In T5041#143810, @fernando wrote:Could we use something like Dannil proposes? https://vyos.dev/T4883 , as you said FRR staticd don't allow this option but it could be useful when we have different mtu over the interface.
- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
Feed All Stories
All Stories
All Stories
Mar 2 2023
Mar 2 2023
Could we use something like Dannil proposes? https://vyos.dev/T4883 , as you said FRR staticd don't allow this option but it could be useful when we have different mtu over the interface.
Cannot reproduce it with this configuration (VyOS 1.4-rolling-202302280651, don't have a lot of file descriptors):
set protocols bfd peer 192.0.2.5 multihop set protocols bfd peer 192.0.2.5 source address '192.0.2.1' set protocols bfd peer 192.0.2.6 multihop set protocols bfd peer 192.0.2.6 source address '192.0.2.1' set protocols bfd profile BBR interval multiplier '3' set protocols bfd profile BBR interval receive '350' set protocols bfd profile BBR interval transmit '350'
The thing is, we don't use iproute2 commands for adding a route. We use FRR staticd for it. As an exception failover route that uses iproute2 commands
FRRouting 8.4.2 doesn't have such option
r14(config)# ip route 192.0.2.1/32 203.0.113.1
<cr>
(1-255) Distance value for this route
INTERFACE IP gateway interface name
dum0 eth0 eth1 eth2 lo veth0 veth1 wg0
Null0 Null interface
color SR-TE color
label Specify label(s) for this route
nexthop-vrf Specify the VRF
table Table to configure
tag Set tag for this route
vrf Specify the VRFshow vpn ipsec remote-access shows only accel-ppp l2tp, pptp https://github.com/vyos/vyos-1x/blob/current/src/op_mode/show_vpn_ra.py
Mar 1 2023
Mar 1 2023
c-po changed the status of T4989: QoS Policy Limiter - classes for marked traffic do not work from Open to Needs testing.
Add another feature that is improved if we're thinking of moving to KEA :
jestabro added a comment to T5040: Generate API GraphQL schema on installation, rather than dynamically.
jestabro triaged T5040: Generate API GraphQL schema on installation, rather than dynamically as Normal priority.
Christian Poessinger <christian@poessinger.com> committed rVYOSONEXa214896fca17: container: T4014: Add `command`, `arg` and `entrypoint` configuration options… (authored by Zen3515).
Christian Poessinger <christian@poessinger.com> committed rVYOSONEX4bcc364559be: T4967: Allow setting container hostname (authored by Viacheslav).
Christian Poessinger <christian@poessinger.com> committed rVYOSONEX3fbe35c8ab0e: T4967: xml: provide re-usable constraint for CLI host-name definitions (authored by c-po).
GitHub <noreply@github.com> committed rVYOSONEXc4afde0f76a3: Merge pull request #1861 from c-po/container-backports (authored by Viacheslav).
Youyuan <youyuanluo@126.com> committed rVYOSONEXefd51fb7876d: policy: T5035: Add more actions to policy route rule.
GitHub <noreply@github.com> committed rVYOSONEX112fabb4bbb0: Merge branch 'vyos:current' into current (authored by Youyuan <83439858+Yuanandcircle@users.noreply.github.com>).
GitHub <noreply@github.com> committed rVYOSONEX157ac088a57f: Merge pull request #1854 from Yuanandcircle/current (authored by c-po).
Currently digging through a bug with ocserv upstream maintainers, might get a 1.1.7 once we fix that or atleast a 1.1.6-4.
Aside from the weird Duo+RADIUS thing, the version noted in this issue currently runs great.
Feb 28 2023
Feb 28 2023
GitHub <noreply@github.com> committed rVYOSONEX851364c00e05: Merge pull request #1857 from nicolas-fort/nft_queue (authored by c-po).
GitHub <noreply@github.com> committed rVYOSONEX36cf6ea9a1c8: Merge pull request #1860 from sever-sever/T4967 (authored by c-po).
My Xbox One game console is set to use "automatic" settings regarding both port selection and forwarding (via UPNP), and in doing so it chose port 54060 on my LAN (and has been distributed the IP address 172.23.217.102 from my DHCP server — which is not VyOS, by the way).
A few issues I'm encountering while trying to test it right now:
Viacheslav changed the status of T4625: Update ocserv to current revision (1.1.6) from In progress to Needs testing.
PR for 1.3 https://github.com/vyos/vyos-build/pull/316
Viacheslav changed the status of T4625: Update ocserv to current revision (1.1.6) from Open to In progress.
Viacheslav moved T4625: Update ocserv to current revision (1.1.6) from Open to Finished on the VyOS 1.4 Sagitta board.
For 1.4
vyos@r14# run show version all | match ocser ii ocserv 1.1.6-3 amd64 OpenConnect VPN server compatible with Cisco AnyConnect VPN [edit] vyos@r14#
Viacheslav moved T4219: support incoming-interface (iif) in local PBR from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
@Nova_Logic Is this bug still active?
It still requires testing
who can test if this feature works as expected?
@zsdc Can we close it?
Viacheslav changed the status of T2640: Running VyOS inside Docker containers from In progress to Needs testing.
a.apostoliuk closed T4955: Openconnect radiusclient.conf generating with extra authserver as Resolved.
a.apostoliuk moved T4955: Openconnect radiusclient.conf generating with extra authserver from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
a.apostoliuk moved T4955: Openconnect radiusclient.conf generating with extra authserver from Open to Finished on the VyOS 1.4 Sagitta board.
Viacheslav changed the status of T4967: Ability to set hostname for the container from Open to In progress.
Viacheslav edited projects for T5038: WAN load balancing sticky-connections inbound does not work., added: VyOS 1.3 Equuleus (1.3.3); removed vyatta-wanloadbalance, VyOS 1.3 Equuleus.
Viacheslav moved T5033: generate-public-key command fails for address with multiple public keys like GitHub from Open to Finished on the VyOS 1.4 Sagitta board.
Viacheslav added a comment to T5033: generate-public-key command fails for address with multiple public keys like GitHub.
PR for 1.3 https://github.com/vyos/vyos-1x/pull/1859
Viacheslav closed T4843: Command-line arguments in container config, a subtask of T578: Support Linux Container, as Resolved.
Done in T4014
Viacheslav changed the status of T4014: Add “command” and “arg” configuration options for containers, a subtask of T2216: Containerized third-party applications for VyOS, from Open to Needs testing.
Viacheslav changed the status of T4014: Add “command” and “arg” configuration options for containers from Open to Needs testing.
Viacheslav moved T5028: Add package exfatprogs to VyOS from Open to Finished on the VyOS 1.4 Sagitta board.
GitHub <noreply@github.com> committed rVYOSONEX9b88a68001b7: Merge pull request #1800 from vfreex/feature-babel (authored by c-po).
GitHub <noreply@github.com> committed rVYOSONEX16d167ac32a3: Merge pull request #1784 from Zen3515/current-add-container-command-arg (authored by c-po).
GitHub <noreply@github.com> committed rVYOSONEX1aeddb187dff: Merge pull request #1853 from sever-sever/T5033 (authored by c-po).
GitHub <noreply@github.com> committed rVYOSONEXcfed824d7279: Merge pull request #1858 from jestabro/typo-openvpn (authored by c-po).
Feb 27 2023
Feb 27 2023
In T4917#140304, @Viacheslav wrote:In T4917#140239, @b- wrote:Thanks! That’ll help me with what I’m working on :)From where does this limitation originate, anyway? Is there a way to at least add . to the acceptable characters list, so as to allow for foo.sh? Would that break something that expects to skip over filenames with dots and other characters?
Not sure exactly but it seems this part of code https://github.com/vyos/vyatta-cfg/blob/ec568ce7b432acda01f9639afb509287a0e3d760/src/commit/commit-algorithm.cpp#L846
c-po moved T4997: Add DHCP client user hooks dir from Open to In Progress on the VyOS 1.4 Sagitta board.
c-po moved T5025: Time-zone validation failed from Open to In Progress on the VyOS 1.4 Sagitta board.
c-po moved T5029: Nginx change default root directory and fix regex from Open to In Progress on the VyOS 1.4 Sagitta board.
GitHub <noreply@github.com> committed rVYOSONEXdfd88d01a7ed: Merge pull request #1856 from jestabro/list-interfaces (authored by c-po).
PR using list_interfaces from vyos-utils:
GitHub <noreply@github.com> committed rVYOSONEX4621cfc37a60: Merge pull request #1855 from aapostoliuk/T4955-2-sagitta (authored by c-po).
Openconnect
[edit] vyos@r14# set vpn openconnect network-settings push-route 100.64.22.0/24 [edit] vyos@r14# commit [ vpn openconnect ] /usr/libexec/vyos/conf_mode/vpn_openconnect.py:32: DeprecationWarning: 'crypt' is deprecated and slated for removal in Python 3.13 from crypt import crypt, mksalt, METHOD_SHA512
marekm added a comment to T4600: Closing IPV6CP by client closes PPPoE link completely, even if IPv6 is optional.
As a temporary workaround, I use the script below. For some reason /etc/rc.local no longer runs automatically on VyOS 1.3.2, so I run it manually after each reboot for now. Until it is run, Phicomm routers keep disconnecting due to failed IPV6CP negotiation incorrectly triggering complete PPPoE session termination. I have two PPPoE servers at different locations for redundancy, both rebooting at the same time is very unlikely, so I can live with it for now.
thank you, yes updating to latest 1.4 rolling has resolved the issue, pls feel free to close this task as duplicate to https://vyos.dev/T4907