Page MenuHomeVyOS Platform
Feed All Stories

Jun 12 2024

Viacheslav closed T6442: CGNAT add address allocation logs to syslog during commit as Resolved.
Jun 12 2024, 6:12 AM · VyOS 1.5 Circinus
gmurphy42 added a comment to T3936: [Feature] - DHCP Option 82 Support.

Happened across this one while trying to find support for defining client classes in Kea in order to pass different PXE boot files depending on client architecture. The following has an example of how this is achieved in kea.

Jun 12 2024, 5:44 AM · VyOS 1.5 Circinus

Jun 11 2024

c-po added a comment to T6407: Generate ipsec profile error.

Can you please retest with the latest ISO as additional fixes got added to the code.

Jun 11 2024, 10:10 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
leleobhz added a comment to T6474: docker: Improve docker support for other platforms.

Just to notice: This task focuses on container part of multi arch support. I can take a look at multiarch pieces outside docker support, but it will demand a deeper knowledge of vyos build system and the vyos goal on multiarch (Or for now, arm) support.

Jun 11 2024, 9:37 PM · VyOS 1.5 Circinus
part1cleth1ef added a comment to T3106: 802.11ax support.

Hey, is this feature currently being worked on? If not then I wouldn't mind working on support for it (I've also created a basic wpa2-enterprise option for client mode)

Jun 11 2024, 9:29 PM · VyOS 1.5 Circinus
leleobhz added a subtask for T3965: arm: Extend configure scripts to allow for arm builds: T6474: docker: Improve docker support for other platforms.
Jun 11 2024, 8:57 PM · VyOS 1.4 Sagitta
leleobhz added a parent task for T6474: docker: Improve docker support for other platforms: T3965: arm: Extend configure scripts to allow for arm builds.
Jun 11 2024, 8:57 PM · VyOS 1.5 Circinus
leleobhz created T6474: docker: Improve docker support for other platforms.
Jun 11 2024, 8:56 PM · VyOS 1.5 Circinus
c-po closed T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs as Resolved.
Jun 11 2024, 3:25 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po moved T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 11 2024, 3:25 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po moved T6473: bgp: missing completion helper for peer-groups inside a VRF from Need Triage to In Progress on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 11 2024, 3:25 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po moved T6473: bgp: missing completion helper for peer-groups inside a VRF from Need Triage to Finished on the VyOS 1.5 Circinus board.
Jun 11 2024, 3:24 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po added a comment to T6473: bgp: missing completion helper for peer-groups inside a VRF.

https://github.com/vyos/vyos-1x/pull/3638

Jun 11 2024, 3:24 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po updated the task description for T6473: bgp: missing completion helper for peer-groups inside a VRF.
Jun 11 2024, 3:08 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
dmbaturin closed T6383: Incorrect completion for rollback-soft as Resolved.
Jun 11 2024, 2:35 PM · VyOS 1.4 Sagitta (1.4.0-GA)
talmakion added a comment to T6157: Can not create two GRE tunnels to the same DST but from different SRC addresses.

@a.apostoliuk this one should be resolved in the current rolling release, if you're able to check it out?

Jun 11 2024, 2:07 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
jestabro closed T6471: Add an optimized get_config_dict for op-mode as Resolved.
Jun 11 2024, 1:32 PM · VyOS 1.5 Circinus
c-po claimed T6473: bgp: missing completion helper for peer-groups inside a VRF.
Jun 11 2024, 12:06 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po created T6473: bgp: missing completion helper for peer-groups inside a VRF.
Jun 11 2024, 12:06 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
Viacheslav triaged T6472: Implement Atomic Write Operations for Config Files as Normal priority.
Jun 11 2024, 11:33 AM
talmakion added a comment to T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.

I have https://github.com/vyos/vyos-1x/pull/3616 and https://github.com/vyos/vyos-1x/pull/3637 as works in progress.

Jun 11 2024, 11:32 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
robertoberto created T6472: Implement Atomic Write Operations for Config Files.
Jun 11 2024, 10:32 AM
Vijayakumar renamed T6469: Remove J2Lint workflow from vyos-1x from Renove J2Lint workflow from vyos-1x to Remove J2Lint workflow from vyos-1x.
Jun 11 2024, 7:13 AM · GitHub Infrastructure
Viacheslav triaged T6470: Deleting a Firewall addrerss-group object that is tied to a NAT rule or other resources doesn't error out, it hangs. as Normal priority.

@lclements0 Add a simple set of commands to reproduce.

Jun 11 2024, 7:03 AM · Restricted Project
jestabro added a comment to T6471: Add an optimized get_config_dict for op-mode.

PR:
https://github.com/vyos/vyos-1x/pull/3628

Jun 11 2024, 3:45 AM · VyOS 1.5 Circinus
jestabro created T6471: Add an optimized get_config_dict for op-mode.
Jun 11 2024, 2:32 AM · VyOS 1.5 Circinus

Jun 10 2024

lclements0 created T6470: Deleting a Firewall addrerss-group object that is tied to a NAT rule or other resources doesn't error out, it hangs..
Jun 10 2024, 11:29 PM · Restricted Project
syncer triaged T6469: Remove J2Lint workflow from vyos-1x as Normal priority.
Jun 10 2024, 9:26 PM · GitHub Infrastructure
artooro added a comment to T6458: Extend support for Lanner appliances with serial LCDs.

I can probably help with this in August when I'll have access to one of these appliances again.

Jun 10 2024, 7:17 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Vijayakumar changed the status of T6469: Remove J2Lint workflow from vyos-1x from Open to In progress.
Jun 10 2024, 6:39 PM · GitHub Infrastructure
Vijayakumar changed the status of T6469: Remove J2Lint workflow from vyos-1x, a subtask of T6309: Check code quality with CodeQL, from Open to In progress.
Jun 10 2024, 6:39 PM · GitHub Infrastructure
L0crian added a comment to T465: ZeroTier integration.

Approaching implementation of ZeroTier from a different angle in:
https://vyos.dev/T6455

Jun 10 2024, 5:59 PM · Rejected
Vijayakumar claimed T6469: Remove J2Lint workflow from vyos-1x.
Jun 10 2024, 5:46 PM · GitHub Infrastructure
Vijayakumar created T6469: Remove J2Lint workflow from vyos-1x.
Jun 10 2024, 5:46 PM · GitHub Infrastructure
Vijayakumar closed T6467: Add sagitta for vyos-1x workflows trigger branch list, a subtask of T6309: Check code quality with CodeQL, as Resolved.
Jun 10 2024, 5:45 PM · GitHub Infrastructure
Vijayakumar closed T6467: Add sagitta for vyos-1x workflows trigger branch list as Resolved.
Jun 10 2024, 5:45 PM · GitHub Infrastructure
L0crian added a comment to T5931: Add option to append route-target when adding additional imports.

Added PR: https://github.com/vyos/vyos-1x/pull/3623

Jun 10 2024, 3:57 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Giggum updated the task description for T5633: op-cmd: Interrupting the "tech-support report" command generates error.
Jun 10 2024, 3:46 PM · Restricted Project, Restricted Project, VyOS 1.5 Circinus
Giggum updated the task description for T5633: op-cmd: Interrupting the "tech-support report" command generates error.
Jun 10 2024, 3:44 PM · Restricted Project, Restricted Project, VyOS 1.5 Circinus
L0crian claimed T5931: Add option to append route-target when adding additional imports.
Jun 10 2024, 3:32 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
c-po closed T6401: Attempts to delete vlan-to-vni option causes an unhandled exception as Resolved.
Jun 10 2024, 12:20 PM · VyOS 1.4 Sagitta (1.4.1)
c-po closed T6463: reverse-proxy: service not reloaded when updating SSL certificate via PKI as Resolved.
Jun 10 2024, 12:20 PM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs from Need Triage to Finished on the VyOS 1.5 Circinus board.
Jun 10 2024, 12:20 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po moved T6463: reverse-proxy: service not reloaded when updating SSL certificate via PKI from Need Triage to Finished on the VyOS 1.5 Circinus board.
Jun 10 2024, 12:19 PM · VyOS 1.4 Sagitta (1.4.1)
c-po closed T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate as Resolved.
Jun 10 2024, 12:19 PM · VyOS 1.4 Sagitta (1.4.1)
c-po closed T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate, a subtask of T6407: Generate ipsec profile error, as Resolved.
Jun 10 2024, 12:19 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po closed T6454: Explicitly set the default reverse proxy mode to HTTP as Resolved.
Jun 10 2024, 12:19 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po closed T6423: Require command definition nodes that have an owner to also have a priority as Resolved.
Jun 10 2024, 12:19 PM · VyOS 1.4 Sagitta (1.4.1)
c-po closed T6464: sstpc: interface not restarted when updating SSL certificate via PKI as Resolved.
Jun 10 2024, 12:19 PM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs from Need Triage to In Progress on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 10 2024, 12:18 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po moved T6463: reverse-proxy: service not reloaded when updating SSL certificate via PKI from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 10 2024, 12:18 PM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 10 2024, 12:18 PM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6454: Explicitly set the default reverse proxy mode to HTTP from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 10 2024, 12:18 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po moved T6423: Require command definition nodes that have an owner to also have a priority from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 10 2024, 12:18 PM · VyOS 1.4 Sagitta (1.4.1)
c-po closed T6453: GRUB variables with `=` in a value are parsed improperly as Resolved.
Jun 10 2024, 12:18 PM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6401: Attempts to delete vlan-to-vni option causes an unhandled exception from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 10 2024, 12:18 PM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6453: GRUB variables with `=` in a value are parsed improperly from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 10 2024, 12:18 PM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6464: sstpc: interface not restarted when updating SSL certificate via PKI from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 10 2024, 12:18 PM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6464: sstpc: interface not restarted when updating SSL certificate via PKI from Need Triage to Finished on the VyOS 1.5 Circinus board.
Jun 10 2024, 12:17 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav changed the status of T6442: CGNAT add address allocation logs to syslog during commit, a subtask of T5169: Add CGNAT Carrier-Grade NAT based on nftables, from Open to In progress.
Jun 10 2024, 11:29 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav changed the status of T6442: CGNAT add address allocation logs to syslog during commit from Open to In progress.
Jun 10 2024, 11:29 AM · VyOS 1.5 Circinus
Viacheslav added a comment to T6442: CGNAT add address allocation logs to syslog during commit.

PR https://github.com/vyos/vyos-1x/pull/3621

set nat cgnat log-allocation
set nat cgnat pool external ext-01 external-port-range '1024-65535'
set nat cgnat pool external ext-01 per-user-limit port '2000'
set nat cgnat pool external ext-01 range 192.168.122.222/32
set nat cgnat pool internal int-01 range '100.64.0.0/28'
set nat cgnat rule 10 source pool 'int-01'
set nat cgnat rule 10 translation pool 'ext-01'

check logs:

Jun 10 14:10:02 r4 sudo[9057]:     vyos : TTY=pts/0 ; PWD=/home/vyos ; USER=root ; COMMAND=/usr/bin/sh -c ' /usr/libexec/vyos/conf_mode/nat_cgnat.py'
Jun 10 14:10:02 r4 sudo[9057]: pam_unix(sudo:session): session opened for user root(uid=0) by vyos(uid=1003)
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.0, external host: 192.168.122.222, Port range: 1024-3023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.1, external host: 192.168.122.222, Port range: 3024-5023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.2, external host: 192.168.122.222, Port range: 5024-7023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.3, external host: 192.168.122.222, Port range: 7024-9023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.4, external host: 192.168.122.222, Port range: 9024-11023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.5, external host: 192.168.122.222, Port range: 11024-13023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.6, external host: 192.168.122.222, Port range: 13024-15023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.7, external host: 192.168.122.222, Port range: 15024-17023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.8, external host: 192.168.122.222, Port range: 17024-19023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.9, external host: 192.168.122.222, Port range: 19024-21023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.10, external host: 192.168.122.222, Port range: 21024-23023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.11, external host: 192.168.122.222, Port range: 23024-25023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.12, external host: 192.168.122.222, Port range: 25024-27023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.13, external host: 192.168.122.222, Port range: 27024-29023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.14, external host: 192.168.122.222, Port range: 29024-31023
Jun 10 14:10:03 r4 cgnat[9059]: Internal host: 100.64.0.15, external host: 192.168.122.222, Port range: 31024-33023
Jun 10 14:10:03 r4 sudo[9057]: pam_unix(sudo:session): session closed for user root
Jun 10 2024, 11:21 AM · VyOS 1.5 Circinus
Viacheslav triaged T6468: Error setting Receive Packet Steering as Normal priority.
Jun 10 2024, 9:13 AM · Restricted Project, VyOS 1.5 Circinus
Charlie-Root created T6468: Error setting Receive Packet Steering.
Jun 10 2024, 8:33 AM · Restricted Project, VyOS 1.5 Circinus
dmbaturin triaged T6455: Add Support for ZeroTier as Wishlist priority.
Jun 10 2024, 7:57 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0)
dmbaturin triaged T6467: Add sagitta for vyos-1x workflows trigger branch list as Normal priority.
Jun 10 2024, 7:56 AM · GitHub Infrastructure
dmbaturin triaged T6463: reverse-proxy: service not reloaded when updating SSL certificate via PKI as High priority.
Jun 10 2024, 7:55 AM · VyOS 1.4 Sagitta (1.4.1)
dmbaturin triaged T6464: sstpc: interface not restarted when updating SSL certificate via PKI as High priority.
Jun 10 2024, 7:55 AM · VyOS 1.4 Sagitta (1.4.1)
dmbaturin triaged T6461: Create a workflow, that checks existence of codeowners file in repo, if not create one. as Normal priority.
Jun 10 2024, 7:54 AM · Restricted Project, GitHub Infrastructure
dmbaturin triaged T6457: Update strip-private function to improve op command output for IPs as Low priority.
Jun 10 2024, 7:53 AM · Restricted Project, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0)
Viacheslav added a comment to T5169: Add CGNAT Carrier-Grade NAT based on nftables.

Accel-ppp does not work with VPP

Jun 10 2024, 7:48 AM · Restricted Project, VyOS 1.5 Circinus
pavel-altair added a comment to T6407: Generate ipsec profile error.
vyos@vyos:~$ dpkg -l | grep vyos-1x
ii  vyos-1x                              1.5dev0-1669-g77cb661d8          amd64        VyOS configuration scripts and data
ii  vyos-1x-vmware                       1.5dev0-1669-g77cb661d8          amd64        VyOS configuration scripts and data for VMware
vyos@vyos:~$
Jun 10 2024, 6:35 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
drw_08 updated subscribers of T6405: Add disk_setup and mounts in vyos cloud-init config under cloud_init_modules .
Jun 10 2024, 5:57 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
Vijayakumar added a comment to T6467: Add sagitta for vyos-1x workflows trigger branch list.

PR https://github.com/vyos/vyos-1x/pull/3615/files

Jun 10 2024, 5:14 AM · GitHub Infrastructure
Vijayakumar changed the status of T6467: Add sagitta for vyos-1x workflows trigger branch list, a subtask of T6309: Check code quality with CodeQL, from Open to In progress.
Jun 10 2024, 5:05 AM · GitHub Infrastructure
Vijayakumar changed the status of T6467: Add sagitta for vyos-1x workflows trigger branch list from Open to In progress.
Jun 10 2024, 5:05 AM · GitHub Infrastructure
Vijayakumar created T6467: Add sagitta for vyos-1x workflows trigger branch list.
Jun 10 2024, 5:05 AM · GitHub Infrastructure
Vijayakumar closed T6466: Add PR checks as mandatory for vyos-1x, a subtask of T6309: Check code quality with CodeQL, as Resolved.
Jun 10 2024, 5:03 AM · GitHub Infrastructure
Vijayakumar closed T6466: Add PR checks as mandatory for vyos-1x as Resolved.
Jun 10 2024, 5:03 AM · GitHub Infrastructure
Vijayakumar created T6466: Add PR checks as mandatory for vyos-1x.
Jun 10 2024, 5:03 AM · GitHub Infrastructure
Giggum created T6465: op-cmd: tech-support report reporting invalid command for Show System Image Storage/Version.
Jun 10 2024, 4:32 AM · Restricted Project, VyOS 1.5 Circinus
Giggum added a comment to T5633: op-cmd: Interrupting the "tech-support report" command generates error.

Updated task description to denote two issues (Bug 1 and Bug 2) with show tech-support report.

Jun 10 2024, 4:24 AM · Restricted Project, Restricted Project, VyOS 1.5 Circinus
Giggum updated the task description for T5633: op-cmd: Interrupting the "tech-support report" command generates error.
Jun 10 2024, 4:23 AM · Restricted Project, Restricted Project, VyOS 1.5 Circinus

Jun 9 2024

marekm added a comment to T6450: Use http instead of https for rolling apt repo access.

@blueish - thanks! Yes, apt-mirror works now - but will it continue to work with the new storage too?
BTW, good to see "deb-src" - but only a few source packages are in there. I think it would be great to have corresponding source for all these *.deb packages in the Debian source package format, then anyone who wants to contribute will be able to use dpkg-buildpackage to rebuild them.

Jun 9 2024, 11:32 PM
c-po added a comment to T6407: Generate ipsec profile error.

Please share the output of dpkg -l | grep vyos-1x

Jun 9 2024, 9:05 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a comment to T6464: sstpc: interface not restarted when updating SSL certificate via PKI.

https://github.com/vyos/vyos-1x/pull/3613

Jun 9 2024, 7:00 PM · VyOS 1.4 Sagitta (1.4.1)
c-po changed the status of T6464: sstpc: interface not restarted when updating SSL certificate via PKI from Open to In progress.
Jun 9 2024, 6:49 PM · VyOS 1.4 Sagitta (1.4.1)
c-po created T6464: sstpc: interface not restarted when updating SSL certificate via PKI.
Jun 9 2024, 6:48 PM · VyOS 1.4 Sagitta (1.4.1)
c-po updated the task description for T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs.
Jun 9 2024, 6:14 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po added a comment to T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs.

https://github.com/vyos/vyos-1x/pull/3611

Jun 9 2024, 6:13 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
pavel-altair added a comment to T6407: Generate ipsec profile error.
vyos@vyos# show vpn ipsec | commands 
set esp-group vpn lifetime '3600'
set esp-group vpn pfs 'enable'
set esp-group vpn proposal 10 encryption 'aes128gcm128'
set esp-group vpn proposal 10 hash 'sha256'
set ike-group vpn key-exchange 'ikev2'
set ike-group vpn lifetime '7200'
set ike-group vpn proposal 10 dh-group '14'
set ike-group vpn proposal 10 encryption 'aes128gcm128'
set ike-group vpn proposal 10 hash 'sha256'
set interface 'eth0'
set options virtual-ip
set remote-access connection support authentication client-mode 'eap-mschapv2'
set remote-access connection support authentication local-id 'ipsec.somedomain'
set remote-access connection support authentication local-users username test password 'test'
set remote-access connection support authentication server-mode 'x509'
set remote-access connection support authentication x509 ca-certificate 'isrgrootx1'
set remote-access connection support authentication x509 ca-certificate 'lets-encrypt-r3'
set remote-access connection support authentication x509 certificate 'vpn2'
set remote-access connection support description 'support remote access'
set remote-access connection support esp-group 'vpn'
set remote-access connection support ike-group 'vpn'
set remote-access connection support local-address 'ip on eth0'
set remote-access connection support pool 'support'
set remote-access pool support name-server '1.1.1.1'
set remote-access pool support name-server '9.9.9.9'
set remote-access pool support prefix '192.168.120.64/27'
[edit]
vyos@vyos#
Jun 9 2024, 6:12 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a comment to T6407: Generate ipsec profile error.

Please share your full ipsec configuration

Jun 9 2024, 6:02 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po claimed T6463: reverse-proxy: service not reloaded when updating SSL certificate via PKI.
Jun 9 2024, 6:01 PM · VyOS 1.4 Sagitta (1.4.1)
c-po created T6463: reverse-proxy: service not reloaded when updating SSL certificate via PKI.
Jun 9 2024, 6:01 PM · VyOS 1.4 Sagitta (1.4.1)
pavel-altair added a comment to T6407: Generate ipsec profile error.
vyos@vyos:~$ generate ipsec profile windows-remote-access support remote ipsec.somedomain 
Traceback (most recent call last):
  File "/usr/libexec/vyos/op_mode/ikev2_profile_generator.py", line 154, in <module>
    cert = load_certificate(pki['certificate'][cert_name]['certificate'])
                            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^
KeyError: 'certificate'
vyos@vyos:~$ show ver
Version:          VyOS 1.5-rolling-202406060020
Release train:    current
Release flavor:   generic
Jun 9 2024, 6:01 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po closed T6281: Wireguard does not pass traffic if VRFs are used as Invalid.
Jun 9 2024, 5:43 PM · VyOS 1.5 Circinus
c-po added a comment to T6281: Wireguard does not pass traffic if VRFs are used.

Reporter action missing - running this setup in production so does not feel like a bug.

Jun 9 2024, 5:43 PM · VyOS 1.5 Circinus
c-po changed the status of T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs from Open to In progress.
Jun 9 2024, 5:29 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po created T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs.
Jun 9 2024, 5:29 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po moved T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate from Need Triage to In Progress on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 9 2024, 12:47 PM · VyOS 1.4 Sagitta (1.4.1)