For anyone interested the latest NSA published guidelines on securing IPSec virtual private metworks.
https://media.defense.gov/2020/Jul/...PRIVATE_NETWORKS_2020_07_01_FINAL_RELEASE.PDF
https://media.defense.gov/2020/Jul/...PRIVATE_NETWORKS_2020_07_01_FINAL_RELEASE.PDF