Page MenuHomeVyOS Platform
Feed All Stories

Sep 15 2022

runar created T4697: policy route: Generating ConfigError failes when tcp flag is missing on set tcp-mss rule commit.
Sep 15 2022, 7:39 PM · VyOS 1.4 Sagitta
syncer moved T4695: Add 'es' and 'jp106' keymap option keyboard-layout from Open to In Progress on the VyOS 1.4 Sagitta board.
Sep 15 2022, 6:55 PM · VyOS 1.4 Sagitta
syncer triaged T4695: Add 'es' and 'jp106' keymap option keyboard-layout as Normal priority.
Sep 15 2022, 6:55 PM · VyOS 1.4 Sagitta
syncer triaged T3424: PPPoE IA-PD doesn't work in VRF as Normal priority.
Sep 15 2022, 6:53 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jack9603301 updated subscribers of T4689: Support RFS(Receive Flow Steering).

I re-reviewed this PR and the following commit from @c-po

Sep 15 2022, 6:45 PM · VyOS 1.4 Sagitta
xPakrikx added a comment to T4687: Canot change configuration after image update from 202207220217 to 202209090217.

Ok now its working. Thanks. My bad.

Sep 15 2022, 4:51 PM · VyOS 1.4 Sagitta
c-po closed T4630: Prevent attempts to use the same interface as a source interface for pseudo-ethernet and MACsec at the same time as Resolved.
Sep 15 2022, 4:01 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
sempervictus committed rVYOSONEXa87ada1c4e9d: T3896: Drop cserv local user req, add groupconfig.
Sep 15 2022, 2:28 PM
sempervictus committed rVYOSONEX0b3bfe97b617: T3896: Use group selector and forced dns tunneling.
Sep 15 2022, 2:28 PM
sempervictus committed rVYOSONEX4a5e4cfd6c11: T3896: update groupconfig syntax per PR1463.
Sep 15 2022, 2:28 PM
sempervictus committed rVYOSONEXe5785ff748f9: T3896: update group syntax per PR1463.
Sep 15 2022, 2:28 PM
GitHub <noreply@github.com> committed rVYOSONEX7a2ad35ec8ec: Merge pull request #1477 from sempervictus/feature/ocserv_groups (authored by Viacheslav).
Sep 15 2022, 2:28 PM
c-po committed rVYOSONEX87894a2fa329: T4630: can not use same source-interface for macsec and pseudo-ethernet.
Sep 15 2022, 2:22 PM
GitHub <noreply@github.com> committed rVYOSONEX435016fdb353: Merge pull request #1519 from c-po/t4630-equuleus-peth-macsec (authored by dmbaturin).
Sep 15 2022, 2:22 PM
Viacheslav moved T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Sep 15 2022, 2:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav closed T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address as Resolved.
Sep 15 2022, 2:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav committed rVYOSONEX3629f376c26b: openvpn: T4679: Fix incorrect verify local and remote address.
Sep 15 2022, 2:07 PM
GitHub <noreply@github.com> committed rVYOSONEXe57146723fd7: Merge pull request #1539 from sever-sever/T4679-eq (authored by dmbaturin).
Sep 15 2022, 2:07 PM
v.huti added a comment to T4180: Support for QoS Policy Propagation via BGP (QPPB).

Changes on the FRR side:

  • Convert xdp helper library to an optional plugin + bgp hook
  • Minor fixes + cleanups
  • Figured out most of the permission problems

Changes on the XDP side:

  • Convert mappings from legacy iproute format to the latest libbpf one
  • New mappings improve debugging experience by implementing pretty-printing for XDP map dumping
  • Added an xdp-loader for xdp-tools repo
Sep 15 2022, 1:57 PM · VyOS Rolling
jack9603301 committed rVYOSONEXac4e07f96ae3: rfs: T4689: Support RFS(Receive Flow Steering).
Sep 15 2022, 12:33 PM
c-po closed T4696: Extend bgp parameters for bgp bestpath peer-type multipath-relax as Resolved.
Sep 15 2022, 12:33 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXd41909874a6a: bgp: T4696: add support for "bestpath peer-type multipath-relax".
Sep 15 2022, 12:33 PM
c-po committed rVYOSONEX3e24e673537c: smoketest: ethernet: rfs: T4689: also test default "0" case.
Sep 15 2022, 12:33 PM
c-po committed rVYOSONEXe976ee9ed5d1: ethernet: rfs: T4689: remove redundant code.
Sep 15 2022, 12:33 PM
c-po committed rVYOSONEX87ee858f1483: Merge branch 'T4689' of https://github.com/jack9603301/vyos-1x into current.
Sep 15 2022, 12:33 PM
c-po changed the status of T4696: Extend bgp parameters for bgp bestpath peer-type multipath-relax from Open to In progress.
Sep 15 2022, 12:14 PM · VyOS 1.4 Sagitta
c-po closed T4691: Upgrade Linux Kernel to latest 5.15.y train as Resolved.
Sep 15 2022, 12:13 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX31602e18386e: smoketest: nhrp: T2199: fix nftables rule/chain names.
Sep 15 2022, 11:26 AM
dmbaturin deleted 1.3.2.
Sep 15 2022, 10:43 AM · VyOS 1.3 Equuleus
dmbaturin created 1.3.2.
Sep 15 2022, 10:42 AM · VyOS 1.3 Equuleus (1.3.2)
aalmenar created T4696: Extend bgp parameters for bgp bestpath peer-type multipath-relax.
Sep 15 2022, 9:52 AM · VyOS 1.4 Sagitta
jack9603301 added a comment to T4689: Support RFS(Receive Flow Steering).

https://github.com/vyos/vyos-1x/pull/1535

Sep 15 2022, 9:44 AM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX9a38b823b8c9: conntrack: T4691: lower "tcp max-retrans" upper limit (authored by c-po).
Sep 15 2022, 6:47 AM
GitHub <noreply@github.com> committed rVYOSONEX9562dd1081ad: smoketest: conntrack: T4691: lower test value for nf_conntrack_tcp_max_retrans (authored by c-po).
Sep 15 2022, 6:41 AM
Unknown Object (User) added a comment to T874: Support for Two Factor Authentication for CLI access via Google Authenticator/OTP.

PR adding libpam-google-authenticator package to VyOS:
https://github.com/vyos/vyos-1x/pull/1541

Sep 15 2022, 5:57 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
GitHub <noreply@github.com> committed rVYOSONEX75c659d96ed3: Create codeql.yml (authored by syncer).
Sep 15 2022, 5:48 AM
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

It seems that we have two constraints here.

Sep 15 2022, 4:35 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Made a fix and now we have:

Sep 15 2022, 4:32 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Let me see if I can fix it.

Sep 15 2022, 4:06 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Doing further testing, it seems adding the explicit-null broke the configuration:

Sep 15 2022, 3:59 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Good news. It seems the patch worked properly. Here we show MPLS labels generated via segment routing for the prefix command:

Sep 15 2022, 3:57 AM · VyOS 1.4 Sagitta

Sep 14 2022

Viacheslav changed the status of T4680: Telegraf prometheus-client listen-address invalid format from Open to In progress.
Sep 14 2022, 7:31 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav changed the status of T4685: Interface does not exist on boot when used as inbound-interface for local policy route from Open to Needs testing.
Sep 14 2022, 7:28 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4695: Add 'es' and 'jp106' keymap option keyboard-layout from In progress to Needs testing.
Sep 14 2022, 7:21 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4687: Canot change configuration after image update from 202207220217 to 202209090217.

As I mentioned above, use it before the configuration, it described in the doc

#!/bin/vbash
Sep 14 2022, 7:17 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX5e159042dc05: keymap: T4695: Add Spain 'es' and Japan 'jp106' keymaps.
Sep 14 2022, 7:13 PM
GitHub <noreply@github.com> committed rVYOSONEX3ed4341db4b3: Merge pull request #1540 from sever-sever/T4695 (authored by c-po).
Sep 14 2022, 7:13 PM
Viacheslav changed the status of T4693: ISIS segment routing was broken... from Open to Needs testing.
Sep 14 2022, 7:12 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.

Interesting article on how and when to match ipsec options: https://thermalcircle.de/doku.php?id=blog:linux:nftables_demystifying_ipsec_expressions

Sep 14 2022, 6:18 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a comment to T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.

There is PR https://github.com/vyos/vyos-1x/pull/1516 for T4667 but it brakes all GRE traffic

Sep 14 2022, 6:04 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a comment to T4695: Add 'es' and 'jp106' keymap option keyboard-layout.

PR https://github.com/vyos/vyos-1x/pull/1540

Sep 14 2022, 5:51 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4695: Add 'es' and 'jp106' keymap option keyboard-layout from Open to In progress.
Sep 14 2022, 5:29 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4695: Add 'es' and 'jp106' keymap option keyboard-layout from Add 'es' and 'jp106' keymap to Add 'es' and 'jp106' keymap option keyboard-layout.
Sep 14 2022, 5:28 PM · VyOS 1.4 Sagitta
Viacheslav created T4695: Add 'es' and 'jp106' keymap option keyboard-layout.
Sep 14 2022, 5:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1539

Sep 14 2022, 3:17 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
lferrarotti added a comment to T3424: PPPoE IA-PD doesn't work in VRF.

Hi all,

Sep 14 2022, 3:09 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEXf379df09d839: Merge pull request #1530 from sever-sever/T4679 (authored by c-po).
Sep 14 2022, 2:34 PM
Viacheslav committed rVYOSONEXf7bab4058d86: openvpn: T4679: Fix incorrect verify local and remote address.
Sep 14 2022, 2:34 PM
sarthurdev committed rVYOSONEX8e8c3bb1cf21: firewall: nat66: policy: T2199: Fix smoketests for nftables updated output.
Sep 14 2022, 2:33 PM
GitHub <noreply@github.com> committed rVYOSONEX2309f4075831: Merge pull request #1538 from sarthurdev/nftables1_tests (authored by c-po).
Sep 14 2022, 2:33 PM
n.fort added a comment to T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.

Do you have a proposed cli format?

Sep 14 2022, 2:22 PM · VyOS 1.4 Sagitta (1.4.0-GA)
jmarmorato created T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.
Sep 14 2022, 1:40 PM · VyOS 1.4 Sagitta (1.4.0-GA)
sarthurdev committed rVYOSONEX31cd47594aa5: nhrp: T2199: Use separate table in nftables for NHRP rules.
Sep 14 2022, 11:24 AM
GitHub <noreply@github.com> committed rVYOSONEX5c21529c812b: Merge pull request #1537 from sarthurdev/nhrp_nftables (authored by c-po).
Sep 14 2022, 11:24 AM
sarthurdev committed rVYOSONEX450ca9a9b46d: firewall: T2199: Refactor firewall + zone-policy, move interfaces under….
Sep 14 2022, 5:56 AM
sarthurdev committed rVYOSONEX31587975258a: firewall: T2199: Move initial firewall tables to data.
Sep 14 2022, 5:56 AM
sarthurdev committed rVYOSONEXf38da6ba4d82: firewall: T4605: Rename filter tables to vyos_filter.
Sep 14 2022, 5:56 AM
sarthurdev committed rVYOSONEX24e5529be7b5: policy: T2199: Typo in policy route smoketest teardown.
Sep 14 2022, 5:56 AM
sarthurdev committed rVYOSONEX30945f39d6d1: zone-policy: T2199: Migrate zone-policy to firewall node.
Sep 14 2022, 5:56 AM
GitHub <noreply@github.com> committed rVYOSONEXe5c9f290b70c: Merge pull request #1534 from sarthurdev/firewall_interfaces (authored by c-po).
Sep 14 2022, 5:56 AM
GitHub <noreply@github.com> committed rVYOSONEX24fc5a832dbd: Merge pull request #1536 from Cheeze-It/current (authored by c-po).
Sep 14 2022, 5:05 AM
Cheeze_It committed rVYOSONEXbc3cfe6e3397: isis: T4693: Fix ISIS segment routing configurations.
Sep 14 2022, 5:05 AM
nickomarsa updated nickomarsa.
Sep 14 2022, 4:31 AM
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Added a pull request for this fix.

Sep 14 2022, 2:48 AM · VyOS 1.4 Sagitta
xPakrikx added a comment to T4687: Canot change configuration after image update from 202207220217 to 202209090217.

Nope, i use CLI for configuration and script for vrrp (wireguard interface enable/disable)

Sep 14 2022, 12:45 AM · VyOS 1.4 Sagitta

Sep 13 2022

Cheeze_It created T4693: ISIS segment routing was broken....
Sep 13 2022, 11:52 PM · VyOS 1.4 Sagitta
c-po added a comment to T2913: Failure to install fpm while building builder docker image.

Fix for 1.3 https://github.com/vyos/vyos-build/pull/261

Sep 13 2022, 7:47 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
c-po edited projects for T2913: Failure to install fpm while building builder docker image, added: VyOS 1.2 Crux (VyOS 1.2.8), VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.2 Crux.
Sep 13 2022, 7:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
c-po changed the status of T2913: Failure to install fpm while building builder docker image from Open to In progress.
Sep 13 2022, 7:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
absolutesantaja created T4692: Docker Builds of Equuleus Fail - public_suffix requires Ruby version >= 2.6.
Sep 13 2022, 5:05 PM
absolutesantaja added a comment to T2913: Failure to install fpm while building builder docker image.

This is also an issue on the 1.3.x builds due to a similar issue. See https://github.com/jordansissel/fpm/issues/1923

Sep 13 2022, 5:00 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a subtask for T2199: Rewrite firewall in new XML/Python style: T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.
Sep 13 2022, 1:03 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav added a parent task for T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups: T2199: Rewrite firewall in new XML/Python style.
Sep 13 2022, 1:02 PM
Viacheslav added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

It should be possible in https://github.com/vyos/vyos-1x/pull/1534 T2199

set firewall interface ethXvX
Sep 13 2022, 11:08 AM
Viacheslav added a comment to T4687: Canot change configuration after image update from 202207220217 to 202209090217.

It seems you use some custom scripts for configuration
You have to use

if [ "$(id -g -n)" != 'vyattacfg' ] ; then
    exec sg vyattacfg -c "/bin/vbash $(readlink -f $0) $@"
fi

before your configuration script

Sep 13 2022, 11:04 AM · VyOS 1.4 Sagitta
c-po updated the task description for T4691: Upgrade Linux Kernel to latest 5.15.y train.
Sep 13 2022, 6:44 AM · VyOS 1.4 Sagitta
c-po moved T4691: Upgrade Linux Kernel to latest 5.15.y train from Open to In Progress on the VyOS 1.4 Sagitta board.
Sep 13 2022, 6:43 AM · VyOS 1.4 Sagitta
c-po changed the status of T4691: Upgrade Linux Kernel to latest 5.15.y train from Open to In progress.
Sep 13 2022, 6:43 AM · VyOS 1.4 Sagitta
c-po created T4691: Upgrade Linux Kernel to latest 5.15.y train.
Sep 13 2022, 6:43 AM · VyOS 1.4 Sagitta

Sep 12 2022

sarthurdev added a comment to T2199: Rewrite firewall in new XML/Python style.

Refactor PR: https://github.com/vyos/vyos-1x/pull/1534

Sep 12 2022, 7:16 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev added a comment to T4605: Firewall change default table names.

PR for filter tables: https://github.com/vyos/vyos-1x/pull/1534

Sep 12 2022, 7:15 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXd283048d3858: Revert "rfs: T4689: Support RFS(Receive Flow Steering)".
Sep 12 2022, 6:50 PM
c-po added a reverting change for rVYOSONEX53355271a286: rfs: T4689: Support RFS(Receive Flow Steering): rVYOSONEXd283048d3858: Revert "rfs: T4689: Support RFS(Receive Flow Steering)".
Sep 12 2022, 6:50 PM
zsdc added a comment to T2189: Adding a large port-range will take ~ 20 minutes to commit.

Should be fixed in https://github.com/vyos/vyatta-cfg-firewall/pull/34

Sep 12 2022, 5:58 PM · VyOS 1.3 Equuleus (1.3.3)
jestabro closed T4690: Update GraphQL resolver for 'SystemStatus' following changes to 'show_uptime' op-mode script as Resolved.
Sep 12 2022, 3:56 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXb032ee2b9a5d: graphql: T4690: update resolver for 'SystemStatus' after 'uptime' update.
Sep 12 2022, 3:56 PM
jestabro changed the status of T4690: Update GraphQL resolver for 'SystemStatus' following changes to 'show_uptime' op-mode script from Open to In progress.
Sep 12 2022, 3:19 PM · VyOS 1.4 Sagitta
c-po closed T4170: Rename "policy ipv6-route" -> "policy route6" as Resolved.
Sep 12 2022, 7:16 AM · VyOS 1.4 Sagitta
c-po added a comment to T4170: Rename "policy ipv6-route" -> "policy route6".

Already renamed:

Sep 12 2022, 7:16 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX252f9eda2b7c: telegraf: T4617: add Restart=always to systemd unit.
Sep 12 2022, 7:00 AM