Page MenuHomeVyOS Platform
Feed Advanced Search

Tue, May 14

Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

If you are really that curious, I can attach a screenshot.

Tue, May 14, 4:04 PM
dylanneild added a comment to T5835: UPnP port mapping / rule installation fails.

If someone wants, I can probably unearth my patches to 1.4 and miniupnpd to make it all work. It was technically functional and worked as expected. I just don't have the time or patience to deal with getting it merged/integrated back into the project.

Tue, May 14, 3:59 PM
dmbaturin added a comment to T5835: UPnP port mapping / rule installation fails.

Out of curiosity, will the details of the poll be public or the results being shared transparently?

Tue, May 14, 3:48 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

A bunch to unpack here.
[...]

Tue, May 14, 3:41 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

Created a poll for maintainers on this topic, and we will go with the decision made.

Tue, May 14, 3:36 PM
dylanneild added a comment to T5835: UPnP port mapping / rule installation fails.

A bunch to unpack here.

Tue, May 14, 3:33 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

go learn how cheap cameras open firewalls via UPnP and make them available on the internet without people being aware of that

or how malware exfiltrates data via port 443 because enterprises can't reliably block outbound traffic on that port.

Tue, May 14, 2:48 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

If you know how to test it will be great to test it. If no one needs it even for tests, what are we talking about?

Tue, May 14, 2:29 PM
syncer added a comment to T5835: UPnP port mapping / rule installation fails.

Created a poll for maintainers on this topic, and we will go with the decision made.

Tue, May 14, 2:27 PM
syncer added a comment to T5835: UPnP port mapping / rule installation fails.
In T5835#187936, @simplysoft wrote:

Yes, that is exactly the point. Glad you did not suggest to remove the NAT capability of vyos because it could be used to bypass security or is not appropriate for an "enterprise"

Tue, May 14, 2:24 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.
In T5835#187933, @simplysoft wrote:

A firewall is doing exactly this all the time when using NAT, autonomously opening ports via call from internal networks (aka internal originated traffic) to allow responses to reach the originator. Enterprises might have some strict outbound rules. For UPnP is exactly the same, an enterprise would have strict rules which services are allowed to open ports.

Not if it's not configured to do so.

Tue, May 14, 2:20 PM
Viacheslav added a comment to T5835: UPnP port mapping / rule installation fails.
In T5835#187933, @simplysoft wrote:

I'm not sure if that summary from you @Viacheslav is fully reflecting the current state.
I'm also not sure if the original implementation never worked, might very well have been broken while refactoring some vyos internals how the firewall is structured, but I guess you should have a better understanding of (the history of) your product. Otherwise I would be very surprised if a broken feature got into your product without every working / being tested.

Tue, May 14, 2:18 PM
syncer added a comment to T5835: UPnP port mapping / rule installation fails.
In T5835#187933, @simplysoft wrote:

A firewall is doing exactly this all the time when using NAT, autonomously opening ports via call from internal networks (aka internal originated traffic) to allow responses to reach the originator. Enterprises might have some strict outbound rules. For UPnP is exactly the same, an enterprise would have strict rules which services are allowed to open ports.

Not if it's not configured to do so.

Tue, May 14, 2:07 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

I'm not sure if that summary from you @Viacheslav is fully reflecting the current state.
I'm also not sure if the original implementation never worked, might very well have been broken while refactoring some vyos internals how the firewall is structured, but I guess you should have a better understanding of (the history of) your product. Otherwise I would be very surprised if a broken feature got into your product without every working / being tested.

Tue, May 14, 2:03 PM
syncer added a comment to T5835: UPnP port mapping / rule installation fails.

I fail to comprehend how a firewall that autonomously opens ports via calls from internal networks is appropriate for an enterprise.
Indeed there are some use cases but this functionality can be used by malicious code and allow bypass security configuration that is enforced otherwise

Tue, May 14, 1:13 PM
Viacheslav added a comment to T5835: UPnP port mapping / rule installation fails.

In summary, it works with custom scripts and patches, but it still does not work from CLI (not fully integrated)
The scripts that should be involved are in the repo https://github.com/miniupnp/miniupnp/tree/miniupnpd_2_3_3/miniupnpd/netfilter_nft/scripts
Until we do not have them and they do not communicate with the firewall, the feature does not work.
A patch is attached in several posts above https://vyos.dev/T5835#174066

Tue, May 14, 12:40 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

Does it work now?

Tue, May 14, 11:04 AM
Viacheslav lowered the priority of T5497: Add ability to resequence rule numbers for firewall from Normal to Wishlist.
Tue, May 14, 10:57 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
n.fort placed T5497: Add ability to resequence rule numbers for firewall up for grabs.
Tue, May 14, 10:56 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
syncer added a comment to T5835: UPnP port mapping / rule installation fails.

Does it work now?

Tue, May 14, 10:43 AM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

One reasons it is rarely seen is as most are not aware of it being used undercover and when not being present, nothing necessarily brakes (due to fallback to other mechanisms). For some home routers we saw this was an undocumented "feature" that you did not have any control over, more recent & reasonable implementation we have seen allow you to enable or disable it (but nothing much more like fine grained permissions)

Tue, May 14, 10:36 AM
Apachez added a comment to T5835: UPnP port mapping / rule installation fails.

I have rarely seen UPnP in enterprise environments and rarely at home even if the main purpose is to use it at home and let applications backdoor your firewall (which often is a bad thing in enterprise evironments).

Tue, May 14, 10:23 AM
syncer added a comment to T5835: UPnP port mapping / rule installation fails.

No doubt that there are other use cases.
since 1.2 LTS, we received zero requests from customers about adding UPnP, hence, don't see any value in it

Tue, May 14, 9:50 AM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

@aidan-gibson main use case is games typically, which is not in priority for us

Tue, May 14, 9:17 AM
syncer added a comment to T5835: UPnP port mapping / rule installation fails.

@aidan-gibson It's never worked, and demand is slim to none
main use case is games typically, which is not in priority for us

Tue, May 14, 7:45 AM
aidan-gibson added a comment to T5835: UPnP port mapping / rule installation fails.

bruh

Tue, May 14, 7:42 AM

Mon, May 13

syncer edited projects for T1070: SWANCTL: DMVPN: ALL peers are deleted in swan when opennhrp tries to delete ONE peer, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:36 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8), Restricted Project
syncer edited projects for T1311: WAN load-balancing can't flush connections when conntrack-sync is enabled, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:35 PM · VyOS 1.3 Equuleus (1.3.8), VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, test
syncer edited projects for T2145: openvpn: server default topology net30 is incompatible with static client IPs for Windows clients, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:34 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8), Restricted Project, openvpn
syncer edited projects for T2207: IPv6 route install failed, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:34 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8), Restricted Project, VyOS 1.5 Circinus
syncer edited projects for T2251: VRF communication breaks when utilizing zone-based firewalling, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:34 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8), Restricted Project
syncer edited projects for T2287: LLDP not working on X710 adapter, i40e driver, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:34 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8), Restricted Project, VyOS 1.5 Circinus
syncer edited projects for T2760: In a load-balanced multi-wan configuration with DHCP assigned addresses, IPsec "dhcp-interface" does not work, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:34 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8), Restricted Project
syncer edited projects for T2762: VRF: when SSHd is VRF bound all commands are executed in VRF context, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:34 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8), Restricted Project
syncer edited projects for T2840: "beep-if-fully-booted" beeps too early, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:33 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8), Restricted Project, VyOS 1.5 Circinus
syncer edited projects for T3824: Ethernet offload options are not populated in new installs, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:33 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8), Restricted Project
syncer edited projects for T3933: The firewall does not filter incoming traffic on the interface with vrf., added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:33 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8), Restricted Project
syncer edited projects for T5444: R8169 driver crash, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:32 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8), Restricted Project
syncer edited projects for T5926: IPSEC does not apply after l2tp configuration was changed, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:32 PM · VyOS 1.3 Equuleus (1.3.8), VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
syncer edited projects for T5881: IPv6 addresses jumbled in flow accounting, added: VyOS 1.3 Equuleus (1.3.8); removed VyOS 1.3 Equuleus (1.3.7).
Mon, May 13, 7:32 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.8)
dmbaturin edited projects for T4915: Minisign verification failure == pass??, added: VyOS 1.4 Sagitta (1.4.0-epa1); removed VyOS 1.4 Sagitta (1.4.0-epa3).
Mon, May 13, 1:43 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
syncer assigned T5835: UPnP port mapping / rule installation fails to dmbaturin.

@dmbaturin, I propose removal of upnp stuff from 1.5 and 1.4

Mon, May 13, 11:17 AM
aidan-gibson added a comment to T5835: UPnP port mapping / rule installation fails.

Any update on this PR? (thanks for the work put into this!!)

Mon, May 13, 8:39 AM

Sat, May 11

dmbaturin changed Why the issue appeared? from none to implementation-mistake on T6056: Applying 'system static-host-mapping' command calls unnecessary snmpd restart.
Sat, May 11, 8:06 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
dmbaturin edited projects for T3642: PKI configuration, added: VyOS 1.4 Sagitta (1.4.0-epa1); removed VyOS 1.4 Sagitta.
Sat, May 11, 4:53 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
DerEnderKeks added a comment to T4923: Zebra sends router advertisements even though it's not supposed to.

I finally managed to narrow this down further. This problem is caused by enabling the extended nexthop capability. FRR intentionally sends RAs when this capability is enabled, althought so far I don't understand why. I opened a discussion in the FRR repo: https://github.com/FRRouting/frr/discussions/15994

Sat, May 11, 11:38 AM · VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project

Fri, May 10

dmbaturin changed Issue type from documentation to improvement on T5418: Allow arbitrary subnets in PPPoE client IP pools.
Fri, May 10, 8:10 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
dmbaturin edited projects for T2801: conntrack-tools flooding logs, added: VyOS 1.4 Sagitta (1.4.0-epa1); removed VyOS 1.5 Circinus, VyOS 1.4 Sagitta.
Fri, May 10, 8:09 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
dmbaturin removed a project from T6056: Applying 'system static-host-mapping' command calls unnecessary snmpd restart: VyOS 1.5 Circinus.
Fri, May 10, 7:51 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
dmbaturin renamed T6261: Typo in the operational mode connect and disconnect command output from Typo in op_mode connect_disconnect print statement for check_ppp_running to Typo in the operational mode connect and disconnect command output.
Fri, May 10, 7:49 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.3 Equuleus (1.3.7)
dmbaturin renamed T5418: Allow arbitrary subnets in PPPoE client IP pools from PPPoE-Server Client IP pool Subnet to Allow arbitrary subnets in PPPoE client IP pools.
Fri, May 10, 7:29 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
dmbaturin edited projects for T5239: Host name and domain name missing from the FRR configuration, added: VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7); removed VyOS 1.5 Circinus, VyOS 1.4 Sagitta.
Fri, May 10, 7:16 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

Just so I dont get the vocabulary wrong here...

Fri, May 10, 4:57 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez reopened T5497: Add ability to resequence rule numbers for firewall as "Known issue".

Ill put it into "known issue" since IMHO a complete "resolved" would be when this feature exists in config-mode aswell.

Fri, May 10, 4:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav added a comment to T5497: Add ability to resequence rule numbers for firewall.

Feel free to reopen it, but I'm not expecting it to be implemented.

Fri, May 10, 3:03 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

The thing is that adding this as op-mode only doesnt really solve anything.

Fri, May 10, 3:01 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav added a comment to T5497: Add ability to resequence rule numbers for firewall.

I think the original request was Add ability to resequence rule numbers for firewall, and we added this tool.
Auto-Apply configuration based on this tool is the wrong way. We haven't had such hacks before and probably won't implement them in the nearest feature.
All configuration changes have to be only per user commit; there should not be any auto-commits/auto applies configs. We have API for these tricks.
CLI is completely different from the cisco/arista logic.

Fri, May 10, 2:51 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

Also NAT-rules are in the need of a resequence feature in the config-mode:

Fri, May 10, 2:17 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
n.fort closed T5497: Add ability to resequence rule numbers for firewall as Resolved.
Fri, May 10, 2:10 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
n.fort added a comment to T5497: Add ability to resequence rule numbers for firewall.

I'm closing this task a solution was included. I'm not in favor of introducing similar command in configuration mode.

Fri, May 10, 2:10 PM · VyOS 1.4 Sagitta (1.4.0-epa1)

Tue, May 7

HollyGurza moved T5164: op cmd: "show dhcp server leases state" with available options does not show any result from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa1) board.
Tue, May 7, 3:16 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
HollyGurza closed T5164: op cmd: "show dhcp server leases state" with available options does not show any result as Resolved.
Tue, May 7, 3:15 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Sat, May 4

Viacheslav added a comment to T2468: Passwords with special characters fail in commit-archive.

Should be fixed after rewriting commit-archive T6304

Sat, May 4, 8:22 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Fri, May 3

Viacheslav added a parent task for T6122: Protocols under VRF config run in a single pass against their conf_mode scripts: T6302: The root task for bugs and improvements related to commit time and boot.
Fri, May 3, 12:52 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Thu, May 2

Viacheslav moved T6056: Applying 'system static-host-mapping' command calls unnecessary snmpd restart from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.7) board.
Thu, May 2, 3:49 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
Viacheslav closed T6056: Applying 'system static-host-mapping' command calls unnecessary snmpd restart as Resolved.
Thu, May 2, 3:49 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
Viacheslav changed the status of T6056: Applying 'system static-host-mapping' command calls unnecessary snmpd restart from Open to Backport candidate.
Thu, May 2, 8:56 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
Viacheslav moved T6056: Applying 'system static-host-mapping' command calls unnecessary snmpd restart from Need Triage to Finished on the VyOS 1.5 Circinus board.
Thu, May 2, 8:56 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)

Wed, May 1

Viacheslav added a comment to T6056: Applying 'system static-host-mapping' command calls unnecessary snmpd restart.

PR https://github.com/vyos/vyos-1x/pull/3386

Wed, May 1, 1:50 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
nvollmar added a comment to T2468: Passwords with special characters fail in commit-archive.

Thanks for the hints, that makes sense. Let's see how that can be implemented :)

Wed, May 1, 9:26 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Apachez added a comment to T2468: Passwords with special characters fail in commit-archive.

For added service when typing just:

Wed, May 1, 9:16 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Apachez added a comment to T2468: Passwords with special characters fail in commit-archive.

You would still be limited to not be able to use " as part of your password.

Wed, May 1, 9:15 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a comment to T2468: Passwords with special characters fail in commit-archive.

There should also be migration scripts, as CLI will be changed.

Wed, May 1, 9:13 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
nvollmar added a comment to T2468: Passwords with special characters fail in commit-archive.

Proposal:

set system config-management commit-archive uri "stor01z-cs.int.trae32566.org/cr01b-vyos"
set system config-management commit-archive scheme "sftp"
set system config-management commit-archive username "cr01b"
set system config-management commit-archive password "$T3$TP@$$W0^%"
Wed, May 1, 8:15 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
nvollmar added a comment to T2468: Passwords with special characters fail in commit-archive.

We could improve it by breaking up configuration, having the user providing a URI, Protocol and optional username/password as separate values.
Then we can properly encode username/password. This would also give more flexibility how username/password are handled and passed on.

Wed, May 1, 8:06 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
nvollmar added a comment to T2468: Passwords with special characters fail in commit-archive.

In both cases it is kind of an user error, the password would have to be properly url encoded if provided in one (@ should be %40 in an URI, a ! should be %21).

Wed, May 1, 8:04 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Mon, Apr 29

rchrist added a comment to T5811: static dhcp-interface routes not installed.

Running into this issue on VyOS 1.5-rolling-202404280021

set protocols static route xxx.xxx.74.149/32 dhcp-interface eth1.999
Mon, Apr 29, 5:23 PM · VyOS 1.4 Sagitta (1.4.0-GA)

Tue, Apr 23

Viacheslav changed the status of T6058: Commit-Archive Save doesn't use https_proxy from Open to Needs reporter action.

@modzilla99 Could you provide an example of set commands to reproduce?

Tue, Apr 23, 5:09 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Mon, Apr 22

jestabro closed T5996: Incorrect behavior for backslash escapes in config save and compare commands, a subtask of T5939: [1.3.5 -> 1.4.0-RC1 Migration] as-path-list Entries Get Messed Up, as Resolved.
Mon, Apr 22, 2:48 PM · VyOS 1.4 Sagitta (1.4.0-GA)

Apr 16 2024

paigeadelethompson added a comment to T6097: vrf_zones blocking ipv6 traffic.

I decided to dig into this a little more and try to trace this out:

sudo nft add chain inet vrf_zones trace_chain { type filter hook prerouting priority -301\; }
sudo nft add rule inet vrf_zones trace_chain meta nftrace set 1
Apr 16 2024, 7:41 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
paigeadelethompson added a comment to T6097: vrf_zones blocking ipv6 traffic.

side note, if you flush ruleset, and only add:

Apr 16 2024, 6:20 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
paigeadelethompson added a comment to T6097: vrf_zones blocking ipv6 traffic.

Something I just figured out is that the minute I do:

Apr 16 2024, 6:06 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Apr 15 2024

jestabro moved T3574: Add constraintGroup for combining validators with logical AND from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa1) board.
Apr 15 2024, 12:10 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro moved T3474: Revisit storing syntax version of interface definitions in XML file from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa1) board.
Apr 15 2024, 12:10 AM · VyOS 1.4 Sagitta (1.4.0-epa1)

Apr 12 2024

dmbaturin closed T1487: DNS (pdns_recursor) stats logs not saved to disk as Resolved.
Apr 12 2024, 3:36 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
dmbaturin renamed T874: Support for Two Factor Authentication for CLI access via Google Authenticator/OTP from Support for Two Factor Authentication for CLI access via Google Authenticator to Support for Two Factor Authentication for CLI access via Google Authenticator/OTP.
Apr 12 2024, 3:33 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin closed T5615: Narrow down spurious name conflict with mdns as Resolved.
Apr 12 2024, 3:13 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin closed T5877: Reduce unnecessary nesting in system domain-search path and improve smoketest as Resolved.
Apr 12 2024, 2:47 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin edited projects for T5351: VyOS deployed with cloud-init improperly saves config.boot, added: VyOS 1.4 Sagitta (1.4.0-epa1); removed VyOS 1.4 Sagitta.
Apr 12 2024, 2:40 PM · VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin edited projects for T5497: Add ability to resequence rule numbers for firewall, added: VyOS 1.4 Sagitta (1.4.0-epa1); removed VyOS 1.4 Sagitta.
Apr 12 2024, 2:32 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin closed T5846: Refactor and simplify DUID definition in conf-mode as Resolved.
Apr 12 2024, 2:18 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin closed T5195: Break up the vyos.util module as Resolved.
Apr 12 2024, 1:56 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin closed T4221: Add a template filter for converting scalars to single-item lists as Resolved.
Apr 12 2024, 12:06 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav closed T3766: containers: Expanding options for networking and building containers as Resolved.

You can create /use your own images

vyos@r4:~$ generate container image foo path 
Possible completions:
  <filename>            Path to Dockerfile
Apr 12 2024, 11:02 AM · VyOS 1.4 Sagitta (1.4.0-epa1)

Apr 11 2024

dmbaturin edited projects for T3474: Revisit storing syntax version of interface definitions in XML file, added: VyOS 1.4 Sagitta (1.4.0-epa1); removed VyOS 1.4 Sagitta.
Apr 11 2024, 7:26 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin closed T3574: Add constraintGroup for combining validators with logical AND as Resolved.
Apr 11 2024, 7:25 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin closed T160: Support NAT64 as Resolved.
Apr 11 2024, 2:45 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin closed T3774: atop logs are not limited in size as Resolved.

Backport to 1.3 is not worth the trouble since the issue is low-impact.

Apr 11 2024, 2:31 PM · VyOS 1.4 Sagitta (1.4.0-epa1)

Apr 4 2024

dmbaturin closed T671: Identify and remove dead code as Resolved.

1.4 is very reasonably clean from that Vyatta cruft, as much as it's possible. We'll create tasks for specific dead code discoveries in the future as needed.

Apr 4 2024, 10:36 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
dmbaturin added a comment to T5605: Do not generate keysize option in OpenVPN configs.

Blowfish support was removed in 1.4, so its key size is no longer an issue.

Apr 4 2024, 10:32 PM · VyOS 1.4 Sagitta (1.4.0-epa1)