"Use SSL, don't roll your own!"
Then we get BEAST, CRIME, Heartbleed, etc., and we discover that the dominant SSL/TLS implementation is a rat's nest of comically awful code:
Look at the older posts for LuLz like: http://opensslrampage.org/post/83007010531/well-even-if-time...
I wonder just how much scrutiny IPSec implementations have gotten, especially since it's such a usability nightmare that nobody uses it.