The roadwarrior alice sitting behind the NAT router moon sets up a tunnel to gateway sun. UDP encapsulation is used to traverse the NAT router. leftfirewall=yes automatically inserts iptables-based firewall rules that let pass the tunneled traffic. In order to test the tunnel, the NAT-ed host alice pings the client bob behind the gateway sun.