The problem persists in FW 00.06.06.1.
If I add the PSK manually in /etc/ipsec.secrets the tunnel works fine. However, /etc/ipsec* files are reproduced at boot time, thus this is not persistent across a reboot. Any suggestion how to implement that in the codebase persistently is appreciated.
edit:
as a workaround add the PSK without special characters in the WebUI -> Save. Then correct the PSK in /etc/config/strongswan.
Re-initiate IPsec "/etc/init.d/ipsec restart" or reboot.