Page MenuHomeVyOS Platform
Feed All Stories

Sep 12 2023

GitHub <noreply@github.com> committed rVYOSONEX87ab93326dfd: Merge pull request #2247 from sever-sever/T5562-sag (authored by Viacheslav).
Sep 12 2023, 10:19 AM
n.fort changed the status of T4072: Feature Request: Firewall on bridge interfaces from In progress to Needs testing.

op-mode: https://github.com/vyos/vyos-1x/pull/2242

Sep 12 2023, 10:17 AM · VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX63cf32004caf: T5562: Cleanup netns for smoketest load-balancing wan (authored by Viacheslav).
Sep 12 2023, 7:48 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX5ecfa73fbb6d: T4754: Fix path for popen moved to utils process (authored by Viacheslav).
Sep 12 2023, 7:48 AM
GitHub <noreply@github.com> committed rVYOSONEXb47a866c2fdf: Merge pull request #2244 from vyos/mergify/bp/sagitta/pr-2235 (authored by Viacheslav).
Sep 12 2023, 7:43 AM

Sep 11 2023

aga added a comment to T5513: Anomalies in show firewall command after refactoring.

100% agree. If this isn't too big of a hassle to implement, I would very much appreciate the approach/workaround of @Apachez, until nftables supports this feature ootb...

Sep 11 2023, 9:29 PM · VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXb0a9782a4a61: T5564: Fix show firewall group and show firewall summary (authored by Viacheslav).
Sep 11 2023, 7:34 PM
GitHub <noreply@github.com> committed rVYOSONEXb2c3ff90c605: Create test.txt (authored by c-po).
Sep 11 2023, 7:10 PM
c-po committed rVYOSONEXcd3dda75534a: GitHub: fix workflow folder for MergifyIo.
Sep 11 2023, 7:07 PM
GitHub <noreply@github.com> committed rVYOSONEX13a352e9357e: GitHub: add MergifyIo action (authored by c-po).
Sep 11 2023, 7:07 PM
Apachez added a comment to T5513: Anomalies in show firewall command after refactoring.

Checked with #netfilter irc-channel.

Sep 11 2023, 6:21 PM · VyOS 1.4 Sagitta
jestabro changed the status of T5353: config-mgmt: normalize archive updates and commit log entries, a subtask of T5347: Compare commit revision bug, from Unknown Status to Resolved.
Sep 11 2023, 5:32 PM · VyOS 1.4 Sagitta
jestabro changed the status of T5353: config-mgmt: normalize archive updates and commit log entries, a subtask of T5551: Missing check for boot_configuration_complete raises error in vyos-save-config.py, from Unknown Status to Resolved.
Sep 11 2023, 5:32 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro changed the status of T5353: config-mgmt: normalize archive updates and commit log entries from Unknown Status to Resolved.
Sep 11 2023, 5:32 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro changed the status of T5551: Missing check for boot_configuration_complete raises error in vyos-save-config.py from Unknown Status to Resolved.
Sep 11 2023, 5:31 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro committed rVYOSONEXc1a078e5e4dd: config-mgmt: T5353: correct update check during boot.
Sep 11 2023, 5:29 PM
jestabro committed rVYOSONEX667e96856856: config-mgmt: T5353: only add log entry if archiving.
Sep 11 2023, 5:29 PM
jestabro committed rVYOSONEXc35a66f327b0: config-mgmt: T5353: after updated save-config, one can include init rev.
Sep 11 2023, 5:29 PM
jestabro committed rVYOSONEXd75a7d17a98b: config-mgmt: T5556: fix bug in revision to archive update.
Sep 11 2023, 5:29 PM
GitHub <noreply@github.com> committed rVYOSONEX2103b5522d21: Merge pull request #2215 from jestabro/T5353-sagitta (authored by jestabro).
Sep 11 2023, 5:29 PM
roedie added a comment to T5080: Disable conntrack by default.

I just tested this with a firewall config with no connection tracking config enabled, still the conntrack modules are loaded and used.

Sep 11 2023, 2:52 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
swanduron added a comment to T5376: Conntrack FTP helper does not work properly.

The same situation as @svd135 . The passive FTP data connection now is stopped by the problem with FTP ALG.

Sep 11 2023, 1:15 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
alainlamar closed T5567: vyos-1x: webproxy: maximum-object-size allowed ranges not in sync with Equuleus as Resolved.
Sep 11 2023, 12:43 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXd2e7eafe84c1: init: remove dependency on frr.service - required for router shutdown.
Sep 11 2023, 12:15 PM
c-po committed rVYOSONEXaf398c51f7d0: init: remove dependency on frr.service - required for router shutdown.
Sep 11 2023, 12:14 PM
Apachez added a comment to T5564: Both show firewall group and show firewall summary fails.

I was thinking about N/D and personally I would prefer "None" to be listed for the various "show firewall" commands instead of N/D.

Sep 11 2023, 10:34 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav created T5570: PAM config RADIUS ignore for default and success.
Sep 11 2023, 10:34 AM · VyOS 1.4 Sagitta (1.4.1)
Apachez added a comment to T5513: Anomalies in show firewall command after refactoring.

Resolved by: https://vyos.dev/T5564

Sep 11 2023, 10:32 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5564: Both show firewall group and show firewall summary fails.

This can be put to resolved when the backports are confirmed aswell.

Sep 11 2023, 10:20 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav moved T5564: Both show firewall group and show firewall summary fails from Open to Backport Candidates on the VyOS 1.5 Circinus board.
Sep 11 2023, 9:58 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a project to T5564: Both show firewall group and show firewall summary fails: VyOS 1.4 Sagitta.
Sep 11 2023, 9:58 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5564: Both show firewall group and show firewall summary fails.

N/D == not defined

Sep 11 2023, 9:54 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5564: Both show firewall group and show firewall summary fails.

Confirmed working with VyOS 1.5-rolling-202309110651

A question before setting this to resolved:

What does N/D mean?

Shouldnt it be N/A instead?

Sep 11 2023, 9:52 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav changed the status of T5518: Add MLD protocol support from In progress to Needs testing.
Sep 11 2023, 9:48 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5564: Both show firewall group and show firewall summary fails.

Confirmed working with VyOS 1.5-rolling-202309110651

Sep 11 2023, 9:41 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5518: Add MLD protocol support.

Im a bit allergic to have stuff automatically created which clearly is not enabled by the config.

Sep 11 2023, 9:21 AM · VyOS 1.4 Sagitta
vfreex added a comment to T5518: Add MLD protocol support.

pim6reg is created by FFR's pim6d. It seems to me that it will create such as interface for each VRF. Does this interface have any functional impact on your setup?

Sep 11 2023, 9:10 AM · VyOS 1.4 Sagitta
sarthurdev closed T5562: Smoketests fail for vyos:current (test_netns.py) as Resolved.

Builds passing: https://github.com/vyos/vyos-rolling-nightly-builds/actions/runs/6142937552

Sep 11 2023, 8:59 AM · VyOS 1.5 Circinus
dmbaturin created T5569: Make it possible to verify the signature of an installed image.
Sep 11 2023, 7:34 AM · VyOS Rolling
c-po changed the status of T3424: PPPoE IA-PD doesn't work in VRF from Unknown Status to Resolved.
Sep 11 2023, 5:16 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po moved T3424: PPPoE IA-PD doesn't work in VRF from Backport Candidates to Finished on the VyOS 1.4 Sagitta board.
Sep 11 2023, 5:16 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po updated the task description for T2472: Ability to configure EIGRP protocol.
Sep 11 2023, 5:15 AM · VyOS Rolling
c-po closed T2773: EIGRP support for VRF as Resolved.
Sep 11 2023, 5:15 AM · VyOS 1.4 Sagitta
c-po changed the status of T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802 from Unknown Status to Resolved.
Sep 11 2023, 5:14 AM · VyOS 1.3 Equuleus (1.3.4)
c-po committed rVYOSONEXd08c6128620e: vxlan: T3700: Revert change to `vyos.utils.process.cmd` (authored by sarthurdev).
Sep 11 2023, 5:11 AM
c-po committed rVYOSONEX6c3defcc1e5e: T5241: Revert change to vyos.utils.process.cmd.
Sep 11 2023, 5:10 AM
sarthurdev committed rVYOSONEXe46afa2c58ee: vxlan: T3700: Revert change to `vyos.utils.process.cmd`.
Sep 11 2023, 5:00 AM
GitHub <noreply@github.com> committed rVYOSONEX8140789fdbc7: Merge pull request #2238 from sarthurdev/current (authored by c-po).
Sep 11 2023, 4:59 AM
Viacheslav committed rVYOSONEXb658f601f03f: T5533: Fix for vrrp dict key if virtual-server is used.
Sep 11 2023, 2:29 AM
GitHub <noreply@github.com> committed rVYOSONEX77b2c4fc2d92: Merge pull request #2214 from sever-sever/T5533-sag (authored by jestabro).
Sep 11 2023, 2:29 AM

Sep 10 2023

sarthurdev changed the status of T5568: Install image from live ISO always defaults boot to KVM entry from In progress to Needs testing.

current PR: https://github.com/vyos/vyatta-cfg-system/pull/205

Sep 10 2023, 11:22 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev changed the status of T5568: Install image from live ISO always defaults boot to KVM entry from Open to In progress.
Sep 10 2023, 10:54 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5559: Selective proxy-arp/proxy-ndp when doing SNAT/DNAT.

PR https://github.com/vyos/vyos-1x/pull/2240

set protocols static proxy-arp 192.0.2.1 interface eth0
set protocols static proxy-arp 192.0.2.1 interface eth1
set protocols static proxy-ndp 2001:db8::1 interface eth1
Sep 10 2023, 10:38 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5518: Add MLD protocol support.

I dont know if its related to this task but I noticed recently that even if I have no IPv6 configured on any interface and have IPv6 disabled for forwarding:

set system ipv6 disable-forwarding

I can in VyOS 1.5-rolling-202309080021 see an additional pim6reg interface!?

vyos@vyos:~$ ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
...
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq master MGMT state UP group default qlen 1000
...
3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq master INTERNET state UP group default qlen 1000
...
4: eth2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq master INTERNET state UP group default qlen 1000
...
5: eth3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq master INTERNET state UP group default qlen 1000
...
6: pim6reg@NONE: <NOARP,UP,LOWER_UP> mtu 1452 qdisc noqueue state UNKNOWN group default qlen 1000
    link/pimreg 
7: INTERNET: <NOARP,MASTER,UP,LOWER_UP> mtu 65575 qdisc noqueue state UP group default qlen 1000
...
8: MGMT: <NOARP,MASTER,UP,LOWER_UP> mtu 65575 qdisc noqueue state UP group default qlen 1000
...

Its also visible when running:

monitor bandwidth interface *
Sep 10 2023, 10:03 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5562: Smoketests fail for vyos:current (test_netns.py).

Latest run https://github.com/vyos/vyos-rolling-nightly-builds/actions/runs/6138721359/job/16655876943

Sep 10 2023, 7:33 PM · VyOS 1.5 Circinus
svd135 added a comment to T5376: Conntrack FTP helper does not work properly.

table ip raw {

ct helper rpc_tcp {
        type "rpc" protocol tcp
        l3proto ip
}
Sep 10 2023, 7:31 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
Apachez added a comment to T3655: NAT doesn't work correctly with VRF.

Oh sorry, I missed that this commit was for LTS 1.3.x series.

Sep 10 2023, 7:13 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
vfreex committed rVYOSONEXaed71d4b7718: T3655: Fix NAT problem with VRF.
Sep 10 2023, 6:37 PM
GitHub <noreply@github.com> committed rVYOSONEX87880a552fd1: Merge pull request #2236 from vfreex/fix-nat-problem-with-vrf (authored by c-po).
Sep 10 2023, 6:37 PM
vfreex added a comment to T3655: NAT doesn't work correctly with VRF.

@Apachez I am running kernel 6.1.49-amd64-vyos and this works fine with my local setup.
The patch is already in linux kernel since at least 4.3 (you can confirm with https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/log/include/net/netfilter/nf_conntrack_zones.h?h=linux-4.3.y), but it was added to nft command only since Feb 2017: https://git.netfilter.org/nftables/commit/src/ct.c?id=ed66d9966294a3bab6c8611e369861ba57374743

Sep 10 2023, 6:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Apachez updated subscribers of T5562: Smoketests fail for vyos:current (test_netns.py).

Fix by @sever regarding those failing conntrack smoketest: https://github.com/vyos/vyos-1x/pull/2234

Sep 10 2023, 6:06 PM · VyOS 1.5 Circinus
sarthurdev added a comment to T5376: Conntrack FTP helper does not work properly.

Can we see the output of sudo nft list table ip raw on an affected router?

Sep 10 2023, 6:06 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
Apachez added a comment to T3655: NAT doesn't work correctly with VRF.

@vfreex the referenced netfilter patch is from 2015, is that really valid for current version thats included in the Linux 6.1 LTS kernel?

Sep 10 2023, 6:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
vfreex added a comment to T3655: NAT doesn't work correctly with VRF.

You can test this approach on a running VyOS router using following commands:

Sep 10 2023, 5:32 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
vfreex added a comment to T3655: NAT doesn't work correctly with VRF.

I created a PR to fix this issue by using direction parameter of conntrack zones: https://github.com/vyos/vyos-1x/pull/2236
I have a very basic VRF setup and it works fine. It would be much appreciated if someone could test this with more complex VRF setup.

Sep 10 2023, 5:04 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
swanduron added a comment to T5376: Conntrack FTP helper does not work properly.

Sorry to bother you @sdev , the latest releases of 1.5-rolling-202309080021 and 1.4-rolling-202309070021 still have this problem.

Sep 10 2023, 3:19 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
c-po closed T5555: Fix timezone migrator (system 13-to-14) as Resolved.
Sep 10 2023, 2:17 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5555: Fix timezone migrator (system 13-to-14) from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.4) board.
Sep 10 2023, 2:16 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po closed T5545: sflow is not working as Resolved.
Sep 10 2023, 2:16 PM · VyOS 1.3 Equuleus (1.3.4)
c-po moved T5545: sflow is not working from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.4) board.
Sep 10 2023, 2:15 PM · VyOS 1.3 Equuleus (1.3.4)
c-po moved T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802 from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.4) board.
Sep 10 2023, 2:14 PM · VyOS 1.3 Equuleus (1.3.4)
c-po closed T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802 as Unknown Status.
Sep 10 2023, 2:14 PM · VyOS 1.3 Equuleus (1.3.4)
c-po added a comment to T5557: bgp: Use treat-as-withdraw for tunnel encapsulation attribute CVE-2023-38802.

Added backport for FRR 7.5 https://github.com/FRRouting/frr/pull/14381

Sep 10 2023, 2:02 PM · VyOS 1.3 Equuleus (1.3.4)
c-po committed rVYOSONEX0ad6d33f2fb1: Debian: bump package version to 1.5dev0.
Sep 10 2023, 1:50 PM
c-po committed rVYOSONEX769770d7619e: T5567: Increase allowed range for maximum-object-size to 1000000 KB for the… (authored by alainlamar).
Sep 10 2023, 1:31 PM
Viacheslav changed the status of T5564: Both show firewall group and show firewall summary fails from Open to Needs testing.
Sep 10 2023, 1:30 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
alainlamar committed rVYOSONEX4401c6920fed: T5567: Increase allowed range for maximum-object-size to 1000000 KB for the….
Sep 10 2023, 1:29 PM
GitHub <noreply@github.com> committed rVYOSONEX8baceafce0cd: Merge pull request #2232 from alainlamar/T5567 (authored by c-po).
Sep 10 2023, 1:29 PM
Viacheslav committed rVYOSONEX9daac1632df9: T5564: Fix show firewall group and show firewall summary.
Sep 10 2023, 1:29 PM
GitHub <noreply@github.com> committed rVYOSONEXaf0a4667326b: Merge pull request #2235 from sever-sever/T5564 (authored by c-po).
Sep 10 2023, 1:29 PM
Viacheslav added a comment to T5559: Selective proxy-arp/proxy-ndp when doing SNAT/DNAT.

I guess we should use the current ip neighbor xxx instead of old arp. I hope it does the same.

sudo ip neighbor add proxy 192.0.2.1 dev eth0
sudo ip -6 neigh add proxy aa::1 dev eth0

Show

vyos@r1# sudo ip neighbor show proxy
192.168.122.11 dev eth0  proxy
192.0.2.1 dev eth0  proxy
aa::1 dev eth0  proxy
[edit]
vyos@r1#
Sep 10 2023, 1:26 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5529: Missing symbolic link in linux-firmware package. as Resolved.
Sep 10 2023, 1:00 PM · VyOS 1.4 Sagitta
Viacheslav closed T5565: Builds as vyos-999-timestamp instead of vyos-1.4-rolling-timestamp as Resolved.
Sep 10 2023, 12:49 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5564: Both show firewall group and show firewall summary fails.

PR https://github.com/vyos/vyos-1x/pull/2235

Sep 10 2023, 11:46 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav committed rVYOSONEXa36443810dbf: T4309: Fix conntrack teamplate group.
Sep 10 2023, 11:00 AM
GitHub <noreply@github.com> committed rVYOSONEX3f4c320cbcd3: Merge pull request #2234 from sever-sever/T4309 (authored by Viacheslav).
Sep 10 2023, 11:00 AM
vfreex committed rVYOSONEX95c6046e7a15: T5518: pim6: Fix smoketests.
Sep 10 2023, 7:47 AM
GitHub <noreply@github.com> committed rVYOSONEX25c36d678b90: Merge pull request #2233 from vfreex/fix-mld-smoketests (authored by c-po).
Sep 10 2023, 7:47 AM
Apachez added a comment to T5562: Smoketests fail for vyos:current (test_netns.py).

The failed smoketest test_interfaces_ethernet.py can be seen at:

Sep 10 2023, 6:14 AM · VyOS 1.5 Circinus
Apachez added a comment to T5562: Smoketests fail for vyos:current (test_netns.py).

The failed smoketest test_protocols_pim6.py seems to have been taken care of by:

Sep 10 2023, 6:13 AM · VyOS 1.5 Circinus
Apachez added a comment to T5562: Smoketests fail for vyos:current (test_netns.py).

Regarding the failing smoketest test_system_conntrack.py (test_conntrack_ignore):

Sep 10 2023, 6:12 AM · VyOS 1.5 Circinus
vfreex added a comment to T5518: Add MLD protocol support.

https://github.com/vyos/vyos-1x/pull/2233 to fix the smoketest.

Sep 10 2023, 5:37 AM · VyOS 1.4 Sagitta
vfreex added a comment to T5518: Add MLD protocol support.

Something is broken in smoketest test_protocols_pim6.py:

https://github.com/vyos/vyos-rolling-nightly-builds/actions/runs/6133954453/job/16646294279

See "Run smoketests" line 28676 and forward.

Sep 10 2023, 5:27 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5518: Add MLD protocol support.

Something is broken in smoketest test_protocols_pim6.py:

Sep 10 2023, 5:18 AM · VyOS 1.4 Sagitta

Sep 9 2023

alainlamar changed the status of T5567: vyos-1x: webproxy: maximum-object-size allowed ranges not in sync with Equuleus from Open to In progress.
Sep 9 2023, 5:46 PM · VyOS 1.4 Sagitta
alainlamar created T5567: vyos-1x: webproxy: maximum-object-size allowed ranges not in sync with Equuleus.
Sep 9 2023, 5:42 PM · VyOS 1.4 Sagitta
alainlamar closed T5540: vyos-1x: Wrong VHT configuration for WiFi 802.11ac as Resolved.
Sep 9 2023, 5:12 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5562: Smoketests fail for vyos:current (test_netns.py).

Still errors in:

Sep 9 2023, 5:05 PM · VyOS 1.5 Circinus
vfreex committed rVYOSONEX99ed6c9edd07: T5518: Add basic MLD support.
Sep 9 2023, 3:21 PM
GitHub <noreply@github.com> committed rVYOSONEX312370c9ef5c: Merge pull request #2179 from vfreex/add-mld (authored by c-po).
Sep 9 2023, 3:21 PM