Page MenuHomeVyOS Platform
Feed All Stories

Aug 11 2022

Viacheslav committed rVYOSONEXfcb2253153be: l2tp: T4603: Add RADIUS nas-ip-address option.
Aug 11 2022, 5:35 AM
GitHub <noreply@github.com> committed rVYOSONEX466e3b192d15: Merge pull request #1464 from sever-sever/T4603 (authored by c-po).
Aug 11 2022, 5:35 AM

Aug 10 2022

Viacheslav closed T4408: Add sshguard to protect against brut-forces as Resolved.
Aug 10 2022, 10:24 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4485: OpenVPN: Allow multiple CAs certificates from In progress to Needs testing.
Aug 10 2022, 10:21 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4595: DPD interval and timeout do not work in DMVPN.

PR https://github.com/vyos/vyos-1x/pull/1465

Aug 10 2022, 10:01 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4603: Need a config option to specify NAS-IP-Address for vpn l2tp.

PR https://github.com/vyos/vyos-1x/pull/1464

Aug 10 2022, 9:07 PM · VyOS 1.4 Sagitta
hard awarded T4502: Consider implementing (NAT/other) flow table offload a Like token.
Aug 10 2022, 8:33 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4603: Need a config option to specify NAS-IP-Address for vpn l2tp from Open to In progress.
Aug 10 2022, 8:23 PM · VyOS 1.4 Sagitta
m4rcu5 added a comment to T4602: DHCP `ping-check` enabled by default.

I've verified this behavior with 1.4-rolling-202207290217 and 1.4-rolling-202204250217.

Aug 10 2022, 8:19 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4118: IPsec syntax overhaul.

PR https://github.com/vyos/vyos-1x/pull/1463
PR https://github.com/vyos/vyatta-cfg-system/pull/184

Aug 10 2022, 8:08 PM · VyOS 1.4 Sagitta
aserkin added a comment to T4603: Need a config option to specify NAS-IP-Address for vpn l2tp.

Hi Viacheslav
Sorry, i probably misspelled the config option. Actually it's availabe at [radius] section of accel-ppp.conf.
Below is the [radius] section from my /run/accel-pppd/l2tp.conf after i changed
/usr/libexec/vyos/conf_mode/vpn_l2tp.py:

Aug 10 2022, 5:14 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4602: DHCP `ping-check` enabled by default.

What version you are using?

Aug 10 2022, 3:44 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4603: Need a config option to specify NAS-IP-Address for vpn l2tp: VyOS 1.4 Sagitta.
Aug 10 2022, 11:28 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4603: Need a config option to specify NAS-IP-Address for vpn l2tp.

@aserkin Could you send an example of the required accel-ppp section? And how do you see this command in VyOS CLI?

Aug 10 2022, 11:28 AM · VyOS 1.4 Sagitta
ovallaste created T4604: bgpd eats huge amount of memory (about 500Megs a day).
Aug 10 2022, 8:42 AM · VyOS 1.4 Sagitta
ovallaste added a watcher for VyOS 1.4 Sagitta: ovallaste.
Aug 10 2022, 8:17 AM
aserkin changed Version from - to 1.4 on T4603: Need a config option to specify NAS-IP-Address for vpn l2tp.
Aug 10 2022, 7:13 AM · VyOS 1.4 Sagitta
aserkin created T4603: Need a config option to specify NAS-IP-Address for vpn l2tp.
Aug 10 2022, 7:12 AM · VyOS 1.4 Sagitta

Aug 9 2022

m4rcu5 added a comment to T4602: DHCP `ping-check` enabled by default.

Allow me to proof the opposite.

Aug 9 2022, 8:23 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4602: DHCP `ping-check` enabled by default.

As remarked and as expected, this option is not enable by default.
Proofs:

  • Fist scenario: no ping-check option introduced in configuration:
Aug 9 2022, 5:05 PM · VyOS 1.4 Sagitta
ajgnet added a comment to T2518: Add support for IPv6 NAT (NPTv6).

@ajgnet If you have a way to limit the dynamic prefix to a known prefix, then using 1:1 NAT66 prefix translation should work (only the host segment is dynamic)

Yes, would be great to fully support dynamic prefix when the prefix is not known

Aug 9 2022, 1:30 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets.

Will be fixed in https://github.com/vyos/vyos-1x/pull/1458

Aug 9 2022, 12:07 PM · VyOS 1.4 Sagitta
n.fort changed the status of T4598: nat66 - Add exclude options, a subtask of T2518: Add support for IPv6 NAT (NPTv6), from In progress to Needs testing.
Aug 9 2022, 10:40 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T4598: nat66 - Add exclude options from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1461

Aug 9 2022, 10:39 AM · VyOS 1.4 Sagitta

Aug 8 2022

Viacheslav added a comment to T4602: DHCP `ping-check` enabled by default.

ping-check shouldn't be allowed by default
To enable it you have to set set service dhcp-server shared-network-name Lan01 ping-check
There is no configuration in generated .conf:

vyos@r14# cat /run/dhcp-server/dhcpd.conf | grep ping
[edit]
vyos@r14#
Aug 8 2022, 8:28 PM · VyOS 1.4 Sagitta
m4rcu5 created T4602: DHCP `ping-check` enabled by default.
Aug 8 2022, 6:37 PM · VyOS 1.4 Sagitta
n.fort committed rVYOSONEX3a9e7eafe531: nat66: T4598: Add exclude options in nat66.
Aug 8 2022, 6:01 PM
n.fort committed rVYOSONEX0863b441f4a9: nat66: T4598: add file nat-exclue.xml.i, which is invoked by nat66.xml.in and….
Aug 8 2022, 6:01 PM
GitHub <noreply@github.com> committed rVYOSONEX7ae34b68649e: Merge pull request #1461 from nicolas-fort/nat66-exclude (authored by c-po).
Aug 8 2022, 6:01 PM
NceAirport added a watcher for VyOS 1.3 Equuleus (1.3.2): NceAirport.
Aug 8 2022, 12:54 PM
n.fort added a subtask for T2518: Add support for IPv6 NAT (NPTv6): T4598: nat66 - Add exclude options.
Aug 8 2022, 11:01 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a parent task for T4598: nat66 - Add exclude options: T2518: Add support for IPv6 NAT (NPTv6).
Aug 8 2022, 11:01 AM · VyOS 1.4 Sagitta
marekm added a comment to T4600: Closing IPV6CP by client closes PPPoE link completely, even if IPv6 is optional.

See also https://github.com/accel-ppp/accel-ppp/issues/57
Testing this patch, PPPoE session with the Phicomm router now stays up, the missing part after "else" is to remove IPv6 configuration from ppp interface (not sure how to do it properly).

diff
diff --git a/accel-pppd/ppp/ppp_ipv6cp.c b/accel-pppd/ppp/ppp_ipv6cp.c
index 1194b31..2bac31b 100644
--- a/accel-pppd/ppp/ppp_ipv6cp.c
+++ b/accel-pppd/ppp/ppp_ipv6cp.c
@@ -738,7 +738,10 @@ static void ipv6cp_recv(struct ppp_handler_t*h)
                        if (conf_ppp_verbose)
                                log_ppp_info2("recv [IPV6CP TermReq id=%x]\n", hdr->id);
                        ppp_fsm_recv_term_req(&ipv6cp->fsm);
-                       ap_session_terminate(&ipv6cp->ppp->ses, TERM_USER_REQUEST, 0);
+                       if (conf_ipv6 == IPV6_REQUIRE)
+                               ap_session_terminate(&ipv6cp->ppp->ses, TERM_USER_REQUEST, 0);
+                       else
+                               ppp_layer_passive(ipv6cp->ppp, &ipv6cp->ld);
                        break;
                case TERMACK:
                        if (conf_ppp_verbose)
Aug 8 2022, 10:01 AM
a.apostoliuk added a comment to T4537: MACsec not working with cipher gcm-aes-256.

I have tested macsec with gcm-aes-256. It works. (1.4-rolling-202208080217)

Aug 8 2022, 7:53 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4538: Macsec does not work correctly when the interface status changes..

I have tested on 1.4-rolling-202208080217.
The first problem was fixed.
The second problem is not fixed

Aug 8 2022, 7:49 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav closed T4586: Add to NAT66: SNAT destination address and DNAT source address. as Resolved.
Aug 8 2022, 7:31 AM · VyOS 1.4 Sagitta

Aug 7 2022

Unknown Object (User) created T4601: dhcp : relay agent IP address issue..
Aug 7 2022, 10:48 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
marekm added a comment to T4600: Closing IPV6CP by client closes PPPoE link completely, even if IPv6 is optional.

Log messages - http://91.224.224.43/phicomm/phicomm6.log
PPPoE server config:

Aug 7 2022, 6:24 PM
marekm created T4600: Closing IPV6CP by client closes PPPoE link completely, even if IPv6 is optional.
Aug 7 2022, 3:21 PM
RyVolodya added a comment to T4598: nat66 - Add exclude options.

Hello, This functionality for nat66 is described here:
https://phabricator.vyos.net/T4586

Aug 7 2022, 11:12 AM · VyOS 1.4 Sagitta

Aug 6 2022

jack9603301 created T4599: run vyos in lxc/lxd.
Aug 6 2022, 5:57 PM
jack9603301 added a comment to T4598: nat66 - Add exclude options.

hi, you can set this to a subtask of my task

Aug 6 2022, 3:31 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4596: "show openconnect-server sessions" command does not work in the openconnect module.

PR https://github.com/vyos/vyos-1x/pull/1462

Aug 6 2022, 10:18 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4596: "show openconnect-server sessions" command does not work in the openconnect module, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 6 2022, 9:48 AM · VyOS Rolling
Viacheslav changed the status of T4596: "show openconnect-server sessions" command does not work in the openconnect module from Open to In progress.
Aug 6 2022, 9:48 AM · VyOS 1.4 Sagitta

Aug 5 2022

GitHub <noreply@github.com> committed rVYOSONEX1b637f78b870: Merge pull request #1460 from sever-sever/T4597 (authored by c-po).
Aug 5 2022, 6:30 PM
Viacheslav committed rVYOSONEXe3209859935e: ocserv: T4597: Check bind port before openconnect commit.
Aug 5 2022, 6:30 PM
Viacheslav updated subscribers of T4597: Check bind port before assign service HTTPS API and openconnect.
Aug 5 2022, 3:48 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4597: Check bind port before assign service HTTPS API and openconnect.

PR checks if openconnect port is listened by another service https://github.com/vyos/vyos-1x/pull/1460

Aug 5 2022, 3:47 PM · VyOS 1.4 Sagitta
n.fort changed the status of T4598: nat66 - Add exclude options from Open to In progress.
Aug 5 2022, 3:16 PM · VyOS 1.4 Sagitta
n.fort claimed T4598: nat66 - Add exclude options.
Aug 5 2022, 3:15 PM · VyOS 1.4 Sagitta
n.fort created T4598: nat66 - Add exclude options.
Aug 5 2022, 3:15 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4597: Check bind port before assign service HTTPS API and openconnect from Open to In progress.
Aug 5 2022, 2:26 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4589: BGP listen limit Increase via CLI command.

It is already present in 1.4

vyos@r14:~$ show conf com | match bgp
set protocols bgp listen limit '1000'
set protocols bgp listen range 192.0.2.0/24 peer-group 'FOO'
set protocols bgp local-as '65001'
set protocols bgp peer-group FOO remote-as '65001'
Aug 5 2022, 12:39 PM · VyOS 1.4 Sagitta (1.4.0-GA)
zsdc changed the status of T4589: BGP listen limit Increase via CLI command from Open to Confirmed.
Aug 5 2022, 12:16 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav created T4597: Check bind port before assign service HTTPS API and openconnect.
Aug 5 2022, 11:40 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4596: "show openconnect-server sessions" command does not work in the openconnect module.
Aug 5 2022, 10:43 AM · VyOS Rolling
Viacheslav added a parent task for T4596: "show openconnect-server sessions" command does not work in the openconnect module: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Aug 5 2022, 10:43 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4596: "show openconnect-server sessions" command does not work in the openconnect module.

It appeared after this commit
It doesn't like this check https://github.com/vyos/vyos-1x/blob/2a10ffa4b5074be27458159fa94d6227d0e5c7f7/src/op_mode/openconnect-control.py#L63-L65
Check root user https://github.com/vyos/vyos-1x/blob/2a10ffa4b5074be27458159fa94d6227d0e5c7f7/python/vyos/util.py#L625-L626

Aug 5 2022, 10:04 AM · VyOS 1.4 Sagitta
a.apostoliuk created T4596: "show openconnect-server sessions" command does not work in the openconnect module.
Aug 5 2022, 8:14 AM · VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX46173f284cd9: T2719: add an exception hierarchy for op mode errors.
Aug 5 2022, 7:31 AM
GitHub <noreply@github.com> committed rVYOSONEX2a10ffa4b507: Merge pull request #1459 from dmbaturin/genop-exn (authored by Viacheslav).
Aug 5 2022, 7:31 AM
a.apostoliuk created T4595: DPD interval and timeout do not work in DMVPN.
Aug 5 2022, 7:21 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXdfb4ce2a5aa4: bgp: T4257: bugfixes after renaming "local-as" to "system-as".
Aug 5 2022, 5:55 AM

Aug 4 2022

HON added a comment to T2408: DHCP Relay upstream and downstream interfaces.

Would it be an option to instead just add new listen-interface and upstream-interface statements, same as for dhcp-relay6? Then keep interface completely unchanged to avoid breaking weird usages, but add some deprecation notice to the CLI.

Aug 4 2022, 8:27 PM · VyOS 1.4 Sagitta
n.fort added a comment to T2408: DHCP Relay upstream and downstream interfaces.

Currently thinking on how to implement this.
One option could be:

Aug 4 2022, 8:11 PM · VyOS 1.4 Sagitta
n.fort added a project to T2408: DHCP Relay upstream and downstream interfaces: VyOS 1.4 Sagitta.
Aug 4 2022, 7:59 PM · VyOS 1.4 Sagitta
c-po closed T4257: Discussion on changing BGP autonomous system number syntax as Resolved.
Aug 4 2022, 7:27 PM · VyOS 1.4 Sagitta
Cheeze_It committed rVYOSONEX967c53e2f3e4: bgp: T4257: Changing BGP "local-as" to "system-as".
Aug 4 2022, 7:27 PM
c-po committed rVYOSONEX2dfd5a3c00b3: bgp: T4257: bugfixes after renaming "local-as" to "system-as".
Aug 4 2022, 7:27 PM
c-po committed rVYOSONEXde04107fbd01: Merge https://github.com/Cheeze-It/vyos-1x into current.
Aug 4 2022, 7:27 PM
c-po committed rVYOSONEXe19889adf8ce: smoketest: macsec: T4537: validate macsec_csindex for both AES-GCM-128 and AES….
Aug 4 2022, 6:55 PM
c-po committed rVYOSONEX0943ac00412b: macsec: T4537: macsec_csindex can be set even without encryption.
Aug 4 2022, 6:55 PM
Nova_Logic renamed T4587: wan load balance issues with 3 or more WANs from wan load balance issues with 3 WANs to wan load balance issues with 3 or more WANs.
Aug 4 2022, 6:55 PM · Bugs, VyOS Rolling
jack9603301 added a comment to T2898: Support NDP proxy.

@hensur You haven't dealt with this for a long time

Aug 4 2022, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4572: Add an option to force interface MTU to the value received from DHCP from Confirmed to Needs testing.
Aug 4 2022, 3:11 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX67583141f433: mtu: T4572: Add DHCP-option MTU to get values from DHCP-server.
Aug 4 2022, 2:41 PM
GitHub <noreply@github.com> committed rVYOSONEXc8ba6bc59d98: Merge pull request #1453 from sever-sever/T4572-eq (authored by dmbaturin).
Aug 4 2022, 2:41 PM
Viacheslav changed the status of T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS Rolling
Viacheslav changed the status of T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4594: Rewrite op-mode IPsec to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS Rolling
Viacheslav changed the status of T4594: Rewrite op-mode IPsec to vyos.opmode format from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4586: Add to NAT66: SNAT destination address and DNAT source address. from Open to Needs testing.
Aug 4 2022, 1:50 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX08699a10ccea: validators: T4586: Add IPv6 exclude validators for address/prefix.
Aug 4 2022, 1:50 PM
Viacheslav committed rVYOSONEXecc03bd6e499: nat66: T4586: Add SNAT destination prefix and DNAT address.
Aug 4 2022, 1:50 PM
GitHub <noreply@github.com> committed rVYOSONEX8af312ecac88: Merge pull request #1457 from sever-sever/T4586 (authored by c-po).
Aug 4 2022, 1:50 PM
Viacheslav added a comment to T4594: Rewrite op-mode IPsec to vyos.opmode format.

PR https://github.com/vyos/vyos-1x/pull/1458
Formatted output

vyos@r14:~$ show vpn ipsec sa
Connection                 State    Uptime    Bytes In/Out    Packets In/Out    Remote address    Remote ID    Proposal
-------------------------  -------  --------  --------------  ----------------  ----------------  -----------  ---------------------------------------
peer_2001-db8--2_tunnel_0  up       9m15s     0B/0B           0/0               2001:db8::2       2001:db8::2  AES_CBC_256/HMAC_SHA2_256_128/MODP_2048
peer_2001-db8--2_tunnel_0  up       24m9s     0B/0B           0/0               2001:db8::2       2001:db8::2  AES_CBC_256/HMAC_SHA2_256_128/MODP_2048
vyos@r14:~$
Aug 4 2022, 1:18 PM · VyOS 1.4 Sagitta
Viacheslav created T4594: Rewrite op-mode IPsec to vyos.opmode format.
Aug 4 2022, 10:11 AM · VyOS 1.4 Sagitta
ssasso added a comment to T4593: Upgrade strongswan to 5.9.8.

From the strongswan 5.9.6 changelog:

Actively initiating duplicate CHILD_SAs within the same IKE_SA is now largely prevented. This can happen if trap policies are installed and an IKE_SA with its CHILD_SAs is reestablished (e.g. with break-before-make reauthentication or dpd_action=restart). This does not prevent duplicates if they are initiated by the two peers concurrently.
Aug 4 2022, 7:15 AM · VyOS 1.4 Sagitta
ssasso updated the task description for T4593: Upgrade strongswan to 5.9.8.
Aug 4 2022, 7:12 AM · VyOS 1.4 Sagitta
ssasso created T4593: Upgrade strongswan to 5.9.8.
Aug 4 2022, 7:10 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXa782eb0711af: bridge: T4579: remove duplicate code path already handled by base class.
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEX03e6b4e9cda0: Revert "vyos.configdict(): T4228: is_member() must split VLAN interfaces".
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEX0bf98f8d7530: bridge: T4579: cleanup interface dict (remove empty keys).
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEX8e54a26f11fe: bridge: T4565: is_member() must return the dict of the member interface.
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEX9d0ca97cc0f1: smoketest: bridge: T4565: changes to lower interfaces must not destroy VLAN….
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEX8c10a1225153: bridge: T4565: bugfix error message when member interface contains an address.
Aug 4 2022, 6:57 AM
c-po committed rVYOSONEXf6dddb5466c9: macsec: T3368: check key length for gcm-aes-128/gcm-aes-256.
Aug 4 2022, 6:57 AM
GitHub <noreply@github.com> committed rVYOSONEX241fad230bee: Merge pull request #1450 from c-po/bridge-fixes-equuleus (authored by c-po).
Aug 4 2022, 6:57 AM
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.204 / 5.10.129 to Update Linux Kernel to v5.4.208 / 5.10.135.
Aug 4 2022, 6:34 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta