Page MenuHomeVyOS Platform
Feed All Stories

Aug 25 2023

syncer edited projects for T5484: set extcommunity - just allow one extend community, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:29 PM
syncer edited projects for T5486: Service dns dynamic cannot pass the smoketest, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:29 PM · VyOS 1.3 Equuleus (1.3.5)
syncer edited projects for T5492: CLI node priority is not inversed on node deletion, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:29 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
syncer edited projects for T5506: Container bridge interfaces do not have a link-local address, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:29 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
syncer triaged T2934: proxy-arp-pvlan on VRRP interface as Low priority.
Aug 25 2023, 9:27 PM · Restricted Project, VyOS Rolling
syncer assigned T2934: proxy-arp-pvlan on VRRP interface to sever.
Aug 25 2023, 9:26 PM · Restricted Project, VyOS Rolling
syncer edited projects for T2612: HTTPS API, changing API key fails but goes through, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:25 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
syncer moved T5428: dhcp: client renewal fails when running inside VRF from Need Triage to Backlog on the VyOS 1.3 Equuleus (1.3.5) board.
Aug 25 2023, 9:25 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
syncer edited projects for T5428: dhcp: client renewal fails when running inside VRF, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:24 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
syncer moved T3424: PPPoE IA-PD doesn't work in VRF from Need Triage to In Progress on the VyOS 1.3 Equuleus (1.3.5) board.
Aug 25 2023, 9:22 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
syncer edited projects for T3424: PPPoE IA-PD doesn't work in VRF, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:22 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
syncer closed T4412: commit archive: reboot not working with sftp as Resolved.
Aug 25 2023, 9:19 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
syncer set the image for VyOS 1.3 Equuleus (1.3.5) to F3829672: profile.
Aug 25 2023, 9:18 PM
syncer created VyOS 1.3 Equuleus (1.3.5).
Aug 25 2023, 9:17 PM
Apachez added a comment to T5118: Cleanup vestigial ntp completion script.

The file list_ntp_servers.sh is nowhere to be found in VyOS 1.4-rolling-202308250021:

Aug 25 2023, 9:15 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5318: Security Vulnerabilities for VyOS 1.3.3 .

I assume this will fix by itself if you build your own 1.3.3 LTS from sources today since 1.3.3 LTS was released in june 2023:

Aug 25 2023, 9:08 PM · VyOS 1.3 Equuleus (1.3.6)
Apachez added a comment to T5408: 15-16 tacacs folders under /home directory.

I guess this can be closed by reason "Not a bug" or similar?

Aug 25 2023, 8:53 PM · VyOS 1.4 Sagitta
Apachez updated subscribers of T5414: dhcp-server does not allow valid bootfile-names.

Isnt this resolved now by the commit of @c-po at 2 aug?

Aug 25 2023, 8:51 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5460: Firewall - remove config-trap.

Using VyOS 1.4-rolling-202308250021 the option "config-trap" is no longer to be found and the remains of config-trap causing commit to crash with a traceback have also been fixed:

Aug 25 2023, 8:46 PM · VyOS 1.4 Sagitta
GitHub <[email protected]> committed rVYOSONEX564a2e6db19b: Update CONTRIBUTING.md (authored by c-po).
Aug 25 2023, 7:06 PM
Viacheslav moved T4825: interfaces veth/veth-pairs -standalone used from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.4) board.
Aug 25 2023, 6:48 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav added a project to T4825: interfaces veth/veth-pairs -standalone used: VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 6:48 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
n.fort committed rVYOSONEX1a2237ba91d5: T5502: firewall: add validator for interface matcher, and allow only interface….
Aug 25 2023, 6:03 PM
GitHub <[email protected]> committed rVYOSONEX3144b67f1b04: Merge pull request #2172 from nicolas-fort/T5502 (authored by c-po).
Aug 25 2023, 6:03 PM
n.fort changed the status of T5472: NAT redirect should not require port from In progress to Needs testing.
Aug 25 2023, 5:03 PM · VyOS 1.4 Sagitta
n.fort closed T5501: Firewall - Allow multiple inbound outbound interface as Invalid.

Closing this task because better way to match multiple interfaces in firewall rules would be using interface groups.

Aug 25 2023, 4:56 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX9763154d99f7: T4825: Add interface type veth.
Aug 25 2023, 4:40 PM
GitHub <[email protected]> committed rVYOSONEXa5c5998a8491: Merge pull request #2170 from sever-sever/T4825-eq (authored by c-po).
Aug 25 2023, 4:40 PM
sarthurdev committed rVYOSONEX8884f021582e: github: Add PR labels to easily identify base branches.
Aug 25 2023, 4:14 PM
GitHub <[email protected]> committed rVYOSONEX9e0ea586159b: Merge pull request #2169 from sarthurdev/current (authored by c-po).
Aug 25 2023, 4:14 PM
sarthurdev committed rVYOSONEX14c7264de462: container: T5463: Fix iteration to publish all port nodes.
Aug 25 2023, 4:12 PM
GitHub <[email protected]> committed rVYOSONEX2d2933788a4b: Merge pull request #2171 from sarthurdev/T5463_fix (authored by c-po).
Aug 25 2023, 4:12 PM
Apachez closed T5468: Remove unused manpages to free up space as Resolved.
Aug 25 2023, 3:46 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5468: Remove unused manpages to free up space.

Confirmed fixed in VyOS 1.4-rolling-202308250021:

Aug 25 2023, 3:45 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

@rherold Well thats how it is today with default-action:accept where ALL ports are open to ALL services on ALL interfaces.

Aug 25 2023, 2:24 PM · VyOS 1.4 Sagitta
Apachez created T5509: Add capability to add firewall rules similar to CoPP through VyOS configuration.
Aug 25 2023, 2:23 PM · VyOS 1.4 Sagitta
n.fort added a comment to T5508: Configuration Migration Fails to New Netfilter Firewall Syntax.

Missing vrrp cli version in last line in config.boot file:

Aug 25 2023, 2:16 PM · VyOS 1.4 Sagitta
rherold added a comment to T5160: Firewall refactor.

@Apachez I would also not want this. Example bgp on eth0 with one peer. I would not like to see to have the bgp port open for all source ips, only for the configured peers and not more.
To make it better to manage for the admins I would like to see a syntax like in junos:

Aug 25 2023, 2:00 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T5463: Containers allow publish IPv6 address port.

PR to fix indentation: https://github.com/vyos/vyos-1x/pull/2171

Aug 25 2023, 1:46 PM · VyOS 1.4 Sagitta
jagekurt attached a referenced file: F3829573: config.boot.2023-08-25-131058.pre-migration.
Aug 25 2023, 1:43 PM · VyOS 1.4 Sagitta
jagekurt attached a referenced file: F3829574: config.boot.
Aug 25 2023, 1:43 PM · VyOS 1.4 Sagitta
jagekurt attached a referenced file: F3829575: running.config.
Aug 25 2023, 1:43 PM · VyOS 1.4 Sagitta
jagekurt created T5508: Configuration Migration Fails to New Netfilter Firewall Syntax.
Aug 25 2023, 1:25 PM · VyOS 1.4 Sagitta
Viacheslav removed a project from T3459: Inform the user when unable to install outdated image: VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 10:29 AM · VyOS 1.4 Sagitta
Viacheslav closed T3536: Unable to list all available routes as Resolved.
Aug 25 2023, 10:25 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T3546: Add support for running scripts on PPPoE server session events.

PR f or 1.3.4 https://github.com/vyos/vyos-1x/pull/2168

Aug 25 2023, 10:18 AM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav changed the status of T3702: Policy: Allow routing by fwmark from Unknown Status to Resolved.
Aug 25 2023, 9:13 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T3774: atop logs are not limited in size.

@zsdc Can we backport it to 1.3?

Aug 25 2023, 9:08 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav closed T5463: Containers allow publish IPv6 address port as Resolved.
Aug 25 2023, 8:56 AM · VyOS 1.4 Sagitta

Aug 24 2023

aga added a comment to T5471: Conntrack logging doesnt seem to be working.

Can also confirm this on multiple nodes with said config, running post-firewall-refactor-builds.

Aug 24 2023, 7:46 PM · VyOS Rolling, Restricted Project
jestabro closed T4292: Rewrite vyatta-save-config.pl to Python, a subtask of T4291: Consolidate component version read/write functions, as Resolved.
Aug 24 2023, 7:32 PM · VyOS 1.4 Sagitta
jestabro closed T4292: Rewrite vyatta-save-config.pl to Python, a subtask of T4316: Update save-config/load-config, as Resolved.
Aug 24 2023, 7:32 PM · VyOS Rolling
jestabro closed T4292: Rewrite vyatta-save-config.pl to Python as Resolved.
Aug 24 2023, 7:32 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXe4831c7ac93c: save-config: T4292: rewrite vyatta-save-config.pl to Python.
Aug 24 2023, 6:38 PM
GitHub <[email protected]> committed rVYOSONEX5ea0428a08ae: Merge pull request #2164 from jestabro/save-config (authored by jestabro).
Aug 24 2023, 6:38 PM
jestabro changed the status of T5305: REST API configure operation should not be defined as async, a subtask of T5006: Http api segfault with concurrent requests, from Unknown Status to Resolved.
Aug 24 2023, 6:36 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jestabro changed the status of T5305: REST API configure operation should not be defined as async from Unknown Status to Resolved.
Aug 24 2023, 6:36 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jestabro changed the status of T5006: Http api segfault with concurrent requests from Unknown Status to Resolved.
Aug 24 2023, 6:36 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jestabro committed rVYOSONEX9f332dc34c93: http-api: T5006: add explicit async to retrieve operation.
Aug 24 2023, 6:17 PM
GitHub <[email protected]> committed rVYOSONEX115dd7858719: Merge pull request #2167 from jestabro/eq-T5006 (authored by c-po).
Aug 24 2023, 6:17 PM
Apachez added a comment to T5507: Improving Firewall Logs.

Related: https://vyos.dev/T5471

Aug 24 2023, 6:05 PM · VyOS Rolling
jestabro added a subtask for T5006: Http api segfault with concurrent requests: T5305: REST API configure operation should not be defined as async.
Aug 24 2023, 5:18 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jestabro added a parent task for T5305: REST API configure operation should not be defined as async: T5006: Http api segfault with concurrent requests.
Aug 24 2023, 5:18 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
aga updated the task description for T5507: Improving Firewall Logs.
Aug 24 2023, 4:20 PM · VyOS Rolling
aga created T5507: Improving Firewall Logs.
Aug 24 2023, 4:18 PM · VyOS Rolling
Viacheslav added a project to T5506: Container bridge interfaces do not have a link-local address: VyOS 1.3 Equuleus (1.3.4).
Aug 24 2023, 4:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX0f3749cb9414: T5506: Add link-local IPv6 address for container interfaces.
Aug 24 2023, 3:48 PM
GitHub <[email protected]> committed rVYOSONEX250a5d13c9e4: Merge pull request #2165 from sever-sever/T5506 (authored by c-po).
Aug 24 2023, 3:48 PM
Viacheslav changed the status of T5506: Container bridge interfaces do not have a link-local address from Open to In progress.
Aug 24 2023, 3:47 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav added a comment to T5506: Container bridge interfaces do not have a link-local address.

PR https://github.com/vyos/vyos-1x/pull/2165

Aug 24 2023, 3:47 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav added a comment to T5463: Containers allow publish IPv6 address port.

Will be fixed in https://vyos.dev/T5506

Aug 24 2023, 3:20 PM · VyOS 1.4 Sagitta
Viacheslav created T5506: Container bridge interfaces do not have a link-local address.
Aug 24 2023, 3:19 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po changed the status of T3424: PPPoE IA-PD doesn't work in VRF from Resolved to Unknown Status.
Aug 24 2023, 1:59 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po committed rVYOSONEX4ea1b1506940: smoketest: T5447: wpa_supplicant is only run if required.
Aug 24 2023, 1:58 PM
c-po committed rVYOSONEX3baba6b47740: system: T5505: fix zebra route-map is not removed from FRR.
Aug 24 2023, 1:58 PM
c-po closed T5505: system: zebra route-map is not removed from FRR , a subtask of T5150: Rework CLI definitions to apply route-maps between routing daemons and zebra/kernel, as Resolved.
Aug 24 2023, 1:55 PM · VyOS 1.4 Sagitta
c-po closed T5505: system: zebra route-map is not removed from FRR as Resolved.
Aug 24 2023, 1:55 PM · VyOS 1.4 Sagitta
c-po created T5505: system: zebra route-map is not removed from FRR .
Aug 24 2023, 1:54 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5463: Containers allow publish IPv6 address port.

In my internal tests, it works even without listen-address

set container name c1 image 'docker.io/ealen/echo-server'
set container name c1 network NET01
set container name c1 port web destination '80'
set container name c1 port web source '8080'
set container network NET01 prefix '10.0.0.0/24'
set container network NET01 prefix '2001:db8:2222::/64'
set interfaces dummy dum0 address '2001:db8:1111::1/64'
set interfaces dummy dum0 address '203.0.113.1/32'
Aug 24 2023, 1:27 PM · VyOS 1.4 Sagitta
Viacheslav created T5504: Make it possible to set more than one peer-address in unicast VRRP.
Aug 24 2023, 11:03 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.3 Equuleus (1.3.7)
Viacheslav closed T5448: Add service zabbix-agent, a subtask of T118: Native Zabbix Support, as Resolved.
Aug 24 2023, 9:14 AM · Restricted Project, VyOS 1.4 Sagitta
Viacheslav closed T5448: Add service zabbix-agent as Resolved.
Aug 24 2023, 9:14 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5497: Add ability to resequence rule numbers for firewall.

@Apachez, I got your point. The thing is, we don't have cisco-like CLI and can modify any seq rule.
It possibly could be from op-mode (not sure) because otherwise, you get resequence per each commit. That is definitely wrong.

Aug 24 2023, 8:48 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

Yes but if you have more than a few rules its shitty to have to do this manually.

Aug 24 2023, 8:37 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav added a comment to T5497: Add ability to resequence rule numbers for firewall.

If it is only per migration, you can change it in migration or rewrite the rules once.

Aug 24 2023, 8:33 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez added a comment to T5160: Firewall refactor.

Then perhaps add it as an global-option or similar to make life easier for the admin to not having to dig into how each service should have the firewall configured in order to make it work properly?

Aug 24 2023, 8:32 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5160: Firewall refactor.

The firewall will not be autoconfigured by bgpd or something else. We are not going to do it.

Aug 24 2023, 8:22 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

@giga1699 Again, if I as an administrator enable BGP and configure it with "neighbor x.x.x.x" I expect this to work without having to setting up multiple additional firewall rules on my own. Same goes with if I enable DHCP-server on the VyOS - I expect it to work.

Aug 24 2023, 8:03 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5468: Remove unused manpages to free up space.

PR created (which replaces previous PR 378): https://github.com/vyos/vyos-build/pull/379

Aug 24 2023, 7:26 AM · VyOS 1.4 Sagitta
twan added a comment to T5498: fsck during boot doesnt work.

No, setting boot=local will run a completely different set of ("vanilla") boot-scripts, which (i guess) will not set up the special mounts that VyOS requires, and you will end up in initramfs with an error.

Aug 24 2023, 6:47 AM · VyOS Rolling, Restricted Project
jamcole added a comment to T5463: Containers allow publish IPv6 address port.

Thanks for adding the "listen-address" configuration option, unfortunately that alone may not be enough to make ipv6 services work on rootful podman. I didn't realize this since I primarily use rootless podman on my Fedora and SuSE machines or docker on the server side.

Aug 24 2023, 2:44 AM · VyOS 1.4 Sagitta

Aug 23 2023

sarthurdev claimed T3509: No BCP38 for IPv6 on VyOS.

Draft PR: https://github.com/vyos/vyos-1x/pull/2163

Aug 23 2023, 11:52 PM · VyOS 1.4 Sagitta
giga1699 added a comment to T5160: Firewall refactor.

@jworrell I agree that if an administrator turns on a service it should be functional. If no firewall is configured, and a security ruleset isn't required for the use case, there's no issue with something being in place that allows that traffic for extra comfort. However, if security rules are in place it should be the burden of the administrator to define how that management traffic should be handled. This would be consistent with previous versions of VyOS that if you applied a default-deny to the local direction of an interface, you would need to specify any management traffic for the interface explicitly. By introducing hidden allows, this would violate the principle of least surprise that you mentioned.

Aug 23 2023, 11:31 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5468: Remove unused manpages to free up space.

PR created: https://github.com/vyos/vyos-build/pull/378

Aug 23 2023, 10:37 PM · VyOS 1.4 Sagitta
Apachez claimed T5468: Remove unused manpages to free up space.
Aug 23 2023, 10:26 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5503: Nightly-builds is missing a latest.iso to be used with add system image.

Include VyOS functions

source /opt/vyatta/etc/functions/script-template

Aug 23 2023, 9:25 PM · VyOS 1.4 Sagitta
Apachez updated the task description for T5497: Add ability to resequence rule numbers for firewall.
Aug 23 2023, 8:34 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez closed T5478: Cannot configure resolver-cache options for firewall as Resolved.
Aug 23 2023, 8:27 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5478: Cannot configure resolver-cache options for firewall.

Verified being fixed in VyOS 1.4-rolling-202308230020.

Aug 23 2023, 8:27 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5463: Containers allow publish IPv6 address port from In progress to Needs testing.
Aug 23 2023, 8:16 PM · VyOS 1.4 Sagitta