Roadwarrior carol proposes 3DES_CBC encryption (together with HMAC_SHA1 authentication) in the first place and AES_CBC_128 encryption in second place for both the ISAKMP and IPsec SAs. Gateway moon defines ike=aes128-sha1 but will accept any other supported algorithm proposed by the peer during Phase 1. But for ESP encryption moon enforces esp=aes128-sha1! by applying the strict flag '!'.