- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
All Stories
Apr 12 2024
The kernel still does not support it without patches
root@r4:/home/vyos# echo "65535" | tee /sys/class/net/br2/bridge/group_fwd_mask 65535 tee: /sys/class/net/br2/bridge/group_fwd_mask: Invalid argument root@r4:/home/vyos#
@tjh Do you still need this package? As it was relevant for ipset/iptables
iprange/stable 1.0.4+ds-2 amd64 optimizing ipsets for iptables
commit 40b0986d66c3a0891dedbedc273b5485e5a8ca3a Author: Lucas Christian <[email protected]> Date: Sat Feb 10 11:26:47 2024 -0800
@m.korobeinikov It could be a part of the existing op-mode generate interfaces debug-archive
Can you extend this script to include the required options and create a PR?
Closes it as wontfix
Note "Note that RFC 1701 is mentioned in MikroTik's docs but there is nothing in common between the standard and the actual protocol used."
Makes sense. Thanks.
You can create /use your own images
vyos@r4:~$ generate container image foo path Possible completions: <filename> Path to Dockerfile
It looks fixed by the upstream
64 bytes from 8.8.8.8: icmp_seq=18 ttl=116 time=20.1 ms 64 bytes from 8.8.8.8: icmp_seq=19 ttl=116 time=20.1 ms 64 bytes from 8.8.8.8: icmp_seq=20 ttl=116 time=20.0 ms 64 bytes from 8.8.8.8: icmp_seq=21 ttl=116 time=20.3 ms 64 bytes from 8.8.8.8: icmp_seq=22 ttl=116 time=20.1 ms 64 bytes from 8.8.8.8: icmp_seq=23 ttl=116 time=20.1 ms 64 bytes from 8.8.8.8: icmp_seq=24 ttl=116 time=20.1 ms 64 bytes from 8.8.8.8: icmp_seq=25 ttl=116 time=20.1 ms 64 bytes from 8.8.8.8: icmp_seq=26 ttl=116 time=20.1 ms
It is not backported to 1.4
So for 1.3, it won't be backported
It was implemented around a year ago https://github.com/vyos/vyos-1x/commit/e201454f073c9a92fb56b65f497eae55fc634521
Just need to check if it works as expected.
In T6222#183247, @Chrisc-c-c wrote:Wouldn’t your suggested fix to https://vyos.dev/T6223 also apply here? If the plan is to validate interface name lengths and allow custom names this would be a non-issue.
After considering, we decided that reset is the same as terminate.
If you want to add a feature start manual initialization, please create a feature request.
Here is an example of a perferctly valid vyos vpn config that will never recover a child SA when resetting it.
In 1.4 and 1.5 command reset vpn ipsec has a termination meaning.
No, it says reset, both the command, and auto complete output. It does not say terminate or clear. If you run a reset you do expect it to restart or re-populate in one way or another, not just stop working completley.
Just to make sure: This change is part of the current nightly build, right?