The roadwarriors carol and dave set up a connection each to gateway moon. The authentication is based on distinct pre-shared keys and Fully Qualified Domain Names and includes a Postquantum Preshared Key (PPK) that's also mixed into the derived key material. The PPK_ID used by dave is unknown to moon but since both peers don't enforce the use of a PPK they fall back to regular authentication by use of the authentication data provided in the NO_PPK_AUTH notify. Upon the successful establishment of the IPsec tunnels, leftfirewall=yes automatically inserts iptables-based firewall rules that let pass the tunneled traffic. In order to test both tunnel and firewall, both carol and dave ping the client alice behind the gateway moon.