Page MenuHomeVyOS Platform
Feed Search

Jul 18 2021

c-po merged T3684: Bridge doesn't show stp states / macs into T3667: brctl is damaged.
Jul 18 2021, 2:02 PM · VyOS 1.4 Sagitta
c-po merged task T3684: Bridge doesn't show stp states / macs into T3667: brctl is damaged.
Jul 18 2021, 2:02 PM · VyOS 1.4 Sagitta
c-po added a comment to T3684: Bridge doesn't show stp states / macs .

Can you please try running this test on a more recent VyOS version?

Jul 18 2021, 2:01 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX13dfa7e0756b: bridge: remove obsolete helper script.
Jul 18 2021, 1:59 PM

Jul 17 2021

c-po changed the status of T3684: Bridge doesn't show stp states / macs from Open to Confirmed.
Jul 17 2021, 10:05 PM · VyOS 1.4 Sagitta
c-po added a comment to T3684: Bridge doesn't show stp states / macs .

brctl is a deprecated package and superseeded by iproute2. Commands will be adjusted, thanks for reporting.

Jul 17 2021, 10:05 PM · VyOS 1.4 Sagitta
c-po claimed T3684: Bridge doesn't show stp states / macs .
Jul 17 2021, 10:04 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXc8639be885e1: ipsec: T2816: add missing +x permission on Python helper.
Jul 17 2021, 8:34 PM
c-po added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

You can find the test here: https://github.com/vyos/vyos-1x/blob/current/smoketest/scripts/cli/test_interfaces_openvpn.py

Jul 17 2021, 6:50 PM · Invalid
c-po committed rVYOSONEX94531412e730: ipsec: T2816: restore erroneous deleted file.
Jul 17 2021, 6:14 PM
c-po added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

Unfortunately I had to revert this PR as it broke the smoketests and also triggered the following OpenVPN error:

Jul 17 2021, 5:20 PM · Invalid
c-po committed rVYOSONEX363d8fb22c98: Revert "openvpn: T56: remove strict checks for tls cert-file and key-file".
Jul 17 2021, 5:19 PM
c-po added a reverting change for rVYOSONEXc414479fdf1d: openvpn: T56: remove strict checks for tls cert-file and key-file: rVYOSONEX363d8fb22c98: Revert "openvpn: T56: remove strict checks for tls cert-file and key-file".
Jul 17 2021, 5:19 PM
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.131 / 5.10.49 to Update Linux Kernel to v5.4.132 / 5.10.50.
Jul 17 2021, 7:16 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEX3c7f7fea1956: vxlan: T3683: bugfix on MTU calculation for IPv6 underlay.
Jul 17 2021, 7:15 AM
c-po committed rVYOSONEXeb8cd3af91ba: vxlan: T3683: bugfix on MTU calculation for IPv6 underlay.
Jul 17 2021, 7:13 AM
c-po committed rVYOSONEX6a8080e1c0a7: xml: provide common "pre-shared-secret" include block.
Jul 17 2021, 7:13 AM
c-po committed rVYOSONEX227391443df0: ipsec: T2816: migrate "ipsec interfaces" to "interface".
Jul 17 2021, 7:13 AM
c-po committed rVYOSONEXed361a825407: xml: provide common "dhcp-interface" include block.
Jul 17 2021, 7:13 AM

Jul 15 2021

c-po committed rVYOSONEXa2ff17e46ec0: vyos-1x-vmware: T3682: remove dhclient from ether-resume.py (authored by yun).
Jul 15 2021, 3:52 AM

Jul 13 2021

c-po added a comment to T3680: Static routes with dhcp-interface are flaky.

Most likely related to T3505

Jul 13 2021, 9:06 PM · VyOS 1.4 Sagitta (1.4.4)

Jul 12 2021

c-po added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

thanks for your detailed bisection of this issue. You mind submitting a GitHub PullRequest as per https://docs.vyos.io/en/equuleus/contributing/development.html?

Jul 12 2021, 6:56 PM · Invalid
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.129 / 5.10.47 to Update Linux Kernel to v5.4.131 / 5.10.49.
Jul 12 2021, 4:45 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T3661: [vrf} route-leaking missing command as Invalid.
Jul 12 2021, 4:41 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX83721c1ce672: vrf: T31: remove supefluous new-lines for each VRF instance.
Jul 12 2021, 4:41 PM
c-po committed rVYOSONEX73e58b7d000c: vrf: route: static: T2450: we also need to migrate the interface based routes.
Jul 12 2021, 4:41 PM
c-po committed rVYOSONEX2f3043ffce8a: op-mode: T427: add "summary" command for WireGuard interface information.
Jul 12 2021, 6:11 AM
c-po committed rVYOSONEX84305a8b98bb: op-mode: T427: add "summary" command for WireGuard interface information.
Jul 12 2021, 6:11 AM

Jul 11 2021

c-po committed rVYOSONEX562f4c276215: ipsec: T2816: use common "if key in dict:" pattern.
Jul 11 2021, 6:08 PM
c-po committed rVYOSONEXbffd2687fa55: ipsec: T2816: fix NameError.
Jul 11 2021, 6:08 PM
c-po added a comment to T3661: [vrf} route-leaking missing command.

I did a short lab test using the following topology based on my assumptions what you wan't to do using VyOS 1.3.0-rc5:

Jul 11 2021, 1:54 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2773: EIGRP support for VRF.

@Viacheslav but that sounds more of a decent FRR bug. We could still consider adding EIGRP support for 1.4

Jul 11 2021, 1:13 PM · VyOS 1.4 Sagitta
c-po moved T3659: Configuration won't accept IPv6 addresses for site-to-site VPN tunnel prefixes/traffic selectors from Open to In Progress on the VyOS 1.4 Sagitta board.
Jul 11 2021, 1:12 PM · VyOS 1.4 Sagitta
c-po moved T3663: Use inotify file watching where applicable from Open to In Progress on the VyOS 1.4 Sagitta board.
Jul 11 2021, 1:12 PM · VyOS 1.4 Sagitta
c-po moved T1210: About IKEv2 IPSec VPN remote access from Open to In Progress on the VyOS 1.4 Sagitta board.
Jul 11 2021, 1:12 PM · VyOS 1.4 Sagitta
c-po changed the status of T1210: About IKEv2 IPSec VPN remote access, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, from Open to Needs testing.
Jul 11 2021, 1:12 PM · VyOS 1.4 Sagitta
c-po changed the status of T1210: About IKEv2 IPSec VPN remote access from Open to Needs testing.
Jul 11 2021, 1:12 PM · VyOS 1.4 Sagitta
c-po closed T3665: Missing VRF support for VxLAN but already documented as Resolved.
Jul 11 2021, 1:09 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX7acd5e4b5319: vxlan: T3665: add VRF support.
Jul 11 2021, 1:09 PM
c-po committed rVYOSONEX701613fc6ec8: smoketest: T3637: add testcase for vrf bind-to-all option.
Jul 11 2021, 1:09 PM
c-po committed rVYOSONEX12bc0e667d66: vxlan: T3665: add VRF support.
Jul 11 2021, 1:08 PM
c-po claimed T3665: Missing VRF support for VxLAN but already documented.
Jul 11 2021, 1:06 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added a project to T3637: vrf: bind-to-all didn't work properly: VyOS 1.3 Equuleus.
Jul 11 2021, 12:33 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po committed rVYOSONEXcc5fdd0bbc95: vrf: T3637: bind-to-all didn't work properly (authored by tjjh89017).
Jul 11 2021, 12:32 PM
c-po added a comment to T3666: VRF bind-to-all - it doesn't apply the settings ..

Backported fix from T3637

Jul 11 2021, 12:31 PM · VyOS 1.3 Equuleus (1.3.0)
c-po merged T3666: VRF bind-to-all - it doesn't apply the settings . into T3637: vrf: bind-to-all didn't work properly.
Jul 11 2021, 12:31 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po merged task T3666: VRF bind-to-all - it doesn't apply the settings . into T3637: vrf: bind-to-all didn't work properly.
Jul 11 2021, 12:31 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T3661: [vrf} route-leaking missing command.
Jul 11 2021, 11:39 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3666: VRF bind-to-all - it doesn't apply the settings . from Open to In progress.
Jul 11 2021, 11:36 AM · VyOS 1.3 Equuleus (1.3.0)

Jul 10 2021

c-po added a comment to T3675: L2TP over IPSEC broken.

I can confirm this on the latest rolling versions, seems to be a problem with the IPSec rewrite/move to swanctl.conf.

Jul 10 2021, 9:00 AM
c-po changed the status of T3675: L2TP over IPSEC broken from Open to Confirmed.
Jul 10 2021, 9:00 AM

Jul 6 2021

c-po closed T3660: Conntrack-Sync configuration command to specify destination udp port for peer as Resolved.
Jul 6 2021, 5:33 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added a comment to T3660: Conntrack-Sync configuration command to specify destination udp port for peer.

Thanks for the confirmation

Jul 6 2021, 5:33 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Jul 4 2021

c-po committed rVYOSONEX70efa3dd54bc: vyos.util: T3663: move inotify-based imports to function level.
Jul 4 2021, 7:43 PM
c-po committed rVYOSONEXb2bf1592189f: ipsec: T1210: T1251: IKEv2 road-warrior support.
Jul 4 2021, 7:19 PM
c-po committed rVYOSONEX79f1c891f3ae: ipsec: T1210: T1251: extend ra config with address pools/traffic selectors (authored by sarthurdev <965089+sarthurdev@users.noreply.github.com>).
Jul 4 2021, 7:19 PM
c-po committed rVYOSONEXa89554bae49d: ipsec: T2816: use common building block/include for port definition.
Jul 4 2021, 7:19 PM
c-po committed rVYOSONEX3851818b7a26: ipsec: T2816: add include definition for ipsec local-address.
Jul 4 2021, 7:19 PM
c-po committed rVYOSONEXb16827699604: ipsec: T2816: add completion helper for VTI interfaces.
Jul 4 2021, 7:19 PM
c-po committed rVYOSONEXc8bf1deec9ce: ipsec: T1210: T1251: add remote-access "name-server" definition to pool config.
Jul 4 2021, 7:19 PM
c-po committed rVYOSONEX1c727bd25ef2: ipsec: T1210: T1251: add "local" traffic-selector include definition.
Jul 4 2021, 7:19 PM
c-po committed rVYOSONEX40c6a0402511: ipsec: T2816: add completion helper for tunnel interfaces.
Jul 4 2021, 7:19 PM
c-po committed rVYOSONEX2680712b7416: smoketest: pki: adjust to "type" node removal on CLI.
Jul 4 2021, 10:15 AM
c-po added a comment to T1251: IKEv2 Agile VPN Support.

@dongjunbo this is a very very basic PR for VyOS 1.4 with the goal to implement this into the main VyOS release.

Jul 4 2021, 10:03 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1210: About IKEv2 IPSec VPN remote access.

https://github.com/vyos/vyos-1x/pull/908

Jul 4 2021, 10:00 AM · VyOS 1.4 Sagitta
c-po added a comment to T1251: IKEv2 Agile VPN Support.

https://github.com/vyos/vyos-1x/pull/908

Jul 4 2021, 10:00 AM · VyOS 1.3 Equuleus (1.3.0)

Jul 3 2021

c-po committed rVYOSONEXce3847239493: ipsec: T2816: remove erroneously added config snipped for road-warriors.
Jul 3 2021, 8:32 PM
c-po added a reverting change for rVYOSONEXfb1802111155: ipsec: T2816: drop duplicate dict key "data" from generate(): rVYOSONEXe30668287ad0: Revert "ipsec: T2816: drop duplicate dict key "data" from generate()".
Jul 3 2021, 7:54 PM
c-po committed rVYOSONEXe30668287ad0: Revert "ipsec: T2816: drop duplicate dict key "data" from generate()".
Jul 3 2021, 7:54 PM
c-po committed rVYOSONEX405954522b8e: ipsec: T1210: T1251: add dependency on libcharon-extauth-plugins.
Jul 3 2021, 5:58 PM
c-po committed rVYOSONEXfb1802111155: ipsec: T2816: drop duplicate dict key "data" from generate().
Jul 3 2021, 5:58 PM
c-po committed rVYOSONEX2aec3e61c913: ipsec: T2816: provide x509 certificate base auth building blocks.
Jul 3 2021, 5:58 PM
c-po committed rVYOSONEX32fab6c7c5a7: ipsec: T2816: provide esp and ike-group XML building block.
Jul 3 2021, 5:58 PM
c-po claimed T1210: About IKEv2 IPSec VPN remote access.
Jul 3 2021, 5:22 PM · VyOS 1.4 Sagitta
c-po closed T57: Make it possible to disable the entire IPsec peer, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jul 3 2021, 5:22 PM · VyOS 1.4 Sagitta
c-po closed T57: Make it possible to disable the entire IPsec peer as Resolved.
Jul 3 2021, 5:22 PM · VyOS 1.4 Sagitta
c-po edited projects for T1210: About IKEv2 IPSec VPN remote access, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Jul 3 2021, 5:20 PM · VyOS 1.4 Sagitta
c-po merged task T1251: IKEv2 Agile VPN Support into T1210: About IKEv2 IPSec VPN remote access.
Jul 3 2021, 5:20 PM · VyOS 1.3 Equuleus (1.3.0)
c-po merged T1251: IKEv2 Agile VPN Support into T1210: About IKEv2 IPSec VPN remote access.
Jul 3 2021, 5:20 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX469cd1de9f90: ipsec: T2816: rework log options for debugging.
Jul 3 2021, 3:49 PM
c-po committed rVYOSONEXdcfeb0de0a51: Merge branch 'ipsec-ikev2-remote-access' of github.com:c-po/vyos-1x into current.
Jul 3 2021, 1:43 PM
c-po committed rVYOSONEXa1abb118c9eb: ipsec: T2816: rework IKE and ESP key assignment.
Jul 3 2021, 1:43 PM
c-po committed rVYOSONEX1e74c0df2179: ipsec: T2816: remove default values from Jinja2 template and place them in XML.
Jul 3 2021, 1:43 PM
c-po committed rVYOSONEX2d79a5000c8a: ipsec: T2816: add Jinja2 converter for ESP/IKE groups to string.
Jul 3 2021, 1:43 PM
c-po committed rVYOSONEXff004bee54df: ipsec: T2816: adjust Jinja2 template to coding style.
Jul 3 2021, 1:43 PM
c-po committed rVYOSONEX1a859a97f840: xml: provide building block for a generic description node.
Jul 3 2021, 1:43 PM
c-po added a comment to T3661: [vrf} route-leaking missing command.

Commands are implemented.

Jul 3 2021, 12:07 PM · VyOS 1.3 Equuleus (1.3.0)

Jul 2 2021

c-po added a comment to T3660: Conntrack-Sync configuration command to specify destination udp port for peer.

Added command set service conntrack-sync interface <intrerface> port <port>

Jul 2 2021, 8:26 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX68d8250fe525: conntrack: T3660: make peer port configurable.
Jul 2 2021, 8:25 PM
c-po committed rVYOSONEX13924804aafa: conntrack: T3535: add support for multiple failsave links.
Jul 2 2021, 8:25 PM
c-po committed rVYOSONEXbc01277bdfdf: conntrack: T3660: make peer port configurable.
Jul 2 2021, 8:25 PM
c-po changed the status of T3660: Conntrack-Sync configuration command to specify destination udp port for peer from Confirmed to Needs testing.
Jul 2 2021, 8:23 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX7c1f2dab543f: conntrack: T3535: add missing valueHelp/constraint for peer CLI node.
Jul 2 2021, 7:56 PM
c-po committed rVYOSONEX96dce0f47805: conntrack: T3535: add missing valueHelp/constraint for peer CLI node.
Jul 2 2021, 7:55 PM
c-po committed rVYOSONEXbfcc86ea5cf6: smoketest: ipam: add site2site x509 auth testcase.
Jul 2 2021, 4:16 PM
c-po committed rVYOSONEX7f97e165a8f3: smoketest: ipsec: IKE and ESP settings can be done one time in setUp().
Jul 2 2021, 4:16 PM
c-po committed rVYOSONEX9c5462908617: smoketest: ipsec: place peer local-address into variable.
Jul 2 2021, 4:16 PM

Jul 1 2021

c-po changed the status of T3660: Conntrack-Sync configuration command to specify destination udp port for peer from Open to Confirmed.
Jul 1 2021, 7:50 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added a project to T3660: Conntrack-Sync configuration command to specify destination udp port for peer: VyOS 1.4 Sagitta.
Jul 1 2021, 7:50 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added a comment to T3660: Conntrack-Sync configuration command to specify destination udp port for peer.

conntrack implementation changed form 1.3 -> 1.4 by a rewrite. Can you please tell us which version of VyOS you are using?

Jul 1 2021, 7:46 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta