I can not reproduce this issue in 1.3-beta-202109050342 and 1.4-rolling-202109050613
- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
All Stories
Sep 5 2021
Here is the screenshot of vulnerability reproduction.
I tried to reproduce the vulnerability we found on v1.2.7 version of VyOS and debug the vulnerability, hoping to provide you with a detailed vulnerability report.
Sep 4 2021
The patch worked up through vyos-1.3-beta-202108311126. It stopped
Client should also enable "SLAAC"
Works as expected it seems https://serverfault.com/a/918480 and https://teamarin.net/2018/06/25/common-mistake-dhcpv6/
Duplicate of T3772
- The problem about DHCPv6 has been solved
- The communication problem has been solved
It seems that the problem is related to IPv6 MSS. When I set IPv6 MSS to 1280 and IPv4 MSS to 1452, the problem seems to disappear
Updated default response to "No"
I don't see any issue yet with multiple static addresses
vyos@r4-1.3:~$ show interfaces
Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface IP Address S/L Description
--------- ---------- --- -----------
eth0 192.168.122.14/24 u/u FOO-BAR
eth1 192.0.2.14/24 u/u FOO
100.64.5.1/24
100.64.6.1/24
2001:db8::199/128adminuser@vyos:~$ show interfaces ethernet eth2
eth2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether 52:54:00:bf:64:0b brd ff:ff:ff:ff:ff:ff inet XX.XXX.XXX.210/28 brd 98.187.179.223 scope global eth2 valid_lft forever preferred_lft forever inet XX.XXX.XXX.212/28 brd 98.187.179.223 scope global secondary eth2 valid_lft forever preferred_lft forever inet XX.XXX.XXX.213/28 brd 98.187.179.223 scope global secondary eth2 valid_lft forever preferred_lft forever inet XX.XXX.XXX.217/28 brd 98.187.179.223 scope global secondary eth2 valid_lft forever preferred_lft forever inet6 fe80::5054:ff:febf:640b/64 scope link valid_lft forever preferred_lft forever Description: WAN Network Interface
I was hoping to get that as well (and have in the past). What could be causing the problem?