Page MenuHomeVyOS Platform
Feed Search

Jul 24 2022

Viacheslav committed rVYOSONEXa5580f2fc6f7: snmp: T2763: Add protocol TCP for service SNMP.
Jul 24 2022, 4:33 PM

Jul 23 2022

Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4145: Conntrack table not showing after firewall rewriting.
Jul 23 2022, 5:44 PM · VyOS Rolling
Viacheslav added a parent task for T4145: Conntrack table not showing after firewall rewriting: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:44 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4552: Unable to reset IPsec IPv6 peer.
Jul 23 2022, 5:41 PM · VyOS Rolling
Viacheslav added a parent task for T4552: Unable to reset IPsec IPv6 peer: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:41 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4543: Show source nat statistics shows incorrect interface.
Jul 23 2022, 5:40 PM · VyOS Rolling
Viacheslav added a parent task for T4543: Show source nat statistics shows incorrect interface: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:40 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4531: NAT op-mode errors with exclude rules.
Jul 23 2022, 5:39 PM · VyOS Rolling
Viacheslav added a parent task for T4531: NAT op-mode errors with exclude rules: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4545: Rewrite show nat source rules.
Jul 23 2022, 5:39 PM · VyOS Rolling
Viacheslav added a parent task for T4545: Rewrite show nat source rules: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4562: Rewrite show vrf to new format.
Jul 23 2022, 5:38 PM · VyOS Rolling
Viacheslav added a parent task for T4562: Rewrite show vrf to new format: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:38 PM · VyOS 1.4 Sagitta
Viacheslav created T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:38 PM · VyOS Rolling
Viacheslav added a comment to T4531: NAT op-mode errors with exclude rules.

It will be fixed in T4545
PR https://github.com/vyos/vyos-1x/pull/1426

Jul 23 2022, 5:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4562: Rewrite show vrf to new format.

PR https://github.com/vyos/vyos-1x/pull/1430

vyos@r14:~$ show vrf
Name    State    MAC address        Flags                     Interfaces
------  -------  -----------------  ------------------------  ---------------
foo     up       be:e3:5c:f1:54:99  noarp,master,up,lower_up  eth1.50,eth1.55
bar     up       1e:7c:94:da:e0:35  noarp,master,up,lower_up  n/a
vyos@r14:~$
Jul 23 2022, 1:57 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4562: Rewrite show vrf to new format from "Bug" to "Feature Request".
Jul 23 2022, 1:42 PM · VyOS 1.4 Sagitta
Viacheslav created T4562: Rewrite show vrf to new format.
Jul 23 2022, 1:42 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4552: Unable to reset IPsec IPv6 peer.

PR https://github.com/vyos/vyos-1x/pull/1428

vyos@r14:~$ reset vpn ipsec-peer 2001:db8::2 
CHILD_SA {21241} closed successfully
CHILD_SA {21243} closed successfully
CHILD_SA {21245} closed successfully
CHILD_SA {21244} closed successfully
CHILD_SA {21247} closed successfully
CHILD_SA {21246} closed successfully
CHILD_SA {21249} closed successfully
CHILD_SA {21248} closed successfully
closing CHILD_SA peer_2001-db8--2_tunnel_0{21250} with SPIs cab47d6b_i (0 bytes) c3cbba13_o (0 bytes) and TS 2001:db8:1111::/64 === 2001:db8:2222::/64
sending DELETE for ESP CHILD_SA with SPI cab47d6b
generating INFORMATIONAL request 14065 [ D ]
sending packet: from 2001:db8::1[500] to 2001:db8::2[500] (69 bytes)
received packet: from 2001:db8::2[500] to 2001:db8::1[500] (69 bytes)
parsed INFORMATIONAL response 14065 [ D ]
received DELETE for ESP CHILD_SA with SPI c3cbba13
CHILD_SA closed
CHILD_SA {21250} closed successfully
establishing CHILD_SA peer_2001-db8--2_tunnel_0{21251}
generating CREATE_CHILD_SA request 14066 [ SA No KE TSi TSr ]
sending packet: from 2001:db8::1[500] to 2001:db8::2[500] (497 bytes)
received packet: from 2001:db8::2[500] to 2001:db8::1[500] (497 bytes)
parsed CREATE_CHILD_SA response 14066 [ SA No KE TSi TSr ]
selected proposal: ESP:AES_GCM_16_256/MODP_2048/NO_EXT_SEQ
CHILD_SA peer_2001-db8--2_tunnel_0{21251} established with SPIs ccaff1e5_i c5a2b674_o and TS 2001:db8:1111::/64 === 2001:db8:2222::/64
connection 'peer_2001-db8--2_tunnel_0' established successfully
Peer reset result: success
vyos@r14:~$
Jul 23 2022, 8:50 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4552: Unable to reset IPsec IPv6 peer from Open to In progress.
Jul 23 2022, 7:56 AM · VyOS 1.4 Sagitta

Jul 22 2022

Viacheslav changed the status of T4546: Does not connect Cisco spoke to VyOS hub. from In progress to Needs testing.
Jul 22 2022, 11:15 PM · VyOS 1.4 Sagitta
Viacheslav closed T4145: Conntrack table not showing after firewall rewriting as Resolved.
Jul 22 2022, 7:30 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX4dc5d78eed41: conntrack: T4145: Modify conntrack to format command runner.
Jul 22 2022, 7:20 PM
Viacheslav added a comment to T4545: Rewrite show nat source rules.

PR https://github.com/vyos/vyos-1x/pull/1426
An example with only one rule 10 raw output

vyos@r14:~$ /usr/libexec/vyos/op_mode/nat.py show_rules --direction source --raw
[
    {
        "rule": {
            "family": "ip",
            "table": "nat",
            "chain": "POSTROUTING",
            "handle": 114,
            "comment": "SRC-NAT-10",
            "expr": [
                {
                    "match": {
                        "op": "==",
                        "left": {
                            "meta": {
                                "key": "oifname"
                            }
                        },
                        "right": "eth0"
                    }
                },
                {
                    "counter": {
                        "packets": 0,
                        "bytes": 0
                    }
                },
                {
                    "masquerade": null
                }
            ]
        }
    }
]
vyos@r14:~$
Jul 22 2022, 4:37 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6: VyOS 1.4 Sagitta.
Jul 22 2022, 1:01 PM · VyOS Rolling
Viacheslav added a comment to T4145: Conntrack table not showing after firewall rewriting.

PR to new format + IPv6 entries https://github.com/vyos/vyos-1x/pull/1425

Jul 22 2022, 12:35 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6.

@aalmenar try the next command

vyos@r14# run reset bgp ipv6 
Possible completions:
  <h:h:h:h:h:h:h:h>
                IPv6 neighbor to clear
  1-4294967295  Reset peers with the AS number
  all           Clear all peers
  external      Reset all external peers
  peer-group    Reset all members of peer-group
Jul 22 2022, 8:20 AM · VyOS Rolling
Viacheslav created T4560: VRF and BGP neighbor local-as error.
Jul 22 2022, 7:46 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4550: router-advert: Add deprecate-prefix & decrement-lifetimes options from Open to In progress.
Jul 22 2022, 1:09 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4556: fastnetmon: Allow configure white_list_path and populate with hosts/networks that should be ignored. from "Task" to "Feature Request".
Jul 22 2022, 12:58 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4558: Incomplete error message when duplicate firewall port-group used.

I just leave it here. We must not return to bug T2189 with this fix.

Jul 22 2022, 12:57 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T4557: fastnetmon: allow configure limits per protocol (tcp, udp, icmp): VyOS 1.4 Sagitta.
Jul 22 2022, 12:51 AM · VyOS 1.4 Sagitta

Jul 21 2022

Viacheslav added a comment to T4553: Allow to set ban time on ddos-protection configuration.

As I remember fastnetmon wasn’t rewritten to dict
And requires manual set default value in config dictionary

Jul 21 2022, 6:06 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4552: Unable to reset IPsec IPv6 peer.
Jul 21 2022, 10:58 AM · VyOS 1.4 Sagitta
Viacheslav created T4552: Unable to reset IPsec IPv6 peer.
Jul 21 2022, 10:56 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4551: IPsec rekeying collisions bug.
Jul 21 2022, 10:43 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4551: IPsec rekeying collisions bug.
Jul 21 2022, 10:40 AM · VyOS 1.4 Sagitta
Viacheslav created T4551: IPsec rekeying collisions bug.
Jul 21 2022, 10:22 AM · VyOS 1.4 Sagitta

Jul 20 2022

Viacheslav moved T4475: route-map does not support ipv6 peer from Open to Finished on the VyOS 1.4 Sagitta board.
Jul 20 2022, 4:32 PM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav added a comment to T4056: Traffic policy not set in live configuration.

@daniil Could you re-check it?

Jul 20 2022, 3:44 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav added a comment to T4537: MACsec not working with cipher gcm-aes-256.

It seems wpa_supplicant doesn't support GCM-AES-256
https://w1.fi/wpa_supplicant/devel/dir_4261af1259721e3e39e0d2dd7354b511.html

Jul 20 2022, 3:31 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4545: Rewrite show nat source rules.

PR https://github.com/vyos/vyos-1x/pull/1420

Jul 20 2022, 1:04 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets.
Jul 20 2022, 11:46 AM · VyOS 1.4 Sagitta
Viacheslav created T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets.
Jul 20 2022, 11:42 AM · VyOS 1.4 Sagitta

Jul 19 2022

Viacheslav claimed T4545: Rewrite show nat source rules.
Jul 19 2022, 5:04 PM · VyOS 1.4 Sagitta
Viacheslav created T4545: Rewrite show nat source rules.
Jul 19 2022, 5:04 PM · VyOS 1.4 Sagitta
Viacheslav created T4543: Show source nat statistics shows incorrect interface.
Jul 19 2022, 12:07 PM · VyOS 1.4 Sagitta

Jul 18 2022

Viacheslav added a comment to T4537: MACsec not working with cipher gcm-aes-256.

Also, there are no any Inbound/Outbound packets with aes-256

vyos@r14:~$ sudo ip -s macsec show
7: macsec1: protect on validate strict sc off sa off encrypt off send_sci on end_station off scb off replay off 
    cipher suite: GCM-AES-256, using ICV length 16
    TXSC: eeb5e212f04f0001 on SA 0
    stats: OutPktsUntagged InPktsUntagged OutPktsTooLong InPktsNoTag InPktsBadTag InPktsUnknownSCI InPktsNoSCI InPktsOverrun
                         0              0              0           0            0                0           0             0
    stats: OutPktsProtected OutPktsEncrypted OutOctetsProtected OutOctetsEncrypted
                          0                0                  0                  0
    offload: off 
vyos@r14:~$

But service starts without issues:

vyos@r14:~$ sudo systemctl status wpa_supplicant-macsec@vxlan1.service
● wpa_supplicant-macsec@vxlan1.service - WPA supplicant daemon (macsec-specific version)
     Loaded: loaded (/lib/systemd/system/wpa_supplicant-macsec@.service; disabled; vendor preset: enabled)
     Active: active (running) since Mon 2022-07-18 20:07:16 EEST; 18min ago
   Main PID: 1802 (wpa_supplicant)
      Tasks: 1 (limit: 9411)
     Memory: 4.4M
        CPU: 101ms
     CGroup: /system.slice/system-wpa_supplicant\x2dmacsec.slice/wpa_supplicant-macsec@vxlan1.service
             └─1802 /sbin/wpa_supplicant -c/run/wpa_supplicant/vxlan1.conf -Dmacsec_linux -ivxlan1
Jul 18 2022, 5:42 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX7094674f13d8: smoketest: T4532: Fix for smoketest flow-accounting.
Jul 18 2022, 11:01 AM
Viacheslav closed T4523: OP-mode Extend conntrack output to get marks, zones and directions as Resolved.
Jul 18 2022, 8:54 AM · VyOS 1.4 Sagitta
Viacheslav closed T4371: Copy contribution guideline from vyos-1x as Resolved.

Done https://github.com/vyos/vyos-vm-images/commit/bafe06bbbf4d67a98c78c01f1cef379eb6d13fa1

Jul 18 2022, 8:48 AM · Restricted Project
Viacheslav added a comment to T4533: Radius clients don’t have simple permissions.

It is operator level, that shouldn’t have permission for configurations. Only basic diagnostics (op-mode)

Jul 18 2022, 6:53 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX51f3c432a766: conntrack: T4523: Extend conntrack output direciton, mark, zone.
Jul 18 2022, 6:11 AM

Jul 17 2022

Viacheslav moved T3435: NAT rules show corruption from Finished to Open on the VyOS 1.4 Sagitta board.
Jul 17 2022, 8:51 AM · VyOS 1.4 Sagitta
Viacheslav reopened T3435: NAT rules show corruption as "Needs testing".
Jul 17 2022, 8:50 AM · VyOS 1.4 Sagitta
Viacheslav closed T3435: NAT rules show corruption as Resolved.
Jul 17 2022, 8:28 AM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX08b1cdd5b686: op-mode: T3435: Fix SNAT any address and DNAT port dict check.
Jul 17 2022, 8:24 AM
Viacheslav added a comment to T3435: NAT rules show corruption.

PR https://github.com/vyos/vyos-1x/pull/1417

Jul 17 2022, 8:21 AM · VyOS 1.4 Sagitta
Viacheslav closed T4028: FRR 8.1 routes not being applied to routing table after reboot if an interface has 2 ip addresses as Resolved.
Jul 17 2022, 6:52 AM · VyOS 1.4 Sagitta

Jul 15 2022

Viacheslav added a comment to T4530: Need MTU warning when CCP is on.

@a.apostoliuk Could you specify how to reproduce this bug?
Some CLI config examples and/or some pings that indicate the issue.

Jul 15 2022, 5:30 PM · VyOS Rolling
Viacheslav edited projects for T2763: New SNMP resource request - SNMP over TCP, added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus (1.3.0).

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1416

Jul 15 2022, 5:14 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4532: Flow-accounting IPv6 server/receiver bug.

Fix smoketest for 1.3 https://github.com/vyos/vyos-1x/pull/1415

Jul 15 2022, 2:36 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav committed rVYOSONEX2b46250616f6: smoketest: T4532: Update smoketest flow-accounting.
Jul 15 2022, 2:16 PM
Viacheslav committed rVYOSONEX1bee7e62b665: netflow: T4532: replace dot and colons to dash.
Jul 15 2022, 2:16 PM
Viacheslav added a comment to T4532: Flow-accounting IPv6 server/receiver bug.

PR for 1.4 https://github.com/vyos/vyos-1x/pull/1414

Jul 15 2022, 1:28 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav added a comment to T4532: Flow-accounting IPv6 server/receiver bug.

Requires update smoketests

Jul 15 2022, 12:49 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav added a comment to T4028: FRR 8.1 routes not being applied to routing table after reboot if an interface has 2 ip addresses.

@diekos Is it working after reboot?

Jul 15 2022, 10:41 AM · VyOS 1.4 Sagitta

Jul 14 2022

Viacheslav renamed T4533: Radius clients don’t have simple permissions from Radius clients doesnt have simple permissions to Radius clients don’t have simple permissions.
Jul 14 2022, 6:46 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX9ec0b176311e: netflow: T4532: Fix flow-accounting server IPv6 bug.
Jul 14 2022, 5:24 PM
Viacheslav added a comment to T3901: Help values do not work for RADIUS authentication users.

It is different shells in 1.4 and 1.3 for this user config
In 1.3 it seems correct:

vyosuser@r1# echo $SHELL
/sbin/radius_shell
[edit]
vyosuser@r1#
Jul 14 2022, 4:27 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a project to T4533: Radius clients don’t have simple permissions: VyOS 1.4 Sagitta.
Jul 14 2022, 3:38 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav assigned T4533: Radius clients don’t have simple permissions to c-po.
Jul 14 2022, 3:35 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav created T4533: Radius clients don’t have simple permissions.
Jul 14 2022, 3:34 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4532: Flow-accounting IPv6 server/receiver bug.

PR https://github.com/vyos/vyos-1x/pull/1412

Jul 14 2022, 1:49 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav claimed T4532: Flow-accounting IPv6 server/receiver bug.
Jul 14 2022, 1:33 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav updated the task description for T4532: Flow-accounting IPv6 server/receiver bug.
Jul 14 2022, 12:58 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav renamed T4532: Flow-accounting IPv6 server/receiver bug from Flow-accounting ipv6 server/receiver bug to Flow-accounting IPv6 server/receiver bug.
Jul 14 2022, 12:56 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav updated the task description for T4532: Flow-accounting IPv6 server/receiver bug.
Jul 14 2022, 12:55 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav changed the status of T4532: Flow-accounting IPv6 server/receiver bug from Open to In progress.
Jul 14 2022, 12:54 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav edited projects for T4532: Flow-accounting IPv6 server/receiver bug, added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus.
Jul 14 2022, 12:54 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav created T4532: Flow-accounting IPv6 server/receiver bug.
Jul 14 2022, 12:54 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav created T4531: NAT op-mode errors with exclude rules.
Jul 14 2022, 9:38 AM · VyOS 1.4 Sagitta

Jul 13 2022

Viacheslav added a comment to T3584: Migrate NTP server addresses from *.pool.ntp.org to our own.

If I want to use also x.pool.ntp.org how should I use it if it will migrate anything from x.pool.ntp.org?

Jul 13 2022, 3:32 PM · VyOS 1.3 Equuleus (1.3.7)
Viacheslav closed T1375: Add clear dhcp server lease function as Resolved.
Jul 13 2022, 2:52 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav changed the status of T3714: Some sysctl custom parameters disappear after reboot from Open to In progress.
Jul 13 2022, 2:49 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav edited projects for T3714: Some sysctl custom parameters disappear after reboot, added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus (1.3.0).
Jul 13 2022, 2:26 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav added a comment to T3714: Some sysctl custom parameters disappear after reboot.

PR https://github.com/vyos/vyatta-cfg-system/pull/182

Jul 13 2022, 2:25 PM · VyOS 1.3 Equuleus (1.3.2)

Jul 12 2022

Viacheslav closed T3864: Add Edgecore build to VyOS 1.3 Equuleus as Resolved.
Jul 12 2022, 7:30 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav moved T4084: Dehardcode the default login banner from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0) board.
Jul 12 2022, 7:27 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T4084: Dehardcode the default login banner as Resolved.
Jul 12 2022, 7:27 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the status of T4113: Incorrect GRUB configuration parsing from In progress to Needs testing.
Jul 12 2022, 7:25 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav closed T4527: Prevent to create VRF name default as Resolved.
Jul 12 2022, 5:14 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX70f42e308a6d: vrf: T4527: Prevent to create VRF with reserved names.
Jul 12 2022, 5:12 PM
Viacheslav added a comment to T260: Redirect traffict between two L3 interfaces.

I only see one solution - exclude mirror node from interface and add it as a separate option/service

set service redirect|port-mirror <x> source tunX 
set service redirect|port-mirror <x> destination tunY

As tc filter applied for every interface step by step and in this case (adding tun0) we don't have tun1 yet

Jul 12 2022, 4:40 PM
Viacheslav added a comment to T260: Redirect traffict between two L3 interfaces.

To reproduce:

Jul 12 2022, 4:10 PM
Viacheslav moved T4527: Prevent to create VRF name default from Open to Finished on the VyOS 1.4 Sagitta board.
Jul 12 2022, 3:31 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4527: Prevent to create VRF name default.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1410

Jul 12 2022, 3:31 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX52342f389af2: vrf: T4527: Prevent to create VRF with reserved names.
Jul 12 2022, 3:05 PM
Viacheslav closed T235: Ability to configure manual IP Rules as Resolved.
Jul 12 2022, 2:47 PM · VyOS 1.4 Sagitta
Viacheslav closed T3948: IPSec VPN: Add a new option "none" for the connection-type as Resolved.
Jul 12 2022, 2:24 PM · VyOS 1.4 Sagitta