Page MenuHomeVyOS Platform
Feed All Stories

Apr 18 2024

tjh created T6248: <device> ip source-validation 'strict' - doesn't set /proc/sys/net/ipv4/conf/<device>/rp_filter.
Apr 18 2024, 12:41 AM · VyOS 1.4 Sagitta (1.4.0-epa2)

Apr 17 2024

jmoore added a comment to T6247: Add CGN "full cone" EIF support per RFC6888 REQ-7.

It very may well have been. That's not really relevant to this request. The repository is an example. We need the feature regardless of the state of the repository.

Apr 17 2024, 11:11 PM · VyOS Rolling
n.fort added a comment to T6247: Add CGN "full cone" EIF support per RFC6888 REQ-7.

I saw such repository more than once, but it seems that it has been abandoned. Last commit is dated two years ago.

Apr 17 2024, 7:01 PM · VyOS Rolling
jmoore added a comment to T6247: Add CGN "full cone" EIF support per RFC6888 REQ-7.

Another example on nftables: https://github.com/fullcone-nat-nftables/nftables-1.0.5-with-fullcone

Apr 17 2024, 6:03 PM · VyOS Rolling
Viacheslav added a subtask for T5169: Add CGNAT Carrier-Grade NAT based on nftables: T6247: Add CGN "full cone" EIF support per RFC6888 REQ-7.
Apr 17 2024, 5:47 PM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav added a parent task for T6247: Add CGN "full cone" EIF support per RFC6888 REQ-7: T5169: Add CGNAT Carrier-Grade NAT based on nftables.
Apr 17 2024, 5:47 PM · VyOS Rolling
Viacheslav removed a project from T6247: Add CGN "full cone" EIF support per RFC6888 REQ-7: VyOS 1.4 Sagitta.

We do not use iptables and their modules for new features.
Feel free to add PR for nftables or if you know which commands should be for nftables

Apr 17 2024, 5:43 PM · VyOS Rolling
SrividyaA added a comment to T6245: Unhandled exception in "show openvpn server".
vyos@test1:~$ sudo cat /run/openvpn/vtun20.status
OpenVPN CLIENT LIST
Updated,2024-04-17 16:40:05
Common Name,Real Address,Bytes Received,Bytes Sent,Connected Since
ROUTING TABLE
Virtual Address,Common Name,Real Address,Last Ref
GLOBAL STATS
Max bcast/mcast queue length,0
END
Apr 17 2024, 4:49 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jmoore created T6247: Add CGN "full cone" EIF support per RFC6888 REQ-7.
Apr 17 2024, 4:34 PM · VyOS Rolling
Giggum added a comment to T4909: Rewrite the NTP op mode in the new format.

From initial PR these two feedback points are now implemented. PR has been amended see https://github.com/vyos/vyos-1x/pull/3307

Apr 17 2024, 4:06 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
wouter0100 added a comment to T6189: BGP L3VPN connectivity is broken after re-enabling VRF.

I think I might've found the cause of this issue: the vni is unset from all VRFs when making changes. I posted a message about this on Slack (and about another, fairly similar, issue) on Slack about this.

Apr 17 2024, 3:20 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav reopened T6221: Enabling VRF breaks connectivity as "Open".
Apr 17 2024, 3:00 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
dex added a comment to T5386: Execute VRRP transition script when `set high-availability disable` is commited.

Just checked with the current rolling release 1.5-rolling-202404141045. After committing set high-availability disable, keepalived is successfully stopped and the logs show that the transition script seems to be executed:

Apr 17 2024, 2:15 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro closed T6243: Update vyos-http-api-tools for package idna security advisory as Resolved.
Apr 17 2024, 1:38 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
jestabro closed T6168: "add system image" does not set the default boot image to the current console type in compatibility mode, a subtask of T6176: image-tools: rationalize setting of console type, as Resolved.
Apr 17 2024, 1:36 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro closed T6168: "add system image" does not set the default boot image to the current console type in compatibility mode as Resolved.
Apr 17 2024, 1:36 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fetzerms added a comment to T6221: Enabling VRF breaks connectivity.

thank you very much for your analysis. I am still wondering, why it breaks with adding the vrf and why it works before.
Also, why it starts to work again, after rebooting when removing the vrf again (but not before rebooting)

Apr 17 2024, 1:35 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav changed the status of T6246: Add support for server health checks to reverse proxy from Open to In progress.
Apr 17 2024, 12:38 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
nvollmar created T6246: Add support for server health checks to reverse proxy.
Apr 17 2024, 11:51 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
GitHub <noreply@github.com> committed rVYOSONEX85f055ba5d76: Merge pull request #3323 from vyos/mergify/bp/sagitta/pr-3192 (authored by dmbaturin).
Apr 17 2024, 10:54 AM
GitHub <noreply@github.com> committed rVYOSONEX0b9d2c64103a: Merge pull request #3324 from vyos/mergify/bp/sagitta/pr-3320 (authored by dmbaturin).
Apr 17 2024, 10:54 AM
Viacheslav added a comment to T6245: Unhandled exception in "show openvpn server".

Needs the original file with OpenVPN addresses/statistics which are parsed /run/openvpn/{interface}.status
Without it, it will be difficult to do something.

Apr 17 2024, 10:46 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav moved T5722: Commit failure when trying to add a route in failover if the gateway is not in the same interface network from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 17 2024, 10:42 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T5722: Commit failure when trying to add a route in failover if the gateway is not in the same interface network as Resolved.
Apr 17 2024, 10:42 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T6221: Enabling VRF breaks connectivity as Invalid.

It is not related to VRF at all and is related to the policy routing logic:
Reproduced even on 1.3.2

set interfaces ethernet eth1 address '192.168.122.14/24'
Apr 17 2024, 10:30 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
SrividyaA triaged T6245: Unhandled exception in "show openvpn server" as Normal priority.
Apr 17 2024, 10:18 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
SrividyaA created T6245: Unhandled exception in "show openvpn server".
Apr 17 2024, 10:17 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
tjh updated the task description for T6244: Improve formatting in "show system uptime".
Apr 17 2024, 9:11 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6244: Improve formatting in "show system uptime" as Wishlist priority.
Apr 17 2024, 9:02 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
tjh assigned T6244: Improve formatting in "show system uptime" to c-po.
Apr 17 2024, 9:02 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
tjh created T6244: Improve formatting in "show system uptime".
Apr 17 2024, 9:00 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T5535: Move disable-directed-broadcast to firewall global-options from Confirmed to Needs testing.
Apr 17 2024, 8:57 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T6191: Policy route set-mss option is not working correctly from Confirmed to Needs testing.
Apr 17 2024, 8:56 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6237: IPSec remote access VPN: ability to set EAP ID of clients as Wishlist priority.
Apr 17 2024, 8:37 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T5360: ddclient generating abuse as Resolved.
Apr 17 2024, 8:36 AM · VyOS 1.4 Sagitta
indrajitr closed T5574: Support per-service cache management for dynamic dns providers as Resolved.
Apr 17 2024, 6:53 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr closed T5612: Miscellaneous improvements and fixes for dynamic DNS configuration as Resolved.
Apr 17 2024, 6:53 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr closed T5723: mdns repeater: Always reload systemd daemon before applying changes as Resolved.
Apr 17 2024, 6:52 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr closed T5966: Adjust dynamic dns configuration address subpath to be more intuitive and other op-mode adjustments, a subtask of T5791: Update dynamic dns configuration path to be consistent with other areas of VyOS, as Resolved.
Apr 17 2024, 6:51 AM · VyOS 1.5 Circinus (2025.11)
indrajitr closed T5966: Adjust dynamic dns configuration address subpath to be more intuitive and other op-mode adjustments as Resolved.

Updates have been applied on 1.4 and 1.5.

Apr 17 2024, 6:51 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
indrajitr added a comment to T5360: ddclient generating abuse.

This can probably be closed.

Apr 17 2024, 6:50 AM · VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX292f4b8efe2a: T6191: do not append action to firewall and policy route|route6 when its not… (authored by n.fort).
Apr 17 2024, 3:26 AM
n.fort committed rVYOSONEX5ab8f9ac47d9: T6191: do not append action to firewall and policy route|route6 when its not….
Apr 17 2024, 3:25 AM
GitHub <noreply@github.com> committed rVYOSONEX24c997dee169: Merge pull request #3320 from nicolas-fort/T6191 (authored by c-po).
Apr 17 2024, 3:25 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX9f62c3082429: image-tools: T6168: compat mode update should preserve console type (authored by jestabro).
Apr 17 2024, 1:40 AM
jestabro moved T6168: "add system image" does not set the default boot image to the current console type in compatibility mode from Open to Finished on the VyOS 1.5 Circinus board.
Apr 17 2024, 1:40 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro closed T6154: Installer should ask for password twice, a subtask of T4516: Rewrite system image manipulation tools in Python, as Resolved.
Apr 17 2024, 1:27 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro closed T6154: Installer should ask for password twice as Resolved.
Apr 17 2024, 1:27 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro moved T6154: Installer should ask for password twice from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 17 2024, 1:27 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
GitHub <noreply@github.com> committed rVYOSONEX06a08f61abb9: Merge pull request #3322 from vyos/mergify/bp/sagitta/pr-3321 (authored by jestabro).
Apr 17 2024, 1:25 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXabfd62665359: image-tools: T6154: installer prompts to confirm a non-default passwd (authored by jestabro).
Apr 17 2024, 1:18 AM
jestabro committed rVYOSONEXf43edbd7cd36: image-tools: T6154: installer prompts to confirm a non-default passwd.
Apr 17 2024, 1:16 AM
GitHub <noreply@github.com> committed rVYOSONEXce7023bea759: Merge pull request #3321 from jestabro/confirm-pass (authored by jestabro).
Apr 17 2024, 1:16 AM

Apr 16 2024

Embezzle claimed T6237: IPSec remote access VPN: ability to set EAP ID of clients.
Apr 16 2024, 8:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
paigeadelethompson added a comment to T6097: vrf_zones blocking ipv6 traffic.

I decided to dig into this a little more and try to trace this out:

sudo nft add chain inet vrf_zones trace_chain { type filter hook prerouting priority -301\; }
sudo nft add rule inet vrf_zones trace_chain meta nftrace set 1
Apr 16 2024, 7:41 PM · VyOS Rolling, VyOS 1.5 Circinus
Giggum updated subscribers of T4909: Rewrite the NTP op mode in the new format.

@dmbaturin, @sever
Would love your input regarding the lack of headers when using the -c option. I've created a PoC around "chronyc -c activity" as it was the most straight forward command to start with.

Apr 16 2024, 7:21 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav changed the status of T6242: Add an option to disable certificate verification to reverse proxy from Open to Needs testing.
Apr 16 2024, 7:20 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fetzerms updated subscribers of T5868: Use Debian snapshot repository in vyos-build Docker image.

@dmbaturin , @Viacheslav - I use debian snapshot repository when building VyOS LTS on my own.

Apr 16 2024, 7:13 PM
paigeadelethompson added a comment to T6097: vrf_zones blocking ipv6 traffic.

side note, if you flush ruleset, and only add:

Apr 16 2024, 6:20 PM · VyOS Rolling, VyOS 1.5 Circinus
paigeadelethompson added a comment to T6097: vrf_zones blocking ipv6 traffic.

Something I just figured out is that the minute I do:

Apr 16 2024, 6:06 PM · VyOS Rolling, VyOS 1.5 Circinus
n.fort added a comment to T6191: Policy route set-mss option is not working correctly.

PR: https://github.com/vyos/vyos-1x/pull/3320

Apr 16 2024, 5:51 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
dmbaturin edited the content of Task creation policy.
Apr 16 2024, 5:49 PM
jestabro moved T6243: Update vyos-http-api-tools for package idna security advisory from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 16 2024, 5:09 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
jestabro moved T6243: Update vyos-http-api-tools for package idna security advisory from Open to Finished on the VyOS 1.5 Circinus board.
Apr 16 2024, 5:09 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
n.fort changed Version from 1.4.0-epa2 to 1.4.0-epa2, 1.5-rolling-202404141045 on T6191: Policy route set-mss option is not working correctly.
Apr 16 2024, 4:57 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T6191: Policy route set-mss option is not working correctly from Open to Confirmed.
Apr 16 2024, 4:57 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a comment to T6022: set system image default-boot.

The regression causing 'image cannot be found" was fixed in https://vyos.dev/T6186.

Apr 16 2024, 4:46 PM · VyOS 1.4 Sagitta (1.4.0)
jestabro added a subtask for T6022: set system image default-boot: T6186: 'set system image default-boot' fails to find images that actually do exist in the system.
Apr 16 2024, 4:45 PM · VyOS 1.4 Sagitta (1.4.0)
jestabro added a parent task for T6186: 'set system image default-boot' fails to find images that actually do exist in the system: T6022: set system image default-boot.
Apr 16 2024, 4:45 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro removed a subtask for T6022: set system image default-boot: T5917: Restore annotations of (running)/(default boot) in select image list.
Apr 16 2024, 4:44 PM · VyOS 1.4 Sagitta (1.4.0)
jestabro removed a parent task for T5917: Restore annotations of (running)/(default boot) in select image list: T6022: set system image default-boot.
Apr 16 2024, 4:44 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
natali-rs1985 committed rVYOSONEX82fdbedb79cf: pppoe-server: T6141: T5364: PPPoE-server add pado-delay without sessions fails.
Apr 16 2024, 4:41 PM
GitHub <noreply@github.com> committed rVYOSONEX41663efaba26: Merge pull request #3317 from natali-rs1985/T6141-equuleus (authored by c-po).
Apr 16 2024, 4:41 PM
jestabro added a subtask for T6022: set system image default-boot: T5917: Restore annotations of (running)/(default boot) in select image list.
Apr 16 2024, 4:41 PM · VyOS 1.4 Sagitta (1.4.0)
jestabro added a parent task for T5917: Restore annotations of (running)/(default boot) in select image list: T6022: set system image default-boot.
Apr 16 2024, 4:41 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEX8f778f989d8f: Merge pull request #3318 from vyos/mergify/bp/sagitta/pr-3315 (authored by c-po).
Apr 16 2024, 4:41 PM
GitHub <noreply@github.com> committed rVYOSONEX5a481813c059: Merge pull request #3319 from vyos/mergify/bp/sagitta/pr-3313 (authored by c-po).
Apr 16 2024, 4:40 PM
Viacheslav changed the status of T5722: Commit failure when trying to add a route in failover if the gateway is not in the same interface network from In progress to Needs testing.
Apr 16 2024, 4:33 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro added a comment to T6243: Update vyos-http-api-tools for package idna security advisory.

PR:
https://github.com/vyos/vyos-http-api-tools/pull/11

Apr 16 2024, 4:31 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
jestabro triaged T6243: Update vyos-http-api-tools for package idna security advisory as Normal priority.
Apr 16 2024, 4:12 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX6cace2df99c7: T5722: Failover route add option onlink (authored by Viacheslav).
Apr 16 2024, 3:10 PM
Viacheslav committed rVYOSONEXbb832acb9788: T5722: Failover route add option onlink.
Apr 16 2024, 3:09 PM
GitHub <noreply@github.com> committed rVYOSONEX6825873bd1e8: Merge pull request #3313 from sever-sever/T5722 (authored by dmbaturin).
Apr 16 2024, 3:08 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXdeb92e466110: T6242: load-balancing reverse-proxy: Ability for ssl backends to not verify… (authored by Embezzle).
Apr 16 2024, 3:08 PM
Embezzle committed rVYOSONEXaafe22d08bb3: T6242: load-balancing reverse-proxy: Ability for ssl backends to not verify….
Apr 16 2024, 3:06 PM
GitHub <noreply@github.com> committed rVYOSONEXc0eec365e2e3: Merge pull request #3315 from Embezzle/T6242 (authored by dmbaturin).
Apr 16 2024, 3:06 PM
Giggum added a comment to T4909: Rewrite the NTP op mode in the new format.

Status update:

  • "Like for like" functionality between .sh script and .py script is complete and working (can be viewed in PR)
  • Raw output capability -> in progress
Apr 16 2024, 1:36 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
Giggum closed T6099: Suppress unsupported interfaces from appearing in messages log by Telegraf as Resolved.
Apr 16 2024, 1:29 PM · VyOS 1.5 Circinus
Giggum added a comment to T6099: Suppress unsupported interfaces from appearing in messages log by Telegraf .

@Viacheslav concur that it looks to be resolved. The last log entry was at 9:10 and nothing telegraph-related has been logged in almost 30 minutes since. I will close ticket. Thank your help and insight.

Apr 16 2024, 1:26 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T6123: Limit NTP allow-client config to internal addresses by default from Open to Needs testing.
Apr 16 2024, 1:03 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav changed the status of T4915: Minisign verification failure == pass?? from Needs testing to Needs reporter action.

We'll close it if no response

Apr 16 2024, 12:40 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav edited projects for T4982: OpenConnect should have TLS 1.0 and TLS 1.1 disabled by default, added: VyOS 1.5 Circinus; removed VyOS 1.4 Sagitta (1.4.0-epa3), Restricted Project.
Apr 16 2024, 12:35 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T5946: TASK [setup-root-partition : Create a fileystem on EFI partition] failing in Docker as Wontfix.

A docker container usually has issues with loop devices:
Use the VM or attach dev

Apr 16 2024, 10:10 AM · VyOS 1.4 Sagitta
HollyGurza added a comment to T4248: There isn't a way to remove the only rule from the (traffic-policy) class..

https://github.com/vyos/vyos-1x/pull/3316

Apr 16 2024, 8:02 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
HollyGurza changed the status of T4248: There isn't a way to remove the only rule from the (traffic-policy) class. from Open to In progress.
Apr 16 2024, 8:01 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 15 2024

Embezzle added a comment to T6242: Add an option to disable certificate verification to reverse proxy.

PR: https://github.com/vyos/vyos-1x/pull/3315

Apr 15 2024, 6:54 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
GitHub <noreply@github.com> committed rVYOSONEXd8bca084a1f0: Merge pull request #3310 from vyos/mergify/bp/sagitta/pr-3309 (authored by c-po).
Apr 15 2024, 6:41 PM
GitHub <noreply@github.com> committed rVYOSONEX131bb134ec7f: Merge pull request #3314 from vyos/mergify/bp/sagitta/pr-3311 (authored by c-po).
Apr 15 2024, 6:39 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXc976d71110df: pki: T6241: Fix dependency updates on PKI changes (authored by sarthurdev).
Apr 15 2024, 6:14 PM
sarthurdev committed rVYOSONEX9f9891a20995: pki: T6241: Fix dependency updates on PKI changes.
Apr 15 2024, 6:12 PM