Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
from router - router over the ipsec tunnel the traffic would be secure but on either side of the lan before it hits the tunnel you would be able to sniff it , most secure devices would have telnet disabled and only allow sshv2