Page MenuHomeVyOS Platform
Feed All Stories

Jan 6 2022

Viacheslav committed rVYOSONEXfab311fa3c79: op-mode: T4142: Fix for show input ifbX interfaces.
Jan 6 2022, 6:36 PM
GitHub <noreply@github.com> committed rVYOSONEX64349844b98f: Merge pull request #1141 from sever-sever/T4142-equ (authored by c-po).
Jan 6 2022, 6:36 PM
n.fort created T4147: New Firewall Implementation - proposed changes on group implementation.
Jan 6 2022, 6:00 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4109: Extend high-availability/keepalived for support virtual-server lb from In progress to Needs testing.
Jan 6 2022, 5:41 PM · VyOS 1.4 Sagitta
rps added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Do we know if this made it into the 1.3.0 release or is this now a 1.4 issue?

Jan 6 2022, 5:39 PM
sarthurdev moved T4133: Firewall network group error with zone-based firewall rules from Open to In Progress on the VyOS 1.4 Sagitta board.
Jan 6 2022, 5:27 PM · VyOS 1.4 Sagitta, VyConf
sarthurdev moved T4145: Conntrack table not showing after firewall rewriting from Open to In Progress on the VyOS 1.4 Sagitta board.
Jan 6 2022, 5:26 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4145: Conntrack table not showing after firewall rewriting from Open to Needs testing.
Jan 6 2022, 4:21 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4145: Conntrack table not showing after firewall rewriting.

Updates the vyatta-conntrack package to work without legacy firewall and fixes the op-mode commands. Should also fix some conntrack functionality (untested).

Jan 6 2022, 3:23 PM · VyOS 1.4 Sagitta
jestabro closed T4146: Nginx should not listen on port 80 as Unknown Status.
Jan 6 2022, 2:21 PM · VyOS 1.3 Equuleus (1.3.5)
jestabro committed rVYOSONEX2c6fe0aeef09: https: T4146: do not listen on port 80.
Jan 6 2022, 2:11 PM
jestabro moved T3785: Add unicode support to configtree backend from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 6 2022, 1:56 PM · VyOS 1.3 Equuleus (1.3.2)
jestabro closed T3785: Add unicode support to configtree backend, a subtask of T2941: Using a non-ASCII character in the description field causes UnicodeDecodeError in configsource.py, as Unknown Status.
Jan 6 2022, 1:56 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jestabro closed T3785: Add unicode support to configtree backend as Unknown Status.
Jan 6 2022, 1:56 PM · VyOS 1.3 Equuleus (1.3.2)
jestabro updated the task description for T3785: Add unicode support to configtree backend.
Jan 6 2022, 1:55 PM · VyOS 1.3 Equuleus (1.3.2)
jestabro triaged T4146: Nginx should not listen on port 80 as Normal priority.
Jan 6 2022, 1:41 PM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav renamed T4145: Conntrack table not showing after firewall rewriting from Conntrack table not showing after firewall after firewall rewriting to Conntrack table not showing after firewall rewriting.
Jan 6 2022, 12:22 PM · VyOS 1.4 Sagitta
Viacheslav created T4145: Conntrack table not showing after firewall rewriting.
Jan 6 2022, 12:07 PM · VyOS 1.4 Sagitta
n.fort updated the task description for T4144: Firewall address-group - Improve error messages.
Jan 6 2022, 11:49 AM · VyOS 1.4 Sagitta
n.fort created T4144: Firewall address-group - Improve error messages.
Jan 6 2022, 11:49 AM · VyOS 1.4 Sagitta
Viacheslav assigned T3914: VRRP rfc3768-compatibility doesn't work with unicast peers to c-po.

Fixed for 1.4 in T4128 with update "keepalived".
In 1.3 we don't update this pkg and it still has this bug.

Jan 6 2022, 11:32 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) created T4143: Wrong section for Cloud-init User-Data for OVA images.
Jan 6 2022, 11:15 AM
Viacheslav closed T4130: Firewall state policy errors chain as Resolved.
Jan 6 2022, 11:14 AM · VyOS 1.4 Sagitta
Viacheslav closed T4135: Declare zone policy firewall without local zone errors as Resolved.
Jan 6 2022, 11:10 AM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX79f6f7061c0c: firewall: zone-policy: T4133: Prevent firewall from trying to clean-up zone….
Jan 6 2022, 8:28 AM
GitHub <noreply@github.com> committed rVYOSONEX83f281c9a3c6: Merge pull request #1139 from sarthurdev/firewall (authored by c-po).
Jan 6 2022, 8:28 AM
c-po closed T4141: Set high-availability vrrp sync-group without members error as Resolved.
Jan 6 2022, 8:26 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po committed rVYOSONEX0a91c5de32b5: vrrp: T4141: bugfix missing {% if %} clause when adding sync-groups.
Jan 6 2022, 8:26 AM
jestabro committed rVYOSONEX5b8550dc1837: config: T3785: drop restriction to ascii in decode.
Jan 6 2022, 1:31 AM

Jan 5 2022

jestabro added a comment to T3785: Add unicode support to configtree backend.

relaxes the condition to escape non-ascii bytes. Updating the commit id in the Dockerfile and relaxing the ascii restriction in configsource.py will allow unicode chars in config.

Jan 5 2022, 6:34 PM · VyOS 1.3 Equuleus (1.3.2)
sarthurdev changed the status of T4133: Firewall network group error with zone-based firewall rules from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1139

Jan 5 2022, 5:10 PM · VyOS 1.4 Sagitta, VyConf
Viacheslav moved T4142: Input ifbX interfaces not displayed in op-mode from Open to Backport Candidates on the VyOS 1.4 Sagitta board.
Jan 5 2022, 4:20 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX5fdf4e598834: op-mode: T4142: Fix for show input ifbX interfaces.
Jan 5 2022, 4:13 PM
GitHub <noreply@github.com> committed rVYOSONEXe4b368b10aee: Merge pull request #1138 from sever-sever/T4142 (authored by jestabro).
Jan 5 2022, 4:13 PM
Viacheslav added a comment to T4142: Input ifbX interfaces not displayed in op-mode.

PR https://github.com/vyos/vyos-1x/pull/1138

vyos@r11-roll:~$ show interfaces input 
Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface        IP Address                        S/L  Description
---------        ----------                        ---  -----------
ifb0             -                                 u/u  FOO
ifb1             -                                 u/u  FOO1
vyos@r11-roll:~$
Jan 5 2022, 4:07 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a project to T4142: Input ifbX interfaces not displayed in op-mode: VyOS 1.3 Equuleus ( 1.3.1).
Jan 5 2022, 3:47 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4142: Input ifbX interfaces not displayed in op-mode from Open to In progress.
Jan 5 2022, 3:42 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav created T4142: Input ifbX interfaces not displayed in op-mode.
Jan 5 2022, 3:41 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
erkin changed the status of T4038: Rewrite `vyatta-image-tools.pl` in Python, a subtask of T3355: Remove all remaining legacy Vyatta code, from Open to In progress.
Jan 5 2022, 2:27 PM · VyOS Rolling
erkin changed the status of T4038: Rewrite `vyatta-image-tools.pl` in Python from Open to In progress.
Jan 5 2022, 2:27 PM · Restricted Project, VyOS 1.4 Sagitta
sarthurdev changed the status of T4133: Firewall network group error with zone-based firewall rules from Open to In progress.
Jan 5 2022, 2:07 PM · VyOS 1.4 Sagitta, VyConf
sarthurdev changed the status of T3635: Add ability to use mDNS repeater with VRRP from In progress to Needs testing.
Jan 5 2022, 1:55 PM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX8cbfda931dba: keepalived: T4109: Update configd-include.json to reflect filename change.
Jan 5 2022, 1:01 PM
GitHub <noreply@github.com> committed rVYOSONEX397dc7a97a43: Merge pull request #1137 from sarthurdev/current (authored by c-po).
Jan 5 2022, 1:01 PM
Viacheslav updated the task description for T4141: Set high-availability vrrp sync-group without members error.
Jan 5 2022, 12:49 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4141: Set high-availability vrrp sync-group without members error from Open to Confirmed.
Jan 5 2022, 12:44 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a project to T4141: Set high-availability vrrp sync-group without members error: VyOS 1.4 Sagitta.
Jan 5 2022, 12:44 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav created T4141: Set high-availability vrrp sync-group without members error.
Jan 5 2022, 12:37 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav created T4140: Lack of SNMP IANA mibs.
Jan 5 2022, 12:06 PM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX96f577ef8272: zone-policy: T4135: Raise error when using an invalid "from" zone..
Jan 5 2022, 7:23 AM
GitHub <noreply@github.com> committed rVYOSONEXb87fd7cb75f7: Merge pull request #1136 from sarthurdev/firewall (authored by c-po).
Jan 5 2022, 7:23 AM
sarthurdev changed the status of T4135: Declare zone policy firewall without local zone errors from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1136

Jan 5 2022, 12:40 AM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4135: Declare zone policy firewall without local zone errors from Open to In progress.
Jan 5 2022, 12:33 AM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEXe536b6a037e6: smoketest: shim: Optimise speed of `lsof` command.
Jan 5 2022, 12:23 AM
GitHub <noreply@github.com> committed rVYOSONEXa893c8d8167e: Merge pull request #1135 from sarthurdev/current (authored by c-po).
Jan 5 2022, 12:23 AM
sarthurdev committed rVYOSONEX459c7079bebe: firewall: zone-policy: T2199: T4130: Fixes for firewall, state-policy and zone….
Jan 5 2022, 12:23 AM
GitHub <noreply@github.com> committed rVYOSONEX7eadd337bed0: Merge pull request #1134 from sarthurdev/firewall (authored by c-po).
Jan 5 2022, 12:23 AM

Jan 4 2022

atoy40 created T4139: Wireless interface member of a bridge.
Jan 4 2022, 8:35 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T4134: Incorrect firewall protocol completion help uppercase and duplicates as Resolved.
Jan 4 2022, 6:20 PM · VyOS 1.4 Sagitta
Viacheslav closed T4132: Impossible to show a specific firewall group as Resolved.
Jan 4 2022, 6:18 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX55bf54afb750: firewall: T4132: Fix for op-mode show firewall group.
Jan 4 2022, 5:24 PM
GitHub <noreply@github.com> committed rVYOSONEXf809139c04e5: Merge pull request #1131 from sever-sever/T4132 (authored by c-po).
Jan 4 2022, 5:24 PM
GitHub <noreply@github.com> committed rVYOSONEX7330c4eff26f: Merge pull request #1132 from sever-sever/T4134 (authored by c-po).
Jan 4 2022, 5:24 PM
Viacheslav committed rVYOSONEX5f2c965d28f7: firewall: T4134: Fix completion help for protocols.
Jan 4 2022, 5:24 PM
Viacheslav committed rVYOSONEXf0d4f6060034: keepalived: T4109: Add XML for high-availability virtual-server.
Jan 4 2022, 5:22 PM
Viacheslav committed rVYOSONEX2817f86a0faf: conntrack-sync: T4109: Change script name for vrrp.
Jan 4 2022, 5:22 PM
Viacheslav committed rVYOSONEXacefbacf7966: keepalived: T4109: Change smoketest correct path vrrp.
Jan 4 2022, 5:22 PM
Viacheslav committed rVYOSONEX362812150565: keepalived: T4109: Add high-availability virtual-server.
Jan 4 2022, 5:22 PM
GitHub <noreply@github.com> committed rVYOSONEX367c2964d6b8: Merge pull request #1121 from sever-sever/T4109 (authored by c-po).
Jan 4 2022, 5:22 PM
Viacheslav assigned T4135: Declare zone policy firewall without local zone errors to sarthurdev.
Jan 4 2022, 4:04 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4134: Incorrect firewall protocol completion help uppercase and duplicates.

PR https://github.com/vyos/vyos-1x/pull/1132

Jan 4 2022, 1:32 PM · VyOS 1.4 Sagitta
Unknown Object (User) renamed T4085: Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict from Rewrite l2tp/pptp remote access to get_config_dict to Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict.
Jan 4 2022, 1:23 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav renamed T4134: Incorrect firewall protocol completion help uppercase and duplicates from Some firewall protocol completion help in uppercase to Incorrect firewall protocol completion help uppercase and duplicates.
Jan 4 2022, 1:21 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4134: Incorrect firewall protocol completion help uppercase and duplicates from Open to In progress.
Jan 4 2022, 12:26 PM · VyOS 1.4 Sagitta
Viacheslav claimed T4134: Incorrect firewall protocol completion help uppercase and duplicates.
Jan 4 2022, 12:26 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4138: NAT configuration allows to set incorrect port range and invalid port from NAT configuration allows to set incorrect port range to NAT configuration allows to set incorrect port range and invalid port.
Jan 4 2022, 12:14 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4137: Firewall group configuration allows to set incorrect port range and invalid port from Firewall group configuration allows incorrect port range to Firewall group configuration allows to set incorrect port range and invalid port.
Jan 4 2022, 12:12 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4137: Firewall group configuration allows to set incorrect port range and invalid port.
Jan 4 2022, 12:10 PM · VyOS 1.4 Sagitta
Viacheslav created T4138: NAT configuration allows to set incorrect port range and invalid port.
Jan 4 2022, 12:05 PM · VyOS 1.4 Sagitta
Viacheslav created T4137: Firewall group configuration allows to set incorrect port range and invalid port.
Jan 4 2022, 12:00 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4132: Impossible to show a specific firewall group.

PR https://github.com/vyos/vyos-1x/pull/1131

vyos@r11-roll:~$ show firewall group 
Possible completions:
  <Enter>       Execute the current command
  FOO           Show firewall group
  FOO2
  NETV6
  PORTGRP
Jan 4 2022, 11:47 AM · VyOS 1.4 Sagitta
Viacheslav claimed T4132: Impossible to show a specific firewall group.
Jan 4 2022, 11:37 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4131: Show firewall group incorrect format members.

In 1.3 it looks like just ipset -L:

vyos@r4:~$ show firewall group 
Name       : FOO2
Type       : address
References : none
Members    :
             203.0.113.3
Jan 4 2022, 9:53 AM · VyOS 1.4 Sagitta
c-po added a comment to T4131: Show firewall group incorrect format members.

Can you please add output from VyOS 1.3 as reference?

Jan 4 2022, 6:52 AM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX84a83ecc4c78: firewall: T4130: Fix firewall state-policy errors.
Jan 4 2022, 4:11 AM
sarthurdev committed rVYOSONEX9213d9cc7bcd: firewall: T4130: Add state-policy test to firewall smoketest.
Jan 4 2022, 4:11 AM
GitHub <noreply@github.com> committed rVYOSONEX993b87458456: Merge pull request #1130 from sarthurdev/firewall (authored by c-po).
Jan 4 2022, 4:11 AM
syncer merged T4136: Firewall State Policy entries fail to load. into T4130: Firewall state policy errors chain.
Jan 4 2022, 1:19 AM · VyOS 1.4 Sagitta
syncer merged task T4136: Firewall State Policy entries fail to load. into T4130: Firewall state policy errors chain.
Jan 4 2022, 1:18 AM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4136: Firewall State Policy entries fail to load..

Duplicate of T4130

Jan 4 2022, 12:45 AM · VyOS 1.4 Sagitta
JamesGreenlee created T4136: Firewall State Policy entries fail to load..
Jan 4 2022, 12:36 AM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4130: Firewall state policy errors chain from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1130

Jan 4 2022, 12:14 AM · VyOS 1.4 Sagitta

Jan 3 2022

sarthurdev changed the status of T4130: Firewall state policy errors chain from Open to In progress.
Jan 3 2022, 9:58 PM · VyOS 1.4 Sagitta
Viacheslav closed T4065: IPSEC configuration error: connection to unix:///var/run/charon.ctl failed: No such file or directory as Resolved.

Fixed in https://github.com/vyos/vyatta-cfg-vpn/pull/56

Jan 3 2022, 9:09 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3914: VRRP rfc3768-compatibility doesn't work with unicast peers.

Maybe fixed in T4128

Jan 3 2022, 9:05 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav renamed T4135: Declare zone policy firewall without local zone errors from Declare zone policy firewall without local zone erros to Declare zone policy firewall without local zone errors.
Jan 3 2022, 8:02 PM · VyOS 1.4 Sagitta
Viacheslav created T4135: Declare zone policy firewall without local zone errors.
Jan 3 2022, 8:00 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4133: Firewall network group error with zone-based firewall rules from Firewall network group error to Firewall network group error with zone-based firewall rules.
Jan 3 2022, 7:47 PM · VyOS 1.4 Sagitta, VyConf
Viacheslav added a comment to T4133: Firewall network group error with zone-based firewall rules.

To reproduce it should be zone-policy firewall rules, for example:

Jan 3 2022, 7:46 PM · VyOS 1.4 Sagitta, VyConf
c-po assigned T4133: Firewall network group error with zone-based firewall rules to sarthurdev.
Jan 3 2022, 7:39 PM · VyOS 1.4 Sagitta, VyConf