Page MenuHomeVyOS Platform
Feed All Stories

Jan 19 2022

hexes added a comment to T4025: OpenVPN server with TAP interface, client didn’t see network.

Hello @Viacheslav, thanks for reply, so, if you'll bridge vtun94 and eth0.94 to br94 will it work in L2 level?
Did you push this update to nightbuild?

Jan 19 2022, 3:39 AM · Bugs, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1), Restricted Project, openvpn
Unknown Object (User) created T4194: prefix-list no check for duplicate entries.
Jan 19 2022, 2:00 AM · VyOS 1.4 Sagitta

Jan 18 2022

Viacheslav added a comment to T4072: Feature Request: Firewall on bridge interfaces.

Some details in T4193

Jan 18 2022, 8:51 PM · VyOS 1.4 Sagitta
dmbaturin created T4193: Add support for transparent firewall.
Jan 18 2022, 7:41 PM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEXa7e14cba820f: firewall: T4188: Create default conntrack `FW_CONNTRACK` chain.
Jan 18 2022, 6:59 PM
GitHub <noreply@github.com> committed rVYOSONEXc77369761f9c: Merge pull request #1178 from sarthurdev/firewall_T4188 (authored by c-po).
Jan 18 2022, 6:59 PM
n.fort closed T292: [ZBF] Allow filtering intra zone traffic as Resolved.
Jan 18 2022, 6:29 PM · VyOS 1.4 Sagitta
n.fort added a comment to T292: [ZBF] Allow filtering intra zone traffic.

Resolved in T3873

Jan 18 2022, 6:29 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4188: Firewall does not correctly handle conntracking from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1178

Jan 18 2022, 6:02 PM · VyOS 1.4 Sagitta
johannrichard awarded T3560: Ability to create groups of MAC addresses a Like token.
Jan 18 2022, 5:46 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T3560: Ability to create groups of MAC addresses, a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Jan 18 2022, 5:35 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev changed the status of T3560: Ability to create groups of MAC addresses from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1177

Jan 18 2022, 5:35 PM · VyOS 1.4 Sagitta
sarthurdev renamed T4188: Firewall does not correctly handle conntracking from Firewall does not match ICMPv6 packets to Firewall does not correctly handle conntracking.
Jan 18 2022, 5:30 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4188: Firewall does not correctly handle conntracking from Open to In progress.

Okay, thanks for the update. I have found a conntrack issue in the code. Will have a fix in shortly.

Jan 18 2022, 5:29 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T3522: policy based routing not working.

Looks like I see the same issue for 1.3.0. Reproducing steps:

set interfaces ethernet eth1 address 'dhcp'
set protocols static table 1 route 0.0.0.0/0 dhcp-interface eth1
Jan 18 2022, 4:06 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
FileGo reopened T4188: Firewall does not correctly handle conntracking as "Open".

Thanks, this does fix the ICMP issue, however rule 10 which is supposed to accept packets with related/established states (say a HTTP response following a request), doesn't seem to match any packets, and the packets get dropped by the default rule.

Jan 18 2022, 4:04 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4178: policy based routing tcp flags issue.

TCP Flags seems to be working on firewall filter config.

Jan 18 2022, 3:01 PM · VyOS 1.4 Sagitta
n.fort closed T3873: Zone based Firewall - Filter traffic in same zone as Resolved.
Jan 18 2022, 2:18 PM · VyOS 1.4 Sagitta
n.fort added a comment to T3873: Zone based Firewall - Filter traffic in same zone.

Tested on VyOS 1.4-rolling-202201180317 and working as expected

Jan 18 2022, 2:18 PM · VyOS 1.4 Sagitta
sarthurdev closed T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails, a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Jan 18 2022, 1:50 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev closed T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails as Resolved.
Jan 18 2022, 1:50 PM · VyOS 1.4 Sagitta
sarthurdev closed T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases , a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Jan 18 2022, 1:50 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev closed T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases as Resolved.
Jan 18 2022, 1:50 PM · VyOS 1.4 Sagitta
sarthurdev closed T3286: Switch the firewall from iptables to nftables, a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Jan 18 2022, 1:47 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev closed T3286: Switch the firewall from iptables to nftables as Resolved.
Jan 18 2022, 1:47 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T1292: Issues while deleting all rules from a firewall, a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Jan 18 2022, 1:45 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev changed the status of T1292: Issues while deleting all rules from a firewall from Open to Needs testing.

Fixed in 1.4 PR: https://github.com/vyos/vyos-1x/pull/1176

Jan 18 2022, 1:45 PM · VyOS 1.4 Sagitta
atoy40 added a comment to T4139: Wireless interface member of a bridge.

@klipz In my case, the only problem is adding the wlan interface to the bridge at startup (looks like an order thing), when vyos is started (and the wlan interface is up) no problem to add it to the bridge witth the CLI.

Jan 18 2022, 8:03 AM · VyOS 1.3 Equuleus (1.3.6)
c-po added a comment to T4187: XDP broken for VLAN/vif interfaces with hardware offloading.

The XDP proof of concept program that is availbale in 1.4 does not support 802.1q - those headers are not parsed and processed.

Jan 18 2022, 5:42 AM · VyOS 1.4 Sagitta
c-po changed the status of T4187: XDP broken for VLAN/vif interfaces with hardware offloading from Open to Confirmed.
Jan 18 2022, 5:41 AM · VyOS 1.4 Sagitta
c-po added a comment to T4189: Ability to set dns forwarding in vrf.

What would be the use-case? We can start PDNS in one VRF context only.

Jan 18 2022, 5:40 AM · VyOS 1.4 Sagitta
c-po changed the status of T3700: Support VLAN tunnel mapping of VLAN aware bridges, a subtask of T3137: Let VLAN aware bridge approach the behavior of professional equipment, from In progress to On hold.
Jan 18 2022, 5:26 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po changed the status of T3700: Support VLAN tunnel mapping of VLAN aware bridges from In progress to On hold.
Jan 18 2022, 5:26 AM · VyOS 1.4 Sagitta
nikeshhajari created T4192: OpenVPN custom option for "--client-to-client" causes configuration error.
Jan 18 2022, 4:11 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a project to T2762: VRF: when SSHd is VRF bound all commands are executed in VRF context: VyOS 1.4 Sagitta.
Jan 18 2022, 2:28 AM · VyOS Rolling

Jan 17 2022

Viacheslav added a comment to T2762: VRF: when SSHd is VRF bound all commands are executed in VRF context.

PR for ping https://github.com/vyos/vyos-1x/pull/1175

Jan 17 2022, 11:47 PM · VyOS Rolling
Viacheslav updated the task description for T4191: Lost access to host after VRF re-creating.
Jan 17 2022, 8:12 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav created T4191: Lost access to host after VRF re-creating.
Jan 17 2022, 8:09 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
sarthurdev closed T4188: Firewall does not correctly handle conntracking as Invalid.

You need to remove the state new match on the rule and it'll work.

Jan 17 2022, 7:54 PM · VyOS 1.4 Sagitta
c-po closed T3164: console-server ssh does not work with RADIUS PAM auth as Resolved.
Jan 17 2022, 7:22 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po moved T3164: console-server ssh does not work with RADIUS PAM auth from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 17 2022, 7:22 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po committed rVYOSONEX385b72da4845: bgp: T3741: bugfix migrator - exit() was called without saving.
Jan 17 2022, 6:33 PM
Viacheslav closed T891: Current multi-table usage with VRF-netns tables in FRR is partially broken for PBR. as Not Applicable.

Close the task
@Watcher7 Re-test it or describe steps hot to reproduce, as since 1.2-rc2 was implemented a lot of changes regarding vrf + frr.
You can set both vrf + next-hop address

Jan 17 2022, 6:05 PM · VyOS 1.3 Equuleus (1.3.0)
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.171 / 5.10.91 to Update Linux Kernel to v5.4.172 / 5.10.92.
Jan 17 2022, 6:05 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
klipz added a comment to T4139: Wireless interface member of a bridge.

I experience the same problem of VyOS failing to add wlan0 to bridge, which persists in all 1.3-epa and 1.3-LTS versions, as well as 1.4 nightly builds.

Jan 17 2022, 5:19 PM · VyOS 1.3 Equuleus (1.3.6)
sarthurdev committed rVYOSONEXab4dd3b7a65d: zone-policy: T3873: Fix intra-zone-filtering return to zone default-action.
Jan 17 2022, 5:08 PM
sarthurdev committed rVYOSONEX64668771d5f1: firewall: policy: T4178: Migrate and refactor tcp flags.
Jan 17 2022, 5:08 PM
sarthurdev committed rVYOSONEX53c2b62dda5b: firewall: T2199: Fix `port-range` validator to accept service names.
Jan 17 2022, 5:08 PM
GitHub <noreply@github.com> committed rVYOSONEX9fb2e1432209: Merge pull request #1174 from sarthurdev/firewall (authored by c-po).
Jan 17 2022, 5:08 PM
n.fort added a comment to T4173: Wan Load Balancing - Error on firewall NAT rules.

Tested and working as expected on VyOS 1.4-rolling-202201150317

Jan 17 2022, 3:48 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4189: Ability to set dns forwarding in vrf.

There are some issues with powerdns in vrf context.

Jan 17 2022, 12:59 PM · VyOS 1.4 Sagitta
UnicronNL created T4190: Add commit comment to the configuration API..
Jan 17 2022, 12:34 PM
sarthurdev added a comment to T4178: policy based routing tcp flags issue.

Included those flags in PR: https://github.com/vyos/vyos-1x/pull/1174

Jan 17 2022, 11:29 AM · VyOS 1.4 Sagitta
n.fort added a comment to T4178: policy based routing tcp flags issue.

Think 2 flag options should be added.
According to nft wiki these are all the flags that nft could match: tcp flags { fin, syn, rst, psh, ack, urg, ecn, cwr}

Jan 17 2022, 11:23 AM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3873: Zone based Firewall - Filter traffic in same zone.

Included in PR: https://github.com/vyos/vyos-1x/pull/1174

Jan 17 2022, 11:08 AM · VyOS 1.4 Sagitta
Viacheslav created T4189: Ability to set dns forwarding in vrf.
Jan 17 2022, 11:02 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4100: Firewall increase maximum number of rules.

It is a different task, it extends only the range which you can to use for rule numbers.
For example, if you want 3 rules
Rule 100, rule 1000, rule 10000 etc.
Accepting time it is another task. B.t.w firewall was rewritten in 1.4, I hope that commit time was decreased.

Jan 17 2022, 10:18 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
FileGo created T4188: Firewall does not correctly handle conntracking.
Jan 17 2022, 6:43 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4100: Firewall increase maximum number of rules.

I think we will have a problem with such a large number of rules. Now, if there are 1500 vyos rules, it takes 30 minutes to load. If there are 999999 rules, it will take a very long time to load.

Jan 17 2022, 12:53 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
bbabich created T4187: XDP broken for VLAN/vif interfaces with hardware offloading.
Jan 17 2022, 12:47 AM · VyOS 1.4 Sagitta

Jan 16 2022

sarthurdev changed the status of T3873: Zone based Firewall - Filter traffic in same zone from Open to In progress.

Thanks, will include a fix in a PR shortly

Jan 16 2022, 9:43 PM · VyOS 1.4 Sagitta
c-po moved T3164: console-server ssh does not work with RADIUS PAM auth from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 16 2022, 8:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po changed the status of T3164: console-server ssh does not work with RADIUS PAM auth from Open to Needs testing.
Jan 16 2022, 8:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po committed rVYOSONEX7e731c0ef503: Revert "migrator: interfaces: T4171: bugfix ConfigTreeError".
Jan 16 2022, 5:55 PM
c-po added a reverting change for rVYOSONEX29efbf51efea: migrator: interfaces: T4171: bugfix ConfigTreeError: rVYOSONEX7e731c0ef503: Revert "migrator: interfaces: T4171: bugfix ConfigTreeError".
Jan 16 2022, 5:55 PM
c-po added a reverting change for rVYOSONEX391ce22b7619: migrator: interfaces: T4171: bugfix ConfigTreeError: rVYOSONEX9f52a4f4ea99: Revert "migrator: interfaces: T4171: bugfix ConfigTreeError".
Jan 16 2022, 5:55 PM
c-po committed rVYOSONEX9f52a4f4ea99: Revert "migrator: interfaces: T4171: bugfix ConfigTreeError".
Jan 16 2022, 5:55 PM
n.fort added a comment to T4160: Firewall - Error in rules that matches everything except something.

I can see the fix, but now trying invert selection on tcp flags doesn't work

Jan 16 2022, 4:07 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4186: Firewall icmp type - Offered options not supported.

PR: https://github.com/vyos/vyos-1x/pull/1173

Jan 16 2022, 3:47 PM · VyOS 1.4 Sagitta
n.fort claimed T4186: Firewall icmp type - Offered options not supported.
Jan 16 2022, 2:09 PM · VyOS 1.4 Sagitta
n.fort created T4186: Firewall icmp type - Offered options not supported.
Jan 16 2022, 2:09 PM · VyOS 1.4 Sagitta
n.fort added a comment to T3873: Zone based Firewall - Filter traffic in same zone.

Testing this feature in VyOS 1.4-rolling-202201100317 I'm getting some unexpected behavior.
Config:

Jan 16 2022, 1:41 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXbcc45248facb: smoketest: ntp: T4184: check for "restrict default ignore" presencex.
Jan 16 2022, 11:17 AM
c-po committed rVYOSONEX89d6b41577a4: smoketest: ntp: re-organize testcases.
Jan 16 2022, 11:17 AM
Viacheslav committed rVYOSONEX585042dba9d7: ntp: T4184: Fix allow-clients address.
Jan 16 2022, 11:16 AM
GitHub <noreply@github.com> committed rVYOSONEX56255941e584: Merge pull request #1172 from sever-sever/T4184-equ (authored by c-po).
Jan 16 2022, 11:16 AM
c-po added a comment to T3700: Support VLAN tunnel mapping of VLAN aware bridges.

For full support we need this added to FRR: https://github.com/FRRouting/frr/pull/9204

Jan 16 2022, 11:02 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXb8039c9888bd: dns-forwarding: T1595: remove unnecessary nesting in migration script 1 -> 2.
Jan 16 2022, 10:16 AM
c-po committed rVYOSONEX3399e0df679f: bgp: T3741: remove unnecessary exit() in migration script 1 -> 2.
Jan 16 2022, 10:16 AM

Jan 15 2022

c-po committed rVYOSONEXba9dc4c2ff89: smoketest: ntp: re-organize testcases.
Jan 15 2022, 4:43 PM
c-po committed rVYOSONEX3ef881fcc3aa: smoketest: ntp: T4184: check for "restrict default ignore" presencex.
Jan 15 2022, 4:43 PM
Viacheslav moved T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from Open to Finished on the VyOS 1.4 Sagitta board.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1172

Jan 15 2022, 4:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX40f0e78dd946: ntp: T4184: Fix allow-clients address.
Jan 15 2022, 3:57 PM
GitHub <noreply@github.com> committed rVYOSONEX618db51b3b4c: Merge pull request #1171 from sever-sever/T4184 (authored by c-po).
Jan 15 2022, 3:57 PM
Viacheslav closed T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0 as Resolved.
Jan 15 2022, 3:52 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4183: IPv6 link-local address not accepted as wireguard peer as Resolved.
Jan 15 2022, 3:52 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXcb69b6e875c9: wireguard: T4183: Allow setting ipv6 link local addres for peer.
Jan 15 2022, 3:50 PM
Viacheslav committed rVYOSONEXc39d6dd7f6a8: listen-address: T4110: Ability to set IPv6 link-local for services.
Jan 15 2022, 3:50 PM
GitHub <noreply@github.com> committed rVYOSONEX31a27136a499: Merge pull request #1170 from sever-sever/T4183-equ (authored by c-po).
Jan 15 2022, 3:50 PM
Viacheslav added a comment to T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.

PR https://github.com/vyos/vyos-1x/pull/1171

Jan 15 2022, 3:47 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav renamed T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from NTP allow-clients address doesn't work to NTP allow-clients address doesn't work it allows to use ntp server for all addresses.
Jan 15 2022, 3:32 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from "Task" to "Bug".
Jan 15 2022, 3:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from Open to In progress.
Jan 15 2022, 3:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1170

Jan 15 2022, 3:13 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1170

Jan 15 2022, 3:12 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav reopened T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0 as "In progress".
Jan 15 2022, 3:01 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav reopened T4183: IPv6 link-local address not accepted as wireguard peer as "In progress".
Jan 15 2022, 1:30 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav moved T4150: VRRP with conntrack-sync does not work from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 15 2022, 1:28 PM · VyOS 1.4 Sagitta
Viacheslav closed T4183: IPv6 link-local address not accepted as wireguard peer as Resolved.
Jan 15 2022, 11:49 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXdbdb736c8512: wireguard: T4183: Allow to set peer IPv6 link-local address.
Jan 15 2022, 7:09 AM