Page MenuHomeVyOS Platform
Feed All Stories

Feb 23 2021

Unknown Object (User) changed the status of T2927: isc-dhcpd release and expiry events never execute from Open to In progress.
Feb 23 2021, 3:55 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.4 Sagitta
pasik added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

also having lots of NAT rules makes the vyos config handling and boot time very slow..

Feb 23 2021, 8:55 AM · VyOS 1.3 Equuleus (1.3.6)
tuxnet created T3348: dhcpd: Can't create new lease file: Permission denied.
Feb 23 2021, 7:46 AM · VyOS 1.3 Equuleus (1.3.6)

Feb 22 2021

wsapplegate added a comment to T3337: Add possibility to serve static DNS zones from the router.

Sorry, I don't have a GitHub account (I try hard to avoid centralized systems). If what you want is a git repo/branch to pull from, I can setup one somewhere and commit the patch there, though.

Feb 22 2021, 11:06 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
wsapplegate added a comment to T3338: Some Cloud-Init configurations can prevent login on the router.
In T3338#87770, @zsdc wrote:

And it is necessary to leave a bug-report on the Proxmox bug tracker to lead this to the logical end. Could you do this?

Feb 22 2021, 11:00 PM
c-po added a comment to T3337: Add possibility to serve static DNS zones from the router.

Any chance you can send this as GitHub PR?

Feb 22 2021, 9:36 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
pasik added a comment to T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts.

and indeed the fix works, I'm now able to add more than 215 dnat rules, and still fetch the config over the vyos http api! Thanks a lot everyone.

Feb 22 2021, 8:59 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
wsapplegate added a comment to T3337: Add possibility to serve static DNS zones from the router.
In T3337#87766, @c-po wrote:
  • adding a cli node that passes raw config values from cli to the daemon is bad (we inherited this for dhcp and openvpn and it caused more harm then good in the last 2 years) - is this mandatory?
Feb 22 2021, 8:36 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
pasik added a comment to T3347: vyos 1.3 beta fails to configure Xen HVM guest ethernet interfaces due to ethtool -g error.

If I disable Xen PV drivers using "xen_platform_pci=0" from the host/dom0 side, and thus I get emulated e1000 NICs in the Xen HVM guest, then setting address to ethernet interfaces works ok..

Feb 22 2021, 8:10 PM · VyOS 1.3 Equuleus (1.3.0)
pasik updated the task description for T3347: vyos 1.3 beta fails to configure Xen HVM guest ethernet interfaces due to ethtool -g error.
Feb 22 2021, 7:12 PM · VyOS 1.3 Equuleus (1.3.0)
pasik created T3347: vyos 1.3 beta fails to configure Xen HVM guest ethernet interfaces due to ethtool -g error.
Feb 22 2021, 7:11 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX09b1b533d14e: tunnel: T3072: remove duplicate key from mapping dict used in apply().
Feb 22 2021, 5:50 PM
c-po committed rVYOSONEXe81c0134e596: tunnel: T3072: remove duplicate key from mapping dict used in apply().
Feb 22 2021, 5:50 PM
c-po committed rVYOSONEXe960935dcb19: vyos.ifconfig: extend debug option to print input dict.
Feb 22 2021, 5:19 PM
c-po committed rVYOSONEXa3e11ace758f: vyos.ifconfig: extend debug option to print input dict.
Feb 22 2021, 5:17 PM
c-po committed rVYOSONEX121ca131f662: xml: tunnel: make individual parameter nodes reusable.
Feb 22 2021, 4:41 PM
c-po committed rVYOSONEX577ae00d0c73: xml: tunnel: erspan: make individual parameter nodes reusable.
Feb 22 2021, 4:37 PM
dmbaturin committed rVYOSONEXbdc35ac8ad1d: Merge branch 'current' of https://github.com/vyos/vyos-1x into current.
Feb 22 2021, 3:04 PM
dmbaturin committed rVYOSONEX28cd2e3edb3e: T3346: handle the case of empty nodes when migrating NAT to syntax version 5.
Feb 22 2021, 3:04 PM
dmbaturin committed rVYOSONEX51dc9eb8c069: T3248: add the missing mode-force option, just a dummy for issuing deprecation….
Feb 22 2021, 3:04 PM
dmbaturin committed rVYOSONEXefc0ecb17de5: T3346: handle the case of empty nodes when migrating NAT to syntax version 5.
Feb 22 2021, 3:04 PM
dmbaturin created T3346: nat 4-to-5 migration script fails when a 'source' or 'destination' node exists but there are no rules.
Feb 22 2021, 3:02 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a comment to T3211: ability to redistribute ISIS into other routing protocols.

PR https://github.com/vyos/vyos-1x/pull/739

Feb 22 2021, 2:50 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a comment to T2947: Nat translation many-many with prefix does not map 1-1..

It seems it works now

Feb 22 2021, 1:40 PM · VyOS 1.4 Sagitta
Viacheslav triaged T3337: Add possibility to serve static DNS zones from the router as Normal priority.
Feb 22 2021, 11:21 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav edited a custom field on T2898: Support NDP proxy.
Feb 22 2021, 11:19 AM · VyOS 1.4 Sagitta
HON added a comment to T3340: Add dhcp-helper package to replace ISC DHCP Relay.

The ISC DHCP relay in VyOS is completely broken for my (non-GRE) use case, I would really like to see it get tossed out for something that works. This might not be the best place to describe my relay problems, but I might as well (skip this paragraph it you're not interested). My setup basically consists of the (ISC) DHCP server host connected to the VyOS router (running on a Dell R320), directly connected to a Cisco ASR920 router. Both VyOS and the ASR are directly connected to user VLANs (VyOS for firewalled/NATed zones and ASR for high-traffic users) and have DHCP relays set up targeting the DHCP server, such that the relayed messages from the ASR passes through the VyOS router towards the DHCP server and should get routed normally (i.e. ignored by the VyOS relay). The VyOS DHCP relay doesn't like this and starts spamming the DHCP messages up to ten or more times, causing wired clients to have to wait maybe ten seconds before getting an IPv4 address and wireless clients to just time out and abort the connection. I can provide the relay logs (mainly screenshots unless i dig up the disk I used) and VyOS config if anyone wants them, but as they have sensitive addresses, I don't intend to post them publicly. EDIT: I should mention that I didn't notice any problems while testing it with only myself, it was when 200 people started connecting the problems started occurring. And the DHCP server VM was not showing any noticable load.

Feb 22 2021, 11:13 AM · VyOS Rolling
Viacheslav closed T3327: OSPFv3: Cannot add dummy interface as Resolved.
Feb 22 2021, 11:10 AM · VyOS 1.4 Sagitta
Viacheslav closed T3290: Disabling GRE conntrack module fails as Unknown Status.
Feb 22 2021, 11:09 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav edited a custom field on T3055: op-mode incorrect naming for ipsec policy-based tunnels .
Feb 22 2021, 11:07 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T3055: op-mode incorrect naming for ipsec policy-based tunnels from "Task" to "Bug".
Feb 22 2021, 11:06 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav triaged T3055: op-mode incorrect naming for ipsec policy-based tunnels as Normal priority.
Feb 22 2021, 11:06 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav triaged T2641: Rewrite vpn ipsec OP commands in new style XML syntax as Normal priority.
Feb 22 2021, 11:05 AM · VyOS 1.4 Sagitta
Viacheslav triaged T3333: "show vpn ipsec sa" reports ESP tunnels to be up when they are not. as Normal priority.
Feb 22 2021, 11:04 AM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a subtask for T2641: Rewrite vpn ipsec OP commands in new style XML syntax: T3333: "show vpn ipsec sa" reports ESP tunnels to be up when they are not..
Feb 22 2021, 11:04 AM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3333: "show vpn ipsec sa" reports ESP tunnels to be up when they are not.: T2641: Rewrite vpn ipsec OP commands in new style XML syntax.
Feb 22 2021, 11:03 AM · VyOS 1.2 Crux (VyOS 1.2.8)
ernstjo added a comment to T3327: OSPFv3: Cannot add dummy interface.

@Viacheslav Looks like it is already fixed with newer release then VyOS 1.4-rolling-202102141111.
I can also add the interface with newer release.

Feb 22 2021, 11:02 AM · VyOS 1.4 Sagitta
Viacheslav triaged T3327: OSPFv3: Cannot add dummy interface as Normal priority.
Feb 22 2021, 11:00 AM · VyOS 1.4 Sagitta
Viacheslav edited a custom field on T3327: OSPFv3: Cannot add dummy interface.
Feb 22 2021, 10:59 AM · VyOS 1.4 Sagitta
Viacheslav triaged T3323: Bgp ttl-security and ebgp-multihop fail as Normal priority.
Feb 22 2021, 10:58 AM · VyOS 1.4 Sagitta
Viacheslav triaged T3287: Ability to set DNAT translation address incorrectly as Normal priority.
Feb 22 2021, 10:57 AM · vyatta-nat, VyOS 1.4 Sagitta
Viacheslav reopened T3290: Disabling GRE conntrack module fails as "Needs testing".
Feb 22 2021, 10:48 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the status of T3299: Allow the web proxy service to listen on all IP addresses from Open to Needs testing.
Feb 22 2021, 10:46 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav claimed T3306: Extend set route-map aggregator as to 4 Bytes .
Feb 22 2021, 10:44 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav triaged T3306: Extend set route-map aggregator as to 4 Bytes as Normal priority.
Feb 22 2021, 10:44 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav triaged T3315: Supports dhcpv6 agent execution from pppoe0 interface as Normal priority.
Feb 22 2021, 10:37 AM
Viacheslav edited a custom field on T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).
Feb 22 2021, 10:34 AM · VyOS 1.5 Circinus
Viacheslav changed Is it a breaking change? from none to compatible on T3320: Bgp neighbor peer-group without peer-group fail.
Feb 22 2021, 10:33 AM · VyOS 1.4 Sagitta
Viacheslav triaged T3320: Bgp neighbor peer-group without peer-group fail as Normal priority.
Feb 22 2021, 10:32 AM · VyOS 1.4 Sagitta
Viacheslav closed T3322: Bgp neighbor timers not applyed to FRR config, a subtask of T2174: Rewrite protocol BGP to new XML/Python style, as Resolved.
Feb 22 2021, 10:31 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T3322: Bgp neighbor timers not applyed to FRR config as Resolved.
Feb 22 2021, 10:31 AM · VyOS 1.4 Sagitta
Viacheslav edited a custom field on T1292: Issues while deleting all rules from a firewall.
Feb 22 2021, 10:27 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T1292: Issues while deleting all rules from a firewall from "Task" to "Bug".
Feb 22 2021, 10:26 AM · VyOS 1.4 Sagitta
Viacheslav triaged T1292: Issues while deleting all rules from a firewall as Normal priority.
Feb 22 2021, 10:26 AM · VyOS 1.4 Sagitta
Viacheslav triaged T1436: Config entries with default values do not correctly show as changed as Low priority.
Feb 22 2021, 10:22 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav triaged T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP as Wishlist priority.
Feb 22 2021, 10:09 AM
Viacheslav triaged T2038: repository organisation change as Normal priority.
Feb 22 2021, 10:06 AM · Invalid
Viacheslav triaged T2114: Use unique interface name prefix for each tunnel type as Low priority.
Feb 22 2021, 10:05 AM · Restricted Project, VyOS Rolling
Viacheslav added a comment to T3190: Unable to subtract value from local-preference in route-map.

As we use 7.5 in 1.4 now, we can implement that feature.

Feb 22 2021, 9:49 AM · VyOS 1.4 Sagitta
Viacheslav triaged T3190: Unable to subtract value from local-preference in route-map as Normal priority.
Feb 22 2021, 9:48 AM · VyOS 1.4 Sagitta
Viacheslav edited a custom field on T3207: OSPF does not convert the area to NSSA .
Feb 22 2021, 9:44 AM
Viacheslav triaged T3207: OSPF does not convert the area to NSSA as Normal priority.
Feb 22 2021, 9:44 AM
Viacheslav triaged T3211: ability to redistribute ISIS into other routing protocols as Normal priority.
Feb 22 2021, 9:41 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 changed the status of T3116: Support back-end L4 level load balancing from Confirmed to In progress.

Start implementing this draft

Feb 22 2021, 9:40 AM · VyOS 1.4 Sagitta
Viacheslav triaged T3225: Adding a BGP neighbor with an address on a local interface throws a vyos.frr.CommitError: Configuration FRR failed while committing code: '' as Normal priority.
Feb 22 2021, 9:37 AM · VyOS 1.4 Sagitta
Viacheslav triaged T3232: ISIS incorrect hostname and LSP ID as Normal priority.
Feb 22 2021, 9:34 AM · Bugs, VyOS Rolling
Viacheslav triaged T3260: MAP-T/MAP-E for CPE and BR as Wishlist priority.
Feb 22 2021, 9:32 AM
Viacheslav edited a custom field on T3286: Switch the firewall from iptables to nftables.
Feb 22 2021, 9:25 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T3286: Switch the firewall from iptables to nftables from "Task" to "Feature Request".
Feb 22 2021, 9:25 AM · VyOS 1.4 Sagitta
Viacheslav triaged T3286: Switch the firewall from iptables to nftables as Normal priority.
Feb 22 2021, 9:25 AM · VyOS 1.4 Sagitta
Viacheslav edited a custom field on T3271: qemu-kvm grub issue.
Feb 22 2021, 9:23 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
dmbaturin added a member for Maintainers: Viacheslav.
Feb 22 2021, 9:23 AM
Viacheslav triaged T3277: DNS Forwarding - reverse zones as Low priority.
Feb 22 2021, 9:22 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
Viacheslav edited a custom field on T3340: Add dhcp-helper package to replace ISC DHCP Relay.
Feb 22 2021, 9:00 AM · VyOS Rolling
Viacheslav edited a custom field on T687: Encryption of configuration files and critical data.
Feb 22 2021, 8:55 AM
Viacheslav edited a custom field on T751: IDS and IPS (suricata).
Feb 22 2021, 8:52 AM · VyOS 1.5 Circinus

Feb 21 2021

rgrant added a comment to T3344: Per VRF dynamic routing support.

Hmmm I retract that, apparently not in my configs. But that review indicates that a common pattern is to define the VRF at a global level, then specify an instance at the BGP level...

Feb 21 2021, 10:03 PM · VyOS 1.4 Sagitta
rgrant added a comment to T3344: Per VRF dynamic routing support.

@c-po not in constrat to other verndors - I know that Juniper ERX allowed for different ASNs if in a VRF. I'll see if I still have some old configs.

Feb 21 2021, 9:24 PM · VyOS 1.4 Sagitta
c-po reopened T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500 as "Needs testing".
Feb 21 2021, 7:08 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX20e500b8a4f6: ethernet: T3342: Xen vif driver requires sg offloading for MTU > 1500 bytes.
Feb 21 2021, 7:07 PM
c-po placed T3229: Ethtool CLI Integration up for grabs.
Feb 21 2021, 6:54 PM · VyOS 1.5 Circinus
c-po added a comment to T3344: Per VRF dynamic routing support.

Unfortunately I can not connect the dots between "still the same process" and set protocols bgp <asn> vs. set protocols vrf <vrf> bgp <asn> (I explicitly left the "move bgp tagNode to node with local-as" topic out of the discussion as this is something different and is addressed via a different task)

Feb 21 2021, 6:50 PM · VyOS 1.4 Sagitta
runar added a comment to T3344: Per VRF dynamic routing support.

Ahh.. yea, i see that now.. i've never done this, so cant say how it work.. but as i can se this is still the same process, so my answer is still the same.... Actually this migth be a good reason for migrating set protocols bgp <asn> to its own local-as <asn> subnode, so the AS is not hardcoded in the configpath

Feb 21 2021, 6:27 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3344: Per VRF dynamic routing support.
Feb 21 2021, 5:39 PM · VyOS 1.4 Sagitta
c-po added a comment to T3344: Per VRF dynamic routing support.

FRR actually supports configuring a different ASN per VRF in contrast to other vendors

Feb 21 2021, 5:38 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXd14d2f30ef59: ethernet: T3163: probe driver for maximum rx/tx ring-buffer size.
Feb 21 2021, 5:24 PM
c-po closed T3163: ethernet ring-buffer can be set with an invalid value as Resolved.
Feb 21 2021, 5:24 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEXcf1156a60e1d: ethernet: T3163: probe driver for maximum rx/tx ring-buffer size.
Feb 21 2021, 5:23 PM
c-po added a project to T3163: ethernet ring-buffer can be set with an invalid value: VyOS 1.4 Sagitta.
Feb 21 2021, 4:37 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po changed the status of T3163: ethernet ring-buffer can be set with an invalid value from Open to In progress.
Feb 21 2021, 4:37 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX65adcc1d80d0: console-server: T2490: do not use cli-shell-api in systemd unit.
Feb 21 2021, 4:26 PM
c-po committed rVYOSONEXd5804b19d3ff: console-server: T2490: do not use cli-shell-api in systemd unit.
Feb 21 2021, 4:26 PM
Unknown Object (User) closed T2521: Need to restart pdns-recursor to check new entries in /etc/hosts, a subtask of T2464: DNS bugs (parent task), as Resolved.
Feb 21 2021, 2:28 PM · VyOS Rolling
Unknown Object (User) closed T2521: Need to restart pdns-recursor to check new entries in /etc/hosts as Resolved.

On 1.3-beta-202102210443 and 1.4-rolling-202102202002 all work properly and don't require any changes, mark as resolved.

Feb 21 2021, 2:28 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) committed rVYOSONEXa42c2322a8db: dhcp-server: T2521: Change pgrep search name.
Feb 21 2021, 2:10 PM
GitHub <noreply@github.com> committed rVYOSONEX1c286a3e0807: Merge pull request #738 from DmitriyEshenko/crux-2102212101 (authored by dmbaturin).
Feb 21 2021, 2:10 PM
Unknown Object (User) added a comment to T2521: Need to restart pdns-recursor to check new entries in /etc/hosts.

I found a similar issue related to this topic in 1.2.6-S1, script on-dhcp-event.sh can't to determine pdns_recursor PID

vyos@vyos# ps ax | grep pdns
 6626 ?        Ssl    0:00 /usr/sbin/pdns_recursor --daemon=no --write-pid=no --disable-syslog --log-timestamp=no
[edit]
vyos@vyos# pgrep "pdns_recursor"
[edit]
vyos@vyos# pgrep pdns_recursor
[edit]
vyos@vyos#

We need to use pgrep pdns

vyos@vyos# pgrep pdns
6626
[edit]
Feb 21 2021, 11:42 AM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) added a project to T2521: Need to restart pdns-recursor to check new entries in /etc/hosts: VyOS 1.2 Crux (VyOS 1.2.7).
Feb 21 2021, 11:39 AM · VyOS 1.2 Crux (VyOS 1.2.7)
sever-sever <v.gletenko@vyos.io> committed rVYOSONEXb5763e329915: bgp: T3322: Fix timers for neighbor.
Feb 21 2021, 10:19 AM
GitHub <noreply@github.com> committed rVYOSONEX50b2882c663a: Merge pull request #737 from sever-sever/T3332 (authored by c-po).
Feb 21 2021, 10:19 AM