ipsec with static keys pfkey interface there already not too hard to add real IPsec bgpd loads the SAs into the kernel bgpd sets up the flows Juniper can do static-keyed IPsec as well works just fine Cisco cannot maybe there's a feature set you could pay extra for, who knows Unfortunately not really used