Page MenuHomeVyOS Platform
Feed All Stories

Oct 13 2023

JeffWDH added a comment to T5653: Command to display fingerprint.
$ show ssh fingerprints
SSH server public key fingerprints:
Oct 13 2023, 5:10 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5634: Remove support for Blowfish and DES from OpenVPN.

OpenVPN cannot pass the smoketest

 DEBUG - ======================================================================
DEBUG - FAIL: test_openvpn_options (__main__.TestInterfacesOpenVPN.test_openvpn_options)
DEBUG - ----------------------------------------------------------------------
DEBUG - Traceback (most recent call last):
DEBUG -   File "/usr/libexec/vyos/tests/smoke/cli/test_interfaces_openvpn.py", line 525, in test_openvpn_options
DEBUG -     self.assertNotEqual(cur_pid, new_pid)
DEBUG - AssertionError: None == None
DEBUG - 
DEBUG - ======================================================================
DEBUG - FAIL: test_openvpn_site2site_interfaces_tun (__main__.TestInterfacesOpenVPN.test_openvpn_site2site_interfaces_tun)
DEBUG - ----------------------------------------------------------------------
DEBUG - Traceback (most recent call last):
DEBUG -   File "/usr/libexec/vyos/tests/smoke/cli/test_interfaces_openvpn.py", line 601, in test_openvpn_site2site_interfaces_tun
DEBUG -     self.assertTrue(process_named_running(PROCESS_NAME))
DEBUG - AssertionError: None is not true
Oct 13 2023, 2:46 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5541: Zone-Based Firewalling in VyOS Sagitta 1.4 from Open to In progress.
Oct 13 2023, 2:10 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
JeffWDH added a comment to T5652: Config migrate to image upgrade does not properly generate home directory.

I had a similar issue going from 1.5-rolling-202309250022 to 1.5-rolling-202310090023.

Oct 13 2023, 12:10 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5254: Modification of any interface setting sets MTU back to default when MTU has been inherited from a bond from In progress to Needs testing.
Oct 13 2023, 9:09 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5654: Migrate policy local-route.
Oct 13 2023, 7:47 AM · Restricted Project, VyOS 1.5 Circinus
fsbof created T5653: Command to display fingerprint.
Oct 13 2023, 1:31 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fsbof updated fsbof.
Oct 13 2023, 1:09 AM

Oct 12 2023

jestabro moved T5649: vyos-1x should generate XML cache after building command templates for less cryptic error on typo from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 12 2023, 6:57 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro closed T5649: vyos-1x should generate XML cache after building command templates for less cryptic error on typo as Resolved.
Oct 12 2023, 6:56 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5651: chain FW_CONNTRACK incorrectly use accept as action.

Then this task can be set to closed and invalid :-)

Oct 12 2023, 6:54 PM · VyOS 1.5 Circinus
Apachez added a comment to T5498: fsck during boot doesnt work.

PR updated: https://github.com/vyos/vyos-build/pull/435

Oct 12 2023, 6:46 PM · Restricted Project, VyOS 1.5 Circinus
sarthurdev closed T5651: chain FW_CONNTRACK incorrectly use accept as action as Invalid.

If you don't use the firewall (statefully at least) then it will go through the FW_CONNTRACK chain and the NAT_CONNTRACK and/or WLB_CONNTRACK chains will be reached, or fall through to the notrack.

Oct 12 2023, 6:29 PM · VyOS 1.5 Circinus
Apachez reopened T5651: chain FW_CONNTRACK incorrectly use accept as action as "Open".

But the NAT_CONNTRACK and WLB_CONNTRACK chains are never evaluted because FW_CONNTRACK always set action to accept?

Oct 12 2023, 6:18 PM · VyOS 1.5 Circinus
gmurphy42 created T5652: Config migrate to image upgrade does not properly generate home directory.
Oct 12 2023, 5:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
zsdc changed the status of T5232: Flow-accounting uacctd.service cannot restart correctly from Open to In progress.

PR: https://github.com/vyos/vyos-1x/pull/2361

Oct 12 2023, 5:31 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
zsdc changed the status of T5233: Op-mode flow-accounting netflow with disable-imt errors from Open to In progress.

This should fix the problem: https://github.com/vyos/vyos-1x/pull/2361

Oct 12 2023, 5:30 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev closed T5651: chain FW_CONNTRACK incorrectly use accept as action as Invalid.

That is how the conntrack enabling system works. FW_CONNTRACK verdict is set to accept when it is determined the firewall needs conntracking (state rules, flowtable etc.), same for NAT_/WLB_ chains. If none require conntrack - all chains will be return and it falls down the chain to the final notrack and conntrack is not enabled.

Oct 12 2023, 5:29 PM · VyOS 1.5 Circinus
Apachez created T5651: chain FW_CONNTRACK incorrectly use accept as action.
Oct 12 2023, 5:05 PM · VyOS 1.5 Circinus
erkin added a subtask for T3356: Script for remote file transfers: T5650: Progressbars suffer from staircasing effect.
Oct 12 2023, 4:40 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin added a parent task for T5650: Progressbars suffer from staircasing effect: T3356: Script for remote file transfers.
Oct 12 2023, 4:40 PM · VyOS 1.4 Sagitta
erkin created T5650: Progressbars suffer from staircasing effect.
Oct 12 2023, 4:40 PM · VyOS 1.4 Sagitta
JeffWDH added a comment to T5647: Extend failover route functionality to use dynamically assigned interface next hops.

An additional "nice to have" would be a hook that runs on route state change.
Examples:

set protocols failover route 0.0.0.0/0 next-hop 100.100.100.1 hook '/config/scripts/failover-hook-100.100.100.1'
Oct 12 2023, 1:53 PM · VyOS 1.5 Circinus
jestabro added projects to T5649: vyos-1x should generate XML cache after building command templates for less cryptic error on typo: VyOS 1.5 Circinus, VyOS 1.4 Sagitta.
Oct 12 2023, 1:45 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro triaged T5649: vyos-1x should generate XML cache after building command templates for less cryptic error on typo as Normal priority.
Oct 12 2023, 1:37 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav updated the task description for T5647: Extend failover route functionality to use dynamically assigned interface next hops.
Oct 12 2023, 10:54 AM · VyOS 1.5 Circinus
Viacheslav removed a project from T1237: Static Route Path Monitoring, failover: VyOS 1.3 Equuleus (1.3.3).
Oct 12 2023, 6:31 AM · VyOS 1.4 Sagitta
Viacheslav moved T1237: Static Route Path Monitoring, failover from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 12 2023, 6:31 AM · VyOS 1.4 Sagitta
devon claimed T5648: ldpd neighbour template errors.

PR: https://github.com/vyos/vyos-1x/pull/2357

Oct 12 2023, 5:53 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
devon created T5648: ldpd neighbour template errors.
Oct 12 2023, 5:49 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro claimed T5644: Firewall groups deletion can break config.
Oct 12 2023, 1:30 AM · VyOS 1.5 Circinus

Oct 11 2023

Viacheslav awarded T5647: Extend failover route functionality to use dynamically assigned interface next hops a Like token.
Oct 11 2023, 6:12 PM · VyOS 1.5 Circinus
JeffWDH created T5647: Extend failover route functionality to use dynamically assigned interface next hops.
Oct 11 2023, 4:58 PM · VyOS 1.5 Circinus
Viacheslav created T5646: QoS policy limiter broken if class without match.
Oct 11 2023, 3:31 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
Viacheslav renamed T5645: Add template for PPPoE-server with custom RADIUS attributes for QoS policy and firewall from Add template for PPPoE server with custom RADIUS attributes for QoS policy and firewall to Add template for PPPoE-server with custom RADIUS attributes for QoS policy and firewall.
Oct 11 2023, 3:12 PM · VyOS 1.5 Circinus
Viacheslav created T5645: Add template for PPPoE-server with custom RADIUS attributes for QoS policy and firewall.
Oct 11 2023, 3:09 PM · VyOS 1.5 Circinus
jestabro changed the status of T2612: HTTPS API, changing API key fails but goes through from In progress to Backport candidate.
Oct 11 2023, 3:06 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort changed the status of T5644: Firewall groups deletion can break config from Open to Confirmed.
Oct 11 2023, 10:22 AM · VyOS 1.5 Circinus
n.fort created T5644: Firewall groups deletion can break config.
Oct 11 2023, 10:20 AM · VyOS 1.5 Circinus
a.apostoliuk changed the status of T5642: op cmd: generate tech-support archive: does not work from Open to In progress.
Oct 11 2023, 8:33 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav changed the status of T5165: Policy local-route ability set protocol and port from Open to Needs testing.
Oct 11 2023, 6:37 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 10 2023

jestabro moved T2612: HTTPS API, changing API key fails but goes through from Backlog to Backport Candidates on the VyOS 1.4 Sagitta board.
Oct 10 2023, 6:39 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro moved T2612: HTTPS API, changing API key fails but goes through from Need Triage to Finished on the VyOS 1.5 Circinus board.
Oct 10 2023, 6:39 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort changed the status of T5643: NAT - Allow interface groups on nat rules from Confirmed to In progress.
Oct 10 2023, 6:18 PM · VyOS 1.5 Circinus
n.fort added a comment to T5643: NAT - Allow interface groups on nat rules.

PR: https://github.com/vyos/vyos-1x/pull/2355

Oct 10 2023, 6:18 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5471: Conntrack logging doesnt seem to be working.

show conntrack statistics shows only sudo conntrack -S command
This won't show any logs

Oct 10 2023, 10:49 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a comment to T5497: Add ability to resequence rule numbers for firewall.

I assume this will end up in config mode aswell before this task can be set to resolved?

Simply because this is a few more steps:

  • Use the command
  • Copy the output
  • Delete current firewall
  • Paste command output
  • Commit

than this:

  • Use the command
  • Commit
Oct 10 2023, 10:41 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
n.fort changed the status of T5643: NAT - Allow interface groups on nat rules from Open to Confirmed.
Oct 10 2023, 10:40 AM · VyOS 1.5 Circinus
n.fort created T5643: NAT - Allow interface groups on nat rules.
Oct 10 2023, 10:40 AM · VyOS 1.5 Circinus
n.fort closed T5014: Destination NAT - Add Load Balancing capabilities as Resolved.
Oct 10 2023, 10:37 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

I assume this will end up in config mode aswell before this task can be set to resolved?

Oct 10 2023, 10:33 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
n.fort added a comment to T5564: Both show firewall group and show firewall summary fails.

Once PR https://github.com/vyos/vyos-1x/pull/2344 is merged, counters and logs for default action should be available once again.

Oct 10 2023, 10:08 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5497: Add ability to resequence rule numbers for firewall.

It's an op-mode command, so it does not changes configuration. User may get something different from what he expected, so at least on this very first attempt of re-generating and re-ordering firewall rules, it's done in op-mode command with no impact on running configuration.

Oct 10 2023, 10:00 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
SrividyaA created T5642: op cmd: generate tech-support archive: does not work.
Oct 10 2023, 7:35 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

The syntax seems to have changed from "produce" to "generate" during this task?

Oct 10 2023, 5:46 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez attached a referenced file: F3877170: T5549_Lynis_audit_system_231010.txt.gz.
Oct 10 2023, 5:40 AM · Invalid
Apachez added a comment to T5549: Result of system audit by Lynis.

Updated scan performed on VyOS 1.5-rolling-202310090023 (see attached file).

Oct 10 2023, 5:39 AM · Invalid
Apachez added a comment to T5471: Conntrack logging doesnt seem to be working.

show conntrack statistics still fails in VyOS 1.5-rolling-202310090023:

Oct 10 2023, 5:28 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Apachez closed T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled as Resolved.

Seems to be fixed in VyOS 1.5-rolling-202310090023:

Oct 10 2023, 5:25 AM · VyOS 1.4 Sagitta
Apachez assigned T5559: Selective proxy-arp/proxy-ndp when doing SNAT/DNAT to Viacheslav.
Oct 10 2023, 5:18 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5564: Both show firewall group and show firewall summary fails.

Problem remains with "N/D" is being used in show firewall groups instead of "None".

Oct 10 2023, 5:15 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez closed T5489: Change to BBR as TCP congestion control, or at least make it an config option as Resolved.

Verified in VyOS 1.5-rolling-202310090023:

Oct 10 2023, 5:03 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez closed T5436: vyos-preconfig-bootup.script is missing as Resolved.

Verified in VyOS 1.5-rolling-202310090023:

Oct 10 2023, 4:59 AM · VyOS 1.4 Sagitta
Apachez closed T5589: Nonstripped binaries exists in VyOS as Resolved.

Works as expected:

Oct 10 2023, 4:28 AM · VyOS 1.5 Circinus

Oct 9 2023

jestabro added a comment to T2612: HTTPS API, changing API key fails but goes through.

PR:
https://github.com/vyos/vyos-1x/pull/2352

Oct 9 2023, 4:39 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dmbaturin renamed T5634: Remove support for Blowfish and DES from OpenVPN from Remove support for Blowfish from OpenVPN to Remove support for Blowfish and DES from OpenVPN.
Oct 9 2023, 3:45 PM · VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T5619: Update the Intel ixgbe driver due to issues with Intel X533.
Oct 9 2023, 6:33 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T2612: HTTPS API, changing API key fails but goes through.

Final testing before PR, the following corrects behavior when configuring the http-api using the http-api, for example:

Oct 9 2023, 1:26 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5498: fsck during boot doesnt work.

PR created: https://github.com/vyos/vyos-build/pull/435

Oct 9 2023, 12:26 AM · Restricted Project, VyOS 1.5 Circinus

Oct 8 2023

Apachez added a comment to T5498: fsck during boot doesnt work.

As @twan mentioned previously...

Oct 8 2023, 11:59 PM · Restricted Project, VyOS 1.5 Circinus
Apachez created T5641: Enable compression of kernel modules.
Oct 8 2023, 10:37 PM · VyOS 1.5 Circinus
Apachez added a comment to T5498: fsck during boot doesnt work.

Turns out that packages/linux-kernel/arch/x86/configs/vyos_defconfig doesnt include xz as option for initrd:

Oct 8 2023, 10:26 PM · Restricted Project, VyOS 1.5 Circinus
Apachez created T5640: Missing compression algorithms in kernel config regarding initrd.
Oct 8 2023, 10:25 PM · Restricted Project, VyOS 1.5 Circinus
Apachez added a comment to T5498: fsck during boot doesnt work.

Will attempt to:

Oct 8 2023, 8:39 PM · Restricted Project, VyOS 1.5 Circinus
Apachez claimed T5498: fsck during boot doesnt work.
Oct 8 2023, 8:36 PM · Restricted Project, VyOS 1.5 Circinus
Apachez claimed T5489: Change to BBR as TCP congestion control, or at least make it an config option.
Oct 8 2023, 8:35 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dex added a comment to T5096: Change 'accept' firewall rule action from 'return' to 'accept'.

I see, looks like a way more streamlined approach. Thank you for the information and the quick response!

Oct 8 2023, 6:54 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5096: Change 'accept' firewall rule action from 'return' to 'accept'.

A new firewall frontend engine was implemented in VyOS 1.4-rolling-202308040557.

Oct 8 2023, 6:45 PM · VyOS 1.4 Sagitta
dex added a comment to T5096: Change 'accept' firewall rule action from 'return' to 'accept'.

Good to hear that this was implemented, thank you! Could you elaborate in which release this feature will be available?

Oct 8 2023, 6:40 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5635: Policy local-route ability with uid or gid.

I think it depends on nftables , https://wiki.nftables.org/wiki-nftables/index.php/Matching_packet_metainformation#Matching_by_socket_UID_.2F_GID , it is first handled by nftables and mark , then use rule .

Oct 8 2023, 6:07 PM · Restricted Project, VyOS 1.5 Circinus
Apachez reopened T5489: Change to BBR as TCP congestion control, or at least make it an config option as "Open".
Oct 8 2023, 5:59 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5489: Change to BBR as TCP congestion control, or at least make it an config option.

PR created: https://github.com/vyos/vyos-1x/pull/2349

Oct 8 2023, 5:43 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po closed T5630: pppoe: allow to specify MRU in addition to already configurable MTU as Resolved.
Oct 8 2023, 4:34 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T4269: node.def generator should automatically add default values.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/2348

Oct 8 2023, 8:34 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po moved T4269: node.def generator should automatically add default values from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 8 2023, 8:07 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po reopened T4269: node.def generator should automatically add default values as "Backport pending".
Oct 8 2023, 8:07 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po moved T5630: pppoe: allow to specify MRU in addition to already configurable MTU from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.5) board.
Oct 8 2023, 7:55 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T5630: pppoe: allow to specify MRU in addition to already configurable MTU.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/2347

Oct 8 2023, 7:54 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
freebsdjlu added a comment to T5635: Policy local-route ability with uid or gid.

I think it depends on nftables , https://wiki.nftables.org/wiki-nftables/index.php/Matching_packet_metainformation#Matching_by_socket_UID_.2F_GID , it is first handled by nftables and mark , then use rule .

Oct 8 2023, 7:51 AM · Restricted Project, VyOS 1.5 Circinus
c-po moved T5630: pppoe: allow to specify MRU in addition to already configurable MTU from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 8 2023, 7:03 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T5630: pppoe: allow to specify MRU in addition to already configurable MTU.

PR for 1.4 https://github.com/vyos/vyos-1x/pull/2346

Oct 8 2023, 7:03 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 7 2023

dmbaturin created T5639: Group vyos-1x dependencies by their VyOS components and specify their purpose.
Oct 7 2023, 5:05 PM · VyOS 1.4 Sagitta

Oct 6 2023

Apachez added a comment to T4502: Consider implementing (NAT/other) flow table offload.

The blog over at claims:

Oct 6 2023, 9:17 PM · VyOS 1.4 Sagitta
dmbaturin created T5638: Add support for requiring numeric values to be ranges rather than single numbers.
Oct 6 2023, 3:58 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5637: Firewall default-action log from Confirmed to In progress.
Oct 6 2023, 2:42 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5637: Firewall default-action log.

PR: https://github.com/vyos/vyos-1x/pull/2344

Oct 6 2023, 2:42 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T5637: Firewall default-action log from Open to Confirmed.
Oct 6 2023, 12:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort created T5637: Firewall default-action log.
Oct 6 2023, 12:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort closed T5096: Change 'accept' firewall rule action from 'return' to 'accept' as Resolved.

Closing this one, because it's already implemented

Oct 6 2023, 11:59 AM · VyOS 1.4 Sagitta
erkin closed T3506: Migrate loadkey command to op-mode, a subtask of T3356: Script for remote file transfers, as Resolved.
Oct 6 2023, 11:34 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta