This scenario tests repeated authentication according to RFC 4478. The iniator carol sets a large ikelifetime=20m but the responder moon defining a much shorter ikelifetime=30s proposes this value via an AUTH_LIFETIME notification to the initiator. Thus the IKE reauthentication takes places after less than 30s. A ping from carol to client alice hiding in the subnet behind moon tests if the CHILD_SA has been inherited by the new IKE_SA.