Page MenuHomeVyOS Platform
Feed All Stories

Aug 6 2021

dmbaturin changed the status of T1083: Implement persistent/random address and port mapping options for NAT rules, a subtask of T3710: Upgrade the kernel in 1.3 to 5.10, from Open to Needs testing.
Aug 6 2021, 8:26 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin changed the status of T1083: Implement persistent/random address and port mapping options for NAT rules from Open to Needs testing.

I've tested it on 1.3 with kernel 5.4.138, and for me the persistent option works as expected. I think it's a non-issue for equuleus already and the task can be closed, though I'd like other people to test that first.

Aug 6 2021, 8:26 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX863d3c78fea3: Merge branch 'equuleus' of github.com:/vyos/vyos-1x into equuleus.
Aug 6 2021, 8:24 PM
dmbaturin committed rVYOSONEX14011bee6993: nat: T1083: add translation options for persistent/random mapping of address… (authored by hard).
Aug 6 2021, 8:24 PM
jestabro added a reverting change for rVYOSONEXa2b959c50c96: http-api: T2768: example using GraphQL for high-level config operations: rVYOSONEX56467e9967d9: Revert "http-api: T2768: example using GraphQL for high-level config operations".
Aug 6 2021, 8:00 PM
jestabro committed rVYOSONEX56467e9967d9: Revert "http-api: T2768: example using GraphQL for high-level config operations".
Aug 6 2021, 8:00 PM
jestabro committed rVYOSONEX158d6f2141d5: Revert "http-api: T2768: add README.graphql".
Aug 6 2021, 8:00 PM
jestabro added a reverting change for rVYOSONEX4a9063f755b7: http-api: T2768: add README.graphql: rVYOSONEX158d6f2141d5: Revert "http-api: T2768: add README.graphql".
Aug 6 2021, 8:00 PM
maznu added a comment to T3724: Allow setting host-name in l2tp section of accel-ppp.

Not having much luck with the build environment — and it doesn't seem to be something I've caused, because I get the same error building vyos-1x from mainline:

Aug 6 2021, 7:22 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro committed rVYOSONEX4a9063f755b7: http-api: T2768: add README.graphql.
Aug 6 2021, 7:13 PM
jestabro committed rVYOSONEXa2b959c50c96: http-api: T2768: example using GraphQL for high-level config operations.
Aug 6 2021, 7:13 PM
jestabro committed rVYOSONEXd3d4e3bedcc0: vyos.template: T2720: allow setting template directory.
Aug 6 2021, 7:13 PM
Viacheslav created T3725: show configuration in json format.
Aug 6 2021, 6:30 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added a comment to T3694: Static routes not installed into kernel nor frr.

@stepler interesting - this bahavior changes when running from frr-reload vs. vtysh.

Aug 6 2021, 4:55 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXd77709252de5: frr: T3694: temporary disable VRF VNI assignment.
Aug 6 2021, 4:54 PM
c-po committed rVYOSONEXecfbeb7fa3b1: frr: T2175: remove no longer required loop when removing VRF VNI.
Aug 6 2021, 4:54 PM
Viacheslav committed rVYOSONEX5efa470b8910: bgp: T548: Migrate maximum-paths to afi ipv4 maximum-paths.
Aug 6 2021, 4:54 PM
GitHub <noreply@github.com> committed rVYOSONEX9aff90d36f15: Merge pull request #954 from sever-sever/T548 (authored by c-po).
Aug 6 2021, 4:54 PM
Viacheslav committed rVYOSONEX4ae22dd44fd4: migration: T548: Rename quagga scripts for correct seq.
Aug 6 2021, 4:53 PM
GitHub <noreply@github.com> committed rVYOSONEX022cb9ead22a: Merge pull request #955 from sever-sever/T548-curr (authored by c-po).
Aug 6 2021, 4:53 PM
maznu added a comment to T3724: Allow setting host-name in l2tp section of accel-ppp.

I think all that is required is in: https://github.com/maznu/vyos-1x/commit/68d7897622ddaa4b2e5a98d79154500b33959567

Aug 6 2021, 2:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
maznu claimed T3724: Allow setting host-name in l2tp section of accel-ppp.
Aug 6 2021, 1:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
maznu added a comment to T3724: Allow setting host-name in l2tp section of accel-ppp.

Hello, @Dmitry, I agree. I'll prepare patches for 1.3 and 1.4.

Aug 6 2021, 1:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
maznu added a comment to T3692: VyOS build failing due to repo.saltstack.com.

Unhelpfully it looks like Salt has changed repo: https://repo.saltproject.io/#debian

Aug 6 2021, 1:29 PM · VyOS 1.4 Sagitta
UnicronNL closed T1153: VyOS 1.2.0RC10, RAID-1, fresh install, unable to save config as Resolved.
Aug 6 2021, 10:26 AM · VyOS 1.3 Equuleus (1.3.0-epa1), test
runar committed rVYOSONEX483c6d8cb24a: T3721: arm64: fastnetmon 1.2 is amd64 only until a propper arm64 build can be….
Aug 6 2021, 6:13 AM
GitHub <noreply@github.com> committed rVYOSONEXf9f97c17bca9: Merge pull request #953 from runborg/T3721 (authored by c-po).
Aug 6 2021, 6:13 AM
Unknown Object (User) added a comment to T3724: Allow setting host-name in l2tp section of accel-ppp.

Hello @maznu , I also prefer the first variant set vpn l2tp remote-access lns host-name example.com I'm sure that we no need to overload l2tp remote-access root noded

Aug 6 2021, 4:49 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Aug 5 2021

Cheeze_It added a comment to T3634: Add op command option for ping for do not fragment bit to be set.

Made the change to "do" and I noticed that.....DF is used even if there is no DF bit explicitly set...:

Aug 5 2021, 10:09 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Cheeze_It added a comment to T3634: Add op command option for ping for do not fragment bit to be set.

It seems the man page that I looked at I either didn't read carefully enough, or I completely messed it up. You're right @Viacheslav.

Aug 5 2021, 9:55 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Cheeze_It added a comment to T3634: Add op command option for ping for do not fragment bit to be set.

Did a quick test...

Aug 5 2021, 9:53 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav closed T696: Rewrite conntrack sync to XML as Resolved.

Already rewritten in 1.4 and 1.3 T3535
https://phabricator.vyos.net/rVYOSONEX21527ef4551613fe9b7eed9e4b2ce33ad46fe540

Aug 5 2021, 9:28 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Cheeze_It added a comment to T3634: Add op command option for ping for do not fragment bit to be set.

Hmmmm....it worked last time. I'll give it another run.

Aug 5 2021, 9:26 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav reopened T3634: Add op command option for ping for do not fragment bit to be set as "Open".

Reopen
It doesn't work properly

Aug 5 2021, 8:39 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav added a project to T681: Shaper QoS policy does not recognize 'lowdelay' DSCP value: VyOS 1.4 Sagitta.
Aug 5 2021, 7:51 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS 1.4 Sagitta (1.4.2), VyOS Rolling
Viacheslav added a comment to T548: BGP IPv6 multipath support.

PR https://github.com/vyos/vyatta-cfg-quagga/pull/87
PR https://github.com/vyos/vyos-1x/pull/954
PR https://github.com/vyos/vyos-1x/pull/955

Aug 5 2021, 7:04 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
maznu created T3724: Allow setting host-name in l2tp section of accel-ppp.
Aug 5 2021, 6:14 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
lawrencepan added a comment to T2851: Invalid passthrough routes installing by strongSwan into table 220.

ipsec start error ..

Aug 5 2021, 3:44 PM · Bugs, VyOS 1.3 Equuleus (1.3.9), test
jestabro added a project to T3574: Add constraintGroup for combining validators with logical AND: test.
Aug 5 2021, 3:02 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro removed a project from T2759: validate-value prints error messages from validators that fail even if overall validation succeeds: VyOS 1.4 Sagitta.
Aug 5 2021, 2:55 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
jestabro added a project to T2759: validate-value prints error messages from validators that fail even if overall validation succeeds: VyOS 1.4 Sagitta.
Aug 5 2021, 2:55 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po closed T3719: Restart vpn shows some missed files, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Aug 5 2021, 2:55 PM · VyOS 1.4 Sagitta
c-po closed T3719: Restart vpn shows some missed files as Resolved.
Aug 5 2021, 2:55 PM · VyOS 1.4 Sagitta
jestabro closed T3574: Add constraintGroup for combining validators with logical AND as Unknown Status.
Aug 5 2021, 2:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Unknown Object (User) added a comment to T2851: Invalid passthrough routes installing by strongSwan into table 220.

It is not critical, please test without this package "libstrongswan-standard-plugins"
All necessary data is already installed.

Aug 5 2021, 1:36 PM · Bugs, VyOS 1.3 Equuleus (1.3.9), test
lawrencepan added a comment to T2851: Invalid passthrough routes installing by strongSwan into table 220.
Setting up libstrongswan (5.7.2-1) ...
Setting up libstrongswan-extra-plugins (5.7.2-1) ...
dpkg: dependency problems prevent configuration of libstrongswan-standard-plugins:
 libstrongswan-standard-plugins depends on libssl1.0.0 (>= 1.0.2~beta3); however:
  Version of libssl1.0.0:amd64 on system is 1.0.1t-1+deb8u14.
Aug 5 2021, 12:37 PM · Bugs, VyOS 1.3 Equuleus (1.3.9), test
Unknown Object (User) added a comment to T2851: Invalid passthrough routes installing by strongSwan into table 220.


I have patched packages for 1.2.8. It works on my routers in the virtual environment.
Instruction:

  1. Upload package to the router
  2. Unarchiv it
sudo tar -xvf strongswan.tar
  1. Install packages
sudo dpkg -i *.deb
  1. Reboot router or reconfigure IPSec
Aug 5 2021, 10:14 AM · Bugs, VyOS 1.3 Equuleus (1.3.9), test
Viacheslav added a subtask for T2816: Rewrite IPsec scripts with the new XML/Python approach: T3723: op-mode IPSec show vpn ipsec sa output with underscores.
Aug 5 2021, 8:20 AM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3723: op-mode IPSec show vpn ipsec sa output with underscores: T2816: Rewrite IPsec scripts with the new XML/Python approach.
Aug 5 2021, 8:20 AM · VyOS 1.4 Sagitta
Viacheslav created T3723: op-mode IPSec show vpn ipsec sa output with underscores.
Aug 5 2021, 8:19 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2816: Rewrite IPsec scripts with the new XML/Python approach: T3722: op-mode IPSec show vpn ike sa always shows L-TIME 0.
Aug 5 2021, 8:14 AM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3722: op-mode IPSec show vpn ike sa always shows L-TIME 0: T2816: Rewrite IPsec scripts with the new XML/Python approach.
Aug 5 2021, 8:14 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.5 Circinus
Viacheslav created T3722: op-mode IPSec show vpn ike sa always shows L-TIME 0.
Aug 5 2021, 8:11 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.5 Circinus
Viacheslav added a comment to T3219: Typo in openvpn server client config for IPv6 iroute.

As I understand there are 2 bugs:

  1. It expected --iroute-ipv6, i.e
iroute-ipv6 2001:470:1f14:af1:: ffff:ffff:ffff:ffff::
  1. Something wrong with such format (ipv6 address/ ipv4 mask)
ifconfig-push 2001:470:1f14:af1::2 255.255.240.0
Aug 5 2021, 7:58 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Aug 4 2021

c-po closed T3704: Add ability to interact with Areca RAID adapers as Resolved.
Aug 4 2021, 7:06 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po claimed T3719: Restart vpn shows some missed files.
Aug 4 2021, 6:59 PM · VyOS 1.4 Sagitta
c-po claimed T3720: IPSec set vti secondary address cause interface disable.
Aug 4 2021, 6:58 PM · VyOS 1.4 Sagitta
c-po closed T3718: VPN IPsec IKE group by default not use DH-group 2, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Aug 4 2021, 6:50 PM · VyOS 1.4 Sagitta
c-po closed T3718: VPN IPsec IKE group by default not use DH-group 2 as Resolved.
Aug 4 2021, 6:50 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX947f8290ea70: ipsec: T3718: fix default processing of ike dh-group proposals.
Aug 4 2021, 6:49 PM
c-po added a comment to T3219: Typo in openvpn server client config for IPv6 iroute.

@SrividyaA does this configuration work or not?

Aug 4 2021, 6:37 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
SrividyaA added a comment to T3219: Typo in openvpn server client config for IPv6 iroute.
set interfaces openvpn vtun10 encryption cipher 'aes256'
set interfaces openvpn vtun10 hash 'sha512'
set interfaces openvpn vtun10 local-host '10.2.0.15'
set interfaces openvpn vtun10 local-port '1194'
set interfaces openvpn vtun10 mode 'server'
set interfaces openvpn vtun10 persistent-tunnel
set interfaces openvpn vtun10 protocol 'udp'
set interfaces openvpn vtun10 server client client1 ip '2001:470:1f14:af1::2'
set interfaces openvpn vtun10 server client client1 subnet '2001:470:1f14:af1::/64'
set interfaces openvpn vtun10 server push-route '2001:db8:0:abc::/64'
set interfaces openvpn vtun10 server subnet '10.140.0.0/20'
set interfaces openvpn vtun10 server topology 'subnet'
set interfaces openvpn vtun10 tls ca-cert-file '/config/auth/ea1/ca.crt'
set interfaces openvpn vtun10 tls cert-file '/config/auth/ea1/central.crt'
set interfaces openvpn vtun10 tls dh-file '/config/auth/ea1/dh.pem'
set interfaces openvpn vtun10 tls key-file '/config/auth/ea1/central.key'
Aug 4 2021, 5:15 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
runar created T3721: ARM64: 1.4: Fastnetmon in current is a precompiled custom "blob" and amd64 only. (blocks all arm64 builds).
Aug 4 2021, 4:51 PM
jestabro changed the status of T3474: Revisit storing syntax version of interface definitions in XML file, a subtask of T1962: Add syntax version to schema, from Open to In progress.
Aug 4 2021, 4:37 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro changed the status of T3474: Revisit storing syntax version of interface definitions in XML file, a subtask of T3475: XML dictionary cache unable to process syntaxVersion elements, from Open to In progress.
Aug 4 2021, 4:37 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro changed the status of T3474: Revisit storing syntax version of interface definitions in XML file from Open to In progress.
Aug 4 2021, 4:37 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro committed rVYOSONEX3a814957f412: configquery: T3402: remove restriction of query to active config.
Aug 4 2021, 3:00 PM
jestabro committed rVYOSONEX62fd0c326173: configquery: T3402: fix imports.
Aug 4 2021, 1:18 PM
Viacheslav closed T320: OSPF does not redistribute connected routes associated with virtual tunnel interfaces as Resolved.

I don't see this bug in 1.3.0-rc5,

Aug 4 2021, 11:24 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Aug 3 2021

c-po committed rVYOSONEXd9d183b6cbcb: isis: T1316: rename Jinja2 template to match other FRR daemons.
Aug 3 2021, 9:38 PM
c-po committed rVYOSONEXd77a2f56ea7e: isis: T1316: rename Jinja2 template to match other FRR daemons.
Aug 3 2021, 9:36 PM
c-po committed rVYOSONEXb55761ba5159: isis: T3693: bugfix Jinja2 template.
Aug 3 2021, 9:36 PM
jestabro committed rVYOSONEX5a11647335dc: configquery: T3402: add op-mode get_config_dict.
Aug 3 2021, 9:28 PM
c-po added a comment to T3694: Static routes not installed into kernel nor frr.

@stepler I created https://github.com/FRRouting/frr/pull/9281 for "easier" debugging

Aug 3 2021, 9:27 PM · VyOS 1.4 Sagitta
lawrencepan added a comment to T2851: Invalid passthrough routes installing by strongSwan into table 220.

OK , Thank you!

Aug 3 2021, 7:55 PM · Bugs, VyOS 1.3 Equuleus (1.3.9), test
Viacheslav committed rVYOSONEX7637a15bc064: l2tpv3: T1594: Fix timeout before set l2tpv3 interface.
Aug 3 2021, 7:29 PM
GitHub <noreply@github.com> committed rVYOSONEXbc9936e5bebd: Merge pull request #950 from sever-sever/T1594 (authored by c-po).
Aug 3 2021, 7:29 PM
c-po changed the status of T3718: VPN IPsec IKE group by default not use DH-group 2, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, from Open to Confirmed.
Aug 3 2021, 7:25 PM · VyOS 1.4 Sagitta
c-po changed the status of T3718: VPN IPsec IKE group by default not use DH-group 2 from Open to Confirmed.
Aug 3 2021, 7:25 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3318: Update Linux Kernel to v5.4.208 / 5.10.142.
Aug 3 2021, 7:17 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po updated the task description for T3318: Update Linux Kernel to v5.4.208 / 5.10.142.
Aug 3 2021, 7:16 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po added a comment to T3694: Static routes not installed into kernel nor frr.

I tried this locally and you can do no router bgp 100 vrf blue before no vni 2000, my vtysh instance does not scream for an error - it more feels like a programming issue on our side.

Aug 3 2021, 7:04 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2851: Invalid passthrough routes installing by strongSwan into table 220.
Aug 3 2021, 5:27 PM · Bugs, VyOS 1.3 Equuleus (1.3.9), test
lawrencepan added a comment to T2851: Invalid passthrough routes installing by strongSwan into table 220.
sudo ip rule add prio 219 from 192.0.2.48/30 to 192.0.2.48/30 lookup main
}
Aug 3 2021, 5:15 PM · Bugs, VyOS 1.3 Equuleus (1.3.9), test
Viacheslav added a comment to T2851: Invalid passthrough routes installing by strongSwan into table 220.

As a workaround it can help in such cases:

Aug 3 2021, 4:58 PM · Bugs, VyOS 1.3 Equuleus (1.3.9), test
lawrencepan added a comment to T2851: Invalid passthrough routes installing by strongSwan into table 220.

I get the same issue in 1.2.8.

Aug 3 2021, 4:46 PM · Bugs, VyOS 1.3 Equuleus (1.3.9), test
jestabro committed rVYOSONEX1d8f1f2a8a28: configquery: T3402: add class using configtree to list tag node values.
Aug 3 2021, 3:59 PM
Viacheslav updated the task description for T3720: IPSec set vti secondary address cause interface disable.
Aug 3 2021, 3:45 PM · VyOS 1.4 Sagitta
jestabro reopened T3402: Add VyOS programming library for operational level commands as "Open".
Aug 3 2021, 3:34 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a subtask for T2816: Rewrite IPsec scripts with the new XML/Python approach: T3720: IPSec set vti secondary address cause interface disable.
Aug 3 2021, 3:29 PM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3720: IPSec set vti secondary address cause interface disable: T2816: Rewrite IPsec scripts with the new XML/Python approach.
Aug 3 2021, 3:29 PM · VyOS 1.4 Sagitta
Viacheslav created T3720: IPSec set vti secondary address cause interface disable.
Aug 3 2021, 3:29 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T3719: Restart vpn shows some missed files.
Aug 3 2021, 3:20 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2816: Rewrite IPsec scripts with the new XML/Python approach: T3719: Restart vpn shows some missed files.
Aug 3 2021, 3:19 PM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3719: Restart vpn shows some missed files: T2816: Rewrite IPsec scripts with the new XML/Python approach.
Aug 3 2021, 3:19 PM · VyOS 1.4 Sagitta
Viacheslav created T3719: Restart vpn shows some missed files.
Aug 3 2021, 3:19 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2816: Rewrite IPsec scripts with the new XML/Python approach: T3718: VPN IPsec IKE group by default not use DH-group 2.
Aug 3 2021, 3:14 PM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3718: VPN IPsec IKE group by default not use DH-group 2: T2816: Rewrite IPsec scripts with the new XML/Python approach.
Aug 3 2021, 3:14 PM · VyOS 1.4 Sagitta
Viacheslav created T3718: VPN IPsec IKE group by default not use DH-group 2.
Aug 3 2021, 2:36 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3717: BGP Peer group without 'remote-as' gives shell error.

@xrobau You have to set remote-as for peer-group or for neighbor

vyos@r4-1.3# set protocols bgp 65001 peer-group FOO 
[edit]
vyos@r4-1.3# set protocols bgp 65001 neighbor 203.0.113.2 peer-group FOO
[edit]
vyos@r4-1.3# set protocols bgp 65001 neighbor 203.0.113.2 remote-as 65002
[edit]
vyos@r4-1.3# commit
[edit]
vyos@r4-1.3#
Aug 3 2021, 11:05 AM · VyOS 1.3 Equuleus (1.3.0), vyos-frr