Page MenuHomeVyOS Platform
Feed All Stories

Sep 29 2021

dmbaturin renamed T1249: multiple PBR rules can set to a single interface from multiply PBR rules can set to a single interface to multiple PBR rules can set to a single interface.
Sep 29 2021, 1:39 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin set Is it a breaking change? to compatible on T1248: Add a function for copying nodes to the vyos.configtree library.
Sep 29 2021, 1:39 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin changed Is it a breaking change? from none to compatible on T1246: VyOS 1.2.0 "openvpn-options" configuration does not allow quotes in values.
Sep 29 2021, 1:38 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin removed a project from T1241: Remove of policy route throws CLI error: VyOS 1.3 Equuleus (1.3.0-epa1).
Sep 29 2021, 1:38 PM · VyOS 1.2 Crux (VyOS 1.2.6)
dmbaturin removed a project from T1238: Wireguard allows invalid IP's: VyOS 1.3 Equuleus (1.3.0-epa1).
Sep 29 2021, 1:38 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin renamed T1236: Update Linux Kernel from Update Linux Kernel to 4.19.20 to Update Linux Kernel.
Sep 29 2021, 1:37 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin placed T1227: rip PW can't be set at interface config up for grabs.
Sep 29 2021, 1:36 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin set Is it a breaking change? to compatible on T1222: OSPF routing problem - route looping.
Sep 29 2021, 1:36 PM · VyOS 1.3 Equuleus (1.3.0-epa1), vyos-frr
dmbaturin set Is it a breaking change? to compatible on T1214: Add `ipaddrcheck` to the packages directory.
Sep 29 2021, 1:35 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin set Is it a breaking change? to compatible on T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.
Sep 29 2021, 1:35 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin set Is it a breaking change? to compatible on T1207: DMVPN behind NAT.
Sep 29 2021, 1:34 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin removed a project from T1205: module pcspkr missing: VyOS 1.3 Equuleus (1.3.0-epa1).
Sep 29 2021, 1:34 PM · VyOS 1.2 Crux (VyOS 1.2.6)
dmbaturin set Is it a breaking change? to compatible on T1202: Add `hvinfo` to the packages directory.
Sep 29 2021, 1:33 PM · VyOS 1.3 Equuleus (1.3.0-epa1), vyos-build
dmbaturin removed a project from T1194: cronjob is being setup even if not saved: VyOS 1.3 Equuleus (1.3.0-epa1).
Sep 29 2021, 1:33 PM · VyOS 1.2 Crux (VyOS 1.2.6)
dmbaturin changed Is it a breaking change? from none to compatible on T1192: Wlan regression between 1.2.0-rc11 and rolling.
Sep 29 2021, 1:29 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin edited projects for T1187: Command show log vpn display wrong information , added: VyOS-1.2.0-GA; removed VyOS 1.3 Equuleus (1.3.0-epa1).
Sep 29 2021, 1:28 PM · VyOS-1.2.0-GA
dmbaturin set Is it a breaking change? to compatible on T1187: Command show log vpn display wrong information .
Sep 29 2021, 1:28 PM · VyOS-1.2.0-GA
dmbaturin set Is it a breaking change? to none on T1184: wireguard - extend documentation with the show interface wireguard commands.
Sep 29 2021, 1:27 PM · VyOS 1.3 Equuleus (1.3.0-epa1)

Sep 28 2021

jestabro updated the task description for T3869: Rewrite vyatta_net_name/vyatta_interface_rescan in Python.
Sep 28 2021, 5:04 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T3871: Resolve unexpected interface name reordering: T3869: Rewrite vyatta_net_name/vyatta_interface_rescan in Python.
Sep 28 2021, 5:03 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
jestabro added a parent task for T3869: Rewrite vyatta_net_name/vyatta_interface_rescan in Python: T3871: Resolve unexpected interface name reordering.
Sep 28 2021, 5:03 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T3871: Resolve unexpected interface name reordering.
Sep 28 2021, 5:02 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
jestabro created T3871: Resolve unexpected interface name reordering.
Sep 28 2021, 5:02 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
zsdc changed the status of T3852: DHCP client issue - interface has two dhclient processes when link is unpluged and then plug again, a subtask of T3471: DHCP hook is not able to detect all running DHCP instances, from Open to Needs testing.
Sep 28 2021, 10:08 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
zsdc changed the status of T3852: DHCP client issue - interface has two dhclient processes when link is unpluged and then plug again from Open to Needs testing.

The issue solved in the https://github.com/vyos/vyos-1x/pull/1017
However, the question if netplug script is necessary at all is still opened.

Sep 28 2021, 10:08 AM · VyOS 1.3 Equuleus (1.3.3)
zsdc added a subtask for T3471: DHCP hook is not able to detect all running DHCP instances: T3852: DHCP client issue - interface has two dhclient processes when link is unpluged and then plug again.
Sep 28 2021, 9:54 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
zsdc added a parent task for T3852: DHCP client issue - interface has two dhclient processes when link is unpluged and then plug again: T3471: DHCP hook is not able to detect all running DHCP instances.
Sep 28 2021, 9:54 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav closed T3853: nat66 rules gets deleted on reboot in 1.4-rolling-202109240217 as Resolved.
Sep 28 2021, 7:07 AM · VyOS 1.4 Sagitta
danielpo added a comment to T3853: nat66 rules gets deleted on reboot in 1.4-rolling-202109240217.

It works now! Thanks!

Sep 28 2021, 6:31 AM · VyOS 1.4 Sagitta
sajiby3k created T3870: Vyos crux with kernel 4.19.207 igb driver missing.
Sep 28 2021, 6:06 AM · VyOS 1.2 Crux

Sep 27 2021

jestabro changed the status of T3869: Rewrite vyatta_net_name/vyatta_interface_rescan in Python from In progress to Needs testing.
Sep 27 2021, 9:07 PM · VyOS 1.4 Sagitta
jestabro added a comment to T3869: Rewrite vyatta_net_name/vyatta_interface_rescan in Python.

In testing:
https://github.com/vyos/vyos-1x/compare/current...jestabro:interface-names
https://github.com/vyos/vyatta-cfg/compare/current...jestabro:interface-names
The following removes legacy code: vyatta_net_name, vyatta_interface_rescan, XorpConfigParser
https://github.com/vyos/vyatta-cfg-system/compare/current...jestabro:interface-names

Sep 27 2021, 9:06 PM · VyOS 1.4 Sagitta
jestabro changed the status of T3869: Rewrite vyatta_net_name/vyatta_interface_rescan in Python from Open to In progress.
Sep 27 2021, 8:10 PM · VyOS 1.4 Sagitta
c-po closed T3858: Deleting OSPFv3 process yields: Unknown command: no router-id as Resolved.
Sep 27 2021, 6:58 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3858: Deleting OSPFv3 process yields: Unknown command: no router-id from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 27 2021, 6:57 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3858: Deleting OSPFv3 process yields: Unknown command: no router-id from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.9) board.
Sep 27 2021, 6:57 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0-epa1)
c-po added a comment to T3858: Deleting OSPFv3 process yields: Unknown command: no router-id.

Backported to crux branch

Sep 27 2021, 6:57 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0-epa1)
c-po added a project to T3858: Deleting OSPFv3 process yields: Unknown command: no router-id: VyOS 1.2 Crux (VyOS 1.2.9).
Sep 27 2021, 6:55 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0-epa1)
c-po committed rVYOSONEX17dc7cd0aaca: nat66: T3863: ndppd requires interfaces to be present.
Sep 27 2021, 6:54 PM
c-po closed T3863: nat66: commit fails/hangs on non existing interface, a subtask of T3853: nat66 rules gets deleted on reboot in 1.4-rolling-202109240217, as Resolved.
Sep 27 2021, 6:54 PM · VyOS 1.4 Sagitta
c-po closed T3863: nat66: commit fails/hangs on non existing interface as Resolved.
Sep 27 2021, 6:54 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXa0202eaf489c: igmp: T2230: fix Jinja2 and FRR indention.
Sep 27 2021, 6:52 PM
c-po committed rVYOSONEXf4732f348ff4: frr: T2175: rename daemon Jinja2 templates to match (d)aemon suffix.
Sep 27 2021, 6:43 PM
c-po committed rVYOSONEX0f25b50ea8c0: smoketest: interface test base class QoS cleanup.
Sep 27 2021, 6:30 PM
c-po committed rVYOSONEXc488f55bd1cf: smoketest: interface test base class for 802.1q should not extend testing to QoS.
Sep 27 2021, 6:30 PM
Viacheslav changed the status of T690: Allow OpenVPN servers to push routes with custom metric values from Open to Needs testing.
Sep 27 2021, 6:05 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav changed the status of T3853: nat66 rules gets deleted on reboot in 1.4-rolling-202109240217 from Confirmed to Needs testing.

@danielpo Will be fixed in the next rolling release.

Sep 27 2021, 6:05 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXc6d0227d96e4: openvpn: T690: Fix template for gateway and metric (authored by Viacheslav).
Sep 27 2021, 5:57 PM
Viacheslav committed rVYOSONEX96681d8bf1ed: openvpn: T690: Fix template for gateway and metric.
Sep 27 2021, 5:56 PM
GitHub <noreply@github.com> committed rVYOSONEX753757b0fdd6: Merge pull request #1015 from sever-sever/T690 (authored by c-po).
Sep 27 2021, 5:56 PM
Viacheslav committed rVYOSONEXb8a8b7f7919f: nat66: T3853: Change priority to 500.
Sep 27 2021, 5:56 PM
GitHub <noreply@github.com> committed rVYOSONEX5c8a103ef475: Merge pull request #1016 from sever-sever/T3853 (authored by c-po).
Sep 27 2021, 5:56 PM
Viacheslav added a comment to T3853: nat66 rules gets deleted on reboot in 1.4-rolling-202109240217.

PR https://github.com/vyos/vyos-1x/pull/1016
Change priority for nat66

Sep 27 2021, 5:55 PM · VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.143 / 5.10.61 to Update Linux Kernel to v5.4.149 / 5.10.69.
Sep 27 2021, 5:53 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T3858: Deleting OSPFv3 process yields: Unknown command: no router-id.

PR https://github.com/vyos/vyatta-cfg-quagga/pull/89

Sep 27 2021, 11:06 AM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav reopened T690: Allow OpenVPN servers to push routes with custom metric values as "Open".

Not all clients support the gateway option (get issues in mac and windows):
Mac

tun_prop_route_error: route destinations other than vpn_gateway or net_gateway are not supported
Sep 27 2021, 10:58 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav claimed T3858: Deleting OSPFv3 process yields: Unknown command: no router-id.
Sep 27 2021, 10:51 AM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T3350: OpenVPN config file generation broken.
set interfaces openvpn vtun20 openvpn-option '--push dhcp-option DNS 203.0.113.1'

generated config:

--push dhcp-option DNS 203.0.113.1

expected configuration:

push dhcp-option "DNS 203.0.113.1"
Sep 27 2021, 8:31 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
zoenan7 added a comment to T3835: vyos router 1.2.7 snmp Dos bug.

By the way, the SNMPD service of the router will not restart automatically. After the SNMP service is attacked, the SNMP service cannot be restored even if the device is restarted, which may be an inappropriate implementation.

Sep 27 2021, 7:45 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zoenan7 added a comment to T3835: vyos router 1.2.7 snmp Dos bug.

I have a question. If you confirm the existence of the vulnerability, can you report to the NET-SNMP vendor and apply for a CVE number?

Sep 27 2021, 7:37 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zoenan7 added a comment to T3835: vyos router 1.2.7 snmp Dos bug.

I have sent the POC of the vulnerability to daniil@vyos.io.

Sep 27 2021, 7:35 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zoenan7 added a comment to T3835: vyos router 1.2.7 snmp Dos bug.

By the way, The password of the compressed package is HGkasjgJFYL261.

Sep 27 2021, 7:28 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zoenan7 added a comment to T3835: vyos router 1.2.7 snmp Dos bug.

Hello, I have found three vulnerabilities in V1.2.7, one of which can also be reproduced in V1.3, please continue to check the other versions, I will send all three POCs to your email, thank you for your work.

Sep 27 2021, 7:25 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zsdc raised the priority of T3350: OpenVPN config file generation broken from Normal to Urgent!.
Sep 27 2021, 7:14 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
lucasec added a comment to T3861: PKI: changing certificates, keys, crls does not "regenerate" the on-disk certificates.

Adding a few notes here:

  • The ideal behavior probably depends on which PKI elements are changed and what services depend on them.
  • E.g. OpenVPN does not require a server restart for a CRL change (see https://openvpn.net/community-resources/controlling-a-running-openvpn-process/), but changing the CA or server cert/key would require a restart.
  • It seems like there are some swanctrl commands that can conditionally reload parts of the config too without taking all tunnels down
  • The former might be useful if you need to renew server certs or something like that and want to do so with the minimal impact
Sep 27 2021, 4:45 AM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)

Sep 26 2021

syncer assigned T3827: interfaces migration script fails on AWS hosts to dmbaturin.
Sep 26 2021, 9:53 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
foxbox created T3868: Regex and/or wildcard not accepted with large-community-list.
Sep 26 2021, 6:21 PM · VyOS 1.4 Sagitta
c-po closed T3867: vxlan: multicast group address is not validated as Resolved.
Sep 26 2021, 5:29 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3867: vxlan: multicast group address is not validated from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 26 2021, 5:29 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3867: vxlan: multicast group address is not validated from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 26 2021, 5:29 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3867: vxlan: multicast group address is not validated from Need Triage to 1.3.0-epa1 on the VyOS 1.3 Equuleus board.
Sep 26 2021, 5:28 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po committed rVYOSONEX2f4466802d54: vxlan: T3867: add multicast validator for group address.
Sep 26 2021, 5:28 PM
c-po committed rVYOSONEX0d7cd4ed5725: vxlan: T3867: add multicast validator for group address.
Sep 26 2021, 5:28 PM
c-po changed the status of T3867: vxlan: multicast group address is not validated from Open to In progress.
Sep 26 2021, 5:20 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po created T3867: vxlan: multicast group address is not validated.
Sep 26 2021, 5:19 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEXcf05add82e54: T3866: ignore interfaces without "address" in DNS forwarding migration.
Sep 26 2021, 3:12 PM
dmbaturin committed rVYOSONEXaa1362cb4fbb: T3866: ignore interfaces without "address" in DNS forwarding migration.
Sep 26 2021, 3:12 PM
dmbaturin created T3866: Configs with DNS forwarding listening on OpenVPN interfaces or interfaces without a fixed address cannot be migrated to the new syntax.
Sep 26 2021, 3:11 PM · VyOS 1.3 Equuleus (1.3.0)
SrividyaA added a comment to T3856: op command: " generate tech-support archive file" option is not working.

@c-po The mentioned completion help stating is wrong then as it says at the specified path.

Sep 26 2021, 2:48 PM · VyOS 1.4 Sagitta, VyOS 1.2 Crux (VyOS 1.2.8)
chaya2z updated the task description for T3865: loadkey command help text missing escape sequence.
Sep 26 2021, 2:33 PM · VyOS 1.4 Sagitta
chaya2z created T3865: loadkey command help text missing escape sequence.
Sep 26 2021, 2:11 PM · VyOS 1.4 Sagitta
UnicronNL changed the status of T3864: Add Edgecore build to VyOS 1.3 Equuleus from Open to In progress.
Sep 26 2021, 12:26 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3826: PKI: op-mode - do input validation when listing certificates as Resolved.
Sep 26 2021, 11:17 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX579c64f5ab5c: op-mode: pki: T3826: perform input validation when listing certificates.
Sep 26 2021, 11:17 AM
c-po committed rVYOSONEX3bc79ff3cb40: ospf: T3757: add completion help when refering to area ID.
Sep 26 2021, 11:10 AM
c-po added a comment to T3853: nat66 rules gets deleted on reboot in 1.4-rolling-202109240217.

Related to T3863 and could also be a XML priority issue as NAT66 has a higher priority then e.g. the tunnel interface

Sep 26 2021, 10:56 AM · VyOS 1.4 Sagitta
c-po triaged T3863: nat66: commit fails/hangs on non existing interface as Normal priority.
Sep 26 2021, 10:55 AM · VyOS 1.4 Sagitta
c-po changed Is it a breaking change? from none to compatible on T3860: Error on pppoe, tunnel and wireguard interfaces for IPv6 EUI64 addresses.
Sep 26 2021, 10:51 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3814: wireguard: commit error showing incorrect peer name from the configured name from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 26 2021, 10:51 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3845: Add "show bgp nexthop" command from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 26 2021, 10:51 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3860: Error on pppoe, tunnel and wireguard interfaces for IPv6 EUI64 addresses from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa1) board.
Sep 26 2021, 10:51 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3814: wireguard: commit error showing incorrect peer name from the configured name from Need Triage to 1.3.0-epa1 on the VyOS 1.3 Equuleus board.
Sep 26 2021, 10:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3845: Add "show bgp nexthop" command from Need Triage to 1.3.0-epa1 on the VyOS 1.3 Equuleus board.
Sep 26 2021, 10:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T3841: dhcp-server: add ping-check option to CLI from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 26 2021, 10:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3672: DHCP-FO with multiple subnets results in invalid/non-functioning dhcpd.conf configuration file output from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 26 2021, 10:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3847: keepalived/vrrp: migrate to get_config_dict() - cleanup from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 26 2021, 10:50 AM · VyOS 1.4 Sagitta
c-po moved T3856: op command: " generate tech-support archive file" option is not working from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 26 2021, 10:50 AM · VyOS 1.4 Sagitta, VyOS 1.2 Crux (VyOS 1.2.8)
c-po moved T3860: Error on pppoe, tunnel and wireguard interfaces for IPv6 EUI64 addresses from Open to Finished on the VyOS 1.4 Sagitta board.
Sep 26 2021, 10:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po moved T3860: Error on pppoe, tunnel and wireguard interfaces for IPv6 EUI64 addresses from Need Triage to 1.3.0-epa1 on the VyOS 1.3 Equuleus board.
Sep 26 2021, 10:49 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po closed T3860: Error on pppoe, tunnel and wireguard interfaces for IPv6 EUI64 addresses as Resolved.
Sep 26 2021, 10:49 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta