PKI and IPSec IKEv2 site-to-site VPN

As you said, I changed the “authentication id” like below.
And I used the following strongswan configuration for the client-side.
path: /etc/strongswan.d/ipsec.conf

I also used the following configuration in swanctl, but the result was the same.
path: /etc/swanctl/swanctl.conf

And I got the following output, but I still do not have an up IPSec connection.
This is ipsec status:

This is journalctl output:

This is tcpdump in CA (VyOS):

Can you tell us what the problem is? I want to implement the PKI and IPSec IKEv2 remote access VPN scenario.
Thank you in advance for your help.