Why? - Remote Access
*The usual IPsec way is to create IKE and Child SAs as needed. This is fine for gateways, but is inconvenient for human users.
*You don't want the remote access client demanding your credentials just because the mail client is trying to reach the IMAP server.
*When it's convenient for the user, she enters her credentials, and creates a stand-by IKE SA.
*When IPsec needs an SA, only a non-intrusive CREATE_CHILD_SA exchange is done.