server: Debian buster (4.19); Strongswan 5.7.2
ipsec.conf
conn %default keyexchange=ikev2 ike=aes256-aes128-sha256-sha1-modp3072-modp204