Page MenuHomeVyOS Platform
Feed All Stories

Feb 10 2023

Viacheslav committed rVYOSONEX3f4aee7a3446: T1993: Extend smoketest for fwmark shaper check.
Feb 10 2023, 6:54 AM
GitHub <noreply@github.com> committed rVYOSONEX7000d33d3dd2: Merge pull request #1808 from sever-sever/T1993 (authored by c-po).
Feb 10 2023, 6:54 AM
anon3fe35 added a comment to T4978: KeyError: 'memory' container_config['memory'] on upgrading to 1.4-rolling-202302041536.

I have the same issue

Feb 10 2023, 3:17 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
syncer changed the subtype of T4443: Wan Load Balancing Multiple Regressions from "Task" to "Bug".
Feb 10 2023, 1:41 AM · VyOS Rolling, Bugs
syncer updated subscribers of T4443: Wan Load Balancing Multiple Regressions.

@zsdc @v.huti this requires your attention

Feb 10 2023, 1:40 AM · VyOS Rolling, Bugs
syncer reassigned T4443: Wan Load Balancing Multiple Regressions from Viacheslav to v.huti.
Feb 10 2023, 1:40 AM · VyOS Rolling, Bugs
jestabro added a comment to T4991: Restore path level information to compare output.

Some adjustments made for command output; re-testing for PR.

Feb 10 2023, 12:53 AM · VyOS 1.4 Sagitta

Feb 9 2023

jestabro added a comment to T4991: Restore path level information to compare output.

Running smoketests; PR's to follow:

Feb 9 2023, 8:17 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4942: Rewrite vyatta-config-mgmt to Python/XML: T4991: Restore path level information to compare output.
Feb 9 2023, 7:32 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4991: Restore path level information to compare output: T4942: Rewrite vyatta-config-mgmt to Python/XML.
Feb 9 2023, 7:32 PM · VyOS 1.4 Sagitta
jestabro changed the status of T4991: Restore path level information to compare output from Open to In progress.
Feb 9 2023, 7:29 PM · VyOS 1.4 Sagitta
dmbaturin created T4990: Commit results may not be properly saved if power is cut immediately after a successful commit.
Feb 9 2023, 4:14 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
a.apostoliuk committed rVYOSONEXcccfa2b3df2f: nhrp: T4905: Rewritten nhrp op-mode in new style.
Feb 9 2023, 3:00 PM
GitHub <noreply@github.com> committed rVYOSONEX078faa6718c2: Merge pull request #1793 from aapostoliuk/T4905-sagitta (authored by dmbaturin).
Feb 9 2023, 3:00 PM
Viacheslav closed T4987: Structure HTTPS-API output - "show ip bgp neighbours" as Invalid.
Feb 9 2023, 10:24 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4852: pppoe - static default route deleted automatically with default-route none option.

eth0 -> PPPoE (Primary link)
eth1 -> DHCP (Backup link)

if I use default-route 'auto' for pppoe then default route via pppoe is not getting configured. That's why I am defining the static default route for pppoe with default-route 'none' option.

Feb 9 2023, 9:58 AM · VyOS 1.4 Sagitta
Viacheslav reopened T4852: pppoe - static default route deleted automatically with default-route none option as "Open".
Feb 9 2023, 9:46 AM · VyOS 1.4 Sagitta
pratik.g added a comment to T4852: pppoe - static default route deleted automatically with default-route none option.

I have two wan links as following-

Feb 9 2023, 9:36 AM · VyOS 1.4 Sagitta
daniil created T4989: QoS Policy Limiter - classes for marked traffic do not work.
Feb 9 2023, 9:20 AM · vyatta-cfg-qos, VyOS 1.4 Sagitta
Nova_Logic added a comment to T4376: DNAT with multiwan and policy routing, incoming connections only work on primary interface.

It looks like mine issue with wan load balancing - reply for dnat-ed packets from secondary interfaces was sent by vyos from "primary" https://phabricator.vyos.net/T4587 . Could you dump traffic and check that possibility

Feb 9 2023, 8:37 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4971: Radius attribute "Framed-Pool" for PPPoE from In progress to Needs testing.
Feb 9 2023, 8:18 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4971: Radius attribute "Framed-Pool" for PPPoE.

@fernandolcx Will be present in the next rolling release, could you test it (after 20230209)?

Feb 9 2023, 8:18 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po committed rVYOSONEX330466f39bd3: vyos.ifconfig: T1579: improve source-validation warning.
Feb 9 2023, 6:51 AM
c-po committed rVYOSONEXe22e9c9210cb: wwan: T3622: add constraint for username/password CLI nodes.
Feb 9 2023, 6:51 AM
c-po added a reverting change for rVYOSONEXb17251334c57: container: T4959: Add container registry authentication config for containers: rVYOSONEXf234b602c4b0: Revert "container: T4959: Add container registry authentication config for….
Feb 9 2023, 6:31 AM
c-po committed rVYOSONEXf234b602c4b0: Revert "container: T4959: Add container registry authentication config for….
Feb 9 2023, 6:31 AM
Zen3515 committed rVYOSONEXb17251334c57: container: T4959: Add container registry authentication config for containers.
Feb 9 2023, 6:31 AM
GitHub <noreply@github.com> committed rVYOSONEXc300df1e5a22: Revert "container: T4959: Add container registry authentication config for… (authored by c-po).
Feb 9 2023, 6:31 AM
GitHub <noreply@github.com> committed rVYOSONEX10ab68a018dd: Merge pull request #1790 from Zen3515/current-add-container-login (authored by c-po).
Feb 9 2023, 6:31 AM
Viacheslav committed rVYOSONEX53d82ea2b142: T4971: PPPoE server add named ip pool and attr Framed-Pool.
Feb 9 2023, 6:11 AM
Viacheslav committed rVYOSONEXb721c5a65e8f: T4971: Add smoketest for named pppoe-server pool.
Feb 9 2023, 6:11 AM
GitHub <noreply@github.com> committed rVYOSONEX707688894c1a: Merge pull request #1803 from sever-sever/T4971 (authored by c-po).
Feb 9 2023, 6:11 AM
dmbaturin committed rVYOSONEX89191003df19: vyos.template: T4988: add bytes and seconds conversion filters.
Feb 9 2023, 6:04 AM
GitHub <noreply@github.com> committed rVYOSONEXcd78fe907711: Merge pull request #1807 from dmbaturin/T4988-new-jinja-filters (authored by c-po).
Feb 9 2023, 6:04 AM

Feb 8 2023

Viacheslav added a comment to T4393: sstp: add support for configuring host-name (SNI).

@c-po Do you have any idea for CLI?

Feb 8 2023, 7:31 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav moved T2603: pppoe-server: reduce min MTU from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 8 2023, 7:26 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav claimed T2229: PPPOE Default Queue type selection.
Feb 8 2023, 6:49 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T2229: PPPOE Default Queue type selection: VyOS 1.4 Sagitta.

@skoenman Could you write some examples of configuration?

Feb 8 2023, 6:48 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4987: Structure HTTPS-API output - "show ip bgp neighbours".

@Usman there is a root task for op-mode rewriting https://phabricator.vyos.net/T4564
https://github.com/vyos/vyos-1x/blob/1042fc32c371a74f048ffaf9a551b5d13c227f45/src/op_mode/bgp.py#L77-L80

Feb 8 2023, 6:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T1993: Extended pppoe rate-limiter .

PR https://github.com/vyos/vyos-1x/pull/1808

Feb 8 2023, 6:14 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Usman added a comment to T4987: Structure HTTPS-API output - "show ip bgp neighbours".

@Viacheslav Thanks, that works great!

Feb 8 2023, 5:34 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4987: Structure HTTPS-API output - "show ip bgp neighbours".

@Usman You have to update to the latest rolling.
https://vyos.net/get/nightly-builds/

Feb 8 2023, 4:17 PM · VyOS 1.4 Sagitta
Usman added a comment to T4987: Structure HTTPS-API output - "show ip bgp neighbours".

Thanks for the reply.

Feb 8 2023, 4:09 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4987: Structure HTTPS-API output - "show ip bgp neighbours".

Hi perhaps it is better to get JSON format

Feb 8 2023, 3:50 PM · VyOS 1.4 Sagitta
dmbaturin created T4988: Expose time and size conversion functions as Jinja2 filters.
Feb 8 2023, 3:41 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T1993: Extended pppoe rate-limiter from Open to In progress.
Feb 8 2023, 3:40 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Usman created T4987: Structure HTTPS-API output - "show ip bgp neighbours".
Feb 8 2023, 3:03 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX9733bbae4e21: T2603: PPPoE-server change default min-mtu value 1280.
Feb 8 2023, 2:51 PM
GitHub <noreply@github.com> committed rVYOSONEX1042fc32c371: Merge pull request #1804 from sever-sever/T2603 (authored by c-po).
Feb 8 2023, 2:51 PM
n.fort added a comment to T4986: Ability to filter traffic originating from the router itself via firewall .

I would prefer a different syntax, in order to avoid the necessity attaching it to an interface. Maybe something like:

Feb 8 2023, 2:11 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4857: SNMP - Implement FRR SNMP recommendations.

Error detected in forum: https://forum.vyos.io/t/unable-to-query-snmp-anymore-in-a-more-recent-1-4-version/10388/3
Fix for that bug: https://github.com/vyos/vyos-1x/pull/1805

Feb 8 2023, 1:35 PM · VyOS 1.4 Sagitta
n.fort changed the status of T4857: SNMP - Implement FRR SNMP recommendations from Confirmed to Needs testing.
Feb 8 2023, 1:33 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T1993: Extended pppoe rate-limiter : VyOS 1.4 Sagitta.
Feb 8 2023, 1:20 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T2603: pppoe-server: reduce min MTU.

PR 1.4 https://github.com/vyos/vyos-1x/pull/1804
PR 1.3 https://github.com/vyos/vyos-1x/pull/1806

Feb 8 2023, 1:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T2603: pppoe-server: reduce min MTU from Open to In progress.
Feb 8 2023, 12:27 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav claimed T2603: pppoe-server: reduce min MTU.
Feb 8 2023, 12:27 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the subtype of T4972: Support FQDN and IPv6 addresses for RADIUS servers in accel-ppp-backed protocols from "Task" to "Feature Request".
Feb 8 2023, 12:10 PM · VyOS Rolling
Viacheslav triaged T4972: Support FQDN and IPv6 addresses for RADIUS servers in accel-ppp-backed protocols as Wishlist priority.
Feb 8 2023, 12:10 PM · VyOS Rolling
Viacheslav closed T4852: pppoe - static default route deleted automatically with default-route none option as Wontfix.
Feb 8 2023, 11:36 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4852: pppoe - static default route deleted automatically with default-route none option.

Why did you delete this option and add a static route? Is there any use case?

Feb 8 2023, 11:20 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4852: pppoe - static default route deleted automatically with default-route none option.

This option has more priority than others.

Feb 8 2023, 11:03 AM · VyOS 1.4 Sagitta
Viacheslav closed T1288: FRR: rewrite staticd backend (/opt/vyatta/share/vyatta-cfg/templates/protocols/static/*), a subtask of T1267: FRR: Add interface name for static routes, as Resolved.
Feb 8 2023, 9:53 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T1288: FRR: rewrite staticd backend (/opt/vyatta/share/vyatta-cfg/templates/protocols/static/*) as Resolved.

Rewritten in 1.4
We are not planning to modify it in 1.3

Feb 8 2023, 9:53 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T4863: need an option for route policy to apply to dynamic interfaces l2tp*/ipoe*/pppoe* (for TCP MSS setting).

Got it; it is impossible for now after this migration https://phabricator.vyos.net/T3090
We are working on the re-design firewall CLI

Feb 8 2023, 9:23 AM · VyOS 1.4 Sagitta
Viacheslav created T4986: Ability to filter traffic originating from the router itself via firewall .
Feb 8 2023, 8:06 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4948: pppoe: add CLI option to allow definition of host-uniq flag from In progress to Needs testing.
Feb 8 2023, 7:38 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4985: reset vpn ipsec-peer command with peer name does not work from "Task" to "Bug".
Feb 8 2023, 7:31 AM · VyOS 1.4 Sagitta

Feb 7 2023

SrividyaA created T4985: reset vpn ipsec-peer command with peer name does not work .
Feb 7 2023, 6:29 PM · VyOS 1.4 Sagitta
Viacheslav closed T4868: L2TP ppp-options ipv6 does not work without ipv6 pool but should as Resolved.
Feb 7 2023, 4:33 PM · VyOS 1.4 Sagitta
Viacheslav moved T4980: chrony not listening as a server from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 7 2023, 4:32 PM · VyOS 1.4 Sagitta
Viacheslav moved T4117: Does not possible to configure PoD/CoA for L2TP vpn from Open to Finished on the VyOS 1.4 Sagitta board.
Feb 7 2023, 4:31 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav closed T4117: Does not possible to configure PoD/CoA for L2TP vpn as Resolved.
Feb 7 2023, 4:31 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
kylem closed T4980: chrony not listening as a server as Resolved.

I built a 1.4 ISO after my change was merged and deployed it to my home network. Setting a restrictive allow list works as expected, only the allowed IPs/subnets are able to use NTP. Removing all allow IPs prevents chrony/ntp from even listening to port 123. I don't think the "deny all" is needed in the code at all, but it is also not preventing the service to run as expected so I'll leave it.

Feb 7 2023, 4:16 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4969: QoS Policy - Unable to set class match mark number from In progress to Needs testing.
Feb 7 2023, 4:04 PM · vyatta-cfg-qos, VyOS 1.4 Sagitta
Viacheslav changed the status of T4980: chrony not listening as a server from Open to Needs testing.
Feb 7 2023, 4:03 PM · VyOS 1.4 Sagitta
aderouineau updated subscribers of T4123: checksum file fails to download from AWS S3 in rolling-release.

@c-po is this an S3 bucket policy issue, or do the files not exist?

Feb 7 2023, 3:57 PM · VyOS 1.4 Sagitta
Viacheslav created T4984: Firewall add mark for outgoing packets.
Feb 7 2023, 11:28 AM · VyOS Rolling
Viacheslav added a comment to T4982: OpenConnect should have TLS 1.0 and TLS 1.1 disabled by default.

Setting it configurable will be a good solution.
Just like it is done in OpenVPN

vyos@r14# set interfaces openvpn vtun0 tls tls-version-min 
Possible completions:
   1.0                  TLS v1.0
   1.1                  TLS v1.1
   1.2                  TLS v1.2
   1.3                  TLS v1.3
Feb 7 2023, 9:34 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav changed the subtype of T4981: Warn when a nat rule evicts a set of other active rules from "Task" to "Feature Request".
Feb 7 2023, 9:14 AM · VyOS Rolling
Viacheslav added a comment to T4971: Radius attribute "Framed-Pool" for PPPoE.

PR https://github.com/vyos/vyos-1x/pull/1803

Feb 7 2023, 8:55 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Zen3515 added a comment to T4983: `shutdown_required` should be set when running command `connect interface wwan0`.

Maybe, we need to handle cron script differently if ping failed?
Please let me know what should be the direction for solving this issue.

Feb 7 2023, 6:26 AM · VyOS Rolling
Zen3515 renamed T4983: `shutdown_required` should be set when running command `connect interface wwan0` from shutdown_required' to `shutdown_required` should be set when running command `connect interface wwan0`.
Feb 7 2023, 6:21 AM · VyOS Rolling
Zen3515 created T4983: `shutdown_required` should be set when running command `connect interface wwan0`.
Feb 7 2023, 6:12 AM · VyOS Rolling

Feb 6 2023

klase created T4982: OpenConnect should have TLS 1.0 and TLS 1.1 disabled by default.
Feb 6 2023, 10:52 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Kyle Mitchell <kyle.m.mitchell@oracle.com> committed rVYOSONEXba6277dfa089: ntp: T4980: change chrony deny all logic.
Feb 6 2023, 9:15 PM
GitHub <noreply@github.com> committed rVYOSONEX6b9b36db47a4: Merge pull request #1802 from kylem0/T4980 (authored by c-po).
Feb 6 2023, 9:15 PM
Alfa80 changed Issue type from unspecified to feature on T4981: Warn when a nat rule evicts a set of other active rules.
Feb 6 2023, 8:36 PM · VyOS Rolling
Alfa80 created T4981: Warn when a nat rule evicts a set of other active rules.
Feb 6 2023, 7:54 PM · VyOS Rolling
kylem updated the task description for T4980: chrony not listening as a server.
Feb 6 2023, 7:13 PM · VyOS 1.4 Sagitta
kylem updated the task description for T4980: chrony not listening as a server.
Feb 6 2023, 7:12 PM · VyOS 1.4 Sagitta
kylem added a comment to T4980: chrony not listening as a server.
Feb 6 2023, 7:12 PM · VyOS 1.4 Sagitta
kylem created T4980: chrony not listening as a server.
Feb 6 2023, 7:04 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX1f71a4f9d733: graphql: T4979: add query show_user_info.
Feb 6 2023, 6:51 PM
jestabro triaged T4979: Add API request 'show_user_info' for UI as Normal priority.
Feb 6 2023, 6:09 PM · VyOS 1.4 Sagitta
zsdc added a comment to T4589: BGP listen limit Increase via CLI command.

We also need to increase opened file descriptors (ulimit -n) to listen limit + some margin.
And consider adding a warning about increasing net.core.optmem_max for systems with a limit of more than 100 peers.

Feb 6 2023, 5:53 PM · VyOS 1.4 Sagitta (1.4.0-GA)
n.fort changed the status of T2408: DHCP Relay upstream and downstream interfaces from In progress to Needs testing.
Feb 6 2023, 3:11 PM · VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4943: Radius SSH login displays "permission denied" on 1.4 rolling release.

It is a problem with mapping user to radius_priv_user
This problem began after https://github.com/vyos/vyos-1x/commit/765f84386b6e94984ff79db2eab36d51f759159b#diff-0ab0ed71ce757261c4a6ae2f3a5bc441d6257d477bfb5435ae38f230777ff81cR51
If I set in sshd_config

Feb 6 2023, 2:15 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4971: Radius attribute "Framed-Pool" for PPPoE from Open to In progress.
Feb 6 2023, 1:28 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav assigned T4968: VPN IPsec check dpd and close action for empty values to a.apostoliuk.
Feb 6 2023, 9:53 AM · VyOS 1.4 Sagitta
jack9603301 added a comment to T4921: Miniupnpd only allows for IGDv2 while IGDv1 is mostly common used and supported.

I'm not free now. I'll check it when I'm free

Feb 6 2023, 8:41 AM · Bugs