Page MenuHomeVyOS Platform
Feed All Stories

May 30 2024

Viacheslav moved T6402: Invalid variables referenced in reverse proxy validation from Open to Finished on the VyOS 1.5 Circinus board.
May 30 2024, 5:55 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Vijayakumar committed rVYOSONEX251b756c4f2a: T6416: added smoke-test workflow.
May 30 2024, 5:33 AM
syncer added a comment to T6416: Run smoke tests before merging .

no it's not
hold on with his task for now

May 30 2024, 5:29 AM · GitHub Infrastructure
Vijayakumar committed rVYOSONEXb28eb848b619: T6416: added smoke-test workflow.
May 30 2024, 5:28 AM
Vijayakumar committed rVYOSONEXbf5243c5e699: T6416: added smoke-test workflow.
May 30 2024, 5:22 AM
Vijayakumar added a comment to T6416: Run smoke tests before merging .

Hope we need to run this for smoke test
https://github.com/vyos/vyos-1x?tab=readme-ov-file#tests

May 30 2024, 4:19 AM · GitHub Infrastructure

May 29 2024

Viacheslav added a comment to T6417: Common storage location for accounts for different VPNs.

It is not clear why it should be ignored? If they should be ignored they must not be in the CLI at all.
Why not use RADIUS authentication for it?

May 29 2024, 11:30 PM · VyOS Rolling
c-po updated the task description for T6419: reverse-proxy: full CA chain is not build when verifying backend server.
May 29 2024, 9:37 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T6419: reverse-proxy: full CA chain is not build when verifying backend server from Open to Finished on the VyOS 1.5 Circinus board.
May 29 2024, 9:31 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T6419: reverse-proxy: full CA chain is not build when verifying backend server from Need Triage to In Progress on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 29 2024, 9:30 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po edited projects for T6419: reverse-proxy: full CA chain is not build when verifying backend server, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta.
May 29 2024, 9:30 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a comment to T6419: reverse-proxy: full CA chain is not build when verifying backend server.

https://github.com/vyos/vyos-1x/pull/3546

May 29 2024, 9:30 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Embezzle closed T6402: Invalid variables referenced in reverse proxy validation as Resolved.

Tested as working in: VyOS 1.5-rolling-202405280020

May 29 2024, 9:10 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po changed the status of T6419: reverse-proxy: full CA chain is not build when verifying backend server from Open to In progress.
May 29 2024, 8:32 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po created T6419: reverse-proxy: full CA chain is not build when verifying backend server.
May 29 2024, 8:32 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po assigned T6418: reverse-proxy: backend http-check CLI option not honored to Viacheslav.
May 29 2024, 8:16 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po created T6418: reverse-proxy: backend http-check CLI option not honored.
May 29 2024, 8:16 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Vijayakumar added a comment to T6416: Run smoke tests before merging .

For this, need to get details on our existing smoke tests.

May 29 2024, 6:51 PM · GitHub Infrastructure
Vijayakumar closed T6397: Triger action on merge, a subtask of T6309: Check code quality with CodeQL, as Resolved.
May 29 2024, 6:49 PM · GitHub Infrastructure
Vijayakumar closed T6397: Triger action on merge as Resolved.
May 29 2024, 6:49 PM · GitHub Infrastructure
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX33c987bf43ad: nat: T6371: fix op mode display of configured ports when comma separated list… (authored by Giggum).
May 29 2024, 6:29 PM
GitHub <noreply@github.com> committed rVYOSONEXb7595ee9d328: nat: T6371: fix op mode display of configured ports when comma separated list… (authored by Giggum).
May 29 2024, 6:27 PM
fernando closed T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr as Resolved.
May 29 2024, 5:57 PM · VyOS 1.4 Sagitta (1.4.1)
fernando added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

@mersl thanks for confirm.

May 29 2024, 5:57 PM · VyOS 1.4 Sagitta (1.4.1)
pavel-altair added a comment to T6417: Common storage location for accounts for different VPNs.

It probably cannot be a universal solution due to specific per-user options.
For example, for opencoonect, you can add otp if you want on a per-user basis and not do it for other users.

vyos@r4# set vpn openconnect authentication local-users username foo 
Possible completions:
   disable              Disable instance
 > otp                  2FA OTP authentication parameters
   password             Password used for authentication

Another case specific client IP address or rate limit

vyos@r4# set vpn sstp authentication local-users username foo 
Possible completions:
   disable              Disable instance
   password             Password for authentication
 > rate-limit           Upload/Download speed limits
   static-ip            Static client IP address (default: *)

Though it could be only for accel-ppp based configuration sstp/l2tp/pptp

specific per-user options can ignored if the protocol does not support them

May 29 2024, 5:43 PM · VyOS Rolling
Viacheslav committed rVYOSONEXf3c14280a625: T6415: Fix variables for repo sync.
May 29 2024, 5:14 PM
Restricted Repository Identity closed T6415: Repo sync, a subtask of T6309: Check code quality with CodeQL, as Resolved.
May 29 2024, 5:14 PM · GitHub Infrastructure
Restricted Repository Identity closed T6415: Repo sync as Resolved by committing rVYOSONEXa234384dd060: Merge pull request #3543 from sever-sever/T6415-fix.
May 29 2024, 5:14 PM · GitHub Infrastructure
GitHub <noreply@github.com> committed rVYOSONEXa234384dd060: Merge pull request #3543 from sever-sever/T6415-fix (authored by c-po).
May 29 2024, 5:14 PM
GitHub <noreply@github.com> committed rVYOSONEX0bada0f998c5: Merge pull request #3544 from vyos/mergify/bp/sagitta/pr-3541 (authored by c-po).
May 29 2024, 5:14 PM
mersl added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

just some show commands with test results on my lab

May 29 2024, 5:04 PM · VyOS 1.4 Sagitta (1.4.1)
mersl added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

very cool! I just rebuild a 1.5-rolling and upgraded my lab router and voila - works as expected ;-)

May 29 2024, 4:41 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav triaged T6417: Common storage location for accounts for different VPNs as Wishlist priority.

It probably cannot be a universal solution due to specific per-user options.
For example, for opencoonect, you can add otp if you want on a per-user basis and not do it for other users.

vyos@r4# set vpn openconnect authentication local-users username foo 
Possible completions:
   disable              Disable instance
 > otp                  2FA OTP authentication parameters
   password             Password used for authentication
May 29 2024, 4:19 PM · VyOS Rolling
pavel-altair created T6417: Common storage location for accounts for different VPNs.
May 29 2024, 2:57 PM · VyOS Rolling
syncer triaged T6416: Run smoke tests before merging as Low priority.
May 29 2024, 2:52 PM · GitHub Infrastructure
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX3bfd91713a5c: openvpn: T6374: only check TLS role for s2s if TLS is configured (authored by dmbaturin).
May 29 2024, 1:59 PM
dmbaturin committed rVYOSONEXf4069582273e: openvpn: T6374: only check TLS role for s2s if TLS is configured.
May 29 2024, 1:57 PM
GitHub <noreply@github.com> committed rVYOSONEX5b1539d65d97: Merge pull request #3541 from dmbaturin/T6374-openvpn-s2s-tls-validation-fix (authored by c-po).
May 29 2024, 1:57 PM
Viacheslav renamed T6416: Run smoke tests before merging from Run smole tests before merging to Run smoke tests before merging .
May 29 2024, 1:53 PM · GitHub Infrastructure
syncer created T6416: Run smoke tests before merging .
May 29 2024, 12:17 PM · GitHub Infrastructure
Viacheslav committed rVYOSONEX8c67e6a317cc: T6349: Reuse repo sync.
May 29 2024, 12:00 PM
GitHub <noreply@github.com> committed rVYOSONEX084699fa9910: Merge pull request #3540 from sever-sever/T6415-reuse (authored by dmbaturin).
May 29 2024, 12:00 PM
fernando added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

we've added this ability to configure the topology on isis :

May 29 2024, 11:16 AM · VyOS 1.4 Sagitta (1.4.1)
fernando changed the subtype of T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr from "Bug" to "Feature Request".
May 29 2024, 11:14 AM · VyOS 1.4 Sagitta (1.4.1)
fernando changed the status of T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr from Open to Needs testing.
May 29 2024, 11:14 AM · VyOS 1.4 Sagitta (1.4.1)
fernando added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

agree ,it's more a feature than a bug : PR https://github.com/vyos/vyos-1x/pull/3537

May 29 2024, 11:11 AM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav claimed T6415: Repo sync.
May 29 2024, 10:29 AM · GitHub Infrastructure
Viacheslav created T6415: Repo sync.
May 29 2024, 10:29 AM · GitHub Infrastructure
HollyGurza claimed T5735: Add CLI and configuration scripts for stunnel.
May 29 2024, 8:33 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
GitHub <noreply@github.com> committed rVYOSONEX48a5ae344dcb: Merge pull request #3538 from vyos/mergify/bp/sagitta/pr-3537 (authored by dmbaturin).
May 29 2024, 8:24 AM
giuavo added a comment to T6253: no-default-route not being honoured.

Are you sure your DHCP server honors the no-default-route option?
I may be wrong, but I think the no-default-route just sets an option in the DHCP request, asking the DHCP server to not send back the default route.
I have the same issue with my ISP, and they told me they will always send a default route via DHCP.
I have solved the issue using DHCP hooks.

May 29 2024, 8:24 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS 1.4 Sagitta (1.4.3), VyOS Rolling
Viacheslav closed T6411: CGNAT does not rely on seq number, a subtask of T5169: Add CGNAT Carrier-Grade NAT based on nftables, as Resolved.
May 29 2024, 8:23 AM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav closed T6411: CGNAT does not rely on seq number as Resolved.
May 29 2024, 8:23 AM · VyOS 1.5 Circinus
Viacheslav committed rVYOSONEX55e02bef4f3a: T6411: CGNAT fix sequences for external address ranges.
May 29 2024, 8:20 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX650989533b0d: ISIS: T6332: Fix isis not working only ipv6 (authored by fett0 <fernando.gmaidana@gmail.com>).
May 29 2024, 8:20 AM
GitHub <noreply@github.com> committed rVYOSONEXdb4c7f15b16b: Merge pull request #3534 from sever-sever/T6411 (authored by dmbaturin).
May 29 2024, 8:20 AM
fett0 <fernando.gmaidana@gmail.com> committed rVYOSONEX03fd368ed263: ISIS: T6332: Fix isis not working only ipv6.
May 29 2024, 8:18 AM
GitHub <noreply@github.com> committed rVYOSONEXdf6ae88f6e36: Merge pull request #3537 from fett0/T6332 (authored by c-po).
May 29 2024, 8:18 AM
Viacheslav added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

More a feature request than a bug

May 29 2024, 8:14 AM · VyOS 1.4 Sagitta (1.4.1)
Unknown Object (User) added a comment to T6181: A feature for checking popular ports..

We will bind the code to a new command in operating mode (for example show ports). This will allow you to use the nmap command from operating mode. Just a convenient feature.

May 29 2024, 5:43 AM
fernando added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

the problem here is that MT options is enable by default when the RIB has ipv4, if not not-MT is enable by default on IPv4 .So, you need to add additional topologies (ipv6-unicast , ipv6-multicast,etc)

May 29 2024, 12:56 AM · VyOS 1.4 Sagitta (1.4.1)

May 28 2024

GitHub <noreply@github.com> committed rVYOSONEXfbf12867c4ba: Merge pull request #3536 from vyos/mergify/bp/sagitta/pr-3528 (authored by c-po).
May 28 2024, 8:57 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXa3763a233d13: openvpn: T6374: ensure that TLS role is configured for site-to-site with TLS (authored by dmbaturin).
May 28 2024, 7:56 PM
dmbaturin committed rVYOSONEX380e998b1034: openvpn: T6374: ensure that TLS role is configured for site-to-site with TLS.
May 28 2024, 7:55 PM
GitHub <noreply@github.com> committed rVYOSONEX7ad2235761aa: Merge pull request #3528 from dmbaturin/T6374-openvpn-s2s-tls-validation (authored by c-po).
May 28 2024, 7:55 PM
GitHub <noreply@github.com> committed rVYOSONEX9d0a453c923f: Merge pull request #3535 from vyos/mergify/bp/sagitta/pr-3530 (authored by c-po).
May 28 2024, 7:51 PM
Vijayakumar closed T6410: separate subset of workflows for documentation, a subtask of T6309: Check code quality with CodeQL, as Resolved.
May 28 2024, 7:14 PM · GitHub Infrastructure
Vijayakumar closed T6410: separate subset of workflows for documentation as Resolved.
May 28 2024, 7:14 PM · GitHub Infrastructure
natali-rs1985 committed rVYOSONEX24d259e57b52: op mode: T6389: Check architecture and flavor compatibility on upgrade attempts.
May 28 2024, 7:02 PM
GitHub <noreply@github.com> committed rVYOSONEX6c295b860e3e: Merge pull request #3533 from natali-rs1985/T6389-current (authored by jestabro).
May 28 2024, 7:02 PM
khramshinr <khramshinr@gmail.com> committed rVYOSONEXcbb61faed494: T5786: Add set/show system image to /image endpoint.
May 28 2024, 6:17 PM
GitHub <noreply@github.com> committed rVYOSONEX4b05357eb847: Merge pull request #3529 from HollyGurza/T5786 (authored by c-po).
May 28 2024, 6:17 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXd180595aff41: T6406: rename cpus to cpu (authored by nvollmar).
May 28 2024, 6:16 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX8007b58f1e0e: T6406: add container cpu limit option (authored by nvollmar).
May 28 2024, 6:16 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX10df4ad8a3d7: T6406: check for required kernel config (authored by nvollmar).
May 28 2024, 6:16 PM
nvollmar committed rVYOSONEX5146cb23fff5: T6406: check for required kernel config.
May 28 2024, 6:16 PM
nvollmar committed rVYOSONEX81dea053e717: T6406: add container cpu limit option.
May 28 2024, 6:16 PM
nvollmar committed rVYOSONEX74910564f82e: T6406: rename cpus to cpu.
May 28 2024, 6:16 PM
GitHub <noreply@github.com> committed rVYOSONEXf04776073d1e: container: T6406: add CLI option for cpu-quota (authored by c-po).
May 28 2024, 6:16 PM
dmbaturin created T6414: Rename the "iso" flavor to "generic".
May 28 2024, 4:43 PM · VyOS Rolling
fernando claimed T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.
May 28 2024, 3:55 PM · VyOS 1.4 Sagitta (1.4.1)
jestabro added a comment to T5786: Add set/show system image to /image endpoint.

Fix link:
https://github.com/vyos/vyos-1x/pull/3529

May 28 2024, 3:03 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T6411: CGNAT does not rely on seq number, a subtask of T5169: Add CGNAT Carrier-Grade NAT based on nftables, from Open to In progress.
May 28 2024, 1:15 PM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav changed the status of T6411: CGNAT does not rely on seq number from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/3534

May 28 2024, 1:15 PM · VyOS 1.5 Circinus
jestabro closed T6404: Include constraintGroup element in reference tree as Resolved.
May 28 2024, 12:39 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro moved T6404: Include constraintGroup element in reference tree from Open to Finished on the VyOS 1.5 Circinus board.
May 28 2024, 12:38 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
SrividyaA claimed T6379: "generate openvpn" uses "comp-lzo no", which leads to problems on Android-Clients.
May 28 2024, 11:27 AM · VyOS 1.4 Sagitta (1.4.1)
a.hajiyev created T6413: BGP conditional route advertisement does not work as expected.
May 28 2024, 10:49 AM · VyOS Rolling, Bugs
ssasso added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

@Viacheslav here you go:

May 28 2024, 10:49 AM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

Can you provide set of commands instead? Bug-report-guidelines

May 28 2024, 10:42 AM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav added a subtask for T5169: Add CGNAT Carrier-Grade NAT based on nftables: T6412: CGNAT allocation calculation may sometimes be incorrect.
May 28 2024, 10:40 AM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav added a parent task for T6412: CGNAT allocation calculation may sometimes be incorrect: T5169: Add CGNAT Carrier-Grade NAT based on nftables.
May 28 2024, 10:40 AM · VyOS 1.5 Circinus
Viacheslav triaged T6412: CGNAT allocation calculation may sometimes be incorrect as Normal priority.
May 28 2024, 10:39 AM · VyOS 1.5 Circinus
Viacheslav created T6412: CGNAT allocation calculation may sometimes be incorrect.
May 28 2024, 10:39 AM · VyOS 1.5 Circinus
mersl added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

@ssasso - thanks for this good catch! Coming from a Junos world, I was a bit surprised at the first place when I enabled ISIS and found no ipv6 isis routes and no multi-topology config option (and yes - we have multi-topology in place)

May 28 2024, 10:09 AM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav renamed T6411: CGNAT does not rely on seq number from CGNAt does not rely on seq number to CGNAT does not rely on seq number.
May 28 2024, 9:32 AM · VyOS 1.5 Circinus
Viacheslav added a subtask for T5169: Add CGNAT Carrier-Grade NAT based on nftables: T6411: CGNAT does not rely on seq number.
May 28 2024, 9:32 AM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav added a parent task for T6411: CGNAT does not rely on seq number: T5169: Add CGNAT Carrier-Grade NAT based on nftables.
May 28 2024, 9:32 AM · VyOS 1.5 Circinus
Viacheslav triaged T6411: CGNAT does not rely on seq number as Low priority.
May 28 2024, 9:30 AM · VyOS 1.5 Circinus
Viacheslav created T6411: CGNAT does not rely on seq number.
May 28 2024, 9:30 AM · VyOS 1.5 Circinus