Page MenuHomeVyOS Platform
Feed All Stories

Jul 25 2022

GitHub <noreply@github.com> committed rVYOSONEX55d7ff854cfe: Merge pull request #1434 from aalmenar/T4556 (authored by c-po).
Jul 25 2022, 5:36 PM
jestabro added a comment to T4554: Implement GraphQL resolvers for standardized op-mode scripts.

https://github.com/vyos/vyos-1x/pull/1432

Jul 25 2022, 3:24 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4544: Generate schema definitions from standardized op-mode scripts.

https://github.com/vyos/vyos-1x/pull/1432

Jul 25 2022, 3:24 PM · VyOS 1.4 Sagitta
jestabro closed T4567: Merge experimental branch of GraphQL development as Resolved.
Jul 25 2022, 3:11 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4556: fastnetmon: Allow configure white_list_path and populate with hosts/networks that should be ignored. from Open to In progress.
Jul 25 2022, 1:45 PM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEXdf7348da1116: Merge pull request #1426 from sever-sever/T4545-nat (authored by c-po).
Jul 25 2022, 1:27 PM
Viacheslav committed rVYOSONEX9228bd31d008: nat: T4545: Rewrite show nat source rules script.
Jul 25 2022, 1:27 PM
Viacheslav committed rVYOSONEX179380776360: IPsec: T4552: Fix reset vpn ipsec peer.
Jul 25 2022, 1:27 PM
GitHub <noreply@github.com> committed rVYOSONEXc8ffb9a03c70: Merge pull request #1428 from sever-sever/T4552 (authored by c-po).
Jul 25 2022, 1:27 PM
Viacheslav committed rVYOSONEX4caffa16a076: vrf: T4562: Rewrite show vrf to vyos.opmode format.
Jul 25 2022, 1:26 PM
GitHub <noreply@github.com> committed rVYOSONEXfd4bda3c791a: Merge pull request #1430 from sever-sever/T4562 (authored by c-po).
Jul 25 2022, 1:26 PM
Viacheslav created T4569: Rewrite show bridge to new format.
Jul 25 2022, 1:07 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4568: show vpn debug peer doesn't work.

PR https://github.com/vyos/vyos-1x/pull/1433

Jul 25 2022, 12:55 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4568: show vpn debug peer doesn't work from Open to In progress.
Jul 25 2022, 12:00 PM · VyOS 1.4 Sagitta
Viacheslav created T4568: show vpn debug peer doesn't work.
Jul 25 2022, 11:55 AM · VyOS 1.4 Sagitta
n.fort added a comment to T4497: ping cannot force ipv4 or ipv6.

Agree that both options are not available in cli.. But, you can use source-address:

Jul 25 2022, 11:37 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4474: Adding more than 1 prefix-list is ignored.

I can't reproduce it (VyOS 1.4-rolling-202207220217):

set policy prefix-list BARRA32 rule 5 action 'permit'
set policy prefix-list BARRA32 rule 5 ge '32'
set policy prefix-list BARRA32 rule 5 le '32'
set policy prefix-list BARRA32 rule 5 prefix '0.0.0.0/0'
set policy prefix-list UTRSv4s25 rule 5 action 'permit'
set policy prefix-list UTRSv4s25 rule 5 le '25'
set policy prefix-list UTRSv4s25 rule 5 prefix '0.0.0.0/0'
set policy prefix-list6 BARRA128 rule 5 action 'permit'
set policy prefix-list6 BARRA128 rule 5 ge '128'
set policy prefix-list6 BARRA128 rule 5 le '128'
set policy prefix-list6 BARRA128 rule 5 prefix '::/0'
set policy prefix-list6 UTRSv6s49 rule 5 action 'permit'
set policy prefix-list6 UTRSv6s49 rule 5 le '49'
set policy prefix-list6 UTRSv6s49 rule 5 prefix '::/0'
Jul 25 2022, 10:40 AM
Viacheslav closed T1233: ipsec vpn sa showing down, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jul 25 2022, 9:42 AM · VyOS 1.4 Sagitta
Viacheslav closed T1233: ipsec vpn sa showing down as Resolved.

Fixed in https://github.com/vyos/vyos-1x/commit/201257fe60afc40d101d162cc08e2878dfa3467b

Jul 25 2022, 9:42 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T3496: show conntrack-sync statistics shows a warning.
Jul 25 2022, 9:40 AM · VyOS Rolling
Viacheslav added a parent task for T3496: show conntrack-sync statistics shows a warning: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 25 2022, 9:40 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3723: op-mode IPSec show vpn ipsec sa output with underscores.

Will be fixed with syntax migration in T4118

Jul 25 2022, 9:38 AM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX8e6f4ee3a95f: graphql: T3993: use existing key auth from REST framework.
Jul 25 2022, 9:34 AM
jestabro committed rVYOSONEXb882e997e18c: graphql: T3993: disable introspection unless set in CLI.
Jul 25 2022, 9:34 AM
jestabro committed rVYOSONEX02beb3ead378: graphql: T3993: add interface-definition for gql.
Jul 25 2022, 9:34 AM
jestabro committed rVYOSONEXf9bd803ffe8a: graphql: T4413: add support for a system status query.
Jul 25 2022, 9:34 AM
jestabro committed rVYOSONEX40d754b44d95: graphql: T4413: update 'SystemStatus' query for standardized op-mode.
Jul 25 2022, 9:34 AM
jestabro committed rVYOSONEXf9d6f0890140: graphql: T3993: add smoketest for GraphQL key authorization.
Jul 25 2022, 9:34 AM
GitHub <noreply@github.com> committed rVYOSONEX3337aedd5f7f: Merge pull request #1431 from jestabro/gql-dev (authored by dmbaturin).
Jul 25 2022, 9:34 AM
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T3937: Rewrite "show system memory" in Python to make it usable as a library function.
Jul 25 2022, 9:33 AM · VyOS Rolling
Viacheslav added a parent task for T3937: Rewrite "show system memory" in Python to make it usable as a library function: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 25 2022, 9:33 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4271: bgp: show ipv6 bgp summary doesn't display neighbor information.

@NikolayP Try the next command:

Jul 25 2022, 9:32 AM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav closed T4493: Incorrect help for "show bgp neighbors" as Resolved.
Jul 25 2022, 9:01 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets.
Jul 25 2022, 8:56 AM · VyOS Rolling
Viacheslav added a parent task for T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 25 2022, 8:56 AM · VyOS 1.4 Sagitta

Jul 24 2022

jestabro created T4567: Merge experimental branch of GraphQL development.
Jul 24 2022, 7:46 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXa5580f2fc6f7: snmp: T2763: Add protocol TCP for service SNMP.
Jul 24 2022, 4:33 PM
GitHub <noreply@github.com> committed rVYOSONEX4168e03721b2: Merge pull request #1416 from sever-sever/T2763-eq (authored by dmbaturin).
Jul 24 2022, 4:33 PM
alainlamar updated the task description for T4566: Cannot log in on serial console on Equuleus v1.3.1.
Jul 24 2022, 5:52 AM · VyOS 1.3 Equuleus (1.3.6)
alainlamar updated the task description for T4566: Cannot log in on serial console on Equuleus v1.3.1.
Jul 24 2022, 5:50 AM · VyOS 1.3 Equuleus (1.3.6)
alainlamar created T4566: Cannot log in on serial console on Equuleus v1.3.1.
Jul 24 2022, 5:48 AM · VyOS 1.3 Equuleus (1.3.6)

Jul 23 2022

sajiby3k created T4565: vlan aware bridge not working .
Jul 23 2022, 7:44 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.2)
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4145: Conntrack table not showing after firewall rewriting.
Jul 23 2022, 5:44 PM · VyOS Rolling
Viacheslav added a parent task for T4145: Conntrack table not showing after firewall rewriting: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:44 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4552: Unable to reset IPsec IPv6 peer.
Jul 23 2022, 5:41 PM · VyOS Rolling
Viacheslav added a parent task for T4552: Unable to reset IPsec IPv6 peer: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:41 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4543: Show source nat statistics shows incorrect interface.
Jul 23 2022, 5:40 PM · VyOS Rolling
Viacheslav added a parent task for T4543: Show source nat statistics shows incorrect interface: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:40 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4531: NAT op-mode errors with exclude rules.
Jul 23 2022, 5:39 PM · VyOS Rolling
Viacheslav added a parent task for T4531: NAT op-mode errors with exclude rules: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4545: Rewrite show nat source rules.
Jul 23 2022, 5:39 PM · VyOS Rolling
Viacheslav added a parent task for T4545: Rewrite show nat source rules: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4562: Rewrite show vrf to new format.
Jul 23 2022, 5:38 PM · VyOS Rolling
Viacheslav added a parent task for T4562: Rewrite show vrf to new format: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:38 PM · VyOS 1.4 Sagitta
Viacheslav created T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:38 PM · VyOS Rolling
Viacheslav added a comment to T4531: NAT op-mode errors with exclude rules.

It will be fixed in T4545
PR https://github.com/vyos/vyos-1x/pull/1426

Jul 23 2022, 5:28 PM · VyOS 1.4 Sagitta
alainlamar updated the task description for T4563: Docker build system is broken (Equuleus v1.3.1).
Jul 23 2022, 2:10 PM · VyOS 1.3 Equuleus (1.3.6)
alainlamar created T4563: Docker build system is broken (Equuleus v1.3.1).
Jul 23 2022, 1:59 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T4562: Rewrite show vrf to new format.

PR https://github.com/vyos/vyos-1x/pull/1430

vyos@r14:~$ show vrf
Name    State    MAC address        Flags                     Interfaces
------  -------  -----------------  ------------------------  ---------------
foo     up       be:e3:5c:f1:54:99  noarp,master,up,lower_up  eth1.50,eth1.55
bar     up       1e:7c:94:da:e0:35  noarp,master,up,lower_up  n/a
vyos@r14:~$
Jul 23 2022, 1:57 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4562: Rewrite show vrf to new format from "Bug" to "Feature Request".
Jul 23 2022, 1:42 PM · VyOS 1.4 Sagitta
Viacheslav created T4562: Rewrite show vrf to new format.
Jul 23 2022, 1:42 PM · VyOS 1.4 Sagitta
goodNETnick <pknet@ya.ru> committed rVYOSONEXdbadbbf6453d: route-map: T4542: match prefix-len Kernel notice.
Jul 23 2022, 10:14 AM
GitHub <noreply@github.com> committed rVYOSONEXe1e9f690d3eb: Merge pull request #1427 from goodNETnick/rm-pref-len (authored by c-po).
Jul 23 2022, 10:14 AM
Unknown Object (User) added a comment to T4542: route-map: "match prefix-len" incorrect behavior.

New PR (Notice corrected):
https://github.com/vyos/vyos-1x/pull/1427

Jul 23 2022, 9:38 AM · VyOS 1.4 Sagitta
aalmenar added a comment to T4556: fastnetmon: Allow configure white_list_path and populate with hosts/networks that should be ignored..

I have added a pull request for this:

Jul 23 2022, 9:24 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4552: Unable to reset IPsec IPv6 peer.

PR https://github.com/vyos/vyos-1x/pull/1428

vyos@r14:~$ reset vpn ipsec-peer 2001:db8::2 
CHILD_SA {21241} closed successfully
CHILD_SA {21243} closed successfully
CHILD_SA {21245} closed successfully
CHILD_SA {21244} closed successfully
CHILD_SA {21247} closed successfully
CHILD_SA {21246} closed successfully
CHILD_SA {21249} closed successfully
CHILD_SA {21248} closed successfully
closing CHILD_SA peer_2001-db8--2_tunnel_0{21250} with SPIs cab47d6b_i (0 bytes) c3cbba13_o (0 bytes) and TS 2001:db8:1111::/64 === 2001:db8:2222::/64
sending DELETE for ESP CHILD_SA with SPI cab47d6b
generating INFORMATIONAL request 14065 [ D ]
sending packet: from 2001:db8::1[500] to 2001:db8::2[500] (69 bytes)
received packet: from 2001:db8::2[500] to 2001:db8::1[500] (69 bytes)
parsed INFORMATIONAL response 14065 [ D ]
received DELETE for ESP CHILD_SA with SPI c3cbba13
CHILD_SA closed
CHILD_SA {21250} closed successfully
establishing CHILD_SA peer_2001-db8--2_tunnel_0{21251}
generating CREATE_CHILD_SA request 14066 [ SA No KE TSi TSr ]
sending packet: from 2001:db8::1[500] to 2001:db8::2[500] (497 bytes)
received packet: from 2001:db8::2[500] to 2001:db8::1[500] (497 bytes)
parsed CREATE_CHILD_SA response 14066 [ SA No KE TSi TSr ]
selected proposal: ESP:AES_GCM_16_256/MODP_2048/NO_EXT_SEQ
CHILD_SA peer_2001-db8--2_tunnel_0{21251} established with SPIs ccaff1e5_i c5a2b674_o and TS 2001:db8:1111::/64 === 2001:db8:2222::/64
connection 'peer_2001-db8--2_tunnel_0' established successfully
Peer reset result: success
vyos@r14:~$
Jul 23 2022, 8:50 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4552: Unable to reset IPsec IPv6 peer from Open to In progress.
Jul 23 2022, 7:56 AM · VyOS 1.4 Sagitta

Jul 22 2022

Viacheslav changed the status of T4546: Does not connect Cisco spoke to VyOS hub. from In progress to Needs testing.
Jul 22 2022, 11:15 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXbc70c1f502bc: macsec: T2023: fixup systemd unit description.
Jul 22 2022, 9:17 PM
c-po committed rVYOSONEX089c10282dcc: op-mode: monitor log help typo.
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEXe1cbb3a777e7: ssh: T3212: cleanup deprecated /etc/default/ssh file.
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEXcfe158844b95: op-mode: add show|monitor log ssh|snmp commands.
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEX8c7cd6f181a4: ssh: T3212: do not load systemd EnvironmentFile.
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEX58df49d71a9c: dns-forwarding: T2185: cleanup deprecated /etc/powerdns files - now living in….
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEX5df343e67f27: ntp: T2185: cleanup deprecated /etc/ntp.conf - now living in /run/ntpd.
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEX4c0cb7f30dc8: fastnetmon: T2659: also clean /etc/networks_whitelist.
Jul 22 2022, 9:16 PM
c-po added a comment to T4560: VRF and BGP neighbor local-as error.

Commit fails b/c of frr-reload output: 200 % Local-AS allowed only for EBGP peers - we should add an appropriate verify() stage I guess.

Jul 22 2022, 9:10 PM · VyOS 1.4 Sagitta
Viacheslav closed T4145: Conntrack table not showing after firewall rewriting as Resolved.
Jul 22 2022, 7:30 PM · VyOS 1.4 Sagitta
zsdc committed rVYOSONEXb639458bad07: nhrp: T4546: Fixed route add command if MTU presented.
Jul 22 2022, 7:26 PM
GitHub <noreply@github.com> committed rVYOSONEX929915b57382: Merge pull request #1418 from zdc/T4546-sagitta (authored by c-po).
Jul 22 2022, 7:26 PM
Viacheslav committed rVYOSONEX4dc5d78eed41: conntrack: T4145: Modify conntrack to format command runner.
Jul 22 2022, 7:20 PM
GitHub <noreply@github.com> committed rVYOSONEX875560ae8a84: Merge pull request #1425 from sever-sever/T4145 (authored by c-po).
Jul 22 2022, 7:20 PM
Viacheslav added a comment to T4545: Rewrite show nat source rules.

PR https://github.com/vyos/vyos-1x/pull/1426
An example with only one rule 10 raw output

vyos@r14:~$ /usr/libexec/vyos/op_mode/nat.py show_rules --direction source --raw
[
    {
        "rule": {
            "family": "ip",
            "table": "nat",
            "chain": "POSTROUTING",
            "handle": 114,
            "comment": "SRC-NAT-10",
            "expr": [
                {
                    "match": {
                        "op": "==",
                        "left": {
                            "meta": {
                                "key": "oifname"
                            }
                        },
                        "right": "eth0"
                    }
                },
                {
                    "counter": {
                        "packets": 0,
                        "bytes": 0
                    }
                },
                {
                    "masquerade": null
                }
            ]
        }
    }
]
vyos@r14:~$
Jul 22 2022, 4:37 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6: VyOS 1.4 Sagitta.
Jul 22 2022, 1:01 PM · VyOS Rolling
Viacheslav added a comment to T4145: Conntrack table not showing after firewall rewriting.

PR to new format + IPv6 entries https://github.com/vyos/vyos-1x/pull/1425

Jul 22 2022, 12:35 PM · VyOS 1.4 Sagitta
c-po added a comment to T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6.

Unfortunately not all commands are present when using the bgp <afi> syntax. We should find the remaining ones and then move all to the new syntax - less confusing

Jul 22 2022, 10:36 AM · VyOS Rolling
aalmenar added a comment to T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6.

@Viacheslav yep that one works...

Jul 22 2022, 8:22 AM · VyOS Rolling
Viacheslav added a comment to T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6.

@aalmenar try the next command

vyos@r14# run reset bgp ipv6 
Possible completions:
  <h:h:h:h:h:h:h:h>
                IPv6 neighbor to clear
  1-4294967295  Reset peers with the AS number
  all           Clear all peers
  external      Reset all external peers
  peer-group    Reset all members of peer-group
Jul 22 2022, 8:20 AM · VyOS Rolling
aalmenar changed Version from - to 1.4-rolling-202207220217 on T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6.
Jul 22 2022, 8:03 AM · VyOS Rolling
aalmenar updated the task description for T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6.
Jul 22 2022, 8:02 AM · VyOS Rolling
aalmenar updated the task description for T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6.
Jul 22 2022, 8:01 AM · VyOS Rolling
aalmenar created T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6.
Jul 22 2022, 7:59 AM · VyOS Rolling
c-po claimed T4560: VRF and BGP neighbor local-as error.
Jul 22 2022, 7:54 AM · VyOS 1.4 Sagitta
Viacheslav created T4560: VRF and BGP neighbor local-as error.
Jul 22 2022, 7:46 AM · VyOS 1.4 Sagitta
vfreex added a project to T4559: vyos-1x: xdp build error: VyOS 1.4 Sagitta.
Jul 22 2022, 7:21 AM · VyOS 1.4 Sagitta
vfreex triaged T4559: vyos-1x: xdp build error as Normal priority.
Jul 22 2022, 7:19 AM · VyOS 1.4 Sagitta
vfreex updated subscribers of T160: Support NAT64.

@aaliddell I am not too concerned about tayga's maintenance. It have been proved to work well for years, and the package is already a part of the official repository of debian. Actually debian's tayga package includes a few patches: https://salsa.debian.org/debian/tayga/-/tree/debian/master/debian/patches

Jul 22 2022, 7:01 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po committed rVYOSONEXbec3e9de40b5: smoketest: router-advert: T4550: test deprecate-prefix & decrement-lifetime CLI….
Jul 22 2022, 6:52 AM
c-po committed rVYOSONEX83d7aa2ff189: smoketest: router-advert: use setUpClass().
Jul 22 2022, 6:52 AM
vfreex committed rVYOSONEX3253864641e7: T4550: router-advert: Add deprecate-prefix & decrement-lifetimes options.
Jul 22 2022, 6:26 AM