Just a few more details:
This is all on a test network 172.31.254.0/24. I've got pfSense 2.0-RELEASE running on an Alix box with a WAN address of 172.31.254.12/24 acting as the VPN concentrator. The LAN network is 192.168.32.0/24.
Client is Windows Vista box running Shrew 2.1.7. It is getting an address via DHCP at 172.31.254.70.
Since the two boxes are both on the same network, my assumption is that I don't need NAT-T. Perhaps that is wrong.
As for firewalling, I've disabled Windows firewall on the Windows machine and added allow all rules on all of the pfSense box's interfaces, including IPsec.
The symptoms are that the connection comes up, with neither pfSense or Shrew complaining, but the traffic doesn't flow.
The client (Windows box running Shrew) is accessing the test network through a WAP... Perhaps that is causing a routing issue, but all looks well from the routing table on the Windows workstation.