Page MenuHomeVyOS Platform
Feed All Stories

Dec 22 2021

erkin lowered the priority of T4090: Source port and interface support for `commit-archive` from Low to Wishlist.
Dec 22 2021, 5:18 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin added a comment to T4090: Source port and interface support for `commit-archive`.

I personally think the interface part is high-effort, low-gain since you can simply use the address of the interface to the same effect, whereas simply providing an interface will force it to decide which address to use on dual-stack systems. It needs to pick between AF_INET and AF_INET6 when creating the socket before setsockopt()ing SO_BINDTODEVICE; although I think we can get away with doing what socket.create_connection() does. Even then, only the SFTP portion of the code directly uses socket — everything else relies on higher level libraries that only expose address and port options. (Also, using a single parameter for both addresses and interfaces is a bad idea, in my opinion, because it's probably more useful to resolve an FQDN string to an address rather than assume all strings are interfaces. But otherwise, we'd need to find a way to resolve conflict between address and interface parameters.) All in all, I don't think the interface parameter is a good idea at all but we'll see.

Dec 22 2021, 5:18 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3356: Script for remote file transfers, a subtask of T3355: Remove all remaining legacy Vyatta code, as Resolved.
Dec 22 2021, 4:53 AM · VyOS Rolling
erkin closed T3356: Script for remote file transfers as Resolved.

All parts completely backported to Equuleus.

Dec 22 2021, 4:53 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin added a subtask for T3356: Script for remote file transfers: T4090: Source port and interface support for `commit-archive`.
Dec 22 2021, 4:52 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin added a parent task for T4090: Source port and interface support for `commit-archive`: T3356: Script for remote file transfers.
Dec 22 2021, 4:52 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3628: commit-archive source-address Interface Broken, a subtask of T3356: Script for remote file transfers, as Not Applicable.
Dec 22 2021, 4:52 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3628: commit-archive source-address Interface Broken as Not Applicable.

I opened a new issue for this: T4090.

Dec 22 2021, 4:52 AM · VyOS 1.4 Sagitta
erkin triaged T4090: Source port and interface support for `commit-archive` as Low priority.
Dec 22 2021, 4:52 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Dec 21 2021

Viacheslav added a comment to T4080: Space in "description" commands.

@m.korobeinikov Could you re-check it and close if necessary?

Dec 21 2021, 11:10 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T3376: Setting ipv6 address autoconf causes all interfaces besides the target to lose their IP as Not Applicable.
Dec 21 2021, 11:01 PM · VyOS 1.4 Sagitta
Viacheslav closed T3466: Ping command not working as expected as Wontfix.
Dec 21 2021, 10:55 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3527: Sometimes installing of static routes failes.

@ernstjo Do you have any news regarding this issue or should we close it?

Dec 21 2021, 10:51 PM
Viacheslav added a comment to T3678: VyOS 1.4: Invalid error message while deleting ipsec vpn configuration.

@SrividyaA Could you re-check it?

Dec 21 2021, 10:41 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXeb478c15b4b8: interface: T4056: Fix unexpected delete tc qdisc.
Dec 21 2021, 10:17 PM
GitHub <noreply@github.com> committed rVYOSONEX07ccea8c761f: Merge pull request #1117 from sever-sever/T4056 (authored by c-po).
Dec 21 2021, 10:17 PM
Viacheslav closed T3931: SSTP doesn't work after rewriting to PKI, a subtask of T3642: PKI configuration, as Resolved.
Dec 21 2021, 10:13 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav closed T3931: SSTP doesn't work after rewriting to PKI as Resolved.
Dec 21 2021, 10:13 PM · VyOS 1.4 Sagitta
Viacheslav closed T4032: PPPoE server firewall zone completion missing as Invalid.
Dec 21 2021, 10:01 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4056: Traffic policy not set in live configuration.

PR https://github.com/vyos/vyos-1x/pull/1117

Dec 21 2021, 9:59 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav added a comment to T4056: Traffic policy not set in live configuration.

@daniil can you edit one file?

sudo nano -c +1308 /usr/lib/python3/dist-packages/vyos/ifconfig/interface.py

And replace string:

if not 'redirect' in self._config:

To string:

if not 'redirect' in self._config and not 'traffic_policy' in self._config:

save and reboot the router or just restart vyos-configd

sudo systemctl restart vyos-configd
Dec 21 2021, 9:20 PM · vyatta-cfg, VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T3006: Accel-PPP & vlan-mon config get invalid VLAN.

I think this is the limitation with the Linux interface name, it should not be higher than 16 characters. In you config I see, as an example (bond0.995.130 = 13 chars and additional part .100 = 4) = 17
I know how we can fix it manually, but I'm not sure that it is a good idea.
Accel-PPP supports name changing for created interface by vlan_mon module

[pppoe]
vlan-name=e0.%P.%N
interface=re:^e0\.\d+\.\d+

you can try to change this manually (edit /run/accel-ppp/pppoe.conf) and restart pppoe-server

Dec 21 2021, 8:47 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4072: Feature Request: Firewall on bridge interfaces from "Task" to "Feature Request".
Dec 21 2021, 8:15 PM · VyOS 1.4 Sagitta
Viacheslav removed a project from T4087: IPsec IKE-group proposals limit of 10 pieces : VyOS 1.2 Crux.
Dec 21 2021, 8:07 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav closed T4013: Add pkg cloudwatch for AWS images as Resolved.
Dec 21 2021, 8:02 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav renamed T4039: Rsyslog to use 'protocol23format' for protocol UDP from Rsyslog to use 'protocol23format' to Rsyslog to use 'protocol23format' for protocol UDP.
Dec 21 2021, 7:55 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T4039: Rsyslog to use 'protocol23format' for protocol UDP.

PR https://github.com/vyos/vyos-1x/pull/1116

Dec 21 2021, 7:51 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a project to T4039: Rsyslog to use 'protocol23format' for protocol UDP: VyOS 1.4 Sagitta.
Dec 21 2021, 6:43 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T4062: VRRP IPSEC-AH : sequence number xxxxxxx already processed. Packet dropped. Local(xxxxxxx).

@boevering Do you know how to reproduce it?

Dec 21 2021, 6:37 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav changed the status of T4021: Long commit time on bridge interface with 1-4094 allowed VLAN tags from Open to Needs testing.
Dec 21 2021, 5:22 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4021: Long commit time on bridge interface with 1-4094 allowed VLAN tags.

@Boman I don't see such issue:

vyos@r11-roll# set interfaces bridge br0 enable-vlan 
[edit]
vyos@r11-roll# set interfaces bridge br0 member interface eth2 allowed-vlan 1-4094
[edit]
vyos@r11-roll# 
[edit]
vyos@r11-roll# time commit
Dec 21 2021, 5:22 PM · VyOS 1.4 Sagitta
Viacheslav moved T3913: VRF traffic fails after upgrade from 1.3.0-RC6 to 1.3.0-EPA1/2 from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0) board.
Dec 21 2021, 5:05 PM · VyOS 1.3 Equuleus (1.3.0)
danhusan closed T3913: VRF traffic fails after upgrade from 1.3.0-RC6 to 1.3.0-EPA1/2 as Resolved.
Dec 21 2021, 5:02 PM · VyOS 1.3 Equuleus (1.3.0)
danhusan added a comment to T3913: VRF traffic fails after upgrade from 1.3.0-RC6 to 1.3.0-EPA1/2.

Confirmed working in 1.3.0 LTS.

Dec 21 2021, 5:01 PM · VyOS 1.3 Equuleus (1.3.0)
daniil added a comment to T1871: Add MTU option to "traffic-policy limiter".

I agree, when offloading is enabled, it is necessary to increase MTU for traffic policing.

Dec 21 2021, 4:37 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
daniil added a comment to T4056: Traffic policy not set in live configuration.
# show traffic-policy 
 limiter 1G {
     default {
         bandwidth 1gbit
         burst 188kb
     }
}
Dec 21 2021, 4:09 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav moved T4053: VRRP impossible to set scripts out of the /config directory from Open to Finished on the VyOS 1.4 Sagitta board.
Dec 21 2021, 4:01 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T4053: VRRP impossible to set scripts out of the /config directory as Resolved.
Dec 21 2021, 4:01 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a comment to T4056: Traffic policy not set in live configuration.

@daniil Can you share an example of traffic-policy 1G?

Dec 21 2021, 3:59 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav closed T4070: NATv4 : inbound-interface type "any" is missing. as Resolved.
Dec 21 2021, 3:56 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4081: VRRP health-check script stops working when setting up a sync group.

PR https://github.com/vyos/vyos-1x/pull/1115

Dec 21 2021, 2:43 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav moved T4082: Add op mode command to restart ldpd from Open to Backport Candidates on the VyOS 1.4 Sagitta board.
Dec 21 2021, 10:48 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav moved T3435: NAT rules show corruption from Finished to In Progress on the VyOS 1.4 Sagitta board.

There is still another bug:

set nat destination rule 120 destination address '203.0.113.1'
set nat destination rule 120 inbound-interface 'eth0'
set nat destination rule 120 protocol 'tcp'
set nat destination rule 120 translation address '192.0.2.40'
Dec 21 2021, 9:58 AM · VyOS 1.4 Sagitta
Viacheslav reopened T3435: NAT rules show corruption as "Needs testing".
Dec 21 2021, 9:56 AM · VyOS 1.4 Sagitta
Viacheslav closed T3435: NAT rules show corruption as Resolved.
Dec 21 2021, 9:16 AM · VyOS 1.4 Sagitta
Viacheslav created T4089: Show nat destination rules shows ip address instead of interface 'any'.
Dec 21 2021, 9:09 AM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX458e0c5c6172: nat: T3435: Fix for op-mode concatenate str.
Dec 21 2021, 9:05 AM
GitHub <noreply@github.com> committed rVYOSONEX9275fd942cef: Merge pull request #1114 from sever-sever/T3435-nat (authored by c-po).
Dec 21 2021, 9:05 AM
Viacheslav edited a custom field on T3435: NAT rules show corruption.
Dec 21 2021, 8:53 AM · VyOS 1.4 Sagitta
Viacheslav lowered the priority of T3435: NAT rules show corruption from High to Normal.
Dec 21 2021, 8:52 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3435: NAT rules show corruption.

PR https://github.com/vyos/vyos-1x/pull/1114

vyos@r11-roll:~$ show nat destination rules 
Rule       Destination                                        Translation                                        Inbound Interface
----       -----------                                        -----------                                        -----------------
100        port 3389                                          192.0.2.40 port 80                                 eth0      
vyos@r11-roll:~$
Dec 21 2021, 8:52 AM · VyOS 1.4 Sagitta
Viacheslav closed T4083: Cluster heartbeat doesn't start b.c lack of directory /run/heartbeat/ as Resolved.
Dec 21 2021, 8:26 AM · VyOS 1.4 Sagitta
xrobau added a comment to T4017: Adding firewall port ranges makes commit/boot MASSIVELY slow.

I'm going to do what I suggested.

Dec 21 2021, 3:50 AM
Unknown Object (User) added a comment to T4078: A hybrid of "network-group" and "address-group"..

@adestis thank you. This issue isn't critical. It's more for to improve the design and for convenience of our customers.
You can use /32 to add a host, but we have to have the opportunity to add hosts without masks.
For example, if you need to create a group consisting of 1000 (or more random hosts), it's more convenient to use configuration without masks.

Dec 21 2021, 12:11 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta

Dec 20 2021

UnicronNL added a comment to T4086: system login banner is not removed on deletion..

@c-po I will check it!

Dec 20 2021, 10:02 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T4086: system login banner is not removed on deletion..

@UnicronNL can you rechecknon todays rolling image? It behaved differently for me

Dec 20 2021, 9:13 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
UnicronNL added a comment to T4086: system login banner is not removed on deletion..

I set the banners via set system login pre-login 'test' and/or set system login post-login 'test'
and then the banners are set. (and the default is overwritten)

Dec 20 2021, 8:48 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po lowered the priority of T4086: system login banner is not removed on deletion. from Normal to Low.
Dec 20 2021, 8:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T4086: system login banner is not removed on deletion. from Open to Needs testing.
Dec 20 2021, 8:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T4086: system login banner is not removed on deletion..

Well deleting the login banner results in the "default" behavior as expected.

Dec 20 2021, 8:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po claimed T4086: system login banner is not removed on deletion..
Dec 20 2021, 6:26 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po closed T4088: Fix typo in login banner as Resolved.
Dec 20 2021, 6:26 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T4088: Fix typo in login banner from Open to Finished on the VyOS 1.4 Sagitta board.
Dec 20 2021, 6:25 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEXeacc2f5e0210: T4088: login banner: Typo in completion help of banner types (authored by SrividyaA).
Dec 20 2021, 6:25 PM
c-po moved T4088: Fix typo in login banner from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0) board.
Dec 20 2021, 6:25 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
SrividyaA committed rVYOSONEXb47e54a84ad9: T4088: login banner: Typo in completion help of banner types.
Dec 20 2021, 6:15 PM
GitHub <noreply@github.com> committed rVYOSONEX8655699ba3f3: Merge pull request #1113 from srividya0208/T4088 (authored by c-po).
Dec 20 2021, 6:15 PM
Viacheslav added a comment to T4083: Cluster heartbeat doesn't start b.c lack of directory /run/heartbeat/.

PR https://github.com/vyos/vyatta-cluster/pull/5

Dec 20 2021, 5:10 PM · VyOS 1.4 Sagitta
Viacheslav claimed T4083: Cluster heartbeat doesn't start b.c lack of directory /run/heartbeat/.
Dec 20 2021, 4:54 PM · VyOS 1.4 Sagitta
daniil added a comment to T4030: SR-IOV and interface renaming bug .

Similar problem:

Dec 20 2021, 3:22 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4087: IPsec IKE-group proposals limit of 10 pieces from "Task" to "Feature Request".
Dec 20 2021, 1:18 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a comment to T4087: IPsec IKE-group proposals limit of 10 pieces .

There is a reason https://github.com/vyos/vyatta-cfg-vpn/blob/de19cb9b03b78c4e3da93e014764bb2400ffe8a6/scripts/vpn-config.pl#L34

Dec 20 2021, 1:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
SrividyaA created T4088: Fix typo in login banner.
Dec 20 2021, 8:13 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
adestis added a comment to T4078: A hybrid of "network-group" and "address-group"..

@m.korobeinikov why not use network group with /32 host addresses ?

Dec 20 2021, 7:41 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
SrividyaA added a comment to T4086: system login banner is not removed on deletion..

The custom banner is removed after the deletion operation. But it shows the default banner:

Dec 20 2021, 7:37 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) updated subscribers of T4087: IPsec IKE-group proposals limit of 10 pieces .

@Viacheslav found the source of the restriction:

Dec 20 2021, 6:30 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Unknown Object (User) created T4087: IPsec IKE-group proposals limit of 10 pieces .
Dec 20 2021, 2:51 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)

Dec 19 2021

UnicronNL triaged T4086: system login banner is not removed on deletion. as Normal priority.
Dec 19 2021, 4:59 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) changed the status of T4085: Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict from Open to In progress.
Dec 19 2021, 3:25 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Unknown Object (User) created T4085: Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict.
Dec 19 2021, 3:25 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
SrividyaA added a comment to T3435: NAT rules show corruption.

It gives a different error when the translation port option is configured for both the source and destination nat:

Dec 19 2021, 11:18 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXb9a639380790: T4070: natv4: Add "any" for inbound-interface list (authored by SrividyaA).
Dec 19 2021, 10:04 AM
SrividyaA committed rVYOSONEXbd53db9eb63b: T4070: natv4: Add "any" for inbound-interface list.
Dec 19 2021, 10:03 AM
GitHub <noreply@github.com> committed rVYOSONEX7b37b836db55: Merge pull request #1112 from srividya0208/T4070 (authored by c-po).
Dec 19 2021, 10:03 AM
SrividyaA added a comment to T4070: NATv4 : inbound-interface type "any" is missing..

submitted this PR: https://github.com/vyos/vyos-1x/pull/1112

Dec 19 2021, 10:03 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX0f04c1cd73fa: vxlan: T3700: add support for Generic Protocol extension (VXLAN-GPE).
Dec 19 2021, 9:39 AM
c-po changed the status of T3700: Support VLAN tunnel mapping of VLAN aware bridges from Open to In progress.
Dec 19 2021, 7:26 AM · VyOS 1.4 Sagitta
c-po changed the status of T3700: Support VLAN tunnel mapping of VLAN aware bridges, a subtask of T3137: Let VLAN aware bridge approach the behavior of professional equipment, from Open to In progress.
Dec 19 2021, 7:26 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po claimed T3700: Support VLAN tunnel mapping of VLAN aware bridges.
Dec 19 2021, 7:26 AM · VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX0e4840724193: T4084: dehardcode the post-login banner.
Dec 19 2021, 4:21 AM
dmbaturin committed rVYOSONEX4957ef1bd8f1: T4084: dehardcode the post-login banner.
Dec 19 2021, 4:13 AM
dmbaturin created T4084: Dehardcode the default login banner.
Dec 19 2021, 4:06 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
dmbaturin closed T3912: Use a more informative default post-login banner as Resolved.
Dec 19 2021, 4:03 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Dec 18 2021

dmbaturin created 1.3.0.
Dec 18 2021, 6:03 PM
danhusan added a comment to T3913: VRF traffic fails after upgrade from 1.3.0-RC6 to 1.3.0-EPA1/2.

Can also confirm that 1.3.0-epa3 is broken, so something must have changed between epa3 and 202112180443.

Dec 18 2021, 5:35 PM · VyOS 1.3 Equuleus (1.3.0)
danhusan added a comment to T3913: VRF traffic fails after upgrade from 1.3.0-RC6 to 1.3.0-EPA1/2.

Tried 1.3-beta-202112180443, seems to be working as it should now.

Dec 18 2021, 3:23 PM · VyOS 1.3 Equuleus (1.3.0)
dennymartten updated dennymartten.
Dec 18 2021, 3:59 AM

Dec 17 2021

zsdc committed rVYOSONEXac73200e4f0c: logs: T3774: Added CLI options to control atop logs rotation.
Dec 17 2021, 7:08 PM
zsdc committed rVYOSONEX89fdb4fbfa05: logs: T3774: Improved logs CLI.
Dec 17 2021, 7:08 PM
zsdc committed rVYOSONEXa22ba14999a3: logs: T3774: Improved logs config rendering.
Dec 17 2021, 7:08 PM