~[#.#.#.#|fqdn.example.com|@fqdn.example.com|"CN=fqdn, OU=...."]
Availability: All Versions
Default: The value of 'left'
How the left participant should be identified for authentication; defaults to the value of 'left' (An IP address, or FQDN. Can be an IP address (in any ipsec_ttoaddr(3) syntax) or a fully-qualified domain name. If a FQDN, it MUST resolve. If you wish to use a FQDN that does not resolve, prefix it with @ (eg: leftid=@random.example.com).
The magic value %myid stands for the current setting of myid. This is set in config setup or by ipsec_whack(8)), or, if not set, it is the IP address in %defaultroute? (if that is supported by a TXT record in its reverse domain), or otherwise it is the system’s hostname (if that is supported by a TXT record in its forward domain), or otherwise it is undefined.