Some handy commands to see what's going on with a strongswan-based ipsec connection ip -s xfrm state ip route list table 220 ipsec status