To elaborate on Racoon, it is a daemon to manage/validate certificates and the like for dynamic IPsec connections from random IP addresses. This is normally needed, and makes things much more complicated.

But for simple, static IP addresses, Racoon is neither needed nor used, and the whole deal gets very simple as a result.
