Page MenuHomeVyOS Platform
Feed All Stories

Jul 26 2022

aderouineau added a comment to T4497: ping cannot force ipv4 or ipv6.

@n.fort source-address is useful especially when more precision is needed. At the moment its use is cumbersome as it does not provide help hint on the addresses assigned to the router, forcing an operator to first list those addresses.

Jul 26 2022, 2:14 AM · VyOS 1.4 Sagitta
aderouineau added a comment to T4492: Incorrect list of neighbors in help for "show bgp vrf VRF neighbors".

As of 1.4-rolling-202207250217 this is still not resolved.

Jul 26 2022, 2:10 AM · VyOS 1.4 Sagitta
aderouineau closed T4495: Combine BGP reset op commands as Resolved.

I can confirm that at least as of version 1.4-rolling-202207250217the op commands have been merged:

vyos@vyos-lab:~$ reset bgp
Possible completions:
  <x.x.x.x>     BGP IPv4/IPv6 neighbor to clear
  <h:h:h:h:h:h:h:h>
  1-4294967295  Reset peers with the AS number
  all           Clear all peers
  external      Reset all external peers
  ipv4          IPv4 Address Family
  ipv6          IPv6 Address Family
  l2vpn         Layer 2 Virtual Private Network Address Family
  peer-group    Reset all members of peer-group
  prefix        Clear bestpath and re-advertise
  vrf           Virtual Routing and Forwarding (VRF)
Jul 26 2022, 2:09 AM · VyOS 1.4 Sagitta
aderouineau created T4570: Exception when trying to set up VXLAN over Wireguard.
Jul 26 2022, 2:01 AM · VyOS 1.4 Sagitta

Jul 25 2022

aalmenar added a comment to T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6.

@c-po which one is the new syntax?

Jul 25 2022, 10:35 PM · VyOS Rolling
aalmenar closed T4474: Adding more than 1 prefix-list is ignored as Invalid.
Jul 25 2022, 10:33 PM
aalmenar added a comment to T4474: Adding more than 1 prefix-list is ignored.

@Viacheslav i believe this one can be closed ge and le where inverted order until i found out the error.

Jul 25 2022, 10:33 PM
c-po committed rVYOSONEX8274e9706adf: bgp: T4560: neighbor/peer-group local-as option is only allowed for eBGP.
Jul 25 2022, 7:10 PM
c-po closed T4560: VRF and BGP neighbor local-as error as Resolved.
Jul 25 2022, 6:52 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX96d2939780dc: fastnetmon: T2659: PID file location is static and can't be changed.
Jul 25 2022, 6:20 PM
Viacheslav committed rVYOSONEX870fe6c828a8: ipsec: T4568: Fix debug IPsec peer.
Jul 25 2022, 5:38 PM
GitHub <noreply@github.com> committed rVYOSONEXd9ef43e31106: Merge pull request #1433 from sever-sever/T4568 (authored by c-po).
Jul 25 2022, 5:38 PM
aalmenar committed rVYOSONEXbd119de6fd32: fastnetmon: T4556: Allow configure white_list_path and populate with….
Jul 25 2022, 5:36 PM
GitHub <noreply@github.com> committed rVYOSONEX55d7ff854cfe: Merge pull request #1434 from aalmenar/T4556 (authored by c-po).
Jul 25 2022, 5:36 PM
jestabro added a comment to T4554: Implement GraphQL resolvers for standardized op-mode scripts.

https://github.com/vyos/vyos-1x/pull/1432

Jul 25 2022, 3:24 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4544: Generate schema definitions from standardized op-mode scripts.

https://github.com/vyos/vyos-1x/pull/1432

Jul 25 2022, 3:24 PM · VyOS 1.4 Sagitta
jestabro closed T4567: Merge experimental branch of GraphQL development as Resolved.
Jul 25 2022, 3:11 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4556: fastnetmon: Allow configure white_list_path and populate with hosts/networks that should be ignored. from Open to In progress.
Jul 25 2022, 1:45 PM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEXdf7348da1116: Merge pull request #1426 from sever-sever/T4545-nat (authored by c-po).
Jul 25 2022, 1:27 PM
Viacheslav committed rVYOSONEX9228bd31d008: nat: T4545: Rewrite show nat source rules script.
Jul 25 2022, 1:27 PM
Viacheslav committed rVYOSONEX179380776360: IPsec: T4552: Fix reset vpn ipsec peer.
Jul 25 2022, 1:27 PM
GitHub <noreply@github.com> committed rVYOSONEXc8ffb9a03c70: Merge pull request #1428 from sever-sever/T4552 (authored by c-po).
Jul 25 2022, 1:27 PM
Viacheslav committed rVYOSONEX4caffa16a076: vrf: T4562: Rewrite show vrf to vyos.opmode format.
Jul 25 2022, 1:26 PM
GitHub <noreply@github.com> committed rVYOSONEXfd4bda3c791a: Merge pull request #1430 from sever-sever/T4562 (authored by c-po).
Jul 25 2022, 1:26 PM
Viacheslav created T4569: Rewrite show bridge to new format.
Jul 25 2022, 1:07 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4568: show vpn debug peer doesn't work.

PR https://github.com/vyos/vyos-1x/pull/1433

Jul 25 2022, 12:55 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4568: show vpn debug peer doesn't work from Open to In progress.
Jul 25 2022, 12:00 PM · VyOS 1.4 Sagitta
Viacheslav created T4568: show vpn debug peer doesn't work.
Jul 25 2022, 11:55 AM · VyOS 1.4 Sagitta
n.fort added a comment to T4497: ping cannot force ipv4 or ipv6.

Agree that both options are not available in cli.. But, you can use source-address:

Jul 25 2022, 11:37 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4474: Adding more than 1 prefix-list is ignored.

I can't reproduce it (VyOS 1.4-rolling-202207220217):

set policy prefix-list BARRA32 rule 5 action 'permit'
set policy prefix-list BARRA32 rule 5 ge '32'
set policy prefix-list BARRA32 rule 5 le '32'
set policy prefix-list BARRA32 rule 5 prefix '0.0.0.0/0'
set policy prefix-list UTRSv4s25 rule 5 action 'permit'
set policy prefix-list UTRSv4s25 rule 5 le '25'
set policy prefix-list UTRSv4s25 rule 5 prefix '0.0.0.0/0'
set policy prefix-list6 BARRA128 rule 5 action 'permit'
set policy prefix-list6 BARRA128 rule 5 ge '128'
set policy prefix-list6 BARRA128 rule 5 le '128'
set policy prefix-list6 BARRA128 rule 5 prefix '::/0'
set policy prefix-list6 UTRSv6s49 rule 5 action 'permit'
set policy prefix-list6 UTRSv6s49 rule 5 le '49'
set policy prefix-list6 UTRSv6s49 rule 5 prefix '::/0'
Jul 25 2022, 10:40 AM
Viacheslav closed T1233: ipsec vpn sa showing down, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jul 25 2022, 9:42 AM · VyOS 1.4 Sagitta
Viacheslav closed T1233: ipsec vpn sa showing down as Resolved.

Fixed in https://github.com/vyos/vyos-1x/commit/201257fe60afc40d101d162cc08e2878dfa3467b

Jul 25 2022, 9:42 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T3496: show conntrack-sync statistics shows a warning.
Jul 25 2022, 9:40 AM · VyOS Rolling
Viacheslav added a parent task for T3496: show conntrack-sync statistics shows a warning: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 25 2022, 9:40 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3723: op-mode IPSec show vpn ipsec sa output with underscores.

Will be fixed with syntax migration in T4118

Jul 25 2022, 9:38 AM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX8e6f4ee3a95f: graphql: T3993: use existing key auth from REST framework.
Jul 25 2022, 9:34 AM
jestabro committed rVYOSONEXb882e997e18c: graphql: T3993: disable introspection unless set in CLI.
Jul 25 2022, 9:34 AM
jestabro committed rVYOSONEX02beb3ead378: graphql: T3993: add interface-definition for gql.
Jul 25 2022, 9:34 AM
jestabro committed rVYOSONEXf9bd803ffe8a: graphql: T4413: add support for a system status query.
Jul 25 2022, 9:34 AM
jestabro committed rVYOSONEX40d754b44d95: graphql: T4413: update 'SystemStatus' query for standardized op-mode.
Jul 25 2022, 9:34 AM
jestabro committed rVYOSONEXf9d6f0890140: graphql: T3993: add smoketest for GraphQL key authorization.
Jul 25 2022, 9:34 AM
GitHub <noreply@github.com> committed rVYOSONEX3337aedd5f7f: Merge pull request #1431 from jestabro/gql-dev (authored by dmbaturin).
Jul 25 2022, 9:34 AM
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T3937: Rewrite "show system memory" in Python to make it usable as a library function.
Jul 25 2022, 9:33 AM · VyOS Rolling
Viacheslav added a parent task for T3937: Rewrite "show system memory" in Python to make it usable as a library function: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 25 2022, 9:33 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4271: bgp: show ipv6 bgp summary doesn't display neighbor information.

@NikolayP Try the next command:

Jul 25 2022, 9:32 AM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav closed T4493: Incorrect help for "show bgp neighbors" as Resolved.
Jul 25 2022, 9:01 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets.
Jul 25 2022, 8:56 AM · VyOS Rolling
Viacheslav added a parent task for T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 25 2022, 8:56 AM · VyOS 1.4 Sagitta

Jul 24 2022

jestabro created T4567: Merge experimental branch of GraphQL development.
Jul 24 2022, 7:46 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXa5580f2fc6f7: snmp: T2763: Add protocol TCP for service SNMP.
Jul 24 2022, 4:33 PM
GitHub <noreply@github.com> committed rVYOSONEX4168e03721b2: Merge pull request #1416 from sever-sever/T2763-eq (authored by dmbaturin).
Jul 24 2022, 4:33 PM
alainlamar updated the task description for T4566: Cannot log in on serial console on Equuleus v1.3.1.
Jul 24 2022, 5:52 AM · VyOS 1.3 Equuleus (1.3.6)
alainlamar updated the task description for T4566: Cannot log in on serial console on Equuleus v1.3.1.
Jul 24 2022, 5:50 AM · VyOS 1.3 Equuleus (1.3.6)
alainlamar created T4566: Cannot log in on serial console on Equuleus v1.3.1.
Jul 24 2022, 5:48 AM · VyOS 1.3 Equuleus (1.3.6)

Jul 23 2022

sajiby3k created T4565: vlan aware bridge not working .
Jul 23 2022, 7:44 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.3 Equuleus (1.3.2)
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4145: Conntrack table not showing after firewall rewriting.
Jul 23 2022, 5:44 PM · VyOS Rolling
Viacheslav added a parent task for T4145: Conntrack table not showing after firewall rewriting: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:44 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4552: Unable to reset IPsec IPv6 peer.
Jul 23 2022, 5:41 PM · VyOS Rolling
Viacheslav added a parent task for T4552: Unable to reset IPsec IPv6 peer: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:41 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4543: Show source nat statistics shows incorrect interface.
Jul 23 2022, 5:40 PM · VyOS Rolling
Viacheslav added a parent task for T4543: Show source nat statistics shows incorrect interface: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:40 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4531: NAT op-mode errors with exclude rules.
Jul 23 2022, 5:39 PM · VyOS Rolling
Viacheslav added a parent task for T4531: NAT op-mode errors with exclude rules: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4545: Rewrite show nat source rules.
Jul 23 2022, 5:39 PM · VyOS Rolling
Viacheslav added a parent task for T4545: Rewrite show nat source rules: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4562: Rewrite show vrf to new format.
Jul 23 2022, 5:38 PM · VyOS Rolling
Viacheslav added a parent task for T4562: Rewrite show vrf to new format: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:38 PM · VyOS 1.4 Sagitta
Viacheslav created T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Jul 23 2022, 5:38 PM · VyOS Rolling
Viacheslav added a comment to T4531: NAT op-mode errors with exclude rules.

It will be fixed in T4545
PR https://github.com/vyos/vyos-1x/pull/1426

Jul 23 2022, 5:28 PM · VyOS 1.4 Sagitta
alainlamar updated the task description for T4563: Docker build system is broken (Equuleus v1.3.1).
Jul 23 2022, 2:10 PM · VyOS 1.3 Equuleus (1.3.6)
alainlamar created T4563: Docker build system is broken (Equuleus v1.3.1).
Jul 23 2022, 1:59 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T4562: Rewrite show vrf to new format.

PR https://github.com/vyos/vyos-1x/pull/1430

vyos@r14:~$ show vrf
Name    State    MAC address        Flags                     Interfaces
------  -------  -----------------  ------------------------  ---------------
foo     up       be:e3:5c:f1:54:99  noarp,master,up,lower_up  eth1.50,eth1.55
bar     up       1e:7c:94:da:e0:35  noarp,master,up,lower_up  n/a
vyos@r14:~$
Jul 23 2022, 1:57 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4562: Rewrite show vrf to new format from "Bug" to "Feature Request".
Jul 23 2022, 1:42 PM · VyOS 1.4 Sagitta
Viacheslav created T4562: Rewrite show vrf to new format.
Jul 23 2022, 1:42 PM · VyOS 1.4 Sagitta
goodNETnick <pknet@ya.ru> committed rVYOSONEXdbadbbf6453d: route-map: T4542: match prefix-len Kernel notice.
Jul 23 2022, 10:14 AM
GitHub <noreply@github.com> committed rVYOSONEXe1e9f690d3eb: Merge pull request #1427 from goodNETnick/rm-pref-len (authored by c-po).
Jul 23 2022, 10:14 AM
Unknown Object (User) added a comment to T4542: route-map: "match prefix-len" incorrect behavior.

New PR (Notice corrected):
https://github.com/vyos/vyos-1x/pull/1427

Jul 23 2022, 9:38 AM · VyOS 1.4 Sagitta
aalmenar added a comment to T4556: fastnetmon: Allow configure white_list_path and populate with hosts/networks that should be ignored..

I have added a pull request for this:

Jul 23 2022, 9:24 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4552: Unable to reset IPsec IPv6 peer.

PR https://github.com/vyos/vyos-1x/pull/1428

vyos@r14:~$ reset vpn ipsec-peer 2001:db8::2 
CHILD_SA {21241} closed successfully
CHILD_SA {21243} closed successfully
CHILD_SA {21245} closed successfully
CHILD_SA {21244} closed successfully
CHILD_SA {21247} closed successfully
CHILD_SA {21246} closed successfully
CHILD_SA {21249} closed successfully
CHILD_SA {21248} closed successfully
closing CHILD_SA peer_2001-db8--2_tunnel_0{21250} with SPIs cab47d6b_i (0 bytes) c3cbba13_o (0 bytes) and TS 2001:db8:1111::/64 === 2001:db8:2222::/64
sending DELETE for ESP CHILD_SA with SPI cab47d6b
generating INFORMATIONAL request 14065 [ D ]
sending packet: from 2001:db8::1[500] to 2001:db8::2[500] (69 bytes)
received packet: from 2001:db8::2[500] to 2001:db8::1[500] (69 bytes)
parsed INFORMATIONAL response 14065 [ D ]
received DELETE for ESP CHILD_SA with SPI c3cbba13
CHILD_SA closed
CHILD_SA {21250} closed successfully
establishing CHILD_SA peer_2001-db8--2_tunnel_0{21251}
generating CREATE_CHILD_SA request 14066 [ SA No KE TSi TSr ]
sending packet: from 2001:db8::1[500] to 2001:db8::2[500] (497 bytes)
received packet: from 2001:db8::2[500] to 2001:db8::1[500] (497 bytes)
parsed CREATE_CHILD_SA response 14066 [ SA No KE TSi TSr ]
selected proposal: ESP:AES_GCM_16_256/MODP_2048/NO_EXT_SEQ
CHILD_SA peer_2001-db8--2_tunnel_0{21251} established with SPIs ccaff1e5_i c5a2b674_o and TS 2001:db8:1111::/64 === 2001:db8:2222::/64
connection 'peer_2001-db8--2_tunnel_0' established successfully
Peer reset result: success
vyos@r14:~$
Jul 23 2022, 8:50 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4552: Unable to reset IPsec IPv6 peer from Open to In progress.
Jul 23 2022, 7:56 AM · VyOS 1.4 Sagitta

Jul 22 2022

Viacheslav changed the status of T4546: Does not connect Cisco spoke to VyOS hub. from In progress to Needs testing.
Jul 22 2022, 11:15 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXbc70c1f502bc: macsec: T2023: fixup systemd unit description.
Jul 22 2022, 9:17 PM
c-po committed rVYOSONEX089c10282dcc: op-mode: monitor log help typo.
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEXe1cbb3a777e7: ssh: T3212: cleanup deprecated /etc/default/ssh file.
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEXcfe158844b95: op-mode: add show|monitor log ssh|snmp commands.
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEX8c7cd6f181a4: ssh: T3212: do not load systemd EnvironmentFile.
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEX58df49d71a9c: dns-forwarding: T2185: cleanup deprecated /etc/powerdns files - now living in….
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEX5df343e67f27: ntp: T2185: cleanup deprecated /etc/ntp.conf - now living in /run/ntpd.
Jul 22 2022, 9:16 PM
c-po committed rVYOSONEX4c0cb7f30dc8: fastnetmon: T2659: also clean /etc/networks_whitelist.
Jul 22 2022, 9:16 PM
c-po added a comment to T4560: VRF and BGP neighbor local-as error.

Commit fails b/c of frr-reload output: 200 % Local-AS allowed only for EBGP peers - we should add an appropriate verify() stage I guess.

Jul 22 2022, 9:10 PM · VyOS 1.4 Sagitta
Viacheslav closed T4145: Conntrack table not showing after firewall rewriting as Resolved.
Jul 22 2022, 7:30 PM · VyOS 1.4 Sagitta
zsdc committed rVYOSONEXb639458bad07: nhrp: T4546: Fixed route add command if MTU presented.
Jul 22 2022, 7:26 PM
GitHub <noreply@github.com> committed rVYOSONEX929915b57382: Merge pull request #1418 from zdc/T4546-sagitta (authored by c-po).
Jul 22 2022, 7:26 PM
Viacheslav committed rVYOSONEX4dc5d78eed41: conntrack: T4145: Modify conntrack to format command runner.
Jul 22 2022, 7:20 PM
GitHub <noreply@github.com> committed rVYOSONEX875560ae8a84: Merge pull request #1425 from sever-sever/T4145 (authored by c-po).
Jul 22 2022, 7:20 PM
Viacheslav added a comment to T4545: Rewrite show nat source rules.

PR https://github.com/vyos/vyos-1x/pull/1426
An example with only one rule 10 raw output

vyos@r14:~$ /usr/libexec/vyos/op_mode/nat.py show_rules --direction source --raw
[
    {
        "rule": {
            "family": "ip",
            "table": "nat",
            "chain": "POSTROUTING",
            "handle": 114,
            "comment": "SRC-NAT-10",
            "expr": [
                {
                    "match": {
                        "op": "==",
                        "left": {
                            "meta": {
                                "key": "oifname"
                            }
                        },
                        "right": "eth0"
                    }
                },
                {
                    "counter": {
                        "packets": 0,
                        "bytes": 0
                    }
                },
                {
                    "masquerade": null
                }
            ]
        }
    }
]
vyos@r14:~$
Jul 22 2022, 4:37 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6: VyOS 1.4 Sagitta.
Jul 22 2022, 1:01 PM · VyOS Rolling
Viacheslav added a comment to T4145: Conntrack table not showing after firewall rewriting.

PR to new format + IPv6 entries https://github.com/vyos/vyos-1x/pull/1425

Jul 22 2022, 12:35 PM · VyOS 1.4 Sagitta
c-po added a comment to T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6.

Unfortunately not all commands are present when using the bgp <afi> syntax. We should find the remaining ones and then move all to the new syntax - less confusing

Jul 22 2022, 10:36 AM · VyOS Rolling
aalmenar added a comment to T4561: reset ip bgp <neighbor> allows reset bgp peer for ipv4, also it should exist one for ipv6.

@Viacheslav yep that one works...

Jul 22 2022, 8:22 AM · VyOS Rolling