A connection between the subnets behind the gateways moon and sun is set up.
The authentication is based on X.509 certificates. Upon the successful
establishment of the IPsec tunnel, leftfirewall=yes automatically
inserts iptables-based firewall rules that let pass the tunneled traffic.
After a while the CHILD_SA is rekeyed by moon (after a deliberately short
time in this test scenario).
In order to test both tunnel and firewall after the rekeying, client alice
behind gateway moon pings client bob located behind gateway sun
twice, once right after the rekeying and once after the old inbound SA has been
deleted.