Page MenuHomeVyOS Platform
Feed All Stories

Sep 25 2020

c-po added a parent task for T2912: When setting MTU check for hardware maximum supported MTU size: T2653: "set interfaces" Python handler code improvements - next iteration.
Sep 25 2020, 6:47 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX49a79954373e: ifconfig: T2912: add helper to retrieve interface min/max supported MTU.
Sep 25 2020, 6:35 PM
c-po updated the task description for T2912: When setting MTU check for hardware maximum supported MTU size.
Sep 25 2020, 6:34 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro committed rVYOSONEXe5ec38fb06f4: syslog: T2899: add migration script for change in port syntax.
Sep 25 2020, 5:53 PM
jestabro committed rVYOSONEXe76d9a009632: syslog: T2899: shift system migration files +1 to allow for crux.
Sep 25 2020, 5:49 PM
jestabro committed rVYOSONEX4c818baa5904: syslog: T1845: fix indentation level.
Sep 25 2020, 5:49 PM
c-po closed T2915: Lost "proxy-arp-pvlan" option for vlan as Resolved.
Sep 25 2020, 5:49 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2921: Migrate "service dns forwarding" to get_config_dict() for ease of source maintenance as Resolved.
Sep 25 2020, 5:22 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXf39f5dde342a: dns: forwarding: T2921: migrate to get_config_dict().
Sep 25 2020, 5:22 PM
mpueschel added a comment to T2700: Redirecting traffic from PPPoE interface to IFB fails.

Yes that's correct. And there is already some sort of check implemented for the node traffic-policy, so it does not fail when the pppoe interface does not exist yet. It just shows a warning: https://github.com/vyos/vyatta-cfg-qos/blob/bbf2b2f06b7a0f883f7134df5e2b3e089015738e/scripts/vyatta-qos.pl#L198

Sep 25 2020, 3:17 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
kroy added a comment to T2700: Redirecting traffic from PPPoE interface to IFB fails.

I think I know what's happening here.

Sep 25 2020, 2:58 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
olofl added a comment to T2899: remote syslog server migration error on update.

I would also like to add that wouldn't it make more sense to set the protocol mode under host aswell rather behind "facility".

Sep 25 2020, 1:56 PM · Restricted Project
jestabro claimed T2899: remote syslog server migration error on update.
Sep 25 2020, 12:54 PM · Restricted Project
c-po closed T2925: Update Linux Kernel to v4.19.147 as Resolved.
Sep 25 2020, 12:26 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2925: Update Linux Kernel to v4.19.147.
Sep 25 2020, 12:25 PM · VyOS 1.3 Equuleus (1.3.0)
bbs2web created T2924: Using 'set src' in a route-map invalidates it as part of a subsequent boot-up.
Sep 25 2020, 9:30 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 25 2020, 9:12 AM · VyOS 1.4 Sagitta

Sep 24 2020

diekos closed T2896: set ip route 0.0.0.0/0 dhcp-interface eth0 as Resolved.

I saw that the new build was online, so I added the image, rebooted and tried to issue the command again.
Everything seems to work, no error when committing and the route is added.

Sep 24 2020, 9:06 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2923: Configuring DHCPv6-PD without a interface to delegate to raises TypeError as Resolved.
Sep 24 2020, 7:34 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX7f09beeac924: dhcpv6-pd: verify: T2923: interface is required where the prefix is assigned.
Sep 24 2020, 7:33 PM
c-po added a comment to T2923: Configuring DHCPv6-PD without a interface to delegate to raises TypeError.

After the fix an error is reported on the CLI:

Sep 24 2020, 7:31 PM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T2923: Configuring DHCPv6-PD without a interface to delegate to raises TypeError.
Sep 24 2020, 7:30 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T2923: Configuring DHCPv6-PD without a interface to delegate to raises TypeError.
Sep 24 2020, 7:26 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2923: Configuring DHCPv6-PD without a interface to delegate to raises TypeError.
Sep 24 2020, 7:25 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX44698fb03cf2: smoketest: dns: dynamic: add missing import statement.
Sep 24 2020, 6:36 PM
jack9603301 updated the task description for T2518: Add support for IPv6 NAT (NPTv6).
Sep 24 2020, 6:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po committed rVYOSONEX806f35b5856c: wireless: T2241: add "wds" CLI option.
Sep 24 2020, 5:56 PM
c-po committed rVYOSONEX58ead7415a3f: smoketest: (re-)use process_named_running() from vyos.util.
Sep 24 2020, 5:55 PM
zsdc created T2922: The `vpn ipsec logging log-modes` miss the IPSec daemons state check.
Sep 24 2020, 4:28 PM · VyOS 1.3 Equuleus ( 1.3.1)
c-po committed rVYOSONEX4db00f1cd820: smoketest: dns: forwarding: T2921: add initial testcases.
Sep 24 2020, 4:24 PM
c-po committed rVYOSONEX2b06653a824f: dns: forwarding: T2921: template cleanup.
Sep 24 2020, 4:24 PM
c-po changed the status of T2921: Migrate "service dns forwarding" to get_config_dict() for ease of source maintenance from Open to In progress.
Sep 24 2020, 4:20 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2921: Migrate "service dns forwarding" to get_config_dict() for ease of source maintenance.
Sep 24 2020, 4:20 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) updated the task description for T2920: Commit crash when adding the second mGRE tunnel with the same key.
Sep 24 2020, 2:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jack9603301 added a comment to T2518: Add support for IPv6 NAT (NPTv6).

Also come back to this question?

Sep 24 2020, 2:15 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Unknown Object (User) created T2920: Commit crash when adding the second mGRE tunnel with the same key.
Sep 24 2020, 12:47 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX19361aad111e: T2482: require pdns >= 4.3.4.
Sep 24 2020, 11:37 AM
jack9603301 added a comment to T2518: Add support for IPv6 NAT (NPTv6).

In linux kernel version 5.8 and above, you can start symmetric translation of ipv6 address prefix by changing snat to to snat prefix to in the policy (without changing the interface identifier), but this function cannot be used before vyos upgrade 5.9 , This patch is not a back-portable patch, so this feature cannot be used in 4.19. There are now 3 solutions:

Sep 24 2020, 11:36 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Sep 23 2020

syncer moved T2482: Update PowerDNS recursor to 4.3.1 for CVE-2020-10995 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Sep 23 2020, 10:44 PM · Restricted Project
syncer added a project to T2482: Update PowerDNS recursor to 4.3.1 for CVE-2020-10995: VyOS 1.3 Equuleus.
Sep 23 2020, 10:44 PM · Restricted Project
syncer reopened T2482: Update PowerDNS recursor to 4.3.1 for CVE-2020-10995 as "Open".
Sep 23 2020, 10:43 PM · Restricted Project
c-po added a comment to T2902: "add system image" fails when appending XX to image name.

So I was super lucky to pick the wrong characters!

Sep 23 2020, 7:09 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Viacheslav added a comment to T2902: "add system image" fails when appending XX to image name.

The problem with that expression
https://github.com/vyos/vyatta-cfg-system/blob/current/scripts/install/install-image-existing#L271

Sep 23 2020, 6:23 PM · VyOS 1.2 Crux (VyOS 1.2.7)
tjh added a comment to T2801: conntrack-tools flooding logs.

Additionally, it only happens after a system image upgrade - it doesn't seem to happen if you reboot again after that.

Sep 23 2020, 5:19 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
Viacheslav added a comment to T2840: "startup-beep" beeps too early.

For testing

Sep 23 2020, 2:55 PM · VyOS Rolling
Viacheslav placed T2868: Tcp-mss option in policy calls kernel-panic up for grabs.
Sep 23 2020, 2:36 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav reopened T2868: Tcp-mss option in policy calls kernel-panic as "Open".
Sep 23 2020, 2:36 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEXca3e8dd78a6f: Merge pull request #550 from sever-sever/T2856_crux (authored by dmbaturin).
Sep 23 2020, 1:50 PM
jack9603301 added a comment to T2518: Add support for IPv6 NAT (NPTv6).

Hi, everyone, I have been looking for a way to handle the 1-to-1 address prefix symmetry mapping. I contacted the IRC channel of the official community. According to the official information, it seems to be resolved in the 5.8 kernel version, otherwise the patch needs to be backported To 4.19.

Sep 23 2020, 1:49 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T2846: ip route doesn't show longer-prefixes as Resolved.
Sep 23 2020, 1:47 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a project to T2856: equuleus: `show version all` throws broken pipe exception on abort: VyOS 1.2 Crux.
Sep 23 2020, 1:41 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
Viacheslav added a comment to T2856: equuleus: `show version all` throws broken pipe exception on abort.

PR for crux https://github.com/vyos/vyos-1x/pull/550

Sep 23 2020, 1:39 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
Unknown Object (User) edited the content of Configuration Mode Templates.
Sep 23 2020, 1:01 PM
Unknown Object (User) edited the content of Configuration Mode Templates.
Sep 23 2020, 12:58 PM
Viacheslav added a comment to T2856: equuleus: `show version all` throws broken pipe exception on abort.

The same bug with crux

Sep 23 2020, 12:35 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
Viacheslav closed T2856: equuleus: `show version all` throws broken pipe exception on abort as Unknown Status.
Sep 23 2020, 12:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
Viacheslav changed the status of T2906: OpenVPN: tls-auth missing key direction from Open to Needs testing.
Sep 23 2020, 12:28 PM · VyOS 1.3 Equuleus (1.3.0), openvpn
diekos added a comment to T2896: set ip route 0.0.0.0/0 dhcp-interface eth0.

I will test with the new release and report my results.
Thank you very much!

Sep 23 2020, 12:24 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav changed the status of T2916: A state of VTI interface in a configuration does not being processing properly from Confirmed to Needs testing.
Sep 23 2020, 12:22 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T2868: Tcp-mss option in policy calls kernel-panic as Resolved.
Sep 23 2020, 12:19 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2868: Tcp-mss option in policy calls kernel-panic.
Sep 23 2020, 12:18 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2896: set ip route 0.0.0.0/0 dhcp-interface eth0.

@diekos Will be fixed in the next rolling release, build after 23 Sep. Check, please.

Sep 23 2020, 12:07 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav claimed T2896: set ip route 0.0.0.0/0 dhcp-interface eth0.
Sep 23 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2896: set ip route 0.0.0.0/0 dhcp-interface eth0.

PR https://github.com/vyos/vyatta-cfg-system/pull/128

Sep 23 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) created T2919: PPPoE server: Called-Station-Id attribute.
Sep 23 2020, 11:48 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
Unknown Object (User) created T2918: Accounting interim jitter for pppoe, l2tp, pptp, ipoe.
Sep 23 2020, 11:41 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
Viacheslav added a comment to T2916: A state of VTI interface in a configuration does not being processing properly.

PR for rolling https://github.com/vyos/vyatta-cfg-vpn/pull/39

Sep 23 2020, 10:54 AM · VyOS 1.3 Equuleus (1.3.0)
tjh added a comment to T2801: conntrack-tools flooding logs.

So I just hit this bug again upgrading from 1.2.6-epa1 to 1.2.6.

Sep 23 2020, 10:00 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
Unknown Object (User) created T2917: PPPoE server: Preallocate NAS-Port-Id.
Sep 23 2020, 9:57 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
jack9603301 added a comment to T2518: Add support for IPv6 NAT (NPTv6).

@c-po The map66 solution last released on July 25th, 2015 does not seem to have been explored. It can work with iptables. I am not sure if it has stopped maintenance. I am considering whether to consider it, but it means that it needs to be compiled, installed and generated deb package , Otherwise vyos cannot install it

Sep 23 2020, 9:11 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
jack9603301 added a comment to T2518: Add support for IPv6 NAT (NPTv6).

Thank you for your suggestion. I am considering how to implement peer-to-peer translation without modifying the interface identifier. According to some information on the Internet, the support of ipv6 nat is divided into peer address and non-equivalent address. The standard https://tools.ietf.org/html/rfc6296 display does not indicate the interface identifier. The symbol cannot be modified, but only stipulates that the address mapping conforms to the one-dimensional linear equation relationship (that is, an address mapping is unique.

Sep 23 2020, 9:03 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po added a comment to T2518: Add support for IPv6 NAT (NPTv6).

We are not forced to nftables and still use iptables6 if its not supported properly.

Sep 23 2020, 6:14 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
jack9603301 added a comment to T2518: Add support for IPv6 NAT (NPTv6).

nftables nat66 seems to be the best solution that can be done now, I am still exploring a better implementation, do you have any suggestions?

Sep 23 2020, 3:57 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Sep 22 2020

c-po added a comment to T2518: Add support for IPv6 NAT (NPTv6).

prefix translation should only be done on equal sized prefixes. This can be easily checked in verify() stage.

Sep 22 2020, 8:18 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jack9603301 added a comment to T2518: Add support for IPv6 NAT (NPTv6).

Well, at present, the nat66 prefix conversion of nftables has not found a way to not change the interface identifier. Maybe other people in the community can provide some suggestions?

Sep 22 2020, 6:50 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po added a comment to T2518: Add support for IPv6 NAT (NPTv6).

I must disagree, prefix translation means only the prefix is translated and the interface identifier keeps the same. Meaning fc00::1111:2222:3333:4444/64 should be translated to 2001:db8::1111:2222:3333:4444/64.

Sep 22 2020, 6:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jack9603301 added a comment to T2518: Add support for IPv6 NAT (NPTv6).

With NFT SNAT prefix translation, the address is not a 1:1 mapping. For example, if we have source prefix 2001:db8:1::/64 and translation prefix of 2001:db8:2::/64, the source address 2001:db8:1::1 will not translate to 2001:db8::2::1. The nftables translation calculates a new address which prevents the 1:1 host address mapping.

Sep 22 2020, 6:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
diekos added a comment to T2896: set ip route 0.0.0.0/0 dhcp-interface eth0.

I only know some python but that looks like the part that gets the gateway from the lease file.
My simple mind would say that the underscore needs to be replaced with a dot, but I have no idea if it really is that simple.

Sep 22 2020, 6:41 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2896: set ip route 0.0.0.0/0 dhcp-interface eth0.

It looks like this code is to blame.
https://github.com/vyos/vyatta-cfg-system/blob/current/scripts/vyatta-dhcp-helper.pl#L21

Sep 22 2020, 6:24 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX92edd930c49b: openvpn: T2906: tls-auth missing key direction (authored by Magnum).
Sep 22 2020, 5:45 PM
GitHub <noreply@github.com> committed rVYOSONEXb2c61e2127d8: openvpn: T2907: add 'none' encryption option to not encrypt any data (authored by Magnum).
Sep 22 2020, 5:44 PM
GitHub <noreply@github.com> committed rVYOSONEXe7f8285d6708: Merge pull request #549 from sever-sever/T2915 (authored by c-po).
Sep 22 2020, 5:43 PM
JessterSB added a comment to T2518: Add support for IPv6 NAT (NPTv6).

Hey guys,

Sep 22 2020, 5:33 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T2915: Lost "proxy-arp-pvlan" option for vlan.

PR https://github.com/vyos/vyos-1x/pull/549

Sep 22 2020, 4:59 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2700: Redirecting traffic from PPPoE interface to IFB fails.

https://forum.vyos.io/t/limit-download-and-upload-on-wan-for-every-vlan/5608/51

Sep 22 2020, 4:58 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
zsdc changed the status of T2916: A state of VTI interface in a configuration does not being processing properly from Open to Confirmed.
Sep 22 2020, 4:55 PM · VyOS 1.3 Equuleus (1.3.0)
zsdc created T2916: A state of VTI interface in a configuration does not being processing properly.
Sep 22 2020, 4:55 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav claimed T2915: Lost "proxy-arp-pvlan" option for vlan.
Sep 22 2020, 4:53 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXfeb491584d84: smoketest: macsec: T2023: check that source-interface is not used by any other….
Sep 22 2020, 4:44 PM
c-po committed rVYOSONEX83a9ce799119: ifconfig: T2653: bond: bridge: ensure member interface is not a source-interface.
Sep 22 2020, 4:44 PM
c-po committed rVYOSONEXd28a6a516d44: ifconfig: T2653: move is_member() from vyos.vylidate to vyos.configdict.
Sep 22 2020, 4:44 PM
Viacheslav created T2915: Lost "proxy-arp-pvlan" option for vlan.
Sep 22 2020, 4:33 PM · VyOS 1.3 Equuleus (1.3.0)
SrividyaA renamed T2914: OpenVPN: Fix for IPv4 remote-host hostname in client mode: from OpenVPN: Fix for IPv4 remote-host addresses in client mode: to OpenVPN: Fix for IPv4 remote-host hostname in client mode:.
Sep 22 2020, 12:12 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
SrividyaA created T2914: OpenVPN: Fix for IPv4 remote-host hostname in client mode:.
Sep 22 2020, 12:11 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
Viacheslav added a comment to T2895: VPN IPsec "leftsubnet" declared 2 times.

PR for rolling https://github.com/vyos/vyatta-cfg-vpn/pull/38

Sep 22 2020, 11:48 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav claimed T2895: VPN IPsec "leftsubnet" declared 2 times.

It declared 2 times, because there is 2 checks

Sep 22 2020, 11:19 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T2883: op-mode reset vpn command shows wrong completion.

PR https://github.com/vyos/vyatta-ravpn/pull/16

Sep 22 2020, 10:39 AM · VyOS 1.2 Crux
Viacheslav added a comment to T2883: op-mode reset vpn command shows wrong completion.

This is the output of this line

Sep 22 2020, 7:45 AM · VyOS 1.2 Crux
azdle created T2913: Failure to install fpm while building builder docker image.
Sep 22 2020, 1:53 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)

Sep 21 2020

c-po claimed T2912: When setting MTU check for hardware maximum supported MTU size.
Sep 21 2020, 8:41 PM · VyOS 1.3 Equuleus (1.3.0)