Page MenuHomeVyOS Platform
Feed All Stories

Mar 7 2023

jestabro closed T2649: Ensure configration mode scripts conform to coding guidelines as Resolved.
Mar 7 2023, 6:36 PM · VyOS 1.3 Equuleus
jestabro added a comment to T2649: Ensure configration mode scripts conform to coding guidelines.

This was a meta-task for conformance to coding guidelines for inclusion of scripts in vyos-configd. Those guidelines are documented and checked in the smoketest test_configd_inspect.py for both Sagitta and Equuleus, and will be closed.

Mar 7 2023, 6:35 PM · VyOS 1.3 Equuleus
jestabro edited projects for T3574: Add constraintGroup for combining validators with logical AND, added: VyOS 1.3 Equuleus (1.3.4); removed VyOS 1.3 Equuleus (1.3.3).

This is potentially a useful feature, but has no current use, so there is no reason to backport it for 1.3.3. I wil add a 1.3.4 tag to keep it in mind in case it is needed for a future backport.

Mar 7 2023, 5:15 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro moved T2838: Ethernet device names changing, multiple hw-id being added from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Mar 7 2023, 5:04 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro closed T2838: Ethernet device names changing, multiple hw-id being added as Resolved.
Mar 7 2023, 5:04 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro added a comment to T2838: Ethernet device names changing, multiple hw-id being added.

As mentioned above, there were two separate issues here:
(1) the issue of quoting of hw-id values is resolved in this task, for both Sagitta and Equuleus

Mar 7 2023, 5:03 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
diodep added a comment to T3655: NAT Problem with VRF.

it doesn't seem the same problem as here, this logic that was applied over this version was vrf not on the table . Could you share full configuration ? there is some point over vrfs / vrf default /leaking that are not clear. So I can replicate the scenery and we see what is going on .

Mar 7 2023, 4:36 PM · VyOS 1.5 Circinus, Known issue, VyOS 1.4 Sagitta
Viacheslav changed the status of T5063: IPoE-server ethX vlan must not be used with client-subnet from Open to In progress.
Mar 7 2023, 3:29 PM · VyOS 1.4 Sagitta
Viacheslav renamed T5063: IPoE-server ethX vlan must not be used with client-subnet from IPoE-server network vlan must not be used with client-subnet to IPoE-server ethX vlan must not be used with client-subnet.
Mar 7 2023, 3:27 PM · VyOS 1.4 Sagitta
Viacheslav created T5063: IPoE-server ethX vlan must not be used with client-subnet.
Mar 7 2023, 3:05 PM · VyOS 1.4 Sagitta
dex added a comment to T5062: `set failed` after VRRP transition scripts.

I'll take a look at the guidelines to contribute, thank you!

Mar 7 2023, 2:17 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5062: `set failed` after VRRP transition scripts.

@dex Update please the documentation if you want to help project or we'll do it later.
Thanks

Mar 7 2023, 2:09 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5061: All containers restart on config change.

The same task T5047

Mar 7 2023, 2:05 PM · VyOS 1.4 Sagitta
dex added a comment to T5062: `set failed` after VRRP transition scripts.

Thank you for the clarification, I will edit my scripts accordingly. I was under the impression that VRRP transition scripts are called with the vyattacfg group out of the box, since there is an example in the documentation which has the sg part missing: https://docs.vyos.io/en/latest/automation/command-scripting.html#run-configuration-commands

Mar 7 2023, 2:05 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5060: add a VRRP 'maintenance mode'.

We cannot disable keepalived as it is used not only for VRRP and also for virtual-server

set high-availability virtual-server xxxx

So it should be something like set high-availability disable
Or just clean the VRRP configuration with set high-availability vrrp disable

Mar 7 2023, 2:03 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T5059: add 'disable' option to DHCP relay config: VyOS 1.4 Sagitta.
Mar 7 2023, 1:59 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5062: `set failed` after VRRP transition scripts.

To make sure that a script is not accidentally called without the vyattacfg group, the script can be safeguarded like this:

if [ "$(id -g -n)" != 'vyattacfg' ] ; then
    exec sg vyattacfg -c "/bin/vbash $(readlink -f $0) $@"
fi

https://docs.vyos.io/en/latest/automation/command-scripting.html#executing-configuration-scripts

Mar 7 2023, 1:58 PM · VyOS 1.4 Sagitta
Viacheslav closed T5058: Extend template filter range_to_regex as Resolved.
Mar 7 2023, 1:31 PM · VyOS 1.4 Sagitta
Viacheslav closed T5057: IPoE server incorrect interface regex as Resolved.
Mar 7 2023, 1:30 PM · VyOS 1.4 Sagitta
dex created T5062: `set failed` after VRRP transition scripts.
Mar 7 2023, 12:48 PM · VyOS 1.4 Sagitta
dex created T5061: All containers restart on config change.
Mar 7 2023, 12:33 PM · VyOS 1.4 Sagitta
dex created T5060: add a VRRP 'maintenance mode'.
Mar 7 2023, 12:25 PM · VyOS 1.4 Sagitta
dex created T5059: add 'disable' option to DHCP relay config.
Mar 7 2023, 12:12 PM · VyOS 1.4 Sagitta
aserkin added a comment to T5045: BFD is not starting after upgrade to 1.4-rolling-202302150317.

again. It says - download complete. And i can get it from the message:

image.png (163×451 px, 8 KB)

Mar 7 2023, 11:32 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5045: BFD is not starting after upgrade to 1.4-rolling-202302150317.

Thank you for the hint, @c-po
Attached the entire config we have on the node.

Mar 7 2023, 11:08 AM · VyOS 1.4 Sagitta
aserkin added a comment to T5045: BFD is not starting after upgrade to 1.4-rolling-202302150317.

Thank you for the hint, @c-po
Attached the entire config we have on the node.


There're not much BGP peers, but quite a number of VRFs which terminate remote access l2tp subscribers.
I'd really appreciate any advice on the system optimization for that particular task - ideally i'd like this node to terminate up to 20k l2tp subscribers with very low traffic (not exceeding 0.5gbps i guess).

Mar 7 2023, 11:01 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5057: IPoE server incorrect interface regex from In progress to Needs testing.
Mar 7 2023, 10:12 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5058: Extend template filter range_to_regex from In progress to Needs testing.
Mar 7 2023, 10:12 AM · VyOS 1.4 Sagitta
Viacheslav closed T3443: Deleting VRRP-VIP and adding the same address to physical interface in one commit fails as Resolved N/A.
Mar 7 2023, 9:22 AM · VyOS 1.2 Crux
Viacheslav added a comment to T5057: IPoE server incorrect interface regex.

PR https://github.com/vyos/vyos-1x/pull/1872

Mar 7 2023, 8:57 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5057: IPoE server incorrect interface regex from Open to In progress.
Mar 7 2023, 7:30 AM · VyOS 1.4 Sagitta
c-po added a comment to T5045: BFD is not starting after upgrade to 1.4-rolling-202302150317.

Well there should be no harm in lifting the limit of open file descriptors for FRR as its a huge process tree.
Can you share your entire protocols configuration tree so we see what else is configured?

Mar 7 2023, 6:47 AM · VyOS 1.4 Sagitta

Mar 6 2023

aserkin added a comment to T5045: BFD is not starting after upgrade to 1.4-rolling-202302150317.

The bfdd process did not start until i changed LimitNOFILE=1024 to LimitNOFILE=2048 in /lib/systemd/system/frr.service
That did the trick, but i'm not sure it's a good solution.
What do you think, @Viacheslav ?

Mar 6 2023, 11:27 PM · VyOS 1.4 Sagitta
aserkin added a comment to T5045: BFD is not starting after upgrade to 1.4-rolling-202302150317.

The limits look like standard
root@nn-vlns-3-1:~# ulimit -Hn
1048576
root@nn-vlns-3-1:~# ulimit -Sn
1024
root@nn-vlns-3-1:~# sysctl fs.file-max
fs.file-max = 9223372036854775807

Mar 6 2023, 8:00 PM · VyOS 1.4 Sagitta
klipz added a comment to T5055: Firewall - Add packet type matcher (pkttype).

@n.fort I apologize for the late entry here - could this also be exposed for NAT rules?
Edit: wow you guys worked so fast on this it got pulled before I could add this request :D

Mar 6 2023, 7:17 PM · VyOS 1.4 Sagitta
n.fort added a comment to T5055: Firewall - Add packet type matcher (pkttype).

PR: https://github.com/vyos/vyos-1x/pull/1871

Mar 6 2023, 7:01 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5055: Firewall - Add packet type matcher (pkttype) from Confirmed to In progress.
Mar 6 2023, 6:47 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5058: Extend template filter range_to_regex.

PR https://github.com/vyos/vyos-1x/pull/1870

>>> from vyos.template import range_to_regex
>>> 
>>> range_to_regex(['11-12', '14-15'])
'(1[1-2]|1[4-5])'
>>> 
>>>
Mar 6 2023, 6:22 PM · VyOS 1.4 Sagitta
Viacheslav renamed T5058: Extend template filter range_to_regex from Extent template filter range_to_regex to Extend template filter range_to_regex.
Mar 6 2023, 5:36 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5058: Extend template filter range_to_regex from Open to In progress.
Mar 6 2023, 5:36 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5058: Extend template filter range_to_regex.
Mar 6 2023, 5:19 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5058: Extend template filter range_to_regex from "Bug" to "Feature Request".
Mar 6 2023, 5:19 PM · VyOS 1.4 Sagitta
Viacheslav created T5058: Extend template filter range_to_regex.
Mar 6 2023, 5:19 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5056: IPoE server vlan-mon is not working .

I created a separate task for it T5057

Mar 6 2023, 3:06 PM · VyOS 1.4 Sagitta
Viacheslav created T5057: IPoE server incorrect interface regex.
Mar 6 2023, 3:05 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5056: IPoE server vlan-mon is not working from In progress to Needs testing.
Mar 6 2023, 2:51 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5056: IPoE server vlan-mon is not working .

The second bug is interface Regex does not work
Get:

interface=re:eth1\.\d+

Expect:

interface=re:^eth1\.(200\d|20[1-9]\d|2[1-9]\d{2}|3000)$
Mar 6 2023, 12:33 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5056: IPoE server vlan-mon is not working .

PR https://github.com/vyos/vyos-1x/pull/1869

vyos@r14# run show conf com | match ipoe
set service ipoe-server authentication mode 'noauth'
set service ipoe-server interface eth1 client-subnet '100.64.24.0/24'
set service ipoe-server interface eth1 network 'vlan'
set service ipoe-server interface eth1 vlan '2000-3000'
[edit]
vyos@r14#

Check config:

vyos@r14# cat /run/accel-pppd/ipoe.conf  | grep "\[ipoe" -A 7
[ipoe]
verbose=1
interface=re:eth1\.\d+,shared=0,mode=L2,ifcfg=1,range=100.64.24.0/24,start=dhcpv4,ipv6=1
noauth=1
proxy-arp=1
Mar 6 2023, 12:06 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5056: IPoE server vlan-mon is not working from Open to In progress.
Mar 6 2023, 11:14 AM · VyOS 1.4 Sagitta
Viacheslav created T5056: IPoE server vlan-mon is not working .
Mar 6 2023, 11:11 AM · VyOS 1.4 Sagitta
n.fort changed the status of T5055: Firewall - Add packet type matcher (pkttype) from Open to Confirmed.
Mar 6 2023, 10:54 AM · VyOS 1.4 Sagitta
n.fort created T5055: Firewall - Add packet type matcher (pkttype).
Mar 6 2023, 10:54 AM · VyOS 1.4 Sagitta
Viacheslav renamed T4973: show dhcp server leases error for lease time 4294967295 from show dhcp server leases error to show dhcp server leases error for static entries.
Mar 6 2023, 10:24 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4973: show dhcp server leases error for lease time 4294967295.

It is incompatible with static entries.
Maybe it should be fixed after migrating to KEA-DHCP T3316

Mar 6 2023, 10:23 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T5053: Vyatta-cfg Post-Removal Hook Tries to Disable Deleted Service: VyOS 1.4 Sagitta.
Mar 6 2023, 10:21 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5054: ipsec: "show vpn ipsec remote-access" does not list active connections.

The similar task T5042

Mar 6 2023, 7:41 AM · VyOS 1.4 Sagitta
c-po created T5054: ipsec: "show vpn ipsec remote-access" does not list active connections.
Mar 6 2023, 7:02 AM · VyOS 1.4 Sagitta

Mar 5 2023

jestabro added a comment to T5051: Use Literal types to provide op-mode CLI choices and API enums.

PR:
https://github.com/vyos/vyos-1x/pull/1868

Mar 5 2023, 9:08 PM · VyOS 1.4 Sagitta
jestabro closed T5040: Generate API GraphQL schema on installation, rather than dynamically as Resolved.
Mar 5 2023, 8:14 PM · VyOS 1.4 Sagitta
sempervictus created T5053: Vyatta-cfg Post-Removal Hook Tries to Disable Deleted Service.
Mar 5 2023, 1:29 AM · VyOS 1.4 Sagitta

Mar 4 2023

RyVolodya created T5052: Error displaying dhcpv6 prefix delegation leases.
Mar 4 2023, 2:41 PM · VyOS 1.4 Sagitta
diodep added a comment to T3655: NAT Problem with VRF.

it doesn't seem the same problem as here, this logic that was applied over this version was vrf not on the table . Could you share full configuration ? there is some point over vrfs / vrf default /leaking that are not clear. So I can replicate the scenery and we see what is going on .

Mar 4 2023, 2:52 AM · VyOS 1.5 Circinus, Known issue, VyOS 1.4 Sagitta

Mar 3 2023

jestabro added a comment to T5051: Use Literal types to provide op-mode CLI choices and API enums.

Needs final testing before PR
https://github.com/vyos/vyos-1x/compare/current...jestabro:literal

Mar 3 2023, 9:20 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T5051: Use Literal types to provide op-mode CLI choices and API enums.
Mar 3 2023, 4:56 PM · VyOS 1.4 Sagitta
jestabro changed the status of T5051: Use Literal types to provide op-mode CLI choices and API enums from Open to In progress.
Mar 3 2023, 4:54 PM · VyOS 1.4 Sagitta
jestabro triaged T5051: Use Literal types to provide op-mode CLI choices and API enums as Normal priority.
Mar 3 2023, 4:54 PM · VyOS 1.4 Sagitta
jestabro created T5051: Use Literal types to provide op-mode CLI choices and API enums.
Mar 3 2023, 4:54 PM · VyOS 1.4 Sagitta
fernando added a comment to T3655: NAT Problem with VRF.

it doesn't seem the same problem as here, this logic that was applied over this version was vrf not on the table . Could you share full configuration ? there is some point over vrfs / vrf default /leaking that are not clear. So I can replicate the scenery and we see what is going on .

Mar 3 2023, 3:14 PM · VyOS 1.5 Circinus, Known issue, VyOS 1.4 Sagitta
Jimz added a comment to T4973: show dhcp server leases error for lease time 4294967295.

Possible completions:

<0-4294967295>       DHCP lease time in seconds
Mar 3 2023, 1:35 PM · VyOS 1.4 Sagitta
Jimz added a comment to T4973: show dhcp server leases error for lease time 4294967295.

Standard lease I have in the configuration is "lease 4294967295"

Mar 3 2023, 1:21 PM · VyOS 1.4 Sagitta
Jimz added a comment to T4973: show dhcp server leases error for lease time 4294967295.

That is a static reservation. Ensures I have the same IP for a specific host.

Mar 3 2023, 1:18 PM · VyOS 1.4 Sagitta
Viacheslav closed T4625: Update ocserv to current revision (1.1.6) as Resolved.

VyOS 1.3-stable-202303030442 Works as expected

vyos@r1# run show conf com | match open
set vpn openconnect authentication mode 'radius'
set vpn openconnect authentication radius server 192.168.122.14 key 'vyos-secret'
set vpn openconnect listen-ports tcp '4433'
set vpn openconnect listen-ports udp '4433'
set vpn openconnect network-settings client-ip-settings subnet '100.64.12.0/24'
set vpn openconnect ssl ca-cert-file '/config/auth/ca.crt'
set vpn openconnect ssl cert-file '/config/auth/server.crt'
set vpn openconnect ssl key-file '/config/auth/server.key'
[edit]
vyos@r1# 
[edit]
vyos@r1# run show version all | match ocser
ii  ocserv                               1.1.6-3                        amd64        OpenConnect VPN server compatible with Cisco AnyConnect VPN
[edit]
vyos@r1# 
[edit]
vyos@r1# run show openconnect-server sessions 
interface    username    ip             remote IP        RX      TX         state      uptime
-----------  ----------  -------------  ---------------  ------  ---------  ---------  --------
sslvpn0      foo         100.64.12.225  192.168.122.205  1.3 KB  152 bytes  connected  55s
[edit]
vyos@r1#
Mar 3 2023, 12:36 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort changed the status of T5050: Firewall - Add options for logging packets from Open to Confirmed.
Mar 3 2023, 12:05 PM · VyOS 1.4 Sagitta
n.fort created T5050: Firewall - Add options for logging packets.
Mar 3 2023, 12:04 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5022: VRRP add mail notification.

PR https://github.com/vyos/vyos-1x/pull/1866

set high-availability vrrp global-parameters notification mail '[email protected]'
set high-availability vrrp global-parameters notification send-faults
set high-availability vrrp global-parameters notification smtp-server address '127.0.0.1'
set high-availability vrrp global-parameters notification smtp-server connection-timeout '30'
set high-availability vrrp global-parameters notification smtp-server port '25'
set high-availability vrrp global-parameters notification source-mail '[email protected]'
set high-availability vrrp global-parameters router-id 'MYROUTER'
Mar 3 2023, 11:41 AM · Restricted Project, VyOS 1.5 Circinus
diodep added a comment to T5048: QoS doesn't work correctly root task.

As I understand there no percent or auto and it now expects only rate, needs to check

vyos@r14# set qos policy shaper test default bandwidth
Possible completions:
   <number>             Bits per second
   <number>bit          Bits per second
   <number>kbit         Kilobits per second
   <number>mbit         Megabits per second
   <number>gbit         Gigabits per second
   <number>tbit         Terabits per second
   <number>
Mar 3 2023, 8:51 AM · VyOS 1.4 Sagitta
Viacheslav assigned T5048: QoS doesn't work correctly root task to c-po.
Mar 3 2023, 8:48 AM · VyOS 1.4 Sagitta
diodep added a comment to T5048: QoS doesn't work correctly root task.

I don't know why when I set bandwidth from 10k-10mbit/s, the QoS shaper works correctly but when I set to 100mbit/s~600mbit/s, I only get fews of mbit/s or tens of mbit/s. When I set above about 800mbit/s it looks like no limitation at all. When I manually set limit by tc commands, it seems okay.

Mar 3 2023, 8:45 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5048: QoS doesn't work correctly root task.

As I understand there no percent or auto and it now expects only rate, needs to check

vyos@r14# set qos policy shaper test default bandwidth
Possible completions:
   <number>             Bits per second
   <number>bit          Bits per second
   <number>kbit         Kilobits per second
   <number>mbit         Megabits per second
   <number>gbit         Gigabits per second
   <number>tbit         Terabits per second
   <number>
Mar 3 2023, 8:39 AM · VyOS 1.4 Sagitta
diodep added a comment to T5048: QoS doesn't work correctly root task.

I don't know why I set a 100mbit/s shaper, but result in lots of retry and 5~10mbit/s speed.

Mar 3 2023, 8:37 AM · VyOS 1.4 Sagitta
diodep added a comment to T5048: QoS doesn't work correctly root task.

Try the latest rolling release

Mar 3 2023, 8:29 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4973: show dhcp server leases error for lease time 4294967295.

@Jimz Which lease time are you useing?

starts 5 2023/03/03 02:09:13;
ends never;

With default config I see something like

lease 192.0.2.10 {
  starts 5 2023/03/03 08:07:15;
  ends 6 2023/03/04 08:07:15;
...
Mar 3 2023, 8:21 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5048: QoS doesn't work correctly root task.

Try the latest rolling release

Mar 3 2023, 8:01 AM · VyOS 1.4 Sagitta
diodep added a comment to T3655: NAT Problem with VRF.

I have almost same problem here. Can't NAT between two VRFs correctly. The outgoing packet has been NATed correctly but the incoming packet seems be dropped, can't reach the source, it seems the return packet can't be tracked correctly.

Mar 3 2023, 6:21 AM · VyOS 1.5 Circinus, Known issue, VyOS 1.4 Sagitta
Jimz added a comment to T4973: show dhcp server leases error for lease time 4294967295.

sh dhcp server leases
Traceback (most recent call last):

File "/usr/libexec/vyos/op_mode/dhcp.py", line 286, in <module>
  res = vyos.opmode.run(sys.modules[__name__])
        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/vyos/opmode.py", line 227, in run
  res = func(**args)
        ^^^^^^^^^^^^
File "/usr/libexec/vyos/op_mode/dhcp.py", line 246, in _wrapper
  return func(*args, **kwargs)
         ^^^^^^^^^^^^^^^^^^^^^
File "/usr/libexec/vyos/op_mode/dhcp.py", line 277, in show_server_leases
  lease_data = _get_raw_server_leases(family=family, pool=pool, sorted=sorted, state=state)
               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/libexec/vyos/op_mode/dhcp.py", line 85, in _get_raw_server_leases
  data_lease['end'] = lease.end.timestamp()
                      ^^^^^^^^^^^^^^^^^^^

AttributeError: 'NoneType' object has no attribute 'timestamp'

Mar 3 2023, 3:12 AM · VyOS 1.4 Sagitta
Jimz added a comment to T4973: show dhcp server leases error for lease time 4294967295.

After the first lease I got the same error:

Mar 3 2023, 3:11 AM · VyOS 1.4 Sagitta
diodep added a comment to T5049: Configure GRE over IPsec tunnel when source port is in VRF, OSPF causes GRE tunnel broken..

Btw, in this rolling release, OSPF BFD in tunnel doesn't work correctly too.

Mar 3 2023, 3:06 AM · VyOS 1.4 Sagitta
diodep created T5049: Configure GRE over IPsec tunnel when source port is in VRF, OSPF causes GRE tunnel broken..
Mar 3 2023, 3:03 AM · VyOS 1.4 Sagitta
diodep added a comment to T4031: Ability to configure DMVPN in vrf.

You can manually modify strongswan's systemd service file to add 'ip vrf exec charond'. But it causes other problem.

Mar 3 2023, 2:47 AM · VyOS 1.4 Sagitta
diodep created T5048: QoS doesn't work correctly root task.
Mar 3 2023, 2:44 AM · VyOS 1.4 Sagitta
Jimz added a comment to T4973: show dhcp server leases error for lease time 4294967295.

I backed up /config/dhcpd.leases - replaced it with an empty file. And it appears to be working, the /config/dhcpd.leases file seems to have been corrupted or malformated.

Mar 3 2023, 2:08 AM · VyOS 1.4 Sagitta
Jimz added a comment to T4973: show dhcp server leases error for lease time 4294967295.

Is there a way to share it privately? It has some of the internal domains and leases.

Mar 3 2023, 1:48 AM · VyOS 1.4 Sagitta

Mar 2 2023

j.bordon added a comment to T4916: Rewrite IPsec authentication.

PR https://github.com/vyos/vyos-1x/pull/1865
We found some issues for the migration and we fixed it on this one.

Mar 2 2023, 6:41 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4712: Collaborative Protection Profile cPP for Network Devices root task: T5046: CLI for password complexity enforcement PAM module.
Mar 2 2023, 4:36 PM · VyOS 1.5 Circinus
Viacheslav added a parent task for T5046: CLI for password complexity enforcement PAM module: T4712: Collaborative Protection Profile cPP for Network Devices root task.
Mar 2 2023, 4:36 PM · VyOS 1.5 Circinus
Viacheslav updated the task description for T5047: Recreate only a specific container.
Mar 2 2023, 3:12 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav created T5047: Recreate only a specific container.
Mar 2 2023, 3:07 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
sarthurdev changed the status of T5039: Can't add new local user from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1863

Mar 2 2023, 2:46 PM · VyOS 1.4 Sagitta
erkin created T5046: CLI for password complexity enforcement PAM module.
Mar 2 2023, 2:42 PM · VyOS 1.5 Circinus
njh added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

I was interested in why ping-check is no longer available.
There is a good article about it here:
https://kb.isc.org/docs/why-doesnt-kea-support-ping-check

Mar 2 2023, 2:08 PM · VyOS 1.5 Circinus