Roadwarrior carol proposes 3DES encryption (together with SHA-1 authentication) in the first place and AES-128 encryption in second place for both the ISAKMP and IPsec SAs. Gateway moon defines ike=aes-128-sha but will accept any other supported algorithm proposed by the peer during Phase 1. But for ESP encryption moon enforces esp=aes-128-sha1! by applying the strict flag '!'.