Page MenuHomeVyOS Platform
Feed All Stories

Nov 28 2020

c-po added a comment to T2947: Nat translation many-many with prefix does not map 1-1..

We actually need this:
http://git.nftables.org/nftables/commit/?id=35a6b10c1bc488ca195e9c641563c29251f725f3

Nov 28 2020, 8:07 PM · VyOS 1.4 Sagitta
c-po changed the status of T3092: nat: migrate to get_config_dict() from Open to In progress.
Nov 28 2020, 7:03 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a subtask for T3092: nat: migrate to get_config_dict(): T2947: Nat translation many-many with prefix does not map 1-1..
Nov 28 2020, 7:03 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a parent task for T2947: Nat translation many-many with prefix does not map 1-1.: T3092: nat: migrate to get_config_dict().
Nov 28 2020, 7:03 PM · VyOS 1.4 Sagitta
c-po created T3092: nat: migrate to get_config_dict().
Nov 28 2020, 7:03 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXfb648267bf5a: system: T3038: remove /dev/console from loadkeys.
Nov 28 2020, 6:14 PM
Viacheslav changed the status of T3091: Add "tag" for static route from Open to Needs testing.
Nov 28 2020, 4:41 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T2890: NAT error adding translation address range as Resolved.

Fixed.

Nov 28 2020, 4:39 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T2539: Issues with parsing ip range for source nat translation address as Resolved.

Fixed

set nat source rule 1000 outbound-interface 'eth1'
set nat source rule 1000 source address '203.0.113.1-203.0.113.4'
set nat source rule 1000 translation address '10.0.0.1-10.0.0.4'
vyos@r5# commit
[ nat ]
Warning: IP address 10.0.0.1 does not exist on the system!
Warning: IP address 10.0.0.4 does not exist on the system!
Nov 28 2020, 4:37 PM · VyConf
Viacheslav changed the status of T3020: The "scp" example is wrong in the bash-completion for "set system config-management commit-archive location" from In progress to Needs testing.
Nov 28 2020, 4:20 PM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav added a comment to T3091: Add "tag" for static route.

PR https://github.com/vyos/vyatta-cfg-quagga/pull/57

Nov 28 2020, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav updated the task description for T3091: Add "tag" for static route.
Nov 28 2020, 4:03 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav updated the task description for T3091: Add "tag" for static route.
Nov 28 2020, 3:07 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav created T3091: Add "tag" for static route.
Nov 28 2020, 2:37 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXb75a8bd4f09f: smoketest: pppoe-server: drop superfluous import.
Nov 28 2020, 2:32 PM
c-po claimed T2947: Nat translation many-many with prefix does not map 1-1..
Nov 28 2020, 2:28 PM · VyOS 1.4 Sagitta
Viacheslav created T3090: Move 'adjust-mss' firewall options to the interface section..
Nov 28 2020, 2:16 PM · VyOS 1.4 Sagitta
Viacheslav closed T2868: Tcp-mss option in policy calls kernel-panic as Resolved.
Nov 28 2020, 1:14 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2713: VyOS must not change permissions on files in /config/auth.

@jjakob can you check the latest rolling?

Nov 28 2020, 10:41 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 updated the task description for T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring.
Nov 28 2020, 10:36 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 updated the task description for T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring.
Nov 28 2020, 10:32 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring.

https://github.com/vyos/vyatta-cfg-qos/pull/8
https://github.com/vyos/vyos-1x/pull/621

Nov 28 2020, 9:57 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 updated the task description for T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring.
Nov 28 2020, 8:23 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 updated the task description for T3030: Support ERSPAN Tunnel Protocol.
Nov 28 2020, 8:23 AM · VyOS 1.4 Sagitta
jack9603301 renamed T3030: Support ERSPAN Tunnel Protocol from Support ERSPAN port mirroring to Support ERSPAN Tunnel Protocol.
Nov 28 2020, 8:22 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXc87ad948999c: vyos.template: T2720: fix remaining in-line time_block syntax.
Nov 28 2020, 7:28 AM
jack9603301 changed the subtype of T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring from "Task" to "Feature Request".
Nov 28 2020, 4:38 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 27 2020

GitHub <noreply@github.com> committed rVYOSONEX41f79409c742: vyos.template: T2720: fix resolv.conf trim blocks (authored by c-po).
Nov 27 2020, 10:23 PM
c-po changed the status of T2947: Nat translation many-many with prefix does not map 1-1. from Open to Confirmed.
Nov 27 2020, 9:31 PM · VyOS 1.4 Sagitta
c-po added a comment to T2947: Nat translation many-many with prefix does not map 1-1..

The root cause here is that there is yet no nftables map support in our template.

Nov 27 2020, 9:30 PM · VyOS 1.4 Sagitta
ossicoinc added a comment to T2947: Nat translation many-many with prefix does not map 1-1..

This one is holding us back from some great 1.3 features... would love to get it looked at!

Nov 27 2020, 7:27 PM · VyOS 1.4 Sagitta
jack9603301 closed T2714: A collection of utilities supporting IPv6 or ipv4 as Resolved.
Nov 27 2020, 3:29 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 closed T2714: A collection of utilities supporting IPv6 or ipv4, a subtask of T2706: Support NDP protocol monitoring, as Resolved.
Nov 27 2020, 3:29 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 closed T2715: Duplicate address detection option supporting ARP, a subtask of T2714: A collection of utilities supporting IPv6 or ipv4, as Resolved.
Nov 27 2020, 3:29 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 closed T2715: Duplicate address detection option supporting ARP as Resolved.
Nov 27 2020, 3:29 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX0b06b4807887: Merge pull request #508 from jack9603301/current (authored by c-po).
Nov 27 2020, 3:25 PM
Viacheslav added a comment to T2713: VyOS must not change permissions on files in /config/auth.

PR https://github.com/vyos/vyatta-cfg-system/pull/132

Nov 27 2020, 3:00 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring.

+1

Nov 27 2020, 2:48 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXa2ac9fac16ee: vyos.template: T2720: always enable Jinja2 trim_blocks feature.
Nov 27 2020, 2:41 PM
Viacheslav changed the status of T2868: Tcp-mss option in policy calls kernel-panic from Open to Needs testing.
Nov 27 2020, 1:56 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2868: Tcp-mss option in policy calls kernel-panic.

PR https://github.com/vyos/vyatta-cfg-firewall/pull/19

Nov 27 2020, 1:19 PM · VyOS 1.3 Equuleus (1.3.0)
runar updated subscribers of T2744: igmp-proxy issue: Address already in use.

@Dmitry I dont really know if this is a good idea.
The reason for this is that the configuration synchronisation between frr daemons depends on the daemons started at the same time, and always running when global configuration is applied.. this is also one of the reasons why frr-daemons starts prior to vyos starting on bootup and not when a daemon is configured. I do not know if this will be a issue with PIM, so i'm not sure what will happen with this daemon.
as an example for such synctonization is a prefix-list.
If you start bgp and ospf and then create a prefix-list, the list will be created in both ospf and bgp.
If you start bgp , then create the prefix-list and then start ospf, ospf will not automatically add the prefix-list but when you show the combined configuration is is still show'ed as a global prefix-list.. to get the prefix-list into ospf you need to manually add the commands to the daemon to get in sync.

Nov 27 2020, 1:18 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 moved T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Nov 27 2020, 10:32 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 changed the status of T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring from Open to In progress.
Nov 27 2020, 10:32 AM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXfb7e761ae3ef: igmp-proxy: T3088: migrate to get_config_dict().
Nov 27 2020, 10:17 AM
c-po committed rVYOSONEX854052217684: vyos.configdict: T2665: add task id comment for later refactoring.
Nov 27 2020, 10:17 AM
c-po committed rVYOSONEX8f328d70fcf8: smoketest: igmp-proxy: T3088: initial testcases.
Nov 27 2020, 10:17 AM
c-po closed T3088: Migrate IGMP-Proxy over to get_config_dict() and add smoketests as Resolved.
Nov 27 2020, 10:04 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3088: Migrate IGMP-Proxy over to get_config_dict() and add smoketests from Open to In progress.
Nov 27 2020, 9:51 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3088: Migrate IGMP-Proxy over to get_config_dict() and add smoketests.
Nov 27 2020, 9:51 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2713: VyOS must not change permissions on files in /config/auth.

This probably happens at this stage.
https://github.com/vyos/vyatta-cfg-system/blob/current/scripts/install/install-image-existing#L217-L224

Nov 27 2020, 9:09 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2868: Tcp-mss option in policy calls kernel-panic.

It seems a wrong logic.
We want that option to have an effect on "local" and "forward" directions, so we use table mangle and "PREROUTING" and VYATTA_FW_IN_HOOK hook
Generated rules

Nov 27 2020, 7:58 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) claimed T1207: DMVPN behind NAT.

Following this issue request https://sourceforge.net/p/opennhrp/support-requests/3/ we need to use transport mode instead of a tunnel. Was tested on AWS node and it looks working even with selector remote_ts = dynamic[gre]

Nov 27 2020, 7:51 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
GitHub <noreply@github.com> committed rVYOSONEX1972691e7fe2: Merge pull request #618 from DmitriyEshenko/fix-igmp-pim (authored by dmbaturin).
Nov 27 2020, 6:46 AM
debiansid added a comment to T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.

it stop at

AR      crypto/built-in.a
  LD [M]  crypto/crypto_simd.o
make[2]: *** [debian/rules:6: build] Error 2
dpkg-buildpackage: error: debian/rules build subprocess returned exit status 2
make[1]: *** [scripts/Makefile.package:83: bindeb-pkg] Error 2
make: *** [Makefile:1464: bindeb-pkg] Error 2
vyos_bld@7f2a9dc49956:/vyos/vyos-build-5.4.78/packages/linux-kernel$
Nov 27 2020, 1:28 AM · VyOS Rolling

Nov 26 2020

Viacheslav added a comment to T2868: Tcp-mss option in policy calls kernel-panic.

T490

Nov 26 2020, 6:11 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2061: protocol logs not sent to remote syslog.

@olofl Can you check the latest rolling release? Are all logs sent correctly?

Nov 26 2020, 4:17 PM · VyOS 1.2 Crux (VyOS 1.2.7)
c-po committed rVYOSONEX64d6e689a827: tunnel: T3072: remove bridgable variable as this is already set by the base….
Nov 26 2020, 4:16 PM
debiansid added a comment to T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.
Nov 26 2020, 4:14 PM · VyOS Rolling
c-po committed rVYOSONEXe59415d350c9: wireguard: T2653: interface is not bridgeable.
Nov 26 2020, 2:50 PM
jack9603301 added a comment to T3030: Support ERSPAN Tunnel Protocol.

PR: https://github.com/vyos/vyos-1x/pull/620

Nov 26 2020, 10:59 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T915: MPLS Support.

Put in a PR to enable ethernet sub interface MPLS enablement

Nov 26 2020, 5:37 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Nov 25 2020

Cheeze_It added a comment to T915: MPLS Support.

@bbs2web, I figured it out. I know what's not working.

Nov 25 2020, 7:57 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Cheeze_It added a comment to T915: MPLS Support.

I just did some testing, and @bbs2web, you're right. Sub interfaces to not get enabled. However main interfaces *DO* get enabled.

Nov 25 2020, 7:24 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Unknown Object (User) claimed T2744: igmp-proxy issue: Address already in use.

Let's run pimd only if IGMP or PIM configured.
https://github.com/vyos/vyos-1x/pull/618
https://github.com/vyos/vyos-build/pull/134

Nov 25 2020, 7:14 PM · VyOS 1.3 Equuleus (1.3.0)
Cheeze_It added a comment to T915: MPLS Support.

Try the new rolling by the way. There was a problem initially that we had to fix. Do like the rolling from 11/25 or tomorrow of 11/26.

Nov 25 2020, 7:06 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
bbs2web added a comment to T915: MPLS Support.

If I remove the manual sysctl lines it surprisingly still appears to work but proc net mpls is not flipped on as I would have expected.

Nov 25 2020, 7:03 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Cheeze_It added a comment to T915: MPLS Support.

@bbs2web, yessir, this is a new changed behavior. In the past when you configured an LDP interface it also enabled MPLS on the same interface.

Nov 25 2020, 5:27 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jack9603301 raised the priority of T3030: Support ERSPAN Tunnel Protocol from Wishlist to Normal.
Nov 25 2020, 2:15 PM · VyOS 1.4 Sagitta
jack9603301 moved T3030: Support ERSPAN Tunnel Protocol from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Nov 25 2020, 1:13 PM · VyOS 1.4 Sagitta
jack9603301 changed the status of T3030: Support ERSPAN Tunnel Protocol from Open to In progress.
Nov 25 2020, 1:12 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T3030: Support ERSPAN Tunnel Protocol.
Nov 25 2020, 12:49 PM · VyOS 1.4 Sagitta
jack9603301 renamed T3030: Support ERSPAN Tunnel Protocol from Support port mirroring to Support ERSPAN port mirroring.
Nov 25 2020, 12:49 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2061: protocol logs not sent to remote syslog.

PR https://github.com/vyos/vyos-build/pull/133

Nov 25 2020, 11:14 AM · VyOS 1.2 Crux (VyOS 1.2.7)
c-po added a comment to T3039: Resize a root partition and filesystem automatically during deployment in virtual environments.

So once a bigger disk is added on system boot the filesystem should be automatically repartitioned and resized to the maximum available space?

Nov 25 2020, 7:17 AM · VyOS 1.3 Equuleus (1.3.6)
bbs2web added a comment to T915: MPLS Support.

Is it expected that 'cat /proc/sys/net/mpls/platform_labels' yields '0' unless one defined 'set protocols mpls interface X'?

Nov 25 2020, 4:53 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Nov 24 2020

c-po added a comment to T3030: Support ERSPAN Tunnel Protocol.
Nov 24 2020, 7:24 PM · VyOS 1.4 Sagitta
c-po closed T3087: Update Linux Kernel to v4.19.160 as Resolved.
Nov 24 2020, 6:54 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3087: Update Linux Kernel to v4.19.160.
Nov 24 2020, 6:53 PM · VyOS 1.3 Equuleus (1.3.0)
sempervictus added a comment to T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.

Created a GitHub PR against 5.4.78 with the core functions listed above, ixbe and QAT in-tree as well as wireguard (avoids the convoluted module builds and permits LTO/CFI passes)

Nov 24 2020, 4:40 PM · VyOS Rolling
jack9603301 updated the task description for T2714: A collection of utilities supporting IPv6 or ipv4.
Nov 24 2020, 3:47 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2715: Duplicate address detection option supporting ARP.

@c-po This task has been completed for so long, can the PR be reviewed?
PR: https://github.com/vyos/vyos-1x/pull/508

Nov 24 2020, 3:38 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3030: Support ERSPAN Tunnel Protocol.

I took a brief look, the ip command seems to support the relevant tunnel type

TYPE := { vlan | veth | vcan | vxcan | dummy | ifb | macvlan | macvtap |
           bridge | bond | team | ipoib | ip6tnl | ipip | sit | vxlan |
           gre | gretap | erspan | ip6gre | ip6gretap | ip6erspan |
           vti | nlmon | team_slave | bond_slave | bridge_slave |
           ipvlan | ipvtap | geneve | vrf | macsec | netdevsim | rmnet |
           xfrm }
Nov 24 2020, 3:19 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2061: protocol logs not sent to remote syslog.

Another bug that the following configuration doesn't configure vtysh level debug

Nov 24 2020, 2:33 PM · VyOS 1.2 Crux (VyOS 1.2.7)
AndyHicks updated the task description for T3086: Scheduled squidguard blacklist update breaks Squid.
Nov 24 2020, 12:19 PM
AndyHicks created T3086: Scheduled squidguard blacklist update breaks Squid.
Nov 24 2020, 12:07 PM
orlandoamador added a comment to T2297: NTP add support for pool configuration.

Perfect. Thanks.

Nov 24 2020, 11:49 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2061: protocol logs not sent to remote syslog.

The main reason is frr code for placing log files in a separate file.
https://github.com/FRRouting/frr/blob/master/tools/etc/rsyslog.d/45-frr.conf

Nov 24 2020, 11:43 AM · VyOS 1.2 Crux (VyOS 1.2.7)
c-po added a comment to T2297: NTP add support for pool configuration.

That is the idea.

Nov 24 2020, 7:28 AM · VyOS 1.4 Sagitta
orlandoamador added a comment to T2297: NTP add support for pool configuration.

So if one uses

set system ntp server <server>

it will render on ntp.conf

server <server> iburst
Nov 24 2020, 12:39 AM · VyOS 1.4 Sagitta

Nov 23 2020

drac added a comment to T2869: Intel ethernet driver defaults sub-optimal.
  1. Totally agree with this. We had this same issue when we used to run Vyatta. Took me ages to figure out too.

However, I'm not sure what would be the best way to implement this is? I read a good explanation here about when to increase and change interrupt settings.
Do you think a config option is best e.g.
set interfaces ethernet eth0 advanced ring rx nnnn

Nov 23 2020, 11:48 PM
GitHub <noreply@github.com> committed rVYOSONEXcf36b7ab1e1e: mpls-conf: T915: fix Python format string after refactoring (authored by Cheeze_It).
Nov 23 2020, 8:59 PM
c-po added a comment to T2297: NTP add support for pool configuration.

Why not introduce a new pool option like: set system ntp server <server> pool ?

Nov 23 2020, 8:49 PM · VyOS 1.4 Sagitta
c-po closed T2694: The information provided by SNMP is incomplete as Invalid.
Nov 23 2020, 5:28 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2694: The information provided by SNMP is incomplete.

Its not a bug of VyOS. The net-snmp linux package we utilize does not support more OIDs.

Nov 23 2020, 5:28 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2542: OpenVPN client tap interfaces not coming up as Resolved.
Nov 23 2020, 5:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2542: OpenVPN client tap interfaces not coming up.

Vtun interfaces are now created prior to starting OpenVPN to always ensure there is a kernel interface available

Nov 23 2020, 5:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T2850: Add BGP template for FRR from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Nov 23 2020, 5:26 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2155: Cannot set anything on Intel 82599ES 10-Gigabit SFI/SFP+ as Resolved.
Nov 23 2020, 5:26 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2205: "set interface ethernet" fails on Hyper-V as Resolved.
Nov 23 2020, 5:26 PM · VyOS 1.3 Equuleus (1.3.0)