In IKE phase 2 the roadwarrior carol proposes to gateway moon the ESP AES 128 bit encryption algorithm combined with AH SHA-1 authentication. In order to accept the AH and ESP encapsulated plaintext packets, the iptables firewall marks all incoming AH packets with the ESP mark. The tunnel mode connection is tested by carol sending a ping to client alice hiding behind gateway moon.