Page MenuHomeVyOS Platform
Feed All Stories

Aug 12 2023

dsummers added a comment to T4818: IPv6 NDP not working everytime.
  1. Vyos Router <-> Switch <-> Multiple Computers
Aug 12 2023, 2:49 PM · VyOS Rolling, Restricted Project
tkmr_akhs created T5469: Incorrect dependency set in the openvpn-dco package when building VyOS for arm64.
Aug 12 2023, 8:53 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5090: Add support for disk encryption during installation.

A workaround in the meantime:

Aug 12 2023, 8:24 AM · VyOS 1.5 Circinus
c-po committed rVYOSONEX011697508b1f: T5467: removing ospf(v3) or isis interface in VRF context did not clear FRR….
Aug 12 2023, 7:02 AM
c-po closed T5467: ospf(v3): removing an interface from the OSPF process does not clear FRR configuration as Resolved.
Aug 12 2023, 7:02 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5090: Add support for disk encryption during installation.

And in that case the attacker would just replace your router with their own since they already got physical access to the box.

Aug 12 2023, 6:40 AM · VyOS 1.5 Circinus
Apachez created T5468: Remove unused manpages to free up space.
Aug 12 2023, 6:32 AM · VyOS 1.4 Sagitta
giga1699 added a comment to T5090: Add support for disk encryption during installation.

There are use cases when it would be ideal to force a password at boot to protect the contents of the configuration. For example, a portable router with sensitive keys meant for temporary network connectivity.

Aug 12 2023, 6:22 AM · VyOS 1.5 Circinus
Apachez added a comment to T5090: Add support for disk encryption during installation.

The problem is how to make sure that the router can boot and reboot (for example "set system option reboot-on-panic" is handy) on itself without somebody having to connect to its console before it starts to function again. Really shitty situation for a remote site because then somebody needs to visit it aswell.

Aug 12 2023, 5:30 AM · VyOS 1.5 Circinus
Viacheslav committed rVYOSONEX58a20e42087c: vyos.util: extend process_named_running() signature with cmdline (authored by c-po).
Aug 12 2023, 5:28 AM
GitHub <[email protected]> committed rVYOSONEX616bdb5299bf: Merge pull request #2127 from sever-sever/T2298-eq (authored by c-po).
Aug 12 2023, 5:28 AM
Apachez added a comment to T4818: IPv6 NDP not working everytime.
  1. How is the physical topology (can you provide a drawing)?
Aug 12 2023, 5:17 AM · VyOS Rolling, Restricted Project
dsummers added a comment to T4818: IPv6 NDP not working everytime.

I am having this exact problem and it evidently has been a problem for quite a few years.

Aug 12 2023, 4:31 AM · VyOS Rolling, Restricted Project
giga1699 added a comment to T5090: Add support for disk encryption during installation.

Can this be accomplished with LUKS?

Aug 12 2023, 4:24 AM · VyOS 1.5 Circinus

Aug 11 2023

n.fort changed the status of T5460: Firewall - remove config-trap from Confirmed to Needs testing.
Aug 11 2023, 10:21 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX073961a5c833: ipv6: T5464: add support for per-interface dad (duplicate address detection)….
Aug 11 2023, 9:02 PM
c-po committed rVYOSONEX63a8d17b8959: ipv6: T5464: use proper XML default for DAD transmits.
Aug 11 2023, 9:02 PM
c-po closed T5464: ipv6: add support for per-interface dad (duplicate address detection) setting as Resolved.
Aug 11 2023, 9:01 PM · VyOS 1.4 Sagitta
c-po added a comment to T5463: Containers allow publish IPv6 address port.

That CLI node ipv6 only implements a minor subset of the entire featureset of port forwarding.

Aug 11 2023, 8:59 PM · VyOS 1.4 Sagitta
c-po changed the status of T5467: ospf(v3): removing an interface from the OSPF process does not clear FRR configuration from Open to In progress.
Aug 11 2023, 8:52 PM · VyOS 1.4 Sagitta
c-po created T5467: ospf(v3): removing an interface from the OSPF process does not clear FRR configuration.
Aug 11 2023, 8:52 PM · VyOS 1.4 Sagitta
n.fort committed rVYOSONEXa8244928af84: T5160: firewall refactor: new cli structure. Update jinja templates, python….
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEX1c2209c1dc84: T5160: firewall refactor: new cli structure. Update only all xml.
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEXac5b9a4630f8: T5160: firewall refactor: new cli structure. Add migration script and update….
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEXdbf7501d0c75: T5160: firewall refactor: re-add missing code in template.py which was….
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEX68d14fe80145: T5160: firewall refactor: change firewall ip to firewall ipv4.
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEX342db936a02a: T5160: firewall refactor. Update op-mode commands to new syntax..
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEXd898739b78f4: T5160: T5250: while refactoring, fix reference column for op-mode command….
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEX68694d022d8f: T5160: firewal refactor: fix tabulation for geo-ip parsing code. Typo fix in….
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEX0300bf433d9a: T5160: firewall refactor: move <set firewall ipv6 ipv6-name ...> to <set….
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEXdbb069151f37: T5160: firewall refactor: fix firewall template for correct rule parsing that….
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEXa07a46d5d4ac: T5160: firewall refactor: change default value for <default-action> from <drop>….
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEXf57ad85b346a: T5160: firewall refactor: fix regexep for connection-status. Create new file….
Aug 11 2023, 8:14 PM
n.fort committed rVYOSONEX4e07fa25f551: T5460: remove config-trap from firewall.
Aug 11 2023, 8:14 PM
GitHub <[email protected]> committed rVYOSONEX482f7e352272: Merge pull request #2016 from nicolas-fort/T5160 (authored by c-po).
Aug 11 2023, 8:14 PM
fernando claimed T5466: L3VPN - label allocation mode .
Aug 11 2023, 8:00 PM · VyOS 1.4 Sagitta
fernando created T5466: L3VPN - label allocation mode .
Aug 11 2023, 7:59 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX71148df948b9: T5448: Move zabbix-agent to node monitoring.
Aug 11 2023, 7:57 PM
GitHub <[email protected]> committed rVYOSONEX142ace2a16fc: Merge pull request #2148 from sever-sever/T5448 (authored by dmbaturin).
Aug 11 2023, 7:57 PM
fernando added a comment to T5456: Add alias for "show ipv6 bgp".

Adding comments : maybe discontinue show ip bgp gives some issues / problems with automation tools (ansible o some custom script)While thinking out loud, it can be useful for new users create to alias.

Aug 11 2023, 7:49 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5456: Add alias for "show ipv6 bgp".

Its not possible to "symlink" it?

Aug 11 2023, 7:26 PM · VyOS 1.4 Sagitta
c-po closed T5465: adjust-mss: config migration fails if applied to a VLAN or Q-in-Q interface, a subtask of T3090: Move 'adjust-mss' firewall options to the interface section., as Resolved.
Aug 11 2023, 7:24 PM · VyOS 1.4 Sagitta
c-po closed T5465: adjust-mss: config migration fails if applied to a VLAN or Q-in-Q interface as Resolved.
Aug 11 2023, 7:24 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXf8b60fff531e: interface: T5465: adjust-mss: config migration fails if applied to a VLAN or Q….
Aug 11 2023, 7:24 PM
c-po changed the status of T5465: adjust-mss: config migration fails if applied to a VLAN or Q-in-Q interface, a subtask of T3090: Move 'adjust-mss' firewall options to the interface section., from Open to In progress.
Aug 11 2023, 7:21 PM · VyOS 1.4 Sagitta
c-po changed the status of T5465: adjust-mss: config migration fails if applied to a VLAN or Q-in-Q interface from Open to In progress.
Aug 11 2023, 7:21 PM · VyOS 1.4 Sagitta
c-po created T5465: adjust-mss: config migration fails if applied to a VLAN or Q-in-Q interface.
Aug 11 2023, 7:20 PM · VyOS 1.4 Sagitta
c-po added a comment to T5456: Add alias for "show ipv6 bgp".

Unfortunately this is "not that easy" as out CLI commands are passed down to FRR raw.

Aug 11 2023, 7:10 PM · VyOS 1.4 Sagitta
c-po moved T5459: ospfv3: add authentication support from Open to In Progress on the VyOS 1.4 Sagitta board.
Aug 11 2023, 7:09 PM · VyOS Rolling
c-po moved T5461: Improve rootfs directory variable from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 11 2023, 7:09 PM · VyOS 1.4 Sagitta
c-po moved T5464: ipv6: add support for per-interface dad (duplicate address detection) setting from Open to In Progress on the VyOS 1.4 Sagitta board.
Aug 11 2023, 7:08 PM · VyOS 1.4 Sagitta
GitHub <[email protected]> committed rVYOSONEX11f46a2b4f85: T5440: Restore pre/postconfig scripts if user deleted them (authored by Apachez).
Aug 11 2023, 6:27 PM
c-po claimed T5464: ipv6: add support for per-interface dad (duplicate address detection) setting.
Aug 11 2023, 6:18 PM · VyOS 1.4 Sagitta
c-po created T5464: ipv6: add support for per-interface dad (duplicate address detection) setting.
Aug 11 2023, 6:15 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5462: Add actual Openssl version 1.1.1v.
Aug 11 2023, 3:54 PM · VyOS 1.3 Equuleus (1.3.5)
Apachez added a comment to T5456: Add alias for "show ipv6 bgp".

But at the same time it would help others who migrate to VyOS from Cisco, Arista etc.

Aug 11 2023, 3:17 PM · VyOS 1.4 Sagitta
jestabro closed T2665: vyos.xml.defaults for tag nodes as Resolved.
Aug 11 2023, 2:31 PM · VyOS 1.4 Sagitta
jestabro closed T5434: Replace remaining calls of vyos.xml library, a subtask of T5218: Revise vyos xml lib for bug fixes and extensions, as Resolved.
Aug 11 2023, 2:30 PM · VyOS 1.4 Sagitta
jestabro closed T5434: Replace remaining calls of vyos.xml library as Resolved.
Aug 11 2023, 2:30 PM · VyOS 1.4 Sagitta
jestabro closed T5319: Remove remaining workarounds for incorrect defaults, a subtask of T5308: Remove workarounds for incorrect defaults in get_interface_dict, as Resolved.
Aug 11 2023, 2:30 PM · VyOS 1.4 Sagitta
jestabro closed T5319: Remove remaining workarounds for incorrect defaults as Resolved.
Aug 11 2023, 2:30 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5463: Containers allow publish IPv6 address port.
Aug 11 2023, 1:39 PM · VyOS 1.4 Sagitta
Viacheslav created T5463: Containers allow publish IPv6 address port.
Aug 11 2023, 1:37 PM · VyOS 1.4 Sagitta
Viacheslav renamed T5462: Add actual Openssl version 1.1.1v from Add acual Openssl version 1.1.1v to Add actual Openssl version 1.1.1v.
Aug 11 2023, 12:09 PM · VyOS 1.3 Equuleus (1.3.5)
fernando added a comment to T5456: Add alias for "show ipv6 bgp".

show ip bgp is an old command, it comes from quagga ...So in my point of view , adding more command to do the same , could generate more confusion . show bgp address-family should be used.

Aug 11 2023, 12:09 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5462: Add actual Openssl version 1.1.1v from "Bug" to "Feature Request".
Aug 11 2023, 12:06 PM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav created T5462: Add actual Openssl version 1.1.1v.
Aug 11 2023, 12:06 PM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav moved T5416: Ignoring "ipsec match-none" for firewall from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 11 2023, 8:18 AM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX378c99fd3782: T5434: replace import of component_version.
Aug 11 2023, 8:03 AM
jestabro committed rVYOSONEX7ed15c92160a: xml: T5218: fix typo in component_version.
Aug 11 2023, 8:03 AM
jestabro committed rVYOSONEX2087d4cb4577: T5319: remove workaround in op-mode show_openconnect_otp.py.
Aug 11 2023, 8:03 AM
jestabro committed rVYOSONEXa34cd5dac7d3: T5434: remove unneeded import.
Aug 11 2023, 8:03 AM
jestabro committed rVYOSONEX0a9b8069155c: T5434: use auto-defaults in op-mode pki.py.
Aug 11 2023, 8:03 AM
jestabro committed rVYOSONEX039116367d8c: T5434: use get_defaults instead of defaults.
Aug 11 2023, 8:03 AM
jestabro committed rVYOSONEX7978ac921fab: T5434: use package specific cache in nosetests.
Aug 11 2023, 8:03 AM
jestabro committed rVYOSONEX549a199e96c9: T5434: drop unneeded cache generation from old lib.
Aug 11 2023, 8:03 AM
jestabro committed rVYOSONEXd64d3b179ce4: T5319: remove defaults workarounds in vyos-domain-resolver.py.
Aug 11 2023, 8:03 AM
GitHub <[email protected]> committed rVYOSONEX43294da10313: Merge pull request #2147 from jestabro/remaining-defaults (authored by Viacheslav).
Aug 11 2023, 8:03 AM
Apachez added a comment to T5461: Improve rootfs directory variable.

PR created: https://github.com/vyos/vyatta-op/pull/66

Aug 11 2023, 7:25 AM · VyOS 1.4 Sagitta
Apachez claimed T5461: Improve rootfs directory variable.
Aug 11 2023, 7:10 AM · VyOS 1.4 Sagitta
Apachez created T5461: Improve rootfs directory variable.
Aug 11 2023, 7:09 AM · VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEXe7d7bd20b8fa: openvpn: T5270: do not require classic DH params in any more.
Aug 11 2023, 5:54 AM
GitHub <[email protected]> committed rVYOSONEX4659f25804bd: Merge pull request #2146 from dmbaturin/T5270-openvpn-dh-optional (authored by c-po).
Aug 11 2023, 5:54 AM

Aug 10 2023

Apachez added a comment to T5460: Firewall - remove config-trap.

Its good for traceability to get a snmp trap sent when the firewall config has been altered/changed/(re-)applied.

Aug 10 2023, 9:30 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5460: Firewall - remove config-trap from Open to Confirmed.
Aug 10 2023, 7:04 PM · VyOS 1.4 Sagitta
n.fort created T5460: Firewall - remove config-trap.
Aug 10 2023, 7:04 PM · VyOS 1.4 Sagitta
n.fort closed T5416: Ignoring "ipsec match-none" for firewall as Resolved.
Aug 10 2023, 6:54 PM · VyOS 1.4 Sagitta
n.fort claimed T5453: Fix nat66 - broken after load-balance was introduced in nat.
Aug 10 2023, 6:38 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXf9acf743cc27: T5448: Add service zabbix-agent version 2.
Aug 10 2023, 3:09 PM
GitHub <[email protected]> committed rVYOSONEXbfbd7273b331: Merge pull request #2140 from sever-sever/T5448 (authored by dmbaturin).
Aug 10 2023, 3:09 PM
Apachez added a comment to T5458: USB Console options is missing for a new image after "add system image" upgrade.

Yeah, no worries.

Aug 10 2023, 2:28 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Apachez added a comment to T5457: Add environmental variable pointing to current rootfs directory.

Im biased but here are my testresults using modified VyOS 1.4-rolling-202308060317:

Aug 10 2023, 2:20 PM · VyOS 1.4 Sagitta
c-po claimed T5459: ospfv3: add authentication support.
Aug 10 2023, 2:19 PM · VyOS Rolling
c-po created T5459: ospfv3: add authentication support.
Aug 10 2023, 2:18 PM · VyOS Rolling
unity added a comment to T5458: USB Console options is missing for a new image after "add system image" upgrade.

@Apachez thank you for your response 🙏
Sorry, I really have attached screenshots but didn't grant access to them. Fixed.

Aug 10 2023, 2:07 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav changed the status of T5457: Add environmental variable pointing to current rootfs directory from In progress to Needs testing.
Aug 10 2023, 1:57 PM · VyOS 1.4 Sagitta
Viacheslav closed T5329: Wireguard interface as GRE tunnel source causes configuration error on boot as Resolved.
Aug 10 2023, 1:56 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
n.fort added a comment to T660: 802.1p CoS priority support.

Some internal test where done, using integration between:

  • Traffic shaper. Currently supported in vyos cli
  • Bridge firewall. Currently not supported in vyos cli.
Aug 10 2023, 1:53 PM · VyOS Rolling
Viacheslav committed rVYOSONEXe27f566f0f65: T5329 : priority: tunnel config is committed before wireguard (authored by SrividyaA).
Aug 10 2023, 1:52 PM
GitHub <[email protected]> committed rVYOSONEX80465e2cb222: Merge pull request #2126 from sever-sever/T5329-eq (authored by c-po).
Aug 10 2023, 1:52 PM