Page MenuHomeVyOS Platform
Feed All Stories

Apr 6 2023

c-po closed T5147: Can't Commit with Container Network as Resolved.
Apr 6 2023, 7:49 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T1237: Static Route Path Monitoring, failover.

PR https://github.com/vyos/vyos-1x/pull/1941

Apr 6 2023, 12:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T1237: Static Route Path Monitoring, failover.

We have targets-checks 203.0.113.1, 192.0.2.1, and if any of these targets are unreachable, we delete this route.
Is it correct?

Apr 6 2023, 11:04 AM · VyOS 1.4 Sagitta
jack9603301 added a comment to T3116: Support back-end L4 level load balancing.

@c-po How is the review and discussion on this feature going?

Apr 6 2023, 10:09 AM · VyOS 1.4 Sagitta
Viacheslav closed T5125: Add op-mode commands for hsflowd based sflow, a subtask of T5086: Integrate hsflowd for sflow accounting, as Resolved.
Apr 6 2023, 8:34 AM · VyOS 1.4 Sagitta
Viacheslav closed T5125: Add op-mode commands for hsflowd based sflow as Resolved.
Apr 6 2023, 8:33 AM · VyOS 1.4 Sagitta
Viacheslav closed T5146: Show recent login of all users, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, as Invalid.
Apr 6 2023, 8:30 AM · VyOS 1.5 Circinus
Viacheslav closed T5146: Show recent login of all users as Invalid.

A similar output exists

 show system login users 
Possible completions:
  <Enter>               Execute the current command
  all                   Show information about all accounts
  locked                Show information about locked accounts
  other                 Show information about non VyOS user accounts
  vyos                  Show information about VyOS user accounts`
Apr 6 2023, 8:30 AM · VyOS 1.4 Sagitta
Viacheslav closed T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events., a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, as Resolved.
Apr 6 2023, 6:48 AM · VyOS 1.5 Circinus
Viacheslav closed T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events. as Resolved.
Apr 6 2023, 6:48 AM · VyOS 1.4 Sagitta
jbhardman created T5147: Can't Commit with Container Network.
Apr 6 2023, 2:36 AM · VyOS 1.4 Sagitta

Apr 5 2023

Viacheslav added a comment to T5146: Show recent login of all users.

PR https://github.com/vyos/vyos-1x/pull/1940

Apr 5 2023, 4:16 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5146: Show recent login of all users, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
Apr 5 2023, 3:57 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T5146: Show recent login of all users from Open to In progress.
Apr 5 2023, 3:57 PM · VyOS 1.4 Sagitta
Viacheslav created T5146: Show recent login of all users.
Apr 5 2023, 3:55 PM · VyOS 1.4 Sagitta
c-po closed T4975: CLI does not work after cutting off the power or reset as Resolved.
Apr 5 2023, 2:43 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T5136: Possible config corruption on upgrade as Resolved.
Apr 5 2023, 2:43 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T425: AWS CloudWatch monitoring scripts as Resolved.
Apr 5 2023, 2:43 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support
c-po closed T425: AWS CloudWatch monitoring scripts, a subtask of T5129: Add AWS build flavour, as Resolved.
Apr 5 2023, 2:43 PM · VyOS 1.4 Sagitta
c-po moved T5136: Possible config corruption on upgrade from Backport Candidates to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Apr 5 2023, 2:42 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav closed T5145: Add maxsyslogins maximum number of all logins on system , a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, as Resolved.
Apr 5 2023, 11:13 AM · VyOS 1.5 Circinus
Viacheslav closed T5145: Add maxsyslogins maximum number of all logins on system as Resolved.
Apr 5 2023, 11:13 AM · VyOS 1.4 Sagitta
marc_s added a comment to T4362: Wan Load Balancing - Can't create routing tables.

@marc_s Will be fixed in the next rolling release, could you check?

Apr 5 2023, 8:56 AM · VyOS 1.4 Sagitta
marc_s added a comment to T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution.

Thanks @Viacheslav will test ASAP, next week I have a maintenance window, will let you know.

Apr 5 2023, 8:55 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5135: Rewrite opennhrp script using vyos.ipsec library as Resolved.
Apr 5 2023, 8:07 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5135: Rewrite opennhrp script using vyos.ipsec library from In progress to Needs testing.
Apr 5 2023, 7:30 AM · VyOS 1.4 Sagitta

Apr 4 2023

Viacheslav changed the status of T5138: Add patch to accel-ppp build L2TP LNS use Calling-Number as RADIUS Calling-Station-ID from In progress to Needs testing.
Apr 4 2023, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system , a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from In progress to Needs testing.
Apr 4 2023, 5:30 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system from In progress to Needs testing.
Apr 4 2023, 5:30 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5145: Add maxsyslogins maximum number of all logins on system .

PR https://github.com/vyos/vyos-1x/pull/1939

set system login max-login-session '1'
set system login timeout '600'
Apr 4 2023, 2:18 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system , a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
Apr 4 2023, 12:57 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system from Open to In progress.
Apr 4 2023, 12:57 PM · VyOS 1.4 Sagitta
Viacheslav created T5145: Add maxsyslogins maximum number of all logins on system .
Apr 4 2023, 12:49 PM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

Is it possible to implement multiple test targets instead of just one?

Apr 4 2023, 12:01 PM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

Bug: unable to rename a failover route:

Apr 4 2023, 11:37 AM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

@Viacheslav Ok!

Apr 4 2023, 11:36 AM · VyOS 1.4 Sagitta
Harliff awarded T1237: Static Route Path Monitoring, failover a Burninate token.
Apr 4 2023, 11:28 AM · VyOS 1.4 Sagitta
Harliff awarded T1237: Static Route Path Monitoring, failover a Like token.
Apr 4 2023, 11:28 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4712: Collaborative Protection Profile cPP for Network Devices root task.
Apr 4 2023, 11:19 AM · VyOS 1.5 Circinus
Viacheslav added a comment to T1237: Static Route Path Monitoring, failover.

@Harliff It is better to write to this task if you find bugs or propose new features.
So anyone could claim/fix it.
Thanks.

Apr 4 2023, 11:11 AM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

@Viacheslav, where is best place to discuss the feature (ask a question or report a bug)?

Apr 4 2023, 11:07 AM · VyOS 1.4 Sagitta
Viacheslav claimed T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 4 2023, 11:06 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 4 2023, 11:05 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 4 2023, 11:05 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events., a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
Apr 4 2023, 11:03 AM · VyOS 1.5 Circinus
Viacheslav changed the status of T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events. from Open to In progress.

PR https://github.com/vyos/vyos-build/pull/333
PR https://github.com/vyos/vyos-1x/pull/1938

Apr 4 2023, 11:03 AM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

Nice feature. I'm testing it now.

Apr 4 2023, 10:17 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5138: Add patch to accel-ppp build L2TP LNS use Calling-Number as RADIUS Calling-Station-ID from Open to In progress.
Apr 4 2023, 9:16 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5125: Add op-mode commands for hsflowd based sflow.

@neilmckee Thanks.
If output looks good we can close the task

Apr 4 2023, 9:03 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5093: Command 'reset vpn ipsec-profile' doesn't work as Resolved.
Apr 4 2023, 8:53 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5093: Command 'reset vpn ipsec-profile' doesn't work from In progress to Needs testing.
Apr 4 2023, 8:50 AM · VyOS 1.4 Sagitta
Viacheslav closed T4362: Wan Load Balancing - Can't create routing tables as Resolved.
Apr 4 2023, 7:28 AM · VyOS 1.4 Sagitta
Viacheslav closed T4362: Wan Load Balancing - Can't create routing tables, a subtask of T4470: Rewrite load-balancing wan to XML/Python, as Resolved.
Apr 4 2023, 7:28 AM · VyOS 1.5 Circinus
Viacheslav added a comment to T4362: Wan Load Balancing - Can't create routing tables.

Fixed in https://github.com/vyos/vyos-1x/commit/bcc9e2092b07954c72a90f3f9916c9e041308b5b

Apr 4 2023, 7:27 AM · VyOS 1.4 Sagitta
Viacheslav closed T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution as Resolved.
Apr 4 2023, 7:27 AM · VyOS 1.4 Sagitta
indrajitr updated the task description for T5144: Modernize dynamic dns operation.
Apr 4 2023, 3:02 AM · VyOS 1.4 Sagitta
indrajitr created T5144: Modernize dynamic dns operation.
Apr 4 2023, 1:40 AM · VyOS 1.4 Sagitta

Apr 3 2023

indrajitr changed the status of T5143: Apply constraint on powerdns forward-zones configuration from Open to In progress.
Apr 3 2023, 10:58 PM · VyOS 1.4 Sagitta
indrajitr created T5143: Apply constraint on powerdns forward-zones configuration.
Apr 3 2023, 10:13 PM · VyOS 1.4 Sagitta
roedie added a comment to T5080: Disable conntrack by default.

I think one of the problems is that all tables are generated even if there are no rules in it.

Apr 3 2023, 7:26 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 3 2023, 6:31 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 3 2023, 6:29 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 3 2023, 6:25 PM · VyOS 1.4 Sagitta
Viacheslav created T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 3 2023, 6:21 PM · VyOS 1.4 Sagitta
Viacheslav updated subscribers of T5138: Add patch to accel-ppp build L2TP LNS use Calling-Number as RADIUS Calling-Station-ID.
Apr 3 2023, 6:06 PM · VyOS 1.4 Sagitta
neilmckee added a comment to T5125: Add op-mode commands for hsflowd based sflow.

Yes. Packet drops are classed as "event_samples" internally. Definitions for telemetry counters are here:
https://github.com/sflow/host-sflow/blob/v2.0.50-4/src/Linux/hsflowd.h#L460-L486

Apr 3 2023, 4:14 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4362: Wan Load Balancing - Can't create routing tables, a subtask of T4470: Rewrite load-balancing wan to XML/Python, from Open to Needs testing.
Apr 3 2023, 3:46 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T4362: Wan Load Balancing - Can't create routing tables from Open to Needs testing.

@marc_s Will be fixed in the next rolling release, could you check?

Apr 3 2023, 3:46 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution from In progress to Needs testing.
Apr 3 2023, 3:45 PM · VyOS 1.4 Sagitta
Viacheslav closed T5139: IKE life-time should start from 0 for disable rekey as Resolved.

Will be available in the next rolling release.

Apr 3 2023, 3:43 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution from Open to In progress.
Apr 3 2023, 12:55 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution.

PR https://github.com/vyos/vyos-1x/pull/1934
PR https://github.com/vyos/vyatta-wanloadbalance/pull/16

Apr 3 2023, 11:49 AM · VyOS 1.4 Sagitta
Viacheslav created T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution.
Apr 3 2023, 11:06 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5139: IKE life-time should start from 0 for disable rekey .

PR https://github.com/vyos/vyos-1x/pull/1933

set vpn ipsec authentication psk MY-PEER id '192.0.2.1'
set vpn ipsec authentication psk MY-PEER id '192.0.2.10'
set vpn ipsec authentication psk MY-PEER secret 'SeCrEt'
set vpn ipsec esp-group ESP proposal 1
set vpn ipsec ike-group IKE key-exchange 'ikev2'
set vpn ipsec ike-group IKE lifetime '0'
set vpn ipsec ike-group IKE proposal 1 dh-group '14'
set vpn ipsec ike-group IKE proposal 1 encryption 'aes256'
set vpn ipsec ike-group IKE proposal 1 hash 'sha256'
set vpn ipsec interface 'eth1'
set vpn ipsec site-to-site peer MY-PEER authentication mode 'pre-shared-secret'
set vpn ipsec site-to-site peer MY-PEER ike-group 'IKE'
set vpn ipsec site-to-site peer MY-PEER local-address '192.0.2.1'
set vpn ipsec site-to-site peer MY-PEER remote-address '192.0.2.10'
set vpn ipsec site-to-site peer MY-PEER tunnel 1 esp-group 'ESP'
set vpn ipsec site-to-site peer MY-PEER tunnel 1 local prefix '10.0.2.0/25'
set vpn ipsec site-to-site peer MY-PEER tunnel 1 remote prefix '10.5.5.0/25'

Expected `no rekeying

vyos@r14:~$ sudo swanctl -L
MY-PEER: IKEv2, no reauthentication, no rekeying, dpd delay 30s
  local:  192.0.2.1
  remote: 192.0.2.10
  local pre-shared key authentication:
  remote pre-shared key authentication:
    id: %any
  MY-PEER-tunnel-1: TUNNEL, rekeying every 3272s, dpd action is none
    local:  10.0.2.0/25
    remote: 10.5.5.0/25
vyos@r14:~$
Apr 3 2023, 10:54 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5139: IKE life-time should start from 0 for disable rekey from Open to In progress.
Apr 3 2023, 10:25 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5139: IKE life-time should start from 0 for disable rekey from "Bug" to "Feature Request".
Apr 3 2023, 10:25 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5140: Firewall network-group problems.

The similar task/bug with address-group T3390 T469 and port-group

Apr 3 2023, 10:08 AM · VyOS 1.3 Equuleus (1.3.4)
n.fort created T5140: Firewall network-group problems.
Apr 3 2023, 9:57 AM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav added a comment to T5125: Add op-mode commands for hsflowd based sflow.

PR https://github.com/vyos/vyos-1x/pull/1932

vyos@r14:~$ show sflow 
--------------------------  -----------------------------------
Agent address               192.168.122.14
sFlow interfaces            ['eth0', 'eth1']
sFlow servers               ['192.168.122.1', '192.168.122.11']
Counter samples sent        159
Datagrams sent              949
Packet samples sent         124
Packet samples dropped      0
Packet drops sent           815
Packet drops suppressed     0
Flow samples suppressed     0
Counter samples suppressed  0
--------------------------  -----------------------------------
vyos@r14:~$
Apr 3 2023, 9:51 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4081: VRRP health-check script stops working when setting up a sync group.

@lcrockett Add please a new bug report.

Apr 3 2023, 9:08 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav created T5139: IKE life-time should start from 0 for disable rekey .
Apr 3 2023, 8:58 AM · VyOS 1.4 Sagitta
PSDev added a comment to T5085: ospfv3 route-map not applied in FRR configuration.

It actually already exists: https://vyos.dev/T1981

Apr 3 2023, 8:56 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5085: ospfv3 route-map not applied in FRR configuration.

@PSDev Add please a separate bug report

Apr 3 2023, 8:54 AM · VyOS 1.4 Sagitta
Viacheslav created T5138: Add patch to accel-ppp build L2TP LNS use Calling-Number as RADIUS Calling-Station-ID.
Apr 3 2023, 7:38 AM · VyOS 1.4 Sagitta
Viacheslav closed T4173: Wan Load Balancing - Error on firewall NAT rules as Resolved.
Apr 3 2023, 6:55 AM · VyOS 1.4 Sagitta
c-po moved T5136: Possible config corruption on upgrade from Need Triage to Backport Candidates on the VyOS 1.3 Equuleus (1.3.3) board.
Apr 3 2023, 6:07 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T5136: Possible config corruption on upgrade from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Apr 3 2023, 6:07 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po added a project to T5136: Possible config corruption on upgrade: VyOS 1.3 Equuleus (1.3.3).
Apr 3 2023, 6:07 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po added a comment to T5136: Possible config corruption on upgrade.

PR for VyOS 1.3 https://github.com/vyos/vyatta-cfg-system/pull/199

Apr 3 2023, 6:06 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
indrajitr added a comment to T2819: Evaluate DDNS (Dynamic DNS client) as successor to ddclient.

As mentioned on slack, there are quite a few contenders:

Apr 3 2023, 12:34 AM · VyOS 1.3 Equuleus (1.3.8)

Apr 2 2023

Harliff added a comment to T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic.

I can confirm this bug in rolling 1.3-2023-03-30.

Apr 2 2023, 4:10 PM · VyOS 1.5 Circinus
PSDev added a comment to T1981: Allow route-map 'set src' to reference both IPv4 and IPv6.

I created a PR based on the changes from the OSPF PR: https://github.com/vyos/vyos-1x/pull/1931

Apr 2 2023, 2:53 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
PSDev added a comment to T1981: Allow route-map 'set src' to reference both IPv4 and IPv6.

https://vyos.dev/T5085 did the changes for OSPF, but we need this for BGP too

Apr 2 2023, 2:34 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
PSDev added a comment to T5085: ospfv3 route-map not applied in FRR configuration.

We actually need the same for BGP...

Apr 2 2023, 2:33 PM · VyOS 1.4 Sagitta
c-po changed the status of T5136: Possible config corruption on upgrade from Open to Needs testing.
Apr 2 2023, 8:08 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T5134: Try if netavark networks can be moved to a VRF instance as Resolved.
Apr 2 2023, 7:54 AM · VyOS 1.4 Sagitta
c-po closed T5134: Try if netavark networks can be moved to a VRF instance, a subtask of T5082: container: switch to netavark network stack, as Resolved.
Apr 2 2023, 7:54 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T5137: show tech support command.

https://github.com/vyos/vyos-1x/pull/1930

Apr 2 2023, 4:47 AM
Unknown Object (User) added a comment to T5137: show tech support command.

Apr 2 2023, 4:12 AM
Unknown Object (User) triaged T5137: show tech support command as Low priority.
Apr 2 2023, 4:12 AM