By setting strictcrlpolicy=yes a strict CRL policy is enforced on both roadwarrior carol and gateway moon. Thus when carol initiates the connection and no current CRL is available, the Main Mode negotiation fails and a http fetch to get the CRL from the web server winnetou is triggered. When the second Main Mode trial comes around the fetched CRL will be available but because the certificate presented by carol has been revoked, the IKE negotatiation will fail.