Page MenuHomeVyOS Platform
Feed All Stories

Nov 23 2020

c-po added a comment to T3074: OpenVPN site-to-site creates wrong peer address.

It looks like this issue is already present in 1.3-rolling-202010270217, before the OpenVPN rewrite to get_config_dict():

Nov 23 2020, 9:29 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3081: get_config_dict() does not honor whitespaces in the CLI values field.
[ interfaces openvpn vtun0 ]
{'auth_user_pass_file': '/run/openvpn/vtun0.pw',
 'daemon_group': 'openvpn',
 'daemon_user': 'openvpn',
 'device_type': 'tun',
 'encryption': {'cipher': 'aes256gcm'},
 'ifname': 'vtun0',
 'keep_alive': {'failure_count': '3', 'interval': '10'},
 'mode': 'server',
 'openvpn_option': ['tls-auth /config/auth/ovpn_test_site2site.key 0'],
 'protocol': 'udp',
 'server': {'name_server': ['10.53.53.53', '10.53.53.54'],
            'push_route': ['0.0.0.0/0'],
            'subnet': ['10.7.178.0/24'],
            'topology': 'net30'},
 'tls': {'ca_cert_file': '/config/auth/ovpn_test_ca.pem',
         'cert_file': '/config/auth/ovpn_test_server.pem',
         'dh_file': '/config/auth/ovpn_test_dh.pem',
         'key_file': '/config/auth/ovpn_test_server.key'},
 'use_lzo_compression': {}}
Nov 23 2020, 9:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02.

We will deal with the compat-names warning once starting on VyOS 1.4 ;)

Nov 23 2020, 9:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02, a subtask of T3060: OpenVPN virtual interface not coming up after upgrade, as Resolved.
Nov 23 2020, 9:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02, a subtask of T3081: get_config_dict() does not honor whitespaces in the CLI values field, as Resolved.
Nov 23 2020, 9:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02 as Resolved.
Nov 23 2020, 9:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2802: Tunnel interface does not apply EUI-64 IPv6 Address as Resolved.
Nov 23 2020, 9:05 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2802: Tunnel interface does not apply EUI-64 IPv6 Address.

Work with latest rolling release:

Nov 23 2020, 9:05 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav assigned T3083: Add feature event-handler to dmbaturin.
Nov 23 2020, 8:42 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav created T3083: Add feature event-handler.
Nov 23 2020, 8:42 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Cheeze_It added a comment to T915: MPLS Support.

Put in a PR for refactor of LDP template, MPLS python handler, addition of global MPLS parameters (via Linux kernel config changes), and separation of MPLS interfaces from LDP interfaces. *PLEASE* know I did do testing but I want more people to test as well. I have uploaded the package file for this PR here so that people can test my work.

Nov 23 2020, 4:10 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jestabro changed the status of T3082: multi_to_list must distinguish between values and defaults, a subtask of T2956: Add support for list of defaultValues, from Open to Confirmed.
Nov 23 2020, 2:50 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro changed the status of T3082: multi_to_list must distinguish between values and defaults, a subtask of T3081: get_config_dict() does not honor whitespaces in the CLI values field, from Open to Confirmed.
Nov 23 2020, 2:50 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro changed the status of T3082: multi_to_list must distinguish between values and defaults from Open to Confirmed.
Nov 23 2020, 2:50 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T3081: get_config_dict() does not honor whitespaces in the CLI values field as Resolved.

See subtask T3082 for origin and details of this issue.

Nov 23 2020, 2:46 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro committed rVYOSONEXfa6413272ee2: defaults: T3082: multi_to_list must distinguish between values and defaults.
Nov 23 2020, 2:41 AM
jestabro committed rVYOSONEX9311dcda624f: configdict: T3081: honor whitespace in multi node values.
Nov 23 2020, 2:41 AM
jestabro updated the task description for T3082: multi_to_list must distinguish between values and defaults.
Nov 23 2020, 2:39 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro added a subtask for T2956: Add support for list of defaultValues: T3082: multi_to_list must distinguish between values and defaults.
Nov 23 2020, 2:37 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro added a parent task for T3082: multi_to_list must distinguish between values and defaults: T2956: Add support for list of defaultValues.
Nov 23 2020, 2:37 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro added a subtask for T3081: get_config_dict() does not honor whitespaces in the CLI values field: T3082: multi_to_list must distinguish between values and defaults.
Nov 23 2020, 1:32 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro added a parent task for T3082: multi_to_list must distinguish between values and defaults: T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 23 2020, 1:32 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro created T3082: multi_to_list must distinguish between values and defaults.
Nov 23 2020, 1:31 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 22 2020

pasik added a comment to T439: local PBR support.

@Viacheslav Thanks a lot, I'll give it a go, hopefully sometime next week.

Nov 22 2020, 8:21 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX7305a71722ae: bgp: T2174: refactor Jinja template and reduce redundant paths.
Nov 22 2020, 7:45 PM
c-po committed rVYOSONEX35319790813c: smoketest: openvpn: T3080: verify configured keep-alive values.
Nov 22 2020, 7:45 PM
c-po committed rVYOSONEX5053f326a9a6: isis: T1316: remove debug print.
Nov 22 2020, 7:45 PM
Cheeze_It added a comment to T915: MPLS Support.

@bbs2web, oh don't you worry. I've had my eyes on it after I get LDP done. I'm almost done with it too.

Nov 22 2020, 6:26 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
bbs2web added a comment to T915: MPLS Support.

Layer 2 mpls functions were merged in to the kernel on the 3rd of October, this should hopefully allow BGP signalled VPLS and static LDP pseudowire tunnels. Support still appears to be missing in FRR and it will probably be a while until VyOS is based on this newer kernel, but hoorray!

Nov 22 2020, 3:14 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav added a comment to T3074: OpenVPN site-to-site creates wrong peer address.

Device-type tap option works incorrectly

set interfaces openvpn vtun20 device-type 'tap'
set interfaces openvpn vtun20 local-address 10.0.0.0
set interfaces openvpn vtun20 local-host '100.64.0.1'
set interfaces openvpn vtun20 local-port '22222'
set interfaces openvpn vtun20 mode 'site-to-site'
set interfaces openvpn vtun20 remote-address '10.0.0.1'
set interfaces openvpn vtun20 remote-host '100.64.0.2'
set interfaces openvpn vtun20 remote-port '22222'
set interfaces openvpn vtun20 shared-secret-key-file '/config/auth/foo.key'
Nov 22 2020, 1:51 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXd4d223ff86e0: op-mode: add "restart" tree.
Nov 22 2020, 1:42 PM
Viacheslav added a comment to T235: Ability to configure manual IP Rules.

@Dataforce @fetzerms
ip rule "from" already in CLI T439

Nov 22 2020, 1:26 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

Okay, then I can merge this service into NAT66

Nov 22 2020, 12:44 PM · VyOS 1.4 Sagitta
c-po added a comment to T2898: Support NDP proxy.

That we can deal with later on when it‘s needed

Nov 22 2020, 12:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T439: local PBR support.

@pasik Can you check if it solves your expectation?

Nov 22 2020, 12:20 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

I can consider migrating to the implementation of nat66, but I'm not sure if there is a case where the nat66 feature does not need to be enabled, but NDP proxy needs to be enabled

Nov 22 2020, 11:54 AM · VyOS 1.4 Sagitta
c-po claimed T2802: Tunnel interface does not apply EUI-64 IPv6 Address.
Nov 22 2020, 11:27 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2898: Support NDP proxy.

I still have the opinion that NDP proxy should be automatically configured when configuring nat66 as by then all interfaces and directions of the translation are known and the user must not configure any additional daemon.

Nov 22 2020, 11:03 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX72cb73892b14: openvpn: T3080: add missing multiplication on keepalive config option.
Nov 22 2020, 9:42 AM
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02, a subtask of T3060: OpenVPN virtual interface not coming up after upgrade, from In progress to Needs testing.
Nov 22 2020, 9:41 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02, a subtask of T3081: get_config_dict() does not honor whitespaces in the CLI values field, from In progress to Needs testing.
Nov 22 2020, 9:41 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02 from In progress to Needs testing.
Nov 22 2020, 9:41 AM · VyOS 1.3 Equuleus (1.3.0)
c-po assigned T3081: get_config_dict() does not honor whitespaces in the CLI values field to jestabro.
Nov 22 2020, 9:26 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:25 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a parent task for T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02: T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:23 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a subtask for T3081: get_config_dict() does not honor whitespaces in the CLI values field: T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02.
Nov 22 2020, 9:23 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated subscribers of T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:22 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:22 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3081: get_config_dict() does not honor whitespaces in the CLI values field from Open to Confirmed.
Nov 22 2020, 9:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02, a subtask of T3060: OpenVPN virtual interface not coming up after upgrade, from Open to In progress.
Nov 22 2020, 8:49 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02 from Open to In progress.
Nov 22 2020, 8:49 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 21 2020

c-po committed rVYOSONEX4b219bbf1b35: smoketest: openvpn: T3060: verify authentication username and password.
Nov 21 2020, 9:07 PM
syncer moved T3035: Allow IPv4 over IPv6 IPsec and vice versa from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Nov 21 2020, 8:54 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T3035: Allow IPv4 over IPv6 IPsec and vice versa from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Nov 21 2020, 8:54 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer changed the status of T3035: Allow IPv4 over IPv6 IPsec and vice versa from Open to Needs testing.
Nov 21 2020, 8:53 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer changed the subtype of T3035: Allow IPv4 over IPv6 IPsec and vice versa from "Task" to "Enhancement".
Nov 21 2020, 8:53 PM · VyOS 1.2 Crux (VyOS 1.2.7)
kroy added a parent task for T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02: T3060: OpenVPN virtual interface not coming up after upgrade.
Nov 21 2020, 5:54 PM · VyOS 1.3 Equuleus (1.3.0)
kroy added a subtask for T3060: OpenVPN virtual interface not coming up after upgrade: T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02.
Nov 21 2020, 5:54 PM · VyOS 1.3 Equuleus (1.3.0)
kroy created T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02.
Nov 21 2020, 5:52 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3060: OpenVPN virtual interface not coming up after upgrade as Resolved.
Nov 21 2020, 4:35 PM · VyOS 1.3 Equuleus (1.3.0)
danielpo added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

Thanks, works now.

Nov 21 2020, 12:58 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

@danielpo thanks foe the config. A new rolling containig a fix for this issue was just published. A smoketest will be added today to ensure this wont happen again.

Nov 21 2020, 12:24 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXed38b0dfc901: openvpn: T3060: fix client authentication username and password file.
Nov 21 2020, 11:00 AM
c-po committed rVYOSONEX8783a4b2db12: openvpn: T3060: always listen op IPv4 and IPv6 sockets.
Nov 21 2020, 11:00 AM
jack9603301 moved T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge from In Progress to Finished on the VyOS 1.3 Equuleus board.
Nov 21 2020, 9:28 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 closed T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge as Resolved.
Nov 21 2020, 9:25 AM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXeb8bac3df75a: system: T3078: fix vyos-configd handling for "system option" path.
Nov 21 2020, 9:05 AM
GitHub <noreply@github.com> committed rVYOSONEX9b8e3d83e9cf: bridge: T3079: bugfix on VLAN 1 is deleted in VLAN-aware bridges (authored by jack9603301).
Nov 21 2020, 8:25 AM
c-po committed rVYOSONEX5b693c3a71f5: ethernet: T3048: fix migrator to also support a plain config.
Nov 21 2020, 8:22 AM
jack9603301 added a comment to T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge.

PR: https://github.com/vyos/vyos-1x/pull/615

Nov 21 2020, 7:08 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 changed Is it a breaking change? from none to compatible on T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge.
Nov 21 2020, 7:08 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 moved T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Nov 21 2020, 5:14 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 changed the status of T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge from Open to In progress.
Nov 21 2020, 5:05 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 created T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge.
Nov 21 2020, 5:05 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 20 2020

danielpo added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.
authentication {
    password xxxx
    username xxxxx
}
device-type tun
encryption {
    cipher aes256
}
firewall {
    in {
        ipv6-name DENYv6_IN
        name DENY_IN
    }
    local {
        ipv6-name DENYv6_IN
        name DENY_IN
    }
}
hash sha256
mode client
openvpn-option "key-direction 1"
openvpn-option route-nopull
persistent-tunnel
protocol tcp-active
remote-host 1.2.3.4
remote-host 1.2.3.5
remote-port 1195
tls {
    ca-cert-file /config/auth/cert.ca
    auth-file  /config/auth/tls-auth
    tls-version-min 1.2
}
Nov 20 2020, 11:47 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3078: CLI cleanup: rename "system options" -> "system option" as Resolved.
Nov 20 2020, 11:39 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX193323ba5d2f: system: T3078: rename "system options" -> "system option".
Nov 20 2020, 11:36 PM
c-po committed rVYOSONEX5f5b2808c0a6: ethernet: T3048: drop static smp-affinity for dynamic performance tuning.
Nov 20 2020, 11:36 PM
c-po closed T3048: Drop static smp-affinity for a more dynamic way using tuned as Resolved.
Nov 20 2020, 11:34 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3078: CLI cleanup: rename "system options" -> "system option" from Open to In progress.
Nov 20 2020, 10:59 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3078: CLI cleanup: rename "system options" -> "system option".
Nov 20 2020, 10:59 PM · VyOS 1.3 Equuleus (1.3.0)
c-po reopened T3060: OpenVPN virtual interface not coming up after upgrade as "Open".
Nov 20 2020, 10:58 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

Please show us your config

Nov 20 2020, 10:58 PM · VyOS 1.3 Equuleus (1.3.0)
danielpo added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

Now this error appear when trying the latest image:

Nov 20 2020, 5:20 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T160: Support NAT64.

@dmbaturin @artooro Come on, remember not to forget NAT46

Nov 20 2020, 4:32 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jack9603301 added a comment to T2898: Support NDP proxy.

@c-po I am thinking, although it is not possible to incorporate NAT66, whether we can prioritize how to improve and incorporate NDP Proxy

Nov 20 2020, 4:28 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T439: local PBR support from Open to Needs testing.
Nov 20 2020, 4:19 PM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX8bc6775a692e: Merge pull request #614 from sever-sever/T439 (authored by c-po).
Nov 20 2020, 3:54 PM
c-po committed rVYOSONEX7fce006670bf: tunnel: T3072: remove debug print code.
Nov 20 2020, 3:47 PM
c-po committed rVYOSONEXca073ba863b5: tunnel: T3072: bugfix KeyError for IPv6 GRE verify code.
Nov 20 2020, 3:47 PM
c-po committed rVYOSONEX1a199ab4a2d3: Makefile: T2653: remove ipv6 wireguard node.
Nov 20 2020, 2:08 PM
c-po closed T3077: WireGuard: automatically create link-local IPv6 adresses, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, as Resolved.
Nov 20 2020, 1:42 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3077: WireGuard: automatically create link-local IPv6 adresses as Resolved.
Nov 20 2020, 1:42 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXe93cc4e4935c: wireguard: ifconfig: T2653: interface address is not mandatory.
Nov 20 2020, 1:42 PM
c-po committed rVYOSONEX221940c94bf2: wireguard: T2653: fix IPv6 peer address configuration.
Nov 20 2020, 1:42 PM
c-po committed rVYOSONEX49be767ce95d: wireguard: T3077: automatically create link-local IPv6 adresses.
Nov 20 2020, 1:42 PM
c-po committed rVYOSONEX3ae4de269951: tunnel: T3072: drop dead code.
Nov 20 2020, 1:42 PM
c-po committed rVYOSONEXfe8d884b564e: tunnel: T3072: support changing tunnel encapsulation on-the-fly.
Nov 20 2020, 1:42 PM
c-po triaged T3077: WireGuard: automatically create link-local IPv6 adresses as Normal priority.
Nov 20 2020, 1:27 PM · VyOS 1.3 Equuleus (1.3.0)