Ever need to basically traceroute with ESP traffic? Handy when you're having IPsec problems because the ESP traffic doesn't make it between point A and B on the Internet. hping to the rescue, increment the TTL (-t) by one each time, and see where you stop getting TTL exceeded in transit messages.
hping -0 184.108.40.206 -H 50 -d 10 -t 1
replacing 220.127.116.11 with the remote IPsec endpoint's IP.