AIX from IBM incorporates an IPSec VPN in the 4.3.3 distribution.
The included client is on the ICSA list. It can be managed
graphically, and has good documentation.
It is a "pure" IPSec implementation that does not use L2TP or PPTP,
which are available on other IBM networking products.
The IKE in AIX uses only RSA signatures or shared keys. The ability
to use X.509 certificates (and perhaps LDAP) should probably show
up in version 5.0.