By setting strictcrlpolicy=yes a strict CRL policy is enforced on
both roadwarrior carol and gateway moon. Thus when carol initiates
the connection and only an expired CRL cache file in /etc/ipsec.d/crls is
available, the Main Mode negotiation fails. A http fetch for an updated CRL fails
because the web server is currently not reachable. Thus the second Main Mode negotiation
fails, too. Finally an ldap fetch to get the CRL from the LDAP server winnetou
is triggered. When the third Main Mode trial comes around, the fetched CRL has become
available and the IKE negotiation completes. The new CRL is again cached locally as a
file in /etc/ipsec.d/crls due to the cachecrls=yes option.