The WLAN clients alice and venus secure all their wireless traffic by setting up an IPsec tunnel to gateway moon. The VPN network mask is Traffic with destination outside the protected network is NAT-ed by router moon. The IPsec connections are tested by pings from alice to venus tunneled via moon and to both the internal and external interface of gateway moon. Access to the gateway is set up by lefthostaccess=yes in conjunction with leftfirewall=yes. At last alice and venus ping the external host sun via the NAT router.

The host system controls the UML instances alice and carol via ssh commands sent over the virtual tap1 interface. In order to keep up the control flow in the presence of the all-encompassing tunnel to the gateway moon an auxiliary passthrough eroute restricted to the ssh port is statically set up by conn system.