So, I'll speak up in favor of Paul's proposal because it better handles separation of key management and AH/ESP. If you use the IKE nonce, folks wishing to use counter-mode-based transforms with other key management protocols will need to do something special since the other KM protocols may not have an exact equivalent. - Bill