Page MenuHomeVyOS Platform
Feed All Stories

Sep 19 2021

c-po moved T3641: Upgrade base system from Debian Buster -> Debian Bullseye from In Progress to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.4 Sagitta
c-po moved T1210: About IKEv2 IPSec VPN remote access from In Progress to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.4 Sagitta
c-po moved T3814: wireguard: commit error showing incorrect peer name from the configured name from In Progress to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3745: op-mode IPSec show vpn ipse sa sorting from In Progress to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
c-po moved T3773: Delete the "show system integrity" command (to prepare for a re-implementation) from Backlog to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3757: OSPF: add support to configure the area at an interface level from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.4 Sagitta
c-po moved T3772: VRRP virtual interfaces are not shown in show interfaces from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3776: Rename FRR daemon restart op-mode commands from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3775: Typo in generated Strongswan VPN-config from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.4 Sagitta
c-po moved T3787: Remove deprecated UDP fragmentation offloading option from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta, test
c-po moved T3090: Move 'adjust-mss' firewall options to the interface section. from Backlog to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.4 Sagitta
c-po moved T3739: policy: route-map: add EVPN match support from In Progress to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.4 Sagitta
c-po moved T3782: Ingress Shaping with IFB No Longer Functional with 1.3 from In Progress to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:05 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3764: Unconfigurable IKE and ESP lifetime from In Progress to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3765: container: additional op-mode commands from Backlog to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3752: generate pki certificate file xxx doesn't touch file from In Progress to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3759: [L3VPN] VPNv4/VPNv6 add commands from In Progress to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3798: bgp: add support for "neighbor <X> local-as replace-as" option from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3789: Add custom validator for base64 encoded CLI data from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3794: MACsec interfaces in down state after create from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3797: show interface errors with vrrp configuration from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3804: cli: Migrate and merge "system name-servers-dhcp" into "system name-server" from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3809: Not possible to add existing ca? from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3812: Vyos and frr route-map config out of sync from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3275: Disable conntrack helpers by default from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.5 Circinus
c-po moved T915: MPLS Support from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3815: pki : the file command 'generate pki wireguard key-pair file' is not working from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3802: Commit fails if ethernet interface doesn't support flow control from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3839: dhcp-server: Allow configuration of a DNS server and domain name on the shared-network level from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T2947: Nat translation many-many with prefix does not map 1-1. from Backport Candidates to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0 from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3838: dhcp-server - sync cli for name-servers to other subsystems from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:04 AM · VyOS 1.4 Sagitta
c-po moved T3840: dns forwarding: Cache size should allow values > 10k from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 19 2021, 7:03 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3840: dns forwarding: Cache size should allow values > 10k from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 19 2021, 7:03 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3837: OpenConnect: Fix typo in help property from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 19 2021, 7:03 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3840: dns forwarding: Cache size should allow values > 10k from Need Triage to 1.3.0-epa1 on the VyOS 1.3 Equuleus board.
Sep 19 2021, 7:03 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3837: OpenConnect: Fix typo in help property from Need Triage to 1.3.0-epa1 on the VyOS 1.3 Equuleus board.
Sep 19 2021, 7:03 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po closed T3840: dns forwarding: Cache size should allow values > 10k as Resolved.
Sep 19 2021, 7:03 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec committed rVYOSONEX60f34805d729: T3840: Allow larger DNS forwarding cache sizes.
Sep 19 2021, 7:01 AM
GitHub <noreply@github.com> committed rVYOSONEX8043764dd236: Merge pull request #1010 from lucasec/dns-fw-cache-size (authored by c-po).
Sep 19 2021, 7:01 AM
lucasec added a comment to T3840: dns forwarding: Cache size should allow values > 10k.

Pull request: https://github.com/vyos/vyos-1x/pull/1010

Sep 19 2021, 4:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec edited a custom field on T3840: dns forwarding: Cache size should allow values > 10k.
Sep 19 2021, 4:29 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec claimed T3840: dns forwarding: Cache size should allow values > 10k.
Sep 19 2021, 4:21 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec created T3840: dns forwarding: Cache size should allow values > 10k.
Sep 19 2021, 4:21 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Sep 18 2021

masimo added a comment to T1968: Allow multiple static routes in dhcp-server.

I'm clearly missing something. I cannot make the configuration as shown by @c-po. If I try to add a 2nd static route, it replaces the first.

Sep 18 2021, 9:02 PM · VyOS 1.4 Sagitta
phoenix committed rVYOSONEX6d3bee0e3c00: OpenConnect: Fix typo in help property.
Sep 18 2021, 8:25 PM
GitHub <noreply@github.com> committed rVYOSONEX3779b32b58eb: Merge pull request #1009 from phoenix0984/equuleus (authored by c-po).
Sep 18 2021, 8:25 PM
c-po committed rVYOSONEXae2dc55aa686: container: T2216: add IPv6 support to container networks.
Sep 18 2021, 8:12 PM
c-po closed T1968: Allow multiple static routes in dhcp-server as Resolved.
Sep 18 2021, 8:11 PM · VyOS 1.4 Sagitta
c-po closed T3838: dhcp-server - sync cli for name-servers to other subsystems as Resolved.
Sep 18 2021, 8:10 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXd411a40a3598: dhcp-server: T3839: support name-servers and domain config per shared-network.
Sep 18 2021, 8:10 PM
c-po committed rVYOSONEX90dffcb3c14e: dhcpv6-server: xml: add description CLI node.
Sep 18 2021, 8:10 PM
c-po committed rVYOSONEX564f05614b6e: dhcp-server: xml: use description building block.
Sep 18 2021, 8:10 PM
c-po committed rVYOSONEXe2f9f4f4e8b2: dhcp-server: T3838: rename dns-server to name-server node.
Sep 18 2021, 8:10 PM
c-po committed rVYOSONEXa4440bd589db: dhcp-server: T1968: allow multiple static-routes to be configured.
Sep 18 2021, 8:10 PM
c-po closed T3839: dhcp-server: Allow configuration of a DNS server and domain name on the shared-network level as Resolved.
Sep 18 2021, 8:08 PM · VyOS 1.4 Sagitta
c-po created T3839: dhcp-server: Allow configuration of a DNS server and domain name on the shared-network level.
Sep 18 2021, 8:08 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3838: dhcp-server - sync cli for name-servers to other subsystems.
Sep 18 2021, 7:42 PM · VyOS 1.4 Sagitta
c-po changed the status of T3838: dhcp-server - sync cli for name-servers to other subsystems from Open to Confirmed.
Sep 18 2021, 7:30 PM · VyOS 1.4 Sagitta
c-po created T3838: dhcp-server - sync cli for name-servers to other subsystems.
Sep 18 2021, 7:30 PM · VyOS 1.4 Sagitta
c-po added a comment to T1968: Allow multiple static routes in dhcp-server.

The following CLI

cpo@LR1.wue3# show service dhcp-server
 shared-network-name LAN {
     subnet 10.0.0.0/24 {
         default-router 10.0.0.1
         dns-server 194.145.150.1
         lease 88
         range 0 {
             start 10.0.0.100
             stop 10.0.0.200
         }
         static-route 194.145.150.0/24 {
             next-hop 1.1.1.1
         }
         static-route 194.145.151.0/24 {
             router 1.1.1.1
         }
     }
 }
Sep 18 2021, 7:09 PM · VyOS 1.4 Sagitta
c-po changed the status of T1968: Allow multiple static routes in dhcp-server from Open to In progress.
Sep 18 2021, 7:08 PM · VyOS 1.4 Sagitta
phoenix triaged T3837: OpenConnect: Fix typo in help property as Low priority.
Sep 18 2021, 4:38 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po closed T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0 as Resolved.
Sep 18 2021, 1:22 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX0ef9c351598d: smoketest: ipsec: only delete nhrp path where it is used.
Sep 18 2021, 1:20 PM
c-po committed rVYOSONEX6f3130ea5c8c: ipsec: vti: T3831: avoid usinf xfrm if_id 0 - implement shift by one.
Sep 18 2021, 1:20 PM
masimo added a comment to T1968: Allow multiple static routes in dhcp-server.

I'm also hitting this issue in 1.4-rolling-202109160217
This task has been kicking around for a while now. What needs to be done to get the code from @ruliane or @elbandi into the rolling build?

Sep 18 2021, 11:19 AM · VyOS 1.4 Sagitta
c-po added a comment to T2738: Modifying configuration in the "interfaces" section from VRRP transition scripts causes configuration lockup and high CPU utilization.

Enabling debugging gives me:

Sep 18 2021, 9:35 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa1)
c-po committed rVYOSONEXdda9f655f949: validator: T2417: bugfix on Python3 f'ormat strings.
Sep 18 2021, 9:27 AM
c-po committed rVYOSONEX24f17e0e41bb: validator: T2417: bugfix on Python3 f'ormat strings.
Sep 18 2021, 9:27 AM
edofullin added a comment to T3657: BGP neighbors ipv6 not able to establish with IPv6 link-local addresses.

Are there updates on this issue?

Sep 18 2021, 8:27 AM · VyOS 1.4 Sagitta
c-po added a comment to T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.

Related/Duplicate issue of T3680

Sep 18 2021, 6:46 AM · VyOS 1.4 Sagitta
kroy updated the task description for T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:30 AM · VyOS 1.4 Sagitta
kroy added a comment to T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.

It's worth adding the no-default-route to the dhcp-options and adding a line like

Sep 18 2021, 5:29 AM · VyOS 1.4 Sagitta
kroy renamed T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway from Setting a default IPv6 route while getting IPv4 route via DHCP removes the IPv4 gateway to Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:27 AM · VyOS 1.4 Sagitta
kroy renamed T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway from Setting a default IPv6 route while getting IPv4 route via DHCP removes the IPv4 route to Setting a default IPv6 route while getting IPv4 route via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:27 AM · VyOS 1.4 Sagitta
kroy updated the task description for T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:24 AM · VyOS 1.4 Sagitta
kroy updated the task description for T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:24 AM · VyOS 1.4 Sagitta
kroy updated the task description for T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:23 AM · VyOS 1.4 Sagitta
kroy changed Version from 1.4-rolling- to 1.4-rolling-202109160207 on T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:22 AM · VyOS 1.4 Sagitta
kroy created T3836: Setting a default IPv6 route while getting IPv4 gateway via DHCP removes the IPv4 gateway.
Sep 18 2021, 5:20 AM · VyOS 1.4 Sagitta

Sep 17 2021

c-po closed T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified as Resolved.
Sep 17 2021, 6:56 PM · VyOS 1.4 Sagitta
c-po added a comment to T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified.

Thank you for testing!

Sep 17 2021, 6:56 PM · VyOS 1.4 Sagitta
erkin committed rVYOSONEXc1e0a1148c86: T3823: Stop strip-private regexp from swallowing quotes.
Sep 17 2021, 6:42 PM
GitHub <noreply@github.com> committed rVYOSONEX4f8ebdd1d644: Merge pull request #1007 from erkin/current (authored by c-po).
Sep 17 2021, 6:42 PM
zoenan7 created T3835: vyos router 1.2.7 snmp Dos bug.
Sep 17 2021, 12:41 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
UnicronNL changed the status of T3834: [OPENVPN] Support for Two Factor Authentication totp. from Open to In progress.
Sep 17 2021, 11:05 AM · VyOS 1.4 Sagitta (1.4.0-GA)
erkin added a comment to T3823: strip-private does not filter public IPv6 addresses.

Something about commands is meddling with strip-private. I'm looking into it.

Sep 17 2021, 8:10 AM · VyOS 1.4 Sagitta
erkin added a comment to T3823: strip-private does not filter public IPv6 addresses.

Now this is quite strange....

$ echo '2001:1578:2fe:fffd::/64' | strip-private
xxxx:xxxx:2fe:fffd::/64
Sep 17 2021, 8:07 AM · VyOS 1.4 Sagitta
erkin changed the status of T3823: strip-private does not filter public IPv6 addresses from Open to In progress.
Sep 17 2021, 8:04 AM · VyOS 1.4 Sagitta
lucasec added a comment to T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified.

Tested on latest build VyOS 1.4-rolling-202109160217 and confirmed it is adding the remote id attribute by default as expected. Connections establish without issue.

Sep 17 2021, 4:02 AM · VyOS 1.4 Sagitta
c-po claimed T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0.
Sep 17 2021, 3:35 AM · VyOS 1.4 Sagitta

Sep 16 2021

sempervictus added a comment to T3833: Cloud-init not finding data source in OpenStack.

Curl checks come back with:

root@vyos:/tmp# curl 169.254.169.254/latest/meta-data
ami-id
ami-launch-index
ami-manifest-path
block-device-mapping/
hostname
instance-action
instance-id
instance-type
local-hostname
local-ipv4
placement/
public-hostname
public-ipv4
public-keys/
reservation-id
security-groups
Sep 16 2021, 4:01 PM · VyOS 1.4 Sagitta
sempervictus renamed T3833: Cloud-init not finding data source in OpenStack from Cloud-init not inding data source in OpenStack to Cloud-init not finding data source in OpenStack.
Sep 16 2021, 3:59 PM · VyOS 1.4 Sagitta
sempervictus created T3833: Cloud-init not finding data source in OpenStack.
Sep 16 2021, 3:53 PM · VyOS 1.4 Sagitta
santhoshtk updated santhoshtk.
Sep 16 2021, 2:37 PM
santhoshtk updated santhoshtk.
Sep 16 2021, 2:36 PM
Viacheslav changed the status of T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0 from Open to Confirmed.

xfrm if_id should not be 0

Sep 16 2021, 1:17 PM · VyOS 1.4 Sagitta

Sep 15 2021

c-po changed the status of T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified from Open to Needs testing.
Sep 15 2021, 5:41 PM · VyOS 1.4 Sagitta