I left out an important detail.. I'll be using the Cisco VPN Concentrator (yes, it's end-of-life this summer).. it has the capability of moving IPSEC onto a regular old TCP port, instead of using ESP / protocol 50 or 51. Slightly wider compatibility this way, in case people are indeed blocking 50 or 51. IKE, as well as the tunnel itself will use this TCP port.