Page MenuHomeVyOS Platform
Feed All Stories

Aug 27 2023

sarthurdev added a comment to T5499: initial arm64 support for RPI4 and QEMU VM.

@tjjh89017 This will need to be re-evaluated. The build from your PR was taking in excess of 8 hours on the build server - the defconfig likely needs to be brought down to only the minimum required modules/drivers for successful builds on target devices.

Aug 27 2023, 4:23 PM
Apachez reopened T5495: Enable snmp module also for frr/ldpd as "Open".

Just a comment:

Aug 27 2023, 3:47 PM · VyOS 1.4 Sagitta
tjjh89017 added a comment to T5512: build linux-firmware script cannot expand asterisks if firmware name is a glob string.

It should be fixed via https://github.com/vyos/vyos-build/pull/382

Aug 27 2023, 1:44 PM · VyOS 1.4 Sagitta
jestabro reopened T3275: Disable conntrack helpers by default as "Open".

Reopen to investigate, as unresolved ... cf. T5515, T3821

Aug 27 2023, 1:29 PM · VyOS 1.5 Circinus
dutty created T5517: Equuleus ISO build fails.
Aug 27 2023, 11:55 AM · VyOS 1.3 Equuleus
sarthurdev added a comment to T3275: Disable conntrack helpers by default.

This does still need to be addressed in 1.4. Without a version string, the 2-to-3 migrator is adding the conntrack helpers to the default config.

Aug 27 2023, 10:58 AM · VyOS 1.5 Circinus
sarthurdev closed T5515: Conntrack helpers should be disabled by default as Invalid.

Duplicate T3275

Aug 27 2023, 10:56 AM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX6b5d3568b88f: firewall: T5080: Disable conntrack unless required by rules.
Aug 27 2023, 10:33 AM
GitHub <noreply@github.com> committed rVYOSONEXd3edda22573f: Merge pull request #2176 from sarthurdev/T5080 (authored by c-po).
Aug 27 2023, 10:33 AM
sarthurdev committed rVYOSONEX0d413f5c5516: github: Labeler needs to run on `pull_request_target`.
Aug 27 2023, 10:32 AM
GitHub <noreply@github.com> committed rVYOSONEX904cbe448c57: Merge pull request #2178 from sarthurdev/labels (authored by c-po).
Aug 27 2023, 10:32 AM
Viacheslav closed T5495: Enable snmp module also for frr/ldpd as Invalid.
Aug 27 2023, 10:27 AM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX8b62065eaa59: github: Set permissions for label workflow.
Aug 27 2023, 10:14 AM
GitHub <noreply@github.com> committed rVYOSONEX63012d655fbe: Merge pull request #2175 from sarthurdev/labels (authored by c-po).
Aug 27 2023, 10:14 AM
sarthurdev added a comment to T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled.

The kernel modules handle tracking of those, rpc/tns are userspace helpers.

Aug 27 2023, 10:14 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled.

So how are all the other helpers added to the ruleset if not dynamically?

Aug 27 2023, 10:12 AM · VyOS 1.4 Sagitta
Apachez created T5516: Add missing conntrack helpers which are available in kernel and userspace conntrackd.
Aug 27 2023, 10:00 AM · VyOS Rolling
Apachez created T5515: Conntrack helpers should be disabled by default.
Aug 27 2023, 9:44 AM · VyOS 1.4 Sagitta
Apachez created T5514: Improve error handling when/if config.boot is deleted or missing .
Aug 27 2023, 9:40 AM · VyOS 1.4 Sagitta (1.4.1)
sarthurdev added a comment to T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled.

They are only defined. Only when the VYOS_CT_HELPER chain is reached will they take effect - see links in my above comment. Being in the default config will have no effect on connection tracking if bypassed by the notrack rule.

Aug 27 2023, 8:48 AM · VyOS 1.4 Sagitta
Apachez reopened T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled as "Open".

Then how come these helpers are always enabled as pointed out at https://vyos.dev/T5080#149232 ?

Aug 27 2023, 8:38 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5080: Disable conntrack by default.

How come these helpers (pointed out by @saintclairpcarvalho but also )https://vyos.dev/T5479) are always enabled?

Aug 27 2023, 8:31 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev changed the status of T5080: Disable conntrack by default, a subtask of T5160: Firewall refactor, from In progress to Needs testing.
Aug 27 2023, 8:22 AM · VyOS 1.4 Sagitta
sarthurdev changed the status of T5080: Disable conntrack by default from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/2176

Aug 27 2023, 8:22 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev closed T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled as Invalid.

They are created but unused by default (see VYOS_CT_HELPER chain)

Aug 27 2023, 8:14 AM · VyOS 1.4 Sagitta
sarthurdev changed the status of T5511: Cleanup of unused directories (and files) in order to shrink image-size from Open to Needs testing.
Aug 27 2023, 8:07 AM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX0e1ec63e513a: qos: T5018: Fix dependents only being set for QoS interfaces.
Aug 27 2023, 5:05 AM
GitHub <noreply@github.com> committed rVYOSONEXf7b7c6df9822: Merge pull request #2174 from sarthurdev/T5018_fix (authored by c-po).
Aug 27 2023, 5:05 AM
Apachez added a comment to T5160: Firewall refactor.

Found some anomalies regarding show firewall command (I assume related to the refactoring) which I have reported in https://vyos.dev/T5513

Aug 27 2023, 1:05 AM · VyOS 1.4 Sagitta
Apachez created T5513: Anomalies in show firewall command after refactoring.
Aug 27 2023, 1:03 AM · VyOS 1.4 Sagitta
sarthurdev changed the status of T5018: Redirect to IFB removed after change in qos policy from Confirmed to Needs testing.

Thanks for following up on this issue @rayzilt

Aug 27 2023, 12:13 AM · VyOS 1.4 Sagitta
syncer moved T4869: A network with `/32` or `/128` mask cannot be removed from a network-group from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.4) board.
Aug 27 2023, 12:12 AM · VyOS 1.3 Equuleus (1.3.4)
syncer edited projects for T4869: A network with `/32` or `/128` mask cannot be removed from a network-group, added: VyOS 1.3 Equuleus (1.3.4); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:12 AM · VyOS 1.3 Equuleus (1.3.4)
syncer edited projects for T4745: CLI TAB issue with values with '-' at the beginning in conf mode, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
syncer edited projects for T4774: Disallow duplicate pubkey on peers of a wireguard interface, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
syncer edited projects for T4692: Docker Builds of Equuleus Fail - public_suffix requires Ruby version >= 2.6, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM
syncer edited projects for T4769: Conntrack settings are not apply properly, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS Rolling, Bugs
syncer edited projects for T4776: NVME storage is not detected properly during installation, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
syncer edited projects for T4811: Webproxy bypassing CLI whitelist command is missing, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
syncer edited projects for T4840: Backend qmicli commands fail, when ModemManager is starting the cellular service, need to use qmi-proxy., added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS Rolling, Bugs
syncer edited projects for T4874: Add Warning message to Equuleus, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.4)
syncer edited projects for T4855: Trying to create more than one tunnel of the same type to the same address causes unhandled exception, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.4)
syncer edited projects for T4972: Support FQDN and IPv6 addresses for RADIUS servers in accel-ppp-backed protocols, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS Rolling
syncer edited projects for T4894: Using the same name for address and network group yields in ipset error, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.4 Sagitta
syncer edited projects for T4895: Tag nodes are overwritten when configured by Cloud-Init from User-Data, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
syncer edited projects for T4976: Unable to form bond with Broadcom Inc. BCM57454 NetXtrem-E, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.4 Sagitta (1.4.0), Bugs
syncer edited projects for T5004: DHCP-Relay potential bug. Static configurations of DHCP-Relay Interfaces, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS Rolling
syncer edited projects for T5140: Firewall network-group problems, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.4)
syncer edited projects for T5190: Cloud-Init cannot fetch Meta-data on machines where the main Ethernet interface is not eth0, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
syncer edited projects for T5180: initramfs-tools ignores firmware from updates directory, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.6)
syncer edited projects for T5182: Update Intel ice driver, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.6)
syncer edited projects for T5187: Update Realtek r8152 driver, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.6)
syncer edited projects for T5220: Unattended installation, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS Rolling
syncer edited projects for T5192: RNDIS Missing from Kernel, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
syncer edited projects for T5235: SSH keys with special characters cannot be applied via Cloud-init, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
syncer edited projects for T5279: vrf bind-to-all not working for TCP, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · Bugs, VyOS 1.3 Equuleus (1.3.9)
syncer edited projects for T5389: add `ftps`, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM
syncer edited projects for T5485: pppoe: using dialer interfaces in wan-load balancing does not re-install default route, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus.
Aug 27 2023, 12:10 AM · Bugs, VyOS Rolling

Aug 26 2023

Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

The refactored firewall frontend uses rule numbers as described in: https://docs.vyos.io/en/latest/configuration/firewall/general.html#firewall-rules

Aug 26 2023, 11:28 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez added a comment to T5511: Cleanup of unused directories (and files) in order to shrink image-size.

PR created: https://github.com/vyos/vyos-build/pull/381

Aug 26 2023, 11:06 PM · VyOS 1.4 Sagitta
Apachez claimed T5511: Cleanup of unused directories (and files) in order to shrink image-size.
Aug 26 2023, 10:36 PM · VyOS 1.4 Sagitta
sarthurdev closed T5039: Can't add new local user as Resolved.
Aug 26 2023, 9:42 PM · VyOS 1.4 Sagitta
sarthurdev closed T5023: PKI commit fails to update dependents as Resolved.
Aug 26 2023, 9:40 PM · VyOS 1.4 Sagitta
sarthurdev closed T4512: enable-default-log on zone-policy as Resolved.
Aug 26 2023, 9:39 PM · VyOS 1.4 Sagitta
sarthurdev closed T5003: Upgrade base system to Debian 12 "Bookworm" as Resolved.
Aug 26 2023, 9:38 PM · VyOS 1.4 Sagitta
sarthurdev closed T5404: Ability to completely disable firewall/conntrack as Invalid.

Closing as dupe of T5080

Aug 26 2023, 9:36 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T5080: Disable conntrack by default, a subtask of T5160: Firewall refactor, from Open to In progress.
Aug 26 2023, 9:35 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T5080: Disable conntrack by default from Open to In progress.
Aug 26 2023, 9:35 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
tjjh89017 added a comment to T5512: build linux-firmware script cannot expand asterisks if firmware name is a glob string.

Raspberry pi 4 wifi driver requires some missing files.

Aug 26 2023, 8:49 PM · VyOS 1.4 Sagitta
tjjh89017 created T5512: build linux-firmware script cannot expand asterisks if firmware name is a glob string.
Aug 26 2023, 8:38 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T3509: No BCP38 for IPv6 on VyOS from In progress to Needs testing.
Aug 26 2023, 5:40 PM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEXd62f8ed1e360: firewall: T3509: Add support for IPv6 return path filtering.
Aug 26 2023, 12:59 PM
sarthurdev committed rVYOSONEXb6f742716da5: interface: T3509: Add per-interface IPv6 source validation.
Aug 26 2023, 12:59 PM
sarthurdev committed rVYOSONEX2509a1ab84cd: firewall: T5160: Remove unused zone template.
Aug 26 2023, 12:59 PM
GitHub <noreply@github.com> committed rVYOSONEX75aa90cf2b23: Merge pull request #2163 from sarthurdev/firewall_rpfilter (authored by c-po).
Aug 26 2023, 12:59 PM
skoenman added a comment to T2229: PPPOE Default Queue type selection.

@skoenman Could you write some examples of configuration?

Ill see if i can get a example more or less of what one wants but it would be there were you asign the queue to the pppoe accoynt when authing..

Aug 26 2023, 8:38 AM · VyOS 1.4 Sagitta
Apachez created T5511: Cleanup of unused directories (and files) in order to shrink image-size.
Aug 26 2023, 2:19 AM · VyOS 1.4 Sagitta
Apachez created T5510: Shrink imagesize and improve read performance by changing mksquashfs syntax.
Aug 26 2023, 2:06 AM · VyOS 1.4 Sagitta

Aug 25 2023

Apachez added a comment to T5112: Enable support for Network Time Security (NTS) for chrony.

Using VyOS 1.4-rolling-202308250021.

Aug 25 2023, 10:01 PM · VyOS 1.4 Sagitta
syncer edited projects for T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM
syncer edited projects for T2934: proxy-arp-pvlan on VRRP interface, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · Restricted Project, VyOS Rolling
syncer edited projects for T2289: Denest cerbot certificate configuration from service https, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
syncer edited projects for T3651: Move certbot request to op-mode, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
syncer edited projects for T3574: Add constraintGroup for combining validators with logical AND, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
syncer edited projects for T3022: Allow to provide custom TLS certificates for the HTTP virtual hosts, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.4 Sagitta (1.4.0)
syncer edited projects for T3980: vrrp transition-script validator makes warning fatal and also causes a python NameError exception, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.3 Equuleus (1.3.6)
syncer edited projects for T5247: the bug of the command "show interfaces system", added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
syncer edited projects for T5270: Make OpenVPN `tls dh-params` optional, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
syncer edited projects for T4146: Nginx should not listen on port 80, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.3 Equuleus (1.3.5)
syncer edited projects for T5269: OpenVPN non-TLS site-to-site mode deprecation, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.4 Sagitta
syncer edited projects for T4318: Add ability to mark nodes as non-tag nodes, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q4), VyOS Rolling
syncer edited projects for T5268: OpenVPN: upgrade package to 2.6 series, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.3 Equuleus (1.3.5)
syncer edited projects for T5271: Add support for peer-fingerprint to OpenVPN, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
syncer edited projects for T5273: Add op mode commands for displaying certificate details and fingerprints, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
syncer edited projects for T5275: Add op mode commands for exporting certificates to PEM files with correct headers, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
syncer edited projects for T5274: Add a deprecation warning for OpenVPN site-to-site with pre-shared secret, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:49 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
syncer edited projects for T75: pmacct-based NetFlow implementation's performance is insufficient for modern networks, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:48 PM · VyOS 1.5 Circinus (2025.11)
syncer edited projects for T5280: Update Expired keys (2023-06-08) for PowerDNS, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:48 PM · VyOS 1.3 Equuleus (1.3.5)
syncer edited projects for T5309: Issues when trying to remove OSPF configuration, added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:48 PM · VyOS 1.3 Equuleus (1.3.5)
syncer edited projects for T102: Add a command like "set service dns dynamic http-request url ...", added: VyOS 1.3 Equuleus (1.3.5); removed VyOS 1.3 Equuleus (1.3.4).
Aug 25 2023, 9:48 PM