Howdy, IPsecPolciyGroup binds together an IKERule and and IPsecRule. I'd like to see a layer of abstraction introduced, namely a KeyManagementRule. Then under keyManagementRule, we could use IKE for KM services if we wanted, but we could also use kerberose, or son-of-ike or manually entered keys, or.... -- Ricky Charlet : Redcreek Communications : usa (510) 795-6903