My question is whether during the IKE and IPSec initialization (phase one and two) other than UDP 500 (ISAKMP), IP 50 (IPSec ESP) and IP 51 (IPSec AH) ports are in use. It seems that if in access-list only these ports are permitted as incoming traffic and nothing else the peers don't negotiate anything.