Initiate IKEv2
Run on the initiator:The output reports an established IKE_SA and an installed
net CHILD_SA. The responder log reports successful authentication for both peer identities.Prove protected traffic
From a host in the initiator protected subnet, send traffic to a host in the responder protected subnet:<RESPONDER_PROTECTED_HOST> with a reachable address covered by <RESPONDER_SUBNET>.
The ping receives three replies. Run
sudo ip -s xfrm state on each gateway and confirm that the ESP packet counters increase.Repeat after restart
Restart strongSwan on both gateways:The second process set loads the token key, establishes a new CHILD_SA, and carries protected traffic.

