By setting strictcrlpolicy=yes a strict CRL policy is enforced on both roadwarrior carol and gateway moon. Thus when carol initiates the connection and no current CRL is available, the Main Mode negotiation fails but a http fetch to get the CRL from the web server winnetou is triggered. When the second Main Mode trial comes around, the fetched CRL will be available and the IKE negotiation completes.