Page MenuHomeVyOS Platform
Feed Search

Sep 10 2021

c-po claimed T3818: BGP export route-map only works after bgpd restart.
Sep 10 2021, 12:25 PM · VyOS 1.4 Sagitta
c-po added a comment to T3818: BGP export route-map only works after bgpd restart.

Can you please share your entire config and what to type to reproduce it? Happy to have a look later on.

Sep 10 2021, 12:24 PM · VyOS 1.4 Sagitta
c-po added a comment to T3818: BGP export route-map only works after bgpd restart.

Can you please retrst with the latest 1.4? the was a bug related to route-maps in bgpd

Sep 10 2021, 11:02 AM · VyOS 1.4 Sagitta
c-po closed T3820: PowerDNS recursor - update from 4.3 -> 4.4 to sync with current as Resolved.
Sep 10 2021, 8:51 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po changed Issue type from feature to upgrade on T3819: Upgrade Salt Stack 3002.3 -> 3003 release train.
Sep 10 2021, 8:51 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3820: PowerDNS recursor - update from 4.3 -> 4.4 to sync with current from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 10 2021, 8:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po changed Issue type from feature to upgrade on T3820: PowerDNS recursor - update from 4.3 -> 4.4 to sync with current.
Sep 10 2021, 8:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po claimed T3820: PowerDNS recursor - update from 4.3 -> 4.4 to sync with current.
Sep 10 2021, 8:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po created T3820: PowerDNS recursor - update from 4.3 -> 4.4 to sync with current.
Sep 10 2021, 8:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3819: Upgrade Salt Stack 3002.3 -> 3003 release train from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 10 2021, 8:48 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po closed T3819: Upgrade Salt Stack 3002.3 -> 3003 release train as Resolved.
Sep 10 2021, 8:48 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3819: Upgrade Salt Stack 3002.3 -> 3003 release train from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 10 2021, 8:48 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3819: Upgrade Salt Stack 3002.3 -> 3003 release train from Need Triage to 1.3.0-epa1 on the VyOS 1.3 Equuleus board.
Sep 10 2021, 8:48 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po added a project to T3819: Upgrade Salt Stack 3002.3 -> 3003 release train: VyOS 1.4 Sagitta.
Sep 10 2021, 8:13 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po changed the status of T3819: Upgrade Salt Stack 3002.3 -> 3003 release train from Open to In progress.
Sep 10 2021, 8:09 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po created T3819: Upgrade Salt Stack 3002.3 -> 3003 release train.
Sep 10 2021, 8:09 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po added a comment to T915: MPLS Support.

Setting this to resolved as implementation is almost complete. Please file individual tasks for bugs so we can properly track them in the 1.3 release cycle.

Sep 10 2021, 6:57 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po closed T915: MPLS Support as Resolved.
Sep 10 2021, 6:56 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Sep 9 2021

c-po committed rVYOSONEX310eb1b52704: wireguard: T3642: improve "set" commands for generated key-pairs.
Sep 9 2021, 9:17 PM
c-po committed rVYOSONEXa50095408e9e: wireguard: T3642: add deprecation notice to old commands for key generation.
Sep 9 2021, 9:17 PM
c-po committed rVYOSONEX9f1a737d46c2: pki: T3642: use f'ormated strings in print().
Sep 9 2021, 9:17 PM
c-po added a comment to T3812: Vyos and frr route-map config out of sync.

Will be fixed in tomorrows rolling - thanks for reporting this.

Sep 9 2021, 3:33 PM · VyOS 1.4 Sagitta
c-po closed T3812: Vyos and frr route-map config out of sync as Resolved.
Sep 9 2021, 3:31 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX3a0e586544fb: policy: T3812: FRR bgpd also knows about route-maps because of rpki.
Sep 9 2021, 3:30 PM
c-po changed the status of T3812: Vyos and frr route-map config out of sync from Open to Confirmed.
Sep 9 2021, 3:09 PM · VyOS 1.4 Sagitta
c-po moved T3817: PKI: add "import" keyword when in "configure" mode from Open to Backlog on the VyOS 1.4 Sagitta board.
Sep 9 2021, 3:07 PM · VyOS 1.4 Sagitta (1.4.0-GA)
c-po created T3817: PKI: add "import" keyword when in "configure" mode.
Sep 9 2021, 3:07 PM · VyOS 1.4 Sagitta (1.4.0-GA)
c-po added a comment to T3815: pki : the file command 'generate pki wireguard key-pair file' is not working.
cpo@LR1.wue3:~$ generate pki wireguard key-pair file test
Private key: QG039BeDoy2MXKxQwFRhYYea7B50crYvZ1RUn+N0c3A=
Public key: iXVG4GSHc0O7NHgX47DhhNO/WWSTZS83/eF2z4GHYSE=
File written to /config/auth/test_public.key
File written to /config/auth/test_private.key
Sep 9 2021, 2:51 PM · VyOS 1.4 Sagitta
c-po closed T3815: pki : the file command 'generate pki wireguard key-pair file' is not working as Resolved.
Sep 9 2021, 2:50 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXbfffe55b2b7c: pki: wireguard: T3815: do not bail out early so keys can be written to file.
Sep 9 2021, 2:50 PM
c-po added a comment to T3816: Error after entering outbound-interface command in NAT.

https://github.com/vyos/vyatta-cfg/commit/68fbc0c20a2b1c92481a9028dd7d21970d4e997b

Sep 9 2021, 12:10 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po closed T3816: Error after entering outbound-interface command in NAT as Resolved.
Sep 9 2021, 12:09 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3816: Error after entering outbound-interface command in NAT from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 9 2021, 12:04 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po changed the status of T3816: Error after entering outbound-interface command in NAT from Open to In progress.
Sep 9 2021, 12:04 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po edited a custom field on T3814: wireguard: commit error showing incorrect peer name from the configured name.
Sep 9 2021, 8:47 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po closed T3814: wireguard: commit error showing incorrect peer name from the configured name as Resolved.
Sep 9 2021, 8:47 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po committed rVYOSONEX4d2201eed00a: vyos.configdict: T3814: use no_tag_node_value_mangle in get_interface_dict().
Sep 9 2021, 8:44 AM
c-po committed rVYOSONEXab75b9bca0fc: vyos.configdict: T3814: use no_tag_node_value_mangle in get_interface_dict().
Sep 9 2021, 8:44 AM
c-po committed rVYOSONEXc593bf7f5977: openvpn: T3805: drop privileges using systemd - required for rtnetlink.
Sep 9 2021, 7:17 AM
c-po committed rVYOSONEX451a7d6d97ee: openvpn: T3805: use vyos.util.makedir() to create system directories.
Sep 9 2021, 7:17 AM
c-po closed T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface as Resolved.
Sep 9 2021, 7:16 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 9 2021, 7:16 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface from Need Triage to 1.3.0-epa1 on the VyOS 1.3 Equuleus board.
Sep 9 2021, 7:16 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3814: wireguard: commit error showing incorrect peer name from the configured name from Open to In Progress on the VyOS 1.4 Sagitta board.
Sep 9 2021, 5:58 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po claimed T3814: wireguard: commit error showing incorrect peer name from the configured name.
Sep 9 2021, 5:55 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po added a comment to T3809: Not possible to add existing ca?.

Your problem is that this is not a CA certificate, it's the servers certificate.

Sep 9 2021, 5:53 AM · VyOS 1.4 Sagitta

Sep 8 2021

c-po added a comment to T3809: Not possible to add existing ca?.

Can you share your CAs public cert for testing?

Sep 8 2021, 6:21 PM · VyOS 1.4 Sagitta
c-po added a comment to T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface.

A new ISO 1.4-rolling-202109081242 is currently build - you may check in 30 minutes and try if this works for you - it did in my example config.

Sep 8 2021, 12:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po added a comment to T3813: Some custom sysctl parameters can't be applied bug.

That would only work if accept_local will be added as proper CLI node on the tunnel interface, or use set system sysctl parameter net.ipv4.conf.default.accept_local value '1'

Sep 8 2021, 12:40 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
c-po committed rVYOSONEX588cc03a6141: openvpn: T3805: fix bool logic in verify_pki() for client mode.
Sep 8 2021, 12:39 PM
c-po committed rVYOSONEX2647edc30f1e: openvpn: T3805: drop privileges using systemd - required for rtnetlink.
Sep 8 2021, 12:39 PM
c-po committed rVYOSONEX84e912ab2f58: openvpn: T3805: use vyos.util.makedir() to create system directories.
Sep 8 2021, 12:39 PM
c-po committed rVYOSONEX63fbd8c663c8: openvpn: T3805: use vyos.util.write_file() to store certificates.
Sep 8 2021, 12:39 PM
c-po moved T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 8 2021, 12:38 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po changed the status of T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface from Confirmed to Needs testing.
Sep 8 2021, 12:37 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po changed the status of T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface from Open to Confirmed.
Sep 8 2021, 12:28 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Sep 7 2021

c-po edited projects for T3796: Wireguard interfaces are not shown in op-mode, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux.
Sep 7 2021, 8:54 PM · VyOS 1.2 Crux (VyOS 1.2.9)
c-po added a comment to T3796: Wireguard interfaces are not shown in op-mode.

@absolutesantaja this is definately a bug in the 1.2.9 op-mode commands

Sep 7 2021, 8:53 PM · VyOS 1.2 Crux (VyOS 1.2.9)
c-po added a comment to T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface.

Can you please share a version of your anonymized client configuration?

Sep 7 2021, 8:35 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po claimed T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface.
Sep 7 2021, 3:26 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po edited a custom field on T3807: Op Command "show interfaces wireguard" does not show the output.
Sep 7 2021, 9:53 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po closed T3807: Op Command "show interfaces wireguard" does not show the output as Resolved.
Sep 7 2021, 9:53 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3807: Op Command "show interfaces wireguard" does not show the output from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 7 2021, 9:53 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3807: Op Command "show interfaces wireguard" does not show the output from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 7 2021, 9:53 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3807: Op Command "show interfaces wireguard" does not show the output from Need Triage to 1.3.0-epa1 on the VyOS 1.3 Equuleus board.
Sep 7 2021, 9:52 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po committed rVYOSONEXadca504a2c5c: scripts: op-mode: T3807: bugfix node.def generator.
Sep 7 2021, 9:52 AM
c-po committed rVYOSONEXff25cb35c93e: op-mode: xml: improve "show interfaces <type>" help text.
Sep 7 2021, 9:52 AM
c-po committed rVYOSONEX7623e37c918c: scripts: op-mode: T3807: bugfix node.def generator.
Sep 7 2021, 9:42 AM
c-po committed rVYOSONEXbd2c79ebb8ab: op-mode: xml: improve "show interfaces <type>" help text.
Sep 7 2021, 9:40 AM
c-po added a comment to T3807: Op Command "show interfaces wireguard" does not show the output.

Same happens to other op-mode commands:

Sep 7 2021, 9:06 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po added a comment to T3809: Not possible to add existing ca?.

please refer to the PKI documentation at https://docs.vyos.io/en/latest/configuration/pki/index.html or https://blog.vyos.io/pki-and-ipsec-ikev2-remote-access-vpn about how the PKI feature is used.

Sep 7 2021, 8:00 AM · VyOS 1.4 Sagitta
c-po reassigned T2541: Openvpn Radius authentication support from c-po to UnicronNL.
Sep 7 2021, 7:40 AM · VyOS 1.3 Equuleus (1.3.8), VyOS 1.4 Sagitta (1.4.0)
c-po committed rVYOSONEXd9f20383323a: login: T971 allow quoting in public-keys options (authored by plett).
Sep 7 2021, 7:38 AM
c-po added a comment to T3794: MACsec interfaces in down state after create .

I tested it on ESXi

Sep 7 2021, 6:19 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Sep 6 2021

c-po added a comment to T3796: Wireguard interfaces are not shown in op-mode.
Sep 6 2021, 7:41 PM · VyOS 1.2 Crux (VyOS 1.2.9)
c-po closed T3794: MACsec interfaces in down state after create as Invalid.
Sep 6 2021, 7:34 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po added a comment to T3794: MACsec interfaces in down state after create .

Works as designed. Note that the MACSec interface will only change its state to u/u after a successful key-exchange.

Sep 6 2021, 7:32 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po committed rVYOSONEXc6039b9a82fe: ifconfig: T3806: "ipv6 address no_default_link_local" required for MTU < 1280.
Sep 6 2021, 7:28 PM
c-po claimed T3794: MACsec interfaces in down state after create .
Sep 6 2021, 7:26 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3800: DHCPv6 client get incorrect mask /128 from Open to In Progress on the VyOS 1.4 Sagitta board.
Sep 6 2021, 7:26 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po closed T3803: Add source-address option to the ping CLI as Resolved.
Sep 6 2021, 7:26 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3803: Add source-address option to the ping CLI from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 6 2021, 7:26 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3803: Add source-address option to the ping CLI from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 6 2021, 7:26 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa1)
c-po closed T3806: Don't set link local ipv6 address if MTU less then 1280 as Resolved.
Sep 6 2021, 7:25 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3806: Don't set link local ipv6 address if MTU less then 1280 from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 6 2021, 7:25 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3806: Don't set link local ipv6 address if MTU less then 1280 from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 6 2021, 7:25 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa1)
c-po committed rVYOSONEX3cd598794515: pki: eapol: T3642: only add "pki" key to interface dict if pki is configured.
Sep 6 2021, 7:24 PM
c-po committed rVYOSONEXb45cef9185cc: pki: eapol: T3642: use write_file() to store certificates.
Sep 6 2021, 7:24 PM
c-po committed rVYOSONEX84a429b41175: ifconfig: T3806: "ipv6 address no_default_link_local" required for MTU < 1280.
Sep 6 2021, 7:24 PM
c-po changed the status of T3806: Don't set link local ipv6 address if MTU less then 1280 from Open to In progress.
Sep 6 2021, 6:33 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa1)
c-po added a comment to T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface.

Does it work if you grand the capabilities to the openvpn group in /etc/security/capability.conf?

Sep 6 2021, 4:41 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po committed rVYOSONEX591eee82296b: T3803: add source-address option to the op mode ping CLI. (authored by dmbaturin).
Sep 6 2021, 4:39 PM
c-po committed rVYOSONEX7546e249708d: https: T2230: only support TLS1.2 and TLS1.3.
Sep 6 2021, 3:24 PM
c-po committed rVYOSONEX407d814966d0: vyos.util: T2755: rename dict_search() function args to match other….
Sep 6 2021, 10:15 AM
c-po committed rVYOSONEX1fc69810450a: pki: T3642: verify() that we can not delete certificates still referenced in CLI.
Sep 6 2021, 10:13 AM
c-po committed rVYOSONEXacc6e461a92b: vyos.util: add function to search a key recursively in a dictionary.
Sep 6 2021, 10:13 AM
c-po committed rVYOSONEX9d0c37fbbc91: vyos.util: T2755: rename dict_search() function args to match other….
Sep 6 2021, 10:13 AM
c-po committed rVYOSONEXb060fb70cdca: pki: xml: T3642: use "txt" as format identifier.
Sep 6 2021, 10:13 AM
c-po committed rVYOSONEXc14bb9ab3811: wwan: T3620: op-mode: not all commands supported by all modems - add info….
Sep 6 2021, 6:24 AM
c-po committed rVYOSONEX10814c4d3360: wwan: T3620: op-mode: not all commands supported by all modems - add info….
Sep 6 2021, 6:24 AM