> [1] https://wiki.strongswan.org/projects/strongswan/wiki/ExpiryRekey#IKEv2 Thanks for the hints, Tobias. I have patched the configuration like this: from esp_proposals = aes256-sha512-ecp521 to esp_proposals = aes256-sha512-ecp521,aes256-sha512 Marco