An IPsec transport-mode connection between the hosts moon and sun is successfully set up. The authentication is based on X.509 certificates.
Upon the successful establishment of the IPsec connection, the updown script automatically inserts iptables-based firewall rules that let pass the protected traffic. In order to test the host-to-host tunnel moon pings sun.