Initiate the CHILD_SA from the initiator
Shell
The output ends with
CHILD_SA net{1} established with SPIs ... and reports initiate completed successfully.Confirm the security associations on both hosts
Run this on the initiator and then on the responder:Shell
Each host reports
ESTABLISHED, IKEv2 with a child SA marked INSTALLED, TUNNEL. The responder’s local identity is CN=StrongSwan, the identity bound to the CryptoHub-resident key:local is the responder’s remote, and the SPI values match with the inbound and outbound roles swapped.
Confirm the CryptoHub performed the authentication
On the responder:Shell
The log shows charon loading the key from the token, then authenticating both identities:
CN=StrongSwan exists on the host.
Validate protected traffic
From the initiator, send traffic into the tunnel:Shell
All packets are answered with no loss.
Shell
The child SA reports non-zero, matching byte and packet counts in each direction, and the counters are mirrored between the two hosts:

