Page MenuHomeVyOS Platform
Feed All Stories

Oct 16 2021

Unknown Object (User) added a comment to T3851: Missing ospf and rip options for bridge vifs.

Tested in VyOS 1.3.0-epa1 & VyOS 1.4-rolling-202109190558

Oct 16 2021, 9:18 AM · VyOS 1.3 Equuleus (1.3.0)
maznu added a comment to T3724: Allow setting host-name in l2tp section of accel-ppp.

https://github.com/vyos/vyos-1x/pull/1028 — though probably needs some tests developed?

Oct 16 2021, 8:20 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
penetal created T3909: Add ability to upload scripts via API.
Oct 16 2021, 5:52 AM · VyOS Rolling
Unknown Object (User) added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

Tested on VyOS 1.3.0-epa1.
Confirm IBGP reflection to non-RR-Client
Lab Topology:

image.png (441×771 px, 89 KB)

RR1 & RR2 -route reflectors
P 3 - RR-Client for RR1 & RR2
P1 - IBGP peering with RR1 only
OSPF-core router - only for core network
Result: P1 gets P 3 routes fron RR1:
vyos@VyOS-P1:~$ sh ip bgp neighbors 10.0.0.1 received-routes
*> 10.0.0.201/32 10.0.0.3 0 100 100 i
*> 10.0.0.202/32 10.0.0.3 0 100 100 i
*> 192.168.3.0/24 10.0.0.3 0 100 100 i

Oct 16 2021, 3:02 AM

Oct 15 2021

Viacheslav closed T3613: Selectors for route-based IPsec tunnel (vti), a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Oct 15 2021, 8:59 PM · VyOS 1.4 Sagitta
Viacheslav closed T3613: Selectors for route-based IPsec tunnel (vti) as Resolved.
Oct 15 2021, 8:59 PM · VyOS 1.4 Sagitta
Viacheslav closed T3673: BGP large-community del operation missing as Resolved.
Oct 15 2021, 8:54 PM · VyOS 1.4 Sagitta
Viacheslav updated subscribers of T3771: DHCPv6 server prefix delegation - dynamically add route to delegated prefix via requesting router.
Oct 15 2021, 8:50 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T3832: Allow to set DHCP client-id in hexadecimal format from In progress to Needs testing.
Oct 15 2021, 8:41 PM · VyOS 1.4 Sagitta
Viacheslav moved T3676: Container option to add Linux capabilities from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 15 2021, 8:40 PM · VyOS 1.4 Sagitta
Viacheslav closed T3676: Container option to add Linux capabilities as Resolved.

@artooro Will be available in the next rolling release
Let us know, if you want some other capabilities

Oct 15 2021, 8:40 PM · VyOS 1.4 Sagitta
jcre added a comment to T3514: NIC flap at any interface change.

Sorry for the late reply, I've been waiting for a maintenance window to test this in. Again as this is a production device I only have limited debug info before having to roll back to the working version. I installed 1.4-rolling-202110150613 and on booting show interfaces does indeed show all the interfaces. The igb driver interfaces were showing as up (u/u). The i40e interfaces were showing as down (u/D).

Oct 15 2021, 8:26 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX70836c5adb4e: dhclient: T3832: Add hexadecimal format for client-id.
Oct 15 2021, 7:46 PM
GitHub <noreply@github.com> committed rVYOSONEXa98efc300c45: Merge pull request #1026 from sever-sever/T3832 (authored by c-po).
Oct 15 2021, 7:46 PM
Viacheslav committed rVYOSONEXa633bdd2ed65: containers: T3676: Allow to set capabilities.
Oct 15 2021, 7:46 PM
GitHub <noreply@github.com> committed rVYOSONEX29c57102b78f: Merge pull request #1027 from sever-sever/T3676 (authored by c-po).
Oct 15 2021, 7:46 PM
Viacheslav added a comment to T3676: Container option to add Linux capabilities.

PR https://github.com/vyos/vyos-1x/pull/1027

Oct 15 2021, 6:23 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3676: Container option to add Linux capabilities from Open to In progress.
Oct 15 2021, 4:05 PM · VyOS 1.4 Sagitta
fernando added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

In the real-world to avoid it they used cluster-id / a session BGP between them , it's the idea of RR :

Oct 15 2021, 3:48 PM
Viacheslav moved T3692: VyOS build failing due to repo.saltstack.com from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 15 2021, 3:33 PM · VyOS 1.4 Sagitta
Viacheslav closed T3692: VyOS build failing due to repo.saltstack.com as Resolved.
Oct 15 2021, 3:33 PM · VyOS 1.4 Sagitta
Viacheslav moved T3693: ISIS Route redistribution ipv6 support missing from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 15 2021, 3:31 PM · VyOS 1.4 Sagitta
Viacheslav closed T3693: ISIS Route redistribution ipv6 support missing as Resolved.
Oct 15 2021, 3:30 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T876: L2TP/IPSEC Client.

Maybe be added to gether with T1229

Oct 15 2021, 3:26 PM · Restricted Project, VyOS Rolling
Unknown Object (User) added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

@francis Sorry, I don't understand the problem.
Agree that route received from one IBGP peer should not be forwarded to another IBGP peer. Except for the RR client.

Oct 15 2021, 2:58 PM
francis added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

@NikolayP The concern here is solely this: IBGP neighbors that do not have route-reflector-client set should not received learned routes. Currently, they do. If this in intentional, then the docs should be updated to clarify this.

Oct 15 2021, 2:31 PM
Viacheslav moved T3702: Policy: Allow routing by fwmark from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 15 2021, 2:26 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T3724: Allow setting host-name in l2tp section of accel-ppp.

@maznu Can you create a PR?

Oct 15 2021, 2:22 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T3748: Container deletion bug as Resolved.

Initial bug was Fixed, VyOS 1.4-rolling-202110130217

vyos@r1-roll# compare 
[edit container]
+name dns02 {
+    image ubuntu:focal
+    network dnsnet {
+        address 10.0.72.253
+    }
+}
+network dnsnet {
+    prefix 10.0.72.0/24
+}
-network net01 {
-    prefix 10.0.72.0/24
-}
Oct 15 2021, 2:18 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

If Cluster ID is not used, full IBGP mesh must be used. Exception is RR client, they should only have peering with RR.
Router 10.0.0.21 has no peering with 10.0.0.3.
This is incorrect IBGP design.

Oct 15 2021, 1:42 PM
c-po added a comment to T3832: Allow to set DHCP client-id in hexadecimal format.

Why not always move to decimal output and detect on demand if colons are present or not and adjust the string? Ne need for the user to take any action at all?

Oct 15 2021, 5:37 AM · VyOS 1.4 Sagitta

Oct 14 2021

jestabro added a subtask for T3371: Replace netplugd by udev rules: T3876: Replace vyos-netplug with a VyOS link state monitor service.
Oct 14 2021, 7:54 PM
jestabro added a parent task for T3876: Replace vyos-netplug with a VyOS link state monitor service: T3371: Replace netplugd by udev rules.
Oct 14 2021, 7:54 PM · VyOS 1.5 Circinus
c-po closed T3801: containers: do not use podman CLI to create container networks as Resolved.
Oct 14 2021, 6:41 PM · VyOS 1.4 Sagitta
c-po added a comment to T3801: containers: do not use podman CLI to create container networks.

Yes, closing this ...

Oct 14 2021, 6:41 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3702: Policy: Allow routing by fwmark from Open to Needs testing.
Oct 14 2021, 6:14 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T3801: containers: do not use podman CLI to create container networks.

@c-po Is it already implemented with commit https://github.com/vyos/vyos-1x/commit/ae2dc55aa68679e828d4bb133fc515172c081d0f ?

Oct 14 2021, 5:36 PM · VyOS 1.4 Sagitta
Viacheslav closed T3811: NAT (op_mode): NAT op_mode command fails. as Resolved.

Fixed, VyOS 1.4-rolling-202110130217

vyos@r1-roll:~$ show nat source rules 
Rule       Source                                             Translation                                        Outbound Interface
----       ------                                             -----------                                        ------------------
3          192.168.0.0/24                                     masquerade                                         eth0
Oct 14 2021, 5:30 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T3810: webproxy squidguard rules don't work properly after rewriting to python. .
Oct 14 2021, 5:15 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav updated the task description for T3810: webproxy squidguard rules don't work properly after rewriting to python. .
Oct 14 2021, 5:15 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
UnicronNL closed T3908: [CLOUDINIT] if the fqdn has no domain name cloudinit will fail to run as Invalid.

Is a double task, it looks like the package is not update upstream.

Oct 14 2021, 3:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
UnicronNL created T3908: [CLOUDINIT] if the fqdn has no domain name cloudinit will fail to run.
Oct 14 2021, 3:01 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
jestabro added a comment to T3876: Replace vyos-netplug with a VyOS link state monitor service.

Work in progress:
https://github.com/vyos/vyos-1x/compare/current...jestabro:linkstate
https://github.com/vyos/vyos-build/compare/current...jestabro:linkstate

Oct 14 2021, 1:38 PM · VyOS 1.5 Circinus
n.fort added a comment to T3907: Firewall - Set log levels.

Maybe, but if the effort is made in order to be able to configure log level, it would be good that it can be set in different levels.
I'm thinking in a mix scenario, where majority of rules may log with info/debug level (for example default accept rules), while other rules may need a warning/error level (some drop rules).

Oct 14 2021, 1:00 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3907: Firewall - Set log levels.

As for me, it should be configured in the global firewall log level, not per rule.

set firewall log-level x
Oct 14 2021, 12:52 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3832: Allow to set DHCP client-id in hexadecimal format.

PR https://github.com/vyos/vyos-1x/pull/1026

Oct 14 2021, 12:43 PM · VyOS 1.4 Sagitta
n.fort created T3907: Firewall - Set log levels.
Oct 14 2021, 12:31 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3832: Allow to set DHCP client-id in hexadecimal format from Open to In progress.
Oct 14 2021, 12:19 PM · VyOS 1.4 Sagitta
Viacheslav reassigned T3865: loadkey command help text missing escape sequence from Viacheslav to chaya2z.

PR https://github.com/vyos/vyatta-cfg-system/pull/170

Oct 14 2021, 10:22 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3865: loadkey command help text missing escape sequence from Open to In progress.
Oct 14 2021, 10:15 AM · VyOS 1.4 Sagitta
Viacheslav moved T3763: wireguard checks if port already binding from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 14 2021, 9:07 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3906: [Traffic Control] Invalid Port Configuration Still Commits.

The real bug is it shouldn't allow port-range values as it is not implemented.
Or just add this feature T2798

Oct 14 2021, 8:55 AM · Known issue, VyOS 1.4 Sagitta
trae32566 created T3906: [Traffic Control] Invalid Port Configuration Still Commits.
Oct 14 2021, 8:28 AM · Known issue, VyOS 1.4 Sagitta
trae32566 awarded T2798: Allow port range in tc filter a Like token.
Oct 14 2021, 8:13 AM · VyOS Rolling
SquirePug added a comment to T3896: Extend ocserv support to allow for per-group configs.

For this we create text files as the group-config includes (they contain route and other per group config directives, generally around security).

Oct 14 2021, 7:05 AM · VyOS 1.4 Sagitta
adaker created T3905: Add NAS-Identifier for system login.
Oct 14 2021, 1:00 AM · VyOS 1.4 Sagitta (1.4.0-GA)

Oct 13 2021

Georgiy-Tugai awarded T3008: Migrate from ntpd to chronyd a Like token.
Oct 13 2021, 3:39 PM · VyOS 1.4 Sagitta
Georgiy-Tugai added a comment to T3008: Migrate from ntpd to chronyd.

图片.png (754×1 px, 114 KB)

图片.png (499×1 px, 60 KB)

Does anyone understand the meaning of these performance data? I don’t know the unit of these data

Oct 13 2021, 3:38 PM · VyOS 1.4 Sagitta
c-po closed T3904: NTP pool associations silently fail as Resolved.
Oct 13 2021, 12:08 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po committed rVYOSONEXd4c5e78fc94a: ntp: T3904: Fix NTP pool associations (authored by Georgiy-Tugai).
Oct 13 2021, 12:08 PM
c-po moved T3904: NTP pool associations silently fail from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 13 2021, 12:08 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3904: NTP pool associations silently fail from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 13 2021, 12:08 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
Georgiy-Tugai committed rVYOSONEX854c68d43d8f: ntp: T3904: Fix NTP pool associations.
Oct 13 2021, 12:07 PM
GitHub <noreply@github.com> committed rVYOSONEX4d99d91829fa: Merge pull request #1023 from Georgiy-Tugai/patch-1 (authored by c-po).
Oct 13 2021, 12:07 PM
c-po changed the status of T3904: NTP pool associations silently fail from Open to In progress.
Oct 13 2021, 12:03 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
Georgiy-Tugai created T3904: NTP pool associations silently fail.
Oct 13 2021, 11:21 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
FileGo added a comment to T3902: Firewall does not load on boot, address-group not found, even though it exists.

If I change the double-quotes to single-quotes for all the rules in that firewall, I get this (no changes detected):

Oct 13 2021, 9:25 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
c-po closed T3277: DNS Forwarding - reverse zones as Resolved.
Oct 13 2021, 7:38 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3277: DNS Forwarding - reverse zones from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 13 2021, 7:38 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3277: DNS Forwarding - reverse zones from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 13 2021, 7:38 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po committed rVYOSONEXe84623a1cd28: dns: T3277: DNS Forwarding - reverse zones for RFC1918 addresses (authored by hard).
Oct 13 2021, 7:38 AM
c-po assigned T3277: DNS Forwarding - reverse zones to hard.
Oct 13 2021, 7:34 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta

Oct 12 2021

Viacheslav moved T3868: Regex and/or wildcard not accepted with large-community-list from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 12 2021, 6:43 PM · VyOS 1.4 Sagitta
Viacheslav closed T3868: Regex and/or wildcard not accepted with large-community-list as Resolved.

@foxbox Will be fixed in the next rolling release.

Oct 12 2021, 6:43 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXe94112281d58: validators: T3868: Allow asterisk symbol in bgp-large-community-list.
Oct 12 2021, 6:38 PM
GitHub <noreply@github.com> committed rVYOSONEX38421c50e9bd: Merge pull request #1025 from sever-sever/T3868 (authored by c-po).
Oct 12 2021, 6:37 PM
Viacheslav added a comment to T3868: Regex and/or wildcard not accepted with large-community-list.

PR https://github.com/vyos/vyos-1x/pull/1025

Oct 12 2021, 6:25 PM · VyOS 1.4 Sagitta
Hydra166 added a comment to T3891: X550-T2/Possibly other X550/X540 cards no link on VyOS.

Messaged

Oct 12 2021, 5:13 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3868: Regex and/or wildcard not accepted with large-community-list from Open to In progress.
Oct 12 2021, 4:44 PM · VyOS 1.4 Sagitta
Viacheslav moved T3881: Wrong description for container section restart from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 12 2021, 4:15 PM · VyOS 1.4 Sagitta
Viacheslav closed T3881: Wrong description for container section restart as Resolved.
Oct 12 2021, 4:15 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3478: Radius from Open to Needs testing.
Oct 12 2021, 4:01 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3478: Radius.

@BiMW Can you re-check it?

Oct 12 2021, 4:01 PM · VyOS 1.4 Sagitta
Viacheslav closed T3701: ipoe server fails to start when configuring radius dynamic-author on ipoe as Resolved.

Not reproducible, VyOS 1.4-rolling-202109300217

set service ipoe-server authentication radius dynamic-author key 'ssss'
set service ipoe-server authentication radius dynamic-author server '192.168.122.11'
set service ipoe-server authentication radius nas-ip-address '192.168.122.11'
set service ipoe-server authentication radius server 192.168.122.11 key 'ciscoradiuskey'
set service ipoe-server interface eth1 client-subnet '192.0.2.0/24'
Oct 12 2021, 3:22 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3902: Firewall does not load on boot, address-group not found, even though it exists.

@FileGo Can you replace double-quotes with single-quotes?

Oct 12 2021, 2:52 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav created T3903: Containers: after command "reboot" the host system will reboot after 1.5 minutes.
Oct 12 2021, 2:47 PM · VyOS 1.4 Sagitta
FileGo created T3902: Firewall does not load on boot, address-group not found, even though it exists.
Oct 12 2021, 1:48 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav closed T3216: Removal of restricted-shell broke configure mode for RADIUS users, a subtask of T671: Identify and remove dead code, as Resolved.
Oct 12 2021, 11:13 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav closed T3216: Removal of restricted-shell broke configure mode for RADIUS users as Resolved.

Fixed

sever@sever:~$ ssh vyosuser@192.168.122.11
Oct 12 2021, 11:13 AM · VyOS 1.4 Sagitta
lucasec added a comment to T562: PDNS: Add support for authoritative dns server.

PR: https://github.com/vyos/vyos-1x/pull/1024

Oct 12 2021, 7:28 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T3896: Extend ocserv support to allow for per-group configs: VyOS 1.4 Sagitta.
Oct 12 2021, 6:11 AM · VyOS 1.4 Sagitta
PeppyH added a comment to T3896: Extend ocserv support to allow for per-group configs.

@SquirePug Can you share more details, which templates and parameters did you edit?

Oct 12 2021, 5:03 AM · VyOS 1.4 Sagitta

Oct 11 2021

Viacheslav closed T2607: Support for pppoe-server radius mode auth and config radius accouting port as Resolved.

Present in 1.4 and 1.3.0-epa1

set service pppoe-server authentication radius server 192.0.2.1 acct-port
Possible completions:
   <1-65535>    Numeric IP port (default: 1813)
Oct 11 2021, 7:28 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3510: RADIUS usersname is not shown on CLI.

@c-po in 1.3.0-epa1 works fine.

Oct 11 2021, 5:53 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX9028e42bd4d4: vyos.configdict: T2653: do not merge in defaults when interface is deleted.
Oct 11 2021, 5:02 PM
c-po added a comment to T3510: RADIUS usersname is not shown on CLI.

What about 1.3.0-epa1?

Oct 11 2021, 2:49 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX46e331cdf44b: vyos.configdict: T2653: do not merge in defaults when interface is deleted.
Oct 11 2021, 2:48 PM
Viacheslav reopened T3510: RADIUS usersname is not shown on CLI as "Open".

Re-opened, the same bug in VyOS 1.4-rolling-202109300217

sever@sever:~/docker$ ssh user@192.168.122.11
Oct 11 2021, 1:24 PM · VyOS 1.4 Sagitta
Viacheslav created T3901: Help values do not work for RADIUS authentication users.
Oct 11 2021, 12:50 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a comment to T3896: Extend ocserv support to allow for per-group configs.

@SquirePug Can you share more details, which templates and parameters did you edit?

Oct 11 2021, 11:16 AM · VyOS 1.4 Sagitta