Page MenuHomeVyOS Platform
Feed All Stories

Jan 10 2022

fernando added a comment to T4163: [BMP-BGP] Routing monitoring feature.

this PR https://github.com/vyos/vyos-1x/pull/1088 only include how to enable daemon , but it doesn't add VyOS-cli commands in BGP (the daemon only allows you to enable it).

Jan 10 2022, 8:43 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po committed rVYOSONEX062762154ae1: conntrack: T3579: use "notrack" over "return" in nft statements.
Jan 10 2022, 8:42 PM
c-po added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

@Viacheslav / @vindenesen that is a bug I have also seen in the old iptables based implementation. Can you please file a bug report towards VyOS 1.2 and 1.3?

Jan 10 2022, 8:38 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX05b5d09ca70c: conntrack: T3579: migrate "conntrack ignore" tree to vyos-1x and nftables.
Jan 10 2022, 8:32 PM
Viacheslav added a comment to T4163: [BMP-BGP] Routing monitoring feature.

There is PR which includes this feature https://github.com/vyos/vyos-1x/pull/1088

Jan 10 2022, 8:17 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
fernando created T4163: [BMP-BGP] Routing monitoring feature.
Jan 10 2022, 8:05 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav assigned T4162: VPN ipsec ike-group - Incorrect value help for ikev2-reauth to n.fort.
Jan 10 2022, 6:49 PM · VyOS 1.4 Sagitta
n.fort created T4162: VPN ipsec ike-group - Incorrect value help for ikev2-reauth.
Jan 10 2022, 6:48 PM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEXdeb9bfa02863: policy: T4155: Fix using incorrect table variable.
Jan 10 2022, 6:42 PM
sarthurdev committed rVYOSONEX67ab81546856: firewall: 4149: Fix verify steps being bypassed when base node is removed.
Jan 10 2022, 6:42 PM
GitHub <noreply@github.com> committed rVYOSONEX436805a69df3: Merge pull request #1151 from sarthurdev/firewall (authored by c-po).
Jan 10 2022, 6:42 PM
sarthurdev changed the status of T4149: [Firewall-IPV6] Error delete Fw rules on VIF/INT from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1151

Jan 10 2022, 6:40 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases , a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Jan 10 2022, 6:40 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev changed the status of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases from Open to Needs testing.

Thanks for catching that!

Jan 10 2022, 6:40 PM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX4ade92549616: Merge pull request #1150 from nicolas-fort/T4161 (authored by c-po).
Jan 10 2022, 6:38 PM
Nicolas Fort <nicolasfort1988@gmail.com> committed rVYOSONEX8dfde277c90c: policy: T4161: Set correct description for local-preference.
Jan 10 2022, 6:38 PM
n.fort added a comment to T4161: Policy route-map - Incorrect value help for local preference.

PR: https://github.com/vyos/vyos-1x/pull/1150

Jan 10 2022, 6:21 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4149: [Firewall-IPV6] Error delete Fw rules on VIF/INT from Open to In progress.
Jan 10 2022, 5:53 PM · VyOS 1.4 Sagitta
syncer added a member for Maintainers: sarthurdev.
Jan 10 2022, 5:52 PM
Viacheslav assigned T4161: Policy route-map - Incorrect value help for local preference to n.fort.
Jan 10 2022, 5:07 PM · VyOS 1.4 Sagitta
n.fort created T4161: Policy route-map - Incorrect value help for local preference.
Jan 10 2022, 5:06 PM · VyOS 1.4 Sagitta
n.fort created T4160: Firewall - Error in rules that matches everything except something.
Jan 10 2022, 4:51 PM · VyOS 1.4 Sagitta
n.fort closed T3115: Add support for firewall on L3 VIF bridge interface as Resolved.
Jan 10 2022, 3:36 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
n.fort added a comment to T3115: Add support for firewall on L3 VIF bridge interface.

Previous example was expanded, in order to test filtering between native bridge interface and vlans interface on bridge.
Filtering rules:

  • Filter traffic from vlan br0.55 to br0.66
  • Filter traffic from vlan1 to br0.55
  • Allow all
Jan 10 2022, 3:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
hensur added a comment to T3818: BGP export route-map only works after bgpd restart.

I'm experiencing this with a custom ISO built from the stable 1.3 sources. Haven't done further debugging yet, a bgpd restart helped every time.

Jan 10 2022, 3:09 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4100: Firewall increase maximum number of rules.

In 1.3 (VyOS 1.3-rolling-202201030317) the rules are handled correctly (except for the numbers in description).

Jan 10 2022, 12:35 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav moved T3299: Allow the web proxy service to listen on all IP addresses from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 10 2022, 9:32 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T3299: Allow the web proxy service to listen on all IP addresses from Unknown Status to Resolved.
Jan 10 2022, 9:32 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXaa438129337c: squid: T3299: Add listen address 0.0.0.0 (authored by sever-sever <v.gletenko@vyos.io>).
Jan 10 2022, 9:02 AM
GitHub <noreply@github.com> committed rVYOSONEX1ddbbe90b32e: Merge pull request #1146 from sever-sever/T3299-equ (authored by c-po).
Jan 10 2022, 9:02 AM
nikeshhajari closed T4158: Add support for "ip nhrp registration no-unique" from FRR as Invalid.
Jan 10 2022, 6:23 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
nikeshhajari added a comment to T4158: Add support for "ip nhrp registration no-unique" from FRR.

Ah! ok, I will close this. Looking at the man pages, seems like open nhrp doesn't have a no-unique registration feature?

Jan 10 2022, 6:23 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T4158: Add support for "ip nhrp registration no-unique" from FRR.

We don’t use frr nhrpd, more details T2326
We use opennhrp

Jan 10 2022, 6:17 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
johannrichard added a comment to T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.

I just realize it's getting more complicated as python/vyos/firewall.py will later write out the rules for these empty groups and when reading-them in, nftables will complain (again) when trying to resolve them, e.g.

Jan 10 2022, 3:06 AM · VyOS 1.4 Sagitta
erkin added a comment to T4038: Rewrite `vyatta-image-tools.pl` in Python.

Pythonic reimplementation complete. Now only the XML op-mode definition and the auto-complete script remain.

Jan 10 2022, 2:51 AM · Restricted Project, VyOS 1.4 Sagitta
johannrichard renamed T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails from Rewrite firewall in new XML/Python style: Empty firewall group (address, network & port) generate invalid nftables config, commit fails to Empty firewall group (address, network & port) generates invalid nftables config, commit fails.
Jan 10 2022, 2:25 AM · VyOS 1.4 Sagitta
johannrichard added a comment to T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.

To my understanding, the template data/templates/firewall/nftables.tmpl is probably the culprit, as it doesn't check whether group_conf.address (and similarly the others) has any elements at all and introduces the offending white-space:

Jan 10 2022, 2:25 AM · VyOS 1.4 Sagitta
johannrichard added a subtask for T2199: Rewrite firewall in new XML/Python style: T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.
Jan 10 2022, 2:12 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
johannrichard added a parent task for T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails: T2199: Rewrite firewall in new XML/Python style.
Jan 10 2022, 2:12 AM · VyOS 1.4 Sagitta
johannrichard created T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.
Jan 10 2022, 2:12 AM · VyOS 1.4 Sagitta

Jan 9 2022

nikeshhajari created T4158: Add support for "ip nhrp registration no-unique" from FRR.
Jan 9 2022, 11:57 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
teadur committed rVYOSONEX7c1ea983c455: T4157: Add jinja2 to test-requirements.txt.
Jan 9 2022, 10:39 PM
GitHub <noreply@github.com> committed rVYOSONEXa9033074f6d7: Merge pull request #1149 from tacerus/pip (authored by dmbaturin).
Jan 9 2022, 10:39 PM
Viacheslav committed rVYOSONEX66d59d9e393c: vrrp: T1972: Ability to set IP address on not vrrp interface.
Jan 9 2022, 8:45 PM
GitHub <noreply@github.com> committed rVYOSONEXdfb2b58e00ea: Merge pull request #1143 from sever-sever/T1972 (authored by c-po).
Jan 9 2022, 8:45 PM
c-po added a comment to T4156: Adding DHCP Option 13 (bootfile-size).

In ISC dhcpd this corresponds to the boot-size option http://www.ipamworldwide.com/ipam/isc-dhcpv4-options.html

Jan 9 2022, 8:36 PM · VyOS 1.4 Sagitta
tacerus triaged T4157: Add jinja2 to pip test requirements as Low priority.
Jan 9 2022, 8:35 PM · VyOS 1.4 Sagitta
tacerus triaged T4156: Adding DHCP Option 13 (bootfile-size) as Low priority.
Jan 9 2022, 8:05 PM · VyOS 1.4 Sagitta
johannrichard added a subtask for T2199: Rewrite firewall in new XML/Python style: T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases .
Jan 9 2022, 7:59 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
johannrichard added a parent task for T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases : T2199: Rewrite firewall in new XML/Python style.
Jan 9 2022, 7:59 PM · VyOS 1.4 Sagitta
c-po moved T3924: VRRP stops working with VRF from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 9 2022, 7:58 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po edited a custom field on T3924: VRRP stops working with VRF.
Jan 9 2022, 7:58 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a project to T3924: VRRP stops working with VRF: VyOS 1.3 Equuleus ( 1.3.1).
Jan 9 2022, 7:58 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po moved T4141: Set high-availability vrrp sync-group without members error from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po moved T4128: keepalived: Upgrade package to add VRF support from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a project to T4128: keepalived: Upgrade package to add VRF support: VyOS 1.3 Equuleus ( 1.3.1).
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a parent task for T4128: keepalived: Upgrade package to add VRF support: T3914: VRRP rfc3768-compatibility doesn't work with unicast peers.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a subtask for T3914: VRRP rfc3768-compatibility doesn't work with unicast peers: T4128: keepalived: Upgrade package to add VRF support.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a comment to T3914: VRRP rfc3768-compatibility doesn't work with unicast peers.

Package upgraded

Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po closed T3914: VRRP rfc3768-compatibility doesn't work with unicast peers as Resolved.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po moved T3914: VRRP rfc3768-compatibility doesn't work with unicast peers from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po committed rVYOSONEX5931d2530e9a: keepalived: T4128: add missing keepalived.service file.
Jan 9 2022, 7:56 PM
c-po committed rVYOSONEX1bb6b4458aa6: keepalived: T4128: add systemd option Type=simple.
Jan 9 2022, 7:56 PM
c-po edited projects for T3914: VRRP rfc3768-compatibility doesn't work with unicast peers, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus (1.3.0).
Jan 9 2022, 7:53 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXfb464f0b7654: keepalived: T4150: Fix template option conntrack_sync_group.
Jan 9 2022, 7:52 PM
GitHub <noreply@github.com> committed rVYOSONEX897510fe6fdf: Merge pull request #1142 from sever-sever/T4150 (authored by c-po).
Jan 9 2022, 7:52 PM
Viacheslav committed rVYOSONEXd997874deb61: nhrp: T4152: Fix template holding-time for nhrp.
Jan 9 2022, 7:46 PM
GitHub <noreply@github.com> committed rVYOSONEX17ea91accc4b: Merge pull request #1145 from sever-sever/T4152 (authored by c-po).
Jan 9 2022, 7:46 PM
Viacheslav updated subscribers of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases .
Jan 9 2022, 7:43 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases from "Task" to "Bug".
Jan 9 2022, 7:40 PM · VyOS 1.4 Sagitta
n.fort added a comment to T3115: Add support for firewall on L3 VIF bridge interface.

Filtering tested on version 1.4-rolling-202201060842

Jan 9 2022, 7:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
hensur added a comment to T2898: Support NDP proxy.

I revisited this in: https://github.com/vyos/vyos-1x/pull/1147

Jan 9 2022, 6:43 PM · VyOS 1.4 Sagitta
johannrichard updated the task description for T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases .
Jan 9 2022, 6:32 PM · VyOS 1.4 Sagitta
johannrichard created T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases .
Jan 9 2022, 6:30 PM · VyOS 1.4 Sagitta
aha added a comment to T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0.

@Viacheslav Yes, You're right.
in.tftpd got started (but only a few seconds).

Jan 9 2022, 6:22 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
n.fort added a comment to T4072: Feature Request: Firewall on bridge interfaces.

Scenario proposed by @NikolayP gives next content in table ip filter:

Jan 9 2022, 6:18 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3706: Add proper priorities for systemd daemons.

A simple check works fine:
Set 20% quota for snmpd
And check it with script:

#!/usr/bin/env bash
Jan 9 2022, 5:12 PM · Bugs, VyOS Rolling
Viacheslav added a comment to T3706: Add proper priorities for systemd daemons.

https://www.freedesktop.org/software/systemd/man/systemd.resource-control.html

Jan 9 2022, 4:53 PM · Bugs, VyOS Rolling
Viacheslav changed the status of T3774: atop logs are not limited in size from In progress to Needs testing.
Jan 9 2022, 4:39 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav closed T3822: OpenVPN processes do not have permission to read key files generated with `run generate openvpn key` as Resolved.

It was fixed in above commits, wrong testing form my site.

Jan 9 2022, 4:28 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0.

@aha As I see tftp can't bind ipv6 link local address:

Jan 9 2022, 3:54 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav edited projects for T3299: Allow the web proxy service to listen on all IP addresses, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus (1.3.0).
Jan 9 2022, 2:56 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T3299: Allow the web proxy service to listen on all IP addresses.

Cherry-pick PR https://github.com/vyos/vyos-1x/pull/1146

Jan 9 2022, 2:56 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4100: Firewall increase maximum number of rules.

It requires checking for 1.3 as it was changed and it uses the old backend on Perl (links above).

Jan 9 2022, 2:31 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
n.fort added a comment to T4100: Firewall increase maximum number of rules.
vyos@vyos# run show config comm | grep fire
set firewall name FOO default-action 'accept'
set firewall name FOO rule 10 action 'accept'
set firewall name FOO rule 10 source address '198.51.100.0/24'
set firewall name FOO rule 999997 action 'drop'
set firewall name FOO rule 999997 source address '203.0.113.0/24'
[edit]
Jan 9 2022, 2:24 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4153: Monitor bandwidth-test initiate not working.

It seems -V option:

Jan 9 2022, 2:24 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort added a comment to T4100: Firewall increase maximum number of rules.
Jan 9 2022, 2:20 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a project to T4154: Error add second gre tunnel with the same source interface: VyOS 1.3 Equuleus ( 1.3.1).
Jan 9 2022, 2:08 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav created T4154: Error add second gre tunnel with the same source interface.
Jan 9 2022, 2:08 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
n.fort created T4153: Monitor bandwidth-test initiate not working.
Jan 9 2022, 2:06 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav moved T4142: Input ifbX interfaces not displayed in op-mode from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 9 2022, 2:02 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4142: Input ifbX interfaces not displayed in op-mode as Resolved.
Jan 9 2022, 2:01 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4152: NHRP shortcut-target holding-time does not work.

PR for 1.3 https://github.com/vyos/vyos-nhrp/pull/7

Jan 9 2022, 1:50 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4152: NHRP shortcut-target holding-time does not work.

PR for 1.4 https://github.com/vyos/vyos-1x/pull/1145

Jan 9 2022, 12:42 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4152: NHRP shortcut-target holding-time does not work from Open to In progress.
Jan 9 2022, 12:19 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4100: Firewall increase maximum number of rules.

Check a real generated firewall iptables/nftables config
As 10000 it is the latest default rule, so your rules can be applied after default action with seq 10000

Jan 9 2022, 9:36 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4087: IPsec IKE-group proposals limit of 10 pieces from Open to Needs testing.
Jan 9 2022, 7:45 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a project to T4087: IPsec IKE-group proposals limit of 10 pieces : VyOS 1.4 Sagitta.

Could you also create a pr for 1.4?
Or 1.4 doesn’t have such limits?

Jan 9 2022, 7:44 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a comment to T4072: Feature Request: Firewall on bridge interfaces.

Does it work with vlan bridges T3115?

Jan 9 2022, 7:40 AM · VyOS 1.4 Sagitta
nikeshhajari created T4152: NHRP shortcut-target holding-time does not work.
Jan 9 2022, 6:39 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta