Summary
StrongSwan IPsec with FIPS option must use keyexchange=ikev2
Use case
9.1.3. Module Configuration
In order to run the module in FIPS mode of operation, the following setting must be included in the ipsec.conf
file:
keyexchange=ikev2
This configuration restricts the module to work with IKEv2 authentication.