Page MenuHomeVyOS Platform
Feed All Stories

Aug 6 2022

jack9603301 created T4599: run vyos in lxc/lxd.
Aug 6 2022, 5:57 PM
jack9603301 added a comment to T4598: nat66 - Add exclude options.

hi, you can set this to a subtask of my task

Aug 6 2022, 3:31 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4596: "show openconnect-server sessions" command does not work in the openconnect module.

PR https://github.com/vyos/vyos-1x/pull/1462

Aug 6 2022, 10:18 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4596: "show openconnect-server sessions" command does not work in the openconnect module, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 6 2022, 9:48 AM · VyOS Rolling
Viacheslav changed the status of T4596: "show openconnect-server sessions" command does not work in the openconnect module from Open to In progress.
Aug 6 2022, 9:48 AM · VyOS 1.4 Sagitta

Aug 5 2022

GitHub <noreply@github.com> committed rVYOSONEX1b637f78b870: Merge pull request #1460 from sever-sever/T4597 (authored by c-po).
Aug 5 2022, 6:30 PM
Viacheslav committed rVYOSONEXe3209859935e: ocserv: T4597: Check bind port before openconnect commit.
Aug 5 2022, 6:30 PM
Viacheslav updated subscribers of T4597: Check bind port before assign service HTTPS API and openconnect.
Aug 5 2022, 3:48 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4597: Check bind port before assign service HTTPS API and openconnect.

PR checks if openconnect port is listened by another service https://github.com/vyos/vyos-1x/pull/1460

Aug 5 2022, 3:47 PM · VyOS 1.4 Sagitta
n.fort changed the status of T4598: nat66 - Add exclude options from Open to In progress.
Aug 5 2022, 3:16 PM · VyOS 1.4 Sagitta
n.fort claimed T4598: nat66 - Add exclude options.
Aug 5 2022, 3:15 PM · VyOS 1.4 Sagitta
n.fort created T4598: nat66 - Add exclude options.
Aug 5 2022, 3:15 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4597: Check bind port before assign service HTTPS API and openconnect from Open to In progress.
Aug 5 2022, 2:26 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4589: BGP listen limit Increase via CLI command.

It is already present in 1.4

vyos@r14:~$ show conf com | match bgp
set protocols bgp listen limit '1000'
set protocols bgp listen range 192.0.2.0/24 peer-group 'FOO'
set protocols bgp local-as '65001'
set protocols bgp peer-group FOO remote-as '65001'
Aug 5 2022, 12:39 PM · VyOS 1.4 Sagitta (1.4.0-GA)
zsdc changed the status of T4589: BGP listen limit Increase via CLI command from Open to Confirmed.
Aug 5 2022, 12:16 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav created T4597: Check bind port before assign service HTTPS API and openconnect.
Aug 5 2022, 11:40 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4596: "show openconnect-server sessions" command does not work in the openconnect module.
Aug 5 2022, 10:43 AM · VyOS Rolling
Viacheslav added a parent task for T4596: "show openconnect-server sessions" command does not work in the openconnect module: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Aug 5 2022, 10:43 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4596: "show openconnect-server sessions" command does not work in the openconnect module.

It appeared after this commit
It doesn't like this check https://github.com/vyos/vyos-1x/blob/2a10ffa4b5074be27458159fa94d6227d0e5c7f7/src/op_mode/openconnect-control.py#L63-L65
Check root user https://github.com/vyos/vyos-1x/blob/2a10ffa4b5074be27458159fa94d6227d0e5c7f7/python/vyos/util.py#L625-L626

Aug 5 2022, 10:04 AM · VyOS 1.4 Sagitta
a.apostoliuk created T4596: "show openconnect-server sessions" command does not work in the openconnect module.
Aug 5 2022, 8:14 AM · VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX46173f284cd9: T2719: add an exception hierarchy for op mode errors.
Aug 5 2022, 7:31 AM
GitHub <noreply@github.com> committed rVYOSONEX2a10ffa4b507: Merge pull request #1459 from dmbaturin/genop-exn (authored by Viacheslav).
Aug 5 2022, 7:31 AM
a.apostoliuk created T4595: DPD interval and timeout do not work in DMVPN.
Aug 5 2022, 7:21 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXdfb4ce2a5aa4: bgp: T4257: bugfixes after renaming "local-as" to "system-as".
Aug 5 2022, 5:55 AM

Aug 4 2022

HON added a comment to T2408: DHCP Relay upstream and downstream interfaces.

Would it be an option to instead just add new listen-interface and upstream-interface statements, same as for dhcp-relay6? Then keep interface completely unchanged to avoid breaking weird usages, but add some deprecation notice to the CLI.

Aug 4 2022, 8:27 PM · VyOS 1.4 Sagitta
n.fort added a comment to T2408: DHCP Relay upstream and downstream interfaces.

Currently thinking on how to implement this.
One option could be:

Aug 4 2022, 8:11 PM · VyOS 1.4 Sagitta
n.fort added a project to T2408: DHCP Relay upstream and downstream interfaces: VyOS 1.4 Sagitta.
Aug 4 2022, 7:59 PM · VyOS 1.4 Sagitta
c-po closed T4257: Discussion on changing BGP autonomous system number syntax as Resolved.
Aug 4 2022, 7:27 PM · VyOS 1.4 Sagitta
Cheeze_It committed rVYOSONEX967c53e2f3e4: bgp: T4257: Changing BGP "local-as" to "system-as".
Aug 4 2022, 7:27 PM
c-po committed rVYOSONEX2dfd5a3c00b3: bgp: T4257: bugfixes after renaming "local-as" to "system-as".
Aug 4 2022, 7:27 PM
c-po committed rVYOSONEXde04107fbd01: Merge https://github.com/Cheeze-It/vyos-1x into current.
Aug 4 2022, 7:27 PM
c-po committed rVYOSONEXe19889adf8ce: smoketest: macsec: T4537: validate macsec_csindex for both AES-GCM-128 and AES….
Aug 4 2022, 6:55 PM
c-po committed rVYOSONEX0943ac00412b: macsec: T4537: macsec_csindex can be set even without encryption.
Aug 4 2022, 6:55 PM
Nova_Logic renamed T4587: wan load balance issues with 3 or more WANs from wan load balance issues with 3 WANs to wan load balance issues with 3 or more WANs.
Aug 4 2022, 6:55 PM · Bugs, VyOS Rolling
jack9603301 added a comment to T2898: Support NDP proxy.

@hensur You haven't dealt with this for a long time

Aug 4 2022, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4572: Add an option to force interface MTU to the value received from DHCP from Confirmed to Needs testing.
Aug 4 2022, 3:11 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX67583141f433: mtu: T4572: Add DHCP-option MTU to get values from DHCP-server.
Aug 4 2022, 2:41 PM
GitHub <noreply@github.com> committed rVYOSONEXc8ba6bc59d98: Merge pull request #1453 from sever-sever/T4572-eq (authored by dmbaturin).
Aug 4 2022, 2:41 PM
Viacheslav changed the status of T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS Rolling
Viacheslav changed the status of T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4594: Rewrite op-mode IPsec to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS Rolling
Viacheslav changed the status of T4594: Rewrite op-mode IPsec to vyos.opmode format from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4586: Add to NAT66: SNAT destination address and DNAT source address. from Open to Needs testing.
Aug 4 2022, 1:50 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX08699a10ccea: validators: T4586: Add IPv6 exclude validators for address/prefix.
Aug 4 2022, 1:50 PM
Viacheslav committed rVYOSONEXecc03bd6e499: nat66: T4586: Add SNAT destination prefix and DNAT address.
Aug 4 2022, 1:50 PM
GitHub <noreply@github.com> committed rVYOSONEX8af312ecac88: Merge pull request #1457 from sever-sever/T4586 (authored by c-po).
Aug 4 2022, 1:50 PM
Viacheslav added a comment to T4594: Rewrite op-mode IPsec to vyos.opmode format.

PR https://github.com/vyos/vyos-1x/pull/1458
Formatted output

vyos@r14:~$ show vpn ipsec sa
Connection                 State    Uptime    Bytes In/Out    Packets In/Out    Remote address    Remote ID    Proposal
-------------------------  -------  --------  --------------  ----------------  ----------------  -----------  ---------------------------------------
peer_2001-db8--2_tunnel_0  up       9m15s     0B/0B           0/0               2001:db8::2       2001:db8::2  AES_CBC_256/HMAC_SHA2_256_128/MODP_2048
peer_2001-db8--2_tunnel_0  up       24m9s     0B/0B           0/0               2001:db8::2       2001:db8::2  AES_CBC_256/HMAC_SHA2_256_128/MODP_2048
vyos@r14:~$
Aug 4 2022, 1:18 PM · VyOS 1.4 Sagitta
Viacheslav created T4594: Rewrite op-mode IPsec to vyos.opmode format.
Aug 4 2022, 10:11 AM · VyOS 1.4 Sagitta
ssasso added a comment to T4593: Upgrade strongswan to 5.9.8.

From the strongswan 5.9.6 changelog:

Actively initiating duplicate CHILD_SAs within the same IKE_SA is now largely prevented. This can happen if trap policies are installed and an IKE_SA with its CHILD_SAs is reestablished (e.g. with break-before-make reauthentication or dpd_action=restart). This does not prevent duplicates if they are initiated by the two peers concurrently.
Aug 4 2022, 7:15 AM · VyOS 1.4 Sagitta
ssasso updated the task description for T4593: Upgrade strongswan to 5.9.8.
Aug 4 2022, 7:12 AM · VyOS 1.4 Sagitta
ssasso created T4593: Upgrade strongswan to 5.9.8.
Aug 4 2022, 7:10 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXa782eb0711af: bridge: T4579: remove duplicate code path already handled by base class.
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEX03e6b4e9cda0: Revert "vyos.configdict(): T4228: is_member() must split VLAN interfaces".
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEX0bf98f8d7530: bridge: T4579: cleanup interface dict (remove empty keys).
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEX8e54a26f11fe: bridge: T4565: is_member() must return the dict of the member interface.
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEX9d0ca97cc0f1: smoketest: bridge: T4565: changes to lower interfaces must not destroy VLAN….
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEX8c10a1225153: bridge: T4565: bugfix error message when member interface contains an address.
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEXf6dddb5466c9: macsec: T3368: check key length for gcm-aes-128/gcm-aes-256.
Aug 4 2022, 6:57 AM
GitHub <noreply@github.com> committed rVYOSONEX241fad230bee: Merge pull request #1450 from c-po/bridge-fixes-equuleus (authored by c-po).
Aug 4 2022, 6:57 AM
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.204 / 5.10.129 to Update Linux Kernel to v5.4.208 / 5.10.135.
Aug 4 2022, 6:34 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEX993961f60ead: macsec: T4592: can not create two interfaces using the same source-interface.
Aug 4 2022, 6:30 AM
c-po committed rVYOSONEX17e76dc77801: smoketest: macsec: T4537: verify macsec_csindex.
Aug 4 2022, 6:30 AM
c-po committed rVYOSONEX475fbb785dca: vyos.config.configdict: T4592: only print interface name, not interface dict on….
Aug 4 2022, 6:30 AM
c-po moved T4592: macsec: can not create two interfaces using the same source-interface from Need Triage to In Progress on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 4 2022, 6:30 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4592: macsec: can not create two interfaces using the same source-interface from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 4 2022, 6:30 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po added a project to T4592: macsec: can not create two interfaces using the same source-interface: VyOS 1.3 Equuleus (1.3.2).
Aug 4 2022, 6:29 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po changed the status of T4592: macsec: can not create two interfaces using the same source-interface from Open to In progress.
Aug 4 2022, 5:30 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po created T4592: macsec: can not create two interfaces using the same source-interface.
Aug 4 2022, 5:30 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

Aug 3 2022

fab.graglia created T4591: Delete my account VyOS Platform.
Aug 3 2022, 7:11 PM · VyOS 1.4 Sagitta
fab.graglia updated fab.graglia.
Aug 3 2022, 7:03 PM
fab.graglia updated fab.graglia.
Aug 3 2022, 6:59 PM
fab.graglia created T4590: QoS configurations causing commit errors..
Aug 3 2022, 6:58 PM
fab.graglia updated fab.graglia.
Aug 3 2022, 6:54 PM
Nova_Logic added a comment to T4470: Rewrite load-balancing wan to XML/Python.

also it would be good if WLB function will control main routing table, that would help to avoid a lot of confusion with protocols static configuration& WLB function. Current documentation does not telling anything about how exactly protocols static 0.0.0.0/0 route must be set with WLB.
From what I had tested:
1)WLB creates additional routing tables and setting PBR rules
2)without protocols static route 0.0.0.0 with next-hops to every wlb GW local vyos traffic would not work(as would not work traffic to vyos)

Aug 3 2022, 6:20 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
pjeevarathinam created T4589: BGP listen limit Increase via CLI command.
Aug 3 2022, 5:25 PM · VyOS 1.4 Sagitta (1.4.0-GA)
e-zann added a watcher for VyOS 1.3 Equuleus: e-zann.
Aug 3 2022, 5:03 PM
e-zann added a watcher for VyOS 1.4 Sagitta: e-zann.
Aug 3 2022, 5:02 PM
pjeevarathinam updated the task description for T4588: BGP Peer Group Scaling issues.
Aug 3 2022, 2:51 PM · VyOS Rolling
pjeevarathinam updated the task description for T4588: BGP Peer Group Scaling issues.
Aug 3 2022, 2:50 PM · VyOS Rolling
pjeevarathinam created T4588: BGP Peer Group Scaling issues.
Aug 3 2022, 2:49 PM · VyOS Rolling
jack9603301 added a comment to T160: Support NAT64.

It sounds like people prefer jool, and in my personal opinion, if there is a package that is still active up to now, like jool, then jool is probably better. But whatever it is, it's foreign to me

Aug 3 2022, 1:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
n.fort committed rVYOSONEX3c97f09dcd77: T4480:webproxy: Add safe-ports and ssl-safe-ports for acel squid config -- Fix….
Aug 3 2022, 1:53 PM
GitHub <noreply@github.com> committed rVYOSONEXe199ae2dd563: Merge pull request #1369 from nicolas-fort/T4480 (authored by dmbaturin).
Aug 3 2022, 1:53 PM
Viacheslav added a comment to T4586: Add to NAT66: SNAT destination address and DNAT source address..

PR https://github.com/vyos/vyos-1x/pull/1457

set nat66 destination rule 10 destination address '2001:db8:1111::/64'
set nat66 destination rule 10 inbound-interface 'eth1'
set nat66 destination rule 10 source address '!2001:db8::6/127'
set nat66 destination rule 10 translation address '2001:db8::444'
set nat66 source rule 10 destination prefix '2001:db8::2/128'
set nat66 source rule 10 outbound-interface 'eth1'
set nat66 source rule 10 source prefix '2001:db8:1111::/64'
set nat66 source rule 10 translation address 'masquerade'
set nat66 source rule 20 destination prefix '!2001:db8::6/127'
set nat66 source rule 20 outbound-interface 'eth1'
set nat66 source rule 20 source prefix '2001:db8:1111::/64'
set nat66 source rule 20 translation address 'masquerade'
Aug 3 2022, 1:07 PM · VyOS 1.4 Sagitta
Nova_Logic added a comment to T4587: wan load balance issues with 3 or more WANs.

Also I had tried to assign IP addresses directly to wan interfaces to test if it's somehow related to usage of vrrp combined with WLB- it does not work.

Aug 3 2022, 10:52 AM · Bugs, VyOS Rolling
Viacheslav added a subtask for T4470: Rewrite load-balancing wan to XML/Python: T4443: Wan Load Balancing Multiple Regressions.
Aug 3 2022, 10:48 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Viacheslav added a parent task for T4443: Wan Load Balancing Multiple Regressions: T4470: Rewrite load-balancing wan to XML/Python.
Aug 3 2022, 10:48 AM · VyOS Rolling, Bugs
Viacheslav added a subtask for T4470: Rewrite load-balancing wan to XML/Python: T4587: wan load balance issues with 3 or more WANs.
Aug 3 2022, 10:47 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Viacheslav added a parent task for T4587: wan load balance issues with 3 or more WANs: T4470: Rewrite load-balancing wan to XML/Python.
Aug 3 2022, 10:47 AM · Bugs, VyOS Rolling
Viacheslav added a project to T4587: wan load balance issues with 3 or more WANs: VyOS 1.4 Sagitta.
Aug 3 2022, 10:47 AM · Bugs, VyOS Rolling
Nova_Logic updated the task description for T4587: wan load balance issues with 3 or more WANs.
Aug 3 2022, 2:51 AM · Bugs, VyOS Rolling

Aug 2 2022

Nova_Logic created T4587: wan load balance issues with 3 or more WANs.
Aug 2 2022, 10:03 PM · Bugs, VyOS Rolling
RyVolodya updated the task description for T4586: Add to NAT66: SNAT destination address and DNAT source address..
Aug 2 2022, 4:43 PM · VyOS 1.4 Sagitta
RyVolodya updated the task description for T4586: Add to NAT66: SNAT destination address and DNAT source address..
Aug 2 2022, 4:37 PM · VyOS 1.4 Sagitta
zsdc changed the status of T4548: GRUB loader configuration rework from Open to In progress.
Aug 2 2022, 4:21 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T4585: Rewrite op-mode containers to vyos.opmode , a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Aug 2 2022, 3:38 PM · VyOS Rolling
Viacheslav closed T4585: Rewrite op-mode containers to vyos.opmode as Resolved.
Aug 2 2022, 3:38 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX08cb76234720: containers: T4585: Add option restart to containers.py.
Aug 2 2022, 3:05 PM
GitHub <noreply@github.com> committed rVYOSONEX89890f5b07a3: Merge pull request #1456 from sever-sever/T4585 (authored by c-po).
Aug 2 2022, 3:05 PM
Viacheslav added a comment to T4585: Rewrite op-mode containers to vyos.opmode .

PR https://github.com/vyos/vyos-1x/pull/1456

vyos@r14:~$ /usr/libexec/vyos/op_mode/container.py restart --name alp01
Container name "alp01" restarted!
vyos@r14:~$ 
vyos@r14:~$ /usr/libexec/vyos/op_mode/container.py restart --name alp02
Error: no container with name or ID alp02 found: no such container
vyos@r14:~$
Aug 2 2022, 2:36 PM · VyOS 1.4 Sagitta