During a test rollout of the new rolling image, I noticed that the API tool we use to push configuration to the new devices wouldn't add the https configuration.
This ticket is only referencing the service https section of the configuration.
After some testing, I have found the following actions all throw an error for "TCP port "9000" is used by another service!":
- Assigning an IPv6 listen address after an IPv4 address
- Deleting an IPv6 listen address when an IPv4 listen address is present
- Assigning a listen address and port all at the same time.
To note, you can assign both IPv4 and IPv6 listen addresses at the same time, as long as the port is not changing.
Please let me know if anything is unclear or if the explanation needs further clarification
Actual testing:
Version being run:
vyos@vyos:~$ show system image Name Default boot Running ----------------------- -------------- --------- 2026.04.29-0041-rolling Yes Yes
Netstat to confirm nothing else is running
vyos@vyos# sudo netstat -nlutp Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 0.0.0.0:21982 0.0.0.0:* LISTEN 3057/sshd: /usr/sbi tcp 0 0 127.0.0.1:2604 0.0.0.0:* LISTEN 1668/ospfd tcp 0 0 127.0.0.1:2605 0.0.0.0:* LISTEN 1655/bgpd tcp 0 0 127.0.0.1:2602 0.0.0.0:* LISTEN 1662/ripd tcp 0 0 127.0.0.1:2601 0.0.0.0:* LISTEN 1647/zebra tcp 0 0 127.0.0.1:2623 0.0.0.0:* LISTEN 1644/mgmtd tcp 0 0 127.0.0.1:2618 0.0.0.0:* LISTEN 1703/fabricd tcp 0 0 127.0.0.1:2616 0.0.0.0:* LISTEN 1700/staticd tcp 0 0 127.0.0.1:2617 0.0.0.0:* LISTEN 1652/bfdd tcp 0 0 127.0.0.1:2612 0.0.0.0:* LISTEN 1688/ldpd tcp 0 0 127.0.0.1:2610 0.0.0.0:* LISTEN 1694/nhrpd tcp 0 0 127.0.0.1:2608 0.0.0.0:* LISTEN 1674/isisd tcp 0 0 127.0.0.1:2609 0.0.0.0:* LISTEN 1677/babeld tcp6 0 0 ::1:2603 :::* LISTEN 1665/ripngd tcp6 0 0 ::1:2606 :::* LISTEN 1671/ospf6d tcp6 0 0 ::1:2622 :::* LISTEN 1680/pim6d tcp6 0 0 :::21982 :::* LISTEN 3057/sshd: /usr/sbi udp 0 0 0.0.0.0:3784 0.0.0.0:* 1652/bfdd udp 0 0 0.0.0.0:123 0.0.0.0:* 2127/chronyd udp 0 0 127.0.0.1:323 0.0.0.0:* 2127/chronyd udp 0 0 0.0.0.0:4784 0.0.0.0:* 1652/bfdd udp6 0 0 :::7784 :::* 1652/bfdd udp6 0 0 :::3784 :::* 1652/bfdd udp6 0 0 :::123 :::* 2127/chronyd udp6 0 0 ::1:323 :::* 2127/chronyd udp6 0 0 :::4784 :::* 1652/bfdd [edit] vyos@vyos# sudo netstat -nlutp | grep 9000 [edit] vyos@vyos#
Adding a listen address and port at the same time:
vyos@vyos# show
api {
keys {
id test {
key 123
}
}
rest {
}
}
[edit service https]
vyos@vyos# set listen-address 192.168.0.1
[edit service https]
vyos@vyos# set port 9000
[edit service https]
vyos@vyos# compare
[https]
+ listen-address "192.168.0.1"
+ port "9000"
[edit service https]
vyos@vyos# commit
[ service https ]
WARNING: No certificate specified, using build-in self-signed
certificates. Do not use them in a production environment!
TCP port "9000" is used by another service!
[[service https]] failed
Commit failed
[edit service https]
vyos@vyos#Adding an IPv6 address while an IPv4 address is present:
vyos@vyos# show service https
api {
keys {
id test {
key 123
}
}
rest {
}
}
listen-address 192.168.0.1
port 9000
vyos@vyos# set service https listen-address ::1
[edit]
vyos@vyos# commit
[ service https ]
WARNING: No certificate specified, using build-in self-signed
certificates. Do not use them in a production environment!
TCP port "9000" is used by another service!
[[service https]] failed
Commit failed
[edit]
vyos@vyos# compare
[service https]
+ listen-address "::1"
[edit]
vyos@vyos# sudo netstat -nlutp | grep 9000
[edit]If you delete the IPv4 address it works again:
vyos@vyos# delete service https listen-address 192.168.0.1
[edit]
vyos@vyos# compare
[service https]
- listen-address "192.168.0.1"
+ listen-address "::1"
[edit]
vyos@vyos# commit
[ service https ]
WARNING: No certificate specified, using build-in self-signed
certificates. Do not use them in a production environment!
[edit]
vyos@vyos# show service https
api {
keys {
id test {
key 123
}
}
rest {
}
}
listen-address ::1
port 9000
[edit]And if you add the IPv4 address second, it actually works:
vyos@vyos# show service https
api {
keys {
id test {
key 123
}
}
rest {
}
}
listen-address ::1
port 9000
[edit]
vyos@vyos# set service https listen-address 192.168.0.1
[edit]
vyos@vyos# compare
[service https]
+ listen-address "192.168.0.1"
[edit]
vyos@vyos# commit
[ service https ]
WARNING: No certificate specified, using build-in self-signed
certificates. Do not use them in a production environment!
[edit]
vyos@vyos# show service https
api {
keys {
id test {
key 123
}
}
rest {
}
}
listen-address ::1
listen-address 192.168.0.1
port 9000
[edit]
vyos@vyos#Deleting an IPv6 listen address when an IPv4 listen address exists, fails:
vyos@vyos# edit service https
[edit service https]
vyos@vyos# delete listen-address
Possible completions:
192.168.0.1
::1
[edit service https]
vyos@vyos# delete listen-address ::1
[edit service https]
vyos@vyos# commit
[ service https ]
WARNING: No certificate specified, using build-in self-signed
certificates. Do not use them in a production environment!
TCP port "9000" is used by another service!
[[service https]] failed
Commit failed
[edit service https]
vyos@vyos# compare
[https]
- listen-address "::1"
[edit service https]
vyos@vyos#