Page MenuHomeVyOS Platform
Feed All Stories

Aug 30 2021

erkin set Issue type to bug on T2575: pppoe-server: does not possibly assign IP address.
Aug 30 2021, 5:40 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2576: "show interfaces" does not return VTI.
Aug 30 2021, 5:40 AM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2577: /31 addresses are unable to be used in many cases from /31 addresses are unable to be used in many cases. to /31 addresses are unable to be used in many cases.
Aug 30 2021, 5:39 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2578: ipaddrcheck unaware of /31 host addresses - can no longer assign /31 mask to interface addresses.
Aug 30 2021, 5:39 AM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2579: The root task for VRF features from The root task for VRF features. to The root task for VRF features.
Aug 30 2021, 5:35 AM · VyOS 1.3 Equuleus (1.3.6)
erkin renamed T2580: Support for ip pools for ippoe from be able to setup ip pools for ippoe to Support for ip pools for ippoe.
Aug 30 2021, 5:35 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
erkin set Issue type to feature on T2581: webproxy: implement proxy chaining.
Aug 30 2021, 5:34 AM · VyOS 1.3 Equuleus (1.3.0), vyatta-webproxy
erkin set Issue type to internal on T2582: Script daemon to offload processing during commit.
Aug 30 2021, 5:34 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2583: vyos-hostsd improvements (partial rewrite).
Aug 30 2021, 5:34 AM · VyOS Rolling
erkin set Issue type to feature on T2584: pppoe-server NAS-Filter-Rule attribute.
Aug 30 2021, 5:33 AM · VyOS Rolling
erkin set Issue type to bug on T2585: Unable to access the Internet after opening PPPoE on-demand dialing.
Aug 30 2021, 5:33 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2586: WWAN default route is not installed into VRF.
Aug 30 2021, 5:33 AM · VyOS 1.3 Equuleus (1.3.0)
erkin placed T2587: Cannot enable the interface when the MTU is set to less than 1280 up for grabs.
Aug 30 2021, 5:33 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2588: Add support for default values to the interface-definition format.
Aug 30 2021, 5:32 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2589: delete pseudo-ethernet failed.
Aug 30 2021, 5:32 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2590: DHCPv6 not updating nameservers and search domains since replacing isc-dhcp-client with WIDE dhcp6c.
Aug 30 2021, 5:31 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.3 Equuleus (1.3.7)
erkin set Issue type to bug on T2591: show command has wrong interfaces ordering.
Aug 30 2021, 5:31 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2592: dhcp-relay discarding packets on valid interfaces.
Aug 30 2021, 5:31 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2593: source NAT translation port can not be set when translation address is set to masquerade.
Aug 30 2021, 5:31 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to improvement on T2594: Missing firmware for iwlwifi.
Aug 30 2021, 5:31 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to upgrade on T2595: Update Linux Kernel to v4.19.128.
Aug 30 2021, 5:26 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2596: Allow specifying source IP for 'add system image'.
Aug 30 2021, 5:26 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2597: Add more options to API.
Aug 30 2021, 5:26 AM
erkin set Issue type to bug on T2599: "show interfaces" does not list VIF interfaces in ascending order.
Aug 30 2021, 5:26 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2600: RADIUS system login configuration rendered wrongly.
Aug 30 2021, 5:25 AM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2601: pppoe-server: Cannot disable CCP from pppoe-server: does not possible to disable ccp to pppoe-server: Cannot disable CCP.
Aug 30 2021, 5:25 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to improvement on T2602: pptp/sstp/l2tp add possibility enable or disable CCP.
Aug 30 2021, 5:24 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to improvement on T2603: pppoe-server: reduce min MTU.
Aug 30 2021, 5:24 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
erkin set Issue type to internal on T2604: Remove use of is_tag in system-syslog.py.
Aug 30 2021, 5:20 AM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2607: Support for pppoe-server radius mode auth and config radius accouting port from pppoe-server radius mode auth, config radius accouting port to Support for pppoe-server radius mode auth and config radius accouting port.
Aug 30 2021, 5:19 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2608: delete pseudo-ethernet failed (another error type).
Aug 30 2021, 5:18 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2609: router-advert: radvd does not start when lifetime is improperly configured.
Aug 30 2021, 5:18 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2610: default-lifetime is not reflected in the RA message.
Aug 30 2021, 5:18 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2611: Prefix list names are shared between ipv4 and ipv6.
Aug 30 2021, 5:12 AM · VyOS 1.3 Equuleus (1.3.4)
erkin set Issue type to bug on T2612: HTTPS API, changing API key fails but goes through.
Aug 30 2021, 5:12 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
erkin set Issue type to internal on T2614: Add an option to mangle dict keys to vyos.config.get_config_dict().
Aug 30 2021, 5:12 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2615: Provide an explicit option for server fingerprint in commit archive, and make insecure the default.
Aug 30 2021, 5:11 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2616: BFD Configuration causes flapping.
Aug 30 2021, 5:11 AM
erkin set Issue type to internal on T2617: Rewrite vyatta-op-quagga "show" to XML.
Aug 30 2021, 5:11 AM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2618: Conversion from 1.2 to 1.3 lost RADVD prefix autonomous-flag setting.
Aug 30 2021, 5:08 AM · VyOS 1.3 Equuleus (1.3.0)
erkin added a project to T2619: Bug: Changes in NAT or ZONES from 1.2 to 1.3: VyOS 1.3 Equuleus.
Aug 30 2021, 5:07 AM · VyOS 1.3 Equuleus (1.3.0)
dmbaturin empowered SrividyaA as an administrator.
Aug 30 2021, 4:05 AM
debiansid created T3784: can't build iso with custom built iptables .
Aug 30 2021, 2:35 AM · VyOS 1.4 Sagitta

Aug 29 2021

c-po committed rVYOSONEX147f655a69cd: vyos.ethtool: T3163: add check_speed_duplex() method.
Aug 29 2021, 9:19 PM
c-po committed rVYOSONEX324aa9598c7d: vyos.ethtool: T3163: prefix class internal data structures with _.
Aug 29 2021, 9:19 PM
c-po committed rVYOSONEXeac8915413ce: vyos.ethtool: T3163: drop obsoleted is_fixed_lro() method.
Aug 29 2021, 8:15 PM
c-po added a comment to T3619: Performance Degradation 1.2 --> 1.3 | High ksoftirqd CPU usage.

An analysis of the code base from VyOS 1.2 -> 1.3 -> 1.4 revealed the following "root-cause"

Aug 29 2021, 8:06 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po changed the status of T3619: Performance Degradation 1.2 --> 1.3 | High ksoftirqd CPU usage from Open to In progress.
Aug 29 2021, 7:39 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po changed the status of T3514: NIC flap at any interface change from On hold to In progress.
Aug 29 2021, 7:05 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added a comment to T1683: Difficulty monitoring VyOS through SNMP.

VyOS 1.4 uses persistent OpenVPN interfaces.

Aug 29 2021, 6:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po committed rVYOSONEXe5796497d558: interfaces: T3777: Does not delete empty eui64 address (authored by Viacheslav).
Aug 29 2021, 6:35 PM
c-po committed rVYOSONEX0deb1709930f: xml: add missing "u32:" value declarator on integer ranges.
Aug 29 2021, 6:34 PM
Viacheslav added a comment to T3782: Ingress Shaping with IFB No Longer Functional with 1.3.
Aug 29 2021, 6:11 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
trystan added a comment to T3782: Ingress Shaping with IFB No Longer Functional with 1.3.

I can confirm that applying

Aug 29 2021, 5:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav added a comment to T3782: Ingress Shaping with IFB No Longer Functional with 1.3.

Possible bug after this commit https://github.com/vyos/vyos-1x/pull/621/commits/ede2972be4c49962a04b1addb9df6ce58f2d9f42
As it works in vyos-1.3-rolling-202011 before that commit.

Aug 29 2021, 5:39 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav changed the status of T3777: adding IPv6 EUI64 address fails commit in 1.3.0-rc6 from Open to Needs testing.
Aug 29 2021, 5:18 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav closed T3708: isisd and gre-bridge commit error as Resolved.

1.3 fixed in T3779

Aug 29 2021, 5:07 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav added a comment to T1683: Difficulty monitoring VyOS through SNMP.

The issue may be with OpenVPN/dynamic interfaces only, without the option "persist".
In that case, if no connectivity between interfaces it tried to re-add the interface "down/up" vtunX with a new SNMP index. And it will be in the loop until connectivity will be restored with the remote site.

Aug 29 2021, 4:39 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sempervictus added a comment to T2191: Using tallow to block sshd probes.

This can be done via the tc kernel module AFAIK. Something like fireqos would be great to have in here, but they're pretty opinionated in how they do things in their tools so probably not a viable drop-in solution.
This can also be done with OSSEC using active response, either by building an OSSEC agent into the image (client key management is kind of a PITA) or by way of remote feed for FW log events showing attempts to connect with an active-response script to temporarily block the offenders with progressively longer blocks on repeat offenses.

Aug 29 2021, 4:06 PM · VyOS 1.3 Equuleus (1.3.6)
sempervictus added a comment to T1942: hardware info collector .

lshw does this already

Aug 29 2021, 4:00 PM · VyOS Rolling
Viacheslav added a comment to T3782: Ingress Shaping with IFB No Longer Functional with 1.3.

Difference between 1.2 and 1.3
1.3 don't have option qdisc ingress ffff: dev eth0 parent ffff:fff1 ----------------

Aug 29 2021, 3:56 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
sempervictus added a comment to T1890: Metatask: rewrite flow-accounting to XML and Python.

I added the kernel netflow module to my pull request a while back - collects and forwards flows to a destination defined in the module parameter set at load-time.
If we want to actually process flows on-system, there's a bunch of modern tooling for that; but in terms of just aggregation and export in canonical format, the kernel module is the best way to go IMO due to the fact that it works at the same tier as the network code itself (ring0).

Aug 29 2021, 3:56 PM · VyOS 1.3 Equuleus (1.3.0)
sempervictus added a comment to T1683: Difficulty monitoring VyOS through SNMP.

Not seeing this issue when setting "description" field - we've run it in production for years bridging our OpenStack and datacenter environments, and the names show up correctly (blanked sensitive details):

image.png (1×1 px, 258 KB)

Aug 29 2021, 3:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sempervictus added a comment to T1619: Migrate user home directories on image update.

From a post-exploitation perspective, this would permit attackers who've compromised an older vulnerable version to persist their payloads in the shell elements (~/.bashrc and friends) across upgrades.

Aug 29 2021, 3:46 PM
sempervictus added a comment to T1437: First boot configuration support.

This seems similar to the "configuration drive" option for OpenStack, which is already handled by cloud-init. Might be handy to implement as a cloud-init local data source and just include CI on all builds since thats becoming an industry standard even on bare metal.

Aug 29 2021, 3:44 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3774: atop logs are not limited in size.

How about CLI set system syslog atop file 5
That means save the latest 5 files.

Aug 29 2021, 3:23 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav assigned T3763: wireguard checks if port already binding to zsdc.
Aug 29 2021, 3:07 PM · VyOS 1.4 Sagitta
sempervictus added a comment to T2888: Cloud-init images refuse to work with network-based datasource such as Ec2 or OpenStack (but do work with OpenStack's config drive).

I've managed to get this working in our own builds by restoring the openstack target and making some changes there - runs fine in AWS, even with a grsec kernel and hardened userspace (Xen is often the worst visor for ring0 memory defenses).

Aug 29 2021, 2:16 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to unspecified on T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting.
Aug 29 2021, 2:15 PM · VyOS 1.2 Crux (VyOS 1.2.8)
erkin set Issue type to bug on T2621: show interfaces repeats interface description if it is longer then an arbitrary number of characters.
Aug 29 2021, 2:15 PM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2622: Pseudo-ethernet interface config disappears across versions from An issue with config migration (interface pseudo ethernet) to Pseudo-ethernet interface config disappears across versions.
Aug 29 2021, 2:15 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2623: Creating sit tunnel fails with “Can not set “local” for tunnel sit tun1 at tunnel creation”.
Aug 29 2021, 2:14 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
erkin set Issue type to bug on T2624: Serial Console: fix migration script for configured powersave and no console.
Aug 29 2021, 2:14 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2626: Changing pseudo-ethernet mode, throws CLI error.
Aug 29 2021, 2:13 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to improvement on T2627: 'system static-host-mapping' only allows one IP address per hostname, it should allow one IPv4 and one IPv6 simultaneously.
Aug 29 2021, 2:13 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2628: Make logs more user friendly..
Aug 29 2021, 2:12 PM · VyOS 1.3 Equuleus (1.3.5)
erkin set Issue type to bug on T2629: VXLAN interfaces don't actually allow you to configure most settings.
Aug 29 2021, 2:12 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2630: Allow Interface MTU over 9000.
Aug 29 2021, 2:12 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2633: Error with arp_accept on tun interface.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2631: l2tp, sstp, pptp add option to disable radius accounting.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2632: WireGuard: Cannot use only one preshared-key for one peer from WireGuard: Can not use only one preshared-key for one peer to WireGuard: Cannot use only one preshared-key for one peer.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2634: remove autogeneration of interface "ip section" from vyatta-cfg-system.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2635: SSH: migrate to get_config_dict().
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to internal on T2636: get_config_dict() shall always return a list on <multi/> nodes.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2637: Vlan is not removed from the system.
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2638: FRR: New framework for configuring FRR .
Aug 29 2021, 2:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2639: sort output of show vpn ipsec sa .
Aug 29 2021, 2:10 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to feature on T2640: Running VyOS inside Docker containers.
Aug 29 2021, 2:09 PM · VyOS 1.3 Equuleus (1.3.3)
erkin renamed T2642: sshd fails to start due to configuration error from sshd Broken on Latest Rolling Release to sshd fails to start due to configuration error.
Aug 29 2021, 2:09 PM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2643: show interfaces does not scale with terminal width from Show Interface Command Issues to show interfaces does not scale with terminal width.
Aug 29 2021, 2:08 PM · VyOS 1.3 Equuleus (1.3.0)
erkin changed Issue type from unspecified to bug on T2644: Bonding interfaces cannot be disabled.
Aug 29 2021, 2:08 PM · VyOS 1.3 Equuleus (1.3.0)
erkin renamed T2644: Bonding interfaces cannot be disabled from Disabling Bonded Interfaces Broken to Bonding interfaces cannot be disabled.
Aug 29 2021, 2:07 PM · VyOS 1.3 Equuleus (1.3.0)
erkin changed Issue type from improvement to bug on T2645: Editing route-map action requires adding a new rule.
Aug 29 2021, 2:07 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin renamed T2645: Editing route-map action requires adding a new rule from Editing route-map Action Requires New Rule to Editing route-map action requires adding a new rule.
Aug 29 2021, 2:07 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin set Issue type to bug on T2646: Sysctl for IPv4 ECMP Hash Policy Not Set.
Aug 29 2021, 2:06 PM · VyOS 1.3 Equuleus (1.3.0)
erkin set Issue type to bug on T2648: router-advert: erroneous syslog warning about invalid all-zeros prefix.
Aug 29 2021, 2:06 PM · VyOS 1.3 Equuleus (1.3.0), test
erkin set Issue type to internal on T2649: Ensure configration mode scripts conform to coding guidelines.
Aug 29 2021, 2:05 PM · VyOS 1.3 Equuleus
erkin set Issue type to improvement on T2650: interfaces bridge, bonding: revert back to per-interface membership syntax.
Aug 29 2021, 2:05 PM · VyOS 1.3 Equuleus (1.3.0)
erkin added a subtask for T3356: Script for remote file transfers: T2651: Generate CLI abstraction for options passed to CURL and SSH client.
Aug 29 2021, 2:05 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin added a parent task for T2651: Generate CLI abstraction for options passed to CURL and SSH client: T3356: Script for remote file transfers.
Aug 29 2021, 2:05 PM · VyOS 1.3 Equuleus (1.3.0)