Page MenuHomeVyOS Platform
Feed All Stories

Feb 15 2023

sarthurdev committed rVYOSONEX819eab870836: debian: T5003: Fix chronyd start error.
Feb 15 2023, 6:06 PM
GitHub <noreply@github.com> committed rVYOSONEXc8a6b4cf2efe: Merge pull request #1817 from sarthurdev/bookworm (authored by c-po).
Feb 15 2023, 6:06 PM
jestabro committed rVYOSONEX694096f108c3: config_mgmt: T4991: use configtree.show_diff instead of Python difflib.
Feb 15 2023, 6:05 PM
GitHub <noreply@github.com> committed rVYOSONEXa48940a943d2: Merge pull request #1811 from jestabro/udiff (authored by c-po).
Feb 15 2023, 6:05 PM
sarthurdev committed rVYOSONEX45b16864b11e: ipsec: T4593: Migrate and remove legacy `include-ipsec` nodes.
Feb 15 2023, 6:03 PM
GitHub <noreply@github.com> committed rVYOSONEX63dfe01db5fb: Merge pull request #1821 from sarthurdev/ipsec (authored by c-po).
Feb 15 2023, 6:03 PM
Viacheslav committed rVYOSONEX21e3a0b0258f: T4971: Accel-ppp verify if client_ip_pool key exists in config.
Feb 15 2023, 6:03 PM
GitHub <noreply@github.com> committed rVYOSONEXc4d26a3aaca6: Merge pull request #1822 from sever-sever/T4971 (authored by c-po).
Feb 15 2023, 6:03 PM
jestabro changed the status of T5006: Http api segfault with concurrent requests from In progress to Needs testing.
Feb 15 2023, 5:09 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jestabro added a comment to T5006: Http api segfault with concurrent requests.

@ammmze That PR is merged, so will be in the next rolling. Kindly let me know of any remaining or other issues you see. I'll add autocannon to my common tests; thanks again for that tip.

Feb 15 2023, 5:09 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jestabro committed rVYOSONEX53bc5334d4da: http-api: T5006: add explicit async to retrieve/configure methods.
Feb 15 2023, 5:01 PM
GitHub <noreply@github.com> committed rVYOSONEXd530c0363df1: Merge pull request #1823 from jestabro/api-async (authored by Viacheslav).
Feb 15 2023, 5:01 PM
jestabro added a comment to T5006: Http api segfault with concurrent requests.

PR:
https://github.com/vyos/vyos-1x/pull/1823

Feb 15 2023, 4:36 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav added a comment to T4971: Radius attribute "Framed-Pool" for PPPoE.

Fix
PR 1.4 https://github.com/vyos/vyos-1x/pull/1822
PR 1.3 https://github.com/vyos/vyos-1x/pull/1824

Feb 15 2023, 3:55 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4971: Radius attribute "Framed-Pool" for PPPoE.
 service {
+    pppoe-server {
+        authentication {
+            mode radius
+            radius {
+                server 172.31.255.2 {
+                    key 123456
+                }
+            }
+        }
+        interface eth1 {
+        }
+    }
 }

when I commit, throws me:

Traceback (most recent call last):
  File "/usr/libexec/vyos/conf_mode/service_pppoe-server.py", line 114, in <module>
    verify(c)
  File "/usr/libexec/vyos/conf_mode/service_pppoe-server.py", line 60, in verify
    verify_accel_ppp_base_service(pppoe)
  File "/usr/lib/python3/dist-packages/vyos/configverify.py", line 424, in verify_accel_ppp_base_service
    for _, v in config['client_ip_pool']['name'].items():
KeyError: 'client_ip_pool'
Feb 15 2023, 3:19 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5008: MACsec CKN of 32 chars is not allowed in CLI, but works fine from Open to In progress.
Feb 15 2023, 2:40 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort changed the status of T5009: op-mode command: restart dhcp relay-agent not working from In progress to Needs testing.
Feb 15 2023, 2:36 PM · VyOS 1.3 Equuleus (1.3.3)
a.apostoliuk claimed T5008: MACsec CKN of 32 chars is not allowed in CLI, but works fine.
Feb 15 2023, 1:59 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4943: Radius SSH login displays "permission denied" on 1.4 rolling release.

Some debugging, the authentication with user vyosunpriv

Feb 15 2023, 1:44 PM · VyOS 1.4 Sagitta
tflabs-nl added a comment to T5010: bgp: EVPN route-target not honored.
set protocols bgp address-family l2vpn-evpn vni 100070 route-target both 70:100070

Should return an error, as this is not implemented.

Feb 15 2023, 1:28 PM · VyOS 1.4 Sagitta
tflabs-nl updated the task description for T5010: bgp: EVPN route-target not honored.
Feb 15 2023, 12:26 PM · VyOS 1.4 Sagitta
tflabs-nl updated the task description for T5010: bgp: EVPN route-target not honored.
Feb 15 2023, 12:26 PM · VyOS 1.4 Sagitta
tflabs-nl created T5010: bgp: EVPN route-target not honored.
Feb 15 2023, 12:24 PM · VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4593: Upgrade strongswan to 5.9.8.

I was wrong. NOT 6 CHILSD_SAs on one tunnel.
6 IKE SAs on one configured tunnel.

Feb 15 2023, 11:50 AM · VyOS 1.4 Sagitta
Viacheslav claimed T5005: Skip user authentication for PPPoE Server with noauth option.
Feb 15 2023, 10:47 AM · VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4593: Upgrade strongswan to 5.9.8.

I met 2 issues after the last commit.
My config:

Feb 15 2023, 10:11 AM · VyOS 1.4 Sagitta
a.apostoliuk moved T4993: Can't delete conntrack ignore rule from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Feb 15 2023, 9:22 AM · VyOS 1.3 Equuleus (1.3.3)
a.apostoliuk moved T4993: Can't delete conntrack ignore rule from Finished to 1.3.3 on the VyOS 1.3 Equuleus board.
Feb 15 2023, 9:22 AM · VyOS 1.3 Equuleus (1.3.3)
a.apostoliuk closed T4993: Can't delete conntrack ignore rule as Resolved.
Feb 15 2023, 9:19 AM · VyOS 1.3 Equuleus (1.3.3)
a.apostoliuk moved T4993: Can't delete conntrack ignore rule from 1.3.3 to Finished on the VyOS 1.3 Equuleus board.
Feb 15 2023, 9:18 AM · VyOS 1.3 Equuleus (1.3.3)
a.apostoliuk reopened T4993: Can't delete conntrack ignore rule as "In progress".
Feb 15 2023, 9:18 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav edited projects for T5009: op-mode command: restart dhcp relay-agent not working, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus.
Feb 15 2023, 9:08 AM · VyOS 1.3 Equuleus (1.3.3)
a.apostoliuk changed the status of T4985: reset vpn ipsec-peer command with peer name does not work from In progress to Needs testing.
Feb 15 2023, 8:49 AM · VyOS 1.4 Sagitta
Viacheslav triaged T4992: Incorrect check is_local_address for bgp neighbor with option ip_nonlocal_bind set as High priority.
Feb 15 2023, 8:29 AM · VyOS 1.3 Equuleus (1.3.3)
ammmze added a comment to T5006: Http api segfault with concurrent requests.

Awesome, I am glad to hear the provided info was helpful! Thank you for the quick investigation and explanation.

Feb 15 2023, 6:11 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta

Feb 14 2023

c-po committed rVYOSONEXe70abc2ea842: smoketest: tftp: T4012: extend process scanning loop for VRFs.
Feb 14 2023, 11:21 PM
GitHub <noreply@github.com> committed rVYOSONEXbf99fd112254: Merge pull request #1818 from c-po/equuleus (authored by dmbaturin).
Feb 14 2023, 11:21 PM
n.fort committed rVYOSONEX0bd37e4718ec: T5009: relay: correct service name for restarting dhcp relay service.
Feb 14 2023, 11:19 PM
GitHub <noreply@github.com> committed rVYOSONEX9538a74382ff: Merge pull request #1820 from nicolas-fort/T5009-restart-relay (authored by dmbaturin).
Feb 14 2023, 11:19 PM
jestabro triaged T5006: Http api segfault with concurrent requests as High priority.
Feb 14 2023, 10:06 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jestabro changed the status of T5006: Http api segfault with concurrent requests from Open to In progress.
Feb 14 2023, 10:05 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jestabro added a comment to T5006: Http api segfault with concurrent requests.

Again, thanks for the detailed reproducer; that made investigation straightforward. This appears to be simply an 'async' issue for FastAPI, the underlying web framework for vyos-http-api. FastAPI is very good at managing red/blue issues automatically, but in this case we need to explicitly annotate the endpoint method with async: an explicit lock does not appear necessary, though I will need to confirm. I'll provide a PR shortly. Thanks again !

Feb 14 2023, 10:04 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
n.fort changed the status of T5009: op-mode command: restart dhcp relay-agent not working from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/1820

Feb 14 2023, 7:04 PM · VyOS 1.3 Equuleus (1.3.3)
c-po committed rVYOSONEXe0e550ad1187: strongSwan: T4593: move to charon-systemd.
Feb 14 2023, 6:47 PM
n.fort added a comment to T5004: DHCP-Relay potential bug. Static configurations of DHCP-Relay Interfaces.

Thanks Keving: https://vyos.dev/T5009

Feb 14 2023, 6:44 PM · VyOS Rolling
n.fort changed the status of T5009: op-mode command: restart dhcp relay-agent not working from Open to Confirmed.
Feb 14 2023, 6:44 PM · VyOS 1.3 Equuleus (1.3.3)
n.fort created T5009: op-mode command: restart dhcp relay-agent not working.
Feb 14 2023, 6:43 PM · VyOS 1.3 Equuleus (1.3.3)
n.fort added a comment to T4601: dhcp : relay agent IP address issue..

Error still present in 1.4: https://vyos.dev/T5004

Feb 14 2023, 6:36 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
kevin.roberts.sealingtech added a comment to T5004: DHCP-Relay potential bug. Static configurations of DHCP-Relay Interfaces.

FYI When I was troubleshooting I used:

Feb 14 2023, 5:53 PM · VyOS Rolling
n.fort added a comment to T5004: DHCP-Relay potential bug. Static configurations of DHCP-Relay Interfaces.

In Both version, restarting relay service solved the issue:

Feb 14 2023, 5:37 PM · VyOS Rolling
a.apostoliuk committed rVYOSONEX2e61af88961d: ipsec: T4985: Fixed 'reset vpn ipsec-peer {peer}' command.
Feb 14 2023, 4:42 PM
GitHub <noreply@github.com> committed rVYOSONEXbfbc88defa84: Merge pull request #1819 from aapostoliuk/T4985-sagitta (authored by c-po).
Feb 14 2023, 4:42 PM
zsdc changed the status of T4992: Incorrect check is_local_address for bgp neighbor with option ip_nonlocal_bind set from Confirmed to In progress.

PR with a fix: https://github.com/vyos/vyatta-cfg/pull/61

Feb 14 2023, 4:30 PM · VyOS 1.3 Equuleus (1.3.3)
n.fort changed Version from VyOS LTS 1.3.2 to VyOS LTS 1.3.2 - vyos-1.4-rolling-202302140317 on T5004: DHCP-Relay potential bug. Static configurations of DHCP-Relay Interfaces.
Feb 14 2023, 3:19 PM · VyOS Rolling
n.fort changed the status of T5004: DHCP-Relay potential bug. Static configurations of DHCP-Relay Interfaces from Open to Confirmed.
Feb 14 2023, 3:19 PM · VyOS Rolling
n.fort added a comment to T5004: DHCP-Relay potential bug. Static configurations of DHCP-Relay Interfaces.

I can confirm this behavior, which occurs when changing IP address on listening interface (where dhcp-discover is captured).
Issue present in 1.3.2 .
It's also present in latest vyos-1.4-rolling-202302140317, regardless if old interface syntax is used, or if new upstream-interfces plus listen-interface commands are used.

Feb 14 2023, 3:18 PM · VyOS Rolling
jestabro claimed T5006: Http api segfault with concurrent requests.

@ammmze Thanks for the detailed report; allow me to investigate.

Feb 14 2023, 2:31 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
anon3fe35 added a comment to T4978: KeyError: 'memory' container_config['memory'] on upgrading to 1.4-rolling-202302041536.

Here's the commands I ran for node-exporter:

Feb 14 2023, 2:28 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
danhusan added a comment to T3700: Support VLAN tunnel mapping of VLAN aware bridges.

https://github.com/FRRouting/frr/pull/12364
riw777 merged commit 91b6db4 into FRRouting:master Feb 14, 2023

Feb 14 2023, 2:24 PM · VyOS 1.4 Sagitta
Viacheslav closed T4999: vyos.util backport dict_search_recursive as Resolved.
Feb 14 2023, 10:29 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav closed T1993: Extended pppoe rate-limiter as Resolved.
Feb 14 2023, 10:28 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
iliessens created T5008: MACsec CKN of 32 chars is not allowed in CLI, but works fine.
Feb 14 2023, 9:55 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
syncer triaged T4782: Allow multiple CA certificates (on e.g. EAPoL) as Low priority.
Feb 14 2023, 8:25 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T4968: VPN IPsec check dpd and close action for empty values as Resolved.
Feb 14 2023, 8:17 AM · VyOS 1.4 Sagitta
a.apostoliuk moved T4968: VPN IPsec check dpd and close action for empty values from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 14 2023, 8:16 AM · VyOS 1.4 Sagitta
jack9603301 created T5007: Interface multicast setting is invalid.
Feb 14 2023, 7:59 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4968: VPN IPsec check dpd and close action for empty values from Open to Needs testing.
Feb 14 2023, 7:54 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4985: reset vpn ipsec-peer command with peer name does not work from Open to In progress.
Feb 14 2023, 7:53 AM · VyOS 1.4 Sagitta
a.apostoliuk claimed T4985: reset vpn ipsec-peer command with peer name does not work .
Feb 14 2023, 7:53 AM · VyOS 1.4 Sagitta
c-po added a comment to T4774: Disallow duplicate pubkey on peers of a wireguard interface.

You can either run both address-families through one tunnel

Feb 14 2023, 7:16 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
ammmze updated the task description for T5006: Http api segfault with concurrent requests.
Feb 14 2023, 5:47 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
ammmze updated the task description for T5006: Http api segfault with concurrent requests.
Feb 14 2023, 5:46 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
ammmze created T5006: Http api segfault with concurrent requests.
Feb 14 2023, 5:39 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
jzatarski added a comment to T4782: Allow multiple CA certificates (on e.g. EAPoL).

Is there any kind of ETA on this? It hasn't moved in a few months, and it is preventing me from being able to upgrade. I understand this probably isn't a huge priority, but an ETA would be nice.

Feb 14 2023, 12:21 AM · VyOS 1.4 Sagitta

Feb 13 2023

fernandolcx created T5005: Skip user authentication for PPPoE Server with noauth option.
Feb 13 2023, 7:37 PM · VyOS 1.4 Sagitta
kevin.roberts.sealingtech added a comment to T5004: DHCP-Relay potential bug. Static configurations of DHCP-Relay Interfaces.

Can you provide this configuration on both setups:

show config comm | grep relay

# And route to relay server
show ip route <relay_server>
Feb 13 2023, 7:23 PM · VyOS Rolling
n.fort added a comment to T5004: DHCP-Relay potential bug. Static configurations of DHCP-Relay Interfaces.

Can you provide this configuration on both setups:

Feb 13 2023, 6:53 PM · VyOS Rolling
kevin.roberts.sealingtech created T5004: DHCP-Relay potential bug. Static configurations of DHCP-Relay Interfaces.
Feb 13 2023, 6:02 PM · VyOS Rolling
sarthurdev added a comment to T5003: Upgrade base system to Debian 12 "Bookworm".

https://github.com/vyos/vyos-build/pull/306
https://github.com/vyos/vyos-1x/pull/1817
https://github.com/vyos/vyatta-cfg/pull/60
https://github.com/vyos/vyos-http-api-tools/pull/3

Feb 13 2023, 5:57 PM · VyOS 1.4 Sagitta
a.apostoliuk committed rVYOSONEXb0f34f5fbdb0: ipsec: T4968: Added default values to dpd and close action.
Feb 13 2023, 5:07 PM
GitHub <noreply@github.com> committed rVYOSONEX3d12327f39b9: Merge pull request #1816 from aapostoliuk/T4968-sagitta (authored by c-po).
Feb 13 2023, 5:07 PM
Viacheslav committed rVYOSONEX209dc64ca31f: T4971: Add accel-ppp include client-ip-pool-name.
Feb 13 2023, 4:38 PM
Viacheslav committed rVYOSONEXa55bbcc8ec25: T4999: Backport vyos util dict_search_recursive.
Feb 13 2023, 4:38 PM
Viacheslav committed rVYOSONEXe7e81746e6ad: T4971: PPPoE server add named ip pool and attr Framed-Pool.
Feb 13 2023, 4:38 PM
GitHub <noreply@github.com> committed rVYOSONEX5e56daaff4ec: Merge pull request #1813 from sever-sever/T4971-eq (authored by c-po).
Feb 13 2023, 4:38 PM
n.fort changed the status of T4153: Monitor bandwidth-test initiate not working from Unknown Status to Resolved.

Then lets close it

Feb 13 2023, 3:47 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort added a comment to T4376: DNAT with multiwan and policy routing, incoming connections only work on primary interface.

I have prepared a configuration example using one of the latest 1.4 images, where more features were introduced.
Scenario and requirements:

  • One vyos router
  • 3 Uplinks to internet (eth0, eth1 and eth2). Static IP used on three links
  • 2 VLANs
    • vif 2: + New Connections from vif-2 routed through WAN-2 + Server on vif 2 should accept ssh connections from internet, through dnat on 3 WAN interfaces (outside port 122)
    • vif 4: + NewConnections from vif-24routed through WAN-2 + Server on vif 4 should accept ssh connections from internet, through dnat on 3 WAN interfaces (outside port 222)
Feb 13 2023, 3:07 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX8c98ceeee57d: T1993: PPPoE-server add section shaper and fwmark option.
Feb 13 2023, 3:06 PM
GitHub <noreply@github.com> committed rVYOSONEX9c481b00cae8: Merge pull request #1812 from sever-sever/T1993-eq (authored by dmbaturin).
Feb 13 2023, 3:06 PM
c-po committed rVYOSONEXb6290329f2d6: T5001: Replace links to the phabricator site.
Feb 13 2023, 2:35 PM
GitHub <noreply@github.com> committed rVYOSONEXe7d80294ca5a: Merge pull request #1815 from c-po/equuleus (authored by dmbaturin).
Feb 13 2023, 2:35 PM
Viacheslav added a comment to T4153: Monitor bandwidth-test initiate not working.

Don't see any issue with 1.3

vyos@r1:~$ monitor bandwidth-test initiate 192.168.122.14
------------------------------------------------------------
Client connecting to 192.168.122.14, TCP port 5001
TCP window size: 85.0 KByte (default)
------------------------------------------------------------
[  3] local 192.168.122.11 port 58042 connected with 192.168.122.14 port 5001
[ ID] Interval       Transfer     Bandwidth
[  3]  0.0-10.0 sec  6.37 GBytes  5.47 Gbits/sec
vyos@r1:~$ 
vyos@r1:~$ show version
Feb 13 2023, 12:09 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk closed T4993: Can't delete conntrack ignore rule as Resolved.
Feb 13 2023, 10:28 AM · VyOS 1.3 Equuleus (1.3.3)
a.apostoliuk changed the status of T4993: Can't delete conntrack ignore rule from In progress to Needs testing.
Feb 13 2023, 10:28 AM · VyOS 1.3 Equuleus (1.3.3)
RyVolodya added a comment to T4153: Monitor bandwidth-test initiate not working.

Everything works on version 1.4

Feb 13 2023, 10:12 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk closed T4905: Convert show nhrp tunnel to tabulate format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Feb 13 2023, 9:58 AM · VyOS Rolling
a.apostoliuk closed T4905: Convert show nhrp tunnel to tabulate format as Resolved.
Feb 13 2023, 9:58 AM · VyOS 1.4 Sagitta
a.apostoliuk moved T4905: Convert show nhrp tunnel to tabulate format from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 13 2023, 9:58 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4905: Convert show nhrp tunnel to tabulate format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Feb 13 2023, 9:58 AM · VyOS Rolling
a.apostoliuk changed the status of T4905: Convert show nhrp tunnel to tabulate format from In progress to Needs testing.
Feb 13 2023, 9:58 AM · VyOS 1.4 Sagitta