A tunnel connecting the subnets behind the gateways moon and sun, respectively, is automatically established by means of the setting auto=start in ipsec.conf. The connection is tested by client alice behind gateway moon pinging the client bob located behind gateway sun.

leftfirewall=yes automatically inserts iptables-based firewall rules that let pass the tunneled traffic.