[strongSwan] Multiple charon daemons mininet namespaces

Piyush Agarwal agarwalpiyush at gmail.com
Wed Apr 26 20:11:06 CEST 2017

I need to run multiple ipsec charon daemons in multiple mininet namespaces
(perhaps some semantics change from ip namespaces).

Sure enough, on following steps from
https://wiki.strongswan.org/projects/strongswan/wiki/Netns (including
piddir change), I could get multiple charon daemons running with* ip
network namespaces*.

I am not trying to achieve two things:
1) Run multiple charon daemons with mininet namespaces
2) Be able to do so without requiring piddir configuration option change.

Regarding (1): I am not sure if mininet namespaces provide for bind
mounting anything /etc/netns/<namespace name>/ to /etc/ for the process
running in that network namespace -- if it doesn't, I will bind mount
manually before starting charon/ipsec. So this should be okay.

But, I am trying to find how I can do away the piddir configuration change
and make it work directly from the deb file install. Is there no way to
achieve this? No environment variable that can be set?

Appreciate any comments/directions/pointers.

Thank you.

Piyush Agarwal
Life can only be understood backwards; but it must be lived forwards.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20170426/2bc831ca/attachment.html>

More information about the Users mailing list