Page MenuHomeVyOS Platform
Feed All Stories

Jan 17 2022

sarthurdev closed T4188: Firewall does not correctly handle conntracking as Invalid.

You need to remove the state new match on the rule and it'll work.

Jan 17 2022, 7:54 PM · VyOS 1.4 Sagitta
c-po closed T3164: console-server ssh does not work with RADIUS PAM auth as Resolved.
Jan 17 2022, 7:22 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po moved T3164: console-server ssh does not work with RADIUS PAM auth from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 17 2022, 7:22 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po committed rVYOSONEX385b72da4845: bgp: T3741: bugfix migrator - exit() was called without saving.
Jan 17 2022, 6:33 PM
Viacheslav closed T891: Current multi-table usage with VRF-netns tables in FRR is partially broken for PBR. as Not Applicable.

Close the task
@Watcher7 Re-test it or describe steps hot to reproduce, as since 1.2-rc2 was implemented a lot of changes regarding vrf + frr.
You can set both vrf + next-hop address

Jan 17 2022, 6:05 PM · VyOS 1.3 Equuleus (1.3.0)
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.171 / 5.10.91 to Update Linux Kernel to v5.4.172 / 5.10.92.
Jan 17 2022, 6:05 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
klipz added a comment to T4139: Wireless interface member of a bridge.

I experience the same problem of VyOS failing to add wlan0 to bridge, which persists in all 1.3-epa and 1.3-LTS versions, as well as 1.4 nightly builds.

Jan 17 2022, 5:19 PM · VyOS 1.3 Equuleus (1.3.6)
sarthurdev committed rVYOSONEXab4dd3b7a65d: zone-policy: T3873: Fix intra-zone-filtering return to zone default-action.
Jan 17 2022, 5:08 PM
sarthurdev committed rVYOSONEX64668771d5f1: firewall: policy: T4178: Migrate and refactor tcp flags.
Jan 17 2022, 5:08 PM
sarthurdev committed rVYOSONEX53c2b62dda5b: firewall: T2199: Fix `port-range` validator to accept service names.
Jan 17 2022, 5:08 PM
GitHub <noreply@github.com> committed rVYOSONEX9fb2e1432209: Merge pull request #1174 from sarthurdev/firewall (authored by c-po).
Jan 17 2022, 5:08 PM
n.fort added a comment to T4173: Wan Load Balancing - Error on firewall NAT rules.

Tested and working as expected on VyOS 1.4-rolling-202201150317

Jan 17 2022, 3:48 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4189: Ability to set dns forwarding in vrf.

There are some issues with powerdns in vrf context.

Jan 17 2022, 12:59 PM · VyOS 1.4 Sagitta
UnicronNL created T4190: Add commit comment to the configuration API..
Jan 17 2022, 12:34 PM
sarthurdev added a comment to T4178: policy based routing tcp flags issue.

Included those flags in PR: https://github.com/vyos/vyos-1x/pull/1174

Jan 17 2022, 11:29 AM · VyOS 1.4 Sagitta
n.fort added a comment to T4178: policy based routing tcp flags issue.

Think 2 flag options should be added.
According to nft wiki these are all the flags that nft could match: tcp flags { fin, syn, rst, psh, ack, urg, ecn, cwr}

Jan 17 2022, 11:23 AM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3873: Zone based Firewall - Filter traffic in same zone.

Included in PR: https://github.com/vyos/vyos-1x/pull/1174

Jan 17 2022, 11:08 AM · VyOS 1.4 Sagitta
Viacheslav created T4189: Ability to set dns forwarding in vrf.
Jan 17 2022, 11:02 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4100: Firewall increase maximum number of rules.

It is a different task, it extends only the range which you can to use for rule numbers.
For example, if you want 3 rules
Rule 100, rule 1000, rule 10000 etc.
Accepting time it is another task. B.t.w firewall was rewritten in 1.4, I hope that commit time was decreased.

Jan 17 2022, 10:18 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
FileGo created T4188: Firewall does not correctly handle conntracking.
Jan 17 2022, 6:43 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4100: Firewall increase maximum number of rules.

I think we will have a problem with such a large number of rules. Now, if there are 1500 vyos rules, it takes 30 minutes to load. If there are 999999 rules, it will take a very long time to load.

Jan 17 2022, 12:53 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
bbabich created T4187: XDP broken for VLAN/vif interfaces with hardware offloading.
Jan 17 2022, 12:47 AM · VyOS 1.4 Sagitta

Jan 16 2022

sarthurdev changed the status of T3873: Zone based Firewall - Filter traffic in same zone from Open to In progress.

Thanks, will include a fix in a PR shortly

Jan 16 2022, 9:43 PM · VyOS 1.4 Sagitta
c-po moved T3164: console-server ssh does not work with RADIUS PAM auth from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 16 2022, 8:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po changed the status of T3164: console-server ssh does not work with RADIUS PAM auth from Open to Needs testing.
Jan 16 2022, 8:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po committed rVYOSONEX7e731c0ef503: Revert "migrator: interfaces: T4171: bugfix ConfigTreeError".
Jan 16 2022, 5:55 PM
c-po added a reverting change for rVYOSONEX29efbf51efea: migrator: interfaces: T4171: bugfix ConfigTreeError: rVYOSONEX7e731c0ef503: Revert "migrator: interfaces: T4171: bugfix ConfigTreeError".
Jan 16 2022, 5:55 PM
c-po added a reverting change for rVYOSONEX391ce22b7619: migrator: interfaces: T4171: bugfix ConfigTreeError: rVYOSONEX9f52a4f4ea99: Revert "migrator: interfaces: T4171: bugfix ConfigTreeError".
Jan 16 2022, 5:55 PM
c-po committed rVYOSONEX9f52a4f4ea99: Revert "migrator: interfaces: T4171: bugfix ConfigTreeError".
Jan 16 2022, 5:55 PM
n.fort added a comment to T4160: Firewall - Error in rules that matches everything except something.

I can see the fix, but now trying invert selection on tcp flags doesn't work

Jan 16 2022, 4:07 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4186: Firewall icmp type - Offered options not supported.

PR: https://github.com/vyos/vyos-1x/pull/1173

Jan 16 2022, 3:47 PM · VyOS 1.4 Sagitta
n.fort claimed T4186: Firewall icmp type - Offered options not supported.
Jan 16 2022, 2:09 PM · VyOS 1.4 Sagitta
n.fort created T4186: Firewall icmp type - Offered options not supported.
Jan 16 2022, 2:09 PM · VyOS 1.4 Sagitta
n.fort added a comment to T3873: Zone based Firewall - Filter traffic in same zone.

Testing this feature in VyOS 1.4-rolling-202201100317 I'm getting some unexpected behavior.
Config:

Jan 16 2022, 1:41 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXbcc45248facb: smoketest: ntp: T4184: check for "restrict default ignore" presencex.
Jan 16 2022, 11:17 AM
c-po committed rVYOSONEX89d6b41577a4: smoketest: ntp: re-organize testcases.
Jan 16 2022, 11:17 AM
Viacheslav committed rVYOSONEX585042dba9d7: ntp: T4184: Fix allow-clients address.
Jan 16 2022, 11:16 AM
GitHub <noreply@github.com> committed rVYOSONEX56255941e584: Merge pull request #1172 from sever-sever/T4184-equ (authored by c-po).
Jan 16 2022, 11:16 AM
c-po added a comment to T3700: Support VLAN tunnel mapping of VLAN aware bridges.

For full support we need this added to FRR: https://github.com/FRRouting/frr/pull/9204

Jan 16 2022, 11:02 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXb8039c9888bd: dns-forwarding: T1595: remove unnecessary nesting in migration script 1 -> 2.
Jan 16 2022, 10:16 AM
c-po committed rVYOSONEX3399e0df679f: bgp: T3741: remove unnecessary exit() in migration script 1 -> 2.
Jan 16 2022, 10:16 AM

Jan 15 2022

c-po committed rVYOSONEXba9dc4c2ff89: smoketest: ntp: re-organize testcases.
Jan 15 2022, 4:43 PM
c-po committed rVYOSONEX3ef881fcc3aa: smoketest: ntp: T4184: check for "restrict default ignore" presencex.
Jan 15 2022, 4:43 PM
Viacheslav moved T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from Open to Finished on the VyOS 1.4 Sagitta board.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1172

Jan 15 2022, 4:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX40f0e78dd946: ntp: T4184: Fix allow-clients address.
Jan 15 2022, 3:57 PM
GitHub <noreply@github.com> committed rVYOSONEX618db51b3b4c: Merge pull request #1171 from sever-sever/T4184 (authored by c-po).
Jan 15 2022, 3:57 PM
Viacheslav closed T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0 as Resolved.
Jan 15 2022, 3:52 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4183: IPv6 link-local address not accepted as wireguard peer as Resolved.
Jan 15 2022, 3:52 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXcb69b6e875c9: wireguard: T4183: Allow setting ipv6 link local addres for peer.
Jan 15 2022, 3:50 PM
Viacheslav committed rVYOSONEXc39d6dd7f6a8: listen-address: T4110: Ability to set IPv6 link-local for services.
Jan 15 2022, 3:50 PM
GitHub <noreply@github.com> committed rVYOSONEX31a27136a499: Merge pull request #1170 from sever-sever/T4183-equ (authored by c-po).
Jan 15 2022, 3:50 PM
Viacheslav added a comment to T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.

PR https://github.com/vyos/vyos-1x/pull/1171

Jan 15 2022, 3:47 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav renamed T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from NTP allow-clients address doesn't work to NTP allow-clients address doesn't work it allows to use ntp server for all addresses.
Jan 15 2022, 3:32 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from "Task" to "Bug".
Jan 15 2022, 3:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from Open to In progress.
Jan 15 2022, 3:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1170

Jan 15 2022, 3:13 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1170

Jan 15 2022, 3:12 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav reopened T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0 as "In progress".
Jan 15 2022, 3:01 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav reopened T4183: IPv6 link-local address not accepted as wireguard peer as "In progress".
Jan 15 2022, 1:30 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav moved T4150: VRRP with conntrack-sync does not work from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 15 2022, 1:28 PM · VyOS 1.4 Sagitta
Viacheslav closed T4183: IPv6 link-local address not accepted as wireguard peer as Resolved.
Jan 15 2022, 11:49 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXdbdb736c8512: wireguard: T4183: Allow to set peer IPv6 link-local address.
Jan 15 2022, 7:09 AM
GitHub <noreply@github.com> committed rVYOSONEX3b4ece7dde02: Merge pull request #1169 from sever-sever/T4183 (authored by c-po).
Jan 15 2022, 7:09 AM
Unknown Object (User) closed T4150: VRRP with conntrack-sync does not work as Resolved.

Re-tested in VyOS 1.4-rolling-202201140317
Now it works, thank you!

Jan 15 2022, 12:45 AM · VyOS 1.4 Sagitta

Jan 14 2022

fernando renamed T4185: [VPN-IPSEC] not boot config after reboot from [VPN-IPSEC] no boot config after reboot to [VPN-IPSEC] not boot config after reboot.
Jan 14 2022, 9:50 PM · VyOS 1.3 Equuleus (1.3.6)
fernando created T4185: [VPN-IPSEC] not boot config after reboot.
Jan 14 2022, 9:44 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav changed the status of T4172: Patch ndppd to not read route table if there are no auto prefixes from Open to In progress.
Jan 14 2022, 9:14 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4183: IPv6 link-local address not accepted as wireguard peer from Open to In progress.
Jan 14 2022, 9:01 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

PR https://github.com/vyos/vyos-1x/pull/1169

Jan 14 2022, 9:01 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4182: Show vrrp if vrrp not configured bug as Resolved.
Jan 14 2022, 8:23 PM · VyOS 1.4 Sagitta
Viacheslav closed T4179: Add op-mode CLI for show high-availability virtual-server as Resolved.
Jan 14 2022, 8:22 PM · VyOS 1.4 Sagitta
Viacheslav closed T4177: Strip-private doesn't work for service monitoring as Resolved.
Jan 14 2022, 8:22 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4150: VRRP with conntrack-sync does not work.

@NikolayP Could you re-test it?

Jan 14 2022, 8:19 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2199: Rewrite firewall in new XML/Python style: T3762: Support network and address groups for policy ipv6-route.
Jan 14 2022, 8:18 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav added a parent task for T3762: Support network and address groups for policy ipv6-route: T2199: Rewrite firewall in new XML/Python style.
Jan 14 2022, 8:18 PM · VyOS 1.4 Sagitta
Viacheslav closed T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID as Resolved.
Jan 14 2022, 8:11 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav edited projects for T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus (1.3.0).
Jan 14 2022, 8:09 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXd63cabb18649: op-mode: T4179: Add op-mode CLI show virtual-server.
Jan 14 2022, 7:31 PM
GitHub <noreply@github.com> committed rVYOSONEX6e8a8934a7d4: Merge pull request #1164 from sever-sever/T4179 (authored by c-po).
Jan 14 2022, 7:31 PM
sarthurdev committed rVYOSONEXdf5a862beb84: firewall: T4178: Use lowercase for TCP flags and add an validator.
Jan 14 2022, 7:31 PM
GitHub <noreply@github.com> committed rVYOSONEX9aa8e51de06b: Merge pull request #1167 from sarthurdev/firewall (authored by c-po).
Jan 14 2022, 7:31 PM
Viacheslav added a comment to T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.

Some detail here T1280

Jan 14 2022, 2:25 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
johannrichard added a comment to T2199: Rewrite firewall in new XML/Python style.

@sdev: in your original commit for this task, recent rules are somehow semi-discarded (the time/counter condition will not be written out; however, the action will be written out) because of an apparent problem with nftables in this area.

Jan 14 2022, 10:10 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
Unknown Object (User) updated the task description for T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.
Jan 14 2022, 10:01 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) renamed T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from NTP allow-clients address requires a reboot to NTP allow-clients address doesn't work.
Jan 14 2022, 9:55 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.
Jan 14 2022, 4:42 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) created T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.
Jan 14 2022, 4:35 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
odhnera added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

Thanks; I just tested commenting out line 5 of that file, and it successfully works around the issue, allowing me to set a link-local IPv6 address as my endpoint. The wireguard connection itself also works, and I can pass traffic.

Jan 14 2022, 1:08 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

@odhnera Try to comment or delete the validation string and restart vyos-configd service

Jan 14 2022, 12:15 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Jan 13 2022

odhnera added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

Getting link-local addresses to work would probably be very low-priority, but I did run into an extremely niche case where I wanted to do that. It's not the type of situation that would happen in a production environment, but I was running VyOS on a computer tethered via ethernet to an Android-based phone, and I wanted to connect to a wireguard peer running on the phone. Modern version of Android randomize the IPv4 address of their tethered interface on each reboot, but their link-local IPv6 address remains the same, making it more convenient to use it.

Jan 13 2022, 11:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

Link-local addresses with %ethX are not accepted in any protocols/peers/etc. A few services are allowed to set them as listen like ssh/dns at the moment.
Is there a real use case why you need it on wireguard interfaces?

Jan 13 2022, 11:23 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4183: IPv6 link-local address not accepted as wireguard peer from "Bug" to "Feature Request".
Jan 13 2022, 11:19 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4025: OpenVPN server with TAP interface, client didn’t see network.

It generates by openvpn, maybe something new in the new OpenVPN version
So I see only one option - add mode server-bridge

Jan 13 2022, 11:02 PM · Bugs, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1), Restricted Project, openvpn
odhnera created T4183: IPv6 link-local address not accepted as wireguard peer.
Jan 13 2022, 10:05 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX6cdeb472d924: vrrp: T4182: Check if VRRP configured in op mode.
Jan 13 2022, 9:17 PM
GitHub <noreply@github.com> committed rVYOSONEX97472739b443: Merge pull request #1166 from sever-sever/T4182 (authored by c-po).
Jan 13 2022, 9:17 PM
fett0 <fernando.gmaidana@gmail.com> committed rVYOSONEXeae32ec9ae9f: Firewall: T4181: Set correct description for ipv6-network-group.
Jan 13 2022, 8:39 PM
GitHub <noreply@github.com> committed rVYOSONEXb3fc933da9b9: Merge pull request #1168 from fett0/T4181 (authored by c-po).
Jan 13 2022, 8:39 PM
Viacheslav assigned T4181: Firewall ipv6-network-group - incorrect description on helper to fernando.
Jan 13 2022, 8:34 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4178: policy based routing tcp flags issue from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1167

Jan 13 2022, 8:29 PM · VyOS 1.4 Sagitta