Page MenuHomeVyOS Platform
Feed All Stories

Apr 5 2023

marc_s added a comment to T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution.

Thanks @Viacheslav will test ASAP, next week I have a maintenance window, will let you know.

Apr 5 2023, 8:55 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5135: Rewrite opennhrp script using vyos.ipsec library as Resolved.
Apr 5 2023, 8:07 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5135: Rewrite opennhrp script using vyos.ipsec library from In progress to Needs testing.
Apr 5 2023, 7:30 AM · VyOS 1.4 Sagitta

Apr 4 2023

Viacheslav committed rVYOSONEXf72fa1359861: T5142: Add audit tool to monitor security-relevant events.
Apr 4 2023, 7:24 PM
Viacheslav changed the status of T5138: Add patch to accel-ppp build L2TP LNS use Calling-Number as RADIUS Calling-Station-ID from In progress to Needs testing.
Apr 4 2023, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system , a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from In progress to Needs testing.
Apr 4 2023, 5:30 PM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system from In progress to Needs testing.
Apr 4 2023, 5:30 PM · VyOS 1.4 Sagitta
a.apostoliuk committed rVYOSONEXa3ce38b4a290: opennhrp: T5135: Rewritten opennhrp script using vyos.ipsec.
Apr 4 2023, 5:24 PM
GitHub <noreply@github.com> committed rVYOSONEX85b46a6b225c: Merge pull request #1937 from aapostoliuk/T5135-sagitta (authored by c-po).
Apr 4 2023, 5:24 PM
Viacheslav committed rVYOSONEXa1ffb5e73760: T5145: Add maximum number of all logins on system.
Apr 4 2023, 5:23 PM
GitHub <noreply@github.com> committed rVYOSONEXe520e0841013: Merge pull request #1939 from sever-sever/T5145 (authored by c-po).
Apr 4 2023, 5:22 PM
Viacheslav added a comment to T5145: Add maxsyslogins maximum number of all logins on system .

PR https://github.com/vyos/vyos-1x/pull/1939

set system login max-login-session '1'
set system login timeout '600'
Apr 4 2023, 2:18 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system , a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
Apr 4 2023, 12:57 PM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system from Open to In progress.
Apr 4 2023, 12:57 PM · VyOS 1.4 Sagitta
Viacheslav created T5145: Add maxsyslogins maximum number of all logins on system .
Apr 4 2023, 12:49 PM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

Is it possible to implement multiple test targets instead of just one?

Apr 4 2023, 12:01 PM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

Bug: unable to rename a failover route:

Apr 4 2023, 11:37 AM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

@Viacheslav Ok!

Apr 4 2023, 11:36 AM · VyOS 1.4 Sagitta
Harliff awarded T1237: Static Route Path Monitoring, failover a Burninate token.
Apr 4 2023, 11:28 AM · VyOS 1.4 Sagitta
Harliff awarded T1237: Static Route Path Monitoring, failover a Like token.
Apr 4 2023, 11:28 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4712: Collaborative Protection Profile cPP for Network Devices root task.
Apr 4 2023, 11:19 AM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Viacheslav added a comment to T1237: Static Route Path Monitoring, failover.

@Harliff It is better to write to this task if you find bugs or propose new features.
So anyone could claim/fix it.
Thanks.

Apr 4 2023, 11:11 AM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

@Viacheslav, where is best place to discuss the feature (ask a question or report a bug)?

Apr 4 2023, 11:07 AM · VyOS 1.4 Sagitta
Viacheslav claimed T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 4 2023, 11:06 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 4 2023, 11:05 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 4 2023, 11:05 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events., a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
Apr 4 2023, 11:03 AM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Viacheslav changed the status of T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events. from Open to In progress.

PR https://github.com/vyos/vyos-build/pull/333
PR https://github.com/vyos/vyos-1x/pull/1938

Apr 4 2023, 11:03 AM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

Nice feature. I'm testing it now.

Apr 4 2023, 10:17 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5138: Add patch to accel-ppp build L2TP LNS use Calling-Number as RADIUS Calling-Station-ID from Open to In progress.
Apr 4 2023, 9:16 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5125: Add op-mode commands for hsflowd based sflow.

@neilmckee Thanks.
If output looks good we can close the task

Apr 4 2023, 9:03 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5093: Command 'reset vpn ipsec-profile' doesn't work as Resolved.
Apr 4 2023, 8:53 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5093: Command 'reset vpn ipsec-profile' doesn't work from In progress to Needs testing.
Apr 4 2023, 8:50 AM · VyOS 1.4 Sagitta
Viacheslav closed T4362: Wan Load Balancing - Can't create routing tables as Resolved.
Apr 4 2023, 7:28 AM · VyOS 1.4 Sagitta
Viacheslav closed T4362: Wan Load Balancing - Can't create routing tables, a subtask of T4470: Rewrite load-balancing wan to XML/Python, as Resolved.
Apr 4 2023, 7:28 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Viacheslav added a comment to T4362: Wan Load Balancing - Can't create routing tables.

Fixed in https://github.com/vyos/vyos-1x/commit/bcc9e2092b07954c72a90f3f9916c9e041308b5b

Apr 4 2023, 7:27 AM · VyOS 1.4 Sagitta
Viacheslav closed T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution as Resolved.
Apr 4 2023, 7:27 AM · VyOS 1.4 Sagitta
indrajitr updated the task description for T5144: Modernize dynamic dns operation.
Apr 4 2023, 3:02 AM · VyOS 1.4 Sagitta
indrajitr created T5144: Modernize dynamic dns operation.
Apr 4 2023, 1:40 AM · VyOS 1.4 Sagitta

Apr 3 2023

indrajitr changed the status of T5143: Apply constraint on powerdns forward-zones configuration from Open to In progress.
Apr 3 2023, 10:58 PM · VyOS 1.4 Sagitta
indrajitr created T5143: Apply constraint on powerdns forward-zones configuration.
Apr 3 2023, 10:13 PM · VyOS 1.4 Sagitta
roedie added a comment to T5080: Disable conntrack by default.

I think one of the problems is that all tables are generated even if there are no rules in it.

Apr 3 2023, 7:26 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 3 2023, 6:31 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 3 2023, 6:29 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 3 2023, 6:25 PM · VyOS 1.4 Sagitta
Viacheslav created T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 3 2023, 6:21 PM · VyOS 1.4 Sagitta
Viacheslav updated subscribers of T5138: Add patch to accel-ppp build L2TP LNS use Calling-Number as RADIUS Calling-Station-ID.
Apr 3 2023, 6:06 PM · VyOS 1.4 Sagitta
neilmckee added a comment to T5125: Add op-mode commands for hsflowd based sflow.

Yes. Packet drops are classed as "event_samples" internally. Definitions for telemetry counters are here:
https://github.com/sflow/host-sflow/blob/v2.0.50-4/src/Linux/hsflowd.h#L460-L486

Apr 3 2023, 4:14 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4362: Wan Load Balancing - Can't create routing tables, a subtask of T4470: Rewrite load-balancing wan to XML/Python, from Open to Needs testing.
Apr 3 2023, 3:46 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Viacheslav changed the status of T4362: Wan Load Balancing - Can't create routing tables from Open to Needs testing.

@marc_s Will be fixed in the next rolling release, could you check?

Apr 3 2023, 3:46 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution from In progress to Needs testing.
Apr 3 2023, 3:45 PM · VyOS 1.4 Sagitta
Viacheslav closed T5139: IKE life-time should start from 0 for disable rekey as Resolved.

Will be available in the next rolling release.

Apr 3 2023, 3:43 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX1b7534855f92: T5125: Sflow op-mode add event_samples_suppressed option.
Apr 3 2023, 3:42 PM
GitHub <noreply@github.com> committed rVYOSONEX94b65bb3936b: Merge pull request #1932 from sever-sever/T5125 (authored by c-po).
Apr 3 2023, 3:42 PM
Viacheslav committed rVYOSONEX1a1f425f869f: T5141: Add numbers for dhclient-exit-hooks.d to enforce order.
Apr 3 2023, 3:42 PM
GitHub <noreply@github.com> committed rVYOSONEXbcc9e2092b07: Merge pull request #1934 from sever-sever/T5141 (authored by c-po).
Apr 3 2023, 3:42 PM
Viacheslav committed rVYOSONEX16a1a69d6e74: T5139: IPSec add IKE lifetime 0 for no rekeying.
Apr 3 2023, 3:41 PM
GitHub <noreply@github.com> committed rVYOSONEX95245860277a: Merge pull request #1933 from sever-sever/T5139 (authored by c-po).
Apr 3 2023, 3:41 PM
Viacheslav changed the status of T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution from Open to In progress.
Apr 3 2023, 12:55 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution.

PR https://github.com/vyos/vyos-1x/pull/1934
PR https://github.com/vyos/vyatta-wanloadbalance/pull/16

Apr 3 2023, 11:49 AM · VyOS 1.4 Sagitta
Viacheslav created T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution.
Apr 3 2023, 11:06 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5139: IKE life-time should start from 0 for disable rekey .

PR https://github.com/vyos/vyos-1x/pull/1933

set vpn ipsec authentication psk MY-PEER id '192.0.2.1'
set vpn ipsec authentication psk MY-PEER id '192.0.2.10'
set vpn ipsec authentication psk MY-PEER secret 'SeCrEt'
set vpn ipsec esp-group ESP proposal 1
set vpn ipsec ike-group IKE key-exchange 'ikev2'
set vpn ipsec ike-group IKE lifetime '0'
set vpn ipsec ike-group IKE proposal 1 dh-group '14'
set vpn ipsec ike-group IKE proposal 1 encryption 'aes256'
set vpn ipsec ike-group IKE proposal 1 hash 'sha256'
set vpn ipsec interface 'eth1'
set vpn ipsec site-to-site peer MY-PEER authentication mode 'pre-shared-secret'
set vpn ipsec site-to-site peer MY-PEER ike-group 'IKE'
set vpn ipsec site-to-site peer MY-PEER local-address '192.0.2.1'
set vpn ipsec site-to-site peer MY-PEER remote-address '192.0.2.10'
set vpn ipsec site-to-site peer MY-PEER tunnel 1 esp-group 'ESP'
set vpn ipsec site-to-site peer MY-PEER tunnel 1 local prefix '10.0.2.0/25'
set vpn ipsec site-to-site peer MY-PEER tunnel 1 remote prefix '10.5.5.0/25'

Expected `no rekeying

vyos@r14:~$ sudo swanctl -L
MY-PEER: IKEv2, no reauthentication, no rekeying, dpd delay 30s
  local:  192.0.2.1
  remote: 192.0.2.10
  local pre-shared key authentication:
  remote pre-shared key authentication:
    id: %any
  MY-PEER-tunnel-1: TUNNEL, rekeying every 3272s, dpd action is none
    local:  10.0.2.0/25
    remote: 10.5.5.0/25
vyos@r14:~$
Apr 3 2023, 10:54 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5139: IKE life-time should start from 0 for disable rekey from Open to In progress.
Apr 3 2023, 10:25 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5139: IKE life-time should start from 0 for disable rekey from "Bug" to "Feature Request".
Apr 3 2023, 10:25 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5140: Firewall network-group problems.

The similar task/bug with address-group T3390 T469 and port-group

Apr 3 2023, 10:08 AM · VyOS 1.3 Equuleus (1.3.4)
n.fort created T5140: Firewall network-group problems.
Apr 3 2023, 9:57 AM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav added a comment to T5125: Add op-mode commands for hsflowd based sflow.

PR https://github.com/vyos/vyos-1x/pull/1932

vyos@r14:~$ show sflow 
--------------------------  -----------------------------------
Agent address               192.168.122.14
sFlow interfaces            ['eth0', 'eth1']
sFlow servers               ['192.168.122.1', '192.168.122.11']
Counter samples sent        159
Datagrams sent              949
Packet samples sent         124
Packet samples dropped      0
Packet drops sent           815
Packet drops suppressed     0
Flow samples suppressed     0
Counter samples suppressed  0
--------------------------  -----------------------------------
vyos@r14:~$
Apr 3 2023, 9:51 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4081: VRRP health-check script stops working when setting up a sync group.

@lcrockett Add please a new bug report.

Apr 3 2023, 9:08 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav created T5139: IKE life-time should start from 0 for disable rekey .
Apr 3 2023, 8:58 AM · VyOS 1.4 Sagitta
PSDev added a comment to T5085: ospfv3 route-map not applied in FRR configuration.

It actually already exists: https://vyos.dev/T1981

Apr 3 2023, 8:56 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5085: ospfv3 route-map not applied in FRR configuration.

@PSDev Add please a separate bug report

Apr 3 2023, 8:54 AM · VyOS 1.4 Sagitta
Viacheslav created T5138: Add patch to accel-ppp build L2TP LNS use Calling-Number as RADIUS Calling-Station-ID.
Apr 3 2023, 7:38 AM · VyOS 1.4 Sagitta
Viacheslav closed T4173: Wan Load Balancing - Error on firewall NAT rules as Resolved.
Apr 3 2023, 6:55 AM · VyOS 1.4 Sagitta
c-po moved T5136: Possible config corruption on upgrade from Need Triage to Backport Candidates on the VyOS 1.3 Equuleus (1.3.3) board.
Apr 3 2023, 6:07 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T5136: Possible config corruption on upgrade from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 3 2023, 6:07 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po added a project to T5136: Possible config corruption on upgrade: VyOS 1.3 Equuleus (1.3.3).
Apr 3 2023, 6:07 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po added a comment to T5136: Possible config corruption on upgrade.

PR for VyOS 1.3 https://github.com/vyos/vyatta-cfg-system/pull/199

Apr 3 2023, 6:06 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
indrajitr added a comment to T2819: Evaluate DDNS (Dynamic DNS client) as successor to ddclient.

As mentioned on slack, there are quite a few contenders:

Apr 3 2023, 12:34 AM

Apr 2 2023

Harliff added a comment to T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic.

I can confirm this bug in rolling 1.3-2023-03-30.

Apr 2 2023, 4:10 PM · VyOS 1.5 Circinus
PSDev added a comment to T1981: Allow route-map 'set src' to reference both IPv4 and IPv6.

I created a PR based on the changes from the OSPF PR: https://github.com/vyos/vyos-1x/pull/1931

Apr 2 2023, 2:53 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
PSDev added a comment to T1981: Allow route-map 'set src' to reference both IPv4 and IPv6.

https://vyos.dev/T5085 did the changes for OSPF, but we need this for BGP too

Apr 2 2023, 2:34 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
PSDev added a comment to T5085: ospfv3 route-map not applied in FRR configuration.

We actually need the same for BGP...

Apr 2 2023, 2:33 PM · VyOS 1.4 Sagitta
c-po changed the status of T5136: Possible config corruption on upgrade from Open to Needs testing.
Apr 2 2023, 8:08 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T5134: Try if netavark networks can be moved to a VRF instance as Resolved.
Apr 2 2023, 7:54 AM · VyOS 1.4 Sagitta
c-po closed T5134: Try if netavark networks can be moved to a VRF instance, a subtask of T5082: container: switch to netavark network stack, as Resolved.
Apr 2 2023, 7:54 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXb65296a0ff39: container: T5134: support binding container network to specific VRF.
Apr 2 2023, 7:53 AM
c-po committed rVYOSONEX809f28f2b95a: xml: re-use generic-description.xml.i building block whenever possible.
Apr 2 2023, 7:53 AM
Unknown Object (User) added a comment to T5137: show tech support command.

https://github.com/vyos/vyos-1x/pull/1930

Apr 2 2023, 4:47 AM
Unknown Object (User) added a comment to T5137: show tech support command.

Apr 2 2023, 4:12 AM
Unknown Object (User) triaged T5137: show tech support command as Low priority.
Apr 2 2023, 4:12 AM

Apr 1 2023

neilmckee added a comment to T5125: Add op-mode commands for hsflowd based sflow.

The packet-drop events are not really samples in the same way as the packets are random-samples and the counters are time-samples. Even if there is only 1 dropped packet it will be sent. So it might be better to change the wording from “Samples drop events sent” to something like “Packet drop events sent” or just “Packet drops sent”. Make sense?

Apr 1 2023, 9:29 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX7d6731435410: T5125: Extend op-mode show sflow add new metric.
Apr 1 2023, 7:30 PM
GitHub <noreply@github.com> committed rVYOSONEX37740abd88aa: Merge pull request #1929 from sever-sever/T5125 (authored by c-po).
Apr 1 2023, 7:30 PM
roedie created T5136: Possible config corruption on upgrade.
Apr 1 2023, 7:03 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T5125: Add op-mode commands for hsflowd based sflow.

PR https://github.com/vyos/vyos-1x/pull/1929

Apr 1 2023, 6:48 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXb53c25a7bcd0: container: T4959: bugfix credential validation on registries.
Apr 1 2023, 4:57 PM
neilmckee added a comment to T5125: Add op-mode commands for hsflowd based sflow.

Apologies. I believe it is corrected now.

Apr 1 2023, 3:37 PM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5135: Rewrite opennhrp script using vyos.ipsec library from Open to In progress.
Apr 1 2023, 2:58 PM · VyOS 1.4 Sagitta
a.apostoliuk created T5135: Rewrite opennhrp script using vyos.ipsec library.
Apr 1 2023, 2:58 PM · VyOS 1.4 Sagitta
c-po updated the task description for T5134: Try if netavark networks can be moved to a VRF instance.
Apr 1 2023, 2:18 PM · VyOS 1.4 Sagitta