A connection between the subnets behind the gateways moon and sun is set up. The authentication is based on X.509 certificates. Upon the successful establishment of the IPsec tunnel, leftfirewall=yes automatically inserts iptables-based firewall rules that let pass the tunneled traffic. After a while the CHILD_SA is rekeyed by moon (after a deliberately short time in this test scenario). In order to test both tunnel and firewall after the rekeying, client alice behind gateway moon pings client bob located behind gateway sun twice, once right after the rekeying and once after the old inbound SA has been deleted.