Page MenuHomeVyOS Platform
Feed All Stories

Jan 10 2024

Viacheslav moved T5918: Verification problem for `set vpn ipsec interface` from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 10 2024, 8:21 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav closed T5918: Verification problem for `set vpn ipsec interface` as Resolved.
Jan 10 2024, 8:21 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEX348892a97be2: Merge pull request #2792 from vyos/mergify/bp/sagitta/pr-2791 (authored by Viacheslav).
Jan 10 2024, 8:21 PM
Viacheslav added a comment to T3566: Add L2vpn instance for mpls .

The kernel is not supporting pseudowire/VPLS now
this patch was never merged into the kernel

Jan 10 2024, 8:16 PM · VyOS Rolling
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX60127f12d6bd: T5918: Fix typo in verify vpn ipsec interface (authored by Viacheslav).
Jan 10 2024, 8:03 PM
Viacheslav committed rVYOSONEX8452d8f49216: T5918: Fix typo in verify vpn ipsec interface.
Jan 10 2024, 8:02 PM
GitHub <noreply@github.com> committed rVYOSONEX7c6cb9829356: Merge pull request #2791 from sever-sever/T5918 (authored by c-po).
Jan 10 2024, 8:02 PM
Viacheslav changed the status of T3429: Hyper-V integration services not working on VyOS 1.4 (sagitta/current) from Open to Needs testing.
Jan 10 2024, 7:50 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5918: Verification problem for `set vpn ipsec interface` from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/2791

Jan 10 2024, 7:46 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav updated subscribers of T5835: UPnP port mapping / rule installation fails.
Jan 10 2024, 7:30 PM
dylanneild added a comment to T5835: UPnP port mapping / rule installation fails.

No, installing the miniupnpd_functions.sh file does not correct the problem.

Jan 10 2024, 7:24 PM
GitHub <noreply@github.com> committed rVYOSONEX3eaf0ca3978a: Merge pull request #2788 from vyos/mergify/bp/sagitta/pr-2787 (authored by Viacheslav).
Jan 10 2024, 7:23 PM
Viacheslav added a comment to T5835: UPnP port mapping / rule installation fails.

Another bug it that /config/upnp.leases is hardcoded, but there is no script who creates it https://github.com/vyos/vyos-1x/blob/aebb458262072457c6a3840d1b17031fbd780eca/data/templates/firewall/upnpd.conf.j2#L128

Jan 10 2024, 7:21 PM
sarthurdev changed the status of T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2790

Jan 10 2024, 7:17 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXb588e0784626: T5688: Changed 'range' to multi in 'client-ip-pool' for accell-ppp (authored by a.apostoliuk).
Jan 10 2024, 7:00 PM
a.apostoliuk committed rVYOSONEX4ffec67d0467: T5688: Changed 'range' to multi in 'client-ip-pool' for accell-ppp.
Jan 10 2024, 6:59 PM
GitHub <noreply@github.com> committed rVYOSONEXaebb45826207: Merge pull request #2777 from aapostoliuk/T5688-multirange (authored by c-po).
Jan 10 2024, 6:59 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX345a59a99b4d: bgp: T5913: allow peer-group support for ipv4|6-labeled-unicast SAFI (authored by c-po).
Jan 10 2024, 6:58 PM
GitHub <noreply@github.com> committed rVYOSONEX9bfc538e7af5: Merge pull request #2782 from vyos/mergify/bp/sagitta/pr-2780 (authored by c-po).
Jan 10 2024, 6:58 PM
Viacheslav moved T5916: Added segment routing check for index size and SRGB size from Open to Finished on the VyOS 1.5 Circinus board.
Jan 10 2024, 6:41 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a project to T5916: Added segment routing check for index size and SRGB size : VyOS 1.5 Circinus.
Jan 10 2024, 6:41 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T5835: UPnP port mapping / rule installation fails.

Will it work if you manually download the functions? https://github.com/miniupnp/miniupnp/blob/miniupnpd_2_3_1/miniupnpd/netfilter_nft/scripts/miniupnpd_functions.sh

Jan 10 2024, 6:39 PM
fghorow added a comment to T5910: Grub problem(?) Serial Console no longer working.

OK, a little digging around in the grub configs led me to a "workaround" solution for the serial console problem after the machine is booted.

Jan 10 2024, 6:29 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort changed the status of T5919: Firewall - opmode for ipv6 from Open to In progress.
Jan 10 2024, 6:26 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort created T5919: Firewall - opmode for ipv6.
Jan 10 2024, 6:26 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
dylanneild added a comment to T5835: UPnP port mapping / rule installation fails.

Can confirm this is exactly the same in 1.4 rolling (as of Jan 09). Same errors. The miniupnpd daemon receives the request (for either a UPnP, NAT-PMP, or PCP port mapping) and then reports the errors @simplysoft reports in the description.

Jan 10 2024, 6:25 PM
c-po committed rVYOSONEXf1411240c6b1: bgp: T5913: allow peer-group support for ipv4|6-labeled-unicast SAFI.
Jan 10 2024, 6:22 PM
GitHub <noreply@github.com> committed rVYOSONEXe890527d7300: Merge pull request #2787 from c-po/bgp-5913 (authored by Viacheslav).
Jan 10 2024, 6:22 PM
c-po closed T5766: http: rewrite conf-mode script to get_config_dict() , a subtask of T5762: http: api: smoketests fail as they can not establish IPv6 connection to uvicorn backend server, as Resolved.
Jan 10 2024, 5:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po closed T5766: http: rewrite conf-mode script to get_config_dict() as Resolved.
Jan 10 2024, 5:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po closed T5766: http: rewrite conf-mode script to get_config_dict() , a subtask of T5782: Use a single config mode script for https and http-api, as Resolved.
Jan 10 2024, 5:58 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po closed T5766: http: rewrite conf-mode script to get_config_dict() , a subtask of T5768: Remove auxiliary http-api.conf for simplification of http-api config mode script, as Resolved.
Jan 10 2024, 5:58 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po closed T5911: pki: service update ignored if certificate name contains a hyphen (-), a subtask of T3642: PKI configuration, as Resolved.
Jan 10 2024, 5:58 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po closed T5911: pki: service update ignored if certificate name contains a hyphen (-) as Resolved.
Jan 10 2024, 5:58 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po moved T5911: pki: service update ignored if certificate name contains a hyphen (-) from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 10 2024, 5:58 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po closed T5902: http: remove virtual-host configuration in webserver, a subtask of T5766: http: rewrite conf-mode script to get_config_dict() , as Resolved.
Jan 10 2024, 5:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po closed T5902: http: remove virtual-host configuration in webserver as Resolved.
Jan 10 2024, 5:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5902: http: remove virtual-host configuration in webserver from In Progress to Finished on the VyOS 1.4 Sagitta board.
Jan 10 2024, 5:57 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po closed T5886: Add support for ACME protocol (LetsEncrypt), a subtask of T3642: PKI configuration, as Resolved.
Jan 10 2024, 5:57 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po closed T5886: Add support for ACME protocol (LetsEncrypt) as Resolved.
Jan 10 2024, 5:57 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po closed T5886: Add support for ACME protocol (LetsEncrypt), a subtask of T5894: Extend get_config_dict() with additional parameter with_pki that defaults to False, as Resolved.
Jan 10 2024, 5:57 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po moved T5913: Allow for Peer-Groups in ipv4-labeled-unicast SAFI from Open to Finished on the VyOS 1.5 Circinus board.
Jan 10 2024, 5:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po changed the status of T5913: Allow for Peer-Groups in ipv4-labeled-unicast SAFI from Open to In progress.
Jan 10 2024, 5:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T5913: Allow for Peer-Groups in ipv4-labeled-unicast SAFI.

PR for 1.5 https://github.com/vyos/vyos-1x/pull/2787 which will be backported to 1.4

Jan 10 2024, 5:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort committed rVYOSONEX62f10e0ec807: T5915:firewall: re-add opmode command for zone based firewall.
Jan 10 2024, 5:28 PM
GitHub <noreply@github.com> committed rVYOSONEX9e3586eb17cb: Merge pull request #2784 from nicolas-fort/T5915 (authored by c-po).
Jan 10 2024, 5:28 PM
sarthurdev committed rVYOSONEXdaffee2cbf00: dhcp: T3316: Move options to separate node and extend scopes.
Jan 10 2024, 5:28 PM
sarthurdev committed rVYOSONEX0cd74e0795ea: dhcp: T5912: Fix hostfile not written for new leases.
Jan 10 2024, 5:28 PM
sarthurdev committed rVYOSONEX74ddb29c6c9c: dhcp: T3316: Fix `listen-address` handling and add `listen-interface` as….
Jan 10 2024, 5:28 PM
sarthurdev committed rVYOSONEX39bf15289ca1: dhcp: T3316: Workaround to append domain suffix to hostfile entries.
Jan 10 2024, 5:28 PM
sarthurdev committed rVYOSONEX41913f4d1d63: dhcp: T5787: Prevent duplicate IP addresses on static mappings.
Jan 10 2024, 5:28 PM
GitHub <noreply@github.com> committed rVYOSONEX085a15059755: Merge pull request #2785 from sarthurdev/kea-options (authored by c-po).
Jan 10 2024, 5:28 PM
jestabro committed rVYOSONEX17a1d31299e8: image-tools: T5917: annotate image list with (running)/(default boot).
Jan 10 2024, 5:27 PM
GitHub <noreply@github.com> committed rVYOSONEXf00779b36af8: Merge pull request #2786 from jestabro/image-annotations (authored by c-po).
Jan 10 2024, 5:27 PM
c-po committed rVYOSONEX4c35c1a4c818: T5916: Added segment routing check for index base size and SRGB base size (authored by Cheeze_It).
Jan 10 2024, 5:26 PM
sarthurdev changed the status of T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration from Open to In progress.
Jan 10 2024, 4:55 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
zsdc created T5918: Verification problem for `set vpn ipsec interface`.
Jan 10 2024, 4:52 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro added a comment to T5917: Restore annotations of (running)/(default boot) in select image list.

PR:
https://github.com/vyos/vyos-1x/pull/2786

Jan 10 2024, 4:14 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro triaged T5917: Restore annotations of (running)/(default boot) in select image list as Normal priority.
Jan 10 2024, 4:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro changed Issue type from unspecified to feature on T3441: More intelligent config loading scripts.
Jan 10 2024, 3:35 PM · VyOS Rolling
jestabro lowered the priority of T3871: Resolve unexpected interface name reordering from High to Normal.

Lowering priority to normal to proceed with adding the interface-monitor daemon development, mentioned above, for 1.5.

Jan 10 2024, 3:32 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
n.fort added a comment to T4610: Firewall with 20K entries cannot load after reboot.

Quick test done on a VM with 1 CPU and 1G RAM:

vyos@1.4.0-rc1# for I in  {1..2542}; do set firewall ipv6 name Test rule $I action accept ; set firewall ipv6 name Test rule $I destination port $I; set firewall ipv6 name Test rule $I protocol tcp ; done
vyos@1.4.0-rc1# time commit
Jan 10 2024, 3:30 PM · VyOS 1.4 Sagitta
n.fort assigned T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration to sarthurdev.
Jan 10 2024, 3:26 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T3833: Cloud-init not finding data source in OpenStack as Resolved.

@sempervictus Thanks for the update!

Jan 10 2024, 3:25 PM · VyOS 1.4 Sagitta
fghorow added a comment to T5910: Grub problem(?) Serial Console no longer working.

OK, the grub serial config described here got me as far as seeing the Grub selection screen at boot time.

Jan 10 2024, 2:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sempervictus updated subscribers of T3833: Cloud-init not finding data source in OpenStack.

Oh wow, this is ancient. Can definitely close this out - @zsdc and i figured out a bunch of the insanity around cloud-init since then and i've got it working in our openstacks as well as public clouds on a single config.

Jan 10 2024, 2:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3984: Ability to disable all logs.

What to do with atop and logrorate?

Jan 10 2024, 1:59 PM
Viacheslav placed T190: two factor authentication for OpenVPN remote VPN tunnels up for grabs.
Jan 10 2024, 1:29 PM · VyOS 1.4 Sagitta (1.4.0)
Viacheslav changed the status of T190: two factor authentication for OpenVPN remote VPN tunnels from Open to Needs testing.

It seems we already have mfa T3834 but it never was documented
https://github.com/vyos/vyos-1x/pull/1008

vyos@r4# set interfaces openvpn vtun0 server mfa totp 
Possible completions:
   challenge            Expect password as result of a challenge response protocol
                        (default: enable)
   digits               Number of digits to use for totp hash (default: 6)
   drift                Time drift in seconds (default: 0)
   slop                 Maximum allowed clock slop in seconds (default: 180)
   step                 Step value for totp in seconds (default: 30)
Jan 10 2024, 1:29 PM · VyOS 1.4 Sagitta (1.4.0)
Viacheslav placed T2541: Openvpn Radius authentication support up for grabs.
Jan 10 2024, 1:22 PM · VyOS 1.3 Equuleus (1.3.8), VyOS 1.4 Sagitta (1.4.0)
Viacheslav changed the status of T858: Full UEFI support from Open to Needs testing.

@xrobau Could you test it?

Jan 10 2024, 1:19 PM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav placed T858: Full UEFI support up for grabs.
Jan 10 2024, 1:18 PM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav placed T1101: Spoke site dynamic IP over NAT connect to Hub site up for grabs.
Dec 9 13:04:57 vyos charon: 07[IKE] no matching CHILD_SA config found

Do you have several connections from the hosts behind the same NAT external address to the same hub?
It worked in my previous tests, but it was just one host behind NAT to connect to the HUB.
Re-check please and close if it works fine now. Need to update.

Jan 10 2024, 1:13 PM
zsdc closed T1437: First boot configuration support as Wontfix.

This is closed now because the required functionality perfectly works with Cloud-init + NoCloud/ConfigDrive.

Jan 10 2024, 1:11 PM · VyOS 1.4 Sagitta
Viacheslav placed T1216: EAP-TTLS-PAP support for RADIUS up for grabs.

@amcmillen Do you have any examples of how to deploy it on Linux / Debian, etc?
Without live examples, we'll mark it as wont fix and task will be closed.

Jan 10 2024, 1:06 PM · VyOS Rolling
Viacheslav closed T1396: Unable to bind SSH only to a dynamic interface as Wontfix.

As I understand, there are now ways to implement it natively for sshd
Reopen please if you have/know a solution for it.

Jan 10 2024, 1:02 PM
Viacheslav updated subscribers of T190: two factor authentication for OpenVPN remote VPN tunnels.

@ordex Les us know if you have some ideas
Thanks

Jan 10 2024, 12:59 PM · VyOS 1.4 Sagitta (1.4.0)
Viacheslav edited projects for T190: two factor authentication for OpenVPN remote VPN tunnels, added: VyOS 1.5 Circinus; removed VyOS 1.3 Equuleus (1.3.6).
Jan 10 2024, 12:58 PM · VyOS 1.4 Sagitta (1.4.0)
Viacheslav reassigned T3583: Overwrite default config ntp settings when custom ntp servers are provided. from UnicronNL to zsdc.
Jan 10 2024, 12:51 PM
Viacheslav updated subscribers of T1369: GCP Networking Failure.

@fernando @zsdc @joshua Could you re-check it, or can we close it?

Jan 10 2024, 12:49 PM · VyOS 1.3 Equuleus (1.3.6), test
sarthurdev moved T5912: DHCP Static mapping don't work on every first lease from Open to In Progress on the VyOS 1.5 Circinus board.
Jan 10 2024, 12:39 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5912: DHCP Static mapping don't work on every first lease, a subtask of T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6), from Confirmed to Needs testing.
Jan 10 2024, 12:38 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5912: DHCP Static mapping don't work on every first lease from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2785

Jan 10 2024, 12:38 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5787: dhcp-server allows duplicate static-mapping for the same IP address from In progress to Needs testing.

1.5 PR: https://github.com/vyos/vyos-1x/pull/2785

Jan 10 2024, 12:38 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

PR for scoped options and bugfixes: https://github.com/vyos/vyos-1x/pull/2785

Jan 10 2024, 12:37 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T3833: Cloud-init not finding data source in OpenStack.

Is it still bug? @sempervictus could you re-check?
We probably need more details

Jan 10 2024, 12:34 PM · VyOS 1.4 Sagitta
Viacheslav closed T4300: Extend list of supported interfaces for Cloud-init Network Configuration as Resolved.

I guess it is already done https://github.com/vyos/vyos-cloud-init/commit/ae74804ede8fb76a7f27ca869f2b880dbe276ca2
@zsdc Can we close it or you are working on it?

Jan 10 2024, 12:31 PM · VyOS 1.4 Sagitta
Viacheslav closed T5012: Control network configuration from Cloud-Init config as Resolved.
Jan 10 2024, 12:24 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5915: Firewall zone - Re add op-mode commands from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/2784

Jan 10 2024, 12:14 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T3429: Hyper-V integration services not working on VyOS 1.4 (sagitta/current).

PR https://github.com/vyos/vyos-build/pull/484

Jan 10 2024, 10:44 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEXd7c50c813982: Merge pull request #2783 from vyos/mergify/bp/sagitta/pr-2263 (authored by c-po).
Jan 10 2024, 10:21 AM
GitHub <noreply@github.com> committed rVYOSONEX7a03e2b0ab1d: Merge pull request #2781 from vyos/mergify/bp/sagitta/pr-2773 (authored by c-po).
Jan 10 2024, 10:21 AM
marc_s added a comment to T5910: Grub problem(?) Serial Console no longer working.

See also forum thread @ https://forum.vyos.io/t/grub-menu-fails-to-load-on-serial-only-devices-with-no-kvm/

Jan 10 2024, 9:23 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav placed T5909: Container registry with authentication prevents config load (section container) after reboot up for grabs.
Jan 10 2024, 7:29 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX2d778c4cb468: T5530: isis: Adding loop free alternate feature (authored by Cheeze_It).
Jan 10 2024, 7:27 AM
dutty added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

On the other hand I would expect someone aka the admin who will configure an enterprise firewall such as VyOS could be called to have at least SOME basic knowledge and also some interest to read the documentation on how to configure the firewall.

Jan 10 2024, 7:21 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX65ad6728da9c: T5916: Added segment routing check for index base size and SRGB base size (authored by Cheeze_It).
Jan 10 2024, 7:12 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX31c816bd5301: pki: T5911: fix service update algorithm if certificate name contains a hyphen… (authored by c-po).
Jan 10 2024, 7:12 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX1f236a3ca731: boot-config-loader: T1622: add missing groups to failsafe user (authored by c-po).
Jan 10 2024, 7:12 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX34eadcf2f74a: https: T5902: remove virtual-host configuration (authored by c-po).
Jan 10 2024, 7:11 AM