Than measure the time of the 1st IKE packet sent as a initiator and the time the phase2 SPI are set. That time would very for all of the variable I mention before.
Ideally, you could run tshark and look at timestamps of a flow of packets for the IKE1 and ESP data. if you are critical you could use IKEv2 to maybe shave a few hairs off in "ms" but this is not going to be very noticeable to the end user & then you have the variable in either the initiator or responder & the layer3 path.
All I can tell you, ipsec-vpns are short in overall setup times than ssl-vpns.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.