Page MenuHomeVyOS Platform
Feed All Stories

Jun 13 2021

c-po moved T3358: VRRP: Is it necessary to support switches between master and backup with script? from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 13 2021, 11:20 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3602: Renaming BGP Peer Groups Leaves Router Broken from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 13 2021, 11:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T3609: BGP Peer Group Changes Slow from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 13 2021, 11:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T3619: Performance Degradation 1.2 --> 1.3 | High ksoftirqd CPU usage from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Jun 13 2021, 11:20 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3620: Rename WWAN interface from wirelessmodem to wwan to use QMI interface from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 13 2021, 11:20 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po closed T3620: Rename WWAN interface from wirelessmodem to wwan to use QMI interface as Resolved.
Jun 13 2021, 11:20 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX7065d0c4fe08: wwan: T3620: reorder mirgation scripts for 1.3 backport.
Jun 13 2021, 11:18 AM
c-po committed rVYOSONEX0352aa560122: wwan: T3620: adjust NAT inbound/outbound interfaces on config migration.
Jun 13 2021, 11:13 AM
c-po committed rVYOSONEXa95d3dd5c43e: wwan: T3620: fix backup route metric in migration script.
Jun 13 2021, 11:13 AM
c-po committed rVYOSONEX8a98235b5d7f: wwan: T3620: rename "wirelessmodem wlm" interfaces to new wwan interface tree.
Jun 13 2021, 11:13 AM
c-po moved T3598: DMVPN/IPSec does not work with upstream Strongswan 5.9 from Open to In Progress on the VyOS 1.4 Sagitta board.
Jun 13 2021, 9:27 AM · VyOS 1.4 Sagitta (1.4.0-GA)
c-po moved T3599: Migrate NHRP to XML/Python from Open to In Progress on the VyOS 1.4 Sagitta board.
Jun 13 2021, 9:27 AM · VyOS 1.4 Sagitta
c-po moved T3606: SNMP unknown notification OID from Open to In Progress on the VyOS 1.4 Sagitta board.
Jun 13 2021, 9:27 AM · VyOS 1.4 Sagitta
c-po moved T3620: Rename WWAN interface from wirelessmodem to wwan to use QMI interface from Open to In Progress on the VyOS 1.4 Sagitta board.
Jun 13 2021, 9:27 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po closed T2173: Add the ability to use VRF on VTI interfaces, a subtask of T2579: The root task for VRF features, as Resolved.
Jun 13 2021, 9:27 AM · VyOS 1.3 Equuleus (1.3.6)
c-po closed T2173: Add the ability to use VRF on VTI interfaces, a subtask of T1888: Update to StrongSwan 5.9.1, as Resolved.
Jun 13 2021, 9:27 AM · VyOS 1.4 Sagitta
c-po closed T2173: Add the ability to use VRF on VTI interfaces, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 13 2021, 9:27 AM · VyOS 1.4 Sagitta
c-po closed T2173: Add the ability to use VRF on VTI interfaces as Resolved.
Jun 13 2021, 9:27 AM · VyOS 1.4 Sagitta
c-po added a comment to T2173: Add the ability to use VRF on VTI interfaces.

@zsdc thanks for confirming. Re-added CLI node

Jun 13 2021, 9:26 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX5c47a1bdb5f5: vti: T2173: add VRF support for virtual tunnel interfaces.
Jun 13 2021, 9:26 AM
c-po committed rVYOSONEXe24e35e1ac11: wwan: T3620: adjust NAT inbound/outbound interfaces on config migration.
Jun 13 2021, 9:06 AM
c-po committed rVYOSONEXd20dd7a0e6af: wwan: T3620: fix backup route metric in migration script.
Jun 13 2021, 8:31 AM
c-po committed rVYOSONEXc2a1c071e7d0: wwan: T3620: rename "wirelessmodem wlm" interfaces to new wwan interface tree.
Jun 13 2021, 7:36 AM
sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEX0b1695221657: ipsec: T57: Support disable on peer, tunnel, dmvpn profile.
Jun 13 2021, 7:00 AM
GitHub <noreply@github.com> committed rVYOSONEXc88d8999873d: Merge pull request #877 from sarthurdev/disable_peer_tunnel (authored by c-po).
Jun 13 2021, 7:00 AM
GitHub <noreply@github.com> committed rVYOSONEX97f5e8562f3a: GitHub: fix yaml typo in PR conflict workflow (authored by c-po).
Jun 13 2021, 6:59 AM

Jun 12 2021

sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEX6c7e22e730da: ipsec: T1501: Use vyos.validate.is_ipv6_link_local.
Jun 12 2021, 9:27 PM
GitHub <noreply@github.com> committed rVYOSONEX198c25432227: Merge pull request #876 from sarthurdev/link_local (authored by c-po).
Jun 12 2021, 9:27 PM
c-po closed T1534: IPSec w/ IKEv2 Invalid local-address "any", a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 12 2021, 9:13 PM · VyOS 1.4 Sagitta
c-po closed T1534: IPSec w/ IKEv2 Invalid local-address "any" as Resolved.
Jun 12 2021, 9:13 PM · VyOS 1.4 Sagitta
sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEXab5bfe76044f: ipsec: T1501: T3617: Add handling for missing addresses on boot when using dhcp….
Jun 12 2021, 8:49 PM
sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEX8ea648e482cf: smoketest: ipsec: T1501: Add smoketest for failed dhcp-interface scenario.
Jun 12 2021, 8:49 PM
GitHub <noreply@github.com> committed rVYOSONEX5d687daba3a3: Merge pull request #875 from sarthurdev/dhcp_address_wait (authored by c-po).
Jun 12 2021, 8:49 PM
sarthurdev added a comment to T1501: VPN Commit Errors.

PR: https://github.com/vyos/vyos-1x/pull/875

Jun 12 2021, 7:21 PM · VyOS 1.3 Equuleus (1.3.0), test
c-po changed the status of T3620: Rename WWAN interface from wirelessmodem to wwan to use QMI interface from Open to In progress.
Jun 12 2021, 5:36 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po closed T3611: WWAN interface (MC7710) no longer works on Kernel 5.10, a subtask of T3620: Rename WWAN interface from wirelessmodem to wwan to use QMI interface, as Resolved.
Jun 12 2021, 5:35 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po closed T3611: WWAN interface (MC7710) no longer works on Kernel 5.10 as Resolved.
Jun 12 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po added a comment to T3611: WWAN interface (MC7710) no longer works on Kernel 5.10.

Works with implementation of T3620

Jun 12 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po added a parent task for T3611: WWAN interface (MC7710) no longer works on Kernel 5.10: T3620: Rename WWAN interface from wirelessmodem to wwan to use QMI interface.
Jun 12 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po added a subtask for T3620: Rename WWAN interface from wirelessmodem to wwan to use QMI interface: T3611: WWAN interface (MC7710) no longer works on Kernel 5.10.
Jun 12 2021, 5:35 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po created T3620: Rename WWAN interface from wirelessmodem to wwan to use QMI interface.
Jun 12 2021, 5:34 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro moved T3616: Update to FastAPI causes regression in vyos-http-api-server from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 12 2021, 5:21 PM · VyOS 1.4 Sagitta
jestabro edited a custom field on T3616: Update to FastAPI causes regression in vyos-http-api-server.
Jun 12 2021, 5:03 PM · VyOS 1.4 Sagitta
jestabro closed T3616: Update to FastAPI causes regression in vyos-http-api-server as Resolved.
Jun 12 2021, 5:03 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T3616: Update to FastAPI causes regression in vyos-http-api-server.
Jun 12 2021, 5:02 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T3616: Update to FastAPI causes regression in vyos-http-api-server.
Jun 12 2021, 5:01 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX3a9041e2d4d4: http-api: T3616: update for strict content-type check in FastAPI 0.65.2.
Jun 12 2021, 4:57 PM
srnoth created T3619: Performance Degradation 1.2 --> 1.3 | High ksoftirqd CPU usage.
Jun 12 2021, 4:24 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po claimed T3606: SNMP unknown notification OID.
Jun 12 2021, 3:45 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX5bdae44e36f6: xml: op-mode: add "show log kernel".
Jun 12 2021, 11:19 AM
c-po committed rVYOSONEX5cf4c64207b6: GitHub: add workflow to check for PR conflicts.
Jun 12 2021, 11:19 AM
c-po committed rVYOSONEX550cea8e88f1: xml: op-mode: add "show log kernel".
Jun 12 2021, 11:19 AM
trae32566 closed T3609: BGP Peer Group Changes Slow as Resolved.

This appears to be fixed in the most recent rolling releases; I'm not sure how, but it's fixed.

Jun 12 2021, 7:20 AM · VyOS 1.3 Equuleus (1.3.0)
gmzamz updated gmzamz.
Jun 12 2021, 4:11 AM

Jun 11 2021

sarthurdev added a comment to T645: Allow multiple prefixes in ipsec tunnel.

Included in PR: https://github.com/vyos/vyos-1x/pull/881

Jun 11 2021, 8:45 PM · VyOS 1.4 Sagitta
acrane1 added a subtask for T2816: Rewrite IPsec scripts with the new XML/Python approach: Unknown Object (Maniphest Task).
Jun 11 2021, 7:47 PM · VyOS 1.4 Sagitta
jestabro lowered the priority of T3616: Update to FastAPI causes regression in vyos-http-api-server from Urgent! to High.
Jun 11 2021, 7:43 PM · VyOS 1.4 Sagitta
zsdc raised the priority of T2173: Add the ability to use VRF on VTI interfaces from Normal to High.

It also works with the current VTI interfaces (sudo ip l set vti1 vrf VRF1).

Jun 11 2021, 7:33 PM · VyOS 1.4 Sagitta
acrane1 merged task T3618: generate invalid configuration files into Restricted Maniphest Task.
Jun 11 2021, 7:12 PM
acrane1 changed the status of T3618: generate invalid configuration files from Open to Confirmed.
Jun 11 2021, 7:11 PM
jestabro added a comment to T3616: Update to FastAPI causes regression in vyos-http-api-server.
Jun 11 2021, 6:58 PM · VyOS 1.4 Sagitta
jestabro triaged T3616: Update to FastAPI causes regression in vyos-http-api-server as Urgent! priority.
Jun 11 2021, 6:49 PM · VyOS 1.4 Sagitta
krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

It's a bit confusing, I can create a tunnel with 0.0.0.0/0 if I need it. That how it is also done on PaloAlto FW and Fortigate. Anyway, it is just my opinion. Thanks for picking up this request so quickly.

Jun 11 2021, 5:15 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

I've left vti esp-group to keep backwards compatibility with current behaviour when vti is configured without any tunnels (when it uses 0.0.0.0/0), in that scenario it would still use the group specified.

Jun 11 2021, 5:00 PM · VyOS 1.4 Sagitta
krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@sdev That makes sense, you can also get rid of "esp-group" under vti as it will be specified per tunnel.
I like that we can specify multiple prefixes under one tunnel but also can configure multiple tunnels for more complex scenarios.

Jun 11 2021, 4:43 PM · VyOS 1.4 Sagitta
Viacheslav closed T3614: Container network name with hyphen fail as Resolved.
Jun 11 2021, 4:34 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

I wonder if instead it should just use the existing tunnel node for this. So if VTI is set on a peer, all configured tunnels get marked for the VTI interface. Current VyOS behaviour allows only for tunnels, or VTI - not both.

Jun 11 2021, 4:27 PM · VyOS 1.4 Sagitta
sever-sever <v.gletenko@vyos.io> committed rVYOSONEXc22c4e90f762: containers: T3614: Fix for network names with hyphen.
Jun 11 2021, 2:07 PM
GitHub <noreply@github.com> committed rVYOSONEX7c2270d298c7: Merge pull request #873 from sever-sever/T3614 (authored by c-po).
Jun 11 2021, 2:07 PM
Viacheslav added a comment to T3614: Container network name with hyphen fail.

PR https://github.com/vyos/vyos-1x/pull/873

Jun 11 2021, 12:46 PM · VyOS 1.4 Sagitta
Viacheslav claimed T3614: Container network name with hyphen fail.
Jun 11 2021, 12:22 PM · VyOS 1.4 Sagitta
Viacheslav created T3614: Container network name with hyphen fail.
Jun 11 2021, 12:21 PM · VyOS 1.4 Sagitta
krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@sdev Yes, this can be done identically as the tunnel definition.

Jun 11 2021, 12:19 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@krox2 Oh I think I understand what you mean. You'd want to also be able to create multiple child SAs each with unique left/right subnets?

Jun 11 2021, 11:45 AM · VyOS 1.4 Sagitta
trae32566 reopened T3563: commit-archive breaks with IPv6 source addresses, a subtask of T3356: Script for remote file transfers, as Open.
Jun 11 2021, 9:45 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
trae32566 reopened T3563: commit-archive breaks with IPv6 source addresses as "Open".

This does not appear to be fixed; I think it's something specific to 1.4:

trae@cr01a-vyos# commit
Using source address fd52:d62e:8011:fffe:192:168:253:2
Archiving config...
  sftp://stor01z-rh8.int.trae32566.org:/int/cr01a-vyos Traceback (most recent call last):
  File "<string>", line 1, in <module>
  File "/usr/lib/python3/dist-packages/vyos/remote.py", line 287, in upload
    upload_sftp(local_path, url.hostname, url.path, username, password, port, source, progressbar)
  File "/usr/lib/python3/dist-packages/vyos/remote.py", line 166, in upload_sftp
    transfer_sftp('upload', *args, **kwargs)
  File "/usr/lib/python3/dist-packages/vyos/remote.py", line 162, in transfer_sftp
    sock.shutdown()
TypeError: shutdown() takes exactly one argument (0 given)
[edit policy route-map BGP-BACKBONE-OUT]
trae@cr01a-vyos# run show ver
Jun 11 2021, 9:45 AM · VyOS 1.4 Sagitta
trae32566 added a comment to T3378: commit-archive source-address broken for IPv6 addresses.

I have a similar problem, but different, in T3563. I've reopened it and added information, but basically 1.4 still has the issue reported in that bug report.

Jun 11 2021, 9:43 AM · VyOS 1.3 Equuleus (1.3.0)
afics added a comment to T3195: Add support for cisco style GRE keepalives.

See [1] from the previous post:

Note: If you don't want to install anything and don't care about some potential security problems, just enable the following 2 options to get native GRE keepalive support on Linux: […]

I care. Setting these sysctl parameters allows for relaying arbitrary traffic through the router.

Jun 11 2021, 9:43 AM · VyOS Rolling

Jun 10 2021

krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@sdev Will it not create a full mesh, for example:
10.10.10.0/24 <--> 192.168.10.0/24
10.10.20.0/24 <--> 192.168.20.0/24
It will also set IPsec for 10.10.10.0/24 <--> 192.168.20.0/24 and 10.10.20.0/24 <--> 192.168.10.0/24 that may not be desired.

Jun 10 2021, 11:09 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

PR https://github.com/vyos/vyos-1x/pull/881

Jun 10 2021, 10:20 PM · VyOS 1.4 Sagitta
krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@Viacheslav Can be similar to policy-based ipsec

# set vpn ipsec site-to-site peer 1.1.1.1 tunnel 1 
Possible completions:
   allow-nat-networks
                Option to allow NAT networks
   allow-public-networks
                Option to allow public networks
   disable      Option to disable vpn tunnel
   esp-group    ESP group name
 > local        Local parameters for interesting traffic
   protocol     Protocol to encrypt
 > remote       Remote parameters for interesting traffic
Jun 10 2021, 9:07 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@krox2 How should looks like a configuration for many local/remote traffic selectors per one vti interface?

Jun 10 2021, 8:46 PM · VyOS 1.4 Sagitta
Viacheslav awarded T3613: Selectors for route-based IPsec tunnel (vti) a Like token.
Jun 10 2021, 8:37 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2816: Rewrite IPsec scripts with the new XML/Python approach: T3613: Selectors for route-based IPsec tunnel (vti).
Jun 10 2021, 8:36 PM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3613: Selectors for route-based IPsec tunnel (vti): T2816: Rewrite IPsec scripts with the new XML/Python approach.
Jun 10 2021, 8:36 PM · VyOS 1.4 Sagitta
krox2 updated the task description for T3613: Selectors for route-based IPsec tunnel (vti).
Jun 10 2021, 8:19 PM · VyOS 1.4 Sagitta
krox2 updated the task description for T3613: Selectors for route-based IPsec tunnel (vti).
Jun 10 2021, 8:18 PM · VyOS 1.4 Sagitta
krox2 created T3613: Selectors for route-based IPsec tunnel (vti).
Jun 10 2021, 8:17 PM · VyOS 1.4 Sagitta
Viacheslav closed T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting as Resolved.
Jun 10 2021, 8:16 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav closed T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 10 2021, 8:16 PM · VyOS 1.4 Sagitta
Viacheslav moved T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting from Backport Candidates to Finished on the VyOS 1.3 Equuleus board.
Jun 10 2021, 8:16 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po committed rVYOSONEX8198cbaa4cf9: xml: ssh: move user/group definition to includable files.
Jun 10 2021, 7:36 PM
c-po committed rVYOSONEX556e03922f78: xml: ssh: move user/group definition to includable files.
Jun 10 2021, 7:36 PM
c-po committed rVYOSONEX1be388a66b0c: vpn: ipsec: T3093: remove leading whitespaces from XML includes.
Jun 10 2021, 7:36 PM
c-po changed the status of T3250: PPPoE server: wrong local usernames from Unknown Status to Resolved.
Jun 10 2021, 7:24 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3250: PPPoE server: wrong local usernames from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2021, 7:24 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3250: PPPoE server: wrong local usernames from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 10 2021, 7:24 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX775eaa3f20c5: pppoe: T3250: Not mangle values for tag nodes (authored by sever-sever <v.gletenko@vyos.io>).
Jun 10 2021, 7:24 PM
jestabro added a comment to T3250: PPPoE server: wrong local usernames.

Already backported: ff7b2b0e62510ef8de28c9c4bfa34badeabec775

Jun 10 2021, 6:59 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po renamed T3483: Update Linux Kernel to v4.19.195 from Update Linux Kernel to v4.19.190 to Update Linux Kernel to v4.19.194.
Jun 10 2021, 5:58 PM · VyOS 1.2 Crux (VyOS 1.2.8)