Hello,
For the problem 1.
It looks like when ScreenOS looks for matching ikev2 gateway, it doesn’t take into account received IKE ID and always uses rsa-sig/rsa-sig gateway if it exists?
>>> This should not happen. Can you post soem more details like debugs ike outputs from the screenOS firewall.
Regards
Vatsa