Page MenuHomeVyOS Platform
Feed All Stories

Aug 30 2021

erkin set Issue type to bug on T2608: delete pseudo-ethernet failed (another error type).
Aug 30 2021, 5:18 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2609: router-advert: radvd does not start when lifetime is improperly configured.
Aug 30 2021, 5:18 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2610: default-lifetime is not reflected in the RA message.
Aug 30 2021, 5:18 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2611: Prefix list names are shared between ipv4 and ipv6.
Aug 30 2021, 5:12 AM · VyOS 1.3 Equuleus (1.3.4)
erkin set Issue type to bug on T2612: HTTPS API, changing API key fails but goes through.
Aug 30 2021, 5:12 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
erkin set Issue type to internal on T2614: Add an option to mangle dict keys to vyos.config.get_config_dict().
Aug 30 2021, 5:12 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2615: Provide an explicit option for server fingerprint in commit archive, and make insecure the default.
Aug 30 2021, 5:11 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2616: BFD Configuration causes flapping.
Aug 30 2021, 5:11 AM
erkin set Issue type to internal on T2617: Rewrite vyatta-op-quagga "show" to XML.
Aug 30 2021, 5:11 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2618: Conversion from 1.2 to 1.3 lost RADVD prefix autonomous-flag setting.
Aug 30 2021, 5:08 AM · VyOS 1.3 Equuleus (1.3.0)
erkin added a project to T2619: Bug: Changes in NAT or ZONES from 1.2 to 1.3: VyOS 1.3 Equuleus.
Aug 30 2021, 5:07 AM · VyOS 1.3 Equuleus (1.3.0)
dmbaturin empowered SrividyaA as an administrator.
Aug 30 2021, 4:05 AM
debiansid created T3784: can't build iso with custom built iptables .
Aug 30 2021, 2:35 AM · VyOS 1.4 Sagitta

Aug 29 2021

c-po committed rVYOSONEX147f655a69cd: vyos.ethtool: T3163: add check_speed_duplex() method.
Aug 29 2021, 9:19 PM
c-po committed rVYOSONEX324aa9598c7d: vyos.ethtool: T3163: prefix class internal data structures with _.
Aug 29 2021, 9:19 PM
c-po committed rVYOSONEXeac8915413ce: vyos.ethtool: T3163: drop obsoleted is_fixed_lro() method.
Aug 29 2021, 8:15 PM
c-po added a comment to T3619: Performance Degradation 1.2 --> 1.3 | High ksoftirqd CPU usage.

An analysis of the code base from VyOS 1.2 -> 1.3 -> 1.4 revealed the following "root-cause"

Aug 29 2021, 8:06 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po changed the status of T3619: Performance Degradation 1.2 --> 1.3 | High ksoftirqd CPU usage from Open to In progress.
Aug 29 2021, 7:39 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po changed the status of T3514: NIC flap at any interface change from On hold to In progress.
Aug 29 2021, 7:05 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added a comment to T1683: Difficulty monitoring VyOS through SNMP.

VyOS 1.4 uses persistent OpenVPN interfaces.

Aug 29 2021, 6:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po committed rVYOSONEXe5796497d558: interfaces: T3777: Does not delete empty eui64 address (authored by Viacheslav).
Aug 29 2021, 6:35 PM
c-po committed rVYOSONEX0deb1709930f: xml: add missing "u32:" value declarator on integer ranges.
Aug 29 2021, 6:34 PM
Viacheslav added a comment to T3782: Ingress Shaping with IFB No Longer Functional with 1.3.
Aug 29 2021, 6:11 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
trystan added a comment to T3782: Ingress Shaping with IFB No Longer Functional with 1.3.

I can confirm that applying

Aug 29 2021, 5:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav added a comment to T3782: Ingress Shaping with IFB No Longer Functional with 1.3.

Possible bug after this commit https://github.com/vyos/vyos-1x/pull/621/commits/ede2972be4c49962a04b1addb9df6ce58f2d9f42
As it works in vyos-1.3-rolling-202011 before that commit.

Aug 29 2021, 5:39 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav changed the status of T3777: adding IPv6 EUI64 address fails commit in 1.3.0-rc6 from Open to Needs testing.
Aug 29 2021, 5:18 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav closed T3708: isisd and gre-bridge commit error as Resolved.

1.3 fixed in T3779

Aug 29 2021, 5:07 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav added a comment to T1683: Difficulty monitoring VyOS through SNMP.

The issue may be with OpenVPN/dynamic interfaces only, without the option "persist".
In that case, if no connectivity between interfaces it tried to re-add the interface "down/up" vtunX with a new SNMP index. And it will be in the loop until connectivity will be restored with the remote site.

Aug 29 2021, 4:39 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sempervictus added a comment to T2191: Using tallow to block sshd probes.

This can be done via the tc kernel module AFAIK. Something like fireqos would be great to have in here, but they're pretty opinionated in how they do things in their tools so probably not a viable drop-in solution.
This can also be done with OSSEC using active response, either by building an OSSEC agent into the image (client key management is kind of a PITA) or by way of remote feed for FW log events showing attempts to connect with an active-response script to temporarily block the offenders with progressively longer blocks on repeat offenses.

Aug 29 2021, 4:06 PM · VyOS 1.3 Equuleus (1.3.6)
sempervictus added a comment to T1942: hardware info collector .

lshw does this already

Aug 29 2021, 4:00 PM · VyOS Rolling
Viacheslav added a comment to T3782: Ingress Shaping with IFB No Longer Functional with 1.3.

Difference between 1.2 and 1.3
1.3 don't have option qdisc ingress ffff: dev eth0 parent ffff:fff1 ----------------

Aug 29 2021, 3:56 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
sempervictus added a comment to T1890: Metatask: rewrite flow-accounting to XML and Python.

I added the kernel netflow module to my pull request a while back - collects and forwards flows to a destination defined in the module parameter set at load-time.
If we want to actually process flows on-system, there's a bunch of modern tooling for that; but in terms of just aggregation and export in canonical format, the kernel module is the best way to go IMO due to the fact that it works at the same tier as the network code itself (ring0).

Aug 29 2021, 3:56 PM · VyOS 1.3 Equuleus (1.3.0)
sempervictus added a comment to T1683: Difficulty monitoring VyOS through SNMP.

Not seeing this issue when setting "description" field - we've run it in production for years bridging our OpenStack and datacenter environments, and the names show up correctly (blanked sensitive details):

image.png (1×1 px, 258 KB)

Aug 29 2021, 3:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sempervictus added a comment to T1619: Migrate user home directories on image update.

From a post-exploitation perspective, this would permit attackers who've compromised an older vulnerable version to persist their payloads in the shell elements (~/.bashrc and friends) across upgrades.

Aug 29 2021, 3:46 PM
sempervictus added a comment to T1437: First boot configuration support.

This seems similar to the "configuration drive" option for OpenStack, which is already handled by cloud-init. Might be handy to implement as a cloud-init local data source and just include CI on all builds since thats becoming an industry standard even on bare metal.

Aug 29 2021, 3:44 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3774: atop logs are not limited in size.

How about CLI set system syslog atop file 5
That means save the latest 5 files.

Aug 29 2021, 3:23 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav assigned T3763: wireguard checks if port already binding to zsdc.
Aug 29 2021, 3:07 PM · VyOS 1.4 Sagitta
sempervictus added a comment to T2888: Cloud-init images refuse to work with network-based datasource such as Ec2 or OpenStack (but do work with OpenStack's config drive).

I've managed to get this working in our own builds by restoring the openstack target and making some changes there - runs fine in AWS, even with a grsec kernel and hardened userspace (Xen is often the worst visor for ring0 memory defenses).

Aug 29 2021, 2:16 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to unspecified on T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting.
Aug 29 2021, 2:15 PM · VyOS 1.2 Crux (VyOS 1.2.8)
erkin set Issue type to bug on T2621: show interfaces repeats interface description if it is longer then an arbitrary number of characters.
Aug 29 2021, 2:15 PM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2622: Pseudo-ethernet interface config disappears across versions from An issue with config migration (interface pseudo ethernet) to Pseudo-ethernet interface config disappears across versions.
Aug 29 2021, 2:15 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2623: Creating sit tunnel fails with “Can not set “local” for tunnel sit tun1 at tunnel creation”.
Aug 29 2021, 2:14 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
erkin set Issue type to bug on T2624: Serial Console: fix migration script for configured powersave and no console.
Aug 29 2021, 2:14 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2626: Changing pseudo-ethernet mode, throws CLI error.
Aug 29 2021, 2:13 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to improvement on T2627: 'system static-host-mapping' only allows one IP address per hostname, it should allow one IPv4 and one IPv6 simultaneously.
Aug 29 2021, 2:13 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2628: Make logs more user friendly..
Aug 29 2021, 2:12 PM · VyOS 1.3 Equuleus (1.3.5)
erkin set Issue type to bug on T2629: VXLAN interfaces don't actually allow you to configure most settings.
Aug 29 2021, 2:12 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2630: Allow Interface MTU over 9000.
Aug 29 2021, 2:12 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2633: Error with arp_accept on tun interface.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2631: l2tp, sstp, pptp add option to disable radius accounting.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2632: WireGuard: Cannot use only one preshared-key for one peer from WireGuard: Can not use only one preshared-key for one peer to WireGuard: Cannot use only one preshared-key for one peer.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2634: remove autogeneration of interface "ip section" from vyatta-cfg-system.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2635: SSH: migrate to get_config_dict().
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2636: get_config_dict() shall always return a list on <multi/> nodes.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2637: Vlan is not removed from the system.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2638: FRR: New framework for configuring FRR .
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2639: sort output of show vpn ipsec sa .
Aug 29 2021, 2:10 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2640: Running VyOS inside Docker containers.
Aug 29 2021, 2:09 PM · VyOS 1.3 Equuleus (1.3.3)
erkin renamed T2642: sshd fails to start due to configuration error from sshd Broken on Latest Rolling Release to sshd fails to start due to configuration error.
Aug 29 2021, 2:09 PM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2643: show interfaces does not scale with terminal width from Show Interface Command Issues to show interfaces does not scale with terminal width.
Aug 29 2021, 2:08 PM · VyOS 1.3 Equuleus (1.3.0)
erkin changed Issue type from unspecified to bug on T2644: Bonding interfaces cannot be disabled.
Aug 29 2021, 2:08 PM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2644: Bonding interfaces cannot be disabled from Disabling Bonded Interfaces Broken to Bonding interfaces cannot be disabled.
Aug 29 2021, 2:07 PM · VyOS 1.3 Equuleus (1.3.0)
erkin changed Issue type from improvement to bug on T2645: Editing route-map action requires adding a new rule.
Aug 29 2021, 2:07 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin renamed T2645: Editing route-map action requires adding a new rule from Editing route-map Action Requires New Rule to Editing route-map action requires adding a new rule.
Aug 29 2021, 2:07 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin set Issue type to bug on T2646: Sysctl for IPv4 ECMP Hash Policy Not Set.
Aug 29 2021, 2:06 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2648: router-advert: erroneous syslog warning about invalid all-zeros prefix.
Aug 29 2021, 2:06 PM · VyOS 1.3 Equuleus (1.3.0), test
erkin set Issue type to internal on T2649: Ensure configration mode scripts conform to coding guidelines.
Aug 29 2021, 2:05 PM · VyOS 1.3 Equuleus
erkin set Issue type to improvement on T2650: interfaces bridge, bonding: revert back to per-interface membership syntax.
Aug 29 2021, 2:05 PM · VyOS 1.3 Equuleus (1.3.0)
erkin added a subtask for T3356: Script for remote file transfers: T2651: Generate CLI abstraction for options passed to CURL and SSH client.
Aug 29 2021, 2:05 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin added a parent task for T2651: Generate CLI abstraction for options passed to CURL and SSH client: T3356: Script for remote file transfers.
Aug 29 2021, 2:05 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2651: Generate CLI abstraction for options passed to CURL and SSH client.
Aug 29 2021, 2:03 PM · VyOS 1.3 Equuleus (1.3.0)
erkin updated the task description for T2652: nat configuration conflicts with wan-load-balance nat rules.
Aug 29 2021, 2:03 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2653: "set interfaces" Python handler code improvements - next iteration.
Aug 29 2021, 2:02 PM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2654: Multiple names unable to be assigned to the same static mapping from Multiple names unable to be assigned to the same static mapping. to Multiple names unable to be assigned to the same static mapping.
Aug 29 2021, 2:02 PM · VyOS 1.3 Equuleus (1.3.2)
erkin set Issue type to internal on T2655: ConfigError formatting issue.
Aug 29 2021, 2:01 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav committed rVYOSONEX0de23064b9d5: interfaces: T3777: Does not delete empty eui64 address.
Aug 29 2021, 2:01 PM
GitHub <noreply@github.com> committed rVYOSONEXa0e115d55800: Merge pull request #981 from sever-sever/T3777 (authored by c-po).
Aug 29 2021, 2:01 PM
erkin set Issue type to internal on T2656: XML: Python default dictionary returns wrong dictionary level(s).
Aug 29 2021, 2:01 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to improvement on T2657: dhcp-server hostfile-update allows any DHCP client to inject an arbitrary hostname into /etc/hosts and pdns-recursor's zones (DNS spoofing as a vector for MITM attacks).
Aug 29 2021, 2:01 PM · VyOS Rolling
erkin set Issue type to bug on T2658: Interface description comment display error.
Aug 29 2021, 2:01 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2659: Add fastnetmon (DDoS detection) support.
Aug 29 2021, 2:01 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2660: XML: Python default dictionary does not obey underscore (_) when flat is False.
Aug 29 2021, 2:01 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to improvement on T2661: SSTP wrong certificates check.
Aug 29 2021, 2:00 PM · VyOS 1.3 Equuleus (1.3.0)
zsdc committed rVYOSONEXc78daaf0f939: wireguard: T3763: Fixed uninitialized port issue.
Aug 29 2021, 2:00 PM
GitHub <noreply@github.com> committed rVYOSONEXafef799f215d: Merge pull request #982 from zdc/T3763-sagitta (authored by c-po).
Aug 29 2021, 2:00 PM
zsdc committed rVYOSONEX8d0207f87cf6: wireguard: T3763: The port availability check fix.
Aug 29 2021, 2:00 PM
erkin set Issue type to internal on T2662: get_config_dict includes node name as key only for tag and leaf nodes.
Aug 29 2021, 2:00 PM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2663: SNMP does not listen on the specified address from SNMP does not listen to the specified address to SNMP does not listen on the specified address.
Aug 29 2021, 2:00 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2665: vyos.xml.defaults for tag nodes.
Aug 29 2021, 1:59 PM · VyOS 1.4 Sagitta
erkin set Issue type to feature on T2666: Packet Processing with eBPF and XDP.
Aug 29 2021, 1:59 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2667: get_config_dict: Use utility function for non-empty path argument.
Aug 29 2021, 1:59 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2668: get_config_dict: add get_first_key arg to utility function get_sub_dict.
Aug 29 2021, 1:59 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2669: DHCP-server overlapping ranges..
Aug 29 2021, 1:58 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin set Issue type to internal on T2670: Remove dependency on show_config from get_config_dict.
Aug 29 2021, 1:58 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2671: SNMP failed to start after the system was rebooted.
Aug 29 2021, 1:58 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2673: After the bridge is configured with Mac, bridge is automatically disabled.
Aug 29 2021, 1:58 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2675: DNS service failed to start.
Aug 29 2021, 1:57 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2676: NTP: migrate to get_config_dict() implementation.
Aug 29 2021, 1:57 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2677: Proposal for clearer DHCPv6-PD configuration options.
Aug 29 2021, 1:57 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2678: High RAM usage on SSH logins with lots of IPv6 routes in the routing table..
Aug 29 2021, 1:57 PM · VyOS 1.3 Equuleus (1.3.0)