Page MenuHomeVyOS Platform
Feed Advanced Search

Dec 3 2024

n.fort created T6933: system option performance overwrites sysctl parameters defined in firewall.
Dec 3 2024, 12:56 PM · VyOS Rolling, VyOS 1.5 Circinus

Nov 27 2024

n.fort added a comment to T6918: pppoe traffic is classified as invalid.

Can you share logs for those entries?

Nov 27 2024, 12:40 PM · VyOS Rolling
n.fort added a comment to T6918: pppoe traffic is classified as invalid.

Can you check manually adding next rule?

Nov 27 2024, 11:26 AM · VyOS Rolling

Nov 13 2024

n.fort placed T6788: FTP PASV breaks control connection up for grabs.
Nov 13 2024, 12:45 PM · Bugs, VyOS Rolling

Nov 11 2024

n.fort placed T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups up for grabs.

This is not valid for 1.4 and 1.5
Only valid for 1.3 and older images.

Nov 11 2024, 10:44 PM
n.fort placed T6097: vrf_zones blocking ipv6 traffic up for grabs.
Nov 11 2024, 10:41 PM · VyOS 1.4 Sagitta (1.4.2)

Oct 31 2024

n.fort added a comment to T6842: Prevent addition of Bond interfaces to Flowtables .

This was supposed to be fixed in https://vyos.dev/T5794
We may need to double check once again

Oct 31 2024, 10:52 AM · VyOS Rolling

Oct 30 2024

n.fort added a comment to T3989: Firewall - Can't delete rule in firewall entry and leave just default-action when firewall entry is in used.

No. It's not applicable for 1.4/1.5

Oct 30 2024, 10:28 AM

Oct 29 2024

n.fort added a comment to T6841: Separate interface and VRF options in firewall zone configuration.

PR: https://github.com/vyos/vyos-1x/pull/4180

Oct 29 2024, 7:18 PM · VyOS 1.5 Circinus, VyOS Rolling
n.fort changed the status of T6841: Separate interface and VRF options in firewall zone configuration from Open to In progress.
Oct 29 2024, 7:04 PM · VyOS 1.5 Circinus, VyOS Rolling
n.fort created T6841: Separate interface and VRF options in firewall zone configuration.
Oct 29 2024, 7:04 PM · VyOS 1.5 Circinus, VyOS Rolling

Oct 23 2024

n.fort added a comment to T6807: Afer the migration from 1.3.x to 1.4.0 "/" character at the end of the users home directory path breaks login.

No constraints for Equuleus: https://github.com/vyos/vyos-1x/blob/equuleus/interface-definitions/system-login.xml.in#L110-L114

Oct 23 2024, 3:50 PM · VyOS Rolling, Bugs

Oct 21 2024

n.fort added a comment to T6793: Firewall Blocking ARP from Podman Container to Gateway.

Can you check adding the next command?

Oct 21 2024, 10:54 AM · Bugs, VyOS Rolling

Oct 8 2024

n.fort closed T6760: Firewall - Add set options of "set policy route" to normal firewall rules as Resolved.
Oct 8 2024, 5:42 PM · VyOS 1.5 Circinus
n.fort closed T6757: Source address for RADIUS auth is not working in OpenConnect server as Resolved.
Oct 8 2024, 5:42 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
n.fort added a comment to T6613: VyOS local system users TACACS+ authorization requests .

Can you check if changing this line https://github.com/vyos/vyos-1x/blob/current/data/templates/login/tacplus_nss.conf.j2#L33 and adding those user helps?
This file can be changed locally in the router: /usr/share/vyos/templates/login/tacplus_nss.conf.j2
Change line:

exclude_users=root,telegraf,radvd,strongswan,tftp,conservr,frr,ocserv,pdns,_chrony,_lldpd,sshd,openvpn,radius_user,radius_priv_user,*{{ ',' + user | join(',') if user is vyos_defined }}

And change it to something like:

Oct 8 2024, 2:39 PM · VyOS 1.4 Sagitta (1.4.2), VyOS 1.5 Circinus, VyOS Rolling

Oct 7 2024

n.fort reassigned T6641: Show command for interface messages from n.fort to HollyGurza.
Oct 7 2024, 11:36 AM · Bugs, VyOS Rolling

Oct 4 2024

n.fort changed the status of T6760: Firewall - Add set options of "set policy route" to normal firewall rules from In progress to Needs testing.
Oct 4 2024, 8:06 PM · VyOS 1.5 Circinus
n.fort closed T6687: NAT - Add support for fqdn entries as Resolved.
Oct 4 2024, 8:05 PM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
n.fort committed rVYOSONEXe846d2c1500d: T6760: firewall: add packet modifications existing in policy route to regular….
Oct 4 2024, 11:21 AM

Oct 3 2024

n.fort added a comment to T6760: Firewall - Add set options of "set policy route" to normal firewall rules.

PR: https://github.com/vyos/vyos-1x/pull/4123

Oct 3 2024, 3:00 PM · VyOS 1.5 Circinus
n.fort changed the status of T6760: Firewall - Add set options of "set policy route" to normal firewall rules from Open to In progress.
Oct 3 2024, 2:50 PM · VyOS 1.5 Circinus
n.fort created T6760: Firewall - Add set options of "set policy route" to normal firewall rules.
Oct 3 2024, 2:49 PM · VyOS 1.5 Circinus
n.fort changed the status of T6757: Source address for RADIUS auth is not working in OpenConnect server from In progress to Needs testing.
Oct 3 2024, 2:43 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
n.fort committed rVYOSONEX289ca9987b14: T6757: Openconnect: fix template for correct config parsing while configuring….
Oct 3 2024, 1:23 PM

Oct 2 2024

n.fort changed the status of T6687: NAT - Add support for fqdn entries from In progress to Needs testing.
Oct 2 2024, 1:34 PM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
n.fort changed the status of T6757: Source address for RADIUS auth is not working in OpenConnect server from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/4120

Oct 2 2024, 1:33 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
n.fort changed the status of T6757: Source address for RADIUS auth is not working in OpenConnect server from Open to Confirmed.
Oct 2 2024, 11:43 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
n.fort created T6757: Source address for RADIUS auth is not working in OpenConnect server.
Oct 2 2024, 11:43 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus

Sep 30 2024

n.fort committed rVYOSONEX4c3d037f036e: T6687: add fqdn support to nat rules..
Sep 30 2024, 2:49 PM

Sep 20 2024

n.fort closed T6723: op-mode command 'show firewall" is not complete as Resolved.
Sep 20 2024, 8:06 PM · VyOS 1.5 Circinus

Sep 18 2024

n.fort committed rVYOSONEX38511df4b376: T6723: firewall: extend op-mode commands <show firewall ..> and a <show log….
Sep 18 2024, 6:38 PM
n.fort changed the status of T6641: Show command for interface messages from Open to In progress.
Sep 18 2024, 3:18 PM · Bugs, VyOS Rolling
n.fort changed the status of T6723: op-mode command 'show firewall" is not complete from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/4084

Sep 18 2024, 2:17 PM · VyOS 1.5 Circinus

Sep 17 2024

n.fort renamed T6723: op-mode command 'show firewall" is not complete from op-mode command 'show filreall" is not complete to op-mode command 'show firewall" is not complete.
Sep 17 2024, 8:30 PM · VyOS 1.5 Circinus
n.fort changed the status of T6723: op-mode command 'show firewall" is not complete from Open to Confirmed.
Sep 17 2024, 8:27 PM · VyOS 1.5 Circinus
n.fort created T6723: op-mode command 'show firewall" is not complete.
Sep 17 2024, 8:27 PM · VyOS 1.5 Circinus
n.fort closed T6647: Zone-based Firewalls on Bridges would flag related DHCP traffic invalid as Resolved.
Sep 17 2024, 3:50 PM · Bugs, VyOS 1.5 Circinus
n.fort closed T6698: Bridge firewall - Add vlan type option as Resolved.
Sep 17 2024, 3:49 PM · VyOS 1.5 Circinus

Sep 3 2024

n.fort changed the status of T6698: Bridge firewall - Add vlan type option from Open to Confirmed.
Sep 3 2024, 3:40 PM · VyOS 1.5 Circinus
n.fort created T6698: Bridge firewall - Add vlan type option.
Sep 3 2024, 3:38 PM · VyOS 1.5 Circinus

Sep 2 2024

n.fort committed rVYOSONEX8e0e1a99e551: T6647: firewall. Introduce patch for accepting ARP and DHCP replies on stateful….
Sep 2 2024, 11:02 AM

Aug 30 2024

n.fort added a comment to T6687: NAT - Add support for fqdn entries.

PR: https://github.com/vyos/vyos-1x/pull/4024

Aug 30 2024, 6:02 PM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
n.fort changed the status of T6687: NAT - Add support for fqdn entries from Open to In progress.
Aug 30 2024, 5:53 PM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
n.fort created T6687: NAT - Add support for fqdn entries.
Aug 30 2024, 5:52 PM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
n.fort closed T6344: multiple ntp listen-address commands not working as Resolved.
Aug 30 2024, 10:49 AM · VyOS 1.4 Sagitta

Aug 29 2024

n.fort added a comment to T6641: Show command for interface messages.

Showing all logs for interface might print more information than it's needed. Maybe a different approach:

Aug 29 2024, 7:24 PM · Bugs, VyOS Rolling
n.fort added a comment to T6344: multiple ntp listen-address commands not working.

PR for docuemntation: https://github.com/vyos/vyos-documentation/pull/1531

Aug 29 2024, 7:10 PM · VyOS 1.4 Sagitta

Aug 26 2024

n.fort added a comment to T6647: Zone-based Firewalls on Bridges would flag related DHCP traffic invalid.

PR: https://github.com/vyos/vyos-1x/pull/4018

Aug 26 2024, 6:24 PM · Bugs, VyOS 1.5 Circinus
n.fort closed T5177: Make the chain policy configurable as Resolved.
Aug 26 2024, 11:46 AM · VyOS 1.5 Circinus

Aug 23 2024

n.fort added a comment to T5177: Make the chain policy configurable.

I think we can close this one

Aug 23 2024, 12:20 PM · VyOS 1.5 Circinus
n.fort closed T6646: 1.3.8 to 1.4.0 config migration fails due to conntrack ignore rule, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
Aug 23 2024, 12:16 PM · VyOS Rolling, Bugs
n.fort closed T6646: 1.3.8 to 1.4.0 config migration fails due to conntrack ignore rule as Resolved.
Aug 23 2024, 12:16 PM · VyOS 1.4 Sagitta (1.4.1)
n.fort closed T5794: Flowtable with Bond Race as Resolved.
Aug 23 2024, 12:15 PM · VyOS Rolling, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
n.fort closed T6636: Show log firewall not printing logs for default-actions for custom ruleset as Resolved.
Aug 23 2024, 12:15 PM · VyOS Rolling, VyOS 1.5 Circinus

Aug 16 2024

n.fort changed the status of T6647: Zone-based Firewalls on Bridges would flag related DHCP traffic invalid from Confirmed to In progress.
Aug 16 2024, 5:44 PM · Bugs, VyOS 1.5 Circinus

Aug 15 2024

n.fort added a comment to T5794: Flowtable with Bond Race.

PR: https://github.com/vyos/vyos-1x/pull/3988

Aug 15 2024, 6:12 PM · VyOS Rolling, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
n.fort closed T6643: IP Address range in firewall rules throws error as Resolved.
Aug 15 2024, 10:42 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus, VyOS Rolling

Aug 14 2024

n.fort committed rVYOSONEX2d953bedd0e4: T6646: conntrack: in ignore rules, if protocols=all, do not append it to the….
Aug 14 2024, 4:34 PM
n.fort committed rVYOSONEX747363e3ecd3: T6636: firewall: fix firewall template in order to write logs for default….
Aug 14 2024, 2:53 PM
n.fort added a comment to T6646: 1.3.8 to 1.4.0 config migration fails due to conntrack ignore rule.

PR: https://github.com/vyos/vyos-1x/pull/3981

Aug 14 2024, 12:16 PM · VyOS 1.4 Sagitta (1.4.1)
n.fort changed the status of T6646: 1.3.8 to 1.4.0 config migration fails due to conntrack ignore rule from Open to In progress.
Aug 14 2024, 11:52 AM · VyOS 1.4 Sagitta (1.4.1)
n.fort changed the status of T6646: 1.3.8 to 1.4.0 config migration fails due to conntrack ignore rule, a subtask of T5938: Migration fail root task for 1.4-rc, from Open to In progress.
Aug 14 2024, 11:52 AM · VyOS Rolling, Bugs

Aug 12 2024

n.fort changed the status of T6643: IP Address range in firewall rules throws error from In progress to Needs testing.
Aug 12 2024, 11:27 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus, VyOS Rolling
n.fort changed the status of T6647: Zone-based Firewalls on Bridges would flag related DHCP traffic invalid from Open to Confirmed.

Config to reproduce the issue:

Aug 12 2024, 11:00 AM · Bugs, VyOS 1.5 Circinus

Aug 10 2024

n.fort committed rVYOSONEXff58f3e5f30d: T6643: firewall: fix ip address range parsing on firewall rules..
Aug 10 2024, 6:48 PM

Aug 9 2024

n.fort changed the status of T6643: IP Address range in firewall rules throws error from Confirmed to In progress.

https://github.com/vyos/vyos-1x/pull/3964

Aug 9 2024, 3:48 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus, VyOS Rolling
n.fort claimed T6643: IP Address range in firewall rules throws error.
Aug 9 2024, 11:18 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus, VyOS Rolling

Aug 7 2024

n.fort closed T6536: Config migration does not work as expected when update from 1.3.2 to 1.4.0 (with NAT with wildcard and sysctl parameters) as Resolved.
Aug 7 2024, 5:01 PM · VyOS 1.4 Sagitta (1.4.1)
n.fort closed T5680: Allow selecting mac-groups in bridge firewall as Resolved.
Aug 7 2024, 5:00 PM · Restricted Project, VyOS 1.5 Circinus
n.fort closed T6631: Error on firewall while using jump-target and no custom ruleset are present as Resolved.

PR https://github.com/vyos/vyos-1x/pull/3901

Aug 7 2024, 4:10 PM · VyOS Rolling, VyOS 1.5 Circinus
n.fort closed T6570: Firewall bridge allways passes traffic to IP layer as Resolved.
Aug 7 2024, 4:10 PM · VyOS Rolling, VyOS 1.5 Circinus

Aug 5 2024

n.fort changed the status of T6636: Show log firewall not printing logs for default-actions for custom ruleset from Open to Confirmed.
Aug 5 2024, 5:42 PM · VyOS Rolling, VyOS 1.5 Circinus
n.fort created T6636: Show log firewall not printing logs for default-actions for custom ruleset.
Aug 5 2024, 5:42 PM · VyOS Rolling, VyOS 1.5 Circinus

Aug 4 2024

n.fort committed rVYOSONEX20551379e8e2: T4072: firewall: extend firewall bridge capabilities, in order to include new….
Aug 4 2024, 7:07 AM
n.fort committed rVYOSONEXa8a9cfe750da: T6570: firewall: add global-option to configure sysctl parameter for….
Aug 4 2024, 7:07 AM
n.fort committed rVYOSONEX7a18c719df1b: T4072: firewall: improve error handling when firewall configuration is wrong..
Aug 4 2024, 7:07 AM
n.fort committed rVYOSONEXfa764927c143: T4072: firewall: extend firewall bridge smoketest.
Aug 4 2024, 7:07 AM
n.fort committed rVYOSONEXc33cd6157ebc: T4072: change same helpers in xml definitions; add notrack action for….
Aug 4 2024, 7:07 AM

Aug 2 2024

n.fort changed the status of T6631: Error on firewall while using jump-target and no custom ruleset are present from Open to In progress.
Aug 2 2024, 11:48 AM · VyOS Rolling, VyOS 1.5 Circinus
n.fort created T6631: Error on firewall while using jump-target and no custom ruleset are present.
Aug 2 2024, 11:48 AM · VyOS Rolling, VyOS 1.5 Circinus

Jul 30 2024

n.fort added a comment to T6570: Firewall bridge allways passes traffic to IP layer.

PR: https://github.com/vyos/vyos-1x/pull/3901

Jul 30 2024, 12:08 PM · VyOS Rolling, VyOS 1.5 Circinus
n.fort changed the status of T5680: Allow selecting mac-groups in bridge firewall from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/3901

Jul 30 2024, 12:08 PM · Restricted Project, VyOS 1.5 Circinus

Jul 29 2024

n.fort closed T6607: Error when deleting VLAN-VNI mapping as Invalid.
Jul 29 2024, 1:31 PM · VyOS 1.5 Circinus

Jul 24 2024

n.fort changed the status of T6570: Firewall bridge allways passes traffic to IP layer from Confirmed to In progress.
Jul 24 2024, 5:41 PM · VyOS Rolling, VyOS 1.5 Circinus
n.fort created T6605: `ConfigError()` behavior is wrong with running `vyos-configd`.
Jul 24 2024, 12:22 PM · VyOS 1.4 Sagitta (1.4.1), VyOS Rolling, VyOS 1.5 Circinus

Jul 18 2024

n.fort claimed T6570: Firewall bridge allways passes traffic to IP layer.
Jul 18 2024, 5:40 PM · VyOS Rolling, VyOS 1.5 Circinus

Jul 12 2024

n.fort changed the status of T6570: Firewall bridge allways passes traffic to IP layer from Open to Confirmed.
Jul 12 2024, 12:13 PM · VyOS Rolling, VyOS 1.5 Circinus
n.fort created T6570: Firewall bridge allways passes traffic to IP layer.
Jul 12 2024, 12:13 PM · VyOS Rolling, VyOS 1.5 Circinus

Jul 4 2024

n.fort added a comment to T5654: Migrate policy local-route.

PR: https://github.com/vyos/vyos-1x/pull/3781

Jul 4 2024, 5:07 PM · VyOS Rolling
n.fort closed T6488: Firewall op mode output incomplete as Resolved.
Jul 4 2024, 11:01 AM · VyOS 1.5 Circinus
n.fort changed the status of T6536: Config migration does not work as expected when update from 1.3.2 to 1.4.0 (with NAT with wildcard and sysctl parameters) from In progress to Needs testing.
Jul 4 2024, 10:59 AM · VyOS 1.4 Sagitta (1.4.1)

Jul 3 2024

n.fort changed the status of T5654: Migrate policy local-route from Open to In progress.
Jul 3 2024, 4:05 PM · VyOS Rolling
n.fort committed rVYOSONEX148af29b6841: T6536: nat: add migration script that replaces wildcard charater supported in 1..
Jul 3 2024, 2:32 PM
n.fort committed rVYOSONEX66ec278393db: T6536: change wildcard character from + to * - extend fix to interfaces defined….
Jul 3 2024, 2:32 PM

Jul 2 2024

n.fort changed the status of T6536: Config migration does not work as expected when update from 1.3.2 to 1.4.0 (with NAT with wildcard and sysctl parameters) from Open to In progress.

PR: https://github.com/vyos/vyos-1x/pull/3749

Jul 2 2024, 12:32 PM · VyOS 1.4 Sagitta (1.4.1)

Jun 25 2024

n.fort committed rVYOSONEXecf3141d5b5f: T3900: extend latest fix for firewall raw implementation to ipv6..
Jun 25 2024, 1:05 PM

Jun 24 2024

n.fort claimed T6266: Firewall flowtable ability to set timeout for TCP and UDP flow.
Jun 24 2024, 11:07 AM · VyOS Rolling
n.fort added a comment to T6266: Firewall flowtable ability to set timeout for TCP and UDP flow.

Now we have:

Jun 24 2024, 11:07 AM · VyOS Rolling

Jun 20 2024

n.fort committed rVYOSONEX7829229e8a91: T3900: firewall: fix for initial implementation - remove jump to state policy….
Jun 20 2024, 8:01 PM