Page MenuHomeVyOS Platform
Feed Search

May 23 2023

Viacheslav closed T4916: Rewrite IPsec authentication as Resolved.
May 23 2023, 3:08 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T3642: PKI configuration: T2289: Denest cerbot certificate configuration from service https.
May 23 2023, 2:33 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav added a parent task for T2289: Denest cerbot certificate configuration from service https: T3642: PKI configuration.
May 23 2023, 2:33 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Viacheslav added a subtask for T3642: PKI configuration: T3651: Move certbot request to op-mode.
May 23 2023, 2:33 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav added a parent task for T3651: Move certbot request to op-mode: T3642: PKI configuration.
May 23 2023, 2:33 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Viacheslav added a comment to T5236: show wan-load-balance not working after reboot.

@danhusan Could you check if the file /var/run/load-balance/wlb.out exists?
https://github.com/vyos/vyatta-wanloadbalance/blob/5a3ab6c426928644dc9ad9a70296263781523919/templates-op/show/wan-load-balance/node.def#L2C15-L5

May 23 2023, 9:26 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5231: Add op-mode for load-balancing reverse-proxy.
May 23 2023, 9:19 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5231: Add op-mode for load-balancing reverse-proxy.

PR https://github.com/vyos/vyos-1x/pull/2015

vyos@r14# run show reverse-proxy 
Proxy name    Role      Status    Req rate    Resp time    Last change
------------  --------  --------  ----------  -----------  -------------
http          FRONTEND  OPEN      0
https         FRONTEND  OPEN      16
stats         FRONTEND  OPEN      0
bk-01         BACKEND   UP                    1 ms         1h34m45s
default-bk    BACKEND   UP                    0 ms         1h34m45s
bk-01         serv-01   UP                    1 ms         1h34m45s
bk-01         serv-02   DOWN                  0 ms         1h34m44s
default-bk    serv-03   no check              0 ms         1h34m45s
[edit]
vyos@r14#
May 23 2023, 8:39 AM · VyOS 1.4 Sagitta
Viacheslav reopened T4737: FRRouting/zebra 7.5.1 does not redistribute routes to other protocols as "Needs testing".
May 23 2023, 4:09 AM · VyOS 1.3 Equuleus (1.3.3)

May 22 2023

Viacheslav closed T4977: Babel routing protocol support as Resolved.
May 22 2023, 7:59 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav changed the status of T5143: Apply constraint on powerdns forward-zones configuration from In progress to Needs testing.
May 22 2023, 7:49 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5115: Support custom port for name servers for forwarding zones from Open to Needs testing.
May 22 2023, 7:46 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T2934: proxy-arp-pvlan on VRRP interface, added: VyOS 1.3 Equuleus (1.3.4); removed VyOS 1.3 Equuleus (1.3.3).
May 22 2023, 7:40 PM · Restricted Project, VyOS Rolling
Viacheslav closed T5214: PPPoE-server incorrect warning if a named pool is defined as Resolved.
May 22 2023, 7:30 PM · VyOS 1.4 Sagitta

May 21 2023

Viacheslav renamed T5233: Op-mode flow-accounting netflow with disable-imt errors from Op-mode flow-accounting with disable-imt errors to Op-mode flow-accounting netflow with disable-imt errors.
May 21 2023, 8:45 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5233: Op-mode flow-accounting netflow with disable-imt errors.
May 21 2023, 8:45 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5232: Flow-accounting uacctd.service cannot restart correctly.
May 21 2023, 8:40 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

May 20 2023

Viacheslav updated the task description for T5231: Add op-mode for load-balancing reverse-proxy.
May 20 2023, 9:11 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5231: Add op-mode for load-balancing reverse-proxy.
May 20 2023, 9:10 AM · VyOS 1.4 Sagitta
Viacheslav renamed T5222: Add load-balancing reverse-proxy based on haproxy from Add load-balancing based on haproxy to Add load-balancing reverse-proxy based on haproxy .
May 20 2023, 8:20 AM · VyOS 1.4 Sagitta
Viacheslav renamed T5231: Add op-mode for load-balancing reverse-proxy from Add op-mode for load-belancing reverse-proxy to Add op-mode for load-balancing reverse-proxy.
May 20 2023, 8:20 AM · VyOS 1.4 Sagitta
Viacheslav created T5231: Add op-mode for load-balancing reverse-proxy.
May 20 2023, 8:20 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5222: Add load-balancing reverse-proxy based on haproxy from Open to Needs testing.
May 20 2023, 7:32 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5230: 1.4 Missing enforce-first-as for bgp peers from Open to Needs testing.
May 20 2023, 7:21 AM

May 19 2023

Viacheslav committed rVYOSONEX9ffbc8d8f9a2: T5222: reverse-proxy fix template for listen-address.
May 19 2023, 6:52 PM
Viacheslav committed rVYOSONEX62ce80bd0cb4: T5222: reverse-proxy add send-proxy option for backend server.
May 19 2023, 6:52 PM
Viacheslav committed rVYOSONEXe9dce894eec2: T5222: load-balancing reverse-proxy add smoketest domains.
May 19 2023, 6:52 PM
Viacheslav added a comment to T5229: CGN -- external ports limitting.

There is the task T5169

May 19 2023, 4:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5222: Add load-balancing reverse-proxy based on haproxy .

PR listen-address fixes https://github.com/vyos/vyos-1x/pull/2013

May 19 2023, 4:29 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXe201bd35511e: T5222: Refactoring load-balancing reverse-proxy.
May 19 2023, 10:21 AM
Viacheslav added a comment to T5222: Add load-balancing reverse-proxy based on haproxy .

PR refactoring https://github.com/vyos/vyos-1x/pull/2012

May 19 2023, 10:15 AM · VyOS 1.4 Sagitta

May 17 2023

Viacheslav committed rVYOSONEX6d0325190fce: T5222: Add load-balancing for web traffic.
May 17 2023, 4:46 PM
Viacheslav changed the subtype of T5227: mDNS reflector should allow additional domains to browse and allow filtering services from "Task" to "Feature Request".
May 17 2023, 8:07 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5225: BGP allowas-in unusable.

@ddominet the correct syntax

set protocols bgp neighbor 192.0.2.11 address-family ipv6-unicast allowas-in number 1
May 17 2023, 8:05 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5225: BGP allowas-in unusable from "Task" to "Bug".
May 17 2023, 5:02 AM · VyOS 1.4 Sagitta

May 15 2023

Viacheslav changed the status of T5197: Conntrack-sync external cache commit error from Open to Needs testing.
May 15 2023, 3:03 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5222: Add load-balancing reverse-proxy based on haproxy .
May 15 2023, 12:29 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5222: Add load-balancing reverse-proxy based on haproxy .
May 15 2023, 12:02 PM · VyOS 1.4 Sagitta
Viacheslav closed T3896: Extend ocserv support to allow for per-group configs as Resolved.
May 15 2023, 8:21 AM · VyOS 1.4 Sagitta

May 13 2023

Viacheslav added a comment to T5222: Add load-balancing reverse-proxy based on haproxy .

PR https://github.com/vyos/vyos-1x/pull/2004

May 13 2023, 1:19 PM · VyOS 1.4 Sagitta

May 12 2023

Viacheslav updated the task description for T5222: Add load-balancing reverse-proxy based on haproxy .
May 12 2023, 6:20 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5222: Add load-balancing reverse-proxy based on haproxy .
May 12 2023, 6:09 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5222: Add load-balancing reverse-proxy based on haproxy .
May 12 2023, 6:01 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5221: BGP as-override behavior differs from new FRR and other vendors from In progress to Needs testing.
May 12 2023, 1:45 PM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav edited projects for T5221: BGP as-override behavior differs from new FRR and other vendors, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus.
May 12 2023, 1:45 PM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav claimed T5222: Add load-balancing reverse-proxy based on haproxy .
May 12 2023, 1:30 PM · VyOS 1.4 Sagitta
Viacheslav renamed T5222: Add load-balancing reverse-proxy based on haproxy from Add loadbalancing based on haproxy to Add load-balancing based on haproxy .
May 12 2023, 1:30 PM · VyOS 1.4 Sagitta
Viacheslav created T5222: Add load-balancing reverse-proxy based on haproxy .
May 12 2023, 1:30 PM · VyOS 1.4 Sagitta

May 11 2023

Viacheslav committed rVYOSONEX163ad47c7906: T5171: Set default value icmp for load-balancing test check.
May 11 2023, 7:16 PM
Viacheslav edited projects for T5219: ddclient: Cloudflare doesn't require login, added: VyOS 1.4 Sagitta; removed ddclient.
May 11 2023, 1:46 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5217: Add firewall SYNPROXY .
May 11 2023, 12:48 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5186: QoS test cannot pass for 1.3.

@c-po I guess it should be v5.4.234

May 11 2023, 12:16 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T4362: Wan Load Balancing - Can't create routing tables.

one issue.
the migration scripts don't take into account older load balancing configs.

if the test > rule > type > ping isn't explicitly set then the rule defaults to the next hop address and ignores the rule entirely.
the default rule seems to be the next hop address for the interface.

May 11 2023, 10:56 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5171: Use XML for conf-mode "load-balancing wan" instead of legacy templates.

set default check type ping https://github.com/vyos/vyos-1x/pull/1998

May 11 2023, 10:55 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5213: Accel-ppp sending accounting interim updates acct-interim-interval option from In progress to Needs testing.
May 11 2023, 6:45 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T3829: Support separated TCP/IP stack via "ip netns".

Veth is not ready to work together with netns
As Interface moves entirely to logical stack and with the next commit will be recreated and try to move to netns again. As it doesn't see veth interface which moved to another logical stack, it tryes to recreate this interface.
We should either fix it or revert the previous commit.

May 11 2023, 3:46 AM · VyOS Rolling

May 10 2023

Viacheslav committed rVYOSONEX153f3579d703: T5213: Add accounting-interim-interval option for L2TP-server.
May 10 2023, 7:13 PM
Viacheslav committed rVYOSONEX98c310462ded: T5213: Add accounting-interim-interval option for PPTP-server.
May 10 2023, 7:12 PM
Viacheslav committed rVYOSONEX3c2a206e733c: T5217: Add smoketest for CONFIG_NFT_SYNPROXY kernel option.
May 10 2023, 7:11 PM
Viacheslav updated the task description for T5217: Add firewall SYNPROXY .
May 10 2023, 2:29 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5217: Add firewall SYNPROXY .

Add kernel module https://github.com/vyos/vyos-build/pull/348

May 10 2023, 1:05 PM · VyOS 1.4 Sagitta
Viacheslav created T5217: Add firewall SYNPROXY .
May 10 2023, 11:45 AM · VyOS 1.4 Sagitta
Viacheslav closed T5209: dhclient load-balancing exit hook 04-dhcp-wanlb returned non-zero exit status as Resolved.
May 10 2023, 9:51 AM · VyOS 1.4 Sagitta
Viacheslav closed T5060: add a VRRP 'maintenance mode' as Resolved.
May 10 2023, 9:48 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5213: Accel-ppp sending accounting interim updates acct-interim-interval option.

PR for L2TP https://github.com/vyos/vyos-1x/pull/1988

May 10 2023, 9:39 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav closed T5065: Mixing `destination port xxx` and `destination group port-group yyy` in firewall rules doesn't work, but can be commited as Resolved.
May 10 2023, 8:10 AM · VyOS 1.4 Sagitta
Viacheslav created T5216: Add encrypting syslog traffic with TLS (SSL).
May 10 2023, 7:29 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5144: Modernize dynamic dns operation from Open to Needs testing.
May 10 2023, 7:20 AM · VyOS 1.4 Sagitta

May 9 2023

Viacheslav committed rVYOSONEXe201454f073c: T5060: Add disable option for high-availability.
May 9 2023, 5:25 PM
Viacheslav committed rVYOSONEX718d11daa2bd: T5213: Add accounting-interim-interval option for PPPoE IPoE SSTP.
May 9 2023, 5:24 PM
Viacheslav committed rVYOSONEX7c23983ba121: T5213: Add smoketest for pppoe-server accounting-interim-interval.
May 9 2023, 5:24 PM
Viacheslav committed rVYOSONEXac0fedb7ac24: T5214: Fix warning if a named pool is defined for PPPoE-server.
May 9 2023, 5:24 PM
Viacheslav changed the status of T5209: dhclient load-balancing exit hook 04-dhcp-wanlb returned non-zero exit status from Open to In progress.

PR https://github.com/vyos/vyatta-wanloadbalance/pull/18

May 9 2023, 2:49 PM · VyOS 1.4 Sagitta
Viacheslav closed T5202: After removal load-balancing a pid remained which used in dhclient-exit-hooks as Resolved.

Fixed with rewriting to systemd unit vyos-wan-load-balance.service

May 9 2023, 2:29 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5213: Accel-ppp sending accounting interim updates acct-interim-interval option.

@Viacheslav Thanks for the prompt response. Not sure if the change will also cover L2TP as well. For example:

set vpn l2tp remote-access authentication radius accounting-interim-interval '60'
May 9 2023, 2:19 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav reopened T5203: load-balancing wan add systemd unit instead of old vyatta-wanloadbalance.init, a subtask of T4470: Rewrite load-balancing wan to XML/Python, as Needs testing.
May 9 2023, 2:05 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Viacheslav reopened T5203: load-balancing wan add systemd unit instead of old vyatta-wanloadbalance.init as "Needs testing".

Sometimes it stuck for ~1.5 minutes after deleting.

vyos@r14# delete load-balancing 
[edit]
vyos@r14# commit
May 9 2023, 2:05 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5214: PPPoE-server incorrect warning if a named pool is defined.

PR https://github.com/vyos/vyos-1x/pull/1986

May 9 2023, 12:40 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5213: Accel-ppp sending accounting interim updates acct-interim-interval option.

PR https://github.com/vyos/vyos-1x/pull/1986

set service pppoe-server authentication mode 'radius'
set service pppoe-server authentication radius accounting-interim-interval '60'
set service pppoe-server authentication radius server 203.0.113.1 key '123'
set service pppoe-server client-ip-pool name POOL-01 gateway-address '192.0.2.1'
set service pppoe-server client-ip-pool name POOL-01 subnet '192.0.2.0/24'
set service pppoe-server interface eth1
May 9 2023, 12:39 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav changed the status of T5214: PPPoE-server incorrect warning if a named pool is defined from Open to In progress.
May 9 2023, 10:36 AM · VyOS 1.4 Sagitta
Viacheslav created T5214: PPPoE-server incorrect warning if a named pool is defined.
May 9 2023, 10:36 AM · VyOS 1.4 Sagitta
Viacheslav renamed T5213: Accel-ppp sending accounting interim updates acct-interim-interval option from Sending accounting interim updates to Accel-ppp sending accounting interim updates acct-interim-interval option.
May 9 2023, 9:28 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav changed the status of T5213: Accel-ppp sending accounting interim updates acct-interim-interval option from Open to In progress.
May 9 2023, 9:28 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T5186: QoS test cannot pass for 1.3.

this is cause by

https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.4.235&id=7a6fb69bbcb21e9ce13bdf18c008c268874f0480

tcindex classifier is removed by upstream kernel, so

08:04:48 DEBUG - filter add dev eth1 parent 11: protocol ip prio 1 handle 128 tcindex classid 11:a

fails.

May 9 2023, 9:01 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T5211: route-map allows both IPv4 and IPv6 in one rule which never match.

We use FRR as the backend and it uses logical AND for match entries

May 9 2023, 7:11 AM

May 8 2023

Viacheslav created T5210: IPSec cosmetic bug for Warning vti inrerface.
May 8 2023, 12:56 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5060: add a VRRP 'maintenance mode'.

PR https://github.com/vyos/vyos-1x/pull/1984

set high-availability disable
set high-availability vrrp group GRP01 address 192.0.2.47/32
set high-availability vrrp group GRP01 interface 'eth1'
set high-availability vrrp group GRP01 vrid '10'
May 8 2023, 11:47 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5060: add a VRRP 'maintenance mode' from Open to In progress.
May 8 2023, 11:41 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5048: QoS doesn't work correctly root task.

It doesn't like protocol tcp

vyos@r14# sudo tc filter replace dev eth1 parent 1: protocol all u32 match ip protocol tcp 0xff action police rate 300000000 burst 15k flowid 1:a
Illegal "match"
[edit]
vyos@r14#

But it works with protocol 6

vyos@r14# sudo tc filter replace dev eth1 parent 1: protocol all u32 match ip protocol 6 0xff action police rate 300000000 burst 15k flowid 1:a
[edit]
vyos@r14#

And next fail:

ardware UUID:    4d6f4d29-1ae8-446f-8d2b-3decd9da64c7
May 8 2023, 10:34 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5209: dhclient load-balancing exit hook 04-dhcp-wanlb returned non-zero exit status.
May 8 2023, 9:55 AM · VyOS 1.4 Sagitta
Viacheslav created T5209: dhclient load-balancing exit hook 04-dhcp-wanlb returned non-zero exit status.
May 8 2023, 9:52 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5202: After removal load-balancing a pid remained which used in dhclient-exit-hooks.
May 8 2023, 9:39 AM · VyOS 1.4 Sagitta
Viacheslav created T5208: Failed to start nvmf-autoconnect.service during the boot.
May 8 2023, 9:29 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5207: Improper NAT66 Support from "Task" to "Feature Request".
May 8 2023, 8:12 AM · VyOS Rolling
Viacheslav closed T5203: load-balancing wan add systemd unit instead of old vyatta-wanloadbalance.init, a subtask of T4470: Rewrite load-balancing wan to XML/Python, as Resolved.
May 8 2023, 7:59 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Viacheslav closed T5203: load-balancing wan add systemd unit instead of old vyatta-wanloadbalance.init as Resolved.
May 8 2023, 7:59 AM · VyOS 1.4 Sagitta

May 7 2023

Viacheslav changed the subtype of T5053: Vyatta-cfg Post-Removal Hook Tries to Disable Deleted Service from "Task" to "Bug".
May 7 2023, 10:53 PM · VyOS 1.4 Sagitta

May 6 2023

Viacheslav committed rVYOSONEXee025e34241a: T5203: Add systemd vyos-wan-load-balance.service.
May 6 2023, 1:06 PM
Viacheslav committed rVYOSONEX454fcea2a3a0: T5203: Use vyos-wan-load-balance.service for load-balancing.
May 6 2023, 1:06 PM

May 5 2023

Viacheslav added a comment to T2754: PBR doesn't work with VRRP.

It should work for 1.4

set policy route foo interface eth1v1
May 5 2023, 2:22 PM · VyOS 1.3 Equuleus (1.3.6)