Page MenuHomeVyOS Platform
Feed All Stories

Oct 11 2021

Unknown Object (User) updated the task description for T3900: Add support for raw tables to firewall.
Oct 11 2021, 9:25 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2)
Viacheslav triaged T3900: Add support for raw tables to firewall as Wishlist priority.
Oct 11 2021, 9:23 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2)
Unknown Object (User) created T3900: Add support for raw tables to firewall.
Oct 11 2021, 8:36 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2)
lucasec added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

Obviously in a perfect world we get "unique" and "stable". I do think giving stability priority makes sense.

Oct 11 2021, 8:05 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
Viacheslav added a comment to T3897: Dynamic DNS doesn't work with IPv6 addresses.

PR https://github.com/vyos/vyos-1x/pull/1022

Oct 11 2021, 6:46 AM · VyOS 1.4 Sagitta
c-po added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

@lucasec the reason for switching to the platform UUID instead of building up out own one was that it was not "unique".

Oct 11 2021, 6:10 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.150 / 5.10.70 to Update Linux Kernel to v5.4.152 / 5.10.72.
Oct 11 2021, 6:07 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

Oct 10 2021

lucasec added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

I surveyed all the hardware I have to see what kind of UUIDs they report:

Oct 10 2021, 11:37 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po closed T3750: pdns-recursor 4.4 issue with dont-query and private DNS servers, a subtask of T3882: Upgrade PowerDNs recursor to 4.5 series, as Resolved.
Oct 10 2021, 5:09 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po closed T3750: pdns-recursor 4.4 issue with dont-query and private DNS servers as Resolved.
Oct 10 2021, 5:09 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po closed T3899: Add support for hd44780 LCD displays, a subtask of T2564: Extend VyOS to support appliance LCDs, as Resolved.
Oct 10 2021, 5:08 PM · VyOS 1.2 Crux (VyOS 1.2.7)
c-po moved T3899: Add support for hd44780 LCD displays from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 10 2021, 5:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po closed T3899: Add support for hd44780 LCD displays as Resolved.
Oct 10 2021, 5:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po moved T3899: Add support for hd44780 LCD displays from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 10 2021, 5:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po committed rVYOSONEXf4d736112b64: lcd: T2564: add support for hd44780 displays.
Oct 10 2021, 5:07 PM
c-po committed rVYOSONEX4218a5bcb109: lcd: T2564: add support for hd44780 displays.
Oct 10 2021, 5:07 PM
c-po changed the status of T3899: Add support for hd44780 LCD displays from Open to In progress.
Oct 10 2021, 5:06 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po closed T3885: dhcpv6-pd: randomly generated DUID is not persisted as Resolved.
Oct 10 2021, 4:06 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3885: dhcpv6-pd: randomly generated DUID is not persisted from Backlog to Finished on the VyOS 1.4 Sagitta board.
Oct 10 2021, 4:06 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3885: dhcpv6-pd: randomly generated DUID is not persisted from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 10 2021, 4:06 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

Implemented in

Oct 10 2021, 4:06 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

The DUID is presented in binary inside /var/lib/dhcpv6/dhcp6c_duid to read it back into ASCII use: hexdump -e '"%07.7_ax " 1/2 "%04x" " " 14/1 "%02x:" "\n"' /var/lib/dhcpv6/dhcp6c_duid

Oct 10 2021, 7:47 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta

Oct 9 2021

trae32566 created T3898: [RADIUS] - Reverse DNS Lookup Failing .
Oct 9 2021, 10:52 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
c-po added a comment to T3090: Move 'adjust-mss' firewall options to the interface section..

You are right @NikolayP but opening an entire subtree might be a bit of overkill.

Oct 9 2021, 5:02 PM · VyOS 1.4 Sagitta
c-po added a comment to T3879: GPG key verification fails when upgrading from a 1.3 beta version.

Unfortunately reverting back the public key did not lead to any good results either.

Oct 9 2021, 7:04 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po raised the priority of T3879: GPG key verification fails when upgrading from a 1.3 beta version from High to Urgent!.
Oct 9 2021, 7:02 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po closed T3894: Tunnel Commit Failed if system does not have `eth0` as Resolved.
Oct 9 2021, 6:40 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po committed rVYOSONEXf19c92f25501: tunnel: T3894: fix design when building synthetic MAC addresses.
Oct 9 2021, 6:40 AM
c-po committed rVYOSONEX1786246655c3: tunnel: T3894: fix design when building synthetic MAC addresses.
Oct 9 2021, 6:40 AM
c-po moved T3894: Tunnel Commit Failed if system does not have `eth0` from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 9 2021, 6:40 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3894: Tunnel Commit Failed if system does not have `eth0` from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 9 2021, 6:40 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po edited a custom field on T3894: Tunnel Commit Failed if system does not have `eth0`.
Oct 9 2021, 6:38 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po edited projects for T3894: Tunnel Commit Failed if system does not have `eth0`, added: VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2); removed VyOS 1.3 Equuleus.
Oct 9 2021, 6:38 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po claimed T3894: Tunnel Commit Failed if system does not have `eth0`.
Oct 9 2021, 5:56 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta

Oct 8 2021

c-po claimed T3879: GPG key verification fails when upgrading from a 1.3 beta version.
Oct 8 2021, 7:35 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po closed T3893: MGRE Tunnel commit crash If sit tunnel available as Resolved.
Oct 8 2021, 7:20 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po committed rVYOSONEXfac3b8fe8670: tunnel: T3893: harden logic when validating tunnel parameters.
Oct 8 2021, 7:20 PM
c-po committed rVYOSONEX5aadf673497b: tunnel: T3893: harden logic when validating tunnel parameters.
Oct 8 2021, 7:20 PM
c-po moved T3893: MGRE Tunnel commit crash If sit tunnel available from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 8 2021, 7:20 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3893: MGRE Tunnel commit crash If sit tunnel available from Need Triage to 1.3.0-epa2 on the VyOS 1.3 Equuleus board.
Oct 8 2021, 7:19 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3893: MGRE Tunnel commit crash If sit tunnel available from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 8 2021, 7:19 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
fernando added a comment to T3655: NAT doesn't work correctly with VRF.

not yet , we 've been trying with different CT but it's not solve the main problem . I understand that disabling conntrack is not possible because is used for nat.

Oct 8 2021, 5:22 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav claimed T3897: Dynamic DNS doesn't work with IPv6 addresses.
Oct 8 2021, 4:17 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T3897: Dynamic DNS doesn't work with IPv6 addresses from "Bug" to "Feature Request".
Oct 8 2021, 3:17 PM · VyOS 1.4 Sagitta
Viacheslav renamed T3897: Dynamic DNS doesn't work with IPv6 addresses from Dynamic DNS doesn't work with IPv6 addresses bug. to Dynamic DNS doesn't work with IPv6 addresses.
Oct 8 2021, 3:17 PM · VyOS 1.4 Sagitta
Viacheslav created T3897: Dynamic DNS doesn't work with IPv6 addresses.
Oct 8 2021, 2:56 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T3090: Move 'adjust-mss' firewall options to the interface section..

Perhaps the command should be changed a bit
MSS is a property of the TCP protocol, not IP:

Oct 8 2021, 12:23 PM · VyOS 1.4 Sagitta
williemmiller updated williemmiller.
Oct 8 2021, 8:29 AM
Viacheslav changed the status of T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client from Open to Needs testing.
Oct 8 2021, 7:08 AM
zoenan7 added a comment to T3835: vyos router 1.2.7 snmp Dos bug.

@dmbaturin Did you get my email? If not, please let me know and I will send it again

Oct 8 2021, 6:23 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
SquirePug created T3896: Extend ocserv support to allow for per-group configs.
Oct 8 2021, 4:39 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3881: Wrong description for container section restart.

@RyVolodya can you check a new image and close this task if it was fixed?

Oct 8 2021, 4:35 AM · VyOS 1.4 Sagitta
volga629-1 added a comment to T3655: NAT doesn't work correctly with VRF.

Is any work around for this scenario ?

Oct 8 2021, 2:51 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Oct 7 2021

anowak created T3895: VYOS firewall rules do not adhere to time schedule unless placed in UTC mode..
Oct 7 2021, 11:33 PM · VyOS 1.4 Sagitta
tywtyw2002 created T3894: Tunnel Commit Failed if system does not have `eth0`.
Oct 7 2021, 8:40 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po changed the status of T3893: MGRE Tunnel commit crash If sit tunnel available from Open to Confirmed.
Oct 7 2021, 8:40 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po added a comment to T3891: X550-T2/Possibly other X550/X540 cards no link on VyOS.

We usually communicate via https://vyos.slack.com

Oct 7 2021, 8:39 PM · VyOS 1.4 Sagitta
tywtyw2002 created T3893: MGRE Tunnel commit crash If sit tunnel available.
Oct 7 2021, 8:18 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
Hydra166 added a comment to T3891: X550-T2/Possibly other X550/X540 cards no link on VyOS.

or matrix

Oct 7 2021, 7:57 PM · VyOS 1.4 Sagitta
Hydra166 added a comment to T3891: X550-T2/Possibly other X550/X540 cards no link on VyOS.

sure I will just create a separate VM with a clean VyOS and the card - you got some sort of irc or discord to communicate?

Oct 7 2021, 7:57 PM · VyOS 1.4 Sagitta
francis added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

Although a cluster ID might be helpful the real problem is that the routes are reflected to all peers – not just ones that are route reflector clients:

Oct 7 2021, 7:20 PM
fernando added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

and It's the way to set on Vyos:

set protocols bgp <asn> parameters cluster-id <id>
Oct 7 2021, 6:50 PM
fernando added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

there is a recommendation that if you use RR in the same hierarchy and avoid loop , we need to set 'cluster-id'

Oct 7 2021, 6:35 PM
c-po added a comment to T3891: X550-T2/Possibly other X550/X540 cards no link on VyOS.

Any chance to get remote access to the system to debug this?

Oct 7 2021, 6:11 PM · VyOS 1.4 Sagitta
francis added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

This creates routing loops on all BGP neighbors as they are all advertising the same routes

Oct 7 2021, 2:44 PM
francis added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

Neighbors that are not route-reflector-client should not receive learned routes, only routes that are explicitly set in the config. So in the example above, I would not expect to have multipath routes for 10.0.0.1 and 10.0.0.2, and I would not expect to see any route for 10.0.0.6

Oct 7 2021, 2:42 PM
francis added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

RR1 - BGP Peer / Route Reflector / 10.0.0.1
RR2 - BGP Peer / Route Reflector / 10.0.0.2
RR3 - BGP Peer / Route Reflector / 10.0.0.3

Oct 7 2021, 2:40 PM
marcelocsilva added a comment to T3884: Realtek RTL8139 Ethernet Card not working..

Problem solved and it was my mistake.

Oct 7 2021, 2:20 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

@francis It is not clear. Can you provide an example of configuration? What do you get and what do you expect?

Oct 7 2021, 6:35 AM
francis added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

Also tested 1.4-rolling-202110020217 and it exhibits the same issue

Oct 7 2021, 3:22 AM
francis created T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.
Oct 7 2021, 2:37 AM

Oct 6 2021

volga629-1 added a comment to T3655: NAT doesn't work correctly with VRF.

The question how to disable connection tracking.

Oct 6 2021, 6:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando added a comment to T3655: NAT doesn't work correctly with VRF.

yes, It is an issues related with the conntrack+ nat/vrf leak , I share something where the problem is clearer :

Oct 6 2021, 5:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
volga629-1 added a comment to T751: IDS and IPS (suricata).

Suricata IPS with ipset

Oct 6 2021, 5:19 PM · VyOS 1.5 Circinus
volga629-1 added a comment to T3655: NAT doesn't work correctly with VRF.

Hello Everyone,
I am testing 1.4 vrf leak from vrf x to default with NAT and is not working as expected. Outbound traffic is get forwarded to gateway NAT applied, but REPLY never forwarded to originator .

Oct 6 2021, 4:37 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Oct 5 2021

c-po closed T3741: [BGP] default no-ipv4-unicast - by default as Resolved.
Oct 5 2021, 5:45 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXadc7ef387d40: op-mode: T3889: do not display redundant hostname when reading logs.
Oct 5 2021, 5:44 PM
c-po committed rVYOSONEXa2920ce9e228: smoketest: bgp: T3741: bugfix invalid IP address (missing prefix size).
Oct 5 2021, 5:44 PM
c-po committed rVYOSONEX30cf3bc79e22: op-mode: T3889: do not display redundant hostname when reading logs.
Oct 5 2021, 5:43 PM
RyVolodya committed rVYOSONEX15d4977f5d52: container: T3881: Fix description for container.
Oct 5 2021, 2:16 PM
GitHub <noreply@github.com> committed rVYOSONEX757d814b0c3b: Merge pull request #1020 from RyVolodya/T3881 (authored by dmbaturin).
Oct 5 2021, 2:16 PM
Hydra166 created T3891: X550-T2/Possibly other X550/X540 cards no link on VyOS.
Oct 5 2021, 11:56 AM · VyOS 1.4 Sagitta
lucasec added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

Yeah, that seems reasonable to me. I would prefer not add clutter to the system node if it can be avoided.

Oct 5 2021, 6:21 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po edited projects for T3885: dhcpv6-pd: randomly generated DUID is not persisted, added: VyOS 1.3 Equuleus (1.3.0-epa2); removed VyOS 1.3 Equuleus.
Oct 5 2021, 6:03 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po changed the status of T3885: dhcpv6-pd: randomly generated DUID is not persisted from Open to Confirmed.
Oct 5 2021, 6:03 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

Should we expose a system-level DUID at all? If a user wants to customize it, they could always set it on a per-interface basis using the existing configuration node.

Oct 5 2021, 6:03 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
Viacheslav closed T3800: DHCPv6 client get incorrect mask /128 as Invalid.
Oct 5 2021, 5:58 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

That seems fair, basically make the DUID generation deterministic. There is some defined structure to the DUID format, I think this would be a "type 3 DUID" per this document: https://www.juniper.net/documentation/en_US/junose15.1/topics/concept/dhcp-unique-id-servers-clients-overview.html.

Oct 5 2021, 5:23 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta

Oct 4 2021

c-po committed rVYOSONEX74a8c4b42b5a: bgp: T3741: "parameter default no-ipv4-unicast" is now a default option.
Oct 4 2021, 8:26 PM
c-po added a comment to T3800: DHCPv6 client get incorrect mask /128.

Can we close it @Viacheslav?

Oct 4 2021, 6:07 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3875: Known issues with vyatta_net_name/vyatta_interface_rescan from Backlog to In Progress on the VyOS 1.4 Sagitta board.
Oct 4 2021, 6:07 PM
c-po moved T3876: Replace vyos-netplug with a VyOS link state monitor service from Backlog to In Progress on the VyOS 1.4 Sagitta board.
Oct 4 2021, 6:07 PM · VyOS 1.5 Circinus
c-po moved T3875: Known issues with vyatta_net_name/vyatta_interface_rescan from Open to Backlog on the VyOS 1.4 Sagitta board.
Oct 4 2021, 6:07 PM
c-po moved T3876: Replace vyos-netplug with a VyOS link state monitor service from Open to Backlog on the VyOS 1.4 Sagitta board.
Oct 4 2021, 6:07 PM · VyOS 1.5 Circinus
c-po moved T3885: dhcpv6-pd: randomly generated DUID is not persisted from Open to Backlog on the VyOS 1.4 Sagitta board.
Oct 4 2021, 6:07 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

what about the following:

  • Add a new system ipv6 duid CLI node which acts as the general DUID used on the system and renders /var/lib/dhcpv6/dhcp6c_duid, if not overwritten at the "interface" level set interfaces ethernet eth0 dhcpv6-options duid
  • If system ipv6 duid is not configured, we "generate" the DUID using the eth0 MAC address automatically and store it in /var/lib/dhcpv6/dhcp6c_duid - thus no issue on image upgrades anymore
Oct 4 2021, 6:06 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po closed T3889: Migrate to journalctl when reading daemon logs as Resolved.
Oct 4 2021, 5:52 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po committed rVYOSONEXb7189cd1df32: op-mode: dhcpv(v6): T3890: retrieve both server and client logfiles.
Oct 4 2021, 5:52 PM
c-po committed rVYOSONEXf43e02715d92: op-mode: T3889: migrate to journalctl when reading daemon logs.
Oct 4 2021, 5:52 PM
c-po added a reverting change for rVYOSONEX6b48900358ce: dhcpv6-pd: T421: disable wide dhcpv6 client debug messages: rVYOSONEX15413605b40b: T3889: Revert "dhcpv6-pd: T421: disable wide dhcpv6 client debug messages".
Oct 4 2021, 5:52 PM