curl - Add support for client-side URL transfer library
debug - Enable extra debug codepaths, like asserts and extra output. If you want to get meaningful backtraces see https://wiki.gentoo.org/wiki/Project:Quality_Assurance/Backtraces
dhcp - Enable server support for querying virtual IP addresses for clients from a DHCP server. (IKEv2 only)
eap - Enable support for the different EAP modules that are supported
farp - Enable faking of ARP responses for virtual IP addresses assigned to clients (IKEv2 only)
gcrypt - Enable dev-libs/libgcrypt plugin which provides 3DES, AES, Blowfish, Camellia, CAST, DES, Serpent and Twofish ciphers along with MD4, MD5 and SHA1/2 hash algorithms, RSA and DH groups 1,2,5,14-18 and 22-24(4.4+). Also includes a software random number generator.
gmp - Add support for dev-libs/gmp (GNU MP library)
ldap - Add LDAP support (Lightweight Directory Access Protocol)
non-root - Force IKEv1/IKEv2 daemons to normal user privileges. This might impose some restrictions mainly to the IKEv1 daemon. Disable only if you really require superuser privileges.
openssl - Enable dev-libs/openssl plugin which is required for Elliptic Curve Cryptography (DH groups 19-21,25,26) and ECDSA. Also provides 3DES, AES, Blowfish, Camellia, CAST, DES, IDEA and RC5 ciphers along with MD2, MD4, MD5 and SHA1/2 hash algorithms, RSA and DH groups 1,2,5,14-18 and 22-24(4.4+) dev-libs/openssl has to be compiled with USE="-bindist".
pam - Add support for PAM (Pluggable Authentication Modules) - DANGEROUS to arbitrarily flip