I ran the "sh crypto ipsec isakmp sa" and saw no associations. Then I checked the routing tables and noticed that EIGRP was being used. Doesn't IPsec need to be encapsulated into a GRE Tunnel to route with EIGRP? Maybe that's why there are no sa's being shown. If this was a model I created, I probably would come to that conclusion, but this is a sample model provided by the developers of the program. Did they miss something?