A quick note, for anyone running strongswan (an ipsec ike2 vpn): switch over to the new conf file format and daemon system sooner rather than later. If you are upgrading to a newer distro (F42 for me), the old strongswan system just doesn't work propely. It'll rekey improperly and just drop SAs (connections) in H2H/N2N scenarios. Nothing you can do will fix this.
Switch to the new format and everything just works. Unfortunately, translating between the old & new conf formats isn't the easiest thing (even with the automated python conversion script) as there isn't a 1-to-1 mapping of options.
Hint: you'll probably need 2 children for a roadwarrior connection... if you know, you know.