Page MenuHomeVyOS Platform
Feed All Stories

Nov 22 2020

c-po committed rVYOSONEXd4d223ff86e0: op-mode: add "restart" tree.
Nov 22 2020, 1:42 PM
Viacheslav added a comment to T235: Ability to configure manual IP Rules.

@Dataforce @fetzerms
ip rule "from" already in CLI T439

Nov 22 2020, 1:26 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

Okay, then I can merge this service into NAT66

Nov 22 2020, 12:44 PM · VyOS 1.4 Sagitta
c-po added a comment to T2898: Support NDP proxy.

That we can deal with later on when it‘s needed

Nov 22 2020, 12:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T439: local PBR support.

@pasik Can you check if it solves your expectation?

Nov 22 2020, 12:20 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

I can consider migrating to the implementation of nat66, but I'm not sure if there is a case where the nat66 feature does not need to be enabled, but NDP proxy needs to be enabled

Nov 22 2020, 11:54 AM · VyOS 1.4 Sagitta
c-po claimed T2802: Tunnel interface does not apply EUI-64 IPv6 Address.
Nov 22 2020, 11:27 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2898: Support NDP proxy.

I still have the opinion that NDP proxy should be automatically configured when configuring nat66 as by then all interfaces and directions of the translation are known and the user must not configure any additional daemon.

Nov 22 2020, 11:03 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX72cb73892b14: openvpn: T3080: add missing multiplication on keepalive config option.
Nov 22 2020, 9:42 AM
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02, a subtask of T3060: OpenVPN virtual interface not coming up after upgrade, from In progress to Needs testing.
Nov 22 2020, 9:41 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02, a subtask of T3081: get_config_dict() does not honor whitespaces in the CLI values field, from In progress to Needs testing.
Nov 22 2020, 9:41 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02 from In progress to Needs testing.
Nov 22 2020, 9:41 AM · VyOS 1.3 Equuleus (1.3.0)
c-po assigned T3081: get_config_dict() does not honor whitespaces in the CLI values field to jestabro.
Nov 22 2020, 9:26 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:25 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a parent task for T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02: T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:23 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a subtask for T3081: get_config_dict() does not honor whitespaces in the CLI values field: T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02.
Nov 22 2020, 9:23 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated subscribers of T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:22 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:22 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3081: get_config_dict() does not honor whitespaces in the CLI values field from Open to Confirmed.
Nov 22 2020, 9:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02, a subtask of T3060: OpenVPN virtual interface not coming up after upgrade, from Open to In progress.
Nov 22 2020, 8:49 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02 from Open to In progress.
Nov 22 2020, 8:49 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 21 2020

c-po committed rVYOSONEX4b219bbf1b35: smoketest: openvpn: T3060: verify authentication username and password.
Nov 21 2020, 9:07 PM
syncer moved T3035: Allow IPv4 over IPv6 IPsec and vice versa from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Nov 21 2020, 8:54 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T3035: Allow IPv4 over IPv6 IPsec and vice versa from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Nov 21 2020, 8:54 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer changed the status of T3035: Allow IPv4 over IPv6 IPsec and vice versa from Open to Needs testing.
Nov 21 2020, 8:53 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer changed the subtype of T3035: Allow IPv4 over IPv6 IPsec and vice versa from "Task" to "Enhancement".
Nov 21 2020, 8:53 PM · VyOS 1.2 Crux (VyOS 1.2.7)
kroy added a parent task for T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02: T3060: OpenVPN virtual interface not coming up after upgrade.
Nov 21 2020, 5:54 PM · VyOS 1.3 Equuleus (1.3.0)
kroy added a subtask for T3060: OpenVPN virtual interface not coming up after upgrade: T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02.
Nov 21 2020, 5:54 PM · VyOS 1.3 Equuleus (1.3.0)
kroy created T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02.
Nov 21 2020, 5:52 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3060: OpenVPN virtual interface not coming up after upgrade as Resolved.
Nov 21 2020, 4:35 PM · VyOS 1.3 Equuleus (1.3.0)
danielpo added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

Thanks, works now.

Nov 21 2020, 12:58 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

@danielpo thanks foe the config. A new rolling containig a fix for this issue was just published. A smoketest will be added today to ensure this wont happen again.

Nov 21 2020, 12:24 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXed38b0dfc901: openvpn: T3060: fix client authentication username and password file.
Nov 21 2020, 11:00 AM
c-po committed rVYOSONEX8783a4b2db12: openvpn: T3060: always listen op IPv4 and IPv6 sockets.
Nov 21 2020, 11:00 AM
jack9603301 moved T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge from In Progress to Finished on the VyOS 1.3 Equuleus board.
Nov 21 2020, 9:28 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 closed T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge as Resolved.
Nov 21 2020, 9:25 AM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXeb8bac3df75a: system: T3078: fix vyos-configd handling for "system option" path.
Nov 21 2020, 9:05 AM
GitHub <noreply@github.com> committed rVYOSONEX9b8e3d83e9cf: bridge: T3079: bugfix on VLAN 1 is deleted in VLAN-aware bridges (authored by jack9603301).
Nov 21 2020, 8:25 AM
c-po committed rVYOSONEX5b693c3a71f5: ethernet: T3048: fix migrator to also support a plain config.
Nov 21 2020, 8:22 AM
jack9603301 added a comment to T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge.

PR: https://github.com/vyos/vyos-1x/pull/615

Nov 21 2020, 7:08 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 changed Is it a breaking change? from none to compatible on T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge.
Nov 21 2020, 7:08 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 moved T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Nov 21 2020, 5:14 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 changed the status of T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge from Open to In progress.
Nov 21 2020, 5:05 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 created T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge.
Nov 21 2020, 5:05 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 20 2020

danielpo added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.
authentication {
    password xxxx
    username xxxxx
}
device-type tun
encryption {
    cipher aes256
}
firewall {
    in {
        ipv6-name DENYv6_IN
        name DENY_IN
    }
    local {
        ipv6-name DENYv6_IN
        name DENY_IN
    }
}
hash sha256
mode client
openvpn-option "key-direction 1"
openvpn-option route-nopull
persistent-tunnel
protocol tcp-active
remote-host 1.2.3.4
remote-host 1.2.3.5
remote-port 1195
tls {
    ca-cert-file /config/auth/cert.ca
    auth-file  /config/auth/tls-auth
    tls-version-min 1.2
}
Nov 20 2020, 11:47 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3078: CLI cleanup: rename "system options" -> "system option" as Resolved.
Nov 20 2020, 11:39 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX193323ba5d2f: system: T3078: rename "system options" -> "system option".
Nov 20 2020, 11:36 PM
c-po committed rVYOSONEX5f5b2808c0a6: ethernet: T3048: drop static smp-affinity for dynamic performance tuning.
Nov 20 2020, 11:36 PM
c-po closed T3048: Drop static smp-affinity for a more dynamic way using tuned as Resolved.
Nov 20 2020, 11:34 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3078: CLI cleanup: rename "system options" -> "system option" from Open to In progress.
Nov 20 2020, 10:59 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3078: CLI cleanup: rename "system options" -> "system option".
Nov 20 2020, 10:59 PM · VyOS 1.3 Equuleus (1.3.0)
c-po reopened T3060: OpenVPN virtual interface not coming up after upgrade as "Open".
Nov 20 2020, 10:58 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

Please show us your config

Nov 20 2020, 10:58 PM · VyOS 1.3 Equuleus (1.3.0)
danielpo added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

Now this error appear when trying the latest image:

Nov 20 2020, 5:20 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T160: Support NAT64.

@dmbaturin @artooro Come on, remember not to forget NAT46

Nov 20 2020, 4:32 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jack9603301 added a comment to T2898: Support NDP proxy.

@c-po I am thinking, although it is not possible to incorporate NAT66, whether we can prioritize how to improve and incorporate NDP Proxy

Nov 20 2020, 4:28 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T439: local PBR support from Open to Needs testing.
Nov 20 2020, 4:19 PM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX8bc6775a692e: Merge pull request #614 from sever-sever/T439 (authored by c-po).
Nov 20 2020, 3:54 PM
c-po committed rVYOSONEX7fce006670bf: tunnel: T3072: remove debug print code.
Nov 20 2020, 3:47 PM
c-po committed rVYOSONEXca073ba863b5: tunnel: T3072: bugfix KeyError for IPv6 GRE verify code.
Nov 20 2020, 3:47 PM
c-po committed rVYOSONEX1a199ab4a2d3: Makefile: T2653: remove ipv6 wireguard node.
Nov 20 2020, 2:08 PM
c-po closed T3077: WireGuard: automatically create link-local IPv6 adresses, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, as Resolved.
Nov 20 2020, 1:42 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3077: WireGuard: automatically create link-local IPv6 adresses as Resolved.
Nov 20 2020, 1:42 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXe93cc4e4935c: wireguard: ifconfig: T2653: interface address is not mandatory.
Nov 20 2020, 1:42 PM
c-po committed rVYOSONEX221940c94bf2: wireguard: T2653: fix IPv6 peer address configuration.
Nov 20 2020, 1:42 PM
c-po committed rVYOSONEX49be767ce95d: wireguard: T3077: automatically create link-local IPv6 adresses.
Nov 20 2020, 1:42 PM
c-po committed rVYOSONEX3ae4de269951: tunnel: T3072: drop dead code.
Nov 20 2020, 1:42 PM
c-po committed rVYOSONEXfe8d884b564e: tunnel: T3072: support changing tunnel encapsulation on-the-fly.
Nov 20 2020, 1:42 PM
c-po triaged T3077: WireGuard: automatically create link-local IPv6 adresses as Normal priority.
Nov 20 2020, 1:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3077: WireGuard: automatically create link-local IPv6 adresses, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, from Open to In progress.
Nov 20 2020, 1:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3077: WireGuard: automatically create link-local IPv6 adresses from Open to In progress.
Nov 20 2020, 1:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3077: WireGuard: automatically create link-local IPv6 adresses.
Nov 20 2020, 1:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2997: DHCP: disallow/do-not-request certain options when requesting IP address from server as Resolved.
Nov 20 2020, 1:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2997: DHCP: disallow/do-not-request certain options when requesting IP address from server.

DNS domain name servers are always requested from the server but must be explicitly "allowed" by set systems name-servers-dhcp

Nov 20 2020, 1:16 PM · VyOS 1.3 Equuleus (1.3.0)
Cremator added a comment to T578: Support Linux Container.

Running Docker on 1.3 rolling works, but there is no integration with the docker bridge interfaces and docker iptables rules obviously.
My goal was to run Traefik and Pihole and it works so far.
https://gist.github.com/Cremator/183c1a4d24e7812f94ec4bd41f7718b3

Nov 20 2020, 12:58 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T2550: OpenVPN: IPv4 not working in client mode as Resolved.
Nov 20 2020, 11:58 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1405: dhclient runs before mac overrides are applied as Resolved.
Nov 20 2020, 11:58 AM
c-po closed T3060: OpenVPN virtual interface not coming up after upgrade as Resolved.
Nov 20 2020, 11:58 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3065: Add "interfaces wirelessmodem" IPv6 support, a subtask of T3063: Add support for Huawei LTE Module ME909s-120, as Resolved.
Nov 20 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3065: Add "interfaces wirelessmodem" IPv6 support as Resolved.
Nov 20 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3072: Migrate tunnel interfaces to new get_config_dict() approach, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, as Resolved.
Nov 20 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3072: Migrate tunnel interfaces to new get_config_dict() approach as Resolved.
Nov 20 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3068: Automatic generation of IPv6 link local addresses for tunnel interfaces, a subtask of T3072: Migrate tunnel interfaces to new get_config_dict() approach, as Resolved.
Nov 20 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3068: Automatic generation of IPv6 link local addresses for tunnel interfaces as Resolved.
Nov 20 2020, 11:57 AM
c-po committed rVYOSONEX7ad026794bee: Merge branch 'tunnel-rewrite' into current.
Nov 20 2020, 11:56 AM
c-po committed rVYOSONEX672eaeb2be1c: tunnel: T3068: automatic generate link-local adresses.
Nov 20 2020, 11:56 AM
c-po committed rVYOSONEX4eef27f0e834: tunnel: T3072: interfaces used for NHRP can not be deleted.
Nov 20 2020, 11:56 AM
c-po committed rVYOSONEX246808bc33a2: tunnel: T3072: xml: harden regex validators.
Nov 20 2020, 11:56 AM
c-po committed rVYOSONEXd98e01da6b18: tunnel: T3072: migrate to get_config_dict().
Nov 20 2020, 11:56 AM
jack9603301 moved T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Nov 20 2020, 11:44 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a subtask for T3072: Migrate tunnel interfaces to new get_config_dict() approach: T3068: Automatic generation of IPv6 link local addresses for tunnel interfaces.
Nov 20 2020, 11:28 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a parent task for T3068: Automatic generation of IPv6 link local addresses for tunnel interfaces: T3072: Migrate tunnel interfaces to new get_config_dict() approach.
Nov 20 2020, 11:28 AM
varac added a comment to T1286: DHCP hostfile-update isn't removing hostfile entries on expiry..

https://marc.info/?l=dhcp-hackers&m=128755776831463 describes the solution.
Setting ClientName, ClientIp, ClientMac, ClientDomain on release and expire fails, and there's no need for that since they are already known.
Simply removing all "set" commands in the release and expire section fixes this bug and restores the desired behaviour that i.e. the leases are removed from /etc/hosts.

Nov 20 2020, 8:30 AM · VyOS 1.3 Equuleus (1.3.0)
tjh added a comment to T2977: Permissions Denied doing "show conntrack-sync status" on backup router.

I just saw the patch above for how to fix this and yes, with that line changed to sudo it now works correctly.
Thanks!

Nov 20 2020, 12:23 AM
tjh created T3076: Router reboot adds unwanted 'conntrack-sync mcast-group '225.0.0.50'' line to configuration.
Nov 20 2020, 12:20 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Nov 19 2020

c-po closed T3075: Update Linux Kernel to v4.19.158 as Resolved.
Nov 19 2020, 9:37 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3075: Update Linux Kernel to v4.19.158.
Nov 19 2020, 9:35 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1405: dhclient runs before mac overrides are applied.

I have adjust the logic which now sets the interface MAC address before any other parameter. Using the OSI model this makes sense as the MAC layer is below IP.

Nov 19 2020, 9:10 PM
c-po committed rVYOSONEX1b3cde673ad0: ifconfig: T1405: ensure MAC address is configured first.
Nov 19 2020, 9:09 PM