At the outset the gateway authenticates itself to the client by sending an
IKEv2 RSA signature accompanied by a certificate.
The roadwarrior carol sets up a connection to gateway moon.
carol uses the Extensible Authentication Protocol
in association with the Authentication and Key Agreement protocol
(EAP-AKA) to authenticate against the gateway. In this scenario,
quintuplets from the SQL database /etc/ipsec.d/ipsec.db are used instead
of a physical USIM card on the client carol. The USIM provider on
gateway moon also stores the quintuplets in an SQL database.