Page MenuHomeVyOS Platform
Feed All Stories

Oct 10 2022

sarthurdev committed rVYOSONEX8269866a5d46: firewall: T4741: Verify zone `from` is defined before use.
Oct 10 2022, 6:04 PM
sarthurdev committed rVYOSONEX47984a6de93b: policy: T4742: Add policy route table auto-complete.
Oct 10 2022, 6:04 PM
GitHub <noreply@github.com> committed rVYOSONEXdfbec80fac0a: Merge pull request #1577 from sarthurdev/T4741 (authored by c-po).
Oct 10 2022, 6:04 PM
Viacheslav committed rVYOSONEXb9de775a5b4f: ssh: T4716: Ablity to configure RekeyLimit data and time.
Oct 10 2022, 6:03 PM
GitHub <noreply@github.com> committed rVYOSONEX9769f25fdf3b: Merge pull request #1563 from sever-sever/T4716 (authored by c-po).
Oct 10 2022, 6:03 PM
Viacheslav closed T538: Support for network mapping in NAT as Resolved.
Oct 10 2022, 5:54 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX98f4cc81235b: conntrack-sync: T4730: Fix listen-address jinja2 template.
Oct 10 2022, 4:35 PM
GitHub <noreply@github.com> committed rVYOSONEXadc9af198365: Merge pull request #1576 from sever-sever/T4730 (authored by c-po).
Oct 10 2022, 4:35 PM
sarthurdev changed the status of T4742: Autocomplete in policy route rule x set table / does not show the tables created in the static protocols from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1577

Oct 10 2022, 2:27 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4741: set firewall zone Local local-zone failed from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1577

Oct 10 2022, 2:27 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be from "Task" to "Bug".
Oct 10 2022, 2:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be.

PR https://github.com/vyos/vyos-1x/pull/1576

Oct 10 2022, 2:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be from Confirmed to In progress.
Oct 10 2022, 1:30 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be from Open to Confirmed.
Oct 10 2022, 1:25 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a project to T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be: VyOS 1.4 Sagitta.
Oct 10 2022, 1:25 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
SrividyaA added a comment to T4741: set firewall zone Local local-zone failed.

zone policy has to be assigned to the firewall rule, that's why the commit failed.

Oct 10 2022, 10:32 AM · VyOS 1.4 Sagitta
Viacheslav edited projects for T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.2).
Oct 10 2022, 10:26 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
HappyShr00m created T4742: Autocomplete in policy route rule x set table / does not show the tables created in the static protocols.
Oct 10 2022, 9:35 AM · VyOS 1.4 Sagitta
roedie changed the status of T4526: keepalived-fifo.py unable to load config from Resolved to Unknown Status.
Oct 10 2022, 9:18 AM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
roedie added a comment to T4526: keepalived-fifo.py unable to load config.

@florin If this is needed I'll make a pull request coming week.

Oct 10 2022, 9:17 AM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX9ab63d484741: firewall: T3907: Fix firewall state-policy logging.
Oct 10 2022, 6:52 AM
GitHub <noreply@github.com> committed rVYOSONEX8bd4c4136a24: Merge pull request #1575 from sarthurdev/firewall_state_log (authored by c-po).
Oct 10 2022, 6:52 AM

Oct 9 2022

tioan created T4741: set firewall zone Local local-zone failed.
Oct 9 2022, 10:16 PM · VyOS 1.4 Sagitta
florin added a comment to T4526: keepalived-fifo.py unable to load config.

I think this needs to be backported to 1.3 too

Oct 9 2022, 9:14 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
a.apostoliuk claimed T4704: Allow to set metric (MED) to rtt with rtt,+rtt or -rtt.
Oct 9 2022, 7:06 PM · VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4740: Show conntrack table ipv6 fail.

I have tested it again. So it happens only if conntrack table is empty.
The same problem with IPv4.

Oct 9 2022, 3:32 PM · VyOS 1.4 Sagitta
a.apostoliuk created T4740: Show conntrack table ipv6 fail.
Oct 9 2022, 3:09 PM · VyOS 1.4 Sagitta
jestabro closed T4738: Extend automatic generation of schema definition files to native configsession functions; use single resolver/directive as Resolved.
Oct 9 2022, 1:54 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX5f81ced8d57d: graphql: T4738: generate schema defs for configsession methods.
Oct 9 2022, 1:46 PM
jestabro committed rVYOSONEX76c9a376c7d4: graphql: T4738: remove templated requests pending rewrite.
Oct 9 2022, 1:46 PM
GitHub <noreply@github.com> committed rVYOSONEX72c97ec2cb86: Merge pull request #1573 from jestabro/gql-simplify (authored by jestabro).
Oct 9 2022, 1:46 PM

Oct 8 2022

Cheeze_It added a comment to T4739: ISIS and OSPF segment routing being refactored.

Added PR for this here, https://github.com/vyos/vyos-1x/pull/1574

Oct 8 2022, 10:54 PM · VyOS 1.4 Sagitta
Rain added a comment to T4612: Support arbitrary netmasks in firewall rules.

I implemented address-mask as described above as well: https://github.com/Rain/vyos-1x/commit/ca6b7340714c6161337f508978b9834722be58dc

Oct 8 2022, 10:12 PM · VyOS 1.4 Sagitta
patrickli added a comment to T4612: Support arbitrary netmasks in firewall rules.

A separate mask field is cleaner also from a documentation point of view. But how would you do it for an address/network group? It only makes sense for a single address I suppose.

Oct 8 2022, 7:05 PM · VyOS 1.4 Sagitta
Rain added a comment to T4612: Support arbitrary netmasks in firewall rules.

On second thought, maybe instead of supporting the ::beef/::ffff syntax we add an address-mask field to source and destination?

Oct 8 2022, 4:02 PM · VyOS 1.4 Sagitta
Cheeze_It claimed T4739: ISIS and OSPF segment routing being refactored.
Oct 8 2022, 3:31 AM · VyOS 1.4 Sagitta
Cheeze_It changed the status of T4739: ISIS and OSPF segment routing being refactored from Open to In progress.
Oct 8 2022, 3:30 AM · VyOS 1.4 Sagitta
Cheeze_It created T4739: ISIS and OSPF segment routing being refactored.
Oct 8 2022, 3:30 AM · VyOS 1.4 Sagitta
Cheeze_It closed T4707: Enable OSPF segment routing as Resolved.
Oct 8 2022, 3:29 AM · VyOS 1.4 Sagitta
Cheeze_It updated subscribers of T4707: Enable OSPF segment routing.

I closed the other PR, and put in https://github.com/vyos/vyos-1x/pull/1572.

Oct 8 2022, 3:28 AM · VyOS 1.4 Sagitta
Rain added a comment to T4612: Support arbitrary netmasks in firewall rules.

I'd like to see this feature added so I went ahead and implemented it: https://github.com/Rain/vyos-1x/commit/975f4fc358f0073f1ad825ea209169766dc2fa51

Oct 8 2022, 2:57 AM · VyOS 1.4 Sagitta

Oct 7 2022

jestabro added a comment to T4738: Extend automatic generation of schema definition files to native configsession functions; use single resolver/directive.

Working directory here; PR pending:
https://github.com/vyos/vyos-1x/compare/current...jestabro:gql-simplify

Oct 7 2022, 7:50 PM · VyOS 1.4 Sagitta
jestabro triaged T4738: Extend automatic generation of schema definition files to native configsession functions; use single resolver/directive as Normal priority.
Oct 7 2022, 7:47 PM · VyOS 1.4 Sagitta
zsdc changed the status of T4737: FRRouting/zebra 7.5.1 does not redistribute routes to other protocols from Open to Confirmed.
Oct 7 2022, 6:39 PM · VyOS 1.3 Equuleus (1.3.3)
zsdc created T4737: FRRouting/zebra 7.5.1 does not redistribute routes to other protocols.
Oct 7 2022, 6:13 PM · VyOS 1.3 Equuleus (1.3.3)
jestabro closed T4736: Error on JSON output of API query ShowConfig as Resolved.
Oct 7 2022, 3:01 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXbb4901773df9: graphql: T4736: fix import error to correct JSON output.
Oct 7 2022, 3:00 PM
jestabro created T4736: Error on JSON output of API query ShowConfig.
Oct 7 2022, 2:55 PM · VyOS 1.4 Sagitta
dmbaturin renamed T4630: Prevent attempts to use the same interface as a source interface for pseudo-ethernet and MACsec at the same time from Pseudo Ethernet can not use identical source-interface as MACsec to Prevent attempts to use the same interface as a source interface for pseudo-ethernet and MACsec at the same time.
Oct 7 2022, 2:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
dmbaturin changed Issue type from unspecified to improvement on T538: Support for network mapping in NAT.
Oct 7 2022, 2:14 PM · VyOS 1.4 Sagitta
dmbaturin renamed T538: Support for network mapping in NAT from Possible to implement Static NAT? to Support for network mapping in NAT.
Oct 7 2022, 2:14 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXb0cb5afe5706: smoketest: ospf: remove old debug code no longer used/required.
Oct 7 2022, 5:47 AM
c-po committed rVYOSONEX95debbf93fe7: ospf: T4707: enable segment-routing on last in FRR configuration.
Oct 7 2022, 5:42 AM
Cheeze_It committed rVYOSONEXb6e690f0f72e: ospf: T4707: Add OSPF segment routing for FRR.
Oct 7 2022, 5:36 AM
GitHub <noreply@github.com> committed rVYOSONEX203d60217e7b: Merge pull request #1572 from Cheeze-It/current (authored by c-po).
Oct 7 2022, 5:36 AM
dmbaturin committed rVYOSONEX14fb82215401: T4726: add completion help and validation for accel-ppp vendor option.
Oct 7 2022, 5:34 AM
GitHub <noreply@github.com> committed rVYOSONEX23f7ef7e9e79: Merge branch 'current' into radius-rate-limit-comp (authored by c-po).
Oct 7 2022, 5:34 AM
GitHub <noreply@github.com> committed rVYOSONEX4608001b073f: Merge pull request #1569 from dmbaturin/radius-rate-limit-comp (authored by c-po).
Oct 7 2022, 5:34 AM
Unknown Object (User) created T4734: Feature Request: openvpn: add OTP 2FA support.
Oct 7 2022, 2:08 AM · VyOS 1.4 Sagitta
Unknown Object (User) created T4733: Feature Request: dhcp server: add VRF support.
Oct 7 2022, 1:55 AM · VyOS 1.4 Sagitta

Oct 6 2022

c-po committed rVYOSONEX067cc12d0e6e: xml: T4722: radius: remove superfluous "default" help string.
Oct 6 2022, 8:49 PM
c-po committed rVYOSONEX997acca44697: smoketest: ethernet: use ifconfig API for VLAN detection on test initialisation.
Oct 6 2022, 8:48 PM
a.apostoliuk committed rVYOSONEX507f6ac42340: policy: T4660: Changed CLI syntax in route-map set community.
Oct 6 2022, 6:47 PM
GitHub <noreply@github.com> committed rVYOSONEX975eaa55f85a: Merge pull request #1567 from aapostoliuk/T4660-sagitta (authored by c-po).
Oct 6 2022, 6:47 PM
aserkin created T4732: need an option for VRF name when you specify location for commit-archive.
Oct 6 2022, 6:02 PM · Restricted Project, VyOS Rolling
aserkin added a comment to T4731: excessive FRR logs about non-existent VRFs.
Oct 6 2022, 4:59 PM · VyOS Rolling, Bugs
aserkin added a comment to T4731: excessive FRR logs about non-existent VRFs.

This a project for mobile access to enterprise networks. VyOS plays as an MPLS-PE router as well as L2TP Network Server. Every subscriber coming via l2tp is directed to the customer's VRF other than default (with RADIUS attribute)

Oct 6 2022, 4:24 PM · VyOS Rolling, Bugs
v.huti claimed T4731: excessive FRR logs about non-existent VRFs.
Oct 6 2022, 2:29 PM · VyOS Rolling, Bugs
v.huti added a comment to T4731: excessive FRR logs about non-existent VRFs.

Hi @aserkin! It looks like you have some frr server misbehavior. It sends up/down events with an unexisting vrf id.
Could you make/describe the setup that causes the issue to appear? Thanks

Oct 6 2022, 12:48 PM · VyOS Rolling, Bugs
zsdc added a member for Maintainers: a.apostoliuk.
Oct 6 2022, 12:40 PM
zsdc assigned T4492: Incorrect list of neighbors in help for "show bgp vrf VRF neighbors" to a.apostoliuk.
Oct 6 2022, 11:14 AM · VyOS 1.4 Sagitta
aserkin created T4731: excessive FRR logs about non-existent VRFs.
Oct 6 2022, 10:44 AM · VyOS Rolling, Bugs
GitHub <noreply@github.com> committed rVYOSONEX50f26c54d095: T4727: add support for RADIUS rate limiting to PPTP (#1570) (authored by dmbaturin).
Oct 6 2022, 6:44 AM
Unknown Object (User) triaged T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be as High priority.
Oct 6 2022, 1:35 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)

Oct 5 2022

pasik added a comment to T4729: VxLAN does not work and deleted after tun changed.

Ah, yeah, that's a valid point for gretap.

Oct 5 2022, 3:07 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
Viacheslav added a comment to T4729: VxLAN does not work and deleted after tun changed.
In T4729#135223, @pasik wrote:

well, "gre" and "gretap" are different types of tunnels, with different features.. so it makes sense to test and validate with the normal "gre", as in your config I don't see a need for "gretap".

Oct 5 2022, 2:42 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
lferrarotti added a comment to T4676: IPoE server with mac authentication generates a wrong dictionary.

I just checked based on your comment and I can also confirm that with 1.4-rolling-202210050218 (using also different syntax) is working perfectly with the authentication.

Oct 5 2022, 11:35 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4676: IPoE server with mac authentication generates a wrong dictionary.

Update: latest rolling has a bit different syntax. I think users just not migrated properly on update. After adding

set service ipoe-server authentication interface eth1.50 mac 00:50:79:66:68:03
set service ipoe-server authentication interface eth1.51 mac 00:50:79:66:68:04

I see that chap-secrets file generated properly and users getsIPs

vyos@vyos# sudo cat /run/accel-pppd/ipoe.chap-secrets 
# username  server  password  acceptable local IP addresses   shaper
eth1.50     * 00:50:79:66:68:03 * 
eth1.51     * 00:50:79:66:68:04
vyos@vyos# run show ipoe-server sessions 
ifname | username |    calling-sid    |     ip      | rate-limit | type | comp | state  |  uptime  
--------+----------+-------------------+-------------+------------+------+------+--------+----------
 ipoe0  | eth1.50  | 00:50:79:66:68:03 | 172.16.50.2 |            | ipoe |      | active | 00:05:21 
 ipoe1  | eth1.51  | 00:50:79:66:68:04 | 172.16.98.2 |            | ipoe |      | active | 00:03:43
Oct 5 2022, 11:05 AM · VyOS 1.4 Sagitta
Unknown Object (User) claimed T4676: IPoE server with mac authentication generates a wrong dictionary.
Oct 5 2022, 8:55 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4676: IPoE server with mac authentication generates a wrong dictionary.

This issue also present in 1.3.0-1.3.2. Latest rolling 1.4-rolling-202210040218 also affected, it has empty user list in chap-secrets

vyos@vyos:~$ sudo cat /run/accel-pppd/ipoe.chap-secrets 
# username  server  password  acceptable local IP addresses   shaper
vyos@vyos:~$
Oct 5 2022, 8:55 AM · VyOS 1.4 Sagitta
pasik added a comment to T4729: VxLAN does not work and deleted after tun changed.

well, "gre" and "gretap" are different types of tunnels, with different features.. so it makes sense to test and validate with the normal "gre", as in your config I don't see a need for "gretap".

Oct 5 2022, 7:33 AM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project

Oct 4 2022

Viacheslav added a comment to T4729: VxLAN does not work and deleted after tun changed.
In T4729#135221, @pasik wrote:

Hmm, any specific reason for the tun0 encapsulation 'gretap' ? did you try with normal 'gre' tunnels ? Does it change anything?

Oct 4 2022, 11:36 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
pasik added a comment to T4729: VxLAN does not work and deleted after tun changed.

Hmm, any specific reason for the tun0 encapsulation 'gretap' ? did you try with normal 'gre' tunnels ? Does it change anything?

Oct 4 2022, 6:29 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
n.fort changed the status of T4706: NAT and NAT66 issues from Confirmed to Needs testing.
Oct 4 2022, 5:53 PM · VyOS 1.4 Sagitta
n.fort closed T4700: Firewall - Add interface match criteria as Resolved.
Oct 4 2022, 5:52 PM · VyOS 1.4 Sagitta
initramfs closed T4685: Interface does not exist on boot when used as inbound-interface for local policy route as Resolved.
Oct 4 2022, 4:59 PM · VyOS 1.4 Sagitta
initramfs closed T4582: Router-advert: Preferred lifetime cannot equal valid lifetime in PIOs as Resolved.
Oct 4 2022, 4:58 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
initramfs closed T4648: PPPoE: Ignore default router from RA when PPPoE default-route is set to none as Resolved.
Oct 4 2022, 4:57 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T4676: IPoE server with mac authentication generates a wrong dictionary.

Needs to check, maybe fixed with rewriting in T4678

Oct 4 2022, 3:48 PM · VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T4676: IPoE server with mac authentication generates a wrong dictionary.
Oct 4 2022, 2:15 PM · VyOS 1.4 Sagitta
n.fort closed T4699: Firewall - Add jump action - Add return action as Resolved.
Oct 4 2022, 12:05 PM · VyOS 1.4 Sagitta
n.fort closed T4651: Firewall - Add options to match packet size as Resolved.
Oct 4 2022, 12:05 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4729: VxLAN does not work and deleted after tun changed.
Oct 4 2022, 8:54 AM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
Viacheslav renamed T4729: VxLAN does not work and deleted after tun changed from VxLAN does not work after tun changed to VxLAN does not work and deleted after tun changed.
Oct 4 2022, 8:49 AM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
Viacheslav updated the task description for T4729: VxLAN does not work and deleted after tun changed.
Oct 4 2022, 8:45 AM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
Viacheslav created T4729: VxLAN does not work and deleted after tun changed.
Oct 4 2022, 8:44 AM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
Viacheslav closed T4708: 'show nat destination rules' throwing an error as Resolved.
Oct 4 2022, 8:13 AM · VyOS 1.4 Sagitta
c-po closed T4652: Upgrade PowerDNS recursor to 4.7 series, a subtask of T3882: Upgrade PowerDNs recursor to 4.5 series, as Resolved.
Oct 4 2022, 6:23 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po closed T4652: Upgrade PowerDNS recursor to 4.7 series as Resolved.
Oct 4 2022, 6:23 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T4702: Wireguard peers configuration is not synchronized with CLI as Resolved.
Oct 4 2022, 6:23 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta