Page MenuHomeVyOS Platform
Feed Search

Sep 4 2023

Apachez attached a referenced file: F3846129: T5549_Lynis_audit_system_230904.txt.gz.
Sep 4 2023, 6:26 PM · Invalid
Apachez added a comment to T5549: Result of system audit by Lynis.

Sep 4 2023, 6:26 PM · Invalid
Apachez created T5549: Result of system audit by Lynis.
Sep 4 2023, 6:23 PM · Invalid

Sep 3 2023

Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Disabling all validators for both vyatta-cfg and vyatta-op bring the boot time down to approx 73 seconds.

Sep 3 2023, 9:41 PM · VyOS Rolling, Bugs
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Modifying node.def (comment out "syntax:expression:") recursively in the paths of:

Sep 3 2023, 9:11 PM · VyOS Rolling, Bugs
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Moving along in the blamegame I will after a tip try to disable the various validators being runned.

Sep 3 2023, 8:56 PM · VyOS Rolling, Bugs
Apachez added a comment to T2431: Python validators are slow.

Any updates to this?

Sep 3 2023, 8:28 PM · VyOS 1.3 Equuleus (1.3.6)
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Can be related: https://vyos.dev/T2431

Sep 3 2023, 7:14 PM · VyOS Rolling, Bugs
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Continued debugging by also modifying /usr/libexec/vyos/services/vyos-configd by adding:

Sep 3 2023, 7:10 PM · VyOS Rolling, Bugs
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Attempted some debugging on this issue.

Sep 3 2023, 6:43 PM · VyOS Rolling, Bugs
Apachez added a comment to T5544: Allow CAP_SYS_MODULE to be set on containers .

According to https://man7.org/linux/man-pages/man7/capabilities.7.html this capability can load, unload AND delete kernel modules.

Sep 3 2023, 4:27 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5532: After add system image the boot stuck and works again after the second reboot.

Still occurs for:

Sep 3 2023, 6:10 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR created: https://github.com/vyos/vyos-build/pull/392

Sep 3 2023, 5:17 AM · VyOS 1.4 Sagitta
Apachez closed T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos as Resolved.
Sep 3 2023, 5:04 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.

Verified working with VyOS 1.4-rolling-202309030023.

Sep 3 2023, 5:03 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.

Was missing quotes around the variable within lb_config_tmpl like so:

Sep 3 2023, 5:02 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Some further testing:

Sep 3 2023, 4:57 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Reference to https://jonathancarter.org/2015/04/06/squashfs-performance-testing/ using 1M blocksize will give approx the same readspeed as with default 128k blocksize but result in an even smaller file.

Sep 3 2023, 4:02 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Regarding filesystem.squashfs the changes through changed mksquashfs syntax are:

Sep 3 2023, 2:48 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Was missing quotes around the variable within lb_config_tmpl like so:

Sep 3 2023, 2:01 AM · VyOS 1.4 Sagitta

Sep 2 2023

Apachez added a comment to T5541: Zone-Based Firewalling in VyOS Sagitta 1.4.

The firewall refactoring released 4th aug 2023 only (so far) took care about the documentation in the configuration section:

Sep 2 2023, 1:20 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez claimed T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.
Sep 2 2023, 11:19 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.

PR created: https://github.com/vyos/vyos-build/pull/391

Sep 2 2023, 11:00 AM · VyOS 1.4 Sagitta
Apachez claimed T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.
Sep 2 2023, 10:45 AM · VyOS 1.4 Sagitta
Apachez created T5538: Change order within variable lb_config_tmpl to fit order of manpage and fix some typos.
Sep 2 2023, 10:45 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR created: https://github.com/vyos/vyos-build/pull/390

Sep 2 2023, 1:27 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR389 build failed:

Sep 2 2023, 1:18 AM · VyOS 1.4 Sagitta

Sep 1 2023

Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

PR created: https://github.com/vyos/vyos-build/pull/389

Sep 1 2023, 7:57 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5534: VRRP rfc3768-compatibility broken after build 1.4-rolling-202308260020.

There was a similar case where it turned out that INPUT/OUTPUT chains for the firewall must be updated to include the stuff VRRP is doing.

Sep 1 2023, 12:22 PM
Apachez added a comment to T5536: show dhcp client leases caues No module named 'vyos.validate'.

Reported in: https://forum.vyos.io/t/error-show-dhcp-lease/12030

Sep 1 2023, 12:12 PM · VyOS 1.4 Sagitta
Apachez closed T5537: show dhcp client leases fails to complete as Invalid.

See this task instead: https://vyos.dev/T5536

Sep 1 2023, 12:11 PM · VyOS 1.4 Sagitta
Apachez created T5537: show dhcp client leases fails to complete.
Sep 1 2023, 12:10 PM · VyOS 1.4 Sagitta

Aug 31 2023

Apachez created T5535: Move disable-directed-broadcast to firewall global-options.
Aug 31 2023, 5:23 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Apachez changed the status of T5513: Anomalies in show firewall command after refactoring from Needs testing to Open.
Aug 31 2023, 10:47 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5513: Anomalies in show firewall command after refactoring.
  1. Error in show firewall group:
Aug 31 2023, 10:47 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5532: After add system image the boot stuck and works again after the second reboot.

I can confirm that I experienced the same thing with update to VyOS 1.4-rolling-202308310021.

Aug 31 2023, 10:22 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5523: CVE-2023-38802.

I assume backports will be used once VyOS 1.3.4 gets compiled?

Aug 31 2023, 10:14 AM · VyOS 1.3 Equuleus

Aug 30 2023

Apachez added a comment to T5522: Add logging for which mksquashfs syntax is being used.

PR1 didnt seem to have any affect on this night build:

Aug 30 2023, 4:19 AM · VyOS Rolling

Aug 28 2023

Apachez added a comment to T5522: Add logging for which mksquashfs syntax is being used.

PR created: https://github.com/vyos/vyos-live-build/pull/1

Aug 28 2023, 10:31 PM · VyOS Rolling
Apachez claimed T5522: Add logging for which mksquashfs syntax is being used.
Aug 28 2023, 10:11 PM · VyOS Rolling
Apachez created T5522: Add logging for which mksquashfs syntax is being used.
Aug 28 2023, 10:11 PM · VyOS Rolling
Apachez added a comment to T1289: route-map set route-type blackhole.

Can be resolved by route-map acting on community (for example <ASN>:888) and setting nexthop to 192.0.2.1 (optional tag 666) or for IPv6 set nexthop 0100:: along with a static route where 192.0.2.1/32 and 0100::/64 have null0 as nexthop.

Aug 28 2023, 12:48 PM · VyOS 1.3 Equuleus (1.3.5)
Apachez added a comment to T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.

Some tests on filesystem.squashfs from VyOS 1.4-rolling-202308280021.

Aug 28 2023, 3:34 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5511: Cleanup of unused directories (and files) in order to shrink image-size.

A note from https://forum.vyos.io/t/clear-logs-on-vyos/6878/10?u=viacheslav that there might be issues if removing directories from within / var/log/* doesnt occur to PR381 since that PR was specific about which files and directories to remove when it comes to / var/log. That is only files NOT directories were removed from / var/log.

Aug 28 2023, 1:19 AM · VyOS 1.4 Sagitta

Aug 27 2023

Apachez added a comment to T5499: initial arm64 support for RPI4 and QEMU VM.

A baseline could be to look at the linux kernel config used by Alpine Linux for their RPI-builds:

Aug 27 2023, 5:03 PM
Apachez reopened T5495: Enable snmp module also for frr/ldpd as "Open".

Just a comment:

Aug 27 2023, 3:47 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled.

So how are all the other helpers added to the ruleset if not dynamically?

Aug 27 2023, 10:12 AM · VyOS 1.4 Sagitta
Apachez created T5516: Add missing conntrack helpers which are available in kernel and userspace conntrackd.
Aug 27 2023, 10:00 AM · VyOS Rolling
Apachez created T5515: Conntrack helpers should be disabled by default.
Aug 27 2023, 9:44 AM · VyOS 1.4 Sagitta
Apachez created T5514: Improve error handling when/if config.boot is deleted or missing .
Aug 27 2023, 9:40 AM · VyOS 1.4 Sagitta (1.4.1)
Apachez reopened T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled as "Open".

Then how come these helpers are always enabled as pointed out at https://vyos.dev/T5080#149232 ?

Aug 27 2023, 8:38 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5080: Disable conntrack by default.

How come these helpers (pointed out by @saintclairpcarvalho but also )https://vyos.dev/T5479) are always enabled?

Aug 27 2023, 8:31 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Apachez added a comment to T5160: Firewall refactor.

Found some anomalies regarding show firewall command (I assume related to the refactoring) which I have reported in https://vyos.dev/T5513

Aug 27 2023, 1:05 AM · VyOS 1.4 Sagitta
Apachez created T5513: Anomalies in show firewall command after refactoring.
Aug 27 2023, 1:03 AM · VyOS 1.4 Sagitta

Aug 26 2023

Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

The refactored firewall frontend uses rule numbers as described in: https://docs.vyos.io/en/latest/configuration/firewall/general.html#firewall-rules

Aug 26 2023, 11:28 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez added a comment to T5511: Cleanup of unused directories (and files) in order to shrink image-size.

PR created: https://github.com/vyos/vyos-build/pull/381

Aug 26 2023, 11:06 PM · VyOS 1.4 Sagitta
Apachez claimed T5511: Cleanup of unused directories (and files) in order to shrink image-size.
Aug 26 2023, 10:36 PM · VyOS 1.4 Sagitta
Apachez created T5511: Cleanup of unused directories (and files) in order to shrink image-size.
Aug 26 2023, 2:19 AM · VyOS 1.4 Sagitta
Apachez created T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.
Aug 26 2023, 2:06 AM · VyOS 1.4 Sagitta

Aug 25 2023

Apachez added a comment to T5112: Enable support for Network Time Security (NTS) for chrony.

Using VyOS 1.4-rolling-202308250021.

Aug 25 2023, 10:01 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5118: Cleanup vestigial ntp completion script.

The file list_ntp_servers.sh is nowhere to be found in VyOS 1.4-rolling-202308250021:

Aug 25 2023, 9:15 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5318: Security Vulnerabilities for VyOS 1.3.3 .

I assume this will fix by itself if you build your own 1.3.3 LTS from sources today since 1.3.3 LTS was released in june 2023:

Aug 25 2023, 9:08 PM · VyOS 1.3 Equuleus (1.3.6)
Apachez added a comment to T5408: 15-16 tacacs folders under /home directory.

I guess this can be closed by reason "Not a bug" or similar?

Aug 25 2023, 8:53 PM · VyOS 1.4 Sagitta
Apachez updated subscribers of T5414: dhcp-server does not allow valid bootfile-names.

Isnt this resolved now by the commit of @c-po at 2 aug?

Aug 25 2023, 8:51 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5460: Firewall - remove config-trap.

Using VyOS 1.4-rolling-202308250021 the option "config-trap" is no longer to be found and the remains of config-trap causing commit to crash with a traceback have also been fixed:

Aug 25 2023, 8:46 PM · VyOS 1.4 Sagitta
Apachez closed T5468: Remove unused manpages to free up space as Resolved.
Aug 25 2023, 3:46 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5468: Remove unused manpages to free up space.

Confirmed fixed in VyOS 1.4-rolling-202308250021:

Aug 25 2023, 3:45 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

@rherold Well thats how it is today with default-action:accept where ALL ports are open to ALL services on ALL interfaces.

Aug 25 2023, 2:24 PM · VyOS 1.4 Sagitta
Apachez created T5509: Add capability to add firewall rules similar to CoPP through VyOS configuration.
Aug 25 2023, 2:23 PM · VyOS 1.4 Sagitta

Aug 24 2023

Apachez added a comment to T5507: Improving Firewall Logs.

Related: https://vyos.dev/T5471

Aug 24 2023, 6:05 PM · VyOS Rolling
Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

Yes but if you have more than a few rules its shitty to have to do this manually.

Aug 24 2023, 8:37 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez added a comment to T5160: Firewall refactor.

Then perhaps add it as an global-option or similar to make life easier for the admin to not having to dig into how each service should have the firewall configured in order to make it work properly?

Aug 24 2023, 8:32 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

@giga1699 Again, if I as an administrator enable BGP and configure it with "neighbor x.x.x.x" I expect this to work without having to setting up multiple additional firewall rules on my own. Same goes with if I enable DHCP-server on the VyOS - I expect it to work.

Aug 24 2023, 8:03 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5468: Remove unused manpages to free up space.

PR created (which replaces previous PR 378): https://github.com/vyos/vyos-build/pull/379

Aug 24 2023, 7:26 AM · VyOS 1.4 Sagitta

Aug 23 2023

Apachez added a comment to T5468: Remove unused manpages to free up space.

PR created: https://github.com/vyos/vyos-build/pull/378

Aug 23 2023, 10:37 PM · VyOS 1.4 Sagitta
Apachez claimed T5468: Remove unused manpages to free up space.
Aug 23 2023, 10:26 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5503: Nightly-builds is missing a latest.iso to be used with add system image.

Include VyOS functions

source /opt/vyatta/etc/functions/script-template

Aug 23 2023, 9:25 PM · VyOS 1.4 Sagitta
Apachez updated the task description for T5497: Add ability to resequence rule numbers for firewall.
Aug 23 2023, 8:34 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez closed T5478: Cannot configure resolver-cache options for firewall as Resolved.
Aug 23 2023, 8:27 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5478: Cannot configure resolver-cache options for firewall.

Verified being fixed in VyOS 1.4-rolling-202308230020.

Aug 23 2023, 8:27 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5503: Nightly-builds is missing a latest.iso to be used with add system image.

So where should this be filed instead?

Aug 23 2023, 8:09 PM · VyOS 1.4 Sagitta
Apachez added a comment to T4610: Firewall with 20K entries cannot load after reboot.

Related: https://vyos.dev/T5388 (Something is fishy with commit and boot times when more than a few hundred static routes are being used).

Aug 23 2023, 8:02 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

The following is for example made up by migration:

Aug 23 2023, 7:47 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez created T5503: Nightly-builds is missing a latest.iso to be used with add system image.
Aug 23 2023, 7:27 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5498: fsck during boot doesnt work.

So the bug is that "boot=live" is being used when installing VyOS to a harddrive?

Aug 23 2023, 7:15 PM · VyOS Rolling, Bugs
Apachez added a comment to T5160: Firewall refactor.

@giga1699 There are already plenty of hidden stuff going on if you take a look at the output of nft -s list ruleset.

Aug 23 2023, 7:13 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5495: Enable snmp module also for frr/ldpd.

Yes, that output seems to have the snmp module (which exists in /usr/lib/x86_64-linux-gnu/frr/modules/) loaded.

Aug 23 2023, 6:53 PM · VyOS 1.4 Sagitta

Aug 21 2023

Apachez added a comment to T5160: Firewall refactor.

Comparing with other vendors thats what you use the ACL for.

Aug 21 2023, 10:42 AM · VyOS 1.4 Sagitta

Aug 20 2023

Apachez added a comment to T5160: Firewall refactor.

A dirty workaround would be to include a "hidden" (as in it exists in nft but not displayed in the vyos-config itself) CoPP table which includes the port(s) needed for:

Aug 20 2023, 11:44 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5160: Firewall refactor.

As seen on slack and I think on the forum.

Aug 20 2023, 11:28 PM · VyOS 1.4 Sagitta
Apachez added a comment to T3509: No BCP38 for IPv6 on VyOS.

Perhaps same workaround as firewalld is implementing through option "IPv6_rpfilter=yes" could be implemented in VyOS (both uses nft)?

Aug 20 2023, 10:49 PM · VyOS 1.4 Sagitta
Apachez added a comment to T3509: No BCP38 for IPv6 on VyOS.

Possibly the fib statement can be used through nft:

Aug 20 2023, 10:37 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5481: Upgrade bug.

Looks like you would need some more extensive checking of that partition.

Aug 20 2023, 9:44 AM · VyOS 1.4 Sagitta

Aug 19 2023

Apachez added a comment to T5481: Upgrade bug.

I have created this task regarding the fsck issues (fsck does not run during boot): https://vyos.dev/T5498

Aug 19 2023, 4:06 PM · VyOS 1.4 Sagitta
Apachez created T5498: fsck during boot doesnt work.
Aug 19 2023, 4:02 PM · VyOS Rolling, Bugs
Apachez created T5497: Add ability to resequence rule numbers for firewall.
Aug 19 2023, 10:34 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez added a comment to T5466: L3VPN - label allocation mode .

In PR 2152:

Aug 19 2023, 8:15 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5496: `show firewall` error.

Works for me without errors but I currently only have an empty ruleset:

Aug 19 2023, 12:19 AM · Restricted Project, VyOS 1.4 Sagitta

Aug 18 2023

Apachez created T5495: Enable snmp module also for frr/ldpd.
Aug 18 2023, 11:04 PM · VyOS 1.4 Sagitta
Apachez created T5493: Add capability to use local and external dynamic-lists for firewall rules but also for various policies such as access-list, route-maps etc..
Aug 18 2023, 6:53 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling