Page MenuHomeVyOS Platform
Feed All Stories

Aug 19 2021

c-po claimed T3751: pki generate ca add new line after passphrase.
Aug 19 2021, 8:53 AM · VyOS 1.4 Sagitta
c-po moved T690: Allow OpenVPN servers to push routes with custom metric values from Open to In Progress on the VyOS 1.4 Sagitta board.
Aug 19 2021, 8:53 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3764: Unconfigurable IKE and ESP lifetime from Open to In Progress on the VyOS 1.4 Sagitta board.
Aug 19 2021, 8:53 AM · VyOS 1.4 Sagitta
c-po moved T3765: container: additional op-mode commands from In Progress to Backlog on the VyOS 1.4 Sagitta board.
Aug 19 2021, 8:53 AM · VyOS 1.4 Sagitta
c-po moved T3766: containers: Expanding options for networking and building containers from Open to In Progress on the VyOS 1.4 Sagitta board.
Aug 19 2021, 8:53 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po moved T3765: container: additional op-mode commands from Open to In Progress on the VyOS 1.4 Sagitta board.
Aug 19 2021, 8:53 AM · VyOS 1.4 Sagitta

Aug 18 2021

c-po claimed T3764: Unconfigurable IKE and ESP lifetime.
Aug 18 2021, 7:07 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXc61f7557a6b5: isis: T3417: last byte of IS-IS network entity title must always be 0.
Aug 18 2021, 6:33 PM
kroy added a comment to T3766: containers: Expanding options for networking and building containers.

Definitely seems to me a op-mode command to trigger a container rebuild would be appropriate.

Aug 18 2021, 6:28 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po edited projects for T3765: container: additional op-mode commands, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Aug 18 2021, 6:27 PM · VyOS 1.4 Sagitta
c-po added a comment to T3766: containers: Expanding options for networking and building containers.

How can I re-trigger the build of the container when I have changed the file?

Aug 18 2021, 6:27 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po added a comment to T3708: isisd and gre-bridge commit error.

HI @Viacheslav, this works even in 1.3, your problem is that you need to merge it with isis['FOO'] and not isis.

Aug 18 2021, 6:19 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
mationsills created T3767: SUPPLY CHAIN MANAGEMENT AND.
Aug 18 2021, 5:38 PM
kroy added a comment to T3766: containers: Expanding options for networking and building containers.

For example,

Aug 18 2021, 5:37 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
kroy added a comment to T3766: containers: Expanding options for networking and building containers.

To wit, I already had this working with multiple networks (I had named them podman0/1/2/3/4/etc), but I wanted to simplify the initial PR here.

Aug 18 2021, 5:07 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
kroy added a comment to T3766: containers: Expanding options for networking and building containers.

Network re-creates every time after reboot and gets configuration from "container network" section.
https://github.com/vyos/vyatta-cfg/blob/242f5685159f615ff79312041d3dde2063e5579a/scripts/init/vyos-router#L273-L277
So there is podman decide how to name this network.

In a different case, it tried to create a network which already been created.

Aug 18 2021, 5:04 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav added a comment to T3766: containers: Expanding options for networking and building containers.

Network re-creates every time after reboot and gets configuration from "container network" section.
https://github.com/vyos/vyatta-cfg/blob/242f5685159f615ff79312041d3dde2063e5579a/scripts/init/vyos-router#L273-L277
So there is podman decide how to name this network.

Aug 18 2021, 4:58 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
kroy updated the task description for T3766: containers: Expanding options for networking and building containers.
Aug 18 2021, 4:56 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
kroy added a comment to T3766: containers: Expanding options for networking and building containers.

PR975

Aug 18 2021, 4:53 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav added a comment to T3506: Migrate loadkey command to op-mode.

From conf mode I get error VyOS 1.4-rolling-202108130117

vyos@vyos-oobm# loadkey vyos scp://vyos@192.168.122.11:/etc/ssh/ssh_host_rsa_key.pub
Global symbol "$generate" requires explicit package name (did you forget to declare "my $generate"?) at /opt/vyatta/sbin/vyatta-load-user-key.pl line 162.
Execution of /opt/vyatta/sbin/vyatta-load-user-key.pl aborted due to compilation errors.
[edit]
vyos@vyos-oobm#
Aug 18 2021, 4:47 PM · VyOS 1.4 Sagitta
kroy changed the status of T3766: containers: Expanding options for networking and building containers from Open to Needs testing.
Aug 18 2021, 4:46 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
kroy updated the task description for T3766: containers: Expanding options for networking and building containers.
Aug 18 2021, 4:46 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
kroy created T3766: containers: Expanding options for networking and building containers.
Aug 18 2021, 4:07 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po updated the task description for T3765: container: additional op-mode commands.
Aug 18 2021, 3:42 PM · VyOS 1.4 Sagitta
c-po created T3765: container: additional op-mode commands.
Aug 18 2021, 3:41 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXb30ca1c18cdb: Debian: containers: T2216: add missing dependency on uidmap.
Aug 18 2021, 3:34 PM
c-po assigned T3764: Unconfigurable IKE and ESP lifetime to sarthurdev.
Aug 18 2021, 3:22 PM · VyOS 1.4 Sagitta
c-po closed T3752: generate pki certificate file xxx doesn't touch file as Resolved.
Aug 18 2021, 3:03 PM · VyOS 1.4 Sagitta
c-po moved T3752: generate pki certificate file xxx doesn't touch file from Open to In Progress on the VyOS 1.4 Sagitta board.
Aug 18 2021, 3:03 PM · VyOS 1.4 Sagitta
c-po moved T3759: [L3VPN] VPNv4/VPNv6 add commands from Open to In Progress on the VyOS 1.4 Sagitta board.
Aug 18 2021, 3:03 PM · VyOS 1.4 Sagitta
c-po added a comment to T3763: wireguard checks if port already binding.

+1

Aug 18 2021, 3:03 PM · VyOS 1.4 Sagitta
c-po added a comment to T3759: [L3VPN] VPNv4/VPNv6 add commands .

The latest rolling 1.4-rolling-202108180805 should have it all.

Aug 18 2021, 2:12 PM · VyOS 1.4 Sagitta
c-po changed the status of T3759: [L3VPN] VPNv4/VPNv6 add commands from In progress to Needs testing.
Aug 18 2021, 2:11 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2816: Rewrite IPsec scripts with the new XML/Python approach: T3764: Unconfigurable IKE and ESP lifetime.
Aug 18 2021, 1:24 PM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3764: Unconfigurable IKE and ESP lifetime: T2816: Rewrite IPsec scripts with the new XML/Python approach.
Aug 18 2021, 1:24 PM · VyOS 1.4 Sagitta
Unknown Object (User) created T3764: Unconfigurable IKE and ESP lifetime.
Aug 18 2021, 1:21 PM · VyOS 1.4 Sagitta
dtoux added a comment to T3537: Unable to override the default OSPFv3 link cost for wireguard interface.

Sounds good to me.

Aug 18 2021, 1:13 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po committed rVYOSONEX47261d051759: bgp: evpn: T1513: VNI rt and rd are only supported under EVPN VRF.
Aug 18 2021, 12:06 PM
c-po committed rVYOSONEX522402ecb797: bgp: evpn: T1513: fix indention when writing address-family config.
Aug 18 2021, 11:58 AM
c-po committed rVYOSONEX8ce0cd9f0994: bgp: evpn: T1513: re-structure route-target XML blocks.
Aug 18 2021, 11:13 AM
c-po committed rVYOSONEXcbf1998ae952: bgp: T3759: add l3vpn "route-target vpn" commands.
Aug 18 2021, 11:13 AM
c-po committed rVYOSONEXef3f17d7e7fb: bgp: T3759: fix indention when writing address-family config.
Aug 18 2021, 11:13 AM
c-po committed rVYOSONEX0df3e23d5719: bgp: T3759: fix "label vpn" help string.
Aug 18 2021, 11:13 AM
c-po committed rVYOSONEX1cc2ac26106f: bgp: T3759: add l3vpn "rd" route-distinguisher commands.
Aug 18 2021, 11:13 AM
c-po committed rVYOSONEX231095f95df1: bgp: T2387: fix indention when writing address-family config.
Aug 18 2021, 11:13 AM
c-po committed rVYOSONEX73c0e8710985: bgp: T3759: add l3vpn "label vpn export" commands.
Aug 18 2021, 11:13 AM
c-po committed rVYOSONEX4058e389f1ca: bgp: T3759: import/export is for AFI "ipv4 unicast" not "ipv4 multicast".
Aug 18 2021, 11:13 AM
Viacheslav updated the task description for T3763: wireguard checks if port already binding.
Aug 18 2021, 10:26 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T3762: Support network and address groups for policy ipv6-route: VyOS 1.4 Sagitta.
Aug 18 2021, 10:19 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T3763: wireguard checks if port already binding.
Aug 18 2021, 10:15 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T3763: wireguard checks if port already binding.
Aug 18 2021, 10:15 AM · VyOS 1.4 Sagitta
Viacheslav created T3763: wireguard checks if port already binding.
Aug 18 2021, 10:10 AM · VyOS 1.4 Sagitta
daniil created T3762: Support network and address groups for policy ipv6-route.
Aug 18 2021, 10:07 AM · VyOS 1.4 Sagitta
Viacheslav closed T3537: Unable to override the default OSPFv3 link cost for wireguard interface as Resolved.

I close the task, because it can't be reproducible in 1.3.0-rc5
Re-open it, if necessary with described step by step how to reproduce it.
Or open a new one.

Aug 18 2021, 9:47 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T3708: isisd and gre-bridge commit error.

from vyos.xml import defaults doesn't work for 1.3 correctly, for some reason it gets 2 isis process with same name "FOO"
https://github.com/sever-sever/vyos-1x/commit/7b0a33618bfa1d1ef99b9744ed1ded49a2c832af

vyos@r4-1.3# compare 
[edit protocols]
+isis FOO {
+    interface tun0 {
+    }
+    net 49.0001.0000.0011.0001.00
+}
[edit]
vyos@r4-1.3# commit
[ protocols isis FOO ]
{'FOO': {'interface': {'tun0': {}}, 'net': '49.0001.0000.0011.0001.00'},
 'lsp_mtu': '1497'}
Only one isis process can be defined
Aug 18 2021, 9:33 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav placed T3708: isisd and gre-bridge commit error up for grabs.
Aug 18 2021, 9:27 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po committed rVYOSONEX8c1bc03f7088: smoketest: ssh: migrate setUp -> setUpClass to run code only once.
Aug 18 2021, 8:00 AM
c-po committed rVYOSONEXc788c26d5b7a: smoketest: nat66: migrate setUp -> setUpClass to run code only once.
Aug 18 2021, 8:00 AM
c-po committed rVYOSONEX39ba9c318538: nptv6: T2518: remove superfluous else clause on missing outbound-interface.
Aug 18 2021, 8:00 AM
c-po committed rVYOSONEX2606f95cb07f: nat: T2198: remove superfluous else clause on missing outbound-interface.
Aug 18 2021, 8:00 AM
c-po committed rVYOSONEX6b2c3906c3ef: nptv6: T2518: add missing verify() stage for mandatory translation address.
Aug 18 2021, 8:00 AM
c-po committed rVYOSONEXc9ad82ef583a: nat66: ndppd: T2518: rename Jinja2 template folder to match common naming….
Aug 18 2021, 8:00 AM
c-po committed rVYOSONEXbd2669f36c2e: ndppd: T2518: add missing if statement for translation address in Jinja2….
Aug 18 2021, 8:00 AM
c-po committed rVYOSONEX63b755f85afb: policy: T2425: import exact Perl match criteria for large-community-list.
Aug 18 2021, 7:24 AM

Aug 17 2021

fernando added a comment to T3759: [L3VPN] VPNv4/VPNv6 add commands .

@c-po Thanks!!! :)

Aug 17 2021, 8:44 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX6d0c73c42029: xml: cleanup - replace format "text" with "txt" as required by the BASH helpers.
Aug 17 2021, 8:31 PM
c-po committed rVYOSONEX053f586fa7a5: bgp: T3759: add l3vpn "import vrf" commands.
Aug 17 2021, 8:31 PM
c-po committed rVYOSONEXda453ff4a810: bgp: T2771: adjust verify() logic to common coding style for validation.
Aug 17 2021, 8:31 PM
c-po committed rVYOSONEX51f7ce31bc60: xml: cleanup - replace format "text" with "txt" as required by the BASH helpers.
Aug 17 2021, 8:31 PM
c-po committed rVYOSONEX1faa8728239c: bgp: T3759: add l3vpn import/export vpn command for IPv4/IPv6 AFI.
Aug 17 2021, 8:31 PM
c-po committed rVYOSONEX387732762169: bgp: T2174: create building block for path-limit which is used in IPv4/IPv6 AFI.
Aug 17 2021, 8:31 PM
c-po added a comment to T3759: [L3VPN] VPNv4/VPNv6 add commands .

thanks for pushing and testing this featureset. Your requested changes will make it into the rolling image the next couple of days!

Aug 17 2021, 8:30 PM · VyOS 1.4 Sagitta
c-po edited projects for T3761: Bump salt-minion to 3000, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux.
Aug 17 2021, 8:15 PM · VyOS 1.2 Crux (VyOS 1.2.9)
wegenerbenjamin created T3761: Bump salt-minion to 3000.
Aug 17 2021, 5:40 PM · VyOS 1.2 Crux (VyOS 1.2.9)
dtoux added a comment to T3552: BFD does not work with OSPFv3 via wireguard.

Any news on this?

Aug 17 2021, 5:26 PM
krox2 created T3760: LLDP causes interface RX drops.
Aug 17 2021, 4:17 PM · VyOS 1.4 Sagitta (1.4.0-GA), lldpd
c-po changed the status of T3759: [L3VPN] VPNv4/VPNv6 add commands from Open to In progress.
Aug 17 2021, 4:10 PM · VyOS 1.4 Sagitta
dtoux added a comment to T3537: Unable to override the default OSPFv3 link cost for wireguard interface.

I haven't tested it directly but I haven't experienced this problem while working on the configuration changes. I don't have much time right now, so I can't test the exact scenario.

Aug 17 2021, 4:01 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav closed T1643: Deleting all firewall zones failed and locked out box, a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Aug 17 2021, 4:00 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav closed T1643: Deleting all firewall zones failed and locked out box as Resolved.

Not reproducible, tested on "1.3-beta-202108151336"

Aug 17 2021, 4:00 PM · VyOS 1.3 Equuleus (1.3.0), test
c-po committed rVYOSONEX46771076d90b: policy: T2425: bgp large-community-list name also supports - and _.
Aug 17 2021, 3:45 PM
c-po committed rVYOSONEX8155f959b897: policy: T2425: bgp ext-community-list name also supports - and _.
Aug 17 2021, 3:45 PM
ciprian.craciun added a comment to T1753: Configuring `ip source-validation loose` doesn't properly configure `sysctl`.

@Viacheslav Sorry for the long delay in replying.

Aug 17 2021, 2:56 PM · Bugs, VyOS 1.5 Circinus
fernando changed Version from - to - VyOS 1.4-rolling-202108081830 on T3759: [L3VPN] VPNv4/VPNv6 add commands .
Aug 17 2021, 1:44 PM · VyOS 1.4 Sagitta
fernando added a project to T3759: [L3VPN] VPNv4/VPNv6 add commands : VyOS 1.4 Sagitta.
Aug 17 2021, 1:43 PM · VyOS 1.4 Sagitta
fernando created T3759: [L3VPN] VPNv4/VPNv6 add commands .
Aug 17 2021, 1:41 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T1753: Configuring `ip source-validation loose` doesn't properly configure `sysctl`.
  1. Bug, values on interfaces are overwritten after firewall global parameters.

By default:

vyos@r4-1.3# sudo sysctl -a | grep "\.rp_filter"
net.ipv4.conf.all.rp_filter = 0
net.ipv4.conf.default.rp_filter = 0
net.ipv4.conf.eth0.rp_filter = 0
net.ipv4.conf.eth1.rp_filter = 0
net.ipv4.conf.eth2.rp_filter = 0
net.ipv4.conf.lo.rp_filter = 0
net.ipv4.conf.vtun10.rp_filter = 0

Set value for the interface eth2 value "loose"

vyos@r4-1.3# set interfaces ethernet eth2 ip source-validation 'loose'
[edit]
vyos@r4-1.3# commit
vyos@r4-1.3# sudo sysctl -a | grep "\.rp_filter"
net.ipv4.conf.all.rp_filter = 0
net.ipv4.conf.default.rp_filter = 0
net.ipv4.conf.eth0.rp_filter = 0
net.ipv4.conf.eth1.rp_filter = 0
net.ipv4.conf.eth2.rp_filter = 2
net.ipv4.conf.lo.rp_filter = 0
net.ipv4.conf.vtun10.rp_filter = 0
Aug 17 2021, 1:37 PM · Bugs, VyOS 1.5 Circinus
Viacheslav added a comment to T1349: L2TP remote-access vpn terminated and not showing as connected.

@Merijn Any updates?

Aug 17 2021, 12:53 PM · VyOS 1.3 Equuleus (1.3.0), test
Viacheslav added a comment to T1487: DNS (pdns_recursor) stats logs not saved to disk.

@c-po Can we close it?

Aug 17 2021, 12:47 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav closed T508: ISC DHCP incorrect UDP checksum generation as Resolved.

Not more actual for 1.3, as it used isc-dhcp-client/isc-dhcp-relay/isc-dhcp-server 4.4.1-2
I can't find in logs something like bad udp checksums

Aug 17 2021, 12:46 PM · VyOS 1.3 Equuleus (1.3.0-epa1), vyatta-dhcp3
c-po added a comment to T1487: DNS (pdns_recursor) stats logs not saved to disk.

From the manual:

Aug 17 2021, 12:06 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
c-po added a comment to T1550: Add support for Large BGP Community show commands.

VyOS 1.3.0-rc6 (upcoming) and 1.4 have the following commands available:

Aug 17 2021, 11:51 AM · VyOS 1.3 Equuleus (1.3.0), test
c-po committed rVYOSONEX4da7d0a721ae: op-mode: xml: bgp: fix large-community help string.
Aug 17 2021, 11:48 AM
c-po committed rVYOSONEX6fa44eaf1f45: op-mode: T1513: bgp: add "show bgp large-community-list" commnad.
Aug 17 2021, 11:48 AM
c-po committed rVYOSONEX77a00e3653a6: op-mode: T1513: bgp: add "show bgp large-community AA:BB:CC exat-match".
Aug 17 2021, 11:48 AM
c-po committed rVYOSONEX21626c4600a1: op-mode: T1513: bgp: xml: provide exact-match building block.
Aug 17 2021, 11:48 AM
c-po committed rVYOSONEX359f0c97f0e6: policy: T2425: add missing validator for large-community-lists.
Aug 17 2021, 11:47 AM
c-po committed rVYOSONEX3535340f0b8d: policy: T2425: add missing constraints for extended and large community lists.
Aug 17 2021, 11:47 AM
c-po committed rVYOSONEX90f778fc04b3: op-mode: T1513: bgp: add "show bgp large-community-list" commnad.
Aug 17 2021, 11:47 AM
c-po committed rVYOSONEXc33ea3f44218: policy: T2425: update help test for BGP communities.
Aug 17 2021, 11:47 AM