This scenario tests repeated authentication according to RFC 4478.
The initiator carol sets a large reauth_time=60m but the responder
moon defining a much shorter reauth_time=30s proposes this
value via an AUTH_LIFETIME notification to the initiator as it can't initiate
the reauthentication itself due to the EAP authentication. Thus the
IKE reauthentication takes places after less than 30s. A ping from
carol to client alice hiding in the subnet behind moon
tests if the CHILD_SA has been recreated under the new IKE_SA.