As a follow-up to my own post…
By enabling the " Prefer old IPsec SAs " my problem has been resolved. The IPSec connection still tries for multiple SAD entries but falls back to the proper number, two.
This config option can be found, in version 1.2.3, in the System menu, under Advanced, in the Miscellaneous config options.
Jason