Page MenuHomeVyOS Platform
Feed All Stories

Feb 13 2024

adestis added a comment to T5493: Add capability to use local and external dynamic-lists for firewall rules but also for various policies such as access-list, route-maps etc..

@Apachez I would need this feature in another feature (https://vyos.dev/T6040) to avoid a double implementation.

Feb 13 2024, 4:20 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Viacheslav changed the status of T5064: Value validation for domain-groups seems to be broken from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/3000

Feb 13 2024, 4:17 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5359: VyOS user/pass remains in config, a subtask of T5907: cloud-init root task for 1.5 and 1.4 , from Open to Needs reporter action.
Feb 13 2024, 3:49 PM · VyOS Rolling
Viacheslav changed the status of T5359: VyOS user/pass remains in config from Open to Needs reporter action.

@greywolfe Any update?

Feb 13 2024, 3:49 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T5376: Conntrack FTP helper does not work properly from Needs testing to Needs reporter action.
Feb 13 2024, 3:47 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
Viacheslav added a comment to T5376: Conntrack FTP helper does not work properly.

@svd135 Can you recheck?

Feb 13 2024, 3:47 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
Viacheslav changed the status of T5481: Upgrade bug from Open to Needs reporter action.

@twan Could you try with the 1.4-rc3 image?

Feb 13 2024, 3:45 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T6040: Implement a firewall blacklisting solution from "Task" to "Feature Request".
Feb 13 2024, 3:43 PM · VyOS Rolling
Viacheslav changed the status of T5482: Chrony NTP Server Fails To Sync Time from Open to Needs reporter action.

@dcplaya provide the whole configuration to reproduce or close the task if the reason is firewall incorrect configuration.

Feb 13 2024, 3:42 PM · VyOS 1.4 Sagitta
adestis updated the task description for T6040: Implement a firewall blacklisting solution.
Feb 13 2024, 3:34 PM · VyOS Rolling
adestis created T6040: Implement a firewall blacklisting solution.
Feb 13 2024, 3:21 PM · VyOS Rolling
Viacheslav added a comment to T5928: Configuration fails to load on boot if offloading has VLAN interfaces defined.

PR https://github.com/vyos/vyos-1x/pull/2999

Feb 13 2024, 12:21 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5930: vrf - route-leak not work using route-target both command. from In progress to Needs testing.
Feb 13 2024, 11:12 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5982: Isolated interfaces smoketest fail as Not Applicable.
Feb 13 2024, 11:10 AM · VyOS 1.3 Equuleus (1.3.7)
sarthurdev changed the status of T5992: DHCP: show dhcp server leases not showing all leases from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2998

Feb 13 2024, 10:57 AM · VyOS 1.5 Circinus (2025.11)
sarthurdev removed a project from T2737: DHCP Lease not displayed with a static map: VyOS 1.5 Circinus.

Not an issue on 1.5 with Kea.

Feb 13 2024, 10:49 AM · Bugs, VyOS Rolling, VyOS 1.5 Circinus
lclements0 created T6039: cloud-init DNS search-domain causes configuration migration/validation error.
Feb 13 2024, 4:47 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX8c78ef0879f2: pki: T6034: add OpenSSH key support.
Feb 13 2024, 4:32 AM
c-po committed rVYOSONEX0f8bf6bd0fb2: pki: T6034: add dependencies to trigger rpki re-run on openssh key update.
Feb 13 2024, 4:32 AM
c-po committed rVYOSONEXac2d7dfac607: rpki: T6034: move SSH authentication keys to PKI subsystem.
Feb 13 2024, 4:32 AM
c-po committed rVYOSONEX4d76e9ef3e77: rpki: T6024: add migration scripts from file based keys to PKI subsystem.
Feb 13 2024, 4:32 AM
c-po committed rVYOSONEX78820752b936: rpki: T6034: remove OpenSSH keys from /run/frr when unloaded.
Feb 13 2024, 4:32 AM
sarthurdev committed rVYOSONEX3bfbbef22954: rpki: T6034: Add missing sections to configtest.
Feb 13 2024, 4:32 AM
GitHub <noreply@github.com> committed rVYOSONEX0732e89d561f: Merge pull request #2988 from c-po/pki-rpki-t6034 (authored by c-po).
Feb 13 2024, 4:32 AM
sarthurdev committed rVYOSONEX04bf9ee39f82: dhcpv6-server: T5993: Add subnet `interface` node, link subnet to locally….
Feb 13 2024, 4:12 AM
GitHub <noreply@github.com> committed rVYOSONEX87ddb8c5e89a: Merge pull request #2997 from sarthurdev/T5993 (authored by c-po).
Feb 13 2024, 4:12 AM

Feb 12 2024

sarthurdev changed the status of T5992: DHCP: show dhcp server leases not showing all leases from Confirmed to In progress.
Feb 12 2024, 11:51 PM · VyOS 1.5 Circinus (2025.11)
sarthurdev moved T5952: DHCP allow same MAC Address on same subnet from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 12 2024, 11:26 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev closed T5952: DHCP allow same MAC Address on same subnet as Resolved.
Feb 12 2024, 11:26 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev moved T5993: DHCP6: no leases are created unless specifying a "interface" on the zone from Open to In Progress on the VyOS 1.5 Circinus board.
Feb 12 2024, 11:05 PM · Bugs, VyOS Rolling, VyOS 1.5 Circinus
sarthurdev edited projects for T5993: DHCP6: no leases are created unless specifying a "interface" on the zone, added: VyOS 1.5 Circinus; removed VyOS 1.4 Sagitta.
Feb 12 2024, 11:05 PM · Bugs, VyOS Rolling, VyOS 1.5 Circinus
sarthurdev changed the status of T5993: DHCP6: no leases are created unless specifying a "interface" on the zone from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2997

Feb 12 2024, 11:05 PM · Bugs, VyOS Rolling, VyOS 1.5 Circinus
sarthurdev changed the status of T5993: DHCP6: no leases are created unless specifying a "interface" on the zone from Confirmed to In progress.
Feb 12 2024, 10:39 PM · Bugs, VyOS Rolling, VyOS 1.5 Circinus
jestabro edited a custom field on T5996: Incorrect behavior for backslash escapes in config save and compare commands.
Feb 12 2024, 9:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a comment to T5996: Incorrect behavior for backslash escapes in config save and compare commands.

This turns out to be non-trivial, due to the interaction between legacy and modern behavior; nonetheless, a simple preliminary fix is in testing, and the task will be updated with the details when the PR is complete.

Feb 12 2024, 9:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
GitHub <noreply@github.com> committed rVYOSONEX6f64847213a0: Merge pull request #2996 from vyos/mergify/bp/sagitta/pr-2993 (authored by c-po).
Feb 12 2024, 8:46 PM
c-po closed T5849: Add SRv6 route commands, a subtask of T591: Support SRv6, as Resolved.
Feb 12 2024, 8:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po closed T5849: Add SRv6 route commands as Resolved.
Feb 12 2024, 8:44 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po closed T5849: Add SRv6 route commands, a subtask of T5788: frr: update to 9.1 release, as Resolved.
Feb 12 2024, 8:44 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po moved T5849: Add SRv6 route commands from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 12 2024, 8:44 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po closed T6010: Support setting multiple values in BGP path-attribute as Resolved.
Feb 12 2024, 8:44 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po moved T6010: Support setting multiple values in BGP path-attribute from In Progress to Finished on the VyOS 1.4 Sagitta board.
Feb 12 2024, 8:44 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po closed T6004: Missing RPKI boot priority prevents it from loading, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
Feb 12 2024, 8:43 PM · VyOS Rolling, Bugs
c-po closed T6004: Missing RPKI boot priority prevents it from loading as Resolved.
Feb 12 2024, 8:43 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa2)
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX61c7202b11d0: ipsec: T5981: Strip '@' from migrated peer name (authored by sarthurdev).
Feb 12 2024, 8:43 PM
sarthurdev committed rVYOSONEX8238f8cdae3a: ipsec: T5981: Strip '@' from migrated peer name.
Feb 12 2024, 8:42 PM
GitHub <noreply@github.com> committed rVYOSONEXfe9147623c9f: Merge pull request #2993 from sarthurdev/T5981 (authored by c-po).
Feb 12 2024, 8:42 PM
GitHub <noreply@github.com> committed rVYOSONEX939e06bcab7d: Merge pull request #2995 from vyos/mergify/bp/sagitta/pr-2994 (authored by c-po).
Feb 12 2024, 8:40 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXe021dee485fb: init: T2044: fix "binary operator expected" when two or more RPKI caches are… (authored by c-po).
Feb 12 2024, 8:33 PM
c-po moved T6032: bgp: add EVPN MAC-VRF Site-of-Origin support from Open to In Progress on the VyOS 1.4 Sagitta board.
Feb 12 2024, 8:33 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po moved T6032: bgp: add EVPN MAC-VRF Site-of-Origin support from Open to Finished on the VyOS 1.5 Circinus board.
Feb 12 2024, 8:33 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po added a comment to T6032: bgp: add EVPN MAC-VRF Site-of-Origin support.

https://github.com/vyos/vyos-1x/pull/2987

Feb 12 2024, 8:32 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po committed rVYOSONEXa5ac522f8c67: init: T2044: fix "binary operator expected" when two or more RPKI caches are….
Feb 12 2024, 8:32 PM
GitHub <noreply@github.com> committed rVYOSONEX69a0fa708654: Merge pull request #2994 from c-po/init-T2044 (authored by c-po).
Feb 12 2024, 8:32 PM
sarthurdev added a comment to T5993: DHCP6: no leases are created unless specifying a "interface" on the zone.

This does seem to be new behaviour introduced with Kea. ISC dhcpd did previously assume local distribution of a subnet based on the interface having an address within the subnet, Kea has changed to require this being explicitly defined.

Feb 12 2024, 8:23 PM · Bugs, VyOS Rolling, VyOS 1.5 Circinus
sarthurdev moved T5981: IPsec site-to-site migrated PKI ca certificates are created with an '@' from Open to In Progress on the VyOS 1.5 Circinus board.
Feb 12 2024, 8:10 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev changed the status of T5981: IPsec site-to-site migrated PKI ca certificates are created with an '@' from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2993

Feb 12 2024, 8:10 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev changed the status of T3771: DHCPv6 server prefix delegation - dynamically add route to delegated prefix via requesting router from In progress to Needs testing.
Feb 12 2024, 7:47 PM · VyOS 1.5 Circinus
thannaske created T6038: Losing default route after first reboot (cloud-init & DHCP).
Feb 12 2024, 6:30 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
evilmog added a comment to T6036: OpenVPN Register client names in DNS via learn-address.

I'm thinking end of the day an integrated learn address script that can update vyos's forwarder or any of the upstream DNS its using, and then calling learn-address on each client learned in the openvpn is the ideal way to do it since learn-address is built into openvpn

Feb 12 2024, 6:00 PM · VyOS Rolling
evilmog added a comment to T6036: OpenVPN Register client names in DNS via learn-address.

Here is a redacted version

Feb 12 2024, 5:59 PM · VyOS Rolling
Viacheslav triaged T6037: QoS policy limiter without specified class selector error as Normal priority.
Feb 12 2024, 5:16 PM · VyOS 1.5 Circinus
Viacheslav updated the task description for T6037: QoS policy limiter without specified class selector error.
Feb 12 2024, 5:15 PM · VyOS 1.5 Circinus
Viacheslav created T6037: QoS policy limiter without specified class selector error.
Feb 12 2024, 5:14 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T6036: OpenVPN Register client names in DNS via learn-address.

@evilmog Can you provide the OpenVPN/other configuration to achieve what you want?

Feb 12 2024, 5:07 PM · VyOS Rolling
n.fort changed the status of T6019: Bump nftables and libnftnl version from In progress to Needs testing.
Feb 12 2024, 5:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T6009: Firewall - Time not working properly when not using UTC from In progress to Needs testing.
Feb 12 2024, 5:05 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
evilmog created T6036: OpenVPN Register client names in DNS via learn-address.
Feb 12 2024, 4:38 PM · VyOS Rolling
Viacheslav changed the status of T1317: OpenVPN configuration fails if it depends on another interface. from In progress to Needs reporter action.

Wait two weeks before closing.
@mb300sd Let us know if it is fixed.

Feb 12 2024, 4:26 PM · VyOS 1.3 Equuleus (1.3.9), test
GitHub <noreply@github.com> committed rVYOSONEX2291f78ed31a: Merge pull request #2992 from vyos/mergify/bp/sagitta/pr-2991 (authored by dmbaturin).
Feb 12 2024, 4:15 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXcc0f08c94b9e: T6019: fix smoketest after upgrading nftables and libnftnl packages. (authored by n.fort).
Feb 12 2024, 3:52 PM
n.fort committed rVYOSONEXf3205d6dd1ea: T6019: fix smoketest after upgrading nftables and libnftnl packages..
Feb 12 2024, 3:52 PM
GitHub <noreply@github.com> committed rVYOSONEX19df28989d72: Merge pull request #2991 from nicolas-fort/T6019 (authored by c-po).
Feb 12 2024, 3:52 PM
Viacheslav triaged T6035: random-detect QoS policies cause commit failures due to a missing tc parameter (avpkt) as Normal priority.
Feb 12 2024, 3:07 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav created T6035: random-detect QoS policies cause commit failures due to a missing tc parameter (avpkt).
Feb 12 2024, 3:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav moved T3843: l2tp configuration not cleared after delete from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 12 2024, 2:25 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
Viacheslav moved T3843: l2tp configuration not cleared after delete from Open to Finished on the VyOS 1.5 Circinus board.
Feb 12 2024, 2:25 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
Viacheslav added a comment to T3843: l2tp configuration not cleared after delete.

It cannot be backported to 1.3 as there are no config-mode-dependencies

Feb 12 2024, 2:24 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
Viacheslav added a comment to T2505: XCP-ng packet drops for small packets (e.g. icmp) under Xen and AWS.

There have been no reports since 2021

Feb 12 2024, 2:21 PM · VyOS Rolling, Bugs, VyOS 1.4 Sagitta (1.4.1)
danhusan added a comment to T5811: static dhcp-interface routes not installed.

@Viacheslav

Feb 12 2024, 1:00 PM · VyOS 1.5 Circinus (2025.11)
n.fort added a comment to T6019: Bump nftables and libnftnl version.

PR for fix in vyos-build: https://github.com/vyos/vyos-build/pull/501
PR for smoketest (modified because of change in build): https://github.com/vyos/vyos-1x/pull/2991

Feb 12 2024, 12:44 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T6009: Firewall - Time not working properly when not using UTC.

PR for fix in vyos-build: https://github.com/vyos/vyos-build/pull/501
PR for smoketest (modified because of change in build): https://github.com/vyos/vyos-1x/pull/2991

Feb 12 2024, 12:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Sonicbx added a comment to T2505: XCP-ng packet drops for small packets (e.g. icmp) under Xen and AWS.

What is the resolution? How was it resolved? @Viacheslav

Feb 12 2024, 12:40 PM · VyOS Rolling, Bugs, VyOS 1.4 Sagitta (1.4.1)
syncer renamed Customer request from Customer ticket to Customer request.
Feb 12 2024, 12:29 PM
dmbaturin created Customer request.
Feb 12 2024, 12:26 PM
HollyGurza changed the status of T6020: VRRP health-check script is not applied correctly in keepalived.conf from Open to In progress.
Feb 12 2024, 11:32 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
HollyGurza claimed T3843: l2tp configuration not cleared after delete.
Feb 12 2024, 11:32 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
HollyGurza claimed T6020: VRRP health-check script is not applied correctly in keepalived.conf.
Feb 12 2024, 11:31 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
dmbaturin added a member for Maintainers: natali-rs1985.
Feb 12 2024, 11:24 AM
dmbaturin added a member for Maintainers: HollyGurza.
Feb 12 2024, 11:24 AM
dmbaturin removed a member for Maintainers: Unknown Object (User).
Feb 12 2024, 11:23 AM
dmbaturin changed the edit policy for T6020: VRRP health-check script is not applied correctly in keepalived.conf.
Feb 12 2024, 11:22 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav moved T5926: IPSEC does not apply after l2tp configuration was changed from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 12 2024, 10:35 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
Viacheslav moved T5926: IPSEC does not apply after l2tp configuration was changed from Open to Finished on the VyOS 1.5 Circinus board.
Feb 12 2024, 10:35 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
Viacheslav edited projects for T4393: sstp: add support for configuring host-name (SNI), added: VyOS 1.5 Circinus; removed VyOS 1.3 Equuleus (1.3.7).
Feb 12 2024, 10:30 AM · VyOS 1.4 Sagitta (1.4.0-GA)
adestis added a comment to T4797: External address/network lists for firewall (Local and remote).

@TheSin- we also need this feature because our old blacklisting implementation is no longer working since the new nft implementation replaces sets after changes in the config.
So we have to go the official way and I just stumbled over your feature request when I started to make my own implementation.
Even when I have not implemented any core parts for VyOS yet, I offer my help with the implementation of this feature.

Feb 12 2024, 10:14 AM · VyOS Rolling
Viacheslav reopened T1311: WAN load-balancing can't flush connections when conntrack-sync is enabled as "Open".
Feb 12 2024, 9:45 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, test
Viacheslav closed T1311: WAN load-balancing can't flush connections when conntrack-sync is enabled as Resolved.
Feb 12 2024, 9:44 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, test
Viacheslav closed T1941: Config mismatch with FRR on misconfiguration of V6 peer, a subtask of T2174: Rewrite protocol BGP to new XML/Python style, as Wontfix.
Feb 12 2024, 9:24 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T1941: Config mismatch with FRR on misconfiguration of V6 peer as Wontfix.
Feb 12 2024, 9:24 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta