Page MenuHomeVyOS Platform
Feed Search

Aug 29 2022

Viacheslav edited projects for T3702: Policy: Allow routing by fwmark, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.0).
Aug 29 2022, 8:02 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T3702: Policy: Allow routing by fwmark.

@syncer We'll add/merge it to 1.3.3 (We discussed it and agree to add it after 1.3.2 release)

Aug 29 2022, 8:02 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXb806fd93cea8: rpki: T4654: Fix RPKI cache description.
Aug 29 2022, 7:45 AM
Viacheslav changed the status of T4654: RPKI cache incorrect description from Open to In progress.
Aug 29 2022, 7:39 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4654: RPKI cache incorrect description.

PR https://github.com/vyos/vyos-1x/pull/1503

Aug 29 2022, 7:39 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a project to T4654: RPKI cache incorrect description: VyOS 1.3 Equuleus (1.3.3).
Aug 29 2022, 7:32 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav renamed T4654: RPKI cache incorrect description from RPKI cache incorrect desctiption to RPKI cache incorrect description.
Aug 29 2022, 7:23 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T2044: RPKI doesn't boot properly.

Hi,

Same issue on VyOS 1.4-rolling-202208240217

And when you set the rpki ips you have wrong description on the options, instead of the "rpki server ip" you have "NTP server"

router# set protocols rpki cache ?
Possible completions:
> <x.x.x.x> IP address of NTP server
> <h:h:h:h:h:h:h:h> IPv6 address of NTP server
> <hostname> Fully qualified domain name of NTP server

Aug 29 2022, 6:56 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T4654: RPKI cache incorrect description.
Aug 29 2022, 6:55 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T2460: Migrate vyatta-nat-translations.pl to Python.

In the 1.4 nat translations were rewritten, but I didn't delete the old python code yet https://github.com/vyos/vyos-1x/pull/1501

Aug 29 2022, 6:29 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav moved T4601: dhcp : relay agent IP address issue. from Backport Candidates to Need Triage on the VyOS 1.3 Equuleus (1.3.3) board.
Aug 29 2022, 6:22 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav moved T4601: dhcp : relay agent IP address issue. from Open to Backport Candidates on the VyOS 1.4 Sagitta board.
Aug 29 2022, 6:22 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav moved T4601: dhcp : relay agent IP address issue. from Need Triage to Backport Candidates on the VyOS 1.3 Equuleus (1.3.3) board.
Aug 29 2022, 6:22 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav edited projects for T4601: dhcp : relay agent IP address issue., added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.0).
Aug 29 2022, 6:21 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav closed T4645: show nat source statistics lack argument --family as Resolved.
Aug 29 2022, 6:21 AM · VyOS 1.4 Sagitta

Aug 27 2022

Viacheslav changed the status of T4650: Rewire show nat translation to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Aug 27 2022, 9:23 AM · VyOS Rolling
Viacheslav changed the status of T4650: Rewire show nat translation to vyos.opmode format from In progress to Needs testing.
Aug 27 2022, 9:23 AM · VyOS 1.4 Sagitta

Aug 26 2022

Viacheslav changed the status of T4631: Add port and protocol to nat66 from In progress to Needs testing.
Aug 26 2022, 5:58 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXb752c8779712: nat66: T4631: Add port and protocol to nat66.
Aug 26 2022, 5:31 PM
Viacheslav committed rVYOSONEX829c67c4da17: smoketest: T4631: Extend smoketes fot nat66 protocol.
Aug 26 2022, 5:31 PM
Viacheslav committed rVYOSONEX5d7a5d433a97: nat: nat66: T4650: Rewrite op-mode nat translation.
Aug 26 2022, 5:30 PM
Viacheslav committed rVYOSONEXc2fc87c02dd5: smoketest: T4643: Delete vpn sstp from config as we have HTTP.
Aug 26 2022, 5:30 PM
Viacheslav added a comment to T4650: Rewire show nat translation to vyos.opmode format.

PR https://github.com/vyos/vyos-1x/pull/1501

Aug 26 2022, 3:58 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4650: Rewire show nat translation to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 26 2022, 2:13 PM · VyOS Rolling
Viacheslav changed the status of T4650: Rewire show nat translation to vyos.opmode format from Open to In progress.
Aug 26 2022, 2:13 PM · VyOS 1.4 Sagitta
Viacheslav created T4650: Rewire show nat translation to vyos.opmode format.
Aug 26 2022, 2:13 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4643: Smoketest exclude either sstp or openconnect from pki-misc default listen port.

Before fix:

06:04:21  DEBUG - FAIL: test_pki_misc (__main__.TestConfigPkiMisc)
06:04:21  DEBUG - ----------------------------------------------------------------------
06:04:21  DEBUG - Traceback (most recent call last):
06:04:21  DEBUG -   File "/usr/bin/vyos-configtest", line 50, in test_config_load
06:04:21  DEBUG -     self.session.commit()
06:04:21  DEBUG - vyos.configsession.ConfigSessionError: [[service https]] failed
06:04:21  DEBUG - Commit failed
06:04:21  DEBUG - 
06:04:21  DEBUG - 
06:04:21  DEBUG - During handling of the above exception, another exception occurred:
06:04:21  DEBUG - 
06:04:21  DEBUG - Traceback (most recent call last):
06:04:21  DEBUG -   File "/usr/bin/vyos-configtest", line 53, in test_config_load
06:04:21  DEBUG -     self.fail()
06:04:21  DEBUG - AssertionError: None

After fix:

vyos@r14:~$ /usr/bin/vyos-configtest
Generating tests
... completed: 0.000608
test_pki_misc (__main__.TestConfigPkiMisc) ...  time: 16.943
ok
Aug 26 2022, 11:15 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4643: Smoketest exclude either sstp or openconnect from pki-misc default listen port.

PR https://github.com/vyos/vyos-1x/pull/1499

Aug 26 2022, 11:02 AM · VyOS 1.4 Sagitta
Viacheslav reopened T4643: Smoketest exclude either sstp or openconnect from pki-misc default listen port as "Needs testing".
Aug 26 2022, 8:46 AM · VyOS 1.4 Sagitta

Aug 25 2022

Viacheslav committed rVYOSONEXe2259e25029a: utils: T4594: Add convert_data util.
Aug 25 2022, 5:26 PM
Viacheslav committed rVYOSONEX2131309c1620: graphql: T4544: Add ipsec.py to op-mode-standardized.json.
Aug 25 2022, 5:26 PM
Viacheslav committed rVYOSONEXdcf89afba457: ipsec: T4594: Rewrite op-mode show vpn ipsec sa.
Aug 25 2022, 5:26 PM
Viacheslav closed T4643: Smoketest exclude either sstp or openconnect from pki-misc default listen port as Resolved.
Aug 25 2022, 5:07 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX53bc8022e3be: op-mode: T4645: Show nat source stat missing argument --family.
Aug 25 2022, 4:55 PM
Viacheslav committed rVYOSONEXfa91f567b7b5: smoketest: T4643: Change openconnect default port.
Aug 25 2022, 4:54 PM
Viacheslav committed rVYOSONEXac885f3e0912: sstp: T4644: Check SSTP bind port before commit.
Aug 25 2022, 4:54 PM
Viacheslav added a comment to T4202: NFT: Zone policies fail to apply when "l2tp+" is in the interface list.

We have to replace it in migration scripts if it is already not done

Aug 25 2022, 1:53 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4645: show nat source statistics lack argument --family.

PR https://github.com/vyos/vyos-1x/pull/1497

vyos@r14:~$ show nat source statistics 
Rule    Packets    Bytes    Interface
------  ---------  -------  -----------
100     1279       107896   eth0
120     1          60       eth1
vyos@r14:~$
Aug 25 2022, 12:33 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4645: show nat source statistics lack argument --family from Open to In progress.
Aug 25 2022, 12:16 PM · VyOS 1.4 Sagitta
Viacheslav created T4645: show nat source statistics lack argument --family.
Aug 25 2022, 12:16 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4606: monitor nat destination translation shows missing script.

The easiest way it add vyatta-nat-translations.pl scripts to the op-mode script directory or rewrite it to the python.

Aug 25 2022, 11:09 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2408: DHCP Relay upstream and downstream interfaces.

Also discussed this configuration:

set service dhcp-relay <tag> interface eth0 upstream
set service dhcp-relay <tag> interface eth1 downstream
set service dhcp-relay <tag> server <x.x.x.x>
set service dhcp-relay <tag> relay-options hop-count 1
set service dhcp-relay <tag> relay-options upsteam-port 547
Aug 25 2022, 10:27 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4644: Check bind port before assign vpn sstp from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/1496

vyos@r14# commit
[ vpn sstp ]
"tcp" port "443" is used by another service
Aug 25 2022, 10:25 AM · VyOS 1.4 Sagitta
Viacheslav created T4644: Check bind port before assign vpn sstp.
Aug 25 2022, 9:32 AM · VyOS 1.4 Sagitta
Viacheslav edited projects for T1070: SWANCTL: DMVPN: ALL peers are deleted in swan when opennhrp tries to delete ONE peer, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.0).
Aug 25 2022, 8:00 AM · Bugs, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
Viacheslav changed the status of T4643: Smoketest exclude either sstp or openconnect from pki-misc default listen port from Open to In progress.
Aug 25 2022, 7:13 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4643: Smoketest exclude either sstp or openconnect from pki-misc default listen port.

PR https://github.com/vyos/vyos-1x/pull/1495

Aug 25 2022, 7:08 AM · VyOS 1.4 Sagitta
Viacheslav created T4643: Smoketest exclude either sstp or openconnect from pki-misc default listen port.
Aug 25 2022, 6:44 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4597: Check bind port before assign service HTTPS API and openconnect from In progress to Needs testing.
Aug 25 2022, 6:33 AM · VyOS 1.4 Sagitta
Viacheslav closed T4626: Error showing nat66 source and destination, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Aug 25 2022, 6:32 AM · VyOS Rolling
Viacheslav closed T4626: Error showing nat66 source and destination as Resolved.
Aug 25 2022, 6:32 AM · VyOS 1.4 Sagitta
Viacheslav closed T4622: Firewall allow drop packets by TCP MSS size as Resolved.
Aug 25 2022, 6:32 AM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXfd15f9d2ab6a: firewall: T4622: Add TCP MSS option.
Aug 25 2022, 4:27 AM

Aug 24 2022

Viacheslav committed rVYOSONEX8d4205a99a9f: nat66: T4626: Rewrite op-mode show nat66 rules.
Aug 24 2022, 6:58 PM
Viacheslav committed rVYOSONEXecaafaa26f85: https: T4597: Verify bind port before apply HTTPS API service.
Aug 24 2022, 5:24 PM
Viacheslav committed rVYOSONEX9b3cdfb96af9: conntrack: T4623: Add conntrack statistics for op-mode.
Aug 24 2022, 5:24 PM
Viacheslav changed the status of T4631: Add port and protocol to nat66 from Open to In progress.
Aug 24 2022, 11:46 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4626: Error showing nat66 source and destination, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 24 2022, 11:41 AM · VyOS Rolling
Viacheslav changed the status of T4626: Error showing nat66 source and destination from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/1491

set nat66 destination rule 100 destination address '2001:1111:1111:1111::10'
set nat66 destination rule 100 inbound-interface 'eth0'
set nat66 destination rule 100 translation address 'fd00:1111:1111:1111::10'
set nat66 source rule 100 destination prefix '!fd00:2222:2222:2222::/64'
set nat66 source rule 100 outbound-interface 'eth0'
set nat66 source rule 100 source prefix 'fd00:1111:1111:1111::/64'
set nat66 source rule 100 translation address '2001:1111:1111:1111::10'
set nat66 source rule 120 destination prefix '2001:db8:2222::/64'
set nat66 source rule 120 outbound-interface 'eth0'
set nat66 source rule 120 source prefix '2001:db8:1111::/64'
set nat66 source rule 120 translation address 'masquerade'
set nat66 source rule 130 destination prefix '2001:db8:2222::/64'
set nat66 source rule 130 outbound-interface 'eth0'
set nat66 source rule 130 source prefix '2001:db8:2244::/64'
set nat66 source rule 130 translation address 'masquerade'

show

vyos@r14:~$ show nat66 source rules 
Rule    Source                    Destination                Proto    Out-Int    Translation
------  ------------------------  -------------------------  -------  ---------  -----------------------
100     fd00:1111:1111:1111::/64  !fd00:2222:2222:2222::/64  IP6      eth0       2001:1111:1111:1111::10
        sport any                 dport any
120     2001:db8:1111::/64        2001:db8:2222::/64         IP6      eth0       masquerade
        sport any                 dport any
130     2001:db8:2244::/64        2001:db8:2222::/64         IP6      eth0       masquerade
        sport any                 dport any
vyos@r14:~$ 
vyos@r14:~$ 
vyos@r14:~$ show nat66 destination  rules 
Rule    Source     Destination              Proto    In-Int    Translation
------  ---------  -----------------------  -------  --------  -----------------------
100     ::/0       2001:1111:1111:1111::10  any      eth0      fd00:1111:1111:1111::10
        sport any  dport any
vyos@r14:~$
Aug 24 2022, 11:41 AM · VyOS 1.4 Sagitta

Aug 23 2022

Viacheslav updated subscribers of T4635: Add zebra option ip nht resolve-via-default as default option.

I prefer to get this option configurable if it is possible
For IPv6 and VRFs - nice to have.
As it is used in BGP, I see something like set protocols bgp parameters next-hop-track resolve-via-default
Or, as it was mentioned in T3500
set routing-options next-hop-track resolve-via-default but it will be an additional node with only one option, needs to think

Aug 23 2022, 2:42 PM · VyOS Rolling
Viacheslav added a comment to T4623: Add show conntrack statistics.

PR https://github.com/vyos/vyos-1x/pull/1489

vyos@r14:~$ show conntrack statistics 
CPU    Found    Invalid    Insert    Insert fail      Drop    Early drop    Errors    Search restart
-----  -------  ---------  --------  ---------------  ------  ------------  --------  -----------------
cpu=0  found=0  invalid=0  insert=0  insert_failed=0  drop=0  early_drop=0  error=0   search_restart=0
cpu=1  found=0  invalid=0  insert=0  insert_failed=0  drop=0  early_drop=0  error=0   search_restart=0
cpu=2  found=0  invalid=0  insert=0  insert_failed=0  drop=0  early_drop=0  error=0   search_restart=0
cpu=3  found=0  invalid=0  insert=0  insert_failed=0  drop=0  early_drop=0  error=0   search_restart=48
vyos@r14:~$
Aug 23 2022, 11:37 AM · VyOS 1.4 Sagitta
Viacheslav claimed T4623: Add show conntrack statistics.
Aug 23 2022, 11:35 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4623: Add show conntrack statistics, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 23 2022, 11:34 AM · VyOS Rolling
Viacheslav changed the status of T4623: Add show conntrack statistics from Open to In progress.
Aug 23 2022, 11:34 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4597: Check bind port before assign service HTTPS API and openconnect.

Check NGINX address/port before applying/committing service https
PR https://github.com/vyos/vyos-1x/pull/1488

Aug 23 2022, 9:36 AM · VyOS 1.4 Sagitta
Viacheslav closed T4618: Traffic policy not set on virtual interfaces as Resolved.
Aug 23 2022, 7:50 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav moved T4618: Traffic policy not set on virtual interfaces from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 23 2022, 3:40 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4309: Support network/address-groups and ipv6-network/ipv6-address-groups in "conntrack ignore".

@daniil, could you check/test this PR https://github.com/vyos/vyos-1x/pull/1487 (only for IPv4)

Aug 23 2022, 1:03 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav moved T4206: Policy Based Routing with DHCP Interface Issue from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 23 2022, 12:48 AM · VyOS 1.3 Equuleus (1.3.2)

Aug 22 2022

Viacheslav closed T4089: Show nat destination rules shows ip address instead of interface 'any', a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Aug 22 2022, 7:22 PM · VyOS Rolling
Viacheslav closed T4089: Show nat destination rules shows ip address instead of interface 'any' as Resolved.
Aug 22 2022, 7:22 PM · VyOS 1.4 Sagitta
Viacheslav created T4638: Deleting a parent interface does not delete its underlying VLAN interfaces.
Aug 22 2022, 6:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T4636: VLAN-Aware bridge not handling local traffic (and not able to perform inter-vlan routing).

I guess it the task T4632

Aug 22 2022, 2:08 PM · VyOS 1.4 Sagitta
Viacheslav assigned T4632: VLAN-aware bridge not working to c-po.
Aug 22 2022, 1:36 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav changed the status of T4634: Bgp neighbor disable-connected-check does not work from Open to In progress.
Aug 22 2022, 1:17 PM · VyOS 1.4 Sagitta
Viacheslav created T4635: Add zebra option ip nht resolve-via-default as default option.
Aug 22 2022, 10:51 AM · VyOS Rolling
Viacheslav created T4634: Bgp neighbor disable-connected-check does not work.
Aug 22 2022, 10:37 AM · VyOS 1.4 Sagitta

Aug 20 2022

Viacheslav added a comment to T4631: Add port and protocol to nat66.

PR https://github.com/vyos/vyos-1x/pull/1482

set nat66 destination rule 120 description 'foo'
set nat66 destination rule 120 destination port '4545'
set nat66 destination rule 120 inbound-interface 'eth0'
set nat66 destination rule 120 protocol 'tcp'
set nat66 destination rule 120 source address '2001:db8:2222::/64'
set nat66 destination rule 120 source port '8080'
set nat66 destination rule 120 translation address '2001:db8:1111::1'
set nat66 destination rule 120 translation port '5555'
Aug 20 2022, 4:33 PM · VyOS 1.4 Sagitta
Viacheslav closed T4596: "show openconnect-server sessions" command does not work in the openconnect module, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Aug 20 2022, 2:29 PM · VyOS Rolling
Viacheslav closed T4596: "show openconnect-server sessions" command does not work in the openconnect module as Resolved.
Aug 20 2022, 2:29 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXc0f5d00d9266: ocserv: T4597: Fix check bounded port by service itself.
Aug 20 2022, 2:15 PM
Viacheslav added a comment to T4597: Check bind port before assign service HTTPS API and openconnect.

Fix PR https://github.com/vyos/vyos-1x/pull/1481

Aug 20 2022, 2:03 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4597: Check bind port before assign service HTTPS API and openconnect.

There is a bug with such implementation check for openconnect
It is not possible to create the second user in another commit (as port already bonded)

vyos@r14# run show conf com | match vpn
set vpn openconnect authentication local-users username foo password 'bar'
set vpn openconnect authentication mode local 'password'
set vpn openconnect listen-ports tcp '8443'
set vpn openconnect listen-ports udp '8443'
set vpn openconnect network-settings client-ip-settings subnet '100.64.0.0/24'
set vpn openconnect network-settings name-server '100.64.0.1'
set vpn openconnect ssl ca-certificate 'ca-ocserv'
set vpn openconnect ssl certificate 'srv-ocserv'
[edit]
vyos@r14# commit
No configuration changes to commit
[edit]
vyos@r14# sudo netstat -tulpn | grep 8443
tcp        0      0 0.0.0.0:8443            0.0.0.0:*               LISTEN      23880/ocserv-main   
tcp6       0      0 :::8443                 :::*                    LISTEN      23880/ocserv-main   
udp        0      0 0.0.0.0:8443            0.0.0.0:*                           23880/ocserv-main   
udp6       0      0 :::8443                 :::*                                23880/ocserv-main   
[edit]
vyos@r14# set vpn openconnect authentication local-users username foo2 password 'bar2'
[edit]
vyos@r14# commit
[ vpn openconnect ]
"tcp" port "8443" is used by another service
Aug 20 2022, 10:45 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4596: "show openconnect-server sessions" command does not work in the openconnect module.

It seems after this commit https://github.com/vyos/vyos-1x/commit/1b637f78b870f8ecc4971de5baf0a6fda54c40f7 for T4597
As the port already listens by ocserv itself, maybe we should revert it or change the logic to check that the port bind is not ocserv service

Aug 20 2022, 6:34 AM · VyOS 1.4 Sagitta

Aug 19 2022

Viacheslav closed T4611: UPnP rule IP should be a prefix instead of an address as Resolved.
Aug 19 2022, 8:05 PM · VyOS 1.4 Sagitta
Viacheslav closed T4620: UPnP does not work due to incorrect template as Resolved.
Aug 19 2022, 8:05 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXd0858015f121: UPnP: T4620: Fix Jinja2 template rules.
Aug 19 2022, 6:31 PM
Viacheslav committed rVYOSONEX6940bcf8d650: UPnP: T4611: Rule must be as prefix instead of an address.
Aug 19 2022, 6:31 PM
Viacheslav updated the task description for T4627: Ability to set host part IPv6 address via interface IP token.
Aug 19 2022, 2:05 PM · VyOS 1.5 Circinus (2025.11), VyOS 1.4 Sagitta (1.4.4)
Viacheslav changed the subtype of T4627: Ability to set host part IPv6 address via interface IP token from "Bug" to "Feature Request".
Aug 19 2022, 1:32 PM · VyOS 1.5 Circinus (2025.11), VyOS 1.4 Sagitta (1.4.4)
Viacheslav created T4627: Ability to set host part IPv6 address via interface IP token.
Aug 19 2022, 1:32 PM · VyOS 1.5 Circinus (2025.11), VyOS 1.4 Sagitta (1.4.4)
Viacheslav moved T4619: Static arp is not set if another entry is present from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 19 2022, 12:09 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4626: Error showing nat66 source and destination.
Aug 19 2022, 9:19 AM · VyOS Rolling
Viacheslav added a parent task for T4626: Error showing nat66 source and destination: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Aug 19 2022, 9:19 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4625: Update ocserv to current revision (1.1.6).

There is an example of how we build ocserv for 1.3 https://github.com/vyos/vyos-build/commit/2e1eac5980720d060834540e717f4f8a1189b9b0

Aug 19 2022, 2:49 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

Aug 18 2022

Viacheslav closed T4570: Exception when trying to set up VXLAN over Wireguard as Resolved.
Aug 18 2022, 7:39 PM · VyOS 1.4 Sagitta
Viacheslav closed T4613: UPnP configuration without listen option fail as Resolved.
Aug 18 2022, 5:57 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .

Try to add some capabilities, for example, CAP_CHOWN or CAP_DAC_OVERRIDE or something else

sudo nano /etc/systemd/system/vyos-telegraf.service.d/10-override.conf

https://github.com/vyos/vyos-1x/blob/1f880973e221b91ac843a27d2e4c0b3de1880b97/data/templates/monitoring/override.conf.j2#L6

Aug 18 2022, 5:56 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4622: Firewall allow drop packets by TCP MSS size.

PR https://github.com/vyos/vyos-1x/pull/1478

set firewall name FOO rule 10 action 'drop'
set firewall name FOO rule 10 protocol 'tcp'
set firewall name FOO rule 10 tcp flags syn
set firewall name FOO rule 10 tcp mss '1-500'
Aug 18 2022, 5:23 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4622: Firewall allow drop packets by TCP MSS size from Open to In progress.
Aug 18 2022, 4:30 PM · VyOS 1.4 Sagitta