Page MenuHomeVyOS Platform
Feed All Stories

Dec 10 2020

dmbaturin edited projects for T461: Central user/key management through JumpCloud, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 12:01 PM
dmbaturin edited projects for T446: Flow accounting enhancements: pre/post NAT, ingress/egress, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 12:00 PM · VyOS 1.4 Sagitta
dmbaturin edited projects for T417: Allow bonding non-ethernet interfaces, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 12:00 PM
dmbaturin edited a custom field on T377: DHCP-relay agent package replacement.
Dec 10 2020, 11:59 AM · Restricted Project, VyOS Rolling
dmbaturin edited projects for T377: DHCP-relay agent package replacement, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:59 AM · Restricted Project, VyOS Rolling
dmbaturin edited projects for T381: config nodes for EasyRSA CAs, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:59 AM · VyOS 1.4 Sagitta
dmbaturin edited projects for T365: OVS as replacement of Linux bridge, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:59 AM
dmbaturin edited projects for T344: Software basesd FastPath, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:59 AM · VyOS 1.5 Circinus
dmbaturin edited projects for T292: [ZBF] Allow filtering intra zone traffic, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:58 AM · VyOS 1.4 Sagitta
dmbaturin edited projects for T291: support for Predictable Network Interface Names, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:58 AM
dmbaturin edited projects for T268: Add support for multiple ospv/ospfv3 routing processes, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:58 AM · VyOS Rolling
dmbaturin edited projects for T264: Use base64 or hex format in ipsec.secrets to allow double quotes, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:57 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus, VyOS Rolling
dmbaturin edited projects for T94: commit archive to AWS S3 , added: VyOS 1.3 Equuleus; removed VyOS 1.4 Sagitta.
Dec 10 2020, 11:57 AM · VyOS Rolling
syncer changed the edit policy for T139: Commit archive backends.
Dec 10 2020, 11:56 AM · VyOS Rolling
dmbaturin edited projects for T260: Redirect traffict between two L3 interfaces, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:56 AM
dmbaturin edited projects for T237: Configuration Archival Periodic, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:56 AM · VyOS Rolling
dmbaturin edited projects for T235: Ability to configure manual IP Rules, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:54 AM · VyOS 1.4 Sagitta
dmbaturin changed Is it a breaking change? from none to compatible on T200: Automated config deployment from a removable drive at installation time.
Dec 10 2020, 11:54 AM · Ideas
dmbaturin edited projects for T200: Automated config deployment from a removable drive at installation time, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:54 AM · Ideas
dmbaturin edited projects for T160: Support NAT64, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:53 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin edited projects for T141: TACACS+ Support, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:53 AM · VyOS 1.4 Sagitta
dmbaturin edited projects for T118: Native Zabbix Support, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:53 AM · Restricted Project, VyOS 1.4 Sagitta
dmbaturin edited projects for T114: Allow wan load-balancing rules to match against groups, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:52 AM · VyOS 1.5 Circinus (2025.11)
dmbaturin edited projects for T110: Ability to store SSH keys out of the config, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:52 AM · VyOS Rolling
dmbaturin changed Is it a breaking change? from none to compatible on T94: commit archive to AWS S3 .
Dec 10 2020, 11:51 AM · VyOS Rolling
dmbaturin edited projects for T94: commit archive to AWS S3 , added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:51 AM · VyOS Rolling
dmbaturin edited projects for T89: Dynamic DNS support for AWS Route53 and other cloud providers, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:50 AM · VyOS Rolling
dmbaturin edited projects for T57: Make it possible to disable the entire IPsec peer, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:50 AM · VyOS 1.4 Sagitta
dmbaturin edited projects for T28: Add auto provisioning, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:49 AM · Bugs, VyOS Rolling
dmbaturin edited projects for T5: command logging (local and remote), added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 10 2020, 11:48 AM · VyOS Rolling
vlesk created T3123: Configuration of vti interface impossible .
Dec 10 2020, 3:08 AM · VyOS 1.3 Equuleus (1.3.0)

Dec 9 2020

Cheeze_It added a comment to T915: MPLS Support.

Put in a PR to add documentation for LDP import/export control again. I didn't rebase properly last time. Sorry everyone :(

Dec 9 2020, 7:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po closed T3122: Update Linux Kernel to v4.19.162 as Resolved.
Dec 9 2020, 7:19 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3122: Update Linux Kernel to v4.19.162.
Dec 9 2020, 7:18 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3121: get_config_dict() and key_mangling=('-', '_') Broke PowerDNS dns_forwarding config file as Resolved.
Dec 9 2020, 7:16 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX2f5de3cfadec: dns: T3121: recursion zone bugfix (authored by NEOMorphey).
Dec 9 2020, 7:16 PM
jack9603301 added a comment to T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring.

Maybe this implementation also has a dependency problem, I will fix it in the near future

Dec 9 2020, 10:21 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.

Sorry, I have changed the repair implementation
PR: https://github.com/vyos/vyos-1x/pull/638

Dec 9 2020, 8:47 AM · VyOS 1.3 Equuleus (1.3.0)
NEOMorphey updated the task description for T3121: get_config_dict() and key_mangling=('-', '_') Broke PowerDNS dns_forwarding config file.
Dec 9 2020, 8:31 AM · VyOS 1.3 Equuleus (1.3.0)
NEOMorphey created T3121: get_config_dict() and key_mangling=('-', '_') Broke PowerDNS dns_forwarding config file.
Dec 9 2020, 8:18 AM · VyOS 1.3 Equuleus (1.3.0)
Cheeze_It committed rVYOSONEXf0543d5d28d5: mpls-conf: T915: Add LDP import and export control.
Dec 9 2020, 7:04 AM
GitHub <noreply@github.com> committed rVYOSONEX9f5f31ed15d6: Merge pull request #639 from Cheeze-It/current (authored by c-po).
Dec 9 2020, 7:04 AM
Cheeze_It added a comment to T915: MPLS Support.

Put in a PR to add LDP import/export control.

Dec 9 2020, 3:15 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Dec 8 2020

Matwolf added a comment to T3117: OpenVPN config migration errors upgrading from 1.3-rolling-202010280217 to 1.3-rolling-202012060217.
In T3117#81576, @c-po wrote:

Unfortunately setting udp4 was never "valid" in the first place, this was only possible by a wrong regex here: https://github.com/vyos/vyos-1x/blob/406083932ae62ccde5ff547ef7d7960efe0269e3/interface-definitions/interfaces-openvpn.xml.in#L345 this has been corrected already which shows the above mentioned result in a not loading config.

Dec 8 2020, 8:42 PM · VyOS 1.3 Equuleus (1.3.0)
c-po triaged T3117: OpenVPN config migration errors upgrading from 1.3-rolling-202010280217 to 1.3-rolling-202012060217 as High priority.
Dec 8 2020, 7:38 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3117: OpenVPN config migration errors upgrading from 1.3-rolling-202010280217 to 1.3-rolling-202012060217 from In progress to Needs testing.
Dec 8 2020, 7:38 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX3226fa1d44d6: openvpn: T3117: fix generated ncp-ciphers in server config.
Dec 8 2020, 7:38 PM
c-po added a comment to T3117: OpenVPN config migration errors upgrading from 1.3-rolling-202010280217 to 1.3-rolling-202012060217.

Unfortunately setting udp4 was never "valid" in the first place, this was only possible by a wrong regex here: https://github.com/vyos/vyos-1x/blob/406083932ae62ccde5ff547ef7d7960efe0269e3/interface-definitions/interfaces-openvpn.xml.in#L345 this has been corrected already which shows the above mentioned result in a not loading config.

Dec 8 2020, 7:14 PM · VyOS 1.3 Equuleus (1.3.0)
c-po assigned T3073: sh nat source translations Python error to moepman.
Dec 8 2020, 6:26 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2562: VyOS can't be used as a DHCP server for a DHCP relay, a subtask of T3100: Migrate DHCP/DHCPv6 server to get_config_dict(), as Resolved.
Dec 8 2020, 6:18 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2562: VyOS can't be used as a DHCP server for a DHCP relay as Resolved.
Dec 8 2020, 6:18 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 reopened T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring as "Needs testing".
Dec 8 2020, 5:39 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3117: OpenVPN config migration errors upgrading from 1.3-rolling-202010280217 to 1.3-rolling-202012060217 from Open to In progress.
Dec 8 2020, 4:53 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2562: VyOS can't be used as a DHCP server for a DHCP relay, a subtask of T3100: Migrate DHCP/DHCPv6 server to get_config_dict(), from In progress to Needs testing.
Dec 8 2020, 4:52 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2562: VyOS can't be used as a DHCP server for a DHCP relay from In progress to Needs testing.
Dec 8 2020, 4:52 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.

Unfortunately this is the wrong way to go. If it is - for whatever reason - not possible to configure the VLAN parameters for this given interface b/c the enslaved interface is yet not present on the system, it should be later configured by the individual interface.

Dec 8 2020, 4:50 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 edited a custom field on T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.
Dec 8 2020, 2:18 PM · VyOS 1.3 Equuleus (1.3.0)
primoz added a comment to T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.

Tried this patch with @jack9603301 , it solves the problem for me.

Dec 8 2020, 2:16 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 renamed T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails from VLAN-aware bridges + VXLAN to When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.
Dec 8 2020, 1:53 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.

@c-po Please merge this PR, the problem will be fixed directly

Dec 8 2020, 1:26 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 changed the status of T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails from Open to In progress.
Dec 8 2020, 1:02 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 triaged T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails as High priority.
Dec 8 2020, 1:02 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.

I may have to change the configuration priority. Due to priority issues, the settings may fail

Dec 8 2020, 12:59 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 closed T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring as Resolved.
Dec 8 2020, 10:34 AM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX2a25efce5f3e: Merge pull request #633 from jack9603301/T3089 (authored by c-po).
Dec 8 2020, 10:28 AM
jack9603301 committed rVYOSONEXe8957b575b05: mirror: T3089: support two-way traffic mirroring.
Dec 8 2020, 10:28 AM
sever-sever <v.gletenko@vyos.io> committed rVYOSONEX9f49c546bed3: bgp: T2174: Fix Template. Update to use FRRConfig framework.
Dec 8 2020, 10:27 AM
GitHub <noreply@github.com> committed rVYOSONEX7ef0840d4642: Merge pull request #637 from sever-sever/T2174 (authored by c-po).
Dec 8 2020, 10:27 AM
Viacheslav added a comment to T2174: Rewrite protocol BGP to new XML/Python style.

PR for fixing bgp template (prefix-list) and add the ability to use updated frr.py framework functions.

Dec 8 2020, 9:39 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.

@primoz Can you contact me in Slack?

Dec 8 2020, 7:40 AM · VyOS 1.3 Equuleus (1.3.0)
debiansid added a comment to T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.

how to build any version of linux kernel using build-kernel.sh and make iso?

Dec 8 2020, 12:51 AM · VyOS Rolling

Dec 7 2020

mandrei05 closed T3120: Python error when deleting nat rule as Resolved.

some corruption. I redeployed the instance and copied the config over and now it works.

Dec 7 2020, 11:41 PM · VyOS 1.3 Equuleus (1.3.0)
mandrei05 created T3120: Python error when deleting nat rule.
Dec 7 2020, 10:42 PM · VyOS 1.3 Equuleus (1.3.0)
constharper updated constharper.
Dec 7 2020, 9:34 PM
akvadrako added a comment to T3118: Support wireless drivers without monitor mode.

To clarify, in this case I am trying to commit a config with an interface that's configured as an AP.

Dec 7 2020, 6:12 PM
c-po added a comment to T3118: Support wireless drivers without monitor mode.

Well this is from old Vyatta times, on system bootup this script is called (https://github.com/vyos/vyatta-cfg-system/blob/current/scripts/system/vyatta_interface_rescan#L137-L140) and a WIFI node is created if a wifi interface is detected. The script could be altered, too if monitor is not supported.

Dec 7 2020, 5:56 PM
Cheeze_It added a comment to T915: MPLS Support.

@bbs2web, here's what I got...

Dec 7 2020, 5:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Cheeze_It added a comment to T915: MPLS Support.

@bbs2web, getting this one (https://downloads.vyos.io/rolling/current/amd64/vyos-1.3-rolling-202012070521-amd64.iso) and will troubleshoot...

Dec 7 2020, 5:35 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
akvadrako added a comment to T3118: Support wireless drivers without monitor mode.

That's a little unclear to me. If the interface is defined but doesn't yet exist, then it needs to be created. A brief look at the code makes it seem like it always creates new interfaces with type=monitor.

Dec 7 2020, 5:30 PM
c-po committed rVYOSONEX345db48254e2: system: T3119: migrate "system ip" to get_config_dict() incl. smoketest.
Dec 7 2020, 5:21 PM
c-po closed T3119: migrate "system ip" to get_config_dict() and provide smoketest as Resolved.
Dec 7 2020, 5:19 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3119: migrate "system ip" to get_config_dict() and provide smoketest.
Dec 7 2020, 5:19 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3118: Support wireless drivers without monitor mode.

I guess the best thing would be to not add this interface at all

Dec 7 2020, 5:19 PM
c-po committed rVYOSONEX55f5a4e17e4a: vyos.ifconfig: T1579: keep IPv6 link-local address on reconfiguration #2.
Dec 7 2020, 4:19 PM
akvadrako created T3118: Support wireless drivers without monitor mode.
Dec 7 2020, 1:44 PM
efficiosoft added a comment to T3113: dhcp-server: Multiple domain-search values are escaped incorrectly.

Thanks for the quick fix!

Dec 7 2020, 12:52 PM
Matwolf created T3117: OpenVPN config migration errors upgrading from 1.3-rolling-202010280217 to 1.3-rolling-202012060217.
Dec 7 2020, 12:49 PM · VyOS 1.3 Equuleus (1.3.0)
syncer set the icon for VyOS 1.4 Sagitta to Experimental.
Dec 7 2020, 11:35 AM
syncer set the image for VyOS 1.4 Sagitta to F1109444: profile.
Dec 7 2020, 11:34 AM
jack9603301 added a comment to T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.

@primoz Delete the old one, create a new bridge after commit, and then commit. Can it work normally?

Dec 7 2020, 9:33 AM · VyOS 1.3 Equuleus (1.3.0)
primoz added a comment to T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.

it's an edit + delete/delete/delete ... no creation (at least in my edge case).

Dec 7 2020, 9:30 AM · VyOS 1.3 Equuleus (1.3.0)
sempervictus added a comment to T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.

Important note on this PR - in order to build the GCC plugins which perform most of the self-protection work, the Docker container needs gcc-8-plugin-dev installed. Otherwise it builds, but silently downgrades the configs dropping RANDSTRUCT/STACKLEAK silently.
Pulled RSBAC out for now (issues with building the rest while its in there but disabled), validated builds with and without the plugins package for GCC8.

Dec 7 2020, 6:37 AM · VyOS Rolling
bbs2web added a comment to T915: MPLS Support.

Installed 1.3-rolling-202012060217 yesterday and the VLAN interfaces don't appear to get MPLS enabled. I essentially removed the following lines, which work as expected when present:

set system sysctl custom net.mpls.conf.eth0/11.input value '1'
set system sysctl custom net.mpls.conf.eth0/13.input value '1'
set system sysctl custom net.mpls.conf.eth0/14.input value '1'
Dec 7 2020, 6:07 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po committed rVYOSONEXeecec6b5caea: dhcp: T2562: add "listen-address" CLI node for better DHCP relay support.
Dec 7 2020, 5:18 AM
GitHub <noreply@github.com> committed rVYOSONEX722e886ac2bf: Merge pull request #636 from c-po/t2562-dhcp (authored by c-po).
Dec 7 2020, 5:18 AM
jack9603301 added a comment to T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.

@c-po Does the deletion of the bridge occur after the new bridge is created or before?

Dec 7 2020, 4:41 AM · VyOS 1.3 Equuleus (1.3.0)
sempervictus added a comment to T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.

Added an inert patch (disabled in Kconfig) for https://www.rsbac.org/ on 5.4. This can be used to significantly harden the restrictions intended by the CLI to limit users to specifically defined roles, same goes for applications/containers.
If adding container support to VyOS is still on the roadmap, we're going to want to take extra care to enforce the boundaries between them and the host since real world use cases are pretty much guaranteed to leave old vulnerable containers running on long-running network appliances making for a variable and worsening attack surface over time.
This isn't quite as integrated and doesnt provide nearly the coverage as what you get with grsec+pax, but a rough approximation of "role-based FS restrictions and runtime hardening" is now in the pull request along with the other stuff which seemed pertinent for upstream.

Dec 7 2020, 3:00 AM · VyOS Rolling
sempervictus added a comment to T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.

Thank you sir. Worked through a clean build, updated patches, rebased, and pushed.

Dec 7 2020, 2:44 AM · VyOS Rolling

Dec 6 2020

primoz added a comment to T3114: When the bridge member is a non-ethernet interface, setting VLAN-aware bridge parameters fails.

As it looks to me (but i'm not sure yet), the configuration system is fixing devices one by one and was trying to add port into new bridge before the old bridges were removed (and so ports were still in them). If this is the case ... not sure that there even exist an easy fix.

Dec 6 2020, 9:34 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX6b7aa5ae54b5: vyos.validate: T1579: support prefix length in is_ipv6_link_local() (authored by c-po).
Dec 6 2020, 8:53 PM