I measure the path first — MTU in both directions, NAT mapping behaviour, which ports and protocols get through, idle-mapping lifetime, loss and jitter at tunnel-sized packets — then build the tunnel around what's actually there. IPsec, WireGuard or OpenVPN.