By setting strictcrlpolicy=yes a strict CRL policy is enforced on both roadwarrior carol and gateway moon. When carol initiates an IPsec connection to moon, both VPN endpoints find a cached CRL in their /etc/ipsec.d/crls/ directories which allows them to immediately verify the certificate received from their peer.