Page MenuHomeVyOS Platform
Feed All Stories

Oct 13 2022

Viacheslav closed T4274: Extend OpenConnect RADIUS Timeout to Permit 2FA Entry as Resolved.
Oct 13 2022, 3:26 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4051: Connected routes strange / not working: VyOS 1.4 Sagitta.

Should be fixed
@primoz Could you check it again?

Oct 13 2022, 3:25 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4462: FRR operational-data pagination: VyOS 1.4 Sagitta.
Oct 13 2022, 3:24 PM · VyOS Rolling
Viacheslav added a comment to T4488: allow manual configuration changes of interfaces created by high-availability with rfc3768-compatibility option .

As a workaround, you can try to use the "transition script" to manipulate with interfaces

Oct 13 2022, 3:22 PM · VyOS Rolling
Viacheslav added a project to T4488: allow manual configuration changes of interfaces created by high-availability with rfc3768-compatibility option : VyOS 1.4 Sagitta.
Oct 13 2022, 3:21 PM · VyOS Rolling
Viacheslav added projects to T4520: Incorrect addresses returned with interaction of static /etc/hosts with DNS64: VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3).
Oct 13 2022, 3:15 PM · VyOS Rolling, Bugs
Viacheslav changed the status of T4728: Crontab file for vyos-wwan is ignored due to missing newline at EOF from Open to Needs testing.
Oct 13 2022, 1:49 PM
Viacheslav closed T4312: Telegraf configuration doesn't accept IPs for URL as Resolved.
Oct 13 2022, 1:45 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav committed rVYOSONEX72c7547efce6: monitoring: T4312: Ability to set IP address in the URL.
Oct 13 2022, 1:45 PM
GitHub <noreply@github.com> committed rVYOSONEXae975a29418a: Merge pull request #1593 from sever-sever/T4312-eq (authored by Viacheslav).
Oct 13 2022, 1:45 PM
Viacheslav added a comment to T4733: Feature Request: dhcp server: add VRF support.

ISC-DHCP-Server does not support vrf's
https://kb.isc.org/docs/isc-dhcp-44-manual-pages-dhcpd

Oct 13 2022, 1:30 PM · VyOS 1.4 Sagitta
danhusan awarded T1237: Static Route Path Monitoring, failover a Orange Medal token.
Oct 13 2022, 1:02 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4733: Feature Request: dhcp server: add VRF support: VyOS 1.4 Sagitta.
Oct 13 2022, 12:54 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4675: telegraf do not start at boot when configured in VRF.

I can't reproduce it

vyos@r14:~$ show conf com | match "vrf|tele"
set interfaces ethernet eth1 vrf 'mgmt'
set service monitoring telegraf influxdb authentication organization 'log@in.local'
set service monitoring telegraf influxdb authentication token 'GuRJc12tIzfjnYdKRAIYbxdWd2aTpOT9PVYNddzDnFV4HkAcD7u7-kndTFXjGuXzJN6TTxmrvPODB4mnFcseDV=='
set service monitoring telegraf influxdb port '8086'
set service monitoring telegraf influxdb url 'https://foo.local'
set service monitoring telegraf prometheus-client
set service monitoring telegraf vrf 'mgmt'
set vrf name mgmt table '1010'
vyos@r14:~$

After reboot, the service telegraf works correctly

vyos@r14:~$ sudo systemctl status telegraf
● telegraf.service - The plugin-driven server agent for reporting metrics into InfluxDB
     Loaded: loaded (/lib/systemd/system/telegraf.service; disabled; vendor preset: enabled)
    Drop-In: /etc/systemd/system/telegraf.service.d
             └─10-override.conf
     Active: active (running) since Thu 2022-10-13 15:24:23 EEST; 1min 19s ago
       Docs: https://github.com/influxdata/telegraf
   Main PID: 1868 (telegraf)
      Tasks: 10 (limit: 9404)
     Memory: 54.4M
        CPU: 2.650s
     CGroup: /system.slice/telegraf.service
             └─vrf
               └─mgmt
                 └─1868 /usr/bin/telegraf --config /run/telegraf/telegraf.conf --config-directory /etc/telegraf/telegraf.d --pidfile /run/telegraf/telegraf.pid
Oct 13 2022, 12:27 PM · VyOS 1.4 Sagitta
Viacheslav closed T4716: SSH ability to configure RekeyLimit, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, as Resolved.
Oct 13 2022, 11:58 AM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Viacheslav closed T4716: SSH ability to configure RekeyLimit as Resolved.
Oct 13 2022, 11:58 AM · VyOS 1.4 Sagitta
Viacheslav closed T4744: BGP directly connected neighbors don't compatible with ebgp-multihop as Resolved.
Oct 13 2022, 11:55 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

KEA DHCP have some hook limitations https://kea.readthedocs.io/en/kea-2.2.0/arm/hooks.html?#available-hook-libraries

Oct 13 2022, 11:40 AM · VyOS 1.5 Circinus
Viacheslav added a comment to T4312: Telegraf configuration doesn't accept IPs for URL.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1593

Oct 13 2022, 11:21 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav closed T4746: Monitoring nft. table vyos_filter by default does not exist but telegraf checks this table as Resolved.
Oct 13 2022, 11:12 AM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX33bf84e66677: monitoring: T4746: Add exception if we do not have firewall rules.
Oct 13 2022, 11:09 AM
GitHub <noreply@github.com> committed rVYOSONEX02f2535dda08: Merge pull request #1592 from sever-sever/T4746 (authored by c-po).
Oct 13 2022, 11:09 AM
Viacheslav changed the status of T4746: Monitoring nft. table vyos_filter by default does not exist but telegraf checks this table from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/1592

Oct 13 2022, 11:06 AM · VyOS 1.4 Sagitta
Viacheslav moved T4312: Telegraf configuration doesn't accept IPs for URL from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 13 2022, 10:54 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav committed rVYOSONEXb52a12553601: monitoring: T4312: Ability to set IP address in the URL.
Oct 13 2022, 10:53 AM
GitHub <noreply@github.com> committed rVYOSONEX219944361140: Merge pull request #1591 from sever-sever/T4312 (authored by c-po).
Oct 13 2022, 10:53 AM
Viacheslav added a comment to T4312: Telegraf configuration doesn't accept IPs for URL.

PR https://github.com/vyos/vyos-1x/pull/1591

Oct 13 2022, 9:34 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4312: Telegraf configuration doesn't accept IPs for URL from Open to In progress.
Oct 13 2022, 9:01 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a project to T4312: Telegraf configuration doesn't accept IPs for URL: VyOS 1.4 Sagitta.
Oct 13 2022, 9:01 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
aalmenar added a comment to T2179: Migrate from radvd to FRR for router advertisements.

i dont know if this is good or not, next version of radvd will include options la RFC8781 which are not even though for frrouting, even im opening them a request for such feature but i dont expect it to be available anytime soon.

Oct 13 2022, 8:32 AM · VyOS Rolling

Oct 12 2022

Viacheslav changed the status of T4744: BGP directly connected neighbors don't compatible with ebgp-multihop from In progress to Needs testing.
Oct 12 2022, 7:17 PM · VyOS 1.4 Sagitta
goodNETnick <pknet@ya.ru> committed rVYOSONEX9821465445b4: system login: T874: add 2FA support for local and ssh authentication. Bugfix.
Oct 12 2022, 7:06 PM
GitHub <noreply@github.com> committed rVYOSONEX74c39157c732: Merge pull request #1585 from goodNETnick/ssh_login_bugfix (authored by jestabro).
Oct 12 2022, 7:06 PM
dmbaturin created T4748: Enforce pull request and commit title format.
Oct 12 2022, 4:46 PM · Infrastructure
Viacheslav committed rVYOSONEXf6d974989202: bgp: T4744: Directly connected neighbors and ebgp-multihop check.
Oct 12 2022, 3:57 PM
GitHub <noreply@github.com> committed rVYOSONEXa057a5c1388a: Merge pull request #1586 from sever-sever/T4744 (authored by c-po).
Oct 12 2022, 3:57 PM
Viacheslav added a comment to T4744: BGP directly connected neighbors don't compatible with ebgp-multihop.

PR https://github.com/vyos/vyos-1x/pull/1586

vyos@r14# commit
[ protocols bgp ]
Ebgp-multihop can not be used with directly connected neighbor "eth0"
Oct 12 2022, 3:06 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4744: BGP directly connected neighbors don't compatible with ebgp-multihop from Open to In progress.
Oct 12 2022, 2:43 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4734: Feature Request: openvpn: add OTP 2FA support.

It is highly desirable to reflect this feature in the documentation
Now it is not clear how to configure and use it

Oct 12 2022, 2:38 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4734: Feature Request: openvpn: add OTP 2FA support.

For 1.4 was implemented in T3834

Oct 12 2022, 1:29 PM · VyOS 1.4 Sagitta
aserkin added a comment to T4731: excessive FRR logs about non-existent VRFs.

That does not change the behavior. I get five messages on session start from bfdd, bgpd, ospfd processes, and 16 messages from all FRR daemons on session stop.
The only way to get rid of them is 'log syslog emergencies' but this filters important events as well.

Oct 12 2022, 1:00 PM · VyOS Rolling, Bugs
Viacheslav added a project to T4734: Feature Request: openvpn: add OTP 2FA support: VyOS 1.3 Equuleus (1.3.3).
Oct 12 2022, 12:38 PM · VyOS 1.4 Sagitta
Viacheslav closed T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be as Resolved.
Oct 12 2022, 12:10 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav committed rVYOSONEX15a649e163fa: conntrack-sync: T4730: Fix listen-address jinja2 template.
Oct 12 2022, 12:10 PM
GitHub <noreply@github.com> committed rVYOSONEXf54f1387c7e5: Merge pull request #1582 from sever-sever/T4730-eq (authored by Viacheslav).
Oct 12 2022, 12:10 PM
Viacheslav closed T4740: Show conntrack table ipv6 fail as Resolved.
Oct 12 2022, 11:16 AM · VyOS 1.4 Sagitta
Viacheslav closed T4747: Monitoring influxdb template input exec plugin does not work as Resolved.
Oct 12 2022, 11:10 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4731: excessive FRR logs about non-existent VRFs.

@aserkin as workaround try to change facility level

vtysh -c "conf t" -c "log facility local0"

But it can affect to bgp logs

Oct 12 2022, 10:15 AM · VyOS Rolling, Bugs
Viacheslav moved T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 12 2022, 9:48 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
n.fort added a comment to T2408: DHCP Relay upstream and downstream interfaces.

+1 for @Viacheslav proposal.

Oct 12 2022, 9:24 AM · VyOS 1.4 Sagitta
aserkin added a comment to T4731: excessive FRR logs about non-existent VRFs.

Any suggestions on the problem, guys?
I see a lot of messages regarding these messages appearing in various scenarios since 2017 or even earlier in FRR community. But did not find any solution actually.

Oct 12 2022, 9:09 AM · VyOS Rolling, Bugs
c-po committed rVYOSONEX1c16a56e7b29: ospf: T4707: fix segment-routing Jinja2 template for explicit-null and no-php….
Oct 12 2022, 7:18 AM
goodNETnick <pknet@ya.ru> committed rVYOSONEX765f84386b6e: system login: T874: add 2FA support for local and ssh authentication.
Oct 12 2022, 7:03 AM
GitHub <noreply@github.com> committed rVYOSONEX6951fa7ef6ea: Merge pull request #1555 from goodNETnick/ssh_otp (authored by c-po).
Oct 12 2022, 7:03 AM
Viacheslav added a comment to T4470: Rewrite load-balancing wan to XML/Python.

@thetooth There is a new feature failover route where you can set metrics
https://github.com/vyos/vyos-1x/pull/1358
It could be extended to some "load-balancing"

Oct 12 2022, 6:40 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
thetooth added a comment to T4470: Rewrite load-balancing wan to XML/Python.

I have used this feature in the past but not anymore due to the issues listed in the regressions task. We are now running pfsense purely for LB since this (mostly) works as advertised. Looking back at this current implementation there are some very useful features that are missing.

Oct 12 2022, 2:58 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling

Oct 11 2022

Viacheslav removed a project from T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6): VyOS 1.3 Equuleus (1.3.3).
Oct 11 2022, 9:17 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T4747: Monitoring influxdb template input exec plugin does not work from In progress to Needs testing.
Oct 11 2022, 9:00 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX6859a2474dab: monitoring: T4747: Fix template check influxdb config.
Oct 11 2022, 8:15 PM
GitHub <noreply@github.com> committed rVYOSONEXb74f297d8a74: Merge pull request #1584 from sever-sever/T4747 (authored by c-po).
Oct 11 2022, 8:15 PM
Viacheslav added a comment to T4747: Monitoring influxdb template input exec plugin does not work.

PR https://github.com/vyos/vyos-1x/pull/1584

vyos@r14# cat /run/telegraf/telegraf.conf | grep 'inputs.exec' -A 8
[[inputs.exec]]
  commands = [
    "/etc/telegraf/custom_scripts/show_firewall_input_filter.py",
    "/etc/telegraf/custom_scripts/show_interfaces_input_filter.py",
    "/etc/telegraf/custom_scripts/vyos_services_input_filter.py"
  ]
  timeout = "10s"
  data_format = "influx"
[edit]
vyos@r14#
Oct 11 2022, 7:44 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4747: Monitoring influxdb template input exec plugin does not work from Open to In progress.
Oct 11 2022, 7:09 PM · VyOS 1.4 Sagitta
Viacheslav moved T4680: Telegraf prometheus-client listen-address invalid format from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 11 2022, 7:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav closed T4680: Telegraf prometheus-client listen-address invalid format as Resolved.
Oct 11 2022, 7:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav created T4747: Monitoring influxdb template input exec plugin does not work.
Oct 11 2022, 7:03 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXb4c2d288b098: monitoring: T4680: Bracketize prometheus listen-address.
Oct 11 2022, 6:49 PM
GitHub <noreply@github.com> committed rVYOSONEXbf949ddcc1b9: Merge pull request #1583 from sever-sever/T4680-eq (authored by c-po).
Oct 11 2022, 6:49 PM
Viacheslav created T4746: Monitoring nft. table vyos_filter by default does not exist but telegraf checks this table.
Oct 11 2022, 6:36 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4680: Telegraf prometheus-client listen-address invalid format.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1583

Oct 11 2022, 6:15 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po committed rVYOSONEX06d6386e5d9f: xml: ospf: isis: T4739: merge include files for MPLS segment-routing.
Oct 11 2022, 5:53 PM
Viacheslav changed the status of T4740: Show conntrack table ipv6 fail from In progress to Needs testing.
Oct 11 2022, 5:46 PM · VyOS 1.4 Sagitta
Cheeze_It committed rVYOSONEX08c2a057917c: isis: T4739: ISIS segment routing being refactored.
Oct 11 2022, 5:34 PM
GitHub <noreply@github.com> committed rVYOSONEX7f7705da4def: Merge pull request #1574 from Cheeze-It/current (authored by c-po).
Oct 11 2022, 5:33 PM
initramfs committed rVYOSONEX2722f6ea29a9: qos: T4688: add xml template for limiter actions.
Oct 11 2022, 5:32 PM
GitHub <noreply@github.com> committed rVYOSONEX25b7d6a5a4e0: Merge pull request #1547 from initramfs/current-limiter-actions (authored by c-po).
Oct 11 2022, 5:32 PM
a.apostoliuk committed rVYOSONEX7b61f2062036: bgp: T4492: Fixed output list in "show bgp vrf VRF neighbors".
Oct 11 2022, 5:32 PM
GitHub <noreply@github.com> committed rVYOSONEXcecab72057ab: Merge pull request #1580 from aapostoliuk/T4492-sagitta (authored by c-po).
Oct 11 2022, 5:32 PM
Viacheslav committed rVYOSONEXe4071bfaede4: conntrack: T4740: Set correct error msg if enrties not found.
Oct 11 2022, 5:31 PM
GitHub <noreply@github.com> committed rVYOSONEX72cf07cc8df5: Merge pull request #1581 from sever-sever/T4740 (authored by c-po).
Oct 11 2022, 5:31 PM
victorhooi added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

I believe the ISC DHCP is now officially deprecated and EOLed:

Oct 11 2022, 2:52 PM · VyOS 1.5 Circinus
Viacheslav added a project to T4680: Telegraf prometheus-client listen-address invalid format: VyOS 1.3 Equuleus (1.3.3).
Oct 11 2022, 2:05 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk created T4745: CLI TAB issue with values with '-' at the beginning in conf mode.
Oct 11 2022, 1:31 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
sarthurdev closed T4741: set firewall zone Local local-zone failed as Resolved.
Oct 11 2022, 1:29 PM · VyOS 1.4 Sagitta
sarthurdev closed T4742: Autocomplete in policy route rule x set table / does not show the tables created in the static protocols as Resolved.
Oct 11 2022, 1:29 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4730: Conntrack-sync error - listen-address is not the correct type in config as it should be.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1582

Oct 11 2022, 1:07 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T4740: Show conntrack table ipv6 fail.

PR https://github.com/vyos/vyos-1x/pull/1581

vyos@r14:~$ show conntrack table ipv6
Entries not found
vyos@r14:~$
Oct 11 2022, 12:23 PM · VyOS 1.4 Sagitta
Viacheslav created T4744: BGP directly connected neighbors don't compatible with ebgp-multihop.
Oct 11 2022, 9:26 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4729: VxLAN does not work and deleted after tun changed.
In T4729#135230, @pasik wrote:

Ah, yeah, that's a valid point for gretap.

Anyway, my point was, it would be good to test if the issue/bug also affects plain 'gre', as behind the scenes 'gre' and 'gretap' are handled and configured differently, even though they might seem as very similar in vyos cli/config.

The bug might affect both, but it would be good to check and verify.

Oct 11 2022, 8:27 AM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
a.apostoliuk changed the status of T4492: Incorrect list of neighbors in help for "show bgp vrf VRF neighbors" from Open to In progress.
Oct 11 2022, 6:54 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4704: Allow to set metric (MED) to rtt with rtt,+rtt or -rtt from Open to In progress.
Oct 11 2022, 6:53 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXe5507b247edc: smoketest: ospf: skip segment-routing test as of FRR issue.
Oct 11 2022, 5:37 AM
sarthurdev committed rVYOSONEX28e06759fdbb: build: T3664: Add missing divert for /usr/share/pam-configs/radius.
Oct 11 2022, 5:25 AM
GitHub <noreply@github.com> committed rVYOSONEX428c5f43ad9c: Merge pull request #1578 from sarthurdev/build_test (authored by c-po).
Oct 11 2022, 5:25 AM

Oct 10 2022

Viacheslav changed the status of T4740: Show conntrack table ipv6 fail from Open to In progress.
Oct 10 2022, 7:59 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4743: Enable IPv6 address for Dynamic DNS.

PR https://github.com/vyos/vyos-1x/pull/1579

set service dns dynamic interface eth2 ipv6-enable
set service dns dynamic interface eth2 service dynv6 host-name 'xxx.dynv6.net'
set service dns dynamic interface eth2 service dynv6 login 'none'
set service dns dynamic interface eth2 service dynv6 password 'passWorD'
set service dns dynamic interface eth2 service dynv6 protocol 'dyndns2'
set service dns dynamic interface eth2 service dynv6 server 'dynv6.com'
Oct 10 2022, 7:43 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4716: SSH ability to configure RekeyLimit, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from In progress to Needs testing.
Oct 10 2022, 7:33 PM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Viacheslav changed the status of T4716: SSH ability to configure RekeyLimit from In progress to Needs testing.
Oct 10 2022, 7:33 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4743: Enable IPv6 address for Dynamic DNS from Open to In progress.
Oct 10 2022, 6:50 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the subtype of T4743: Enable IPv6 address for Dynamic DNS from "Bug" to "Feature Request".
Oct 10 2022, 6:49 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav created T4743: Enable IPv6 address for Dynamic DNS.
Oct 10 2022, 6:49 PM · VyOS 1.3 Equuleus (1.3.3)