Page MenuHomeVyOS Platform
Feed All Stories

May 17 2024

jestabro moved T6356: Correct the syntax of config.boot.default [..., 'ntp', 'server'] from leaf node with value to tag node from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 17 2024, 2:58 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a comment to T6344: multiple ntp listen-address commands not working.

Maybe we should create another xml file identical to listen-address.xml.i but without multi option define in line 16.

May 17 2024, 2:55 PM · VyOS 1.4 Sagitta
n.fort added a comment to T6344: multiple ntp listen-address commands not working.

Maybe we should create another xml file identical to listen-address.xml.i but without multi option define in line 16.

May 17 2024, 2:19 PM · VyOS 1.4 Sagitta
natali-rs1985 changed the status of T5487: OPENVPN -DEPRECATED OPTION: --cipher from Confirmed to In progress.
May 17 2024, 11:02 AM · VyOS 1.5 Circinus, Restricted Project
n.fort added a comment to T6362: Create a conntrack/translations logger daemon.

Related to https://vyos.dev/T5471 ?

May 17 2024, 10:53 AM · VyOS 1.5 Circinus
Viacheslav triaged T6362: Create a conntrack/translations logger daemon as Wishlist priority.
May 17 2024, 10:40 AM · VyOS 1.5 Circinus
Viacheslav added a subtask for T5169: Add CGNAT Carrier-Grade NAT based on nftables: T6362: Create a conntrack/translations logger daemon.
May 17 2024, 10:40 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a parent task for T6362: Create a conntrack/translations logger daemon: T5169: Add CGNAT Carrier-Grade NAT based on nftables.
May 17 2024, 10:40 AM · VyOS 1.5 Circinus
Viacheslav created T6362: Create a conntrack/translations logger daemon.
May 17 2024, 10:39 AM · VyOS 1.5 Circinus
Viacheslav added a subtask for T5169: Add CGNAT Carrier-Grade NAT based on nftables: T6361: Integrate Port Control Protocol (PCP) RFC 6887.
May 17 2024, 10:17 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a parent task for T6361: Integrate Port Control Protocol (PCP) RFC 6887: T5169: Add CGNAT Carrier-Grade NAT based on nftables.
May 17 2024, 10:17 AM · VyOS 1.5 Circinus
Viacheslav triaged T6361: Integrate Port Control Protocol (PCP) RFC 6887 as Low priority.
May 17 2024, 10:17 AM · VyOS 1.5 Circinus
Viacheslav created T6361: Integrate Port Control Protocol (PCP) RFC 6887.
May 17 2024, 10:16 AM · VyOS 1.5 Circinus
Viacheslav added a subtask for T5169: Add CGNAT Carrier-Grade NAT based on nftables: T6360: CGNAT add the ability to exclude (bypass) the translations for specific destinations.
May 17 2024, 9:57 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a parent task for T6360: CGNAT add the ability to exclude (bypass) the translations for specific destinations: T5169: Add CGNAT Carrier-Grade NAT based on nftables.
May 17 2024, 9:57 AM · VyOS 1.5 Circinus
Viacheslav triaged T6360: CGNAT add the ability to exclude (bypass) the translations for specific destinations as Wishlist priority.
May 17 2024, 9:57 AM · VyOS 1.5 Circinus
Viacheslav created T6360: CGNAT add the ability to exclude (bypass) the translations for specific destinations.
May 17 2024, 9:56 AM · VyOS 1.5 Circinus
HollyGurza added a comment to T6354: Get rid of the custom boot type check in version.py.

https://github.com/vyos/vyos-1x/pull/3474

May 17 2024, 9:31 AM · VyOS 1.5 Circinus
natali-rs1985 changed Is it a breaking change? from compatible to syntax on T5487: OPENVPN -DEPRECATED OPTION: --cipher.
May 17 2024, 9:21 AM · VyOS 1.5 Circinus, Restricted Project
Viacheslav closed T6347: CGNAT external pools containing dashes cause Traceback error, a subtask of T5169: Add CGNAT Carrier-Grade NAT based on nftables, as Resolved.
May 17 2024, 9:15 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav closed T6347: CGNAT external pools containing dashes cause Traceback error as Resolved.
May 17 2024, 9:15 AM · VyOS 1.5 Circinus
Viacheslav closed T6351: CGNAT add check if external and internal pools exists, a subtask of T5169: Add CGNAT Carrier-Grade NAT based on nftables, as Resolved.
May 17 2024, 9:14 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav closed T6351: CGNAT add check if external and internal pools exists as Resolved.
May 17 2024, 9:14 AM · VyOS 1.5 Circinus
Viacheslav closed T6350: CGNAT add op-mode to get current port allocation mapping, a subtask of T5169: Add CGNAT Carrier-Grade NAT based on nftables, as Resolved.
May 17 2024, 9:14 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav closed T6350: CGNAT add op-mode to get current port allocation mapping as Resolved.
May 17 2024, 9:14 AM · VyOS 1.5 Circinus
Viacheslav triaged T6346: Boot to multi-user.target instead of graphical.target as Normal priority.
May 17 2024, 9:12 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
Viacheslav triaged T6343: Firewall source validation loose end up in complete traffic block on VRF interface as Normal priority.
May 17 2024, 9:12 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6357: Create test repository to validate setup as Normal priority.
May 17 2024, 9:12 AM · GitHub Infrastructure
a.apostoliuk changed the status of T6359: Multicast does not forward after reboot from Open to In progress.
May 17 2024, 8:35 AM · VyOS 1.3 Equuleus (1.3.8)
a.apostoliuk triaged T6359: Multicast does not forward after reboot as Normal priority.
May 17 2024, 8:33 AM · VyOS 1.3 Equuleus (1.3.8)
a.apostoliuk created T6359: Multicast does not forward after reboot.
May 17 2024, 8:32 AM · VyOS 1.3 Equuleus (1.3.8)
Viacheslav triaged T6358: Container config option to enable host pid as Wishlist priority.
May 17 2024, 8:29 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
nvollmar created T6358: Container config option to enable host pid.
May 17 2024, 8:24 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
syncer created T6357: Create test repository to validate setup.
May 17 2024, 7:55 AM · GitHub Infrastructure
a.apostoliuk placed T6157: Can not create two GRE tunnels to the same DST but from different SRC addresses up for grabs.
May 17 2024, 7:37 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
a.apostoliuk changed the status of T6157: Can not create two GRE tunnels to the same DST but from different SRC addresses from In progress to Open.
May 17 2024, 7:37 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Viacheslav added a comment to T5835: UPnP port mapping / rule installation fails.

I'd prefer to integrate the Port Control Protocol (PCP) instead.

pcp.png (410×767 px, 50 KB)

May 17 2024, 7:34 AM
a.apostoliuk placed T5710: PPPoE-server add option permit any-login up for grabs.
May 17 2024, 7:07 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a comment to T5835: UPnP port mapping / rule installation fails.

You can still have it in a container easily; as I mentioned, it has never worked since 2021
You do not lose anything.

May 17 2024, 6:45 AM
Viacheslav changed the status of T6350: CGNAT add op-mode to get current port allocation mapping, a subtask of T5169: Add CGNAT Carrier-Grade NAT based on nftables, from Open to In progress.
May 17 2024, 6:41 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav changed the status of T6350: CGNAT add op-mode to get current port allocation mapping from Open to In progress.
May 17 2024, 6:41 AM · VyOS 1.5 Circinus
Res added a comment to T5835: UPnP port mapping / rule installation fails.

dylanneild added a comment.Tue, May 14, 8:59 AM
If someone wants, I can probably unearth my patches to 1.4 and miniupnpd to make it all work. It was technically functional and worked as expected. I just don't have the time or patience to deal with getting it merged/integrated back into the project.

The only thing I didn't add was a status script to get lease data, but that would be easy enough to create.

I'm AFK for a few days and would have to spin up some cold VMware instances so it'd take me a bit to grab / package up the relevant components.

May 17 2024, 2:20 AM

May 16 2024

aga added a comment to T6355: Make the strip-private filter obfuscate only passwords and private keys.

I also agree that the "default" stripping-behaviour should definitely be rethought for certain parts of the config. For example: the full public-key gets shown of the wireguard-peers on interfaces.

May 16 2024, 11:55 PM · VyOS 1.5 Circinus
alainlamar updated the task description for T6320: WiFi: Enable support for 6GHz AccesPoints.
May 16 2024, 9:53 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
alainlamar updated the task description for T6320: WiFi: Enable support for 6GHz AccesPoints.
May 16 2024, 9:52 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
Vijayakumar changed the status of T6349: keep all workflows as reusable workflows in global .github and make vyox-1x to use from there, a subtask of T6309: Check code quality with CodeQL, from Open to In progress.
May 16 2024, 7:12 PM · GitHub Infrastructure
Vijayakumar changed the status of T6349: keep all workflows as reusable workflows in global .github and make vyox-1x to use from there from Open to In progress.
May 16 2024, 7:12 PM · GitHub Infrastructure
jestabro removed a project from T6149: Update node_data when merging nodes in reference tree generation: VyOS 1.5 Circinus.
May 16 2024, 6:58 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro closed T6149: Update node_data when merging nodes in reference tree generation, a subtask of T6146: Add python script to get all priorities of service or section from XML, as Resolved.
May 16 2024, 6:56 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro closed T6149: Update node_data when merging nodes in reference tree generation as Resolved.
May 16 2024, 6:56 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a project to T6149: Update node_data when merging nodes in reference tree generation: VyOS 1.4 Sagitta (1.4.0-epa3).
May 16 2024, 6:55 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6350: CGNAT add op-mode to get current port allocation mapping.

PR https://github.com/vyos/vyos-1x/pull/3466

vyos@r4:~$ show nat cgnat allocation 
Internal IP    External IP      Port range
-------------  ---------------  ------------
100.64.0.0     192.168.122.222  1024-3023
100.64.0.1     192.168.122.222  3024-5023
100.64.0.2     192.168.122.222  5024-7023
100.64.0.3     192.168.122.222  7024-9023
100.64.0.4     192.168.122.222  9024-11023
100.64.0.5     192.168.122.222  11024-13023
100.64.0.6     192.168.122.222  13024-15023
100.64.0.7     192.168.122.222  15024-17023
100.64.0.8     192.168.122.222  17024-19023
100.64.0.9     192.168.122.222  19024-21023
100.64.0.10    192.168.122.222  21024-23023
100.64.0.11    192.168.122.222  23024-25023
100.64.0.12    192.168.122.222  25024-27023
100.64.0.13    192.168.122.222  27024-29023
100.64.0.14    192.168.122.222  29024-31023
100.64.0.15    192.168.122.222  31024-33023
vyos@r4:~$
May 16 2024, 6:42 PM · VyOS 1.5 Circinus
jestabro triaged T6356: Correct the syntax of config.boot.default [..., 'ntp', 'server'] from leaf node with value to tag node as Normal priority.
May 16 2024, 6:18 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po closed T4519: DHCPv6: "set show dhcpv6 server leases" should show DUID instead of IAID_DUID as Resolved.
May 16 2024, 6:12 PM · VyOS 1.4 Sagitta (1.4.0-GA)
c-po moved T4519: DHCPv6: "set show dhcpv6 server leases" should show DUID instead of IAID_DUID from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 16 2024, 6:12 PM · VyOS 1.4 Sagitta (1.4.0-GA)
c-po assigned T4519: DHCPv6: "set show dhcpv6 server leases" should show DUID instead of IAID_DUID to nvollmar.
May 16 2024, 6:11 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav changed the status of T6351: CGNAT add check if external and internal pools exists, a subtask of T5169: Add CGNAT Carrier-Grade NAT based on nftables, from Open to In progress.
May 16 2024, 4:34 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav changed the status of T6351: CGNAT add check if external and internal pools exists from Open to In progress.
May 16 2024, 4:34 PM · VyOS 1.5 Circinus
Viacheslav triaged T6351: CGNAT add check if external and internal pools exists as Low priority.
May 16 2024, 4:34 PM · VyOS 1.5 Circinus
Viacheslav claimed T6351: CGNAT add check if external and internal pools exists.

PR https://github.com/vyos/vyos-1x/pull/3464

set nat cgnat pool external ext1 external-port-range '1024-65535'
set nat cgnat pool external ext1 per-user-limit port '2000'
set nat cgnat pool external ext1 range 192.168.122.222/32
set nat cgnat pool internal int1 range '100.64.0.0/28'
set nat cgnat rule 10 source pool 'fake-pool'
set nat cgnat rule 10 translation pool 'ext1'
May 16 2024, 4:33 PM · VyOS 1.5 Circinus
Viacheslav updated the task description for T6351: CGNAT add check if external and internal pools exists.
May 16 2024, 4:31 PM · VyOS 1.5 Circinus
dmbaturin created T6355: Make the strip-private filter obfuscate only passwords and private keys.
May 16 2024, 3:42 PM · VyOS 1.5 Circinus
Apachez added a comment to T6353: Disallow setting user password to "vyos" (the default).

I think a warning is better than to block it from being set, specially since the workaround to load it through already existing config still remains.

May 16 2024, 3:11 PM · Restricted Project, VyOS 1.5 Circinus
dmbaturin created T6354: Get rid of the custom boot type check in version.py.
May 16 2024, 2:43 PM · VyOS 1.5 Circinus
dmbaturin created T6353: Disallow setting user password to "vyos" (the default).
May 16 2024, 2:17 PM · Restricted Project, VyOS 1.5 Circinus
erkin created T6352: Tool for generating valid configs based on XML schemas.
May 16 2024, 2:01 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a subtask for T5169: Add CGNAT Carrier-Grade NAT based on nftables: T6351: CGNAT add check if external and internal pools exists.
May 16 2024, 12:27 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a parent task for T6351: CGNAT add check if external and internal pools exists: T5169: Add CGNAT Carrier-Grade NAT based on nftables.
May 16 2024, 12:27 PM · VyOS 1.5 Circinus
Viacheslav created T6351: CGNAT add check if external and internal pools exists.
May 16 2024, 12:26 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T6347: CGNAT external pools containing dashes cause Traceback error.

PR https://github.com/vyos/vyos-1x/pull/3463

May 16 2024, 12:16 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T6347: CGNAT external pools containing dashes cause Traceback error, a subtask of T5169: Add CGNAT Carrier-Grade NAT based on nftables, from Open to In progress.
May 16 2024, 11:52 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav changed the status of T6347: CGNAT external pools containing dashes cause Traceback error from Open to In progress.
May 16 2024, 11:52 AM · VyOS 1.5 Circinus
natali-rs1985 changed Is it a breaking change? from none to compatible on T6348: SNAT op-mode fails with flowtable offload entries.
May 16 2024, 11:14 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
natali-rs1985 changed the status of T6348: SNAT op-mode fails with flowtable offload entries from Open to In progress.
May 16 2024, 11:09 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
dmbaturin closed T6339: Display the flavor name and build comment in "show version" as Resolved.
May 16 2024, 10:56 AM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav triaged T6350: CGNAT add op-mode to get current port allocation mapping as Wishlist priority.
May 16 2024, 10:38 AM · VyOS 1.5 Circinus
Viacheslav created T6350: CGNAT add op-mode to get current port allocation mapping.
May 16 2024, 10:38 AM · VyOS 1.5 Circinus
Viacheslav triaged T6349: keep all workflows as reusable workflows in global .github and make vyox-1x to use from there as Normal priority.
May 16 2024, 10:27 AM · GitHub Infrastructure
Vijayakumar claimed T6349: keep all workflows as reusable workflows in global .github and make vyox-1x to use from there.
May 16 2024, 10:25 AM · GitHub Infrastructure
Vijayakumar created T6349: keep all workflows as reusable workflows in global .github and make vyox-1x to use from there.
May 16 2024, 10:24 AM · GitHub Infrastructure
Viacheslav updated the task description for T6348: SNAT op-mode fails with flowtable offload entries.
May 16 2024, 10:20 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav triaged T6348: SNAT op-mode fails with flowtable offload entries as Normal priority.
May 16 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav updated the task description for T6348: SNAT op-mode fails with flowtable offload entries.
May 16 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav created T6348: SNAT op-mode fails with flowtable offload entries.
May 16 2024, 10:16 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a subtask for T5169: Add CGNAT Carrier-Grade NAT based on nftables: T6347: CGNAT external pools containing dashes cause Traceback error.
May 16 2024, 9:38 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a parent task for T6347: CGNAT external pools containing dashes cause Traceback error: T5169: Add CGNAT Carrier-Grade NAT based on nftables.
May 16 2024, 9:38 AM · VyOS 1.5 Circinus
Viacheslav triaged T6347: CGNAT external pools containing dashes cause Traceback error as Normal priority.
May 16 2024, 9:37 AM · VyOS 1.5 Circinus
Viacheslav created T6347: CGNAT external pools containing dashes cause Traceback error.
May 16 2024, 9:37 AM · VyOS 1.5 Circinus
Viacheslav changed the status of T6058: Commit-Archive Save doesn't use https_proxy from Needs reporter action to Open.
May 16 2024, 7:55 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
modzilla99 added a comment to T6058: Commit-Archive Save doesn't use https_proxy.

sorry for the late reply.You don't need any special commands. The only thing you have to set is the proxy and the commit archive.

May 16 2024, 7:42 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Viacheslav added a comment to T6344: multiple ntp listen-address commands not working.

@molocho see the tasks T5301 T5154 and https://chrony-project.org/doc/4.3/chrony.conf.html#bindaddress

May 16 2024, 7:15 AM · VyOS 1.4 Sagitta
Viacheslav triaged T6345: Source NAT Port Mapping setting of Fully-Random is superfluous in Kernels 5.0 onwards as Normal priority.
May 16 2024, 7:10 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
nvollmar added a comment to T4519: DHCPv6: "set show dhcpv6 server leases" should show DUID instead of IAID_DUID.

IMO it would make sense to show the DUID since that has to be passed for static mappings and is also configured on the client side

May 16 2024, 5:53 AM · VyOS 1.4 Sagitta (1.4.0-GA)
c-po closed T6333: non-free-firmware to trixie as Resolved.
May 16 2024, 5:26 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po moved T6333: non-free-firmware to trixie from Need Triage to Finished on the VyOS 1.5 Circinus board.
May 16 2024, 5:26 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po moved T6333: non-free-firmware to trixie from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0) board.
May 16 2024, 5:26 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po added a project to T6333: non-free-firmware to trixie: VyOS 1.4 Sagitta (1.4.0).
May 16 2024, 5:26 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po added a comment to T6346: Boot to multi-user.target instead of graphical.target.

https://github.com/vyos/vyos-build/pull/624

May 16 2024, 5:24 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po updated the task description for T6346: Boot to multi-user.target instead of graphical.target.
May 16 2024, 5:23 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po claimed T6346: Boot to multi-user.target instead of graphical.target.
May 16 2024, 5:22 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus