Page MenuHomeVyOS Platform
Feed All Stories

Jul 29 2023

RFigas changed the status of T5418: Allow arbitrary subnets in PPPoE client IP pools from Open to In progress.
Jul 29 2023, 10:40 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
RFigas created T5418: Allow arbitrary subnets in PPPoE client IP pools.
Jul 29 2023, 10:11 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
Apachez created T5417: nft -o (optimizing ruleset) fails with error: "internal:0:0-0: Error: Could not process rule: File exists" .
Jul 29 2023, 9:44 PM · VyOS Rolling, Restricted Project
daniil created T5416: Ignoring "ipsec match-none" for firewall.
Jul 29 2023, 9:11 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX019f90fb65cb: T5411: remove old background monitor implementation for webproxy.
Jul 29 2023, 9:08 PM
c-po committed rVYOSONEX7568912d4831: T5411: remove old background monitor implementation.
Jul 29 2023, 9:05 PM
c-po added a comment to T3355: Remove all remaining legacy Vyatta code.

For "show dhcp client" command https://github.com/vyos/vyos-1x/pull/2120

Jul 29 2023, 9:00 PM · VyOS Rolling
jestabro committed rVYOSONEX3fb9cda51a40: xml: T5403: remove incorrect arg check.
Jul 29 2023, 8:46 PM
jestabro committed rVYOSONEXe3f0a514d8da: xml: T5403: set explicit package name.
Jul 29 2023, 8:28 PM
jestabro committed rVYOSONEXd59c9c35c037: xml: T5403: fix installation of xml cache.
Jul 29 2023, 8:05 PM
Apachez added a comment to T5414: dhcp-server does not allow valid bootfile-names.

I added this comment to PR 2118:

Jul 29 2023, 7:58 PM · VyOS 1.4 Sagitta
Apachez added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

A not too uncommon workaround for this is to disable the lease-file (if possible) and give out leases based on option82 information instead.

Jul 29 2023, 7:41 PM · VyOS 1.5 Circinus
Apachez added a comment to T5413: Deny the opportunity to use one public/private key pair on both wireguard peers..

Is this a limit of wireguard?

Jul 29 2023, 7:38 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po committed rVYOSONEX399edb32eb68: vpp: T1797: change dependency to amd64 builds only.
Jul 29 2023, 7:10 PM
twan added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

I'm using the *-parameters in isc-dhcp to manage ddns updates to an external nameserver. This way dns-entries supplied by dhcp-server will be kept in sync, even when using dhcp-failover.
I would love to still be able to keep this functionality with Kea in some way. Either by providing corresponding custom-parameters, or adding native support for this scenario.

Jul 29 2023, 2:47 PM · VyOS 1.5 Circinus
c-po added a parent task for T3700: Support VLAN tunnel mapping of VLAN aware bridges: T5415: Upgrade FRR to version 9.0.
Jul 29 2023, 10:24 AM · VyOS 1.4 Sagitta
c-po added a subtask for T5415: Upgrade FRR to version 9.0: T3700: Support VLAN tunnel mapping of VLAN aware bridges.
Jul 29 2023, 10:24 AM · VyOS 1.4 Sagitta
c-po changed the status of T5415: Upgrade FRR to version 9.0 from Open to In progress.
Jul 29 2023, 10:24 AM · VyOS 1.4 Sagitta
c-po created T5415: Upgrade FRR to version 9.0.
Jul 29 2023, 9:18 AM · VyOS 1.4 Sagitta
jestabro closed T5403: Add support for extending xml cache as Resolved.
Jul 29 2023, 1:45 AM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX223a6c5cd63f: xml: T5403: add support for supplemental xml cache.
Jul 29 2023, 1:32 AM
GitHub <[email protected]> committed rVYOSONEXad27d4d9cd23: Merge pull request #2116 from jestabro/user-def (authored by jestabro).
Jul 29 2023, 1:32 AM

Jul 28 2023

c-po closed T5411: Remove old background monitoring implementation, a subtask of T3355: Remove all remaining legacy Vyatta code, as Resolved.
Jul 28 2023, 8:50 PM · VyOS Rolling
c-po closed T5411: Remove old background monitoring implementation as Resolved.
Jul 28 2023, 8:50 PM · VyOS 1.4 Sagitta
etedor added a comment to T5414: dhcp-server does not allow valid bootfile-names.

I have submitted PR 2118 for this issue.

Jul 28 2023, 6:26 PM · VyOS 1.4 Sagitta
etedor updated the task description for T5414: dhcp-server does not allow valid bootfile-names.
Jul 28 2023, 6:11 PM · VyOS 1.4 Sagitta
etedor updated the task description for T5414: dhcp-server does not allow valid bootfile-names.
Jul 28 2023, 5:57 PM · VyOS 1.4 Sagitta
etedor created T5414: dhcp-server does not allow valid bootfile-names.
Jul 28 2023, 5:51 PM · VyOS 1.4 Sagitta
jestabro closed T5317: configtree: remove mutable references, a subtask of T5316: configtree: use a single pass of the diff algorithm, as Resolved.
Jul 28 2023, 4:49 PM · VyOS 1.4 Sagitta
jestabro closed T5317: configtree: remove mutable references as Resolved.
Jul 28 2023, 4:49 PM · VyOS 1.4 Sagitta
jestabro closed T5316: configtree: use a single pass of the diff algorithm as Resolved.
Jul 28 2023, 4:49 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXe310cb6e194b: configtree: T5316: use single-pass to drop trim function.
Jul 28 2023, 4:40 PM
zsdc changed the status of T5410: Improve `utils.convert.convert_data()` to process all stdtypes from Open to In progress.

PR: https://github.com/vyos/vyos-1x/pull/2117

Jul 28 2023, 2:45 PM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5413: Deny the opportunity to use one public/private key pair on both wireguard peers. from Open to In progress.
Jul 28 2023, 1:50 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
a.apostoliuk triaged T5413: Deny the opportunity to use one public/private key pair on both wireguard peers. as Normal priority.
Jul 28 2023, 1:50 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav closed T5401: Using load config restarts containers every time as Invalid.

You skip this warning and delte version number line

// Warning: Do not remove the following line
// vyos-config-version: "bgp@4:broadcast-relay@1:cluster@1:config-management@1:conntrack@3:conntrack-sync@2:container@1:dhcp-relay@2:dhcp-server@6:dhcpv6-server@1:dns-dynamic@1:dns-forwarding@4:firewall@10:flow-accounting@1:https@4:ids@1:interfaces@29:ipoe-server@1:ipsec@12:isis@3:l2tp@4:lldp@1:mdns@1:monitoring@1:nat@5:nat66@1:ntp@2:openconnect@2:ospf@2:policy@5:pppoe-server@6:pptp@2:qos@2:quagga@11:rip@1:rpki@1:salt@1:snmp@3:ssh@2:sstp@4:system@26:vrf@3:vrrp@4:vyos-accel-ppp@2:wanloadbalance@3:webproxy@2"
// Release version: 1.4-rolling-202307090317
Jul 28 2023, 10:31 AM · VyOS 1.4 Sagitta
m4rcu5 closed T4602: DHCP `ping-check` enabled by default as Resolved.

I've recently migrated from a PCEngines APU2C4 to a Wyse 5070 with a X520 card, as well as upgrading to VyOS 1.4-rolling-202305081003
After which I was unable to reproduce this issue. Roaming now works fine without the ICMP check.

Jul 28 2023, 10:28 AM · VyOS 1.4 Sagitta

Jul 27 2023

c-po committed rVYOSONEX2015717bdc87: T5411: add additional monitor log targets.
Jul 27 2023, 8:04 PM
jestabro added a subtask for T4820: Support for inter-config-mode script dependencies: T5412: Add support for extending config-mode dependencies in supplemental package.
Jul 27 2023, 6:58 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T5412: Add support for extending config-mode dependencies in supplemental package: T4820: Support for inter-config-mode script dependencies.
Jul 27 2023, 6:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a subtask for T5403: Add support for extending xml cache : T5412: Add support for extending config-mode dependencies in supplemental package.
Jul 27 2023, 6:56 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T5412: Add support for extending config-mode dependencies in supplemental package: T5403: Add support for extending xml cache .
Jul 27 2023, 6:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro triaged T5412: Add support for extending config-mode dependencies in supplemental package as Normal priority.
Jul 27 2023, 6:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po changed the status of T5411: Remove old background monitoring implementation, a subtask of T3355: Remove all remaining legacy Vyatta code, from Open to In progress.
Jul 27 2023, 6:52 PM · VyOS Rolling
c-po changed the status of T5411: Remove old background monitoring implementation from Open to In progress.
Jul 27 2023, 6:52 PM · VyOS 1.4 Sagitta
c-po created T5411: Remove old background monitoring implementation.
Jul 27 2023, 6:52 PM · VyOS 1.4 Sagitta
Viacheslav closed T5368: FastNetmon service ids ddos-protection add support sflow mode as Resolved.
Jul 27 2023, 6:00 PM · VyOS 1.4 Sagitta
zsdc created T5410: Improve `utils.convert.convert_data()` to process all stdtypes.
Jul 27 2023, 4:20 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXbd4bb4f869d6: T5368: service ids ddos-protection add support sflow mode.
Jul 27 2023, 4:10 PM
GitHub <[email protected]> committed rVYOSONEXb76f103317b5: Merge pull request #2105 from sever-sever/T5368 (authored by dmbaturin).
Jul 27 2023, 4:10 PM
a.apostoliuk changed the status of T5409: Add 'set interfaces wireguard wgX threaded' from Open to In progress.
Jul 27 2023, 3:01 PM · VyOS 1.4 Sagitta
a.apostoliuk created T5409: Add 'set interfaces wireguard wgX threaded'.
Jul 27 2023, 3:00 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXfe821df79b74: T5258: git Actions use ubuntu-22.04 for PR conflicts checker.
Jul 27 2023, 2:41 PM
GitHub <[email protected]> committed rVYOSONEXc91089b40866: Merge pull request #2115 from sever-sever/T5258-eq (authored by dmbaturin).
Jul 27 2023, 2:41 PM
SrividyaA committed rVYOSONEXf0a630cce26a: T5127: vpnv4/vpnv6 : warning for router-id.
Jul 27 2023, 2:12 PM
GitHub <[email protected]> committed rVYOSONEXef6cc1f32566: Merge pull request #2114 from srividya0208/T5252 (authored by c-po).
Jul 27 2023, 2:12 PM
jestabro added a comment to T5403: Add support for extending xml cache .

PR:
https://github.com/vyos/vyos-1x/pull/2116

Jul 27 2023, 1:23 PM · VyOS 1.4 Sagitta
n.fort claimed T5406: "update webproxy blacklists" fails when vrf is being configured.
Jul 27 2023, 10:11 AM · VyOS 1.4 Sagitta
sarthurdev added a comment to T5404: Ability to completely disable firewall/conntrack.

It is a bug that it’s on by default, see other task. Will be fixed after new firewall refactor is merged.

Jul 27 2023, 9:31 AM · VyOS 1.4 Sagitta
c-po added a comment to T4974: OpenVPN- Data Channel Offload(DCO).

From the VyOS documentation and https://community.openvpn.net/openvpn/wiki/DataChannelOffload

Jul 27 2023, 9:26 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5404: Ability to completely disable firewall/conntrack.

Then how come conntrack modules are loaded (and there is content in the ruleset "sudo nft -s list ruleset") when I have no firewall rules configured?

Jul 27 2023, 9:25 AM · VyOS 1.4 Sagitta
c-po added a comment to T4974: OpenVPN- Data Channel Offload(DCO).

CLI adjusted to:

Jul 27 2023, 9:23 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX3de59f1365e5: wwan: T3795: remove superfluous call to set_level().
Jul 27 2023, 9:18 AM
c-po committed rVYOSONEX32b9ac3653fa: openvpn: T4974: move CLI node "enable-dco" -> "offload dco" to match other….
Jul 27 2023, 9:18 AM
c-po committed rVYOSONEX341a84240e6d: openvpn: T4974: restructure get_config().
Jul 27 2023, 9:18 AM
Viacheslav awarded T5403: Add support for extending xml cache a Like token.
Jul 27 2023, 9:06 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5404: Ability to completely disable firewall/conntrack.

Conntrack should be disabled by default https://vyos.dev/T5080

Jul 27 2023, 9:03 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5408: 15-16 tacacs folders under /home directory.

It is not a bug.
It is the implementation of TACACS authentication https://github.com/vyos/vyos-1x/pull/2038
https://github.com/vyos/vyos-1x/blob/fa07179ae7f1dc07e6ccc1b20d2b81384b6efe07/debian/vyos-1x.postinst#L47-L52

Jul 27 2023, 8:56 AM · VyOS 1.4 Sagitta
a.hajiyev created T5408: 15-16 tacacs folders under /home directory.
Jul 27 2023, 8:00 AM · VyOS 1.4 Sagitta
jvoss created T5407: Static routes pointed to container networks fail to persist after reboot.
Jul 27 2023, 2:53 AM · VyOS 1.4 Sagitta
Apachez created T5406: "update webproxy blacklists" fails when vrf is being configured.
Jul 27 2023, 2:43 AM · VyOS 1.4 Sagitta
Apachez created T5405: Add VRF support for "update geoip".
Jul 27 2023, 2:37 AM · VyOS Rolling
Apachez created T5404: Ability to completely disable firewall/conntrack.
Jul 27 2023, 2:24 AM · VyOS 1.4 Sagitta

Jul 26 2023

c-po closed T4974: OpenVPN- Data Channel Offload(DCO) as Resolved.
Jul 26 2023, 9:15 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXfa07179ae7f1: openvpn: T4974: dynamically load/unload kernel module.
Jul 26 2023, 9:14 PM
c-po committed rVYOSONEX9e0a9b7df3d7: openvpn: T4974: do not automatically load the DCO module.
Jul 26 2023, 8:29 PM
c-po closed T5365: Container systemd units require authentication as Resolved.
Jul 26 2023, 7:47 PM · VyOS 1.4 Sagitta
jestabro changed the status of T5403: Add support for extending xml cache from Open to In progress.
Jul 26 2023, 6:51 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5399: "show ntp" fails when vrf is being configured.

Tested and verified as described in the pull request:

Jul 26 2023, 5:55 PM · VyOS 1.4 Sagitta
Apachez added a comment to rVYOSONEX5f2e9cb81d89: T5154: NTP: allow maximum of one ipv4 and one ipv6 address on parameter <listen….

Oh, and the reason for why using chrony instead of ntpsec is?

Jul 26 2023, 5:52 PM
n.fort added a comment to rVYOSONEX5f2e9cb81d89: T5154: NTP: allow maximum of one ipv4 and one ipv6 address on parameter <listen….

Why this limit?

Example: I have 5 interfaces and want to let NTP-clients sync to my VyOS device on 3 of them (which is their default gateway on each network).

With this change this wont be possible unless I enable firewall rules or am I missing something here?

Jul 26 2023, 5:45 PM
Apachez added a comment to rVYOSONEX5f2e9cb81d89: T5154: NTP: allow maximum of one ipv4 and one ipv6 address on parameter <listen….

Why this limit?

Jul 26 2023, 5:00 PM
n.fort committed rVYOSONEX5f2e9cb81d89: T5154: NTP: allow maximum of one ipv4 and one ipv6 address on parameter <listen….
Jul 26 2023, 4:50 PM
GitHub <[email protected]> committed rVYOSONEXfc35434bfb0d: Merge pull request #2078 from nicolas-fort/T5154 (authored by Viacheslav).
Jul 26 2023, 4:50 PM
jack9603301 added a comment to T5341: Improve CLI for high-availability virtual-server to work with multiple ports.
Jul 26 2023, 4:49 PM · VyOS 1.4 Sagitta
n.fort added a comment to T5399: "show ntp" fails when vrf is being configured.

Thanks for testing and submitting PR

Jul 26 2023, 1:37 PM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5402: VRRP router with rfc3768-compatibility sends multiple ARP replies from Open to In progress.
Jul 26 2023, 12:17 PM · VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
a.apostoliuk created T5402: VRRP router with rfc3768-compatibility sends multiple ARP replies .
Jul 26 2023, 12:17 PM · VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav closed T5398: FRR mangles container network interface names as Resolved.
Jul 26 2023, 12:01 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5399: "show ntp" fails when vrf is being configured from Open to Needs testing.
Jul 26 2023, 12:01 PM · VyOS 1.4 Sagitta
Apachez committed rVYOSONEXb3eaa3c11a37: T5399: VRF-support for show ntp.
Jul 26 2023, 11:48 AM
GitHub <[email protected]> committed rVYOSONEX6a1a687f8b8f: Merge pull request #2112 from Apachez-/T5399 (authored by c-po).
Jul 26 2023, 11:48 AM
Apachez added a comment to T5399: "show ntp" fails when vrf is being configured.

Pull request created: https://github.com/vyos/vyos-1x/pull/2112

Jul 26 2023, 9:51 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5399: "show ntp" fails when vrf is being configured.

There is this line in the code https://github.com/vyos/vyos-1x/blob/688755a988e233e221bf920e391e35d5ddc9cb56/src/op_mode/show_ntp.sh#L21

Jul 26 2023, 7:56 AM · VyOS 1.4 Sagitta
yzguy added a comment to T5401: Using load config restarts containers every time.

https://github.com/vyos/vyos-1x/pull/2111

Jul 26 2023, 4:32 AM · VyOS 1.4 Sagitta
yzguy created T5401: Using load config restarts containers every time.
Jul 26 2023, 3:11 AM · VyOS 1.4 Sagitta
yzguy updated subscribers of T5365: Container systemd units require authentication.

@c-po just added the sudo on a live box to test the changes and I can confirm that fixes it. No auth prompt when doing a load config.
Now I did notice that every time I do a load config it runs that migration script which stops/starts the container which is not ideal.

Jul 26 2023, 2:23 AM · VyOS 1.4 Sagitta

Jul 25 2023

Apachez added a comment to T5399: "show ntp" fails when vrf is being configured.

I can confirm that altering line 21 as suggested fixes this issue.

Jul 25 2023, 11:29 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5398: FRR mangles container network interface names from Open to Needs testing.
Jul 25 2023, 9:28 PM · VyOS 1.4 Sagitta
jvoss committed rVYOSONEX20ac831df73a: static: T5398: do not mangle interface names in FRR.
Jul 25 2023, 9:26 PM