Hi Marko, > What is the reason for this ? Is it the expected behaviour ? Yes, how could the client know that this is the first IKE_SA with the peer if it doesn't know the peer's identity (rightid=%any)? Regards, Tobias