Page MenuHomeVyOS Platform
Feed All Stories

Mar 14 2023

hcuk94 added a comment to T1229: Add support for unencrypted L2TPv2 client connections.

Just adding my +1 for this feature, would be very useful.
If I get time in the coming weeks/months I will try and pick up on the analysis where @njh left off.

Mar 14 2023, 8:22 AM · VyOS 1.5 Circinus
klipz added a comment to T5055: Firewall - Add packet type matcher (pkttype).

@n.fort A quick test of this against latest rolling looks like it's working as expected for general firewall rules:

Mar 14 2023, 1:35 AM · VyOS 1.4 Sagitta
mas90 created T5085: ospfv3 route-map not applied in FRR configuration.
Mar 14 2023, 1:28 AM · VyOS 1.4 Sagitta

Mar 13 2023

n.fort changed the status of T5050: Firewall - Add options for logging packets from Confirmed to In progress.
Mar 13 2023, 5:51 PM · VyOS 1.4 Sagitta
Solideco added a comment to T5022: VRRP add mail notification.

I agree that the Keepalivd SMTP implementation is lacking authentication.

Mar 13 2023, 4:37 PM · Restricted Project, VyOS 1.5 Circinus
n.fort changed the status of T5055: Firewall - Add packet type matcher (pkttype) from In progress to Needs testing.
Mar 13 2023, 3:44 PM · VyOS 1.4 Sagitta
marc_s added a comment to T4362: Wan Load Balancing - Can't create routing tables.

@Viacheslav I may be on to something. It's related to the order of execution of the DHCP client exit hook scripts in /etc/dhcp/dhclient-exit-hooks.d.

Mar 13 2023, 3:12 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2516: vyos-container: cannot configure ethernet interface.

PR for 1.4 https://github.com/vyos/vyos-1x/pull/1886

vyos@91800359325b# set interfaces ethernet eth0 address 192.0.2.5/24
[edit]
vyos@91800359325b# commit
[ interfaces ethernet eth0 ]
sudo: unable to resolve host 91800359325b: System error
Mar 13 2023, 1:38 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T2516: vyos-container: cannot configure ethernet interface from Needs testing to In progress.
Mar 13 2023, 1:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a project to T2516: vyos-container: cannot configure ethernet interface: VyOS 1.4 Sagitta.
Mar 13 2023, 1:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
marc_s added a comment to T4362: Wan Load Balancing - Can't create routing tables.

Also see https://forum.vyos.io/t/1-4-rolling-route-table-for-wan-load-balancing-not-created/.

Mar 13 2023, 11:23 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5074: Show IPSEC SA failed if remote access IKEv2 vpn is used. as Resolved.
Mar 13 2023, 10:18 AM · VyOS 1.4 Sagitta
a.apostoliuk moved T5074: Show IPSEC SA failed if remote access IKEv2 vpn is used. from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Mar 13 2023, 10:17 AM · VyOS 1.4 Sagitta
Viacheslav closed T4973: show dhcp server leases error for lease time 4294967295 as Resolved.
Mar 13 2023, 10:02 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5084: Interfrace negotiation may not work on some platforms.
Mar 13 2023, 9:48 AM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav created T5084: Interfrace negotiation may not work on some platforms.
Mar 13 2023, 9:47 AM · VyOS 1.4 Sagitta (1.4.0-GA)
aserkin added a comment to T5077: routes completely dropped from the node while running L2TP LNS service.

Actually only multihop BGP peers go down. Others are up, but the routes received from them does not go to kernel, so the connectivity drops.
Latest techsupport: https://oc.cpm.ru/index.php/s/Fg9FfoOatihBOrQ
The system was alive more than 12 hours, but crashed the same way as before.

Mar 13 2023, 8:23 AM · VyOS 1.4 Sagitta (1.4.0-GA)

Mar 12 2023

stepler added a comment to T5080: Conntrack enabled by default.

I don't think this ever worked as intended: see T3275#103228, vyos-build PR 185, and T3821.

Mar 12 2023, 3:16 PM · VyOS 1.4 Sagitta
penetal created T5083: extend interface schema to include which parameters are required.
Mar 12 2023, 8:56 AM
c-po claimed T5082: container: switch to netavark network stack.
Mar 12 2023, 7:49 AM · VyOS 1.4 Sagitta
c-po created T5082: container: switch to netavark network stack.
Mar 12 2023, 7:49 AM · VyOS 1.4 Sagitta
c-po changed the status of T5047: Recreate only a specific container from Open to In progress.
Mar 12 2023, 7:24 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

Mar 11 2023

Cheeze_It claimed T5081: ISIS and OSPF syncronization with IGP-LDP sync.
Mar 11 2023, 10:42 PM · VyOS 1.4 Sagitta
Cheeze_It created T5081: ISIS and OSPF syncronization with IGP-LDP sync.
Mar 11 2023, 10:38 PM · VyOS 1.4 Sagitta
c-po closed T5076: CI/CD: Docker container is bloated by legacy and conflicting dependencies as Resolved.
Mar 11 2023, 10:26 PM · VyOS 1.4 Sagitta
c-po moved T5076: CI/CD: Docker container is bloated by legacy and conflicting dependencies from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Mar 11 2023, 10:26 PM · VyOS 1.4 Sagitta
sarthurdev claimed T5080: Conntrack enabled by default.
Mar 11 2023, 3:40 PM · VyOS 1.4 Sagitta
sarthurdev created T5080: Conntrack enabled by default.
Mar 11 2023, 3:39 PM · VyOS 1.4 Sagitta

Mar 10 2023

c-po updated subscribers of T5022: VRRP add mail notification.

after an internal discussion we came to the conslusion that keepalived SMTP implementation is incomplete (e.g. it lacks authentication). In order to still support your request we think we should enable support of 3rd party configurations placed in e.g. /etc/keepalived/conf.d.

Mar 10 2023, 8:25 PM · Restricted Project, VyOS 1.5 Circinus
c-po moved T4959: Add container registry authentication config for containers from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Mar 10 2023, 8:19 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po changed the status of T4959: Add container registry authentication config for containers from In progress to Needs testing.
Mar 10 2023, 8:19 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T5079: xml: schema extension to support defaultValues on tagNodes from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Mar 10 2023, 8:19 PM · VyOS 1.4 Sagitta
c-po added a project to T5079: xml: schema extension to support defaultValues on tagNodes: VyOS 1.3 Equuleus (1.3.3).
Mar 10 2023, 8:18 PM · VyOS 1.4 Sagitta
c-po changed Difficulty level from unknown to easy on T5079: xml: schema extension to support defaultValues on tagNodes.
Mar 10 2023, 7:27 PM · VyOS 1.4 Sagitta
c-po changed the status of T5079: xml: schema extension to support defaultValues on tagNodes, a subtask of T4959: Add container registry authentication config for containers, from Open to In progress.
Mar 10 2023, 7:27 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po changed the status of T5079: xml: schema extension to support defaultValues on tagNodes from Open to In progress.
Mar 10 2023, 7:27 PM · VyOS 1.4 Sagitta
c-po created T5079: xml: schema extension to support defaultValues on tagNodes.
Mar 10 2023, 7:27 PM · VyOS 1.4 Sagitta
MartB added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

@sdev just for clarification do you mean "deleted" as in only existing entries but new ones will work or completely deleted?
Im asking because I do use keas global, subnet, pool and class option-data support extensively outside of vyos.
If this would stay/become a part of vyos that would be great!

Mar 10 2023, 5:27 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5058: Extend template filter range_to_regex.

PR https://github.com/vyos/vyos-1x/pull/1884

>>> range_to_regex(['10-20', '22-35', '50'])
'(1\\d|20|2[2-9]|3[0-5]|50)'
>>>
Mar 10 2023, 2:05 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5070: show bgp nexthop unavailable in VRF from Open to Needs testing.
Mar 10 2023, 1:02 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5074: Show IPSEC SA failed if remote access IKEv2 vpn is used. from In progress to Needs testing.
Mar 10 2023, 12:40 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4973: show dhcp server leases error for lease time 4294967295 from In progress to Needs testing.

Will be fixed in the next rolling release

Mar 10 2023, 12:02 PM · VyOS 1.4 Sagitta
tfiebig added a comment to T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes'.

Wanted to have the ticketid to write the right commit message right away. Diff is here: https://github.com/vyos/vyos-1x/compare/current...ichdasich:vyos-1x:filtered_routes

Mar 10 2023, 11:51 AM · VyOS 1.4 Sagitta
tfiebig created T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes'.
Mar 10 2023, 11:50 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5058: Extend template filter range_to_regex.

If we add vlan to range we get error

set service ipoe-server authentication mode 'noauth'
set service ipoe-server client-ip-pool name POOL1 gateway-address '192.0.2.1'
set service ipoe-server client-ip-pool name POOL1 subnet '192.0.2.0/24'
set service ipoe-server interface eth1 vlan '2000-3000'
commit
set service ipoe-server interface eth1 vlan '50'
commit

The second commit:

Mar 10 2023, 10:18 AM · VyOS 1.4 Sagitta
Viacheslav reopened T5058: Extend template filter range_to_regex as "Needs testing".
Mar 10 2023, 10:16 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4925: Need to add the possibility to configure Pseudo-Random Functions (PRF) in IKEv2 from Open to In progress.
Mar 10 2023, 9:35 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk added a project to T4925: Need to add the possibility to configure Pseudo-Random Functions (PRF) in IKEv2: VyOS 1.3 Equuleus (1.3.3).
Mar 10 2023, 9:35 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk reopened T4925: Need to add the possibility to configure Pseudo-Random Functions (PRF) in IKEv2 as "Open".
Mar 10 2023, 9:34 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav changed the status of T4973: show dhcp server leases error for lease time 4294967295 from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/1883

Mar 10 2023, 9:20 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5074: Show IPSEC SA failed if remote access IKEv2 vpn is used. from Open to In progress.
Mar 10 2023, 8:18 AM · VyOS 1.4 Sagitta
a.apostoliuk claimed T5074: Show IPSEC SA failed if remote access IKEv2 vpn is used..
Mar 10 2023, 8:18 AM · VyOS 1.4 Sagitta
aserkin created T5077: routes completely dropped from the node while running L2TP LNS service.
Mar 10 2023, 7:44 AM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav renamed T4973: show dhcp server leases error for lease time 4294967295 from show dhcp server leases error for static entries to show dhcp server leases error for lease time 4294967295.
Mar 10 2023, 7:12 AM · VyOS 1.4 Sagitta

Mar 9 2023

klipz updated subscribers of T5055: Firewall - Add packet type matcher (pkttype).

@n.fort @Viacheslav
Here is an example of what I am after for DNAT rule, specifically, using meta pkttype:

Mar 9 2023, 7:31 PM · VyOS 1.4 Sagitta
c-po changed the status of T5076: CI/CD: Docker container is bloated by legacy and conflicting dependencies from Open to In progress.
Mar 9 2023, 7:06 PM · VyOS 1.4 Sagitta
c-po created T5076: CI/CD: Docker container is bloated by legacy and conflicting dependencies.
Mar 9 2023, 7:06 PM · VyOS 1.4 Sagitta
c-po closed T4952: Improve interface completion helper CLI experience as Resolved.
Mar 9 2023, 6:43 PM · VyOS 1.4 Sagitta
daniil added a comment to T4989: QoS Policy Limiter - classes for marked traffic do not work.

QoS Policy Limiter now works correctly.
But the shaper classes for tagged traffic don't work.

Mar 9 2023, 6:35 PM · vyatta-cfg-qos, VyOS 1.4 Sagitta
Jimz added a comment to T4973: show dhcp server leases error for lease time 4294967295.

I was able to get it to work as expected by reducing the lease below 4294967295 and removing the /config/dhcpd.leases file. It should work per the instruction to make the lease effectively static. It had worked in the past so at some point the check that the resultant lease end day is numeric.

Mar 9 2023, 5:59 PM · VyOS 1.4 Sagitta
Jimz added a comment to T4973: show dhcp server leases error for lease time 4294967295.

Example configuration:

Mar 9 2023, 5:25 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T5018: Redirect to IFB removed after change in qos policy.

PR: https://github.com/vyos/vyos-1x/pull/1881

Mar 9 2023, 5:09 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T5018: Redirect to IFB removed after change in qos policy from Confirmed to In progress.
Mar 9 2023, 4:26 PM · VyOS 1.4 Sagitta
Viacheslav awarded T5046: CLI for password complexity enforcement PAM module a Like token.
Mar 9 2023, 4:18 PM · VyOS 1.5 Circinus
Viacheslav closed T5066: Different GRE tunnel but same tunnel keys error as Resolved.
Mar 9 2023, 4:02 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav changed the status of T5073: IPoE-server interface option failed to parse from In progress to Needs testing.
Mar 9 2023, 3:58 PM · VyOS 1.4 Sagitta
sarthurdev closed T5075: QoS removes interface mirror/redirect rules as Invalid.

My bad

Mar 9 2023, 3:23 PM · VyOS 1.4 Sagitta
rayzilt added a comment to T5075: QoS removes interface mirror/redirect rules.

Seems to be the same task -> https://vyos.dev/T5018

Mar 9 2023, 3:22 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T5075: QoS removes interface mirror/redirect rules from Open to In progress.
Mar 9 2023, 3:15 PM · VyOS 1.4 Sagitta
sarthurdev created T5075: QoS removes interface mirror/redirect rules.
Mar 9 2023, 3:15 PM · VyOS 1.4 Sagitta
tfiebig added a comment to T5069: bgp large-community-list regex validation incomplete.

Just put this on a live system, and it behaves as intended (so far). Special meaning of _ would certainly have to be added to the check, i guess, but that needs further delving into bgp-regex syntax.

Mar 9 2023, 2:45 PM · VyOS 1.4 Sagitta (1.4.0-epa3), Restricted Project, VyOS 1.5 Circinus
erkin changed the status of T5046: CLI for password complexity enforcement PAM module, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
Mar 9 2023, 2:42 PM · VyOS 1.5 Circinus
erkin changed the status of T5046: CLI for password complexity enforcement PAM module from Open to In progress.
Mar 9 2023, 2:42 PM · VyOS 1.5 Circinus
erkin updated the task description for T5046: CLI for password complexity enforcement PAM module.
Mar 9 2023, 2:41 PM · VyOS 1.5 Circinus
tfiebig added a comment to T5070: show bgp nexthop unavailable in VRF.

https://github.com/vyos/vyos-1x/pull/1880

Mar 9 2023, 2:07 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4973: show dhcp server leases error for lease time 4294967295.

@Jimz could you share an example of configuration?
I can't reproduce it with

set service dhcp-server shared-network-name Lan01 authoritative
set service dhcp-server shared-network-name Lan01 name-server '1.1.1.1'
set service dhcp-server shared-network-name Lan01 subnet 192.0.2.0/24 default-router '192.0.2.1'
set service dhcp-server shared-network-name Lan01 subnet 192.0.2.0/24 range R1 start '192.0.2.10'
set service dhcp-server shared-network-name Lan01 subnet 192.0.2.0/24 range R1 stop '192.0.2.254'
set service dhcp-server shared-network-name Lan01 subnet 192.0.2.0/24 static-mapping myhost ip-address '192.0.2.5'
set service dhcp-server shared-network-name Lan01 subnet 192.0.2.0/24 static-mapping myhost mac-address '02:a6:0c:88:3e:a2'
Mar 9 2023, 1:43 PM · VyOS 1.4 Sagitta
tfiebig added a comment to T5070: show bgp nexthop unavailable in VRF.

Let me give it another test-run in a bit and then i'll issue a PR.

Mar 9 2023, 12:56 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5070: show bgp nexthop unavailable in VRF.

Could you create a PR?

Mar 9 2023, 12:52 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3008: Migrate from ntpd to chronyd.

Discovered a couple of problems with chrony using the existing CLI.

Mar 9 2023, 12:25 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5063: IPoE-server ethX vlan must not be used with client-subnet.

PR https://github.com/vyos/vyos-1x/pull/1879

Mar 9 2023, 11:00 AM · VyOS 1.4 Sagitta
a.apostoliuk created T5074: Show IPSEC SA failed if remote access IKEv2 vpn is used..
Mar 9 2023, 9:25 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5066: Different GRE tunnel but same tunnel keys error.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1878

Mar 9 2023, 9:21 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav edited projects for T5066: Different GRE tunnel but same tunnel keys error, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.2).
Mar 9 2023, 8:53 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav moved T5066: Different GRE tunnel but same tunnel keys error from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Mar 9 2023, 8:52 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T5073: IPoE-server interface option failed to parse.

PR https://github.com/vyos/vyos-1x/pull/1877

Mar 9 2023, 8:15 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5073: IPoE-server interface option failed to parse from Open to In progress.
Mar 9 2023, 7:29 AM · VyOS 1.4 Sagitta
Viacheslav created T5073: IPoE-server interface option failed to parse.
Mar 9 2023, 7:29 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T5071: QOS-Rewrite: DSCP match missing from "Task" to "Bug".
Mar 9 2023, 3:56 AM · VyOS 1.4 Sagitta
MartB created T5072: QOS-Rewrite: protocol name used literally.
Mar 9 2023, 1:35 AM · VyOS 1.4 Sagitta
MartB created T5071: QOS-Rewrite: DSCP match missing.
Mar 9 2023, 1:31 AM · VyOS 1.4 Sagitta
MartB added a comment to T4989: QoS Policy Limiter - classes for marked traffic do not work.

@c-po Isnt this implementation wrong for "shaper" anyway?
The speed should only be taken from the interface as an last resort, if the default bandwidth is configured in a no percentage unit it should be used instead, no?

Mar 9 2023, 1:23 AM · vyatta-cfg-qos, VyOS 1.4 Sagitta

Mar 8 2023

tfiebig created T5070: show bgp nexthop unavailable in VRF.
Mar 8 2023, 8:30 PM · VyOS 1.4 Sagitta
tfiebig created T5069: bgp large-community-list regex validation incomplete.
Mar 8 2023, 7:39 PM · VyOS 1.4 Sagitta (1.4.0-epa3), Restricted Project, VyOS 1.5 Circinus
jestabro triaged T5068: Generate op-mode API client requests along with schema generation as Normal priority.
Mar 8 2023, 7:39 PM · VyOS 1.4 Sagitta
jestabro edited projects for T4396: HTTP API no response after several days restarted, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.3).
Mar 8 2023, 7:16 PM · VyOS 1.4 Sagitta
jestabro closed T4396: HTTP API no response after several days restarted as Resolved N/A.

This was never reproduced; user will report if recurrence and we will reopen as needed.

Mar 8 2023, 7:15 PM · VyOS 1.4 Sagitta
jestabro edited projects for T4318: Add delete_tag to configtree.py, added: VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.4); removed VyOS 1.3 Equuleus (1.3.3).

Lower priority and will need testing when implemented.

Mar 8 2023, 7:10 PM · VyOS 1.5 Circinus, Restricted Project
jestabro closed T4381: OpenVPN: Add "Tunnel IP" column in "show openvpn server" operational command as Resolved.
Mar 8 2023, 3:17 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro closed T4872: Op-mode show openvpn misses a case when parsing for tunnel IP, a subtask of T4381: OpenVPN: Add "Tunnel IP" column in "show openvpn server" operational command, as Resolved.
Mar 8 2023, 3:16 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro closed T4872: Op-mode show openvpn misses a case when parsing for tunnel IP as Resolved.
Mar 8 2023, 3:16 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta