I forgot an important requirement:When the keying method is used to protect a SIP/SRTP application, the protected application MUST work in all NAT traversal scenarios in which the unprotected application works.
Thanks Francois for the clarifications. David