swanctl doesn't do any (online) certificate validation, it just parses and or decrypts them and passes them on to the daemon.
Tests transport mode and UDP encapsulation with random source ports. Interestingly, the responder always uses the same SA to respond (maybe due to the cache on the policy).