Summary
Disable all StrongSwan IPsec default plugins, enabling only FIPS-compliant ones
Disabling the default crypto plugins in strongSwan 5.9.6+ and enabling one that links a FIPS-certified crypto library (e.g., OpenSSL) prevents strongSwan from doing any crypto operations itself.
https://docs.strongswan.org/docs/5.9/install/autoconf.html