I set the Ike to V2 now.
There is no traffic yet. i have to check if this is running before i can proceed fight with the firewall and the routing i think....
but the child SAs tell me always the first 2 available connections that are enabled. and no matter which one.
this time it shows only one, maybe the 2nd server on the other side is switched off
i cleand the ip address out because its a public IP
con1000:
#236 192.168.33.61/32
Local: cd989838
Remote: 60c4ba15 xxx.xxx.xxx.xxx/32
Rekey: 2542 seconds (00:42:22)
Life: 3472 seconds (00:57:52)
Install: 128 seconds (00:02:08) AES_CBC
HMAC_SHA1_96
IPComp: none Bytes-In: 0 (0 B)
Packets-In: 0
Bytes-Out: 0 (0 B)
Packets-Out: 0
when i disable this first two entries it shows me ( again i cleaned addresses out for being public, this time all )
con1000:
#238 xxx.xxx.xxx.xxx/32
Local: c144a229
Remote: 549b87ca xxx.xxx.xxx.xxx/32
xxx.xxx.xxx.xxx/32
Rekey: 2892 seconds (00:48:12)
Life: 3595 seconds (00:59:55)
Install: 5 seconds (00:00:05) AES_CBC
HMAC_SHA1_96
IPComp: none Bytes-In: 0 (0 B)
Packets-In: 0
Bytes-Out: 0 (0 B)
Packets-Out: 0
of course the remote addresses are different ones from the one before