Page MenuHomeVyOS Platform
Feed All Stories

Mar 24 2022

zsdc changed the status of T2117: Update Cloud-init version and actualize our changes to it from Needs testing to In progress.

Updated: we need to update 20.4 to 22.1 because 20.4 cannot extract SSH keys from the Azure Stack Hub data source.

Mar 24 2022, 6:19 PM
c-po closed T4230: OpenVPN server configuration deleted after reboot when using a VRRP virtual-address as Resolved.
Mar 24 2022, 5:36 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po moved T4230: OpenVPN server configuration deleted after reboot when using a VRRP virtual-address from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Mar 24 2022, 5:36 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po moved T4230: OpenVPN server configuration deleted after reboot when using a VRRP virtual-address from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Mar 24 2022, 5:36 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po added a project to T4230: OpenVPN server configuration deleted after reboot when using a VRRP virtual-address: VyOS 1.4 Sagitta.
Mar 24 2022, 5:36 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po edited projects for T4230: OpenVPN server configuration deleted after reboot when using a VRRP virtual-address, added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta.
Mar 24 2022, 5:35 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po added a comment to T4219: support incoming-interface (iif) in local PBR .

Testcase still fails on VyOS 1.3

Mar 24 2022, 5:26 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T4301: The "arp-monitor" option in bonding interface settings does not work as Resolved.
Mar 24 2022, 5:22 PM · VyOS 1.4 Sagitta
c-po moved T4284: QoS: rewrite to XML and Python from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Mar 24 2022, 5:21 PM · VyOS 1.4 Sagitta
c-po closed T4290: BGP source-interface fails to commit as Resolved.
Mar 24 2022, 5:21 PM · VyOS 1.4 Sagitta
c-po closed T4294: Adding a new openvpn-option does not restart the OpenVPN process as Resolved.
Mar 24 2022, 5:20 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4294: Adding a new openvpn-option does not restart the OpenVPN process from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Mar 24 2022, 5:20 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po edited projects for T4294: Adding a new openvpn-option does not restart the OpenVPN process, added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus.
Mar 24 2022, 5:19 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
syncer set the image for VyOS 1.3 Equuleus (1.3.2) to F2633268: profile.
Mar 24 2022, 5:14 PM
syncer updated the image for VyOS 1.3 Equuleus from F1142386: profile to F2633266: profile.
Mar 24 2022, 5:14 PM
syncer created VyOS 1.3 Equuleus (1.3.2).
Mar 24 2022, 5:13 PM
c-po moved T4294: Adding a new openvpn-option does not restart the OpenVPN process from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Mar 24 2022, 4:46 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po claimed T4294: Adding a new openvpn-option does not restart the OpenVPN process.
Mar 24 2022, 4:46 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
erkin added a subtask for T3355: Remove all remaining legacy Vyatta code: T4316: Update save-config/load-config.
Mar 24 2022, 2:13 PM · VyOS 1.5 Circinus
erkin added a parent task for T4316: Update save-config/load-config: T3355: Remove all remaining legacy Vyatta code.
Mar 24 2022, 2:13 PM · VyOS 1.4 Sagitta (1.4.0-GA)
erkin updated subscribers of T4316: Update save-config/load-config.
Mar 24 2022, 2:09 PM · VyOS 1.4 Sagitta (1.4.0-GA)
jestabro updated the task description for T4318: Add ability to mark nodes as non-tag nodes.
Mar 24 2022, 1:16 PM · VyOS 1.5 Circinus, Restricted Project
jestabro updated the task description for T4318: Add ability to mark nodes as non-tag nodes.
Mar 24 2022, 1:03 PM · VyOS 1.5 Circinus, Restricted Project
jestabro triaged T4318: Add ability to mark nodes as non-tag nodes as Normal priority.
Mar 24 2022, 1:02 PM · VyOS 1.5 Circinus, Restricted Project
jalazaro updated the task description for T4317: IP routes loss after AgentX master agent failed to respond to ping.
Mar 24 2022, 12:34 PM · VyOS 1.2 Crux
jalazaro created T4317: IP routes loss after AgentX master agent failed to respond to ping.
Mar 24 2022, 12:32 PM · VyOS 1.2 Crux
jestabro updated the task description for T4316: Update save-config/load-config.
Mar 24 2022, 12:27 PM · VyOS 1.4 Sagitta (1.4.0-GA)
jestabro created T4316: Update save-config/load-config.
Mar 24 2022, 12:25 PM · VyOS 1.4 Sagitta (1.4.0-GA)
syncer triaged T4315: Telegraf - Output to prometheus as Normal priority.
Mar 24 2022, 11:38 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
syncer assigned T4315: Telegraf - Output to prometheus to Viacheslav.
Mar 24 2022, 11:37 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
NceAirport created T4315: Telegraf - Output to prometheus.
Mar 24 2022, 9:15 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

Mar 23 2022

SrividyaA claimed T4308: Op-comm "Show log frr" to view specific protocol logs.
Mar 23 2022, 6:46 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro moved T4314: Latest 1.4 Rolling release config migration error from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Mar 23 2022, 4:19 PM · VyOS 1.4 Sagitta
jestabro added a project to T4314: Latest 1.4 Rolling release config migration error: VyOS 1.4 Sagitta.
Mar 23 2022, 4:19 PM · VyOS 1.4 Sagitta
jestabro closed T4314: Latest 1.4 Rolling release config migration error as Resolved.
Mar 23 2022, 4:11 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4314: Latest 1.4 Rolling release config migration error.

Yes, thank you.

Mar 23 2022, 3:25 PM · VyOS 1.4 Sagitta
pieteras.meyer added a comment to T4314: Latest 1.4 Rolling release config migration error.

@jestabro , I don't have access to that file anymore, I have already reconfigured the router,

Mar 23 2022, 3:04 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4314: Latest 1.4 Rolling release config migration error.

@pieteras.meyer , while I investigate a related issue, could you share the version before and after you attempted the failed upgrade, and the version string at the bottom of the config file in the before version ? Thanks.

Mar 23 2022, 2:55 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4314: Latest 1.4 Rolling release config migration error.

Given that your current version is 1.4 20210504, this will be the next nightly, though it may be critical enough to build a rolling release now, in which case a few hours.

Mar 23 2022, 2:27 PM · VyOS 1.4 Sagitta
pieteras.meyer added a comment to T4314: Latest 1.4 Rolling release config migration error.

Okay thanks, which rolling release can I used that does not contain this bug?

Mar 23 2022, 1:58 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4314: Latest 1.4 Rolling release config migration error.

Yes, this is an identified bug, thanks to your report:

Mar 23 2022, 1:12 PM · VyOS 1.4 Sagitta
pieteras.meyer added a comment to T4314: Latest 1.4 Rolling release config migration error.

Config in FRR is missing config from VyOS like route-maps

Mar 23 2022, 12:24 PM · VyOS 1.4 Sagitta
pieteras.meyer added a comment to T4314: Latest 1.4 Rolling release config migration error.

Below is config commands from before the upgrade

Mar 23 2022, 12:22 PM · VyOS 1.4 Sagitta
pieteras.meyer created T4314: Latest 1.4 Rolling release config migration error.
Mar 23 2022, 12:20 PM · VyOS 1.4 Sagitta

Mar 22 2022

jestabro added a comment to T1610: Support operator mode commands via REST API.

My understanding of the requirement would be, say, T3758 in the case of op-mode. I consider this to require the refinement of op-mode firstly, as one wants per-command authorization.

Mar 22 2022, 3:01 PM
jestabro added a comment to T1610: Support operator mode commands via REST API.

op-mode endpoints for 'show', 'generate', 'image' have been a part of the REST API for a while, as I'm sure you are aware (just to be clear):

Mar 22 2022, 2:36 PM
adestis added a comment to T1610: Support operator mode commands via REST API.

@adestis there were discussions on this in the past week --- I will be helping @dmbaturin with the task

Mar 22 2022, 1:53 PM
dmbaturin added a project to T4313: "generate public-key-command" throws unhandled exceptions when it cannot retrieve the key: VyOS 1.3 Equuleus.
Mar 22 2022, 8:38 AM · VyOS 1.3 Equuleus (1.3.2)
dmbaturin created T4313: "generate public-key-command" throws unhandled exceptions when it cannot retrieve the key.
Mar 22 2022, 8:38 AM · VyOS 1.3 Equuleus (1.3.2)
fortinj1354 added a comment to T4312: Telegraf configuration doesn't accept IPs for URL.

After some testing in regex101, it seems like a good replacement regex would be ^(http:\/\/|https:\/\/)?[a-z0-9]+(?:[\-\.]{1}[a-z0-9]+)*(\/.*)?$ but I'm not well versed enough to build an image off of my own branch to test that, and I can't figure out how to modify the installed version to use the new regex to test.

Mar 22 2022, 3:24 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
fortinj1354 created T4312: Telegraf configuration doesn't accept IPs for URL.
Mar 22 2022, 3:00 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)

Mar 21 2022

dmbaturin edited projects for T4311: CVE-2021-4034: local privilege escalation in PolKit, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus (1.3.0).
Mar 21 2022, 7:18 PM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin closed T4311: CVE-2021-4034: local privilege escalation in PolKit as Resolved.
Mar 21 2022, 7:17 PM · VyOS 1.3 Equuleus ( 1.3.1)
c-po added a comment to T4308: Op-comm "Show log frr" to view specific protocol logs.

I very much like this idea.

Mar 21 2022, 6:41 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
dmbaturin created T4311: CVE-2021-4034: local privilege escalation in PolKit.
Mar 21 2022, 12:16 PM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin closed T4310: CVE-2022-0778: infinite loop in OpenSSL certificate parsing as Resolved.
Mar 21 2022, 12:12 PM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin renamed T4310: CVE-2022-0778: infinite loop in OpenSSL certificate parsing from CVE-2022-0778 to CVE-2022-0778: infinite loop in OpenSSL certificate parsing.
Mar 21 2022, 12:06 PM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin created T4310: CVE-2022-0778: infinite loop in OpenSSL certificate parsing.
Mar 21 2022, 12:06 PM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin changed Issue type from unspecified to bug on T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.
Mar 21 2022, 11:58 AM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin changed Issue type from unspecified to bug on T4234: Show firewall partly broken in 1.3.x.
Mar 21 2022, 11:57 AM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin renamed T4168: IPsec VPN is impossible to restart when DMVPN is configured from Does not possible to reset VPN properly when DMVPN configured to IPsec VPN is impossible to restart when DMVPN is configured.
Mar 21 2022, 11:56 AM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin renamed T4165: Custom conntrack rules cannot be deleted from Delete custom conntrack timeout firewall bug to Custom conntrack rules cannot be deleted.
Mar 21 2022, 11:55 AM · VyOS 1.3 Equuleus ( 1.3.1)
fernando closed T4304: [OSPF]import/export filter inter-area prefix as Resolved.
# applied filter on area-ospf
Mar 21 2022, 11:48 AM · VyOS 1.4 Sagitta
daniil created T4309: Support network/address-groups and ipv6-network/ipv6-address-groups in "conntrack ignore".
Mar 21 2022, 10:26 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
dmbaturin changed Why the issue appeared? from none to implementation-mistake on T4152: NHRP shortcut-target holding-time does not work.
Mar 21 2022, 8:11 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin changed Why the issue appeared? from none to implementation-mistake on T4142: Input ifbX interfaces not displayed in op-mode.
Mar 21 2022, 8:10 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin changed Issue type from unspecified to bug on T4081: VRRP health-check script stops working when setting up a sync group.
Mar 21 2022, 8:09 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin renamed T3914: VRRP rfc3768-compatibility doesn't work with unicast peers from vrrp rfc3768-compatibility doesn't work with unicast peers to VRRP rfc3768-compatibility doesn't work with unicast peers.
Mar 21 2022, 8:08 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin changed Issue type from unspecified to feature on T3872: Add configurable telegraf monitoring service.
Mar 21 2022, 8:08 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin renamed T3299: Allow the web proxy service to listen on all IP addresses from Webproxy is prohibited from listening on all IP addresses to Allow the web proxy service to listen on all IP addresses.
Mar 21 2022, 8:07 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin set Issue type to improvement on T3299: Allow the web proxy service to listen on all IP addresses.
Mar 21 2022, 8:06 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Mar 20 2022

SrividyaA created T4308: Op-comm "Show log frr" to view specific protocol logs.
Mar 20 2022, 3:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
n.fort closed T4298: vyos-vm-images: fix ansible group name and remove obsolete empty command as Resolved.
Mar 20 2022, 1:18 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4298: vyos-vm-images: fix ansible group name and remove obsolete empty command.

Ok, thanks for the clarification.
I'm closing this task and marking it as resolved.

Mar 20 2022, 1:17 PM · VyOS 1.4 Sagitta

Mar 19 2022

fernando added a comment to T4163: [BMP-BGP] Routing monitoring feature.

I've been testing , now we are able to configure BMP with load configuration .in latest version 8.2.2(they solved these issues)

Mar 19 2022, 7:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
hakwerk added a comment to T4298: vyos-vm-images: fix ansible group name and remove obsolete empty command.

Yes it is, although PR https://github.com/vyos/vyos-vm-images/pull/25 then caused some new issues but I just now reported those in T4278

Mar 19 2022, 12:26 PM · VyOS 1.4 Sagitta
hakwerk added a comment to T4278: vyos-vm-images: fix vagrant libvirt box.

@higebu it looks like PR https://github.com/vyos/vyos-vm-images/pull/25 caused some new issues (I use the qemu.yaml build). First:

fatal: [localhost]: FAILED! => {"changed": false, "msg": "AnsibleUndefinedVariable: 'enable_dhcp' is undefined"}

I propose to use this in the template (same for enable_ssh):

{% if enable_dhcp | default(True) %}

Or alternatively define those variables in all playbooks.

Mar 19 2022, 12:25 PM · Restricted Project, VyOS 1.4 Sagitta

Mar 18 2022

danielpo added a comment to T4239: static-host-mapping only working on ipv4 addresses.

Sure, but its not being applied in the pdns recursor so I cant use static host mapping for ipv6 in my network, only locally on the vyos host. (It works fine with ipv4).

Mar 18 2022, 8:58 PM · VyOS 1.4 Sagitta
n.fort closed T4286: Fix for firewall ipv6 name address validator as Resolved.
Mar 18 2022, 6:32 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4298: vyos-vm-images: fix ansible group name and remove obsolete empty command.

@hakwerk . Is this solved in PR https://github.com/vyos/vyos-vm-images/pull/24 ??

Mar 18 2022, 6:31 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4299: Firewall - GeoIP filtering.

Splitting ipv4 files, and just adding what needed. In my case, I extracted content from geoip-ipv4.nft and create and include file geoip-CA-ipv4.nft (Canada IPs)

Mar 18 2022, 6:20 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4299: Firewall - GeoIP filtering.

Perhaps only in-use sets can be determined and loaded?

Mar 18 2022, 5:36 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4299: Firewall - GeoIP filtering.

After some custom build and POC, here's what I got:

  • Filtering works, as shown in this table:
Mar 18 2022, 5:27 PM · VyOS 1.4 Sagitta
chesskuo added a comment to T4288: IPsec tunnel will break when ESP timeout.

@SrividyaA Thanks !!!!

Mar 18 2022, 2:15 PM · VyOS 1.4 Sagitta
SrividyaA closed T4307: Policy routing anymore, Commit generating errors as Invalid.
Mar 18 2022, 2:06 PM · VyOS 1.4 Sagitta
SrividyaA added a comment to T4288: IPsec tunnel will break when ESP timeout.

Submitted PR: https://github.com/vyos/vyos-1x/pull/1251

Mar 18 2022, 2:01 PM · VyOS 1.4 Sagitta
danielpo added a comment to T4307: Policy routing anymore, Commit generating errors.

Thanks, Not really sure what happened, but I deleted config.boot and rebooted, Now it works to add a policy again.

Mar 18 2022, 1:52 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4307: Policy routing anymore, Commit generating errors.

Error implies that firewall failed to configure on boot as mangle table is missing. Any logs/config trace from boot?

Mar 18 2022, 1:42 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4307: Policy routing anymore, Commit generating errors.

Can you share configuration that you are deleting? So far, I can't reproduce error

Mar 18 2022, 1:41 PM · VyOS 1.4 Sagitta
danielpo created T4307: Policy routing anymore, Commit generating errors.
Mar 18 2022, 12:45 PM · VyOS 1.4 Sagitta

Mar 17 2022

c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.184 / 5.10.105 to Update Linux Kernel to v5.4.185 / 5.10.106.
Mar 17 2022, 8:02 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dmbaturin triaged T4306: Do not check for ditry repository when building release images as Low priority.
Mar 17 2022, 6:33 PM · VyOS 1.3 Equuleus (1.3.4)
fernando added a comment to T4304: [OSPF]import/export filter inter-area prefix.

PR https://github.com/vyos/vyos-1x/pull/1250

Mar 17 2022, 5:45 PM · VyOS 1.4 Sagitta

Mar 16 2022

dberlin added a comment to T4305: Global log facility does not have consistent default settings, and doesn't change when modified.

My guess, looking now at commit logs, is that T4250 broke this. It looks like we attempted to move the settings to system logs, but the rsyslog part of the config still remains in system syslog, where the default does not match the new logrotate template (and the settings between rsyslog and logrotate can get out of sync).

Mar 16 2022, 9:33 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
fernando claimed T4304: [OSPF]import/export filter inter-area prefix.
Mar 16 2022, 8:35 PM · VyOS 1.4 Sagitta
dberlin updated the task description for T4305: Global log facility does not have consistent default settings, and doesn't change when modified.
Mar 16 2022, 7:59 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dberlin created T4305: Global log facility does not have consistent default settings, and doesn't change when modified.
Mar 16 2022, 7:57 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
fernando created T4304: [OSPF]import/export filter inter-area prefix.
Mar 16 2022, 7:56 PM · VyOS 1.4 Sagitta
SrividyaA claimed T4288: IPsec tunnel will break when ESP timeout.
Mar 16 2022, 7:11 PM · VyOS 1.4 Sagitta
erkin reopened T3644: Replace GCC with a simpler preprocessor for including nested XML snippets in XML documents as "On hold".

Note: Equuleus still uses the C preprocessor. // substrings (otherwise interpreted as comments) were escaped as \/\/ in op-mode-definitions/generate-public-key-command.xml.in in Equuleus and should be converted back eventually.

Mar 16 2022, 6:56 PM · VyOS 1.4 Sagitta (1.4.0-GA)