Comment 2 for bug 2049624

Revision history for this message
Dmitriy Rabotyagov (noonedeadpunk) wrote :

Hey there,

I think, you actually should be able to provide a custom template of config for both ipsec.conf and strongswan.conf through appropriate config options:
https://docs.openstack.org/neutron-vpnaas/latest/configuration/l3_agent.html#strongswan

However, if memory does not fail me, EL are supposed to be using libreswan, which is quite outdated at the moment.

There is a patch though [1], which potentially fixes state of libreswan

[1] https://review.opendev.org/c/openstack/neutron-vpnaas/+/895824