Page MenuHomeVyOS Platform
Feed Search

Sep 20 2019

vindenesen added a comment to T1675: OpenVPN - Specify minimum TLS version.

Pull request created: https://github.com/vyos/vyos-1x/pull/133

Sep 20 2019, 11:07 AM · VyOS 1.3 Equuleus (1.3.0)
vindenesen changed the status of T1675: OpenVPN - Specify minimum TLS version from Open to In progress.
Sep 20 2019, 10:46 AM · VyOS 1.3 Equuleus (1.3.0)
vindenesen claimed T1675: OpenVPN - Specify minimum TLS version.
Sep 20 2019, 10:46 AM · VyOS 1.3 Equuleus (1.3.0)
vindenesen created T1675: OpenVPN - Specify minimum TLS version.
Sep 20 2019, 10:45 AM · VyOS 1.3 Equuleus (1.3.0)

Sep 19 2019

hagbard closed T1670: OpenVPN option for tls-auth as Resolved.

PR merged https://github.com/vyos/vyos-1x/pull/131

Sep 19 2019, 8:24 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1673: vif bridge-group not migrated to bridge member interface.

Please share a pre and post-commit config block for me for testing.

Sep 19 2019, 8:16 PM · VyOS 1.3 Equuleus (1.3.0)
mb300sd added a comment to T1673: vif bridge-group not migrated to bridge member interface.

The loading error is caused by bridging a l2tpv3 interface, didn't see the cause at first because of the other errors. Since the bridge is now created at priority 470, and l2tpv3 is 800, when before an interface would be added to the bridge as it is created.

Sep 19 2019, 7:56 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen added a comment to T1670: OpenVPN option for tls-auth.

Pull request added: https://github.com/vyos/vyos-1x/pull/131

Sep 19 2019, 7:44 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1672: Wireguard keys not automatically moved from Open to Confirmed.
Sep 19 2019, 7:32 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1672: Wireguard keys not automatically moved.
Sep 19 2019, 7:31 PM · VyOS 1.3 Equuleus (1.3.0)
mb300sd added a comment to T1673: vif bridge-group not migrated to bridge member interface.

After adding the vif to bridge member interfaces, I get a config load error on boot. Running config, load, commit, works. Something to do with the order the configs get applied?

Sep 19 2019, 7:04 PM · VyOS 1.3 Equuleus (1.3.0)
mb300sd renamed T1673: vif bridge-group not migrated to bridge member interface from bridge-group missing from vif to vif bridge-group not migrated to bridge member interface.
Sep 19 2019, 6:59 PM · VyOS 1.3 Equuleus (1.3.0)
mb300sd changed Is it a breaking change? from behavior to syntax on T1673: vif bridge-group not migrated to bridge member interface.
Sep 19 2019, 6:55 PM · VyOS 1.3 Equuleus (1.3.0)
mb300sd added a comment to T1673: vif bridge-group not migrated to bridge member interface.

Just noticed bridge has a member interface parameter now. The vif bridge-group config was not migrated.

Sep 19 2019, 6:55 PM · VyOS 1.3 Equuleus (1.3.0)
mb300sd created T1673: vif bridge-group not migrated to bridge member interface.
Sep 19 2019, 6:51 PM · VyOS 1.3 Equuleus (1.3.0)
mb300sd created T1672: Wireguard keys not automatically moved.
Sep 19 2019, 6:49 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen updated the task description for T1670: OpenVPN option for tls-auth.
Sep 19 2019, 5:55 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen added a comment to T1670: OpenVPN option for tls-auth.
Sep 19 2019, 4:03 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen triaged T1670: OpenVPN option for tls-auth as Low priority.
Sep 19 2019, 3:48 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen updated the task description for T1670: OpenVPN option for tls-auth.
Sep 19 2019, 3:42 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen claimed T1670: OpenVPN option for tls-auth.
Sep 19 2019, 3:42 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen created T1670: OpenVPN option for tls-auth.
Sep 19 2019, 3:41 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard moved T1664: Ipoe with bond per vlan don't work from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Sep 19 2019, 3:19 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a project to T1664: Ipoe with bond per vlan don't work: VyOS 1.3 Equuleus.
Sep 19 2019, 3:19 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard moved T1664: Ipoe with bond per vlan don't work from Finished to Backlog on the VyOS 1.2 Crux board.
Sep 19 2019, 3:18 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1664: Ipoe with bond per vlan don't work as Resolved.

Thanks for testing.

Sep 19 2019, 3:18 PM · VyOS 1.3 Equuleus (1.3.0)
sever added a comment to T1664: Ipoe with bond per vlan don't work.

@hagbard
In VyOS 1.2-rolling-201909190545 all work. Fixed. Thank's.

Sep 19 2019, 8:52 AM · VyOS 1.3 Equuleus (1.3.0)

Sep 18 2019

kroy created T1668: Integration between VyOS installs and a centralized repository..
Sep 18 2019, 11:20 PM · VyOS Networks Controller
hagbard added a comment to T1664: Ipoe with bond per vlan don't work.

@sever I see that the new package hasn't been autobuild in our CI, I see to get that fixed. If you are in urgent need of the change, please build and install vyos-1x manually.

Sep 18 2019, 3:42 PM · VyOS 1.3 Equuleus (1.3.0)
sever added a comment to T1664: Ipoe with bond per vlan don't work.

In release VyOS 1.2-rolling-201909180118 I dont see this command

Sep 18 2019, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)

Sep 16 2019

hagbard changed the status of T1664: Ipoe with bond per vlan don't work from In progress to Needs testing.
Sep 16 2019, 9:41 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1664: Ipoe with bond per vlan don't work.

Tomorrows rolling ISO will have the patch applied.
Please test and let me know how it goes.

Sep 16 2019, 9:36 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1664: Ipoe with bond per vlan don't work from Confirmed to In progress.

@sever Issue found and working on a patch.

ifname  | called-sid |    calling-sid    |     ip      | ip6 | ip6-dp | rate-limit | state  |  uptime  |        sid       
----------+------------+-------------------+-------------+-----+--------+------------+--------+----------+------------------
 bond0.51 | bond0.51   | 08:00:27:82:43:ae | 192.168.0.2 |     |        |            | active | 00:01:03 | d060220ce77252a9

Auto creation of vlans failed.

Sep 16 2019, 9:28 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1664: Ipoe with bond per vlan don't work from Open to Confirmed.
Sep 16 2019, 5:33 PM · VyOS 1.3 Equuleus (1.3.0)
sever added a comment to T1664: Ipoe with bond per vlan don't work.

@hagbard in first my message actual config for bond1 with client-subnet 10.3.0.0/23 and authentication mode "local".
I plan to use several vlan's for several services.
You use it without vlans.

Sep 16 2019, 4:19 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1664: Ipoe with bond per vlan don't work.

everything works without issue as far a I see.

Sep 16 2019, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1664: Ipoe with bond per vlan don't work.

@sever Yeah, sorry about the typo. You need to define an IP pool and an authentication method if you are not using a RADIUS server for that.
(I have bond0 in my lab so you need to change that to bond1 if you copy).

Sep 16 2019, 4:09 PM · VyOS 1.3 Equuleus (1.3.0)
sever added a comment to T1664: Ipoe with bond per vlan don't work.

@hagbard bond0 - is WAN interface without vlans/tags. For DHCP listening I use bond1 interface, not PPP.
A try man https://vyos.readthedocs.io/en/latest/services/ipoe-server.html

Sep 16 2019, 3:54 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1664: Ipoe with bond per vlan don't work.

@sever Can you please try: set service pppoe-server interface bond0 vlan-id 55. And have a look into /var/log/messages what accel is reporting there once the dhcp reply arrives. I'm going to lab up your config and test as well.
Also you need to define an IP pool a client can get an IP address from.
https://vyos.readthedocs.io/en/latest/services/ipoe-server.html
(btw: show config comands gives you a nicer config overview)

Sep 16 2019, 3:43 PM · VyOS 1.3 Equuleus (1.3.0)
sever added a comment to T1664: Ipoe with bond per vlan don't work.

@sever Can you please also share your pppoe-server config?

Sep 16 2019, 3:29 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1664: Ipoe with bond per vlan don't work.

@sever Can you please also share your pppoe-server config?

Sep 16 2019, 3:12 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1664: Ipoe with bond per vlan don't work.
Sep 16 2019, 3:10 PM · VyOS 1.3 Equuleus (1.3.0)
sever created T1664: Ipoe with bond per vlan don't work.
Sep 16 2019, 8:03 AM · VyOS 1.3 Equuleus (1.3.0)
sever added a comment to T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338.
In T1660#43438, @c-po wrote:

Please test again with the rolling release from 2019-09-14. Thanks for reporting the issue.

Sep 16 2019, 7:02 AM · VyOS 1.3 Equuleus (1.3.0)

Sep 13 2019

c-po added a comment to T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338.

Please test again with the rolling release from 2019-09-14. Thanks for reporting the issue.

Sep 13 2019, 6:44 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a parent task for T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338: T1614: Rewrite bonding interface in new style XML syntax.
Sep 13 2019, 6:41 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338 as Resolved.
Sep 13 2019, 6:40 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard reassigned T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338 from hagbard to Unknown Object (User).
Sep 13 2019, 4:06 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338.

PR https://github.com/vyos/vyos-1x/pull/128

Sep 13 2019, 4:02 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338.
Sep 13 2019, 3:49 PM · VyOS 1.3 Equuleus (1.3.0)
sever created T1660: Bonding dont’t work on VyOS 1.2-rolling-201909120338.
Sep 13 2019, 3:41 PM · VyOS 1.3 Equuleus (1.3.0)

Sep 11 2019

hagbard changed the status of T770: Bonded interfaces get updated with incorrect hw-id in config. from Confirmed to In progress.
Sep 11 2019, 5:16 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
zsdc changed the status of T1654: sFlow: multiple "sflow server" not work, and "disable-imt" could break configuration from Open to Confirmed.
Sep 11 2019, 4:07 PM · VyOS 1.3 Equuleus (1.3.0)
zsdc created T1654: sFlow: multiple "sflow server" not work, and "disable-imt" could break configuration.
Sep 11 2019, 4:06 PM · VyOS 1.3 Equuleus (1.3.0)

Sep 10 2019

hagbard closed T1644: Wireguard listen ports lower than 1024 as Wontfix.

I think encapsulate the udp based traffic into tcp is more than counter productive and makes it an easy DoS target.

Sep 10 2019, 3:36 AM · Rejected
Asteroza added a comment to T1644: Wireguard listen ports lower than 1024.

Actually somebody made a nifty websocket tunnel named wstunnel (similar to stunnel conceptually, but websockets is more natural for tunneling generic binary protocols thanks to webRTC...) that seems to work alright for Wireguard.

Sep 10 2019, 1:06 AM · Rejected
trystan added a comment to T1644: Wireguard listen ports lower than 1024.

I was thinking some more along the lines of stunnel and wrapping wireguard that way but it would require additional packaging and integration on the vyos side. Luckily whatever outbound filtering is in place for this specific implementation seems to be relatively basic and limited to port blocking/whitelisting.

Sep 10 2019, 12:51 AM · Rejected
Asteroza added a comment to T1644: Wireguard listen ports lower than 1024.

As long as the local nginx is not listening on the external interface on udp/443, functionally there should be no limitation to running wireguard on 443 there. A convoluted script to check that the current config has no existing 443 mapping is one solution, but that seems a bit fragile, and wouldn't really tell you where in the config the blocking 443 instance is.

Sep 10 2019, 12:30 AM · Rejected

Sep 9 2019

hagbard added a comment to T1644: Wireguard listen ports lower than 1024.

Why not using ports higher 1024? Port 80 and 443 are so called privileged ports, not sure if that is really required. Port udp/80, udp/443 for instance may interfere in the future with QUIC.

Sep 9 2019, 9:49 PM · Rejected
trystan added a comment to T1644: Wireguard listen ports lower than 1024.

Yes, I understand that. The primary request is to be able to set a listen port lower than 1024 without having to create a destination NAT rule to get the same result.

Sep 9 2019, 9:29 PM · Rejected
hagbard added a comment to T1644: Wireguard listen ports lower than 1024.

That is listen port. endpoints are peer specific, if you have multiple peers on the same interface, each one has of course it's own endpoint if you want to initiate the connections. Otherwise, once the other peer connected to your gateway (assuming the handshake was successful), this information is taken from the header.

Sep 9 2019, 9:24 PM · Rejected
trystan added a comment to T1644: Wireguard listen ports lower than 1024.
set interfaces wireguard wg1 port 443
Sep 9 2019, 9:14 PM · Rejected
hagbard added a comment to T1644: Wireguard listen ports lower than 1024.

@trystan Listen or endpoint? The listen port had been limited to avoid issues with IANA assigned ports.
udp/80 or udp/443 might not m=be the best option anyway.

Sep 9 2019, 8:57 PM · Rejected
hagbard claimed T1644: Wireguard listen ports lower than 1024.
Sep 9 2019, 8:50 PM · Rejected
trystan created T1644: Wireguard listen ports lower than 1024.
Sep 9 2019, 7:54 PM · Rejected
kroy updated the task description for T1643: Deleting all firewall zones failed and locked out box.
Sep 9 2019, 6:34 PM · VyOS 1.3 Equuleus (1.3.0), test
kroy created T1643: Deleting all firewall zones failed and locked out box.
Sep 9 2019, 6:33 PM · VyOS 1.3 Equuleus (1.3.0), test
rcit created T1642: BGP configuration error when using remove-private-as.
Sep 9 2019, 12:16 PM · VyOS 1.2 Crux (VyOS 1.2.3)

Sep 6 2019

hagbard changed the status of T770: Bonded interfaces get updated with incorrect hw-id in config. from In progress to Confirmed.
Sep 6 2019, 7:05 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard added a project to T770: Bonded interfaces get updated with incorrect hw-id in config.: VyOS 1.2 Crux.
Sep 6 2019, 7:04 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
kroy added a parent task for T1638: vyos-hostsd not setting system domain name : T1598: New implementation of the resolv.conf and hosts update mechanism.
Sep 6 2019, 2:17 PM · VyOS 1.2 Crux (VyOS 1.2.4)
kroy updated the task description for T1638: vyos-hostsd not setting system domain name .
Sep 6 2019, 2:13 PM · VyOS 1.2 Crux (VyOS 1.2.4)
kroy created T1638: vyos-hostsd not setting system domain name .
Sep 6 2019, 2:12 PM · VyOS 1.2 Crux (VyOS 1.2.4)

Sep 4 2019

c-po added a comment to T1633: Cannot bridge interfaces.

The documentation is also correct. Please not that there are two git branches for the documentation, current and equuleus. You send me the VyOS 1.2.2 crux link. I gave you the upcoming VyOS 1.2 equuleus link.

Sep 4 2019, 1:57 PM · VyOS 1.3 Equuleus (1.3.0)
fadly.tabrani changed the subtype of T1633: Cannot bridge interfaces from "Bug" to "Task".

Thanks! Should update the documentation @ https://vyos.readthedocs.io/en/latest/interfaces/bridging.html

Sep 4 2019, 12:45 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1633: Cannot bridge interfaces as Invalid.
Sep 4 2019, 12:37 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1633: Cannot bridge interfaces.

The bahavior has changed, see https://vyos.readthedocs.io/en/equuleus/interfaces/bridging.html and T1556

Sep 4 2019, 12:36 PM · VyOS 1.3 Equuleus (1.3.0)
fadly.tabrani created T1633: Cannot bridge interfaces.
Sep 4 2019, 12:32 PM · VyOS 1.3 Equuleus (1.3.0)

Sep 3 2019

c-po added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

When the site looses connection and thus a SIGUSR21 is sent to OpenVPN to restart internally the priviledges have dropped and yes, /sbin/ip can't be called again.

Sep 3 2019, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
hexes updated the task description for T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.
Sep 3 2019, 3:32 PM · VyOS 1.3 Equuleus (1.3.0)
hexes created T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.
Sep 3 2019, 3:29 PM · VyOS 1.3 Equuleus (1.3.0)
c-po assigned T1629: IP addresses configured on vif-s interfaces are not added to the system to dmbaturin.
Sep 3 2019, 2:59 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1629: IP addresses configured on vif-s interfaces are not added to the system.
Sep 3 2019, 2:58 PM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T1626: BGP exchanges prefixes without specified address-family.
Sep 3 2019, 8:49 AM · VyOS 1.3 Equuleus (1.3.0), test
c-po created T1626: BGP exchanges prefixes without specified address-family.
Sep 3 2019, 8:49 AM · VyOS 1.3 Equuleus (1.3.0), test

Aug 31 2019

syncer changed the status of T1417: IPv6 zone based firewall rules can't be modified from Open to Needs testing.
Aug 31 2019, 12:18 AM

Aug 30 2019

jjakob created T1620: Leases in "show dhcp server leases" lose Pool and Hostname after some time in the S1 VyOS Public space.
Aug 30 2019, 9:54 AM · VyOS 1.3 Equuleus (1.3.6)

Aug 29 2019

c-po closed T1618: ping wont accept arguments as Invalid.
Aug 29 2019, 10:12 AM · Rejected
c-po added a comment to T1618: ping wont accept arguments.

This is "as intended" b/c ping is an op-mode command.

Aug 29 2019, 10:12 AM · Rejected
Harliff created T1618: ping wont accept arguments.
Aug 29 2019, 9:51 AM · Rejected

Aug 27 2019

c-po added a project to T1613: IPv6 traffic is not captured by NetFlow sensor (pmacct/NFLOG): VyOS 1.3 Equuleus.
Aug 27 2019, 8:23 PM · VyOS 1.2 Crux (VyOS 1.2.3)
c-po added a comment to T1613: IPv6 traffic is not captured by NetFlow sensor (pmacct/NFLOG).

backported to crux

Aug 27 2019, 8:23 PM · VyOS 1.2 Crux (VyOS 1.2.3)
zsdc added a comment to T1613: IPv6 traffic is not captured by NetFlow sensor (pmacct/NFLOG).

Pull request for fixing this problem: https://github.com/vyos/vyatta-netflow/pull/4

Aug 27 2019, 6:49 PM · VyOS 1.2 Crux (VyOS 1.2.3)
nirmal created T1616: 'renew dhcpv6 interface <interfaceName>' command fails, but work within config session.
Aug 27 2019, 4:48 PM · VyOS 1.2 Crux (VyOS 1.2.3)
dmbaturin added a subtask for T1598: New implementation of the resolv.conf and hosts update mechanism: T1540: Static-host-mappings disappear from /etc/hosts after a while.
Aug 27 2019, 6:00 AM · VyOS 1.2 Crux (VyOS 1.2.3)
dmbaturin added a subtask for T1598: New implementation of the resolv.conf and hosts update mechanism: T1542: static-host-mapping entries broken after reboot.
Aug 27 2019, 5:58 AM · VyOS 1.2 Crux (VyOS 1.2.3)

Aug 26 2019

zsdc changed the status of T1613: IPv6 traffic is not captured by NetFlow sensor (pmacct/NFLOG) from Open to In progress.
Aug 26 2019, 5:45 PM · VyOS 1.2 Crux (VyOS 1.2.3)
zsdc created T1613: IPv6 traffic is not captured by NetFlow sensor (pmacct/NFLOG).
Aug 26 2019, 5:45 PM · VyOS 1.2 Crux (VyOS 1.2.3)
c-po added a comment to T1591: OpenVPN "run show openvpn client status" does not work.

Resolved with rewrite of op-mode scripts in Python.

Aug 26 2019, 2:22 PM · VyOS 1.3 Equuleus (1.3.0)
MarcSim added a comment to T1545: IPSEC vti issue.

We have change vyos configuration.
Now, our vyos still have 1 interface but haven't two ip adresses.
It have only one private IP.
VPN coming from wan connecte to it by public IP manage by compgany firewall and VPN coming from Local network connect to it by private ip adresses.

Aug 26 2019, 10:31 AM · VyOS 1.3 Equuleus (1.3.0)