`listen-netns` is new in ocserv 1.1.1, while iproute2's `ip netns` will work
more universally on Linux, allowing testing on older Linux distributions (see
https://gitlab.com/openconnect/vpnc-scripts/-/commit/
c95a3ad0e77963fea73c185ff0308e1edabe522c#note_457425702)
Signed-off-by: Daniel Lenski <dlenski@gmail.com>
isolate-workers = @ISOLATE_WORKERS@
-listen-netns = @LISTEN_NS@
+# Only supported in ocserv v1.1.1+; use iproute2's ip netns to run
+# in network namespaces with earlier versions.
+#listen-netns = @LISTEN_NS@
max-ban-score = 0
isolate-workers = @ISOLATE_WORKERS@
-listen-netns = @LISTEN_NS@
+# Only supported in ocserv v1.1.1+; use iproute2's ip netns to run
+# in network namespaces with earlier versions.
+#listen-netns = @LISTEN_NS@
max-ban-score = 0
echo " * Running server on ${ADDRESS}:${PORT}"
-# runs on NSNAME2 due to configuration
-${OCSERV} -p ${PIDFILE} -c ${CONFIG} ${DEBUG} -f &
+# run on NSNAME2
+${CMDNS2} ${OCSERV} -p ${PIDFILE} -c ${CONFIG} ${DEBUG} -f &
sleep 4
echo " * Running server on ${ADDRESS}:${PORT}"
-# runs on NSNAME2 due to configuration
-${OCSERV} -p ${PIDFILE} -c ${CONFIG} ${DEBUG} -f &
+# run on NSNAME2
+${CMDNS2} ${OCSERV} -p ${PIDFILE} -c ${CONFIG} ${DEBUG} -f &
sleep 4