Page MenuHomeVyOS Platform
Feed All Stories

Jul 21 2022

Cheeze_It added a comment to T4257: Discussion on changing BGP autonomous system number syntax.

Put in pull request https://github.com/vyos/vyos-1x/pull/1423

Jul 21 2022, 6:38 PM · VyOS 1.4 Sagitta
c-po closed T4555: fastnetmon: add IPv6 support as Resolved.
Jul 21 2022, 6:23 PM · VyOS 1.4 Sagitta
c-po created T4555: fastnetmon: add IPv6 support.
Jul 21 2022, 6:23 PM · VyOS 1.4 Sagitta
c-po added a comment to T4553: Allow to set ban time on ddos-protection configuration.

That's what commit 5e510e45f6f9 did :)

Jul 21 2022, 6:16 PM · VyOS 1.4 Sagitta
c-po added a project to T4553: Allow to set ban time on ddos-protection configuration: VyOS 1.4 Sagitta.
Jul 21 2022, 6:16 PM · VyOS 1.4 Sagitta
jestabro removed a subtask for T2719: Standardized op mode script structure: T4554: Implement GraphQL resolvers for standardized op-mode scripts.
Jul 21 2022, 6:14 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
jestabro removed a parent task for T4554: Implement GraphQL resolvers for standardized op-mode scripts: T2719: Standardized op mode script structure.
Jul 21 2022, 6:14 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4554: Implement GraphQL resolvers for standardized op-mode scripts: T2719: Standardized op mode script structure.
Jul 21 2022, 6:13 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T2719: Standardized op mode script structure: T4554: Implement GraphQL resolvers for standardized op-mode scripts.
Jul 21 2022, 6:13 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
jestabro added a subtask for T4544: Generate schema definitions from standardized op-mode scripts: T4554: Implement GraphQL resolvers for standardized op-mode scripts.
Jul 21 2022, 6:13 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4554: Implement GraphQL resolvers for standardized op-mode scripts: T4544: Generate schema definitions from standardized op-mode scripts.
Jul 21 2022, 6:13 PM · VyOS 1.4 Sagitta
jestabro created T4554: Implement GraphQL resolvers for standardized op-mode scripts.
Jul 21 2022, 6:12 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4553: Allow to set ban time on ddos-protection configuration.

As I remember fastnetmon wasn’t rewritten to dict
And requires manual set default value in config dictionary

Jul 21 2022, 6:06 PM · VyOS 1.4 Sagitta
c-po triaged T4553: Allow to set ban time on ddos-protection configuration as Wishlist priority.
Jul 21 2022, 5:20 PM · VyOS 1.4 Sagitta
c-po closed T4553: Allow to set ban time on ddos-protection configuration as Resolved.
Jul 21 2022, 5:20 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXa06a2b58cac1: fastnetmon: T4553: band-time - zero value is prohibited.
Jul 21 2022, 5:19 PM
c-po committed rVYOSONEX5e510e45f6f9: fastnetmon: T4553: add processing of XML defaultValue definitions.
Jul 21 2022, 5:19 PM
c-po committed rVYOSONEXf40fe618f2a3: fastnetmon: T4553: Allow to configure ban_time instead of 1900s default value (authored by aalmenar).
Jul 21 2022, 5:19 PM
aalmenar created T4553: Allow to set ban time on ddos-protection configuration.
Jul 21 2022, 5:00 PM · VyOS 1.4 Sagitta
v.huti added a comment to T4180: Support for QoS Policy Propagation via BGP (QPPB).

You can find the latest version of the demo implementation here:

  1. volodymyrhuti/linux/tree/QPPB_DEMO_V1.1
  2. volodymyrhuti/frr/tree/QPPB_DEMO_V1.1
Jul 21 2022, 1:56 PM · VyOS Rolling
a.apostoliuk added a comment to T4537: MACsec not working with cipher gcm-aes-256.

I installed wpa_supplicant version 2.10. But it did not help.
I compared debugs of wpa_supplicant and found the difference

Jul 21 2022, 12:33 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav updated the task description for T4552: Unable to reset IPsec IPv6 peer.
Jul 21 2022, 10:58 AM · VyOS 1.4 Sagitta
Viacheslav created T4552: Unable to reset IPsec IPv6 peer.
Jul 21 2022, 10:56 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4551: IPsec rekeying collisions bug.
Jul 21 2022, 10:43 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4551: IPsec rekeying collisions bug.
Jul 21 2022, 10:40 AM · VyOS 1.4 Sagitta
Viacheslav created T4551: IPsec rekeying collisions bug.
Jul 21 2022, 10:22 AM · VyOS 1.4 Sagitta
vfreex created T4550: router-advert: Add deprecate-prefix & decrement-lifetimes options.
Jul 21 2022, 8:01 AM · VyOS 1.4 Sagitta

Jul 20 2022

dmbaturin committed rVYOSONEX812a4fc3f306: T2719: prototype of an op mode command runner.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXa55a47c6417e: T2719: fix commands in the op mode definitions.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEX3a9d9b4297c5: T2719: correctly handle the raw argument for all show_* commands.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXa90faa4ddcd9: T2719: fix module import path.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXf08b850f2974: T2719: handle the case when script subcommand is not given.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXaeb9491a7ac3: T2719: correct script calls in 'show arp'.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXdb5952f2bb09: T2719: add reset command to the neighbor script.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXf0e0a2393b48: T2719: make re functions usage in vyos.opmode more consistent.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEX352713d5948d: T2719: correct module path in the neighbor script.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEX53c9b500f085: T2719: correct neighbor commands for IPv6.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEX651eb5794d22: T2719: handle non-existent interfaces in the neighbor script.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEX81f7df57eeb0: T2719: use _is_show for detecting show functions.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXb8e2a0650168: T2719: add general support for boolean options to generative op mode.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXfbde12af711b: T2719: initial version of the route op mode script.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEX1b425cd96b51: T2719: convert 'show version' to the new op mode style.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXdc4b80f1aee3: T2719: convert the 'show system memory' script to the new style.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXd94344008085: T2719: update op mode CLI definition for 'show version'.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXee5f697065eb: T2719: rework 'show hardware cpu *' commands in the new style.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEX8d8c14b53408: T2719: patch for general support for boolean options (authored by jestabro).
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXe64fcfd60142: T2719: fix a stray empty key in the CPU data dict.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEX39fbe8eecf9f: T2719: fix indentation in vyos.opmode.
Jul 20 2022, 8:33 PM
dmbaturin committed rVYOSONEXf9e835c41643: T2719: fix unused imports.
Jul 20 2022, 8:33 PM
GitHub <noreply@github.com> committed rVYOSONEXf424d84f4179: Merge pull request #1351 from dmbaturin/genop (authored by jestabro).
Jul 20 2022, 8:33 PM
n.fort placed T4475: route-map does not support ipv6 peer up for grabs.
Jul 20 2022, 5:16 PM · VyOS 1.3 Equuleus (1.3.4)
n.fort added a comment to T4475: route-map does not support ipv6 peer.

Modyfing file pointed by @Viacheslav , makes ipv6 peer option available.
But while testing config, it's not possible to insert an ipv6 address: validator rejects input.
Validator used: syntax:expression: exec "/opt/vyatta/sbin/vyatta-policy.pl --check-peer-syntax $VAR(@)"; "peer must be either an IP or local"

Jul 20 2022, 5:10 PM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav moved T4475: route-map does not support ipv6 peer from Open to Finished on the VyOS 1.4 Sagitta board.
Jul 20 2022, 4:32 PM · VyOS 1.3 Equuleus (1.3.4)
purpendicular created T4549: Email notification functionality.
Jul 20 2022, 4:27 PM · VyOS Rolling
daniil closed T4056: Traffic policy not set in live configuration as Resolved.
Jul 20 2022, 3:45 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav added a comment to T4056: Traffic policy not set in live configuration.

@daniil Could you re-check it?

Jul 20 2022, 3:44 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav added a comment to T4537: MACsec not working with cipher gcm-aes-256.

It seems wpa_supplicant doesn't support GCM-AES-256
https://w1.fi/wpa_supplicant/devel/dir_4261af1259721e3e39e0d2dd7354b511.html

Jul 20 2022, 3:31 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4545: Rewrite show nat source rules.

PR https://github.com/vyos/vyos-1x/pull/1420

Jul 20 2022, 1:04 PM · VyOS 1.4 Sagitta
zsdc created T4548: GRUB loader configuration rework.
Jul 20 2022, 12:01 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav updated the task description for T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets.
Jul 20 2022, 11:46 AM · VyOS 1.4 Sagitta
Viacheslav created T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets.
Jul 20 2022, 11:42 AM · VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4537: MACsec not working with cipher gcm-aes-256.

I have just tested it again. Macsec does not work.

Jul 20 2022, 10:52 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
goodNETnick <pknet@ya.ru> committed rVYOSONEXd59c232a6fbf: route-map: T4542: match prefix-len BGP notice.
Jul 20 2022, 9:37 AM
GitHub <noreply@github.com> committed rVYOSONEX38d753f83088: Merge pull request #1419 from goodNETnick/rm-pref-len (authored by c-po).
Jul 20 2022, 9:37 AM
Unknown Object (User) added a comment to T4542: route-map: "match prefix-len" incorrect behavior.

PR with notice:
https://github.com/vyos/vyos-1x/pull/1419

Jul 20 2022, 9:26 AM · VyOS 1.4 Sagitta

Jul 19 2022

zsdc changed the status of T4546: Does not connect Cisco spoke to VyOS hub. from Confirmed to In progress.

PR for 1.4: https://github.com/vyos/vyos-1x/pull/1418

Jul 19 2022, 7:16 PM · VyOS 1.4 Sagitta
zsdc changed the status of T4546: Does not connect Cisco spoke to VyOS hub. from Open to Confirmed.
Jul 19 2022, 7:01 PM · VyOS 1.4 Sagitta
RyVolodya created T4546: Does not connect Cisco spoke to VyOS hub..
Jul 19 2022, 6:58 PM · VyOS 1.4 Sagitta
Viacheslav claimed T4545: Rewrite show nat source rules.
Jul 19 2022, 5:04 PM · VyOS 1.4 Sagitta
Viacheslav created T4545: Rewrite show nat source rules.
Jul 19 2022, 5:04 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T4544: Generate schema definitions from standardized op-mode scripts.
Jul 19 2022, 1:28 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T3993: Extend HTTP API GraphQL support: T4544: Generate schema definitions from standardized op-mode scripts.
Jul 19 2022, 1:09 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4544: Generate schema definitions from standardized op-mode scripts: T3993: Extend HTTP API GraphQL support.
Jul 19 2022, 1:09 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4544: Generate schema definitions from standardized op-mode scripts: T2719: Standardized op mode script structure.
Jul 19 2022, 1:07 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T2719: Standardized op mode script structure: T4544: Generate schema definitions from standardized op-mode scripts.
Jul 19 2022, 1:07 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
jestabro triaged T4544: Generate schema definitions from standardized op-mode scripts as Normal priority.
Jul 19 2022, 1:06 PM · VyOS 1.4 Sagitta
zsdc triaged T4542: route-map: "match prefix-len" incorrect behavior as Low priority.
Jul 19 2022, 12:41 PM · VyOS 1.4 Sagitta
zsdc changed the status of T4542: route-map: "match prefix-len" incorrect behavior from Open to Confirmed.

This is a behavior "by design". The prefix-len option cannot be used for BGP routes. We should add this notice to the CLI.
Check: http://docs.frrouting.org/en/latest/routemap.html#clicmd-match-ip-address-prefix-len-0-32

Jul 19 2022, 12:41 PM · VyOS 1.4 Sagitta
Viacheslav created T4543: Show source nat statistics shows incorrect interface.
Jul 19 2022, 12:07 PM · VyOS 1.4 Sagitta
aalmenar added a comment to T160: Support NAT64.

While i like the inclusion of NAT64 inside vyos (And the effort vfreex has made), i believe that tayga is not the way to go, it was last updated on 2010-12-12 according to the readme in it. Jool on the other hand has a bigger throughput being kernel module. The only issue i believe is the module compilation cause configuration is quite easy.

Jul 19 2022, 11:05 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po added a comment to T4542: route-map: "match prefix-len" incorrect behavior.

Can you check with the latest rolling release? it uses FRR 8.3

Jul 19 2022, 9:21 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4542: route-map: "match prefix-len" incorrect behavior.

Probably a problem with FRR

Jul 19 2022, 6:59 AM · VyOS 1.4 Sagitta
Unknown Object (User) renamed T4542: route-map: "match prefix-len" incorrect behavior from route-map: "match prefix-len" does not function correctly to route-map: "match prefix-len" incorrect behavior.
Jul 19 2022, 6:55 AM · VyOS 1.4 Sagitta
Unknown Object (User) created T4542: route-map: "match prefix-len" incorrect behavior.
Jul 19 2022, 6:52 AM · VyOS 1.4 Sagitta
c-po added a comment to T4515: Reduce telegraf binary size.

Will be fixed in the next rolling release. Thanks!

Jul 19 2022, 6:33 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEX0c10980c37d2: smoketest: telegraf: use generic service availability check.
Jul 19 2022, 6:32 AM
c-po added a comment to T4533: Radius clients don’t have simple permissions.

@dannyvanderaa this is true - but as of VyOS 1.3 there is no longer an operator mode due to security issues. Operator level was removed, it will come back once the entire codebase rewrite is complete.

Jul 19 2022, 6:27 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dannyvanderaa added a comment to T4533: Radius clients don’t have simple permissions.

Several access levels are required on our end. In my opinion an operator / read only user should also be able to perform some basic commands (like ping and arp)

Jul 19 2022, 5:34 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

Jul 18 2022

c-po committed rVYOSONEX82d8494d349e: macsec: T4537: support online ciper and source-interface re-configuration.
Jul 18 2022, 9:48 PM
c-po committed rVYOSONEX393355f7feaa: macsec: T4537: allow 32-byte keys for gcm-aes-256.
Jul 18 2022, 9:48 PM
c-po added a comment to T4537: MACsec not working with cipher gcm-aes-256.

Also cipher changes require a reboot. Nice bug - thanks for this riddle ;)

Jul 18 2022, 8:34 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po claimed T4537: MACsec not working with cipher gcm-aes-256.
Jul 18 2022, 8:27 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
l.austenfeld added a comment to T4515: Reduce telegraf binary size.

This change currently removes the nstat plugin which is used in the configuration (https://github.com/vyos/vyos-1x/blob/current/data/templates/monitoring/telegraf.j2#L108).
This results in telegraf crashing on startup. Adding the plugin back to the https://github.com/vyos/vyos-build/blob/current/packages/telegraf/plugins/inputs/all/all.go file fixes this (Tested by compiling a patched package and installing it on a broken install).
As far as I can tell this is the only missing plugin.

Jul 18 2022, 6:06 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4537: MACsec not working with cipher gcm-aes-256.

Also, there are no any Inbound/Outbound packets with aes-256

vyos@r14:~$ sudo ip -s macsec show
7: macsec1: protect on validate strict sc off sa off encrypt off send_sci on end_station off scb off replay off 
    cipher suite: GCM-AES-256, using ICV length 16
    TXSC: eeb5e212f04f0001 on SA 0
    stats: OutPktsUntagged InPktsUntagged OutPktsTooLong InPktsNoTag InPktsBadTag InPktsUnknownSCI InPktsNoSCI InPktsOverrun
                         0              0              0           0            0                0           0             0
    stats: OutPktsProtected OutPktsEncrypted OutOctetsProtected OutOctetsEncrypted
                          0                0                  0                  0
    offload: off 
vyos@r14:~$

But service starts without issues:

vyos@r14:~$ sudo systemctl status wpa_supplicant-macsec@vxlan1.service
● wpa_supplicant-macsec@vxlan1.service - WPA supplicant daemon (macsec-specific version)
     Loaded: loaded (/lib/systemd/system/wpa_supplicant-macsec@.service; disabled; vendor preset: enabled)
     Active: active (running) since Mon 2022-07-18 20:07:16 EEST; 18min ago
   Main PID: 1802 (wpa_supplicant)
      Tasks: 1 (limit: 9411)
     Memory: 4.4M
        CPU: 101ms
     CGroup: /system.slice/system-wpa_supplicant\x2dmacsec.slice/wpa_supplicant-macsec@vxlan1.service
             └─1802 /sbin/wpa_supplicant -c/run/wpa_supplicant/vxlan1.conf -Dmacsec_linux -ivxlan1
Jul 18 2022, 5:42 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEXfc395620cc8d: bgp: T4490: check peer-group for AFI/SAFI before issuing warning.
Jul 18 2022, 3:58 PM
c-po added a comment to T4490: BGP- warning message that AFI/SAFI is needed to establish the neighborship.
set protocols bgp local-as 200
set protocols bgp peer-group foo remote-as external
set protocols bgp peer-group foo address-family ipv4-unicast  ipv6-unicast
set protocols bgp neighbor 1.1.1.1 peer-group foo
commit
Jul 18 2022, 3:46 PM · VyOS 1.4 Sagitta
c-po added a comment to T4541: Improve `strip-private` to make stripped configs reproducible.

This might confuse the users as now there is sensitive information again, but a different one.

Jul 18 2022, 11:53 AM · VyOS Rolling
zsdc created T4541: Improve `strip-private` to make stripped configs reproducible.
Jul 18 2022, 11:47 AM · VyOS Rolling
c-po closed T4539: qat: update Intel QuickAssist release version 1.7.L.4.16.0-00017, a subtask of T3318: Update Linux Kernel to v5.4.208 / 5.10.142, as Resolved.
Jul 18 2022, 11:33 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4539: qat: update Intel QuickAssist release version 1.7.L.4.16.0-00017 as Resolved.
Jul 18 2022, 11:33 AM · VyOS 1.4 Sagitta