and a reminder - the /proc/sys/net/ipv4/xfrm4_gc_thresh param is a per-netns value, so it should be changed in each container.
and a reminder - the /proc/sys/ net/ipv4/ xfrm4_gc_ thresh param is a per-netns value, so it should be changed in each container.