Ideally, adding AES to an existing IPsec chip should involve a relatively simple change, not radical architectural modifications. To be fair, changing from triple-DES to AES does require a change due solely to the different block size, and this is not insignificant