[IPSEC]: Restrict socket policy loading to CAP_NET_ADMIN.