bgpd - ipsec integration As we had the pfkey interface already, it was not too hard to do real IPsec bgpd loads the SAs into the kernel bgpd sets up the flows Juniper can do static-keyed IPsec as well, we're compatible. Cisco cannot - well, maybe there's a feature set you could pay extra for, who knows...