The roadwarrior carol and the gateway moon use the botan plugin based on the Botan library for all cryptographical functions whereas roadwarrior dave uses the default strongSwan cryptographical plugins. The authentication is based on X.509 certificates and the key exchange on modp3072.

Upon the successful establishment of the IPsec tunnels, the updown script automatically inserts iptables-based firewall rules that let pass the tunneled traffic. In order to test both tunnel and firewall, both carol and dave ping the client alice behind the gateway moon.