IPSec is a strong and reliable piece of technology, but it's too much a bag of large standards with too many parameters to choose from.
Just every proprietary firewall-box provider implements his own set of cutomiseable parameters related to other hardcoded defaults.
Yes, Symantec sucks hard. More than e.g. Watchguard.
If you want to be sure to be able to reliably connect different ipsec-stacks, just stick to open source implementations.
All the other problems you mentioned are about human mistakes. Watch and learn :)
IPSec is a strong and reliable piece of technology, but it's too much a bag of large standards with too many parameters to choose from.
Just every proprietary firewall-box provider implements his own set of cutomiseable parameters related to other hardcoded defaults.
Yes, Symantec sucks hard. More than e.g. Watchguard.
If you want to be sure to be able to reliably connect different ipsec-stacks, just stick to open source implementations.
All the other problems you mentioned are about human mistakes. Watch and learn :)