Page MenuHomeVyOS Platform
Feed All Stories

Dec 23 2021

Viacheslav moved T4092: IKEv2 mobike commit failed with DMVPN nhrp from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Dec 23 2021, 3:22 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
daniil reopened T4055: Add VRF support for HTTP(S) API service as "Open".

Forgot about the process "vyos-http-api-server". The process must be launched in the required vrf. Otherwise, we get an error: Otherwise, we get an error:

Dec 23 2021, 2:54 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
erkin set Issue type to bug on T3563: commit-archive breaks with IPv6 source addresses.
Dec 23 2021, 2:18 PM · VyOS 1.4 Sagitta
erkin set Issue type to feature-removal on T3506: Migrate loadkey command to op-mode.
Dec 23 2021, 2:18 PM · VyOS 1.4 Sagitta
erkin closed T4090: Source port and interface support for `commit-archive`, a subtask of T3356: Script for remote file transfers, as Wontfix.
Dec 23 2021, 2:17 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T4090: Source port and interface support for `commit-archive` as Wontfix.

If anyone actually wants support for source port parameter, feel free to reopen this, but the interface parameter is a no-go. In the meantime, rewriting vyatta-config-mgmt takes precedence.

Dec 23 2021, 2:17 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3354: Convert strip-private script from Perl to Python as Resolved.
Dec 23 2021, 1:28 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3354: Convert strip-private script from Perl to Python, a subtask of T3355: Remove all remaining legacy Vyatta code, as Resolved.
Dec 23 2021, 1:28 PM · VyOS 1.5 Circinus
erkin added a subtask for T3356: Script for remote file transfers: T4091: Progress bar support for HTTP uploads.
Dec 23 2021, 1:27 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin added a parent task for T4091: Progress bar support for HTTP uploads: T3356: Script for remote file transfers.
Dec 23 2021, 1:27 PM · VyOS 1.5 Circinus
erkin added a comment to T4090: Source port and interface support for `commit-archive`.

That's a good idea. What remains in that repo was hardly touched in a decade.

Dec 23 2021, 1:23 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed Difficulty level from unknown to normal on T3854: Missing op-mode commands for conntrack-sync.
Dec 23 2021, 12:29 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T3854: Missing op-mode commands for conntrack-sync from "Task" to "Bug".
Dec 23 2021, 12:28 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T3854: Missing op-mode commands for conntrack-sync from Open to In progress.
Dec 23 2021, 12:28 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) updated subscribers of T4081: VRRP health-check script stops working when setting up a sync group.
Dec 23 2021, 4:34 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Dec 22 2021

Viacheslav changed the status of T4092: IKEv2 mobike commit failed with DMVPN nhrp from Open to In progress.
Dec 22 2021, 6:53 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a project to T4092: IKEv2 mobike commit failed with DMVPN nhrp: VyOS 1.2 Crux (VyOS 1.2.9).
Dec 22 2021, 6:48 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav renamed T4092: IKEv2 mobike commit failed with DMVPN nhrp from Reopen: IKEv2 mobike commit failed to IKEv2 mobike commit failed with DMVPN nhrp.
Dec 22 2021, 6:37 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a comment to T4092: IKEv2 mobike commit failed with DMVPN nhrp.

PR https://github.com/vyos/vyatta-cfg-vpn/pull/52

Dec 22 2021, 6:34 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav claimed T4092: IKEv2 mobike commit failed with DMVPN nhrp.
Dec 22 2021, 6:03 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a comment to T4092: IKEv2 mobike commit failed with DMVPN nhrp.

It doesn't matter what you add mobike disable or enable
A possible reason it generates incorrect swanctl.conf for option mobike

Dec 22 2021, 5:56 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a comment to T4092: IKEv2 mobike commit failed with DMVPN nhrp.

@nikeshhajari thanks, I can reproduce it in 1.3:

set interfaces ethernet eth0 address '192.168.122.14/24'
set interfaces tunnel tun0 encapsulation 'gre'
set interfaces tunnel tun0 multicast 'enable'
set interfaces tunnel tun0 parameters ip key '1'
set interfaces tunnel tun0 source-address '192.168.122.14'
set protocols nhrp tunnel tun0 cisco-authentication 'orange'
set protocols nhrp tunnel tun0 holding-time '300'
set protocols nhrp tunnel tun0 multicast 'dynamic'
set protocols nhrp tunnel tun0 redirect
set protocols nhrp tunnel tun0 shortcut
set vpn ipsec esp-group ESP-HUB compression 'disable'
set vpn ipsec esp-group ESP-HUB lifetime '3600'
set vpn ipsec esp-group ESP-HUB mode 'tunnel'
set vpn ipsec esp-group ESP-HUB pfs 'dh-group21'
set vpn ipsec esp-group ESP-HUB proposal 1 encryption 'aes256'
set vpn ipsec esp-group ESP-HUB proposal 1 hash 'sha256'
set vpn ipsec esp-group ESP-HUB proposal 2 encryption 'aes256'
set vpn ipsec esp-group ESP-HUB proposal 2 hash 'sha256'
set vpn ipsec ike-group IKE-HUB ikev2-reauth 'no'
set vpn ipsec ike-group IKE-HUB key-exchange 'ikev2'
set vpn ipsec ike-group IKE-HUB lifetime '28800'
set vpn ipsec ike-group IKE-HUB proposal 1 dh-group '21'
set vpn ipsec ike-group IKE-HUB proposal 1 encryption 'aes256'
set vpn ipsec ike-group IKE-HUB proposal 1 hash 'sha256'
set vpn ipsec ike-group IKE-HUB proposal 2 dh-group '21'
set vpn ipsec ike-group IKE-HUB proposal 2 encryption 'aes256'
set vpn ipsec ike-group IKE-HUB proposal 2 hash 'sha256'
set vpn ipsec ipsec-interfaces interface 'eth0'
set vpn ipsec profile NHRPVPN authentication mode 'pre-shared-secret'
set vpn ipsec profile NHRPVPN authentication pre-shared-secret 'PRE_SHARED_KEY'
set vpn ipsec profile NHRPVPN bind tunnel 'tun0'
set vpn ipsec profile NHRPVPN esp-group 'ESP-HUB'
set vpn ipsec profile NHRPVPN ike-group 'IKE-HUB'
commit

Add mobile disable:

set vpn ipsec ike-group IKE-HUB mobike 'disable'
commit
[ vpn ]
Warning: unable to [reload changes to swanctl.conf], received error code 5632
Dec 22 2021, 5:51 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a comment to T4090: Source port and interface support for `commit-archive`.

I prefer to rewrite the whole https://github.com/vyos/vyatta-config-mgmt to XML/python

Dec 22 2021, 5:30 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
boevering added a comment to T4062: VRRP IPSEC-AH : sequence number xxxxxxx already processed. Packet dropped. Local(xxxxxxx).

@Viacheslav the only way is by letting it run.
As adviced in the slack I upgraed to differt version, just now it dropped again.
This time it's differtent as the backup still sayes it still the backup node but all traffic to the VRRP address is offline.

Dec 22 2021, 3:50 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T4093: SNMPv3 snmpd.conf generation bug.

A similar bug I see in 1.2 with such configuration:

set service snmp contact 'test'
set service snmp listen-address 192.168.122.12
set service snmp location 'test'
set service snmp v3 user foo auth encrypted-key '0x2e312e332e362e312e362e332e31302e312e322e34'
set service snmp v3 user foo auth type 'sha'
set service snmp v3 user foo privacy encrypted-key '0x'
set service snmp v3 user foo privacy type 'aes'
Dec 22 2021, 3:29 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4056: Traffic policy not set in live configuration as Resolved.
Dec 22 2021, 2:13 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav added projects to T4093: SNMPv3 snmpd.conf generation bug: VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0).
Dec 22 2021, 2:04 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4093: SNMPv3 snmpd.conf generation bug.

end of /etc/snmp/snmpd.conf

# group
group  usm test
Dec 22 2021, 2:00 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
daniil added a comment to T4056: Traffic policy not set in live configuration.

Thank you, problem solved!

Dec 22 2021, 1:59 PM · vyatta-cfg, VyOS 1.4 Sagitta
Unknown Object (User) created T4093: SNMPv3 snmpd.conf generation bug.
Dec 22 2021, 1:59 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
SrividyaA set Issue type to bug on T3678: VyOS 1.4: Invalid error message while deleting ipsec vpn configuration.
Dec 22 2021, 1:40 PM · VyOS 1.4 Sagitta
SrividyaA closed T3678: VyOS 1.4: Invalid error message while deleting ipsec vpn configuration, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Dec 22 2021, 1:40 PM · VyOS 1.4 Sagitta
SrividyaA closed T3678: VyOS 1.4: Invalid error message while deleting ipsec vpn configuration as Resolved.

Working in latest release:

Dec 22 2021, 1:40 PM · VyOS 1.4 Sagitta
Unknown Object (User) changed the subtype of T4081: VRRP health-check script stops working when setting up a sync group from "Task" to "Bug".
Dec 22 2021, 10:11 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T4081: VRRP health-check script stops working when setting up a sync group from Backport candidate to Confirmed.
Dec 22 2021, 10:05 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T4081: VRRP health-check script stops working when setting up a sync group from Confirmed to Backport candidate.

Duplicate PR:
https://github.com/vyos/vyos-1x/pull/1118
Request revoked

Dec 22 2021, 10:00 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
hexes added a comment to T4025: OpenVPN server with TAP interface, client didn’t see network.

VyOS 1.3.0-epa3 with config below works good:

Dec 22 2021, 8:06 AM · Restricted Project, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1), Restricted Project, openvpn
nikeshhajari created T4092: IKEv2 mobike commit failed with DMVPN nhrp.
Dec 22 2021, 8:03 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
erkin triaged T4091: Progress bar support for HTTP uploads as Low priority.
Dec 22 2021, 5:27 AM · VyOS 1.5 Circinus
erkin lowered the priority of T4090: Source port and interface support for `commit-archive` from Low to Wishlist.
Dec 22 2021, 5:18 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin added a comment to T4090: Source port and interface support for `commit-archive`.

I personally think the interface part is high-effort, low-gain since you can simply use the address of the interface to the same effect, whereas simply providing an interface will force it to decide which address to use on dual-stack systems. It needs to pick between AF_INET and AF_INET6 when creating the socket before setsockopt()ing SO_BINDTODEVICE; although I think we can get away with doing what socket.create_connection() does. Even then, only the SFTP portion of the code directly uses socket — everything else relies on higher level libraries that only expose address and port options. (Also, using a single parameter for both addresses and interfaces is a bad idea, in my opinion, because it's probably more useful to resolve an FQDN string to an address rather than assume all strings are interfaces. But otherwise, we'd need to find a way to resolve conflict between address and interface parameters.) All in all, I don't think the interface parameter is a good idea at all but we'll see.

Dec 22 2021, 5:18 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3356: Script for remote file transfers, a subtask of T3355: Remove all remaining legacy Vyatta code, as Resolved.
Dec 22 2021, 4:53 AM · VyOS 1.5 Circinus
erkin closed T3356: Script for remote file transfers as Resolved.

All parts completely backported to Equuleus.

Dec 22 2021, 4:53 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin added a subtask for T3356: Script for remote file transfers: T4090: Source port and interface support for `commit-archive`.
Dec 22 2021, 4:52 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin added a parent task for T4090: Source port and interface support for `commit-archive`: T3356: Script for remote file transfers.
Dec 22 2021, 4:52 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3628: commit-archive source-address Interface Broken, a subtask of T3356: Script for remote file transfers, as Resolved N/A.
Dec 22 2021, 4:52 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3628: commit-archive source-address Interface Broken as Resolved N/A.

I opened a new issue for this: T4090.

Dec 22 2021, 4:52 AM · VyOS 1.4 Sagitta
erkin triaged T4090: Source port and interface support for `commit-archive` as Low priority.
Dec 22 2021, 4:52 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Dec 21 2021

Viacheslav added a comment to T4080: Space in "description" commands.

@m.korobeinikov Could you re-check it and close if necessary?

Dec 21 2021, 11:10 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T3376: Setting ipv6 address autoconf causes all interfaces besides the target to lose their IP as Resolved N/A.
Dec 21 2021, 11:01 PM · VyOS 1.4 Sagitta
Viacheslav closed T3466: Ping command not working as expected as Wontfix.
Dec 21 2021, 10:55 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3527: Sometimes installing of static routes failes.

@ernstjo Do you have any news regarding this issue or should we close it?

Dec 21 2021, 10:51 PM
Viacheslav added a comment to T3678: VyOS 1.4: Invalid error message while deleting ipsec vpn configuration.

@SrividyaA Could you re-check it?

Dec 21 2021, 10:41 PM · VyOS 1.4 Sagitta
Viacheslav closed T3931: SSTP doesn't work after rewriting to PKI, a subtask of T3642: PKI configuration, as Resolved.
Dec 21 2021, 10:13 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav closed T3931: SSTP doesn't work after rewriting to PKI as Resolved.
Dec 21 2021, 10:13 PM · VyOS 1.4 Sagitta
Viacheslav closed T4032: PPPoE server firewall zone completion missing as Invalid.
Dec 21 2021, 10:01 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4056: Traffic policy not set in live configuration.

PR https://github.com/vyos/vyos-1x/pull/1117

Dec 21 2021, 9:59 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav added a comment to T4056: Traffic policy not set in live configuration.

@daniil can you edit one file?

sudo nano -c +1308 /usr/lib/python3/dist-packages/vyos/ifconfig/interface.py

And replace string:

if not 'redirect' in self._config:

To string:

if not 'redirect' in self._config and not 'traffic_policy' in self._config:

save and reboot the router or just restart vyos-configd

sudo systemctl restart vyos-configd
Dec 21 2021, 9:20 PM · vyatta-cfg, VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T3006: Accel-PPP & vlan-mon config get invalid VLAN.

I think this is the limitation with the Linux interface name, it should not be higher than 16 characters. In you config I see, as an example (bond0.995.130 = 13 chars and additional part .100 = 4) = 17
I know how we can fix it manually, but I'm not sure that it is a good idea.
Accel-PPP supports name changing for created interface by vlan_mon module

[pppoe]
vlan-name=e0.%P.%N
interface=re:^e0\.\d+\.\d+

you can try to change this manually (edit /run/accel-ppp/pppoe.conf) and restart pppoe-server

Dec 21 2021, 8:47 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4072: Feature Request: Firewall on bridge interfaces from "Task" to "Feature Request".
Dec 21 2021, 8:15 PM · VyOS 1.4 Sagitta
Viacheslav removed a project from T4087: IPsec IKE-group proposals limit of 10 pieces : VyOS 1.2 Crux.
Dec 21 2021, 8:07 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav closed T4013: Add pkg cloudwatch for AWS images as Resolved.
Dec 21 2021, 8:02 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav renamed T4039: Rsyslog to use 'protocol23format' for protocol UDP from Rsyslog to use 'protocol23format' to Rsyslog to use 'protocol23format' for protocol UDP.
Dec 21 2021, 7:55 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T4039: Rsyslog to use 'protocol23format' for protocol UDP.

PR https://github.com/vyos/vyos-1x/pull/1116

Dec 21 2021, 7:51 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a project to T4039: Rsyslog to use 'protocol23format' for protocol UDP: VyOS 1.4 Sagitta.
Dec 21 2021, 6:43 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T4062: VRRP IPSEC-AH : sequence number xxxxxxx already processed. Packet dropped. Local(xxxxxxx).

@boevering Do you know how to reproduce it?

Dec 21 2021, 6:37 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav changed the status of T4021: Long commit time on bridge interface with 1-4094 allowed VLAN tags from Open to Needs testing.
Dec 21 2021, 5:22 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4021: Long commit time on bridge interface with 1-4094 allowed VLAN tags.

@Boman I don't see such issue:

vyos@r11-roll# set interfaces bridge br0 enable-vlan 
[edit]
vyos@r11-roll# set interfaces bridge br0 member interface eth2 allowed-vlan 1-4094
[edit]
vyos@r11-roll# 
[edit]
vyos@r11-roll# time commit
Dec 21 2021, 5:22 PM · VyOS 1.4 Sagitta
Viacheslav moved T3913: VRF traffic fails after upgrade from 1.3.0-RC6 to 1.3.0-EPA1/2 from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0) board.
Dec 21 2021, 5:05 PM · VyOS 1.3 Equuleus (1.3.0)
danhusan closed T3913: VRF traffic fails after upgrade from 1.3.0-RC6 to 1.3.0-EPA1/2 as Resolved.
Dec 21 2021, 5:02 PM · VyOS 1.3 Equuleus (1.3.0)
danhusan added a comment to T3913: VRF traffic fails after upgrade from 1.3.0-RC6 to 1.3.0-EPA1/2.

Confirmed working in 1.3.0 LTS.

Dec 21 2021, 5:01 PM · VyOS 1.3 Equuleus (1.3.0)
daniil added a comment to T1871: Add MTU option to "traffic-policy limiter".

I agree, when offloading is enabled, it is necessary to increase MTU for traffic policing.

Dec 21 2021, 4:37 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
daniil added a comment to T4056: Traffic policy not set in live configuration.
# show traffic-policy 
 limiter 1G {
     default {
         bandwidth 1gbit
         burst 188kb
     }
}
Dec 21 2021, 4:09 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav moved T4053: VRRP impossible to set scripts out of the /config directory from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Dec 21 2021, 4:01 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T4053: VRRP impossible to set scripts out of the /config directory as Resolved.
Dec 21 2021, 4:01 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a comment to T4056: Traffic policy not set in live configuration.

@daniil Can you share an example of traffic-policy 1G?

Dec 21 2021, 3:59 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav closed T4070: NATv4 : inbound-interface type "any" is missing. as Resolved.
Dec 21 2021, 3:56 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4081: VRRP health-check script stops working when setting up a sync group.

PR https://github.com/vyos/vyos-1x/pull/1115

Dec 21 2021, 2:43 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav moved T4082: Add op mode command to restart ldpd from Need Triage to Backport Candidates on the VyOS 1.4 Sagitta board.
Dec 21 2021, 10:48 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav moved T3435: NAT rules show corruption from Finished to In Progress on the VyOS 1.4 Sagitta board.

There is still another bug:

set nat destination rule 120 destination address '203.0.113.1'
set nat destination rule 120 inbound-interface 'eth0'
set nat destination rule 120 protocol 'tcp'
set nat destination rule 120 translation address '192.0.2.40'
Dec 21 2021, 9:58 AM · VyOS 1.4 Sagitta
Viacheslav reopened T3435: NAT rules show corruption as "Needs testing".
Dec 21 2021, 9:56 AM · VyOS 1.4 Sagitta
Viacheslav closed T3435: NAT rules show corruption as Resolved.
Dec 21 2021, 9:16 AM · VyOS 1.4 Sagitta
Viacheslav created T4089: Show nat destination rules shows ip address instead of interface 'any'.
Dec 21 2021, 9:09 AM · VyOS 1.4 Sagitta
Viacheslav changed Difficulty level from unknown to normal on T3435: NAT rules show corruption.
Dec 21 2021, 8:53 AM · VyOS 1.4 Sagitta
Viacheslav lowered the priority of T3435: NAT rules show corruption from High to Normal.
Dec 21 2021, 8:52 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3435: NAT rules show corruption.

PR https://github.com/vyos/vyos-1x/pull/1114

vyos@r11-roll:~$ show nat destination rules 
Rule       Destination                                        Translation                                        Inbound Interface
----       -----------                                        -----------                                        -----------------
100        port 3389                                          192.0.2.40 port 80                                 eth0      
vyos@r11-roll:~$
Dec 21 2021, 8:52 AM · VyOS 1.4 Sagitta
Viacheslav closed T4083: Cluster heartbeat doesn't start b.c lack of directory /run/heartbeat/ as Resolved.
Dec 21 2021, 8:26 AM · VyOS 1.4 Sagitta
xrobau added a comment to T4017: Adding firewall port ranges makes commit/boot MASSIVELY slow.

I'm going to do what I suggested.

Dec 21 2021, 3:50 AM
Unknown Object (User) added a comment to T4078: A hybrid of "network-group" and "address-group"..

@adestis thank you. This issue isn't critical. It's more for to improve the design and for convenience of our customers.
You can use /32 to add a host, but we have to have the opportunity to add hosts without masks.
For example, if you need to create a group consisting of 1000 (or more random hosts), it's more convenient to use configuration without masks.

Dec 21 2021, 12:11 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta

Dec 20 2021

UnicronNL added a comment to T4086: system login banner is not removed on deletion..

@c-po I will check it!

Dec 20 2021, 10:02 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T4086: system login banner is not removed on deletion..

@UnicronNL can you rechecknon todays rolling image? It behaved differently for me

Dec 20 2021, 9:13 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
UnicronNL added a comment to T4086: system login banner is not removed on deletion..

I set the banners via set system login pre-login 'test' and/or set system login post-login 'test'
and then the banners are set. (and the default is overwritten)

Dec 20 2021, 8:48 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po lowered the priority of T4086: system login banner is not removed on deletion. from Normal to Low.
Dec 20 2021, 8:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T4086: system login banner is not removed on deletion. from Open to Needs testing.
Dec 20 2021, 8:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T4086: system login banner is not removed on deletion..

Well deleting the login banner results in the "default" behavior as expected.

Dec 20 2021, 8:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po claimed T4086: system login banner is not removed on deletion..
Dec 20 2021, 6:26 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po closed T4088: Fix typo in login banner as Resolved.
Dec 20 2021, 6:26 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T4088: Fix typo in login banner from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Dec 20 2021, 6:25 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T4088: Fix typo in login banner from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0) board.
Dec 20 2021, 6:25 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a comment to T4083: Cluster heartbeat doesn't start b.c lack of directory /run/heartbeat/.

PR https://github.com/vyos/vyatta-cluster/pull/5

Dec 20 2021, 5:10 PM · VyOS 1.4 Sagitta