Solved! Go to Solution.
I think that there is not a big difference from the security view. ESP has a better performance than oNCP. So if you use VoIP i would recommend ESP.
I'd vote for ESP for the simple fact that it uses udp.. Less prone to port scans and the like and it's faster.
ESP has 1.5X the performance of NCP. Use ESP always.
I would not recommend always using ESP. In fact, there are cases where the packet size of ESP can do some very funky things to routers (WRT, DLINK). We have had numerous reports of faulty DNS, packet loss, etc. when using ESP transport mode. The benefit to using NCP/oNCP is that you have a lot more flexibility because it rides over TCP (connection-oriented, retransmission of lost packets) so if you don't need to run stream-dependent traffic like VoIP or streaming media, NCP can in fact be just as effective to the end-users.
Hope that helps.