Page MenuHomeVyOS Platform
Feed Search

Dec 11 2016

EwaldvanGeffen created T208: Ability to ignore default-route from dhcpcd per interface.
Dec 11 2016, 10:32 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
EwaldvanGeffen added a comment to T167: "set service ssh allow-root" is not enough to root system-access via ssh.

That's strange because it's exactly what the code does: https://github.com/vyos/vyatta-cfg-system/blob/current/templates/service/ssh/allow-root/node.def

Dec 11 2016, 10:27 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
EwaldvanGeffen closed T207: bridge-utils location as Resolved.

Closed in https://github.com/vyos/vyatta-op/pull/7

Dec 11 2016, 10:20 PM · VyOS 1.1.x (1.1.8)
EwaldvanGeffen created T207: bridge-utils location.
Dec 11 2016, 9:13 PM · VyOS 1.1.x (1.1.8)
EwaldvanGeffen added a comment to T161: VyOS 1.2 (jessie) testing spreadsheet.

Maybe it's interesting to attach the configs to the tested-build data-entry.

Dec 11 2016, 12:39 AM · Invalid

Dec 10 2016

jclendenan added a comment to T200: Automated config deployment from a removable drive at installation time.

Great, I hadn't realized you were showing the selection method, not the script building.

Dec 10 2016, 2:20 AM · Ideas

Dec 8 2016

hexes added a comment to T200: Automated config deployment from a removable drive at installation time.

jclendenan, /tmp/eee is just a sample file where installation script could take a list of available configs.
Almost like you describe below:

Dec 8 2016, 5:15 PM · Ideas
jclendenan added a comment to T200: Automated config deployment from a removable drive at installation time.

I like the concept, although I'm less sure about aggigating the config's together into /tmp/eee rather than using a static config.boot file

Dec 8 2016, 3:13 AM · Ideas

Dec 5 2016

hexes added a comment to T200: Automated config deployment from a removable drive at installation time.
cat /etc/udev/rules.d/100-usbflash.rules 
KERNEL=="sd?1", SUBSYSTEMS=="usb", ACTION=="add", SYMLINK+="adminStick", RUN+="/usr/bin/logger Start mounting", RUN+="/home/vyos/mountAdminStick"
Dec 5 2016, 11:02 AM · Ideas
hexes created T201: Beep When Fully Booted.
Dec 5 2016, 7:22 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
dmbaturin created T200: Automated config deployment from a removable drive at installation time.
Dec 5 2016, 5:32 AM · Ideas

Dec 4 2016

elico added a comment to Q56: nDPI integration, what is required?.

Tried to compile on sqeeze and got errors so it will only meet .1.2.0.

Dec 4 2016, 2:54 AM · VyOS 1.1.x (1.1.8)

Dec 2 2016

thomas.courbon created T199: openVPN client/server bridge : need to specify server subnet..
Dec 2 2016, 3:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Nov 23 2016

dmbaturin added a comment to T194: failed to parse tmpl [/protocols/static/route].

@hexes Could you update the task and specify which image you use and which error you get in it?

Nov 23 2016, 5:56 PM
dmbaturin triaged T194: failed to parse tmpl [/protocols/static/route] as Urgent! priority.
Nov 23 2016, 5:42 PM
dmbaturin added a project to T194: failed to parse tmpl [/protocols/static/route]: VyOS 1.1.x (1.1.8).
Nov 23 2016, 4:10 PM

Nov 22 2016

syncer reassigned T91: Memory leak in the Perl bindings for CStore (Vyatta::Config) from syncer to jhendryUK.
Nov 22 2016, 4:16 PM · VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer claimed T91: Memory leak in the Perl bindings for CStore (Vyatta::Config).
Nov 22 2016, 4:15 PM · VyOS 1.2 Crux (VyOS 1.2.0-rc1)
UnicronNL closed T189: ipsec/l2tp in Vyos current doesn't start as Resolved.

Pluto has changed to charon.

Nov 22 2016, 12:41 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
UnicronNL claimed T189: ipsec/l2tp in Vyos current doesn't start.
Nov 22 2016, 12:40 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
step.kh added a comment to T161: VyOS 1.2 (jessie) testing spreadsheet.

Hello. I want to participate in testing if possible. Thanks.

Nov 22 2016, 4:00 AM · Invalid

Nov 19 2016

elico added a comment to Q56: nDPI integration, what is required?.

@mickvav The userspace software is not something that we need in the build.
I have just built it since it's in the packages\repo.
The important thing is the module and the libraries to build them.
I will try to disable the userspace software build and move on from there.

Nov 19 2016, 5:59 PM · VyOS 1.1.x (1.1.8)
mickvav added a comment to Q56: nDPI integration, what is required?.

Well, just to make things clear - nDPI is actually a userspace software, that performs DPI analisis of data flow (from pcap-ed interface in real time or from .pcap file). It's interface to netfilter goes through ndpi-netfilter package, which actually opens kernel-userspace socket to forward some packets throug nDPI in userspace. If I am right in brief, we have two important steps:

  1. Make userspace software compile and work.

I thing, this should require almost no vyos-specific coding - just original package should be compiled on vyos vuild system into .deb

  1. Make netfilter-related package integrate into vyos iptables configuration.

Here we need to create some package like vyos-ndpi-netfilter, which fetches and compiles ndpi-netfilter, handles vyos configuration templates and creates correctly working .deb with all this stuff.
vyos-ndpi-netfilter.deb should depend on ndpi.deb

Nov 19 2016, 12:00 PM · VyOS 1.1.x (1.1.8)
Alexis added a comment to T172: URGENT: Fix Quagga CVE-2016-1245.

@mickvav Sorry, I don't have a build environment set up right now. I opened this ticket mostly as a service to the VyOs commmunity since nobody on the quagga side had gotten around to alerting you.

Nov 19 2016, 5:27 AM · VyOS 1.1.x (1.1.8)
EwaldvanGeffen updated the task description for T193: Kick ISC DHCP-server to a more recent version.
Nov 19 2016, 12:58 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
EwaldvanGeffen created T193: Kick ISC DHCP-server to a more recent version.
Nov 19 2016, 12:58 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
EwaldvanGeffen added a comment to Q56: nDPI integration, what is required?.

I think the next step for this proof-of-concept is to be tried and validated (setup log rules, tcpdump and send in traffic, manually compare counters to dump) then merged into the regular build-process and finally come up with a CLI syntax.

Nov 19 2016, 12:13 AM · VyOS 1.1.x (1.1.8)
EwaldvanGeffen added a comment to T186: DHCP with VRRP.

Could this patch be your solution. I remember there was the duplicate print effect when using DHCP-FO on the entries in the lease file in a specific condition that I've made it to ignore.

Nov 19 2016, 12:09 AM · VyOS 1.1.x (1.1.8)

Nov 18 2016

elico added a comment to Q56: nDPI integration, what is required?.

It took faster then expected with a help from a friend so:
https://github.com/elico/debian8-dev-ndpi-vel

Nov 18 2016, 1:31 PM · VyOS 1.1.x (1.1.8)
elico added a comment to Q56: nDPI integration, what is required?.

In order to speed up the build process I want us to work on the VYOS development docker container.
Once we will have this I and others can do things much faster.
I will try to share my build node for debian in two days and then we can move forward from this one step forward towards simple kernel compilation for VYOS in a docker container.
After we will have this we can simply buidl the NDPI modules(which are being used in zeroshell....).

Nov 18 2016, 11:31 AM · VyOS 1.1.x (1.1.8)
mickvav added a comment to Q56: nDPI integration, what is required?.

How exactly can we help you?

Nov 18 2016, 4:58 AM · VyOS 1.1.x (1.1.8)

Nov 16 2016

elico added a comment to Q56: nDPI integration, what is required?.

OK I have just seen that Mikrotik routers have p2p block and it's an iptables level concept.
I have compiled the module for debian but needs some help from others.
Waiting for others to help.

Nov 16 2016, 9:04 PM · VyOS 1.1.x (1.1.8)

Nov 14 2016

fatihusta added a comment to T190: two factor authentication for OpenVPN remote VPN tunnels.

Hi
I think maybe we use openvpn dynamic challenge respons function for two factor auth.
Sms, email. etc.

Nov 14 2016, 4:44 PM · VyOS 1.4 Sagitta (1.4.0)

Nov 13 2016

syncer updated subscribers of T186: DHCP with VRRP.

@dmbaturin this is candidate for 1.1.8 too
@EwaldvanGeffen, as you more aware, any ideas why it happens again?
Thanks!

Nov 13 2016, 4:45 PM · VyOS 1.1.x (1.1.8)
syncer reassigned T186: DHCP with VRRP from syncer to EwaldvanGeffen.
Nov 13 2016, 4:44 PM · VyOS 1.1.x (1.1.8)

Nov 12 2016

jhendryUK added a comment to T190: two factor authentication for OpenVPN remote VPN tunnels.

Here is a sanitised copy of the auth-ldap script. I never wrote it! Its just what we use :) It will need modifying to work

Nov 12 2016, 12:23 PM · VyOS 1.4 Sagitta (1.4.0)
Boltsie added a comment to T173: Static routes ignored with DHCP received gateway.

Maybe you can resolve with this method.

I did not test

Nov 12 2016, 5:48 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA)

Nov 10 2016

mickvav added a comment to T172: URGENT: Fix Quagga CVE-2016-1245.

Sent pull request. This thing is really trivial. @Alexis, would be so kind to that resulting package is ok? My building appliance is somewhat disabled right now and I have only a tiny amount of time to do recreate it, so I will be able to test that everything is ok next week only, sorry.

Nov 10 2016, 1:38 PM · VyOS 1.1.x (1.1.8)
amos.shapira added a comment to T190: two factor authentication for OpenVPN remote VPN tunnels.

This is different but might be a little related - FoxPass publishes a one-line tweak to VyOS 1.0 to let them support two-factor authentication for IPSec VPN at https://foxpass.readme.io/docs/vyatta-vyos-ubiquity-vpn-clients
It would be nice to have this change possible via an option.

Nov 10 2016, 11:26 AM · VyOS 1.4 Sagitta (1.4.0)
jhendryUK added a comment to T190: two factor authentication for OpenVPN remote VPN tunnels.

We do this a lot, having certificate + user auth for OpenVPN. Using this open VPN option, a custom auth script and extra packages:

Nov 10 2016, 10:24 AM · VyOS 1.4 Sagitta (1.4.0)
tsumaru720 added a comment to T186: DHCP with VRRP.
simon@vy-gw-a:~$ show version
Version:      VyOS 1.1.7
Description:  VyOS 1.1.7 (helium)                                                                                                                                                     
Copyright:    2016 VyOS maintainers and contributors                                                                                                                                  
Built by:     maintainers@vyos.net                                                                                                                                                    
Built on:     Wed Feb 17 09:57:31 UTC 2016
Build ID:     1602170957-4459750
System type:  x86 64-bit
Boot via:     image
Hypervisor:   KVM
HW model:     Standard PC (i440FX + PIIX, 1996)
HW S/N:       Not Specified
HW UUID:      7FD7FCB0-0515-3347-B1CF-10CA6690F0C7
Uptime:       09:49:13 up 3 days,  8:15,  2 users,  load average: 0.02, 0.02, 0.05
Nov 10 2016, 9:48 AM · VyOS 1.1.x (1.1.8)
syncer added a project to T190: two factor authentication for OpenVPN remote VPN tunnels: VyOS 1.1.x (1.1.8).
Nov 10 2016, 9:27 AM · VyOS 1.4 Sagitta (1.4.0)

Nov 9 2016

oliveriandrea created T189: ipsec/l2tp in Vyos current doesn't start.
Nov 9 2016, 10:28 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
oliveriandrea created T188: tail: unrecognized file system type 0x794c7630.
Nov 9 2016, 10:23 PM · Rejected
EwaldvanGeffen added a comment to T186: DHCP with VRRP.

When doing DHCP-FO it's intentional both machines send out a lease. The duplicate 'lease' issue in the show statements should've been resolved in latest versions IIRC. Which version are you running?

Nov 9 2016, 7:09 PM · VyOS 1.1.x (1.1.8)
tsumaru720 added a comment to T186: DHCP with VRRP.

https://phabricator.vyos.net/P14

Nov 9 2016, 11:22 AM · VyOS 1.1.x (1.1.8)
syncer triaged T186: DHCP with VRRP as Normal priority.

@EwaldvanGeffen I recall you had tested something similar in terms of setup of DHCP
can you assist here?
Suspecting some issues there

Nov 9 2016, 11:02 AM · VyOS 1.1.x (1.1.8)

Nov 7 2016

oliveriandrea added a comment to T129: Lithium does not commit boot configuration.

This bug is also present in the last night build

Nov 7 2016, 8:10 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Nov 6 2016

fatihusta added a comment to T173: Static routes ignored with DHCP received gateway.

Maybe you can resolve with this method.

Nov 6 2016, 4:45 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
Alexis added a comment to T172: URGENT: Fix Quagga CVE-2016-1245.

@dmbaturin I understand, and I didn't mean to be someone just grousing from the sidelines. My evaluation of that specific patch is the most I can offer at the moment.

Nov 6 2016, 12:29 AM · VyOS 1.1.x (1.1.8)
dmbaturin added a comment to T172: URGENT: Fix Quagga CVE-2016-1245.

@Alexis I wish, with this shortage of contributors, we were really in position to make specific plans regarding the timeframe. ;)
This also applies to the security updates issue. We really need a dedicated security watcher, but, sadly, no one wants to take up this role, so it's always done in a haphazard manner, which is a bad experience for both end users and developers, but that's what we've got.
In a few years of project life, the number of people committed to using VyOS in production grew, but the number of people committed to developing it almost did not, it's still just a few people who have to do everything, and, frankly, it's taxing. At this point, none of us can turn it into a full time job (the commercial support thing @syncer and I started may change it in the future and give some of the maintainers guaranteed N hours a week to spend on it, but it's still a very early stage).

Nov 6 2016, 12:05 AM · VyOS 1.1.x (1.1.8)

Nov 5 2016

Alexis added a comment to T172: URGENT: Fix Quagga CVE-2016-1245.

@dmbaturin Oops, started my reply before your second comment was posted.

Nov 5 2016, 11:56 PM · VyOS 1.1.x (1.1.8)
Alexis added a comment to T172: URGENT: Fix Quagga CVE-2016-1245.

@dmbaturin I'm glad to hear that you'll be releasing a new version soon.

Nov 5 2016, 11:36 PM · VyOS 1.1.x (1.1.8)
dmbaturin added a comment to T172: URGENT: Fix Quagga CVE-2016-1245.

@Alexis By the way, if you are into the quagga source code, maybe you want to join the work on switching to the upstream or cumulus quagga and "forth-porting" vyatta changes to it?

Nov 5 2016, 11:22 PM · VyOS 1.1.x (1.1.8)
dmbaturin added a comment to T172: URGENT: Fix Quagga CVE-2016-1245.

@Alexis Please don't panic. This bug is only exploitable if RA handling is enabled in quagga, and by default it is not. Setting interface's IPv6 to autoconf doesn't enable it in zebra either.
I agree it should be included in 1.1.8, but it's not urgent. I suppose we'll build 1.1.8 some time next week anyway, there are other issues to be addressed.

Nov 5 2016, 11:18 PM · VyOS 1.1.x (1.1.8)
Alexis added a comment to T172: URGENT: Fix Quagga CVE-2016-1245.
  1. It's one freaking line
Nov 5 2016, 9:42 PM · VyOS 1.1.x (1.1.8)
syncer added a comment to T172: URGENT: Fix Quagga CVE-2016-1245.

@Alexis, sure, but don't have habit apply everything on first request from internet.

Nov 5 2016, 2:06 PM · VyOS 1.1.x (1.1.8)
Alexis added a comment to T172: URGENT: Fix Quagga CVE-2016-1245.

@syncer Did you read what I wrote??

Nov 5 2016, 1:21 PM · VyOS 1.1.x (1.1.8)
syncer updated subscribers of T141: TACACS+ Support.

@whiskeyalpharomeo pointed to
https://github.com/jeroennijhof/pam_tacplus
I talked with @dmbaturin and it looks like via PAM we can perform at least something basic.
@dmbaturin can you comment more ?

Nov 5 2016, 1:00 PM · VyOS 1.4 Sagitta
syncer lowered the priority of T129: Lithium does not commit boot configuration from Urgent! to Normal.
Nov 5 2016, 12:29 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer assigned T172: URGENT: Fix Quagga CVE-2016-1245 to mickvav.

@mickvav can you see if it something trivial to port in?

Nov 5 2016, 12:25 PM · VyOS 1.1.x (1.1.8)
syncer lowered the priority of T173: Static routes ignored with DHCP received gateway from Urgent! to Normal.

@EwaldvanGeffen can you check this one
Thanks!

Nov 5 2016, 12:23 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)

Nov 4 2016

ruffy91 added a comment to T88: IPsec tunnel broken after nightly build upgrade.

I have a similar problem, since 1.1.7 PFS in phase 2 is not working.
"Oakley Transform [AES_CBC (256), HMAC_SHA2_256, (null)] refused due to strict flag."
As you can see there is no pfs proposal sent by 1.1.7.
The same with a tunnel between 1.1.7 and pfsense 2.3.2.
When activating PFS on both there is no matching proposal, when disabling PFS on pfSense a proposal is found.

Nov 4 2016, 9:02 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Nov 3 2016

job added a comment to T143: Add support for Large BGP Community.

Yes, waiting a bit does not hurt. We are working on version 3 of the patch to accomodate the missing features

Nov 3 2016, 3:10 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)
mickvav added a comment to T143: Add support for Large BGP Community.

Reviewed the discussion there - I think we have to wait at least couple of weeks until it will be at least a little bit tested there...

Nov 3 2016, 2:41 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)

Oct 29 2016

job added a comment to T143: Add support for Large BGP Community.

The Quagga has been provided with a patch to support Large BGP Communities. This patch is for Quagga 1.1.0 but should be easy to backport if needed.

Oct 29 2016, 5:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)
gadams set Version to dev build 999.201609230235 on T179: dnsmasq startup dependencies seem off.
Oct 29 2016, 7:05 AM · Invalid
gadams created T179: dnsmasq startup dependencies seem off.
Oct 29 2016, 7:04 AM · Invalid
gadams added a comment to T155: NTP wasn't running, nor conigured in 1.2.0-beta1.

Hmm. Things are afoot.

Oct 29 2016, 6:47 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Oct 26 2016

FullMonty added a comment to T141: TACACS+ Support.

Hi, I'm new and found my way here via WAR's blog post.
Big +1 for TACACS+ support.
I manage a bunch of cisco routers and now have half a dozen or so vyos routers in the mix too. I need to grant junior admins rights to these while limiting their ability to break stuff and currently use TACACS+ for this with the cisco routers we manage. I would love to do the same for the growing fleet of vyos virtual routers.

Oct 26 2016, 6:52 AM · VyOS 1.4 Sagitta

Oct 19 2016

elico added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@hmkias I think that some kind of a daemon would be required to "coordinate" between the squid machine to the VYOS.
I had an idea about it in the past but never had the chance to actually implement it with vyatta.
However I have seen that in ZEROSHELL there is a very nice feature which test for proxy IP level availability.
How complex would it be to make a condition to the policy based on a lock file?

Oct 19 2016, 6:44 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

Oct 18 2016

Boltsie created T173: Static routes ignored with DHCP received gateway.
Oct 18 2016, 1:53 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
Alexis added a comment to T143: Add support for Large BGP Community.

Why aren't you all discussing this on the Quagga mailing list? More generally, what is the VyOS project policy about work that belongs in upstream?

Oct 18 2016, 9:35 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)

Oct 12 2016

higebu added a comment to T164: Create image for MicroSoft Azure.

@amos.shapira Thanks!

Oct 12 2016, 12:54 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3), Hyper-V/Azure Support

Oct 7 2016

Boltsie added a comment to T155: NTP wasn't running, nor conigured in 1.2.0-beta1.

Can you test if this happens with SNMP in this particular 1.2.0-beta1 build as well, and maybe in the preview images? I may have just had it happen after rebooting an instance...

Oct 7 2016, 11:42 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
gadams added a comment to T117: Cannot install from ISO via serial console on ttyS1.

Recent dev builds on the current (lithium) branch don't need to be told which port is the console; systemd is able to figure it out, and spawns the correct getty processes.

Oct 7 2016, 7:21 AM · VyOS 1.3 Equuleus (1.3.6)
gadams created T169: Image install should put correct serial console device in created GRUB menu entry.
Oct 7 2016, 7:19 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Oct 6 2016

syncer assigned T168: Issue committing 'remote-ip' when configuring tun interface to dmbaturin.
Oct 6 2016, 5:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)
gadams added a comment to T155: NTP wasn't running, nor conigured in 1.2.0-beta1.

I've written a handy script to start ntpd manually:

Oct 6 2016, 6:57 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
gadams added a comment to T155: NTP wasn't running, nor conigured in 1.2.0-beta1.

I tried adding this to /config/scripts/vyatta-postconfig-bootup.script:

Oct 6 2016, 5:36 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
gadams added a project to T155: NTP wasn't running, nor conigured in 1.2.0-beta1: VyOS 1.1.x (1.1.8).

This hack does work, but it only lasts until you reboot VyOS. When the OS comes back up, you'll need to do this again.

Oct 6 2016, 5:20 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Oct 5 2016

syncer triaged T167: "set service ssh allow-root" is not enough to root system-access via ssh as Low priority.
Oct 5 2016, 11:29 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
syncer added a project to T168: Issue committing 'remote-ip' when configuring tun interface: VyOS 1.1.x (1.1.8).

Thanks for report @JBFUK !

Oct 5 2016, 11:28 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)

Oct 2 2016

job added a comment to T143: Add support for Large BGP Community.

Through an early allocation, IANA assigned 30 as the path attribute value for Large BGP Communities.

Oct 2 2016, 1:43 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)

Sep 30 2016

amos.shapira added a comment to T164: Create image for MicroSoft Azure.

I'm not sure how much this will help, but I have a branch on a fork of vyos-build to build AMI's from ISO files: https://github.com/amosshapira/vyos-build/tree/make-ami

Sep 30 2016, 10:22 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3), Hyper-V/Azure Support
syncer added a comment to T164: Create image for MicroSoft Azure.

Same is true for T100

Sep 30 2016, 3:05 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3), Hyper-V/Azure Support
syncer updated subscribers of T164: Create image for MicroSoft Azure.

It´s time to build something for Azure
i have an account in Azure for testing and would be glad participate in the coordinated effort

Sep 30 2016, 3:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3), Hyper-V/Azure Support
higebu updated the task description for T164: Create image for MicroSoft Azure.
Sep 30 2016, 3:05 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3), Hyper-V/Azure Support
higebu created T164: Create image for MicroSoft Azure.
Sep 30 2016, 1:18 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3), Hyper-V/Azure Support

Sep 26 2016

elico added a comment to Q56: nDPI integration, what is required?.

@EwaldvanGeffen The main point is that the basic and working extra modules should be usable to the public since it gives anyone that want's to enhance the existing code.
The main example is blocking windows updates, if you have the sources you can see it's being blocked based couple simple things:
domain name in plain HTTP
domain name in SNI of SSL

Sep 26 2016, 10:33 PM · VyOS 1.1.x (1.1.8)
EwaldvanGeffen added a comment to Q56: nDPI integration, what is required?.

I have used nDPI on CentOS 5 in the past with 'fair' results. The problem is that the makers of nDPI went commercial and their old/OSS package is afair not maintained anymore.

Sep 26 2016, 10:20 PM · VyOS 1.1.x (1.1.8)
elico added a comment to Q56: nDPI integration, what is required?.

@mickvav I do not need it personally since it works for me fine on other systems but I would like to put my efforts in order to have others have some benefit from my work.
I will take a look at the ipt-netflow-code work and with time I will probably practice it.

Sep 26 2016, 1:28 PM · VyOS 1.1.x (1.1.8)
mickvav added a comment to Q56: nDPI integration, what is required?.

@elico, have a look at https://github.com/mickvav/ipt-netflow-code - it's my vyos/debian repackage for ipt-netflow - another iptables target module which I've ported (and use in production) on my own vyos repackage. If you take it's "debian/" folder, put in your repo, than we can fork it and maintain as submodule.

Sep 26 2016, 12:45 PM · VyOS 1.1.x (1.1.8)
elico added a comment to Q56: nDPI integration, what is required?.

@mickvav I learned the debian packaging and produced more then one or these for Squid-Cache but everytime I am sitting on the build it's from 0.
To deploy most of my compiled softwares I am using a tar.xz which can be deployed ontop of the existing system as a 'module' and I found it much simpler for me to work with simple bash scripts then the debian packaging.
Without someone helping me to repackage over and over couple times of packages then it's not being pulled into the box but merely passing from one side to the other...
@dmbaturin gave me couple tips and cleared things for me.
I will try to finish couple things here before we\I can dive into the subject.

Sep 26 2016, 12:11 PM · VyOS 1.1.x (1.1.8)
mickvav added a comment to Q56: nDPI integration, what is required?.

Well, I think, I can try to make this thing work on VyOS, especially if the community is interested.
@elico, it seems to me to be that if you have this thing working with ubuntu you already have some debian folder which produces .deb's on dpkg-buildpackage correctly, or you mean that after just "make && make install" on running system, it installs and works?

Sep 26 2016, 10:14 AM · VyOS 1.1.x (1.1.8)

Sep 23 2016

elico added a comment to Q56: nDPI integration, what is required?.

It can be disabled as will.
It works or not like any other external module which doesn't require kernel changes.( the specific ve21loring version)

Sep 23 2016, 7:02 AM · VyOS 1.1.x (1.1.8)
rps added a comment to Q56: nDPI integration, what is required?.

It looks interesting and I think QoS is a good application of nDPI. I'm a little nervous about what the performance and stability implications are. Not having looked into it much is it implemented as a module that could be disabled if needed?

Sep 23 2016, 12:03 AM · VyOS 1.1.x (1.1.8)

Sep 22 2016

syncer updated subscribers of Q56: nDPI integration, what is required?.

@EwaldvanGeffen @rps @jhendryUK @trickv @UnicronNL @afics @dmbaturin
Can this be candidate for inclusion ?
Use case:
QoS subsystem, with nDPI we can add speed shaping for some(or all) protocols supported by nDPI
http://www.ntop.org/products/deep-packet-inspection/ndpi/

Sep 22 2016, 10:46 PM · VyOS 1.1.x (1.1.8)
syncer changed the visibility for Q56: nDPI integration, what is required?.
Sep 22 2016, 10:43 PM · VyOS 1.1.x (1.1.8)
hmkias added a comment to Q52: Integrate Vyos with standalone web filtering device?.

I m thinking on two approaches to the problem, WCCP or patching Squid. Ultimately the complexity and time decides the way.

Sep 22 2016, 5:06 AM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)