Page MenuHomeVyOS Platform
Feed All Stories

Oct 12 2022

GitHub <noreply@github.com> committed rVYOSONEXa057a5c1388a: Merge pull request #1586 from sever-sever/T4744 (authored by c-po).
Oct 12 2022, 3:57 PM
Viacheslav added a comment to T4744: BGP directly connected neighbors don't compatible with ebgp-multihop.

PR https://github.com/vyos/vyos-1x/pull/1586

vyos@r14# commit
[ protocols bgp ]
Ebgp-multihop can not be used with directly connected neighbor "eth0"
Oct 12 2022, 3:06 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4744: BGP directly connected neighbors don't compatible with ebgp-multihop from Open to In progress.
Oct 12 2022, 2:43 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4734: Feature Request: openvpn: add OTP 2FA support.

It is highly desirable to reflect this feature in the documentation
Now it is not clear how to configure and use it

Oct 12 2022, 2:38 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4734: Feature Request: openvpn: add OTP 2FA support.

For 1.4 was implemented in T3834

Oct 12 2022, 1:29 PM · VyOS 1.4 Sagitta
aserkin added a comment to T4731: excessive FRR logs about non-existent VRFs.

That does not change the behavior. I get five messages on session start from bfdd, bgpd, ospfd processes, and 16 messages from all FRR daemons on session stop.
The only way to get rid of them is 'log syslog emergencies' but this filters important events as well.

Oct 12 2022, 1:00 PM · VyOS Rolling, Bugs
Viacheslav added a project to T4734: Feature Request: openvpn: add OTP 2FA support: VyOS 1.3 Equuleus (1.3.3).
Oct 12 2022, 12:38 PM · VyOS 1.4 Sagitta
Viacheslav closed T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be as Resolved.
Oct 12 2022, 12:10 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav committed rVYOSONEX15a649e163fa: conntrack-sync: T4730: Fix listen-address jinja2 template.
Oct 12 2022, 12:10 PM
GitHub <noreply@github.com> committed rVYOSONEXf54f1387c7e5: Merge pull request #1582 from sever-sever/T4730-eq (authored by Viacheslav).
Oct 12 2022, 12:10 PM
Viacheslav closed T4740: Show conntrack table ipv6 fail as Resolved.
Oct 12 2022, 11:16 AM · VyOS 1.4 Sagitta
Viacheslav closed T4747: Monitoring influxdb template input exec plugin does not work as Resolved.
Oct 12 2022, 11:10 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4731: excessive FRR logs about non-existent VRFs.

@aserkin as workaround try to change facility level

vtysh -c "conf t" -c "log facility local0"

But it can affect to bgp logs

Oct 12 2022, 10:15 AM · VyOS Rolling, Bugs
Viacheslav moved T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 12 2022, 9:48 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
n.fort added a comment to T2408: DHCP Relay upstream and downstream interfaces.

+1 for @Viacheslav proposal.

Oct 12 2022, 9:24 AM · VyOS 1.4 Sagitta
aserkin added a comment to T4731: excessive FRR logs about non-existent VRFs.

Any suggestions on the problem, guys?
I see a lot of messages regarding these messages appearing in various scenarios since 2017 or even earlier in FRR community. But did not find any solution actually.

Oct 12 2022, 9:09 AM · VyOS Rolling, Bugs
c-po committed rVYOSONEX1c16a56e7b29: ospf: T4707: fix segment-routing Jinja2 template for explicit-null and no-php….
Oct 12 2022, 7:18 AM
goodNETnick <pknet@ya.ru> committed rVYOSONEX765f84386b6e: system login: T874: add 2FA support for local and ssh authentication.
Oct 12 2022, 7:03 AM
GitHub <noreply@github.com> committed rVYOSONEX6951fa7ef6ea: Merge pull request #1555 from goodNETnick/ssh_otp (authored by c-po).
Oct 12 2022, 7:03 AM
Viacheslav added a comment to T4470: Rewrite load-balancing wan to XML/Python.

@thetooth There is a new feature failover route where you can set metrics
https://github.com/vyos/vyos-1x/pull/1358
It could be extended to some "load-balancing"

Oct 12 2022, 6:40 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
thetooth added a comment to T4470: Rewrite load-balancing wan to XML/Python.

I have used this feature in the past but not anymore due to the issues listed in the regressions task. We are now running pfsense purely for LB since this (mostly) works as advertised. Looking back at this current implementation there are some very useful features that are missing.

Oct 12 2022, 2:58 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling

Oct 11 2022

Viacheslav removed a project from T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6): VyOS 1.3 Equuleus (1.3.3).
Oct 11 2022, 9:17 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T4747: Monitoring influxdb template input exec plugin does not work from In progress to Needs testing.
Oct 11 2022, 9:00 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX6859a2474dab: monitoring: T4747: Fix template check influxdb config.
Oct 11 2022, 8:15 PM
GitHub <noreply@github.com> committed rVYOSONEXb74f297d8a74: Merge pull request #1584 from sever-sever/T4747 (authored by c-po).
Oct 11 2022, 8:15 PM
Viacheslav added a comment to T4747: Monitoring influxdb template input exec plugin does not work.

PR https://github.com/vyos/vyos-1x/pull/1584

vyos@r14# cat /run/telegraf/telegraf.conf | grep 'inputs.exec' -A 8
[[inputs.exec]]
  commands = [
    "/etc/telegraf/custom_scripts/show_firewall_input_filter.py",
    "/etc/telegraf/custom_scripts/show_interfaces_input_filter.py",
    "/etc/telegraf/custom_scripts/vyos_services_input_filter.py"
  ]
  timeout = "10s"
  data_format = "influx"
[edit]
vyos@r14#
Oct 11 2022, 7:44 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4747: Monitoring influxdb template input exec plugin does not work from Open to In progress.
Oct 11 2022, 7:09 PM · VyOS 1.4 Sagitta
Viacheslav moved T4680: Telegraf prometheus-client listen-address invalid format from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 11 2022, 7:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav closed T4680: Telegraf prometheus-client listen-address invalid format as Resolved.
Oct 11 2022, 7:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav created T4747: Monitoring influxdb template input exec plugin does not work.
Oct 11 2022, 7:03 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXb4c2d288b098: monitoring: T4680: Bracketize prometheus listen-address.
Oct 11 2022, 6:49 PM
GitHub <noreply@github.com> committed rVYOSONEXbf949ddcc1b9: Merge pull request #1583 from sever-sever/T4680-eq (authored by c-po).
Oct 11 2022, 6:49 PM
Viacheslav created T4746: Monitoring nft. table vyos_filter by default does not exist but telegraf checks this table.
Oct 11 2022, 6:36 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4680: Telegraf prometheus-client listen-address invalid format.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1583

Oct 11 2022, 6:15 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po committed rVYOSONEX06d6386e5d9f: xml: ospf: isis: T4739: merge include files for MPLS segment-routing.
Oct 11 2022, 5:53 PM
Viacheslav changed the status of T4740: Show conntrack table ipv6 fail from In progress to Needs testing.
Oct 11 2022, 5:46 PM · VyOS 1.4 Sagitta
Cheeze_It committed rVYOSONEX08c2a057917c: isis: T4739: ISIS segment routing being refactored.
Oct 11 2022, 5:34 PM
GitHub <noreply@github.com> committed rVYOSONEX7f7705da4def: Merge pull request #1574 from Cheeze-It/current (authored by c-po).
Oct 11 2022, 5:33 PM
initramfs committed rVYOSONEX2722f6ea29a9: qos: T4688: add xml template for limiter actions.
Oct 11 2022, 5:32 PM
GitHub <noreply@github.com> committed rVYOSONEX25b7d6a5a4e0: Merge pull request #1547 from initramfs/current-limiter-actions (authored by c-po).
Oct 11 2022, 5:32 PM
a.apostoliuk committed rVYOSONEX7b61f2062036: bgp: T4492: Fixed output list in "show bgp vrf VRF neighbors".
Oct 11 2022, 5:32 PM
GitHub <noreply@github.com> committed rVYOSONEXcecab72057ab: Merge pull request #1580 from aapostoliuk/T4492-sagitta (authored by c-po).
Oct 11 2022, 5:32 PM
Viacheslav committed rVYOSONEXe4071bfaede4: conntrack: T4740: Set correct error msg if enrties not found.
Oct 11 2022, 5:31 PM
GitHub <noreply@github.com> committed rVYOSONEX72cf07cc8df5: Merge pull request #1581 from sever-sever/T4740 (authored by c-po).
Oct 11 2022, 5:31 PM
victorhooi added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

I believe the ISC DHCP is now officially deprecated and EOLed:

Oct 11 2022, 2:52 PM · VyOS 1.5 Circinus
Viacheslav added a project to T4680: Telegraf prometheus-client listen-address invalid format: VyOS 1.3 Equuleus (1.3.3).
Oct 11 2022, 2:05 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk created T4745: CLI TAB issue with values with '-' at the beginning in conf mode.
Oct 11 2022, 1:31 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
sarthurdev closed T4741: set firewall zone Local local-zone failed as Resolved.
Oct 11 2022, 1:29 PM · VyOS 1.4 Sagitta
sarthurdev closed T4742: Autocomplete in policy route rule x set table / does not show the tables created in the static protocols as Resolved.
Oct 11 2022, 1:29 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1582

Oct 11 2022, 1:07 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T4740: Show conntrack table ipv6 fail.

PR https://github.com/vyos/vyos-1x/pull/1581

vyos@r14:~$ show conntrack table ipv6
Entries not found
vyos@r14:~$
Oct 11 2022, 12:23 PM · VyOS 1.4 Sagitta
Viacheslav created T4744: BGP directly connected neighbors don't compatible with ebgp-multihop.
Oct 11 2022, 9:26 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4729: VxLAN does not work and deleted after tun changed.
In T4729#135230, @pasik wrote:

Ah, yeah, that's a valid point for gretap.

Anyway, my point was, it would be good to test if the issue/bug also affects plain 'gre', as behind the scenes 'gre' and 'gretap' are handled and configured differently, even though they might seem as very similar in vyos cli/config.

The bug might affect both, but it would be good to check and verify.

Oct 11 2022, 8:27 AM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
a.apostoliuk changed the status of T4492: Incorrect list of neighbors in help for "show bgp vrf VRF neighbors" from Open to In progress.
Oct 11 2022, 6:54 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4704: Allow to set metric (MED) to rtt with rtt,+rtt or -rtt from Open to In progress.
Oct 11 2022, 6:53 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXe5507b247edc: smoketest: ospf: skip segment-routing test as of FRR issue.
Oct 11 2022, 5:37 AM
sarthurdev committed rVYOSONEX28e06759fdbb: build: T3664: Add missing divert for /usr/share/pam-configs/radius.
Oct 11 2022, 5:25 AM
GitHub <noreply@github.com> committed rVYOSONEX428c5f43ad9c: Merge pull request #1578 from sarthurdev/build_test (authored by c-po).
Oct 11 2022, 5:25 AM

Oct 10 2022

Viacheslav changed the status of T4740: Show conntrack table ipv6 fail from Open to In progress.
Oct 10 2022, 7:59 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4743: Enable IPv6 address for Dynamic DNS.

PR https://github.com/vyos/vyos-1x/pull/1579

set service dns dynamic interface eth2 ipv6-enable
set service dns dynamic interface eth2 service dynv6 host-name 'xxx.dynv6.net'
set service dns dynamic interface eth2 service dynv6 login 'none'
set service dns dynamic interface eth2 service dynv6 password 'passWorD'
set service dns dynamic interface eth2 service dynv6 protocol 'dyndns2'
set service dns dynamic interface eth2 service dynv6 server 'dynv6.com'
Oct 10 2022, 7:43 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4716: SSH ability to configure RekeyLimit, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from In progress to Needs testing.
Oct 10 2022, 7:33 PM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Viacheslav changed the status of T4716: SSH ability to configure RekeyLimit from In progress to Needs testing.
Oct 10 2022, 7:33 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4743: Enable IPv6 address for Dynamic DNS from Open to In progress.
Oct 10 2022, 6:50 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the subtype of T4743: Enable IPv6 address for Dynamic DNS from "Bug" to "Feature Request".
Oct 10 2022, 6:49 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav created T4743: Enable IPv6 address for Dynamic DNS.
Oct 10 2022, 6:49 PM · VyOS 1.3 Equuleus (1.3.3)
sarthurdev committed rVYOSONEX8269866a5d46: firewall: T4741: Verify zone `from` is defined before use.
Oct 10 2022, 6:04 PM
sarthurdev committed rVYOSONEX47984a6de93b: policy: T4742: Add policy route table auto-complete.
Oct 10 2022, 6:04 PM
GitHub <noreply@github.com> committed rVYOSONEXdfbec80fac0a: Merge pull request #1577 from sarthurdev/T4741 (authored by c-po).
Oct 10 2022, 6:04 PM
Viacheslav committed rVYOSONEXb9de775a5b4f: ssh: T4716: Ablity to configure RekeyLimit data and time.
Oct 10 2022, 6:03 PM
GitHub <noreply@github.com> committed rVYOSONEX9769f25fdf3b: Merge pull request #1563 from sever-sever/T4716 (authored by c-po).
Oct 10 2022, 6:03 PM
Viacheslav closed T538: Support for network mapping in NAT as Resolved.
Oct 10 2022, 5:54 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX98f4cc81235b: conntrack-sync: T4730: Fix listen-address jinja2 template.
Oct 10 2022, 4:35 PM
GitHub <noreply@github.com> committed rVYOSONEXadc9af198365: Merge pull request #1576 from sever-sever/T4730 (authored by c-po).
Oct 10 2022, 4:35 PM
sarthurdev changed the status of T4742: Autocomplete in policy route rule x set table / does not show the tables created in the static protocols from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1577

Oct 10 2022, 2:27 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4741: set firewall zone Local local-zone failed from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1577

Oct 10 2022, 2:27 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be from "Task" to "Bug".
Oct 10 2022, 2:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be.

PR https://github.com/vyos/vyos-1x/pull/1576

Oct 10 2022, 2:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be from Confirmed to In progress.
Oct 10 2022, 1:30 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be from Open to Confirmed.
Oct 10 2022, 1:25 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a project to T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be: VyOS 1.4 Sagitta.
Oct 10 2022, 1:25 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
SrividyaA added a comment to T4741: set firewall zone Local local-zone failed.

zone policy has to be assigned to the firewall rule, that's why the commit failed.

Oct 10 2022, 10:32 AM · VyOS 1.4 Sagitta
Viacheslav edited projects for T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.2).
Oct 10 2022, 10:26 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
HappyShr00m created T4742: Autocomplete in policy route rule x set table / does not show the tables created in the static protocols.
Oct 10 2022, 9:35 AM · VyOS 1.4 Sagitta
roedie changed the status of T4526: keepalived-fifo.py unable to load config from Resolved to Unknown Status.
Oct 10 2022, 9:18 AM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
roedie added a comment to T4526: keepalived-fifo.py unable to load config.

@florin If this is needed I'll make a pull request coming week.

Oct 10 2022, 9:17 AM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX9ab63d484741: firewall: T3907: Fix firewall state-policy logging.
Oct 10 2022, 6:52 AM
GitHub <noreply@github.com> committed rVYOSONEX8bd4c4136a24: Merge pull request #1575 from sarthurdev/firewall_state_log (authored by c-po).
Oct 10 2022, 6:52 AM

Oct 9 2022

tioan created T4741: set firewall zone Local local-zone failed.
Oct 9 2022, 10:16 PM · VyOS 1.4 Sagitta
florin added a comment to T4526: keepalived-fifo.py unable to load config.

I think this needs to be backported to 1.3 too

Oct 9 2022, 9:14 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
a.apostoliuk claimed T4704: Allow to set metric (MED) to rtt with rtt,+rtt or -rtt.
Oct 9 2022, 7:06 PM · VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4740: Show conntrack table ipv6 fail.

I have tested it again. So it happens only if conntrack table is empty.
The same problem with IPv4.

Oct 9 2022, 3:32 PM · VyOS 1.4 Sagitta
a.apostoliuk created T4740: Show conntrack table ipv6 fail.
Oct 9 2022, 3:09 PM · VyOS 1.4 Sagitta
jestabro closed T4738: Extend automatic generation of schema definition files to native configsession functions; use single resolver/directive as Resolved.
Oct 9 2022, 1:54 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX5f81ced8d57d: graphql: T4738: generate schema defs for configsession methods.
Oct 9 2022, 1:46 PM
jestabro committed rVYOSONEX76c9a376c7d4: graphql: T4738: remove templated requests pending rewrite.
Oct 9 2022, 1:46 PM
GitHub <noreply@github.com> committed rVYOSONEX72c97ec2cb86: Merge pull request #1573 from jestabro/gql-simplify (authored by jestabro).
Oct 9 2022, 1:46 PM

Oct 8 2022

Cheeze_It added a comment to T4739: ISIS and OSPF segment routing being refactored.

Added PR for this here, https://github.com/vyos/vyos-1x/pull/1574

Oct 8 2022, 10:54 PM · VyOS 1.4 Sagitta
Rain added a comment to T4612: Support arbitrary netmasks in firewall rules.

I implemented address-mask as described above as well: https://github.com/Rain/vyos-1x/commit/ca6b7340714c6161337f508978b9834722be58dc

Oct 8 2022, 10:12 PM · VyOS 1.4 Sagitta
patrickli added a comment to T4612: Support arbitrary netmasks in firewall rules.

A separate mask field is cleaner also from a documentation point of view. But how would you do it for an address/network group? It only makes sense for a single address I suppose.

Oct 8 2022, 7:05 PM · VyOS 1.4 Sagitta
Rain added a comment to T4612: Support arbitrary netmasks in firewall rules.

On second thought, maybe instead of supporting the ::beef/::ffff syntax we add an address-mask field to source and destination?

Oct 8 2022, 4:02 PM · VyOS 1.4 Sagitta