Option 1 :
Enforce secure practices with regards to VPN parameter selection, and specifically the following:
Use "Main Mode" IKE with Certificates issued by a Certificate Authority, rather than "Aggressive Mode" with Pre-shared Keys. Note while this mode is more secure because it provides identity protection, it does require additional planning and resources to implement.
Resources listed under "Related Links" below can be referenced when configuring Main Mode Certificate based VPN tunnels.