@MacLemon sad news :( IIRC there was an article talking about how the NSA contributed to IPSec to make it needlessly complicated, thus making successful proper implementations rare enough that they could still be hacked.
Have you considered looking into wireguard? (mostly for my own [morbid] curiosity)