Page MenuHomeVyOS Platform
Feed All Stories

Sep 13 2022

Viacheslav added a parent task for T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups: T2199: Rewrite firewall in new XML/Python style.
Sep 13 2022, 1:02 PM · Restricted Project, Restricted Project, VyOS 1.3 Equuleus (1.3.9)
Viacheslav added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

It should be possible in https://github.com/vyos/vyos-1x/pull/1534 T2199

set firewall interface ethXvX
Sep 13 2022, 11:08 AM · Restricted Project, Restricted Project, VyOS 1.3 Equuleus (1.3.9)
Viacheslav added a comment to T4687: Canot change configuration after image update from 202207220217 to 202209090217.

It seems you use some custom scripts for configuration
You have to use

if [ "$(id -g -n)" != 'vyattacfg' ] ; then
    exec sg vyattacfg -c "/bin/vbash $(readlink -f $0) $@"
fi

before your configuration script

Sep 13 2022, 11:04 AM · VyOS 1.4 Sagitta
c-po updated the task description for T4691: Upgrade Linux Kernel to latest 5.15.y train.
Sep 13 2022, 6:44 AM · VyOS 1.4 Sagitta
c-po moved T4691: Upgrade Linux Kernel to latest 5.15.y train from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Sep 13 2022, 6:43 AM · VyOS 1.4 Sagitta
c-po changed the status of T4691: Upgrade Linux Kernel to latest 5.15.y train from Open to In progress.
Sep 13 2022, 6:43 AM · VyOS 1.4 Sagitta
c-po created T4691: Upgrade Linux Kernel to latest 5.15.y train.
Sep 13 2022, 6:43 AM · VyOS 1.4 Sagitta

Sep 12 2022

sarthurdev added a comment to T2199: Rewrite firewall in new XML/Python style.

Refactor PR: https://github.com/vyos/vyos-1x/pull/1534

Sep 12 2022, 7:16 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev added a comment to T4605: Firewall change default table names.

PR for filter tables: https://github.com/vyos/vyos-1x/pull/1534

Sep 12 2022, 7:15 PM · VyOS 1.4 Sagitta
zsdc added a comment to T2189: Adding a large port-range will take ~ 20 minutes to commit.

Should be fixed in https://github.com/vyos/vyatta-cfg-firewall/pull/34

Sep 12 2022, 5:58 PM · VyOS 1.3 Equuleus (1.3.3)
jestabro closed T4690: Update GraphQL resolver for 'SystemStatus' following changes to 'show_uptime' op-mode script as Resolved.
Sep 12 2022, 3:56 PM · VyOS 1.4 Sagitta
jestabro changed the status of T4690: Update GraphQL resolver for 'SystemStatus' following changes to 'show_uptime' op-mode script from Open to In progress.
Sep 12 2022, 3:19 PM · VyOS 1.4 Sagitta
c-po closed T4170: Rename "policy ipv6-route" -> "policy route6" as Resolved.
Sep 12 2022, 7:16 AM · VyOS 1.4 Sagitta
c-po added a comment to T4170: Rename "policy ipv6-route" -> "policy route6".

Already renamed:

Sep 12 2022, 7:16 AM · VyOS 1.4 Sagitta
c-po closed T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> as Resolved.
Sep 12 2022, 7:00 AM · VyOS 1.4 Sagitta
c-po closed T4647: Add Google Virtual NIC (gVNIC) support as Resolved.
Sep 12 2022, 6:57 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.208 / 5.10.135 to Update Linux Kernel to v5.4.208 / 5.10.142.
Sep 12 2022, 6:56 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
jack9603301 moved T4689: Support RFS(Receive Flow Steering) from In Progress to Finished on the VyOS 1.4 Sagitta board.
Sep 12 2022, 6:53 AM · VyOS 1.4 Sagitta
jack9603301 changed the status of T4689: Support RFS(Receive Flow Steering) from In progress to Needs testing.
Sep 12 2022, 6:53 AM · VyOS 1.4 Sagitta

Sep 11 2022

jack9603301 added a comment to T4689: Support RFS(Receive Flow Steering).

PR: https://github.com/vyos/vyos-1x/pull/1533

Sep 11 2022, 7:09 PM · VyOS 1.4 Sagitta
jack9603301 changed the status of T4689: Support RFS(Receive Flow Steering) from Open to In progress.
Sep 11 2022, 4:38 PM · VyOS 1.4 Sagitta
jack9603301 claimed T4689: Support RFS(Receive Flow Steering).
Sep 11 2022, 4:37 PM · VyOS 1.4 Sagitta
jack9603301 moved T4689: Support RFS(Receive Flow Steering) from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Sep 11 2022, 4:37 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T4689: Support RFS(Receive Flow Steering).
Sep 11 2022, 2:44 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T4689: Support RFS(Receive Flow Steering).
Sep 11 2022, 2:41 PM · VyOS 1.4 Sagitta
jack9603301 renamed T4689: Support RFS(Receive Flow Steering) from Support RFS to Support RFS(Receive Flow Steering).
Sep 11 2022, 2:39 PM · VyOS 1.4 Sagitta
jack9603301 created T4689: Support RFS(Receive Flow Steering).
Sep 11 2022, 2:39 PM · VyOS 1.4 Sagitta
initramfs updated the task description for T4688: Add support for customizing packet verdict actions in limiter traffic policy.
Sep 11 2022, 12:38 PM · VyOS 1.3 Equuleus (1.3.5)
initramfs created T4688: Add support for customizing packet verdict actions in limiter traffic policy.
Sep 11 2022, 12:23 PM · VyOS 1.3 Equuleus (1.3.5)

Sep 10 2022

syncer reassigned T4443: Wan Load Balancing Multiple Regressions from dmbaturin to Viacheslav.
Sep 10 2022, 10:36 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.9)
roedie added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.
In T1185#133944, @sdev wrote:

A similar syntax change is in progress as part of a larger firewall refactor. It should reach the 1.4 branch in a week or so. It should allow for any valid existing interface name.

Sep 10 2022, 6:31 PM · Restricted Project, Restricted Project, VyOS 1.3 Equuleus (1.3.9)
sarthurdev added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Just a suggestion, would it be a weird idea to move the firewall config from the interface section to the firewall section? A bit like the zone config. So something like:

set firewall local interface eth0 name <firewall-filter>
set firewall in interface eth0 name <firewall-filter>
set firewall out interface eth0 name <firewall-filter>
set firewall local interface bond0.10v22v6 ipv6-name <firewall-filter>

The problem is that using zone-policy firewall is a bit overkill for a pure router or even a router with async routing. In which scenario I guess only the local variant would be useful.

Sep 10 2022, 6:23 PM · Restricted Project, Restricted Project, VyOS 1.3 Equuleus (1.3.9)
roedie added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Or, come to think, some free from of set interfaces unknown <typeyourownname> firewall local name <ruleset> where you can only config stuff that doesn't really depend on an interface.

Sep 10 2022, 6:17 PM · Restricted Project, Restricted Project, VyOS 1.3 Equuleus (1.3.9)
roedie added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Just a suggestion, would it be a weird idea to move the firewall config from the interface section to the firewall section? A bit like the zone config. So something like:

Sep 10 2022, 6:09 PM · Restricted Project, Restricted Project, VyOS 1.3 Equuleus (1.3.9)
jack9603301 changed the subtype of T4659: Use vtysh to display bridge and some interface parameter information from "Task" to "Feature Request".
Sep 10 2022, 3:10 PM · VyOS 1.4 Sagitta
xPakrikx created T4687: Canot change configuration after image update from 202207220217 to 202209090217.
Sep 10 2022, 3:10 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T4686: Provides support for veth.
Sep 10 2022, 2:31 PM · VyOS 1.4 Sagitta
jack9603301 changed the subtype of T4686: Provides support for veth from "Task" to "Feature Request".
Sep 10 2022, 2:22 PM · VyOS 1.4 Sagitta
jack9603301 added a subtask for T3829: Support separated TCP/IP stack via "ip netns": T4686: Provides support for veth.
Sep 10 2022, 2:20 PM · Restricted Project, VyOS 1.5 Circinus
jack9603301 added a parent task for T4686: Provides support for veth: T3829: Support separated TCP/IP stack via "ip netns".
Sep 10 2022, 2:20 PM · VyOS 1.4 Sagitta
jack9603301 created T4686: Provides support for veth.
Sep 10 2022, 12:59 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T874: Support for Two Factor Authentication for CLI access via Google Authenticator/OTP.

First we need to include the "google-authenticator" in our build

Sep 10 2022, 1:57 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Unknown Object (User) claimed T874: Support for Two Factor Authentication for CLI access via Google Authenticator/OTP.
Sep 10 2022, 1:54 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
initramfs updated the task description for T4685: Interface does not exist on boot when used as inbound-interface for local policy route.
Sep 10 2022, 1:47 AM · VyOS 1.4 Sagitta

Sep 9 2022

initramfs created T4685: Interface does not exist on boot when used as inbound-interface for local policy route.
Sep 9 2022, 11:17 PM · VyOS 1.4 Sagitta
zsdc changed the status of T2189: Adding a large port-range will take ~ 20 minutes to commit from Open to In progress.
Sep 9 2022, 8:12 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T4684: Rewrite show ip route by protocol to vyos.opmode format.

/usr/libexec/vyos/op_mode/route.py already exists but without an execution flag
PR https://github.com/vyos/vyos-1x/pull/1531

Sep 9 2022, 3:13 PM · VyOS 1.4 Sagitta
Viacheslav created T4684: Rewrite show ip route by protocol to vyos.opmode format.
Sep 9 2022, 2:39 PM · VyOS 1.4 Sagitta
jestabro closed T4681: Complete standardization of show_uptime.py, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Sep 9 2022, 12:59 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro closed T4681: Complete standardization of show_uptime.py as Resolved.
Sep 9 2022, 12:59 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4681: Complete standardization of show_uptime.py.
Sep 9 2022, 12:59 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro added a parent task for T4681: Complete standardization of show_uptime.py: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Sep 9 2022, 12:59 PM · VyOS 1.4 Sagitta
jestabro closed T4682: Rewrite 'show system storage' in standardized format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Sep 9 2022, 12:58 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro closed T4682: Rewrite 'show system storage' in standardized format as Resolved.
Sep 9 2022, 12:58 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4682: Rewrite 'show system storage' in standardized format.
Sep 9 2022, 12:58 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro added a parent task for T4682: Rewrite 'show system storage' in standardized format: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Sep 9 2022, 12:58 PM · VyOS 1.4 Sagitta
NceAirport removed a watcher for VyOS 1.3 Equuleus (1.3.2): NceAirport.
Sep 9 2022, 12:16 PM
zsdc added a comment to T4647: Add Google Virtual NIC (gVNIC) support.

I am suggesting marking this task as "Resolved" because the driver works by himself and NIC can be used with a proper configuration.

Sep 9 2022, 11:35 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address.

PR https://github.com/vyos/vyos-1x/pull/1530

Sep 9 2022, 10:49 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address from Open to In progress.

The real check without IPv4 local/remote:

vyos@r14# commit
[ interfaces openvpn vtun2 ]
Sep 9 2022, 10:30 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs created T4683: Add kitty-terminfo package to build.
Sep 9 2022, 10:20 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4672: RADIUS server disable does not work from Open to Needs testing.
Sep 9 2022, 6:53 AM · VyOS 1.4 Sagitta

Sep 8 2022

jestabro updated the task description for T4682: Rewrite 'show system storage' in standardized format.
Sep 8 2022, 9:20 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4681: Complete standardization of show_uptime.py.

https://github.com/vyos/vyos-1x/pull/1528

Sep 8 2022, 8:33 PM · VyOS 1.4 Sagitta
jestabro renamed T4682: Rewrite 'show system storage' in standardized format from Rewrite 'show system storage' in standarized format to Rewrite 'show system storage' in standardized format.
Sep 8 2022, 8:33 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4682: Rewrite 'show system storage' in standardized format.

https://github.com/vyos/vyos-1x/pull/1529

Sep 8 2022, 8:33 PM · VyOS 1.4 Sagitta
jestabro changed the status of T4682: Rewrite 'show system storage' in standardized format from Open to In progress.
Sep 8 2022, 8:26 PM · VyOS 1.4 Sagitta
jestabro edited projects for T4681: Complete standardization of show_uptime.py, added: VyOS 1.4 Sagitta; removed VyOS 1.2 Crux.
Sep 8 2022, 8:26 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T4681: Complete standardization of show_uptime.py.
Sep 8 2022, 7:59 PM · VyOS 1.4 Sagitta
jestabro changed the status of T4681: Complete standardization of show_uptime.py from Open to In progress.
Sep 8 2022, 7:56 PM · VyOS 1.4 Sagitta
ServerForge added a comment to T4680: Telegraf prometheus-client listen-address invalid format.

Created pull request with fix. https://github.com/vyos/vyos-1x/pull/1527

Sep 8 2022, 5:46 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
ServerForge created T4680: Telegraf prometheus-client listen-address invalid format.
Sep 8 2022, 5:34 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
roedie closed T4526: keepalived-fifo.py unable to load config as Resolved.

I've tested this and it seems to work correctly.

Sep 8 2022, 5:11 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
Viacheslav changed Version from VyOS 1.3.1-S1,VyOS 1.3.2 to VyOS 1.3.1-S1, VyOS 1.3.2, VyOS 1.4-rolling-202209070217 on T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address.
Sep 8 2022, 4:40 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a project to T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address: VyOS 1.4 Sagitta.
Sep 8 2022, 4:40 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav created T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address.
Sep 8 2022, 4:30 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
roedie added a comment to T4665: Keepalived cannot use same VRID for VRRPv2 and VRRPv3.

The interface naming is incorrect after this change for the second interface with the same VRID. It breaks show int.

Sep 8 2022, 2:54 PM · VyOS 1.4 Sagitta
n.fort changed the status of T1024: Policy Based Routing by DSCP from In progress to Needs testing.
Sep 8 2022, 11:23 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav created T4678: Rewrite service ipoe-server to get_config_dict.
Sep 8 2022, 10:12 AM · VyOS 1.4 Sagitta
Viacheslav created T4677: show version shows lts_build true.
Sep 8 2022, 9:22 AM

Sep 7 2022

Viacheslav updated the task description for T4676: IPoE server with mac authentication generates a wrong dictionary.
Sep 7 2022, 4:28 PM · VyOS 1.4 Sagitta
Viacheslav created T4676: IPoE server with mac authentication generates a wrong dictionary.
Sep 7 2022, 4:16 PM · VyOS 1.4 Sagitta
jestabro changed Is it a breaking change? from none to compatible on T4669: Extend numeric.ml for inversion of values and range values.
Sep 7 2022, 3:36 PM · VyOS 1.4 Sagitta
n.fort changed Version from - to 1.4 on T1024: Policy Based Routing by DSCP.
Sep 7 2022, 2:31 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort changed the status of T1024: Policy Based Routing by DSCP from On hold to In progress.
Sep 7 2022, 2:30 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort added a comment to T1024: Policy Based Routing by DSCP.

PR: https://github.com/vyos/vyos-1x/pull/1525

Sep 7 2022, 2:30 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
aserkin created T4675: telegraf do not start at boot when configured in VRF.
Sep 7 2022, 2:01 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .

@aserkin Could you create a PR?

Sep 7 2022, 1:38 PM · VyOS 1.4 Sagitta
dmbaturin edited the content of 1.3.2.
Sep 7 2022, 1:35 PM · VyOS 1.3 Equuleus
dmbaturin added a comment to T4647: Add Google Virtual NIC (gVNIC) support.

As @zsdc says, it's not enough to just have the driver, the problem is that it doesn't work with MTUs over 1460, and VyOS now tries to force it to 1500 if it's not specified. We need to adjust that logic so that MTU setting error doesn't cause a commit error.

Sep 7 2022, 1:34 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dmbaturin reopened T4647: Add Google Virtual NIC (gVNIC) support as "Open".
Sep 7 2022, 1:32 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
aserkin added a comment to T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .

I'd suggest adding

**Restart=always
RestartSec=10**

to /usr/share/vyos/templates/telegraf/override.conf.j2 as it is done for ntp.service.
Otherwise the telegraf service do not start - it does 5 start attempts very quickly during boot with error:

Sep 07 11:43:59 vyos-lns-1 systemd[1]: telegraf.service: Failed with result 'exit-code'.
Sep 07 11:43:59 vyos-lns-1 systemd[1]: telegraf.service: Scheduled restart job, restart counter is at 5.
Sep 07 11:43:59 vyos-lns-1 systemd[1]: telegraf.service: Start request repeated too quickly.
Sep 07 11:43:59 vyos-lns-1 systemd[1]: telegraf.service: Failed with result 'exit-code'.

and stays in a failed state.
see boot log attached.

Sep 7 2022, 9:28 AM · VyOS 1.4 Sagitta

Sep 6 2022

jestabro closed T4674: API should show op-mode error message, if present, a subtask of T4640: Integrate op-mode exception hierarchy into API, as Resolved.
Sep 6 2022, 8:24 PM · VyOS 1.4 Sagitta
jestabro closed T4674: API should show op-mode error message, if present as Resolved.
Sep 6 2022, 8:24 PM · VyOS 1.4 Sagitta
jestabro closed T4673: op-mode bridge.py should raise error on show_fdb for nonexistent bridge interface as Resolved.
Sep 6 2022, 8:23 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4673: op-mode bridge.py should raise error on show_fdb for nonexistent bridge interface.

PR:
https://github.com/vyos/vyos-1x/pull/1524

Sep 6 2022, 7:45 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4640: Integrate op-mode exception hierarchy into API: T4674: API should show op-mode error message, if present.
Sep 6 2022, 7:45 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4674: API should show op-mode error message, if present: T4640: Integrate op-mode exception hierarchy into API.
Sep 6 2022, 7:45 PM · VyOS 1.4 Sagitta
n.fort claimed T1024: Policy Based Routing by DSCP.
Sep 6 2022, 6:37 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro changed the status of T4674: API should show op-mode error message, if present from Open to In progress.
Sep 6 2022, 6:07 PM · VyOS 1.4 Sagitta