Page MenuHomeVyOS Platform
Feed All Stories

Oct 17 2020

superq added a comment to T973: Create Prometheus Exporter for VyOS .

We should avoid having a constellation of exporters, but favour having a single one. I feel like starting and stopping those would be pretty icky.

Oct 17 2020, 1:22 PM · VyOS Rolling, VyOS 1.5 Circinus
UnicronNL claimed T2834: Config rollback function is broken due lack access to the config.boot.
Oct 17 2020, 12:57 PM · Restricted Project
Viacheslav added a comment to T752: Add an option to disable IPv4 forwarding on specific interface only.

PR https://github.com/vyos/vyos-1x/pull/576

Oct 17 2020, 12:54 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
jack9603301 added a comment to T2986: Unable to build qemu image due to misconfigured Packer.

Must this command be executed from docker now?

Oct 17 2020, 11:55 AM · VyOS 1.3 Equuleus (1.3.0)
c-po edited projects for T2792: Failed to run `sudo make qemu` with vyos-build container due to the change of packer, added: VyOS 1.3 Equuleus; removed vyos-build.
Oct 17 2020, 11:45 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2792: Failed to run `sudo make qemu` with vyos-build container due to the change of packer as Resolved.
Oct 17 2020, 11:44 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2986: Unable to build qemu image due to misconfigured Packer as Invalid.
Oct 17 2020, 11:37 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2986: Unable to build qemu image due to misconfigured Packer.

This will break builds in out Docker environment where we ship a packer version. See T2792 and https://github.com/vyos/vyos-build/commit/e2dd9db8a2539b6d13c98d89e18872336cf8f974

Oct 17 2020, 11:37 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 updated the task description for T2986: Unable to build qemu image due to misconfigured Packer.
Oct 17 2020, 10:52 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 created T2986: Unable to build qemu image due to misconfigured Packer.
Oct 17 2020, 10:51 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed Version from - to 1.3-rolling-202010081758 on T2985: Add glue code to create bridge interface on demand.
Oct 17 2020, 10:01 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2985: Add glue code to create bridge interface on demand from Open to In progress.
Oct 17 2020, 10:00 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2985: Add glue code to create bridge interface on demand, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, from Open to In progress.
Oct 17 2020, 10:00 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2985: Add glue code to create bridge interface on demand.
Oct 17 2020, 9:59 AM · VyOS 1.3 Equuleus (1.3.0)
jmcg added a comment to T1229: Add support for unencrypted L2TPv2 client connections.

Also very interested in this. Ready and willing to test.

Oct 17 2020, 9:39 AM · VyOS Rolling
GitHub <noreply@github.com> committed rVYOSONEXfcf90cd860ba: Merge pull request #573 from sever-sever/T2938 (authored by c-po).
Oct 17 2020, 9:20 AM
Viacheslav closed T2981: MPLS LDP neighbor session clear capability as Resolved.

@Cheeze_It thanks, works fine.

Oct 17 2020, 8:32 AM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEXaa8445674565: Merge pull request #575 from DmitriyEshenko/ipoe-fix-issue01 (authored by c-po).
Oct 17 2020, 7:49 AM
Unknown Object (User) changed the status of T2984: (igb, ixgbe) HW queues applied only for the first 2 interfaces from In progress to Needs testing.

PR https://github.com/vyos/vyos-build/pull/128

Oct 17 2020, 7:16 AM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) changed the status of T2984: (igb, ixgbe) HW queues applied only for the first 2 interfaces from Open to In progress.
Oct 17 2020, 7:09 AM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) created T2984: (igb, ixgbe) HW queues applied only for the first 2 interfaces .
Oct 17 2020, 7:09 AM · VyOS 1.2 Crux (VyOS 1.2.7)

Oct 16 2020

Unknown Object (User) changed the status of T2978: IPoE service does not work on shared mode from Confirmed to Needs testing.

PR https://github.com/vyos/vyos-1x/pull/575

Oct 16 2020, 11:29 PM · VyOS 1.3 Equuleus (1.3.0)
Cheeze_It changed the status of T2981: MPLS LDP neighbor session clear capability from Open to Needs testing.
Oct 16 2020, 11:24 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX397d6618d000: Merge pull request #574 from Cheeze-It/current (authored by c-po).
Oct 16 2020, 8:46 PM
c-po added a comment to T752: Add an option to disable IPv4 forwarding on specific interface only.

That would be a workaround only - see IPv6 syntax above. Using the refactored interface handling (T2653) makes this a low-hanging fruit.

Oct 16 2020, 8:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Cheeze_It added a comment to T915: MPLS Support.

I'll be giving those a test once T2981 is done. I'll report back here with results :)

Oct 16 2020, 8:26 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Cheeze_It added a comment to T2981: MPLS LDP neighbor session clear capability.

PR is added here...

Oct 16 2020, 7:07 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) created T2983: Add support to DHCP server include an extended config.
Oct 16 2020, 6:47 PM · VyOS 1.3 Equuleus (1.3.4)
jack9603301 added a comment to T973: Create Prometheus Exporter for VyOS .

Quite interesting, support, in fact some information can not be captured from SNMP very well

Oct 16 2020, 6:36 PM · VyOS Rolling, VyOS 1.5 Circinus
syncer reassigned T973: Create Prometheus Exporter for VyOS from kroy to superq.
Oct 16 2020, 6:27 PM · VyOS Rolling, VyOS 1.5 Circinus
owensresearch awarded T2257: BGP does not work with VRF a Heartbreak token.
Oct 16 2020, 6:22 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T752: Add an option to disable IPv4 forwarding on specific interface only.

How about this?

Oct 16 2020, 5:28 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T2938: Adding remote Syslog RFC5424 compatibility.

@D0peX That's correct? I updated pr

Oct 16 2020, 2:29 PM · VyOS 1.3 Equuleus (1.3.0)
D0peX added a comment to T2938: Adding remote Syslog RFC5424 compatibility.

Thank you Viacheslav

Oct 16 2020, 2:06 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav changed the status of T2907: OpenVPN: Option to disable encryption from Open to Needs testing.
Oct 16 2020, 1:46 PM · VyOS 1.3 Equuleus (1.3.0), openvpn
Viacheslav claimed T2938: Adding remote Syslog RFC5424 compatibility.
Oct 16 2020, 1:14 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav updated subscribers of T2982: show protocols bfd command parse failure.

@c-po @dmbaturin It can be safely cherry-picked to the "crux".
I tested this on 1.2.6-s1, it works.

Oct 16 2020, 1:11 PM · Ready for Crux (1.2.x), VyOS 1.2 Crux
Viacheslav added a comment to T2938: Adding remote Syslog RFC5424 compatibility.

PR https://github.com/vyos/vyos-1x/pull/573

Oct 16 2020, 12:56 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2965: Brief BFD Peer Info.

@trae32566 Will be added in the next rolling release.
Check, please.

Oct 16 2020, 12:09 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX2b60994ce283: Merge pull request #572 from sever-sever/T2965 (authored by c-po).
Oct 16 2020, 9:34 AM
Viacheslav added a comment to T2958: DHCP server doesn't work from a live CD.

The possible reason, that it can't get the lease file, because that directory not present in the LiveCD

lease_file = "/config/dhcpd.leases"
Oct 16 2020, 8:19 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav claimed T2965: Brief BFD Peer Info.
Oct 16 2020, 7:46 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2965: Brief BFD Peer Info.

PR https://github.com/vyos/vyos-1x/pull/572

Oct 16 2020, 7:46 AM · VyOS 1.3 Equuleus (1.3.0)
trae32566 added a comment to T2965: Brief BFD Peer Info.

That sounds great to me! I actually like that more.

Oct 16 2020, 7:23 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2965: Brief BFD Peer Info.

Proposed cli
One of them

Oct 16 2020, 7:22 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav assigned T2981: MPLS LDP neighbor session clear capability to Cheeze_It.
Oct 16 2020, 7:11 AM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEXa5a77c47168b: Merge pull request #571 from sever-sever/T915_holdtime_explicit (authored by c-po).
Oct 16 2020, 6:43 AM
Viacheslav added a comment to T2982: show protocols bfd command parse failure.

It was fixed in the rolling T2573
https://phabricator.vyos.net/rVYOSONEXf812c5d1ce01efa8323bfb797c57f68f474665bb

Oct 16 2020, 6:16 AM · Ready for Crux (1.2.x), VyOS 1.2 Crux
qxmips published a new version of 1.2.6.
Oct 16 2020, 3:12 AM
qxmips edited the content of 1.2.6.
Oct 16 2020, 3:09 AM

Oct 15 2020

c-po renamed T2980: FRR bfdd crash due to invalid length from FRR bfdd crash due to invlid length to FRR bfdd crash due to invalid length.
Oct 15 2020, 8:16 PM · VyOS 1.3 Equuleus (1.3.0)
dirtycache created T2982: show protocols bfd command parse failure.
Oct 15 2020, 8:00 PM · Ready for Crux (1.2.x), VyOS 1.2 Crux
Viacheslav added a comment to T2979: BGP route leak at system boot.

@Robot82
It will be by default in the new BGP implementation.
https://github.com/vyos/vyos-1x/blob/current/data/templates/frr/bgp.frr.tmpl#L5

Oct 15 2020, 6:47 PM · VyOS 1.2 Crux
Viacheslav added a comment to T2981: MPLS LDP neighbor session clear capability.

Proposed CLI

reset mpls ldp neighbor x.x.x.x
Oct 15 2020, 6:44 PM · VyOS 1.3 Equuleus (1.3.0)
Cheeze_It changed Is it a breaking change? from none to compatible on T2981: MPLS LDP neighbor session clear capability.
Oct 15 2020, 6:21 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T915: MPLS Support.

PR https://github.com/vyos/vyos-1x/pull/571

Oct 15 2020, 6:06 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Cheeze_It created T2981: MPLS LDP neighbor session clear capability.
Oct 15 2020, 6:05 PM · VyOS 1.3 Equuleus (1.3.0)
trae32566 added a comment to T2980: FRR bfdd crash due to invalid length.

awesome, thanks!

Oct 15 2020, 4:52 PM · VyOS 1.3 Equuleus (1.3.0)
trae32566 awarded T2980: FRR bfdd crash due to invalid length a Like token.
Oct 15 2020, 4:51 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.

https://forum.vyos.io/t/limit-bandwith-for-indivindual-ips-on-1-2-5/5947/30?u=s.lorente

Oct 15 2020, 4:19 PM
c-po added a comment to T2980: FRR bfdd crash due to invalid length.

Also submitted PR for FRR 7.3 series https://github.com/FRRouting/frr/pull/7318

Oct 15 2020, 3:23 PM · VyOS 1.3 Equuleus (1.3.0)
Robot82 added a comment to T2979: BGP route leak at system boot.

OK, thank you. I will test this. This should probably be made as default.

Oct 15 2020, 3:09 PM · VyOS 1.2 Crux
jack9603301 added a comment to T766: Implement support for the Tinc VPN daemon.

@runar The preliminary integration of tinc is basically completed, please see

Oct 15 2020, 12:52 PM
Unknown Object (User) added a comment to T2978: IPoE service does not work on shared mode.

Yes, both clients configured as DHCP clients.
Client 1 - eth0 - 50:00:00:06:00:00
Client 2 - eth0 - 50:00:00:07:00:00

Oct 15 2020, 12:18 PM · VyOS 1.3 Equuleus (1.3.0)
danhusan added a comment to T2979: BGP route leak at system boot.

This has come up multiple times before, see https://phabricator.vyos.net/T1698 for the solution.

Oct 15 2020, 12:14 PM · VyOS 1.2 Crux
Viacheslav added a comment to T2713: VyOS must not change permissions on files in /config/auth.

I can confirm.
It happens after update procedure.

Oct 15 2020, 12:03 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2834: Config rollback function is broken due lack access to the config.boot.

If I do a clean install of 1.2.6-s1 from iso, the rollback works fine.
If deploy from a qcow2 image, I see a similar error.

Oct 15 2020, 6:15 AM · Restricted Project

Oct 14 2020

soxrok2212 added a comment to T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing.

I should add that building the package on arm64 hardware (pi3/4) works fine. Building in the docker container fails.

Oct 14 2020, 11:41 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po changed the status of T2980: FRR bfdd crash due to invalid length from Open to Needs testing.
Oct 14 2020, 7:41 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2980: FRR bfdd crash due to invalid length.
Oct 14 2020, 7:40 PM · VyOS 1.3 Equuleus (1.3.0)
marekm added a comment to T2060: source-validation will be configured at different locations and could lead to massive confusion.

Just my thoughts - there are situations where rp_filter is not sufficient, and it was not clear to me how to do this cleanly with the zone firewall, so I ended up hacking a few iptables commands in rc.local instead.

Oct 14 2020, 6:59 PM · VyOS 1.3 Equuleus (1.3.6), VyOS-1.2.0-GA
Robot82 created T2979: BGP route leak at system boot.
Oct 14 2020, 6:30 PM · VyOS 1.2 Crux
runar added a comment to T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing.

the issue is verified by soxrok2122 by using a stock ubuntu 20 host with the stock vyos/vyos-build:current-arm64 docker image

Oct 14 2020, 5:39 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
runar reopened T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing, a subtask of T476: Update the base system to Debian 10 (Buster), as Open.
Oct 14 2020, 5:36 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
runar reopened T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing as "Open".

I'm reopening this issue as this seams to still be an issue. reported by user soxrok2212 on slack (#vyos-on-arm64)

Oct 14 2020, 5:36 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T2978: IPoE service does not work on shared mode.

It seems Client1 and Client2 only DHCP-clients.

Oct 14 2020, 3:10 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2978: IPoE service does not work on shared mode.

Could you share also Client1 and Client2 configuration? Would be nice adding this lab setup to the docs

Oct 14 2020, 2:31 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) changed the status of T2978: IPoE service does not work on shared mode from Open to Confirmed.
Oct 14 2020, 8:14 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) created T2978: IPoE service does not work on shared mode.
Oct 14 2020, 8:14 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T2972: PPPoE server rate limiter allows max 65535 kbps to be set as Resolved.
Oct 14 2020, 7:59 AM · VyOS 1.2 Crux (VyOS 1.2.7)
Magnum added a comment to T2969: OpenVPN: command_set on interface is not applied, if interface doesn't come up in commit.
interfaces {
    ethernet eth2 {
        address 10.201.1.2/30
        description WAN
        hw-id 0c:6b:af:b0:4f:02
    }
    openvpn vtun11 {
        description "CPE MGMT"
        device-type tun
        encryption {
            cipher aes256
        }
        hash sha1
        mode client
        persistent-tunnel
        protocol udp
        remote-host 10.200.200.11
        remote-port 1194
        tls {
            auth-file /config/auth/shared.key
            ca-cert-file /config/auth/ca.crt
            cert-file /config/auth/cpe1-1.crt
            key-file /config/auth/cpe1-1.key
        }
        vrf CPE-MGMT
    }
}
protocols {
    static {
        route 0.0.0.0/0 {
            next-hop 10.201.1.1 {
            }
        }
    }
}
vrf {
    name CPE-MGMT {
        description "CPE MGMT"
        table 112
    }
}
Oct 14 2020, 7:01 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2969: OpenVPN: command_set on interface is not applied, if interface doesn't come up in commit.

Please share your OpenVPN config

Oct 14 2020, 4:58 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2972: PPPoE server rate limiter allows max 65535 kbps to be set from In progress to Needs testing.
Oct 14 2020, 4:56 AM · VyOS 1.2 Crux (VyOS 1.2.7)
tjh created T2977: Permissions Denied doing "show conntrack-sync status" on backup router.
Oct 14 2020, 12:41 AM

Oct 13 2020

GitHub <noreply@github.com> committed rVYOSONEX9c83149664e5: Merge pull request #568 from DmitriyEshenko/crux-pppoe-shaper-incr (authored by c-po).
Oct 13 2020, 6:01 PM
GitHub <noreply@github.com> committed rVYOSONEX741cd00fb687: Merge pull request #566 from DmitriyEshenko/incr-pppoe-shaper (authored by c-po).
Oct 13 2020, 5:57 PM
c-po committed rVYOSONEX6c2a2cb8ce98: pppoe-server: T2976: fix local-users default value retrieval from XML.
Oct 13 2020, 4:56 PM
c-po edited a custom field on T2976: Client IP pool does not work for PPPoE local users.
Oct 13 2020, 4:49 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2976: Client IP pool does not work for PPPoE local users as Resolved.
Oct 13 2020, 4:49 PM · VyOS 1.3 Equuleus (1.3.0)
runar added a comment to T766: Implement support for the Tinc VPN daemon.

I think we could generate private/public keys using openssl instead of using the tinc utility to generate it... But i have not tested it

Oct 13 2020, 4:10 PM
jack9603301 added a comment to T766: Implement support for the Tinc VPN daemon.

I am implementing tinc, but there is a problem I haven't figured out. Normally, in order for tinc to run, it must have a public key and a private key, and it happens that there will be a prompt for this generation command (ask where to save, etc), and it happens that the public key of the local node in the hosts directory is usually used together with some host configuration options. Is there a better way to implement it?

Oct 13 2020, 4:07 PM
SrividyaA added a comment to T2924: Using 'set src' in a route-map invalidates it as part of a subsequent boot-up.

PR: https://github.com/vyos/vyos-1x/pull/569

Oct 13 2020, 1:06 PM · VyOS 1.3 Equuleus (1.3.0)
Magnum added a comment to T2969: OpenVPN: command_set on interface is not applied, if interface doesn't come up in commit.

This bug seems to be worse than I thought.
Here's an example:
On reboot an openvpn client inteface will come up outside the vrf. Any routes that get pushed by the server will not get added to the client because it's wants to add the routes inside the vrf of the vtun interface - but the vtun isn't a member.
Heres a log snippet:

Oct 13 2020, 11:35 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2972: PPPoE server rate limiter allows max 65535 kbps to be set.

PR for CRUX https://github.com/vyos/vyos-1x/pull/568

Oct 13 2020, 11:20 AM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) changed the status of T2972: PPPoE server rate limiter allows max 65535 kbps to be set from Open to In progress.
Oct 13 2020, 10:54 AM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) updated the task description for T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.
Oct 13 2020, 10:51 AM
Unknown Object (User) updated the task description for T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.
Oct 13 2020, 10:48 AM
Unknown Object (User) updated the task description for T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.
Oct 13 2020, 10:45 AM
Magnum added a comment to T2969: OpenVPN: command_set on interface is not applied, if interface doesn't come up in commit.

You're right, if-up.d scripts only get run for the interfaces defined in /etc/network/interfaces.

Oct 13 2020, 10:29 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) changed the status of T2976: Client IP pool does not work for PPPoE local users from Open to In progress.
Oct 13 2020, 9:53 AM · VyOS 1.3 Equuleus (1.3.0)