Page MenuHomeVyOS Platform
Feed All Stories

Sep 25 2023

dmbaturin renamed T3546: Add support for running scripts on PPPoE server session events from Add pppoe-server CLI custom script feature to Add support for running scripts on PPPoE server session events.
Sep 25 2023, 1:37 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin set Issue type to feature on T3546: Add support for running scripts on PPPoE server session events.
Sep 25 2023, 1:36 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin set Issue type to bug on T3339: Cloud-Init domain search setting not applied.
Sep 25 2023, 1:36 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin closed T5533: Keepalived VRRP IPv6 group enters in FAULT state as Resolved.
Sep 25 2023, 1:28 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dmbaturin renamed T5526: Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax from BGP peer-group - don't support add interfaces over peer neigborhs to Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax.
Sep 25 2023, 1:27 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.8)
indrajitr updated the task description for T5615: Narrow down spurious name conflict with mdns.
Sep 25 2023, 4:47 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
indrajitr updated the task description for T5615: Narrow down spurious name conflict with mdns.
Sep 25 2023, 4:31 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
indrajitr triaged T5615: Narrow down spurious name conflict with mdns as Normal priority.
Sep 25 2023, 4:29 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro added a comment to T5522: Add logging for which mksquashfs syntax is being used.

Note that is is the "--debug" flag that one wants in order to see the full mksquashfs command that is executed.

Sep 25 2023, 12:57 AM · VyOS 1.5 Circinus
jestabro claimed T5611: Difference in config file after interface MAC changed.
Sep 25 2023, 12:08 AM · Restricted Project, VyOS 1.3 Equuleus (1.3.9)

Sep 24 2023

jestabro added a comment to T3871: Resolve unexpected interface name reordering.

@stingalleman As mentioned above (and confirmed in discussions earlier this week), we've had few if any reports of issues with the udev approach, so we would be very interested to hear details of your case.

Sep 24 2023, 11:52 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
sarthurdev added a comment to T5599: Firewall unexpectedly changes some sysctl options.

Not sure what to do on this one. The firewall is depending on conntrack module, which updates the conntrack related sysctls. It'd be the same if someone defines custom sysctls used by other conf scripts.

Sep 24 2023, 6:30 PM · Restricted Project, VyOS 1.5 Circinus
stingalleman added a comment to T3871: Resolve unexpected interface name reordering.

When will this bug be fixed? I am having a lot of issues with this.

Sep 24 2023, 4:17 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
Apachez closed T5511: Cleanup of unused directories (and files) in order to shrink image-size as Resolved.

Verified to be working as expected.

Sep 24 2023, 2:47 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5522: Add logging for which mksquashfs syntax is being used.

@jestabro I havent verified it yet but then perhaps the buildscript for VyOS should be altered to include --verbose?

Sep 24 2023, 2:45 PM · VyOS 1.5 Circinus
Apachez closed T5591: Cleanup of FRR daemons-file and various FRR fixes as Resolved.

Verified through smoketests.

Sep 24 2023, 2:45 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5614: Add conntrack helper matching on firewall from Open to In progress.
Sep 24 2023, 2:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez closed T5604: List of debian archives is out of date (non-free-firmware is missing) as Resolved.
Sep 24 2023, 2:44 PM · VyOS 1.5 Circinus
Apachez added a comment to T5604: List of debian archives is out of date (non-free-firmware is missing).

Verified through smoketests.

Sep 24 2023, 2:44 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5606: IPSec VPN: Allow multiple CAs certificates from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2305

Sep 24 2023, 1:54 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev moved T5606: IPSec VPN: Allow multiple CAs certificates from Need Triage to In Progress on the VyOS 1.5 Circinus board.
Sep 24 2023, 12:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a project to T5606: IPSec VPN: Allow multiple CAs certificates: VyOS 1.5 Circinus.
Sep 24 2023, 12:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev changed the status of T5606: IPSec VPN: Allow multiple CAs certificates from Open to In progress.
Sep 24 2023, 12:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a comment to T5160: Firewall refactor.

PR removing zone-policy op-mode: https://github.com/vyos/vyos-1x/pull/2304

Sep 24 2023, 11:44 AM · VyOS 1.4 Sagitta
sarthurdev changed the status of T5376: Conntrack FTP helper does not work properly from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2304

Sep 24 2023, 11:44 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
sarthurdev changed the status of T5598: unknown parameter 'nf_conntrack_helper' ignored from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2304

Sep 24 2023, 11:44 AM · VyOS 1.5 Circinus
indrajitr updated the task description for T5612: Miscellaneous improvements and fixes for dynamic DNS configuration.
Sep 24 2023, 1:32 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sep 23 2023

Viacheslav changed the edit policy for T5613: VyOS in container bugs.
Sep 23 2023, 5:56 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a parent task for T2115: VyOS Docker container not load config: T5613: VyOS in container bugs.
Sep 23 2023, 5:53 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.5 Circinus
Viacheslav added a subtask for T5613: VyOS in container bugs: T2115: VyOS Docker container not load config.
Sep 23 2023, 5:53 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a project to T2115: VyOS Docker container not load config: VyOS 1.5 Circinus.
Sep 23 2023, 5:53 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.5 Circinus
Viacheslav updated the task description for T5613: VyOS in container bugs.
Sep 23 2023, 5:08 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav created T5613: VyOS in container bugs.
Sep 23 2023, 5:07 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav closed T5518: Add MLD protocol support as Resolved.
Sep 23 2023, 2:22 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3214: OpenVPN IPv6 fixes from Open to Needs testing.
Sep 23 2023, 1:55 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T5604: List of debian archives is out of date (non-free-firmware is missing) from Open to Needs testing.
Sep 23 2023, 1:48 PM · VyOS 1.5 Circinus

Sep 22 2023

indrajitr triaged T5612: Miscellaneous improvements and fixes for dynamic DNS configuration as Normal priority.
Sep 22 2023, 8:15 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5602: For reverse-proxy type of load-balancing feature, support "backup" option in backends configuration as Resolved.
Sep 22 2023, 4:16 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a project to T4624: Move some op mode commands to "execute" and "produce" command families: VyOS 1.5 Circinus.
Sep 22 2023, 4:14 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a comment to T5497: Add ability to resequence rule numbers for firewall.

Op-mode command reduce
PR https://github.com/vyos/vyos-1x/pull/2302

vyos@r4:~$ show conf com | match firew
set firewall ipv4 input filter default-action 'accept'
set firewall ipv4 input filter rule 1 action 'accept'
set firewall ipv4 input filter rule 1 description 'Allow loopback'
set firewall ipv4 input filter rule 1 inbound-interface interface-name 'lo'
set firewall ipv4 input filter rule 1 source address '127.0.0.0/8'
set firewall ipv4 input filter rule 2 action 'accept'
set firewall ipv4 input filter rule 2 description 'Allow established/related'
set firewall ipv4 input filter rule 2 state established 'enable'
set firewall ipv4 input filter rule 2 state related 'enable'
set firewall ipv4 input filter rule 60 action 'accept'
set firewall ipv4 input filter rule 60 description 'Allow SSH from trusted networks'
set firewall ipv4 input filter rule 60 destination port '22'
set firewall ipv4 input filter rule 60 protocol 'tcp'
set firewall ipv4 input filter rule 10000 action 'drop'
set firewall ipv4 input filter rule 10000 description 'Drop everything else'
vyos@r4:~$ 
vyos@r4:~$ produce firewall rule-resequence start 10 step 10
Sep 22 2023, 3:58 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro moved T5607: Adjust RAID smoketest for non-deterministic SCSI device probing from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Sep 22 2023, 3:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5607: Adjust RAID smoketest for non-deterministic SCSI device probing as Resolved.
Sep 22 2023, 3:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro moved T5608: Rewrite add/delete raid member to Python and remove from vyatta-op from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Sep 22 2023, 3:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5608: Rewrite add/delete raid member to Python and remove from vyatta-op, a subtask of T5607: Adjust RAID smoketest for non-deterministic SCSI device probing, as Resolved.
Sep 22 2023, 3:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5608: Rewrite add/delete raid member to Python and remove from vyatta-op as Resolved.
Sep 22 2023, 3:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5608: Rewrite add/delete raid member to Python and remove from vyatta-op, a subtask of T5609: Add util to get drive device name from id, as Resolved.
Sep 22 2023, 3:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro moved T5609: Add util to get drive device name from id from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Sep 22 2023, 3:04 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5609: Add util to get drive device name from id, a subtask of T5607: Adjust RAID smoketest for non-deterministic SCSI device probing, as Resolved.
Sep 22 2023, 3:04 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5609: Add util to get drive device name from id as Resolved.
Sep 22 2023, 3:04 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.apostoliuk created T5611: Difference in config file after interface MAC changed.
Sep 22 2023, 9:34 AM · Restricted Project, VyOS 1.3 Equuleus (1.3.9)

Sep 21 2023

indrajitr updated the task description for T5574: Support per-service cache management for dynamic dns providers.
Sep 21 2023, 10:25 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5610: Cloudflare blocks pasting of code to vyos.dev.

The quickfix is to add a space for your paths so something that looks like /usr/local/bin if cloudflare blocks that you just add a space after the first / and the WAF is bypassed.

Sep 21 2023, 3:55 PM
b- created T5610: Cloudflare blocks pasting of code to vyos.dev.
Sep 21 2023, 3:48 PM
Viacheslav moved T5576: Add bgp remove-private-as all option from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Sep 21 2023, 3:08 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav moved T5576: Add bgp remove-private-as all option from Need Triage to Finished on the VyOS 1.5 Circinus board.
Sep 21 2023, 3:08 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T5594: VRRP - Error if using IPv6 Link Local as hello source address from In progress to Needs testing.
Sep 21 2023, 11:48 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus
n.fort added a comment to T5600: Firewall - Remove or extend constraint on 'interface-name'.

PR: https://github.com/vyos/vyos-1x/pull/2300

Sep 21 2023, 11:25 AM · VyOS 1.5 Circinus
sarthurdev changed the status of T5376: Conntrack FTP helper does not work properly from Open to Confirmed.
Sep 21 2023, 9:49 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
sarthurdev changed the status of T5598: unknown parameter 'nf_conntrack_helper' ignored from Open to Confirmed.

This is likely also the issue causing T5376

Sep 21 2023, 9:49 AM · VyOS 1.5 Circinus
Viacheslav moved T5590: Firewall "log enable" logs every packet from Need Triage to Finished on the VyOS 1.5 Circinus board.
Sep 21 2023, 6:22 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav moved T5602: For reverse-proxy type of load-balancing feature, support "backup" option in backends configuration from Need Triage to Finished on the VyOS 1.5 Circinus board.
Sep 21 2023, 5:40 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sep 20 2023

jestabro added a comment to T5607: Adjust RAID smoketest for non-deterministic SCSI device probing.

PRs:
https://github.com/vyos/vyos-1x/pull/2298
https://github.com/vyos/vyatta-op/pull/71
https://github.com/vyos/vyos-build/pull/419

Sep 20 2023, 8:38 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
rayzilt closed T5590: Firewall "log enable" logs every packet as Resolved.

Great, Thanks!

Sep 20 2023, 8:17 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro added a subtask for T5609: Add util to get drive device name from id: T5608: Rewrite add/delete raid member to Python and remove from vyatta-op.
Sep 20 2023, 8:12 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro added a parent task for T5608: Rewrite add/delete raid member to Python and remove from vyatta-op: T5609: Add util to get drive device name from id.
Sep 20 2023, 8:12 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro added a parent task for T5609: Add util to get drive device name from id: T5607: Adjust RAID smoketest for non-deterministic SCSI device probing.
Sep 20 2023, 8:12 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro added a subtask for T5607: Adjust RAID smoketest for non-deterministic SCSI device probing: T5609: Add util to get drive device name from id.
Sep 20 2023, 8:12 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro triaged T5609: Add util to get drive device name from id as Normal priority.
Sep 20 2023, 8:11 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro added a subtask for T5607: Adjust RAID smoketest for non-deterministic SCSI device probing: T5608: Rewrite add/delete raid member to Python and remove from vyatta-op.
Sep 20 2023, 8:07 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro added a parent task for T5608: Rewrite add/delete raid member to Python and remove from vyatta-op: T5607: Adjust RAID smoketest for non-deterministic SCSI device probing.
Sep 20 2023, 8:07 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro triaged T5608: Rewrite add/delete raid member to Python and remove from vyatta-op as Normal priority.
Sep 20 2023, 8:07 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro triaged T5607: Adjust RAID smoketest for non-deterministic SCSI device probing as Normal priority.
Sep 20 2023, 8:02 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5601: TCP reverse-Roxy based on FQDN.

Oops, sorry about that!

Sep 20 2023, 4:20 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5601: TCP reverse-Roxy based on FQDN.

@Apachez It is not FQDN based

Sep 20 2023, 4:15 PM · VyOS 1.4 Sagitta
vvinci00 added a comment to T5601: TCP reverse-Roxy based on FQDN.

Should I ask this to you.

Sep 20 2023, 4:06 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5601: TCP reverse-Roxy based on FQDN.

Hello,

I need to reverse proxy TCP traffic.
the traffic is not HTTP/HTTPS

Sep 20 2023, 4:04 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5604: List of debian archives is out of date (non-free-firmware is missing).

PR created: https://github.com/vyos/vyos-build/pull/418

Sep 20 2023, 3:58 PM · VyOS 1.5 Circinus
Viacheslav closed T5601: TCP reverse-Roxy based on FQDN as Wontfix.

Contact our sales or ask forum

Sep 20 2023, 3:45 PM · VyOS 1.4 Sagitta
vvinci00 added a comment to T5601: TCP reverse-Roxy based on FQDN.

It's possible to use VyOS as reverse proxy on TCP traffic (not HTTP)?
if yes, what configuration it's necessary?
if not, do you know any solutions that can help me?

Sep 20 2023, 3:43 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5601: TCP reverse-Roxy based on FQDN.

Hello,

I need to reverse proxy TCP traffic.
the traffic is not HTTP/HTTPS

Sep 20 2023, 3:41 PM · VyOS 1.4 Sagitta
vvinci00 added a comment to T5601: TCP reverse-Roxy based on FQDN.

I need to reverse proxy TCP traffic.
the traffic is not HTTP/HTTPS

Sep 20 2023, 3:34 PM · VyOS 1.4 Sagitta
fernando added a project to T5487: OPENVPN -DEPRECATED OPTION: --cipher: VyOS 1.3 Equuleus (1.3.5).
Sep 20 2023, 2:55 PM · VyOS 1.5 Circinus, Restricted Project
SrividyaA created T5606: IPSec VPN: Allow multiple CAs certificates.
Sep 20 2023, 2:21 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
dmbaturin closed T5271: Add support for peer-fingerprint to OpenVPN, a subtask of T5269: OpenVPN non-TLS site-to-site mode deprecation, as Resolved.
Sep 20 2023, 1:42 PM · VyOS 1.4 Sagitta
dmbaturin closed T5271: Add support for peer-fingerprint to OpenVPN as Resolved.
Sep 20 2023, 1:42 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav moved T5241: Support veth interfaces to working with netns from Need Triage to Finished on the VyOS 1.5 Circinus board.
Sep 20 2023, 12:22 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav moved T5241: Support veth interfaces to working with netns from Finished to Backlog on the VyOS 1.4 Sagitta board.
Sep 20 2023, 12:22 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5238: interface virtual-etherne - error when it doesn't use a peer , a subtask of T3829: Support separated TCP/IP stack via "ip netns", as Resolved.
Sep 20 2023, 12:16 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav closed T5238: interface virtual-etherne - error when it doesn't use a peer as Resolved.
Sep 20 2023, 12:16 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5241: Support veth interfaces to working with netns.

set netns name mgmt
set interfaces virtual-ethernet veth1 address '10.0.0.0/31'
set interfaces virtual-ethernet veth1 peer-name 'veth10'
set interfaces virtual-ethernet veth10 address '10.0.0.1/31'
set interfaces virtual-ethernet veth10 netns 'mgmt'
set interfaces virtual-ethernet veth10 peer-name 'veth1'

Sep 20 2023, 12:14 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5241: Support veth interfaces to working with netns, a subtask of T3829: Support separated TCP/IP stack via "ip netns", as Resolved.
Sep 20 2023, 12:13 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav closed T5241: Support veth interfaces to working with netns as Resolved.
Sep 20 2023, 12:13 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T5217: Add firewall SYNPROXY .

PR https://github.com/vyos/vyos-1x/pull/2295

set system sysctl parameter net.ipv4.tcp_syncookies value '1'
set system sysctl parameter net.ipv4.tcp_timestamps value '1'
Sep 20 2023, 12:02 PM · VyOS 1.4 Sagitta
dmbaturin updated the task description for T5605: Do not generate keysize option in OpenVPN configs.
Sep 20 2023, 9:39 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin created T5605: Do not generate keysize option in OpenVPN configs.
Sep 20 2023, 9:23 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez claimed T5604: List of debian archives is out of date (non-free-firmware is missing).
Sep 20 2023, 9:21 AM · VyOS 1.5 Circinus
Viacheslav added a comment to T5602: For reverse-proxy type of load-balancing feature, support "backup" option in backends configuration.

PR https://github.com/vyos/vyos-1x/pull/2294

Sep 20 2023, 7:42 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5602: For reverse-proxy type of load-balancing feature, support "backup" option in backends configuration from Open to In progress.
Sep 20 2023, 7:33 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav renamed T5599: Firewall unexpectedly changes some sysctl options from Firwall unexpectedly changes some sysctl options to Firewall unexpectedly changes some sysctl options.
Sep 20 2023, 7:02 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav closed T5588: Add kernel conntrack_bridge module as Resolved.
Sep 20 2023, 6:45 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus