The roadwarrior carol sets up a connection to gateway moon. The strong mutual authentication of both peers is based on EAP-TLS only (without a separate IKEv2 authentication), using TLS client and server certificates, respectively.
The roadwarrior dave doesn't have the appropriate CA certificate installed and, therefore, doesn't trust gateway moon's certificate and rejects it.