They only route UDP and TCP to your VM, so if you want IPSec, you have to mess about with 'Amazon Virtual Private Cloud'.