cmb, thank you for information. Yes, I'm using IKEv2, for security. I didn't know that switching to IKEv2 also [accidentally] activates MOBIKE. It doesn't seem to have been mentioned in the 2.2 release notes.
From pftop status display (below), I can confirm that ESP tunnels between pfSense firewalls with public IP addresses remain pure ESP, not UDP-tunneled. It's just the IPsec status page that displays misleading information.
Thanks again!
pfTop: Up State 1-100/17675, View: default, Order: dest. port
PR D SRC DEST STATE AGE EXP PKTS BYTES
esp I xxx.xxx.11.62:0 xxx.xxx.84.122:0 2:2 38661 59 8936K 8989M
esp O xxx.xxx.84.122:0 xxx.xxx.227.40:0 2:2 41009 60 228K 40M
...
tcp I 74.125.82.172:33980 192.168.0.75:25 10:10 106 11 491 340K
tcp O 74.125.82.172:33980 192.168.0.75:25 10:10 106 11 491 340K
tcp I 192.168.19.4:4261 192.168.12.20:42 4:4 39727 86274 194 20994
tcp I 192.168.16.3:1087 192.168.12.20:42 4:4 37625 84775 186 19694
udp I 192.168.12.26:56079 8.8.8.8:53 1:2 15 15 2 352
udp I 192.168.12.26:55595 8.8.8.8:53 1:2 12 18 2 276
udp I 192.168.12.16:56447 23.5.165.172:53 1:2 7 23 2 152
...