Page MenuHomeVyOS Platform
Feed All Stories

Apr 10 2023

tfiebig added a comment to T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes'.

done

Apr 10 2023, 12:02 PM · VyOS 1.4 Sagitta
Viacheslav closed T5070: show bgp nexthop unavailable in VRF as Resolved.
Apr 10 2023, 11:52 AM · VyOS 1.4 Sagitta
rayzilt added a comment to T5018: Redirect to IFB removed after change in qos policy.

After applying above rules an a system without any qos configured, it failed to create the redirect, commit was succesfull but tc disk show did not show the redirect. After removing and applying the redirect between commits, the redirect was present.
Changing the max bandwidth to 10mbit and commiting removed the redirect again.

Apr 10 2023, 11:49 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes'.

Create please the PR
Thanks.

Apr 10 2023, 11:48 AM · VyOS 1.4 Sagitta
Viacheslav closed T5110: Show frr op-mode vtysh_pam: Failed in account validation, a subtask of T5100: Update FRR to 8.5, as Resolved.
Apr 10 2023, 11:46 AM · VyOS 1.4 Sagitta
Viacheslav closed T5110: Show frr op-mode vtysh_pam: Failed in account validation as Resolved.
Apr 10 2023, 11:46 AM · VyOS 1.4 Sagitta
Viacheslav reopened T5151: EAP-TLS TLSv1.0/1.1 regression after T5003 as "Needs testing".

It cannot pass the smoketest /usr/libexec/vyos/tests/smoke/cli/test_interfaces_wireless.py

06:48:28  DEBUG - test_wireless_access_point_bridge (__main__.WirelessInterfaceTest.test_wireless_access_point_bridge) ... FAIL
06:48:29  DEBUG - test_wireless_access_point_bridge (__main__.WirelessInterfaceTest.test_wireless_access_point_bridge) ... ERROR
06:48:30  DEBUG - test_wireless_add_single_ip_address (__main__.WirelessInterfaceTest.test_wireless_add_single_ip_address) ... ERROR
06:48:32  DEBUG - test_wireless_add_single_ip_address (__main__.WirelessInterfaceTest.test_wireless_add_single_ip_address) ... ERROR
06:48:33  DEBUG - test_wireless_hostapd_config (__main__.WirelessInterfaceTest.test_wireless_hostapd_config) ... FAIL
06:48:34  DEBUG - test_wireless_hostapd_config (__main__.WirelessInterfaceTest.test_wireless_hostapd_config) ... ERROR
06:48:37  DEBUG - test_wireless_hostapd_wpa_config (__main__.WirelessInterfaceTest.test_wireless_hostapd_wpa_config) ... FAIL
06:48:38  DEBUG - test_wireless_hostapd_wpa_config (__main__.WirelessInterfaceTest.test_wireless_hostapd_wpa_config) ... ERROR
Apr 10 2023, 11:12 AM · VyOS 1.4 Sagitta
syncer reopened T425: AWS CloudWatch monitoring scripts, a subtask of T5129: Add AWS build flavour, as Open.
Apr 10 2023, 11:08 AM · VyOS 1.4 Sagitta
syncer reopened T425: AWS CloudWatch monitoring scripts as "Open".

Requires some additional work
we need to preserve configuration between upgrade
alternatively, we need to investigate if default config can be used with VM role

Apr 10 2023, 11:08 AM · VyOS 1.3 Equuleus (1.3.3), Amazon AWS Support
Viacheslav changed the status of T5148: OpenVPN cannot start due to could not load plugin shared object /openvpn-otp.so from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/1945

Apr 10 2023, 10:49 AM · VyOS 1.4 Sagitta
Viacheslav moved T5151: EAP-TLS TLSv1.0/1.1 regression after T5003 from Open to Finished on the VyOS 1.4 Sagitta board.
Apr 10 2023, 8:26 AM · VyOS 1.4 Sagitta
chenxiaolong closed T5151: EAP-TLS TLSv1.0/1.1 regression after T5003 as Resolved.

Closing as resolved because the PRs were merged (thanks for the quick review!)

Apr 10 2023, 12:48 AM · VyOS 1.4 Sagitta

Apr 9 2023

zsdc committed rVYOSONEX0df49bcea9e3: image: T4516: Added system image tools.
Apr 9 2023, 8:53 PM
chenxiaolong committed rVYOSONEXc53d73cd8958: eapol: T5151: Allow TLSv1.0/1.1 for EAP-TLS.
Apr 9 2023, 7:13 PM
GitHub <[email protected]> committed rVYOSONEXf5d40cf3cf8b: Merge pull request #1944 from chenxiaolong/eapol_tls_1.0_regression (authored by c-po).
Apr 9 2023, 7:13 PM
chenxiaolong added a comment to T4782: Allow multiple CA certificates (on e.g. EAPoL).

For eapol specifically, if your use case involves only a single chain (1 root CA + 1 or more intermediate CAs), then my fix from T4245 should do the trick. You can add each root/intermediate CA to the PKI and then set eapol to the leaf intermediate CA. When the wpa_supplicant configuration is generated, vyos will add the intermediate CA and all of its parents to the .crt file.

Apr 9 2023, 5:02 PM · VyOS 1.4 Sagitta
chenxiaolong added a comment to T5151: EAP-TLS TLSv1.0/1.1 regression after T5003.

Submitted PRs:

Apr 9 2023, 4:55 PM · VyOS 1.4 Sagitta
chenxiaolong created T5151: EAP-TLS TLSv1.0/1.1 regression after T5003.
Apr 9 2023, 4:41 PM · VyOS 1.4 Sagitta
v.huti claimed T2326: Migrate NHRP(DMVPN) to FRR.
Apr 9 2023, 11:57 AM · VyOS 1.5 Circinus

Apr 8 2023

c-po changed the status of T5150: Rework CLI definitions to apply route-maps between routing daemons and zebra/kernel from Open to In progress.
Apr 8 2023, 7:28 PM · VyOS 1.4 Sagitta
c-po updated the task description for T5150: Rework CLI definitions to apply route-maps between routing daemons and zebra/kernel.
Apr 8 2023, 7:28 PM · VyOS 1.4 Sagitta
c-po created T5150: Rework CLI definitions to apply route-maps between routing daemons and zebra/kernel.
Apr 8 2023, 7:27 PM · VyOS 1.4 Sagitta

Apr 7 2023

jestabro closed T5149: op-mode openvpn should not raise error in case interface is disabled as Resolved.
Apr 7 2023, 6:37 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXd5eafd464047: openvpn: T5149: do not raise error in case of disabled interface.
Apr 7 2023, 6:22 PM
jestabro triaged T5149: op-mode openvpn should not raise error in case interface is disabled as Normal priority.
Apr 7 2023, 6:04 PM · VyOS 1.4 Sagitta
Viacheslav reopened T5148: OpenVPN cannot start due to could not load plugin shared object /openvpn-otp.so as "Open".
Apr 7 2023, 12:25 PM · VyOS 1.4 Sagitta
Viacheslav closed T5148: OpenVPN cannot start due to could not load plugin shared object /openvpn-otp.so as Invalid.
Apr 7 2023, 12:01 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5148: OpenVPN cannot start due to could not load plugin shared object /openvpn-otp.so.

Otp not configured

Apr 7 2023, 12:01 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5148: OpenVPN cannot start due to could not load plugin shared object /openvpn-otp.so.
Apr 7 2023, 12:00 PM · VyOS 1.4 Sagitta
Viacheslav created T5148: OpenVPN cannot start due to could not load plugin shared object /openvpn-otp.so.
Apr 7 2023, 11:56 AM · VyOS 1.4 Sagitta

Apr 6 2023

c-po closed T5147: Can't Commit with Container Network as Resolved.
Apr 6 2023, 7:49 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T1237: Static Route Path Monitoring, failover.

PR https://github.com/vyos/vyos-1x/pull/1941

Apr 6 2023, 12:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T1237: Static Route Path Monitoring, failover.

We have targets-checks 203.0.113.1, 192.0.2.1, and if any of these targets are unreachable, we delete this route.
Is it correct?

Apr 6 2023, 11:04 AM · VyOS 1.4 Sagitta
jack9603301 added a comment to T3116: Support back-end L4 level load balancing.

@c-po How is the review and discussion on this feature going?

Apr 6 2023, 10:09 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX5f94bde6d602: container: T5147: ensure container network exists before VRF operation.
Apr 6 2023, 9:24 AM
Viacheslav closed T5125: Add op-mode commands for hsflowd based sflow, a subtask of T5086: Integrate hsflowd for sflow accounting, as Resolved.
Apr 6 2023, 8:34 AM · VyOS 1.4 Sagitta
Viacheslav closed T5125: Add op-mode commands for hsflowd based sflow as Resolved.
Apr 6 2023, 8:33 AM · VyOS 1.4 Sagitta
Viacheslav closed T5146: Show recent login of all users, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, as Invalid.
Apr 6 2023, 8:30 AM · VyOS 1.5 Circinus
Viacheslav closed T5146: Show recent login of all users as Invalid.

A similar output exists

 show system login users 
Possible completions:
  <Enter>               Execute the current command
  all                   Show information about all accounts
  locked                Show information about locked accounts
  other                 Show information about non VyOS user accounts
  vyos                  Show information about VyOS user accounts`
Apr 6 2023, 8:30 AM · VyOS 1.4 Sagitta
Viacheslav closed T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events., a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, as Resolved.
Apr 6 2023, 6:48 AM · VyOS 1.5 Circinus
Viacheslav closed T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events. as Resolved.
Apr 6 2023, 6:48 AM · VyOS 1.4 Sagitta
jbhardman created T5147: Can't Commit with Container Network.
Apr 6 2023, 2:36 AM · VyOS 1.4 Sagitta

Apr 5 2023

Viacheslav added a comment to T5146: Show recent login of all users.

PR https://github.com/vyos/vyos-1x/pull/1940

Apr 5 2023, 4:16 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5146: Show recent login of all users, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
Apr 5 2023, 3:57 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T5146: Show recent login of all users from Open to In progress.
Apr 5 2023, 3:57 PM · VyOS 1.4 Sagitta
Viacheslav created T5146: Show recent login of all users.
Apr 5 2023, 3:55 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX9ea856640af3: schema: T5079: extension to support defaultValues on tagNodes.
Apr 5 2023, 3:52 PM
c-po committed rVYOSONEXdf58e083979a: container: T4959: add registry authentication option.
Apr 5 2023, 3:52 PM
GitHub <[email protected]> committed rVYOSONEX0b0f991a8646: Merge pull request #1928 from c-po/t4959-backport (authored by c-po).
Apr 5 2023, 3:52 PM
c-po closed T4975: CLI does not work after cutting off the power or reset as Resolved.
Apr 5 2023, 2:43 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T5136: Possible config corruption on upgrade as Resolved.
Apr 5 2023, 2:43 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T425: AWS CloudWatch monitoring scripts as Resolved.
Apr 5 2023, 2:43 PM · VyOS 1.3 Equuleus (1.3.3), Amazon AWS Support
c-po closed T425: AWS CloudWatch monitoring scripts, a subtask of T5129: Add AWS build flavour, as Resolved.
Apr 5 2023, 2:43 PM · VyOS 1.4 Sagitta
c-po moved T5136: Possible config corruption on upgrade from Backport Candidates to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Apr 5 2023, 2:42 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav closed T5145: Add maxsyslogins maximum number of all logins on system , a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, as Resolved.
Apr 5 2023, 11:13 AM · VyOS 1.5 Circinus
Viacheslav closed T5145: Add maxsyslogins maximum number of all logins on system as Resolved.
Apr 5 2023, 11:13 AM · VyOS 1.4 Sagitta
marc_s added a comment to T4362: Wan Load Balancing - Can't create routing tables.

@marc_s Will be fixed in the next rolling release, could you check?

Apr 5 2023, 8:56 AM · VyOS 1.4 Sagitta
marc_s added a comment to T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution.

Thanks @Viacheslav will test ASAP, next week I have a maintenance window, will let you know.

Apr 5 2023, 8:55 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5135: Rewrite opennhrp script using vyos.ipsec library as Resolved.
Apr 5 2023, 8:07 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5135: Rewrite opennhrp script using vyos.ipsec library from In progress to Needs testing.
Apr 5 2023, 7:30 AM · VyOS 1.4 Sagitta

Apr 4 2023

Viacheslav committed rVYOSONEXf72fa1359861: T5142: Add audit tool to monitor security-relevant events.
Apr 4 2023, 7:24 PM
Viacheslav changed the status of T5138: Add patch to accel-ppp build L2TP LNS use Calling-Number as RADIUS Calling-Station-ID from In progress to Needs testing.
Apr 4 2023, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system , a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from In progress to Needs testing.
Apr 4 2023, 5:30 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system from In progress to Needs testing.
Apr 4 2023, 5:30 PM · VyOS 1.4 Sagitta
a.apostoliuk committed rVYOSONEXa3ce38b4a290: opennhrp: T5135: Rewritten opennhrp script using vyos.ipsec.
Apr 4 2023, 5:24 PM
GitHub <[email protected]> committed rVYOSONEX85b46a6b225c: Merge pull request #1937 from aapostoliuk/T5135-sagitta (authored by c-po).
Apr 4 2023, 5:24 PM
Viacheslav committed rVYOSONEXa1ffb5e73760: T5145: Add maximum number of all logins on system.
Apr 4 2023, 5:23 PM
GitHub <[email protected]> committed rVYOSONEXe520e0841013: Merge pull request #1939 from sever-sever/T5145 (authored by c-po).
Apr 4 2023, 5:22 PM
Viacheslav added a comment to T5145: Add maxsyslogins maximum number of all logins on system .

PR https://github.com/vyos/vyos-1x/pull/1939

set system login max-login-session '1'
set system login timeout '600'
Apr 4 2023, 2:18 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system , a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
Apr 4 2023, 12:57 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T5145: Add maxsyslogins maximum number of all logins on system from Open to In progress.
Apr 4 2023, 12:57 PM · VyOS 1.4 Sagitta
Viacheslav created T5145: Add maxsyslogins maximum number of all logins on system .
Apr 4 2023, 12:49 PM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

Is it possible to implement multiple test targets instead of just one?

Apr 4 2023, 12:01 PM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

Bug: unable to rename a failover route:

Apr 4 2023, 11:37 AM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

@Viacheslav Ok!

Apr 4 2023, 11:36 AM · VyOS 1.4 Sagitta
Harliff awarded T1237: Static Route Path Monitoring, failover a Burninate token.
Apr 4 2023, 11:28 AM · VyOS 1.4 Sagitta
Harliff awarded T1237: Static Route Path Monitoring, failover a Like token.
Apr 4 2023, 11:28 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4712: Collaborative Protection Profile cPP for Network Devices root task.
Apr 4 2023, 11:19 AM · VyOS 1.5 Circinus
Viacheslav added a comment to T1237: Static Route Path Monitoring, failover.

@Harliff It is better to write to this task if you find bugs or propose new features.
So anyone could claim/fix it.
Thanks.

Apr 4 2023, 11:11 AM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

@Viacheslav, where is best place to discuss the feature (ask a question or report a bug)?

Apr 4 2023, 11:07 AM · VyOS 1.4 Sagitta
Viacheslav claimed T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 4 2023, 11:06 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 4 2023, 11:05 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 4 2023, 11:05 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events., a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
Apr 4 2023, 11:03 AM · VyOS 1.5 Circinus
Viacheslav changed the status of T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events. from Open to In progress.

PR https://github.com/vyos/vyos-build/pull/333
PR https://github.com/vyos/vyos-1x/pull/1938

Apr 4 2023, 11:03 AM · VyOS 1.4 Sagitta
Harliff added a comment to T1237: Static Route Path Monitoring, failover.

Nice feature. I'm testing it now.

Apr 4 2023, 10:17 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5138: Add patch to accel-ppp build L2TP LNS use Calling-Number as RADIUS Calling-Station-ID from Open to In progress.
Apr 4 2023, 9:16 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5125: Add op-mode commands for hsflowd based sflow.

@neilmckee Thanks.
If output looks good we can close the task

Apr 4 2023, 9:03 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5093: Command 'reset vpn ipsec-profile' doesn't work as Resolved.
Apr 4 2023, 8:53 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5093: Command 'reset vpn ipsec-profile' doesn't work from In progress to Needs testing.
Apr 4 2023, 8:50 AM · VyOS 1.4 Sagitta
Viacheslav closed T4362: Wan Load Balancing - Can't create routing tables as Resolved.
Apr 4 2023, 7:28 AM · VyOS 1.4 Sagitta
Viacheslav closed T4362: Wan Load Balancing - Can't create routing tables, a subtask of T4470: Rewrite load-balancing wan to XML/Python, as Resolved.
Apr 4 2023, 7:28 AM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav added a comment to T4362: Wan Load Balancing - Can't create routing tables.

Fixed in https://github.com/vyos/vyos-1x/commit/bcc9e2092b07954c72a90f3f9916c9e041308b5b

Apr 4 2023, 7:27 AM · VyOS 1.4 Sagitta
Viacheslav closed T5141: Add numbers for dhclient-exit-hooks.d to enforce script order execution as Resolved.
Apr 4 2023, 7:27 AM · VyOS 1.4 Sagitta
indrajitr updated the task description for T5144: Modernize dynamic dns operation.
Apr 4 2023, 3:02 AM · VyOS 1.4 Sagitta
indrajitr created T5144: Modernize dynamic dns operation.
Apr 4 2023, 1:40 AM · VyOS 1.4 Sagitta

Apr 3 2023

indrajitr changed the status of T5143: Apply constraint on powerdns forward-zones configuration from Open to In progress.
Apr 3 2023, 10:58 PM · VyOS 1.4 Sagitta
indrajitr created T5143: Apply constraint on powerdns forward-zones configuration.
Apr 3 2023, 10:13 PM · VyOS 1.4 Sagitta
roedie added a comment to T5080: Disable conntrack by default.

I think one of the problems is that all tables are generated even if there are no rules in it.

Apr 3 2023, 7:26 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav updated the task description for T5142: One of the requirements is to use a system auditing tool to monitor and log all security-relevant events..
Apr 3 2023, 6:31 PM · VyOS 1.4 Sagitta