quickvpn client would use ssl to establish tunnel, during the verifying network, it would use IPSec to establish another tunnel for the ping purpose. So please create Group VPN first.
For the "expired" entry, if the pool are full, new host would use those old IPs; if the pool is not full, new host would use next new IPs available.
If the client can not get ip, then need to troubleshoot, or raise a case for that.