The roadwarrior alice sitting behind the NAT router moon sets up a tunnel to gateway sun. Since the firewall on sun blocks the ESP protocol, enforced UDP encapsulation (forceencaps=yes) is used by alice to punch through this hurdle. leftfirewall=yes automatically inserts iptables-based firewall rules that let pass the tunneled traffic. In order to test the tunnel, host alice pings the client bob behind the gateway sun.