In T4891#139693, @RyVolodya wrote:I reproduced this configuration. Version VyOS 1.4-rolling-202212270317 - BFD works fine.
Configuration:
set interfaces ethernet eth0 address '10.221.3.18/30' set interfaces ethernet eth0 mtu '9000' set interfaces ethernet eth0 offload gro set interfaces ethernet eth0 offload gso set interfaces ethernet eth0 offload sg set interfaces ethernet eth0 offload tsoBFD peer status:
BFD Peers: peer 10.221.3.17 vrf default ID: 2428685750 Remote ID: 2382320760 Active mode Status: up Uptime: 30 minute(s), 19 second(s) Diagnostics: ok Remote diagnostics: ok Peer Type: configured RTT min/avg/max: 0/0/0 usec Local timers: Detect-multiplier: 5 Receive interval: 100ms Transmission interval: 100ms Echo receive interval: 50ms Echo transmission interval: disabled Remote timers: Detect-multiplier: 5 Receive interval: 100ms Transmission interval: 100ms Echo receive interval: 50ms [edit]Try upgrading the VyOS to the latest version.
- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
Feed All Stories
All Stories
All Stories
Apr 11 2023
Apr 11 2023
Apr 10 2023
Apr 10 2023
Viacheslav changed the status of T5012: Control network configuration from Cloud-Init config from In progress to Needs testing.
Fixed in T5047
Viacheslav changed the status of T5065: Mixing `destination port xxx` and `destination group port-group yyy` in firewall rules doesn't work, but can be commited from In progress to Needs testing.
GitHub <noreply@github.com> committed rVYOSONEXc5cd065773a0: Merge pull request #1936 from indrajitr/ddclient-opmode (authored by c-po).
GitHub <noreply@github.com> committed rVYOSONEX37b98709d96d: Merge pull request #1947 from sever-sever/T5148 (authored by c-po).
GitHub <noreply@github.com> committed rVYOSONEXc8562d33e7d9: Merge pull request #1949 from sever-sever/T5065 (authored by c-po).
GitHub <noreply@github.com> committed rVYOSONEX40f60ae63e0d: Merge pull request #1948 from chenxiaolong/T5151 (authored by c-po).
Unknown Object (User) added a comment to T425: AWS CloudWatch monitoring scripts.
Notice. Initially this task was about monitoring scripts but they were deprecated. Then aws-cloudwatch-agent emerged.
aws-cloudwatch-agent was successfully added to vyos-build:equuleus. But cloudwatch configuration preservation between image updates is not.
This task was closed mistakenly prematurely thus should be reopen.
Viacheslav changed the status of T5065: Mixing `destination port xxx` and `destination group port-group yyy` in firewall rules doesn't work, but can be commited from Open to In progress.
I found the issue. This was caused by bumping the debian packaging scripts from debian/2%2.10-10 to debian/2%2.10-12, which includes https://salsa.debian.org/debian/wpa/-/commit/d204ceb5a2dc33db888eb55b5fee542a1005e69c. This is not compatible with vyos because vyos uses a config path in /run.
Thanks, I ran the ethernet smoke tests, but not the wireless ones. I'll investigate right away.
Viacheslav closed T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes' as Resolved.
So we can close it. Thank you for contributing.
tfiebig added a comment to T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes'.
kk, will try to remember to setup a box for that; Usually rolling my own images. ;-)
Viacheslav added a comment to T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes'.
Just waiting for a new rolling image and checking that those commands are present for CLI :)
If all goods we can close it
Viacheslav changed the subtype of T5122: Move "archive-areas" to defaults.toml to support "non-free-firmware" repository from "Task" to "Feature Request".
tfiebig added a comment to T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes'.
What is meant with testing? Writing the unit tests? Or seeing whether it actually works? If it is the latter, this is in prod on my boxes for roughly a month ;-)
Targets and logs will be fixed in the next rolling release
GitHub <noreply@github.com> committed rVYOSONEX3593ecfa51a6: Merge pull request #1941 from sever-sever/T1237 (authored by Viacheslav).
sskaje added a comment to T5122: Move "archive-areas" to defaults.toml to support "non-free-firmware" repository.
My fault, the double quotes were mis-removed in the PR when cleaning code.
Viacheslav added a comment to T5148: OpenVPN cannot start due to could not load plugin shared object /openvpn-otp.so.
Smoketest PR https://github.com/vyos/vyos-1x/pull/1947
Viacheslav changed the status of T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes' from Open to Needs testing.
GitHub <noreply@github.com> committed rVYOSONEX28c01a860582: Merge pull request #1942 from sever-sever/T4770 (authored by dmbaturin).
Viacheslav changed the status of T5148: OpenVPN cannot start due to could not load plugin shared object /openvpn-otp.so from In progress to Needs testing.
GitHub <noreply@github.com> committed rVYOSONEX14cbda871f7e: Merge pull request #1946 from ichdasich/filtered_routes (authored by dmbaturin).
GitHub <noreply@github.com> committed rVYOSONEX0ae6ad7af43c: Merge pull request #1945 from sever-sever/T5148 (authored by dmbaturin).
tfiebig added a comment to T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes'.
done
After applying above rules an a system without any qos configured, it failed to create the redirect, commit was succesfull but tc disk show did not show the redirect. After removing and applying the redirect between commits, the redirect was present.
Changing the max bandwidth to 10mbit and commiting removed the redirect again.
Viacheslav added a comment to T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes'.
Create please the PR
Thanks.
Viacheslav closed T5110: Show frr op-mode vtysh_pam: Failed in account validation, a subtask of T5100: Update FRR to 8.5, as Resolved.
It cannot pass the smoketest /usr/libexec/vyos/tests/smoke/cli/test_interfaces_wireless.py
06:48:28 DEBUG - test_wireless_access_point_bridge (__main__.WirelessInterfaceTest.test_wireless_access_point_bridge) ... FAIL 06:48:29 DEBUG - test_wireless_access_point_bridge (__main__.WirelessInterfaceTest.test_wireless_access_point_bridge) ... ERROR 06:48:30 DEBUG - test_wireless_add_single_ip_address (__main__.WirelessInterfaceTest.test_wireless_add_single_ip_address) ... ERROR 06:48:32 DEBUG - test_wireless_add_single_ip_address (__main__.WirelessInterfaceTest.test_wireless_add_single_ip_address) ... ERROR 06:48:33 DEBUG - test_wireless_hostapd_config (__main__.WirelessInterfaceTest.test_wireless_hostapd_config) ... FAIL 06:48:34 DEBUG - test_wireless_hostapd_config (__main__.WirelessInterfaceTest.test_wireless_hostapd_config) ... ERROR 06:48:37 DEBUG - test_wireless_hostapd_wpa_config (__main__.WirelessInterfaceTest.test_wireless_hostapd_wpa_config) ... FAIL 06:48:38 DEBUG - test_wireless_hostapd_wpa_config (__main__.WirelessInterfaceTest.test_wireless_hostapd_wpa_config) ... ERROR
syncer reopened T425: AWS CloudWatch monitoring scripts, a subtask of T5129: Add AWS build flavour, as Open.
Requires some additional work
we need to preserve configuration between upgrade
alternatively, we need to investigate if default config can be used with VM role
Viacheslav changed the status of T5148: OpenVPN cannot start due to could not load plugin shared object /openvpn-otp.so from Open to In progress.
Viacheslav moved T5151: EAP-TLS TLSv1.0/1.1 regression after T5003 from Open to Finished on the VyOS 1.4 Sagitta board.
Closing as resolved because the PRs were merged (thanks for the quick review!)
Apr 9 2023
Apr 9 2023
GitHub <noreply@github.com> committed rVYOSONEXf5d40cf3cf8b: Merge pull request #1944 from chenxiaolong/eapol_tls_1.0_regression (authored by c-po).
For eapol specifically, if your use case involves only a single chain (1 root CA + 1 or more intermediate CAs), then my fix from T4245 should do the trick. You can add each root/intermediate CA to the PKI and then set eapol to the leaf intermediate CA. When the wpa_supplicant configuration is generated, vyos will add the intermediate CA and all of its parents to the .crt file.
Submitted PRs:
Apr 8 2023
Apr 8 2023
c-po changed the status of T5150: Rework CLI definitions to apply route-maps between routing daemons and zebra/kernel from Open to In progress.
c-po updated the task description for T5150: Rework CLI definitions to apply route-maps between routing daemons and zebra/kernel.
Apr 7 2023
Apr 7 2023
jestabro closed T5149: op-mode openvpn should not raise error in case interface is disabled as Resolved.
jestabro triaged T5149: op-mode openvpn should not raise error in case interface is disabled as Normal priority.
Viacheslav added a comment to T5148: OpenVPN cannot start due to could not load plugin shared object /openvpn-otp.so.
Otp not configured
Viacheslav updated the task description for T5148: OpenVPN cannot start due to could not load plugin shared object /openvpn-otp.so.
Apr 6 2023
Apr 6 2023
We have targets-checks 203.0.113.1, 192.0.2.1, and if any of these targets are unreachable, we delete this route.
Is it correct?
@c-po How is the review and discussion on this feature going?
Viacheslav closed T5125: Add op-mode commands for hsflowd based sflow, a subtask of T5086: Integrate hsflowd for sflow accounting, as Resolved.
Viacheslav closed T5146: Show recent login of all users, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, as Invalid.
A similar output exists
show system login users Possible completions: <Enter> Execute the current command all Show information about all accounts locked Show information about locked accounts other Show information about non VyOS user accounts vyos Show information about VyOS user accounts`
Apr 5 2023
Apr 5 2023
Viacheslav changed the status of T5146: Show recent login of all users, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
GitHub <noreply@github.com> committed rVYOSONEX0b0f991a8646: Merge pull request #1928 from c-po/t4959-backport (authored by c-po).
c-po closed T425: AWS CloudWatch monitoring scripts, a subtask of T5129: Add AWS build flavour, as Resolved.
c-po moved T5136: Possible config corruption on upgrade from Backport Candidates to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Viacheslav closed T5145: Add maxsyslogins maximum number of all logins on system , a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, as Resolved.
In T4362#146398, @Viacheslav wrote:@marc_s Will be fixed in the next rolling release, could you check?