> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Initiate and validate the tunnel

> Establish the IKEv2 CHILD_SA, verify ESP-protected traffic, and repeat after restart.

Establish the tunnel from the initiator and prove that protected traffic crosses the CHILD\_SA.

## Initiate IKEv2

Run on the initiator:

```shell theme={null}
sudo swanctl --initiate --ike initiator --child net --timeout 60
sudo swanctl --list-sas
```

<Check>
  The output reports an established IKE\_SA and an installed `net` CHILD\_SA. The responder log reports successful authentication for both peer identities.
</Check>

Run on the responder:

```shell theme={null}
sudo grep -E \
  "authentication of 'initiator.example.com'|authentication of 'responder.example.com'" \
  /var/log/charon-debug.log | tail -10
```

## Prove protected traffic

From a host in the initiator protected subnet, send traffic to a host in the responder protected subnet:

```shell theme={null}
ping -c 3 <RESPONDER_PROTECTED_HOST>
```

Replace `<RESPONDER_PROTECTED_HOST>` with a reachable address covered by `<RESPONDER_SUBNET>`.

<Check>
  The ping receives three replies. Run `sudo ip -s xfrm state` on each gateway and confirm that the ESP packet counters increase.
</Check>

## Repeat after restart

Restart strongSwan on both gateways:

```shell theme={null}
sudo systemctl restart strongswan-starter
sudo swanctl --load-all --clear --raw
```

Initiate the tunnel again from the initiator, then repeat the ping and XFRM checks.

<Check>
  The second process set loads the token key, establishes a new CHILD\_SA, and carries protected traffic.
</Check>
