Page MenuHomeVyOS Platform
Feed Advanced Search

Jan 10 2024

c-po closed T5886: Add support for ACME protocol (LetsEncrypt), a subtask of T5894: Extend get_config_dict() with additional parameter with_pki that defaults to False, as Resolved.
Jan 10 2024, 5:57 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po moved T5913: Allow for Peer-Groups in ipv4-labeled-unicast SAFI from Open to Finished on the VyOS 1.5 Circinus board.
Jan 10 2024, 5:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po changed the status of T5913: Allow for Peer-Groups in ipv4-labeled-unicast SAFI from Open to In progress.
Jan 10 2024, 5:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T5913: Allow for Peer-Groups in ipv4-labeled-unicast SAFI.

PR for 1.5 https://github.com/vyos/vyos-1x/pull/2787 which will be backported to 1.4

Jan 10 2024, 5:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev changed the status of T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration from Open to In progress.
Jan 10 2024, 4:55 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
zsdc created T5918: Verification problem for `set vpn ipsec interface`.
Jan 10 2024, 4:52 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro added a comment to T5917: Restore annotations of (running)/(default boot) in select image list.

PR:
https://github.com/vyos/vyos-1x/pull/2786

Jan 10 2024, 4:14 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro triaged T5917: Restore annotations of (running)/(default boot) in select image list as Normal priority.
Jan 10 2024, 4:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jestabro lowered the priority of T3871: Resolve unexpected interface name reordering from High to Normal.

Lowering priority to normal to proceed with adding the interface-monitor daemon development, mentioned above, for 1.5.

Jan 10 2024, 3:32 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
n.fort added a comment to T4610: Firewall with 20K entries cannot load after reboot.

Quick test done on a VM with 1 CPU and 1G RAM:

[email protected]# for I in  {1..2542}; do set firewall ipv6 name Test rule $I action accept ; set firewall ipv6 name Test rule $I destination port $I; set firewall ipv6 name Test rule $I protocol tcp ; done
[email protected]# time commit
Jan 10 2024, 3:30 PM · VyOS 1.4 Sagitta
n.fort assigned T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration to sarthurdev.
Jan 10 2024, 3:26 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T3833: Cloud-init not finding data source in OpenStack as Resolved.

@sempervictus Thanks for the update!

Jan 10 2024, 3:25 PM · VyOS 1.4 Sagitta
fghorow added a comment to T5910: Grub problem(?) Serial Console no longer working.

OK, the grub serial config described here got me as far as seeing the Grub selection screen at boot time.

Jan 10 2024, 2:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sempervictus updated subscribers of T3833: Cloud-init not finding data source in OpenStack.

Oh wow, this is ancient. Can definitely close this out - @zsdc and i figured out a bunch of the insanity around cloud-init since then and i've got it working in our openstacks as well as public clouds on a single config.

Jan 10 2024, 2:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3984: Ability to disable all logs.

What to do with atop and logrorate?

Jan 10 2024, 1:59 PM
zsdc closed T1437: First boot configuration support as Wontfix.

This is closed now because the required functionality perfectly works with Cloud-init + NoCloud/ConfigDrive.

Jan 10 2024, 1:11 PM · VyOS 1.4 Sagitta
Viacheslav reassigned T3583: Overwrite default config ntp settings when custom ntp servers are provided. from UnicronNL to zsdc.
Jan 10 2024, 12:51 PM
sarthurdev changed the status of T5787: dhcp-server allows duplicate static-mapping for the same IP address from In progress to Needs testing.

1.5 PR: https://github.com/vyos/vyos-1x/pull/2785

Jan 10 2024, 12:38 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T3833: Cloud-init not finding data source in OpenStack.

Is it still bug? @sempervictus could you re-check?
We probably need more details

Jan 10 2024, 12:34 PM · VyOS 1.4 Sagitta
Viacheslav closed T4300: Extend list of supported interfaces for Cloud-init Network Configuration as Resolved.

I guess it is already done https://github.com/vyos/vyos-cloud-init/commit/ae74804ede8fb76a7f27ca869f2b880dbe276ca2
@zsdc Can we close it or you are working on it?

Jan 10 2024, 12:31 PM · VyOS 1.4 Sagitta
Viacheslav closed T5012: Control network configuration from Cloud-Init config as Resolved.
Jan 10 2024, 12:24 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5915: Firewall zone - Re add op-mode commands from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/2784

Jan 10 2024, 12:14 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T3429: Hyper-V integration services not working on VyOS 1.4 (sagitta/current).

PR https://github.com/vyos/vyos-build/pull/484

Jan 10 2024, 10:44 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
marc_s added a comment to T5910: Grub problem(?) Serial Console no longer working.

See also forum thread @ https://forum.vyos.io/t/grub-menu-fails-to-load-on-serial-only-devices-with-no-kvm/

Jan 10 2024, 9:23 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav placed T5909: Container registry with authentication prevents config load (section container) after reboot up for grabs.
Jan 10 2024, 7:29 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
dutty added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

On the other hand I would expect someone aka the admin who will configure an enterprise firewall such as VyOS could be called to have at least SOME basic knowledge and also some interest to read the documentation on how to configure the firewall.

Jan 10 2024, 7:21 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
stingalleman added a comment to T3871: Resolve unexpected interface name reordering.

@stingalleman As mentioned above (and confirmed in discussions earlier this week), we've had few if any reports of issues with the udev approach, so we would be very interested to hear details of your case.

Jan 10 2024, 2:03 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
Cheeze_It renamed T5916: Added segment routing check for index size and SRGB size from Add protocol handler tiebreaker for Segment Routing for IS-IS and OSPF for index base values larger than label base to Added segment routing check for index size and SRGB size .
Jan 10 2024, 1:34 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Cheeze_It added a comment to T5916: Added segment routing check for index size and SRGB size .

Put in the PR for this at https://github.com/vyos/vyos-1x/pull/2780

Jan 10 2024, 1:34 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Cheeze_It changed the status of T5916: Added segment routing check for index size and SRGB size from Open to Needs testing.
Jan 10 2024, 1:13 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T3984: Ability to disable all logs.

Could for example be that set system options logtoram enables the feature while set system options logtoram size 32M sets the desired size where the default is 32M or whatever would be needed as a sane minimum.

Jan 10 2024, 12:40 AM

Jan 9 2024

MattK added a comment to T3984: Ability to disable all logs.

Maybe making the size of the ramdisk configurable via CLI would be wise? I feel that there's enough variation in hardware configurations out there that hard-coding a value would cause problems.

Jan 9 2024, 11:28 PM
Apachez added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

On the other hand I would expect someone aka the admin who will configure an enterprise firewall such as VyOS could be called to have at least SOME basic knowledge and also some interest to read the documentation on how to configure the firewall.

Jan 9 2024, 11:01 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dutty added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

As a side comment, the new firewall system allows more granular control and sometimes may simplify configuration. It follows better the lower level logic of nftables.

Jan 9 2024, 9:57 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev changed the status of T5787: dhcp-server allows duplicate static-mapping for the same IP address from Open to In progress.
Jan 9 2024, 9:55 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
dutty added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

Yes, I agree with that, readability will be better if everything is in order.

Jan 9 2024, 9:42 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

I suggest changing order just as a cosmetic fix: feels more reasonable/readable to parse first "incoming", and then "outgoing"

Jan 9 2024, 9:37 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dutty added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

@n.fort
Looks like 1) and 2) is correct, as well as 'Action=accept in vyos command shall remain as accept in nftables'.
However, the 3) is not obvious to me. As long as all rules with Action=Accept in both IN and OUT chains will migrate to Action=return, looks like there should be no difference in order, other than probably for performance reason.

Jan 9 2024, 9:33 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
tjh added a comment to T2801: conntrack-tools flooding logs.

I stopped using conntrack-sync before I moved to 1.3 (which I am currently running) so I can't confirm either way.
I expect it's no longer an issue though and this task can be closed.

Jan 9 2024, 9:17 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
dmbaturin closed T3513: Attempting to remove firewall rule results in error, a subtask of T2199: Rewrite firewall in new XML/Python style, as Not Applicable.
Jan 9 2024, 8:56 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
dmbaturin triaged T3566: Add L2vpn instance for mpls as Normal priority.
Jan 9 2024, 8:55 PM · VyOS Rolling
dmbaturin removed a project from T3763: wireguard checks if port already binding: VyOS 1.3 Equuleus (1.3.6).
Jan 9 2024, 8:55 PM · VyOS 1.4 Sagitta
dmbaturin closed T3763: wireguard checks if port already binding as Resolved.
Jan 9 2024, 8:54 PM · VyOS 1.4 Sagitta
n.fort added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

Changes that seems to be needed only in migration script https://github.com/vyos/vyos-1x/blob/current/src/migration-scripts/firewall/10-to-11:

  • Use accept action for base-chains (it's done, no change needed here).
  • Migrate action=accept to action=return on every rule.
  • fix order and ensure all "in" rules are applied first.
Jan 9 2024, 8:54 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dmbaturin triaged T4394: Improve VYOS_DEBUG profiling support as High priority.
Jan 9 2024, 8:53 PM · VyOS Rolling
dmbaturin triaged T4375: hairpin nat (nat reflector) "hijacks" all outgoing traffic on specified port to any destination as High priority.
Jan 9 2024, 8:53 PM · VyOS 1.4 Sagitta (1.4.1)
dmbaturin triaged T3501: Allow using more than one tuned profile as Wishlist priority.
Jan 9 2024, 8:52 PM · VyOS Rolling
dmbaturin closed T4358: Image sizes have grown significantly in 1.4 as Not Applicable.

This issue is on and off, but mostly solved now.

Jan 9 2024, 8:51 PM · VyOS 1.4 Sagitta
dmbaturin triaged T3499: Podman is not compatible with nat rules as High priority.
Jan 9 2024, 8:49 PM · VyOS 1.4 Sagitta
dmbaturin changed the status of T3489: NUMA has been disabled for the past few years and no-one has noticed from Unknown Status to Resolved.
Jan 9 2024, 8:49 PM · VyOS 1.4 Sagitta
dmbaturin closed T3479: route-maps containing "aggregator as" can not be deleted as Not Applicable.
Jan 9 2024, 8:48 PM · VyOS 1.4 Sagitta
dmbaturin closed T3476: Update availability check as Resolved.
Jan 9 2024, 8:45 PM · VyOS 1.4 Sagitta
dmbaturin triaged T3449: Unsuccessful attempt at network boot causes packet loss on associated VLAN as High priority.
Jan 9 2024, 8:44 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin triaged T3427: Show prefix received via IA_PD in interface info as Low priority.
Jan 9 2024, 8:43 PM
dmbaturin triaged T3430: Cloud-init failing with “Unable to render networking” on VyOS 1.3 as High priority.
Jan 9 2024, 8:42 PM · VyOS 1.4 Sagitta
dmbaturin triaged T3393: IPoE does not assign IPv6 PD or WAN address as High priority.
Jan 9 2024, 8:39 PM
dmbaturin triaged T3401: Bond VRRP Race Condition as High priority.
Jan 9 2024, 8:38 PM · VyOS 1.4 Sagitta
dmbaturin triaged T3334: Changing serial settings from a serial console ends session abruptly as High priority.
Jan 9 2024, 8:32 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin triaged T3338: Some Cloud-Init configurations can prevent login on the router as High priority.
Jan 9 2024, 8:31 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin triaged T3011: router becomes unreachable for few minutes when vti interfaces goes down as High priority.
Jan 9 2024, 8:31 PM · VyOS 1.4 Sagitta
dmbaturin triaged T3224: Implement 'feasible' RPF as Wishlist priority.
Jan 9 2024, 8:30 PM · VyOS Rolling, VyOS 1.5 Circinus
dmbaturin closed T3209: Load balancing rules in firewall, a subtask of T3116: Support back-end L4 level load balancing, as Invalid.
Jan 9 2024, 8:29 PM · VyOS 1.4 Sagitta
dmbaturin closed T3209: Load balancing rules in firewall as Invalid.

This needs to be properly worded as a feature request, if it's still relevant with the new firewall implementation.

Jan 9 2024, 8:29 PM · VyOS 1.4 Sagitta
dmbaturin triaged T3204: Performance system option destroy defined sysctl custom params as High priority.
Jan 9 2024, 8:28 PM · VyOS Rolling, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
dmbaturin edited projects for T3203: BGP unnumbered - commit fails when route-reflector-client is set, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.6).
Jan 9 2024, 8:26 PM · VyOS 1.4 Sagitta
dmbaturin triaged T3159: L2TP MTU mismatch between client and server as Normal priority.
Jan 9 2024, 8:23 PM · Restricted Project, VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
dmbaturin triaged T3153: Route leaking to default VRF in Wireguard as Normal priority.
Jan 9 2024, 8:22 PM
dmbaturin triaged T3086: Scheduled squidguard blacklist update breaks Squid as High priority.
Jan 9 2024, 8:21 PM
dmbaturin triaged T3071: Display VLAN mode information on the network interface as Low priority.
Jan 9 2024, 8:21 PM
dmbaturin added a comment to T3062: Multiple Wireless SSID's on Single Wireless Card causes a crash.

Someone needs to test it on a system with a real wireless NIC.

Jan 9 2024, 8:18 PM
dmbaturin triaged T3062: Multiple Wireless SSID's on Single Wireless Card causes a crash as High priority.
Jan 9 2024, 8:18 PM
dmbaturin triaged T2971: Provide a CLI solution for Ingress Shaping when there is SNAT as Low priority.
Jan 9 2024, 8:17 PM
dmbaturin removed a project from T2844: BGP conf_mode errors disable-send-community: VyOS 1.3 Equuleus (1.3.6).
Jan 9 2024, 8:16 PM · VyOS 1.4 Sagitta
dmbaturin closed T2844: BGP conf_mode errors disable-send-community as Resolved.
Jan 9 2024, 8:16 PM · VyOS 1.4 Sagitta
dmbaturin triaged T2840: "beep-if-fully-booted" beeps too early as Low priority.
Jan 9 2024, 8:15 PM · VyOS Rolling, Restricted Project
dmbaturin triaged T2804: OSPFv3 Stub / NSSA [no summary] as Normal priority.
Jan 9 2024, 8:10 PM · VyOS Rolling
dmbaturin added a comment to T2801: conntrack-tools flooding logs.

I presume it's no longer an issue, but I'd like to confirm.

Jan 9 2024, 8:09 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
dmbaturin triaged T2801: conntrack-tools flooding logs as High priority.
Jan 9 2024, 8:09 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
dmbaturin triaged T2798: Allow port range in tc filter as Low priority.
Jan 9 2024, 8:08 PM · VyOS Rolling
dmbaturin triaged T2770: Allow any character to be used in the SNMP community field as Low priority.
Jan 9 2024, 8:04 PM · VyOS Rolling
dmbaturin triaged T2768: Define a high level HTTP API as Normal priority.
Jan 9 2024, 8:03 PM · VyOS Rolling
dmbaturin triaged T2762: VRF: when SSHd is VRF bound all commands are executed in VRF context as High priority.
Jan 9 2024, 8:02 PM · VyOS Rolling
dmbaturin triaged T2760: In a load-balanced multi-wan configuration with DHCP assigned addresses, IPsec "dhcp-interface" does not work as High priority.
Jan 9 2024, 8:02 PM · VyOS Rolling, Restricted Project
dmbaturin closed T2755: Requirements for partial interface setup as Resolved.
Jan 9 2024, 8:01 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
dmbaturin triaged T2505: XCP-ng packet drops for small packets (e.g. icmp) under Xen and AWS as High priority.
Jan 9 2024, 7:58 PM · VyOS Rolling, Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin triaged T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic as High priority.
Jan 9 2024, 7:56 PM · VyOS 1.5 Circinus
dmbaturin closed T2721: Set FQ-CoDel as the default queueing mechanism for every class in Shaper as Resolved.
Jan 9 2024, 7:56 PM · VyOS 1.4 Sagitta
dmbaturin triaged T2584: pppoe-server NAS-Filter-Rule attribute as Normal priority.
Jan 9 2024, 7:55 PM · VyOS Rolling
dmbaturin triaged T2477: Make VyOS interactively ask whether user trust remote host SSH fingerprint as Low priority.
Jan 9 2024, 7:51 PM · VyOS Rolling
dmbaturin triaged T2468: Passwords with special characters fail in commit-archive as Low priority.
Jan 9 2024, 7:50 PM · VyOS Rolling, Restricted Project
dmbaturin triaged T2287: LLDP not working on X710 adapter, i40e driver as High priority.
Jan 9 2024, 6:48 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
dmbaturin triaged T3721: ARM64: 1.4: Fastnetmon in current is a precompiled custom "blob" and amd64 only. (blocks all arm64 builds) as Low priority.
Jan 9 2024, 6:45 PM · VyOS Rolling, VyOS 1.5 Circinus
dmbaturin changed the status of T3721: ARM64: 1.4: Fastnetmon in current is a precompiled custom "blob" and amd64 only. (blocks all arm64 builds) from Needs testing to On hold.
Jan 9 2024, 6:45 PM · VyOS Rolling, VyOS 1.5 Circinus
dmbaturin triaged T3652: BGP handshake with cisco router ends in timeout as High priority.
Jan 9 2024, 6:43 PM · VyOS 1.4 Sagitta
dmbaturin closed T3712: route-map comm-list can't be used without option delete as Not Applicable.

The original syntax is now allowed anymore.

Jan 9 2024, 6:42 PM
dmbaturin added a comment to T3493: DHCPv6 does not have prefix range validation.

Should be easy to do now that ipaddrcheck supports range validation.

Jan 9 2024, 6:39 PM · VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin triaged T3493: DHCPv6 does not have prefix range validation as High priority.
Jan 9 2024, 6:39 PM · VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin closed T3587: Intel QAT support is broken on VyOS 1.4 due to a Kernel Crash as Not Applicable.
Jan 9 2024, 6:38 PM · VyOS 1.4 Sagitta
dmbaturin closed T2300: Cannot remove PBR as Not Applicable.
Jan 9 2024, 6:34 PM · VyOS 1.4 Sagitta
dmbaturin triaged T2207: IPv6 route install failed as High priority.
Jan 9 2024, 6:34 PM