Page MenuHomeVyOS Platform
Feed All Stories

Apr 30 2023

dcplaya added a comment to T5082: container: switch to netavark network stack.

If I pre-load my zone firewall with the new interface format (pod-$containerName) and upgrade to vyos-1.4-rolling-202304290647, it seems to upgrade seamlessly

Apr 30 2023, 3:39 AM · VyOS 1.4 Sagitta
giga1699 created T5192: RNDIS Missing from Kernel.
Apr 30 2023, 12:07 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta

Apr 29 2023

dcplaya added a comment to T5082: container: switch to netavark network stack.
Apr 29 2023, 6:18 PM · VyOS 1.4 Sagitta
anon3fe35 added a comment to T5082: container: switch to netavark network stack.

@carazzim0 good find, I updated that and now everything appears to be working again!

Apr 29 2023, 12:09 PM · VyOS 1.4 Sagitta
Viacheslav moved T4971: Radius attribute "Framed-Pool" for PPPoE from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Apr 29 2023, 9:59 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a project to T4971: Radius attribute "Framed-Pool" for PPPoE: VyOS 1.3 Equuleus (1.3.3).
Apr 29 2023, 9:59 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
carazzim0 added a comment to T5082: container: switch to netavark network stack.

Wouldn't it make sense to add iptables as a direct dependency then? Looking back at Debian Bullseye, iptables was still a direct dependency to the podman package. But as of Debian Bookworm, iptables is just a suggested package to podman.

root@bullseye:/# apt-cache depends podman | grep iptables
  Depends: iptables
Apr 29 2023, 7:21 AM · VyOS 1.4 Sagitta
c-po added a comment to T5082: container: switch to netavark network stack.

In either case when trying to PING or TRACEROUTE from a device on my LAN network I can PING and TRACEROUTE 192.168.254.2.

Apr 29 2023, 6:19 AM · VyOS 1.4 Sagitta
c-po added a comment to T5082: container: switch to netavark network stack.

No iptables installed, and also no vyos-1x-smoketest package.

Apr 29 2023, 6:09 AM · VyOS 1.4 Sagitta

Apr 28 2023

SrividyaA added a comment to T5127: VPNv4/VPNv6 routes are not reinstalled following link flap.

I was able to reproduce the issue in the lab. In order to avoid an automatic assignment of RD after the interface flap, you could add a dummy or loopback interface to the vrf and define it as router-id in your existing configuration, For example:

Apr 28 2023, 7:03 PM · VyOS 1.4 Sagitta
anon3fe35 added a comment to T5082: container: switch to netavark network stack.

I want to describe my issues but I am not able to do so very easily since I don't have ipmi on my router.

Apr 28 2023, 6:26 PM · VyOS 1.4 Sagitta
carazzim0 added a comment to T5082: container: switch to netavark network stack.

I updated one of my servers to the latest rolling:

[email protected]:~$ show version
Version:          VyOS 1.4-rolling-202304280615           <-- 28.04.2023
Release train:    current
Apr 28 2023, 6:12 PM · VyOS 1.4 Sagitta
dmbaturin created T5191: Replace underscores with hyphens in command-line options generated by vyos.opmode.
Apr 28 2023, 4:57 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po reopened T5082: container: switch to netavark network stack as "Needs testing".
Apr 28 2023, 4:34 PM · VyOS 1.4 Sagitta
c-po updated subscribers of T5082: container: switch to netavark network stack.

can you add some more detials? I just used your above container config and upgraded from a VyOS version that came with CNI to a version with netavark and I do not see that error.
netavark was added 2023-04-02.

Apr 28 2023, 4:34 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5171: Use XML for conf-mode "load-balancing wan" instead of legacy templates.

PR https://github.com/vyos/vyos-1x/pull/1973
PR https://github.com/vyos/vyatta-wanloadbalance/pull/17

Apr 28 2023, 10:48 AM · VyOS 1.4 Sagitta
spion06 added a comment to T4974: OpenVPN- Data Channel Offload(DCO).

I made an attempt at integrating openvpn-dco into the build here https://github.com/spion06/vyos-build/tree/ovpn-dco. This works fine for me in my testing so far. The kernel module loaded, verified in the logs that it detected and used the dco tunnel. I'm not super familiar with the build system or what else would need to be done for contributing this. I'm just and end-user who would like to see this feature :)

Apr 28 2023, 12:39 AM · VyOS 1.4 Sagitta

Apr 27 2023

zsdc changed the status of T5190: Cloud-Init cannot fetch Meta-data on machines where the main Ethernet interface is not eth0 from Open to In progress.
Apr 27 2023, 10:31 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
zsdc created T5190: Cloud-Init cannot fetch Meta-data on machines where the main Ethernet interface is not eth0.
Apr 27 2023, 10:31 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po moved T5010: bgp: EVPN route-target not honored from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Apr 27 2023, 8:36 PM · VyOS 1.4 Sagitta
c-po changed the status of T5010: bgp: EVPN route-target not honored from Open to Needs testing.
Apr 27 2023, 8:35 PM · VyOS 1.4 Sagitta
c-po created T5189: bgp: add evpn anycast gateway support.
Apr 27 2023, 7:54 PM · VyOS 1.5 Circinus
c-po added a comment to T5010: bgp: EVPN route-target not honored.

Your CLI config is valid in general but FRR will refuse it with the error message: This command is only supported under EVPN VRF

Apr 27 2023, 7:29 PM · VyOS 1.4 Sagitta
c-po closed T5174: vrf: ensure no duplicate VNIs can be created as Resolved.
Apr 27 2023, 6:48 PM · VyOS 1.4 Sagitta
Viacheslav closed T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd as Resolved.
Apr 27 2023, 6:45 PM · VyOS 1.4 Sagitta
jestabro closed T5185: Static IPv6 route with blackhole fails as Resolved.
Apr 27 2023, 4:20 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T5188: Update Intel igc driver for improved 2.5 GbE support, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus.
Apr 27 2023, 4:15 PM · VyOS 1.3 Equuleus (1.3.7)
Viacheslav closed T5183: IPv6 route6 problem as Resolved.
Apr 27 2023, 4:14 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.

PR https://github.com/vyos/vyos-1x/pull/1972

Apr 27 2023, 4:12 PM · VyOS 1.4 Sagitta
pasik created T5188: Update Intel igc driver for improved 2.5 GbE support.
Apr 27 2023, 3:29 PM · VyOS 1.3 Equuleus (1.3.7)
oTamurazo added a comment to T5185: Static IPv6 route with blackhole fails.

Dear Jestabro,
i built an updated docker image and a new ISO, i do confirm now IPv6 is working correctly.

Apr 27 2023, 3:23 PM · VyOS 1.4 Sagitta
zsdc changed the status of T5187: Update Realtek r8152 driver from Open to In progress.

PR: https://github.com/vyos/vyos-build/pull/343

Apr 27 2023, 2:43 PM · VyOS 1.3 Equuleus (1.3.6)
zsdc created T5187: Update Realtek r8152 driver.
Apr 27 2023, 2:17 PM · VyOS 1.3 Equuleus (1.3.6)
jestabro closed T5175: http-api: error in MultiPart parser for FastAPI version >= 0.91.0 as Resolved.
Apr 27 2023, 2:09 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro closed T5176: http-api: update vyos-http-api-tools for FastAPI security vulnerability, a subtask of T5175: http-api: error in MultiPart parser for FastAPI version >= 0.91.0, as Resolved.
Apr 27 2023, 2:03 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro closed T5176: http-api: update vyos-http-api-tools for FastAPI security vulnerability as Resolved.
Apr 27 2023, 2:02 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
diodep closed T5123: Display route originator in show ospf table command as Resolved.

Ok, if we merge the patch (backported to frr v8.5), this task can be close.

Apr 27 2023, 12:37 PM · VyOS 1.4 Sagitta
n.fort closed T5037: Firewall - Add queue action as Resolved.
Apr 27 2023, 11:23 AM · VyOS 1.4 Sagitta
n.fort closed T5050: Firewall - Add options for logging packets as Resolved.
Apr 27 2023, 11:21 AM · VyOS 1.4 Sagitta
n.fort closed T5055: Firewall - Add packet type matcher (pkttype) as Resolved.
Apr 27 2023, 11:20 AM · VyOS 1.4 Sagitta
n.fort closed T5128: Policy route - Allow wildcard interfaces as Resolved.
Apr 27 2023, 11:19 AM · VyOS 1.4 Sagitta
diodep added a comment to T5123: Display route originator in show ospf table command.
Apr 27 2023, 10:13 AM · VyOS 1.4 Sagitta
Viacheslav reopened T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd as "Needs testing".
Apr 27 2023, 9:53 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5186: QoS test cannot pass for 1.3.
Apr 27 2023, 8:10 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav triaged T5186: QoS test cannot pass for 1.3 as High priority.
Apr 27 2023, 8:00 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav edited projects for T5186: QoS test cannot pass for 1.3, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.4 Sagitta.
Apr 27 2023, 7:59 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav updated the task description for T5186: QoS test cannot pass for 1.3.
Apr 27 2023, 7:58 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav created T5186: QoS test cannot pass for 1.3.
Apr 27 2023, 7:56 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T5116: Better VRF support.

I think the only solution is to use network namespaces
https://docs.strongswan.org/docs/5.9/howtos/nameSpaces.html

Apr 27 2023, 7:37 AM · VyOS 1.5 Circinus
joshua.hanley added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

Usernames usually take the following format: abc-1234-12
Passwords are a combination of alphanumeric characters.

Apr 27 2023, 7:11 AM · VyOS 1.4 Sagitta
diodep added a comment to T5116: Better VRF support.
In T5116#147640, @c-po wrote:

Do you know how to tell Linux to use nameservers within a VRF?
What you mean IPSec/OpenVPN "punch a tunnel through a VRF" ? So the underlay should run via a VRF? source-interface binding does not work?

Apr 27 2023, 6:21 AM · VyOS 1.5 Circinus

Apr 26 2023

jestabro added a comment to T5183: IPv6 route6 problem.

Thanks for opening the task; note that Viacheslav had opened
https://vyos.dev/T5185
as well, and the updates on the now fixed issue can be found there. This task can be merged into that one and closed.

Apr 26 2023, 8:03 PM · VyOS 1.4 Sagitta
jestabro added a comment to T5185: Static IPv6 route with blackhole fails.

Merged and repos updated, so this will be in the next nightly build. Note that for a local build, one will need an updated Docker image for the update to vyos1x-config.

Apr 26 2023, 8:00 PM · VyOS 1.4 Sagitta
c-po added a comment to T5116: Better VRF support.

Do you know how to tell Linux to use nameservers within a VRF?
What you mean IPSec/OpenVPN "punch a tunnel through a VRF" ? So the underlay should run via a VRF? source-interface binding does not work?

Apr 26 2023, 6:59 PM · VyOS 1.5 Circinus
c-po moved T5132: Operational command "show isis vrf XXX route | neighbord" aren't working from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T5134: Try if netavark networks can be moved to a VRF instance from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T5174: vrf: ensure no duplicate VNIs can be created from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T4998: pppoe username validation too restrictive (regression) from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T5114: bgp: implement new CLI commands introduced in FRR 8.5 from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T366: SNMP Query for BGP Tunnels Returns IPv4 Tunnels Only from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:57 PM · VyOS 1.4 Sagitta
c-po moved T5170: Relocate ntp config path in config.boot.default from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:56 PM · VyOS 1.4 Sagitta
c-po moved T5075: QoS removes interface mirror/redirect rules from In Progress to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:56 PM · VyOS 1.4 Sagitta
c-po moved T4571: Sflow with vrf configured does not use vrf to validate agent-address IP from vrf-configured interfaces from Backport Candidates to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:56 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T5178: Fix missed case in multi_to_list conversion from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Apr 26 2023, 6:56 PM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
jestabro changed the status of T5185: Static IPv6 route with blackhole fails from Open to In progress.

This is a simple bug in the recently introduced configtree node name comparison function; fixed and should be in next rolling.

Apr 26 2023, 5:38 PM · VyOS 1.4 Sagitta
jestabro triaged T5185: Static IPv6 route with blackhole fails as Urgent! priority.
Apr 26 2023, 4:33 PM · VyOS 1.4 Sagitta
jestabro claimed T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 4:29 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

Do you have users/passwords with specsymbols or not utf-8 or some ascii symbols?

Apr 26 2023, 3:43 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 3:40 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 3:40 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 3:36 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 3:36 PM · VyOS 1.4 Sagitta
Viacheslav created T5185: Static IPv6 route with blackhole fails.
Apr 26 2023, 3:34 PM · VyOS 1.4 Sagitta
joshua.hanley added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

hmmm very strange.... here is my configuration (IP addresses removed):

Apr 26 2023, 1:45 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

Could you provide l2tp configuration? show conf com | match l2tp
I cannot reproduce it

vyos@r14:~$ 
vyos@r14:~$ show l2tp-server sessions 
 ifname | username |      ip      | ip6 | ip6-dp |  calling-sid  | rate-limit | state  |  uptime  | rx-bytes | tx-bytes 
--------+----------+--------------+-----+--------+---------------+------------+--------+----------+----------+----------
 l2tp0  | alice    | 100.64.203.0 |     |        | 192.168.122.1 |            | active | 00:00:10 | 246 B    | 208 B
vyos@r14:~$ 
vyos@r14:~$ 
vyos@r14:~$ show version 
Version:          VyOS 1.4-rolling-202304261027
Release train:    current
Apr 26 2023, 1:41 PM · VyOS 1.4 Sagitta
joshua.hanley added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

@Viacheslav It hangs for a while and then eventually the following output:

Apr 26 2023, 1:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5184: Unable to display L2TP sessions l2tp-server sessions.

@joshua.hanley Could you provide the output of the next command?

sudo accel-cmd -p 2004 show sessions
Apr 26 2023, 1:10 PM · VyOS 1.4 Sagitta
joshua.hanley updated the task description for T5184: Unable to display L2TP sessions l2tp-server sessions.
Apr 26 2023, 12:57 PM · VyOS 1.4 Sagitta
joshua.hanley created T5184: Unable to display L2TP sessions l2tp-server sessions.
Apr 26 2023, 12:56 PM · VyOS 1.4 Sagitta
oTamurazo created T5183: IPv6 route6 problem.
Apr 26 2023, 12:47 PM · VyOS 1.4 Sagitta
Viacheslav closed T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd as Resolved.
Apr 26 2023, 12:37 PM · VyOS 1.4 Sagitta
SrividyaA changed the status of T5127: VPNv4/VPNv6 routes are not reinstalled following link flap from Open to Confirmed.
Apr 26 2023, 11:44 AM · VyOS 1.4 Sagitta
zsdc added a comment to T5182: Update Intel ice driver.

PR with dependencies: https://github.com/vyos/vyos-build/pull/341

Apr 26 2023, 11:10 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.

PR https://github.com/vyos/vyos-1x/pull/1971

Apr 26 2023, 9:47 AM · VyOS 1.4 Sagitta

Apr 25 2023

zsdc changed the status of T5182: Update Intel ice driver from Open to In progress.

PR (for build): https://github.com/vyos/vyos-build/pull/340

Apr 25 2023, 10:55 PM · VyOS 1.3 Equuleus (1.3.6)
jestabro closed T5179: multi nodes defined in XML are not properly represented as list in get_config_dict(), a subtask of T3234: multi_to_list fails in certain cases, with root cause an element redundancy in XML interface-definitions, as Resolved.
Apr 25 2023, 9:08 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jestabro closed T5179: multi nodes defined in XML are not properly represented as list in get_config_dict() as Resolved.
Apr 25 2023, 9:08 PM · VyOS 1.4 Sagitta
zsdc created T5182: Update Intel ice driver.
Apr 25 2023, 7:59 PM · VyOS 1.3 Equuleus (1.3.6)
zsdc changed the status of T5180: initramfs-tools ignores firmware from updates directory from Open to In progress.

PR: https://github.com/vyos/vyos-build/pull/339

Apr 25 2023, 7:48 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav assigned T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd to c-po.
Apr 25 2023, 6:27 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.

Incorrect modify modify_section: starting search for '^vrf protocols' until '^exit-vrf'

vyos@r14# delete vrf name red vni 
[edit]
vyos@r14# commit
[ vrf name red vni 3000 ]
{'name': {'protocols': {'bgp': {'address_family': {'ipv4_unicast': {'redistribute': {'connected': {}}},
                                                   'l2vpn_evpn': {'advertise': {'ipv4': {'unicast': {}}}}},
                                'system_as': '65001'}},
          'table': '3000'}}
load_configuration: Configuration loaded from FRR daemon zebra
load_configuration:  loaded      0 !
load_configuration:  loaded      1 frr version 8.5
load_configuration:  loaded      2 frr defaults traditional
load_configuration:  loaded      3 hostname debian
load_configuration:  loaded      4 log syslog
load_configuration:  loaded      5 log facility local7
load_configuration:  loaded      6 hostname r14
load_configuration:  loaded      7 service integrated-vtysh-config
load_configuration:  loaded      8 !
load_configuration:  loaded      9 vrf red
load_configuration:  loaded     10  vni 3000
load_configuration:  loaded     11 exit-vrf
load_configuration:  loaded     12 !
load_configuration:  loaded     13 end
modify_section: starting search for '^vrf protocols' until '^exit-vrf'
Apr 25 2023, 5:38 PM · VyOS 1.4 Sagitta
aserkin added a comment to T5169: Add CGNAT Carrier-Grade NAT based on nftables.
Apr 25 2023, 4:11 PM · VyOS 1.5 Circinus
aserkin added a comment to T5169: Add CGNAT Carrier-Grade NAT based on nftables.

Two cents from the fields. It will be nice to see vrf aware cg-nat solution, when subscribers from a number of "inside" vrfs NAT'ed into one outside vrf. Of course if that's possible.

Apr 25 2023, 4:10 PM · VyOS 1.5 Circinus
Viacheslav updated the task description for T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.
Apr 25 2023, 3:20 PM · VyOS 1.4 Sagitta
Viacheslav renamed T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd from Wrong dependencies or priorities for zebra vni vrf and bgpd to Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.
Apr 25 2023, 3:13 PM · VyOS 1.4 Sagitta
Viacheslav created T5181: Wrong dependencies or priorities for zebra vni vrf interfaces and bgpd.
Apr 25 2023, 3:09 PM · VyOS 1.4 Sagitta
jestabro renamed T5178: Fix missed case in multi_to_list conversion from Fix misssed case in multi_to_list conversion to Fix missed case in multi_to_list conversion.
Apr 25 2023, 1:43 PM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
zsdc created T5180: initramfs-tools ignores firmware from updates directory.
Apr 25 2023, 12:33 PM · VyOS 1.3 Equuleus (1.3.6)
jestabro added a comment to T5179: multi nodes defined in XML are not properly represented as list in get_config_dict().

Test case above produces:

Apr 25 2023, 6:00 AM · VyOS 1.4 Sagitta
jestabro added a comment to T5179: multi nodes defined in XML are not properly represented as list in get_config_dict().

PR:
https://github.com/vyos/vyos-1x/pull/1970

Apr 25 2023, 5:57 AM · VyOS 1.4 Sagitta