Things that will be of use to you:

*) the ipsec.conf man page
*) racoon (/usr/ports/security/racoon)
*) ipfilter

that's how we do it here...

