PR for fix in vyos-build: https://github.com/vyos/vyos-build/pull/501
PR for smoketest (modified because of change in build): https://github.com/vyos/vyos-1x/pull/2991
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Advanced Search
Feb 12 2024
Feb 6 2024
Feb 5 2024
What version? Can you upgrade to 1.4?
Feb 2 2024
Feb 1 2024
Jan 26 2024
Jan 23 2024
Pr for 1.5: https://github.com/vyos/vyos-1x/pull/2887
Jan 22 2024
Jan 12 2024
Jan 11 2024
Jan 10 2024
Quick test done on a VM with 1 CPU and 1G RAM:
[email protected]# for I in {1..2542}; do set firewall ipv6 name Test rule $I action accept ; set firewall ipv6 name Test rule $I destination port $I; set firewall ipv6 name Test rule $I protocol tcp ; done [email protected]# time commit
Jan 9 2024
I suggest changing order just as a cosmetic fix: feels more reasonable/readable to parse first "incoming", and then "outgoing"
Changes that seems to be needed only in migration script https://github.com/vyos/vyos-1x/blob/current/src/migration-scripts/firewall/10-to-11:
- Use accept action for base-chains (it's done, no change needed here).
- Migrate action=accept to action=return on every rule.
- fix order and ensure all "in" rules are applied first.
PR for Equuleus: https://github.com/vyos/vyos-1x/pull/2776
Jan 8 2024
Jan 5 2024
New PR for dynamic address groups: https://github.com/vyos/vyos-1x/pull/2756
Jan 4 2024
Jan 3 2024
Jan 2 2024
Dec 27 2023
Dec 22 2023
I stil haven't tried nat64, but quick config example, for nat64 for single ipv6 address is not allowed by our cli:
Dec 21 2023
Configuration shared seems to work correctly on latest version:
Dec 11 2023
Dec 7 2023
Dec 6 2023
In the past any interface was supported, and it has been removed.
If you want to match any interface, you can complete remove interface matcher from the rule, since it's not mandatory (as it was in the past):
delete nat source rule 110 outbound-interface
Dec 5 2023
Nov 29 2023
Nov 28 2023
Nov 27 2023
The problem is that, comparing to command output on 1.3, it only show the leases granted by the router (and doesn't contain leases granted by the second router, regardless of states primary|secondary.
So user might think synchronization between routers defined in fail-over mode is broken.
But this is not the case. As explained in the description, all information about leases, granted by both routers, is present on lease files on both routers.
Nov 24 2023
And going further, we may create an extra column, in order to print if the lease was granted by Local-Router or by fail-over router..
Example:
Changing this line: https://github.com/vyos/vyos-1x/blob/current/src/op_mode/dhcp.py#L117C9-L117C107
Nov 23 2023
We'll discuss this internally, but for sure a fix should be applied.
Thanks for such a detailed bug-report.
Nov 22 2023
PR for bridge: https://github.com/vyos/vyos-1x/pull/2528
Nov 21 2023
Nov 16 2023
Re-Opening. this need to be extended to bridge firewall
Nov 14 2023
New patch for migration scripts in 1.5: https://github.com/vyos/vyos-1x/pull/2480
Nov 13 2023
PR for Sagitta: https://github.com/vyos/vyos-1x/pull/2478
PR for Sagitta: https://github.com/vyos/vyos-1x/pull/2478