A connection between the subnets behind the gateways moon and sun is set up. The host moon starts the Trusted Key Manager (TKM) and the Ada XFRM proxy, which relays XFRM kernel messages to charon. The authentication is based on X.509 certificates. In order to test the tunnel, client alice behind gateway moon pings client bob located behind gateway sun.