The roadwarriors carol and dave set up a connection each to gateway moon. The key exchange is based on NTRU encryption with a cryptographical strength of 128 bit and 192 bit for carol and dave, respectively. Authentication is based on strong preshared keys (PSKs). Both carol and dave request a virtual IP via the IKEv2 configuration payload by using the vips = 0.0.0.0 parameter. The gateway moon assigns virtual IP addresses from a simple pool in a monotonously increasing order.
Upon the successful establishment of the IPsec tunnels, the updown-script automatically inserts iptables-based firewall rules that let pass the tunneled traffic. In order to test both tunnel and firewall, both carol and dave ping the client alice behind the gateway moon.