I think I dug in over my head, and am hoping some kind soul can throw me a lifeline.
Here's the config.
Server (A) runs RHEL 6.8 and StrongSwan 5.5.3, running IPsec VPN to various clients on the Internet. The clients inhabit the 10.200.x.x domain. The server inhabits the 192.168.0.x domain...