Page MenuHomeVyOS Platform
Feed Search

Mar 8 2019

hagbard triaged T1288: FRR: rewrite staticd backend (/opt/vyatta/share/vyatta-cfg/templates/protocols/static/*) as Normal priority.
Mar 8 2019, 9:07 PM · VyOS 1.3 Equuleus (1.3.3)
hagbard added a comment to T1267: FRR: Add interface name for static routes.

@zsdc How quickly needs that to be resolved? It requires quite some work on the backend for the cli.

Mar 8 2019, 9:03 PM · VyOS 1.3 Equuleus (1.3.0)

Feb 28 2019

hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Since it's not a wireguard issue rather then a network issue between both systems, I'll remove it from 1.2 and put it into 1.3 .

Feb 28 2019, 5:46 PM · Invalid

Feb 27 2019

hagbard closed T686: 'run show openvpn client-status' is not displaying local tunnel address as Wontfix.

That information is not easily visible, never been according to the openvpn folks.

Feb 27 2019, 8:58 PM · Rejected
hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Do you see now the udp arriving on both sides?

Feb 27 2019, 8:55 PM · Invalid
Maltahl added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Ye it works fine. How else would it be able to work before with same routers, same ips, same config ? I can also access services no problem on the remote site (reverse proxy) but not services on the local network on the remote site.

Feb 27 2019, 7:07 PM · Invalid
hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

@Maltahl any news on the traffic via vlan?

Feb 27 2019, 7:03 PM · Invalid
syncer changed the status of T1267: FRR: Add interface name for static routes from Open to Confirmed.
Feb 27 2019, 12:34 PM · VyOS 1.3 Equuleus (1.3.0)

Feb 26 2019

hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

The wg traffic from host1 never reaches host 2, therefore wireguard can't function. Suggested to investigate the infrastructure to see if the traffic leaves actually the premises. Will put the task on hold meanwhile.

Feb 26 2019, 6:26 PM · Invalid

Feb 23 2019

dmbaturin added a comment to T1148: epa2 BGP peers initiate before config is fully loaded, routes leak..

@danhusan IPv6 should not be affected. Workaround for IPv4:

Feb 23 2019, 10:13 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Feb 22 2019

hagbard edited projects for T1262: dhcp requested WAN ip address doesn't get search parameter in /etc/resolv.conf in 1.2.0-rolling+201902210337, added: VyOS 1.2 Crux (VyOS 1.2.2); removed VyOS 1.2 Crux (VyOS 1.2.0-GA).
Feb 22 2019, 8:46 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project, VyOS 1.2 Crux (VyOS 1.2.9), test

Feb 19 2019

hagbard closed T1051: Update openvpn to support TLS 1.2 as Resolved.

Tested it myself and can't find any issues.

Feb 19 2019, 7:02 PM · VyOS 1.2 Crux (VyOS 1.2.2)
hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

No idea what that could be, it's for sure a config problem since many others use it as well as myself with no issue at all. Is there any way I can access your env?

Feb 19 2019, 7:00 PM · Invalid
Maltahl added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Tried both and they solved the issue but same problem with the tunnel not going up is the same.
I tried regen keys on both ends. No dice.

Feb 19 2019, 4:25 PM · Invalid

Feb 15 2019

hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Should be in the latest rolling or here: http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyos-1x/vyos-1x_1.2.0-13_all.deb

Feb 15 2019, 8:37 PM · Invalid
Maltahl added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

@hagbard is the patch for the validator issue in latest rolling or do you have a .deb i can apply ? :)

Feb 15 2019, 8:32 PM · Invalid
hagbard changed the status of T686: 'run show openvpn client-status' is not displaying local tunnel address from In progress to On hold.

The client status file information is quite different compared to the one from a server config, I couldn't find a way yet to retrieve the information for the table.

Feb 15 2019, 7:00 PM · Rejected
hagbard changed the status of T686: 'run show openvpn client-status' is not displaying local tunnel address from Open to In progress.
Feb 15 2019, 6:37 PM · Rejected

Feb 13 2019

hagbard added a comment to T1051: Update openvpn to support TLS 1.2.

@thinkl33t Please test the latest rolling which has openvpn2.4 installed.

Feb 13 2019, 4:20 PM · VyOS 1.2 Crux (VyOS 1.2.2)

Feb 12 2019

fmayo added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

I am affected too by this issue.

Feb 12 2019, 4:15 PM · VyOS 1.3 Equuleus (1.3.6)

Feb 11 2019

hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Ok, so that issue has been corrected, I used the wrong validator. (https://github.com/vyos/vyos-1x/commit/1842fc9fdbcfa877e42714eaf620dff18ff9859c)

Feb 11 2019, 4:52 PM · Invalid
hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Hmm, that (the IP validation) was a different change which was working. I'll have a look.

Feb 11 2019, 4:43 PM · Invalid
Maltahl added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

All right, let me know if you need help.

Feb 11 2019, 2:40 PM · Invalid

Feb 9 2019

hagbard closed T1010: improper pid file handling of webgui as Resolved.
Feb 9 2019, 10:16 PM · VyOS 1.2 Crux (VyOS 1.2.2)
hagbard added a comment to T1010: improper pid file handling of webgui.
Feb 9 2019, 11:06 AM · VyOS 1.2 Crux (VyOS 1.2.2)

Feb 8 2019

hagbard changed the status of T1010: improper pid file handling of webgui from Open to In progress.
Feb 8 2019, 7:36 PM · VyOS 1.2 Crux (VyOS 1.2.2)
hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

All right, let me know if you need help.

Feb 8 2019, 6:49 PM · Invalid
Merijn added a comment to T1148: epa2 BGP peers initiate before config is fully loaded, routes leak..

@zsdc i meant test with 1.2.0 :-)

Feb 8 2019, 12:11 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
zsdc added a comment to T1148: epa2 BGP peers initiate before config is fully loaded, routes leak..

@danhusan , you can send the configuration to support@vyos.io with the theme "Phabricator T1148". Also, please check if a remote side of BGP peering run in active or passive mode?

Feb 8 2019, 12:10 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Merijn added a comment to T1148: epa2 BGP peers initiate before config is fully loaded, routes leak..

We are seeing this issue mostly on BGP routers with Internet Exchange connections because at a reboot we are hitting max-prefix limits with a lot of peers.
At this moment it is not possible to upgrade to latest 1.2.0, still running 1.1.8.

Feb 8 2019, 8:06 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Maltahl added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Will try to reinstall the baremetal router since it is the most inconsistant of the two routers. The virtual one works with other peers.

Feb 8 2019, 6:51 AM · Invalid
danhusan added a comment to T1148: epa2 BGP peers initiate before config is fully loaded, routes leak..

Small config, just 4 interfaces with IPv4 and IPv6 + some BGP config. I am running the VyOS instance in ESXi with some fairly modern hardware.
Unfortunately I cannot just reboot this device at will. If you provide your email I can send over the config.

Feb 8 2019, 6:23 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Feb 7 2019

hagbard added a comment to T1051: Update openvpn to support TLS 1.2.

@thinkl33t Can you please test?

Feb 7 2019, 11:46 PM · VyOS 1.2 Crux (VyOS 1.2.2)
syncer moved T989: Add support for IPoE server from Needs Triage to In Progress on the VyOS 1.2 Crux (VyOS 1.2.2) board.
Feb 7 2019, 11:25 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer moved T891: Current multi-table usage with VRF-netns tables in FRR is partially broken for PBR. from Needs Triage to In Progress on the VyOS 1.2 Crux (VyOS 1.2.2) board.
Feb 7 2019, 11:25 PM · VyOS 1.3 Equuleus (1.3.0)
syncer moved T686: 'run show openvpn client-status' is not displaying local tunnel address from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.2) board.
Feb 7 2019, 11:24 PM · Rejected
syncer assigned T686: 'run show openvpn client-status' is not displaying local tunnel address to hagbard.
Feb 7 2019, 11:24 PM · Rejected
syncer reassigned T1010: improper pid file handling of webgui from dmbaturin to hagbard.

@hagbard we need to remove all old stuff including lightttpd
we going to replace it with nginx as per T808

Feb 7 2019, 11:23 PM · VyOS 1.2 Crux (VyOS 1.2.2)
syncer edited projects for T1169: LLDP potentially broken, added: VyOS 1.2 Crux (VyOS 1.2.2); removed VyOS 1.2 Crux (VyOS 1.2.0-GA).
Feb 7 2019, 11:20 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
zsdc added a comment to T1148: epa2 BGP peers initiate before config is fully loaded, routes leak..

Hello @danhusan!
How big is your configuration at all? Can you provide depersonalized config? Which hardware or virtual machine using for VyOS? Can you provide full log of booting?
We can't confidently reproduce this bug. Looks like configuration can't load quickly enough or something like this.

Feb 7 2019, 8:21 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
ekim added a comment to T1171: 1.2.0 epa2 - IPsec VPN initiation.

Received the following commit error:

Feb 7 2019, 6:33 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Hmm. That's weird, I tested some rolling releases and 1.2.0, directly connected and via 5 hops, I can't reproduce what you see. If your crypto is ok and you have the the interface up and running, there won't be an issue. I would also see way more bug tickets here. So , I still believe yoru setup is incorrect, however it's hard to say where it fails. If the wg interface has no incoming and outgoing traffic, it's most likely routing. If inside the wg interface traffic goes out but is not answered but received on the upstream interface, somet6hing is wrong with the crypto. In your sho interface output is shows that traffic is being sent, but nothing recveived, that means the traffic you receive on the WAN side can't be authenticated, so that is an crypto issue. Either the traffic can't be decrypted or there is no existing setup for this public key. If the public key fits, then you can always decrypt with with your private one.

Feb 7 2019, 6:12 PM · Invalid
Maltahl added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

@Maltahl That smells more like an issue with your key setup. The wg interface listens on any interface which is up and running. If the traffic inside the wg interface doesn't show anything, that means it can't decrypt the traffic with your private key.

Feb 7 2019, 5:55 PM · Invalid
hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

@Maltahl That smells more like an issue with your key setup. The wg interface listens on any interface which is up and running. If the traffic inside the wg interface doesn't show anything, that means it can't decrypt the traffic with your private key.

Feb 7 2019, 5:52 PM · Invalid
ekim added a comment to T1171: 1.2.0 epa2 - IPsec VPN initiation.

Ah, I misread, my apologies. Let me try.

Feb 7 2019, 5:40 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
EwaldvanGeffen added a comment to T1171: 1.2.0 epa2 - IPsec VPN initiation.

@ekim rephrased: remove the DHCP-interface option and only use and configure the local-address to 0.0.0.0.

Feb 7 2019, 5:17 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Maltahl added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

@hagbard i have tried removing all firewall rules on both routers and checked that the wireguard module was running. i have also tried allowing all traffic and also allowed udp for the wireguard port when it arrived.

Feb 7 2019, 2:26 PM · Invalid

Feb 5 2019

hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Tested the config above with in 1.2, no issues found. Not sure what it is yet, but it looks like that either the traffic doesn't really reach the destination (aka endpoint) or vice versa. Awaiting some show output to check the key config etc.

Feb 5 2019, 11:40 PM · Invalid
ekim added a comment to T1171: 1.2.0 epa2 - IPsec VPN initiation.

No. The configuration 'dhcp-interface' and 'local-address' are mutually exclusive , so attempting to commit a configuration with both results in a commit error.

Feb 5 2019, 9:34 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
EwaldvanGeffen added a comment to T1171: 1.2.0 epa2 - IPsec VPN initiation.

Can you try without dhcp-interface and set 0.0.0.0 as local-address?

Feb 5 2019, 8:56 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

@Maltahl You can use any rolling, I made an enhancement yesterday to disable peers, but other than that the code hasn't been touched for a while. If the rolling release works, I need to have a look into 1.2.0. I tested with your config above and everything was working as expected, but I'm around today so feel free to ping me on slack in 1hr.

Feb 5 2019, 4:14 PM · Invalid
syncer reassigned T1171: 1.2.0 epa2 - IPsec VPN initiation from dmbaturin to Unknown Object (User).
Feb 5 2019, 3:07 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer edited projects for T1226: Wireguard not working between vyos routers 1.2.0, added: VyOS 1.2 Crux (VyOS 1.2.2); removed VyOS 1.2 Crux.
Feb 5 2019, 2:20 PM · Invalid
syncer changed the status of T1230: Improving Boot Time for Large Firewall Configurations from Open to Confirmed.
Feb 5 2019, 2:17 PM · VyOS 1.3 Equuleus (1.3.6)
syncer edited projects for T1230: Improving Boot Time for Large Firewall Configurations, added: VyOS 1.2 Crux (VyOS 1.2.2); removed VyOS 1.2 Crux.
Feb 5 2019, 2:17 PM · VyOS 1.3 Equuleus (1.3.6)
syncer moved T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups from Needs Triage to In Progress on the VyOS 1.2 Crux (VyOS 1.2.2) board.
Feb 5 2019, 2:14 PM
syncer reopened T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups as "In progress".
Feb 5 2019, 2:14 PM
syncer edited projects for T1051: Update openvpn to support TLS 1.2, added: VyOS 1.2 Crux (VyOS 1.2.2); removed VyOS 1.2 Crux (VyOS 1.2.0-GA).
Feb 5 2019, 2:13 PM · VyOS 1.2 Crux (VyOS 1.2.2)
syncer edited projects for T1148: epa2 BGP peers initiate before config is fully loaded, routes leak., added: VyOS 1.2 Crux (VyOS 1.2.2); removed VyOS 1.2 Crux (VyOS 1.2.0-GA).
Feb 5 2019, 2:13 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer created VyOS 1.2 Crux (VyOS 1.2.2).
Feb 5 2019, 2:11 PM