Page MenuHomeVyOS Platform
Feed All Stories

Aug 10 2020

Unknown Object (User) changed the status of T2227: MPLS documentation, a subtask of T915: MPLS Support, from Open to On hold.
Aug 10 2020, 5:06 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T2227: MPLS documentation from Open to On hold.

Currently the only application of VyOS LDP is as P router (backbone router in an MPLS cloud).

Aug 10 2020, 5:06 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
Viacheslav claimed T2779: LLDP: "show lldp neighbors interface" does not yield any result.
Aug 10 2020, 5:00 PM · VyOS 1.3 Equuleus (1.3.0)
ajgnet added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

Additionally, sometimes the Peer ID and Local ID are not correctly formatted. for example:

Aug 10 2020, 4:21 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

It seems a parser issue. We are reviewing the script https://github.com/vyos/vyatta-op-vpn/blob/current/scripts/vyatta-op-vpn.pl

Aug 10 2020, 4:14 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

When the configuration provided is reproduced, the problem occurs: show ike sa is "down" while show ipsec sa is "up".

Aug 10 2020, 3:45 PM · VyOS 1.3 Equuleus (1.3.0)
c-po triaged T2767: The interface cannot be disabled for network enabled configuration as High priority.
Aug 10 2020, 3:28 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T2781: Create op-mode top-level wrapper for ssh command.
Aug 10 2020, 3:26 PM · Bugs, VyOS Rolling
c-po created T2781: Create op-mode top-level wrapper for ssh command.
Aug 10 2020, 3:25 PM · Bugs, VyOS Rolling
c-po reassigned T2623: Creating sit tunnel fails with “Can not set “local” for tunnel sit tun1 at tunnel creation” from c-po to thomas-mangin.
Aug 10 2020, 3:20 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po claimed T2762: VRF: when SSHd is VRF bound all commands are executed in VRF context.
Aug 10 2020, 3:17 PM · VyOS Rolling
jack9603301 updated the task description for T2518: Add support for IPv6 NAT (NPTv6).
Aug 10 2020, 11:03 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T2760: In a load-balanced multi-wan configuration with DHCP assigned addresses, IPsec "dhcp-interface" does not work.

ref T2747

Aug 10 2020, 8:42 AM · VyOS Rolling, Bugs
Viacheslav added a comment to T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic.
And script

#!/usr/bin/env bash

Aug 10 2020, 8:38 AM · VyOS 1.5 Circinus
c-po closed T2780: Update Linux Kernel to v4.19.138 as Resolved.
Aug 10 2020, 8:16 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2780: Update Linux Kernel to v4.19.138.
Aug 10 2020, 7:35 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2779: LLDP: "show lldp neighbors interface" does not yield any result.
Aug 10 2020, 7:32 AM · VyOS 1.3 Equuleus (1.3.0)
c-po renamed T2777: "monitor dhcp" does not output any DHCP related information from "monitor dhcp" does not outpu any DHCP related information to "monitor dhcp" does not output any DHCP related information.
Aug 10 2020, 7:22 AM · VyOS 1.3 Equuleus (1.3.0)
c-po triaged T2778: Migrate "system syslog" to get_config_dict() to support new features as Normal priority.
Aug 10 2020, 7:21 AM · VyOS 1.4 Sagitta
c-po added a parent task for T2769: Add VRF support for syslog: T2778: Migrate "system syslog" to get_config_dict() to support new features.
Aug 10 2020, 7:10 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po added a subtask for T2778: Migrate "system syslog" to get_config_dict() to support new features: T2769: Add VRF support for syslog.
Aug 10 2020, 7:10 AM · VyOS 1.4 Sagitta
c-po created T2778: Migrate "system syslog" to get_config_dict() to support new features.
Aug 10 2020, 7:10 AM · VyOS 1.4 Sagitta
c-po created T2777: "monitor dhcp" does not output any DHCP related information.
Aug 10 2020, 6:52 AM · VyOS 1.3 Equuleus (1.3.0)
ajgnet created T2776: QAT acceleration not working for IPSec AES-128 (CBC) / SHA256 tunnel .
Aug 10 2020, 1:55 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Aug 9 2020

ajgnet created T2775: QAT acceleration for OpenVPN.
Aug 9 2020, 4:21 PM · VyOS Rolling
c-po claimed T2767: The interface cannot be disabled for network enabled configuration.
Aug 9 2020, 2:30 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T2769: Add VRF support for syslog.
Aug 9 2020, 2:29 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po claimed T2774: Bridge interface randomly disable itself.
Aug 9 2020, 2:29 PM · VyOS 1.3 Equuleus (1.3.0)
brussell added a comment to T2100: BGP route adverisement wih checks rib.

Sounds good thanks.

Aug 9 2020, 7:16 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po added a comment to T2774: Bridge interface randomly disable itself.

Your rolling release is from a time where the interface configuration changed heavily. An entire new concept was added, please retry with one of the latest rollings.

Aug 9 2020, 6:13 AM · VyOS 1.3 Equuleus (1.3.0)

Aug 8 2020

jestabro committed rVYOSONEX98e5105de439: http api: T1431: update args of call to install-image.
Aug 8 2020, 9:53 PM
jestabro added a comment to T2100: BGP route adverisement wih checks rib.

FRR 7.4 has been released, and the default behaviour has been changed, commit 62282e8379. @Viacheslav, when we update to this version, I can work with you to update the migration script.

Aug 8 2020, 5:11 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
jestabro changed the status of T2612: HTTPS API, changing API key fails but goes through from Confirmed to On hold.

As discussed in above comment, this is understandable behaviour, but will be re-investigated after the move to fastapi, re T2397.

Aug 8 2020, 3:57 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro closed T1949: Multihop IPv6 BFD is unconfigurable as Resolved.
Aug 8 2020, 3:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
jestabro changed the status of T1974: Allow route-map to set administrative distance from Unknown Status to Resolved.
Aug 8 2020, 3:46 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6), vyatta-cfg-quagga
jestabro closed T2501: Cannot recover from failed boot config load as Resolved.

Addressed in T2568.

Aug 8 2020, 3:40 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T2497: Cache config string during commit as Resolved.

This was an early experiment which contributed some ideas towards T2582; closed as superseded by that task.

Aug 8 2020, 3:37 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T2716: Shaper-HFSC shapes but does not control latency correctly as Resolved.

I am giving up with HFSC. I have been studying it for a long time, I have tested it in many different ways, without VyOS too. The only thing I have found is that this is is not a problem of VyOS.

Aug 8 2020, 3:12 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
kabaga created T2774: Bridge interface randomly disable itself.
Aug 8 2020, 12:05 AM · VyOS 1.3 Equuleus (1.3.0)

Aug 7 2020

Unknown Object (User) created T2773: EIGRP support for VRF.
Aug 7 2020, 8:03 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T2772: BGP Route Distinguisher & Route Target Extended Community.

Route Distinguisher & Route Targets are, in general, configured under VRF proccess. Below a sample of how this configurations would looks like:

Aug 7 2020, 7:57 PM · VyOS 1.3 Equuleus (1.3.5)
Unknown Object (User) updated subscribers of T2772: BGP Route Distinguisher & Route Target Extended Community.
Aug 7 2020, 7:55 PM · VyOS 1.3 Equuleus (1.3.5)
Unknown Object (User) created T2772: BGP Route Distinguisher & Route Target Extended Community.
Aug 7 2020, 7:53 PM · VyOS 1.3 Equuleus (1.3.5)
Unknown Object (User) added a comment to T2771: BGP VPNv4 & VPNv6 Address Family Support.

Bellow a sample of how BGP VPNv4 and VPNv6 AF configuration looks like:

Aug 7 2020, 7:46 PM · VyOS 1.3 Equuleus (1.3.5)
Unknown Object (User) created T2771: BGP VPNv4 & VPNv6 Address Family Support.
Aug 7 2020, 7:38 PM · VyOS 1.3 Equuleus (1.3.5)
ajgnet added a comment to T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic.

Sure thing. Note my configuration contains some table maps that I have set up to route VPN traffic, and certain source IPs through specific interfaces. But there is no effect on the load-balancer when these sections are removed. Thank you.

Aug 7 2020, 4:08 PM · VyOS 1.5 Circinus
Unknown Object (User) added a comment to T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic.

Could you please provide full configuration or at least protocol section configuration?

Aug 7 2020, 3:57 PM · VyOS 1.5 Circinus
jack9603301 added a comment to T2518: Add support for IPv6 NAT (NPTv6).

GNS3 virtualization network verification passed

Aug 7 2020, 3:24 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
thomas-mangin added a comment to T2623: Creating sit tunnel fails with “Can not set “local” for tunnel sit tun1 at tunnel creation”.

I will have a look as this was not supported by vyatta and therefore not added to the code when converted to python

Aug 7 2020, 1:01 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
zsdc reassigned T2623: Creating sit tunnel fails with “Can not set “local” for tunnel sit tun1 at tunnel creation” from SrividyaA to c-po.
Aug 7 2020, 12:59 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
zsdc created T2770: Allow any character to be used in the SNMP community field.
Aug 7 2020, 12:49 PM · VyOS Rolling
thomas-mangin added a comment to T2768: Define a high level HTTP API.

Coming with a syntax which is not ultimately going to be as complex as the cli may be an impossible challenge. Changing the API to include in the XML what is path vs payload may indeed lead to indeed a better API tho. The example given use the word create in the path when REST would use POST.

Aug 7 2020, 12:40 PM · VyOS Rolling
zsdc created T2769: Add VRF support for syslog.
Aug 7 2020, 12:07 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin created T2768: Define a high level HTTP API.
Aug 7 2020, 11:33 AM · VyOS Rolling
jack9603301 created T2767: The interface cannot be disabled for network enabled configuration.
Aug 7 2020, 8:34 AM · VyOS 1.3 Equuleus (1.3.0)

Aug 6 2020

SrividyaA added a comment to T2623: Creating sit tunnel fails with “Can not set “local” for tunnel sit tun1 at tunnel creation”.

The commit fails when the local-ip option is included only with the 6RD prefix options (without 6RD option, 6in4 tunnel is created). In the tunnel.py script, local value is not defined as result stack trace is received

Aug 6 2020, 10:03 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
runar added a comment to T2766: vyos-build: build-config: arm64 is not a valid architecture.

PR: https://github.com/vyos/vyos-build/pull/116

Aug 6 2020, 9:33 PM
runar created T2766: vyos-build: build-config: arm64 is not a valid architecture.
Aug 6 2020, 9:29 PM
runar closed T2765: vyatta-cfg-system: arm: vyatta-cfg-system is dependent on a amd64 only package as Resolved.

PR Merged

Aug 6 2020, 9:21 PM
runar added a comment to T2765: vyatta-cfg-system: arm: vyatta-cfg-system is dependent on a amd64 only package.

PR: https://github.com/vyos/vyatta-cfg-system/pull/127

Aug 6 2020, 9:12 PM
zsdc assigned T2760: In a load-balanced multi-wan configuration with DHCP assigned addresses, IPsec "dhcp-interface" does not work to SrividyaA.
Aug 6 2020, 9:00 PM · VyOS Rolling, Bugs
runar created T2765: vyatta-cfg-system: arm: vyatta-cfg-system is dependent on a amd64 only package.
Aug 6 2020, 8:44 PM
runar closed T2422: arm: docker: Unable to build docker container for ARM and ARM64 as Resolved.

Container fixed, closing this ticket

Aug 6 2020, 5:59 PM
runar closed T1927: Extend main docker container to support arm builds as Resolved.

The CI is now extended to build arm containers by default. they are also exported to dockerhub. closing this ticket

Aug 6 2020, 5:58 PM
jjakob changed the status of T2764: Increase maximum number of NAT rules from Open to In progress.
Aug 6 2020, 3:37 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
jestabro added a comment to T2688: add xml definition to router.

Discussion updated in PR 513.
https://github.com/vyos/vyos-1x/pull/513

Aug 6 2020, 3:25 PM
c-po added a comment to T2764: Increase maximum number of NAT rules.

This will be a oneliner in the new XML implementation. Just send PR

Aug 6 2020, 1:16 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
jjakob triaged T2764: Increase maximum number of NAT rules as Normal priority.
Aug 6 2020, 11:35 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
jack9603301 updated the task description for T2723: Support tcptraceroute.
Aug 6 2020, 9:31 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2677: Proposal for clearer DHCPv6-PD configuration options.

Reading the UBNT source code I see:

Aug 6 2020, 9:27 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2723: Support tcptraceroute.

https://github.com/vyos/vyos-1x/pull/522

Aug 6 2020, 9:11 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2763: New SNMP resource request - SNMP over TCP.

I find the above mentioned syntax to clumsy:

Aug 6 2020, 6:47 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T2763: New SNMP resource request - SNMP over TCP.

@srgabrieltelecon create please Pull Request.

Aug 6 2020, 6:30 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

Aug 5 2020

Unknown Object (User) added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

I´ve used the version of the software: VyOS 1.3-rolling-202007300117.
As I´ve used GRE tunnels it does not simulates the same scenario reported, which uses pure IPsec. I will configure IPsec tunnels over physical interfaces and log the results here again.

Aug 5 2020, 11:35 PM · VyOS 1.3 Equuleus (1.3.0)
srgabrieltelecon triaged T2763: New SNMP resource request - SNMP over TCP as Normal priority.
Aug 5 2020, 8:19 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
ajgnet added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

I suspect this could be related to displaying a peer with a hostname that contains a dash, such as, "abc-peer12.dyndns.org." Or, possibly a string matching error getting thrown off by "AES_GCM_16_128/MODP_2048"

Aug 5 2020, 5:38 PM · VyOS 1.3 Equuleus (1.3.0)
ajgnet added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

The IKE SA appears down in your second example?

Aug 5 2020, 5:02 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

vyos@HUB-2# sh vpn
ipsec {

esp-group MyESPGroup {
    proposal 1 {
        encryption aes256
        hash md5
    }
}
ike-group MyIKEGroup {
    proposal 1 {
        dh-group 2
        encryption aes256
        hash md5
    }
}
ipsec-interfaces {
    interface eth0.100
}
site-to-site {
    peer 169.254.100.1 {
        authentication {
            mode pre-shared-secret
            pre-shared-secret MYSECRETKEY
        }
        default-esp-group MyESPGroup
        ike-group MyIKEGroup
        local-address 169.254.100.6
        tunnel 20 {
            protocol gre
        }
    }
}

}
[edit]

Aug 5 2020, 4:59 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

I´ve configured a simple P-2P IPsec/GRE Tunnel and the command shows IKE and IPsec SAs UP:

Aug 5 2020, 4:58 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2723: Support tcptraceroute.

Dependency and VRF support for tcptraceroute6 will be submitted in the next few days

Aug 5 2020, 2:05 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 changed the status of T2723: Support tcptraceroute, a subtask of T2714: A collection of utilities supporting IPv6 or ipv4, from Needs testing to In progress.
Aug 5 2020, 2:03 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 changed the status of T2723: Support tcptraceroute from Needs testing to In progress.
Aug 5 2020, 2:03 PM · VyOS 1.3 Equuleus (1.3.0)
thomas-mangin added a comment to T2759: validate-value prints error messages from validators that fail even if overall validation succeeds.

I would have expected the output generated to be an OR of the validators or regexes and allow the output if any would have passed it

Aug 5 2020, 10:08 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po edited a custom field on T2762: VRF: when SSHd is VRF bound all commands are executed in VRF context.
Aug 5 2020, 9:15 AM · VyOS Rolling
c-po created T2762: VRF: when SSHd is VRF bound all commands are executed in VRF context.
Aug 5 2020, 9:15 AM · VyOS Rolling
c-po created T2761: Extend "show vrrp" op-mode command with router priority.
Aug 5 2020, 8:14 AM · VyOS 1.3 Equuleus (1.3.0)

Aug 4 2020

c-po committed rVYOSONEX846e306700af: ssh: T2651: add cli options for source address.
Aug 4 2020, 8:35 PM
c-po renamed T2651: Generate CLI abstraction for options passed to CURL and SSH client from Generate CLI abstraction for options passed to CURL to Generate CLI abstraction for options passed to CURL and SSH client.
Aug 4 2020, 8:33 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2759: validate-value prints error messages from validators that fail even if overall validation succeeds.

Before adding "<defaultValue>" it was working but not now.

Aug 4 2020, 5:52 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav closed T2637: Vlan is not removed from the system, a subtask of T2353: Interface [conf_mode] errors parent task, as Resolved.
Aug 4 2020, 4:26 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T2637: Vlan is not removed from the system as Resolved.

Fixed, VyOS 1.3-rolling-202008040823

Aug 4 2020, 4:26 PM · VyOS 1.3 Equuleus (1.3.0)
jjakob added a comment to T2750: Use m4 as a template processor.

I wasn't trying to solve any specific issue. I was working on some other project, trying to use GCC as a preprocessor, the same way as it's used here, and ran into those obstacles I listed in the original description, which are present here too. I was made aware m4 is much more suitable to template processing than GCC as it was actually designed and made for it.
As for using any self-made code to do this, I have no problem with that as long as it's well known this is what is now used, is documented, and then an effort made to port all preprocessing to it. I see no sense using two or three different preprocessors.

Aug 4 2020, 2:31 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 added a comment to T2724: Support for IPv6 Toolset.

Update document

Aug 4 2020, 2:14 PM · VyOS 1.3 Equuleus (1.3.0)
thomas-mangin added a comment to T2518: Add support for IPv6 NAT (NPTv6).

Thank you for writing some testing code using the smoketest repository. It may take a few working days for anyone to come back to you.

Aug 4 2020, 1:50 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po added a comment to T2651: Generate CLI abstraction for options passed to CURL and SSH client.

SSH only supports "source-address" via its BindAddress option

Aug 4 2020, 12:54 PM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T2651: Generate CLI abstraction for options passed to CURL and SSH client.
Aug 4 2020, 12:54 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T2651: Generate CLI abstraction for options passed to CURL and SSH client.
Aug 4 2020, 12:53 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2518: Add support for IPv6 NAT (NPTv6).

smoketest for nptv6

Aug 4 2020, 11:03 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
ajgnet created T2760: In a load-balanced multi-wan configuration with DHCP assigned addresses, IPsec "dhcp-interface" does not work.
Aug 4 2020, 10:14 AM · VyOS Rolling, Bugs
c-po created T2759: validate-value prints error messages from validators that fail even if overall validation succeeds.
Aug 4 2020, 8:22 AM · VyOS 1.3 Equuleus (1.3.0-epa1)