veni, vidi, vici!
It's nice when stuff starts to work. We can now enter our lab, get a DHCP address, simultaneously submitting our RSA key to the DHCP server which inserts it into DNS, and then create an IPsec security association to the router!
huzzah.
this took far too much configuration magic.