Page MenuHomeVyOS Platform
Feed Search

Nov 1 2020

Viacheslav created T3037: Bgp afi ipv6-unicast capability dynamic bug.
Nov 1 2020, 3:15 PM · VyOS 1.2 Crux (VyOS 1.2.7)

Oct 27 2020

Viacheslav added a project to T2933: VRRP add option virtual_ipaddress_excluded: Restricted Project.
Oct 27 2020, 5:58 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project

Oct 26 2020

Viacheslav added a comment to T2982: show protocols bfd command parse failure.

PR for crux https://github.com/vyos/vyos-1x/pull/582

Oct 26 2020, 1:13 PM · Ready for Crux (1.2.x), VyOS 1.2 Crux
Unknown Object (User) added a comment to T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.

Once this task is solved, QoS documentation should include a subsection about NAT, explaining the procedure for both outbound and inbound traffic.

Oct 26 2020, 9:35 AM

Oct 25 2020

blucafee80 created T3012: DHCPv6 relay requires address when it shouldn't.
Oct 25 2020, 12:11 AM · VyOS 1.2 Crux

Oct 22 2020

jack9603301 added a comment to T3008: Migrate from ntpd to chronyd.

It looks good, I want to ask how other people in the community think about this?

Oct 22 2020, 6:25 PM · VyOS 1.4 Sagitta
Gunni added a comment to T3008: Migrate from ntpd to chronyd.
  1. If the user configures his cluster as a "pool" or a bunch of "server" they should work fine, he can also "allow" them to connect to him if he wishes. I would recommend connecting to a good pool myself, or a low stratum device hosted locally, instead of making some kind of cluster.
  2. https://listengine.tuxfamily.org/chrony.tuxfamily.org/chrony-users/2016/03/msg00001.html
Oct 22 2020, 6:17 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T3008: Migrate from ntpd to chronyd.

Does anyone understand the meaning of these performance data? I don’t know the unit of these data

Oct 22 2020, 6:16 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T3008: Migrate from ntpd to chronyd.
  1. 1. When the user's data source uses NTP cluster, whether switching to the new service may lead to the compatibility problem of NTP cluster network
Oct 22 2020, 6:12 PM · VyOS 1.4 Sagitta
Gunni added a comment to T3008: Migrate from ntpd to chronyd.

Yes, absolutely, and if you visit the link in the post you'll see a comparison of them, and at the bottom is some explanation.

Oct 22 2020, 5:57 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T3008: Migrate from ntpd to chronyd.

Can chronyd completely replace NTP?

Oct 22 2020, 5:56 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T3008: Migrate from ntpd to chronyd: VyOS 1.3 Equuleus.
Oct 22 2020, 5:07 PM · VyOS 1.4 Sagitta

Oct 21 2020

Gunni updated the task description for T3008: Migrate from ntpd to chronyd.
Oct 21 2020, 9:13 PM · VyOS 1.4 Sagitta
Gunni created T3008: Migrate from ntpd to chronyd.
Oct 21 2020, 9:12 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T2944: NTP by default listen on any address/interface from Open to Needs testing.
Oct 21 2020, 8:03 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
Viacheslav added a comment to T2895: VPN IPsec "leftsubnet" declared 2 times.

Do we need it for "crux"?
This does not affect the work of VPN service.

Oct 21 2020, 7:56 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Oct 20 2020

Viacheslav closed T2982: show protocols bfd command parse failure as Unknown Status.
Oct 20 2020, 9:54 AM · Ready for Crux (1.2.x), VyOS 1.2 Crux

Oct 19 2020

SrividyaA created T2999: Add snmp mibs for QoS.
Oct 19 2020, 1:18 PM · Restricted Project, VyOS Rolling
Unknown Object (User) changed the status of T2883: op-mode reset vpn command shows wrong completion from Open to In progress.

It looks like this works, but when we don't have any connected user, it listed the current directory file

vyos@RTR1:~$ touch 1.txt
vyos@RTR1:~$ reset vpn remote-access user <tab>
Possible completions:
  1.txt         Terminate specified user's current remote access VPN session(s)

After a user connected, all works properly

vyos@RTR1:~$ reset vpn remote-access user <tab>
Possible completions:
  test1         Terminate specified user's current remote access VPN session(s)
Oct 19 2020, 11:30 AM · VyOS 1.2 Crux

Oct 17 2020

rherold created T2988: ip source validation not working for ipv6 aka move it to netfilter.
Oct 17 2020, 7:10 PM · VyOS 1.2 Crux

Oct 16 2020

Viacheslav updated subscribers of T2982: show protocols bfd command parse failure.

@c-po @dmbaturin It can be safely cherry-picked to the "crux".
I tested this on 1.2.6-s1, it works.

Oct 16 2020, 1:11 PM · Ready for Crux (1.2.x), VyOS 1.2 Crux
Viacheslav added a comment to T2982: show protocols bfd command parse failure.

It was fixed in the rolling T2573
https://phabricator.vyos.net/rVYOSONEXf812c5d1ce01efa8323bfb797c57f68f474665bb

Oct 16 2020, 6:16 AM · Ready for Crux (1.2.x), VyOS 1.2 Crux

Oct 15 2020

dirtycache created T2982: show protocols bfd command parse failure.
Oct 15 2020, 8:00 PM · Ready for Crux (1.2.x), VyOS 1.2 Crux
Viacheslav added a comment to T2979: BGP route leak at system boot.

@Robot82
It will be by default in the new BGP implementation.
https://github.com/vyos/vyos-1x/blob/current/data/templates/frr/bgp.frr.tmpl#L5

Oct 15 2020, 6:47 PM · VyOS 1.2 Crux
Unknown Object (User) added a comment to T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.

https://forum.vyos.io/t/limit-bandwith-for-indivindual-ips-on-1-2-5/5947/30?u=s.lorente

Oct 15 2020, 4:19 PM
Robot82 added a comment to T2979: BGP route leak at system boot.

OK, thank you. I will test this. This should probably be made as default.

Oct 15 2020, 3:09 PM · VyOS 1.2 Crux
danhusan added a comment to T2979: BGP route leak at system boot.

This has come up multiple times before, see https://phabricator.vyos.net/T1698 for the solution.

Oct 15 2020, 12:14 PM · VyOS 1.2 Crux

Oct 14 2020

Robot82 created T2979: BGP route leak at system boot.
Oct 14 2020, 6:30 PM · VyOS 1.2 Crux

Oct 13 2020

Unknown Object (User) updated the task description for T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.
Oct 13 2020, 10:51 AM
Unknown Object (User) updated the task description for T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.
Oct 13 2020, 10:48 AM
Unknown Object (User) updated the task description for T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.
Oct 13 2020, 10:45 AM

Oct 8 2020

Unknown Object (User) added a comment to T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.

https://forum.openwrt.org/t/ingress-traffic-shaping-with-snat/40226

Oct 8 2020, 10:21 PM
Unknown Object (User) added a project to T2971: Provide a CLI solution for Ingress Shaping when there is SNAT: VyOS 1.3 Equuleus.
Oct 8 2020, 10:07 PM
Unknown Object (User) updated the task description for T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.
Oct 8 2020, 10:06 PM
Unknown Object (User) renamed T2971: Provide a CLI solution for Ingress Shaping when there is SNAT from Provide a CLI solution for Ingress Shaping when there is SNAT. to Provide a CLI solution for Ingress Shaping when there is SNAT.
Oct 8 2020, 9:53 PM
Unknown Object (User) created T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.
Oct 8 2020, 9:25 PM

Oct 6 2020

trae32566 created T2965: Brief BFD Peer Info.
Oct 6 2020, 7:37 AM · VyOS 1.3 Equuleus (1.3.0)

Oct 2 2020

Unknown Object (User) added a comment to T2954: Use kernel mode L2TP in xl2tpd.

Note: New xl2tpd package does not work with the followings params in options.xl2tpd

crtscts
lock
Oct 2 2020, 7:13 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) created T2954: Use kernel mode L2TP in xl2tpd.
Oct 2 2020, 7:00 PM · VyOS 1.2 Crux (VyOS 1.2.7)
jack9603301 added a comment to T2898: Support NDP proxy.

At this stage, I can't realize the automatic configuration of NDP proxy. On the other hand, although I don't know what additional application scenarios will be in addition to nat66, I hope to give full play to the full potential of NDP proxy, so I don't want to bind it to nat66 artificially.

Oct 2 2020, 2:22 AM · VyOS 1.4 Sagitta

Oct 1 2020

c-po added a comment to T2898: Support NDP proxy.

Still wondering why ndp-proxy can not be part of the nat66 tree.
When a NAT66 translation is added we know the prefix (src and dst), the in/out-bound interface - so another CLI option (ndp-proxy) could probably be added to not open up an additional service node.

Oct 1 2020, 8:06 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

@c-po Request merge https://github.com/vyos/vyos-1x/pull/556

Oct 1 2020, 2:22 PM · VyOS 1.4 Sagitta
Maltahl added a comment to T2943: Wireguard allow use of hostname as endpoint.
In T2943#76739, @runar wrote:

as a workaround you could add this to a post-boot script on the device.

Oct 1 2020, 1:50 PM · VyOS 1.2 Crux
runar closed T2943: Wireguard allow use of hostname as endpoint as Wontfix.

This is disallowed by design by the VyOS team. the reason for this is partly because of the configuration order done by VyOS and how the dns lookup is handled by Wireguard.
Yes, the wg configuration utillity DOES handle DNS lookups, but NO, Wireguard does not handle them. This means that the DNS lookups is done once (and only once) when the wg command is executed on creation of the tunnel and then the resulting ip result is stored in wireguard. this results in the dns lookup will fail after a reboot of the VyOS device because it cant resolve the dns of the endpoint at that point (this is done before routing is enabled on the device)

Oct 1 2020, 12:28 PM · VyOS 1.2 Crux
Viacheslav added a comment to T2944: NTP by default listen on any address/interface.

PR for Rolling https://github.com/vyos/vyos-1x/pull/559

Oct 1 2020, 10:05 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
Viacheslav claimed T2944: NTP by default listen on any address/interface.
Oct 1 2020, 9:51 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
Viacheslav created T2944: NTP by default listen on any address/interface.
Oct 1 2020, 9:44 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
Maltahl created T2943: Wireguard allow use of hostname as endpoint.
Oct 1 2020, 8:06 AM · VyOS 1.2 Crux

Sep 30 2020

jack9603301 added a comment to T2898: Support NDP proxy.

Already basically ready to merge

Sep 30 2020, 2:15 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 30 2020, 1:31 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2933: VRRP add option virtual_ipaddress_excluded.

PR for crux https://github.com/vyos/vyos-1x/pull/558

Sep 30 2020, 9:14 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project

Sep 29 2020

jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 29 2020, 6:27 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 29 2020, 5:12 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2933: VRRP add option virtual_ipaddress_excluded.

PR https://github.com/vyos/vyos-1x/pull/557

Sep 29 2020, 12:56 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
jack9603301 added a comment to T2898: Support NDP proxy.

https://github.com/vyos/vyos-1x/pull/556

Sep 29 2020, 8:50 AM · VyOS 1.4 Sagitta
Unknown Object (User) created T2934: proxy-arp-pvlan on VRRP interface.
Sep 29 2020, 7:00 AM · Restricted Project, VyOS Rolling

Sep 28 2020

Viacheslav created T2933: VRRP add option virtual_ipaddress_excluded.
Sep 28 2020, 8:44 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 28 2020, 2:02 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 28 2020, 9:15 AM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 28 2020, 3:39 AM · VyOS 1.4 Sagitta

Sep 27 2020

jack9603301 added a comment to T2898: Support NDP proxy.

Write redundant and intrusive code for all interface types, which may introduce unknown errors (I can’t guarantee 100% accuracy without testing)

Sep 27 2020, 4:30 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

@c-po I am thinking about a problem. Placing proxy-ndp under the child node of interface may generate redundant implementation code and is intrusive. In fact, for proxy-ndp, only one configuration file is needed. Is this Reasonable? I don't even know how to fully test whether the intrusive code affects the basic functions of the router.

Sep 27 2020, 4:26 PM · VyOS 1.4 Sagitta

Sep 26 2020

Viacheslav added a comment to T2793: compare + TAB completion does not show proper username if user contains _.

It looks like this problem is around here
https://github.com/vyos/vyatta-cfg/blob/current/etc/bash_completion.d/vyatta-cfg#L280-L290

Sep 26 2020, 4:24 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav changed the status of T2856: equuleus: `show version all` throws broken pipe exception on abort from Unknown Status to Resolved.
Sep 26 2020, 9:49 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux

Sep 25 2020

mpueschel added a comment to T2700: Redirecting traffic from PPPoE interface to IFB fails.

Yes that's correct. And there is already some sort of check implemented for the node traffic-policy, so it does not fail when the pppoe interface does not exist yet. It just shows a warning: https://github.com/vyos/vyatta-cfg-qos/blob/bbf2b2f06b7a0f883f7134df5e2b3e089015738e/scripts/vyatta-qos.pl#L198

Sep 25 2020, 3:17 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
kroy added a comment to T2700: Redirecting traffic from PPPoE interface to IFB fails.

I think I know what's happening here.

Sep 25 2020, 2:58 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 25 2020, 9:12 AM · VyOS 1.4 Sagitta

Sep 23 2020

Viacheslav added a project to T2856: equuleus: `show version all` throws broken pipe exception on abort: VyOS 1.2 Crux.
Sep 23 2020, 1:41 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux

Sep 22 2020

Unknown Object (User) added a comment to T2700: Redirecting traffic from PPPoE interface to IFB fails.

https://forum.vyos.io/t/limit-download-and-upload-on-wan-for-every-vlan/5608/51

Sep 22 2020, 4:58 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
SrividyaA renamed T2914: OpenVPN: Fix for IPv4 remote-host hostname in client mode: from OpenVPN: Fix for IPv4 remote-host addresses in client mode: to OpenVPN: Fix for IPv4 remote-host hostname in client mode:.
Sep 22 2020, 12:12 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
SrividyaA created T2914: OpenVPN: Fix for IPv4 remote-host hostname in client mode:.
Sep 22 2020, 12:11 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
Viacheslav added a comment to T2895: VPN IPsec "leftsubnet" declared 2 times.

PR for rolling https://github.com/vyos/vyatta-cfg-vpn/pull/38

Sep 22 2020, 11:48 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav claimed T2895: VPN IPsec "leftsubnet" declared 2 times.

It declared 2 times, because there is 2 checks

Sep 22 2020, 11:19 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T2883: op-mode reset vpn command shows wrong completion.

PR https://github.com/vyos/vyatta-ravpn/pull/16

Sep 22 2020, 10:39 AM · VyOS 1.2 Crux
Viacheslav added a comment to T2883: op-mode reset vpn command shows wrong completion.

This is the output of this line

Sep 22 2020, 7:45 AM · VyOS 1.2 Crux
azdle created T2913: Failure to install fpm while building builder docker image.
Sep 22 2020, 1:53 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)

Sep 21 2020

jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 21 2020, 6:41 AM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 21 2020, 5:58 AM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 21 2020, 5:58 AM · VyOS 1.4 Sagitta

Sep 20 2020

jack9603301 added a comment to T2898: Support NDP proxy.

@c-po If I want to be an interface-ethernet.xml.in Add custom configuration actions (such as proxy NDP) with certain extensibility (its configuration can be extended in other places). What should I do?

Sep 20 2020, 3:19 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T2898: Support NDP proxy.

@Cheeze_It

I also take into account the specific situation of the ndp proxy, the configuration of this link prompts, the configuration format of the ndp proxy is like this.

https://manpages.debian.org/buster/ndppd/ndppd.conf.5.en.html

Sep 20 2020, 12:22 AM · VyOS 1.4 Sagitta

Sep 19 2020

jack9603301 moved T2898: Support NDP proxy from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Sep 19 2020, 6:12 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

I also take into account the specific situation of the ndp proxy, the configuration of this link prompts, the configuration format of the ndp proxy is like this.

Sep 19 2020, 6:06 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 19 2020, 5:51 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 19 2020, 5:51 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

No arp proxy option is found in the configuration path, ndp proxy can manage multiple address rules under one interface

vyos@vyos# set interfaces ethernet eth0 ip 
Possible completions:
   arp-cache-timeout
                ARP cache entry timeout in seconds
   disable-arp-filter
                Disable ARP filter on this interface
   enable-arp-accept
                Enable ARP accept on this interface
   enable-arp-announce
                Enable ARP announce on this interface
   enable-arp-ignore
                Enable ARP ignore on this interface
   enable-proxy-arp
                Enable proxy-arp on this interface
 > ospf         Open Shortest Path First (OSPF) parameters
   proxy-arp-pvlan
                Enable private VLAN proxy ARP on this interface
 > rip          Routing Information Protocol (RIP)
   source-validation
                Policy for source validation by reversed path, as specified in RFC3704
Sep 19 2020, 5:46 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

Although I intended to think that it is easier to write scripts under the protocol, but from an intuitive point of view, it seems that this path is also a good choice (users can use the same command line as the arp proxy to configure) I have written it A sample, then only need to decide how to modify the cli

Sep 19 2020, 5:24 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

set interfaces ethernet eth0 ip proxy-arp

The more suitable position may be set protocol ndp-proxy

I...really would like to not put it under "protocols" but to put it under the interface. It's *much* easier and more intuitive to see it under the interface/sub-interface than to see it in its' own stanza under "protocol" node.

Also, I'd argue it would be reasonable to separate ARP proxy and NDP proxy. That way one can pick and choose. Of course ARP proxy can't work without an IP address configured. NDP proxy can't be configured without an IPv6 address configured (those could be used as checks against configuring it on an empty interface).

Sep 19 2020, 5:21 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

If possible, give your suggested cli path for my reference

Sep 19 2020, 5:18 PM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T2898: Support NDP proxy.

set interfaces ethernet eth0 ip proxy-arp

The more suitable position may be set protocol ndp-proxy

Sep 19 2020, 5:00 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 19 2020, 1:34 PM · VyOS 1.4 Sagitta
jack9603301 changed the status of T2898: Support NDP proxy from Open to In progress.
Sep 19 2020, 9:39 AM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 19 2020, 7:21 AM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

I can't find how to enable ipv6 connection tracking. Recompiling and modifying the linux kernel switch does not seem to see the module loaded. I think the current nat66 has completed 90%, and only need to implement ndp proxy to make it work normally.

Sep 19 2020, 7:20 AM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

set interfaces ethernet eth0 ip proxy-arp

Sep 19 2020, 7:17 AM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

I think we do need it, we can’t let users manage all IP manually unless we implement stateful NAT66

Sep 19 2020, 7:15 AM · VyOS 1.4 Sagitta
c-po added a comment to T2898: Support NDP proxy.

set interfaces ethernet eth0 ip proxy-arp. Isn‘t the Kernel sysctl interface enough? Do we really need a daemon?

Sep 19 2020, 6:57 AM · VyOS 1.4 Sagitta
jack9603301 triaged T2898: Support NDP proxy as Normal priority.
Sep 19 2020, 6:41 AM · VyOS 1.4 Sagitta
jack9603301 claimed T2898: Support NDP proxy.
Sep 19 2020, 6:40 AM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T2898: Support NDP proxy.
Sep 19 2020, 6:30 AM · VyOS 1.4 Sagitta