Page MenuHomeVyOS Platform
Feed All Stories

Jun 30 2021

rherold added a comment to T3655: NAT doesn't work correctly with VRF.

as I wrote on slack, from my point of view it is a kernel problem. It seems that the conntrack in the kernel detects the packets eben if they come in on an input interface in default and so
the nat code won'T match cause for conntrack the outgoing interface is still eth0 which is in vrf OOBM instead pppoe0.

Jun 30 2021, 1:59 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando added a comment to T3655: NAT doesn't work correctly with VRF.

Hi ruben,

Jun 30 2021, 12:21 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Jun 29 2021

Matwolf added a comment to T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.

upgraded to 1.4-rolling-202106290839 but still not working for my setup...

Jun 29 2021, 10:44 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX31bbac481c53: Debian: T3641: remove absolut path to tcpdump which now resides in /usr/bin.
Jun 29 2021, 7:45 PM
Viacheslav added a comment to T3652: BGP handshake with cisco router ends in timeout.

Is it worked in 1.3/1.2?

Jun 29 2021, 6:49 PM · VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T3593: PPPoE server called-sid format does not work from Unknown Status to Resolved.
Jun 29 2021, 6:42 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX35b2fbbf7dc9: pppoe-server: T3593: Change called-sid position in template (authored by Unknown Object (User)).
Jun 29 2021, 6:41 PM
Unknown Object (User) added a comment to T3408: vyos 1.4 not delivering ipv6 to devices via PPPOE.

Hello @joeudes , it looks like without enabled ppp-option ipv6 it should not work

set service pppoe-server ppp-options ipv6 allow
Jun 29 2021, 6:29 PM · VyOS 1.4 Sagitta
c-po added a comment to T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.

the new build is already available. I am unsure if this works or is even supported by FRR.
Please consult FRR manual and try configuring this manually from vtysh.

Jun 29 2021, 6:26 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T2883: op-mode reset vpn command shows wrong completion.

@Viacheslav it is reproducible in 1.2.7

vyos@vyos:~$ touch file1
vyos@vyos:~$ touch file2
vyos@vyos:~$ touch file3
vyos@vyos:~$ ls
file1  file2  file3
vyos@vyos:~$ reset vpn remote-access user 
Possible completions:
  file1         Terminate specified user's current remote access VPN session(s)
  file2
  file3
Jun 29 2021, 6:17 PM · VyOS 1.2 Crux
Unknown Object (User) added projects to T3405: PPPoE server unit-cache: VyOS 1.3 Equuleus, Restricted Project.
Jun 29 2021, 6:13 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project, VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T3405: PPPoE server unit-cache from Open to Needs testing.
Jun 29 2021, 6:12 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project, VyOS 1.4 Sagitta
c-po committed rVYOSONEX6fdb90a43e91: pppoe-server: T3405: Add interface cache feature (authored by Unknown Object (User)).
Jun 29 2021, 5:58 PM
c-po committed rVYOSONEXb50f2ffb470e: openvpn: T3641: adjust deprecated "openvpn --genkey" command.
Jun 29 2021, 5:58 PM
c-po committed rVYOSONEX065c6b620cb5: pppoe-server: T3405: Add interface cache feature (authored by Unknown Object (User)).
Jun 29 2021, 5:55 PM
Matwolf added a comment to T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.

looking at your configuration I see you set the neighbor using the interface name.
But in that case how does FFR know which IP address to connect to initiate a BGP session? Works in passive mode only?

Jun 29 2021, 5:22 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3642: PKI configuration.

PR is in: https://github.com/vyos/vyos-1x/pull/901

Jun 29 2021, 4:39 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po closed T1441: Add support for IPSec XFRM interfaces as Resolved.
Jun 29 2021, 4:38 PM · VyOS 1.4 Sagitta
c-po changed Is it a breaking change? from none to validation on T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.
Jun 29 2021, 4:36 PM · VyOS 1.4 Sagitta
c-po changed Version from -VyOS 1.4-rolling-202106260417 to 1.4-rolling-202106260417 on T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.
Jun 29 2021, 4:36 PM · VyOS 1.4 Sagitta
c-po closed T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses as Resolved.
Jun 29 2021, 4:36 PM · VyOS 1.4 Sagitta
c-po added a comment to T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.

Bug confirmed and fixed,

Jun 29 2021, 4:36 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX6152084f5f49: smoketest: bgp: T3657: test ipv6 link-local peering.
Jun 29 2021, 4:34 PM
c-po committed rVYOSONEX0751065ffa21: ipsec: T1441: switch from vti to xfrm interfaces.
Jun 29 2021, 4:34 PM
c-po committed rVYOSONEX5a5c0cd2e6f5: bgp: T3657: fix remote-as validator for IPv6 link-local peering.
Jun 29 2021, 4:34 PM
ernstjo updated the task description for T3652: BGP handshake with cisco router ends in timeout.
Jun 29 2021, 3:00 PM · VyOS 1.4 Sagitta
ernstjo added a comment to T3652: BGP handshake with cisco router ends in timeout.

I haven't access to the Cisco one because that is configured by another provider:

Jun 29 2021, 3:00 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T3651: Move certbot request to op-mode.
Jun 29 2021, 2:04 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
ropeguru added a comment to T1229: Add support for unencrypted L2TPv2 client connections.

Should I hold out any hope for this to be implemented? Still willing to help test and do whatever I can to get this in.

Jun 29 2021, 12:41 PM · VyOS Rolling
sarthurdev changed the status of T3642: PKI configuration, a subtask of T2799: VyOS Certificates Manager, from Open to In progress.
Jun 29 2021, 12:37 PM · VyOS 1.3 Equuleus (1.3.6)
sarthurdev changed the status of T3642: PKI configuration from Open to In progress.

I should soon have a PR ready for this, including an update to IPSec config to show how to port existing configs to use PKI.

Jun 29 2021, 12:37 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
zsdc assigned T3655: NAT doesn't work correctly with VRF to fernando.
Jun 29 2021, 12:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
dmbaturin added a comment to T3642: PKI configuration.

I like the design!

Jun 29 2021, 11:31 AM · VyOS 1.4 Sagitta (1.4.0-epa1)

Jun 28 2021

fernando added a comment to T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.
In T3657#97243, @c-po wrote:

I wonder why you use ebgp multihop wirh link local addresses?

I used it only for testing (but this command increment ttl in two).

Jun 28 2021, 7:39 PM · VyOS 1.4 Sagitta
c-po changed the status of T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses from Open to Confirmed.
Jun 28 2021, 7:07 PM · VyOS 1.4 Sagitta
c-po added a comment to T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.

even if FRR manual states the deprecation notice, we have our own layer of abstraction and will deal with it once it is required.
For the time beeing, I just checked the commands (using tab completion).

Jun 28 2021, 6:59 PM · VyOS 1.4 Sagitta
Matwolf added a comment to T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.
In T3657#97243, @c-po wrote:

Also FRR manual states:

When you connect to a BGP peer over an IPv6 link-local address, you have to specify the IFNAME of the interface used for the connection. T

Please try set protocols bgp neighbor <addr> interface eth1

Jun 28 2021, 6:36 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T3655: NAT doesn't work correctly with VRF from "Task" to "Bug".
Jun 28 2021, 5:56 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T3076: Router reboot adds unwanted 'conntrack-sync mcast-group '225.0.0.50'' line to configuration.

For 1.2.7 it adds unexpected multicast group per "save"
Configs for reproduce:

Jun 28 2021, 5:46 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po added a comment to T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.

I wonder why you use ebgp multihop wirh link local addresses?

Jun 28 2021, 5:45 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3045: Changes to Conntrack-Sync don't apply correctly (Mutlicast->UDP).

To reproduce (VyOS 1.3-beta-202106271614):

Jun 28 2021, 5:00 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.2 Crux (VyOS 1.2.9)
stepler added a comment to T3240: Support per-interface DHCPv6 DUIDs.

Verified working in GNS3 on 1.3.0-rc4. Note that /var/lib/dhcpv6/dhcp6c_duid is not used if send client-id is configured.

Jun 28 2021, 5:00 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a project to T3045: Changes to Conntrack-Sync don't apply correctly (Mutlicast->UDP): VyOS 1.2 Crux (VyOS 1.2.8).
Jun 28 2021, 4:46 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav edited projects for T3045: Changes to Conntrack-Sync don't apply correctly (Mutlicast->UDP), added: VyOS 1.3 Equuleus; removed VyOS 1.2 Crux.
Jun 28 2021, 4:45 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a subtask for T3076: Router reboot adds unwanted 'conntrack-sync mcast-group '225.0.0.50'' line to configuration: T3045: Changes to Conntrack-Sync don't apply correctly (Mutlicast->UDP).
Jun 28 2021, 4:45 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a parent task for T3045: Changes to Conntrack-Sync don't apply correctly (Mutlicast->UDP): T3076: Router reboot adds unwanted 'conntrack-sync mcast-group '225.0.0.50'' line to configuration.
Jun 28 2021, 4:45 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.2 Crux (VyOS 1.2.9)
SrividyaA added a comment to T3656: IPSec 1.4 : "show vpn ike sa" does not show the correct default ike version.

Parent Task: https://phabricator.vyos.net/T2816

Jun 28 2021, 4:38 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T3076: Router reboot adds unwanted 'conntrack-sync mcast-group '225.0.0.50'' line to configuration, added: VyOS 1.2 Crux (VyOS 1.2.8), VyOS 1.3 Equuleus; removed VyOS 1.2 Crux.
Jun 28 2021, 4:05 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
fernando added a comment to T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.

I add an extra commentary , it is config on FRR:

Jun 28 2021, 2:47 PM · VyOS 1.4 Sagitta
rherold added a comment to T3655: NAT doesn't work correctly with VRF.

As requested the config{F1499926}

Jun 28 2021, 2:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
SrividyaA added a comment to T3656: IPSec 1.4 : "show vpn ike sa" does not show the correct default ike version.

I have tried one more scenario:

Jun 28 2021, 2:18 PM · VyOS 1.4 Sagitta
SrividyaA updated the task description for T3656: IPSec 1.4 : "show vpn ike sa" does not show the correct default ike version.
Jun 28 2021, 1:51 PM · VyOS 1.4 Sagitta
fernando created T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.
Jun 28 2021, 1:45 PM · VyOS 1.4 Sagitta
SrividyaA created T3656: IPSec 1.4 : "show vpn ike sa" does not show the correct default ike version.
Jun 28 2021, 11:26 AM · VyOS 1.4 Sagitta
Viacheslav closed T3567: Building Crux from Docker Image failing to download repo index as Resolved.
Jun 28 2021, 10:53 AM · VyOS 1.2 Crux, vyos-build
Viacheslav closed T3627: Building Crux from Docker image failing as Resolved.
Jun 28 2021, 10:52 AM · VyOS 1.2 Crux, vyos-build
Matwolf added a comment to T941: BGP neighbours with IPv6 link-local addresses.

Hi, any updates on this?

Jun 28 2021, 10:00 AM · VyOS 1.3 Equuleus (1.3.9), test
rherold created T3655: NAT doesn't work correctly with VRF.
Jun 28 2021, 9:57 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T3648: op-mode: nat rules broken.

Doesn't work, VyOS 1.4-rolling-202106271939

Jun 28 2021, 9:19 AM · VyOS 1.4 Sagitta

Jun 27 2021

klipz created T3654: 1.2.7 - OpenVPN tunnel interface disappears on virtualized VyOS router/ESXi host.
Jun 27 2021, 8:26 PM · VyOS 1.2 Crux (VyOS 1.2.9)
UnicronNL closed T3653: Cloudinit subnet error if a cidr (/24) is used instead of a subnet mask (255.255.255.0) as Resolved.
Jun 27 2021, 6:54 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a project to T3627: Building Crux from Docker image failing: VyOS 1.2 Crux.
Jun 27 2021, 3:50 PM · VyOS 1.2 Crux, vyos-build
jack9603301 triaged T3648: op-mode: nat rules broken as Low priority.
Jun 27 2021, 3:19 PM · VyOS 1.4 Sagitta
jack9603301 changed the subtype of T3648: op-mode: nat rules broken from "Task" to "Bug".
Jun 27 2021, 3:19 PM · VyOS 1.4 Sagitta
UnicronNL updated the task description for T3653: Cloudinit subnet error if a cidr (/24) is used instead of a subnet mask (255.255.255.0).
Jun 27 2021, 3:19 PM · VyOS 1.2 Crux (VyOS 1.2.8)
UnicronNL triaged T3653: Cloudinit subnet error if a cidr (/24) is used instead of a subnet mask (255.255.255.0) as Urgent! priority.
Jun 27 2021, 3:18 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po committed rVYOSONEX09efa0550dd1: op-mode: bond: T2546: implement "show interface bond * slaves" command.
Jun 27 2021, 9:14 AM
c-po added a comment to T2770: Allow any character to be used in the SNMP community field.

What would be the "full set" up supported characters? If I remember correctly this regex is inherited from VyOS 1.1

Jun 27 2021, 7:42 AM · VyOS Rolling
c-po moved T2770: Allow any character to be used in the SNMP community field from Open to Backlog on the VyOS 1.4 Sagitta board.
Jun 27 2021, 7:42 AM · VyOS Rolling
c-po moved T3651: Move certbot request to op-mode from Open to Backlog on the VyOS 1.4 Sagitta board.
Jun 27 2021, 7:42 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
c-po added a comment to T3652: BGP handshake with cisco router ends in timeout.

Please share your Cisco and VyOS config, and also the Cisco router Model/Version

Jun 27 2021, 7:41 AM · VyOS 1.4 Sagitta
ernstjo updated the task description for T3652: BGP handshake with cisco router ends in timeout.
Jun 27 2021, 12:43 AM · VyOS 1.4 Sagitta
ernstjo created T3652: BGP handshake with cisco router ends in timeout.
Jun 27 2021, 12:42 AM · VyOS 1.4 Sagitta
raphielscape added a comment to T2869: Intel ethernet driver defaults sub-optimal.

For RPS, we maybe can adapt https://github.com/bhuanand/rps-rfs-configuration to VyOS?

Jun 27 2021, 12:03 AM

Jun 26 2021

GitHub <noreply@github.com> committed rVYOSONEXd34cd9572dd6: Debian: disable systemd salt-minion configuration - all handled in vyos-build (authored by c-po).
Jun 26 2021, 9:39 PM
GitHub <noreply@github.com> committed rVYOSONEXefcce444dbc0: Debian: ensure path for vyos-postconfig-bootup.script exists (authored by c-po).
Jun 26 2021, 9:37 PM
c-po committed rVYOSONEX707fe801eac4: Debian: drop ipsec key removal from postinst script - done on every system boot.
Jun 26 2021, 9:00 PM
c-po committed rVYOSONEXc121218b4883: Import vyos-postconfig-bootup.script from vyatta-cfg-system.
Jun 26 2021, 9:00 PM
c-po committed rVYOSONEX0f6ec4722215: Import configuration files from vyatta-cfg-system.
Jun 26 2021, 9:00 PM
c-po committed rVYOSONEX87c7a1243e0b: Debian: no need to disable salt-minion in postinst script.
Jun 26 2021, 8:12 PM
c-po committed rVYOSONEX120b866bf28f: Import sudoers configuration from vyatta-cfg-system.
Jun 26 2021, 8:12 PM
c-po committed rVYOSONEX2124089f7d83: banner: T2135: adjust to raw strings from vyatta-cfg repo.
Jun 26 2021, 7:32 PM
jestabro added a subtask for T2289: Denest cerbot certificate configuration from service https: T3651: Move certbot request to op-mode.
Jun 26 2021, 6:52 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
jestabro added a parent task for T3651: Move certbot request to op-mode: T2289: Denest cerbot certificate configuration from service https.
Jun 26 2021, 6:52 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
jestabro created T3651: Move certbot request to op-mode.
Jun 26 2021, 6:51 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
c-po committed rVYOSONEX3d2f2ca9696c: banner: T2135: adjust to raw strings from vyatta-cfg repo.
Jun 26 2021, 5:56 PM
sarthurdev added a comment to T3642: PKI configuration.

When using show pki ... commands you would be able to see the relation between certificates and CAs.

Jun 26 2021, 5:27 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po committed rVYOSONEXf98bad44fc9c: nat: T1083: fix Jinja2 templating error.
Jun 26 2021, 2:57 PM
Viacheslav changed the status of T3648: op-mode: nat rules broken from Open to Needs testing.
Jun 26 2021, 2:04 PM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX166d44b32813: nat: T1083: add translation options for persistent/random mapping of address… (authored by hard).
Jun 26 2021, 7:48 AM
c-po closed T3586: Tunnel/Wireguard/VTI: replace random get_mac function with addrgenmode as Invalid.
Jun 26 2021, 7:43 AM · VyOS 1.4 Sagitta
c-po added a comment to T3586: Tunnel/Wireguard/VTI: replace random get_mac function with addrgenmode.

THis is infact only relevant when IPv6 addressing is used.

Jun 26 2021, 7:39 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX3ffe114e8e89: openvpn: T3641: adjust deprecated "openvpn --genkey" command.
Jun 26 2021, 7:34 AM
c-po committed rVYOSONEXa6b526fd9826: ipsec: T3643: us vyos.util.copy_file() over raw UNIX cp command.
Jun 26 2021, 7:25 AM
c-po committed rVYOSONEX5303ec39f6f0: vyos.util: add new helper copy_file().
Jun 26 2021, 7:25 AM
c-po committed rVYOSONEX8108ca69e7d8: ipsec: T3643: use variable for path names.
Jun 26 2021, 7:25 AM
c-po added a reverting change for rVYOSONEX95bbbb8bed92: ipsec: T3643: move swanctl.conf to /run: rVYOSONEX03e1d273acf3: Revert "ipsec: T3643: move swanctl.conf to /run".
Jun 26 2021, 7:25 AM
c-po committed rVYOSONEX03e1d273acf3: Revert "ipsec: T3643: move swanctl.conf to /run".
Jun 26 2021, 7:25 AM

Jun 25 2021

jack9603301 committed rVYOSONEXe2561b55c66c: nat: nat66: T3648: Fix script logic errors and missing logic handling.
Jun 25 2021, 8:56 PM
GitHub <noreply@github.com> committed rVYOSONEX037aa93f4936: Merge pull request #899 from jack9603301/T3648 (authored by c-po).
Jun 25 2021, 8:56 PM