Page MenuHomeVyOS Platform
Feed All Stories

Jun 17 2020

c-po edited projects for T2478: login radius: use NAS-IP-Address if defined source address, added: VyOS 1.2 Crux (VyOS 1.2.6); removed Ready for Crux (1.2.x).
Jun 17 2020, 5:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
c-po moved T2478: login radius: use NAS-IP-Address if defined source address from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 17 2020, 5:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
c-po added a comment to T2478: login radius: use NAS-IP-Address if defined source address.

Feature now also in crux version ob libpam-radius.

Jun 17 2020, 5:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
GitHub <noreply@github.com> committed rVYOSONEX99bdbf785957: Merge pull request #462 from DmitriyEshenko/cur-1x-17062020 (authored by c-po).
Jun 17 2020, 4:53 PM
Demon_H created T2608: delete pseudo-ethernet failed (another error type).
Jun 17 2020, 2:20 PM · VyOS 1.3 Equuleus (1.3.0)
Demon_H claimed T2607: Support for pppoe-server radius mode auth and config radius accouting port.
Jun 17 2020, 1:37 PM · VyOS 1.3 Equuleus (1.3.0)
Demon_H created T2607: Support for pppoe-server radius mode auth and config radius accouting port.
Jun 17 2020, 1:36 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) changed the status of T2299: login radius-server priority from Open to Needs testing.

Add PR for rolling https://github.com/vyos/vyos-1x/pull/462

Jun 17 2020, 1:26 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) claimed T2225: PIM/IGMP documentation.
Jun 17 2020, 10:32 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
lawrencepan created T2606: ikev2 mobike commit failed .
Jun 17 2020, 9:07 AM · VyOS 1.2 Crux
jjakob added a comment to T2582: Script daemon to offload processing during commit.

There is another use of is_tag/is_leaf in python/vyos/validate.py is_member, as it can work on both bridge and bond members, and they have different syntax for member interfaces. It would only be possible to hardcode each case and remove the use of is_*

Jun 17 2020, 9:02 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T1720: support for more 'show ip route' commands as Resolved.
Jun 17 2020, 8:09 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav changed the status of T2141: Static ARP is not applied on boot from Open to Needs testing.

In the latest rolling, I don't see this bug.

VyOS 1.3-rolling-202006170117
Jun 17 2020, 7:01 AM · VyOS 1.3 Equuleus (1.3.0)
tjh added a comment to T1938: syslog doesn't start automatically.

Hmmm is it the fact I have a remote syslog configured that triggers this bug?
I didn't realise that, I'll have to remove it and see if it helps.
It's very frustrating not having the firewall logs available to view.

Jun 17 2020, 4:15 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
tjh added a comment to T2478: login radius: use NAS-IP-Address if defined source address.

For what little to no weight my opinion matters, I also agree that this should be backported to Crux.
As I've bashed my head into it testing :-)

Jun 17 2020, 4:14 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
jestabro updated the task description for T2582: Script daemon to offload processing during commit.
Jun 17 2020, 1:12 AM · VyOS 1.3 Equuleus (1.3.0)

Jun 16 2020

Unknown Object (User) added a comment to T2584: pppoe-server NAS-Filter-Rule attribute.

Implementation steps:

  1. Add $INCLUDE dictionary.rfc4849 to /usr/share/accel-ppp/radius/dictionary file
  2. Add required modules for use ip-pre-up/ip-up/ip-down scripts
[modules]
sigchld
pppd_compat

And pppd_compat params

[pppd-compat]
verbose=1
ip-pre-up=/path/to/ip-pre-up 
radattr-prefix=/var/run/radattr
  1. Create ip-pre-up/ip-down script which will get configured firewall names and rules from CLI or supported script

Note: When ip-pre-up return 1 then the session will not start like described in https://tools.ietf.org/html/rfc4849

Jun 16 2020, 7:45 PM · VyOS Rolling
Viacheslav closed T2156: PIM op-mode commands, a subtask of T1729: PIM (Protocol Independent Multicast) implementation, as Resolved.
Jun 16 2020, 6:35 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
Viacheslav closed T2156: PIM op-mode commands as Resolved.
Jun 16 2020, 6:35 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX883426259651: Merge pull request #459 from DmitriyEshenko/1x-ppp-16062020 (authored by c-po).
Jun 16 2020, 5:20 PM
GitHub <noreply@github.com> committed rVYOSONEX5692f4324277: Merge pull request #460 from DmitriyEshenko/1xl2tp16062020 (authored by c-po).
Jun 16 2020, 5:20 PM
c-po closed T2605: SNMP service is not disabled by default as Resolved.
Jun 16 2020, 4:40 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
c-po moved T2605: SNMP service is not disabled by default from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 16 2020, 4:40 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
c-po moved T2605: SNMP service is not disabled by default from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.6) board.
Jun 16 2020, 4:40 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
c-po changed the status of T2605: SNMP service is not disabled by default from Open to In progress.
Jun 16 2020, 4:33 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
c-po created T2605: SNMP service is not disabled by default.
Jun 16 2020, 4:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
c-po committed rVYOSONEX1be2084f3b93: snmp: T2321: use restart of start in systemctl.
Jun 16 2020, 4:29 PM
jestabro closed T2568: Add some missing checks in config, a subtask of T2501: Cannot recover from failed boot config load, as Resolved.
Jun 16 2020, 3:54 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T2568: Add some missing checks in config as Resolved.
Jun 16 2020, 3:54 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro committed rVYOSONEX3891799d970f: config: T2568: add missing error checking.
Jun 16 2020, 3:54 PM
jestabro closed T2604: Remove use of is_tag in system-syslog.py as Resolved.
Jun 16 2020, 3:51 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro committed rVYOSONEX796a815c6014: syslog: T2604: remove unnecessary use of is_tag.
Jun 16 2020, 3:51 PM
jestabro created T2604: Remove use of is_tag in system-syslog.py.
Jun 16 2020, 3:20 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2602: pptp/sstp/l2tp add possibility enable or disable CCP.

Fixed https://github.com/vyos/vyos-1x/pull/460.

Jun 16 2020, 10:21 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2602: pptp/sstp/l2tp add possibility enable or disable CCP.

Does not possible to disable ccp in l2tp

vyos@RTR1# set vpn l2tp remote-access ccp-disable 
[edit]
vyos@RTR1# commit
[ vpn l2tp ]
VyOS had an issue completing a command.
Jun 16 2020, 10:04 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) created T2603: pppoe-server: reduce min MTU.
Jun 16 2020, 8:49 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Unknown Object (User) claimed T2602: pptp/sstp/l2tp add possibility enable or disable CCP.
Jun 16 2020, 8:36 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) created T2602: pptp/sstp/l2tp add possibility enable or disable CCP.
Jun 16 2020, 8:36 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) changed the status of T2601: pppoe-server: Cannot disable CCP from Open to Needs testing.

PR https://github.com/vyos/vyos-1x/pull/459

Jun 16 2020, 8:29 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) claimed T2601: pppoe-server: Cannot disable CCP.
Jun 16 2020, 7:36 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) created T2601: pppoe-server: Cannot disable CCP.
Jun 16 2020, 7:36 AM · VyOS 1.3 Equuleus (1.3.0)

Jun 15 2020

Unknown Object (User) added a comment to T2572: Wrong default units when defining traffic policy bandwidth.

By the way, shouldn't we better talk through slack? : )

Jun 15 2020, 9:49 PM
Unknown Object (User) added a comment to T2572: Wrong default units when defining traffic policy bandwidth.

I tested on PPPoE the simple configuration I gave you on slack. It works perfectly, delay goes down for interactive traffic and bulk flows are distributed fairly.

Jun 15 2020, 9:48 PM
c-po closed T2588: Add support for default values to the interface-definition format as Invalid.
Jun 15 2020, 7:20 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2588: Add support for default values to the interface-definition format.

My fault. defaultValue must pe placed outside of properties

Jun 15 2020, 7:20 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX9c4d9a76d58d: Merge pull request #458 from thomas-mangin/T2599 (authored by c-po).
Jun 15 2020, 6:48 PM
c-po added a comment to T2518: Add support for IPv6 NAT (NPTv6).

@alexandrestein can I assume you‘re using NPTv6 on VyOS 1.2 series? If so you mind sharing an example/configuration so we can also improve our documentation?

Jun 15 2020, 5:15 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jack9603301 added a comment to T2518: Add support for IPv6 NAT (NPTv6).

@alexandrestein Sorry, I didn't understand some of them, but I opened this task list to track 1.3 nptv6 process, not about the DHCP support of wireguard. If you need this function or find that there is a bug in wireguard's DHCP, you should submit a bug report task list separately.

Jun 15 2020, 4:45 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
alexandrestein added a comment to T2518: Add support for IPv6 NAT (NPTv6).

Thank you @jack9603301.

Jun 15 2020, 4:35 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
thomas-mangin closed T2591: show command has wrong interfaces ordering as Resolved.
Jun 15 2020, 3:40 PM · VyOS 1.3 Equuleus (1.3.0)
thomas-mangin added a comment to T2591: show command has wrong interfaces ordering.

@Dmitry correct same bug - thank you. resolved.

Jun 15 2020, 3:40 PM · VyOS 1.3 Equuleus (1.3.0)
thomas-mangin closed T2576: "show interfaces" does not return VTI as Resolved.
Jun 15 2020, 3:39 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2572: Wrong default units when defining traffic policy bandwidth.

@c-po I have never tested QoS on PPPoE in my lab. I'm having a look and come back to you.

Jun 15 2020, 3:32 PM
Unknown Object (User) added a comment to T2599: "show interfaces" does not list VIF interfaces in ascending order.

I think this is a related task https://phabricator.vyos.net/T2591

Jun 15 2020, 3:30 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2599: "show interfaces" does not list VIF interfaces in ascending order.
Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface        IP Address                        S/L  Description
---------        ----------                        ---  -----------
dum0             172.18.254.201/32                 u/u
eth0             -                                 u/u
eth0.5           -                                 u/u
eth0.10          -                                 u/u
eth0.15          -                                 u/u
eth0.201         172.18.201.10/24                  u/u
eth0.202         2001:affe::201/64                 u/u
eth1             fd00::ffff/64                     u/u
eth2             -                                 A/D
lo               127.0.0.1/8                       u/u
                 ::1/128
Jun 15 2020, 3:29 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2599: "show interfaces" does not list VIF interfaces in ascending order as Resolved.
Jun 15 2020, 3:29 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX8193515fe6fe: Merge pull request #457 from thomas-mangin/T2599 (authored by c-po).
Jun 15 2020, 3:26 PM
c-po added a comment to T2572: Wrong default units when defining traffic policy bandwidth.
vyos@vyos:~$ show config commands | grep traffic
set interfaces pppoe pppoe0 traffic-policy out 'QoS'
set traffic-policy shaper QoS bandwidth '50mbit'
set traffic-policy shaper QoS default bandwidth '100%'
set traffic-policy shaper QoS default queue-type 'fq-codel'
vyos@vyos:~$ tc class show dev pppoe0
vyos@vyos:~$
Jun 15 2020, 3:23 PM
thomas-mangin added a comment to T2599: "show interfaces" does not list VIF interfaces in ascending order.

https://github.com/vyos/vyos-1x/pull/457

Jun 15 2020, 3:23 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2572: Wrong default units when defining traffic policy bandwidth.

Hey @zsdc , thanks for having a look into it.

Jun 15 2020, 3:14 PM
fabio.prina added a comment to T2576: "show interfaces" does not return VTI.

Thanks to all of you

Jun 15 2020, 2:56 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2599: "show interfaces" does not list VIF interfaces in ascending order from Need Triage to Backlog on the VyOS 1.3 Equuleus board.
Jun 15 2020, 2:54 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2576: "show interfaces" does not return VTI from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Jun 15 2020, 2:54 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2576: "show interfaces" does not return VTI from Open to Needs testing.
Jun 15 2020, 2:54 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX79bb346293e9: login: radius: T2600: fix wrongly redered pam_radius_auth.conf.
Jun 15 2020, 2:53 PM
c-po closed T2600: RADIUS system login configuration rendered wrongly as Resolved.
Jun 15 2020, 2:53 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2600: RADIUS system login configuration rendered wrongly from Open to In progress.
Jun 15 2020, 2:31 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2600: RADIUS system login configuration rendered wrongly.
Jun 15 2020, 2:23 PM · VyOS 1.3 Equuleus (1.3.0)
c-po renamed T2599: "show interfaces" does not list VIF interfaces in ascending order from "show interfaces" does not list VIF interfaces in natural sorted order to "show interfaces" does not list VIF interfaces in ascending order.
Jun 15 2020, 2:19 PM · VyOS 1.3 Equuleus (1.3.0)
c-po assigned T2599: "show interfaces" does not list VIF interfaces in ascending order to thomas-mangin.
Jun 15 2020, 2:18 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2599: "show interfaces" does not list VIF interfaces in ascending order.
Jun 15 2020, 2:18 PM · VyOS 1.3 Equuleus (1.3.0)
thomas-mangin added a comment to T2576: "show interfaces" does not return VTI.

The patch was merged and the issue should be resolved with the next ISO.

Jun 15 2020, 2:10 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEXd119be2a5d9f: Merge pull request #456 from thomas-mangin/T2576 (authored by c-po).
Jun 15 2020, 12:55 PM
thomas-mangin added a comment to T2576: "show interfaces" does not return VTI.

https://github.com/vyos/vyos-1x/pull/456

Jun 15 2020, 11:53 AM · VyOS 1.3 Equuleus (1.3.0)
zsdc assigned T2572: Wrong default units when defining traffic policy bandwidth to Unknown Object (User).

@s.lorente can you check this with actually configured tc values?

Jun 15 2020, 11:13 AM
olofl added a comment to T109: VyOS Can Lose Parts Of Its Config On Reboot - In Certain Situations.

This config was lost after first boot. Ping T2598
VyOS 1.2.3

Jun 15 2020, 9:53 AM · VyOS 1.3 Equuleus (1.3.3)
Demon_H added a comment to T2574: wan-load-balance snat bug and route problem.

And i wonder why there is a rule which is 'WANLOADBALANCE_OUT -p icmp -m icmp --icmp-type any -j ACCEPT'.
May i know the purpose of the rule ?

Jun 15 2020, 9:39 AM · VyOS 1.3 Equuleus (1.3.6)
Demon_H added a comment to T2574: wan-load-balance snat bug and route problem.

It seems to be ok in vyos-1.3-rolling-202006150117-amd64.iso. Thanks a lot.

Jun 15 2020, 9:28 AM · VyOS 1.3 Equuleus (1.3.6)
olofl added a comment to T2598: Error when commiting firewall groups.

When googling on the error given, T109 shows up where I had posted about this in 2018. I'm not sure it's related to this. Im not sure any configuration has been lost on reboot.

Jun 15 2020, 9:22 AM · VyOS 1.2 Crux
olofl created T2598: Error when commiting firewall groups.
Jun 15 2020, 9:20 AM · VyOS 1.2 Crux
Demon_H added a comment to T2574: wan-load-balance snat bug and route problem.

I did not config any nat rule.

Jun 15 2020, 8:00 AM · VyOS 1.3 Equuleus (1.3.6)
c-po added a comment to T2574: wan-load-balance snat bug and route problem.

Please also share your NAT configuration

Jun 15 2020, 7:45 AM · VyOS 1.3 Equuleus (1.3.6)
Demon_H added a comment to T2574: wan-load-balance snat bug and route problem.

And I found that when I changed the wan load-balance configuration, the load-balance process failed to come up.
And I excuted the show wan-load-balance command, it returned the message 'WAN load balancing is not configured'.
After reboot, it became all right then.

Jun 15 2020, 2:21 AM · VyOS 1.3 Equuleus (1.3.6)
Demon_H added a comment to T2574: wan-load-balance snat bug and route problem.

This is my config below:

load-balancing {
    wan {
        enable-local-traffic
        interface-health pppoe0 {
            failure-count 5
            nexthop dhcp
            success-count 1
            test 0 {
                resp-time 5
                target 119.29.29.29
                ttl-limit 1
                type ping
            }
        }
        interface-health pppoe1 {
            failure-count 5
            nexthop dhcp
            success-count 1
            test 0 {
                resp-time 5
                target 119.29.29.29
                ttl-limit 1
                type ping
            }
        }
        interface-health pppoe2 {
            failure-count 5
            nexthop dhcp
            success-count 1
            test 0 {
                resp-time 5
                target 119.29.29.29
                ttl-limit 1
                type ping
            }
        }
        interface-health pppoe3 {
            failure-count 5
            nexthop dhcp
            success-count 1
            test 0 {
                resp-time 5
                target 119.29.29.29
                ttl-limit 1
                type ping
            }
        }
        rule 1 {
            inbound-interface eth1
            interface pppoe0 {
                weight 1
            }
            interface pppoe1 {
                weight 1
            }
            interface pppoe2 {
                weight 1
            }
            interface pppoe3 {
                weight 1
            }
            protocol all
        }
        sticky-connections {
        }
    }
}
Jun 15 2020, 2:18 AM · VyOS 1.3 Equuleus (1.3.6)
mpueschel added a comment to T2550: OpenVPN: IPv4 not working in client mode.

The same issue is present in site-to-site mode. local-host can be set there, but should not be required as the WAN ip might be dynamic

Jun 15 2020, 12:16 AM · VyOS 1.3 Equuleus (1.3.0)

Jun 14 2020

IZT_crobinson created T2597: Add more options to API.
Jun 14 2020, 10:48 PM
xrobau updated the task description for T2596: Allow specifying source IP for 'add system image'.
Jun 14 2020, 9:34 PM · VyOS 1.3 Equuleus (1.3.0)
xrobau updated the task description for T2596: Allow specifying source IP for 'add system image'.
Jun 14 2020, 9:32 PM · VyOS 1.3 Equuleus (1.3.0)
xrobau updated the task description for T2596: Allow specifying source IP for 'add system image'.
Jun 14 2020, 9:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2596: Allow specifying source IP for 'add system image'.

Probably is can be set in a curlrc file which is populated from CLI options

Jun 14 2020, 8:52 PM · VyOS 1.3 Equuleus (1.3.0)
xrobau added a comment to T1872: Removing serial console port from ESXi VM causes flooded syslog.

Confirmed fixed, thanks @c-po!

Jun 14 2020, 8:49 PM · VyOS 1.3 Equuleus (1.3.0)
xrobau updated the task description for T2596: Allow specifying source IP for 'add system image'.
Jun 14 2020, 8:46 PM · VyOS 1.3 Equuleus (1.3.0)
xrobau updated the task description for T2596: Allow specifying source IP for 'add system image'.
Jun 14 2020, 8:39 PM · VyOS 1.3 Equuleus (1.3.0)
xrobau created T2596: Allow specifying source IP for 'add system image'.
Jun 14 2020, 8:34 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T1538: Update conntrack-sync packages to fix VRRP issues.
Jun 14 2020, 8:19 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a project to T1538: Update conntrack-sync packages to fix VRRP issues: VyOS 1.3 Equuleus.
Jun 14 2020, 8:11 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.
Jun 14 2020, 8:10 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a project to T1729: PIM (Protocol Independent Multicast) implementation: VyOS 1.2 Crux (VyOS 1.2.6).
Jun 14 2020, 8:08 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
Unknown Object (User) added a comment to T1729: PIM (Protocol Independent Multicast) implementation.

Add PR for CRUX.
https://github.com/vyos/vyos-build/pull/107
https://github.com/vyos/vyos-1x/pull/455

Jun 14 2020, 8:07 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
xrobau placed T1538: Update conntrack-sync packages to fix VRRP issues up for grabs.
Jun 14 2020, 8:02 PM · VyOS 1.3 Equuleus (1.3.0)