Page MenuHomeVyOS Platform
Feed All Stories

Aug 25 2022

c-po committed rVYOSONEXb7a8bb398121: proxy: T4642: allow https proxy transports.
Aug 25 2022, 5:25 PM
GitHub <noreply@github.com> committed rVYOSONEXbf45a3c86afb: Merge pull request #1494 from c-po/equuleus-proxy-t4642 (authored by c-po).
Aug 25 2022, 5:25 PM
c-po changed the status of T4647: Add Google Virtual NIC (gVNIC) support from Open to In progress.
Aug 25 2022, 5:15 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4647: Add Google Virtual NIC (gVNIC) support from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 25 2022, 5:14 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po edited a custom field on T4647: Add Google Virtual NIC (gVNIC) support.
Aug 25 2022, 5:14 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po edited projects for T4647: Add Google Virtual NIC (gVNIC) support, added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus.
Aug 25 2022, 5:14 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4647: Add Google Virtual NIC (gVNIC) support from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 25 2022, 5:14 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po added a comment to T4647: Add Google Virtual NIC (gVNIC) support.

PR for 1.3 https://github.com/vyos/vyos-build/pull/258

Aug 25 2022, 5:14 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav closed T4643: Smoketest exclude either sstp or openconnect from pki-misc default listen port as Resolved.
Aug 25 2022, 5:07 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX73be77ec42d0: proxy: T4642: allow https proxy transports.
Aug 25 2022, 4:59 PM
c-po committed rVYOSONEX02e3dbbe53ac: ssh: T2185: use reload-or-restart on configuration changes.
Aug 25 2022, 4:59 PM
c-po committed rVYOSONEXcfde4b498634: ifconfig: T2223: add vlan switch for Section.interfaces().
Aug 25 2022, 4:59 PM
c-po committed rVYOSONEX7d83077102b5: ntp: T2185: use reload-or-restart on configuration changes.
Aug 25 2022, 4:59 PM
c-po committed rVYOSONEX85e0d4ecbf69: telegraf: T3872: re-use existing XML building blocks.
Aug 25 2022, 4:59 PM
c-po committed rVYOSONEX1b5b6d8b9d3e: telegraf: T4617: add VRF support.
Aug 25 2022, 4:59 PM
Viacheslav committed rVYOSONEX53bc8022e3be: op-mode: T4645: Show nat source stat missing argument --family.
Aug 25 2022, 4:55 PM
GitHub <noreply@github.com> committed rVYOSONEX6d82dab3c2e8: Merge pull request #1497 from sever-sever/T4645 (authored by c-po).
Aug 25 2022, 4:55 PM
Viacheslav committed rVYOSONEXfa91f567b7b5: smoketest: T4643: Change openconnect default port.
Aug 25 2022, 4:54 PM
GitHub <noreply@github.com> committed rVYOSONEX4f5f01f6a4f0: Merge pull request #1495 from sever-sever/T4643 (authored by c-po).
Aug 25 2022, 4:54 PM
Viacheslav committed rVYOSONEXac885f3e0912: sstp: T4644: Check SSTP bind port before commit.
Aug 25 2022, 4:54 PM
GitHub <noreply@github.com> committed rVYOSONEXa12a392ef7c3: Merge pull request #1496 from sever-sever/T4644 (authored by c-po).
Aug 25 2022, 4:54 PM
c-po edited a custom field on T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> .
Aug 25 2022, 4:52 PM · VyOS 1.4 Sagitta
c-po changed the status of T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> from Open to In progress.
Aug 25 2022, 4:52 PM · VyOS 1.4 Sagitta
zsdc assigned T4647: Add Google Virtual NIC (gVNIC) support to c-po.
Aug 25 2022, 2:30 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
zsdc updated the task description for T4647: Add Google Virtual NIC (gVNIC) support.
Aug 25 2022, 2:13 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
zsdc created T4647: Add Google Virtual NIC (gVNIC) support.
Aug 25 2022, 2:12 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4202: NFT: Zone policies fail to apply when "l2tp+" is in the interface list.

We have to replace it in migration scripts if it is already not done

Aug 25 2022, 1:53 PM · VyOS 1.4 Sagitta
v.huti added a comment to T4180: Support for QoS Policy Propagation via BGP (QPPB).

The latest version of the demo can be found here:

  1. volodymyrhuti/frr/tree/QPPB_DEMO_V1.3
  2. volodymyrhuti/xdp_qppb
Aug 25 2022, 1:47 PM · VyOS Rolling
RyVolodya updated the task description for T4646: USB serial output console does not work.
Aug 25 2022, 12:50 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
RyVolodya created T4646: USB serial output console does not work.
Aug 25 2022, 12:43 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Viacheslav added a comment to T4645: show nat source statistics lack argument --family.

PR https://github.com/vyos/vyos-1x/pull/1497

vyos@r14:~$ show nat source statistics 
Rule    Packets    Bytes    Interface
------  ---------  -------  -----------
100     1279       107896   eth0
120     1          60       eth1
vyos@r14:~$
Aug 25 2022, 12:33 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4645: show nat source statistics lack argument --family from Open to In progress.
Aug 25 2022, 12:16 PM · VyOS 1.4 Sagitta
Viacheslav created T4645: show nat source statistics lack argument --family.
Aug 25 2022, 12:16 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4606: monitor nat destination translation shows missing script.

The easiest way it add vyatta-nat-translations.pl scripts to the op-mode script directory or rewrite it to the python.

Aug 25 2022, 11:09 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2408: DHCP Relay upstream and downstream interfaces.

Also discussed this configuration:

set service dhcp-relay <tag> interface eth0 upstream
set service dhcp-relay <tag> interface eth1 downstream
set service dhcp-relay <tag> server <x.x.x.x>
set service dhcp-relay <tag> relay-options hop-count 1
set service dhcp-relay <tag> relay-options upsteam-port 547
Aug 25 2022, 10:27 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4644: Check bind port before assign vpn sstp from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/1496

vyos@r14# commit
[ vpn sstp ]
"tcp" port "443" is used by another service
Aug 25 2022, 10:25 AM · VyOS 1.4 Sagitta
Viacheslav created T4644: Check bind port before assign vpn sstp.
Aug 25 2022, 9:32 AM · VyOS 1.4 Sagitta
Viacheslav edited projects for T1070: SWANCTL: DMVPN: ALL peers are deleted in swan when opennhrp tries to delete ONE peer, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.0).
Aug 25 2022, 8:00 AM · Bugs, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
zsdc added a project to T1070: SWANCTL: DMVPN: ALL peers are deleted in swan when opennhrp tries to delete ONE peer: VyOS 1.4 Sagitta.
Aug 25 2022, 7:48 AM · Bugs, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
Viacheslav changed the status of T4643: Smoketest exclude either sstp or openconnect from pki-misc default listen port from Open to In progress.
Aug 25 2022, 7:13 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4643: Smoketest exclude either sstp or openconnect from pki-misc default listen port.

PR https://github.com/vyos/vyos-1x/pull/1495

Aug 25 2022, 7:08 AM · VyOS 1.4 Sagitta
Viacheslav created T4643: Smoketest exclude either sstp or openconnect from pki-misc default listen port.
Aug 25 2022, 6:44 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4597: Check bind port before assign service HTTPS API and openconnect from In progress to Needs testing.
Aug 25 2022, 6:33 AM · VyOS 1.4 Sagitta
Viacheslav closed T4626: Error showing nat66 source and destination, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Aug 25 2022, 6:32 AM · VyOS Rolling
Viacheslav closed T4626: Error showing nat66 source and destination as Resolved.
Aug 25 2022, 6:32 AM · VyOS 1.4 Sagitta
Viacheslav closed T4622: Firewall allow drop packets by TCP MSS size as Resolved.
Aug 25 2022, 6:32 AM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXfd15f9d2ab6a: firewall: T4622: Add TCP MSS option.
Aug 25 2022, 4:27 AM
GitHub <noreply@github.com> committed rVYOSONEX20090229009d: Merge pull request #1478 from sever-sever/T4622 (authored by c-po).
Aug 25 2022, 4:27 AM

Aug 24 2022

zsdc closed T4113: Incorrect GRUB configuration parsing as Unknown Status.
Aug 24 2022, 8:16 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po moved T4630: Prevent attempts to use the same interface as a source interface for pseudo-ethernet and MACsec at the same time from In Progress to Finished on the VyOS 1.4 Sagitta board.
Aug 24 2022, 7:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po closed T4633: Change keepalived to v2.2.7 as Resolved.
Aug 24 2022, 7:45 PM · VyOS 1.4 Sagitta
c-po closed T4641: prefix-list allows ipv6 prefix as input as Resolved.
Aug 24 2022, 7:45 PM · VyOS 1.4 Sagitta
c-po moved T4633: Change keepalived to v2.2.7 from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 24 2022, 7:45 PM · VyOS 1.4 Sagitta
c-po moved T4641: prefix-list allows ipv6 prefix as input from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 24 2022, 7:45 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXeb4a7ee3afc0: T4630: can not use same source-interface for macsec and pseudo-ethernet.
Aug 24 2022, 7:45 PM
Viacheslav committed rVYOSONEX8d4205a99a9f: nat66: T4626: Rewrite op-mode show nat66 rules.
Aug 24 2022, 6:58 PM
GitHub <noreply@github.com> committed rVYOSONEXaaa83a8c19cf: Merge pull request #1491 from sever-sever/T4626 (authored by c-po).
Aug 24 2022, 6:58 PM
a.apostoliuk committed rVYOSONEX38ab693dc975: opennhrp: T1070: Fixed removal all SAs in script.
Aug 24 2022, 6:58 PM
GitHub <noreply@github.com> committed rVYOSONEX7577d45ef4bd: Merge pull request #1490 from aapostoliuk/T1070-sagitta (authored by c-po).
Aug 24 2022, 6:58 PM
c-po moved T4642: proxy: hyphen not allowed in proxy URL from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Aug 24 2022, 6:07 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po added a comment to T4642: proxy: hyphen not allowed in proxy URL.

PR for equuleus https://github.com/vyos/vyos-1x/pull/1494

Aug 24 2022, 6:07 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po moved T4642: proxy: hyphen not allowed in proxy URL from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 24 2022, 6:06 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po committed rVYOSONEXc4159ee846d4: smoketest: bgp: T4634: validate "disable-connected-check" option.
Aug 24 2022, 6:01 PM
c-po committed rVYOSONEXbfa13e367d0b: proxy: T4642: bugfix regex, add hyphen to allow list.
Aug 24 2022, 6:01 PM
c-po committed rVYOSONEXb7feed29627c: op-mode: T4390: migrate "show log vpn" to journalctl.
Aug 24 2022, 6:01 PM
c-po committed rVYOSONEX254285bb5d70: op-mode: extend "monitor log vpn" option.
Aug 24 2022, 6:01 PM
c-po committed rVYOSONEXf5360b98703e: ipsec: T2185: use systemd to start/stop service.
Aug 24 2022, 6:01 PM
roedie committed rVYOSONEX5fa3468ff2d6: BGP: T4634: Allow configuration of disable-connected-check.
Aug 24 2022, 5:41 PM
GitHub <noreply@github.com> committed rVYOSONEX4d34c858d05a: Merge pull request #1483 from roedie/T4634 (authored by c-po).
Aug 24 2022, 5:41 PM
c-po changed the status of T4642: proxy: hyphen not allowed in proxy URL from Open to In progress.
Aug 24 2022, 5:39 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po created T4642: proxy: hyphen not allowed in proxy URL.
Aug 24 2022, 5:39 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
roedie committed rVYOSONEXed5fb0645367: keepalived: T4526: keepalived-fifo.py unable to load config.
Aug 24 2022, 5:26 PM
GitHub <noreply@github.com> committed rVYOSONEXe6bae7dc1120: Merge pull request #1486 from roedie/T4526-2 (authored by c-po).
Aug 24 2022, 5:26 PM
Viacheslav committed rVYOSONEXecaafaa26f85: https: T4597: Verify bind port before apply HTTPS API service.
Aug 24 2022, 5:24 PM
GitHub <noreply@github.com> committed rVYOSONEX04096a1abc98: Merge pull request #1488 from sever-sever/T4597 (authored by c-po).
Aug 24 2022, 5:24 PM
Viacheslav committed rVYOSONEX9b3cdfb96af9: conntrack: T4623: Add conntrack statistics for op-mode.
Aug 24 2022, 5:24 PM
GitHub <noreply@github.com> committed rVYOSONEXa87e4fcc3512: Merge pull request #1489 from sever-sever/T4623 (authored by c-po).
Aug 24 2022, 5:24 PM
n.fort committed rVYOSONEX079316a8bb33: Policy: T4641: allow only ipv4 prefixes on prefix-list.
Aug 24 2022, 5:23 PM
GitHub <noreply@github.com> committed rVYOSONEXdd2855ceb243: Merge pull request #1492 from nicolas-fort/T4641 (authored by c-po).
Aug 24 2022, 5:23 PM
n.fort added a comment to T4641: prefix-list allows ipv6 prefix as input.

PR: https://github.com/vyos/vyos-1x/pull/1492

Aug 24 2022, 12:00 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4631: Add port and protocol to nat66 from Open to In progress.
Aug 24 2022, 11:46 AM · VyOS 1.4 Sagitta
n.fort claimed T4641: prefix-list allows ipv6 prefix as input.
Aug 24 2022, 11:44 AM · VyOS 1.4 Sagitta
n.fort changed the status of T4641: prefix-list allows ipv6 prefix as input from Open to In progress.
Aug 24 2022, 11:44 AM · VyOS 1.4 Sagitta
n.fort created T4641: prefix-list allows ipv6 prefix as input.
Aug 24 2022, 11:44 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4626: Error showing nat66 source and destination, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 24 2022, 11:41 AM · VyOS Rolling
Viacheslav changed the status of T4626: Error showing nat66 source and destination from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/1491

set nat66 destination rule 100 destination address '2001:1111:1111:1111::10'
set nat66 destination rule 100 inbound-interface 'eth0'
set nat66 destination rule 100 translation address 'fd00:1111:1111:1111::10'
set nat66 source rule 100 destination prefix '!fd00:2222:2222:2222::/64'
set nat66 source rule 100 outbound-interface 'eth0'
set nat66 source rule 100 source prefix 'fd00:1111:1111:1111::/64'
set nat66 source rule 100 translation address '2001:1111:1111:1111::10'
set nat66 source rule 120 destination prefix '2001:db8:2222::/64'
set nat66 source rule 120 outbound-interface 'eth0'
set nat66 source rule 120 source prefix '2001:db8:1111::/64'
set nat66 source rule 120 translation address 'masquerade'
set nat66 source rule 130 destination prefix '2001:db8:2222::/64'
set nat66 source rule 130 outbound-interface 'eth0'
set nat66 source rule 130 source prefix '2001:db8:2244::/64'
set nat66 source rule 130 translation address 'masquerade'

show

vyos@r14:~$ show nat66 source rules 
Rule    Source                    Destination                Proto    Out-Int    Translation
------  ------------------------  -------------------------  -------  ---------  -----------------------
100     fd00:1111:1111:1111::/64  !fd00:2222:2222:2222::/64  IP6      eth0       2001:1111:1111:1111::10
        sport any                 dport any
120     2001:db8:1111::/64        2001:db8:2222::/64         IP6      eth0       masquerade
        sport any                 dport any
130     2001:db8:2244::/64        2001:db8:2222::/64         IP6      eth0       masquerade
        sport any                 dport any
vyos@r14:~$ 
vyos@r14:~$ 
vyos@r14:~$ show nat66 destination  rules 
Rule    Source     Destination              Proto    In-Int    Translation
------  ---------  -----------------------  -------  --------  -----------------------
100     ::/0       2001:1111:1111:1111::10  any      eth0      fd00:1111:1111:1111::10
        sport any  dport any
vyos@r14:~$
Aug 24 2022, 11:41 AM · VyOS 1.4 Sagitta
c-po added a comment to T4635: Add zebra option ip nht resolve-via-default as default option.

I am more +1 on set system ip(v6) nht because what happens if out of random another protocol will support this? Also it's a zebra option as you described, not a bgpd option.

Aug 24 2022, 6:22 AM · VyOS Rolling

Aug 23 2022

roedie added a comment to T4635: Add zebra option ip nht resolve-via-default as default option.

While reading the FRR docs I see it is only used in BGP and nowhere else. That would make something like set protocols bgp parameters next-hop-track resolve-via-default logical.

Aug 23 2022, 4:13 PM · VyOS Rolling
jestabro committed rVYOSONEXf66ad001e153: graphql: T3993: reorganize/rename directory structure.
Aug 23 2022, 4:01 PM
jestabro committed rVYOSONEXbf178babd96e: graphql: T4544: fix for directly running on system for testing.
Aug 23 2022, 4:01 PM
jestabro committed rVYOSONEX8eede91cd252: graphql: T3993: add missing sys.exit().
Aug 23 2022, 4:01 PM
jestabro added a subtask for T2719: Standardized op mode script structure: T4640: Integrate op-mode exception hierarchy into API.
Aug 23 2022, 3:10 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
jestabro added a subtask for T3993: Extend HTTP API GraphQL support: T4640: Integrate op-mode exception hierarchy into API.
Aug 23 2022, 3:10 PM · VyOS 1.4 Sagitta
jestabro added parent tasks for T4640: Integrate op-mode exception hierarchy into API: T3993: Extend HTTP API GraphQL support, T2719: Standardized op mode script structure.
Aug 23 2022, 3:10 PM · VyOS 1.4 Sagitta
Viacheslav updated subscribers of T4635: Add zebra option ip nht resolve-via-default as default option.

I prefer to get this option configurable if it is possible
For IPv6 and VRFs - nice to have.
As it is used in BGP, I see something like set protocols bgp parameters next-hop-track resolve-via-default
Or, as it was mentioned in T3500
set routing-options next-hop-track resolve-via-default but it will be an additional node with only one option, needs to think

Aug 23 2022, 2:42 PM · VyOS Rolling
jestabro created T4640: Integrate op-mode exception hierarchy into API.
Aug 23 2022, 2:33 PM · VyOS 1.4 Sagitta
roedie created T4639: Crowdsec in VyOS (Blocking only).
Aug 23 2022, 2:18 PM · VyOS Rolling
jestabro reassigned T4597: Check bind port before assign service HTTPS API and openconnect from jestabro to Viacheslav.
Aug 23 2022, 1:31 PM · VyOS 1.4 Sagitta
roedie added a comment to T4635: Add zebra option ip nht resolve-via-default as default option.

@Viacheslav Do you just want this option added to the zebra config, or you it also be possible to enable/disable this via the conf mode?

Aug 23 2022, 1:02 PM · VyOS Rolling
Viacheslav added a comment to T4623: Add show conntrack statistics.

PR https://github.com/vyos/vyos-1x/pull/1489

vyos@r14:~$ show conntrack statistics 
CPU    Found    Invalid    Insert    Insert fail      Drop    Early drop    Errors    Search restart
-----  -------  ---------  --------  ---------------  ------  ------------  --------  -----------------
cpu=0  found=0  invalid=0  insert=0  insert_failed=0  drop=0  early_drop=0  error=0   search_restart=0
cpu=1  found=0  invalid=0  insert=0  insert_failed=0  drop=0  early_drop=0  error=0   search_restart=0
cpu=2  found=0  invalid=0  insert=0  insert_failed=0  drop=0  early_drop=0  error=0   search_restart=0
cpu=3  found=0  invalid=0  insert=0  insert_failed=0  drop=0  early_drop=0  error=0   search_restart=48
vyos@r14:~$
Aug 23 2022, 11:37 AM · VyOS 1.4 Sagitta