Here's a real world example of peer-to-peer VPN only. Actual use is for a WiFi connection:
Code:
ike passive esp from 192.168.1.1 to 192.168.2.51 \
srcid jggimi.jggimi.homeip.net dstid netbook.jggimi.homeip.net \
tag ipsec
This is sufficient to set up bi-directional SAs and Flows. Works with -current's (and 4.8's) ACPI sleep mode on the netbook, too.