The roadwarrior carol sets up a connection to gateway moon. At the outset the gateway authenticates itself to the client by sending an IKEv2 digital signature accompanied by an X.509 certificate.

Next carol uses the GSM Subscriber Identity Module (EAP-SIM) method of the Extensible Authentication Protocol to authenticate herself. In this scenario triplets from the file /etc/ipsec.d/triplets.dat are used instead of a physical SIM card.