By setting strictcrlpolicy=yes a strict CRL policy is enforced on both roadwarrior carol and gateway moon. The remote host carol initiates the connection and presents a certificate that has been revoked by the current CRL causing the IKE negotiation to fail.