>> Yes. I had bad experiences with the built-in IPSec implementation (via
>> the netfilter module) and wanted to have tools like "ipsec eroute" to
>> control (and view) the tunnels. The kernel IPSec has hidden so much that
>> I never knew where I should look for configuration problems. This may
>> have changed since I last checked.
There are definitely issues which still need to be resolved with the 26sec
stack.  But this is not one of them.  You can look at the policies (aka
eroutes) using setkey -PD and manipulate them using setkey.

Future versions of ip(8) will also allow you to do this via ip xfrm policy.

