If the devices were tied into VLANs through VPNs, then then packets could be captured over a virtual maintenance port.
True and the person scooping up packets on that maintenance port would most likely be in a position to have the keys also so they could decrypt. BUT seriously, that would be an enormous amount of packet data to collect and would have had to be done on each router. I’d believe in aliens at Roswell before believing that actually happened.