Page MenuHomeVyOS Platform
Feed All Stories

Jun 7 2021

Viacheslav added a comment to T3017: bridge will lose the tuntap member after reboots.

@jingyun Can you describe steps on how to reproduce it? Or re-check it.
My test config after reboot works fine

set interfaces bridge br0 member interface tun0
set interfaces tunnel tun0 encapsulation 'gre-bridge'
set interfaces tunnel tun0 local-ip '100.64.0.1'
set interfaces tunnel tun0 remote-ip '100.64.0.254'
Jun 7 2021, 6:08 PM · Invalid
c-po committed rVYOSONEXe69879df07e1: smoketest: ipsec: chmod +x testcase.
Jun 7 2021, 5:41 PM
c-po committed rVYOSONEXaf76ccbe603e: nhrp: T3599: adjust Jinja2 template to common style pattern.
Jun 7 2021, 5:41 PM
c-po committed rVYOSONEXeee2bb6c242f: ipsec: T2816: adjust Jinja2 template to common style pattern.
Jun 7 2021, 5:41 PM
Viacheslav moved T3138: ddclient improperly updated when apply rfc2136 config from Open to Backport Candidates on the VyOS 1.4 Sagitta board.
Jun 7 2021, 5:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po closed T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 7 2021, 5:10 PM · VyOS 1.4 Sagitta
c-po closed T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan as Resolved.
Jun 7 2021, 5:10 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 7 2021, 5:09 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX19b8f729dc53: vti: T3588: remove interfaces not bound to IPSec tunnel.
Jun 7 2021, 5:08 PM
c-po committed rVYOSONEX13236b0a6632: ipsec: T3588: remove site-to-site tunnel CLI options only valid in Openswan.
Jun 7 2021, 4:55 PM
Viacheslav changed the status of T3602: Renaming BGP Peer Groups Leaves Router Broken, a subtask of T3182: Main blocker Task for FRR 7.4/7.5 series update, from Open to Needs testing.
Jun 7 2021, 4:40 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the status of T3602: Renaming BGP Peer Groups Leaves Router Broken from Open to Needs testing.
Jun 7 2021, 4:40 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T3516: FRR 7.5 adds a second route when you attempt to change a static route distance instead of overwriting the old route, a subtask of T3182: Main blocker Task for FRR 7.4/7.5 series update, as Resolved.
Jun 7 2021, 4:39 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T3516: FRR 7.5 adds a second route when you attempt to change a static route distance instead of overwriting the old route as Resolved.
Jun 7 2021, 4:39 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav claimed T3602: Renaming BGP Peer Groups Leaves Router Broken.
Jun 7 2021, 4:35 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3602: Renaming BGP Peer Groups Leaves Router Broken.

PR https://github.com/vyos/vyatta-cfg-quagga/pull/81

Jun 7 2021, 4:20 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a subtask for T3182: Main blocker Task for FRR 7.4/7.5 series update: T3602: Renaming BGP Peer Groups Leaves Router Broken.
Jun 7 2021, 2:44 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a parent task for T3602: Renaming BGP Peer Groups Leaves Router Broken: T3182: Main blocker Task for FRR 7.4/7.5 series update.
Jun 7 2021, 2:44 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3602: Renaming BGP Peer Groups Leaves Router Broken.

https://github.com/vyos/vyatta-cfg-quagga/blob/fef5870b764e6166b639043fadb9317c8a49881d/scripts/bgp/vyatta-bgp.pl#L621-L625
https://github.com/vyos/vyatta-cfg-quagga/blob/fef5870b764e6166b639043fadb9317c8a49881d/scripts/bgp/vyatta-bgp.pl#L802-L806

Jun 7 2021, 2:31 PM · VyOS 1.3 Equuleus (1.3.0)
sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEX05b5cd0d8c11: nhrp: T3599: Update config path to new /run directory.
Jun 7 2021, 1:01 PM
GitHub <noreply@github.com> committed rVYOSONEX84ec8b75c190: Merge pull request #868 from sarthurdev/current (authored by c-po).
Jun 7 2021, 1:01 PM
Viacheslav added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

In the crux.

set system conntrack timeout custom rule 10 destination address '203.0.113.74'
set system conntrack timeout custom rule 10 destination port '80'
set system conntrack timeout custom rule 10 protocol tcp established '300'
set system conntrack timeout custom rule 10 source address '192.0.2.168'

commit

vyos@r2-lts# commit
[ system conntrack hash-size 32768 ]
Updated conntrack hash size. This change will take affect when the system is rebooted.
Jun 7 2021, 12:39 PM · VyOS 1.4 Sagitta
anthr76 added a comment to T3600: DHCP Interface static route breaks PBR.

It looks like your assessment is correct. It also seems like next-hop IP would be sufficient as well if I wasn't dealing with dynamic WAN IPs. For the moment I'm sticking with interface instead of dhcp-interface. The related issue you sent seems exactly related to this.

Jun 7 2021, 11:55 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T3505: Commits do not respect changes in FRR that are not stored in a config: T3600: DHCP Interface static route breaks PBR.
Jun 7 2021, 9:17 AM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a parent task for T3600: DHCP Interface static route breaks PBR: T3505: Commits do not respect changes in FRR that are not stored in a config.
Jun 7 2021, 9:17 AM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.

Clarifying as requested by c-po:

Jun 7 2021, 9:12 AM · VyOS 1.4 Sagitta
vindenesen added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

I believe I have found out why modification/deletion of rules fails. This is the rule definition in iptables:

Jun 7 2021, 9:10 AM · VyOS 1.4 Sagitta
trae32566 created T3602: Renaming BGP Peer Groups Leaves Router Broken.
Jun 7 2021, 8:39 AM · VyOS 1.3 Equuleus (1.3.0)

Jun 6 2021

fernando added a comment to T3600: DHCP Interface static route breaks PBR.

I think it is also related https://phabricator.vyos.net/T3522

Jun 6 2021, 9:53 PM · VyOS 1.4 Sagitta
fernando added a comment to T3600: DHCP Interface static route breaks PBR.

I have checked that functionality , i can replicate the issues .although there is a workaround if you "set protocols static table 11 route 0.0.0.0/0 dhcp-interface " any interfaces , it doesn't see in your table ( table 10 /11 ) we can see theses routes in the default table , let me show :

Jun 6 2021, 9:50 PM · VyOS 1.4 Sagitta
c-po closed T842: Adopt VyOS CLI to latest StrongSwan options and deprecated Keywords, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 6 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po closed T842: Adopt VyOS CLI to latest StrongSwan options and deprecated Keywords, a subtask of T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan, as Resolved.
Jun 6 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po closed T842: Adopt VyOS CLI to latest StrongSwan options and deprecated Keywords as Resolved.
Jun 6 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 6 2021, 5:17 PM · VyOS 1.4 Sagitta
erkin claimed T3459: Inform the user when unable to install outdated image.
Jun 6 2021, 2:21 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX5bca2a9009b0: ipsec: T3588: remove CLI options deprecated by strongSwan.
Jun 6 2021, 1:57 PM
c-po committed rVYOSONEXfbedc0b14440: T1168: ipsec: add copyright header to migration script.
Jun 6 2021, 1:57 PM
erkin committed rVYOSONEXace6cc3b5165: T3356: remote: Add friendly download procedure for user-facing scripts.
Jun 6 2021, 1:49 PM
erkin committed rVYOSONEXdd94e6f1cf76: T3356: remote: Add authentication support.
Jun 6 2021, 1:49 PM
erkin committed rVYOSONEX0aa64e0c260d: T3356: remote: Read username and password from environment variables.
Jun 6 2021, 1:49 PM
erkin committed rVYOSONEXf3072a64a807: T3356: Add progressbars to FTP transfers.
Jun 6 2021, 1:49 PM
erkin committed rVYOSONEX0856dd2f2584: T3356: Add progressbars to SFTP and HTTP transfers.
Jun 6 2021, 1:49 PM
GitHub <noreply@github.com> committed rVYOSONEXf0bceeeb67e0: Merge pull request #846 from erkin/current (authored by c-po).
Jun 6 2021, 1:49 PM
UnicronNL triaged T3601: Error in ssh keys for vmware cloud-init if ssh keys is left empty. as Normal priority.
Jun 6 2021, 1:09 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po committed rVYOSONEX6289ee5ac3e7: Debian: add missing dependency on vyatta-cfg.
Jun 6 2021, 9:37 AM
c-po committed rVYOSONEXfd9032fb7bfc: Debian: add missing dependency on vyatta-cfg.
Jun 6 2021, 9:35 AM
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 6 2021, 9:11 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX4d295da35caa: nhrp: T3599: replace vyos-opennhrp with opennhrp package.
Jun 6 2021, 9:03 AM
sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEXb3bce6497cc2: nhrp: T3599: Migrate NHRP to XML/Python.
Jun 6 2021, 9:01 AM
sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEX68e5ca6b56b2: nhrp: T3599: Remove vpn_ipsec.py from configd until bug is resolved.
Jun 6 2021, 9:01 AM
GitHub <noreply@github.com> committed rVYOSONEXf9c142bab451: Merge pull request #865 from sarthurdev/current (authored by c-po).
Jun 6 2021, 9:01 AM

Jun 5 2021

anthr76 created T3600: DHCP Interface static route breaks PBR.
Jun 5 2021, 11:41 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXc1a450a72aa9: ipsec: T3093: drop superfluous top level priority.
Jun 5 2021, 4:34 PM
sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEXa7ca03799105: ipsec: T2816: Fix typo from refactor.
Jun 5 2021, 6:26 AM
GitHub <noreply@github.com> committed rVYOSONEX71313fb44520: Merge pull request #866 from sarthurdev/fix-ipsec (authored by c-po).
Jun 5 2021, 6:26 AM

Jun 4 2021

sarthurdev changed the status of T3599: Migrate NHRP to XML/Python from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/865

Jun 4 2021, 9:55 PM · VyOS 1.4 Sagitta
c-po added a comment to T3040: NHRP IPv6 Support.

Hi @francis the latest FRR version lacks support for Cisco authentication https://github.com/FRRouting/frr/blob/master/nhrpd/nhrp_peer.c#L1212

Jun 4 2021, 6:33 PM · VyOS 1.5 Circinus
c-po closed T3595: Cannot create new VTI interface, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 4 2021, 5:34 PM · VyOS 1.4 Sagitta
c-po closed T3595: Cannot create new VTI interface as Resolved.
Jun 4 2021, 5:34 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX31d58e7d038d: vti: T3595: error out when adding VTI interface withouth IPSec.
Jun 4 2021, 5:34 PM
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 4 2021, 5:33 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T3599: Migrate NHRP to XML/Python from Open to In progress.
Jun 4 2021, 5:28 PM · VyOS 1.4 Sagitta
francis added a comment to T3040: NHRP IPv6 Support.

@c-po with this merge on FRR https://github.com/FRRouting/frr/pull/8153#event-4589485067 is migration possible? Possibly related to https://phabricator.vyos.net/T2326

Jun 4 2021, 4:45 PM · VyOS 1.5 Circinus
francis added a comment to T2326: Migrate NHRP(DMVPN) to FRR.
Jun 4 2021, 4:44 PM · VyOS 1.5 Circinus
jack9603301 added a comment to T3596: Support wide-dhcp6-relay.

I wonder why this is flagged only as refactoring bit you open an entire new CLI tree.

Jun 4 2021, 2:34 PM
c-po added a comment to T3596: Support wide-dhcp6-relay.

Hi Jack,

Jun 4 2021, 2:04 PM
jack9603301 added a comment to T3596: Support wide-dhcp6-relay.

PR draft: https://github.com/vyos/vyos-1x/pull/863

Jun 4 2021, 1:08 PM
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.123 / 5.10.41 to Update Linux Kernel to v5.4.124 / 5.10.42.
Jun 4 2021, 12:55 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T3195: Add support for cisco style GRE keepalives from Open to Backlog on the VyOS 1.4 Sagitta board.
Jun 4 2021, 12:52 PM · VyOS Rolling
c-po changed the status of T3195: Add support for cisco style GRE keepalives from Open to Needs testing.
Jun 4 2021, 12:52 PM · VyOS Rolling
c-po moved T3195: Add support for cisco style GRE keepalives from Need Triage to Backlog on the VyOS 1.3 Equuleus board.
Jun 4 2021, 12:51 PM · VyOS Rolling
c-po moved T3592: Set default TTL 64 for tunnels from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 4 2021, 12:51 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3592: Set default TTL 64 for tunnels from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 4 2021, 12:50 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3594: Disable by default service strongswan-starter from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 4 2021, 12:50 PM · VyOS 1.4 Sagitta
c-po closed T3592: Set default TTL 64 for tunnels as Resolved.
Jun 4 2021, 12:50 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX5a029892e97a: tunnels: T3592: Set default TTL to 64 (authored by sever-sever <v.gletenko@vyos.io>).
Jun 4 2021, 12:48 PM
c-po moved T3132: Enable egress flow accounting from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 4 2021, 12:39 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX77866ccb1619: flow-accounting: T3132: fix egress iptables chain (authored by jpbede).
Jun 4 2021, 12:39 PM
c-po added a project to T3132: Enable egress flow accounting: VyOS 1.3 Equuleus.
Jun 4 2021, 12:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jpbede committed rVYOSONEX95cc2e4b4c11: flow-accounting: T3132: fix egress iptables chain.
Jun 4 2021, 12:32 PM
GitHub <noreply@github.com> committed rVYOSONEXe0c86b974891: Merge pull request #864 from jpbede/fix-flow-accounting-egress (authored by c-po).
Jun 4 2021, 12:32 PM
sever-sever <v.gletenko@vyos.io> committed rVYOSONEXb4db37507635: tunnels: T3592: Set default TTL to 64.
Jun 4 2021, 12:31 PM
GitHub <noreply@github.com> committed rVYOSONEX5ae12f898eae: Merge pull request #861 from sever-sever/T3592 (authored by c-po).
Jun 4 2021, 12:31 PM

Jun 3 2021

fernando added a comment to T3578: Prefix-List(6) update cause empty prefix-list(6).

Sorry for confusing with the status of the ticket , I wanted to put in pending . I was trying to replicate the issues in a lab environment but it wasn't possible , let me show :

Jun 3 2021, 10:52 PM · VyOS 1.4 Sagitta
rpeterson changed the status of T3233: Interface redirect to dum0 from Invalid to Resolved.

I got it to work with version 1.4-rolling-202105291042. Here's the configuration that works:

Jun 3 2021, 9:59 PM · VyOS 1.4 Sagitta
jpbede added a comment to T3132: Enable egress flow accounting.

@tuxis-ie found the issue. Used the wrong iptables chain. See https://github.com/vyos/vyos-1x/pull/864

Jun 3 2021, 4:37 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 edited a custom field on T3116: Support back-end L4 level load balancing.
Jun 3 2021, 4:10 PM · VyOS 1.4 Sagitta
dmbaturin changed Is it a breaking change? from none to behavior on T3592: Set default TTL 64 for tunnels.
Jun 3 2021, 3:59 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sarthurdev created T3598: DMVPN/IPSec does not work with upstream Strongswan 5.9.
Jun 3 2021, 2:32 PM · VyOS 1.4 Sagitta (1.4.0-GA)
jpbede added a comment to T3132: Enable egress flow accounting.

@tuxis-ie thanks for testing this out. Will check this.

Jun 3 2021, 1:57 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Unknown Object (User) closed T3593: PPPoE server called-sid format does not work as Unknown Status.

Please, backport it to 1.3 rolling https://phabricator.vyos.net/rVYOSONEX4b646c1fb31a1a9f9c9d1658734d478fed5f19f1

Jun 3 2021, 12:36 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
RyVolodya added a comment to T3593: PPPoE server called-sid format does not work.

This bag is present in VyOS version 1.3-beta-202105271929

Jun 3 2021, 12:34 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 changed the subtype of T3596: Support wide-dhcp6-relay from "Bug" to "Feature Request".
Jun 3 2021, 11:21 AM
jack9603301 changed the subtype of T3596: Support wide-dhcp6-relay from "Feature Request" to "Bug".
Jun 3 2021, 10:45 AM
vindenesen added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

I tried to create a custom timeout rule for tcp port 80. First I assumed that everything was fine since the first commit succeeded without error messages. But when I wanted to alter the rule, it failed. Below you see an example where I first create a rule, and then try to delete it. Afterwards any commits regarding custom timeouts fails.

Jun 3 2021, 8:30 AM · VyOS 1.4 Sagitta
c-po added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

Yes, also this part will be migrated in the next couple of weeks as we plan to get rid of all legacy code in the 1.4 release cycle.

Jun 3 2021, 7:42 AM · VyOS 1.4 Sagitta
c-po changed the status of T3595: Cannot create new VTI interface, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, from Open to Confirmed.
Jun 3 2021, 7:40 AM · VyOS 1.4 Sagitta
c-po changed the status of T3595: Cannot create new VTI interface from Open to Confirmed.
Jun 3 2021, 7:40 AM · VyOS 1.4 Sagitta
c-po claimed T3595: Cannot create new VTI interface.
Jun 3 2021, 7:38 AM · VyOS 1.4 Sagitta
jack9603301 closed T3384: Support UDP bandwidth testing as Resolved.
Jun 3 2021, 6:53 AM · VyOS 1.4 Sagitta