Page MenuHomeVyOS Platform

Port in use errors with IPv6 and IPv4 listen addresses in the https service
Open, LowPublic

Description

During a test rollout of the new rolling image, I noticed that the API tool we use to push configuration to the new devices wouldn't add the https configuration.

This ticket is only referencing the service https section of the configuration.

After some testing, I have found the following actions all throw an error for "TCP port "9000" is used by another service!":

  • Assigning an IPv6 listen address after an IPv4 address
  • Deleting an IPv6 listen address when an IPv4 listen address is present
  • Assigning a listen address and port all at the same time.

To note, you can assign both IPv4 and IPv6 listen addresses at the same time, as long as the port is not changing.

Please let me know if anything is unclear or if the explanation needs further clarification

Actual testing:

Version being run:

vyos@vyos:~$ show system image 
Name                     Default boot    Running
-----------------------  --------------  ---------
2026.04.29-0041-rolling  Yes             Yes

Netstat to confirm nothing else is running

vyos@vyos# sudo netstat -nlutp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name    
tcp        0      0 0.0.0.0:21982           0.0.0.0:*               LISTEN      3057/sshd: /usr/sbi 
tcp        0      0 127.0.0.1:2604          0.0.0.0:*               LISTEN      1668/ospfd          
tcp        0      0 127.0.0.1:2605          0.0.0.0:*               LISTEN      1655/bgpd           
tcp        0      0 127.0.0.1:2602          0.0.0.0:*               LISTEN      1662/ripd           
tcp        0      0 127.0.0.1:2601          0.0.0.0:*               LISTEN      1647/zebra          
tcp        0      0 127.0.0.1:2623          0.0.0.0:*               LISTEN      1644/mgmtd          
tcp        0      0 127.0.0.1:2618          0.0.0.0:*               LISTEN      1703/fabricd        
tcp        0      0 127.0.0.1:2616          0.0.0.0:*               LISTEN      1700/staticd        
tcp        0      0 127.0.0.1:2617          0.0.0.0:*               LISTEN      1652/bfdd           
tcp        0      0 127.0.0.1:2612          0.0.0.0:*               LISTEN      1688/ldpd           
tcp        0      0 127.0.0.1:2610          0.0.0.0:*               LISTEN      1694/nhrpd          
tcp        0      0 127.0.0.1:2608          0.0.0.0:*               LISTEN      1674/isisd          
tcp        0      0 127.0.0.1:2609          0.0.0.0:*               LISTEN      1677/babeld         
tcp6       0      0 ::1:2603                :::*                    LISTEN      1665/ripngd         
tcp6       0      0 ::1:2606                :::*                    LISTEN      1671/ospf6d         
tcp6       0      0 ::1:2622                :::*                    LISTEN      1680/pim6d          
tcp6       0      0 :::21982                :::*                    LISTEN      3057/sshd: /usr/sbi 
udp        0      0 0.0.0.0:3784            0.0.0.0:*                           1652/bfdd           
udp        0      0 0.0.0.0:123             0.0.0.0:*                           2127/chronyd        
udp        0      0 127.0.0.1:323           0.0.0.0:*                           2127/chronyd        
udp        0      0 0.0.0.0:4784            0.0.0.0:*                           1652/bfdd           
udp6       0      0 :::7784                 :::*                                1652/bfdd           
udp6       0      0 :::3784                 :::*                                1652/bfdd           
udp6       0      0 :::123                  :::*                                2127/chronyd        
udp6       0      0 ::1:323                 :::*                                2127/chronyd        
udp6       0      0 :::4784                 :::*                                1652/bfdd           
[edit]
vyos@vyos# sudo netstat -nlutp | grep 9000
[edit]
vyos@vyos#

Adding a listen address and port at the same time:

vyos@vyos# show
 api {
     keys {
         id test {
             key 123
         }
     }
     rest {
     }
 }
[edit service https]
vyos@vyos# set listen-address 192.168.0.1
[edit service https]
vyos@vyos# set port 9000
[edit service https]
vyos@vyos# compare
[https]
+ listen-address "192.168.0.1"
+ port "9000"
[edit service https]
vyos@vyos# commit
[ service https ]
WARNING: No certificate specified, using build-in self-signed
certificates. Do not use them in a production environment!
TCP port "9000" is used by another service!
[[service https]] failed
Commit failed
[edit service https]
vyos@vyos#

Adding an IPv6 address while an IPv4 address is present:

vyos@vyos# show service https
 api {
     keys {
         id test {
             key 123
         }
     }
     rest {
     }
 }
 listen-address 192.168.0.1
 port 9000
vyos@vyos# set service https listen-address ::1
[edit]
vyos@vyos# commit
[ service https ]
WARNING: No certificate specified, using build-in self-signed
certificates. Do not use them in a production environment!
TCP port "9000" is used by another service!
[[service https]] failed
Commit failed
[edit]
vyos@vyos# compare
[service https]
+ listen-address "::1"
[edit]
vyos@vyos# sudo netstat -nlutp | grep 9000
[edit]

If you delete the IPv4 address it works again:

vyos@vyos# delete service https listen-address 192.168.0.1 
[edit]
vyos@vyos# compare
[service https]
- listen-address "192.168.0.1"
+ listen-address "::1"
[edit]
vyos@vyos# commit
[ service https ]
WARNING: No certificate specified, using build-in self-signed
certificates. Do not use them in a production environment!
[edit]
vyos@vyos# show service https 
 api {
     keys {
         id test {
             key 123
         }
     }
     rest {
     }
 }
 listen-address ::1
 port 9000
[edit]

And if you add the IPv4 address second, it actually works:

vyos@vyos# show service https
 api {
     keys {
         id test {
             key 123
         }
     }
     rest {
     }
 }
 listen-address ::1
 port 9000
[edit]
vyos@vyos# set service https listen-address 192.168.0.1
[edit]
vyos@vyos# compare
[service https]
+ listen-address "192.168.0.1"
[edit]
vyos@vyos# commit
[ service https ]
WARNING: No certificate specified, using build-in self-signed
certificates. Do not use them in a production environment!
[edit]
vyos@vyos# show service https 
 api {
     keys {
         id test {
             key 123
         }
     }
     rest {
     }
 }
 listen-address ::1
 listen-address 192.168.0.1
 port 9000
[edit]
vyos@vyos#

Deleting an IPv6 listen address when an IPv4 listen address exists, fails:

vyos@vyos# edit service https 
[edit service https]
vyos@vyos# delete listen-address 
Possible completions:
   192.168.0.1          
   ::1                  
      
[edit service https]
vyos@vyos# delete listen-address ::1 
[edit service https]
vyos@vyos# commit
[ service https ]
WARNING: No certificate specified, using build-in self-signed
certificates. Do not use them in a production environment!
TCP port "9000" is used by another service!
[[service https]] failed
Commit failed
[edit service https]
vyos@vyos# compare
[https]
- listen-address "::1"
[edit service https]
vyos@vyos#

Details

Version
2026.04.29-0041-rolling
Is it a breaking change?
Behavior change
Issue type
Bug (incorrect behavior)