Why can't we have IPSec + IKEv2 everywhere as originally intended as part of IPv6. No "VPN" necessary.

We're not in IPv6 world yet, but even if we were, Amazon AWS EC2 would doubtless continue to make IPSec awkward.

They only route UDP and TCP to your VM, so if you want IPSec, you have to mess about with 'Amazon Virtual Private Cloud'.

That makes snooping much more difficult.

