I think Darren's summary is pretty accurate. It's kind of a toss up. However, one difference that I note is that with the dhcp approach, all client config is (potentially) done prior to the instantiation of the child sa. I'm not sure if this is a benefit or not, but it might be. Scott