Page MenuHomeVyOS Platform
Feed All Stories

Mar 21 2022

c-po added a comment to T4308: Op-comm "Show log frr" to view specific protocol logs.

I very much like this idea.

Mar 21 2022, 6:41 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX18483a2f7d18: mirror: T3089: add verify_mirror() also for bond and bridge interfaces.
Mar 21 2022, 5:52 PM
dmbaturin created T4311: CVE-2021-4034: local privilege escalation in PolKit.
Mar 21 2022, 12:16 PM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin closed T4310: CVE-2022-0778: infinite loop in OpenSSL certificate parsing as Resolved.
Mar 21 2022, 12:12 PM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin renamed T4310: CVE-2022-0778: infinite loop in OpenSSL certificate parsing from CVE-2022-0778 to CVE-2022-0778: infinite loop in OpenSSL certificate parsing.
Mar 21 2022, 12:06 PM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin created T4310: CVE-2022-0778: infinite loop in OpenSSL certificate parsing.
Mar 21 2022, 12:06 PM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin changed Issue type from unspecified to bug on T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.
Mar 21 2022, 11:58 AM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin changed Issue type from unspecified to bug on T4234: Show firewall partly broken in 1.3.x.
Mar 21 2022, 11:57 AM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin renamed T4168: IPsec VPN is impossible to restart when DMVPN is configured from Does not possible to reset VPN properly when DMVPN configured to IPsec VPN is impossible to restart when DMVPN is configured.
Mar 21 2022, 11:56 AM · VyOS 1.3 Equuleus ( 1.3.1)
dmbaturin renamed T4165: Custom conntrack rules cannot be deleted from Delete custom conntrack timeout firewall bug to Custom conntrack rules cannot be deleted.
Mar 21 2022, 11:55 AM · VyOS 1.3 Equuleus ( 1.3.1)
fernando closed T4304: [OSPF]import/export filter inter-area prefix as Resolved.
# applied filter on area-ospf
Mar 21 2022, 11:48 AM · VyOS 1.4 Sagitta
daniil created T4309: Support network/address-groups and ipv6-network/ipv6-address-groups in "conntrack ignore".
Mar 21 2022, 10:26 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
dmbaturin edited a custom field on T4152: NHRP shortcut-target holding-time does not work.
Mar 21 2022, 8:11 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin edited a custom field on T4142: Input ifbX interfaces not displayed in op-mode.
Mar 21 2022, 8:10 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin changed Issue type from unspecified to bug on T4081: VRRP health-check script stops working when setting up a sync group.
Mar 21 2022, 8:09 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin renamed T3914: VRRP rfc3768-compatibility doesn't work with unicast peers from vrrp rfc3768-compatibility doesn't work with unicast peers to VRRP rfc3768-compatibility doesn't work with unicast peers.
Mar 21 2022, 8:08 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin changed Issue type from unspecified to feature on T3872: Add configurable telegraf monitoring service.
Mar 21 2022, 8:08 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin renamed T3299: Allow the web proxy service to listen on all IP addresses from Webproxy is prohibited from listening on all IP addresses to Allow the web proxy service to listen on all IP addresses.
Mar 21 2022, 8:07 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin set Issue type to improvement on T3299: Allow the web proxy service to listen on all IP addresses.
Mar 21 2022, 8:06 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Mar 20 2022

SrividyaA created T4308: Op-comm "Show log frr" to view specific protocol logs.
Mar 20 2022, 3:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
n.fort closed T4298: vyos-vm-images: fix ansible group name and remove obsolete empty command as Resolved.
Mar 20 2022, 1:18 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4298: vyos-vm-images: fix ansible group name and remove obsolete empty command.

Ok, thanks for the clarification.
I'm closing this task and marking it as resolved.

Mar 20 2022, 1:17 PM · VyOS 1.4 Sagitta
fett0 <fernando.gmaidana@gmail.com> committed rVYOSONEXc29c6d3d654c: OSPF : T4304: Set import/export filter inter-area prefix.
Mar 20 2022, 8:25 AM
fett0 <fernando.gmaidana@gmail.com> committed rVYOSONEX496d2a5fd8c3: smoketest: Verify export-list rule to ospf-area.
Mar 20 2022, 8:25 AM
fett0 <fernando.gmaidana@gmail.com> committed rVYOSONEX91d19038f9e3: OSPF : T4304: add check access-list is defined.
Mar 20 2022, 8:25 AM
GitHub <noreply@github.com> committed rVYOSONEXf2ebdfa4b856: Merge pull request #1250 from fett0/T4304 (authored by c-po).
Mar 20 2022, 8:25 AM

Mar 19 2022

fernando added a comment to T4163: [BMP-BGP] Routing monitoring feature.

I've been testing , now we are able to configure BMP with load configuration .in latest version 8.2.2(they solved these issues)

Mar 19 2022, 7:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
hakwerk added a comment to T4298: vyos-vm-images: fix ansible group name and remove obsolete empty command.

Yes it is, although PR https://github.com/vyos/vyos-vm-images/pull/25 then caused some new issues but I just now reported those in T4278

Mar 19 2022, 12:26 PM · VyOS 1.4 Sagitta
hakwerk added a comment to T4278: vyos-vm-images: fix vagrant libvirt box.

@higebu it looks like PR https://github.com/vyos/vyos-vm-images/pull/25 caused some new issues (I use the qemu.yaml build). First:

fatal: [localhost]: FAILED! => {"changed": false, "msg": "AnsibleUndefinedVariable: 'enable_dhcp' is undefined"}

I propose to use this in the template (same for enable_ssh):

{% if enable_dhcp | default(True) %}

Or alternatively define those variables in all playbooks.

Mar 19 2022, 12:25 PM · Restricted Project, VyOS 1.4 Sagitta

Mar 18 2022

danielpo added a comment to T4239: static-host-mapping only working on ipv4 addresses.

Sure, but its not being applied in the pdns recursor so I cant use static host mapping for ipv6 in my network, only locally on the vyos host. (It works fine with ipv4).

Mar 18 2022, 8:58 PM · VyOS 1.4 Sagitta
n.fort closed T4286: Fix for firewall ipv6 name address validator as Resolved.
Mar 18 2022, 6:32 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4298: vyos-vm-images: fix ansible group name and remove obsolete empty command.

@hakwerk . Is this solved in PR https://github.com/vyos/vyos-vm-images/pull/24 ??

Mar 18 2022, 6:31 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4299: Firewall - GeoIP filtering.

Splitting ipv4 files, and just adding what needed. In my case, I extracted content from geoip-ipv4.nft and create and include file geoip-CA-ipv4.nft (Canada IPs)

Mar 18 2022, 6:20 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4299: Firewall - GeoIP filtering.

Perhaps only in-use sets can be determined and loaded?

Mar 18 2022, 5:36 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4299: Firewall - GeoIP filtering.

After some custom build and POC, here's what I got:

  • Filtering works, as shown in this table:
Mar 18 2022, 5:27 PM · VyOS 1.4 Sagitta
chesskuo added a comment to T4288: IPsec tunnel will break when ESP timeout.

@SrividyaA Thanks !!!!

Mar 18 2022, 2:15 PM · VyOS 1.4 Sagitta
SrividyaA closed T4307: Policy routing anymore, Commit generating errors as Invalid.
Mar 18 2022, 2:06 PM · VyOS 1.4 Sagitta
SrividyaA added a comment to T4288: IPsec tunnel will break when ESP timeout.

Submitted PR: https://github.com/vyos/vyos-1x/pull/1251

Mar 18 2022, 2:01 PM · VyOS 1.4 Sagitta
danielpo added a comment to T4307: Policy routing anymore, Commit generating errors.

Thanks, Not really sure what happened, but I deleted config.boot and rebooted, Now it works to add a policy again.

Mar 18 2022, 1:52 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4307: Policy routing anymore, Commit generating errors.

Error implies that firewall failed to configure on boot as mangle table is missing. Any logs/config trace from boot?

Mar 18 2022, 1:42 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4307: Policy routing anymore, Commit generating errors.

Can you share configuration that you are deleting? So far, I can't reproduce error

Mar 18 2022, 1:41 PM · VyOS 1.4 Sagitta
danielpo created T4307: Policy routing anymore, Commit generating errors.
Mar 18 2022, 12:45 PM · VyOS 1.4 Sagitta

Mar 17 2022

c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.184 / 5.10.105 to Update Linux Kernel to v5.4.185 / 5.10.106.
Mar 17 2022, 8:02 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dmbaturin triaged T4306: Do not check for ditry repository when building release images as Low priority.
Mar 17 2022, 6:33 PM · VyOS 1.3 Equuleus (1.3.4)
fernando added a comment to T4304: [OSPF]import/export filter inter-area prefix.

PR https://github.com/vyos/vyos-1x/pull/1250

Mar 17 2022, 5:45 PM · VyOS 1.4 Sagitta

Mar 16 2022

dberlin added a comment to T4305: Global log facility does not have consistent default settings, and doesn't change when modified.

My guess, looking now at commit logs, is that T4250 broke this. It looks like we attempted to move the settings to system logs, but the rsyslog part of the config still remains in system syslog, where the default does not match the new logrotate template (and the settings between rsyslog and logrotate can get out of sync).

Mar 16 2022, 9:33 PM · VyOS Rolling
fernando claimed T4304: [OSPF]import/export filter inter-area prefix.
Mar 16 2022, 8:35 PM · VyOS 1.4 Sagitta
dberlin updated the task description for T4305: Global log facility does not have consistent default settings, and doesn't change when modified.
Mar 16 2022, 7:59 PM · VyOS Rolling
dberlin created T4305: Global log facility does not have consistent default settings, and doesn't change when modified.
Mar 16 2022, 7:57 PM · VyOS Rolling
fernando created T4304: [OSPF]import/export filter inter-area prefix.
Mar 16 2022, 7:56 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXa5ae8f831fef: smoketest: remove failfast=True from certian tests.
Mar 16 2022, 7:35 PM
c-po committed rVYOSONEX71805191d1e6: frr: T4302: fix Jinja2 template to match new FRR syntax.
Mar 16 2022, 7:35 PM
c-po committed rVYOSONEXb1449aa2bd20: T3506: loadkey: fix build error.
Mar 16 2022, 7:28 PM
SrividyaA claimed T4288: IPsec tunnel will break when ESP timeout.
Mar 16 2022, 7:11 PM · VyOS 1.4 Sagitta
erkin reopened T3644: Replace GCC with a simpler preprocessor for including nested XML snippets in XML documents as "On hold".

Note: Equuleus still uses the C preprocessor. // substrings (otherwise interpreted as comments) were escaped as \/\/ in op-mode-definitions/generate-public-key-command.xml.in in Equuleus and should be converted back eventually.

Mar 16 2022, 6:56 PM
EasyNet added a comment to T1467: Loopback interface naming and dummy devices.

Hi all,

Mar 16 2022, 3:39 PM
daniil created T4303: BGP neighbor interface v6only fails to commit.
Mar 16 2022, 1:47 PM · VyOS 1.4 Sagitta
egoistdream added a comment to T3976: Missing prefix-list and access-list option from ipv6 route-map.

FRRouting Release 8.2.2 was relased, when we will see this implemented?

Mar 16 2022, 9:28 AM

Mar 15 2022

c-po closed T4302: FRRouting upgrade to release 8.2.2 as Resolved.
Mar 15 2022, 8:51 PM · VyOS 1.4 Sagitta
c-po renamed T4302: FRRouting upgrade to release 8.2.2 from frr: Upgrade to version 8.2 to FRRouting upgrade to release 8.2.2.
Mar 15 2022, 8:28 PM · VyOS 1.4 Sagitta
c-po updated the task description for T4302: FRRouting upgrade to release 8.2.2.
Mar 15 2022, 8:27 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX9f40bd4dd5dd: bonding: T4301: Fixed arp-monitor option (authored by zsdc).
Mar 15 2022, 8:20 PM
zsdc committed rVYOSONEXdf4b544c2997: bonding: T4301: Fixed arp-monitor option.
Mar 15 2022, 8:20 PM
GitHub <noreply@github.com> committed rVYOSONEX80abdb1ff0f3: Merge pull request #1249 from zdc/T4301-sagitta (authored by c-po).
Mar 15 2022, 8:20 PM
c-po committed rVYOSONEXfd9cb1574f2e: frr: T4302: upgrade to version 8.2.
Mar 15 2022, 8:10 PM
c-po changed the status of T4302: FRRouting upgrade to release 8.2.2 from Open to In progress.
Mar 15 2022, 6:04 PM · VyOS 1.4 Sagitta
c-po created T4302: FRRouting upgrade to release 8.2.2.
Mar 15 2022, 6:04 PM · VyOS 1.4 Sagitta
zsdc added a comment to T4301: The "arp-monitor" option in bonding interface settings does not work.

The same issue with set interfaces bonding bond0 arp-monitor interval 'X' option. Also extra conversion between variable types.
Added the fix to the same PR.

Mar 15 2022, 5:01 PM · VyOS 1.4 Sagitta
zsdc edited a custom field on T4301: The "arp-monitor" option in bonding interface settings does not work.
Mar 15 2022, 4:32 PM · VyOS 1.4 Sagitta
zsdc changed the status of T4301: The "arp-monitor" option in bonding interface settings does not work from Open to In progress.

Fixed in https://github.com/vyos/vyos-1x/pull/1249

Mar 15 2022, 4:32 PM · VyOS 1.4 Sagitta
zsdc created T4301: The "arp-monitor" option in bonding interface settings does not work.
Mar 15 2022, 4:01 PM · VyOS 1.4 Sagitta
zsdc changed the status of T4300: Extend list of supported interfaces for Cloud-init Network Configuration from Open to In progress.
Mar 15 2022, 3:45 PM · VyOS 1.4 Sagitta
zsdc created T4300: Extend list of supported interfaces for Cloud-init Network Configuration.
Mar 15 2022, 1:06 PM · VyOS 1.4 Sagitta
fernando closed T4293: Add "set ip-next-hop unchanged" in route-map as Resolved.
Mar 15 2022, 11:28 AM · VyOS 1.4 Sagitta
rob added a comment to T4293: Add "set ip-next-hop unchanged" in route-map.

The PR is merged with the wrong Task number. This can be closed.

Mar 15 2022, 10:08 AM · VyOS 1.4 Sagitta

Mar 14 2022

n.fort committed rVYOSONEXff0e43807789: Firewall: T4286: Correct ipv6-range validator.
Mar 14 2022, 6:56 PM
GitHub <noreply@github.com> committed rVYOSONEX4924a82cbdc7: Merge pull request #1247 from nicolas-fort/T4286 (authored by c-po).
Mar 14 2022, 6:56 PM
SrividyaA added a comment to T4288: IPsec tunnel will break when ESP timeout.

IKEv2 has a different working behavior compared to the IKEv1. IKEv2 provides proper inline rekeying of IKE SAs by use of CREATE_CHILD_SA exchanges. This means that new keys may be established without any interruption of the existing IKE and IPsec SAs.

Mar 14 2022, 1:04 PM · VyOS 1.4 Sagitta
SrividyaA closed T4275: Incorrect val_help for local/remote prefix in ipsec vpn as Resolved.
Mar 14 2022, 9:26 AM · VyOS 1.4 Sagitta

Mar 13 2022

n.fort created T4299: Firewall - GeoIP filtering.
Mar 13 2022, 2:14 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4298: vyos-vm-images: fix ansible group name and remove obsolete empty command.

Update download URL -> PR: https://github.com/vyos/vyos-vm-images/pull/26

Mar 13 2022, 1:33 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4290: BGP source-interface fails to commit.

PR https://github.com/vyos/vyos-1x/pull/1248

Mar 13 2022, 1:01 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4290: BGP source-interface fails to commit from Open to In progress.
Mar 13 2022, 12:57 PM · VyOS 1.4 Sagitta
Viacheslav moved T1856: Support configuring IPSec SA bytes from Open to Finished on the VyOS 1.4 Sagitta board.
Mar 13 2022, 11:46 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)

Mar 12 2022

n.fort added a comment to T4286: Fix for firewall ipv6 name address validator.

PR for 1.4: https://github.com/vyos/vyos-1x/pull/1247

Mar 12 2022, 3:23 PM · VyOS 1.4 Sagitta
zsdc closed T4002: firewall group network-group long names restriction incorrect behavior as Resolved.
Mar 12 2022, 12:13 PM · VyOS 1.3 Equuleus ( 1.3.1)
zsdc moved T4296: Interface config injected by Cloud-Init may interfere with VyOS native from Open to Finished on the VyOS 1.4 Sagitta board.
Mar 12 2022, 12:08 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
zsdc closed T4296: Interface config injected by Cloud-Init may interfere with VyOS native as Resolved.

Fixed for both 1.3 and 1.4.

Mar 12 2022, 12:07 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.183 / 5.10.104 to Update Linux Kernel to v5.4.184 / 5.10.105.
Mar 12 2022, 8:22 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
plett committed rVYOSONEX7549c847c3df: policy: T2493 ip-next-hop unchanged & peer-address.
Mar 12 2022, 8:20 AM
c-po committed rVYOSONEX56febd155792: Merge branch 'T2493-nexthop-unchanged' of https://github.com/plett/vyos-1x into….
Mar 12 2022, 8:20 AM
Viacheslav closed T4265: Add op-mode for bgp flowspec state and routes as Resolved.
Mar 12 2022, 7:44 AM · VyOS 1.4 Sagitta
zsdc committed rVYOSONEXebb524702e1c: logrotate: T4250: Fixed logrotate config generation.
Mar 12 2022, 7:27 AM
GitHub <noreply@github.com> committed rVYOSONEX1e17d1d45a09: Merge pull request #1241 from zdc/T4250-sagitta (authored by c-po).
Mar 12 2022, 7:27 AM
Viacheslav committed rVYOSONEXb1d4be53cd13: bgp: T4265: Add op-mode for bgp flowspec routes.
Mar 12 2022, 7:25 AM
GitHub <noreply@github.com> committed rVYOSONEX2d3f5a03de3e: Merge pull request #1246 from sever-sever/T4265 (authored by c-po).
Mar 12 2022, 7:25 AM

Mar 11 2022

Viacheslav changed the status of T4122: interface ip address config missing after upgrade from 1.2.8 to 1.3.0 (when redirect is configured?) from Resolved to Unknown Status.
Mar 11 2022, 6:32 PM · VyOS 1.3 Equuleus (1.3.3)
n.fort closed T4122: interface ip address config missing after upgrade from 1.2.8 to 1.3.0 (when redirect is configured?) as Resolved.
Mar 11 2022, 6:20 PM · VyOS 1.3 Equuleus (1.3.3)
n.fort updated n.fort.
Mar 11 2022, 6:18 PM
n.fort claimed T4286: Fix for firewall ipv6 name address validator.
Mar 11 2022, 6:17 PM · VyOS 1.4 Sagitta