bgpd - ipsec integration As we had the pfkey interface already, it was not too hard to do real IPsec bgpd loads the SAs into the kernel bgpd sets up the flows Juniper can do static-keyed IPsec as well, we're compatible. Cisco cannot, of course (could cause CPU load after all!)