at the outset the gateway authenticates itself to the client by sending an IKEv2 RSA signature accompanied by a certificate. The roadwarrior carol sets up a connection to gateway moon. carol uses the Extensible Authentication Protocol in association with the Authentication and Key Agreement protocol (EAP-AKA) to authenticate against the gateway. This protocol is used in UMTS, but here a secret from ipsec.secrets is used instead of a USIM/(R)UIM. In addition to her IKEv2 identity carol@strongswan.org, roadwarrior carol uses the EAP identity carol.