j3g@ubuntu-16:~$ sudo ipsec statusall [sudo] password for j3g: Status of IKE charon daemon (strongSwan 5.3.5, Linux 4.4.0-116-generic, x86_64): uptime: 9 hours, since Sep 11 14:12:51 2018 malloc: sbrk 1486848, mmap 0, used 370000, free 1116848 worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 0 loaded plugins: charon test-vectors aes rc2 sha1 sha2 md4 md5 random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs8 pkcs12 pgp dnskey sshkey pem openssl fips-prf gmp agent xcbc hmac gcm attr kernel-netlink resolve socket-default connmark stroke updown Virtual IP pools (size/online/offline): 10.10.10.0/30: 2/0/0 10.10.11.0/30: 2/0/0 Listening IP addresses: 192.168.123.129 Connections: standard: 192.168.123.129...%any IKEv2, dpddelay=300s standard: local: [s.acme.xyz] uses public key authentication standard: cert: "C=OO, O=ACME, OU=ACME Standard, CN=s.acme.xyz" standard: remote: uses public key authentication standard: ca: "C=OO, O=ACME, OU=ACME Standard, CN=s.i.acme.xyz" standard: child: 0.0.0.0/0 === dynamic TUNNEL, dpdaction=clear maintenance: 192.168.123.129...%any IKEv2, dpddelay=300s maintenance: local: [s.acme.xyz] uses public key authentication maintenance: cert: "C=OO, O=ACME, OU=ACME Maintenance, CN=s.acme.xyz" maintenance: remote: uses public key authentication maintenance: ca: "C=OO, O=ACME, OU=ACME Maintenance, CN=m.i.acme.xyz" maintenance: child: 0.0.0.0/0 === dynamic TUNNEL, dpdaction=clear Security Associations (0 up, 0 connecting): none