Page MenuHomeVyOS Platform
Feed All Stories

Oct 19 2022

Viacheslav created T4762: Show nat rules with empty rules incorrect error.
Oct 19 2022, 5:37 PM · VyOS 1.4 Sagitta
c-po changed the status of T4511: IPv6 DNS lookup from On hold to Needs testing.
Oct 19 2022, 5:36 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin triaged T4761: Add a generic URL validator as Normal priority.
Oct 19 2022, 4:46 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
a.apostoliuk changed the status of T4704: Allow to set metric (MED) to rtt with rtt,+rtt or -rtt from In progress to Open.
Oct 19 2022, 3:38 PM · VyOS 1.4 Sagitta
a.apostoliuk added a parent task for T4745: CLI TAB issue with values with '-' at the beginning in conf mode: T4704: Allow to set metric (MED) to rtt with rtt,+rtt or -rtt.
Oct 19 2022, 3:37 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
a.apostoliuk added a subtask for T4704: Allow to set metric (MED) to rtt with rtt,+rtt or -rtt: T4745: CLI TAB issue with values with '-' at the beginning in conf mode.
Oct 19 2022, 3:37 PM · VyOS 1.4 Sagitta
Nova_Logic added a comment to T4470: Rewrite load-balancing wan to XML/Python.

so you mean that new WLB implementation(on which I assume we're discussing here) would not mark incoming packets/sessions to allow vyos to DNAT/send replies to correct WAN like pfsense for example does?

Oct 19 2022, 2:36 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T4758: Rewrite show dhcp server to vyos.opmode format.

PR https://github.com/vyos/vyos-1x/pull/1604

Oct 19 2022, 2:26 PM · VyOS 1.4 Sagitta
initramfs created T4760: VyOS does not support running multiple instances of DHCPv6 clients.
Oct 19 2022, 11:41 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
thetooth added a comment to T4470: Rewrite load-balancing wan to XML/Python.

@Nova_Logic I understand your frustration with the old WLB, it is not compatible with policy routes, DNAT, or fwmarks due to the way it's implemented. However WLB or this new implementation are not ingress capable tools. That is, these fill a niche in SMB setups where BGP peering is not possible (due to the use of commodity ISPs), or the cost and/or complexity of operating an IGP or even physically connecting into something like enterprise ethernet, is just completely out of the question. Despite the limitations these setups still need a way to switch over from faulted links quickly and reliably so you don't have an office full of people twiddling there thumbs while the internet is down.

Oct 19 2022, 11:38 AM · VyOS 1.5 Circinus
n.fort created T4759: domain-group on policy route not working.
Oct 19 2022, 11:24 AM · VyOS 1.4 Sagitta
Nova_Logic added a comment to T4470: Rewrite load-balancing wan to XML/Python.

Also it seems, that’s issue appears on 3 or more wans, as I remember it worked with 2 WAN interfaces

Oct 19 2022, 9:40 AM · VyOS 1.5 Circinus
Nova_Logic added a comment to T4470: Rewrite load-balancing wan to XML/Python.

The problem is that failover route will not solve multiwan scenarios where you have 2 or more links for incoming traffic, I.e web. Most good infrastructures would have dedicated management uplink, and also multiple WANs for serving client traffic. That approach increases infrastructure security and provide much more cleaner way to define zone policies. But to do that all traffic, especially incoming one must be correctly marked. I’ve tried a lot of ways to configure wlb, but every time vyos had tried to reply from the wrong interface, that’s why I had crated a bug task here

Oct 19 2022, 9:39 AM · VyOS 1.5 Circinus

Oct 18 2022

c-po closed T4533: Radius clients don’t have simple permissions as Resolved.
Oct 18 2022, 7:37 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T4533: Radius clients don’t have simple permissions from Backport Candidates to Finished on the VyOS 1.4 Sagitta board.
Oct 18 2022, 7:37 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T4533: Radius clients don’t have simple permissions from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Oct 18 2022, 7:36 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
SrividyaA added a comment to T4741: set firewall zone Local local-zone failed.

@tioan , Have you assigned your local-zone to the firewall rule ? Please use the latest version and share the error

Oct 18 2022, 6:41 PM · VyOS 1.4 Sagitta
Viacheslav removed a parent task for T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Oct 18 2022, 5:26 PM · VyOS 1.4 Sagitta
Viacheslav removed a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI.
Oct 18 2022, 5:26 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a parent task for T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Oct 18 2022, 5:23 PM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T4754: Improvement: system login: show configured 2FA OTP key: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Oct 18 2022, 5:23 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added subtasks for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI, T4754: Improvement: system login: show configured 2FA OTP key.
Oct 18 2022, 5:23 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
syncer changed the status of T725: Cake and FQ-PIE, a subtask of T4284: QoS: rewrite to XML and Python, from Open to In progress.
Oct 18 2022, 2:52 PM · VyOS 1.4 Sagitta
syncer changed the status of T725: Cake and FQ-PIE from Open to In progress.
Oct 18 2022, 2:52 PM · VyOS 1.4 Sagitta
jestabro closed T4753: Extend automatic generation of schema to query SystemStatus as Resolved.
Oct 18 2022, 1:31 PM · VyOS 1.4 Sagitta
jestabro closed T4753: Extend automatic generation of schema to query SystemStatus, a subtask of T4738: Extend automatic generation of schema definition files to native configsession functions; use single resolver/directive, as Resolved.
Oct 18 2022, 1:31 PM · VyOS 1.4 Sagitta
n.fort changed the status of T2408: DHCP Relay upstream and downstream interfaces from Open to In progress.
Oct 18 2022, 12:00 PM · VyOS 1.4 Sagitta
n.fort claimed T2408: DHCP Relay upstream and downstream interfaces.
Oct 18 2022, 12:00 PM · VyOS 1.4 Sagitta
n.fort added a comment to T2408: DHCP Relay upstream and downstream interfaces.

PR: https://github.com/vyos/vyos-1x/pull/1603

Oct 18 2022, 12:00 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4758: Rewrite show dhcp server to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Oct 18 2022, 11:53 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav changed the status of T4758: Rewrite show dhcp server to vyos.opmode format from Open to In progress.
Oct 18 2022, 11:53 AM · VyOS 1.4 Sagitta
Viacheslav created T4758: Rewrite show dhcp server to vyos.opmode format.
Oct 18 2022, 11:53 AM · VyOS 1.4 Sagitta
Viacheslav closed T4684: Rewrite show ip route by protocol to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Oct 18 2022, 11:47 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav closed T4684: Rewrite show ip route by protocol to vyos.opmode format as Resolved.
Oct 18 2022, 11:47 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4754: Improvement: system login: show configured 2FA OTP key.

PR:
https://github.com/vyos/vyos-1x/pull/1602

Oct 18 2022, 11:28 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
njh awarded T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6) a Like token.
Oct 18 2022, 11:04 AM · VyOS 1.5 Circinus
c-po claimed T725: Cake and FQ-PIE.
Oct 18 2022, 9:38 AM · VyOS 1.4 Sagitta
c-po added a comment to T4533: Radius clients don’t have simple permissions.

PR for VyOS 1.3 https://github.com/vyos/vyatta-cfg-system/pull/187

Oct 18 2022, 9:31 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zsdc claimed T1875: Add the ability to use network address as BGP neighbor (bgp listen range).
Oct 18 2022, 9:25 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zsdc reopened T1875: Add the ability to use network address as BGP neighbor (bgp listen range), a subtask of T2174: Rewrite protocol BGP to new XML/Python style, as Backport candidate.
Oct 18 2022, 9:24 AM · VyOS 1.3 Equuleus (1.3.0)
zsdc reopened T1875: Add the ability to use network address as BGP neighbor (bgp listen range) as "Backport candidate".
Oct 18 2022, 9:24 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4755: Configure unsuccessful logon attempts.

Tested with next configuration:

vyos@r14:~$ sudo cat /etc/pam.d/common-auth 
auth  required      pam_env.so
auth  required      pam_faillock.so preauth silent audit deny=3 unlock_time=300
auth  sufficient    pam_unix.so  nullok  try_first_pass
auth  [default=die] pam_faillock.so  authfail  audit  deny=3  unlock_time=300
auth  requisite     pam_succeed_if.so uid >= 1000 quiet_success
auth  required      pam_deny.so
vyos@r14:~$
Oct 18 2022, 9:15 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
c-po reassigned T4533: Radius clients don’t have simple permissions from c-po to Viacheslav.
Oct 18 2022, 9:10 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav changed the status of T4714: Delete unused ipset from the filecaps from In progress to Needs testing.
Oct 18 2022, 8:30 AM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T4756: General applications that support SOCAT.
Oct 18 2022, 7:53 AM · Restricted Project, VyOS 1.5 Circinus
jack9603301 updated the task description for T4756: General applications that support SOCAT.
Oct 18 2022, 7:43 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav changed the status of T4714: Delete unused ipset from the filecaps from Open to In progress.

PR https://github.com/vyos/vyatta-cfg-system/pull/186

Oct 18 2022, 6:52 AM · VyOS 1.4 Sagitta
jack9603301 created T4757: General applications that support UDPTUNNEL(UDP OVER TCP,TCP OVER UDP).
Oct 18 2022, 6:47 AM · Restricted Project, VyOS 1.5 Circinus
jack9603301 updated the task description for T4756: General applications that support SOCAT.
Oct 18 2022, 6:13 AM · Restricted Project, VyOS 1.5 Circinus

Oct 17 2022

Viacheslav updated the task description for T4712: Collaborative Protection Profile cPP for Network Devices root task.
Oct 17 2022, 2:12 PM · VyOS 1.5 Circinus
Viacheslav updated subscribers of T4720: Ability to configure SSH HostKeyAlgorithms.
Oct 17 2022, 1:42 PM · VyOS 1.4 Sagitta
Viacheslav claimed T4720: Ability to configure SSH HostKeyAlgorithms.
Oct 17 2022, 12:25 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4720: Ability to configure SSH HostKeyAlgorithms, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
Oct 17 2022, 12:25 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T4720: Ability to configure SSH HostKeyAlgorithms from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/1601

set service ssh hostkey-algorithm '[email protected]'
set service ssh hostkey-algorithm 'ssh-rsa'
Oct 17 2022, 12:25 PM · VyOS 1.4 Sagitta
aserkin added a comment to T4731: excessive FRR logs about non-existent VRFs.

Added more bgpd/ospfd events to the log. The VRF Id seem to be correct. But the events look curious. After session start the interface is first created in vrf default (vrf default, id:0) followed by bgpd/ospfd events, then accel-ppp process moves it to destination vrf (vrf client, id:5) which is follwed by the bgpd/ospfd errors.
Finally, with more or less than 5000 sessions bgpd accidentally becomes unresponsive and utilizes 200% cpu (8 cores are used on VM). Accel-pppd process having all network destinations unreachable also goes unresponsive a bit later.
After that we have to reboot.

Oct 17 2022, 12:11 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
jestabro claimed T3909: Add ability to upload scripts via API.
Oct 17 2022, 10:46 AM · VyOS 1.5 Circinus
jack9603301 created T4756: General applications that support SOCAT.
Oct 17 2022, 10:31 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav updated the task description for T4755: Configure unsuccessful logon attempts.
Oct 17 2022, 10:30 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav created T4755: Configure unsuccessful logon attempts.
Oct 17 2022, 10:03 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav updated subscribers of T3909: Add ability to upload scripts via API.
Oct 17 2022, 9:35 AM · VyOS 1.5 Circinus
Viacheslav added a comment to T4487: Create container without downloaded image wrong behavior.

@CuBiC3D There is a comment of the commit https://github.com/vyos/vyos-1x/commit/373227e717fac82af5ea8d71e611a3df1c59054e

Oct 17 2022, 9:23 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T4752: ICMP redirects not working / not properly configured: VyOS 1.3 Equuleus (1.3.3).
Oct 17 2022, 9:08 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Viacheslav closed T4725: Unable to reset vpn IPsec peer as Resolved.
Oct 17 2022, 9:00 AM · VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T4734: Feature Request: openvpn: add OTP 2FA support.
Oct 17 2022, 7:34 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T4752: ICMP redirects not working / not properly configured: VyOS 1.4 Sagitta.
Oct 17 2022, 6:50 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Cheeze_It changed the status of T4739: ISIS and OSPF segment routing being refactored from Needs testing to Known issue.
Oct 17 2022, 5:21 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4739: ISIS and OSPF segment routing being refactored.

I am finding out, it seems OSPF SR doesn't work properly :(

Oct 17 2022, 5:19 AM · VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T4754: Improvement: system login: show configured 2FA OTP key.
Oct 17 2022, 12:46 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Unknown Object (User) claimed T4754: Improvement: system login: show configured 2FA OTP key.
Oct 17 2022, 12:45 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Unknown Object (User) created T4754: Improvement: system login: show configured 2FA OTP key.
Oct 17 2022, 12:45 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Unknown Object (User) changed the subtype of T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI from "Task" to "Enhancement".
Oct 17 2022, 12:38 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI.

https://github.com/vyos/vyos-1x/pull/1599

Oct 17 2022, 12:34 AM · VyOS 1.4 Sagitta

Oct 16 2022

MrLenin updated MrLenin.
Oct 16 2022, 11:52 PM
Cheeze_It added a comment to T4739: ISIS and OSPF segment routing being refactored.

Here is ISIS segment routing working:

Oct 16 2022, 10:55 PM · VyOS 1.4 Sagitta
syncer added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

Basically,
all commercial hooks need to be implemented

Oct 16 2022, 10:21 PM · VyOS 1.5 Circinus
syncer raised the priority of T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6) from Wishlist to High.
Oct 16 2022, 10:20 PM · VyOS 1.5 Circinus
jestabro renamed T4753: Extend automatic generation of schema to query SystemStatus from Extend automatic generation of shcema to query SystemStatus to Extend automatic generation of schema to query SystemStatus.
Oct 16 2022, 7:25 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4738: Extend automatic generation of schema definition files to native configsession functions; use single resolver/directive: T4753: Extend automatic generation of schema to query SystemStatus.
Oct 16 2022, 7:25 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4753: Extend automatic generation of schema to query SystemStatus: T4738: Extend automatic generation of schema definition files to native configsession functions; use single resolver/directive.
Oct 16 2022, 7:25 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T4753: Extend automatic generation of schema to query SystemStatus.
Oct 16 2022, 7:24 PM · VyOS 1.4 Sagitta
jestabro triaged T4753: Extend automatic generation of schema to query SystemStatus as Normal priority.
Oct 16 2022, 7:24 PM · VyOS 1.4 Sagitta
thetooth added a comment to T4470: Rewrite load-balancing wan to XML/Python.

I have been thinking about this over the weekend and looked into your failover implementation, there's nothing wrong with it and should serve most peoples needs. That said I am not too good with python so it was more straight forward to start from scratch.

Oct 16 2022, 2:29 PM · VyOS 1.5 Circinus
aderouineau added a comment to T4123: checksum file fails to download from AWS S3 in rolling-release.

I confirm this is still an issue in 1.4-rolling-202207250217 trying to download 1.4-rolling-202210150526:

Oct 16 2022, 3:25 AM · VyOS 1.4 Sagitta

Oct 15 2022

tioan added a comment to T4741: set firewall zone Local local-zone failed.

@SrividyaA
The documentation at https://docs.vyos.io/en/latest/configuration/firewall/zone.html currently contains the following regarding local-zone:

Oct 15 2022, 9:32 PM · VyOS 1.4 Sagitta
CuBiC3D added a comment to T4487: Create container without downloaded image wrong behavior.

Why does the image has to be added manually and can not be pulled from the registry if not locally available?

Oct 15 2022, 5:35 PM · VyOS 1.4 Sagitta
dex created T4752: ICMP redirects not working / not properly configured.
Oct 15 2022, 11:00 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Unknown Object (User) claimed T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI.
Oct 15 2022, 6:57 AM · VyOS 1.4 Sagitta
Unknown Object (User) created T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI.
Oct 15 2022, 6:13 AM · VyOS 1.4 Sagitta
Cheeze_It changed the status of T4739: ISIS and OSPF segment routing being refactored from In progress to Needs testing.
Oct 15 2022, 4:00 AM · VyOS 1.4 Sagitta

Oct 14 2022

jestabro closed T4749: Use config_dict for conf_mode http-api.py as Resolved.
Oct 14 2022, 8:29 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4533: Radius clients don’t have simple permissions from Open to Needs testing.
Oct 14 2022, 6:30 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav moved T4533: Radius clients don’t have simple permissions from Need Triage to Backport Candidates on the VyOS 1.4 Sagitta board.
Oct 14 2022, 6:24 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4533: Radius clients don’t have simple permissions.

PR https://github.com/vyos/vyos-1x/pull/1598

Oct 14 2022, 6:11 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro changed Difficulty level from easy to normal on T4749: Use config_dict for conf_mode http-api.py.
Oct 14 2022, 4:33 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3905: Add NAS-Identifier for system login.

@adaker
Could you describe the check/test procedure, how to test that all works as you expected?

Oct 14 2022, 2:44 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Arc771 added a comment to T4750: Support of higher level SSH keys (sk-ssh-ed25519).

Ah, yea that is true.
They are enabled by default.

Oct 14 2022, 12:58 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4750: Support of higher level SSH keys (sk-ssh-ed25519).

I mean Linux man https://man7.org/linux/man-pages/man5/sshd_config.5.html

HostKeyAlgorithms
        Specifies the host key signature algorithms that the server
        offers.  The default for this option is:
Oct 14 2022, 12:49 PM · VyOS 1.4 Sagitta
Arc771 added a comment to T4750: Support of higher level SSH keys (sk-ssh-ed25519).

What do you mean by "enable by default"?
The issue is that, right now, we are unable to add these kind of ssh keys because the cli won't let you define the type.

Oct 14 2022, 12:38 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4750: Support of higher level SSH keys (sk-ssh-ed25519).

Also, it should be enabled by default (at least in ssh documentation)
Could you check it?

Oct 14 2022, 12:36 PM · VyOS 1.4 Sagitta
Viacheslav closed T4672: RADIUS server disable does not work as Resolved.
Oct 14 2022, 12:32 PM · VyOS 1.4 Sagitta