Ivan Pepelnjak of ipSpace.net comments:
Jason Edelman wrote a great blog post after watching Ethan Banks struggle with yet another multi-vendor IPsec deployment. Some of his ideas make perfect sense (wiki-like web site documenting working configurations between vendor X and Y for every possible X and Y), others less so (tunnel broker — particularly in view of recent Tor challenges), but let’s step back a bit and ask ourselves “Why is IPsec so complex?”
Ivan once again asks a simple question with a no-so-simple answer. IPSec has many layers that need to be understood. Ivan does a great job of teaching us about them.
Read more at: Why is IPsec so Complex?