An IPsec transport-mode connection between the natted host alice and gateway sun is successfully set up. The client venus behind the same NAT as client alice also establishes the same transport-mode connection. sun uses the connmark plugin and a %unique mark on the CHILD_SAs to select the correct return path SA using connection tracking. This allows sun to talk to both nodes for client initiated flows, even if the SAs are actually both over moon.
To test the connection, both hosts establish an SSH connection to sun.