Mhm as a "workaround" i've removed the whole IKEv1 block fom ipsec.conf (+increased dpddelay)
Then copying it over +live reload via /jffs/scripts:
ipsec statusall then shows only listening for ikev2
So far so good, ikev2 clients still connect fine - but i'm a bloody newb when it comes to...