Page MenuHomeVyOS Platform
Feed Advanced Search

May 22 2023

Viacheslav closed T4977: Babel routing protocol support as Resolved.
May 22 2023, 7:59 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav changed the status of T5143: Apply constraint on powerdns forward-zones configuration from In progress to Needs testing.
May 22 2023, 7:49 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5115: Support custom port for name servers for forwarding zones from Open to Needs testing.
May 22 2023, 7:46 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T2934: proxy-arp-pvlan on VRRP interface, added: VyOS 1.3 Equuleus (1.3.4); removed VyOS 1.3 Equuleus (1.3.3).
May 22 2023, 7:40 PM · Restricted Project, VyOS Rolling
Viacheslav closed T5214: PPPoE-server incorrect warning if a named pool is defined as Resolved.
May 22 2023, 7:30 PM · VyOS 1.4 Sagitta
zsdc created T5235: SSH keys with special characters cannot be applied via Cloud-init.
May 22 2023, 2:06 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po moved T5234: Add bash identifier for given VRF instance from Open to Finished on the VyOS 1.4 Sagitta board.
May 22 2023, 7:19 AM · VyOS 1.4 Sagitta

May 21 2023

jestabro closed T5218: Revise vyos xml lib for bug fixes and extensions, a subtask of T2665: vyos.xml.defaults for tag nodes, as Resolved.
May 21 2023, 11:31 PM · VyOS 1.4 Sagitta
jestabro closed T5218: Revise vyos xml lib for bug fixes and extensions as Resolved.
May 21 2023, 11:31 PM · VyOS 1.4 Sagitta
c-po closed T5234: Add bash identifier for given VRF instance as Unknown Status.
May 21 2023, 9:15 PM · VyOS 1.4 Sagitta
c-po updated the task description for T5234: Add bash identifier for given VRF instance.
May 21 2023, 9:07 PM · VyOS 1.4 Sagitta
c-po updated the task description for T5234: Add bash identifier for given VRF instance.
May 21 2023, 9:06 PM · VyOS 1.4 Sagitta
c-po claimed T5234: Add bash identifier for given VRF instance.
May 21 2023, 7:10 PM · VyOS 1.4 Sagitta
c-po closed T4675: telegraf do not start at boot when configured in VRF as Invalid.
May 21 2023, 7:05 PM · VyOS 1.4 Sagitta
c-po added a comment to T2251: VRF communication breaks when utilizing zone-based firewalling.

Please re-test with latest 1.4 release as the firewall was moved from iptables -> nftables

May 21 2023, 7:05 PM · VyOS Rolling, Restricted Project
c-po closed T4733: Feature Request: dhcp server: add VRF support as Resolved.
May 21 2023, 7:04 PM · VyOS 1.4 Sagitta
c-po added a comment to T4733: Feature Request: dhcp server: add VRF support.

Hi @daniil and @NikolayP,

May 21 2023, 7:04 PM · VyOS 1.4 Sagitta
Viacheslav renamed T5233: Op-mode flow-accounting netflow with disable-imt errors from Op-mode flow-accounting with disable-imt errors to Op-mode flow-accounting netflow with disable-imt errors.
May 21 2023, 8:45 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5233: Op-mode flow-accounting netflow with disable-imt errors.
May 21 2023, 8:45 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5232: Flow-accounting uacctd.service cannot restart correctly.
May 21 2023, 8:40 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

May 20 2023

c-po added a comment to T5192: RNDIS Missing from Kernel.

Could you write and test an udev rule which renames the RNDIS usb0 device to wwan*?

May 20 2023, 6:47 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav updated the task description for T5231: Add op-mode for load-balancing reverse-proxy.
May 20 2023, 9:11 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5231: Add op-mode for load-balancing reverse-proxy.
May 20 2023, 9:10 AM · VyOS 1.4 Sagitta
Viacheslav renamed T5222: Add load-balancing reverse-proxy based on haproxy from Add load-balancing based on haproxy to Add load-balancing reverse-proxy based on haproxy .
May 20 2023, 8:20 AM · VyOS 1.4 Sagitta
Viacheslav renamed T5231: Add op-mode for load-balancing reverse-proxy from Add op-mode for load-belancing reverse-proxy to Add op-mode for load-balancing reverse-proxy.
May 20 2023, 8:20 AM · VyOS 1.4 Sagitta
Viacheslav created T5231: Add op-mode for load-balancing reverse-proxy.
May 20 2023, 8:20 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5222: Add load-balancing reverse-proxy based on haproxy from Open to Needs testing.
May 20 2023, 7:32 AM · VyOS 1.4 Sagitta

May 19 2023

Viacheslav added a comment to T5229: CGN -- external ports limitting.

There is the task T5169

May 19 2023, 4:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5222: Add load-balancing reverse-proxy based on haproxy .

PR listen-address fixes https://github.com/vyos/vyos-1x/pull/2013

May 19 2023, 4:29 PM · VyOS 1.4 Sagitta
m1nus created T5229: CGN -- external ports limitting.
May 19 2023, 11:12 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5222: Add load-balancing reverse-proxy based on haproxy .

PR refactoring https://github.com/vyos/vyos-1x/pull/2012

May 19 2023, 10:15 AM · VyOS 1.4 Sagitta

May 17 2023

jestabro added a comment to T5228: Simplify get_config_dict and add argument with_defaults.

Draft until the dependency PR is merged:
https://github.com/vyos/vyos-1x/pull/1997

May 17 2023, 9:10 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T5218: Revise vyos xml lib for bug fixes and extensions: T5228: Simplify get_config_dict and add argument with_defaults.
May 17 2023, 6:29 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T5228: Simplify get_config_dict and add argument with_defaults: T5218: Revise vyos xml lib for bug fixes and extensions.
May 17 2023, 6:29 PM · VyOS 1.4 Sagitta
jestabro changed the status of T5228: Simplify get_config_dict and add argument with_defaults from Open to In progress.
May 17 2023, 6:29 PM · VyOS 1.4 Sagitta
fernando added a comment to T3655: NAT doesn't work correctly with VRF.

I've done test , regarding the original issues that it was nat+route-leaking (default + foo) , which is working on the last rolling (VyOS 1.4-rolling-202305140317). however, I've tried some test using two vrf+route-leaking and NAT , I can replicated the issue:

May 17 2023, 3:19 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po closed T5208: Failed to start nvmf-autoconnect.service during the boot as Resolved.
May 17 2023, 1:56 PM · VyOS 1.4 Sagitta
Restricted Repository Identity closed T5226: Deduplicate and standardize validators and constraints for hostname and IP address as Resolved by committing rVYOSONEX0c91c356183b: Merge pull request #2008 from indrajitr/misc-conf-mode-fixes.
May 17 2023, 1:46 PM · VyOS 1.4 Sagitta
ddominet closed T5225: BGP allowas-in unusable as Resolved.
May 17 2023, 11:49 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5227: mDNS reflector should allow additional domains to browse and allow filtering services from "Task" to "Feature Request".
May 17 2023, 8:07 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5225: BGP allowas-in unusable.

@ddominet the correct syntax

set protocols bgp neighbor 192.0.2.11 address-family ipv6-unicast allowas-in number 1
May 17 2023, 8:05 AM · VyOS 1.4 Sagitta
indrajitr created T5227: mDNS reflector should allow additional domains to browse and allow filtering services.
May 17 2023, 6:11 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5225: BGP allowas-in unusable from "Task" to "Bug".
May 17 2023, 5:02 AM · VyOS 1.4 Sagitta
indrajitr changed the status of T5226: Deduplicate and standardize validators and constraints for hostname and IP address from Open to In progress.
May 17 2023, 4:02 AM · VyOS 1.4 Sagitta

May 16 2023

jestabro closed T5194: Add reference tree to vyos1x-config as Resolved.
May 16 2023, 6:31 PM · VyOS 1.4 Sagitta
mborodin added a comment to T3598: DMVPN/IPSec does not work with upstream Strongswan 5.9.

I've managed to adapt Alpine Linux patches to build Debian 11 StrongSwan 5.9.1 package, feel free to use it

May 16 2023, 11:24 AM · VyOS 1.4 Sagitta (1.4.0-GA)
ddominet added a project to T5225: BGP allowas-in unusable: VyOS 1.4 Sagitta.
May 16 2023, 10:41 AM · VyOS 1.4 Sagitta
diodep added a comment to T3655: NAT doesn't work correctly with VRF.

I have NAT working with vrf in VyOS 1.4-rolling-202208290458 + custom nat offload

set interfaces ethernet eth0 address '192.168.122.14/24'
set interfaces ethernet eth1 address '192.0.2.1/24'
set interfaces ethernet eth1 vrf 'foo'
set protocols static route 192.0.2.0/24 interface eth1 vrf 'foo'
set system conntrack
set vrf name foo protocols static route 0.0.0.0/0 next-hop 192.168.122.1 interface 'eth0'
set vrf name foo protocols static route 0.0.0.0/0 next-hop 192.168.122.1 vrf 'default'
set vrf name foo table '1010'

Nftables

root@r14:/home/vyos# cat nat.nft 
flush ruleset

table ip filter {
	flowtable fastnat {
		hook ingress priority filter
		devices = { eth0, eth1 }
	}

	chain forward {
		type filter hook forward priority filter; policy accept;
		ip protocol { tcp, udp } flow add @fastnat
	}
}
table ip nat {
	chain POSTROUTING {
		type nat hook postrouting priority srcnat; policy accept;
		ip saddr 192.0.2.0/24 oif "eth0" snat to 192.168.122.14 persistent
	}

	chain PREROUTING {
		type nat hook prerouting priority dstnat; policy accept;
	}
}

Conntrack table

vyos@r14:~$ sudo conntrack -F
conntrack v1.4.6 (conntrack-tools): connection tracking table has been emptied.
vyos@r14:~$ 
vyos@r14:~$ sudo conntrack -L
tcp      6 431999 ESTABLISHED src=192.168.122.14 dst=192.168.122.1 sport=22 dport=44462 src=192.168.122.1 dst=192.168.122.14 sport=44462 dport=22 [ASSURED] mark=0 use=1
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=33018 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=33018 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=37517 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=37517 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=59794 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=59794 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=39288 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=39288 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=39616 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=39616 [OFFLOAD] mark=0 use=2
icmp     1 29 src=192.0.2.2 dst=1.1.1.1 type=8 code=0 id=12387 src=1.1.1.1 dst=192.168.122.14 type=0 code=0 id=12387 mark=0 use=1
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=41155 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=41155 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=39829 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=39829 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=33655 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=33655 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=44835 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=44835 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=40213 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=40213 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=33729 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=33729 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=48344 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=48344 [OFFLOAD] mark=0 use=2
conntrack v1.4.6 (conntrack-tools): 14 flow entries have been shown.
vyos@r14:~$

This works for me too on current rolling releases from Jan-2023 to now.

May 16 2023, 6:57 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
indrajitr changed the status of T5144: Modernize dynamic dns operation from Needs testing to In progress.

More PRs
https://github.com/vyos/vyos-1x/pull/2005
https://github.com/vyos/vyos-build/pull/349
https://github.com/vyos/vyatta-cfg-system/pull/202

May 16 2023, 5:10 AM · VyOS 1.4 Sagitta

May 15 2023

a.apostoliuk added a comment to T4031: Ability to configure DMVPN in vrf.

I reproduced the problem.
I received the next logs

May 15 2023, 3:45 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5197: Conntrack-sync external cache commit error from Open to Needs testing.
May 15 2023, 3:03 PM · VyOS 1.4 Sagitta
daniil added a comment to T5197: Conntrack-sync external cache commit error.

Version 1.4-rolling-202305150317 does not have the problem.

May 15 2023, 1:42 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5222: Add load-balancing reverse-proxy based on haproxy .
May 15 2023, 12:29 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5222: Add load-balancing reverse-proxy based on haproxy .
May 15 2023, 12:02 PM · VyOS 1.4 Sagitta
Viacheslav closed T3896: Extend ocserv support to allow for per-group configs as Resolved.
May 15 2023, 8:21 AM · VyOS 1.4 Sagitta
PeppyH added a comment to T3896: Extend ocserv support to allow for per-group configs.

This can be closed now. I've submitted a Documentation PR

May 15 2023, 6:04 AM · VyOS 1.4 Sagitta

May 13 2023

Viacheslav added a comment to T5222: Add load-balancing reverse-proxy based on haproxy .

PR https://github.com/vyos/vyos-1x/pull/2004

May 13 2023, 1:19 PM · VyOS 1.4 Sagitta

May 12 2023

c-po added a comment to T5222: Add load-balancing reverse-proxy based on haproxy .

We should make the ssl-bind ciphers and ssl-bind-options configurable (<multi/> node) by the user

May 12 2023, 7:50 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5222: Add load-balancing reverse-proxy based on haproxy .
May 12 2023, 6:20 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5222: Add load-balancing reverse-proxy based on haproxy .
May 12 2023, 6:09 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5222: Add load-balancing reverse-proxy based on haproxy .
May 12 2023, 6:01 PM · VyOS 1.4 Sagitta
bbabich added a comment to T3655: NAT doesn't work correctly with VRF.

I have NAT working with vrf in VyOS 1.4-rolling-202208290458 + custom nat offload

set interfaces ethernet eth0 address '192.168.122.14/24'
set interfaces ethernet eth1 address '192.0.2.1/24'
set interfaces ethernet eth1 vrf 'foo'
set protocols static route 192.0.2.0/24 interface eth1 vrf 'foo'
set system conntrack
set vrf name foo protocols static route 0.0.0.0/0 next-hop 192.168.122.1 interface 'eth0'
set vrf name foo protocols static route 0.0.0.0/0 next-hop 192.168.122.1 vrf 'default'
set vrf name foo table '1010'

Nftables

root@r14:/home/vyos# cat nat.nft 
flush ruleset

table ip filter {
	flowtable fastnat {
		hook ingress priority filter
		devices = { eth0, eth1 }
	}

	chain forward {
		type filter hook forward priority filter; policy accept;
		ip protocol { tcp, udp } flow add @fastnat
	}
}
table ip nat {
	chain POSTROUTING {
		type nat hook postrouting priority srcnat; policy accept;
		ip saddr 192.0.2.0/24 oif "eth0" snat to 192.168.122.14 persistent
	}

	chain PREROUTING {
		type nat hook prerouting priority dstnat; policy accept;
	}
}

Conntrack table

vyos@r14:~$ sudo conntrack -F
conntrack v1.4.6 (conntrack-tools): connection tracking table has been emptied.
vyos@r14:~$ 
vyos@r14:~$ sudo conntrack -L
tcp      6 431999 ESTABLISHED src=192.168.122.14 dst=192.168.122.1 sport=22 dport=44462 src=192.168.122.1 dst=192.168.122.14 sport=44462 dport=22 [ASSURED] mark=0 use=1
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=33018 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=33018 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=37517 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=37517 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=59794 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=59794 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=39288 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=39288 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=39616 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=39616 [OFFLOAD] mark=0 use=2
icmp     1 29 src=192.0.2.2 dst=1.1.1.1 type=8 code=0 id=12387 src=1.1.1.1 dst=192.168.122.14 type=0 code=0 id=12387 mark=0 use=1
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=41155 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=41155 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=39829 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=39829 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=33655 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=33655 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=44835 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=44835 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=40213 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=40213 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=33729 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=33729 [OFFLOAD] mark=0 use=2
udp      17 src=192.0.2.2 dst=1.1.1.1 sport=48344 dport=53 src=1.1.1.1 dst=192.168.122.14 sport=53 dport=48344 [OFFLOAD] mark=0 use=2
conntrack v1.4.6 (conntrack-tools): 14 flow entries have been shown.
vyos@r14:~$
May 12 2023, 2:24 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort assigned T5210: IPSec cosmetic bug for Warning vti inrerface to jnulandicho.
May 12 2023, 2:15 PM · VyOS 1.4 Sagitta
Viacheslav claimed T5222: Add load-balancing reverse-proxy based on haproxy .
May 12 2023, 1:30 PM · VyOS 1.4 Sagitta
Viacheslav renamed T5222: Add load-balancing reverse-proxy based on haproxy from Add loadbalancing based on haproxy to Add load-balancing based on haproxy .
May 12 2023, 1:30 PM · VyOS 1.4 Sagitta
Viacheslav created T5222: Add load-balancing reverse-proxy based on haproxy .
May 12 2023, 1:30 PM · VyOS 1.4 Sagitta
Zen3515 changed the status of T5219: ddclient: Cloudflare doesn't require login from Open to In progress.

I've create a pull request for this task at https://github.com/vyos/vyos-1x/pull/2002

May 12 2023, 9:44 AM · VyOS 1.4 Sagitta
c-po closed T2778: Migrate "system syslog" to get_config_dict() to support new features as Resolved.
May 12 2023, 5:28 AM · VyOS 1.4 Sagitta
c-po moved T2778: Migrate "system syslog" to get_config_dict() to support new features from Backlog to Finished on the VyOS 1.4 Sagitta board.
May 12 2023, 5:27 AM · VyOS 1.4 Sagitta
c-po changed the status of T2769: Add VRF support for syslog, a subtask of T2778: Migrate "system syslog" to get_config_dict() to support new features, from Unknown Status to Resolved.
May 12 2023, 5:27 AM · VyOS 1.4 Sagitta
c-po changed the status of T2769: Add VRF support for syslog from Unknown Status to Resolved.
May 12 2023, 5:27 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

May 11 2023

c-po moved T2769: Add VRF support for syslog from Backlog to Finished on the VyOS 1.4 Sagitta board.
May 11 2023, 6:46 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T2769: Add VRF support for syslog from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
May 11 2023, 6:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po added a comment to T2769: Add VRF support for syslog.

Backport for 1.3.3 https://github.com/vyos/vyos-1x/pull/2001

May 11 2023, 6:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zsdc changed the status of T5220: Unattended installation from Open to In progress.
May 11 2023, 6:22 PM · VyOS Rolling
zsdc created T5220: Unattended installation.
May 11 2023, 6:20 PM · VyOS Rolling
jestabro added a comment to T5194: Add reference tree to vyos1x-config.

PR:
https://github.com/vyos/vyos1x-config/pull/17

May 11 2023, 1:47 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T5219: ddclient: Cloudflare doesn't require login, added: VyOS 1.4 Sagitta; removed ddclient.
May 11 2023, 1:46 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5217: Add firewall SYNPROXY .
May 11 2023, 12:48 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4362: Wan Load Balancing - Can't create routing tables.

one issue.
the migration scripts don't take into account older load balancing configs.

if the test > rule > type > ping isn't explicitly set then the rule defaults to the next hop address and ignores the rule entirely.
the default rule seems to be the next hop address for the interface.

May 11 2023, 10:56 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5171: Use XML for conf-mode "load-balancing wan" instead of legacy templates.

set default check type ping https://github.com/vyos/vyos-1x/pull/1998

May 11 2023, 10:55 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5213: Accel-ppp sending accounting interim updates acct-interim-interval option from In progress to Needs testing.
May 11 2023, 6:45 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T3829: Support separated TCP/IP stack via "ip netns".

Veth is not ready to work together with netns
As Interface moves entirely to logical stack and with the next commit will be recreated and try to move to netns again. As it doesn't see veth interface which moved to another logical stack, it tryes to recreate this interface.
We should either fix it or revert the previous commit.

May 11 2023, 3:46 AM · VyOS Rolling

May 10 2023

jestabro added a subtask for T2665: vyos.xml.defaults for tag nodes: T5218: Revise vyos xml lib for bug fixes and extensions.
May 10 2023, 10:17 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T5218: Revise vyos xml lib for bug fixes and extensions: T2665: vyos.xml.defaults for tag nodes.
May 10 2023, 10:16 PM · VyOS 1.4 Sagitta
jestabro added a comment to T5218: Revise vyos xml lib for bug fixes and extensions.

PR:
https://github.com/vyos/vyos-1x/pull/1997
This will remain in draft until corresponding PR fro vyos1x-config is merged.

May 10 2023, 10:16 PM · VyOS 1.4 Sagitta
jestabro changed the status of T5218: Revise vyos xml lib for bug fixes and extensions from Open to In progress.
May 10 2023, 10:01 PM · VyOS 1.4 Sagitta
syncer changed the status of T3829: Support separated TCP/IP stack via "ip netns" from Open to In progress.
May 10 2023, 7:27 PM · VyOS Rolling
syncer changed the status of T160: Support NAT64 from Open to In progress.
May 10 2023, 7:08 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav updated the task description for T5217: Add firewall SYNPROXY .
May 10 2023, 2:29 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5217: Add firewall SYNPROXY .

Add kernel module https://github.com/vyos/vyos-build/pull/348

May 10 2023, 1:05 PM · VyOS 1.4 Sagitta
Viacheslav created T5217: Add firewall SYNPROXY .
May 10 2023, 11:45 AM · VyOS 1.4 Sagitta
aserkin removed a watcher for VyOS 1.4 Sagitta: aserkin.
May 10 2023, 11:40 AM
Viacheslav closed T5209: dhclient load-balancing exit hook 04-dhcp-wanlb returned non-zero exit status as Resolved.
May 10 2023, 9:51 AM · VyOS 1.4 Sagitta
Viacheslav closed T5060: add a VRRP 'maintenance mode' as Resolved.
May 10 2023, 9:48 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5213: Accel-ppp sending accounting interim updates acct-interim-interval option.

PR for L2TP https://github.com/vyos/vyos-1x/pull/1988

May 10 2023, 9:39 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
a.apostoliuk added a comment to T5197: Conntrack-sync external cache commit error.

Not working. The same errors

May 10 2023, 9:32 AM · VyOS 1.4 Sagitta
Viacheslav closed T5065: Mixing `destination port xxx` and `destination group port-group yyy` in firewall rules doesn't work, but can be commited as Resolved.
May 10 2023, 8:10 AM · VyOS 1.4 Sagitta
Viacheslav created T5216: Add encrypting syslog traffic with TLS (SSL).
May 10 2023, 7:29 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5144: Modernize dynamic dns operation from Open to Needs testing.
May 10 2023, 7:20 AM · VyOS 1.4 Sagitta