Now you are confusing me .. If I remember correctly, when you add a routed IPsec tunnel there should already be a gateway created for you?
VTI is known to have MTU issues in FreeBSD, there is a bug somewhere around. I'd consider route based only if really necessary