Page MenuHomeVyOS Platform
Feed All Stories

Jul 19 2021

syncer moved T3149: ospfv3 bfd configuration bug / typo. config applied to wrong interface name. from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.8) board.
Jul 19 2021, 8:52 PM · VyOS 1.2 Crux (VyOS 1.2.8), Restricted Project
syncer moved T3521: Operator user level permission for "show version" from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.8) board.
Jul 19 2021, 8:52 PM · VyOS 1.2 Crux (VyOS 1.2.8)
syncer moved T3333: "show vpn ipsec sa" reports ESP tunnels to be up when they are not. from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.8) board.
Jul 19 2021, 8:52 PM · VyOS 1.2 Crux (VyOS 1.2.8)
syncer moved T3582: 'delete log file' does not work from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.8) board.
Jul 19 2021, 8:52 PM · VyOS 1.2 Crux (VyOS 1.2.8)
syncer moved T3653: Cloudinit subnet error if a cidr (/24) is used instead of a subnet mask (255.255.255.0) from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.8) board.
Jul 19 2021, 8:52 PM · VyOS 1.2 Crux (VyOS 1.2.8)
syncer moved T2806: ipsec generates false warning on commit when local prefix is sourced from loopback from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.8) board.
Jul 19 2021, 8:52 PM · VyOS 1.2 Crux (VyOS 1.2.8)
syncer edited projects for T2296: Upgrade WALinux to 2.2.41, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.3 Equuleus (1.3.4)
syncer edited projects for T2108: Use minisign/signify instead of GPG for release signing, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
syncer edited projects for T2800: Pseudo-Ethernet: source-interface must not be member of a bridge, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer edited projects for T3253: rpki: multiple peers cannot be configured , added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.3 Equuleus (1.3.0)
syncer edited projects for T3381: Change GRE tunnel failed, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
syncer edited projects for T3467: cannot set vrrp virtual-address with /31 mask when router uses networkaddress., added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.2 Crux (VyOS 1.2.9)
syncer edited projects for T3396: syslog can't be configured with an ipv6 literal destination in 1.2.x, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
syncer edited projects for T3479: route-maps containing "aggregator as" can not be deleted, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.4 Sagitta
syncer edited projects for T3394: Error on removing dhcpv6 address from interface, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.2 Crux (VyOS 1.2.9)
syncer edited projects for T1199: SNMP BGP4-MIB: bgp4PathAttrCalcLocalPref and bgp4PathAttrLocalPref filled incorrectly, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.6)
syncer edited projects for T1200: SNMP GET broken at least for BGP4-MIB, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.6)
syncer edited projects for T1790: OSPF Exchanged Routes marked as invalid when run through a GRE PTMP/PTP OSPF between peers , added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM
syncer edited projects for T3017: bridge will lose the tuntap member after reboots, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · Invalid
syncer edited projects for T3045: Changes to Conntrack-Sync don't apply correctly (Mutlicast->UDP), added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.2 Crux (VyOS 1.2.9)
syncer edited projects for T3076: Router reboot adds unwanted 'conntrack-sync mcast-group '225.0.0.50'' line to configuration, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer edited projects for T3397: getty forces --keep-baud in 1.2.x, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS Rolling, VyOS 1.4 Sagitta (1.4.1), VyOS 1.3 Equuleus (1.3.9)
syncer edited projects for T3689: static ipv6 route doesn't deleted in some cases, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.3 Equuleus (1.3.0), Ready for Crux (1.2.x), VyOS 1.2 Crux (VyOS 1.2.9)
syncer edited projects for T3671: Webproxy not functional in 1.2.8 update, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.2 Crux (VyOS 1.2.9)
syncer edited projects for T3674: Webproxy squid is stared by default without any configuration, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:51 PM · VyOS 1.2 Crux (VyOS 1.2.9)
syncer edited projects for T3254: Dynamic DNS status shows incorrect last update time, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.8).
Jul 19 2021, 8:50 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta, ddclient
syncer set the image for VyOS 1.2 Crux (VyOS 1.2.9) to F1681237: profile.
Jul 19 2021, 8:50 PM
syncer archived VyOS 1.2 Crux (VyOS 1.2.7).
Jul 19 2021, 8:50 PM
syncer moved T3152: wan-load-balance does not show connections from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:50 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T3238: Update Linux Kernel to v4.19.178 from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:50 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T3085: IPv6 BGP Neighbor Weight from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:50 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T3265: RPKI: Cache-peer SSH connection misses public key portion from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T627: IPSec configuration directive deletion fails, causes bad IPSec state on reboot. from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T2647: ipsec disableuniqreqids generate a wrong ipsec.conf from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T2954: Use kernel mode L2TP in xl2tpd from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T3301: Wrong format and valueHelp for policy as-path-list regex from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.4 Sagitta
syncer moved T3304: No way to use ipv4 address as next-hop in route-map from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.4 Sagitta, VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T2061: protocol logs not sent to remote syslog from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T2521: Need to restart pdns-recursor to check new entries in /etc/hosts from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T1080: L2tpv3 config delete on reboot/startup from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T3623: Fix for dummy interface option in the operational command "clear interfaces dummy" from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.4 Sagitta, VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T3395: WAN load-balancing fails with nexthop dhcp from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.4 Sagitta
syncer moved T3343: Wrong output conntrack-sync status from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer edited projects for T2801: conntrack-tools flooding logs, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.7).
Jul 19 2021, 8:49 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
syncer edited projects for T2664: vyos-hostsd overriding dns forward configuration, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.7).
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.9)
syncer edited projects for T3270: Backport VyOS-specific modules for Cloud-init from equuleus, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.7).
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.9)
syncer edited projects for T3469: Upgrading from 1.2.6-S1 to 1.2.7 changes order of NICs on second reboot, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.7).
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.9)
syncer edited projects for T3626: Configuring and disabling DHCP Server, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.7).
Jul 19 2021, 8:49 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
syncer edited projects for T3654: 1.2.7 - OpenVPN tunnel interface disappears on virtualized VyOS router/ESXi host, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux (VyOS 1.2.7).
Jul 19 2021, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.9)
syncer moved T3349: Ethernet: "disable" flag is not honored after a reboot for VIF interfaces from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Jul 19 2021, 8:48 PM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.4 Sagitta
syncer created VyOS 1.2 Crux (VyOS 1.2.9).
Jul 19 2021, 8:47 PM
c-po committed rVYOSONEX2975c5e835fd: vrf: T3655: fix potential error when removing VRF connection tracking table.
Jul 19 2021, 6:54 PM
c-po added a project to T3576: ISIS does not support IPV6: VyOS 1.3 Equuleus.
Jul 19 2021, 5:59 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po merged T3687: IS-IS is missing IPv6 support into T3576: ISIS does not support IPV6.
Jul 19 2021, 5:59 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po merged task T3687: IS-IS is missing IPv6 support into T3576: ISIS does not support IPV6.
Jul 19 2021, 5:59 PM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEXba4e07155e49: isis: T3576: add IPv6 support.
Jul 19 2021, 5:59 PM
c-po added a comment to T3687: IS-IS is missing IPv6 support.

This is already available in VyOS 1.4

Jul 19 2021, 5:57 PM · VyOS 1.3 Equuleus (1.3.0)
Cheeze_It added a comment to T3687: IS-IS is missing IPv6 support.

@Scoopta, thank you. That's good. I *think* know how the logic should go. Shouldn't be difficult but I'll consult with @Viacheslav and @c-po on how we should tackle it. It shouldn't be hard, but I want to make sure I properly do it :)

Jul 19 2021, 5:40 PM · VyOS 1.3 Equuleus (1.3.0)
Cheeze_It updated subscribers of T3687: IS-IS is missing IPv6 support.

@Viacheslav, @c-po, the ISIS FRR Jinja2 template is significantly different between 1.3 and 1.4. Should I try to make the change on 1.3 and then merge? Or should I make it on 1.4 and we'll find a way to merge it back into 1.3?

Jul 19 2021, 5:39 PM · VyOS 1.3 Equuleus (1.3.0)
sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEX75fbbc836d8a: pki: wireguard: T3642: Migrate Wireguard private key directly into CLI.
Jul 19 2021, 5:26 PM
sarthurdev <965089+sarthurdev@users.noreply.github.com> committed rVYOSONEXc96c3ea2ed67: pki: wireguard: T3642: Replace/remove old Wireguard op-mode commands.
Jul 19 2021, 5:26 PM
GitHub <noreply@github.com> committed rVYOSONEXa2e708384f1e: Merge pull request #929 from sarthurdev/pki_wg (authored by c-po).
Jul 19 2021, 5:26 PM
c-po committed rVYOSONEX02043297db68: ipsec: T1210: add "unique" option to specify how to handle multiple connections.
Jul 19 2021, 5:23 PM
c-po committed rVYOSONEX9556d78b1d54: ipsec: T1210: split out pool from remote-access configuration.
Jul 19 2021, 5:23 PM
Scoopta added a comment to T3687: IS-IS is missing IPv6 support.

@Cheeze_It Yes, I actually patched my version of vyos already. Just have to add

ipv6 router isis {{ process }}

to the frr isis template file

Jul 19 2021, 5:17 PM · VyOS 1.3 Equuleus (1.3.0)
sarthurdev updated the task description for T3642: PKI configuration.
Jul 19 2021, 5:17 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
sarthurdev added a comment to T3642: PKI configuration.

PKI Wireguard PR: https://github.com/vyos/vyos-1x/pull/929

Jul 19 2021, 5:17 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Cheeze_It added a comment to T3687: IS-IS is missing IPv6 support.

@Viacheslav, @Scoopta, I take it for default originate on IPv6 there's a requirement to have "ipv6 router isis" added on the interface? I'm thinking yes. If it's a yes (which I'm thinking it is) then I believe this should be fairly easy to add. I'll give it a check guys.

Jul 19 2021, 5:03 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3687: IS-IS is missing IPv6 support.

@Scoopta Provide please example of configuration with every task.
If it a possible example of frr, for what you get and what you expected.

Jul 19 2021, 4:51 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav updated subscribers of T3687: IS-IS is missing IPv6 support.
Jul 19 2021, 4:45 PM · VyOS 1.3 Equuleus (1.3.0)
fernando updated subscribers of T3655: NAT doesn't work correctly with VRF.

thanks for your comment , we are testing first with @rherold , I understand that your case is similar but it's not the same (you have an explicit route-leaking between default vrf and vrf X ). So we also need to test it and try to sure the version solved it .

Jul 19 2021, 3:30 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T3689: static ipv6 route doesn't deleted in some cases.

PR for 1.3 https://github.com/vyos/vyatta-cfg-quagga/pull/84

Jul 19 2021, 2:48 PM · VyOS 1.3 Equuleus (1.3.0), Ready for Crux (1.2.x), VyOS 1.2 Crux (VyOS 1.2.9)
tjjh89017 updated subscribers of T3655: NAT doesn't work correctly with VRF.

@zsdc
please take a look on this
it might be some similar issue in this patch?
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next.git/commit/?id=0fb4d21956f4a9af225594a46857ccf29bd747bc

Jul 19 2021, 2:29 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T3676: Container option to add Linux capabilities.

Can you send more examples how it looks like in podman cli?
Which parameters do you set, and how to check if it is successfully applied?

Jul 19 2021, 9:35 AM · VyOS 1.4 Sagitta

Jul 18 2021

c-po committed rVYOSONEX48c768abbf53: ipsec: T1210: remote-access pools can not hold both IPv4 and IPv6 prefixes.
Jul 18 2021, 7:36 PM
c-po committed rVYOSONEX0a9ff39b4880: ipsec: T2816: limit remote-access nameservers to two IPv4 and two for IPv6.
Jul 18 2021, 6:37 PM
c-po committed rVYOSONEXe202bff78246: ipsec: l2tp: T2816: use common if 'key' in dict pattern.
Jul 18 2021, 6:37 PM
c-po added a reverting change for rVYOSONEX70f7f06e778e: T3641: fastnetmon package is not available for Debian Bullseye: rVYOSONEXcb58eaaeff50: Revert "T3641: fastnetmon package is not available for Debian Bullseye".
Jul 18 2021, 6:37 PM
c-po committed rVYOSONEXcb58eaaeff50: Revert "T3641: fastnetmon package is not available for Debian Bullseye".
Jul 18 2021, 6:37 PM
c-po committed rVYOSONEX62725916c44e: smoketest: ospf: extend passive-interface debugging with kernel log.
Jul 18 2021, 4:12 PM
c-po merged T3684: Bridge doesn't show stp states / macs into T3667: brctl is damaged.
Jul 18 2021, 2:02 PM · VyOS 1.4 Sagitta
c-po merged task T3684: Bridge doesn't show stp states / macs into T3667: brctl is damaged.
Jul 18 2021, 2:02 PM · VyOS 1.4 Sagitta
c-po added a comment to T3684: Bridge doesn't show stp states / macs .

Can you please try running this test on a more recent VyOS version?

Jul 18 2021, 2:01 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX13dfa7e0756b: bridge: remove obsolete helper script.
Jul 18 2021, 1:59 PM

Jul 17 2021

yun added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

I have made a second attempt of the PR: https://github.com/vyos/vyos-1x/pull/928
The original tls configuration checks are back, but it's only checked if no alternative authentication methods are configured.

Jul 17 2021, 11:05 PM · Invalid
c-po changed the status of T3684: Bridge doesn't show stp states / macs from Open to Confirmed.
Jul 17 2021, 10:05 PM · VyOS 1.4 Sagitta
c-po added a comment to T3684: Bridge doesn't show stp states / macs .

brctl is a deprecated package and superseeded by iproute2. Commands will be adjusted, thanks for reporting.

Jul 17 2021, 10:05 PM · VyOS 1.4 Sagitta
c-po claimed T3684: Bridge doesn't show stp states / macs .
Jul 17 2021, 10:04 PM · VyOS 1.4 Sagitta
yun added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

As I suspected, it check if the ConfigSession properly errors if "tls cert-file" and "tls key-file" are NOT defined (for server):

Jul 17 2021, 9:19 PM · Invalid
c-po committed rVYOSONEXc8639be885e1: ipsec: T2816: add missing +x permission on Python helper.
Jul 17 2021, 8:34 PM
zsdc committed rVYOSONEX22791e26f444: VRF: T3655: proper connection tracking for VRFs.
Jul 17 2021, 8:33 PM
GitHub <noreply@github.com> committed rVYOSONEX76466a4b974a: Merge pull request #927 from zdc/T3655-sagitta (authored by c-po).
Jul 17 2021, 8:33 PM
tjjh89017 added a comment to T3655: NAT doesn't work correctly with VRF.

something like this in 1.4 nft
https://www.spinics.net/lists/netfilter/msg58240.html

Jul 17 2021, 7:44 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
tjjh89017 added a comment to T3655: NAT doesn't work correctly with VRF.

It seems 1.4-rolling has this bug also
i setup vrf wg with all wireguard clients (with private ip)
and setup vrf leak to vrf default
NAT didn't work on it.
it will send un-NAT packet to eth0

Jul 17 2021, 7:22 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

You can find the test here: https://github.com/vyos/vyos-1x/blob/current/smoketest/scripts/cli/test_interfaces_openvpn.py

Jul 17 2021, 6:50 PM · Invalid
c-po committed rVYOSONEX94531412e730: ipsec: T2816: restore erroneous deleted file.
Jul 17 2021, 6:14 PM
yun added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

Hmm. Can you point me to the smoketest that failed? I will investigate. Maybe it actually tests if the strict check are in place, because now cert-file and key-file are optional, but it should keep working if you configure it.

Jul 17 2021, 5:56 PM · Invalid
c-po added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

Unfortunately I had to revert this PR as it broke the smoketests and also triggered the following OpenVPN error:

Jul 17 2021, 5:20 PM · Invalid
c-po committed rVYOSONEX363d8fb22c98: Revert "openvpn: T56: remove strict checks for tls cert-file and key-file".
Jul 17 2021, 5:19 PM
c-po added a reverting change for rVYOSONEXc414479fdf1d: openvpn: T56: remove strict checks for tls cert-file and key-file: rVYOSONEX363d8fb22c98: Revert "openvpn: T56: remove strict checks for tls cert-file and key-file".
Jul 17 2021, 5:19 PM