The roadwarrior carol sets up a connection to gateway moon. At the outset the gateway authenticates itself to the client by sending an IKEv2 digital signature accompanied by an X.509 certificate.
Next carol uses the Authentication and Key Agreement (EAP-AKA) method of the Extensible Authentication Protocol to authenticate herself. This EAP method used in UMTS, but here a secret defined in swanctl.conf is used instead of a USIM/(R)UIM device. In addition to her IKEv2 identity carol@strongswan.org, roadwarrior carol uses the EAP identity carol.