Page MenuHomeVyOS Platform
Feed All Stories

Aug 22 2022

roedie added a comment to T4526: keepalived-fifo.py unable to load config.

I've create a PR which does the retry part. It retries 10 time every 0.5 seconds until it succeeds or it's out of retries.

Aug 22 2022, 4:14 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
c-po changed the status of T4637: Upgrade to podman 4.2.0 from Open to In progress.
Aug 22 2022, 4:04 PM · VyOS 1.4 Sagitta
c-po created T4637: Upgrade to podman 4.2.0.
Aug 22 2022, 4:03 PM · VyOS 1.4 Sagitta
c-po moved T4629: Raised ConfigErrors contain dict instead of only the dict key from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 22 2022, 4:03 PM · VyOS 1.3 Equuleus (1.3.2)
c-po moved T4632: VLAN-aware bridge not working from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 22 2022, 4:03 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4629: Raised ConfigErrors contain dict instead of only the dict key as Resolved.
Aug 22 2022, 4:03 PM · VyOS 1.3 Equuleus (1.3.2)
c-po added a project to T4632: VLAN-aware bridge not working: VyOS 1.3 Equuleus (1.3.2).
Aug 22 2022, 4:03 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po added a comment to T4632: VLAN-aware bridge not working.

Tested via:

Aug 22 2022, 4:02 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po added a comment to T4632: VLAN-aware bridge not working.

PR https://github.com/vyos/vyos-1x/pull/1484

Aug 22 2022, 4:01 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po changed the status of T4632: VLAN-aware bridge not working from Open to In progress.
Aug 22 2022, 3:53 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
krox2 added a comment to T4526: keepalived-fifo.py unable to load config.

This is what I did (forgot to write it here) with the difference that my sleep timer is 60s as my config has many lines.
Would be good to have this fixed properly.

Aug 22 2022, 2:55 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
ssasso added a comment to T4636: VLAN-Aware bridge not handling local traffic (and not able to perform inter-vlan routing).

I think I found the "problematic" commit.
https://github.com/vyos/vyos-1x/commit/41477cc85208507be55f8db4e412ad78eae764eb#diff-8e6f3b9122c8406707eb59334978290d083995acf7de0323111d4eed1656693dL311

Aug 22 2022, 2:36 PM · VyOS 1.4 Sagitta
ssasso added a comment to T4636: VLAN-Aware bridge not handling local traffic (and not able to perform inter-vlan routing).
Aug 22 2022, 2:26 PM · VyOS 1.4 Sagitta
roedie added a comment to T4526: keepalived-fifo.py unable to load config.

The problem here seems to be that keepalived is started before the complete commit is finished. So conf.get_config_dict() fails to get the config.

Aug 22 2022, 2:21 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
ssasso added a comment to T4636: VLAN-Aware bridge not handling local traffic (and not able to perform inter-vlan routing).

With an older version:

vagrant@s1:~$ sudo bridge vlan
port              vlan-id
eth1              1000 PVID Egress Untagged
eth2              1001 PVID Egress Untagged
br0               1 PVID Egress Untagged
                  1000
                  1001
vagrant@s1:~$ show version
Aug 22 2022, 2:21 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4636: VLAN-Aware bridge not handling local traffic (and not able to perform inter-vlan routing).

I guess it the task T4632

Aug 22 2022, 2:08 PM · VyOS 1.4 Sagitta
itspngu added a comment to T4606: monitor nat destination translation shows missing script.

Can confirm.

Aug 22 2022, 2:06 PM · VyOS 1.4 Sagitta
ssasso created T4636: VLAN-Aware bridge not handling local traffic (and not able to perform inter-vlan routing).
Aug 22 2022, 1:40 PM · VyOS 1.4 Sagitta
Viacheslav assigned T4632: VLAN-aware bridge not working to c-po.
Aug 22 2022, 1:36 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
roedie added a comment to T4633: Change keepalived to v2.2.7.

Created PR for this https://github.com/vyos/vyos-build/pull/256

Aug 22 2022, 1:20 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4634: Bgp neighbor disable-connected-check does not work from Open to In progress.
Aug 22 2022, 1:17 PM · VyOS 1.4 Sagitta
roedie added a comment to T4634: Bgp neighbor disable-connected-check does not work.

Hi, I've created https://github.com/vyos/vyos-1x/pull/1483 for this one.

Aug 22 2022, 11:28 AM · VyOS 1.4 Sagitta
Viacheslav created T4635: Add zebra option ip nht resolve-via-default as default option.
Aug 22 2022, 10:51 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav created T4634: Bgp neighbor disable-connected-check does not work.
Aug 22 2022, 10:37 AM · VyOS 1.4 Sagitta

Aug 21 2022

roedie created T4633: Change keepalived to v2.2.7.
Aug 21 2022, 7:04 PM · VyOS 1.4 Sagitta
a.apostoliuk created T4632: VLAN-aware bridge not working.
Aug 21 2022, 11:59 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

Aug 20 2022

jestabro added a comment to T4628: ConfigTree() throws ValueError() if tagNode contains whitespaces.

@c-po @itspngu , as mentioned above, we have held off on implementing the fix, as there is a compelling argument to disallow whitespace in tag node names, just as it is disallowed in node names in general; making an exception in the case of tag node names invites problems going forward. On the other hand, thanks to the details that you provided, @itspngu, we can implement a workaround for the case of ssh-copy-id; I know of no other instance of the problem. If we do find a necessary use case of whitespace in tag node names in the future, the simple fix can then be implemented.

Aug 20 2022, 9:18 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4631: Add port and protocol to nat66.

PR https://github.com/vyos/vyos-1x/pull/1482

set nat66 destination rule 120 description 'foo'
set nat66 destination rule 120 destination port '4545'
set nat66 destination rule 120 inbound-interface 'eth0'
set nat66 destination rule 120 protocol 'tcp'
set nat66 destination rule 120 source address '2001:db8:2222::/64'
set nat66 destination rule 120 source port '8080'
set nat66 destination rule 120 translation address '2001:db8:1111::1'
set nat66 destination rule 120 translation port '5555'
Aug 20 2022, 4:33 PM · VyOS 1.4 Sagitta
Viacheslav closed T4596: "show openconnect-server sessions" command does not work in the openconnect module, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Aug 20 2022, 2:29 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav closed T4596: "show openconnect-server sessions" command does not work in the openconnect module as Resolved.
Aug 20 2022, 2:29 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4597: Check bind port before assign service HTTPS API and openconnect.

Fix PR https://github.com/vyos/vyos-1x/pull/1481

Aug 20 2022, 2:03 PM · VyOS 1.4 Sagitta
RyVolodya created T4631: Add port and protocol to nat66.
Aug 20 2022, 12:45 PM · VyOS 1.4 Sagitta
c-po added a comment to T4628: ConfigTree() throws ValueError() if tagNode contains whitespaces.

@itspngu you might try tomorrows rolling release and upgrade again. The issue should be resolved - it also helps us to see of the fix works!

Aug 20 2022, 12:29 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4597: Check bind port before assign service HTTPS API and openconnect.

There is a bug with such implementation check for openconnect
It is not possible to create the second user in another commit (as port already bonded)

vyos@r14# run show conf com | match vpn
set vpn openconnect authentication local-users username foo password 'bar'
set vpn openconnect authentication mode local 'password'
set vpn openconnect listen-ports tcp '8443'
set vpn openconnect listen-ports udp '8443'
set vpn openconnect network-settings client-ip-settings subnet '100.64.0.0/24'
set vpn openconnect network-settings name-server '100.64.0.1'
set vpn openconnect ssl ca-certificate 'ca-ocserv'
set vpn openconnect ssl certificate 'srv-ocserv'
[edit]
vyos@r14# commit
No configuration changes to commit
[edit]
vyos@r14# sudo netstat -tulpn | grep 8443
tcp        0      0 0.0.0.0:8443            0.0.0.0:*               LISTEN      23880/ocserv-main   
tcp6       0      0 :::8443                 :::*                    LISTEN      23880/ocserv-main   
udp        0      0 0.0.0.0:8443            0.0.0.0:*                           23880/ocserv-main   
udp6       0      0 :::8443                 :::*                                23880/ocserv-main   
[edit]
vyos@r14# set vpn openconnect authentication local-users username foo2 password 'bar2'
[edit]
vyos@r14# commit
[ vpn openconnect ]
"tcp" port "8443" is used by another service
Aug 20 2022, 10:45 AM · VyOS 1.4 Sagitta
itspngu added a comment to T4628: ConfigTree() throws ValueError() if tagNode contains whitespaces.

Note that a fix for 1.4 will address the user's issue, as he is updating to 1.4-rolling, so the migration will take place upon booting into 1.4.

Aug 20 2022, 9:21 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4596: "show openconnect-server sessions" command does not work in the openconnect module.

It seems after this commit https://github.com/vyos/vyos-1x/commit/1b637f78b870f8ecc4971de5baf0a6fda54c40f7 for T4597
As the port already listens by ocserv itself, maybe we should revert it or change the logic to check that the port bind is not ocserv service

Aug 20 2022, 6:34 AM · VyOS 1.4 Sagitta
tjh added a comment to T4412: commit archive: reboot not working with sftp.

I can confirm this has been the reason I've had issues upgrading from 1.2.x to 1.3.x.
Removing this statement before attempting, I can now upgrade from 1.2 to 1.3 smoothly, no OOM errors or other problems.

Aug 20 2022, 1:46 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta

Aug 19 2022

jestabro changed the status of T4628: ConfigTree() throws ValueError() if tagNode contains whitespaces from Open to On hold.

This is on hold, pending discussion on whether whitespace should be allowed in tag node names in 1.4.

Aug 19 2022, 11:46 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
diogog added a comment to T4596: "show openconnect-server sessions" command does not work in the openconnect module.

The show command worked:

Aug 19 2022, 10:11 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4628: ConfigTree() throws ValueError() if tagNode contains whitespaces.

Note that a fix for 1.4 will address the user's issue, as he is updating to 1.4-rolling, so the migration will take place upon booting into 1.4.

Aug 19 2022, 10:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro added a project to T4628: ConfigTree() throws ValueError() if tagNode contains whitespaces: VyOS 1.4 Sagitta.
Aug 19 2022, 9:59 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro added a comment to T4628: ConfigTree() throws ValueError() if tagNode contains whitespaces.

https://github.com/vyos/vyos1x-config/pull/11

Aug 19 2022, 9:53 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav closed T4611: UPnP rule IP should be a prefix instead of an address as Resolved.
Aug 19 2022, 8:05 PM · VyOS 1.4 Sagitta
Viacheslav closed T4620: UPnP does not work due to incorrect template as Resolved.
Aug 19 2022, 8:05 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4628: ConfigTree() throws ValueError() if tagNode contains whitespaces.

I see the issue. Whitespace is fine in a tag node name as long as the name is quoted, however ConfigTree.to_string() does not re-quote the name, hence on the next migration script, parsing the config file will throw an error. I will investigate the proper solution.

Aug 19 2022, 7:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po claimed T4630: Prevent attempts to use the same interface as a source interface for pseudo-ethernet and MACsec at the same time.
Aug 19 2022, 6:44 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po created T4630: Prevent attempts to use the same interface as a source interface for pseudo-ethernet and MACsec at the same time.
Aug 19 2022, 6:43 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po changed the status of T4629: Raised ConfigErrors contain dict instead of only the dict key from Open to In progress.
Aug 19 2022, 6:35 PM · VyOS 1.3 Equuleus (1.3.2)
c-po added a comment to T4629: Raised ConfigErrors contain dict instead of only the dict key.

PR https://github.com/vyos/vyos-1x/pull/1480

Aug 19 2022, 6:35 PM · VyOS 1.3 Equuleus (1.3.2)
c-po claimed T4629: Raised ConfigErrors contain dict instead of only the dict key.
Aug 19 2022, 6:17 PM · VyOS 1.3 Equuleus (1.3.2)
c-po created T4629: Raised ConfigErrors contain dict instead of only the dict key.
Aug 19 2022, 6:17 PM · VyOS 1.3 Equuleus (1.3.2)
c-po changed the status of T4538: Macsec does not work correctly when the interface status changes. from In progress to Needs testing.
Aug 19 2022, 6:13 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po added a comment to T4538: Macsec does not work correctly when the interface status changes..

PR for vyos 1.3 (equuleus) https://github.com/vyos/vyos-1x/pull/1479

Aug 19 2022, 6:05 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
jestabro claimed T4628: ConfigTree() throws ValueError() if tagNode contains whitespaces.
Aug 19 2022, 5:58 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po created T4628: ConfigTree() throws ValueError() if tagNode contains whitespaces.
Aug 19 2022, 5:56 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T4614: OpenConnect split-dns directive as Resolved.
Aug 19 2022, 2:39 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4614: OpenConnect split-dns directive from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 19 2022, 2:38 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po edited projects for T4614: OpenConnect split-dns directive, added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus (1.3.3).
Aug 19 2022, 2:38 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4616: openconnect: KeyError: 'local_users' as Resolved.
Aug 19 2022, 2:38 PM · VyOS 1.3 Equuleus (1.3.2)
c-po moved T4616: openconnect: KeyError: 'local_users' from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 19 2022, 2:38 PM · VyOS 1.3 Equuleus (1.3.2)
c-po edited projects for T4616: openconnect: KeyError: 'local_users', added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus (1.3.3).
Aug 19 2022, 2:38 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav updated the task description for T4627: Ability to set host part IPv6 address via interface ip token.
Aug 19 2022, 2:05 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav changed the subtype of T4627: Ability to set host part IPv6 address via interface ip token from "Bug" to "Feature Request".
Aug 19 2022, 1:32 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav created T4627: Ability to set host part IPv6 address via interface ip token.
Aug 19 2022, 1:32 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav moved T4619: Static arp is not set if another entry is present from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Aug 19 2022, 12:09 PM · VyOS 1.4 Sagitta
aserkin added a comment to T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .

Nothing helps

Aug 19 2022, 11:15 AM · VyOS 1.4 Sagitta
daniil closed T4619: Static arp is not set if another entry is present as Resolved.

Successfully tested

Aug 19 2022, 9:31 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4626: Error showing nat66 source and destination.
Aug 19 2022, 9:19 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a parent task for T4626: Error showing nat66 source and destination: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Aug 19 2022, 9:19 AM · VyOS 1.4 Sagitta
RyVolodya created T4626: Error showing nat66 source and destination.
Aug 19 2022, 8:40 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4625: Update ocserv to current revision (1.1.6).

There is an example of how we build ocserv for 1.3 https://github.com/vyos/vyos-build/commit/2e1eac5980720d060834540e717f4f8a1189b9b0

Aug 19 2022, 2:49 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

Aug 18 2022

sempervictus created T4625: Update ocserv to current revision (1.1.6).
Aug 18 2022, 11:44 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
pjeevarathinam added a comment to T4588: BGP Peer Group Scaling issues.

I was also suggested to try this -

Aug 18 2022, 11:35 PM · VyOS 1.4 Sagitta (1.4.1)
pjeevarathinam added a comment to T4588: BGP Peer Group Scaling issues.

I tried this command as suggested - no luck.

Aug 18 2022, 11:34 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav closed T4570: Exception when trying to set up VXLAN over Wireguard as Resolved.
Aug 18 2022, 7:39 PM · VyOS 1.4 Sagitta
Viacheslav closed T4613: UPnP configuration without listen option fail as Resolved.
Aug 18 2022, 5:57 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .

Try to add some capabilities, for example, CAP_CHOWN or CAP_DAC_OVERRIDE or something else

sudo nano /etc/systemd/system/vyos-telegraf.service.d/10-override.conf

https://github.com/vyos/vyos-1x/blob/1f880973e221b91ac843a27d2e4c0b3de1880b97/data/templates/monitoring/override.conf.j2#L6

Aug 18 2022, 5:56 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4622: Firewall allow drop packets by TCP MSS size.

PR https://github.com/vyos/vyos-1x/pull/1478

set firewall name FOO rule 10 action 'drop'
set firewall name FOO rule 10 protocol 'tcp'
set firewall name FOO rule 10 tcp flags syn
set firewall name FOO rule 10 tcp mss '1-500'
Aug 18 2022, 5:23 PM · VyOS 1.4 Sagitta
dmbaturin created T4624: Move some op mode commands to "execute" and "produce" command families.
Aug 18 2022, 5:09 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav changed the status of T4622: Firewall allow drop packets by TCP MSS size from Open to In progress.
Aug 18 2022, 4:30 PM · VyOS 1.4 Sagitta
jestabro edited projects for T4146: Nginx should not listen on port 80, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.2).

Discussed in dev meeting today and the conclusion was to move this to 1.3.3.

Aug 18 2022, 3:44 PM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav added a comment to T4610: Firewall with 20K entries cannot load after reboot.

I did my internal tests and can't reproduce it
20K entries applied in 0.20 sec

root@r14:/home/vyos# cat tmp.nft | wc -l
20029
root@r14:/home/vyos# 
root@r14:/home/vyos# sudo time nft -f tmp.nft
real	0m 0.20s
user	0m 0.13s
sys	0m 0.06s
root@r14:/home/vyos#

200K entries in 2 sec

root@r14:/home/vyos# cat tmp.nft | wc -l
200029
root@r14:/home/vyos# 
root@r14:/home/vyos# sudo nft flush ruleset
root@r14:/home/vyos# 
root@r14:/home/vyos# sudo time nft -f tmp.nft
real	0m 1.91s
user	0m 1.20s
sys	0m 0.70s
root@r14:/home/vyos#
Aug 18 2022, 1:49 PM · VyOS 1.4 Sagitta
aserkin added a comment to T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .

The only way to start telegraf with ip vrf exec i found - is to comment out
#User=telegraf
in /etc/systemd/system/vyos-telegraf.service and
chown root:root /run/telegraf

Aug 18 2022, 11:07 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4623: Add show conntrack statistics.
Aug 18 2022, 10:09 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a parent task for T4623: Add show conntrack statistics: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Aug 18 2022, 10:09 AM · VyOS 1.4 Sagitta
Viacheslav created T4623: Add show conntrack statistics.
Aug 18 2022, 10:02 AM · VyOS 1.4 Sagitta

Aug 17 2022

sarthurdev added a comment to T4612: Support arbitrary netmasks in firewall rules.

Not supported at the moment, but we can look into adding it for both ipv4/v6 in 1.4

Aug 17 2022, 8:05 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4605: Firewall change default table names.

While I'm for changing to prefixed tables, I think the issue of tailscale and custom apps should fall under the accepted risk of running custom scripts outside of the config.

Aug 17 2022, 8:02 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4610: Firewall with 20K entries cannot load after reboot.

Any config available to test against?

Aug 17 2022, 7:53 PM · VyOS 1.4 Sagitta
sempervictus added a comment to T3896: Extend ocserv support to allow for per-group configs.

I think that having the configuration stored exclusively in files outside the config file breaks portability as exporting system state through # show | commands won't produce an output sufficient for full state backup of a device.
If the configuration attributes were all in the CLI which then generated the relevant files in the FS, that would address the stateless backing filesystem concern by centralizing the device config as the source of truth.
@SquirePug - could you possibly provide a link to or the contents of the changes you made? Thanks

Aug 17 2022, 4:41 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4622: Firewall allow drop packets by TCP MSS size.
Aug 17 2022, 4:12 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4622: Firewall allow drop packets by TCP MSS size from Firewall allow drop packets by TCP MSS to Firewall allow drop packets by TCP MSS size.
Aug 17 2022, 4:11 PM · VyOS 1.4 Sagitta
Viacheslav created T4622: Firewall allow drop packets by TCP MSS size.
Aug 17 2022, 3:37 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4619: Static arp is not set if another entry is present from Open to Needs testing.
Aug 17 2022, 3:22 PM · VyOS 1.4 Sagitta
Viacheslav moved T4480: add an ability to configure squid acl safe ports and acl ssl safe ports from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Aug 17 2022, 3:20 PM · VyOS 1.4 Sagitta
Viacheslav moved T4598: nat66 - Add exclude options from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Aug 17 2022, 3:19 PM · VyOS 1.4 Sagitta
n.fort closed T4480: add an ability to configure squid acl safe ports and acl ssl safe ports as Resolved.
Aug 17 2022, 1:47 PM · VyOS 1.4 Sagitta
n.fort closed T4598: nat66 - Add exclude options, a subtask of T2518: Add support for IPv6 NAT (NPTv6), as Resolved.
Aug 17 2022, 1:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort closed T4598: nat66 - Add exclude options as Resolved.
Aug 17 2022, 1:46 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4601: dhcp : relay agent IP address issue..

@m.korobeinikov Could you check it in 1.3

Aug 17 2022, 11:31 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta