After establishing an IKE_SA, we check if any of its child configs define generic SELinux labels and install trap policies for them if necessary narrowed to the current (virtual) IPs.