Page MenuHomeVyOS Platform
Feed All Stories

Sep 15 2023

Apachez added a comment to T4502: Consider implementing (NAT/other) flow table offload.

Tried to enable both software and hardware flowtable with VyOS 1.5-rolling-202309151051:

Sep 15 2023, 5:32 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5586: Disable by default SNMP for Keepalived VRRP.

How does FRR/vrrpd work regarding SNMP compatability?

Sep 15 2023, 4:55 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav moved T5586: Disable by default SNMP for Keepalived VRRP from Need Triage to Finished on the VyOS 1.5 Circinus board.
Sep 15 2023, 4:24 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav closed T5587: Firwall can not pass the smoketest as Resolved.

Fixed

Sep 15 2023, 4:23 PM · VyOS 1.5 Circinus
Viacheslav created T5588: Add kernel conntrack_bridge module.
Sep 15 2023, 2:48 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev added a comment to T5587: Firwall can not pass the smoketest.
Sep 15 2023, 8:48 AM · VyOS 1.5 Circinus
sarthurdev moved T5568: Install image from live ISO always defaults boot to KVM entry from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Sep 15 2023, 8:18 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev added a comment to T5587: Firwall can not pass the smoketest.

https://github.com/vyos/vyos-1x/pull/2272 should fix this

Sep 15 2023, 8:00 AM · VyOS 1.5 Circinus
Viacheslav created T5587: Firwall can not pass the smoketest.
Sep 15 2023, 7:58 AM · VyOS 1.5 Circinus
Viacheslav changed the status of T5586: Disable by default SNMP for Keepalived VRRP from Open to In progress.
Sep 15 2023, 7:40 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5586: Disable by default SNMP for Keepalived VRRP.

PR https://github.com/vyos/vyos-1x/pull/2273

Sep 15 2023, 7:35 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added projects to T5586: Disable by default SNMP for Keepalived VRRP: VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.5).
Sep 15 2023, 7:35 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav renamed T5586: Disable by default SNMP for Keepalived VRRP from Disable be default SNMP for Keepalived VRRP to Disable by default SNMP for Keepalived VRRP.
Sep 15 2023, 7:34 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
vfreex updated subscribers of T4502: Consider implementing (NAT/other) flow table offload.

Some extra lines were mistakenly included during rebase:

Sep 15 2023, 6:48 AM · VyOS 1.4 Sagitta
Viacheslav created T5586: Disable by default SNMP for Keepalived VRRP.
Sep 15 2023, 6:46 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav changed the status of T5579: Log firewall - Wrong command after firewall refactor, a subtask of T5160: Firewall refactor, from In progress to Needs testing.
Sep 15 2023, 6:31 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5579: Log firewall - Wrong command after firewall refactor from In progress to Needs testing.
Sep 15 2023, 6:31 AM · VyOS 1.5 Circinus
Viacheslav changed the status of T5574: Support per-service cache management for dynamic dns providers from Open to Needs testing.
Sep 15 2023, 6:30 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5585: Fix file access mode for dynamic dns configuration from Open to Needs testing.
Sep 15 2023, 6:29 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr claimed T5585: Fix file access mode for dynamic dns configuration.
Sep 15 2023, 3:53 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr created T5585: Fix file access mode for dynamic dns configuration.
Sep 15 2023, 3:52 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr updated the task description for T5574: Support per-service cache management for dynamic dns providers.
Sep 15 2023, 3:51 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr renamed T5574: Support per-service cache management for dynamic dns providers from Inprove and refactor dns dynamic service configuration to Support per-service cache management for dynamic dns providers.
Sep 15 2023, 3:49 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T4502: Consider implementing (NAT/other) flow table offload.

Note that PR2062 is broken.

Sep 15 2023, 2:01 AM · VyOS 1.4 Sagitta

Sep 14 2023

n.fort changed the status of T5579: Log firewall - Wrong command after firewall refactor, a subtask of T5160: Firewall refactor, from Confirmed to In progress.
Sep 14 2023, 6:45 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5579: Log firewall - Wrong command after firewall refactor from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/2268

Sep 14 2023, 6:45 PM · VyOS 1.5 Circinus
I-n-d-y added a project to T5425: enable VRF for conntrack-sync: VyOS 1.5 Circinus.
Sep 14 2023, 5:51 PM · VyOS 1.5 Circinus, vyatta-conntrack-sync
dmbaturin created 1.3.4.
Sep 14 2023, 1:07 PM
Apachez added a comment to T5499: initial arm64 support for RPI4 and QEMU VM.

Regarding testing of arm-builds, hopefully this article might come handy (how to use qemu-system-aarch64 (on x86) part of the qemu-system-arm package):

Sep 14 2023, 12:41 PM · VyOS 1.5 Circinus
aalmenar added a comment to T5546: Failed upgrade from 1.4-rolling-202212310809 to 1.4-rolling-202309030023.

In my case the upgrade from 1.4-rolling-202308060317 to vyos-1.4-rolling-202308060317 made the vrf unavailable so no access to management. Booting back to old version became working again.

Sep 14 2023, 12:36 PM · VyOS 1.4 Sagitta (1.4.1)
Apachez added a comment to T5511: Cleanup of unused directories (and files) in order to shrink image-size.

The excludes-file in PR406 had incorrectly a '/' as first character (for the directory to be excluded from the squashfs-file).

Sep 14 2023, 12:01 PM · VyOS 1.4 Sagitta
yun added a comment to T5455: SSH fingerprints aren't migrated to the new image on upgrade.

Would also be nice to include the global known_hosts file in /etc/ssh/ssh_known_hosts.

Sep 14 2023, 10:57 AM · VyOS 1.4 Sagitta (1.4.1)
yun added a comment to T5541: Zone-Based Firewalling in VyOS Sagitta 1.4.

I would also like to know if zone based firewall still work or support is removed?

Sep 14 2023, 10:56 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5584: System cannot boot with commit-arachive location sftp in some cases.
Sep 14 2023, 8:19 AM · Restricted Project, VyOS 1.3 Equuleus (1.3.9)
Apachez added a comment to T2044: RPKI doesn't boot properly.

PR created: https://github.com/vyos/vyos-1x/pull/2264

Sep 14 2023, 8:14 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5530: Add LFA to IS-IS from Open to In progress.
Sep 14 2023, 8:00 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
Apachez added a comment to T2044: RPKI doesn't boot properly.

Should probably add "-M rpki" permanently to FRR/bgp.

Sep 14 2023, 7:53 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T2044: RPKI doesn't boot properly.

Could the error from latest nightly be due to that rpki module isnt loaded for FRR/bgp?

Sep 14 2023, 7:39 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
maimun.najib created T5583: PPPoE server on vpp interface.
Sep 14 2023, 7:07 AM · VyOS 1.4 Sagitta
vfreex added a comment to T3655: NAT doesn't work correctly with VRF.

@fernando This is really nice. Thank you for the testing!

Sep 14 2023, 7:02 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Apachez added a comment to T2044: RPKI doesn't boot properly.

Could https://vyos.dev/T2044 be related to the failed nightly build from last night?

Sep 14 2023, 6:53 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Cheeze_It added a comment to T5530: Add LFA to IS-IS.

Added PR here https://github.com/vyos/vyos-1x/pull/2263

Sep 14 2023, 1:27 AM · VyOS 1.4 Sagitta (1.4.0-epa2)

Sep 13 2023

Apachez added a comment to T5471: Conntrack logging doesnt seem to be working.

This is still the case in VyOS 1.5-rolling-202309130022:

Sep 13 2023, 9:43 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Apachez added a comment to T5513: Anomalies in show firewall command after refactoring.

Suggestion of "hidden" ruleset (visible when doing show firewall and show firewall statistics):

Sep 13 2023, 9:39 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5511: Cleanup of unused directories (and files) in order to shrink image-size.

PR created: https://github.com/vyos/vyos-build/pull/406

Sep 13 2023, 9:08 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5511: Cleanup of unused directories (and files) in order to shrink image-size.

Found out that mksquashfs supports -ef EXCLUDE_FILE as a file that (line by line) defines which files and directories to be excluded during creation of filesystem.squashfs. Adding -wildcard will make it possible to use wildcards within the EXCLUDE_FILE.

Sep 13 2023, 8:49 PM · VyOS 1.4 Sagitta
zsdc changed the status of T5577: Optimize PAM configs for RADIUS/TACACS+ from Open to In progress.

PR for 1.5: https://github.com/vyos/vyos-1x/pull/2256

Sep 13 2023, 8:43 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5575: ARP/NDP table-size isnt set properly.

PR updated: https://github.com/vyos/vyos-1x/pull/2255

Sep 13 2023, 7:14 PM · VyOS 1.5 Circinus
Apachez added a comment to T5582: Add a command to force NTP sync.

Something like this console command but more handy in op-mode?

Sep 13 2023, 6:49 PM · VyOS 1.4 Sagitta
dmbaturin created T5582: Add a command to force NTP sync.
Sep 13 2023, 5:41 PM · VyOS 1.4 Sagitta
c-po added a comment to T5581: Add "show ip nht" op-mode command (IPv4 nexthop tracking table).

PR https://github.com/vyos/vyos-1x/pull/2257

Sep 13 2023, 4:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5581: Add "show ip nht" op-mode command (IPv4 nexthop tracking table) from Need Triage to Finished on the VyOS 1.5 Circinus board.
Sep 13 2023, 4:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5581: Add "show ip nht" op-mode command (IPv4 nexthop tracking table) from Backlog to In Progress on the VyOS 1.4 Sagitta board.
Sep 13 2023, 4:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5581: Add "show ip nht" op-mode command (IPv4 nexthop tracking table) from Need Triage to Backlog on the VyOS 1.4 Sagitta board.
Sep 13 2023, 4:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po changed the status of T5581: Add "show ip nht" op-mode command (IPv4 nexthop tracking table) from Open to In progress.
Sep 13 2023, 4:55 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po created T5581: Add "show ip nht" op-mode command (IPv4 nexthop tracking table).
Sep 13 2023, 4:54 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
fernando added a comment to T4919: TPM-backed config encryption.

@sdev greats !!!

Sep 13 2023, 4:39 PM · VyOS 1.5 Circinus
ServerForge created T5580: vyos-1x package builds as 1.5 on sagitta branch.
Sep 13 2023, 3:40 PM · VyOS 1.4 Sagitta
n.fort added a subtask for T5160: Firewall refactor: T5579: Log firewall - Wrong command after firewall refactor.
Sep 13 2023, 3:07 PM · VyOS 1.4 Sagitta
n.fort added a parent task for T5579: Log firewall - Wrong command after firewall refactor: T5160: Firewall refactor.
Sep 13 2023, 3:07 PM · VyOS 1.5 Circinus
n.fort changed the status of T5579: Log firewall - Wrong command after firewall refactor from Open to Confirmed.
Sep 13 2023, 3:07 PM · VyOS 1.5 Circinus
n.fort created T5579: Log firewall - Wrong command after firewall refactor.
Sep 13 2023, 3:07 PM · VyOS 1.5 Circinus
Apachez added a comment to T5575: ARP/NDP table-size isnt set properly.

PR created: https://github.com/vyos/vyos-1x/pull/2255

Sep 13 2023, 12:08 PM · VyOS 1.5 Circinus
Apachez added a comment to T5575: ARP/NDP table-size isnt set properly.

Turns out that the values who override the vyos-config values are set in /etc/sysctl.d/30-vyos-router.conf:

Sep 13 2023, 11:50 AM · VyOS 1.5 Circinus
Apachez claimed T5575: ARP/NDP table-size isnt set properly.
Sep 13 2023, 11:48 AM · VyOS 1.5 Circinus
sarthurdev changed the status of T5571: Firewall does not delete networks from the table raw from Open to Confirmed.
Sep 13 2023, 10:49 AM · VyOS 1.5 Circinus
n.fort changed the status of T5561: NAT - Inbound or outbound interface should not be mandatory from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/2253

Sep 13 2023, 10:47 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5575: ARP/NDP table-size isnt set properly.

I can confirm that setting these values AFTER boot (and doing commit) they will be properly set.

Sep 13 2023, 10:42 AM · VyOS 1.5 Circinus
Viacheslav changed the status of T5576: Add bgp remove-private-as all option from Open to In progress.
Sep 13 2023, 10:19 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav edited projects for T5578: "ikev2-reauth" description contains outdated information, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Sep 13 2023, 9:48 AM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav added a comment to T5576: Add bgp remove-private-as all option.

PR for 1.3.x https://github.com/vyos/vyatta-cfg-quagga/pull/102
PR for the current https://github.com/vyos/vyos-1x/pull/2252

Sep 13 2023, 9:47 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev added a comment to T4919: TPM-backed config encryption.

@fernando See here: https://github.com/vyos/vyos-build/pull/297

Sep 13 2023, 9:35 AM · VyOS 1.5 Circinus
a.apostoliuk changed the status of T5578: "ikev2-reauth" description contains outdated information from Open to In progress.
Sep 13 2023, 9:16 AM · VyOS 1.3 Equuleus (1.3.5)
a.apostoliuk created T5578: "ikev2-reauth" description contains outdated information.
Sep 13 2023, 9:16 AM · VyOS 1.3 Equuleus (1.3.5)
zsdc added a parent task for T5554: Disable sudo for PAM RADIUS: T5577: Optimize PAM configs for RADIUS/TACACS+.
Sep 13 2023, 8:08 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
zsdc added a parent task for T5570: PAM config RADIUS ignore for default and success: T5577: Optimize PAM configs for RADIUS/TACACS+.
Sep 13 2023, 8:08 AM · VyOS 1.4 Sagitta (1.4.1)
zsdc added subtasks for T5577: Optimize PAM configs for RADIUS/TACACS+: T5570: PAM config RADIUS ignore for default and success, T5554: Disable sudo for PAM RADIUS.
Sep 13 2023, 8:08 AM · VyOS 1.4 Sagitta
zsdc created T5577: Optimize PAM configs for RADIUS/TACACS+.
Sep 13 2023, 8:07 AM · VyOS 1.4 Sagitta
Viacheslav created T5576: Add bgp remove-private-as all option.
Sep 13 2023, 8:03 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez created T5575: ARP/NDP table-size isnt set properly.
Sep 13 2023, 7:54 AM · VyOS 1.5 Circinus
c-po added a comment to T5523: CVE-2023-38802.

Which VyOS 1.4-rolling will have the fixes made by FRRouting?

Sep 13 2023, 6:22 AM · VyOS 1.3 Equuleus
c-po merged T5523: CVE-2023-38802 into T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802.
Sep 13 2023, 6:16 AM · VyOS 1.3 Equuleus (1.3.4)
c-po merged task T5523: CVE-2023-38802 into T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802.
Sep 13 2023, 6:16 AM · VyOS 1.3 Equuleus
syncer assigned T5573: Fix ddclient cache entries to indrajitr.
Sep 13 2023, 3:13 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr updated the task description for T5573: Fix ddclient cache entries.
Sep 13 2023, 3:04 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr triaged T5574: Support per-service cache management for dynamic dns providers as Normal priority.
Sep 13 2023, 2:08 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr created T5573: Fix ddclient cache entries.
Sep 13 2023, 1:38 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5572: Add capability for sending Gratuitous ARP (GARP) and the equal for IPv6.

Turns out to exist an RFC for this regarding IPv6 along with a naming:

Sep 13 2023, 12:54 AM · VyOS 1.5 Circinus
Apachez created T5572: Add capability for sending Gratuitous ARP (GARP) and the equal for IPv6.
Sep 13 2023, 12:35 AM · VyOS 1.5 Circinus

Sep 12 2023

Apachez renamed T5559: Selective proxy-arp/proxy-ndp when doing SNAT/DNAT from Selective proxy-arp when doing SNAT to Selective proxy-arp/proxy-ndp when doing SNAT/DNAT.
Sep 12 2023, 11:26 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
syncer reassigned T5523: CVE-2023-38802 from v.huti to c-po.
Sep 12 2023, 11:16 PM · VyOS 1.3 Equuleus
fernando changed the status of T3655: NAT doesn't work correctly with VRF from Backport candidate to Needs testing.
Sep 12 2023, 6:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando added a comment to T3655: NAT doesn't work correctly with VRF.

command on 1.5 :

Sep 12 2023, 6:36 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a comment to T5522: Add logging for which mksquashfs syntax is being used.

@Apachez note that all lb commands take --debug and --verbose: using 'lb build --debug' in scripts/build-vyos-image will output the full mksquashfs command.

Sep 12 2023, 6:36 PM · VyOS 1.5 Circinus
fernando changed the status of T3655: NAT doesn't work correctly with VRF from In progress to Backport candidate.
Sep 12 2023, 4:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando updated subscribers of T3655: NAT doesn't work correctly with VRF.

@vfreex I've tested in my labs related this issues , I can confirm that it work as expected . this original zone solved the problem when there was a src-nat /dst-nat with different VRFs or leaking with them ,Thanks you for this contribution .

Sep 12 2023, 4:16 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
yun added a comment to T2405: commit archive to GIT.

Note that command = command.lstrip() for def cmd in python/vyos/utils/process.py was reverted yesterday.

Causes funny problems during smoketests.

Sep 12 2023, 3:34 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5571: Firewall does not delete networks from the table raw.
Sep 12 2023, 3:09 PM · VyOS 1.5 Circinus
Apachez added a comment to T2405: commit archive to GIT.

Note that command = command.lstrip() for def cmd in python/vyos/utils/process.py was reverted yesterday.

Sep 12 2023, 1:46 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
yun added a comment to T2405: commit archive to GIT.

I created a PR for Git support here: https://github.com/vyos/vyos-1x/pull/2241

Sep 12 2023, 1:22 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta