Page MenuHomeVyOS Platform
Feed All Stories

Apr 28 2023

spion06 added a comment to T4974: OpenVPN- Data Channel Offload(DCO).

I made an attempt at integrating openvpn-dco into the build here https://github.com/spion06/vyos-build/tree/ovpn-dco. This works fine for me in my testing so far. The kernel module loaded, verified in the logs that it detected and used the dco tunnel. I'm not super familiar with the build system or what else would need to be done for contributing this. I'm just and end-user who would like to see this feature :)

Apr 28 2023, 12:39 AM · VyOS 1.4 Sagitta

Apr 27 2023

zsdc changed the status of T5190: Cloud-Init cannot fetch Meta-data on machines where the main Ethernet interface is not eth0 from Open to In progress.
Apr 27 2023, 10:31 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
zsdc created T5190: Cloud-Init cannot fetch Meta-data on machines where the main Ethernet interface is not eth0.
Apr 27 2023, 10:31 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po moved T5010: bgp: EVPN route-target not honored from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 27 2023, 8:36 PM · VyOS 1.4 Sagitta
c-po changed the status of T5010: bgp: EVPN route-target not honored from Open to Needs testing.
Apr 27 2023, 8:35 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX78a9eaaf8be3: bgp: T5010: add verify() for L2VPN EVPN route-distinguisher and route-target.
Apr 27 2023, 8:35 PM
c-po committed rVYOSONEXe624d9c6cac6: bgp: T5010: fix for-loop copy/paste error.
Apr 27 2023, 8:35 PM
c-po added a reverting change for rVYOSONEXbfe57cf80f4c: bgp: T3734: only support "l2vpn-evpn advertise-all-vni" in default VRF: rVYOSONEX20eee1c4e17b: Revert "bgp: T3734: only support "l2vpn-evpn advertise-all-vni" in default VRF".
Apr 27 2023, 8:03 PM
c-po committed rVYOSONEX923d7f1d75a4: bgp: T5010: add missing for-loop when iterating over "both" route-target.
Apr 27 2023, 8:03 PM
c-po committed rVYOSONEX20eee1c4e17b: Revert "bgp: T3734: only support "l2vpn-evpn advertise-all-vni" in default VRF".
Apr 27 2023, 8:03 PM
c-po created T5189: bgp: add evpn anycast gateway support.
Apr 27 2023, 7:54 PM · VyOS Rolling
c-po added a comment to T5010: bgp: EVPN route-target not honored.

Your CLI config is valid in general but FRR will refuse it with the error message: This command is only supported under EVPN VRF

Apr 27 2023, 7:29 PM · VyOS 1.4 Sagitta
c-po closed T5174: vrf: ensure no duplicate VNIs can be created as Resolved.
Apr 27 2023, 6:48 PM · VyOS 1.4 Sagitta
Viacheslav closed T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd as Resolved.
Apr 27 2023, 6:45 PM · VyOS 1.4 Sagitta
jestabro closed T5185: Static IPv6 route with blackhole fails as Resolved.
Apr 27 2023, 4:20 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX9d7c9af77992: T5181: Fix condition to detect correct vrf name for vrf-vni.
Apr 27 2023, 4:17 PM
GitHub <noreply@github.com> committed rVYOSONEXc2e8bbc64a5c: Merge pull request #1972 from sever-sever/T5181 (authored by c-po).
Apr 27 2023, 4:17 PM
Viacheslav edited projects for T5188: Update Intel igc driver for improved 2.5 GbE support, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus.
Apr 27 2023, 4:15 PM · VyOS 1.3 Equuleus (1.3.8)
Viacheslav closed T5183: IPv6 route6 problem as Resolved.
Apr 27 2023, 4:14 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.

PR https://github.com/vyos/vyos-1x/pull/1972

Apr 27 2023, 4:12 PM · VyOS 1.4 Sagitta
pasik created T5188: Update Intel igc driver for improved 2.5 GbE support.
Apr 27 2023, 3:29 PM · VyOS 1.3 Equuleus (1.3.8)
oTamurazo added a comment to T5185: Static IPv6 route with blackhole fails.

Dear Jestabro,
i built an updated docker image and a new ISO, i do confirm now IPv6 is working correctly.

Apr 27 2023, 3:23 PM · VyOS 1.4 Sagitta
zsdc changed the status of T5187: Update Realtek r8152 driver from Open to In progress.

PR: https://github.com/vyos/vyos-build/pull/343

Apr 27 2023, 2:43 PM · VyOS 1.3 Equuleus (1.3.6)
dmbaturin committed rVYOSONEXf32348935adc: conntrack-sync: T4888: rewrite the op mode script in the new format.
Apr 27 2023, 2:31 PM
GitHub <noreply@github.com> committed rVYOSONEX5875f9a5e365: Merge pull request #1721 from dmbaturin/T4888-conntrack-sync-op-mode (authored by jestabro).
Apr 27 2023, 2:31 PM
zsdc created T5187: Update Realtek r8152 driver.
Apr 27 2023, 2:17 PM · VyOS 1.3 Equuleus (1.3.6)
jestabro changed the status of T5175: http-api: error in MultiPart parser for FastAPI version >= 0.91.0 from Unknown Status to Resolved.
Apr 27 2023, 2:09 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro changed the status of T5176: http-api: update vyos-http-api-tools for FastAPI security vulnerability, a subtask of T5175: http-api: error in MultiPart parser for FastAPI version >= 0.91.0, from Unknown Status to Resolved.
Apr 27 2023, 2:03 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro changed the status of T5176: http-api: update vyos-http-api-tools for FastAPI security vulnerability from Unknown Status to Resolved.
Apr 27 2023, 2:02 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro committed rVYOSONEXb8920d636aec: http-api: T5175: check value of attribute for FastAPI>=0.91.0.
Apr 27 2023, 1:26 PM
GitHub <noreply@github.com> committed rVYOSONEX2c5307d42e0d: Merge pull request #1969 from jestabro/eq-multipart-parser (authored by dmbaturin).
Apr 27 2023, 1:26 PM
diodep closed T5123: Display route originator in show ospf table command as Resolved.

Ok, if we merge the patch (backported to frr v8.5), this task can be close.

Apr 27 2023, 12:37 PM · VyOS 1.4 Sagitta
n.fort closed T5037: Firewall - Add queue action as Resolved.
Apr 27 2023, 11:23 AM · VyOS 1.4 Sagitta
n.fort closed T5050: Firewall - Add options for logging packets as Resolved.
Apr 27 2023, 11:21 AM · VyOS 1.4 Sagitta
n.fort closed T5055: Firewall - Add packet type matcher (pkttype) as Resolved.
Apr 27 2023, 11:20 AM · VyOS 1.4 Sagitta
n.fort closed T5128: Policy route - Allow wildcard interfaces as Resolved.
Apr 27 2023, 11:19 AM · VyOS 1.4 Sagitta
diodep added a comment to T5123: Display route originator in show ospf table command.
Apr 27 2023, 10:13 AM · VyOS 1.4 Sagitta
Viacheslav reopened T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd as "Needs testing".
Apr 27 2023, 9:53 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5186: QoS test cannot pass for 1.3.
Apr 27 2023, 8:10 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav triaged T5186: QoS test cannot pass for 1.3 as High priority.
Apr 27 2023, 8:00 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav edited projects for T5186: QoS test cannot pass for 1.3, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.4 Sagitta.
Apr 27 2023, 7:59 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav updated the task description for T5186: QoS test cannot pass for 1.3.
Apr 27 2023, 7:58 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav created T5186: QoS test cannot pass for 1.3.
Apr 27 2023, 7:56 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T5116: Better VRF support.

I think the only solution is to use network namespaces
https://docs.strongswan.org/docs/5.9/howtos/nameSpaces.html

Apr 27 2023, 7:37 AM · VyOS Rolling
joshua.hanley added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

Usernames usually take the following format: abc-1234-12
Passwords are a combination of alphanumeric characters.

Apr 27 2023, 7:11 AM · VyOS 1.4 Sagitta
diodep added a comment to T5116: Better VRF support.
In T5116#147640, @c-po wrote:

Do you know how to tell Linux to use nameservers within a VRF?
What you mean IPSec/OpenVPN "punch a tunnel through a VRF" ? So the underlay should run via a VRF? source-interface binding does not work?

Apr 27 2023, 6:21 AM · VyOS Rolling

Apr 26 2023

c-po committed rVYOSONEX1cf55506151c: bgp: T5181: FRR can not tear down VRF isntance if l3vni is still configured.
Apr 26 2023, 10:13 PM
c-po committed rVYOSONEX71e45dd1c473: vrf: T5174: ensure no duplicate VNIs can be defined.
Apr 26 2023, 10:13 PM
jestabro added a comment to T5183: IPv6 route6 problem.

Thanks for opening the task; note that Viacheslav had opened
https://vyos.dev/T5185
as well, and the updates on the now fixed issue can be found there. This task can be merged into that one and closed.

Apr 26 2023, 8:03 PM · VyOS 1.4 Sagitta
jestabro added a comment to T5185: Static IPv6 route with blackhole fails.

Merged and repos updated, so this will be in the next nightly build. Note that for a local build, one will need an updated Docker image for the update to vyos1x-config.

Apr 26 2023, 8:00 PM · VyOS 1.4 Sagitta
c-po added a comment to T5116: Better VRF support.

Do you know how to tell Linux to use nameservers within a VRF?
What you mean IPSec/OpenVPN "punch a tunnel through a VRF" ? So the underlay should run via a VRF? source-interface binding does not work?

Apr 26 2023, 6:59 PM · VyOS Rolling
c-po moved T5132: Operational command "show isis vrf XXX route | neighbord" aren't working from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T5134: Try if netavark networks can be moved to a VRF instance from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T5174: vrf: ensure no duplicate VNIs can be created from Open to In Progress on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T4998: pppoe username validation too restrictive (regression) from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T5114: bgp: implement new CLI commands introduced in FRR 8.5 from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T366: SNMP Query for BGP Tunnels Returns IPv4 Tunnels Only from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T5170: Relocate ntp config path in config.boot.default from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:56 PM · VyOS 1.4 Sagitta
c-po moved T5075: QoS removes interface mirror/redirect rules from In Progress to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:56 PM · VyOS 1.4 Sagitta
c-po moved T4571: Sflow with vrf configured does not use vrf to validate agent-address IP from vrf-configured interfaces from Backport Candidates to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:56 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T5178: Fix missed case in multi_to_list conversion from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:56 PM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
jestabro changed the status of T5185: Static IPv6 route with blackhole fails from Open to In progress.

This is a simple bug in the recently introduced configtree node name comparison function; fixed and should be in next rolling.

Apr 26 2023, 5:38 PM · VyOS 1.4 Sagitta
jestabro triaged T5185: Static IPv6 route with blackhole fails as Urgent! priority.
Apr 26 2023, 4:33 PM · VyOS 1.4 Sagitta
jestabro claimed T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 4:29 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

Do you have users/passwords with specsymbols or not utf-8 or some ascii symbols?

Apr 26 2023, 3:43 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 3:40 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 3:40 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 3:36 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 3:36 PM · VyOS 1.4 Sagitta
Viacheslav created T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 3:34 PM · VyOS 1.4 Sagitta
joshua.hanley added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

hmmm very strange.... here is my configuration (IP addresses removed):

Apr 26 2023, 1:45 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

Could you provide l2tp configuration? show conf com | match l2tp
I cannot reproduce it

vyos@r14:~$ 
vyos@r14:~$ show l2tp-server sessions 
 ifname | username |      ip      | ip6 | ip6-dp |  calling-sid  | rate-limit | state  |  uptime  | rx-bytes | tx-bytes 
--------+----------+--------------+-----+--------+---------------+------------+--------+----------+----------+----------
 l2tp0  | alice    | 100.64.203.0 |     |        | 192.168.122.1 |            | active | 00:00:10 | 246 B    | 208 B
vyos@r14:~$ 
vyos@r14:~$ 
vyos@r14:~$ show version 
Version:          VyOS 1.4-rolling-202304261027
Release train:    current
Apr 26 2023, 1:41 PM · VyOS 1.4 Sagitta
joshua.hanley added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

@Viacheslav It hangs for a while and then eventually the following output:

Apr 26 2023, 1:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

@joshua.hanley Could you provide the output of the next command?

sudo accel-cmd -p 2004 show sessions
Apr 26 2023, 1:10 PM · VyOS 1.4 Sagitta
joshua.hanley updated the task description for T5184: Unable to display L2TP sessions l2tp-server sessions.
Apr 26 2023, 12:57 PM · VyOS 1.4 Sagitta
joshua.hanley created T5184: Unable to display L2TP sessions l2tp-server sessions.
Apr 26 2023, 12:56 PM · VyOS 1.4 Sagitta
oTamurazo created T5183: IPv6 route6 problem.
Apr 26 2023, 12:47 PM · VyOS 1.4 Sagitta
Viacheslav closed T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd as Resolved.
Apr 26 2023, 12:37 PM · VyOS 1.4 Sagitta
SrividyaA changed the status of T5127: VPNv4/VPNv6 routes are not reinstalled following link flap from Open to Confirmed.
Apr 26 2023, 11:44 AM · VyOS 1.4 Sagitta
zsdc added a comment to T5182: Update Intel ice driver.

PR with dependencies: https://github.com/vyos/vyos-build/pull/341

Apr 26 2023, 11:10 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav committed rVYOSONEXa1c559e3660a: T5181: Fix for correct deleting vni under vrf.
Apr 26 2023, 10:12 AM
GitHub <noreply@github.com> committed rVYOSONEX930f76cf88a4: Merge pull request #1971 from sever-sever/T5181 (authored by c-po).
Apr 26 2023, 10:12 AM
Viacheslav added a comment to T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.

PR https://github.com/vyos/vyos-1x/pull/1971

Apr 26 2023, 9:47 AM · VyOS 1.4 Sagitta

Apr 25 2023

zsdc changed the status of T5182: Update Intel ice driver from Open to In progress.

PR (for build): https://github.com/vyos/vyos-build/pull/340

Apr 25 2023, 10:55 PM · VyOS 1.3 Equuleus (1.3.6)
jestabro closed T5179: multi nodes defined in XML are not properly represented as list in get_config_dict(), a subtask of T3234: multi_to_list fails in certain cases, with root cause an element redundancy in XML interface-definitions, as Resolved.
Apr 25 2023, 9:08 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jestabro closed T5179: multi nodes defined in XML are not properly represented as list in get_config_dict() as Resolved.
Apr 25 2023, 9:08 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXa50aa1732a54: xml: T5179: fix missed case in multi_to_list conversion.
Apr 25 2023, 8:08 PM
GitHub <noreply@github.com> committed rVYOSONEX28429f615e1e: Merge pull request #1970 from jestabro/xml-merge (authored by c-po).
Apr 25 2023, 8:08 PM
c-po committed rVYOSONEX7bd6e4ef5faa: vrf: T5150: fix improper config dict generation for individual vni configuration.
Apr 25 2023, 8:07 PM
zsdc created T5182: Update Intel ice driver.
Apr 25 2023, 7:59 PM · VyOS 1.3 Equuleus (1.3.6)
zsdc changed the status of T5180: initramfs-tools ignores firmware from updates directory from Open to In progress.

PR: https://github.com/vyos/vyos-build/pull/339

Apr 25 2023, 7:48 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav assigned T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd to c-po.
Apr 25 2023, 6:27 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.

Incorrect modify modify_section: starting search for '^vrf protocols' until '^exit-vrf'

vyos@r14# delete vrf name red vni 
[edit]
vyos@r14# commit
[ vrf name red vni 3000 ]
{'name': {'protocols': {'bgp': {'address_family': {'ipv4_unicast': {'redistribute': {'connected': {}}},
                                                   'l2vpn_evpn': {'advertise': {'ipv4': {'unicast': {}}}}},
                                'system_as': '65001'}},
          'table': '3000'}}
load_configuration: Configuration loaded from FRR daemon zebra
load_configuration:  loaded      0 !
load_configuration:  loaded      1 frr version 8.5
load_configuration:  loaded      2 frr defaults traditional
load_configuration:  loaded      3 hostname debian
load_configuration:  loaded      4 log syslog
load_configuration:  loaded      5 log facility local7
load_configuration:  loaded      6 hostname r14
load_configuration:  loaded      7 service integrated-vtysh-config
load_configuration:  loaded      8 !
load_configuration:  loaded      9 vrf red
load_configuration:  loaded     10  vni 3000
load_configuration:  loaded     11 exit-vrf
load_configuration:  loaded     12 !
load_configuration:  loaded     13 end
modify_section: starting search for '^vrf protocols' until '^exit-vrf'
Apr 25 2023, 5:38 PM · VyOS 1.4 Sagitta
aserkin added a comment to T5169: Add CGNAT Carrier-Grade NAT based on nftables.
Apr 25 2023, 4:11 PM · VyOS Rolling, VyOS 1.5 Circinus
aserkin added a comment to T5169: Add CGNAT Carrier-Grade NAT based on nftables.

Two cents from the fields. It will be nice to see vrf aware cg-nat solution, when subscribers from a number of "inside" vrfs NAT'ed into one outside vrf. Of course if that's possible.

Apr 25 2023, 4:10 PM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav updated the task description for T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.
Apr 25 2023, 3:20 PM · VyOS 1.4 Sagitta
Viacheslav renamed T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd from Wrong dependencies or priorities for zebra vni vrf and bgpd to Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.
Apr 25 2023, 3:13 PM · VyOS 1.4 Sagitta
Viacheslav created T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.
Apr 25 2023, 3:09 PM · VyOS 1.4 Sagitta
jestabro renamed T5178: Fix missed case in multi_to_list conversion from Fix misssed case in multi_to_list conversion to Fix missed case in multi_to_list conversion.
Apr 25 2023, 1:43 PM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
zsdc created T5180: initramfs-tools ignores firmware from updates directory.
Apr 25 2023, 12:33 PM · VyOS 1.3 Equuleus (1.3.6)