Page MenuHomeVyOS Platform
Feed Search

Oct 18 2019

hagbard changed the status of T1684: Unable to enable IPv6 autoconf on PPPoE from Unknown Status to Resolved.
Oct 18 2019, 7:58 PM · VyOS 1.2 Crux (VyOS 1.2.3)
hagbard moved T1684: Unable to enable IPv6 autoconf on PPPoE from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Oct 18 2019, 7:58 PM · VyOS 1.2 Crux (VyOS 1.2.3)
hagbard added a comment to T1741: Add system wide proxy setting.

already added to the documentation: https://vyos.readthedocs.io/en/latest/system/proxy.html

Oct 18 2019, 7:40 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard committed rVYOSONEXf87b5fa3b9a2: system-proxy: T1741 - Add system wide proxy setting.
Oct 18 2019, 7:38 PM
hagbard committed rVYOSONEXd2aa68e5e6a1: wireguard - remove endpoint check to enable roaming connections.
Oct 18 2019, 6:44 PM
hagbard changed the status of T1741: Add system wide proxy setting from In progress to Needs testing.

https://github.com/vyos/vyos-1x/commit/df9544233fb661e830285c1a0d7755cff4b27408
https://github.com/vyos/vyatta-cfg-system/commit/3a99ea6e9b8ef9ef417d38d1d0bab8d2d2401aa8 (add system image)

Oct 18 2019, 6:03 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard committed rVYOSONEXdf9544233fb6: system-proxy: T1741 - Add system wide proxy setting CLI implementation.
Oct 18 2019, 5:59 PM
hagbard added a comment to T1741: Add system wide proxy setting.

I have an idea, I can either write it to profile.d, that is exporting http_proxy, https_proxy and ftp_proxy into the shell env, and in the install-image script if the profile files exists, I load it which exposes these variables as well and curl is working with no issue. If removed, that file won't exists and curl works like it did before. If the proxy variables shouldn't be in the user environment, I can write it to a particular file only used by scripts which which would need that information.

Oct 18 2019, 5:13 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1741: Add system wide proxy setting.

curl only accepts ~/.curlrc, so that can become a hassle with multiple home directories on a box.

Oct 18 2019, 4:42 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard moved T1720: support for more 'show ip route' commands from In Progress to Backlog on the VyOS 1.2 Crux board.
Oct 18 2019, 4:23 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1741: Add system wide proxy setting.

That would work but it's only for a single programm you define it. I think it could be enough for the beginning. I still have to check if curlrc is being read when invoked from the perl script, it usually should.

Oct 18 2019, 3:10 PM · VyOS 1.3 Equuleus (1.3.0)

Oct 17 2019

hagbard added a comment to T1741: Add system wide proxy setting.

The removal makes a little headache. Setting it system wide is not an issue at all, writing and execute in profile.d. Removing it would require to logout and login again to re-read the bash.profile. I may have to rethink that. Also the image download is invoked via a perl script, so http_proxy will be lost anyway.

Oct 17 2019, 10:01 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard triaged T1741: Add system wide proxy setting as Normal priority.
Oct 17 2019, 9:49 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1741: Add system wide proxy setting from Open to In progress.
Oct 17 2019, 9:49 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1741: Add system wide proxy setting.

I have that issue for a while here too and just helped myself locally. I'll can take care of that.

Oct 17 2019, 3:10 PM · VyOS 1.3 Equuleus (1.3.0)

Oct 15 2019

hagbard added a comment to T1732: Removing vyatta-webproxy module.

Most enterprises use it still as a cheap authentication method, I'm totally in favor to drop it, not only in vyos. Breaking it off (they generate fitting ssl certs on the fly signed with a private PKI), is questionable as well, since I think https should be end to end encryption, everyone who messes with that idea, well I wouldn't trust them on other items as well.

Oct 15 2019, 4:36 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

works with:

Version:          VyOS 1.2-rolling-201910110117
Built by:         autobuild@vyos.net
Built on:         Fri 11 Oct 2019 01:17 UTC
Build UUID:       48a11fa6-8c59-4dbb-94a3-215376c09a02
Build Commit ID:  46f9b2ab60e4fa
Oct 15 2019, 4:22 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

Can't create an iso right now to test it.

Oct 15 2019, 4:17 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

typo fixed: https://github.com/vyos/vyos-1x/commit/50acd442ade9a4e447269eaf94ce14d354af8d0c
http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyos-1x/vyos-1x_1.3.0-16_all.deb should work now

Oct 15 2019, 3:56 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard committed rVYOSONEX50acd442ade9: snmpd: T1705 - High CPU usage by bgpd when snmp is active.
Oct 15 2019, 3:56 PM

Oct 11 2019

hagbard moved T1684: Unable to enable IPv6 autoconf on PPPoE from In Progress to Finished on the VyOS 1.3 Equuleus board.
Oct 11 2019, 9:21 PM · VyOS 1.2 Crux (VyOS 1.2.3)
hagbard claimed T1604: equuleus: buster: vbash: tab completion breaks.

@jjakob Is that still an issue? I have the lastest 1.3 rolling form today and can't reproduce the issue.

Oct 11 2019, 8:35 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails.

running from the live-cd I think.

Oct 11 2019, 7:59 PM · Invalid
hagbard committed rVYOSONEX5c834feebe5e: Merge branch 'equuleus' of https://github.com/vyos/vyos-1x into equuleus.
Oct 11 2019, 6:50 PM
hagbard committed rVYOSONEXc5ae327c93c0: Merge branch 'current' into equuleus.
Oct 11 2019, 6:50 PM
hagbard lowered the priority of T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails from High to Normal.

@brian.ward Please show the output of df-h at your earliest convenience.

Oct 11 2019, 5:53 PM · Invalid
hagbard closed T1722: Add ability to debug Wireguard connections as Wontfix.
Oct 11 2019, 5:49 PM · Rejected
hagbard added a comment to T1722: Add ability to debug Wireguard connections.

@bertleywjh any other input, or can I close the ticket?

Oct 11 2019, 5:44 PM · Rejected
hagbard added a project to T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails: VyOS 1.2 Crux.
Oct 11 2019, 5:27 PM · Invalid
hagbard added a comment to T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails.

@brian.ward Can you please check that /config is mounted?

Oct 11 2019, 5:25 PM · Invalid
hagbard added a comment to T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails.

Can't reproduce it, it does work without any issues. I copied and executed your config and did a commit.

Oct 11 2019, 5:23 PM · Invalid
hagbard claimed T1725: VyOS 1.2 Rolling 201910110117 DHCP Server Configuration Fails.
Oct 11 2019, 5:20 PM · Invalid
hagbard moved T1723: wireguard - Interface wg01 could not be brought up in time from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Oct 11 2019, 4:51 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard removed a project from T1723: wireguard - Interface wg01 could not be brought up in time : VyOS 1.2 Crux.
Oct 11 2019, 4:51 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1723: wireguard - Interface wg01 could not be brought up in time as Resolved.

Looks like it has changed already in ifconfig.py. Tested it successfully as well.
https://github.com/vyos/vyos-1x/commit/f5c04661e6c031baedb6092ecafee501cca7bc28#diff-def38e05f2ac1eb35139b37ec8d47338R1375

Oct 11 2019, 4:51 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard moved T1720: support for more 'show ip route' commands from Need Triage to In Progress on the VyOS 1.2 Crux board.
Oct 11 2019, 4:41 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard moved T1724: wireguard - add endpoint check in verify() from In Progress to Finished on the VyOS 1.3 Equuleus board.
Oct 11 2019, 4:10 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1724: wireguard - add endpoint check in verify() as Resolved.
Oct 11 2019, 4:10 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard committed rVYOSONEXb8996f981276: wireguard: T1724 - add check for option endpoint.
Oct 11 2019, 3:46 PM
hagbard changed the status of T1724: wireguard - add endpoint check in verify() from Open to In progress.
Oct 11 2019, 3:43 PM · VyOS 1.3 Equuleus (1.3.0)

Oct 10 2019

hagbard triaged T1724: wireguard - add endpoint check in verify() as Normal priority.
Oct 10 2019, 10:42 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1724: wireguard - add endpoint check in verify().
Oct 10 2019, 10:42 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T1724: wireguard - add endpoint check in verify().
Oct 10 2019, 10:42 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard triaged T1723: wireguard - Interface wg01 could not be brought up in time as Normal priority.
Oct 10 2019, 10:40 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1723: wireguard - Interface wg01 could not be brought up in time .

@cpo operstate will be unknown for wg interfaces, I think it's the only interface type having unknown. Anything else should be up or down, I think. I can re-implement with the wg class if that's better.
Let me know what you think, wg is working with no issues, so functionality isn't an issue here.

Oct 10 2019, 10:40 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard updated the task description for T1723: wireguard - Interface wg01 could not be brought up in time .
Oct 10 2019, 10:32 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard updated the task description for T1723: wireguard - Interface wg01 could not be brought up in time .
Oct 10 2019, 10:29 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1723: wireguard - Interface wg01 could not be brought up in time .
Oct 10 2019, 10:26 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T1723: wireguard - Interface wg01 could not be brought up in time .
Oct 10 2019, 10:25 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1722: Add ability to debug Wireguard connections.

@bertleywjh wg state and link state is all is unfortunately all you will be able to see, plus like when was the last handshake and how many bytes were transfered. AFAIK there is no other way to see states of the handshake etc.

Oct 10 2019, 9:58 PM · Rejected
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

@fvbrasileiro here you go: https://downloads.vyos.io/rolling/current/amd64/vyos-1.2-rolling-201910102056-amd64.iso

Oct 10 2019, 9:27 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

@fvbrasileiro Yeah, we found that out too today, we are working on a solution already. Please be patient.

Oct 10 2019, 8:54 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard moved T1722: Add ability to debug Wireguard connections from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Oct 10 2019, 8:38 PM · Rejected
hagbard moved T1722: Add ability to debug Wireguard connections from Need Triage to In Progress on the VyOS 1.2 Crux board.
Oct 10 2019, 8:38 PM · Rejected
hagbard triaged T1722: Add ability to debug Wireguard connections as Normal priority.
Oct 10 2019, 8:38 PM · Rejected
hagbard added a comment to T1722: Add ability to debug Wireguard connections.

@bertleywjh What issue are your trying to debug?

Oct 10 2019, 8:37 PM · Rejected
hagbard claimed T1722: Add ability to debug Wireguard connections.
Oct 10 2019, 8:35 PM · Rejected
hagbard changed the status of T1720: support for more 'show ip route' commands from Open to In progress.

Next rolling will have it: https://github.com/vyos/vyatta-op-quagga/commit/219265ae4c8886bb6997ffc79f34610d6e2ea2d0 or you can manually install from the source below, if it is an urgent matter.

Oct 10 2019, 8:35 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1720: support for more 'show ip route' commands .

The cli part for the routing suite is up for rewrite, json is only working because it's supported by frr and the cli doesn't filter it. I think getting show ip route tag 20 working shouldn't be a big deal, but I try to avoid to add too much to the cli, will make just the rewrite way harder.

Oct 10 2019, 6:13 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

There were multiple complains about bgpd crashes, memory issues inthe forum. They used the workaround removing the tables from snmpd successfully.

Oct 10 2019, 4:17 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard added a comment to T1720: support for more 'show ip route' commands .

@olofl How do you set the tag? via CLI?

Oct 10 2019, 4:13 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1720: support for more 'show ip route' commands .
Oct 10 2019, 3:49 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1705: High CPU usage by bgpd when snmp is active.

@fvbrasileiro Please test at your earliest convenience.

Oct 10 2019, 3:10 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard moved T1705: High CPU usage by bgpd when snmp is active from Need Triage to In Progress on the VyOS 1.2 Crux board.
Oct 10 2019, 3:07 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard changed the status of T1705: High CPU usage by bgpd when snmp is active from Open to Needs testing.
Oct 10 2019, 3:07 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard committed rVYOSONEXe45648cdd5a5: snmpd: T1705 - High CPU usage by bgpd when snmp is active.
Oct 10 2019, 3:05 PM
hagbard claimed T1705: High CPU usage by bgpd when snmp is active.
Oct 10 2019, 2:50 PM · VyOS 1.2 Crux (VyOS 1.2.4)

Oct 9 2019

hagbard closed T1718: ISO check in /opt/vyatta/sbin/install-image faulty as Resolved.

https://github.com/vyos/vyatta-cfg-system/commit/4b3434f8fab3201e7483bff95af71b7a1f51a13c

Oct 9 2019, 8:25 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard committed rVYOSONEX9b5867b7345e: Merge branch 'current' into equuleus.
Oct 9 2019, 4:30 PM
hagbard committed rVYOSONEXf8be18fbc549: Merge branch 'current' into equuleus.
Oct 9 2019, 4:25 PM
hagbard closed T1719: ssh deprecated options as Resolved.

1.2 is not affected which runs OpenSSH_6.7p1 Debian-5+deb8u8, OpenSSL 1.0.1t 3 May 2016

Oct 9 2019, 4:19 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing, a subtask of T476: Update the base system to Debian 10 (Buster), as Resolved.
Oct 9 2019, 3:19 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard closed T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing as Resolved.
Oct 9 2019, 3:19 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard committed rVYOSONEXc4dbaa158c9b: ssh - T1719: ssh deprecated options removed.
Oct 9 2019, 3:18 PM
hagbard moved T1718: ISO check in /opt/vyatta/sbin/install-image faulty from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Oct 9 2019, 3:18 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard moved T1719: ssh deprecated options from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Oct 9 2019, 3:18 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard renamed T1719: ssh deprecated options from ssh depricated options to ssh deprecated options.
Oct 9 2019, 3:15 PM · VyOS 1.3 Equuleus (1.3.0)

Oct 8 2019

hagbard added a comment to T1719: ssh deprecated options.

Can we just remove the deprecated options from being generated? They only leave a few lines in syslog, but these options are deprecated already in stretch.
(https://www.openssh.com/txt/release-7.5 ff)

Oct 8 2019, 10:05 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1719: ssh deprecated options.
Oct 8 2019, 9:58 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T1719: ssh deprecated options.
Oct 8 2019, 9:58 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1717: disable multiple daemons to autostart at boot as Resolved.

https://github.com/vyos/vyos-build/commit/1ff1b22726f1f4678dca8295860623d728e20521

Oct 8 2019, 8:43 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1718: ISO check in /opt/vyatta/sbin/install-image faulty.
Oct 8 2019, 8:28 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T1718: ISO check in /opt/vyatta/sbin/install-image faulty.
Oct 8 2019, 8:26 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1717: disable multiple daemons to autostart at boot from Open to In progress.
Oct 8 2019, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1717: disable multiple daemons to autostart at boot.
  • systemctl disable pacemaker
  • systemctl disable corosync
  • systemctl disable wpa_supplicant
  • systemctl disable squid
Oct 8 2019, 4:11 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard renamed T1717: disable multiple daemons to autostart at boot from disable pacemaker, squid autostart at boot to disable multiple daemons to autostart at boot.
Oct 8 2019, 3:55 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard triaged T1717: disable multiple daemons to autostart at boot as Normal priority.
Oct 8 2019, 3:51 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T1717: disable multiple daemons to autostart at boot.
Oct 8 2019, 3:51 PM · VyOS 1.3 Equuleus (1.3.0)

Oct 3 2019

hagbard moved T1700: Wireguard FQDN endpoint doesn't work after reboot from In Progress to Finished on the VyOS 1.3 Equuleus board.
Oct 3 2019, 5:39 PM · Rejected
hagbard moved T1700: Wireguard FQDN endpoint doesn't work after reboot from Backlog to Finished on the VyOS 1.2 Crux board.
Oct 3 2019, 5:39 PM · Rejected
hagbard closed T1700: Wireguard FQDN endpoint doesn't work after reboot as Wontfix.
Oct 3 2019, 5:38 PM · Rejected

Oct 2 2019

hagbard added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

Shall I close it as won't fix, given the fact that it is an upstream issue. Anything build around it, is in my opinion just a kludge, unless we would go with a separate daemon which can check and re-establish connections if they fail. The danger is that vyos becomes then more a server than a router. As workaround, a cronjob could do that as well, either setting an option via cli (wg-heartbeat or so since keepalive is a wg option already), which drops a cronjob onto the box and checks the wg endpoint periodically, if it fails it just calls diable/enable and checks again for X times, before it sleeps for let's say 24hs or so. @kroy would something like acronjob help you? Could be also set as a @reboot job and once the traffic flows it kicks itself out. Just wanna throw out ideas here.

Oct 2 2019, 7:18 PM · Rejected

Oct 1 2019

hagbard closed T1706: wireguard broken in latest rolling as Resolved.
Oct 1 2019, 7:53 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1706: wireguard broken in latest rolling.

https://github.com/vyos/vyos-1x/commit/cf499f958423919264884e9f1c5c1b593fd9de0e next rolling will have it fixed.

Oct 1 2019, 7:53 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard committed rVYOSONEXcf499f958423: [wireguard] - T1706: wireguard broken in latest rolling.
Oct 1 2019, 7:52 PM
hagbard moved T1706: wireguard broken in latest rolling from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Oct 1 2019, 7:42 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1706: wireguard broken in latest rolling.

They have been committed at the same time, while I was using the current version if ifconfig.py and new one was published.
https://github.com/vyos/vyos-1x/commit/c24eb48c54b562fe7f78cdda82f2e245e9ab8506

Oct 1 2019, 7:39 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard renamed T1706: wireguard broken in latest rolling from wigreuard broken in latest rolling to wireguard broken in latest rolling.
Oct 1 2019, 7:05 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1706: wireguard broken in latest rolling.
Oct 1 2019, 6:55 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T1706: wireguard broken in latest rolling.
Oct 1 2019, 6:55 PM · VyOS 1.3 Equuleus (1.3.0)