Page MenuHomeVyOS Platform
Feed All Stories

Feb 3 2022

Viacheslav added a comment to T4193: Add support for transparent firewall.

PR for op-mode https://github.com/vyos/vyos-1x/pull/1204

Feb 3 2022, 4:11 PM · VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX1920c4faa9d2: firewall-bridge: T4193: Add verify for action reject (authored by Viacheslav).
Feb 3 2022, 1:57 PM
zsdc assigned T4176: VyOS CLI command: show openvpn server/client does not display output to RyVolodya.
Feb 3 2022, 11:29 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
zsdc assigned T4192: OpenVPN custom option for "--client-to-client" causes configuration error to RyVolodya.
Feb 3 2022, 11:26 AM · VyOS 1.3 Equuleus (1.3.0)
sarthurdev committed rVYOSONEX9f7f1ebb15a2: firewall: T4178: Fix only inverse matching on tcp flags.
Feb 3 2022, 7:27 AM
GitHub <noreply@github.com> committed rVYOSONEX26774b890443: Merge pull request #1201 from sarthurdev/T4178_2 (authored by c-po).
Feb 3 2022, 7:27 AM
c-po closed T4218: firewall: rule name is not allowed to start with a number as Resolved.
Feb 3 2022, 7:05 AM · VyOS 1.4 Sagitta
c-po added a comment to T4218: firewall: rule name is not allowed to start with a number.

Thanks - works again

Feb 3 2022, 7:05 AM · VyOS 1.4 Sagitta

Feb 2 2022

sarthurdev changed the status of T4178: policy based routing tcp flags issue from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1201

Feb 2 2022, 11:36 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4178: policy based routing tcp flags issue from Needs testing to In progress.

Adding this issue to this task: https://forum.vyos.io/t/firewall-configuration-issue-after-upgrade/8414

Feb 2 2022, 11:07 PM · VyOS 1.4 Sagitta
Unknown Object (User) created T4226: VRRP transition-script does not work for groups name which contains -(minus) sign.
Feb 2 2022, 8:24 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T3872: Add configurable telegraf monitoring service.

PR https://github.com/vyos/vyos-1x/pull/1200
Fix for telegraf template/scripts for services.

Feb 2 2022, 6:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4194: prefix-list no check for duplicate entries from Open to Needs testing.
Feb 2 2022, 4:59 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4210: NAT source/destination negated ports throws an error.

I've used for these tests (VyOS 1.4-rolling-202202010836)
The same situation in general when you want to use "!".
Bad exampels.

set nat source rule 10 destination port !1-5
set nat source rule 10 destination port !22
set nat source rule 10 destination port !http
set nat source rule 10 destination port telnet,!http,!123,1001-1005
set nat source rule 10 destination port telnet,http,!123,1001-1005
Feb 2 2022, 2:54 AM · VyOS 1.4 Sagitta

Feb 1 2022

Unknown Object (User) added a comment to T4218: firewall: rule name is not allowed to start with a number.

( VyOS 1.4-rolling-202202010836)- Rule name which starts with a number work well.

Feb 1 2022, 9:44 PM · VyOS 1.4 Sagitta
mTx87 closed T4225: Performance degration with latest rolling release as Resolved.
Feb 1 2022, 2:04 PM · VyOS 1.4 Sagitta
mTx87 created T4225: Performance degration with latest rolling release.
Feb 1 2022, 1:50 PM · VyOS 1.4 Sagitta
hensur added a comment to T4151: IPV6 local PBR Support.

docs: https://github.com/vyos/vyos-documentation/pull/707

Feb 1 2022, 12:45 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
SrividyaA added a comment to T4222: Support for TWAMP as round-trip metric.

I have found the following links:

Feb 1 2022, 12:22 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
mTx87 added a comment to T4216: Firewall: can't use negated groups in firewall rules.

tested my previous code in latest rolling, looking good so far.
no errors on commiting.

Feb 1 2022, 12:02 PM · VyOS 1.4 Sagitta
adestis closed T4198: Error shown on commit as Resolved.
Feb 1 2022, 10:56 AM · VyOS 1.3 Equuleus (1.3.0)
adestis added a comment to T4198: Error shown on commit.

Seems like this is already handled in T4101

Feb 1 2022, 10:51 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T4138: NAT configuration allows to set incorrect port range and invalid port as Resolved.
Feb 1 2022, 9:31 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4222: Support for TWAMP as round-trip metric.

Is there any Linux implementation?

Feb 1 2022, 9:04 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
c-po added a comment to T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso).

reverted broken commit

Feb 1 2022, 7:02 AM · VyOS 1.4 Sagitta
c-po closed T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso) as Resolved.
Feb 1 2022, 7:02 AM · VyOS 1.4 Sagitta
c-po added a comment to T4220: Commit broke dhclient 78b247b724f74bdabab0706aaa7f5b00e5809bc1.

reverted commit

Feb 1 2022, 7:02 AM · VyOS 1.4 Sagitta
c-po added a reverting change for rVYOSONEX78b247b724f7: dhclient: T3392: remove /usr/sbin prefix from iproute2 ip command: rVYOSONEXbf549b34e7da: Revert "dhclient: T3392: remove /usr/sbin prefix from iproute2 ip command".
Feb 1 2022, 7:02 AM
c-po committed rVYOSONEXbf549b34e7da: Revert "dhclient: T3392: remove /usr/sbin prefix from iproute2 ip command".
Feb 1 2022, 7:02 AM
c-po closed T4220: Commit broke dhclient 78b247b724f74bdabab0706aaa7f5b00e5809bc1 as Resolved.
Feb 1 2022, 7:02 AM · VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso) from Open to Confirmed.
Feb 1 2022, 12:32 AM · VyOS 1.4 Sagitta
mshipman updated the task description for T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso).
Feb 1 2022, 12:27 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso).

Confirm
VyOS 1.4-rolling-202201291849

Feb 1 2022, 12:25 AM · VyOS 1.4 Sagitta
mshipman added a comment to T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso).

My hunch would be that this is the breaking commit, given the context:

Feb 1 2022, 12:00 AM · VyOS 1.4 Sagitta

Jan 31 2022

mshipman created T4224: Ethernet interfaces configured for DHCP not working on latest rolling snapshot (vyos-1.4-rolling-202201291849-amd64.iso).
Jan 31 2022, 9:58 PM · VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.174 / 5.10.94 to Update Linux Kernel to v5.4.175 / 5.10.95.
Jan 31 2022, 8:59 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEX494ca8ffa043: upnpd: T3420: code cleanup.
Jan 31 2022, 8:57 PM
c-po committed rVYOSONEX2ac8376ca1b7: upnpd: T3420: use proper include directives.
Jan 31 2022, 8:57 PM
c-po committed rVYOSONEX3dc698f18bc8: smoketest: upnpd: T3420: refine code and re-use paths.
Jan 31 2022, 8:57 PM
hensur committed rVYOSONEXc6c562eca6ff: policy: T4219: add local-route(6) incoming-interface.
Jan 31 2022, 6:27 PM
GitHub <noreply@github.com> committed rVYOSONEXb3066e73ff48: Merge pull request #1196 from hensur/current-ipv6-local-route-iif (authored by c-po).
Jan 31 2022, 6:27 PM
sarthurdev committed rVYOSONEXed67750b94e8: firewall: T4218: Adds a prefix to all user defined chains.
Jan 31 2022, 6:26 PM
sarthurdev committed rVYOSONEX985a9e8536cb: firewall: T4216: Add support for negated firewall groups.
Jan 31 2022, 6:26 PM
sarthurdev committed rVYOSONEX8532f2c391e8: policy: T4213: Fix duplicate commands from multiple rules with single table.
Jan 31 2022, 6:26 PM
sarthurdev committed rVYOSONEXfafd25143d46: firewall: T2199: Add constraint for tagnode names.
Jan 31 2022, 6:26 PM
sarthurdev committed rVYOSONEXff2cc45f8ba6: firewall: T2199: Fix errors when referencing an empty chain.
Jan 31 2022, 6:26 PM
GitHub <noreply@github.com> committed rVYOSONEX36e54482a242: Merge pull request #1199 from sarthurdev/T4218 (authored by c-po).
Jan 31 2022, 6:26 PM
GitHub <noreply@github.com> committed rVYOSONEX3aa1ec3f03a9: Merge pull request #1198 from vyos/force_to_list (authored by c-po).
Jan 31 2022, 6:26 PM
danielpo added a comment to T4223: policy route cannot have several entries with the same table.

Thanks!😀

Jan 31 2022, 5:25 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4216: Firewall: can't use negated groups in firewall rules from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1199

Jan 31 2022, 5:06 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4218: firewall: rule name is not allowed to start with a number from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1199

Jan 31 2022, 5:06 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4223: policy route cannot have several entries with the same table from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1199

Jan 31 2022, 5:05 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4223: policy route cannot have several entries with the same table from Open to In progress.

I already have a fix for this from your comment on T4213. Will have it included in a PR shortly.

Jan 31 2022, 4:47 PM · VyOS 1.4 Sagitta
danielpo created T4223: policy route cannot have several entries with the same table.
Jan 31 2022, 4:39 PM · VyOS 1.4 Sagitta
SrividyaA created T4222: Support for TWAMP as round-trip metric.
Jan 31 2022, 3:11 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX84d790b65e13: T4221: add force_to_list Jinja2 filter.
Jan 31 2022, 12:56 PM
dmbaturin triaged T4221: Add a template filter for converting scalars to single-item lists as Low priority.
Jan 31 2022, 12:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1)

Jan 30 2022

dmbaturin committed rVYOSONEX35f7cac7750c: T4193: handle groups with only one element correctly.
Jan 30 2022, 1:28 PM
dmbaturin committed rVYOSONEX0c265e420bdf: T4193: bail out early if bridge firewall policy is not assigned.
Jan 30 2022, 1:28 PM
dmbaturin committed rVYOSONEX793185dc09d5: T4193: Remove a debug print.
Jan 30 2022, 1:28 PM
dmbaturin committed rVYOSONEXdcad12c21979: T4193: fix module imports.
Jan 30 2022, 1:28 PM
dmbaturin committed rVYOSONEX3700c3780ede: firewall-bridge: T4193: Checks if firewall or group not configured (authored by Viacheslav).
Jan 30 2022, 1:28 PM
danielpo created T4220: Commit broke dhclient 78b247b724f74bdabab0706aaa7f5b00e5809bc1.
Jan 30 2022, 8:09 AM · VyOS 1.4 Sagitta
Rhongomiant added a comment to T4206: Policy Based Routing with DHCP Interface Issue.

I don't know what I'm building. How can I be sure I'm actually building 1.3.0 rather than 1.4? I ask because when I boot off the build I compiled I get the following message at the start of the boot process. Is it 1.3.0 or sagitta (1.4)?

Jan 30 2022, 6:14 AM · VyOS 1.3 Equuleus (1.3.2)

Jan 29 2022

Unknown Object (User) added a comment to T4218: firewall: rule name is not allowed to start with a number.

The same situation if you set the number or special symbol.

Jan 29 2022, 11:18 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4218: firewall: rule name is not allowed to start with a number from Open to In progress.
Jan 29 2022, 10:34 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4216: Firewall: can't use negated groups in firewall rules from Confirmed to In progress.
Jan 29 2022, 10:34 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4214: [DHCP] static route dhcp-interface issues.

I've checked the same scenario on the cisco router.

Jan 29 2022, 10:04 PM · VyOS 1.5 Circinus, VyOS Rolling
hensur committed rVYOSONEXc501ae0fdc5d: policy: T4151: remove all previous rules on edit.
Jan 29 2022, 6:41 PM
hensur committed rVYOSONEX87d93efc27d8: policy: T4151: bugfix smoketest.
Jan 29 2022, 6:41 PM
GitHub <noreply@github.com> committed rVYOSONEX0a0d4abc02da: Merge pull request #1195 from hensur/current-ipv6-local-route (authored by c-po).
Jan 29 2022, 6:41 PM
sarthurdev committed rVYOSONEX1c828cc5a1dc: firewall: T4178: Fix dict_keys issue with tcp flags.
Jan 29 2022, 6:31 PM
GitHub <noreply@github.com> committed rVYOSONEXd679e9517657: Merge pull request #1197 from sarthurdev/T4178_1 (authored by c-po).
Jan 29 2022, 6:31 PM
n.fort closed T4153: Monitor bandwidth-test initiate not working as Resolved.
Jan 29 2022, 5:33 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jack9603301 committed rVYOSONEX14750f65db2d: upnpd: T3420: Add miniupnpd-nftables package.
Jan 29 2022, 5:08 PM
jack9603301 committed rVYOSONEX600d0c76750a: upnpd: T3420: Add the UPnP command line.
Jan 29 2022, 5:08 PM
jack9603301 committed rVYOSONEXb57b048623d0: upnpd: T3420: Implement features.
Jan 29 2022, 5:08 PM
jack9603301 committed rVYOSONEXc7cdb87fa09a: upnpd: T3420: Fix IPv6 errors.
Jan 29 2022, 5:08 PM
GitHub <noreply@github.com> committed rVYOSONEX8aa7ea8f6c84: Merge pull request #789 from jack9603301/T3420 (authored by dmbaturin).
Jan 29 2022, 5:08 PM
hensur added a comment to T4219: support incoming-interface (iif) in local PBR .

PR: https://github.com/vyos/vyos-1x/pull/1196

Jan 29 2022, 12:51 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
hensur claimed T4219: support incoming-interface (iif) in local PBR .
Jan 29 2022, 12:40 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
hensur created T4219: support incoming-interface (iif) in local PBR .
Jan 29 2022, 12:39 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
hensur added a comment to T4151: IPV6 local PBR Support.

PR: https://github.com/vyos/vyos-1x/pull/1195

Jan 29 2022, 12:33 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Rhongomiant added a comment to T4207: Policy Based Route Issue with Rules for Multiple Tables.

Failover is handled by my firewall which is upstream of VyOS which I am using more as a router than anything. The commit you listed I believe is actually the fix for T4206, not for this, but I can certainly try that to see if I'm up and running and to see if the issue I'm reporting here is resolved, since I have only tried this setup in 1.3.0 RC6. I'm not sure why you'd think I'd need " failover with custom hook-scripts" for this issue. All I'm trying to do is have a PBR for traffic with the destination IP of local VyOS interfaces to use the main table rather than the vrf table. I also have an issue where if I ping the IP on the FIOS WAN interface from upstream, the reply traffic from the VyOS is sent downstream to the FiOS gateway, so this fails. However, the VyOS isn't doing that for the WOW! WAN interface, and I get the replies as expected. So it seems there are strange things happening. Either things not being cleaned up and/or not being set up right.

Jan 29 2022, 11:27 AM · Bugs, VyOS 1.3 Equuleus (1.3.8)

Jan 28 2022

Unknown Object (User) added a comment to T4215: Change the description of the "reboot in" command..

Good question. I missed this moment.
So, if you want to reload in some minutes, VYOS offered you two variants:

  1. To choose between 1 and 99
  2. To set time when you want to reload VYOS if 99 minutes too short for you (for example 10:00, 12:45, 23:59, and so on)

But descriptions of thees command doesn't have enough information about it.

Jan 28 2022, 9:52 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po assigned T4218: firewall: rule name is not allowed to start with a number to sarthurdev.
Jan 28 2022, 9:22 PM · VyOS 1.4 Sagitta
c-po created T4218: firewall: rule name is not allowed to start with a number.
Jan 28 2022, 9:22 PM · VyOS 1.4 Sagitta
c-po closed T4217: firewall: port-group requires protocol to be set - but not in VyOS 1.3 as Resolved.
Jan 28 2022, 9:21 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX78b247b724f7: dhclient: T3392: remove /usr/sbin prefix from iproute2 ip command.
Jan 28 2022, 9:16 PM
c-po committed rVYOSONEX137c9b8b4c01: firewall: T4217: install protocol tcp_udp if port group does not use a protocol.
Jan 28 2022, 9:16 PM
c-po changed the status of T4217: firewall: port-group requires protocol to be set - but not in VyOS 1.3 from Open to In progress.
Jan 28 2022, 9:11 PM · VyOS 1.4 Sagitta
c-po created T4217: firewall: port-group requires protocol to be set - but not in VyOS 1.3.
Jan 28 2022, 9:11 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4209: Firewall incorrect handler for recent count and time.

I've actually found a way to define this properly, resulting rule now looks like below:

tcp dport { 22 } add @FOO_30 { ip saddr limit rate over 4/minute burst 4 packets } counter packets 3 bytes 156 reject comment "FOO-30"
ct state { new } tcp dport { 22 } counter packets 5 bytes 260 return comment "FOO-40"
Jan 28 2022, 6:00 PM · VyOS 1.4 Sagitta
Viacheslav closed T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses as Resolved.
Jan 28 2022, 5:31 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
sarthurdev changed the status of T4216: Firewall: can't use negated groups in firewall rules from Open to Confirmed.
Jan 28 2022, 5:02 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4198: Error shown on commit.

@adestis https://github.com/vyos/vyatta-config-mgmt/tree/equuleus

Jan 28 2022, 4:56 PM · VyOS 1.3 Equuleus (1.3.0)
adestis added a comment to T4198: Error shown on commit.

I could commit a merge request but I have not figured out in which repo the file is located.

Jan 28 2022, 3:38 PM · VyOS 1.3 Equuleus (1.3.0)
adestis added a comment to T4198: Error shown on commit.

@Viacheslav steps to reproduce:

Jan 28 2022, 3:35 PM · VyOS 1.3 Equuleus (1.3.0)
adestis updated the task description for T4198: Error shown on commit.
Jan 28 2022, 3:15 PM · VyOS 1.3 Equuleus (1.3.0)
mTx87 created T4216: Firewall: can't use negated groups in firewall rules.
Jan 28 2022, 2:51 PM · VyOS 1.4 Sagitta