Roadwarrior carol proposes 3DES_CBC encryption (together with
HMAC_SHA1 authentication) in the first place and AES_CBC_128 encryption in
second place for both the ISAKMP and IPsec SAs. Gateway moon defines
ike=aes128-sha1 but will accept any other supported algorithm proposed
by the peer during Phase 1. But for ESP encryption moon enforces
esp=aes128-sha1! by applying the strict flag '!'.