Page MenuHomeVyOS Platform
Feed All Stories

Aug 20 2023

c-po added a comment to T5491: Hostapd - AP-Mode - allow white-/blacklisting of Clients.

PR https://github.com/vyos/vyos-1x/pull/2159

Aug 20 2023, 1:04 PM · VyOS 1.4 Sagitta
twan added a comment to T5481: Upgrade bug.

I ran what you suggested, but it still shows wrong block/inode count right after boot.

Aug 20 2023, 12:07 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5481: Upgrade bug.

Looks like you would need some more extensive checking of that partition.

Aug 20 2023, 9:44 AM · VyOS 1.4 Sagitta
c-po added a comment to T5494: Add SSSD IPA and Kerberos support.

As I understabd FreeIPA is an alternative to ActiveDirectory? And SSSD should support authentication via LDAP only if the backend is AD.

Aug 20 2023, 9:26 AM · VyOS 1.5 Circinus
twan added a comment to T5481: Upgrade bug.

I managed to enter initramfs on the machine running in a VM by appending break to grub. From there I manually ran a fs check, which didn't show any issues.

Aug 20 2023, 9:05 AM · VyOS 1.4 Sagitta
c-po changed the status of T5470: wlan: can not disable interface if SSID is not configured from Unknown Status to Resolved.
Aug 20 2023, 7:52 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta

Aug 19 2023

c-po committed rVYOSONEXa2b9b7937d07: wifi: T5470: improve error message.
Aug 19 2023, 7:14 PM
GitHub <[email protected]> committed rVYOSONEXf70e2b69a5ba: Merge pull request #2158 from c-po/t5470-wifi-equuleus (authored by Viacheslav).
Aug 19 2023, 7:14 PM
Apachez added a comment to T5481: Upgrade bug.

I have created this task regarding the fsck issues (fsck does not run during boot): https://vyos.dev/T5498

Aug 19 2023, 4:06 PM · VyOS 1.4 Sagitta
Apachez created T5498: fsck during boot doesnt work.
Aug 19 2023, 4:02 PM · VyOS Rolling, Restricted Project
c-po moved T5470: wlan: can not disable interface if SSID is not configured from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.4) board.
Aug 19 2023, 3:08 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po moved T5470: wlan: can not disable interface if SSID is not configured from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 19 2023, 3:07 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po changed the status of T5470: wlan: can not disable interface if SSID is not configured from Resolved to Unknown Status.
Aug 19 2023, 3:07 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po added a comment to T5470: wlan: can not disable interface if SSID is not configured.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/2158

Aug 19 2023, 3:07 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po closed T5470: wlan: can not disable interface if SSID is not configured as Resolved.
Aug 19 2023, 2:52 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po committed rVYOSONEXffb798b4678f: wifi: T5470: improve error message.
Aug 19 2023, 2:52 PM
twan attached a referenced file: F3823454: config.boot-pre-fw-prived.
Aug 19 2023, 2:49 PM · VyOS 1.4 Sagitta
twan attached a referenced file: F3823453: config.boot.2023-08-15-184048.pre-migration-prived.
Aug 19 2023, 2:49 PM · VyOS 1.4 Sagitta
c-po updated the task description for T5470: wlan: can not disable interface if SSID is not configured.
Aug 19 2023, 2:47 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
twan added a comment to T5481: Upgrade bug.

Both attached files seem to be downloadable (but now viewable in browser) from the download-link in the upper right corner after clicking a file.

Aug 19 2023, 2:46 PM · VyOS 1.4 Sagitta
Apachez created T5497: Add ability to resequence rule numbers for firewall.
Aug 19 2023, 10:34 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po committed rVYOSONEX7bae85fd670d: bgp: T5466: rename type on CLI per-nexhop -> per-nexthop for l3vpn MPLS labels.
Aug 19 2023, 9:11 AM
h-eberhardt added a comment to T5494: Add SSSD IPA and Kerberos support.

Thank you for taking a look on the PR.

Aug 19 2023, 8:40 AM · VyOS 1.5 Circinus
Apachez added a comment to T5466: L3VPN - label allocation mode .

In PR 2152:

Aug 19 2023, 8:15 AM · VyOS 1.4 Sagitta
c-po added a comment to T5494: Add SSSD IPA and Kerberos support.

Adding Kerberos to a router is overkill in my opinion. I'd agree on adding LDAP(s) auth support via sssd of course, but Kerberos is simply a bit beyond the scope.

Aug 19 2023, 7:59 AM · VyOS 1.5 Circinus
Apachez added a comment to T5496: `show firewall` error.

Works for me without errors but I currently only have an empty ruleset:

Aug 19 2023, 12:19 AM · Restricted Project, VyOS 1.4 Sagitta

Aug 18 2023

dongjunbo updated the task description for T5496: `show firewall` error.
Aug 18 2023, 11:37 PM · Restricted Project, VyOS 1.4 Sagitta
dongjunbo updated the task description for T5496: `show firewall` error.
Aug 18 2023, 11:23 PM · Restricted Project, VyOS 1.4 Sagitta
dongjunbo created T5496: `show firewall` error.
Aug 18 2023, 11:22 PM · Restricted Project, VyOS 1.4 Sagitta
Apachez created T5495: Enable snmp module also for frr/ldpd.
Aug 18 2023, 11:04 PM · VyOS 1.4 Sagitta
syncer changed the status of T5494: Add SSSD IPA and Kerberos support from Open to In progress.
Aug 18 2023, 9:44 PM · VyOS 1.5 Circinus
fernando added a comment to T5481: Upgrade bug.

I couldn't open those files, but it can be related our firewall refactor :

Aug 18 2023, 9:21 PM · VyOS 1.4 Sagitta
h-eberhardt raised the priority of T5494: Add SSSD IPA and Kerberos support from Low to Normal.
Aug 18 2023, 8:53 PM · VyOS 1.5 Circinus
h-eberhardt created T5494: Add SSSD IPA and Kerberos support.
Aug 18 2023, 8:53 PM · VyOS 1.5 Circinus
c-po claimed T5491: Hostapd - AP-Mode - allow white-/blacklisting of Clients.
Aug 18 2023, 8:41 PM · VyOS 1.4 Sagitta
fernando changed the status of T5487: OPENVPN -DEPRECATED OPTION: --cipher from Open to Confirmed.
Aug 18 2023, 8:07 PM · VyOS 1.5 Circinus, Restricted Project
fernando added a comment to T5487: OPENVPN -DEPRECATED OPTION: --cipher.

I confirm this warning message , although, on Linux doesn't affect or at least with our server/client work as expected :

Aug 18 2023, 8:05 PM · VyOS 1.5 Circinus, Restricted Project
Viacheslav added a comment to T5493: Add capability to use local and external dynamic-lists for firewall rules but also for various policies such as access-list, route-maps etc..

The similar task https://vyos.dev/T4797

Aug 18 2023, 7:34 PM · VyOS Rolling
Apachez created T5493: Add capability to use local and external dynamic-lists for firewall rules but also for various policies such as access-list, route-maps etc..
Aug 18 2023, 6:53 PM · VyOS Rolling
jestabro claimed T5492: CLI node priority is not inversed on node deletion.
Aug 18 2023, 2:28 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po created T5492: CLI node priority is not inversed on node deletion.
Aug 18 2023, 12:00 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
mkrsn updated the task description for T5491: Hostapd - AP-Mode - allow white-/blacklisting of Clients.
Aug 18 2023, 10:56 AM · VyOS 1.4 Sagitta
mkrsn created T5491: Hostapd - AP-Mode - allow white-/blacklisting of Clients.
Aug 18 2023, 10:53 AM · VyOS 1.4 Sagitta
Viacheslav closed T5488: System conntrack ignore does not take any effect as Resolved.
Aug 18 2023, 8:00 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX0e1bc3d4e92d: smoketest: bgp: T5466: remove trailing whitespace.
Aug 18 2023, 6:33 AM
c-po committed rVYOSONEX6c00ee0c8486: login: T5490: allow . (dot) in user home-directory path.
Aug 18 2023, 6:33 AM
giga1699 changed the status of T5447: Allow static MACsec keys with peers from Open to In progress.

Pull request #2156 opened
https://github.com/vyos/vyos-1x/pull/2156

Aug 18 2023, 1:26 AM · VyOS 1.4 Sagitta

Aug 17 2023

c-po changed the status of T5459: ospfv3: add authentication support from Open to In progress.
Aug 17 2023, 8:39 PM · VyOS Rolling
c-po closed T5409: Add 'set interfaces wireguard wgX threaded' as Resolved.
Aug 17 2023, 8:03 PM · VyOS 1.4 Sagitta
a.apostoliuk committed rVYOSONEX0d54be778ba2: wireguard: T5409: Added 'set interfaces wireguard wgX threaded'.
Aug 17 2023, 7:54 PM
c-po committed rVYOSONEX113ed87c0aa9: wireguard: T5409: rename threaded CLI not to per-client-thread.
Aug 17 2023, 7:54 PM
c-po committed rVYOSONEX6bd061100ae4: wireless: T5409: add per-client-thread CLI option.
Aug 17 2023, 7:54 PM
GitHub <[email protected]> committed rVYOSONEX49f25c568c91: Merge pull request #2130 from aapostoliuk/T5409-sagitta (authored by c-po).
Aug 17 2023, 7:54 PM
Viacheslav committed rVYOSONEX8c2aa73dce97: T5488: Set correct priority -300 for conntrack entries.
Aug 17 2023, 7:21 PM
GitHub <[email protected]> committed rVYOSONEX214d0d4933e9: Merge pull request #2155 from sever-sever/T5488 (authored by c-po).
Aug 17 2023, 7:21 PM
Apachez added a comment to T5478: Cannot configure resolver-cache options for firewall.

This error not only occurs for new settings in global-options but also for older:

Aug 17 2023, 7:08 PM · VyOS 1.4 Sagitta
c-po moved T5409: Add 'set interfaces wireguard wgX threaded' from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 17 2023, 6:53 PM · VyOS 1.4 Sagitta
c-po added a comment to T5409: Add 'set interfaces wireguard wgX threaded'.

PR https://github.com/vyos/vyos-1x/pull/2130

Aug 17 2023, 6:53 PM · VyOS 1.4 Sagitta
c-po claimed T5409: Add 'set interfaces wireguard wgX threaded'.
Aug 17 2023, 6:53 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXb9655365bcc0: login: T5490: add stricter validation for home-directory path.
Aug 17 2023, 6:37 PM
c-po committed rVYOSONEX3834e3e49ca5: radius: T5490: add stricter validation for key.
Aug 17 2023, 6:37 PM
c-po closed T5490: login: add missing regex for home direcotry and radius server key as Resolved.
Aug 17 2023, 6:37 PM · VyOS 1.4 Sagitta
c-po changed the status of T5490: login: add missing regex for home direcotry and radius server key from Open to In progress.
Aug 17 2023, 6:36 PM · VyOS 1.4 Sagitta
c-po created T5490: login: add missing regex for home direcotry and radius server key.
Aug 17 2023, 6:35 PM · VyOS 1.4 Sagitta
Apachez updated the task description for T5489: Change to BBR as TCP congestion control, or at least make it an config option.
Aug 17 2023, 5:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez created T5489: Change to BBR as TCP congestion control, or at least make it an config option.
Aug 17 2023, 5:50 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5486: Service dns dynamic cannot pass the smoketest from Unknown Status to Resolved.
Aug 17 2023, 5:46 PM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav added a comment to T5488: System conntrack ignore does not take any effect.

PR https://github.com/vyos/vyos-1x/pull/2155

Aug 17 2023, 5:44 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXa2e1199c73ba: T5486: smoketest: adjust to new process_named_running() implementation.
Aug 17 2023, 5:43 PM
GitHub <[email protected]> committed rVYOSONEX7cbec4a80c1b: Merge pull request #2154 from sever-sever/T5486 (authored by c-po).
Aug 17 2023, 5:43 PM
Viacheslav changed the status of T5488: System conntrack ignore does not take any effect from Open to In progress.
Aug 17 2023, 5:26 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5488: System conntrack ignore does not take any effect.

Priority must be less than -200 https://github.com/vyos/vyos-1x/blob/08cb4f350b335d5af401f30850d410b4be38530d/data/vyos-firewall-init.conf#L23-L32
https://wiki.nftables.org/wiki-nftables/index.php/Setting_packet_connection_tracking_metainformation#notrack_-_Bypass_connection_tracking

	chain PREROUTING {
		type filter hook prerouting priority -200; policy accept;
		counter packets 6405 bytes 444828 jump VYOS_CT_IGNORE
		counter packets 6405 bytes 444828 jump VYOS_CT_TIMEOUT
		counter packets 6405 bytes 444828 jump VYOS_CT_PREROUTING_HOOK
		counter packets 6405 bytes 444828 jump FW_CONNTRACK
		notrack
	}
Aug 17 2023, 5:19 PM · VyOS 1.4 Sagitta
Viacheslav created T5488: System conntrack ignore does not take any effect.
Aug 17 2023, 4:52 PM · VyOS 1.4 Sagitta
fernando created T5487: OPENVPN -DEPRECATED OPTION: --cipher.
Aug 17 2023, 4:06 PM · VyOS 1.5 Circinus, Restricted Project
Viacheslav committed rVYOSONEX477c2def5fb4: T5223: Fix removing key id for GRE tunnel.
Aug 17 2023, 12:43 PM
GitHub <[email protected]> committed rVYOSONEXdcb02916ddde: Merge pull request #2153 from sever-sever/T5223 (authored by dmbaturin).
Aug 17 2023, 12:43 PM
c-po moved T5428: dhcp: client renewal fails when running inside VRF from Finished to Backlog on the VyOS 1.3 Equuleus (1.3.4) board.
Aug 17 2023, 11:11 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po committed rVYOSONEX08cb4f350b33: console-server: T2490: add op-mode commands to display log.
Aug 17 2023, 11:10 AM
c-po committed rVYOSONEX1a69e9bb4b4e: Revert: dhcp: T5428: always release lease from default VRF.
Aug 17 2023, 11:10 AM
c-po added a reverting change for rVYOSONEX9afcea251bdc: dhcp: T5428: always release lease from default VRF: rVYOSONEX1a69e9bb4b4e: Revert: dhcp: T5428: always release lease from default VRF.
Aug 17 2023, 11:10 AM
Viacheslav added a comment to T5486: Service dns dynamic cannot pass the smoketest.

PR https://github.com/vyos/vyos-1x/pull/2154

Aug 17 2023, 11:10 AM · VyOS 1.3 Equuleus (1.3.5)
c-po added a comment to T5428: dhcp: client renewal fails when running inside VRF.

Tested after merging T5476 and now we see a proper DHCP release message

Aug 17 2023, 11:04 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav closed T5486: Service dns dynamic cannot pass the smoketest as Unknown Status.
Aug 17 2023, 10:58 AM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav added a comment to T5486: Service dns dynamic cannot pass the smoketest.

It could be incorrect process name name='ddclient - sleeping for 10 seconds' expectedd ddclient, possible bug after commit https://github.com/vyos/vyos-1x/commit/58a20e42087cbb7a1b3b4725fa40fd15a31bb4ed

psutil.Process(pid=2282, name='sshd', started='12:29:23')
psutil.Process(pid=2283, name='vbash', started='12:29:23')
psutil.Process(pid=2625, name='rsyslogd', started='12:30:31')
psutil.Process(pid=9841, name='vbash', started='13:02:24')
psutil.Process(pid=10249, name='kworker/u2:1-events_unbound', started='13:03:58')
psutil.Process(pid=10735, name='kworker/0:1-mm_percpu_wq', started='13:10:42')
psutil.Process(pid=10737, name='kworker/u2:2-events_unbound', started='13:10:42')
psutil.Process(pid=10987, name='ddclient - sleeping for 10 seconds', started='13:12:47')
Aug 17 2023, 10:37 AM · VyOS 1.3 Equuleus (1.3.5)
fett0 <[email protected]> committed rVYOSONEX77ef9f800421: T5466: L3VPN label allocation mode.
Aug 17 2023, 10:13 AM
GitHub <[email protected]> committed rVYOSONEXd4e9652083ce: Merge pull request #2152 from fett0/T5466 (authored by c-po).
Aug 17 2023, 10:13 AM
Viacheslav created T5486: Service dns dynamic cannot pass the smoketest.
Aug 17 2023, 9:54 AM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav moved T5223: tunnel key doesn't clear from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 17 2023, 9:44 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T5223: tunnel key doesn't clear .

PR for 1.3.4 https://github.com/vyos/vyos-1x/pull/2153

Aug 17 2023, 9:44 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po closed T5476: netplug: replace Perl helper scripts with a Python equivalent as Resolved.
Aug 17 2023, 9:42 AM · VyOS 1.4 Sagitta
c-po closed T5437: logrotate.service fails to start as Not Applicable.
Aug 17 2023, 9:24 AM · VyOS 1.4 Sagitta
c-po added a comment to T5437: logrotate.service fails to start.

Thanks @Apachez - closing

Aug 17 2023, 9:24 AM · VyOS 1.4 Sagitta
Viacheslav closed T4202: NFT: Zone policies fail to apply when "l2tp+" is in the interface list as Resolved.
Aug 17 2023, 7:46 AM · VyOS 1.4 Sagitta
SrividyaA added projects to T5223: tunnel key doesn't clear : VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3).
Aug 17 2023, 6:45 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
SrividyaA closed T5223: tunnel key doesn't clear as Resolved.
Aug 17 2023, 6:35 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav edited projects for T5484: set extcommunity - just allow one extend community, added: VyOS 1.3 Equuleus (1.3.4); removed VyOS 1.3 Equuleus.
Aug 17 2023, 5:39 AM

Aug 16 2023

c-po created T5485: pppoe: using dialer interfaces in wan-load balancing does not re-install default route.
Aug 16 2023, 9:15 PM · Restricted Project, VyOS Rolling
fernando updated the task description for T5484: set extcommunity - just allow one extend community.
Aug 16 2023, 8:29 PM
fernando created T5484: set extcommunity - just allow one extend community.
Aug 16 2023, 7:41 PM
Sophie added a comment to T5160: Firewall refactor.

If there would never be such then "INVALID" wouldnt exist as an option.

Aug 16 2023, 7:29 PM · VyOS 1.4 Sagitta