Page MenuHomeVyOS Platform
Feed All Stories

Feb 18 2022

fernando created T4258: [DHCP-SERVER] error parameter on Failover.
Feb 18 2022, 6:29 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4254: VPN IPSec charon add options cisco_flexvpn and install_virtual_ip_on.

PR https://github.com/vyos/vyos-1x/pull/1226

Feb 18 2022, 10:52 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4254: VPN IPSec charon add options cisco_flexvpn and install_virtual_ip_on.
Feb 18 2022, 9:14 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4232: VyOS 1.2 traffic-policy shaper match interface not working.

@kirvio Could you check it on 1.3/1.4?

Feb 18 2022, 8:33 AM · VyOS 1.2 Crux
kirvio triaged T4232: VyOS 1.2 traffic-policy shaper match interface not working as High priority.
Feb 18 2022, 6:05 AM · VyOS 1.2 Crux
chenxiaolong added a comment to T4245: eapol: Support for specifying the full CA chain of trust for both client and server.

PR for documentation: https://github.com/vyos/vyos-documentation/pull/719

Feb 18 2022, 12:33 AM
chenxiaolong added a comment to T4245: eapol: Support for specifying the full CA chain of trust for both client and server.

I've submitted a PR here: https://github.com/vyos/vyos-1x/pull/1227

Feb 18 2022, 12:03 AM

Feb 17 2022

Viacheslav updated the task description for T4254: VPN IPSec charon add options cisco_flexvpn and install_virtual_ip_on.
Feb 17 2022, 9:14 PM · VyOS 1.4 Sagitta
xtremxyz closed T4253: default-route pppoe client connection as Resolved.

It's not a bug, to automatically add the routes when the link is disconnected, set the connect-on-demand parameter.

Feb 17 2022, 8:36 PM
Cheeze_It claimed T4257: Discussion on changing BGP autonomous system number syntax.
Feb 17 2022, 8:27 PM · VyOS 1.4 Sagitta
Cheeze_It updated subscribers of T4257: Discussion on changing BGP autonomous system number syntax.
Feb 17 2022, 8:24 PM · VyOS 1.4 Sagitta
Cheeze_It created T4257: Discussion on changing BGP autonomous system number syntax.
Feb 17 2022, 8:24 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXe9717236fb23: vyos.configverify: T4255: fix unexpected print of dictionary instead of key.
Feb 17 2022, 8:13 PM
c-po closed T4255: Unexpected print of dict bridge on delete as Resolved.
Feb 17 2022, 8:13 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po moved T4255: Unexpected print of dict bridge on delete from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 17 2022, 8:13 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po moved T4255: Unexpected print of dict bridge on delete from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Feb 17 2022, 8:12 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po changed the status of T4255: Unexpected print of dict bridge on delete from Open to In progress.
Feb 17 2022, 8:12 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po committed rVYOSONEX9e626ce7bad2: vyos.configverify: T4255: fix unexpected print of dictionary instead of key.
Feb 17 2022, 8:11 PM
Viacheslav committed rVYOSONEX4552dbcf38b0: openvpn: T3686: Fix for check local-address in script and tmpl.
Feb 17 2022, 7:58 PM
GitHub <noreply@github.com> committed rVYOSONEX1e60e4a29688: Merge pull request #1221 from sever-sever/T3686-equ (authored by c-po).
Feb 17 2022, 7:58 PM
c-po committed rVYOSONEX1cbcbf40b772: openvpn: T4230: globally enable ip_nonlocal_bind.
Feb 17 2022, 7:58 PM
Viacheslav changed the status of T3600: DHCP Interface static route breaks PBR, a subtask of T3505: Commits do not respect changes in FRR that are not stored in a config, from In progress to Needs testing.
Feb 17 2022, 7:58 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav changed the status of T3600: DHCP Interface static route breaks PBR from In progress to Needs testing.
Feb 17 2022, 7:58 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX4ecfd5d87c33: openvpn: T4230: Delete checks if local-host address assigned.
Feb 17 2022, 7:57 PM
GitHub <noreply@github.com> committed rVYOSONEX1d141f9927f6: Merge pull request #1211 from sever-sever/T4230-cur (authored by c-po).
Feb 17 2022, 7:57 PM
c-po closed T4154: Error add second gre tunnel with the same source interface as Resolved.
Feb 17 2022, 7:55 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
vplehto updated the task description for T4256: Display static DHCP server leases in the operational command output.
Feb 17 2022, 7:34 PM · VyOS 1.5 Circinus
Viacheslav closed T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus as Resolved.

@dutty Thanks for confirming.

Feb 17 2022, 7:18 PM · VyOS 1.3 Equuleus ( 1.3.1)
dutty added a comment to T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.

I just built ISO from the 1.3 branch and tried (1.3-rolling-202202171824). ocserv works normal. The issue is probably resolved.
Thank you.

Feb 17 2022, 7:16 PM · VyOS 1.3 Equuleus ( 1.3.1)
vplehto created T4256: Display static DHCP server leases in the operational command output.
Feb 17 2022, 6:40 PM · VyOS 1.5 Circinus
Viacheslav created T4255: Unexpected print of dict bridge on delete.
Feb 17 2022, 4:36 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4254: VPN IPSec charon add options cisco_flexvpn and install_virtual_ip_on from Open to In progress.
Feb 17 2022, 4:10 PM · VyOS 1.4 Sagitta
Viacheslav created T4254: VPN IPSec charon add options cisco_flexvpn and install_virtual_ip_on.
Feb 17 2022, 4:08 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID from In progress to Needs testing.
Feb 17 2022, 3:53 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
jestabro moved T3474: Revisit storing syntax version of interface definitions in XML file from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 17 2022, 3:32 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro closed T3474: Revisit storing syntax version of interface definitions in XML file, a subtask of T1962: Add syntax version to schema, as Unknown Status.
Feb 17 2022, 3:32 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T3474: Revisit storing syntax version of interface definitions in XML file, a subtask of T3475: XML dictionary cache unable to process syntaxVersion elements, as Unknown Status.
Feb 17 2022, 3:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro closed T3474: Revisit storing syntax version of interface definitions in XML file as Unknown Status.
Feb 17 2022, 3:32 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro committed rVYOSONEX3795fdba8edf: xml: T3474: add component version include files.
Feb 17 2022, 3:31 PM
jestabro committed rVYOSONEXd9a1f8deceec: xml: T3474: add smoketest to check xml component versions are maintained.
Feb 17 2022, 3:31 PM
jestabro committed rVYOSONEX425f8f16caa7: xml: T3474: get component version dictionary from xml cache, not legacy.
Feb 17 2022, 3:31 PM
GitHub <noreply@github.com> committed rVYOSONEXe66879f71da3: Merge pull request #1225 from jestabro/component-version (authored by jestabro).
Feb 17 2022, 3:31 PM
dmbaturin claimed T4252: `show configuration json` (op mode) and `show | json` (conf mode) represent multi-value nodes differently.
Feb 17 2022, 2:31 PM · VyOS Rolling, Restricted Project
Viacheslav committed rVYOSONEXb99432ee2dc8: vrrp: T1972: Ability to set IP address on not vrrp interface.
Feb 17 2022, 2:22 PM
GitHub <noreply@github.com> committed rVYOSONEXb14e91cb5547: Merge pull request #1224 from sever-sever/T1972-equ (authored by dmbaturin).
Feb 17 2022, 2:22 PM
c-po closed T4240: Cannot add wlan0 to bridge via configure as Resolved.
Feb 17 2022, 1:54 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po moved T4240: Cannot add wlan0 to bridge via configure from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Feb 17 2022, 1:54 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po committed rVYOSONEX267818cb247f: wireless: T4240: bugfix interface bridging.
Feb 17 2022, 1:54 PM
xtremxyz created T4253: default-route pppoe client connection.
Feb 17 2022, 12:02 PM
Viacheslav changed the status of T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus from Confirmed to Needs testing.
Feb 17 2022, 10:34 AM · VyOS 1.3 Equuleus ( 1.3.1)
Viacheslav added a comment to T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.

CI job for re-build pkg ocserv should fix this issue.

Feb 17 2022, 10:28 AM · VyOS 1.3 Equuleus ( 1.3.1)
chenxiaolong renamed T4245: eapol: Support for specifying the full CA chain of trust for both client and server from eapol: Support for multiple CA certificates (eg. intermediate + root) to eapol: Support for specifying the full CA chain of trust for both client and server.
Feb 17 2022, 7:38 AM
chenxiaolong added a comment to T4245: eapol: Support for specifying the full CA chain of trust for both client and server.

After further testing, it looks like it's not necessary to have <iface>_ca.pem contain both the server and client chains of trust.

Feb 17 2022, 7:32 AM
chenxiaolong added a comment to T4245: eapol: Support for specifying the full CA chain of trust for both client and server.

I started working on implementing my "alternative" idea. It's a little bit more complicated than I first thought because we have to consider both the server and client chain of trust.

Feb 17 2022, 7:16 AM
chenxiaolong created T4252: `show configuration json` (op mode) and `show | json` (conf mode) represent multi-value nodes differently.
Feb 17 2022, 5:39 AM · VyOS Rolling, Restricted Project
bbabich created T4251: Add TLS functionality for rsyslog.
Feb 17 2022, 4:51 AM · VyOS 1.4 Sagitta (1.4.4), VyOS 1.5 Circinus (1.5-stream-2025-Q4)
jestabro added a comment to T3474: Revisit storing syntax version of interface definitions in XML file.

https://github.com/vyos/vyos-1x/pull/1225

Feb 17 2022, 3:51 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
klipz added a comment to T4240: Cannot add wlan0 to bridge via configure.

@c-po Thank you for the work on this.

Feb 17 2022, 1:20 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)

Feb 16 2022

Viacheslav edited projects for T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus.
Feb 16 2022, 11:26 PM · VyOS 1.3 Equuleus ( 1.3.1)
Viacheslav changed the status of T4197: Vyos arm64-latest build issue with telegraf pkg from Open to Needs testing.
Feb 16 2022, 11:25 PM · VyOS 1.4 Sagitta
c-po moved T4240: Cannot add wlan0 to bridge via configure from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 16 2022, 9:19 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po committed rVYOSONEXf076f9f4cf6e: policy: T2425: add completion helper script when referencing IP addresses.
Feb 16 2022, 9:18 PM
c-po committed rVYOSONEX1ceaed55a629: wireless: T4240: bugfix interface bridging.
Feb 16 2022, 9:18 PM
Viacheslav added a comment to T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.

Install official pkg solve the issue

wget http://ftp.de.debian.org/debian/pool/main/o/ocserv/ocserv_0.12.2-3_amd64.deb
dpkg -i *.deb
`
Feb 16 2022, 9:12 PM · VyOS 1.3 Equuleus ( 1.3.1)
c-po changed the status of T4240: Cannot add wlan0 to bridge via configure from Open to Needs testing.
Feb 16 2022, 8:53 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
Viacheslav added a comment to T4249: Add support for device mapping in containers.
Feb 16 2022, 8:44 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.

Can be related
Found out some strange things, client address was banned:

ocserv[2072]: main: added 1 points (total 1) for IP '192.168.122.1' to ban list
Feb 16 2022, 7:14 PM · VyOS 1.3 Equuleus ( 1.3.1)
zsdc created T4250: Organize logrotate settings to avoid duplicates.
Feb 16 2022, 6:09 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus from Open to Confirmed.
Feb 16 2022, 5:48 PM · VyOS 1.3 Equuleus ( 1.3.1)
Viacheslav added a comment to T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.

I don't see any issues with LTS 1.3.0

Feb 16 2022, 5:48 PM · VyOS 1.3 Equuleus ( 1.3.1)
Viacheslav added a comment to T4249: Add support for device mapping in containers.

Thanks
Is it required point of binding in a container?
For example:

podman run --rm -it --device=/dev/vdb:/dev/xvdc:rwm --net host ubuntu bash
Feb 16 2022, 4:17 PM · VyOS 1.4 Sagitta
Yuanandyuan added a comment to T4249: Add support for device mapping in containers.

You can get access to host netwoks with set container name foo allow-host-networks

Feb 16 2022, 3:56 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4249: Add support for device mapping in containers.

You can get access to host netwoks with set container name foo allow-host-networks

Feb 16 2022, 3:44 PM · VyOS 1.4 Sagitta
Yuanandyuan created T4249: Add support for device mapping in containers.
Feb 16 2022, 3:39 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1224

Feb 16 2022, 3:09 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav reopened T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID as "In progress".
Feb 16 2022, 2:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4237: Conntrack-sync error - error adding listen-address command as Resolved.
Feb 16 2022, 1:58 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
Viacheslav added a comment to T973: Create Prometheus Exporter for VyOS .

@anthr76 we have ready telegraf exporter, maybe it will work for you?
https://docs.vyos.io/en/latest/configuration/service/monitoring.html

Feb 16 2022, 1:34 PM · VyOS Rolling, VyOS 1.5 Circinus
anthr76 added a comment to T973: Create Prometheus Exporter for VyOS .

Does anyone at least have an example of how to use the snmp exporter? For example a snmp.yml or generate one with the given mibs?

Feb 16 2022, 1:28 PM · VyOS Rolling, VyOS 1.5 Circinus
Unknown Object (User) closed T3408: vyos 1.4 not delivering ipv6 to devices via PPPOE as Invalid.

Tested on 1.4-rolling-202202150317 and 1.3.0, all works

Feb 16 2022, 11:18 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4248: There isn't a way to remove the only rule from the (traffic-policy) class. from "Task" to "Bug".
Feb 16 2022, 7:08 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Unknown Object (User) triaged T4248: There isn't a way to remove the only rule from the (traffic-policy) class. as Low priority.
Feb 16 2022, 1:10 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Feb 15 2022

pedro added a comment to T941: BGP neighbours with IPv6 link-local addresses.

this is very similar to https://phabricator.vyos.net/T3657 , so it seems that this is going to be fixed in 1.4 ( proof https://forum.vyos.io/t/bgp-peering-with-ipv6-link-local-addresses/7309/14 ). Is this going to be backported to 1.3 ? Anyone is able to find the commit that introduced the feature on 1.4? Maybe it is something easy to patch

Feb 15 2022, 11:26 PM · VyOS 1.3 Equuleus (1.3.9), test
Viacheslav moved T1292: Issues while deleting all rules from a firewall from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 15 2022, 10:12 PM · VyOS 1.4 Sagitta
sarthurdev updated subscribers of T4145: Conntrack table not showing after firewall rewriting.

I think @c-po has started migrating it in T3579 but op-mode not yet complete.

Feb 15 2022, 7:10 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4145: Conntrack table not showing after firewall rewriting.

Comman "show conntrack ..." not available any more in latest?

Feb 15 2022, 7:04 PM · VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T3494: DHCPv6 leases traceback when PD using from Unknown Status to Resolved.
Feb 15 2022, 6:58 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
n.fort added a comment to T3989: Firewall - Can't delete rule in firewall entry and leave just default-action when firewall entry is in used.

Duplicate T1292 was assigned to 1.4 version, and I close it because it was solved.
This bug remains open for 1.3 Equuleus

Feb 15 2022, 6:56 PM
n.fort closed T1292: Issues while deleting all rules from a firewall, a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Feb 15 2022, 6:51 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
n.fort closed T1292: Issues while deleting all rules from a firewall as Resolved.
Feb 15 2022, 6:51 PM · VyOS 1.4 Sagitta
n.fort added a comment to T1292: Issues while deleting all rules from a firewall.

Tested on VyOS 1.4-rolling-202202150317 and working as expected.

Feb 15 2022, 6:50 PM · VyOS 1.4 Sagitta
n.fort closed T4160: Firewall - Error in rules that matches everything except something as Resolved.
vyos@vyos# run show config comm | grep fire
set firewall name FOO rule 10 action 'accept'
set firewall name FOO rule 10 protocol 'tcp'
set firewall name FOO rule 10 tcp flags not ack
set firewall name FOO rule 10 tcp flags syn
set firewall name FOO rule 40 action 'accept'
set firewall name FOO rule 40 protocol '!gre'
[edit]
vyos@vyos# sudo nft list chain ip filter NAME_FOO
table ip filter {
	chain NAME_FOO {
		tcp flags & (syn | ack) == syn counter packets 0 bytes 0 return comment "FOO-10"
		meta l4proto != gre counter packets 0 bytes 0 return comment "FOO-40"
		counter packets 0 bytes 0 return comment "FOO default-action accept"
	}
}
Feb 15 2022, 6:44 PM · VyOS 1.4 Sagitta
n.fort closed T4201: Firewall - ICMPv6 matches not working as expected on 1.3.0 as Resolved.

Solved. New commands:

Feb 15 2022, 6:22 PM · VyOS 1.3 Equuleus (1.3.0)
rgrant created T4247: Access Control for SSH (and other?) services.
Feb 15 2022, 5:00 PM
Unknown Object (User) committed rVYOSONEX81add0813735: dhcpv6-server: T3494: Get address from network to correct sorting.
Feb 15 2022, 4:03 PM
GitHub <noreply@github.com> committed rVYOSONEX40bf0d3ff078: Merge pull request #1222 from DmitriyEshenko/eq-1x-15022022 (authored by c-po).
Feb 15 2022, 4:03 PM
Viacheslav committed rVYOSONEX283688fe52bd: conntrack-sync: T4237: Fix checks for listen-address list to str.
Feb 15 2022, 4:03 PM
GitHub <noreply@github.com> committed rVYOSONEX0f788abea73f: Merge pull request #1223 from sever-sever/T4237-cur (authored by c-po).
Feb 15 2022, 4:03 PM
Unknown Object (User) closed T3006: Accel-PPP & vlan-mon config get invalid VLAN as Resolved.
Feb 15 2022, 3:35 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav moved T4237: Conntrack-sync error - error adding listen-address command from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.

PR for current https://github.com/vyos/vyos-1x/pull/1223

Feb 15 2022, 12:53 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)