A quick note, for anyone running strongswan (an ipsec ike2 vpn): switch
over to the new conf file format and daemon system sooner rather than
later. If you are upgrading to a newer distro (F42 for me), the old
strongswan system just doesn't work propely. It'll rekey improperly and
just drop SAs (connections) in H2H/N2N scenarios. Nothing you can do will
fix this.
Switch to the new format and everything just works. Unfortunately,
translating between the old & new conf formats isn't the easiest thing
(even with the automated python conversion script) as there isn't a 1-to-1
mapping of options.
Hint: you'll probably need 2 children for a roadwarrior connection... if
you know, you know.