In addition to everyone else's comments, you also need to include the original hosts inside your network (this is needed to trigger the VPN negotiation). Verify the NAT policy also will contain appropriate rules for the inside hosts to have NAT applied (you could also NAT the internal hosts to another external host other than your gateway's own IP, if you wanted). The original 192.168.1.x hosts AND the NAT IP needs to be in your VPN domain for your side. The remote side only needs your NAT IP.
This is what's causing your rekey to fail after 60 minutes.