Hi Bill, I prefer configuration payload for serving the IP address, Domain name servers and other information. It gives flexibility in the deployment and the configuration can be configured locally OR configuration can be retrieved from the DHCP Server OR other mechanism. So, by de-coupling the serving IP address from specific protocol like DHCP will give lot of flexibility.-Ravi
As should surprise nobody, I strongly support the use of DHCP over IKE instead of the config payload approach for a number of reasons. Among other things it coexists better with existing non-IPsec network infrastructure and provides a better future expansion/extension path, and avoids a bunch of redundant standardization work. - Bill