What's your key life on Ike and IPSec?
Maybe extend it to 86400 for Ike and 43200 for IPSec so it doesn't renegotiate often. A reasonable enc/hash like aes128/sha1 should be fine.
Maybe extend it to 86400 for Ike and 43200 for IPSec so it doesn't renegotiate often. A reasonable enc/hash like aes128/sha1 should be fine.