The roadwarrior carol sets up a connection to gateway moon. Both carol and moon define a static virtual IP using the leftsourceip parameter. leftfirewall=yes automatically inserts iptables-based firewall rules that let pass the tunneled traffic. In order to test the tunnel, carol pings the client alice behind the gateway moon as well as the inner interface of the gateway. The source IP of the two pings will be the virtual IP carol1. Also thanks to its virtual IP moon1 the gateway moon is able to ping carol1 by using the existing subnet-subnet IPsec tunnel.