"Paul" wrote:

> You don't need to put in the rightid, it will come
from the certificate.

The problem was caused by the mismatch between the
rightid in isec.conf and the id the west received from
the peer. In west's ipsec.conf, I specified: 

rightid="C=ca, ST=ontario, O=xelerance, L=toronto,
OU=support staff, CN=east, e=east at xelerance.com"

The id from the east was:
"C=ca, ST=ontario, O=xelerance, OU=support staff,
CN=east, e=east at xelerance.com"

Either I remove rightid from ipsec.conf, as Paul
suggested, or I correct rightid to match with what the
east sends over, the ipsec connection will be
established successfully.  Thanks, Paul.


