That exactly what I needed :) That had not occurred to me.

> So after getting IPSEC running using racoon and SPD after reading the howto
> It occurred to me that doing PSK with SPD directly instead of using racoon
> for a simple point to point setup seems a whole lot easier. (plus no ports
> needed for automatic keying).

You mean manually-added IPsec SAs?

> Can somebody give me the reasons why I might want to stay with racoon over
> SPD on a simple setup like I described?

If you have a sufficiently motivated adversary, he/she can capture your
traffic and replay it.  There's no replay protection without key refreshment.