connections {

   gw-gw {
      local_addrs  = 192.168.0.1
      remote_addrs = 192.168.0.2 

      local {
         auth = pubkey
         certs = moonCert.pem
         id = moon.strongswan.org
      }
      remote {
         auth = pubkey
         id = sun.strongswan.org 
      }
      children {
         net-net {
            local_ts  = 10.1.0.0/16 
            remote_ts = 10.2.0.0/16 

            updown = /etc/updown
            esp_proposals = aes128gcm128-x25519
         }
      }
      version = 2
      mobike = no
      proposals = aes128-sha256-x25519
   }
}