (instead of the usual RSA) in addition to ECDH cipher suites to reduce datagram size if this is an option for you.

1) https://en.wikipedia.org/wiki/Path_MTU_Discovery#Problems

