Page MenuHomeVyOS Platform
Feed All Stories

Oct 29 2022

sarthurdev changed the status of T3903: Containers: after command "reboot" the host system will reboot after 1.5 minutes from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1628

Oct 29 2022, 5:48 PM · VyOS 1.4 Sagitta
c-po changed the status of T4784: Add description node for static route/route6 tagNodes from Open to In progress.
Oct 29 2022, 5:43 PM · VyOS 1.4 Sagitta
c-po created T4784: Add description node for static route/route6 tagNodes.
Oct 29 2022, 5:43 PM · VyOS 1.4 Sagitta
dmbaturin created T4783: Add support for stunnel.
Oct 29 2022, 10:13 AM · VyOS 1.4 Sagitta
olivier.hault added a comment to T970: Support matching domain name in firewall rules.

Still on track for 1.4 ?

Oct 29 2022, 9:49 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Darkness4 updated the task description for T4781: cloud-init fails to handle "::" as a netmask for routes.
Oct 29 2022, 1:03 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
jzatarski created T4782: Allow multiple CA certificates (on e.g. EAPoL).
Oct 29 2022, 12:44 AM · VyOS 1.4 Sagitta
Darkness4 updated the task description for T4781: cloud-init fails to handle "::" as a netmask for routes.
Oct 29 2022, 12:01 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)

Oct 28 2022

Darkness4 updated the task description for T4781: cloud-init fails to handle "::" as a netmask for routes.
Oct 28 2022, 11:41 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
Darkness4 updated the task description for T4781: cloud-init fails to handle "::" as a netmask for routes.
Oct 28 2022, 11:39 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
Darkness4 updated the task description for T4781: cloud-init fails to handle "::" as a netmask for routes.
Oct 28 2022, 11:33 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
Darkness4 created T4781: cloud-init fails to handle "::" as a netmask for routes.
Oct 28 2022, 11:32 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
n.fort added a comment to T4780: Firewall - Add interface group.

PR: https://github.com/vyos/vyos-1x/pull/1626

Oct 28 2022, 7:46 PM · VyOS 1.4 Sagitta
jestabro closed T4291: Consolidate component version read/write functions, a subtask of T4316: Update save-config/load-config, as Resolved.
Oct 28 2022, 7:26 PM · VyOS 1.4 Sagitta (1.4.0-GA)
jestabro closed T4291: Consolidate component version read/write functions as Resolved.
Oct 28 2022, 7:26 PM · VyOS 1.4 Sagitta
aalmenar added a comment to T3640: Allow resetting Wireguard interface.

There's something weird happening with this. If you change simply persistent-keepalive from 25 to 30 or 30 to 25 will reactivate the peer. At least thats my experience. Doing anything else didnt work for me including:

Oct 28 2022, 6:33 PM · Restricted Project, VyOS 1.5 Circinus
n.fort changed the status of T4780: Firewall - Add interface group from Open to In progress.
Oct 28 2022, 6:18 PM · VyOS 1.4 Sagitta
n.fort created T4780: Firewall - Add interface group.
Oct 28 2022, 6:17 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3903: Containers: after command "reboot" the host system will reboot after 1.5 minutes.

Best suggestion seems to be introducing a script to call podman stop -t N on shutdown/reboot to reduce the timeout before SIGKILL is sent.

Oct 28 2022, 1:27 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4771: Rewrite protocol BGP op-mode to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Oct 28 2022, 12:47 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav changed the status of T4771: Rewrite protocol BGP op-mode to vyos.opmode format from Open to In progress.
Oct 28 2022, 12:46 PM · VyOS 1.4 Sagitta
c-po reopened T4177: Strip-private doesn't work for service monitoring as "Backport candidate".
Oct 28 2022, 12:44 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin created T4779: Make raw op mode command outputs use bytes for data amount values.
Oct 28 2022, 12:24 PM · VyOS 1.4 Sagitta
zsdc added a comment to T1875: Add the ability to use network address as BGP neighbor (bgp listen range).

Backported in https://github.com/vyos/vyatta-cfg-quagga/pull/97

Oct 28 2022, 11:42 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
rherold added a comment to T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP.

Is there some progress? VPP is available for AArch64 in meantime.
Here some news about VPP performance:

Oct 28 2022, 7:46 AM · Restricted Project, VyOS 1.5 Circinus

Oct 27 2022

sarthurdev changed the status of T4774: Disallow duplicate pubkey on peers of a wireguard interface from Open to In progress.

1.4 PR: https://github.com/vyos/vyos-1x/pull/1621

Oct 27 2022, 10:54 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
jestabro closed T4778: Raise error UnconfiguredSubsystem if op-mode ipsec.py fails initialization, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Oct 27 2022, 7:14 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro closed T4778: Raise error UnconfiguredSubsystem if op-mode ipsec.py fails initialization as Resolved.
Oct 27 2022, 7:14 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4778: Raise error UnconfiguredSubsystem if op-mode ipsec.py fails initialization.
Oct 27 2022, 7:03 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a parent task for T4778: Raise error UnconfiguredSubsystem if op-mode ipsec.py fails initialization: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Oct 27 2022, 7:03 PM · VyOS 1.4 Sagitta
jestabro triaged T4778: Raise error UnconfiguredSubsystem if op-mode ipsec.py fails initialization as Normal priority.
Oct 27 2022, 6:57 PM · VyOS 1.4 Sagitta
zsdc added a comment to T4776: NVME storage is not detected properly during installation.

Fixed in https://github.com/vyos/vyatta-cfg-system/pull/188

Oct 27 2022, 4:51 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav updated the task description for T4777: Ability to get logs in machine readable format.
Oct 27 2022, 1:58 PM · VyOS 1.5 Circinus
Viacheslav updated the task description for T4777: Ability to get logs in machine readable format.
Oct 27 2022, 1:54 PM · VyOS 1.5 Circinus
Viacheslav created T4777: Ability to get logs in machine readable format.
Oct 27 2022, 1:52 PM · VyOS 1.5 Circinus
Viacheslav closed T4762: Show nat rules with empty rules incorrect error, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Oct 27 2022, 12:56 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav closed T4762: Show nat rules with empty rules incorrect error as Resolved.
Oct 27 2022, 12:56 PM · VyOS 1.4 Sagitta
Viacheslav closed T4763: Change XML for Show nat destination statistics, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Oct 27 2022, 12:55 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav closed T4763: Change XML for Show nat destination statistics as Resolved.
Oct 27 2022, 12:55 PM · VyOS 1.4 Sagitta
zsdc changed the status of T4776: NVME storage is not detected properly during installation from Open to In progress.
Oct 27 2022, 10:50 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
zsdc created T4776: NVME storage is not detected properly during installation.
Oct 27 2022, 10:48 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4774: Disallow duplicate pubkey on peers of a wireguard interface from "Task" to "Bug".
Oct 27 2022, 10:33 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Alfa80 added projects to T4774: Disallow duplicate pubkey on peers of a wireguard interface: VyOS 1.3 Equuleus, VyOS 1.4 Sagitta.
Oct 27 2022, 6:52 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Unknown Object (User) created T4775: A new command for Interfaces debugging.
Oct 27 2022, 12:59 AM · VyOS 1.5 Circinus

Oct 26 2022

Alfa80 created T4774: Disallow duplicate pubkey on peers of a wireguard interface.
Oct 26 2022, 7:50 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
jestabro closed T4773: Add camel_case to snake_case conversion utility as Resolved.
Oct 26 2022, 12:06 AM · VyOS 1.4 Sagitta

Oct 25 2022

sarthurdev changed the status of T4764: NAT tables vyos_nat and vyos_static_nat not deleting after deleting nat from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1618

Oct 25 2022, 10:02 PM · VyOS 1.4 Sagitta
jestabro triaged T4773: Add camel_case to snake_case conversion utility as Normal priority.
Oct 25 2022, 6:50 PM · VyOS 1.4 Sagitta
jestabro closed T4574: Add token based authentication to GraphQL API as Resolved.
Oct 25 2022, 5:09 PM · VyOS 1.4 Sagitta
Viacheslav closed T4720: Ability to configure SSH HostKeyAlgorithms, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, as Resolved.
Oct 25 2022, 5:02 PM · VyOS 1.5 Circinus
Viacheslav closed T4720: Ability to configure SSH HostKeyAlgorithms as Resolved.
Oct 25 2022, 5:02 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4764: NAT tables vyos_nat and vyos_static_nat not deleting after deleting nat from Open to In progress.
Oct 25 2022, 10:29 AM · VyOS 1.4 Sagitta

Oct 24 2022

jestabro closed T4772: Return list of dicts in 'raw' output of route.py instead of dict with redundant information as Resolved.
Oct 24 2022, 7:17 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4772: Return list of dicts in 'raw' output of route.py instead of dict with redundant information.

PR:
https://github.com/vyos/vyos-1x/pull/1614

Oct 24 2022, 3:56 PM · VyOS 1.4 Sagitta
jestabro triaged T4772: Return list of dicts in 'raw' output of route.py instead of dict with redundant information as Normal priority.
Oct 24 2022, 2:57 PM · VyOS 1.4 Sagitta
dcplaya added a comment to T4487: Create container without downloaded image wrong behavior.

A simple work around could be to trigger a podman start command when a restart container $CONTAINER_NAME is entered. If the pod isnt already running or in a stopped state, it will look at the config and start it up.

Oct 24 2022, 4:39 AM · VyOS 1.4 Sagitta

Oct 23 2022

jestabro added a comment to T4574: Add token based authentication to GraphQL API.

PR:
https://github.com/vyos/vyos-1x/pull/1613

Oct 23 2022, 7:19 PM · VyOS 1.4 Sagitta
Viacheslav closed T3723: op-mode IPSec show vpn ipsec sa output with underscores, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Oct 23 2022, 7:08 PM · VyOS 1.4 Sagitta
Viacheslav closed T3723: op-mode IPSec show vpn ipsec sa output with underscores as Resolved.
Oct 23 2022, 7:08 PM · VyOS 1.4 Sagitta
aderouineau added a comment to T2196: Dynamic ipv4 interface list hairpin.

Any update on this, since it's been more than 2 years since the initial request? This would indeed be very useful for hairpin NAT. It it complicated to implement?

Oct 23 2022, 3:06 AM · VyOS 1.3 Equuleus (1.3.8), VyOS 1.4 Sagitta (1.4.0-GA)
aderouineau added a comment to T3910: Hairpin NAT Not Functioning Correctly.

I think this should be re-opened. The solution that is documented does not follow the spirit of hairpin NAT, which is that traffic on port N not actually destined to the inside target should not be redirected.

Oct 23 2022, 2:58 AM · Rejected

Oct 21 2022

Unknown Object (User) added a comment to T4767: replace sh to Python (generate_ipsec_debug_archive.sh).

https://github.com/vyos/vyos-1x/pull/1646

Oct 21 2022, 10:02 PM
Viacheslav created T4771: Rewrite protocol BGP op-mode to vyos.opmode format.
Oct 21 2022, 7:18 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4770: Rewrite OpenVPN op-mode to vyos.opmode format.
Oct 21 2022, 6:43 PM · VyOS 1.4 Sagitta
Viacheslav created T4770: Rewrite OpenVPN op-mode to vyos.opmode format.
Oct 21 2022, 6:32 PM · VyOS 1.4 Sagitta
jestabro closed T4768: Change name of api child node from 'gql' to 'graphql' as Resolved.
Oct 21 2022, 5:17 PM · VyOS 1.4 Sagitta
jestabro changed the status of T4768: Change name of api child node from 'gql' to 'graphql' from Open to In progress.
Oct 21 2022, 3:49 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4768: Change name of api child node from 'gql' to 'graphql'.

PR:
https://github.com/vyos/vyos-1x/pull/1610

Oct 21 2022, 3:49 PM · VyOS 1.4 Sagitta
zsdc created T4769: Conntrack settings are not apply properly.
Oct 21 2022, 3:44 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.9)
zsdc closed T2189: Adding a large port-range will take ~ 20 minutes to commit as Resolved.
Oct 21 2022, 2:44 PM · VyOS 1.3 Equuleus (1.3.3)
a.apostoliuk changed the status of T4496: ping vrf help does not list VRFs from Open to In progress.
Oct 21 2022, 2:29 PM · VyOS 1.4 Sagitta
a.apostoliuk claimed T4496: ping vrf help does not list VRFs.
Oct 21 2022, 2:29 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4767: replace sh to Python (generate_ipsec_debug_archive.sh) from Open to In progress.
Oct 21 2022, 2:25 PM
thetooth added a comment to T4587: wan load balance issues with 3 or more WANs.

@Nova_Logic As a workaround can you try the following configuration, this should ensure the behaviour you're after:

policy {
    local-route {
        rule 1 {
            fwmark 201
            inbound-interface eth0
            set {
                table 201
            }
        }
        rule 2 {
            fwmark 202
            inbound-interface eth0
            set {
                table 202
            }
        }
        rule 3 {
            fwmark 203
            inbound-interface eth0
            set {
                table 203
            }
        }
    }
}
Oct 21 2022, 2:12 PM · Restricted Project, VyOS 1.5 Circinus
thetooth added a comment to T4587: wan load balance issues with 3 or more WANs.

I had a closer look at this, the commits here and here should have brought this back from the dead but there is a small issue where the table "ip nat" is used when at the same time all of the nat related chains were refactored into the vyos_nat table. The normal functionality of WLB isn't affected because the mangle table isn't changed.

Oct 21 2022, 1:42 PM · Restricted Project, VyOS 1.5 Circinus
jestabro created T4768: Change name of api child node from 'gql' to 'graphql'.
Oct 21 2022, 1:40 PM · VyOS 1.4 Sagitta
Nova_Logic added a comment to T4470: Rewrite load-balancing wan to XML/Python.

@thetooth but according to current docs that exactly what is documented in docs: https://docs.vyos.io/en/equuleus/configuration/loadbalancing/index.html

Oct 21 2022, 11:15 AM · VyOS 1.5 Circinus
a.apostoliuk moved T4660: Reorganize route map set community CLI from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 21 2022, 8:18 AM · VyOS 1.4 Sagitta
a.apostoliuk moved T4492: Incorrect list of neighbors in help for "show bgp vrf VRF neighbors" from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 21 2022, 8:12 AM · VyOS 1.4 Sagitta
Unknown Object (User) assigned T4767: replace sh to Python (generate_ipsec_debug_archive.sh) to Viacheslav.
Oct 21 2022, 3:26 AM
Unknown Object (User) created T4767: replace sh to Python (generate_ipsec_debug_archive.sh).
Oct 21 2022, 3:25 AM

Oct 20 2022

Alfa80 created T4766: Enable Cross-Protocol Translation (relay).
Oct 20 2022, 6:47 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T4612: Support arbitrary netmasks in firewall rules.

Also, it can be wildcard-address
@Rain Could you create a PR?

Oct 20 2022, 4:08 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4720: Ability to configure SSH HostKeyAlgorithms, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from In progress to Needs testing.
Oct 20 2022, 3:28 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T4720: Ability to configure SSH HostKeyAlgorithms from In progress to Needs testing.
Oct 20 2022, 3:28 PM · VyOS 1.4 Sagitta
zsdc updated the task description for T4737: FRRouting/zebra 7.5.1 does not redistribute routes to other protocols.
Oct 20 2022, 1:49 PM · VyOS 1.3 Equuleus (1.3.3)
zsdc updated the task description for T4764: NAT tables vyos_nat and vyos_static_nat not deleting after deleting nat.
Oct 20 2022, 12:47 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4762: Show nat rules with empty rules incorrect error.

PR https://github.com/vyos/vyos-1x/pull/1606

Oct 20 2022, 12:02 PM · VyOS 1.4 Sagitta
dmbaturin created T4765: Normalize field names in op mode JSON outputs.
Oct 20 2022, 11:39 AM · VyOS 1.4 Sagitta
Viacheslav renamed T4764: NAT tables vyos_nat and vyos_static_nat not deleting after deleting nat from NAT tables vyos_nat and vyos_static_nat not delete after deleting nat to NAT tables vyos_nat and vyos_static_nat not deleting after deleting nat.
Oct 20 2022, 11:14 AM · VyOS 1.4 Sagitta
Viacheslav created T4764: NAT tables vyos_nat and vyos_static_nat not deleting after deleting nat.
Oct 20 2022, 11:14 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4763: Change XML for Show nat destination statistics, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Oct 20 2022, 10:43 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav changed the status of T4763: Change XML for Show nat destination statistics from Open to In progress.
Oct 20 2022, 10:43 AM · VyOS 1.4 Sagitta
Viacheslav created T4763: Change XML for Show nat destination statistics.
Oct 20 2022, 10:42 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4762: Show nat rules with empty rules incorrect error, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Oct 20 2022, 9:07 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav changed the status of T4762: Show nat rules with empty rules incorrect error from Open to In progress.
Oct 20 2022, 9:07 AM · VyOS 1.4 Sagitta
thetooth added a comment to T4470: Rewrite load-balancing wan to XML/Python.

@Nova_Logic no it would not function as intended, the reason is say you have 3 interfaces, and interface 1 has a metric of 1, 2 a metric of 2, etc. If a packet comes in off one of these interfaces it will be routed to it's destination with the appropriate DNAT rule, the source address is the initiators global unicast address with the mac of the router itself. Now when your service replies it's hosts routing table looks like

0.0.0.0/0 via routers-localaddr

The destination address is of course the remote global unicast address of the client and the source is the local area network address (information is still sufficient at this point), however the routers table will look like

0.0.0.0 via iface1 metric 1
0.0.0.0 via iface2 metric 2
0.0.0.0 via iface3 metric 3

So the reply will always go out iface1, source NAT happens post routing, so the source address of the reply packet from the initiating clients perspective has changed, thus being invalid and dropped by any correctly configured firewall.

Oct 20 2022, 5:40 AM · VyOS 1.5 Circinus

Oct 19 2022

c-po moved T4511: IPv6 DNS lookup from In Progress to Finished on the VyOS 1.4 Sagitta board.
Oct 19 2022, 5:42 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav changed Difficulty level from unknown to normal on T4762: Show nat rules with empty rules incorrect error.
Oct 19 2022, 5:38 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4762: Show nat rules with empty rules incorrect error from "Feature Request" to "Bug".
Oct 19 2022, 5:37 PM · VyOS 1.4 Sagitta