Page MenuHomeVyOS Platform
Feed All Stories

Sep 19 2021

lucasec edited a custom field on T3840: dns forwarding: Cache size should allow values > 10k.
Sep 19 2021, 4:29 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec claimed T3840: dns forwarding: Cache size should allow values > 10k.
Sep 19 2021, 4:21 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec created T3840: dns forwarding: Cache size should allow values > 10k.
Sep 19 2021, 4:21 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Sep 18 2021

masimo added a comment to T1968: Allow multiple static routes in dhcp-server.

I'm clearly missing something. I cannot make the configuration as shown by @c-po. If I try to add a 2nd static route, it replaces the first.

Sep 18 2021, 9:02 PM · VyOS 1.4 Sagitta
phoenix committed rVYOSONEX6d3bee0e3c00: OpenConnect: Fix typo in help property.
Sep 18 2021, 8:25 PM
GitHub <noreply@github.com> committed rVYOSONEX3779b32b58eb: Merge pull request #1009 from phoenix0984/equuleus (authored by c-po).
Sep 18 2021, 8:25 PM
c-po committed rVYOSONEXae2dc55aa686: container: T2216: add IPv6 support to container networks.
Sep 18 2021, 8:12 PM
c-po closed T1968: Allow multiple static routes in dhcp-server as Resolved.
Sep 18 2021, 8:11 PM · VyOS 1.4 Sagitta
c-po closed T3838: dhcp-server - sync cli for name-servers to other subsystems as Resolved.
Sep 18 2021, 8:10 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXd411a40a3598: dhcp-server: T3839: support name-servers and domain config per shared-network.
Sep 18 2021, 8:10 PM
c-po committed rVYOSONEX90dffcb3c14e: dhcpv6-server: xml: add description CLI node.
Sep 18 2021, 8:10 PM
c-po committed rVYOSONEX564f05614b6e: dhcp-server: xml: use description building block.
Sep 18 2021, 8:10 PM
c-po committed rVYOSONEXe2f9f4f4e8b2: dhcp-server: T3838: rename dns-server to name-server node.
Sep 18 2021, 8:10 PM
c-po committed rVYOSONEXa4440bd589db: dhcp-server: T1968: allow multiple static-routes to be configured.
Sep 18 2021, 8:10 PM
c-po closed T3839: dhcp-server: Allow configuration of a DNS server and domain name on the shared-network level as Resolved.
Sep 18 2021, 8:08 PM · VyOS 1.4 Sagitta
c-po created T3839: dhcp-server: Allow configuration of a DNS server and domain name on the shared-network level.
Sep 18 2021, 8:08 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3838: dhcp-server - sync cli for name-servers to other subsystems.
Sep 18 2021, 7:42 PM · VyOS 1.4 Sagitta
c-po changed the status of T3838: dhcp-server - sync cli for name-servers to other subsystems from Open to Confirmed.
Sep 18 2021, 7:30 PM · VyOS 1.4 Sagitta
c-po created T3838: dhcp-server - sync cli for name-servers to other subsystems.
Sep 18 2021, 7:30 PM · VyOS 1.4 Sagitta
c-po added a comment to T1968: Allow multiple static routes in dhcp-server.

The following CLI

cpo@LR1.wue3# show service dhcp-server
 shared-network-name LAN {
     subnet 10.0.0.0/24 {
         default-router 10.0.0.1
         dns-server 194.145.150.1
         lease 88
         range 0 {
             start 10.0.0.100
             stop 10.0.0.200
         }
         static-route 194.145.150.0/24 {
             next-hop 1.1.1.1
         }
         static-route 194.145.151.0/24 {
             router 1.1.1.1
         }
     }
 }
Sep 18 2021, 7:09 PM · VyOS 1.4 Sagitta
c-po changed the status of T1968: Allow multiple static routes in dhcp-server from Open to In progress.
Sep 18 2021, 7:08 PM · VyOS 1.4 Sagitta
phoenix triaged T3837: OpenConnect: Fix typo in help property as Low priority.
Sep 18 2021, 4:38 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po closed T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0 as Resolved.
Sep 18 2021, 1:22 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX0ef9c351598d: smoketest: ipsec: only delete nhrp path where it is used.
Sep 18 2021, 1:20 PM
c-po committed rVYOSONEX6f3130ea5c8c: ipsec: vti: T3831: avoid usinf xfrm if_id 0 - implement shift by one.
Sep 18 2021, 1:20 PM
masimo added a comment to T1968: Allow multiple static routes in dhcp-server.

I'm also hitting this issue in 1.4-rolling-202109160217
This task has been kicking around for a while now. What needs to be done to get the code from @ruliane or @elbandi into the rolling build?

Sep 18 2021, 11:19 AM · VyOS 1.4 Sagitta
c-po added a comment to T2738: Modifying configuration in the "interfaces" section from VRRP transition scripts causes configuration lockup and high CPU utilization.

Enabling debugging gives me:

Sep 18 2021, 9:35 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa1)
c-po committed rVYOSONEXdda9f655f949: validator: T2417: bugfix on Python3 f'ormat strings.
Sep 18 2021, 9:27 AM
c-po committed rVYOSONEX24f17e0e41bb: validator: T2417: bugfix on Python3 f'ormat strings.
Sep 18 2021, 9:27 AM
edofullin added a comment to T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.

Are there updates on this issue?

Sep 18 2021, 8:27 AM · VyOS 1.4 Sagitta
c-po added a comment to T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.

Related/Duplicate issue of T3680

Sep 18 2021, 6:46 AM · VyOS 1.4 Sagitta
kroy updated the task description for T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:30 AM · VyOS 1.4 Sagitta
kroy added a comment to T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.

It's worth adding the no-default-route to the dhcp-options and adding a line like

Sep 18 2021, 5:29 AM · VyOS 1.4 Sagitta
kroy renamed T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway from Setting a default IPv6 route while getting IPv4 route via DHCP removes the IPv4 gateway to Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:27 AM · VyOS 1.4 Sagitta
kroy renamed T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway from Setting a default IPv6 route while getting IPv4 route via DHCP removes the IPv4 route to Setting a default IPv6 route while getting IPv4 route via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:27 AM · VyOS 1.4 Sagitta
kroy updated the task description for T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:24 AM · VyOS 1.4 Sagitta
kroy updated the task description for T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:24 AM · VyOS 1.4 Sagitta
kroy updated the task description for T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:23 AM · VyOS 1.4 Sagitta
kroy changed Version from 1.4-rolling- to 1.4-rolling-202109160207 on T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:22 AM · VyOS 1.4 Sagitta
kroy created T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:20 AM · VyOS 1.4 Sagitta

Sep 17 2021

c-po closed T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified as Resolved.
Sep 17 2021, 6:56 PM · VyOS 1.4 Sagitta
c-po added a comment to T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified.

Thank you for testing!

Sep 17 2021, 6:56 PM · VyOS 1.4 Sagitta
erkin committed rVYOSONEXc1e0a1148c86: T3823: Stop strip-private regexp from swallowing quotes.
Sep 17 2021, 6:42 PM
GitHub <noreply@github.com> committed rVYOSONEX4f8ebdd1d644: Merge pull request #1007 from erkin/current (authored by c-po).
Sep 17 2021, 6:42 PM
zoenan7 created T3835: vyos router 1.2.7 snmp Dos bug.
Sep 17 2021, 12:41 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
UnicronNL changed the status of T3834: [OPENVPN] Support for Two Factor Authentication totp. from Open to In progress.
Sep 17 2021, 11:05 AM · VyOS 1.4 Sagitta (1.4.0-GA)
erkin added a comment to T3823: strip-private does not filter public IPv6 addresses.

Something about commands is meddling with strip-private. I'm looking into it.

Sep 17 2021, 8:10 AM · VyOS 1.4 Sagitta
erkin added a comment to T3823: strip-private does not filter public IPv6 addresses.

Now this is quite strange....

$ echo '2001:1578:2fe:fffd::/64' | strip-private
xxxx:xxxx:2fe:fffd::/64
Sep 17 2021, 8:07 AM · VyOS 1.4 Sagitta
erkin changed the status of T3823: strip-private does not filter public IPv6 addresses from Open to In progress.
Sep 17 2021, 8:04 AM · VyOS 1.4 Sagitta
lucasec added a comment to T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified.

Tested on latest build VyOS 1.4-rolling-202109160217 and confirmed it is adding the remote id attribute by default as expected. Connections establish without issue.

Sep 17 2021, 4:02 AM · VyOS 1.4 Sagitta
c-po claimed T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0.
Sep 17 2021, 3:35 AM · VyOS 1.4 Sagitta

Sep 16 2021

sempervictus added a comment to T3833: Cloud-init not finding data source in OpenStack.

Curl checks come back with:

root@vyos:/tmp# curl 169.254.169.254/latest/meta-data
ami-id
ami-launch-index
ami-manifest-path
block-device-mapping/
hostname
instance-action
instance-id
instance-type
local-hostname
local-ipv4
placement/
public-hostname
public-ipv4
public-keys/
reservation-id
security-groups
Sep 16 2021, 4:01 PM · VyOS 1.4 Sagitta
sempervictus renamed T3833: Cloud-init not finding data source in OpenStack from Cloud-init not inding data source in OpenStack to Cloud-init not finding data source in OpenStack.
Sep 16 2021, 3:59 PM · VyOS 1.4 Sagitta
sempervictus created T3833: Cloud-init not finding data source in OpenStack.
Sep 16 2021, 3:53 PM · VyOS 1.4 Sagitta
santhoshtk updated santhoshtk.
Sep 16 2021, 2:37 PM
santhoshtk updated santhoshtk.
Sep 16 2021, 2:36 PM
Viacheslav changed the status of T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0 from Open to Confirmed.

xfrm if_id should not be 0

Sep 16 2021, 1:17 PM · VyOS 1.4 Sagitta

Sep 15 2021

c-po changed the status of T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified from Open to Needs testing.
Sep 15 2021, 5:41 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXee547e028192: typo: remove unnecessary 'i' from help (authored by Javinator9889 <dev@javinator9889.com>).
Sep 15 2021, 5:40 PM
c-po committed rVYOSONEX3e85333ae7c5: ipsec: T3830: "authentication id|use-x509-id" are mutually exclusive.
Sep 15 2021, 5:39 PM
c-po committed rVYOSONEX74878d141574: ipsec: T3830: set connections.<conn>.remote<suffix>.id to "peer" if undefined.
Sep 15 2021, 5:39 PM
c-po added a comment to T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified.

From https://wiki.strongswan.org/projects/strongswan/wiki/ConnSection (1.3 behavior)

Sep 15 2021, 5:37 PM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEXec9503a9ec48: typo: remove unnecessary 'i' from help (authored by Javinator9889 <dev@javinator9889.com>).
Sep 15 2021, 5:37 PM
GitHub <noreply@github.com> committed rVYOSONEXbcb1bffec87a: xml: remove unnecessary "i" from help in source-address-ipv4 building block (authored by c-po).
Sep 15 2021, 5:37 PM
zsdc created T3832: Allow to set DHCP client-id in hexadecimal format.
Sep 15 2021, 3:27 PM · VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0.
Sep 15 2021, 9:13 AM · VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0.
Sep 15 2021, 9:12 AM · VyOS 1.4 Sagitta
Unknown Object (User) created T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0.
Sep 15 2021, 8:43 AM · VyOS 1.4 Sagitta
lucasec assigned T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified to c-po.
Sep 15 2021, 5:57 AM · VyOS 1.4 Sagitta
lucasec created T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified.
Sep 15 2021, 5:57 AM · VyOS 1.4 Sagitta

Sep 14 2021

c-po committed rVYOSONEX184f25819fa4: dhcpv6-pd: T421: disable wide dhcpv6 client debug messages.
Sep 14 2021, 5:51 PM
c-po committed rVYOSONEX6b48900358ce: dhcpv6-pd: T421: disable wide dhcpv6 client debug messages.
Sep 14 2021, 5:51 PM
c-po committed rVYOSONEX842bc6d6fd68: openvpn: T3822: fix certificate permissions.
Sep 14 2021, 4:28 PM
GitHub <noreply@github.com> committed rVYOSONEX7ed55fa5a999: Merge pull request #1005 from sarthurdev/T3828 (authored by c-po).
Sep 14 2021, 4:25 PM
sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEXb60069c4d8d2: ipsec: T3828: Update interface definitions for new behaviour.
Sep 14 2021, 4:25 PM
sarthurdev added a comment to T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta.

Good shout, fixed in following PR: https://github.com/vyos/vyos-1x/pull/1005

Sep 14 2021, 9:05 AM · VyOS 1.4 Sagitta
Viacheslav removed a project from T3702: Policy: Allow routing by fwmark: VyOS 1.2 Crux.
Sep 14 2021, 8:09 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T3823: strip-private does not filter public IPv6 addresses.

This line doesn't match ipv6 addresses https://github.com/vyos/vyos-1x/blob/f86b7314d025fd0cf11c2d91638ed3cc7c4fa507/src/helpers/strip-private.py#L66

Sep 14 2021, 7:19 AM · VyOS 1.4 Sagitta
lucasec added a comment to T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta.

Booted my host with 1.4-rolling-202109140217 and confirmed pfs enabled is now generating the expected swanctl.conf file to match the old behavior. If I don't report back in exactly an hour from now that my tunnels died, we can assume the fix works.

Sep 14 2021, 5:03 AM · VyOS 1.4 Sagitta

Sep 13 2021

c-po changed the status of T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta from Open to Needs testing.
Sep 13 2021, 8:28 PM · VyOS 1.4 Sagitta
rherold added a comment to T3655: NAT doesn't work correctly with VRF.

Please take a look at the commit 9213ce6672582bc12f02c1530726fe97030d2cfe for kernel 5.13.

Sep 13 2021, 8:01 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T3829: Support separated TCP/IP stack via "ip netns".

To start the proposed CLI:
Needs to be discussed.

Sep 13 2021, 7:34 PM · VyOS Rolling
Viacheslav created T3829: Support separated TCP/IP stack via "ip netns".
Sep 13 2021, 6:21 PM · VyOS Rolling
c-po updated the task description for T3318: Update Linux Kernel to v5.4.208 / 5.10.142.
Sep 13 2021, 6:15 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEX2e68b070f153: ipsec: T3828: Use IKE dh-group when ESP dh-group is set to `enable`.
Sep 13 2021, 5:11 PM
GitHub <noreply@github.com> committed rVYOSONEXd2123a834dad: Merge pull request #1004 from sarthurdev/T3828 (authored by c-po).
Sep 13 2021, 5:11 PM
stepler added a comment to T3824: Ethernet offload options are not populated in new installs.

1.3-beta-202109120646 doesn't have any commits from T3821:

Sep 13 2021, 1:38 PM
Viacheslav added a subtask for T2199: Rewrite firewall in new XML/Python style: T478: Firewall address group (multi and nesting).
Sep 13 2021, 1:14 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav added a parent task for T478: Firewall address group (multi and nesting): T2199: Rewrite firewall in new XML/Python style.
Sep 13 2021, 1:14 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta.

PR: https://github.com/vyos/vyos-1x/pull/1004

Sep 13 2021, 12:52 PM · VyOS 1.4 Sagitta
sagartc updated sagartc.
Sep 13 2021, 12:45 PM
dmbaturin added a comment to T3824: Ethernet offload options are not populated in new installs.

Migration scripts are meant for adjusting old configs for a new configuration syntax version. I feel that using that mechanism for fresh installs is wrong and we should move that logic to a different place, ideally to the script that inserts MAC addresses in the config—I forgot which script it is.

Sep 13 2021, 9:49 AM
Viacheslav added a comment to T3825: [DHCP]removes default route .

FRR behaviour without "interface" in route - it replaced metric with value without metric

r12-lts(config)# ip route 0.0.0.0/0 192.168.122.1
r12-lts(config)# 
r12-lts(config)# do sho run | include 0.0.0.0
ip route 0.0.0.0/0 192.168.122.1
r12-lts(config)# 
r12-lts(config)# ip route 0.0.0.0/0 192.168.122.1 210
r12-lts(config)# 
r12-lts(config)# do sho run | include 0.0.0.0
ip route 0.0.0.0/0 192.168.122.1 210
r12-lts(config)# 
r12-lts(config)# ip route 0.0.0.0/0 192.168.122.1
r12-lts(config)# 
r12-lts(config)# do sho run | include 0.0.0.0
ip route 0.0.0.0/0 192.168.122.1
r12-lts(config)# 
r12-lts(config)# ip route 0.0.0.0/0 192.168.122.1 eth0 210
r12-lts(config)# 
r12-lts(config)# do sho run | include 0.0.0.0
ip route 0.0.0.0/0 192.168.122.1
ip route 0.0.0.0/0 192.168.122.1 eth0 210
r12-lts(config)#
Sep 13 2021, 9:04 AM · VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a comment to T3825: [DHCP]removes default route .

To reproduce:

set interfaces ethernet eth0 address 'dhcp'
set protocols static route 0.0.0.0/0 next-hop 192.168.122.1
Sep 13 2021, 8:50 AM · VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav edited projects for T3825: [DHCP]removes default route , added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux.
Sep 13 2021, 8:33 AM · VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav changed the status of T3825: [DHCP]removes default route from Open to Confirmed.
Sep 13 2021, 8:33 AM · VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav changed the status of T3810: webproxy squidguard rules don't work properly after rewriting to python. from Open to Needs testing.
Sep 13 2021, 7:56 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
lucasec assigned T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta to c-po.
Sep 13 2021, 7:20 AM · VyOS 1.4 Sagitta
lucasec created T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta.
Sep 13 2021, 7:20 AM · VyOS 1.4 Sagitta
c-po added a comment to T3821: Add latest versions to default config files.

Ot feels thos change broke more then it fixed. Can we revert it?

Sep 13 2021, 4:56 AM · VyOS 1.5 Circinus