Page MenuHomeVyOS Platform
Feed All Stories

Feb 1 2022

c-po closed T4220: Commit broke dhclient 78b247b724f74bdabab0706aaa7f5b00e5809bc1 as Resolved.
Feb 1 2022, 7:02 AM · VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso) from Open to Confirmed.
Feb 1 2022, 12:32 AM · VyOS 1.4 Sagitta
mshipman updated the task description for T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso).
Feb 1 2022, 12:27 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso).

Confirm
VyOS 1.4-rolling-202201291849

Feb 1 2022, 12:25 AM · VyOS 1.4 Sagitta
mshipman added a comment to T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso).

My hunch would be that this is the breaking commit, given the context:

Feb 1 2022, 12:00 AM · VyOS 1.4 Sagitta

Jan 31 2022

mshipman created T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso).
Jan 31 2022, 9:58 PM · VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.174 / 5.10.94 to Update Linux Kernel to v5.4.175 / 5.10.95.
Jan 31 2022, 8:59 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEX494ca8ffa043: upnpd: T3420: code cleanup.
Jan 31 2022, 8:57 PM
c-po committed rVYOSONEX2ac8376ca1b7: upnpd: T3420: use proper include directives.
Jan 31 2022, 8:57 PM
c-po committed rVYOSONEX3dc698f18bc8: smoketest: upnpd: T3420: refine code and re-use paths.
Jan 31 2022, 8:57 PM
hensur committed rVYOSONEXc6c562eca6ff: policy: T4219: add local-route(6) incoming-interface.
Jan 31 2022, 6:27 PM
GitHub <noreply@github.com> committed rVYOSONEXb3066e73ff48: Merge pull request #1196 from hensur/current-ipv6-local-route-iif (authored by c-po).
Jan 31 2022, 6:27 PM
sarthurdev committed rVYOSONEXed67750b94e8: firewall: T4218: Adds a prefix to all user defined chains.
Jan 31 2022, 6:26 PM
sarthurdev committed rVYOSONEX985a9e8536cb: firewall: T4216: Add support for negated firewall groups.
Jan 31 2022, 6:26 PM
sarthurdev committed rVYOSONEX8532f2c391e8: policy: T4213: Fix duplicate commands from multiple rules with single table.
Jan 31 2022, 6:26 PM
sarthurdev committed rVYOSONEXfafd25143d46: firewall: T2199: Add constraint for tagnode names.
Jan 31 2022, 6:26 PM
sarthurdev committed rVYOSONEXff2cc45f8ba6: firewall: T2199: Fix errors when referencing an empty chain.
Jan 31 2022, 6:26 PM
GitHub <noreply@github.com> committed rVYOSONEX36e54482a242: Merge pull request #1199 from sarthurdev/T4218 (authored by c-po).
Jan 31 2022, 6:26 PM
GitHub <noreply@github.com> committed rVYOSONEX3aa1ec3f03a9: Merge pull request #1198 from vyos/force_to_list (authored by c-po).
Jan 31 2022, 6:26 PM
danielpo added a comment to T4223: policy route cannot have several entries with the same table.

Thanks!😀

Jan 31 2022, 5:25 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4216: Firewall: can't use negated groups in firewall rules from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1199

Jan 31 2022, 5:06 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4218: firewall: rule name is not allowed to start with a number from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1199

Jan 31 2022, 5:06 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4223: policy route cannot have several entries with the same table from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1199

Jan 31 2022, 5:05 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4223: policy route cannot have several entries with the same table from Open to In progress.

I already have a fix for this from your comment on T4213. Will have it included in a PR shortly.

Jan 31 2022, 4:47 PM · VyOS 1.4 Sagitta
danielpo created T4223: policy route cannot have several entries with the same table.
Jan 31 2022, 4:39 PM · VyOS 1.4 Sagitta
SrividyaA created T4222: Support for TWAMP as round-trip metric.
Jan 31 2022, 3:11 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX84d790b65e13: T4221: add force_to_list Jinja2 filter.
Jan 31 2022, 12:56 PM
dmbaturin triaged T4221: Add a template filter for converting scalars to single-item lists as Low priority.
Jan 31 2022, 12:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1)

Jan 30 2022

dmbaturin committed rVYOSONEX35f7cac7750c: T4193: handle groups with only one element correctly.
Jan 30 2022, 1:28 PM
dmbaturin committed rVYOSONEX0c265e420bdf: T4193: bail out early if bridge firewall policy is not assigned.
Jan 30 2022, 1:28 PM
dmbaturin committed rVYOSONEX793185dc09d5: T4193: Remove a debug print.
Jan 30 2022, 1:28 PM
dmbaturin committed rVYOSONEXdcad12c21979: T4193: fix module imports.
Jan 30 2022, 1:28 PM
dmbaturin committed rVYOSONEX3700c3780ede: firewall-bridge: T4193: Checks if firewall or group not configured (authored by Viacheslav).
Jan 30 2022, 1:28 PM
danielpo created T4220: Commit broke dhclient 78b247b724f74bdabab0706aaa7f5b00e5809bc1.
Jan 30 2022, 8:09 AM · VyOS 1.4 Sagitta
Rhongomiant added a comment to T4206: Policy Based Routing with DHCP Interface Issue.

I don't know what I'm building. How can I be sure I'm actually building 1.3.0 rather than 1.4? I ask because when I boot off the build I compiled I get the following message at the start of the boot process. Is it 1.3.0 or sagitta (1.4)?

Jan 30 2022, 6:14 AM · VyOS 1.3 Equuleus (1.3.2)

Jan 29 2022

Unknown Object (User) added a comment to T4218: firewall: rule name is not allowed to start with a number.

The same situation if you set the number or special symbol.

Jan 29 2022, 11:18 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4218: firewall: rule name is not allowed to start with a number from Open to In progress.
Jan 29 2022, 10:34 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4216: Firewall: can't use negated groups in firewall rules from Confirmed to In progress.
Jan 29 2022, 10:34 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4214: [DHCP] static route dhcp-interface issues.

I've checked the same scenario on the cisco router.

Jan 29 2022, 10:04 PM · VyOS 1.5 Circinus, VyOS Rolling
hensur committed rVYOSONEXc501ae0fdc5d: policy: T4151: remove all previous rules on edit.
Jan 29 2022, 6:41 PM
hensur committed rVYOSONEX87d93efc27d8: policy: T4151: bugfix smoketest.
Jan 29 2022, 6:41 PM
GitHub <noreply@github.com> committed rVYOSONEX0a0d4abc02da: Merge pull request #1195 from hensur/current-ipv6-local-route (authored by c-po).
Jan 29 2022, 6:41 PM
sarthurdev committed rVYOSONEX1c828cc5a1dc: firewall: T4178: Fix dict_keys issue with tcp flags.
Jan 29 2022, 6:31 PM
GitHub <noreply@github.com> committed rVYOSONEXd679e9517657: Merge pull request #1197 from sarthurdev/T4178_1 (authored by c-po).
Jan 29 2022, 6:31 PM
n.fort closed T4153: Monitor bandwidth-test initiate not working as Resolved.
Jan 29 2022, 5:33 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jack9603301 committed rVYOSONEX14750f65db2d: upnpd: T3420: Add miniupnpd-nftables package.
Jan 29 2022, 5:08 PM
jack9603301 committed rVYOSONEX600d0c76750a: upnpd: T3420: Add the UPnP command line.
Jan 29 2022, 5:08 PM
jack9603301 committed rVYOSONEXb57b048623d0: upnpd: T3420: Implement features.
Jan 29 2022, 5:08 PM
jack9603301 committed rVYOSONEXc7cdb87fa09a: upnpd: T3420: Fix IPv6 errors.
Jan 29 2022, 5:08 PM
GitHub <noreply@github.com> committed rVYOSONEX8aa7ea8f6c84: Merge pull request #789 from jack9603301/T3420 (authored by dmbaturin).
Jan 29 2022, 5:08 PM
hensur added a comment to T4219: support incoming-interface (iif) in local PBR .

PR: https://github.com/vyos/vyos-1x/pull/1196

Jan 29 2022, 12:51 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
hensur claimed T4219: support incoming-interface (iif) in local PBR .
Jan 29 2022, 12:40 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
hensur created T4219: support incoming-interface (iif) in local PBR .
Jan 29 2022, 12:39 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
hensur added a comment to T4151: IPV6 local PBR Support.

PR: https://github.com/vyos/vyos-1x/pull/1195

Jan 29 2022, 12:33 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Rhongomiant added a comment to T4207: Policy Based Route Issue with Rules for Multiple Tables.

Failover is handled by my firewall which is upstream of VyOS which I am using more as a router than anything. The commit you listed I believe is actually the fix for T4206, not for this, but I can certainly try that to see if I'm up and running and to see if the issue I'm reporting here is resolved, since I have only tried this setup in 1.3.0 RC6. I'm not sure why you'd think I'd need " failover with custom hook-scripts" for this issue. All I'm trying to do is have a PBR for traffic with the destination IP of local VyOS interfaces to use the main table rather than the vrf table. I also have an issue where if I ping the IP on the FIOS WAN interface from upstream, the reply traffic from the VyOS is sent downstream to the FiOS gateway, so this fails. However, the VyOS isn't doing that for the WOW! WAN interface, and I get the replies as expected. So it seems there are strange things happening. Either things not being cleaned up and/or not being set up right.

Jan 29 2022, 11:27 AM · Bugs, VyOS 1.3 Equuleus (1.3.8)

Jan 28 2022

Unknown Object (User) added a comment to T4215: Change the description of the "reboot in" command..

Good question. I missed this moment.
So, if you want to reload in some minutes, VYOS offered you two variants:

  1. To choose between 1 and 99
  2. To set time when you want to reload VYOS if 99 minutes too short for you (for example 10:00, 12:45, 23:59, and so on)

But descriptions of thees command doesn't have enough information about it.

Jan 28 2022, 9:52 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po assigned T4218: firewall: rule name is not allowed to start with a number to sarthurdev.
Jan 28 2022, 9:22 PM · VyOS 1.4 Sagitta
c-po created T4218: firewall: rule name is not allowed to start with a number.
Jan 28 2022, 9:22 PM · VyOS 1.4 Sagitta
c-po closed T4217: firewall: port-group requires protocol to be set - but not in VyOS 1.3 as Resolved.
Jan 28 2022, 9:21 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX78b247b724f7: dhclient: T3392: remove /usr/sbin prefix from iproute2 ip command.
Jan 28 2022, 9:16 PM
c-po committed rVYOSONEX137c9b8b4c01: firewall: T4217: install protocol tcp_udp if port group does not use a protocol.
Jan 28 2022, 9:16 PM
c-po changed the status of T4217: firewall: port-group requires protocol to be set - but not in VyOS 1.3 from Open to In progress.
Jan 28 2022, 9:11 PM · VyOS 1.4 Sagitta
c-po created T4217: firewall: port-group requires protocol to be set - but not in VyOS 1.3.
Jan 28 2022, 9:11 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4209: Firewall incorrect handler for recent count and time.

I've actually found a way to define this properly, resulting rule now looks like below:

tcp dport { 22 } add @FOO_30 { ip saddr limit rate over 4/minute burst 4 packets } counter packets 3 bytes 156 reject comment "FOO-30"
ct state { new } tcp dport { 22 } counter packets 5 bytes 260 return comment "FOO-40"
Jan 28 2022, 6:00 PM · VyOS 1.4 Sagitta
Viacheslav closed T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses as Resolved.
Jan 28 2022, 5:31 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
sarthurdev changed the status of T4216: Firewall: can't use negated groups in firewall rules from Open to Confirmed.
Jan 28 2022, 5:02 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4198: Error shown on commit.

@adestis https://github.com/vyos/vyatta-config-mgmt/tree/equuleus

Jan 28 2022, 4:56 PM · VyOS 1.3 Equuleus (1.3.0)
adestis added a comment to T4198: Error shown on commit.

I could commit a merge request but I have not figured out in which repo the file is located.

Jan 28 2022, 3:38 PM · VyOS 1.3 Equuleus (1.3.0)
adestis added a comment to T4198: Error shown on commit.

@Viacheslav steps to reproduce:

Jan 28 2022, 3:35 PM · VyOS 1.3 Equuleus (1.3.0)
adestis updated the task description for T4198: Error shown on commit.
Jan 28 2022, 3:15 PM · VyOS 1.3 Equuleus (1.3.0)
mTx87 created T4216: Firewall: can't use negated groups in firewall rules.
Jan 28 2022, 2:51 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4214: [DHCP] static route dhcp-interface issues.

I'm not completely sure that behavior in 1.4 is the correct one.
If I add these two routes:

vyos@vyos# set protocols static route 8.8.8.8/32 dhcp-interface eth0
vyos@vyos# set protocols static route 8.8.8.8/32 dhcp-interface eth1

I would expect to see both in main routing table, as it is in 1.3 version. I would expect that latest command doesn't overwrite previous command, as user may want/need redundancy for that particular route.
So I think that adding routes to main routing table and not overwriting previous entry is the correct behavior.
IMO in 1.3:

  • Second route is added and not overwriten in main routing table -- OK
  • But in vyos cli, second route overwrites the first one, when both routes should remain present in config --- Not OK
Jan 28 2022, 1:45 PM · VyOS 1.5 Circinus, VyOS Rolling
thomasjsn added a comment to T4209: Firewall incorrect handler for recent count and time.

I agree with @johannrichard, having recent "change" behavior is probably going to cause some confusion.

Jan 28 2022, 1:11 PM · VyOS 1.4 Sagitta
johannrichard added a comment to T4209: Firewall incorrect handler for recent count and time.

I‘m no expert here nor extremely strong opiniated. My thoughts though: if theres no exact equivalent, why try to re-implement the recent functionality with nftables at „all“ cost?

Jan 28 2022, 1:02 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4215: Change the description of the "reboot in" command..

Why is it 1-99?
If I want to reboot the router in 1500 min?

Jan 28 2022, 10:25 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
danielpo added a comment to T4213: ipv6 policy routing not working anymore.

Hi again, I found another bug, if I have two policy routes with the same table it tries to create the table twice, and it doesn't work because the table is already created:

Jan 28 2022, 5:59 AM · VyOS 1.4 Sagitta
aohanian added a comment to T4214: [DHCP] static route dhcp-interface issues.

It's good to know that it works as expected on 1.4-rolling. Is it possible to get a fix for 1.3?

Jan 28 2022, 3:24 AM · VyOS 1.5 Circinus, VyOS Rolling
Unknown Object (User) created T4215: Change the description of the "reboot in" command..
Jan 28 2022, 2:18 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Unknown Object (User) closed T4115: reboot in <x> not working as expected as Resolved.

We didn't receive the customer's request.
The timers work without problems.
I'll open a design request to see the range 1-99.

Jan 28 2022, 2:05 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4214: [DHCP] static route dhcp-interface issues.

I have emulated the same scenario in to vyos VyOS 1.4-rolling-202201041316
And it works well.
{

vyos@vyos:~$ show dhcp client leases
interface  : eth0
ip address : 172.168.32.146     [Active]
subnet mask: 255.255.255.0
domain name: localdomain        [overridden by domain-name set using CLI]
router     : 172.168.32.2
name server: 172.168.32.2
dhcp server: 172.168.32.254
lease time : 1800
last update: Fri Jan 28 01:09:31 UTC 2022
expiry     : Fri Jan 28 01:39:30 UTC 2022
reason     : RENEW
Jan 28 2022, 1:47 AM · VyOS 1.5 Circinus, VyOS Rolling

Jan 27 2022

sarthurdev closed T4213: ipv6 policy routing not working anymore as Resolved.

Good to hear, going to mark this as resolved.

Jan 27 2022, 10:08 PM · VyOS 1.4 Sagitta
danielpo added a comment to T4213: ipv6 policy routing not working anymore.

Hi,
I applied your new policy-route.py manually, and now my ipv6 pbr works again!! Thanks a lot!

Jan 27 2022, 9:49 PM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX25e97e0b0224: policy: T4213: Fix rule creation/deletion for IPv6 policy routes.
Jan 27 2022, 9:29 PM
GitHub <noreply@github.com> committed rVYOSONEXa23cc19ad88b: Merge pull request #1194 from sarthurdev/T4213 (authored by c-po).
Jan 27 2022, 9:28 PM
sarthurdev changed the status of T4213: ipv6 policy routing not working anymore from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1194

Jan 27 2022, 9:23 PM · VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.172 / 5.10.92 to Update Linux Kernel to v5.4.174 / 5.10.94.
Jan 27 2022, 9:07 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
sarthurdev added a comment to T4209: Firewall incorrect handler for recent count and time.
In T4209#117429, @sdev wrote:

Would changing the guide to use limit rate 4/minute achieve the same target functionality?

What is the practical difference between limit rate and recent? Is it just two different ways of accomplishing the same?

Jan 27 2022, 8:38 PM · VyOS 1.4 Sagitta
thomasjsn added a comment to T4209: Firewall incorrect handler for recent count and time.
In T4209#117429, @sdev wrote:

Would changing the guide to use limit rate 4/minute achieve the same target functionality?

Jan 27 2022, 8:34 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4209: Firewall incorrect handler for recent count and time from Open to In progress.
Jan 27 2022, 8:30 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4209: Firewall incorrect handler for recent count and time.

I've come up with a working idea how to implement but would like feedback before submitting a PR.

Jan 27 2022, 8:29 PM · VyOS 1.4 Sagitta
fernando created T4214: [DHCP] static route dhcp-interface issues.
Jan 27 2022, 7:53 PM · VyOS 1.5 Circinus, VyOS Rolling
sarthurdev changed the status of T4213: ipv6 policy routing not working anymore from Open to In progress.

Thanks for the report, I believe I know what's caused it to break. Hopefully will have a fix in for the build tomorrow.

Jan 27 2022, 5:19 PM · VyOS 1.4 Sagitta
danielpo updated the task description for T4213: ipv6 policy routing not working anymore.
Jan 27 2022, 4:38 PM · VyOS 1.4 Sagitta
danielpo created T4213: ipv6 policy routing not working anymore.
Jan 27 2022, 4:38 PM · VyOS 1.4 Sagitta
hensur added a comment to T4151: IPV6 local PBR Support.

I'm looking into it. I'm going to add a test with multiple commits. Good catch, I didn't test this. :)

Jan 27 2022, 4:13 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
sarthurdev added a comment to T2199: Rewrite firewall in new XML/Python style.

@johannrichard Hey sorry I didn't see your comment, I suggest we move the discussion to the dedicated task: https://phabricator.vyos.net/T4209

Jan 27 2022, 3:33 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev moved T2199: Rewrite firewall in new XML/Python style from Open to In Progress on the VyOS 1.4 Sagitta board.
Jan 27 2022, 3:29 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev closed T3762: Support network and address groups for policy ipv6-route, a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Jan 27 2022, 3:28 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev closed T3762: Support network and address groups for policy ipv6-route as Resolved.

This was included with the new firewall, going to mark as resolved.

Jan 27 2022, 3:28 PM · VyOS 1.4 Sagitta
sarthurdev closed T3495: Modernising port/protocol definitions, a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Jan 27 2022, 3:25 PM · VyOS 1.4 Sagitta (1.4.0-epa2)