I think I have to apoligize, since the description is not clear. I just saw the example at the end of the description but that is for running the container in site to site VPN mode. The error message still indicates that the container is trying to manage networks which requires either using a privileged container or NET_ADMIN capability. The site-to-site VPN mode also requires the SYS_MODULE capability according to the description. Try NET_ADMIN first.