The roadwarrior carol proposes 3DES encryption with SHA-1 authentication in the first place and AES-128 encryption with SHA-1 authentication in the second place for both the ISAKMP and IPsec SA. The gateway moon enforces ike=aes-128-sha! for Phase 1 by using the strict flag '!', but will accept any other supported algorithm proposed by the peer for Phase 2 , even though moon defines itself esp=aes-128-sha1 only.