From the description, I suspect that the router is capable of terminating a VPN itself, so by default it will intercept any VPN packets and process them. The passthrough option allows these packets to be passed through as they are ignored by the router and processed like any other packet destined for a host on the ‘inside’.
Your second question is not so obvious. Phase 1 is UDP (IP protocol 17, port 500), the Phase 2 uses ESP (IP Protocol 50) so I suspect that UDP was permitted, but not ESP ? Does the config permit UDP and TCP but not other IP protocols ? Without seeing the config, and knowing the specific device it is a little difficult to diagnose further.