Page MenuHomeVyOS Platform
Feed All Stories

Nov 22 2023

n.fort closed T5590: Firewall "log enable" logs every packet as Resolved.
Nov 22 2023, 7:18 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort closed T5616: Firewall mark - Add capabilities for matching firewall mark as Resolved.
Nov 22 2023, 7:16 PM · VyOS 1.5 Circinus
n.fort closed T5643: NAT - Allow interface groups on nat rules as Resolved.
Nov 22 2023, 7:15 PM · VyOS 1.5 Circinus
n.fort closed T5681: Interface match - Simplified and unified cli as Resolved.
Nov 22 2023, 7:14 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort closed T5729: Firewall, nat and policy route - Switch to valueless as Resolved.
Nov 22 2023, 7:11 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T5637: Firewall default-action log from Confirmed to Needs testing.
Nov 22 2023, 7:07 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav assigned T5774: commit-archive to FTP server broken after update (VyOS 1.5-rolling) to erkin.
Nov 22 2023, 5:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav triaged T5774: commit-archive to FTP server broken after update (VyOS 1.5-rolling) as Normal priority.
Nov 22 2023, 4:56 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
I-n-d-y raised the priority of T5774: commit-archive to FTP server broken after update (VyOS 1.5-rolling) from Low to Requires assessment.
Nov 22 2023, 4:54 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
I-n-d-y created T5774: commit-archive to FTP server broken after update (VyOS 1.5-rolling).
Nov 22 2023, 4:52 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a project to T5773: Unable to load config via HTTP: VyOS 1.5 Circinus.
Nov 22 2023, 4:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav updated the task description for T5773: Unable to load config via HTTP.
Nov 22 2023, 4:51 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
erkin claimed T5773: Unable to load config via HTTP.
Nov 22 2023, 4:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav triaged T5773: Unable to load config via HTTP as Urgent! priority.
Nov 22 2023, 4:38 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5773: Unable to load config via HTTP.
Nov 22 2023, 4:38 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
JeffWDH added a project to T5771: GeoIP - Include RFC reserved IP ranges in inverse-match rules: VyOS 1.5 Circinus.
Nov 22 2023, 2:10 PM · Restricted Project, VyOS 1.5 Circinus
c-po added a comment to T5630: pppoe: allow to specify MRU in addition to already configurable MTU.

A fix that changes the behavior back to it was https://github.com/vyos/vyos-1x/pull/2527

Nov 22 2023, 12:22 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort added a comment to T5637: Firewall default-action log.

PR for bridge: https://github.com/vyos/vyos-1x/pull/2528

Nov 22 2023, 12:08 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.apostoliuk changed the status of T5413: Deny the opportunity to use one public/private key pair on both wireguard peers. from Needs testing to In progress.
Nov 22 2023, 11:36 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
a.apostoliuk added a project to T5413: Deny the opportunity to use one public/private key pair on both wireguard peers.: VyOS 1.3 Equuleus (1.3.5).
Nov 22 2023, 11:35 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5413: Deny the opportunity to use one public/private key pair on both wireguard peers. from In progress to Needs testing.
Nov 22 2023, 11:14 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
a.apostoliuk closed T4877: Need verification in using import vrf and import vpn, export vpn commands as Resolved.
Nov 22 2023, 11:11 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5578: "ikev2-reauth" description contains outdated information as Resolved.
Nov 22 2023, 10:51 AM · VyOS 1.3 Equuleus (1.3.5)
a.apostoliuk closed T5426: Add exceptions in vici functions calls as Resolved.
Nov 22 2023, 10:50 AM · VyOS 1.4 Sagitta
a.apostoliuk moved T5338: Add 'mpls bgp forwarding' feature from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Nov 22 2023, 10:48 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5338: Add 'mpls bgp forwarding' feature, a subtask of T5337: MPLS/BGP: Route leak does not happen from the VPNv4 table to specific vrf, as Resolved.
Nov 22 2023, 10:48 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5338: Add 'mpls bgp forwarding' feature as Resolved.
Nov 22 2023, 10:48 AM · VyOS 1.4 Sagitta
a.apostoliuk placed T5201: Add Split Tunneling for L2TP/PPTP/SSTP VPN Clients up for grabs.
Nov 22 2023, 10:43 AM · VyOS 1.5 Circinus
Viacheslav closed T5767: Add reboot and poweroff the system via API as Resolved.

Works fine

$ curl -k --location --request POST 'https://192.168.122.11/reboot'   --form data='{"op": "reboot", "path": ["now"]}'   --form key='foo'
{"success": true, "data": "Warning: there are unsaved configuration changes!\nRun 'save' command if you do not want to lose those changes after reboot/shutdown.\n\n", "error": null}
Nov 22 2023, 9:31 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.hajiyev closed T4021: Long commit time on bridge interface with 1-4094 allowed VLAN tags as Resolved.
Nov 22 2023, 7:42 AM · VyOS 1.4 Sagitta
a.hajiyev added a comment to T4021: Long commit time on bridge interface with 1-4094 allowed VLAN tags.

Tested on VyOS 1.4-rolling-202311100309:

Nov 22 2023, 7:41 AM · VyOS 1.4 Sagitta
a.hajiyev closed T3818: BGP export route-map only works after bgpd restart as Resolved.
Nov 22 2023, 7:20 AM · VyOS 1.4 Sagitta
a.hajiyev added a comment to T3818: BGP export route-map only works after bgpd restart.

Tested in VyOS 1.4-rolling-202311100309:
The configuration:

Nov 22 2023, 7:19 AM · VyOS 1.4 Sagitta
a.hajiyev removed a project from T2845: BGP conf_mode unable to delete configuration with peer-group: VyOS 1.4 Sagitta.
Nov 22 2023, 6:15 AM · VyOS 1.4 Sagitta
a.hajiyev added a comment to T2845: BGP conf_mode unable to delete configuration with peer-group.

Tested in VyOS 1.4-rolling-202311100309
The configuration:
VyOS:

Nov 22 2023, 4:47 AM · VyOS 1.4 Sagitta
dmbaturin created T5772: Require HTTPS API server configurations to include at least one key if key-based auth is used.
Nov 22 2023, 12:26 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav added a comment to T5767: Add reboot and poweroff the system via API.

@a.apostoliuk will be available in the next rolling release.

Nov 22 2023, 12:14 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav changed the status of T5767: Add reboot and poweroff the system via API from In progress to Needs testing.
Nov 22 2023, 12:14 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Nov 21 2023

Viacheslav updated the task description for T5765: Add OpenConfig gNMI gRPC integration.
Nov 21 2023, 11:57 PM · VyOS 1.5 Circinus
dotAndy added a comment to T5761: Allow PPPoE interface to be assigned IPv6 address via DHCPv6.

I had the below set on the pppoe interface to allow for DHCPv6-PD. That part was working fine it was just the pppoe interface that wasn't picking up an address:

Nov 21 2023, 10:44 PM · VyOS 1.5 Circinus
c-po added a project to T5769: VTI tunnels lose their v6 Link Local addresses when set down/up: VyOS 1.4 Sagitta.
Nov 21 2023, 9:17 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po changed the status of T5769: VTI tunnels lose their v6 Link Local addresses when set down/up from Open to In progress.
Nov 21 2023, 9:17 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po added a comment to T5769: VTI tunnels lose their v6 Link Local addresses when set down/up.

This is related to Kernel addr_gen_mode beeing globally disabled. It's actually on my "to refactor list" and with this bug it gainer priority!

Nov 21 2023, 9:16 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a project to T5767: Add reboot and poweroff the system via API: VyOS 1.4 Sagitta.
Nov 21 2023, 8:23 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
JeffWDH added a comment to T5771: GeoIP - Include RFC reserved IP ranges in inverse-match rules.

Although, now that I look at the contents of the 'zz' country code, I wonder if there are unintended consequences to specifying some of these... Such as the multicast ones, etc.

Nov 21 2023, 7:56 PM · Restricted Project, VyOS 1.5 Circinus
c-po updated the task description for T5762: http: api: smoketests fail as they can not establish IPv6 connection to uvicorn backend server.
Nov 21 2023, 7:48 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
JeffWDH updated the task description for T5771: GeoIP - Include RFC reserved IP ranges in inverse-match rules.
Nov 21 2023, 7:39 PM · Restricted Project, VyOS 1.5 Circinus
JeffWDH updated the task description for T5771: GeoIP - Include RFC reserved IP ranges in inverse-match rules.
Nov 21 2023, 7:37 PM · Restricted Project, VyOS 1.5 Circinus
JeffWDH created T5771: GeoIP - Include RFC reserved IP ranges in inverse-match rules.
Nov 21 2023, 7:35 PM · Restricted Project, VyOS 1.5 Circinus
giga1699 claimed T5770: MACsec not encrypting.

PR2518 submitted

Nov 21 2023, 7:01 PM · VyOS 1.5 Circinus
giga1699 created T5770: MACsec not encrypting.
Nov 21 2023, 6:53 PM · VyOS 1.5 Circinus
c-po claimed T5769: VTI tunnels lose their v6 Link Local addresses when set down/up.
Nov 21 2023, 6:29 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
gmurphy42 created T5769: VTI tunnels lose their v6 Link Local addresses when set down/up.
Nov 21 2023, 6:05 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T4072: Feature Request: Firewall on bridge interfaces from In progress to Needs testing.
Nov 21 2023, 5:46 PM · VyOS 1.4 Sagitta
jestabro changed Is it a breaking change? from compatible to validation on T5768: Remove auxiliary http-api.conf for simplification of http-api config mode script.
Nov 21 2023, 4:47 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro added a subtask for T5768: Remove auxiliary http-api.conf for simplification of http-api config mode script: T5766: http: rewrite conf-mode script to get_config_dict() .
Nov 21 2023, 4:45 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro added a parent task for T5766: http: rewrite conf-mode script to get_config_dict() : T5768: Remove auxiliary http-api.conf for simplification of http-api config mode script.
Nov 21 2023, 4:45 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a subtask for T5762: http: api: smoketests fail as they can not establish IPv6 connection to uvicorn backend server: T5768: Remove auxiliary http-api.conf for simplification of http-api config mode script.
Nov 21 2023, 4:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a parent task for T5768: Remove auxiliary http-api.conf for simplification of http-api config mode script: T5762: http: api: smoketests fail as they can not establish IPv6 connection to uvicorn backend server.
Nov 21 2023, 4:44 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro triaged T5768: Remove auxiliary http-api.conf for simplification of http-api config mode script as Normal priority.
Nov 21 2023, 4:44 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav placed T5167: Add a simple file server up for grabs.
Nov 21 2023, 2:35 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5767: Add reboot and poweroff the system via API.

PR https://github.com/vyos/vyos-1x/pull/2516

Nov 21 2023, 10:47 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav changed the status of T5767: Add reboot and poweroff the system via API from Open to In progress.
Nov 21 2023, 10:14 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.apostoliuk created T5767: Add reboot and poweroff the system via API.
Nov 21 2023, 8:46 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po updated the task description for T5766: http: rewrite conf-mode script to get_config_dict() .
Nov 21 2023, 8:04 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po claimed T5766: http: rewrite conf-mode script to get_config_dict() .
Nov 21 2023, 7:56 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po created T5766: http: rewrite conf-mode script to get_config_dict() .
Nov 21 2023, 7:56 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5760: DHCP client custom dhcp-options from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Nov 21 2023, 7:27 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po moved T5760: DHCP client custom dhcp-options from Need Triage to Finished on the VyOS 1.5 Circinus board.
Nov 21 2023, 7:27 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po added a comment to T5760: DHCP client custom dhcp-options.

I need to requst subnet-mask, routers, rfc3442-classless-static-routes

Nov 21 2023, 7:26 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po closed T5762: http: api: smoketests fail as they can not establish IPv6 connection to uvicorn backend server as Resolved.
Nov 21 2023, 7:25 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5762: http: api: smoketests fail as they can not establish IPv6 connection to uvicorn backend server from Need Triage to Finished on the VyOS 1.5 Circinus board.
Nov 21 2023, 7:25 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5762: http: api: smoketests fail as they can not establish IPv6 connection to uvicorn backend server from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Nov 21 2023, 7:25 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav updated the task description for T5765: Add OpenConfig gNMI gRPC integration.
Nov 21 2023, 2:26 AM · VyOS 1.5 Circinus

Nov 20 2023

Viacheslav created T5765: Add OpenConfig gNMI gRPC integration.
Nov 20 2023, 9:13 PM · VyOS 1.5 Circinus
zsdc added a comment to T5577: Optimize PAM configs for RADIUS/TACACS+.

Backports:
1.4 - https://github.com/vyos/vyos-1x/pull/2512
1.3 - https://github.com/vyos/vyos-1x/pull/2513

Nov 20 2023, 5:14 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T5764: Fix race condition in vyos-grub-update service unit.
Nov 20 2023, 4:48 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro added a subtask for T4516: Rewrite system image manipulation tools in Python: T5764: Fix race condition in vyos-grub-update service unit.
Nov 20 2023, 4:47 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a parent task for T5764: Fix race condition in vyos-grub-update service unit: T4516: Rewrite system image manipulation tools in Python.
Nov 20 2023, 4:47 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro triaged T5764: Fix race condition in vyos-grub-update service unit as High priority.
Nov 20 2023, 4:46 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro triaged T5763: Fix imprecise check for remote file name in vyos-load-config.py as Normal priority.
Nov 20 2023, 4:27 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T5761: Allow PPPoE interface to be assigned IPv6 address via DHCPv6.

Did you try it?

set interfaces pppoe pppoe1 ipv6
Nov 20 2023, 1:38 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5743: HTTPS API ability to import PKI certificates.

If someone will implement it, there was a discussion https://github.com/vyos/vyos-1x/pull/2488

Nov 20 2023, 12:42 PM · VyOS 1.5 Circinus
c-po updated subscribers of T5762: http: api: smoketests fail as they can not establish IPv6 connection to uvicorn backend server.
Nov 20 2023, 9:21 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T5762: http: api: smoketests fail as they can not establish IPv6 connection to uvicorn backend server.

Draft PR for 1.5 https://github.com/vyos/vyos-1x/pull/2508

Nov 20 2023, 9:21 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po claimed T5762: http: api: smoketests fail as they can not establish IPv6 connection to uvicorn backend server.
Nov 20 2023, 8:38 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po created T5762: http: api: smoketests fail as they can not establish IPv6 connection to uvicorn backend server.
Nov 20 2023, 8:38 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T2816: Rewrite IPsec scripts with the new XML/Python approach as Resolved.
Nov 20 2023, 7:38 AM · VyOS 1.4 Sagitta
a.hajiyev added a comment to T2737: DHCP Lease not displayed with a static map.

Tested in VyOS 1.4-rolling-202311100309:
Configurations:

Nov 20 2023, 6:31 AM · Restricted Project, VyOS 1.5 Circinus
fkszczot added a comment to T5760: DHCP client custom dhcp-options.

This PR LGTM as it addresses my main need, although I think it'd be better to add support for the rest of options from RFC 2132 (eventually).
When talking about request as an option I'm talking about adding a way to add a request (or also request) statement to dhclient.conf. I need to requst subnet-mask, routers, rfc3442-classless-static-routes from my ISP, and the current implementation doesn't allow me to do that.

Nov 20 2023, 5:55 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.hajiyev changed the status of T2816: Rewrite IPsec scripts with the new XML/Python approach from In progress to Open.
Nov 20 2023, 5:04 AM · VyOS 1.4 Sagitta
a.hajiyev added a comment to T2816: Rewrite IPsec scripts with the new XML/Python approach.

Tested on VyOS 1.4-rolling-202311100309 and VyOS 1.5-rolling-202311160736 - L-Time shows 0. But supposed to show 3600 according to the configuration.

Nov 20 2023, 5:00 AM · VyOS 1.4 Sagitta

Nov 19 2023

c-po added a comment to T5760: DHCP client custom dhcp-options.

dhcp-server's raw parameters, which would pass options to dhclient as-is

Nov 19 2023, 8:50 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po changed the status of T5760: DHCP client custom dhcp-options from Open to In progress.
Nov 19 2023, 7:45 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
dotAndy created T5761: Allow PPPoE interface to be assigned IPv6 address via DHCPv6.
Nov 19 2023, 3:15 PM · VyOS 1.5 Circinus
fkszczot assigned T5760: DHCP client custom dhcp-options to c-po.
Nov 19 2023, 1:38 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fkszczot created T5760: DHCP client custom dhcp-options.
Nov 19 2023, 1:38 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
ishan added a comment to T5686: Loss of connectivity on dhcp enabled ethernet interfaces after abrupt link restarts.

oh okay. I don't know what else to do. this is difficult to replicate and it's scary if this happens when i am not at home and primary wan is also unavailable.

Nov 19 2023, 9:17 AM · Restricted Project, VyOS 1.5 Circinus
syncer assigned T94: commit archive to AWS S3 to Viacheslav.
Nov 19 2023, 8:20 AM · VyOS 1.5 Circinus
syncer updated the task description for T139: Commit archive backends.
Nov 19 2023, 8:20 AM · VyOS 1.5 Circinus