The roadwarrior carol sets up a connection to gateway moon. At the outset the gateway authenticates itself to the client by sending an IKEv2 digital signature accompanied by an X.509 certificate.

Next carol uses the Microsoft CHAP version 2 (EAP-MSCHAPV2) method of the Extensible Authentication Protocol to authenticate herself. This EAP method is used e.g. by the Windows 7/8/10 Agile VPN client.

In addition to her IKEv2 identity which defaults to her IP address, roadwarrior carol uses the EAP identity carol.