FYI - I just initiated a network connection session on a PC into my SSL box through my Juniper SSG20 firewall. When I did a flow capture on the SSG20 I saw traffic flowing to/from the PC on ports 1111 and 1129. Killed and restarted the NC session and saw new traffic on 1139. Hope that helps a bit.
My IVEs sit behind internet-facing routers which allow only the following inbound traffic -
I'm wondering if the traffic you are seeing is the ESP traffic. NC will attempt to use ESP before switching to UDP 4500 or NCP.