Page MenuHomeVyOS Platform
Feed All Stories

Oct 10 2023

n.fort added a comment to T5643: NAT - Allow interface groups on nat rules.

PR: https://github.com/vyos/vyos-1x/pull/2355

Oct 10 2023, 6:18 PM · VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX9c7a4b43278e: http-api: T2612: reload server within configsession for api self-config (authored by jestabro).
Oct 10 2023, 6:12 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX09adc91eda58: http-api: T2612: send response before reconfiguring api server (authored by jestabro).
Oct 10 2023, 6:12 PM
jestabro committed rVYOSONEX93d2ea7d635c: http-api: T2612: reload server within configsession for api self-config.
Oct 10 2023, 6:11 PM
jestabro committed rVYOSONEX7d597a6dca15: http-api: T2612: send response before reconfiguring api server.
Oct 10 2023, 6:11 PM
GitHub <noreply@github.com> committed rVYOSONEXf48727eee9cb: Merge pull request #2352 from jestabro/api-self-config (authored by dmbaturin).
Oct 10 2023, 6:11 PM
Viacheslav added a comment to T5471: Conntrack logging doesnt seem to be working.

show conntrack statistics shows only sudo conntrack -S command
This won't show any logs

Oct 10 2023, 10:49 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.2), VyOS Rolling
Viacheslav added a comment to T5497: Add ability to resequence rule numbers for firewall.

I assume this will end up in config mode aswell before this task can be set to resolved?

Simply because this is a few more steps:

  • Use the command
  • Copy the output
  • Delete current firewall
  • Paste command output
  • Commit

than this:

  • Use the command
  • Commit
Oct 10 2023, 10:41 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
n.fort changed the status of T5643: NAT - Allow interface groups on nat rules from Open to Confirmed.
Oct 10 2023, 10:40 AM · VyOS 1.5 Circinus
n.fort created T5643: NAT - Allow interface groups on nat rules.
Oct 10 2023, 10:40 AM · VyOS 1.5 Circinus
n.fort closed T5014: Destination NAT - Add Load Balancing capabilities as Resolved.
Oct 10 2023, 10:37 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

I assume this will end up in config mode aswell before this task can be set to resolved?

Oct 10 2023, 10:33 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
n.fort added a comment to T5564: Both show firewall group and show firewall summary fails.

Once PR https://github.com/vyos/vyos-1x/pull/2344 is merged, counters and logs for default action should be available once again.

Oct 10 2023, 10:08 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5497: Add ability to resequence rule numbers for firewall.

It's an op-mode command, so it does not changes configuration. User may get something different from what he expected, so at least on this very first attempt of re-generating and re-ordering firewall rules, it's done in op-mode command with no impact on running configuration.

Oct 10 2023, 10:00 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
SrividyaA created T5642: op cmd: generate tech-support archive: does not work.
Oct 10 2023, 7:35 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

The syntax seems to have changed from "produce" to "generate" during this task?

Oct 10 2023, 5:46 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez attached a referenced file: F3877170: T5549_Lynis_audit_system_231010.txt.gz.
Oct 10 2023, 5:40 AM · Invalid
Apachez added a comment to T5549: Result of system audit by Lynis.

Updated scan performed on VyOS 1.5-rolling-202310090023 (see attached file).

Oct 10 2023, 5:39 AM · Invalid
Apachez added a comment to T5471: Conntrack logging doesnt seem to be working.

show conntrack statistics still fails in VyOS 1.5-rolling-202310090023:

Oct 10 2023, 5:28 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.2), VyOS Rolling
Apachez closed T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled as Resolved.

Seems to be fixed in VyOS 1.5-rolling-202310090023:

Oct 10 2023, 5:25 AM · VyOS 1.4 Sagitta
Apachez assigned T5559: Selective proxy-arp/proxy-ndp when doing SNAT/DNAT to Viacheslav.
Oct 10 2023, 5:18 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5564: Both show firewall group and show firewall summary fails.

Problem remains with "N/D" is being used in show firewall groups instead of "None".

Oct 10 2023, 5:15 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez closed T5489: Change to BBR as TCP congestion control, or at least make it an config option as Resolved.

Verified in VyOS 1.5-rolling-202310090023:

Oct 10 2023, 5:03 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez closed T5436: vyos-preconfig-bootup.script is missing as Resolved.

Verified in VyOS 1.5-rolling-202310090023:

Oct 10 2023, 4:59 AM · VyOS 1.4 Sagitta
Apachez closed T5589: Nonstripped binaries exists in VyOS as Resolved.

Works as expected:

Oct 10 2023, 4:28 AM · VyOS 1.5 Circinus
jestabro committed rVYOSONEX9ceba9ede21f: conf-mode: T5412: remove refs to vyos module for use by addon packages.
Oct 10 2023, 2:11 AM

Oct 9 2023

jestabro added a comment to T2612: HTTPS API, changing API key fails but goes through.

PR:
https://github.com/vyos/vyos-1x/pull/2352

Oct 9 2023, 4:39 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dmbaturin renamed T5634: Remove support for Blowfish and DES from OpenVPN from Remove support for Blowfish from OpenVPN to Remove support for Blowfish and DES from OpenVPN.
Oct 9 2023, 3:45 PM · VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T5619: Update the Intel ixgbe driver due to issues with Intel X533.
Oct 9 2023, 6:33 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T2612: HTTPS API, changing API key fails but goes through.

Final testing before PR, the following corrects behavior when configuring the http-api using the http-api, for example:

Oct 9 2023, 1:26 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5498: fsck during boot doesnt work.

PR created: https://github.com/vyos/vyos-build/pull/435

Oct 9 2023, 12:26 AM · VyOS Rolling, Bugs

Oct 8 2023

Apachez added a comment to T5498: fsck during boot doesnt work.

As @twan mentioned previously...

Oct 8 2023, 11:59 PM · VyOS Rolling, Bugs
Apachez created T5641: Enable compression of kernel modules.
Oct 8 2023, 10:37 PM
Apachez added a comment to T5498: fsck during boot doesnt work.

Turns out that packages/linux-kernel/arch/x86/configs/vyos_defconfig doesnt include xz as option for initrd:

Oct 8 2023, 10:26 PM · VyOS Rolling, Bugs
Apachez created T5640: Missing compression algorithms in kernel config regarding initrd.
Oct 8 2023, 10:25 PM · VyOS Rolling
Apachez added a comment to T5498: fsck during boot doesnt work.

Will attempt to:

Oct 8 2023, 8:39 PM · VyOS Rolling, Bugs
Apachez claimed T5498: fsck during boot doesnt work.
Oct 8 2023, 8:36 PM · VyOS Rolling, Bugs
Apachez claimed T5489: Change to BBR as TCP congestion control, or at least make it an config option.
Oct 8 2023, 8:35 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dex added a comment to T5096: Change 'accept' firewall rule action from 'return' to 'accept'.

I see, looks like a way more streamlined approach. Thank you for the information and the quick response!

Oct 8 2023, 6:54 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5096: Change 'accept' firewall rule action from 'return' to 'accept'.

A new firewall frontend engine was implemented in VyOS 1.4-rolling-202308040557.

Oct 8 2023, 6:45 PM · VyOS 1.4 Sagitta
dex added a comment to T5096: Change 'accept' firewall rule action from 'return' to 'accept'.

Good to hear that this was implemented, thank you! Could you elaborate in which release this feature will be available?

Oct 8 2023, 6:40 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5635: Policy local-route ability with uid or gid.

I think it depends on nftables , https://wiki.nftables.org/wiki-nftables/index.php/Matching_packet_metainformation#Matching_by_socket_UID_.2F_GID , it is first handled by nftables and mark , then use rule .

Oct 8 2023, 6:07 PM · Restricted Project, VyOS Rolling
Apachez reopened T5489: Change to BBR as TCP congestion control, or at least make it an config option as "Open".
Oct 8 2023, 5:59 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXf7ecf80824cc: Change to BBR as TCP congestion control, or at least make it an config option (authored by Apachez).
Oct 8 2023, 5:56 PM
Apachez committed rVYOSONEXac1bd7c2f69e: Change to BBR as TCP congestion control, or at least make it an config option.
Oct 8 2023, 5:55 PM
GitHub <noreply@github.com> committed rVYOSONEX1280734bc53b: Merge pull request #2349 from Apachez-/T5489 (authored by c-po).
Oct 8 2023, 5:55 PM
Apachez added a comment to T5489: Change to BBR as TCP congestion control, or at least make it an config option.

PR created: https://github.com/vyos/vyos-1x/pull/2349

Oct 8 2023, 5:43 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Cheeze_It committed rVYOSONEX7a2b70bd73c8: T5530: isis: Adding loop free alternate feature.
Oct 8 2023, 5:15 PM
GitHub <noreply@github.com> committed rVYOSONEX8da99e575caa: Merge pull request #2263 from Cheeze-It/current (authored by Viacheslav).
Oct 8 2023, 5:15 PM
c-po closed T5630: pppoe: allow to specify MRU in addition to already configurable MTU as Resolved.
Oct 8 2023, 4:34 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX32dc990e1eed: T5213: Add accounting-interim-interval option for PPPoE-server.
Oct 8 2023, 4:16 PM
GitHub <noreply@github.com> committed rVYOSONEXe6118a08081f: Merge pull request #2333 from sever-sever/T5213-eq (authored by dmbaturin).
Oct 8 2023, 4:16 PM
c-po committed rVYOSONEX88c1fd3a3592: pppoe: T5630: allow to specify MRU in addition to already configurable MTU.
Oct 8 2023, 4:14 PM
c-po committed rVYOSONEXab2aeec41a2e: pppoe: T5630: verify MRU is less or equal then MTU.
Oct 8 2023, 4:14 PM
GitHub <noreply@github.com> committed rVYOSONEX07758d372bbc: Merge pull request #2347 from c-po/equuleus (authored by dmbaturin).
Oct 8 2023, 4:14 PM
dmbaturin committed rVYOSONEX4912aca0e402: debian: T5639: group dependencies and add comments.
Oct 8 2023, 3:51 PM
GitHub <noreply@github.com> committed rVYOSONEXfd4096a42419: Merge pull request #2345 from dmbaturin/T5639-group-deps (authored by c-po).
Oct 8 2023, 3:51 PM
c-po added a comment to T4269: node.def generator should automatically add default values.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/2348

Oct 8 2023, 8:34 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po moved T4269: node.def generator should automatically add default values from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 8 2023, 8:07 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po changed the status of T4269: node.def generator should automatically add default values from Resolved to Unknown Status.
Oct 8 2023, 8:07 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po moved T5630: pppoe: allow to specify MRU in addition to already configurable MTU from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.5) board.
Oct 8 2023, 7:55 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T5630: pppoe: allow to specify MRU in addition to already configurable MTU.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/2347

Oct 8 2023, 7:54 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
freebsdjlu added a comment to T5635: Policy local-route ability with uid or gid.

I think it depends on nftables , https://wiki.nftables.org/wiki-nftables/index.php/Matching_packet_metainformation#Matching_by_socket_UID_.2F_GID , it is first handled by nftables and mark , then use rule .

Oct 8 2023, 7:51 AM · Restricted Project, VyOS Rolling
c-po moved T5630: pppoe: allow to specify MRU in addition to already configurable MTU from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 8 2023, 7:03 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T5630: pppoe: allow to specify MRU in addition to already configurable MTU.

PR for 1.4 https://github.com/vyos/vyos-1x/pull/2346

Oct 8 2023, 7:03 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 7 2023

GitHub <noreply@github.com> committed rVYOSONEX7720ee247c03: Merge pull request #2346 from vyos/mergify/bp/sagitta/pr-2335 (authored by c-po).
Oct 7 2023, 5:50 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX713647429b98: pppoe: T5630: verify MRU is less or equal then MTU (authored by c-po).
Oct 7 2023, 5:15 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXe4fabffe7408: pppoe: T5630: allow to specify MRU in addition to already configurable MTU (authored by c-po).
Oct 7 2023, 5:15 PM
c-po committed rVYOSONEXe062a8c11856: pppoe: T5630: allow to specify MRU in addition to already configurable MTU.
Oct 7 2023, 5:13 PM
c-po committed rVYOSONEXe357258e645c: pppoe: T5630: verify MRU is less or equal then MTU.
Oct 7 2023, 5:13 PM
GitHub <noreply@github.com> committed rVYOSONEX0d975350d0a9: Merge pull request #2335 from c-po/t5630-pppoe-mru (authored by dmbaturin).
Oct 7 2023, 5:13 PM
dmbaturin created T5639: Group vyos-1x dependencies by their VyOS components and specify their purpose.
Oct 7 2023, 5:05 PM · VyOS 1.4 Sagitta

Oct 6 2023

Apachez added a comment to T4502: Consider implementing (NAT/other) flow table offload.

The blog over at claims:

Oct 6 2023, 9:17 PM · VyOS 1.4 Sagitta
dmbaturin created T5638: Add support for requiring numeric values to be ranges rather than single numbers.
Oct 6 2023, 3:58 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5637: Firewall default-action log from Confirmed to In progress.
Oct 6 2023, 2:42 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5637: Firewall default-action log.

PR: https://github.com/vyos/vyos-1x/pull/2344

Oct 6 2023, 2:42 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
erkin committed rVYOSONEX58b186c6fa2c: op-mode: T5608: Fix help message for `delete raid`.
Oct 6 2023, 12:16 PM
GitHub <noreply@github.com> committed rVYOSONEXf1eac571f22a: Merge pull request #2343 from erkin/raid (authored by dmbaturin).
Oct 6 2023, 12:16 PM
n.fort changed the status of T5637: Firewall default-action log from Open to Confirmed.
Oct 6 2023, 12:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort created T5637: Firewall default-action log.
Oct 6 2023, 12:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort closed T5096: Change 'accept' firewall rule action from 'return' to 'accept' as Resolved.

Closing this one, because it's already implemented

Oct 6 2023, 11:59 AM · VyOS 1.4 Sagitta
erkin closed T3506: Migrate loadkey command to op-mode, a subtask of T3356: Script for remote file transfers, as Resolved.
Oct 6 2023, 11:34 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3506: Migrate loadkey command to op-mode, a subtask of T3355: Remove all remaining legacy Vyatta code, as Resolved.
Oct 6 2023, 11:34 AM · VyOS Rolling
erkin closed T3506: Migrate loadkey command to op-mode as Resolved.
Oct 6 2023, 11:34 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5165: Policy local-route ability set protocol and port.

PR https://github.com/vyos/vyos-1x/pull/2342

set policy local-route rule 23 destination port '222'
set policy local-route rule 23 protocol 'tcp'
set policy local-route rule 23 set table '123'
set policy local-route rule 23 source port '8888'

Check:

vyos@r4# ip rule show prio 23
23:	from all ipproto tcp sport 8888 dport 222 lookup 123
[edit]
vyos@r4#
Oct 6 2023, 9:27 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T5635: Policy local-route ability with uid or gid.

It supports uidrange https://man7.org/linux/man-pages/man8/ip-rule.8.html
is it what you want?

uidrange NUMBER-NUMBER
       select the uid value to match.

I don't see gid option there.

Oct 6 2023, 5:39 AM · Restricted Project, VyOS Rolling
Viacheslav added a comment to T5635: Policy local-route ability with uid or gid.
Oct 6 2023, 5:36 AM · Restricted Project, VyOS Rolling
Viacheslav closed T5576: Add bgp remove-private-as all option as Resolved.
Oct 6 2023, 5:23 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav claimed T5165: Policy local-route ability set protocol and port.
Oct 6 2023, 4:31 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro changed the status of T2612: HTTPS API, changing API key fails but goes through from Open to In progress.
Oct 6 2023, 4:25 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
swanduron added a comment to T5376: Conntrack FTP helper does not work properly.

Hello @sdev , could you please help to check if the fix can resolve the problem with FTP ALG? I tested the newest rolling release but the PASV command still causes the data connection gets failed. My testing FTP server and client are both Filezilla product, please correct me if any mistakes I made during the test.

Oct 6 2023, 4:24 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
freebsdjlu created T5636: Add GeoIP matching support for policy route.
Oct 6 2023, 1:24 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
freebsdjlu created T5635: Policy local-route ability with uid or gid.
Oct 6 2023, 1:13 AM · Restricted Project, VyOS Rolling

Oct 5 2023

jestabro added a comment to T2612: HTTPS API, changing API key fails but goes through.

Yes, I will add that as a first step ...

Oct 5 2023, 5:42 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro closed T5631: Ability to export the current configuration in JSON format as Unknown Status.

Added for 1.4, 1.5; as mentioned above, a backport to Equuleus will require a different implementation.

Oct 5 2023, 5:41 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
GitHub <noreply@github.com> committed rVYOSONEX669acb05c91a: Merge pull request #2341 from vyos/mergify/bp/sagitta/pr-2339 (authored by jestabro).
Oct 5 2023, 5:39 PM
jestabro moved T5631: Ability to export the current configuration in JSON format from Open to Finished on the VyOS 1.5 Circinus board.
Oct 5 2023, 5:35 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX0b832eca6d2d: config: T5631: save copy of config in JSON format on commit (authored by jestabro).
Oct 5 2023, 5:35 PM
jestabro moved T4320: Remove legacy version files in vyatta-cfg-system/cfg-version from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 5 2023, 5:32 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro closed T4320: Remove legacy version files in vyatta-cfg-system/cfg-version, a subtask of T3355: Remove all remaining legacy Vyatta code, as Resolved.
Oct 5 2023, 5:31 PM · VyOS Rolling