Page MenuHomeVyOS Platform
Feed All Stories

Oct 31 2023

Viacheslav added a project to T5702: Add ability to set include_ifmib_iface_prefix and ifmib_max_num_ifaces for SNMP: VyOS 1.4 Sagitta.
Oct 31 2023, 4:01 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav created T5702: Add ability to set include_ifmib_iface_prefix and ifmib_max_num_ifaces for SNMP.
Oct 31 2023, 4:00 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav claimed T5701: Update telegraf package.

PR https://github.com/vyos/vyos-build/pull/448

Oct 31 2023, 2:08 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav created T5701: Update telegraf package.
Oct 31 2023, 10:37 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav created T5700: Monitoring telegraf deprecated plugins inputs outputs.
Oct 31 2023, 10:31 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav changed the status of T5695: Build FRR with LUA scripts --enable-scripting option from Open to Needs testing.
Oct 31 2023, 8:33 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po committed rVYOSONEXd46124c5073e: T5558: smoketest: fix nat definitions on dialup-router-medium-vpn #2.
Oct 31 2023, 7:14 AM
c-po closed T5668: Disable VXLAN bridge learning and enable neigh_suppress when using EVPN as Resolved.
Oct 31 2023, 6:37 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po moved T5668: Disable VXLAN bridge learning and enable neigh_suppress when using EVPN from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 31 2023, 6:37 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po closed T5699: vxlan: migrate "external" CLI know to "parameters external" as Resolved.
Oct 31 2023, 6:37 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po closed T5699: vxlan: migrate "external" CLI know to "parameters external", a subtask of T5671: vxlan: change port to IANA assigned default port, as Resolved.
Oct 31 2023, 6:37 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po moved T5699: vxlan: migrate "external" CLI know to "parameters external" from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 31 2023, 6:37 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po moved T5699: vxlan: migrate "external" CLI know to "parameters external" from Open to Finished on the VyOS 1.5 Circinus board.
Oct 31 2023, 6:37 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEX4766fc5aae39: Merge pull request #2419 from vyos/mergify/bp/sagitta/pr-2413 (authored by c-po).
Oct 31 2023, 6:32 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX2e85b7ccef45: vxlan: T5668: add CLI knob to enable ARP/ND suppression (authored by c-po).
Oct 31 2023, 6:01 AM
c-po committed rVYOSONEXec9a95502daa: vxlan: T5668: add CLI knob to enable ARP/ND suppression.
Oct 31 2023, 5:59 AM
GitHub <noreply@github.com> committed rVYOSONEX82a0067ca2d4: Merge pull request #2413 from c-po/t5668-vxlan (authored by c-po).
Oct 31 2023, 5:59 AM
GitHub <noreply@github.com> committed rVYOSONEXc937ef1b220b: Merge pull request #2418 from vyos/mergify/bp/sagitta/pr-2417 (authored by c-po).
Oct 31 2023, 5:57 AM

Oct 30 2023

Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX4fdecbf61b02: vxlan: T5699: migrate "external" CLI know to "parameters external" (authored by c-po).
Oct 30 2023, 5:53 PM
c-po committed rVYOSONEXcc7ba8824a5e: vxlan: T5699: migrate "external" CLI know to "parameters external".
Oct 30 2023, 5:52 PM
GitHub <noreply@github.com> committed rVYOSONEX18a0accde0cb: Merge pull request #2417 from c-po/vxlan-t5699 (authored by c-po).
Oct 30 2023, 5:52 PM
Viacheslav added a comment to T5695: Build FRR with LUA scripts --enable-scripting option.

PR https://github.com/vyos/vyos-build/pull/445

Oct 30 2023, 5:19 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po added a comment to T5699: vxlan: migrate "external" CLI know to "parameters external".

https://github.com/vyos/vyos-1x/pull/2417

Oct 30 2023, 3:33 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEX2d60bc124447: Merge pull request #2400 from vyos/mergify/bp/sagitta/pr-2355 (authored by Viacheslav).
Oct 30 2023, 3:27 PM
c-po claimed T5699: vxlan: migrate "external" CLI know to "parameters external".
Oct 30 2023, 3:09 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po created T5699: vxlan: migrate "external" CLI know to "parameters external".
Oct 30 2023, 3:09 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po added a comment to T5698: EVPN ESI Multihoming.

PR for 1.5 which will be backported to 1.4 https://github.com/vyos/vyos-1x/pull/2416

Oct 30 2023, 2:45 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX4cff02302537: T5681: Firewall,Nat and Nat66: simplified and standarize interface matcher… (authored by n.fort).
Oct 30 2023, 10:42 AM

Oct 29 2023

a-bali added a comment to T4902: snmpd: exclude container storage from monitoring.

I don't see this fix having been backported to Equuleus.

Oct 29 2023, 4:35 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T5619: Update the Intel ixgbe driver due to issues with Intel X533.

I'm building 1.4 rolling with the ixgbe out-of-tree driver if anyone cares.

Oct 29 2023, 3:00 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
aderouineau added a comment to T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.

Instead of "deny all" if no allow-clients are configured then localhost is always allowed. Can be handy when using containers and other if needed to sync to localhost for whatever reason (if the use of RTC isnt enough).

Oct 29 2023, 2:53 PM · VyOS Rolling
n.fort committed rVYOSONEX6248b2ae1a45: T5558: smoketest: fix nat definitions on dialup-router-medium-vpn..
Oct 29 2023, 2:30 PM
GitHub <noreply@github.com> committed rVYOSONEXd223ee5fc5c0: Merge pull request #2414 from nicolas-fort/T5558-fix-nat (authored by c-po).
Oct 29 2023, 2:30 PM
JeffWDH added a comment to T5661: Add show show ssh dynamic-protection attacker and show log ssh dynamic-protection.

This has been implemented in 1.5 and 1.4.

Oct 29 2023, 2:28 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.5)
shthead added a comment to T5698: EVPN ESI Multihoming.

@Apachez this request stems from this issue: https://forum.vyos.io/t/evpn-vxlan-esi-lag-duplicate-packets/12581

Oct 29 2023, 2:23 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort committed rVYOSONEXcd5316c26665: T5513: T5564: update op-mode command show firewall. Counter available for….
Oct 29 2023, 1:50 PM
GitHub <noreply@github.com> committed rVYOSONEX8c71f1360c6b: Merge pull request #2408 from nicolas-fort/T5513-show-fwall (authored by c-po).
Oct 29 2023, 1:50 PM
Apachez added a comment to T5698: EVPN ESI Multihoming.

Both single-active and all-active should be supported when it comes to EVPN Multihoming.

Oct 29 2023, 1:36 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po changed the status of T5698: EVPN ESI Multihoming from Open to In progress.
Oct 29 2023, 12:46 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po created T5698: EVPN ESI Multihoming.
Oct 29 2023, 12:46 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
happy42779 created T5697: event-handler keep failing.
Oct 29 2023, 11:15 AM · VyOS 1.4 Sagitta
JeffWDH committed rVYOSONEXe3f6196ffc90: T5661: Add show ssh dynamic-protection and show log ssh dynamic-protection.
Oct 29 2023, 8:57 AM
c-po committed rVYOSONEX963fd35e9f9e: op-mode: T5661: use common journalctl syntax for sshguard.
Oct 29 2023, 8:57 AM
c-po committed rVYOSONEXb34b1992a65e: op-mode: T5661: remove call to sudo in ssh.py and move it to XML definition.
Oct 29 2023, 8:57 AM
c-po committed rVYOSONEX57000d752c61: op-mode: T5661: add "monitor ssh dynamic-protection" command to follow the….
Oct 29 2023, 8:57 AM
GitHub <noreply@github.com> committed rVYOSONEX5974491d4b69: Merge pull request #2412 from JeffWDH/sagitta (authored by c-po).
Oct 29 2023, 8:57 AM
c-po committed rVYOSONEX78e00bf4099b: op-mode: T5661: add "monitor ssh dynamic-protection" command to follow the….
Oct 29 2023, 7:09 AM
c-po committed rVYOSONEX428dee29d36c: op-mode: T5661: remove call to sudo in ssh.py and move it to XML definition.
Oct 29 2023, 7:09 AM
c-po committed rVYOSONEXe1b4e972b409: op-mode: T5661: use common journalctl syntax for sshguard.
Oct 29 2023, 7:09 AM
Apachez created T5696: Make it possible to shutdown/suspend/disable VLAN 1.
Oct 29 2023, 5:54 AM · VyOS Rolling

Oct 28 2023

ishan added a comment to T5686: Loss of connectivity on dhcp enabled ethernet interfaces after abrupt link restarts.

I believe it's probably generating this error because modem sends an empty hostname.

Oct 28 2023, 7:51 PM · VyOS Rolling, Bugs
ishan added a comment to T5686: Loss of connectivity on dhcp enabled ethernet interfaces after abrupt link restarts.

Logs from just dhclient.

Oct 28 2023, 7:32 PM · VyOS Rolling, Bugs
ishan added a comment to T5686: Loss of connectivity on dhcp enabled ethernet interfaces after abrupt link restarts.

I didn't update it since the initial report and I don't really understand how/why it's working again.

Oct 28 2023, 7:31 PM · VyOS Rolling, Bugs
c-po moved T5668: Disable VXLAN bridge learning and enable neigh_suppress when using EVPN from Open to Finished on the VyOS 1.5 Circinus board.
Oct 28 2023, 7:27 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po added a project to T5668: Disable VXLAN bridge learning and enable neigh_suppress when using EVPN: VyOS 1.4 Sagitta.
Oct 28 2023, 7:27 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po added a comment to T5668: Disable VXLAN bridge learning and enable neigh_suppress when using EVPN.

PR for 1.5 current https://github.com/vyos/vyos-1x/pull/2413 which will then also be backported to 1.4

Oct 28 2023, 7:26 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
ishan added a comment to T5686: Loss of connectivity on dhcp enabled ethernet interfaces after abrupt link restarts.

I would still recommend you to try to test to put a L2-switch between your 5G-router and the VyOS box and see if that resolves the situation.

Oct 28 2023, 7:24 PM · VyOS Rolling, Bugs
JeffWDH added a comment to T5653: Command to display fingerprint.

This functionality has also been backported to 1.4 so it will be in the next LTS release.

Oct 28 2023, 1:49 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
JeffWDH committed rVYOSONEXced9ddc3fa63: T5653: Command to display SSH server fingerprint.
Oct 28 2023, 1:17 PM
GitHub <noreply@github.com> committed rVYOSONEX2c87e2440cab: Merge pull request #2410 from JeffWDH/sagitta (authored by Viacheslav).
Oct 28 2023, 1:17 PM
Viacheslav updated the task description for T5695: Build FRR with LUA scripts --enable-scripting option.
Oct 28 2023, 9:21 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav updated the task description for T5695: Build FRR with LUA scripts --enable-scripting option.
Oct 28 2023, 8:34 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav created T5695: Build FRR with LUA scripts --enable-scripting option.
Oct 28 2023, 8:16 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po changed the status of T5668: Disable VXLAN bridge learning and enable neigh_suppress when using EVPN from Open to In progress.
Oct 28 2023, 6:49 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.

Original template /usr/share/vyos/templates/chrony/chrony.conf.j2 (just the allow and listen sections):

Oct 28 2023, 3:51 AM · VyOS Rolling
aderouineau added a comment to T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.

What kind of cleanup are you talking about?

Oct 28 2023, 3:33 AM · VyOS Rolling
Apachez added a comment to T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.

Turns out that the output of bindaddress will be broken unless put in a loop even if a single entry the only allowed entry.

Oct 28 2023, 3:26 AM · VyOS Rolling
aderouineau added a comment to T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.

This task is regarding to add localhost by default as allowed source to speak to chronyd (the current NTP daemon in VyOS).

Oct 28 2023, 3:05 AM · VyOS Rolling
Apachez claimed T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.
Oct 28 2023, 3:04 AM · VyOS Rolling
Apachez added a comment to T5691: `show ntp` not working.

Since the root cause for this task have been identified and fixed by the reporting user (and the task is set to invalid) I have created another task for the spinoff regarding cleaning up of the template used by chronyd:

Oct 28 2023, 3:03 AM · VyOS 1.5 Circinus
Apachez created T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.
Oct 28 2023, 3:01 AM · VyOS Rolling
Apachez added a comment to T5691: `show ntp` not working.

As it seems according to https://manpages.debian.org/bookworm/chrony/chrony.conf.5.en.html both bindaddress and binddevice can only be specified once.

Oct 28 2023, 2:51 AM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

Ahh yes, I think there is another task in here regarding adding firewall rules by default to the firewall to avoid situations like this :-)

Oct 28 2023, 2:38 AM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

I added the above modifications to /usr/share/vyos/templates/chrony/chrony.conf.j2 and rebooted VyOS 1.5-rolling-202310240118.

Oct 28 2023, 2:36 AM · VyOS 1.5 Circinus
aderouineau closed T5691: `show ntp` not working as Invalid.
Oct 28 2023, 2:26 AM · VyOS 1.5 Circinus
aderouineau added a comment to T5691: `show ntp` not working.

I found the issue. I was missing a firewall input rule to allow anything from lo.

Oct 28 2023, 2:26 AM · VyOS 1.5 Circinus
syncer triaged T5595: Multicast - PIM bfd feature enable as Normal priority.
Oct 28 2023, 2:21 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
syncer changed the status of T5595: Multicast - PIM bfd feature enable from Open to In progress.
Oct 28 2023, 2:20 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
aderouineau added a comment to T5691: `show ntp` not working.

With my config chronyd still listens locally on 323:

udp        0      0 192.168.2.253:123       0.0.0.0:*                           20420/chronyd
udp        0      0 127.0.0.1:323           0.0.0.0:*                           20420/chronyd
udp6       0      0 ::1:323                 :::*                                20420/chronyd
Oct 28 2023, 2:13 AM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

I havent been using ninja2 scripting previously but Im guessing something like this would be needed:

Oct 28 2023, 2:01 AM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

Here is the output of sudo ls -la /run/chrony (just booted up so drift will probably missing for some time):

Oct 28 2023, 1:47 AM · VyOS 1.5 Circinus
Apachez added a comment to T5595: Multicast - PIM bfd feature enable .

Any docs or example on how bfd interacts with pim?

Oct 28 2023, 1:24 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Oct 27 2023

fernando added a comment to T5595: Multicast - PIM bfd feature enable .

PR : https://github.com/vyos/vyos-1x/pull/2411

Oct 27 2023, 11:54 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
rayzilt added a comment to T5018: Redirect to IFB removed after change in qos policy.

@Viacheslav yes, I already did last month, but there were lots of errors when veryfing the fix.
I figured it came due to the changes performed by task https://vyos.dev/T5048.

Oct 27 2023, 6:39 PM · VyOS 1.4 Sagitta
aderouineau added a comment to T5691: `show ntp` not working.

It is not, but I do not want to make my NTP internet-facing anyways.

Oct 27 2023, 6:02 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5691: `show ntp` not working.

Is your WAN interface also in net 192.168.0.0/16?

Oct 27 2023, 5:44 PM · VyOS 1.5 Circinus
aderouineau added a comment to T5691: `show ntp` not working.

Can you show the output of sudo ls -la /run/chrony?

Oct 27 2023, 5:40 PM · VyOS 1.5 Circinus
aderouineau added a comment to T5691: `show ntp` not working.

My VyOS NTP config:

set allow-client address '192.168.0.0/16'
set listen-address '192.168.2.253'
set server time.aws.com pool
set server time.google.com pool
Oct 27 2023, 5:39 PM · VyOS 1.5 Circinus
zsdc moved T5652: Config migrate to image upgrade does not properly generate home directory from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 27 2023, 5:18 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
zsdc closed T5652: Config migrate to image upgrade does not properly generate home directory, a subtask of T5663: pmacct package contains unwanted data, as Resolved.
Oct 27 2023, 5:18 PM · VyOS 1.5 Circinus
zsdc closed T5652: Config migrate to image upgrade does not properly generate home directory as Resolved.
Oct 27 2023, 5:18 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
zsdc closed T5663: pmacct package contains unwanted data as Resolved.
Oct 27 2023, 5:17 PM · VyOS 1.5 Circinus
Apachez added a comment to T5690: Change to definition of environment variable 'vyos_rootfs_dir' is incorrect.

PR created: https://github.com/vyos/vyatta-op/pull/79

Oct 27 2023, 4:09 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5693: Adding variable vyos_persistence_dir (and improve variable vyos_rootfs_dir).

PR created: https://github.com/vyos/vyatta-op/pull/79

Oct 27 2023, 4:07 PM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

How is your current ntp configuration (as outputed by show config commands)?

Oct 27 2023, 3:12 PM · VyOS 1.5 Circinus
Apachez added a comment to T5686: Loss of connectivity on dhcp enabled ethernet interfaces after abrupt link restarts.

I would still recommend you to try to test to put a L2-switch between your 5G-router and the VyOS box and see if that resolves the situation.

Oct 27 2023, 3:06 PM · VyOS Rolling, Bugs
Apachez claimed T5693: Adding variable vyos_persistence_dir (and improve variable vyos_rootfs_dir).
Oct 27 2023, 2:39 PM · VyOS 1.5 Circinus
Apachez created T5693: Adding variable vyos_persistence_dir (and improve variable vyos_rootfs_dir).
Oct 27 2023, 2:39 PM · VyOS 1.5 Circinus
Apachez added a comment to T5690: Change to definition of environment variable 'vyos_rootfs_dir' is incorrect.

One way however to make the variable more robust in case there are for whatever reason more than one squashfs mounted object available is to select the one who is "loop0".

Oct 27 2023, 2:30 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5690: Change to definition of environment variable 'vyos_rootfs_dir' is incorrect.

Looking through https://vyos.dev/T5457 I now get what you meant by "re-broke it".

Oct 27 2023, 2:23 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus