> This is a surprising set of claims. First of all, that is not the only information needed to configure IPsec: critically, correct use of IPsec requires you to specify exactly which cipher suites you want to allow. This is an unanswerable question for anyone who is not a cryptography expert. The defaults are virtually never secure or cross-platform.
This is so true. I once configured a Sonicwall and Cisco router and even though all encryption settings for both phase 1 and phase 2 were exactly the same, the tunnel refused to come up with negotiation errors. I had to change ciphers on both sides before it worked. Vendor incompatibility is an absolute pain with IPsec and IKE.