Page MenuHomeVyOS Platform
Feed Advanced Search

Jul 25 2024

natali-rs1985 moved T3202: Enable wireguard debug messages by default from Open to Finished on the VyOS 1.5 Circinus board.
Jul 25 2024, 10:16 AM · VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project, VyOS 1.5 Circinus
natali-rs1985 moved T3202: Enable wireguard debug messages by default from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
Jul 25 2024, 10:15 AM · VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project, VyOS 1.5 Circinus

Jul 18 2024

HollyGurza added a comment to T5471: Conntrack logging doesnt seem to be working.

https://github.com/vyos/vyos-1x/pull/3804

Jul 18 2024, 5:52 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Jul 17 2024

c-po changed the status of T6584: Revert addition of Linux Kernel MT7921 driver, a subtask of T6293: add Mediatek MT7921 to defconfig, from Open to In progress.
Jul 17 2024, 6:49 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a comment to T6584: Revert addition of Linux Kernel MT7921 driver.

https://github.com/vyos/vyos-build/pull/699

Jul 17 2024, 6:49 AM · VyOS 1.4 Sagitta (1.4.1), VyOS Rolling, VyOS 1.5 Circinus
c-po created T6584: Revert addition of Linux Kernel MT7921 driver.
Jul 17 2024, 6:46 AM · VyOS 1.4 Sagitta (1.4.1), VyOS Rolling, VyOS 1.5 Circinus
c-po added a comment to T6293: add Mediatek MT7921 to defconfig.

This actually causes Kernel Panics during boot, so lets remove this option again.

Jul 17 2024, 6:42 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Jul 7 2024

lucasec added a comment to T921: Encrypted DNS.

There are two possible places where encrypted DNS support might be desired in a standard setup where VyOS is hosting a local resolver/recursor:

Jul 7 2024, 3:11 AM · VyOS 1.4 Sagitta (1.4.0-GA)

Jul 3 2024

dmbaturin closed T5752: Check compatibility of new image tools with XCP-NG images as Resolved.

Seems to work well enough in 1.4.0. If any issues turn up, we'll make separate tasks.

Jul 3 2024, 12:21 PM · VyOS 1.4 Sagitta (1.4.0-GA)

Jul 2 2024

jestabro closed T6006: Configure system-specific capabilities independently of migration scripts, a subtask of T3824: Ethernet offload options are not populated in new installs, as Resolved.
Jul 2 2024, 6:37 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
Viacheslav added a comment to T6379: "generate openvpn" uses "comp-lzo no", which leads to problems on Android-Clients.

Should fix it https://github.com/vyos/vyos-1x/pull/3747

Jul 2 2024, 5:56 AM · VyOS 1.4 Sagitta (1.4.1)

Jul 1 2024

erkin reassigned T3644: Replace GCC with a simpler preprocessor for including nested XML snippets in XML documents from erkin to dmbaturin.
Jul 1 2024, 12:36 PM · VyOS 1.4 Sagitta (1.4.0-GA)
erkin reassigned T5985: Downloaded files end up with unwieldy file attributes from erkin to dmbaturin.
Jul 1 2024, 12:35 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
erkin reassigned T4583: Rewrite VRRP op-mode to vyos.opmode format from erkin to dmbaturin.
Jul 1 2024, 12:34 PM · Restricted Project, VyOS 1.5 Circinus

Jun 28 2024

Viacheslav closed T5359: VyOS user/pass remains in config, a subtask of T5907: cloud-init root task for 1.5 and 1.4 , as Not Applicable.
Jun 28 2024, 11:43 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)

Jun 27 2024

c-po closed T6519: interfaces: 20-to-21 -> migration fails if new system has less ethernet interfaces, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
Jun 27 2024, 6:23 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)

Jun 26 2024

c-po changed the status of T6519: interfaces: 20-to-21 -> migration fails if new system has less ethernet interfaces, a subtask of T5938: Migration fail root task for 1.4-rc, from Open to In progress.
Jun 26 2024, 1:30 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
HollyGurza changed the status of T5878: Make the list of SSH server ciphers configurable from Open to In progress.
Jun 26 2024, 8:24 AM · VyOS 1.4 Sagitta (1.4.1)
HollyGurza moved T5878: Make the list of SSH server ciphers configurable from Need Triage to In Progress on the VyOS 1.4 Sagitta (1.4.0-GA) board.
Jun 26 2024, 8:24 AM · VyOS 1.4 Sagitta (1.4.1)

Jun 25 2024

HollyGurza added a comment to T5878: Make the list of SSH server ciphers configurable.

https://github.com/vyos/vyos-1x/pull/3721

Jun 25 2024, 10:39 AM · VyOS 1.4 Sagitta (1.4.1)
HollyGurza claimed T5878: Make the list of SSH server ciphers configurable.
Jun 25 2024, 7:12 AM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav moved T6365: Negating interface names in NAT configuration causes invalid warnings from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
Jun 25 2024, 4:24 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav closed T6365: Negating interface names in NAT configuration causes invalid warnings as Resolved.
Jun 25 2024, 4:24 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Giggum added a comment to T6365: Negating interface names in NAT configuration causes invalid warnings.

Should this ticket be closed? I see the PRs were merged more than a month ago.

Jun 25 2024, 2:09 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Jun 24 2024

alainlamar updated the task description for T6320: WiFi: Enable support for 6GHz AccesPoints.
Jun 24 2024, 1:14 PM · VyOS Rolling, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
alainlamar updated the task description for T6320: WiFi: Enable support for 6GHz AccesPoints.
Jun 24 2024, 1:10 PM · VyOS Rolling, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po closed T6480: PermissionError: [Errno 13] Permission denied: '/config/auth/letsencrypt/live/..../cert.pem, a subtask of T6377: PermissionError on /config/auth/letsencrypt/live/ when running show pki, as Resolved.
Jun 24 2024, 8:21 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)

Jun 21 2024

talmakion added a comment to T3334: Changing serial settings from a serial console ends session abruptly.

Created PR https://github.com/vyos/vyos-1x/pull/3698

Jun 21 2024, 8:53 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)

Jun 20 2024

dmbaturin edited projects for T1070: SWANCTL: DMVPN: ALL peers are deleted in swan when opennhrp tries to delete ONE peer, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
dmbaturin edited projects for T2251: VRF communication breaks when utilizing zone-based firewalling, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
dmbaturin edited projects for T2498: Expected error when deleting vif that has dhcp-server configured, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin edited projects for T3159: L2TP MTU mismatch between client and server, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
dmbaturin edited projects for T3232: ISIS incorrect hostname and LSP ID, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus, VyOS Rolling
dmbaturin edited projects for T3207: OSPF does not convert the area to NSSA , added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin edited projects for T3315: Supports dhcpv6 agent execution from pppoe0 interface, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin edited projects for T3383: BGP IPv6 neighbor statements configuration not normalized., added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin edited projects for T3397: getty forces --keep-baud in 1.2.x, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.2 Crux (VyOS 1.2.9)
dmbaturin edited projects for T3314: Udev rules try to rename active interfaces in some environments, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin edited projects for T3583: Overwrite default config ntp settings when custom ntp servers are provided., added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin edited projects for T3410: Unsafe processing of special characters in CLI autocomplete, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.5 Circinus, VyOS Rolling
dmbaturin edited projects for T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin edited projects for T3824: Ethernet offload options are not populated in new installs, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
dmbaturin edited projects for T3933: The firewall does not filter incoming traffic on the interface with vrf., added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
dmbaturin edited projects for T4455: smp-affinity required by some platforms but doesn't exists in the CLI, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · VyOS 1.4 Sagitta (1.4.0), VyOS Rolling, VyOS 1.5 Circinus
dmbaturin edited projects for T5004: DHCP-Relay potential bug. Static configurations of DHCP-Relay Interfaces, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T4818: IPv6 NDP not working everytime, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin edited projects for T5444: R8169 driver crash, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T5570: PAM config RADIUS ignore for default and success, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T5790: ISIS invalid format of hello packet when interface mtu is between 1501 and 1535, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T5881: IPv6 addresses jumbled in flow accounting, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:18 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T1790: OSPF Exchanged Routes marked as invalid when run through a GRE PTMP/PTP OSPF between peers , added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T6157: Can not create two GRE tunnels to the same DST but from different SRC addresses, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T2145: openvpn: server default topology net30 is incompatible with static client IPs for Windows clients, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T2003: BGP FQDN capability has improper hostname after new image install, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T2505: XCP-ng packet drops for small packets (e.g. icmp) under Xen and AWS, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T2207: IPv6 route install failed, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T2287: LLDP not working on X710 adapter, i40e driver, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T2616: BFD Configuration causes flapping, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T2760: In a load-balanced multi-wan configuration with DHCP assigned addresses, IPsec "dhcp-interface" does not work, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T2657: dhcp-server hostfile-update allows any DHCP client to inject an arbitrary hostname into /etc/hosts and pdns-recursor's zones (DNS spoofing as a vector for MITM attacks), added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T3204: Performance system option destroy defined sysctl custom params, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · VyOS Rolling, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T2881: Bug in weight calculation for failover mode, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM
dmbaturin edited projects for T2762: VRF: when SSHd is VRF bound all commands are executed in VRF context, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T4280: dhcp-relay: does not work with wireguard uplink, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · VyOS 1.3 Equuleus, Restricted Project
dmbaturin edited projects for T3393: IPoE does not assign IPv6 PD or WAN address, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T4452: WAN load-balancing exclude rules break PBR, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T4281: System users migration can lead to inaccessible shell, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T4600: Closing IPV6CP by client closes PPPoE link completely, even if IPv6 is optional, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T4520: Incorrect addresses returned with interaction of static /etc/hosts with DNS64, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T4816: IPv4-mapped and IPv4-compatible IPv6 addresses not valid anymore, added: VyOS 1.3 Equuleus (1.3.9); removed VyOS 1.3 Equuleus (1.3.8).
Jun 20 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)

Jun 18 2024

syncer closed T5847: Protocol failover stopped working after suspend + resume as Wontfix.

Suspend/Resume is not supported operation

Jun 18 2024, 10:04 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Harliff added a comment to T5847: Protocol failover stopped working after suspend + resume.

Note for myself:

Jun 18 2024, 9:45 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Harliff added a comment to T5847: Protocol failover stopped working after suspend + resume.

Logs from VM:

Jun 18 2024, 9:12 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Harliff added a comment to T5847: Protocol failover stopped working after suspend + resume.

I've modified the protocol ospf settings to check if it will affect static routing or not.
The static routing are not affected (still no route to 0.0.0.0/0):

Jun 18 2024, 9:05 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Harliff added a comment to T5847: Protocol failover stopped working after suspend + resume.

Hi!
Recently I've note that this bug is not affects only protocol failover, but also protocol static routers.

Jun 18 2024, 8:56 PM · VyOS 1.4 Sagitta (1.4.0-GA)

Jun 17 2024

c-po closed T6407: Generate ipsec profile error as Resolved.
Jun 17 2024, 5:48 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
pavel-altair added a comment to T6407: Generate ipsec profile error.

all work!
Thank you

Jun 17 2024, 2:58 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po changed the status of T6407: Generate ipsec profile error from Open to Needs testing.
Jun 17 2024, 6:45 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a comment to T6407: Generate ipsec profile error.

@pavel-altair can you please re-test with VyOS 1.5-rolling-202406170021

Jun 17 2024, 6:45 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Jun 16 2024

syncer lowered the priority of T3410: Unsafe processing of special characters in CLI autocomplete from Urgent! to Normal.
Jun 16 2024, 2:53 PM · Restricted Project, VyOS 1.5 Circinus, VyOS Rolling
syncer changed the status of T4667: DMVPN IPSec allows cleartext GRE over the internet when reconnecting from Open to In progress.
Jun 16 2024, 2:50 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
syncer changed the status of T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic from Open to In progress.
Jun 16 2024, 2:49 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
syncer assigned T4667: DMVPN IPSec allows cleartext GRE over the internet when reconnecting to talmakion.
Jun 16 2024, 2:49 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
syncer set Forum thread to https://forum.vyos.io/t/outbound-ipsec-filtering-by-firewall-would-like-some-dev-opinions/14710 on T4667: DMVPN IPSec allows cleartext GRE over the internet when reconnecting.
Jun 16 2024, 2:48 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
syncer set Forum thread to https://forum.vyos.io/t/outbound-ipsec-filtering-by-firewall-would-like-some-dev-opinions/14710 on T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.
Jun 16 2024, 2:48 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Jun 15 2024

syncer assigned T3204: Performance system option destroy defined sysctl custom params to c-po.

@c-po, can you see if it's still actual, and if not, close it
Thanks!

Jun 15 2024, 9:19 PM · VyOS Rolling, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
talmakion added a comment to T4026: PKI: generate pki certificate sign <ca-name> is not working.

I've created a PR for this: https://github.com/vyos/vyos-1x/pull/3655

Jun 15 2024, 4:31 PM · VyOS 1.4 Sagitta (1.4.1)
talmakion added a comment to T5514: Improve error handling when/if config.boot is deleted or missing .

I've created a PR with a very simple fix: https://github.com/vyos/vyos-1x/pull/3654

Jun 15 2024, 3:39 PM · VyOS 1.4 Sagitta (1.4.1)

Jun 14 2024

c-po added a comment to T6407: Generate ipsec profile error.

https://github.com/vyos/vyos-1x/pull/3646

Jun 14 2024, 11:31 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a comment to T6407: Generate ipsec profile error.

I can now reproduce the issue. The reason I was unable to reproduce this was I missed out that you use an ACME certificate

Jun 14 2024, 11:06 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a subtask for T6377: PermissionError on /config/auth/letsencrypt/live/ when running show pki: T6480: PermissionError: [Errno 13] Permission denied: '/config/auth/letsencrypt/live/..../cert.pem.
Jun 14 2024, 10:32 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
c-po added a comment to T6407: Generate ipsec profile error.
Jun 14 2024, 10:10 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
pavel-altair added a comment to T6407: Generate ipsec profile error.
vyos@vyos:~$ generate ipsec profile windows-remote-access support remote ipsec.somedomain
Traceback (most recent call last):
  File "/usr/libexec/vyos/op_mode/ikev2_profile_generator.py", line 153, in <module>
    cert_data = load_certificate(pki['certificate'][cert_name]['certificate'])
                                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^
KeyError: 'certificate'
vyos@vyos:~$ show ver | match Version:
Version:          VyOS 1.5-rolling-202406130020
vyos@vyos:~$
Jun 14 2024, 6:56 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Jun 13 2024

c-po added a comment to T6407: Generate ipsec profile error.

This is not the latest image. Please use 1.5-rolling-202406130020

Jun 13 2024, 7:14 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
zsdc moved T6038: Losing default route after first reboot (cloud-init & DHCP) from In Progress to Finished on the VyOS 1.5 Circinus board.
Jun 13 2024, 2:52 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
zsdc closed T6038: Losing default route after first reboot (cloud-init & DHCP), a subtask of T5907: cloud-init root task for 1.5 and 1.4 , as Resolved.
Jun 13 2024, 2:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
zsdc closed T6038: Losing default route after first reboot (cloud-init & DHCP) as Resolved.
Jun 13 2024, 2:52 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
zsdc closed T5351: VyOS deployed with cloud-init improperly saves config.boot, a subtask of T5907: cloud-init root task for 1.5 and 1.4 , as Resolved.
Jun 13 2024, 2:48 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
zsdc closed T5351: VyOS deployed with cloud-init improperly saves config.boot as Resolved.

The only reason I see why this can happen is that the config.boot format can be unexpected. But this should not happen anymore, because now Cloud-init always runs migrations before doing any work, which should always add required metadata if the original file is a valid VyOS config.

Jun 13 2024, 2:48 PM · VyOS 1.4 Sagitta (1.4.0-GA)
L0crian placed T5931: Add option to append route-target when adding additional imports up for grabs.
Jun 13 2024, 1:29 PM · Restricted Project, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)