
The usual IPsec way is to create IKE and
Child SAs as
needed. This is fine for gateways, but is inconvenient for human users.
You don't want the remote access client demanding your credentials just because the
mail client is
trying to reach the IMAP server.
When it's convenient for the user, she enters
her credentials,
and creates a stand-by IKE SA.
When IPsec needs an SA, only a non-intrusive CREATE_CHILD_SA exchange is done.