By setting strictcrlpolicy=yes a strict CRL policy is enforced on both roadwarrior carol and gateway moon. Thus when carol initiates the connection and only an expired CRL cache file in /etc/ipsec.d/crls is available, the Main Mode negotiation fails. A http fetch for an updated CRL fails because the web server is currently not reachable. Thus the second Main Mode negotiation fails, too. Finally an ldap fetch to get the CRL from the LDAP server winnetou is triggered. When the third Main Mode trial comes around, the fetched CRL has become available and the IKE negotiation completes. The new CRL is again cached locally as a file in /etc/ipsec.d/crls due to the cachecrls=yes option.