I've noticed that established VPN tunnels never show up in netstat -a. The service ports (IKE, Wireguard, etc.) do show up as listening.
But established endpoints are never visible. Do they operate at a different layer of the network stack, or e.g. are using ESP and thus hidden? Regards Lloyd

