Page MenuHomeVyOS Platform
Feed All Stories

Sep 15 2022

c-po changed the status of T4696: Extend bgp parameters for bgp bestpath peer-type multipath-relax from Open to In progress.
Sep 15 2022, 12:14 PM · VyOS 1.4 Sagitta
c-po closed T4691: Upgrade Linux Kernel to latest 5.15.y train as Resolved.
Sep 15 2022, 12:13 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX31602e18386e: smoketest: nhrp: T2199: fix nftables rule/chain names.
Sep 15 2022, 11:26 AM
dmbaturin deleted 1.3.2.
Sep 15 2022, 10:43 AM · VyOS 1.3 Equuleus
dmbaturin created 1.3.2.
Sep 15 2022, 10:42 AM · VyOS 1.3 Equuleus (1.3.2)
aalmenar created T4696: Extend bgp parameters for bgp bestpath peer-type multipath-relax.
Sep 15 2022, 9:52 AM · VyOS 1.4 Sagitta
jack9603301 added a comment to T4689: Support RFS(Receive Flow Steering).

https://github.com/vyos/vyos-1x/pull/1535

Sep 15 2022, 9:44 AM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX9a38b823b8c9: conntrack: T4691: lower "tcp max-retrans" upper limit (authored by c-po).
Sep 15 2022, 6:47 AM
GitHub <noreply@github.com> committed rVYOSONEX9562dd1081ad: smoketest: conntrack: T4691: lower test value for nf_conntrack_tcp_max_retrans (authored by c-po).
Sep 15 2022, 6:41 AM
Unknown Object (User) added a comment to T874: Support for Two Factor Authentication for CLI access via Google Authenticator/OTP.

PR adding libpam-google-authenticator package to VyOS:
https://github.com/vyos/vyos-1x/pull/1541

Sep 15 2022, 5:57 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
GitHub <noreply@github.com> committed rVYOSONEX75c659d96ed3: Create codeql.yml (authored by syncer).
Sep 15 2022, 5:48 AM
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

It seems that we have two constraints here.

Sep 15 2022, 4:35 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Made a fix and now we have:

Sep 15 2022, 4:32 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Let me see if I can fix it.

Sep 15 2022, 4:06 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Doing further testing, it seems adding the explicit-null broke the configuration:

Sep 15 2022, 3:59 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Good news. It seems the patch worked properly. Here we show MPLS labels generated via segment routing for the prefix command:

Sep 15 2022, 3:57 AM · VyOS 1.4 Sagitta

Sep 14 2022

Viacheslav changed the status of T4680: Telegraf prometheus-client listen-address invalid format from Open to In progress.
Sep 14 2022, 7:31 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav changed the status of T4685: Interface does not exist on boot when used as inbound-interface for local policy route from Open to Needs testing.
Sep 14 2022, 7:28 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4695: Add 'es' and 'jp106' keymap option keyboard-layout from In progress to Needs testing.
Sep 14 2022, 7:21 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4687: Canot change configuration after image update from 202207220217 to 202209090217.

As I mentioned above, use it before the configuration, it described in the doc

#!/bin/vbash
Sep 14 2022, 7:17 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX5e159042dc05: keymap: T4695: Add Spain 'es' and Japan 'jp106' keymaps.
Sep 14 2022, 7:13 PM
GitHub <noreply@github.com> committed rVYOSONEX3ed4341db4b3: Merge pull request #1540 from sever-sever/T4695 (authored by c-po).
Sep 14 2022, 7:13 PM
Viacheslav changed the status of T4693: ISIS segment routing was broken... from Open to Needs testing.
Sep 14 2022, 7:12 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.

Interesting article on how and when to match ipsec options: https://thermalcircle.de/doku.php?id=blog:linux:nftables_demystifying_ipsec_expressions

Sep 14 2022, 6:18 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a comment to T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.

There is PR https://github.com/vyos/vyos-1x/pull/1516 for T4667 but it brakes all GRE traffic

Sep 14 2022, 6:04 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a comment to T4695: Add 'es' and 'jp106' keymap option keyboard-layout.

PR https://github.com/vyos/vyos-1x/pull/1540

Sep 14 2022, 5:51 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4695: Add 'es' and 'jp106' keymap option keyboard-layout from Open to In progress.
Sep 14 2022, 5:29 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4695: Add 'es' and 'jp106' keymap option keyboard-layout from Add 'es' and 'jp106' keymap to Add 'es' and 'jp106' keymap option keyboard-layout.
Sep 14 2022, 5:28 PM · VyOS 1.4 Sagitta
Viacheslav created T4695: Add 'es' and 'jp106' keymap option keyboard-layout.
Sep 14 2022, 5:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1539

Sep 14 2022, 3:17 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
lferrarotti added a comment to T3424: PPPoE IA-PD doesn't work in VRF.

Hi all,

Sep 14 2022, 3:09 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEXf379df09d839: Merge pull request #1530 from sever-sever/T4679 (authored by c-po).
Sep 14 2022, 2:34 PM
Viacheslav committed rVYOSONEXf7bab4058d86: openvpn: T4679: Fix incorrect verify local and remote address.
Sep 14 2022, 2:34 PM
sarthurdev committed rVYOSONEX8e8c3bb1cf21: firewall: nat66: policy: T2199: Fix smoketests for nftables updated output.
Sep 14 2022, 2:33 PM
GitHub <noreply@github.com> committed rVYOSONEX2309f4075831: Merge pull request #1538 from sarthurdev/nftables1_tests (authored by c-po).
Sep 14 2022, 2:33 PM
n.fort added a comment to T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.

Do you have a proposed cli format?

Sep 14 2022, 2:22 PM · VyOS 1.4 Sagitta (1.4.0-GA)
jmarmorato created T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.
Sep 14 2022, 1:40 PM · VyOS 1.4 Sagitta (1.4.0-GA)
sarthurdev committed rVYOSONEX31cd47594aa5: nhrp: T2199: Use separate table in nftables for NHRP rules.
Sep 14 2022, 11:24 AM
GitHub <noreply@github.com> committed rVYOSONEX5c21529c812b: Merge pull request #1537 from sarthurdev/nhrp_nftables (authored by c-po).
Sep 14 2022, 11:24 AM
sarthurdev committed rVYOSONEX450ca9a9b46d: firewall: T2199: Refactor firewall + zone-policy, move interfaces under….
Sep 14 2022, 5:56 AM
sarthurdev committed rVYOSONEX31587975258a: firewall: T2199: Move initial firewall tables to data.
Sep 14 2022, 5:56 AM
sarthurdev committed rVYOSONEXf38da6ba4d82: firewall: T4605: Rename filter tables to vyos_filter.
Sep 14 2022, 5:56 AM
sarthurdev committed rVYOSONEX24e5529be7b5: policy: T2199: Typo in policy route smoketest teardown.
Sep 14 2022, 5:56 AM
sarthurdev committed rVYOSONEX30945f39d6d1: zone-policy: T2199: Migrate zone-policy to firewall node.
Sep 14 2022, 5:56 AM
GitHub <noreply@github.com> committed rVYOSONEXe5c9f290b70c: Merge pull request #1534 from sarthurdev/firewall_interfaces (authored by c-po).
Sep 14 2022, 5:56 AM
GitHub <noreply@github.com> committed rVYOSONEX24fc5a832dbd: Merge pull request #1536 from Cheeze-It/current (authored by c-po).
Sep 14 2022, 5:05 AM
Cheeze_It committed rVYOSONEXbc3cfe6e3397: isis: T4693: Fix ISIS segment routing configurations.
Sep 14 2022, 5:05 AM
nickomarsa updated nickomarsa.
Sep 14 2022, 4:31 AM
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Added a pull request for this fix.

Sep 14 2022, 2:48 AM · VyOS 1.4 Sagitta
xPakrikx added a comment to T4687: Canot change configuration after image update from 202207220217 to 202209090217.

Nope, i use CLI for configuration and script for vrrp (wireguard interface enable/disable)

Sep 14 2022, 12:45 AM · VyOS 1.4 Sagitta

Sep 13 2022

Cheeze_It created T4693: ISIS segment routing was broken....
Sep 13 2022, 11:52 PM · VyOS 1.4 Sagitta
c-po added a comment to T2913: Failure to install fpm while building builder docker image.

Fix for 1.3 https://github.com/vyos/vyos-build/pull/261

Sep 13 2022, 7:47 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
c-po edited projects for T2913: Failure to install fpm while building builder docker image, added: VyOS 1.2 Crux (VyOS 1.2.8), VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.2 Crux.
Sep 13 2022, 7:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
c-po changed the status of T2913: Failure to install fpm while building builder docker image from Open to In progress.
Sep 13 2022, 7:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
absolutesantaja created T4692: Docker Builds of Equuleus Fail - public_suffix requires Ruby version >= 2.6.
Sep 13 2022, 5:05 PM
absolutesantaja added a comment to T2913: Failure to install fpm while building builder docker image.

This is also an issue on the 1.3.x builds due to a similar issue. See https://github.com/jordansissel/fpm/issues/1923

Sep 13 2022, 5:00 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a subtask for T2199: Rewrite firewall in new XML/Python style: T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.
Sep 13 2022, 1:03 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav added a parent task for T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups: T2199: Rewrite firewall in new XML/Python style.
Sep 13 2022, 1:02 PM
Viacheslav added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

It should be possible in https://github.com/vyos/vyos-1x/pull/1534 T2199

set firewall interface ethXvX
Sep 13 2022, 11:08 AM
Viacheslav added a comment to T4687: Canot change configuration after image update from 202207220217 to 202209090217.

It seems you use some custom scripts for configuration
You have to use

if [ "$(id -g -n)" != 'vyattacfg' ] ; then
    exec sg vyattacfg -c "/bin/vbash $(readlink -f $0) $@"
fi

before your configuration script

Sep 13 2022, 11:04 AM · VyOS 1.4 Sagitta
c-po updated the task description for T4691: Upgrade Linux Kernel to latest 5.15.y train.
Sep 13 2022, 6:44 AM · VyOS 1.4 Sagitta
c-po moved T4691: Upgrade Linux Kernel to latest 5.15.y train from Open to In Progress on the VyOS 1.4 Sagitta board.
Sep 13 2022, 6:43 AM · VyOS 1.4 Sagitta
c-po changed the status of T4691: Upgrade Linux Kernel to latest 5.15.y train from Open to In progress.
Sep 13 2022, 6:43 AM · VyOS 1.4 Sagitta
c-po created T4691: Upgrade Linux Kernel to latest 5.15.y train.
Sep 13 2022, 6:43 AM · VyOS 1.4 Sagitta

Sep 12 2022

sarthurdev added a comment to T2199: Rewrite firewall in new XML/Python style.

Refactor PR: https://github.com/vyos/vyos-1x/pull/1534

Sep 12 2022, 7:16 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev added a comment to T4605: Firewall change default table names.

PR for filter tables: https://github.com/vyos/vyos-1x/pull/1534

Sep 12 2022, 7:15 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXd283048d3858: Revert "rfs: T4689: Support RFS(Receive Flow Steering)".
Sep 12 2022, 6:50 PM
c-po added a reverting change for rVYOSONEX53355271a286: rfs: T4689: Support RFS(Receive Flow Steering): rVYOSONEXd283048d3858: Revert "rfs: T4689: Support RFS(Receive Flow Steering)".
Sep 12 2022, 6:50 PM
zsdc added a comment to T2189: Adding a large port-range will take ~ 20 minutes to commit.

Should be fixed in https://github.com/vyos/vyatta-cfg-firewall/pull/34

Sep 12 2022, 5:58 PM · VyOS 1.3 Equuleus (1.3.3)
jestabro closed T4690: Update GraphQL resolver for 'SystemStatus' following changes to 'show_uptime' op-mode script as Resolved.
Sep 12 2022, 3:56 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXb032ee2b9a5d: graphql: T4690: update resolver for 'SystemStatus' after 'uptime' update.
Sep 12 2022, 3:56 PM
jestabro changed the status of T4690: Update GraphQL resolver for 'SystemStatus' following changes to 'show_uptime' op-mode script from Open to In progress.
Sep 12 2022, 3:19 PM · VyOS 1.4 Sagitta
c-po closed T4170: Rename "policy ipv6-route" -> "policy route6" as Resolved.
Sep 12 2022, 7:16 AM · VyOS 1.4 Sagitta
c-po added a comment to T4170: Rename "policy ipv6-route" -> "policy route6".

Already renamed:

Sep 12 2022, 7:16 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX252f9eda2b7c: telegraf: T4617: add Restart=always to systemd unit.
Sep 12 2022, 7:00 AM
c-po closed T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> as Resolved.
Sep 12 2022, 7:00 AM · VyOS 1.4 Sagitta
c-po closed T4647: Add Google Virtual NIC (gVNIC) support as Resolved.
Sep 12 2022, 6:57 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.208 / 5.10.135 to Update Linux Kernel to v5.4.208 / 5.10.142.
Sep 12 2022, 6:56 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
jack9603301 moved T4689: Support RFS(Receive Flow Steering) from In Progress to Finished on the VyOS 1.4 Sagitta board.
Sep 12 2022, 6:53 AM · VyOS 1.4 Sagitta
jack9603301 changed the status of T4689: Support RFS(Receive Flow Steering) from In progress to Needs testing.
Sep 12 2022, 6:53 AM · VyOS 1.4 Sagitta
roedie committed rVYOSONEX803f1bdc4ae1: T4665: Keepalived: Fix interface names.
Sep 12 2022, 6:07 AM
jack9603301 committed rVYOSONEX53355271a286: rfs: T4689: Support RFS(Receive Flow Steering).
Sep 12 2022, 6:07 AM
GitHub <noreply@github.com> committed rVYOSONEXd2338b7f5b09: Merge pull request #1526 from roedie/T4665-2 (authored by c-po).
Sep 12 2022, 6:07 AM
GitHub <noreply@github.com> committed rVYOSONEX84ee78e52471: Merge pull request #1533 from jack9603301/T4689 (authored by c-po).
Sep 12 2022, 6:07 AM

Sep 11 2022

jack9603301 added a comment to T4689: Support RFS(Receive Flow Steering).

PR: https://github.com/vyos/vyos-1x/pull/1533

Sep 11 2022, 7:09 PM · VyOS 1.4 Sagitta
jack9603301 changed the status of T4689: Support RFS(Receive Flow Steering) from Open to In progress.
Sep 11 2022, 4:38 PM · VyOS 1.4 Sagitta
jack9603301 claimed T4689: Support RFS(Receive Flow Steering).
Sep 11 2022, 4:37 PM · VyOS 1.4 Sagitta
jack9603301 moved T4689: Support RFS(Receive Flow Steering) from Open to In Progress on the VyOS 1.4 Sagitta board.
Sep 11 2022, 4:37 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T4689: Support RFS(Receive Flow Steering).
Sep 11 2022, 2:44 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T4689: Support RFS(Receive Flow Steering).
Sep 11 2022, 2:41 PM · VyOS 1.4 Sagitta
jack9603301 renamed T4689: Support RFS(Receive Flow Steering) from Support RFS to Support RFS(Receive Flow Steering).
Sep 11 2022, 2:39 PM · VyOS 1.4 Sagitta
jack9603301 created T4689: Support RFS(Receive Flow Steering).
Sep 11 2022, 2:39 PM · VyOS 1.4 Sagitta
initramfs updated the task description for T4688: Add support for customizing packet verdict actions in limiter traffic policy.
Sep 11 2022, 12:38 PM · VyOS 1.3 Equuleus (1.3.5)
initramfs created T4688: Add support for customizing packet verdict actions in limiter traffic policy.
Sep 11 2022, 12:23 PM · VyOS 1.3 Equuleus (1.3.5)

Sep 10 2022

syncer reassigned T4443: Wan Load Balancing Multiple Regressions from dmbaturin to Viacheslav.
Sep 10 2022, 10:36 PM · VyOS Rolling, Bugs
roedie added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.
In T1185#133944, @sdev wrote:

A similar syntax change is in progress as part of a larger firewall refactor. It should reach the 1.4 branch in a week or so. It should allow for any valid existing interface name.

Sep 10 2022, 6:31 PM
sarthurdev added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Just a suggestion, would it be a weird idea to move the firewall config from the interface section to the firewall section? A bit like the zone config. So something like:

set firewall local interface eth0 name <firewall-filter>
set firewall in interface eth0 name <firewall-filter>
set firewall out interface eth0 name <firewall-filter>
set firewall local interface bond0.10v22v6 ipv6-name <firewall-filter>

The problem is that using zone-policy firewall is a bit overkill for a pure router or even a router with async routing. In which scenario I guess only the local variant would be useful.

Sep 10 2022, 6:23 PM
roedie added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Or, come to think, some free from of set interfaces unknown <typeyourownname> firewall local name <ruleset> where you can only config stuff that doesn't really depend on an interface.

Sep 10 2022, 6:17 PM
roedie added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Just a suggestion, would it be a weird idea to move the firewall config from the interface section to the firewall section? A bit like the zone config. So something like:

Sep 10 2022, 6:09 PM
jack9603301 changed the subtype of T4659: Use vtysh to display bridge and some interface parameter information from "Task" to "Feature Request".
Sep 10 2022, 3:10 PM · VyOS 1.4 Sagitta