- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
Jun 24 2026
@ssasso you can verify it by deleting 'address-family l2vpn-evpn vni <id>':
I have found the root cause of this issue:
- VyOS generates a vni <id> block inside router bgp <asn> vrf <name> / address-family l2vpn evpn for each VRF:
FRR has a bug where no bmp connect HOSTNAME port PORT min-retry MSEC max-retry MSEC source-interface WORD always fails with "No such active connection found" even when the parameters match the active connection. Deletion only works when source-interface is omitted from the command.
Update -- confirmed to be a bug, since rolling release works perfectly.
Here you go:
Jun 23 2026
I'll have to think about how to test this now, we migrated the last Sophos UTM over the weekend, after which we migrated all tunnels from IPSec to wireguard.
Hopefully resolved by upgrading to Strongswan 6.0.6.
Could you please check latest rolling release?
Thank you.
I don't know if the default value of 1 is a good idea, but per feature, it could be.
For example, we use it in the OpenVPN https://github.com/vyos/vyos-1x/blob/3edf114bed538733388252da0d23b49002273558/src/conf_mode/interfaces_openvpn.py#L844
@ssasso, I would be grateful if you provide the output of the following command:
- sudo /usr/lib/frr/frr-reload.py --reload --debug --stdout /run/frr/config/vyos.frr.conf
Jun 22 2026
Ran into this on a rolling build (FRR 10.5.2). Without any source binding, the session stays stuck in Connecting with (unspec) as local address:
Jun 21 2026
Jun 20 2026
PR: https://github.com/vyos/vyos-1x/pull/5284
Suggested CLI and details in PR.
Jun 19 2026
A workaround to using a custom private registry is to manually preload the images.
Cannot reproduce on version 2026.06.16-1247-rolling
Jun 19 10:10:41 vyos dhclient[1840]: DHCPDISCOVER on eth3 to 255.255.255.255 port 67 interval 12
Jun 19 10:10:50 vyos vyos-configd[738]: Received message: {"type": "init"}
Jun 19 10:10:50 vyos vyos-configd[738]: config session pid is 2765
Jun 19 10:10:50 vyos vyos-configd[738]: config session sudo_user is vyos
Jun 19 10:10:50 vyos vyos-configd[738]: commit_scripts: ['vpn_ipsec']
Jun 19 10:10:50 vyos vyos-configd[738]: Received message: {"type": "node", "last": true, "data": "/usr/libexec/vyos/conf_mode/vpn_ipsec.py"}
Jun 19 10:10:50 vyos systemd[1]: Reloading strongSwan IPsec IKEv1/IKEv2 daemon using swanctl...
Jun 19 10:10:50 vyos charon-systemd[3326]: loaded 0 entries for attr plugin configuration
Jun 19 10:10:50 vyos charon-systemd[3326]: loaded 0 RADIUS server configurations
Jun 19 10:10:50 vyos charon-systemd[3326]: loaded IKE shared key with id 'ike-VPP' for: '192.0.2.1', '192.0.2.2'
Jun 19 10:10:50 vyos charon-systemd[3326]: updated vici connection: VPP
Jun 19 10:10:50 vyos swanctl[3857]: loaded ike secret 'ike-VPP'
Jun 19 10:10:50 vyos swanctl[3857]: no authorities found, 0 unloaded
Jun 19 10:10:50 vyos swanctl[3857]: no pools found, 0 unloaded
Jun 19 10:10:50 vyos swanctl[3857]: loaded connection 'VPP'
Jun 19 10:10:50 vyos swanctl[3857]: successfully loaded 1 connections, 0 unloaded
Jun 19 10:10:50 vyos systemd[1]: Reloaded strongSwan IPsec IKEv1/IKEv2 daemon using swanctl.
Jun 19 10:10:50 vyos vyos-configd[738]: [vpn_ipsec]
Jun 19 10:10:50 vyos vyos-configd[738]: scripts_called: ['vpn_ipsec']
Jun 19 10:10:50 vyos vyos-configd[738]: Sending reply: SUCCESS with output
Jun 19 10:10:50 vyos systemd[1]: opt-vyatta-config-tmp-new_config_2765.mount: Deactivated successfully.
Jun 19 10:10:52 vyos commit[3904]: Successful change to active configuration by user vyos on /dev/ttyS0Jun 18 2026
I was able to achieve the PCP set with different CoS value with subsystem tc of linux. Re-using the available options of QoS, it is possible to identify CoS values (L2 traffic) for ingress and egress. Let me explain how Linux performs the PCP values.