Page MenuHomeVyOS Platform
Feed Search

Apr 8 2024

n.fort created T6213: Validations in firewall groups mistakenly reject correct configurations.
Apr 8 2024, 11:11 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 5 2024

n.fort changed the status of T6205: ipoe: error in migration script logic while renaming mac-address to mac, a subtask of T5938: Migration fail root task for 1.4-rc, from Open to Confirmed.
Apr 5 2024, 2:59 PM · VyOS Rolling, Bugs
n.fort changed the status of T6205: ipoe: error in migration script logic while renaming mac-address to mac from Open to Confirmed.
Apr 5 2024, 2:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 4 2024

n.fort committed rVYOSONEX5cb8e7862698: T6068: dhcp-server: add command <set service dhcp-server high-availability….
Apr 4 2024, 3:11 PM
n.fort committed rVYOSONEXc6e80f7ab8a2: T6068: T6171: change <fail-over> node from dhcp-server to <high-availability>..
Apr 4 2024, 11:56 AM

Apr 3 2024

n.fort added a comment to T6171: Rename the DHCP server "failover" command to "high-availability mode".

PR for Sagitta: https://github.com/vyos/vyos-1x/pull/3239

Apr 3 2024, 6:09 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6068: Support active-active and active-passive high availability modes in DHCP server.

PR for Sagitta: https://github.com/vyos/vyos-1x/pull/3239

Apr 3 2024, 6:09 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6200: Error on adding a wildcard interface.

Try with:

Apr 3 2024, 6:08 PM · VyOS 1.4 Sagitta

Mar 26 2024

n.fort committed rVYOSONEX38b2390bc084: T6171: dhcp-server: add fix for smoketest.
Mar 26 2024, 12:32 PM

Mar 25 2024

n.fort committed rVYOSONEX98f923bd0f4d: T6171: migrate <set service dhcp-server failover> to <set service dhcp-server….
Mar 25 2024, 7:28 PM
n.fort added a comment to T6171: Rename the DHCP server "failover" command to "high-availability mode".

PR for current: https://github.com/vyos/vyos-1x/pull/3188

Mar 25 2024, 6:40 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T6171: Rename the DHCP server "failover" command to "high-availability mode" from Open to In progress.
Mar 25 2024, 2:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort created T6171: Rename the DHCP server "failover" command to "high-availability mode".
Mar 25 2024, 2:41 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 22 2024

n.fort closed T6110: Insufficient validation of range option with failover in DHCP server as Resolved.
Mar 22 2024, 3:07 PM · VyOS 1.3 Equuleus (1.3.7)
n.fort moved T6136: Configuring a dynamic address group, config script did not check whether the group was created from Open to Finished on the VyOS 1.5 Circinus board.
Mar 22 2024, 3:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort closed T6136: Configuring a dynamic address group, config script did not check whether the group was created as Resolved.
Mar 22 2024, 3:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort moved T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity from Open to Finished on the VyOS 1.5 Circinus board.
Mar 22 2024, 3:04 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort closed T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
Mar 22 2024, 3:04 PM · VyOS Rolling, Bugs
n.fort closed T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity as Resolved.
Mar 22 2024, 3:04 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6068: Support active-active and active-passive high availability modes in DHCP server.
Mar 22 2024, 2:40 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T6068: Support active-active and active-passive high availability modes in DHCP server from Open to In progress.
Mar 22 2024, 10:59 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 20 2024

n.fort added a project to T6147: Conntrack not working as expected with global state-policy: VyOS 1.5 Circinus.
Mar 20 2024, 6:56 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T6147: Conntrack not working as expected with global state-policy from Open to Confirmed.
Mar 20 2024, 6:52 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort created T6147: Conntrack not working as expected with global state-policy.
Mar 20 2024, 6:51 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 19 2024

n.fort changed the status of T6136: Configuring a dynamic address group, config script did not check whether the group was created from In progress to Needs testing.
Mar 19 2024, 8:36 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 18 2024

n.fort committed rVYOSONEXe2df1f492977: T6136: add error checks when using dynamic firewall groups.
Mar 18 2024, 5:55 PM
n.fort changed the status of T6136: Configuring a dynamic address group, config script did not check whether the group was created from Confirmed to In progress.
Mar 18 2024, 3:01 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6136: Configuring a dynamic address group, config script did not check whether the group was created.

And a simple note for your usage @wenzk
Change
set firewall ipv4 name WAN_IN rule 30 icmp
to this:
set firewall ipv4 name WAN_IN rule 30 protocol icmp

Mar 18 2024, 3:00 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6136: Configuring a dynamic address group, config script did not check whether the group was created.

PR: https://github.com/vyos/vyos-1x/pull/3146

Mar 18 2024, 2:57 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort claimed T6136: Configuring a dynamic address group, config script did not check whether the group was created.
Mar 18 2024, 10:03 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 16 2024

n.fort committed rVYOSONEX1048f49e403d: T6090: fix policy route migration script. Ensure that tcp flags migration….
Mar 16 2024, 8:46 AM

Mar 15 2024

n.fort added a comment to T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity.

PR for 1.5: https://github.com/vyos/vyos-1x/pull/3137

Mar 15 2024, 9:45 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a project to T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity: VyOS 1.5 Circinus.
Mar 15 2024, 9:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity, a subtask of T5938: Migration fail root task for 1.4-rc, from Open to Confirmed.
Mar 15 2024, 2:33 PM · VyOS Rolling, Bugs
n.fort changed the status of T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity from Open to Confirmed.
Mar 15 2024, 2:33 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 14 2024

n.fort committed rVYOSONEXd56b4c05726d: T6110: dhcp: add error check when fail-over is enabled on a subnet, but range….
Mar 14 2024, 4:10 PM

Mar 8 2024

n.fort added a comment to T6110: Insufficient validation of range option with failover in DHCP server.

PR: https://github.com/vyos/vyos-1x/pull/3111

Mar 8 2024, 3:16 PM · VyOS 1.3 Equuleus (1.3.7)
n.fort changed the status of T6110: Insufficient validation of range option with failover in DHCP server from Open to Confirmed.
Mar 8 2024, 2:27 PM · VyOS 1.3 Equuleus (1.3.7)
n.fort created T6110: Insufficient validation of range option with failover in DHCP server.
Mar 8 2024, 2:27 PM · VyOS 1.3 Equuleus (1.3.7)
n.fort closed T6086: NAT does not work with network-groups as Resolved.
Mar 8 2024, 12:01 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort closed T6075: Applying firewall rules with a non-existent interface group as Resolved.
Mar 8 2024, 11:32 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort closed T6061: connection-status nat destination firewall filter not working in 1.4.0-epa1 as Resolved.
Mar 8 2024, 11:32 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort closed T6094: Destination Nat not Making Firewall Rules as Resolved.
Mar 8 2024, 11:31 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus

Mar 6 2024

n.fort changed the status of T6097: vrf_zones blocking ipv6 traffic from Open to Confirmed.
Mar 6 2024, 1:32 PM · VyOS Rolling, VyOS 1.5 Circinus
n.fort changed the status of T6094: Destination Nat not Making Firewall Rules from In progress to Needs testing.
Mar 6 2024, 1:27 PM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
n.fort changed the status of T6061: connection-status nat destination firewall filter not working in 1.4.0-epa1 from In progress to Needs testing.
Mar 6 2024, 1:24 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort changed the status of T6075: Applying firewall rules with a non-existent interface group from In progress to Needs testing.
Mar 6 2024, 1:24 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort committed rVYOSONEX3c0634e572ff: T6075: firewall and NAT: check if interface-group exists when using them in….
Mar 6 2024, 11:33 AM
n.fort committed rVYOSONEX8f2534e9654b: T6061: fix rule parsing when connection-status is used.
Mar 6 2024, 4:32 AM

Mar 5 2024

n.fort added a comment to T6075: Applying firewall rules with a non-existent interface group.

PR: https://github.com/vyos/vyos-1x/pull/3088

Mar 5 2024, 1:49 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort changed the status of T6075: Applying firewall rules with a non-existent interface group from Open to In progress.
Mar 5 2024, 1:32 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort changed the status of T6094: Destination Nat not Making Firewall Rules from Open to In progress.
Mar 5 2024, 11:04 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
n.fort raised the priority of T6061: connection-status nat destination firewall filter not working in 1.4.0-epa1 from Normal to High.
Mar 5 2024, 11:03 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort changed the status of T6061: connection-status nat destination firewall filter not working in 1.4.0-epa1 from Open to In progress.

PR: https://github.com/vyos/vyos-1x/pull/3087

Mar 5 2024, 11:02 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort added a comment to T6094: Destination Nat not Making Firewall Rules.

PR: https://github.com/vyos/vyos-1x/pull/3087

Mar 5 2024, 11:01 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus

Mar 4 2024

n.fort added a comment to T6094: Destination Nat not Making Firewall Rules.

Duplicated: https://vyos.dev/T6061

Mar 4 2024, 3:20 PM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
n.fort changed the status of T6086: NAT does not work with network-groups from In progress to Needs testing.
Mar 4 2024, 2:02 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort committed rVYOSONEXa7a0c90404d0: T6086: NAT: fix nat rules when using source-groups and translation address is a….
Mar 4 2024, 1:50 PM
n.fort claimed T6061: connection-status nat destination firewall filter not working in 1.4.0-epa1.
Mar 4 2024, 1:38 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort changed the status of T6086: NAT does not work with network-groups from Confirmed to In progress.
Mar 4 2024, 11:37 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort added a comment to T6086: NAT does not work with network-groups.

PR: https://github.com/vyos/vyos-1x/pull/3080

Mar 4 2024, 11:37 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
n.fort closed T6054: load-balancing wan - doesn't configure a list of ports as Resolved.
Mar 4 2024, 10:06 AM · VyOS 1.4 Sagitta (1.4.0-epa2)

Feb 23 2024

n.fort committed rVYOSONEX6d79c73d4fa2: T6054: WLB: fix rules parsing when using multiple ports in one rule.
Feb 23 2024, 2:22 PM
n.fort added a comment to T6054: load-balancing wan - doesn't configure a list of ports .

PR: https://github.com/vyos/vyos-1x/pull/3042

Feb 23 2024, 2:16 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
n.fort changed the status of T6054: load-balancing wan - doesn't configure a list of ports from Open to Confirmed.
Feb 23 2024, 12:31 PM · VyOS 1.4 Sagitta (1.4.0-epa2)

Feb 20 2024

n.fort added a project to T6049: wwan didn't setup static IP addres and MTU on wwan0: VyOS 1.4 Sagitta.
Feb 20 2024, 6:48 PM · Bugs, VyOS Rolling

Feb 16 2024

n.fort moved T6019: Bump nftables and libnftnl version from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 16 2024, 10:35 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort closed T6019: Bump nftables and libnftnl version as Resolved.
Feb 16 2024, 10:34 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort moved T6009: Firewall - Time not working properly when not using UTC from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 16 2024, 10:33 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort closed T6009: Firewall - Time not working properly when not using UTC as Resolved.
Feb 16 2024, 10:33 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Feb 12 2024

n.fort changed the status of T6019: Bump nftables and libnftnl version from In progress to Needs testing.
Feb 12 2024, 5:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T6009: Firewall - Time not working properly when not using UTC from In progress to Needs testing.
Feb 12 2024, 5:05 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort committed rVYOSONEXf3205d6dd1ea: T6019: fix smoketest after upgrading nftables and libnftnl packages..
Feb 12 2024, 3:52 PM
n.fort added a comment to T6019: Bump nftables and libnftnl version.

PR for fix in vyos-build: https://github.com/vyos/vyos-build/pull/501
PR for smoketest (modified because of change in build): https://github.com/vyos/vyos-1x/pull/2991

Feb 12 2024, 12:44 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T6009: Firewall - Time not working properly when not using UTC.

PR for fix in vyos-build: https://github.com/vyos/vyos-build/pull/501
PR for smoketest (modified because of change in build): https://github.com/vyos/vyos-1x/pull/2991

Feb 12 2024, 12:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Feb 6 2024

n.fort changed the status of T6019: Bump nftables and libnftnl version from Open to In progress.
Feb 6 2024, 11:58 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort created T6019: Bump nftables and libnftnl version.
Feb 6 2024, 11:57 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Feb 5 2024

n.fort added a comment to T445: iptables error with policy routing.

What version? Can you upgrade to 1.4?

Feb 5 2024, 9:37 PM · VyOS 1.3 Equuleus (1.3.8), test
n.fort changed the status of T6009: Firewall - Time not working properly when not using UTC from Confirmed to In progress.
Feb 5 2024, 10:17 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Feb 2 2024

n.fort changed the status of T6009: Firewall - Time not working properly when not using UTC from Open to Confirmed.
Feb 2 2024, 11:08 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort updated the task description for T6009: Firewall - Time not working properly when not using UTC.
Feb 2 2024, 11:05 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort created T6009: Firewall - Time not working properly when not using UTC.
Feb 2 2024, 11:03 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Feb 1 2024

n.fort committed rVYOSONEX6ce5fedb602c: T4839: firewall: Add dynamic address group in firewall configuration, and….
Feb 1 2024, 8:22 PM
n.fort changed the status of T5977: nftables: Operation not supported when using match-ipsec in outbound firewall from In progress to Needs testing.
Feb 1 2024, 10:21 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
n.fort committed rVYOSONEX9d490ecf616e: T5977: firewall: remove ipsec options in output chain rule definitions, since….
Feb 1 2024, 7:15 AM

Jan 26 2024

n.fort closed T5779: custom conntrack timeout rule not applicable as Resolved.
Jan 26 2024, 7:18 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort closed T5957: Firewall fails to delete inbound-interface name as Resolved.
Jan 26 2024, 7:18 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Jan 23 2024

n.fort added a comment to T5977: nftables: Operation not supported when using match-ipsec in outbound firewall.

Pr for 1.5: https://github.com/vyos/vyos-1x/pull/2887

Jan 23 2024, 8:27 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
n.fort added a project to T5977: nftables: Operation not supported when using match-ipsec in outbound firewall: VyOS 1.5 Circinus.
Jan 23 2024, 11:47 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
n.fort changed the status of T5977: nftables: Operation not supported when using match-ipsec in outbound firewall from Confirmed to In progress.
Jan 23 2024, 11:47 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
n.fort changed the status of T5977: nftables: Operation not supported when using match-ipsec in outbound firewall from Open to Confirmed.
Jan 23 2024, 10:49 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus

Jan 22 2024

n.fort changed the status of T5957: Firewall fails to delete inbound-interface name from In progress to Needs testing.
Jan 22 2024, 2:19 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort reopened T5779: custom conntrack timeout rule not applicable as "Needs testing".
Jan 22 2024, 2:19 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort moved T5160: Firewall refactor from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 22 2024, 2:12 PM · VyOS 1.4 Sagitta
n.fort closed T5160: Firewall refactor as Resolved.
Jan 22 2024, 2:09 PM · VyOS 1.4 Sagitta
n.fort committed rVYOSONEX0a436e1fce66: T5957: fix removal of interface in firewall rules..
Jan 22 2024, 12:17 PM
n.fort changed the status of T5957: Firewall fails to delete inbound-interface name from Confirmed to In progress.
Jan 22 2024, 11:39 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5957: Firewall fails to delete inbound-interface name.

PR: https://github.com/vyos/vyos-1x/pull/2873

Jan 22 2024, 11:39 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Jan 12 2024

n.fort committed rVYOSONEX5c4c873f9c36: T5922: firewall: fix intra-zone filtering parsing rules; update firewall….
Jan 12 2024, 4:02 PM
n.fort added a comment to T5922: Firewall - bug in zone config.

PR: https://github.com/vyos/vyos-1x/pull/2807

Jan 12 2024, 3:03 PM · VyOS 1.5 Circinus