Page MenuHomeVyOS Platform
Feed Search

Jan 10 2024

sarthurdev added a comment to T5787: dhcp-server allows duplicate static-mapping for the same IP address.

1.4 PR: https://github.com/vyos/vyos-1x/pull/2794

Jan 10 2024, 9:19 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev moved T5550: Source validation on interface does not work properly from Open to Finished on the VyOS 1.5 Circinus board.
Jan 10 2024, 9:11 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev added a project to T5550: Source validation on interface does not work properly: VyOS 1.5 Circinus.
Jan 10 2024, 9:11 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev changed the status of T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2790

Jan 10 2024, 7:17 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEXdaffee2cbf00: dhcp: T3316: Move options to separate node and extend scopes.
Jan 10 2024, 5:28 PM
sarthurdev committed rVYOSONEX0cd74e0795ea: dhcp: T5912: Fix hostfile not written for new leases.
Jan 10 2024, 5:28 PM
sarthurdev committed rVYOSONEX74ddb29c6c9c: dhcp: T3316: Fix `listen-address` handling and add `listen-interface` as….
Jan 10 2024, 5:28 PM
sarthurdev committed rVYOSONEX39bf15289ca1: dhcp: T3316: Workaround to append domain suffix to hostfile entries.
Jan 10 2024, 5:28 PM
sarthurdev committed rVYOSONEX41913f4d1d63: dhcp: T5787: Prevent duplicate IP addresses on static mappings.
Jan 10 2024, 5:28 PM
sarthurdev changed the status of T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration from Open to In progress.
Jan 10 2024, 4:55 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev moved T5912: DHCP Static mapping don't work on every first lease from Open to In Progress on the VyOS 1.5 Circinus board.
Jan 10 2024, 12:39 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5912: DHCP Static mapping don't work on every first lease, a subtask of T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6), from Confirmed to Needs testing.
Jan 10 2024, 12:38 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5912: DHCP Static mapping don't work on every first lease from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2785

Jan 10 2024, 12:38 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5787: dhcp-server allows duplicate static-mapping for the same IP address from In progress to Needs testing.

1.5 PR: https://github.com/vyos/vyos-1x/pull/2785

Jan 10 2024, 12:38 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

PR for scoped options and bugfixes: https://github.com/vyos/vyos-1x/pull/2785

Jan 10 2024, 12:37 PM · VyOS 1.5 Circinus

Jan 9 2024

sarthurdev changed the status of T5787: dhcp-server allows duplicate static-mapping for the same IP address from Open to In progress.
Jan 9 2024, 9:55 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev changed the status of T5912: DHCP Static mapping don't work on every first lease, a subtask of T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6), from Open to Confirmed.
Jan 9 2024, 8:55 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5912: DHCP Static mapping don't work on every first lease from Open to Confirmed.
Jan 9 2024, 8:54 PM · VyOS 1.5 Circinus

Jan 7 2024

sarthurdev added a comment to T5876: Dhcp bug in latest 1.5 rolling releases.

Is this still an issue on newer rolling images? This PR addresses ownership issues in /config on system update: https://github.com/vyos/vyos-1x/pull/2731

Jan 7 2024, 7:21 PM · VyOS 1.5 Circinus

Jan 4 2024

sarthurdev added a comment to T5876: Dhcp bug in latest 1.5 rolling releases.

Can you provide your DHCP server config?

Jan 4 2024, 3:26 PM · VyOS 1.5 Circinus

Dec 17 2023

sarthurdev committed rVYOSONEX8e0a54676ff2: dhcp: T3316: Kea DHCP and DHCPv6 fixes.
Dec 17 2023, 7:14 AM
sarthurdev added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).
  • with set service dhcp-server hostfile-update the file /etc/hosts doesn't get update with any entry from dhcp at all

Thanks, will investigate this.

@sdev, this will require adjusting on-dhcp-event.sh. I have a hacky local version that writes to /etc/hosts that partially works -- the $domain part is not picked up (which I suspect could be related to how kea-dhcp4.conf is generating the FQDN).

Do you want me to raise a draft PR for you to review?

Dec 17 2023, 12:56 AM · VyOS 1.5 Circinus
sarthurdev added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

Update PR: https://github.com/vyos/vyos-1x/pull/2646

Dec 17 2023, 12:55 AM · VyOS 1.5 Circinus
sarthurdev added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

@Zen3515

  • dhcp server doesn't start automatically after reboot, and due to the next problem, I'm forced to use set service dhcp-server disable then delete service dhcp-server disable after each boot

Could not reproduce this:

Welcome to VyOS - vyos ttyS0
...
vyos@vyos:~$ ps aux | grep kea
_kea        1818  1.6  0.9  67384 20324 ?        Ssl  00:14   0:00 /usr/sbin/kea-dhcp4 -c /run/kea/kea-dhcp4.conf
Dec 17 2023, 12:31 AM · VyOS 1.5 Circinus

Dec 13 2023

sarthurdev committed rVYOSONEX56a8eaeda7e8: dhcp: T3316: Fix dhcp op-mode state 'all' matching.
Dec 13 2023, 6:53 AM
sarthurdev committed rVYOSONEX7d50be0318db: dhcp: T3316: Fix raw op-mode lease output.
Dec 13 2023, 6:53 AM

Dec 12 2023

sarthurdev added a comment to T5820: error on dhcpv6-server range prefix with trailing colon (:).

I think this regex needs to be made more strict to prevent this issue.

Dec 12 2023, 11:46 PM · VyOS Rolling, Bugs

Dec 9 2023

sarthurdev committed rVYOSONEXd95200e96763: dhcp: T3316: Migrate dhcp/dhcpv6 server to Kea.
Dec 9 2023, 8:36 PM
sarthurdev committed rVYOSONEX4484a7398482: dhcp: T3316: Add captive portal v4/v6 options.
Dec 9 2023, 8:36 PM
sarthurdev committed rVYOSONEX2787e7915c12: dhcp: T3316: Add time-zone node for options 100 and 101.
Dec 9 2023, 8:36 PM

Oct 26 2023

sarthurdev closed T3509: No BCP38 for IPv6 on VyOS as Resolved.
Oct 26 2023, 12:49 PM · VyOS 1.4 Sagitta
sarthurdev closed T5558: Update config test to check resulting migrations as Resolved.
Oct 26 2023, 12:48 PM · VyOS 1.5 Circinus
sarthurdev closed T5568: Install image from live ISO always defaults boot to KVM entry as Resolved.
Oct 26 2023, 12:48 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev added a comment to T5606: IPSec VPN: Allow multiple CAs certificates.

@SrividyaA Can you confirm this is working as you expect?

Oct 26 2023, 12:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev closed T4309: Support network/address-groups and ipv6-network/ipv6-address-groups in "conntrack ignore" as Resolved.
Oct 26 2023, 12:41 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a project to T4309: Support network/address-groups and ipv6-network/ipv6-address-groups in "conntrack ignore": VyOS 1.5 Circinus.
Oct 26 2023, 12:41 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev moved T4903: Support IPv6 addresses in "set system conntrack ignore" from Finished to Backlog on the VyOS 1.4 Sagitta board.
Oct 26 2023, 12:40 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev moved T4903: Support IPv6 addresses in "set system conntrack ignore" from Open to Finished on the VyOS 1.5 Circinus board.
Oct 26 2023, 12:40 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a project to T4903: Support IPv6 addresses in "set system conntrack ignore": VyOS 1.5 Circinus.
Oct 26 2023, 12:40 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev closed T4903: Support IPv6 addresses in "set system conntrack ignore" as Resolved.
Oct 26 2023, 12:39 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a comment to T5550: Source validation on interface does not work properly.

@a.apostoliuk Can you confirm this is working as expected?

Oct 26 2023, 12:38 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev closed T5571: Firewall does not delete networks from the table raw as Resolved.
Oct 26 2023, 12:37 PM · VyOS 1.5 Circinus
sarthurdev closed T5598: unknown parameter 'nf_conntrack_helper' ignored as Resolved.
Oct 26 2023, 12:36 PM · VyOS 1.5 Circinus

Oct 12 2023

sarthurdev closed T5651: chain FW_CONNTRACK incorrectly use accept as action as Invalid.

If you don't use the firewall (statefully at least) then it will go through the FW_CONNTRACK chain and the NAT_CONNTRACK and/or WLB_CONNTRACK chains will be reached, or fall through to the notrack.

Oct 12 2023, 6:29 PM · VyOS 1.5 Circinus
sarthurdev closed T5651: chain FW_CONNTRACK incorrectly use accept as action as Invalid.

That is how the conntrack enabling system works. FW_CONNTRACK verdict is set to accept when it is determined the firewall needs conntracking (state rules, flowtable etc.), same for NAT_/WLB_ chains. If none require conntrack - all chains will be return and it falls down the chain to the final notrack and conntrack is not enabled.

Oct 12 2023, 5:29 PM · VyOS 1.5 Circinus

Sep 29 2023

sarthurdev committed rVYOSONEX42ff4d8a7ba7: conntrack: T5376: Fixes for conntrack-sync configdep.
Sep 29 2023, 1:39 PM

Sep 28 2023

sarthurdev committed rVYOSONEX6eda98d14ad9: firewall: T5217: Synproxy bugfix and ct state conflict checking.
Sep 28 2023, 7:16 PM
sarthurdev committed rVYOSONEXfd0bcaf120bc: conntrack: T5376: T5598: Fix for kernel conntrack helpers.
Sep 28 2023, 2:54 PM
sarthurdev committed rVYOSONEX5acf5acedbf7: conntrack: T5376: Use vyos.configdep to call conntrack-sync.
Sep 28 2023, 2:54 PM
sarthurdev committed rVYOSONEX81dee963a9ca: firewall: T5614: Add support for matching on conntrack helper.
Sep 28 2023, 2:52 PM
sarthurdev committed rVYOSONEX1ac230548c86: ipsec: T5606: Add support for whole CA chains.
Sep 28 2023, 2:43 PM

Sep 26 2023

sarthurdev committed rVYOSONEX9b9b37e9cbb2: firewall: T5160: Remove zone policy op-mode.
Sep 26 2023, 6:11 PM

Sep 24 2023

sarthurdev added a comment to T5599: Firewall unexpectedly changes some sysctl options.

Not sure what to do on this one. The firewall is depending on conntrack module, which updates the conntrack related sysctls. It'd be the same if someone defines custom sysctls used by other conf scripts.

Sep 24 2023, 6:30 PM · VyOS Rolling, Bugs
sarthurdev changed the status of T5614: Add conntrack helper matching on firewall from Open to In progress.
Sep 24 2023, 2:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev changed the status of T5606: IPSec VPN: Allow multiple CAs certificates from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2305

Sep 24 2023, 1:54 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev moved T5606: IPSec VPN: Allow multiple CAs certificates from Open to In Progress on the VyOS 1.5 Circinus board.
Sep 24 2023, 12:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a project to T5606: IPSec VPN: Allow multiple CAs certificates: VyOS 1.5 Circinus.
Sep 24 2023, 12:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev changed the status of T5606: IPSec VPN: Allow multiple CAs certificates from Open to In progress.
Sep 24 2023, 12:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a comment to T5160: Firewall refactor.

PR removing zone-policy op-mode: https://github.com/vyos/vyos-1x/pull/2304

Sep 24 2023, 11:44 AM · VyOS 1.4 Sagitta
sarthurdev changed the status of T5376: Conntrack FTP helper does not work properly from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2304

Sep 24 2023, 11:44 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
sarthurdev changed the status of T5598: unknown parameter 'nf_conntrack_helper' ignored from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2304

Sep 24 2023, 11:44 AM · VyOS 1.5 Circinus

Sep 21 2023

sarthurdev changed the status of T5376: Conntrack FTP helper does not work properly from Open to Confirmed.
Sep 21 2023, 9:49 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
sarthurdev changed the status of T5598: unknown parameter 'nf_conntrack_helper' ignored from Open to Confirmed.

This is likely also the issue causing T5376

Sep 21 2023, 9:49 AM · VyOS 1.5 Circinus

Sep 20 2023

sarthurdev committed rVYOSONEXcdbe969308c1: conntrack: firewall: T4502: Update conntrack check for new flowtable CLI.
Sep 20 2023, 4:12 AM

Sep 19 2023

sarthurdev added a comment to T4502: Consider implementing (NAT/other) flow table offload.

Perhaps a possible way to detect if the nic supports hardware flowtables or not.

Try to set sudo ethtool -K eth0 hw-tc-offload on.

If the result becomes:

Actual changes:
hw-tc-offload: off [requested on]
Could not change any device features

Then it doesnt support hardware flowtables.

Could also verify by reading the capability like so:

$ ethtool -k eth0 | grep hw-tc-offload
hw-tc-offload: off [fixed]
Sep 19 2023, 6:27 PM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX41133869c50c: firewall: T4502: Update to flowtable CLI.
Sep 19 2023, 4:48 PM
sarthurdev committed rVYOSONEXbbe32749e66c: firewall: ethernet: T4502: Add interface offload node and verify interface….
Sep 19 2023, 4:48 PM
sarthurdev committed rVYOSONEX0984a36f6d64: bridge: T4072: Prevent error when removing firewall bridge config.
Sep 19 2023, 4:48 PM

Sep 18 2023

sarthurdev committed rVYOSONEX4c9c2e372aa5: github: Update PR template with section of related PRs.
Sep 18 2023, 6:44 PM
sarthurdev committed rVYOSONEX416faf18d087: nat: Remove deprecated kernel check.
Sep 18 2023, 6:44 PM
sarthurdev committed rVYOSONEX734d84f69694: conntrack: T5571: Refactor conntrack to be independent conf script from….
Sep 18 2023, 6:44 PM
sarthurdev committed rVYOSONEXfb3ef9af5e39: conntrack: T5217: Add tcp flag matching to `system conntrack ignore`.
Sep 18 2023, 6:44 PM

Sep 16 2023

sarthurdev changed the status of T5571: Firewall does not delete networks from the table raw from Confirmed to Needs testing.

Fixed in PR: https://github.com/vyos/vyos-1x/pull/2276

Sep 16 2023, 11:45 AM · VyOS 1.5 Circinus

Sep 15 2023

sarthurdev added a comment to T5587: Firwall can not pass the smoketest.
Sep 15 2023, 8:48 AM · VyOS 1.5 Circinus
sarthurdev moved T5568: Install image from live ISO always defaults boot to KVM entry from Open to In Progress on the VyOS 1.4 Sagitta board.
Sep 15 2023, 8:18 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev added a comment to T5587: Firwall can not pass the smoketest.

https://github.com/vyos/vyos-1x/pull/2272 should fix this

Sep 15 2023, 8:00 AM · VyOS 1.5 Circinus

Sep 13 2023

sarthurdev changed the status of T5571: Firewall does not delete networks from the table raw from Open to Confirmed.
Sep 13 2023, 10:49 AM · VyOS 1.5 Circinus
sarthurdev added a comment to T4919: TPM-backed config encryption.

@fernando See here: https://github.com/vyos/vyos-build/pull/297

Sep 13 2023, 9:35 AM · VyOS Rolling, VyOS 1.5 Circinus

Sep 11 2023

sarthurdev closed T5562: Smoketests fail for vyos:current (test_netns.py) as Resolved.

Builds passing: https://github.com/vyos/vyos-rolling-nightly-builds/actions/runs/6142937552

Sep 11 2023, 8:59 AM · VyOS 1.5 Circinus
sarthurdev committed rVYOSONEXe46afa2c58ee: vxlan: T3700: Revert change to `vyos.utils.process.cmd`.
Sep 11 2023, 5:00 AM

Sep 10 2023

sarthurdev changed the status of T5568: Install image from live ISO always defaults boot to KVM entry from In progress to Needs testing.

current PR: https://github.com/vyos/vyatta-cfg-system/pull/205

Sep 10 2023, 11:22 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev changed the status of T5568: Install image from live ISO always defaults boot to KVM entry from Open to In progress.
Sep 10 2023, 10:54 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev added a comment to T5376: Conntrack FTP helper does not work properly.

Can we see the output of sudo nft list table ip raw on an affected router?

Sep 10 2023, 6:06 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus

Sep 8 2023

sarthurdev committed rVYOSONEX56a6e53f78f1: smoketest: T5558: Extend configtest to allow checking of migration script….
Sep 8 2023, 5:32 AM

Sep 7 2023

sarthurdev changed the status of T5558: Update config test to check resulting migrations from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2221

Sep 7 2023, 7:36 PM · VyOS 1.5 Circinus
sarthurdev moved T5558: Update config test to check resulting migrations from Open to In Progress on the VyOS 1.5 Circinus board.
Sep 7 2023, 5:53 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T5558: Update config test to check resulting migrations from Open to In progress.
Sep 7 2023, 5:53 PM · VyOS 1.5 Circinus
sarthurdev committed rVYOSONEXb357b70647c9: system: T5555: Fix time-zone migrator changing valid time-zones to UTC.
Sep 7 2023, 3:06 PM
sarthurdev committed rVYOSONEXd1edbfd18e71: system: T5555: Fix time-zone migrator changing valid time-zones to UTC.
Sep 7 2023, 2:17 PM
sarthurdev committed rVYOSONEXc85095572c0a: system: T5555: Fix time-zone migrator changing valid time-zones to UTC.
Sep 7 2023, 2:16 PM
sarthurdev moved T5555: Fix timezone migrator (system 13-to-14) from Need Triage to In Progress on the VyOS 1.3 Equuleus (1.3.5) board.
Sep 7 2023, 1:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev moved T5555: Fix timezone migrator (system 13-to-14) from Open to In Progress on the VyOS 1.5 Circinus board.
Sep 7 2023, 1:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev moved T5555: Fix timezone migrator (system 13-to-14) from Open to In Progress on the VyOS 1.4 Sagitta board.
Sep 7 2023, 1:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev changed the status of T5555: Fix timezone migrator (system 13-to-14) from In progress to Needs testing.

current PR: https://github.com/vyos/vyos-1x/pull/2217
1.4 PR: https://github.com/vyos/vyos-1x/pull/2218
1.3 PR: https://github.com/vyos/vyos-1x/pull/2219

Sep 7 2023, 12:54 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev changed the status of T5555: Fix timezone migrator (system 13-to-14) from Open to In progress.
Sep 7 2023, 12:29 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev created T5555: Fix timezone migrator (system 13-to-14).
Sep 7 2023, 12:29 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sep 6 2023

sarthurdev committed rVYOSONEX5a8e3089b35e: conntrack: T4309: T4903: Refactor `system conntrack ignore` rule generation….
Sep 6 2023, 6:26 PM
sarthurdev committed rVYOSONEX02d1cf37ef1a: conntrack: T4309: Add `conntrack ignore` smoketest.
Sep 6 2023, 6:26 PM
sarthurdev committed rVYOSONEX2c88d01697ee: nat: T1877: Fix typo in nat ConfigError.
Sep 6 2023, 6:26 PM
sarthurdev committed rVYOSONEX0de3de1e0a78: interface: T5550: Interface source-validation priority over global value.
Sep 6 2023, 6:25 PM