On Fri, 17 Jun 2011, Florian Harmuth wrote: > conn %default > compress=no > disablearrivalcheck=no > authby=rsasig > leftrsasigkey=%cert > rightrsasigkey=%cert You're missing a leftcert=/etc/ipsec.d/certs/yourcert.pem Paul