Hi Moon,
Thanks for your feedback. Do you work for Microsoft?
Enforcing TCP is against the RFC: http://tools.ietf.org/html/rfc3261. See section 18: All SIP elements MUST implement UDP and TCP. SIP elements MAY implement other protocols.
So clearly enforcing TCP is NOT allowed. Moreover, 3CX actually supports TCP. We are fully aware of the advantages of TCP. But the way Microsoft negotiates, its not RFC either and our TCP never 'kicks in'. As a matter of fact our 3CX Tunnel uses TCP, so there is no problem using TCP with 3CX.
In regards to security, there are plenty of ways to implement this well. For example, you could implement an OpenVPN link between sites easily. We are actually planning on making a free install to do this. Though anybody can do it today easily by downloading and installing OpenVPN. Some phones are rumored to ship with an OpenVPN client as well very soon. Yes, IPsec is a pig, but then again this is a microsoft thing. I was forced to study it for my MCSE

But there are so many better ways to do security nowadays.
I dont want to sound anti microsoft because we are not. We love windows. And the new windows 2008 is great.
However Microsoft OCS has been designed from the ground up to disrupt the VOIP and SIP standard and lock customers in to Microsoft standards. Witness the proprietary codecs, TCP as mentioned above, and plenty of other stuff. Note also that the Office Communicator 2007 only works with OCS. This is leveraging the Office installed base to try and enforce OCS. This is illegal here in the European Community and legal proceedings are just a matter of time. Office Communicator 2007 MUST and will support interoperability with 'real' SIP servers as well.
That said we are not ruling out OCS in the future, we are keeping a close eye on its development and will re-consider it in the future