Page MenuHomeVyOS Platform
Feed Search

Jan 30 2019

hagbard claimed T1217: 1.2.0 LTS cant delete wireguard wg0 interface.
Jan 30 2019, 10:23 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard added a comment to T1051: Update openvpn to support TLS 1.2.

@c-po imported and test against latest rolling, I couldn't find any issue with 2.4.

Jan 30 2019, 8:15 PM · VyOS 1.2 Crux (VyOS 1.2.2)
hagbard added a comment to T1051: Update openvpn to support TLS 1.2.

@c-po it only affects clients which enforce tls 1.0 or 1.1, at least what I have tested. The perl code needs quite some rework, so I think I split the task into getting a newer release of openvpn into the build. Newer versions have tls 1.0 and 1.1 disabled per default from what I have read, so I think it might be more a changelog announcement that with the new version only tls 1.2 is automatically supported and you have the option to enable weak ciphers via opt .... or so. I'm not too sure yet, I think I have to wait a little on the response once the newer version is in rolling and the feedback I receive.

Jan 30 2019, 6:06 PM · VyOS 1.2 Crux (VyOS 1.2.2)

Jan 29 2019

hagbard added a comment to T166: NPTv6 is broken in the rolling release 999.201609170235 .

Done. https://github.com/vyos/vyatta-nat/commit/98ce64bc3c73118c8e909173da460501ca6cabf1

Jan 29 2019, 11:27 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard closed T166: NPTv6 is broken in the rolling release 999.201609170235 as Resolved.

Perfect. Merged: https://github.com/vyos/vyatta-cfg-firewall/commit/23447bef89a46f44d7544f15c2755d33f38ffd4c

Jan 29 2019, 9:43 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard added a comment to T1051: Update openvpn to support TLS 1.2.
In T1051#27092, @c-po wrote:

set interfaces openvpn vtun0 disable-weak-tls-ciphers

Jan 29 2019, 6:32 PM · VyOS 1.2 Crux (VyOS 1.2.2)
hagbard added a comment to T166: NPTv6 is broken in the rolling release 999.201609170235 .

@Merijn Have you tested your changes already? I was only bale to find https://github.com/vyos/vyatta-cfg-firewall/pull/12 which only contains the ip6tables targets, did you send PRs for systctl too?

Jan 29 2019, 6:30 PM · VyOS 1.2 Crux (VyOS 1.2.1)

Jan 28 2019

hagbard changed the status of T833: New PPTP server implementation based on accel-ppp, a subtask of T742: Replace poptop and xl2tpd with accel-ppp, from On hold to Confirmed.
Jan 28 2019, 10:57 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard changed the status of T833: New PPTP server implementation based on accel-ppp from On hold to Confirmed.
Jan 28 2019, 10:57 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard added a comment to T1051: Update openvpn to support TLS 1.2.

@syncer Currently we ship in the iso openvpn from main, we could use it from bpo which would be 2.4 (2.6 is the latest), or we replace it with a self-compiled 2.6, or do you just want cpo's solution implemented?

Jan 28 2019, 4:48 PM · VyOS 1.2 Crux (VyOS 1.2.2)

Jan 26 2019

hagbard renamed T1205: module pcspkr missing from module pcspkr missiing to module pcspkr missing.
Jan 26 2019, 6:35 PM · VyOS 1.2 Crux (VyOS 1.2.6)
hagbard closed T1193: libvyosconfig parser cannot handle top level leaf and tag nodes as Resolved.
Jan 26 2019, 6:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard created T1205: module pcspkr missing.
Jan 26 2019, 6:25 PM · VyOS 1.2 Crux (VyOS 1.2.6)
hagbard added a comment to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

Rebuilding iso, once it finished it will have the correct version.
[...]
Get:152 http://dev.packages.vyos.net/repositories/current/vyos/ current/main libvyosconfig0 amd64 0.0.6 [841 kB]
[...]
Will test it from the iso, just for peace of mind.

Jan 26 2019, 5:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard claimed T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

Dev.packages has 0.0.06, so something goes sideways during build process, I will work on that and test. I'll take the task back and close it when resolved in ci (looking into it right now). I manually installed the package and everything works as expected.

Jan 26 2019, 5:26 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

Still same issue on 1.2.0-rolling+201901250337.

Jan 26 2019, 5:21 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

Nice! I will test it tomorrow for sure.

Jan 26 2019, 2:28 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 25 2019

hagbard closed T1178: Scheduled script breaks ability to modify configuration as Resolved.
Jan 25 2019, 8:07 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard committed rVYOSONEX2ff09dbd66ee: Fix: T1178: Scheduled script breaks ability to modify configuration.
Jan 25 2019, 8:04 PM
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

Anyone?

Jan 25 2019, 6:13 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 23 2019

hagbard reassigned T1193: libvyosconfig parser cannot handle top level leaf and tag nodes from hagbard to dmbaturin.
Jan 23 2019, 8:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

Found the bug, https://github.com/hagbard-01/vyos-1x/releases/download/1.2.0-10/vyos-1x_1.2.0-10_all.deb should fix it. As soon as You guys can confirm, I push it upstream.

Jan 23 2019, 7:56 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

@c-po All right, found it. Try it without arguments, then it ends up just as */5 * * * * root /usr/bin/logger which causes the issue. That shouldn't be too hard to fix, the existence of the cronjobfile after a reboot without the save command however is a longer journey.

Jan 23 2019, 6:32 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

Thanks that helps, I gotta review. Remote authenticated users would act like local ones by the way, pam would resolve it or if it can't be resolved, con exits with 1.

Jan 23 2019, 6:07 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

@c-po
*/5 * * * * cpo sg vyattacfg "/usr/bin/logger foo"

Jan 23 2019, 7:44 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

I had to pass on libvyos and OCAML, just reading and understanding a few lines took me forever. What would be the fix?

Jan 23 2019, 6:41 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 22 2019

hagbard updated subscribers of T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.
Jan 22 2019, 10:58 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

Issue sits somewhere in vyos.configtree

Jan 22 2019, 10:45 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T1193: libvyosconfig parser cannot handle top level leaf and tag nodes from Open to Confirmed.
Jan 22 2019, 10:39 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard claimed T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.
Jan 22 2019, 10:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

All right, can you please test: https://github.com/hagbard-01/vyos-1x/releases/download/1.2.0-10/vyos-1x_1.2.0-10_all.deb

Jan 22 2019, 10:26 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard renamed T1194: cronjob is being setup even if not saved from conjobs is being setup even if not saved to conjob is being setup even if not saved.
Jan 22 2019, 8:58 PM · VyOS 1.2 Crux (VyOS 1.2.6)
hagbard created T1194: cronjob is being setup even if not saved.
Jan 22 2019, 8:53 PM · VyOS 1.2 Crux (VyOS 1.2.6)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

OK, so the issue happens only if a) the cronjobs was executed by root and b) it modifies the config (which gets then rewritten via union-fs). I created another user called test01, the user vyos has a cron job in his name, regardless what user (test01 or vyos) the script runs, all stays healthy. As soon as the script is triggered via root, you can't set anything in your running config due to the permission changes I wrote yesterday.

Jan 22 2019, 8:42 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard committed rVYOSONEX58d1afe53c2a: Revert "adjusted unit test".
Jan 22 2019, 6:38 PM
hagbard committed rVYOSONEX44dea640c658: Revert "Fix: T1178 - Scheduled script breaks ability to modify configuration".
Jan 22 2019, 6:38 PM
hagbard added a reverting change for rVYOSONEX0d80b06ccd33: adjusted unit test: rVYOSONEX58d1afe53c2a: Revert "adjusted unit test".
Jan 22 2019, 6:38 PM
hagbard added a reverting change for rVYOSONEX632893abf5c7: Fix: T1178 - Scheduled script breaks ability to modify configuration: rVYOSONEX44dea640c658: Revert "Fix: T1178 - Scheduled script breaks ability to modify configuration".
Jan 22 2019, 6:38 PM
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

Thanks for confirming. With 2 users, you may encounter always the issue that a cronjob locks up your ability to change the config afterwards. For now the manual workaround should help you, I'm going to revert my changes from yesterday and return to the drawing board.

Jan 22 2019, 6:35 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard closed T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient as Resolved.

Thx for testing.

Jan 22 2019, 6:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard closed T894: DHCP not renewed after switching network as Resolved.

Fixed via T1181

Jan 22 2019, 6:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard closed T894: DHCP not renewed after switching network, a subtask of T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient, as Resolved.
Jan 22 2019, 6:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

I wouldn't execute a scheduled script. Thats all. Do you recreate then a different user? Since all users have admin privs, the probem with the change permissions will persist. Actually makes it works, one user can block the other. So, I have to find something else out.

Jan 22 2019, 6:13 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

@cpo it would just exit 1. I gotta look into the possibility to see the commit user, I was under the assumption that the vyos user always exists. If there are multiple (at least 2 different) and the cron runs a root or the user (the one which did not setup the job), it will disable any config for all other users, since the filesystem permissions change. ACL's would be something which can solve it, but I have to verify it. I'll keep this task open to track it. Do you just replace the vyos user, or are you using root only in your config?

Jan 22 2019, 4:38 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 21 2019

hagbard assigned T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups to Merijn.
Jan 21 2019, 10:11 PM
hagbard moved T894: DHCP not renewed after switching network from Needs Triage to In Progress on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 21 2019, 10:06 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T894: DHCP not renewed after switching network.

@yun can you please test with the latest rolling?

Jan 21 2019, 10:06 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

@kroy install http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyos-1x/vyos-1x_1.2.0-10_all.deb and try again, I have the changes in that package and tonights rolling will have it too. I couldn't find anywhere a requirement that the cronjobs need root, so I switched it to always run as vyos which keeps the file system permissions intact. Test it on a test machine first, but it should now do what you want, I used your script code from above, but didn't have any real ospf adjacency with any other route, but that shouldn't matter at all. Let me know the results please.

Jan 21 2019, 9:20 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard committed rVYOSONEX0d80b06ccd33: adjusted unit test.
Jan 21 2019, 9:12 PM
hagbard committed rVYOSONEX632893abf5c7: Fix: T1178 - Scheduled script breaks ability to modify configuration.
Jan 21 2019, 9:11 PM
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

OK, I think I found it, however so far I can only give you a quick workaround rather than solving it.
Short explanation, if you setup cron, your script is executed as root which changes the permissions for the configs on union-fs and the directories, that's why already a set fails, it can't simply write as user vyos to the directory.
To get your stuff working, try the following (preferably on a test box, I used the rolling from tonight but any 1.2 image should work if it's not older than 3 months or so)

Jan 21 2019, 8:41 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

The 'commit' causes the issue, but right now I'm not sure why.

Jan 21 2019, 8:03 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.
In T1178#30992, @kroy wrote:

@hagbard Note that a reboot does fix the ability to edit configuration again until the next time the cron script runs.

Jan 21 2019, 6:13 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T1178: Scheduled script breaks ability to modify configuration from Open to Needs testing.
Jan 21 2019, 6:09 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.
Jan 21 2019, 6:09 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

I'm going to implement it into the configuration, which will assure that is it going to be the last step executed after a reboot.

Jan 21 2019, 5:21 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard edited projects for T894: DHCP not renewed after switching network, added: VyOS 1.2 Crux (VyOS 1.2.0-GA); removed VyOS 1.2 Crux (VyOS 1.2.0-EPA3).
Jan 21 2019, 5:19 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 18 2019

hagbard added a comment to T1184: wireguard - extend documentation with the show interface wireguard commands.

wireguard identifies peers on their key, improve the command for sh int wireguard wg01 peers etc. so that the peer name from the config is visible as well.

Jan 18 2019, 9:07 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard added a comment to T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.

@ekim https://downloads.vyos.io/rolling/current/amd64/vyos-1.2.0-rolling%2B201901181924-amd64.iso should address the dhcp issue, can you please test? I only tested on VMs yet.

Jan 18 2019, 7:07 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T894: DHCP not renewed after switching network from In progress to Needs testing.

@yun https://downloads.vyos.io/rolling/current/amd64/vyos-1.2.0-rolling%2B201901181924-amd64.iso should address that issue, can you please test? I only tested on VMs yet.

Jan 18 2019, 7:07 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T894: DHCP not renewed after switching network, a subtask of T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient, from In progress to Needs testing.
Jan 18 2019, 7:07 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard triaged T1184: wireguard - extend documentation with the show interface wireguard commands as Low priority.
Jan 18 2019, 6:05 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard claimed T1184: wireguard - extend documentation with the show interface wireguard commands.
Jan 18 2019, 6:05 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard created T1184: wireguard - extend documentation with the show interface wireguard commands.
Jan 18 2019, 6:05 PM · VyOS 1.3 Equuleus (1.3.0-epa1)

Jan 17 2019

hagbard added a comment to T894: DHCP not renewed after switching network.

pending ci netplugd integration, local tests were quite successful, I think it can be release into rolling in the next few days.

Jan 17 2019, 8:10 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T894: DHCP not renewed after switching network from Open to In progress.
Jan 17 2019, 8:09 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T894: DHCP not renewed after switching network, a subtask of T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient, from Open to In progress.
Jan 17 2019, 8:09 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard claimed T894: DHCP not renewed after switching network.
Jan 17 2019, 8:09 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard closed T1028: Suspending and resuming VyOS in VMware will result in loss of static ip addresses as Resolved.
Jan 17 2019, 7:57 PM
hagbard claimed T1028: Suspending and resuming VyOS in VMware will result in loss of static ip addresses.

http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyos-vmwaretools-scripts/vyos-vmwaretools-scripts_1.0-1_all.deb

Jan 17 2019, 6:08 PM

Jan 16 2019

hagbard added a comment to T894: DHCP not renewed after switching network.

T1181 will fix that issue.

Jan 16 2019, 11:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a subtask for T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient: T894: DHCP not renewed after switching network.
Jan 16 2019, 11:37 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a parent task for T894: DHCP not renewed after switching network: T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.
Jan 16 2019, 11:37 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.

All right @ekim I have that feature working in an experimental package. If you want to test it you can build it from here:
https://github.com/hagbard-01/vyos-netplug via dpkg-buildpackage -b -tc -uc -us and install it on any rolling iso. I used the latest for my tests, but it should work on older ones too. It will still take a little time to have that pushed into the normal build process, since it requires some integration work.

Jan 16 2019, 11:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.

@ekim Yeah, that is a known issue I was looking into a while ago already. disable/enable in eth interfaces should now work in the latest rolling, the plug-in and unplug will still need a little. I'll keep this task here open for it.

Jan 16 2019, 5:53 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T166: NPTv6 is broken in the rolling release 999.201609170235 .

I think I know what you mean now, it also starts translating the global address on the external interface. Can you send a PR for the changes you've made please?

Jan 16 2019, 12:02 AM · VyOS 1.2 Crux (VyOS 1.2.1)

Jan 15 2019

hagbard added a comment to T166: NPTv6 is broken in the rolling release 999.201609170235 .

At the first quick review it works:

Jan 15 2019, 11:52 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard added a comment to T166: NPTv6 is broken in the rolling release 999.201609170235 .

@Merijn I haven't added anything. I just tested nptv6 and it was working as expected. I used your setup you have initially posted, I just used a different interface for the outgoing traffic. I confirmed via tcpdump that NAT did work.

Jan 15 2019, 10:06 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard claimed T1178: Scheduled script breaks ability to modify configuration.
Jan 15 2019, 9:15 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard moved T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient from Need Triage to In Progress on the VyOS 1.2 Crux board.
Jan 15 2019, 8:41 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard renamed T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient from Stagnant IP on DHCP interface to disable/enable interface with dhcp ip assignement fails to restart dhclient.
Jan 15 2019, 8:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient from Open to Needs testing.
Jan 15 2019, 8:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.

@ekim I think I found it. When I put the interface into disabled mode and then delete disabled, the dhcp client isn't started anymore if the address is supposed to be received via dhcp, correct?

Jan 15 2019, 8:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard claimed T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.
Jan 15 2019, 7:55 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.

Have you checked on the server DHCP server side for issues?

Jan 15 2019, 7:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T166: NPTv6 is broken in the rolling release 999.201609170235 from Open to Needs testing.

I've tested it without doing anything on the code and everything is working properly.

Jan 15 2019, 6:58 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard closed T1026: Removing tunnel deletes all tunnels? as Resolved.
Jan 15 2019, 5:48 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard closed T1135: "firewall send-redirects enable" works only after switching from disabled state on running system as Resolved.
Jan 15 2019, 5:48 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 11 2019

hagbard added a comment to T1026: Removing tunnel deletes all tunnels?.

That's all to test. I did test it based on the config you provide above, I just want to see if there are any corner case I did not consider.

Jan 11 2019, 6:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 10 2019

hagbard added a comment to T1166: Flow-accounting not working with PPPoE interfaces.

I got a bit further. uacctd seems to have an issue, I started manually pmacctd on pppoe0 and everything is working well. Uacctd shows that it gets hit with something when I check via strace, but it doesn't show anything.

Jan 10 2019, 7:59 PM · Bugs, VyOS 1.3 Equuleus (1.3.8), test

Jan 8 2019

hagbard closed T1107: Grub: no input from serial console (menu doesn't respond to keystrokes) as Resolved.

merged and closed on @kroy 's behalf. (https://phabricator.vyos.net/R5:749d923ee9704624a476bef17d66d752aff6bf0d)
thx @kroy

Jan 8 2019, 10:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard changed the status of T1135: "firewall send-redirects enable" works only after switching from disabled state on running system from In progress to Needs testing.
Jan 8 2019, 10:28 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

The latest rolling has now 'net.ipv4.conf.all.send_redirects = 0', can you please test if that would solve that issue?

Jan 8 2019, 10:23 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

But wouldn't that be a n SA issue in strongswan?
Found their bugreports, I think the best and safest way is to turn redirects entirely off and set an option in interfaces to turn it on. That way we can assure that a warning messages is also read and understood. agree?

Jan 8 2019, 9:07 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

Hmm, I don't like the leaking part :D (I doubt that it will be unecrypted, but haven't tested it yet) . Per default redirects are enabled on every interface, which is the default.

Jan 8 2019, 8:42 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

@zsdc if I understand you correctly, you want that /proc/sys/net/ipv4/conf/all/send_redirects is always 0 unless configured on purpose, correct?
Per default router should do that.

Jan 8 2019, 6:02 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard changed the status of T1135: "firewall send-redirects enable" works only after switching from disabled state on running system from Open to In progress.
Jan 8 2019, 5:48 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 7 2019

hagbard changed the status of T1026: Removing tunnel deletes all tunnels? from In progress to Needs testing.
Jan 7 2019, 11:21 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1026: Removing tunnel deletes all tunnels?.

Sorry for the delay @Barrysdca , please test the rolling release January 8th. or alternativly you can install http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyatta-cfg-system/vyatta-cfg-system_0.20.44+vyos2+current17_amd64.deb as well, which should fix the issue.
Please provide feedback as soon as you can, I tested the config you have posted above and everything appears to be working well now with the new package.

Jan 7 2019, 11:21 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard changed the status of T1026: Removing tunnel deletes all tunnels? from On hold to In progress.
Jan 7 2019, 10:29 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)