The roadwarriors carol and dave set up a connection each to gateway moon. The IKEv1 main mode authentication is based on X.509 certificates. On the gateway two connections with differing parameters are defined: One for carol using the IKE proposal aes128-sha256-modp3072 allowing to reach host alice and one for dave using the IKE proposal 3des-sha1-modp2048 allowing to reach host venus.

Since the IP addresses of carol and dave are not known to moon the matching connection definition can only be determined by moon after the peer identities have been received.

Upon the successful establishment of the IPsec tunnels, carol pings the client alice and dave the client venus lying in two different subnets behind the gateway moon.