Page MenuHomeVyOS Platform
Feed All Stories

Jul 12 2024

SrividyaA added a comment to T6545: OpenVPN: Remove "none" option for ncp-cipher encryption.

@Viacheslav, Thank you for the hint. After further analysis, these are the findings from the tests done in the lab running 1.4.0 version on both sides with server/client setup.

Jul 12 2024, 12:02 PM · Restricted Project, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0)
Viacheslav added a comment to T4945: Telegraf- allow the plugin to run custom-script.

@fernando Any idea for CLI?

Jul 12 2024, 7:03 AM · VyOS 1.5 Circinus
vyosbot placed T2554: Failsafe reboot timer up for grabs.
Jul 12 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot placed T3224: Implement 'feasible' RPF up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T200: Automated config deployment from a removable drive at installation time up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T4190: Add commit comment to the configuration API. up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T3109: Add a disable option to the WAN load balancing rules up for grabs.
Jul 12 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot placed T3973: Feature Request: Multicast ping. Change TTL in Echo-reply from VyOS up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T5390: VyOS public/private Swarm up for grabs.
Jul 12 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot placed T3096: Add a build option to disallow live CD boot up for grabs.
Jul 12 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot placed T4599: run vyos in lxc/lxd up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T4945: Telegraf- allow the plugin to run custom-script up for grabs.
Jul 12 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot placed T5391: Swarm Service up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T5392: Swarm consent PoC up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T5395: Swarm discovery PoC up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T5393: Swarm Service VyOS configuration and tooling up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T5394: Swarm node evolution PoC up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T5396: Swarm Client up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T5657: Add VRF support for zabbix-agent up for grabs.
Jul 12 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot placed T5569: Make it possible to verify the signature of an installed image up for grabs.
Jul 12 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot placed T4406: Make an API endpoint for for anonymous host info retrieval (e.g. by a login page) up for grabs.
Jul 12 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus
vyosbot placed T4914: Rewrite the PKI op mode in the new style up for grabs.
Jul 12 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot placed T5263: Generalization of REST configure endpoint up for grabs.
Jul 12 2024, 6:02 AM · VyOS 1.4 Sagitta

Jul 11 2024

jestabro added a comment to T6559: vyos-configd should return commit error on config dependency error.

The solution sketched above will be handled in subtask T6569; in this task we will revert to using only the local redundancy removal in order to provide per-script error reporting.

Jul 11 2024, 5:21 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
jestabro removed a subtask for T5731: Add ability to call config dependencies by canonical function instead of whole script: T6559: vyos-configd should return commit error on config dependency error.
Jul 11 2024, 5:18 PM · VyOS 1.5 Circinus
jestabro removed a parent task for T6559: vyos-configd should return commit error on config dependency error: T5731: Add ability to call config dependencies by canonical function instead of whole script.
Jul 11 2024, 5:18 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
jestabro added a subtask for T5731: Add ability to call config dependencies by canonical function instead of whole script: T6569: Cache results of config script stages under configd, for use by configdep.
Jul 11 2024, 5:18 PM · VyOS 1.5 Circinus
jestabro added a subtask for T6559: vyos-configd should return commit error on config dependency error: T6569: Cache results of config script stages under configd, for use by configdep.
Jul 11 2024, 5:18 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
jestabro added parent tasks for T6569: Cache results of config script stages under configd, for use by configdep: T6559: vyos-configd should return commit error on config dependency error, T5731: Add ability to call config dependencies by canonical function instead of whole script.
Jul 11 2024, 5:18 PM · VyOS 1.5 Circinus
jestabro created T6569: Cache results of config script stages under configd, for use by configdep.
Jul 11 2024, 5:17 PM · VyOS 1.5 Circinus
zsdc added a comment to T6568: SSH keys with the same name replace each other during system initialization by Cloud-init.

PR for current: https://github.com/vyos/vyos-cloud-init/pull/78

Jul 11 2024, 12:07 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
zsdc moved T6568: SSH keys with the same name replace each other during system initialization by Cloud-init from Need Triage to In Progress on the VyOS 1.5 Circinus board.
Jul 11 2024, 11:49 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
zsdc changed the status of T6568: SSH keys with the same name replace each other during system initialization by Cloud-init from Open to In progress.
Jul 11 2024, 11:49 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
zsdc created T6568: SSH keys with the same name replace each other during system initialization by Cloud-init.
Jul 11 2024, 11:48 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
zsdc added a comment to T6544: `vyos_net_name` locking logic is broken.

PR for 1.4: https://github.com/vyos/vyos-1x/pull/3806

Jul 11 2024, 11:38 AM · Restricted Project, VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav triaged T6567: Allow passing attribute 'home' to IP address as Wishlist priority.
Jul 11 2024, 7:08 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T6545: OpenVPN: Remove "none" option for ncp-cipher encryption.

@Viacheslav, For site-to-site or server/client mode, when used cipher option as none then also issue is noticed. When you commit, it gives this warning:

vyos@vyos# set int openvpn vtun1 encryption cipher none
[edit]
vyos@vyos# commit
Warning: "encryption none" was specified!
No encryption will be performed and data is transmitted in plain text over the network!

Logs:

Jul 10 14:51:39 openvpn-vtun1[12357]: Cipher NONE not supported
Jul 11 2024, 7:04 AM · Restricted Project, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0)
vyosbot placed T3909: Add ability to upload scripts via API up for grabs.
Jul 11 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot placed T3957: Attach "origin labels" to IP addresses up for grabs.
Jul 11 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot placed T3955: Allow commit-confirm through http API up for grabs.
Jul 11 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot placed T3721: ARM64: 1.4: Fastnetmon in current is a precompiled custom "blob" and amd64 only. (blocks all arm64 builds) up for grabs.
Jul 11 2024, 6:02 AM · Restricted Project, VyOS 1.5 Circinus

Jul 10 2024

ordex created T6567: Allow passing attribute 'home' to IP address.
Jul 10 2024, 10:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po changed the status of T6566: op-mode: "monitor bandwidth" add support for listing all interfaces concurrently from Open to In progress.
Jul 10 2024, 6:37 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po added a comment to T6566: op-mode: "monitor bandwidth" add support for listing all interfaces concurrently.

https://github.com/vyos/vyos-1x/pull/3805

Jul 10 2024, 6:37 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po created T6566: op-mode: "monitor bandwidth" add support for listing all interfaces concurrently.
Jul 10 2024, 6:35 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
SrividyaA added a comment to T6545: OpenVPN: Remove "none" option for ncp-cipher encryption.

@Viacheslav, For site-to-site or server/client mode, when used cipher option as none then also issue is noticed. When you commit, it gives this warning:

Jul 10 2024, 3:15 PM · Restricted Project, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0)
MPStudyly added a comment to T6563: Expose Jool's stateless NAT46 feature (SIIT-DC).

Any idea for CLI?

Jul 10 2024, 1:02 PM · VyOS 1.5 Circinus

Jul 9 2024

Vijayakumar changed the status of T6565: Use bullfrog action to get the outbound info audit - vyos-1x current from Open to In progress.
Jul 9 2024, 7:21 PM · GitHub Infrastructure
Vijayakumar changed the status of T6565: Use bullfrog action to get the outbound info audit - vyos-1x current, a subtask of T6309: Check code quality with CodeQL, from Open to In progress.
Jul 9 2024, 7:21 PM · GitHub Infrastructure
Vijayakumar created T6565: Use bullfrog action to get the outbound info audit - vyos-1x current.
Jul 9 2024, 7:16 PM · GitHub Infrastructure
Viacheslav triaged T6563: Expose Jool's stateless NAT46 feature (SIIT-DC) as Wishlist priority.

Any idea for CLI?

Jul 9 2024, 7:29 AM · VyOS 1.5 Circinus

Jul 8 2024

Vijayakumar renamed T6564: workflow trigger restrictions as per change type, vyos-1x sagitta, circinus, equuleus from workflow trigger restrictions as per change type, vyos-1x sagitta to workflow trigger restrictions as per change type, vyos-1x sagitta, circinus, equuleus.
Jul 8 2024, 7:27 PM · GitHub Infrastructure
Vijayakumar claimed T6564: workflow trigger restrictions as per change type, vyos-1x sagitta, circinus, equuleus.
Jul 8 2024, 7:00 PM · GitHub Infrastructure
Vijayakumar created T6564: workflow trigger restrictions as per change type, vyos-1x sagitta, circinus, equuleus.
Jul 8 2024, 7:00 PM · GitHub Infrastructure
dmbaturin removed a project from T1467: Loopback interface naming and dummy devices: VyOS 1.5 Circinus.
Jul 8 2024, 2:55 PM
dmbaturin closed T1467: Loopback interface naming and dummy devices as Wontfix.

Since loopback and dummy are fundamentally different in Linux, trying to pretend they are not would be misleading rather than helpful. Unless anything changes in the kernel, we should keep things as is.

Jul 8 2024, 2:54 PM
MPStudyly created T6563: Expose Jool's stateless NAT46 feature (SIIT-DC).
Jul 8 2024, 10:24 AM · VyOS 1.5 Circinus
Viacheslav triaged T6558: VRF removals are not validated against VRF usage as Wishlist priority.
Jul 8 2024, 8:12 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav triaged T6561: show ntp is not vrf aware as Normal priority.
Jul 8 2024, 7:32 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
Viacheslav changed the subtype of T6562: config-sync is not vrf aware from "Task" to "Feature Request".
Jul 8 2024, 7:32 AM · VyOS 1.5 Circinus
Giggum added a comment to T6371: Show nat source rules shows unexpected dictionary.

PR: https://github.com/vyos/vyos-1x/pull/3778

Jul 8 2024, 12:53 AM · Restricted Project, VyOS 1.5 Circinus
jestabro added a subtask for T5731: Add ability to call config dependencies by canonical function instead of whole script: T6559: vyos-configd should return commit error on config dependency error.
Jul 8 2024, 12:38 AM · VyOS 1.5 Circinus
jestabro added a parent task for T6559: vyos-configd should return commit error on config dependency error: T5731: Add ability to call config dependencies by canonical function instead of whole script.
Jul 8 2024, 12:38 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
jestabro added a comment to T6559: vyos-configd should return commit error on config dependency error.

Recovering gracefully and logging an error is a simple fix, and will be committed in the interim while the larger issue is addressed: namely, when running under vyos-configd, a ConfigError in a called dependency script should elicit a commit error in the originating config session. Here, however, we confront again the constraints of operating under the legacy commit algorithm. To address the matter, we will implement a partial solution to T5731 so as to catch verification errors in the (first instance of) sequential processing of the priority queue and cache the data for final processing of the activation stages (generate/apply); errors in the latter stages, as less common, will be logged. The sketch provided summarizes a design that balances the needs of early and correct (verify stage) error reporting with removing redundancy overhead when running under configd.

Jul 8 2024, 12:38 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus

Jul 7 2024

danhusan changed Version from - to 1.4.0 on T6562: config-sync is not vrf aware.
Jul 7 2024, 7:59 PM · VyOS 1.5 Circinus
danhusan created T6562: config-sync is not vrf aware.
Jul 7 2024, 7:57 PM · VyOS 1.5 Circinus
danhusan created T6561: show ntp is not vrf aware.
Jul 7 2024, 7:51 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
Vijayakumar closed T6560: workflow trigger restrictions as per change type, vyos-1x current, a subtask of T6309: Check code quality with CodeQL, as Resolved.
Jul 7 2024, 7:37 PM · GitHub Infrastructure
Vijayakumar closed T6560: workflow trigger restrictions as per change type, vyos-1x current as Resolved.
Jul 7 2024, 7:37 PM · GitHub Infrastructure
Vijayakumar renamed T6560: workflow trigger restrictions as per change type, vyos-1x current from skip workflows as per change type to workflow trigger restrictions as per change type, vyos-1x current.
Jul 7 2024, 7:37 PM · GitHub Infrastructure
Vijayakumar closed T6556: wokrflow trigger branches cleanup, a subtask of T6309: Check code quality with CodeQL, as Resolved.
Jul 7 2024, 7:36 PM · GitHub Infrastructure
Vijayakumar closed T6556: wokrflow trigger branches cleanup as Resolved.
Jul 7 2024, 7:36 PM · GitHub Infrastructure
Vijayakumar closed T6546: add permissions for unused import workflow callers, a subtask of T6309: Check code quality with CodeQL, as Resolved.
Jul 7 2024, 7:30 PM · GitHub Infrastructure
Vijayakumar closed T6546: add permissions for unused import workflow callers as Resolved.
Jul 7 2024, 7:30 PM · GitHub Infrastructure
Vijayakumar closed T6540: add reusable workflows for vyatta-bash, a subtask of T6309: Check code quality with CodeQL, as Resolved.
Jul 7 2024, 7:28 PM · GitHub Infrastructure
Vijayakumar closed T6540: add reusable workflows for vyatta-bash as Resolved.
Jul 7 2024, 7:28 PM · GitHub Infrastructure
Vijayakumar closed T6509: Add PR comment in case of unused import check fails, a subtask of T6309: Check code quality with CodeQL, as Resolved.
Jul 7 2024, 7:20 PM · GitHub Infrastructure
Vijayakumar closed T6509: Add PR comment in case of unused import check fails as Resolved.
Jul 7 2024, 7:20 PM · GitHub Infrastructure
theotherdave added a watcher for VyOS 1.5 Circinus: theotherdave.
Jul 7 2024, 3:20 PM
lucasec added a comment to T921: Encrypted DNS.

There are two possible places where encrypted DNS support might be desired in a standard setup where VyOS is hosting a local resolver/recursor:

Jul 7 2024, 3:11 AM · VyOS 1.4 Sagitta (1.4.0-GA)

Jul 6 2024

vyosbot closed T6496: Add support for WPA-Enterprise client-mode as Resolved.
Jul 6 2024, 6:02 AM · VyOS 1.5 Circinus
vyosbot closed T6539: Add logging options to load-balancer reverse-proxy as Resolved.
Jul 6 2024, 6:02 AM · VyOS 1.4 Sagitta (1.4.1), Restricted Project, VyOS 1.5 Circinus
stephenmcmahon added a comment to T6211: kea DHCP server not vrf aware.

After spending more time handling VRFs within VyOS the answer from @Viacheslav is best

Jul 6 2024, 2:30 AM · Restricted Project, VyOS 1.5 Circinus

Jul 5 2024

fernando added a comment to T6211: kea DHCP server not vrf aware.

Probably the best way will be moving the config to the vrf section (not implemented)
For example:

set vrf name foo service dhcp-server shared-network-name eth1 option default-router '192.168.1.1'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 lease '300'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 range default start '192.168.1.10'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 range default stop '192.168.1.100'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 subnet-id '1'
Jul 5 2024, 7:42 PM · Restricted Project, VyOS 1.5 Circinus
Vijayakumar created T6560: workflow trigger restrictions as per change type, vyos-1x current.
Jul 5 2024, 7:31 PM · GitHub Infrastructure
jestabro created T6559: vyos-configd should return commit error on config dependency error.
Jul 5 2024, 5:44 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
talmakion created T6558: VRF removals are not validated against VRF usage.
Jul 5 2024, 9:45 AM · Restricted Project, VyOS 1.5 Circinus
stephenmcmahon added a comment to T6211: kea DHCP server not vrf aware.

Probably the best way will be moving the config to the vrf section (not implemented)
For example:

set vrf name foo service dhcp-server shared-network-name eth1 option default-router '192.168.1.1'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 lease '300'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 range default start '192.168.1.10'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 range default stop '192.168.1.100'
set vrf name foo service dhcp-server shared-network-name eth1 subnet 192.168.1.0/24 subnet-id '1'

And start several instances, each with its configuration.

Jul 5 2024, 9:27 AM · Restricted Project, VyOS 1.5 Circinus
c-po moved T6496: Add support for WPA-Enterprise client-mode from Need Triage to Finished on the VyOS 1.5 Circinus board.
Jul 5 2024, 7:00 AM · VyOS 1.5 Circinus
c-po changed the status of T6539: Add logging options to load-balancer reverse-proxy from In progress to Needs testing.
Jul 5 2024, 6:39 AM · VyOS 1.4 Sagitta (1.4.1), Restricted Project, VyOS 1.5 Circinus
c-po moved T6539: Add logging options to load-balancer reverse-proxy from Need Triage to Finished on the VyOS 1.5 Circinus board.
Jul 5 2024, 6:39 AM · VyOS 1.4 Sagitta (1.4.1), Restricted Project, VyOS 1.5 Circinus
c-po added a comment to T6539: Add logging options to load-balancer reverse-proxy.

https://github.com/vyos/vyos-1x/pull/3790

Jul 5 2024, 6:39 AM · VyOS 1.4 Sagitta (1.4.1), Restricted Project, VyOS 1.5 Circinus
c-po closed T6290: SNMPD show logs systemstats_linux: unexpected header length as Resolved.
Jul 5 2024, 6:31 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
c-po moved T6290: SNMPD show logs systemstats_linux: unexpected header length from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jul 5 2024, 6:30 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
c-po closed T4287: wireless: cannot set regulatory domain as Resolved.
Jul 5 2024, 6:30 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
c-po moved T4287: wireless: cannot set regulatory domain from In Progress to Finished on the VyOS 1.5 Circinus board.
Jul 5 2024, 6:30 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
c-po moved T4287: wireless: cannot set regulatory domain from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jul 5 2024, 6:30 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
Viacheslav added a comment to T4600: Closing IPV6CP by client closes PPPoE link completely, even if IPv6 is optional.

Add PR on accell-ppp repo or patch in the vyos-build via PR https://github.com/vyos/vyos-build/tree/current/packages/linux-kernel/patches/accel-ppp
There are no other options for review.

Jul 5 2024, 6:16 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1)
Viacheslav closed T6557: Cloudflare is restricting sagitta-packages.vyos.net as Wontfix.

https://forum.vyos.io/t/lts-release-package-repositories-permanently-closed-for-public-access/

Jul 5 2024, 5:34 AM · VyOS 1.4 Sagitta
miguemely updated the task description for T6557: Cloudflare is restricting sagitta-packages.vyos.net.
Jul 5 2024, 1:19 AM · VyOS 1.4 Sagitta