Firewall policy is probably to block everything by default unless explicitly allowed (hence explicitly opening port 80, 22, 443, etc.). Hence comments above saying that IPSec would need to be ...