The roadwarrior carol sets up a connection to gateway moon. At the outset the gateway authenticates itself to the client by sending an IKEv2 digital signature accompanied by an X.509 certificate.

Next carol uses a mutual EAP-TLS authentication based on X.509 certificates. The gateway forwards all EAP messages to the AAA RADIUS server alice.