Page MenuHomeVyOS Platform
Feed All Stories

Apr 8 2021

c-po changed the status of T3456: firewall: rules that should be deleted seem to be still in use from Unknown Status to Resolved.
Apr 8 2021, 7:35 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po moved T3456: firewall: rules that should be deleted seem to be still in use from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.8) board.
Apr 8 2021, 7:35 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po added a comment to T3464: OSPF: route-map names containing a hypen are not "found".

https://github.com/vyos/vyos-1x/pull/800

Apr 8 2021, 6:53 PM · VyOS 1.4 Sagitta
c-po closed T3463: Prevent IPv4 Route exchange with IPv6 neighbors as Resolved.
Apr 8 2021, 6:24 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX6f6f45c57eef: bgp: T3463: change no-ipv4-unicast order when applying configuration.
Apr 8 2021, 6:23 PM
c-po changed the status of T3463: Prevent IPv4 Route exchange with IPv6 neighbors from Open to In progress.
Apr 8 2021, 6:11 PM · VyOS 1.4 Sagitta
c-po added a comment to T3463: Prevent IPv4 Route exchange with IPv6 neighbors.

Looks like that is actually working.

Apr 8 2021, 6:11 PM · VyOS 1.4 Sagitta
carl.byington closed T3462: show ipv6 bgp -- missing as Resolved.

Oops, I did not see that. Thanks.

Apr 8 2021, 6:08 PM · VyOS 1.4 Sagitta
carl.byington added a comment to T3463: Prevent IPv4 Route exchange with IPv6 neighbors.

I modified bgp.frr.tmpl, but systemctl restart vyos-configd did not seem to do anything. Rebooting the router produces the correct config:

Apr 8 2021, 6:05 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3464: OSPF: route-map names containing a hypen are not "found".
Apr 8 2021, 3:21 PM · VyOS 1.4 Sagitta
c-po added a comment to T3374: IPv6 GRE Tunnel issues.

@linuxludo thanks for the heads-up - should be fixed in the next bugfix version of 5.10 then which I regularely update VyOS to. See T3318

Apr 8 2021, 1:51 PM · VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.109 / 5.10.27 to Update Linux Kernel to v5.4.110 / 5.10.28.
Apr 8 2021, 1:51 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po added a comment to T3463: Prevent IPv4 Route exchange with IPv6 neighbors.

We probably should move the following statement https://github.com/vyos/vyos-1x/blob/current/data/templates/frr/bgp.frr.tmpl#L362-L364

Apr 8 2021, 12:41 PM · VyOS 1.4 Sagitta
linuxludo added a comment to T3374: IPv6 GRE Tunnel issues.

Just for your information.
The patch was added to kernel 5.4, 5.10 and 5.11.
https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/

Apr 8 2021, 12:04 PM · VyOS 1.4 Sagitta
c-po moved T3464: OSPF: route-map names containing a hypen are not "found" from Open to In Progress on the VyOS 1.4 Sagitta board.
Apr 8 2021, 11:04 AM · VyOS 1.4 Sagitta
c-po changed the status of T3464: OSPF: route-map names containing a hypen are not "found" from Open to In progress.
Apr 8 2021, 11:04 AM · VyOS 1.4 Sagitta
c-po updated the task description for T3464: OSPF: route-map names containing a hypen are not "found".
Apr 8 2021, 11:03 AM · VyOS 1.4 Sagitta
c-po created T3464: OSPF: route-map names containing a hypen are not "found".
Apr 8 2021, 9:41 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3463: Prevent IPv4 Route exchange with IPv6 neighbors.

If you add neighbor/commit and after that commit adding "set protocols bgp parameters default no-ipv4-unicast" it can not be accepted. Because neighbor was added before this command.
Re-create neighbor and commit. And check again.

Apr 8 2021, 9:31 AM · VyOS 1.4 Sagitta
c-po added a comment to T3462: show ipv6 bgp -- missing.

When on VyOS 1.4 please use the show bgp ipv6 command as exposed by FRR. The show ip bgp command is only kept as not all options from show ip bgp are exposed in FRR under the show bgp ipv4 tree.

Apr 8 2021, 8:48 AM · VyOS 1.4 Sagitta
c-po claimed T3462: show ipv6 bgp -- missing.
Apr 8 2021, 8:16 AM · VyOS 1.4 Sagitta

Apr 7 2021

carl.byington created T3463: Prevent IPv4 Route exchange with IPv6 neighbors.
Apr 7 2021, 10:04 PM · VyOS 1.4 Sagitta
carl.byington created T3462: show ipv6 bgp -- missing.
Apr 7 2021, 9:21 PM · VyOS 1.4 Sagitta
Viacheslav triaged T3460: bgp, Configuration FRR failed while commiting code as Normal priority.
Apr 7 2021, 9:02 PM · VyOS 1.4 Sagitta
Unknown Object (User) created T3461: OpenConnect Server redundancy check.
Apr 7 2021, 7:56 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a comment to T3460: bgp, Configuration FRR failed while commiting code.

You can't/don't need to set local-as for neighbor [ if neighbor local as == your global asn ]
Can you send a code error?

Apr 7 2021, 7:33 PM · VyOS 1.4 Sagitta
carl.byington created T3460: bgp, Configuration FRR failed while commiting code.
Apr 7 2021, 7:21 PM · VyOS 1.4 Sagitta
blucafee80 added a comment to T3012: DHCPv6 relay requires address when it shouldn't.

I don't understand how DHCP relays work, esp in a pfsense environment. Not worth looking at this.

Apr 7 2021, 2:10 PM · VyOS 1.2 Crux
blucafee80 closed T3012: DHCPv6 relay requires address when it shouldn't as Invalid.
Apr 7 2021, 2:08 PM · VyOS 1.2 Crux
c-po committed rVYOSONEXce361fe12c43: vrf: T3344: re-add virtual network identifier.
Apr 7 2021, 12:57 PM
c-po committed rVYOSONEXaa35e4650537: vrf: T3344: re-add virtual network identifier.
Apr 7 2021, 12:56 PM
erkin triaged T3459: Inform the user when unable to install outdated image as Wishlist priority.
Apr 7 2021, 12:30 PM · VyOS 1.4 Sagitta

Apr 6 2021

pasik created T3458: vyos docs missing gretap from tunnel section.
Apr 6 2021, 8:00 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project, VyOS 1.4 Sagitta

Apr 5 2021

c-po committed rVYOSONEX44f766a7880e: tunnel: T3030: move erspan type into regular tunnel interface.
Apr 5 2021, 9:25 PM
c-po committed rVYOSONEXecf53662f75b: smoketest: config: tunnel-broker: adjust l2tpv3 local/remote addresses.
Apr 5 2021, 6:16 PM
c-po added a project to T3454: dhclient reject option: VyOS 1.3 Equuleus.
Apr 5 2021, 2:55 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po closed T3454: dhclient reject option as Unknown Status.
Apr 5 2021, 2:54 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T1612: dhcp-server time-offset fails to validate as Resolved.

Fixed. 1.2.7, VyOS 1.3.0-rc3, VyOS 1.4-rolling-202104041918

Apr 5 2021, 2:36 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXb9fc9f1ea598: smoketest: l2tpv3: only remove modules if they are loaded.
Apr 5 2021, 2:33 PM
c-po committed rVYOSONEX0ac696663b68: smoketest: l2tpv3: only remove modules if they are loaded.
Apr 5 2021, 2:30 PM
c-po committed rVYOSONEX8e61868039d8: smoketest: config: evpn-leaf: set 1500 byte mtu on vxlan interface.
Apr 5 2021, 2:30 PM
scj643 committed rVYOSONEXe8535616aae2: interfaces: dhcp-client: T3454: add reject option.
Apr 5 2021, 2:25 PM
GitHub <noreply@github.com> committed rVYOSONEX43894aae1737: Merge pull request #799 from scj643/current (authored by c-po).
Apr 5 2021, 2:25 PM
c-po closed T3418: BGP: system wide known interface can not be used as neighbor as Resolved.
Apr 5 2021, 2:13 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX1e66589d1f67: bgp: T3418: peer-group and remote-as must be present under interface node.
Apr 5 2021, 2:13 PM
c-po committed rVYOSONEX23598fc082fc: vyos.template: T3418: add new is_interface helper function.
Apr 5 2021, 2:13 PM
c-po moved T3456: firewall: rules that should be deleted seem to be still in use from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.8) board.
Apr 5 2021, 1:58 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po moved T3456: firewall: rules that should be deleted seem to be still in use from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 5 2021, 1:58 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po moved T3456: firewall: rules that should be deleted seem to be still in use from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Apr 5 2021, 1:58 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po edited projects for T3456: firewall: rules that should be deleted seem to be still in use, added: VyOS 1.2 Crux (VyOS 1.2.8); removed VyOS 1.2 Crux.
Apr 5 2021, 1:58 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po changed the status of T3418: BGP: system wide known interface can not be used as neighbor from In progress to Needs testing.
Apr 5 2021, 1:29 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added a comment to T3418: BGP: system wide known interface can not be used as neighbor.

I wonder if this used to work in the past?

Apr 5 2021, 1:29 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the status of T1894: FRR config not loaded after daemons segfault or restart, a subtask of T3217: Save FRR configuration on each commit, from Open to Needs testing.
Apr 5 2021, 1:25 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav changed the status of T1894: FRR config not loaded after daemons segfault or restart from Open to Needs testing.
Apr 5 2021, 1:25 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav added a comment to T1894: FRR config not loaded after daemons segfault or restart.

@maznu @Merijn Can you test the latest rolling 1.4 release?
It should be fixed.
You can kill ripd/ripng/ospfd/bgpd/isisd daemons or allow it for watchfrr.

Apr 5 2021, 1:25 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po closed T1080: L2tpv3 config delete on reboot/startup as Wontfix.
Apr 5 2021, 1:23 PM · VyOS 1.2 Crux (VyOS 1.2.7)
c-po added a comment to T1080: L2tpv3 config delete on reboot/startup.

Turns out this is not a VyOS limitation but is a Linux Kernel/iproute2 limitation.

Apr 5 2021, 1:22 PM · VyOS 1.2 Crux (VyOS 1.2.7)
c-po closed T3438: VRF: removing vif which belongs to a vrf, will delete the entire vrf from the operating system as Resolved.
Apr 5 2021, 1:21 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEXe7c643c8c8b8: vrf: vlan: T3438: do not automatically delete upper interface.
Apr 5 2021, 1:21 PM
Viacheslav added a subtask for T3217: Save FRR configuration on each commit: T1894: FRR config not loaded after daemons segfault or restart.
Apr 5 2021, 1:20 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav added a parent task for T1894: FRR config not loaded after daemons segfault or restart: T3217: Save FRR configuration on each commit.
Apr 5 2021, 1:20 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav added a project to T1894: FRR config not loaded after daemons segfault or restart: VyOS 1.4 Sagitta.
Apr 5 2021, 1:19 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po changed the status of T3456: firewall: rules that should be deleted seem to be still in use, a subtask of T2199: Rewrite firewall in new XML/Python style, from Resolved to Unknown Status.
Apr 5 2021, 12:54 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
c-po changed the status of T3456: firewall: rules that should be deleted seem to be still in use from Resolved to Unknown Status.
Apr 5 2021, 12:54 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Restricted Repository Identity closed T3456: firewall: rules that should be deleted seem to be still in use, a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Apr 5 2021, 12:52 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Restricted Repository Identity closed T3456: firewall: rules that should be deleted seem to be still in use as Resolved by committing Restricted Diffusion Commit.
Apr 5 2021, 12:51 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po added a comment to T3456: firewall: rules that should be deleted seem to be still in use.

Fixed via https://github.com/vyos/vyatta-cfg-firewall/pull/21

Apr 5 2021, 12:50 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po committed rVYOSONEX49cfd4e0c56a: smoketest: config: bgp: remove graceful-restart option due to frr-reload bug.
Apr 5 2021, 12:49 PM
c-po added a comment to T3456: firewall: rules that should be deleted seem to be still in use.

This bug also persists in VyOS 1.2.7

Apr 5 2021, 11:19 AM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po added projects to T3456: firewall: rules that should be deleted seem to be still in use: VyOS 1.3 Equuleus, VyOS 1.2 Crux.
Apr 5 2021, 11:17 AM · VyOS 1.2 Crux (VyOS 1.2.8)

Apr 4 2021

c-po committed rVYOSONEXa394e6939c0e: smoketest: l2tpv3: unload kernel modules after test.
Apr 4 2021, 7:18 PM
c-po committed rVYOSONEX89db4e6cb936: bgp: T1711: fix completion helpers after as number cli change.
Apr 4 2021, 6:55 PM
Viacheslav added a comment to T3456: firewall: rules that should be deleted seem to be still in use.

The same with "policy" /usr/libexec/vyos/tests/config/dialup-router-medium-vpn

Apr 4 2021, 5:13 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a subtask for T2199: Rewrite firewall in new XML/Python style: T2503: IPv6 Firewall configuration error: Cannot delete rule set "GUEST-WAN-6" (still in use).
Apr 4 2021, 3:39 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav added a parent task for T2503: IPv6 Firewall configuration error: Cannot delete rule set "GUEST-WAN-6" (still in use): T2199: Rewrite firewall in new XML/Python style.
Apr 4 2021, 3:38 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a project to T1097: Make firewall groups work everywhere that's appropropriate: VyOS 1.4 Sagitta.
Apr 4 2021, 3:37 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2199: Rewrite firewall in new XML/Python style: T1097: Make firewall groups work everywhere that's appropropriate.
Apr 4 2021, 3:36 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav added a parent task for T1097: Make firewall groups work everywhere that's appropropriate: T2199: Rewrite firewall in new XML/Python style.
Apr 4 2021, 3:36 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2199: Rewrite firewall in new XML/Python style: T3286: Switch the firewall from iptables to nftables.
Apr 4 2021, 3:35 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav added a parent task for T3286: Switch the firewall from iptables to nftables: T2199: Rewrite firewall in new XML/Python style.
Apr 4 2021, 3:35 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2199: Rewrite firewall in new XML/Python style: T1292: Issues while deleting all rules from a firewall.
Apr 4 2021, 3:32 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav added a parent task for T1292: Issues while deleting all rules from a firewall: T2199: Rewrite firewall in new XML/Python style.
Apr 4 2021, 3:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3456: firewall: rules that should be deleted seem to be still in use.

To reproduce it add firewall and attach it to interface

Apr 4 2021, 3:19 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po added a comment to T3456: firewall: rules that should be deleted seem to be still in use.

Usually on delete, the firewall should be detached from the interface first as the logic should go from the highest priority to the lowest one.

Apr 4 2021, 3:11 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a comment to T3456: firewall: rules that should be deleted seem to be still in use.

It is a priority for configurations
When the system load, the firewall should have configuration, and after configuration is applied to the interface.
So I think we can't delete it in one commit, it tried to delete the firewall before detaching the firewall from the interface.

Apr 4 2021, 2:30 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a comment to T3217: Save FRR configuration on each commit.
Apr 4 2021, 2:30 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
bbs2web added a comment to T915: MPLS Support.

So I finally stopped being lazy and got VyOS in to GNS3. As with our production routers MPLS remains off after restarting with either 1.3-rolling-202104021041 or 1.4-rolling-202104022042 for VLAN sub interfaces. Ethernet parent interfaces have their mpls state managed correctly.

Apr 4 2021, 1:51 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
craterman added a comment to T3207: OSPF does not convert the area to NSSA .

It seems fixed for rolling release 1.4 because soft has been moved to FRR7.5.1
Of course it is not fixed for rolling release 1.3 (and as I understand won't be) due to FRR7.3.1

Apr 4 2021, 9:55 AM
c-po committed rVYOSONEX6330708f7ad5: T3457: output the "monitor log" command in a colorful way.
Apr 4 2021, 8:03 AM
c-po committed rVYOSONEX35e596811820: T3457: output the "monitor log" command in a colorful way.
Apr 4 2021, 8:03 AM
c-po closed T3457: Output the "monitor log" command in a colorful way as Resolved.
Apr 4 2021, 8:01 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po created T3457: Output the "monitor log" command in a colorful way.
Apr 4 2021, 7:58 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Apr 3 2021

klipz added a comment to T1311: WAN load-balancing can't flush connections when conntrack-sync is enabled.

@syncer
Sorry to dredge up an old bug, but I believe I've hit this today on 1.2.7-LTS myself. Per @zsdc's original description, It seems that when you configure:

Apr 3 2021, 7:58 PM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, test
c-po added a subtask for T2199: Rewrite firewall in new XML/Python style: T3456: firewall: rules that should be deleted seem to be still in use.
Apr 3 2021, 5:45 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
c-po added a parent task for T3456: firewall: rules that should be deleted seem to be still in use: T2199: Rewrite firewall in new XML/Python style.
Apr 3 2021, 5:45 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po updated the task description for T3456: firewall: rules that should be deleted seem to be still in use.
Apr 3 2021, 5:45 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po created T3456: firewall: rules that should be deleted seem to be still in use.
Apr 3 2021, 5:43 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po committed rVYOSONEX9018ba6522ee: Jenkins: select build library from proper branch "equuleus".
Apr 3 2021, 2:17 PM
c-po added projects to T2108: Use minisign/signify instead of GPG for release signing: VyOS 1.4 Sagitta, VyOS 1.2 Crux (VyOS 1.2.8).
Apr 3 2021, 1:57 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
c-po added a comment to T2108: Use minisign/signify instead of GPG for release signing.

Added minisign package https://github.com/vyos/vyos-build/tree/current/packages/minisign and also included this in vyos-1x dependency list for crux, equuleus and current

Apr 3 2021, 1:56 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta