Page MenuHomeVyOS Platform
Feed All Stories

Nov 23 2023

c-po committed rVYOSONEX1ba7d4e3e91b: https api: T5772: check if keys are configured (authored by dmbaturin).
Nov 23 2023, 12:44 PM
GitHub <noreply@github.com> committed rVYOSONEX11d531ece3e0: Merge pull request #2534 from c-po/backport-pr-2522 (authored by c-po).
Nov 23 2023, 12:44 PM
Viacheslav claimed T5776: Enable VFIO support.
Nov 23 2023, 12:40 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
marvin added a comment to T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.

Agree with @Viacheslav and @GurliGebis comments above.

Nov 23 2023, 12:39 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5659: VPP cannot add interface to dataplane if it already has an address configured as Resolved.
Nov 23 2023, 11:19 AM · VyOS 1.5 Circinus
Unknown Object (User) added a comment to T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.

I agree, without it, you end up repeating yourself alot, with the established, related and invalid rules.
As long as they are applied before the zone specific rules (which is how I guess it used to work), it makes sense.

Nov 23 2023, 11:15 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T4867: "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors.

There are different commands

vyos@r1:~$ show bgp neighbors 192.168.122.14 advertised-routes 
% No such neighbor or address family
vyos@r1:~$ 
vyos@r1:~$ show ip  bgp neighbors 192.168.122.14 advertised-routes 
vyos@r1:~$
Nov 23 2023, 11:10 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.

Should we return global state policy?
It was useful.

Nov 23 2023, 11:04 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort changed the status of T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config from Open to Confirmed.
Nov 23 2023, 10:48 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
zsdc created T5776: Enable VFIO support.
Nov 23 2023, 10:44 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro committed rVYOSONEX33d5d429f590: http-api: T5768: remove auxiliary http-api.conf.
Nov 23 2023, 10:35 AM
GitHub <noreply@github.com> committed rVYOSONEX6afd6eeb87a3: Merge pull request #2532 from jestabro/drop-http-api-conf (authored by c-po).
Nov 23 2023, 10:35 AM
n.fort claimed T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.
Nov 23 2023, 10:30 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po committed rVYOSONEX57ba2fa91573: https api: T5772: check if keys are configured (authored by dmbaturin).
Nov 23 2023, 10:25 AM
c-po committed rVYOSONEX58c50db26158: https api: T5772: check if keys are configured (authored by dmbaturin).
Nov 23 2023, 10:17 AM
a.hajiyev closed T4891: BFD flapping loop as Resolved.
Nov 23 2023, 9:42 AM · VyOS 1.4 Sagitta
a.hajiyev added a comment to T4891: BFD flapping loop.

Tested in VyOS 1.4-rolling-202311100309:

Nov 23 2023, 9:42 AM · VyOS 1.4 Sagitta
a.hajiyev closed T4867: "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Nov 23 2023, 8:01 AM · VyOS Rolling
a.hajiyev closed T4867: "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors as Resolved.
Nov 23 2023, 8:01 AM · VyOS 1.4 Sagitta
a.hajiyev added a comment to T4867: "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors.

Tested in VyOS 1.4-rolling-202311100309
Configs:
Node-1

Nov 23 2023, 8:01 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5612: Miscellaneous improvements and fixes for dynamic DNS configuration.

Backport to 1.4 has conflicts https://github.com/vyos/vyos-1x/pull/2533

Nov 23 2023, 7:26 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX3cb68cbaa6d9: ddclient: T5612: Relax hostname validation for apex and wildcard entry (authored by indrajitr).
Nov 23 2023, 7:21 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX03ee00ab1814: ddclient: T5612: Additional refactoring for scripts and smoketests (authored by indrajitr).
Nov 23 2023, 7:21 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXfd0498763192: ddclient: T5612: Enable TTL support for web-service based protocols (authored by indrajitr).
Nov 23 2023, 7:21 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXcb84ddeb9708: ddclient: T5612: Adjust validator and completion for ddclient (authored by indrajitr).
Nov 23 2023, 7:21 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXfd483ee899fc: ddclient: T5612: Refactor zone configuration (authored by indrajitr).
Nov 23 2023, 7:21 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX9df7f042305c: ddclient: T5612: Generate more reliable ddclient config (authored by indrajitr).
Nov 23 2023, 7:21 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXbb3b9a045af2: ddclient: T5612: Improve dual stack support for dyndns2 protocol (authored by indrajitr).
Nov 23 2023, 7:21 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX1b7e1da145a6: ddclient: T5612: Fix VRF support for ddclient service (authored by indrajitr).
Nov 23 2023, 7:21 AM

Nov 22 2023

marvin updated the task description for T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.
Nov 22 2023, 10:09 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
marvin updated the task description for T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.
Nov 22 2023, 9:46 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
marvin updated the task description for T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.
Nov 22 2023, 9:45 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
marvin updated the task description for T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.
Nov 22 2023, 9:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
marvin updated the task description for T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.
Nov 22 2023, 9:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
marvin created T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.
Nov 22 2023, 9:43 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a comment to T5768: Remove auxiliary http-api.conf for simplification of http-api config mode script.

PR:
https://github.com/vyos/vyos-1x/pull/2532

Nov 22 2023, 7:37 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
gsggage added a comment to T5612: Miscellaneous improvements and fixes for dynamic DNS configuration.

@Viacheslav
I missed running git pull on my ansible execution node. Works as it should. Thank you!

Nov 22 2023, 7:35 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort closed T5590: Firewall "log enable" logs every packet as Resolved.
Nov 22 2023, 7:18 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort closed T5616: Firewall mark - Add capabilities for matching firewall mark as Resolved.
Nov 22 2023, 7:16 PM · VyOS 1.5 Circinus
n.fort closed T5643: NAT - Allow interface groups on nat rules as Resolved.
Nov 22 2023, 7:15 PM · VyOS 1.5 Circinus
n.fort closed T5681: Interface match - Simplified and unified cli as Resolved.
Nov 22 2023, 7:14 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort closed T5729: Firewall, nat and policy route - Switch to valueless as Resolved.
Nov 22 2023, 7:11 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T5637: Firewall default-action log from Confirmed to Needs testing.
Nov 22 2023, 7:07 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav assigned T5774: commit-archive to FTP server broken after update (VyOS 1.5-rolling) to erkin.
Nov 22 2023, 5:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav triaged T5774: commit-archive to FTP server broken after update (VyOS 1.5-rolling) as Normal priority.
Nov 22 2023, 4:56 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
I-n-d-y raised the priority of T5774: commit-archive to FTP server broken after update (VyOS 1.5-rolling) from Low to Requires assessment.
Nov 22 2023, 4:54 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
I-n-d-y created T5774: commit-archive to FTP server broken after update (VyOS 1.5-rolling).
Nov 22 2023, 4:52 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a project to T5773: Unable to load config via HTTP: VyOS 1.5 Circinus.
Nov 22 2023, 4:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav updated the task description for T5773: Unable to load config via HTTP.
Nov 22 2023, 4:51 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
erkin claimed T5773: Unable to load config via HTTP.
Nov 22 2023, 4:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav triaged T5773: Unable to load config via HTTP as Urgent! priority.
Nov 22 2023, 4:38 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5773: Unable to load config via HTTP.
Nov 22 2023, 4:38 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXca9c77af975e: https api: T5772: check if keys are configured (authored by dmbaturin).
Nov 22 2023, 3:08 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX78d4a8268792: https api: T5772: check if keys are configured (authored by dmbaturin).
Nov 22 2023, 3:08 PM
GitHub <noreply@github.com> committed rVYOSONEXc1e170c88cd2: Merge pull request #2522 from dmbaturin/require-api-keys (authored by c-po).
Nov 22 2023, 3:07 PM
dmbaturin committed rVYOSONEX8c450ea7f538: https api: T5772: check if keys are configured.
Nov 22 2023, 3:07 PM
JeffWDH added a project to T5771: GeoIP - Include RFC reserved IP ranges in inverse-match rules: VyOS 1.5 Circinus.
Nov 22 2023, 2:10 PM · Restricted Project, VyOS Rolling
GitHub <noreply@github.com> committed rVYOSONEX319e1bf7f23c: Merge pull request #2529 from vyos/mergify/bp/sagitta/pr-2527 (authored by dmbaturin).
Nov 22 2023, 12:26 PM
n.fort committed rVYOSONEXc45b695ca068: T5637: firewall: extend rule for default-action to firewall bridge, in order to….
Nov 22 2023, 12:24 PM
GitHub <noreply@github.com> committed rVYOSONEX8f853daa22fe: Merge pull request #2528 from nicolas-fort/T5637-Extend-bridge (authored by c-po).
Nov 22 2023, 12:24 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX2dd0aa94e080: pppoe: T5630: make MRU default to MTU if unspecified (authored by c-po).
Nov 22 2023, 12:24 PM
c-po committed rVYOSONEXffd7339e2ea3: pppoe: T5630: make MRU default to MTU if unspecified.
Nov 22 2023, 12:23 PM
GitHub <noreply@github.com> committed rVYOSONEX9a5785c698d5: Merge pull request #2527 from c-po/t5630-mru-part-2 (authored by c-po).
Nov 22 2023, 12:23 PM
c-po added a comment to T5630: pppoe: allow to specify MRU in addition to already configurable MTU.

A fix that changes the behavior back to it was https://github.com/vyos/vyos-1x/pull/2527

Nov 22 2023, 12:22 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort added a comment to T5637: Firewall default-action log.

PR for bridge: https://github.com/vyos/vyos-1x/pull/2528

Nov 22 2023, 12:08 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.apostoliuk changed the status of T5413: Deny the opportunity to use one public/private key pair on both wireguard peers. from Needs testing to In progress.
Nov 22 2023, 11:36 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
a.apostoliuk added a project to T5413: Deny the opportunity to use one public/private key pair on both wireguard peers.: VyOS 1.3 Equuleus (1.3.5).
Nov 22 2023, 11:35 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5413: Deny the opportunity to use one public/private key pair on both wireguard peers. from In progress to Needs testing.
Nov 22 2023, 11:14 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
a.apostoliuk closed T4877: Need verification in using import vrf and import vpn, export vpn commands as Resolved.
Nov 22 2023, 11:11 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5578: "ikev2-reauth" description contains outdated information as Resolved.
Nov 22 2023, 10:51 AM · VyOS 1.3 Equuleus (1.3.5)
a.apostoliuk closed T5426: Add exceptions in vici functions calls as Resolved.
Nov 22 2023, 10:50 AM · VyOS 1.4 Sagitta
a.apostoliuk moved T5338: Add 'mpls bgp forwarding' feature from Open to Finished on the VyOS 1.4 Sagitta board.
Nov 22 2023, 10:48 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5338: Add 'mpls bgp forwarding' feature, a subtask of T5337: MPLS/BGP: Route leak does not happen from the VPNv4 table to specific vrf, as Resolved.
Nov 22 2023, 10:48 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5338: Add 'mpls bgp forwarding' feature as Resolved.
Nov 22 2023, 10:48 AM · VyOS 1.4 Sagitta
a.apostoliuk placed T5201: Add Split Tunneling for L2TP/PPTP/SSTP VPN Clients up for grabs.
Nov 22 2023, 10:43 AM · VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXb083d60102e5: vxlan: T5759: change default MTU from 1450 -> 1500 bytes (authored by c-po).
Nov 22 2023, 10:06 AM
c-po committed rVYOSONEX4a163b016333: vxlan: T5759: change default MTU from 1450 -> 1500 bytes.
Nov 22 2023, 10:04 AM
GitHub <noreply@github.com> committed rVYOSONEX6dfbf213fe83: Merge pull request #2503 from c-po/t5759-vxlan-mtu (authored by c-po).
Nov 22 2023, 10:04 AM
GitHub <noreply@github.com> committed rVYOSONEXb1ef7ba3e5f6: Merge pull request #2525 from vyos/mergify/bp/sagitta/pr-2499 (authored by c-po).
Nov 22 2023, 10:04 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX449ab8521298: vxlan: T5753: add support for VNI filtering (authored by c-po).
Nov 22 2023, 9:38 AM
c-po committed rVYOSONEX35f6033d2105: vxlan: T5753: add support for VNI filtering.
Nov 22 2023, 9:37 AM
GitHub <noreply@github.com> committed rVYOSONEX00a28fe512cc: Merge pull request #2499 from c-po/t5753-vxlan-vnifilter (authored by c-po).
Nov 22 2023, 9:37 AM
Viacheslav closed T5767: Add reboot and poweroff the system via API as Resolved.

Works fine

$ curl -k --location --request POST 'https://192.168.122.11/reboot'   --form data='{"op": "reboot", "path": ["now"]}'   --form key='foo'
{"success": true, "data": "Warning: there are unsaved configuration changes!\nRun 'save' command if you do not want to lose those changes after reboot/shutdown.\n\n", "error": null}
Nov 22 2023, 9:31 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.hajiyev closed T4021: Long commit time on bridge interface with 1-4094 allowed VLAN tags as Resolved.
Nov 22 2023, 7:42 AM · VyOS 1.4 Sagitta
a.hajiyev added a comment to T4021: Long commit time on bridge interface with 1-4094 allowed VLAN tags.

Tested on VyOS 1.4-rolling-202311100309:

Nov 22 2023, 7:41 AM · VyOS 1.4 Sagitta
a.hajiyev closed T3818: BGP export route-map only works after bgpd restart as Resolved.
Nov 22 2023, 7:20 AM · VyOS 1.4 Sagitta
a.hajiyev added a comment to T3818: BGP export route-map only works after bgpd restart.

Tested in VyOS 1.4-rolling-202311100309:
The configuration:

Nov 22 2023, 7:19 AM · VyOS 1.4 Sagitta
a.hajiyev removed a project from T2845: BGP conf_mode unable to delete configuration with peer-group: VyOS 1.4 Sagitta.
Nov 22 2023, 6:15 AM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX756bd6d45ab7: Merge pull request #2523 from vyos/mergify/bp/sagitta/pr-2519 (authored by Viacheslav).
Nov 22 2023, 6:09 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX92a75196e5a0: http: T5762: rename "virtual-host listen-port" -> "virtual-host port" (authored by c-po).
Nov 22 2023, 5:51 AM
c-po committed rVYOSONEX0e885f1bf014: http: T5762: rename "virtual-host listen-port" -> "virtual-host port".
Nov 22 2023, 5:30 AM
GitHub <noreply@github.com> committed rVYOSONEXaf08c30063fb: Merge pull request #2519 from c-po/t5762-vhost-port (authored by jestabro).
Nov 22 2023, 5:30 AM
a.hajiyev added a comment to T2845: BGP conf_mode unable to delete configuration with peer-group.

Tested in VyOS 1.4-rolling-202311100309
The configuration:
VyOS:

Nov 22 2023, 4:47 AM · VyOS 1.4 Sagitta
dmbaturin created T5772: Require HTTPS API server configurations to include at least one key if key-based auth is used.
Nov 22 2023, 12:26 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav added a comment to T5767: Add reboot and poweroff the system via API.

@a.apostoliuk will be available in the next rolling release.

Nov 22 2023, 12:14 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav changed the status of T5767: Add reboot and poweroff the system via API from In progress to Needs testing.
Nov 22 2023, 12:14 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEXd908073cac14: Merge pull request #2521 from vyos/mergify/bp/sagitta/pr-2516 (authored by dmbaturin).
Nov 22 2023, 12:10 AM
GitHub <noreply@github.com> committed rVYOSONEX93ded25d1900: Merge pull request #2520 from vyos/mergify/bp/sagitta/pr-2518 (authored by dmbaturin).
Nov 22 2023, 12:10 AM
n.fort committed rVYOSONEX4e8839b6d78c: T5419: firewall: backport firewall flowtable to Sagitta..
Nov 22 2023, 12:09 AM
GitHub <noreply@github.com> committed rVYOSONEXc87edc8f1f61: Merge pull request #2517 from nicolas-fort/T5419-FT-Sagitta (authored by dmbaturin).
Nov 22 2023, 12:09 AM