Page MenuHomeVyOS Platform
Feed All Stories

Mar 17 2024

c-po changed the status of T6133: Add domain-name to commit-archive, a subtask of T4942: Rewrite vyatta-config-mgmt to Python/XML, from Open to In progress.
Mar 17 2024, 1:42 PM · VyOS 1.4 Sagitta
c-po changed the status of T6133: Add domain-name to commit-archive from Open to In progress.
Mar 17 2024, 1:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po created T6133: Add domain-name to commit-archive.
Mar 17 2024, 1:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
trae32566 triaged T6132: Conntrack-sync Internal Cache Growing Uncontrollably as High priority.
Mar 17 2024, 12:35 PM · Restricted Project, VyOS 1.5 Circinus
matthewr added a comment to T6076: [1.3.3->1.4.0-epa1 Migration] Most of config missing.

See T6131 for a report of the VTUN/OSPF issue with a simple lab config, which occurs separately from a migration.

Mar 17 2024, 10:26 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
matthewr created T6131: Disabling openvpn interface(s) causes OSPF to fail to load on reboot.
Mar 17 2024, 10:22 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
matthewr created T6130: [1.3.6->1.4.0-epa2 Migration] BGP "set community" missing.
Mar 17 2024, 9:48 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po added a comment to T6129: bgp: add route-map option "as-path exclude all".

https://github.com/vyos/vyos-1x/pull/3139

Mar 17 2024, 7:44 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po updated the task description for T6129: bgp: add route-map option "as-path exclude all".
Mar 17 2024, 7:42 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po changed the status of T6129: bgp: add route-map option "as-path exclude all" from Open to In progress.
Mar 17 2024, 7:40 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po changed the status of T6129: bgp: add route-map option "as-path exclude all", a subtask of T5788: frr: update to 9.1 release, from Open to In progress.
Mar 17 2024, 7:40 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
c-po created T6129: bgp: add route-map option "as-path exclude all".
Mar 17 2024, 7:40 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 16 2024

dmbaturin added a comment to T6128: minisign.pub is wrong on https://vyos.net/get/nightly-builds/.

We'll update the key and make a post about it soon, sorry for the lengthy mix-up.

Mar 16 2024, 8:30 PM · VyOS 1.5 Circinus
robertoberto added a comment to T6128: minisign.pub is wrong on https://vyos.net/get/nightly-builds/.

comments above are for https://vyos.net/get/nightly-builds/

Mar 16 2024, 5:51 PM · VyOS 1.5 Circinus
robertoberto created T6128: minisign.pub is wrong on https://vyos.net/get/nightly-builds/.
Mar 16 2024, 5:34 PM · VyOS 1.5 Circinus
penetal added a comment to T5083: extend interface schema to include which parameters are required.

Bumped into another instance of this issue:

curl -k --location --request POST "https://$VYOS_HOST/configure" --form key="$VYOS_KEY" --form data='[{"op":"set","path":["policy", "access-list", "2", "rule", "5", "description", "2024-03-16T14:52:44Z"]}]'
{"success": false, "error": "[[policy]] failed\nCommit failed\n", "data": null}
Mar 16 2024, 2:59 PM
c-po moved T4022: Add package nat-rtsp-dkms from Open to Finished on the VyOS 1.5 Circinus board.
Mar 16 2024, 11:33 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEX5daebff4a5cc: Merge pull request #3112 from Ingramz/add-rtsp-2 (authored by c-po).
Mar 16 2024, 11:33 AM
Indrek Ardel <[email protected]> committed rVYOSONEX3e1e2a3e7b6f: conntrack: T4022: add RTSP conntrack helper.
Mar 16 2024, 11:33 AM
c-po added a project to T4022: Add package nat-rtsp-dkms: VyOS 1.4 Sagitta (1.4.0).
Mar 16 2024, 11:33 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEXd18d773238ef: Merge pull request #3138 from vyos/mergify/bp/sagitta/pr-3137 (authored by dmbaturin).
Mar 16 2024, 11:22 AM
penetal added a comment to T6069: HTTP API segfault during concurrent configuration requests.

@jestabro I have tested my usecase now and it seems the problem is fixed and the API no longer segfaults. Thank you so much for the fix and the fantastic turn around on this.

Mar 16 2024, 9:11 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
Viacheslav committed rVYOSONEX25b611f50452: T6121: Extend service config-sync to new sections.
Mar 16 2024, 8:47 AM
GitHub <[email protected]> committed rVYOSONEXaea9bfb803c8: Merge pull request #3132 from sever-sever/T6121 (authored by c-po).
Mar 16 2024, 8:47 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX4413e5b633c6: T6090: fix policy route migration script. Ensure that tcp flags migration… (authored by n.fort).
Mar 16 2024, 8:47 AM
n.fort committed rVYOSONEX1048f49e403d: T6090: fix policy route migration script. Ensure that tcp flags migration….
Mar 16 2024, 8:46 AM
GitHub <[email protected]> committed rVYOSONEX828e94d7cb67: Merge pull request #3137 from nicolas-fort/T6090-policy (authored by c-po).
Mar 16 2024, 8:46 AM

Mar 15 2024

L0crian added a comment to T6127: Ability to view logs for rules with Offload not functional.

Should add the ability to view the default action log would be nice as well.

Mar 15 2024, 10:33 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
L0crian renamed T6127: Ability to view logs for rules with Offload not functional from Ability to view logs for rules with Offload not available to Ability to view logs for rules with Offload not functional.
Mar 15 2024, 10:09 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
L0crian created T6127: Ability to view logs for rules with Offload not functional.
Mar 15 2024, 10:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity.

PR for 1.5: https://github.com/vyos/vyos-1x/pull/3137

Mar 15 2024, 9:45 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a project to T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity: VyOS 1.5 Circinus.
Mar 15 2024, 9:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
anonuser445y6 added a comment to T6126: Unable to add image.

I can download the image and add it from path just fine, e.g this works fine:

Mar 15 2024, 7:45 PM · VyOS 1.4 Sagitta
anonuser445y6 created T6126: Unable to add image.
Mar 15 2024, 7:31 PM · VyOS 1.4 Sagitta
daniil renamed T6125: Support 802.1ad (0x88a8) vlan filtering for bridge from Support 802.1ad (0x88a8) for bridge to Support 802.1ad (0x88a8) vlan filtering for bridge.
Mar 15 2024, 6:10 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
daniil created T6125: Support 802.1ad (0x88a8) vlan filtering for bridge.
Mar 15 2024, 6:07 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Apachez added a comment to T6091: [1.3.3->1.4.0-epa1 Migration] NTP "listen-address" config removed.

Proper would be to throw out chrony and use ntpsec instead which supports proper filtering.

Mar 15 2024, 5:06 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T6124: Docker equuleus build image doesn't build due to fpm, added: VyOS 1.3 Equuleus (1.3.7); removed VyOS 1.3 Equuleus.
Mar 15 2024, 3:46 PM · VyOS 1.3 Equuleus (1.3.7)
Viacheslav triaged T6124: Docker equuleus build image doesn't build due to fpm as High priority.
Mar 15 2024, 3:45 PM · VyOS 1.3 Equuleus (1.3.7)
matthewr added a comment to T6091: [1.3.3->1.4.0-epa1 Migration] NTP "listen-address" config removed.

Given that Chrony only allows one bind address, versus ntpd which allows multiple, a "wontfix" sounds like the correct answer! :-)

Mar 15 2024, 3:12 PM · VyOS 1.4 Sagitta
MattK updated the task description for T6124: Docker equuleus build image doesn't build due to fpm.
Mar 15 2024, 3:02 PM · VyOS 1.3 Equuleus (1.3.7)
MattK created T6124: Docker equuleus build image doesn't build due to fpm.
Mar 15 2024, 2:57 PM · VyOS 1.3 Equuleus (1.3.7)
n.fort changed the status of T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity, a subtask of T5938: Migration fail root task for 1.4-rc, from Open to Confirmed.
Mar 15 2024, 2:33 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
n.fort changed the status of T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity from Open to Confirmed.
Mar 15 2024, 2:33 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6116: VyOS can't work as expected at k8s platform as Normal priority.
Mar 15 2024, 2:30 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav changed the status of T6109: remote syslog does not get all the logs from Open to Needs reporter action.

@m.serdienis Add set of configuration commands to reproduce.

Mar 15 2024, 2:26 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po closed T6091: [1.3.3->1.4.0-epa1 Migration] NTP "listen-address" config removed as Wontfix.
Mar 15 2024, 2:26 PM · VyOS 1.4 Sagitta
c-po added a comment to T6091: [1.3.3->1.4.0-epa1 Migration] NTP "listen-address" config removed.

The issue is which to choose if there are multiple, thus removing all, chrony will listen on all interfaces.

Mar 15 2024, 2:26 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T6108: VTYSH - Slowdown, added: VyOS 1.3 Equuleus (1.3.7); removed VyOS 1.3 Equuleus.
Mar 15 2024, 2:25 PM · Restricted Project, VyOS Rolling
Viacheslav triaged T6108: VTYSH - Slowdown as Normal priority.
Mar 15 2024, 2:25 PM · Restricted Project, VyOS Rolling
Viacheslav triaged T6106: Improve the commit error message for the case when route-reflector-client option is defined in a peer-group as High priority.
Mar 15 2024, 2:24 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6105: Service HTTPS using ACME certificate does not present full chain as Normal priority.
Mar 15 2024, 2:24 PM · VyOS 1.5 Circinus
Viacheslav triaged T6092: Static interface index as Wishlist priority.
Mar 15 2024, 2:23 PM · VyOS 1.5 Circinus
Viacheslav triaged T6091: [1.3.3->1.4.0-epa1 Migration] NTP "listen-address" config removed as Normal priority.

Most likely won't fix
https://chrony-project.org/doc/3.4/chrony.conf.html

Mar 15 2024, 2:23 PM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity: T5938: Migration fail root task for 1.4-rc.
Mar 15 2024, 2:02 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a subtask for T5938: Migration fail root task for 1.4-rc: T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity.
Mar 15 2024, 2:02 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Viacheslav triaged T6090: Migration of "policy route" configs fails due to TCP flag case sensitivity as High priority.
Mar 15 2024, 2:01 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6120: integration speedtest cli as Wishlist priority.

I don't think it is expected to get speed to the node itself.
A router is generally used for forwarding traffic. It is better to use iperf to check the speed between 2 hosts.

Mar 15 2024, 1:54 PM · VyOS 1.5 Circinus
c-po closed T6118: radvd: RFC8781: add nat64prefix support as Resolved.
Mar 15 2024, 12:39 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po moved T6118: radvd: RFC8781: add nat64prefix support from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0) board.
Mar 15 2024, 12:39 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Apachez added a comment to T4610: Firewall with 20K entries cannot load after reboot.

There do already exists tasks regarding commit and boot times such as: https://vyos.dev/T5388

Mar 15 2024, 10:35 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4610: Firewall with 20K entries cannot load after reboot.

@Apachez the original issue was related nft

If use nftables natively as:
Mar 15 2024, 7:54 AM · VyOS 1.4 Sagitta
GitHub <[email protected]> committed rVYOSONEXa0b2b259484d: Merge pull request #3136 from vyos/mergify/bp/sagitta/pr-3135 (authored by c-po).
Mar 15 2024, 6:25 AM
GitHub <[email protected]> committed rVYOSONEXdbd54c1ed094: Merge pull request #3134 from vyos/mergify/bp/sagitta/pr-3133 (authored by c-po).
Mar 15 2024, 6:25 AM
Giggum changed Version from - to VyOS 1.4.0-epa1 on T6123: Limit NTP allow-client config to internal addresses by default.
Mar 15 2024, 1:01 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Giggum created T6123: Limit NTP allow-client config to internal addresses by default.
Mar 15 2024, 12:43 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Mar 14 2024

Apachez added a comment to T4610: Firewall with 20K entries cannot load after reboot.

I wouldnt call 1m37s of commit time for a single line of configchange as "resolved"...

Mar 14 2024, 10:33 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Also probably related: https://forum.vyos.io/t/long-commit-time-for-multiple-vrfs/14053

Mar 14 2024, 8:48 PM · Restricted Project, VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXaacdd44508d3: xml: T160: improve NAT64 help string (authored by c-po).
Mar 14 2024, 8:32 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX25005a9a95f5: xml: T2518: improve NAT66/NPTv6 help string (authored by c-po).
Mar 14 2024, 8:32 PM
c-po committed rVYOSONEX63de63f43aaa: xml: T2518: improve NAT66/NPTv6 help string.
Mar 14 2024, 8:31 PM
c-po committed rVYOSONEX7ca0ad917440: xml: T160: improve NAT64 help string.
Mar 14 2024, 8:31 PM
GitHub <[email protected]> committed rVYOSONEXf237e75e9fd1: Merge pull request #3135 from c-po/xml-nat66 (authored by c-po).
Mar 14 2024, 8:31 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX8bd803ec62e9: xml: T3642: improve PKI CLI help string (authored by c-po).
Mar 14 2024, 8:20 PM
c-po committed rVYOSONEXd6226d60dce4: xml: T3642: improve PKI CLI help string.
Mar 14 2024, 8:19 PM
GitHub <[email protected]> committed rVYOSONEXf23ff39cf3e2: Merge pull request #3133 from c-po/xml (authored by c-po).
Mar 14 2024, 8:19 PM
L0crian updated the task description for T6122: Protocols under VRF config run in a single pass against their conf_mode scripts.
Mar 14 2024, 8:10 PM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6118: radvd: RFC8781: add nat64prefix support from Open to Finished on the VyOS 1.5 Circinus board.
Mar 14 2024, 8:02 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po moved T6118: radvd: RFC8781: add nat64prefix support from Open to 1.4.0 on the VyOS 1.4 Sagitta board.
Mar 14 2024, 8:02 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro closed T6111: Minor revision to unicode support in configtree backend as Unknown Status.
Mar 14 2024, 6:16 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
natali-rs1985 committed rVYOSONEX0364d44b4ffb: snmp: T2998: SNMP v3 oid "exclude" option fix.
Mar 14 2024, 4:11 PM
natali-rs1985 committed rVYOSONEX1fb746332602: snmp: T2998: updated snmp.py.
Mar 14 2024, 4:11 PM
GitHub <[email protected]> committed rVYOSONEX713b2f370213: Merge pull request #3121 from natali-rs1985/T2998-equuleus (authored by dmbaturin).
Mar 14 2024, 4:10 PM
n.fort committed rVYOSONEXd56b4c05726d: T6110: dhcp: add error check when fail-over is enabled on a subnet, but range….
Mar 14 2024, 4:10 PM
GitHub <[email protected]> committed rVYOSONEXc2e66922c93b: Merge pull request #3111 from nicolas-fort/T6110 (authored by dmbaturin).
Mar 14 2024, 4:10 PM
Viacheslav triaged T6122: Protocols under VRF config run in a single pass against their conf_mode scripts as Normal priority.
Mar 14 2024, 2:33 PM · VyOS 1.4 Sagitta (1.4.1)
L0crian created T6122: Protocols under VRF config run in a single pass against their conf_mode scripts.
Mar 14 2024, 2:28 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav added a comment to T6121: Extend service config-sync for sections vpn, policy, vrf.

PR https://github.com/vyos/vyos-1x/pull/3132

set service config-sync mode 'load'
set service config-sync secondary address '192.0.2.1'
set service config-sync secondary key 'xxx'
set service config-sync section firewall
set service config-sync section interfaces pseudo-ethernet
set service config-sync section interfaces virtual-ethernet
set service config-sync section nat
set service config-sync section nat66
set service config-sync section protocols static
set service config-sync section pki
set service config-sync section vrf

Change some section:

vyos@r4# set nat source rule 100 outbound-interface name 'eth0'
[edit]
vyos@r4# set nat source rule 100 source address '10.0.0.0/24'
[edit]
vyos@r4# set nat source rule 100 translation address 'masquerade'
[edit]
vyos@r4# commit
INFO:vyos_config_sync:Config synchronization: Mode=load, Secondary=192.0.2.1
[edit]
vyos@r4#
Mar 14 2024, 1:50 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
natali-rs1985 committed rVYOSONEXd632ce658cbe: vrrp: T5504: Keepalived VRRP ability to set more than one peer-address.
Mar 14 2024, 11:14 AM
GitHub <[email protected]> committed rVYOSONEX1ba302d55b86: Merge pull request #3130 from natali-rs1985/T5504-equuleus (authored by dmbaturin).
Mar 14 2024, 11:14 AM
Apachez added a comment to T2433: Improve CLI value validator performance.

Is this related to the long commit and boot times when one have more than a handful routes or firewall rules as described in https://vyos.dev/T5388 ?

Mar 14 2024, 10:54 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
natali-rs1985 added a comment to T5504: Make it possible to set more than one peer-address in unicast VRRP.

PR for 1.3: https://github.com/vyos/vyos-1x/pull/3130

Mar 14 2024, 9:46 AM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.3 Equuleus (1.3.7)
Viacheslav claimed T6121: Extend service config-sync for sections vpn, policy, vrf.
Mar 14 2024, 9:11 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav created T6121: Extend service config-sync for sections vpn, policy, vrf.
Mar 14 2024, 9:11 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Unknown Object (User) created T6120: integration speedtest cli.
Mar 14 2024, 8:18 AM · VyOS 1.5 Circinus
HollyGurza claimed T3232: ISIS incorrect hostname and LSP ID.
Mar 14 2024, 7:46 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus, VyOS Rolling
HollyGurza added a comment to T1871: Add MTU option to "traffic-policy limiter".

https://github.com/vyos/vyos-1x/pull/3131

Mar 14 2024, 7:40 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 13 2024

a.apostoliuk added a comment to T3040: NHRP IPv6 Support.

I have tested FRR NHRP with IPv6 as an overlay and I found some issues.

Mar 13 2024, 3:13 PM · VyOS 1.5 Circinus
a.apostoliuk added a subtask for T2326: Migrate NHRP(DMVPN) to FRR: T3040: NHRP IPv6 Support.
Mar 13 2024, 1:53 PM · VyOS 1.5 Circinus
a.apostoliuk added a parent task for T3040: NHRP IPv6 Support: T2326: Migrate NHRP(DMVPN) to FRR.
Mar 13 2024, 1:53 PM · VyOS 1.5 Circinus