Page MenuHomeVyOS Platform
Feed All Stories

Apr 10 2024

Viacheslav added a comment to T6222: VRRP rfc3768-compatibility not working correctly when resulting interface name is over 15 characters.

It is another bug, it should be a separate bug report https://vyos.dev/T6223

Apr 10 2024, 1:38 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
natali-rs1985 changed the status of T6141: Trying to set PADO delay in PPPoE server without also configuring the session options causes a commit failure from Open to In progress.
Apr 10 2024, 1:10 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa2)
natali-rs1985 added a comment to T5364: Make it possible to set the PADO delay to 0.

related to T6141

Apr 10 2024, 1:09 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3)
Chrisc-c-c added a comment to T6222: VRRP rfc3768-compatibility not working correctly when resulting interface name is over 15 characters.

After a bit more digging it looks like the 15 character limit is a kernel limitation, so the issue is more with how the interfaces are named when creating VRRP groups and no real handling of a scenario where the length is over 15 characters.

Apr 10 2024, 12:56 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
d.shleg added a comment to T6082: BGP doesn't allow the same local AS and remote AS in peer groups.

Yes, initial not applied. I corrected config and received other error

Apr 10 2024, 12:52 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Giggum updated subscribers of T5795: Better support for dynamic IPv6 prefixes.

https://vyos.dev/T3771 was resolved should this one be closed as well given your comment @sever ?

Apr 10 2024, 12:51 PM · VyOS Rolling
Viacheslav added a comment to T6221: Enabling VRF breaks connectivity.

I don't have any issues with your config, but my addresses (of course, I don't have all BGP VPN connections, etc.)

vyos@r4# set vrf name foo table 10101
[edit]
vyos@r4# commit
[edit]
vyos@r4# 
[edit]
vyos@r4# run show ver
Version:          VyOS 1.5-rolling-202404090019
Release train:    current
Apr 10 2024, 12:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Giggum attached a referenced file: F4264754: show_conf.png.
Apr 10 2024, 12:40 PM · VyOS Rolling
Giggum attached a referenced file: F4264753: changes_chrony_conf_j2.png.
Apr 10 2024, 12:40 PM · VyOS Rolling
Chrisc-c-c added a comment to T6222: VRRP rfc3768-compatibility not working correctly when resulting interface name is over 15 characters.

Log output when starting keepalived:

Apr 10 2024, 12:30 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
fetzerms updated the task description for T6221: Enabling VRF breaks connectivity.
Apr 10 2024, 12:23 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Chrisc-c-c created T6222: VRRP rfc3768-compatibility not working correctly when resulting interface name is over 15 characters.
Apr 10 2024, 12:15 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
fetzerms added a comment to T6221: Enabling VRF breaks connectivity.

Yup... it does not even come back after commit-confirm - so I assume something more severe crashes.

Apr 10 2024, 12:14 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fetzerms added a comment to T6221: Enabling VRF breaks connectivity.

Unfortunately this also breaks after the commit (even tho the "commit" command finalizes). If I recall correctly, a commit-confirm won't reboot the box either - but I'll double check that.

Apr 10 2024, 12:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6082: BGP doesn't allow the same local AS and remote AS in peer groups.

@d.shleg As I mentioned the config is not applied by FRR

r4# show run bgpd
Building configuration...
Apr 10 2024, 11:55 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
fetzerms added a comment to T6221: Enabling VRF breaks connectivity.

Yes, let me try.

Apr 10 2024, 11:52 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6221: Enabling VRF breaks connectivity.

Could you try the latest rolling?

Apr 10 2024, 11:51 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
d.shleg added a comment to T6082: BGP doesn't allow the same local AS and remote AS in peer groups.

Message at 6 March

Apr 10 2024, 11:47 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
d.shleg added a comment to T6082: BGP doesn't allow the same local AS and remote AS in peer groups.

Initial not confirmed by FRR, but I provided configuration is accepted by FRR but not applied by vyos. Please look messages

Apr 10 2024, 11:45 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
fetzerms updated the task description for T6221: Enabling VRF breaks connectivity.
Apr 10 2024, 11:25 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
fetzerms added a comment to T6221: Enabling VRF breaks connectivity.

Ok. Just to clarify, as T6097 talks about ipv6: This seems to break both ipv6 and ipv4 connectivity for me

Apr 10 2024, 11:23 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6082: BGP doesn't allow the same local AS and remote AS in peer groups.

Your initial configuration and adding a new peer is not acceptable by FRR

vyos@r4# run show ver
Version:          VyOS 1.5-rolling-202404090019
Release train:    current
vyos@r4# compare 
[protocols bgp neighbor]
+ 10.177.75.2 {
+     peer-group "OVERLAY"
+     remote-as "64542"
+ }
Apr 10 2024, 11:20 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6221: Enabling VRF breaks connectivity.

Probably the same task https://vyos.dev/T6097

Apr 10 2024, 11:04 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
fetzerms added a comment to T6221: Enabling VRF breaks connectivity.

I only created a vrf (but did not assign it to anything else). Is that intend to break connectivity?

Apr 10 2024, 10:23 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Apachez added a comment to T6221: Enabling VRF breaks connectivity.

Thats common with other vendors aswell.

Apr 10 2024, 10:16 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
fetzerms triaged T6221: Enabling VRF breaks connectivity as Normal priority.
Apr 10 2024, 9:50 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T5750: Upgrade from 1.3.4 to 1.4 Rolling fails QoS, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
Apr 10 2024, 9:28 AM · VyOS Rolling, Bugs
Viacheslav closed T5750: Upgrade from 1.3.4 to 1.4 Rolling fails QoS as Resolved.
Apr 10 2024, 9:28 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5858: Improve the formatting of conntrack statistics output as Resolved.
Apr 10 2024, 8:55 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav moved T5858: Improve the formatting of conntrack statistics output from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 10 2024, 8:55 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a project to T5858: Improve the formatting of conntrack statistics output: VyOS 1.4 Sagitta (1.4.0-epa3).
Apr 10 2024, 8:55 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
a.apostoliuk claimed T6100: NAT config migration error in 1.4.0-epa1 if invalid address/network defined in 1.3.6 version.
Apr 10 2024, 7:17 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6220: add IPv6 support for TACACS as Wishlist priority.
Apr 10 2024, 7:06 AM · VyOS Rolling
Viacheslav closed T6106: Improve the commit error message for the case when route-reflector-client option is defined in a peer-group as Resolved.
Apr 10 2024, 7:05 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T2801: conntrack-tools flooding logs as Not Applicable.
Apr 10 2024, 7:03 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
Viacheslav moved T6124: Docker equuleus build image doesn't build due to fpm from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.7) board.
Apr 10 2024, 7:02 AM · VyOS 1.3 Equuleus (1.3.7)
Apachez placed T5498: fsck during boot doesnt work up for grabs.

Removed assignee for now in case somebody else wants to fix this?

Apr 10 2024, 5:52 AM · VyOS Rolling, Bugs
Apachez placed T5522: Add logging for which mksquashfs syntax is being used up for grabs.

Removed assignee for now in case somebody else wants to fix this?

Apr 10 2024, 5:46 AM · VyOS Rolling
Apachez placed T5641: Enable compression of kernel modules up for grabs.

Removed assignee for now in case somebody else wants to fix this?

Apr 10 2024, 5:45 AM
Apachez added a comment to T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.

Removed assignee for now in case somebody else wants to fix this?

Apr 10 2024, 5:45 AM · VyOS Rolling
Apachez placed T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once up for grabs.
Apr 10 2024, 5:43 AM · VyOS Rolling
MattK closed T6124: Docker equuleus build image doesn't build due to fpm as Resolved.

Confirmed this is now fixed.

Apr 10 2024, 5:39 AM · VyOS 1.3 Equuleus (1.3.7)
tjh added a comment to T2801: conntrack-tools flooding logs.

Sorry guys - I'm on 1.4-epa2 these days but aren't doing VRRP/Conntrack sync anymore.

Apr 10 2024, 5:27 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
HollyGurza closed T6206: L2tp smoketest fails if vyos-configd is running as Resolved.
Apr 10 2024, 3:49 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
HollyGurza added a comment to T6106: Improve the commit error message for the case when route-reflector-client option is defined in a peer-group.

i think yes, now we will show frr logs for unhandled exceptions and normal short messages for others e.g. route-reflector-client only supported for iBGP peers

Apr 10 2024, 3:45 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Thunderstorm claimed T6220: add IPv6 support for TACACS.
Apr 10 2024, 2:25 AM · VyOS Rolling
Thunderstorm created T6220: add IPv6 support for TACACS.
Apr 10 2024, 2:25 AM · VyOS Rolling
Giggum added a comment to T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.

I gave it a go due to similarities between this and https://vyos.dev/T6123.

Apr 10 2024, 2:07 AM · VyOS Rolling

Apr 9 2024

tgnthump added a comment to T6219: sysctl options support for containers.

Started on a PR: https://github.com/vyos/vyos-1x/pull/3288

Apr 9 2024, 7:45 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav triaged T6218: Container network interface in VRF fails to generate IPv6 link-local address as Normal priority.
Apr 9 2024, 7:35 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
GitHub <noreply@github.com> committed rVYOSONEX240218750c3a: Merge pull request #3287 from vyos/mergify/bp/sagitta/pr-3286 (authored by Viacheslav).
Apr 9 2024, 7:31 PM
tgnthump added a comment to T6219: sysctl options support for containers.

My specific use case is a container that requires --sysctl=net.ipv4.conf.all.forwarding=1

Apr 9 2024, 6:41 PM · VyOS 1.4 Sagitta (1.4.1)
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX5497edf69c7e: container: T6218: fix host IPv6 link-local address for VRF networks (authored by jvoss).
Apr 9 2024, 6:34 PM
jvoss committed rVYOSONEX6b5590ae3325: container: T6218: fix host IPv6 link-local address for VRF networks.
Apr 9 2024, 6:33 PM
GitHub <noreply@github.com> committed rVYOSONEX5d890037b177: Merge pull request #3286 from jvoss/eui64_podman_vrf (authored by c-po).
Apr 9 2024, 6:33 PM
tgnthump created T6219: sysctl options support for containers.
Apr 9 2024, 6:30 PM · VyOS 1.4 Sagitta (1.4.1)
jvoss updated the task description for T6218: Container network interface in VRF fails to generate IPv6 link-local address.
Apr 9 2024, 6:28 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jvoss claimed T6218: Container network interface in VRF fails to generate IPv6 link-local address.
Apr 9 2024, 6:19 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jvoss created T6218: Container network interface in VRF fails to generate IPv6 link-local address.
Apr 9 2024, 6:19 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
GitHub <noreply@github.com> committed rVYOSONEX9a965086a3eb: Merge pull request #3285 from vyos/mergify/bp/sagitta/pr-3259 (authored by c-po).
Apr 9 2024, 4:56 PM
Viacheslav closed T3409: Add back TCP-MSS Clamp to PMTU as Resolved.

Mark it as resolved, reopen the task if required.

Apr 9 2024, 4:21 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T6106: Improve the commit error message for the case when route-reflector-client option is defined in a peer-group.

Was it fixed?

Apr 9 2024, 4:12 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav changed the status of T6106: Improve the commit error message for the case when route-reflector-client option is defined in a peer-group from In progress to Needs testing.
Apr 9 2024, 4:12 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6124: Docker equuleus build image doesn't build due to fpm.

@MattK Could you re-check and close it?

Apr 9 2024, 4:08 PM · VyOS 1.3 Equuleus (1.3.7)
Viacheslav changed the status of T6132: Conntrack-sync Internal Cache Growing Uncontrollably from Open to Needs reporter action.
Apr 9 2024, 4:06 PM · VyOS Rolling, Bugs
Viacheslav changed the status of T6212: Firewall offload counters show always zero from Open to Needs testing.
Apr 9 2024, 4:06 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T2801: conntrack-tools flooding logs.

@tjh Any updates?
By the way there is a new option

vyos@r4# set service conntrack-sync disable-syslog 
[edit]
vyos@r4#
Apr 9 2024, 4:04 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX5264ba80e8c6: container: T6210: add capability sys-nice (authored by theflakes).
Apr 9 2024, 3:59 PM
GitHub <noreply@github.com> committed rVYOSONEXb8f3c61ca514: container: T6210: add capability sys-nice (authored by theflakes).
Apr 9 2024, 3:58 PM
Viacheslav added a comment to T5745: conntrack-sync: Multiprimary setups for HA/VRRP.

https://conntrack-tools.netfilter.org/manual.html#sync-aa

conntrackd allows you to deploy an symmetric Active-Active setup based on a static approach. For example, assume that you have two virtual IPs, vIP1 and vIP2, and two firewall replicas, FW1 and FW2. You can give the virtual vIP1 to the firewall FW1 and the vIP2 to the FW2.
Apr 9 2024, 3:58 PM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync
GitHub <noreply@github.com> committed rVYOSONEX98d6fdffeae4: Merge pull request #3284 from vyos/mergify/bp/sagitta/pr-3283 (authored by c-po).
Apr 9 2024, 3:43 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXde1afd1cfe39: T6199: add missing build dependency (authored by c-po).
Apr 9 2024, 3:23 PM
c-po committed rVYOSONEX8e2330fed648: T6199: add missing build dependency.
Apr 9 2024, 3:22 PM
GitHub <noreply@github.com> committed rVYOSONEX1f369d50c15b: Merge pull request #3283 from c-po/T6199-build-fix (authored by c-po).
Apr 9 2024, 3:22 PM
GitHub <noreply@github.com> committed rVYOSONEX80257788f205: Merge pull request #3282 from vyos/mergify/bp/sagitta/pr-3280 (authored by c-po).
Apr 9 2024, 3:09 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX3419a8f039a6: T5858: Fix op-mode format for show conntrack statistics (authored by Viacheslav).
Apr 9 2024, 2:58 PM
Viacheslav committed rVYOSONEX13ed4f9d489d: T5858: Fix op-mode format for show conntrack statistics.
Apr 9 2024, 2:56 PM
GitHub <noreply@github.com> committed rVYOSONEX28e8233baae5: Merge pull request #3280 from sever-sever/T5858 (authored by dmbaturin).
Apr 9 2024, 2:56 PM
Viacheslav added a project to T6217: Set the log id of the VRRP contrack-sync script to vyos-vrrp-conntracksync: Restricted Project.
Apr 9 2024, 2:56 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6132: Conntrack-sync Internal Cache Growing Uncontrollably.

@trae32566 Can you provide the next output?

sudo conntrackd -C /run/conntrackd/conntrackd.conf -s  && echo "conntrack_count: " && sudo conntrack -C
sudo conntrackd -C /run/conntrackd/conntrackd.conf -s network
sudo conntrackd -C /run/conntrackd/conntrackd.conf -s cache
sudo conntrackd -C /run/conntrackd/conntrackd.conf -s runtime
sudo conntrackd -C /run/conntrackd/conntrackd.conf -s link
sudo conntrackd -C /run/conntrackd/conntrackd.conf -s queue
Apr 9 2024, 1:05 PM · VyOS Rolling, Bugs
Viacheslav triaged T6217: Set the log id of the VRRP contrack-sync script to vyos-vrrp-conntracksync as Low priority.
Apr 9 2024, 12:21 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav created T6217: Set the log id of the VRRP contrack-sync script to vyos-vrrp-conntracksync.
Apr 9 2024, 12:20 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a subtask for T5938: Migration fail root task for 1.4-rc: T6216: Firewall group names that contain the '+' character break the config.
Apr 9 2024, 12:20 PM · VyOS Rolling, Bugs
n.fort added a parent task for T6216: Firewall group names that contain the '+' character break the config: T5938: Migration fail root task for 1.4-rc.
Apr 9 2024, 12:20 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
HollyGurza added a comment to T6206: L2tp smoketest fails if vyos-configd is running.

https://github.com/vyos/vyatta-cfg/pull/77

Apr 9 2024, 12:11 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
n.fort changed the status of T6216: Firewall group names that contain the '+' character break the config from Open to Confirmed.
Apr 9 2024, 12:11 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort created T6216: Firewall group names that contain the '+' character break the config.
Apr 9 2024, 12:11 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6213: Validations in firewall groups mistakenly reject correct configurations.

PR: https://github.com/vyos/vyos-1x/pull/3281

Apr 9 2024, 11:13 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6214: Error when using some constraints.

PR: https://github.com/vyos/vyos-1x/pull/3281

Apr 9 2024, 11:13 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
a.hajiyev added a comment to T6215: Replace confusing error messages with clear ones when delete rule form firewall policy.

https://github.com/vyos/vyatta-cfg-firewall/pull/37

Apr 9 2024, 10:56 AM · VyOS 1.3 Equuleus (1.3.8)
a.hajiyev created T6215: Replace confusing error messages with clear ones when delete rule form firewall policy.
Apr 9 2024, 10:51 AM · VyOS 1.3 Equuleus (1.3.8)
Viacheslav moved T6121: Extend service config-sync for sections vpn, policy, vrf from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 9 2024, 10:32 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav edited projects for T6121: Extend service config-sync for sections vpn, policy, vrf, added: VyOS 1.4 Sagitta (1.4.0-epa3); removed VyOS 1.4 Sagitta (1.4.0-epa2).
Apr 9 2024, 10:32 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav moved T6121: Extend service config-sync for sections vpn, policy, vrf from Open to Finished on the VyOS 1.5 Circinus board.
Apr 9 2024, 10:32 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T6121: Extend service config-sync for sections vpn, policy, vrf as Resolved.
Apr 9 2024, 10:32 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav changed the status of T5858: Improve the formatting of conntrack statistics output from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/3280

vyos@r15-left:~$ show conntrack statistics 
CPU    Found    Invalid    Insert    Insert fail    Drop    Early drop    Errors    Search restart
-----  -------  ---------  --------  -------------  ------  ------------  --------  ----------------  --  --
0      0        280        0         1              1       0             1         0                 2   0
1      0        73         0         0              0       0             126       0                 1   0
vyos@r15-left:~$
Apr 9 2024, 10:30 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort renamed T6214: Error when using some constraints from Error when using some contraints to Error when using some constraints.
Apr 9 2024, 9:45 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
n.fort created T6214: Error when using some constraints.
Apr 9 2024, 9:44 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
Giggum updated the task description for T6123: Limit NTP allow-client config to internal addresses by default.
Apr 9 2024, 12:36 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Giggum updated the task description for T6123: Limit NTP allow-client config to internal addresses by default.
Apr 9 2024, 12:18 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus