iptables -t nat -A PREROUTING -d DESTINATION_IP -j DNAT --to-destination NEW_DESTINATION_IP
iptables -t nat -A POSTROUTING -s SOURCE_IP -d NEW_DESTINATION_IP -j SNAT --to-source NEW_SOURCE_IP
Next, you need to sure that IPSec policy contains both IP (NEW_SOURCE_IP and NEW_DESTINATION_IP)
Masquerade action does not work when you use IPSec, because IPSec tunnels haven't interface.