I just realized I've been fueling this round-and-round due to a misinterpretation on my part. From IKE, ... If ISAKMP is acting as a client negotiator on behalf of another party, the identities of the parties MUST be passed as IDci and then IDcr. This is clearly what everyone is referring to, and I had forgotten this. My apologies for the error on my part.