Page MenuHomeVyOS Platform
Feed All Stories

Oct 6 2019

c-po claimed T1712: DHCP client sometimes doesn't start.
Oct 6 2019, 7:29 AM · VyOS 1.3 Equuleus (1.3.0)

Oct 5 2019

albeu added a comment to T1712: DHCP client sometimes doesn't start.

The following patch fix the issue for me:

Oct 5 2019, 9:55 PM · VyOS 1.3 Equuleus (1.3.0)
albeu created T1712: DHCP client sometimes doesn't start.
Oct 5 2019, 9:52 PM · VyOS 1.3 Equuleus (1.3.0)

Oct 4 2019

c-po updated the task description for T1682: Migrate to new Jenkins Pipeline script.
Oct 4 2019, 1:43 PM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T1682: Migrate to new Jenkins Pipeline script.
Oct 4 2019, 1:43 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T1299: Allow SNMPd to be extended with custom scripts from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.4) board.
Oct 4 2019, 1:42 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po moved T1638: vyos-hostsd not setting system domain name from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.4) board.
Oct 4 2019, 1:42 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po moved T1496: Separate rolling release and LTS kernel builds from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.4) board.
Oct 4 2019, 1:42 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po closed T1496: Separate rolling release and LTS kernel builds as Resolved.
Oct 4 2019, 1:42 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po closed T1496: Separate rolling release and LTS kernel builds, a subtask of T1682: Migrate to new Jenkins Pipeline script, as Resolved.
Oct 4 2019, 1:42 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1496: Separate rolling release and LTS kernel builds.

New Kernel Pipelines are at https://github.com/vyos/vyos-build-kernel

Oct 4 2019, 1:42 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po moved T1708: Update Rolling Release Kernel to 4.19.76 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Oct 4 2019, 1:41 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po closed T1707: DHCP static mapping and exclude address not working as Resolved.
Oct 4 2019, 1:38 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po moved T1707: DHCP static mapping and exclude address not working from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Oct 4 2019, 1:38 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po moved T1707: DHCP static mapping and exclude address not working from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.4) board.
Oct 4 2019, 1:38 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po edited projects for T1707: DHCP static mapping and exclude address not working, added: VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.4); removed VyOS 1.2 Crux.
Oct 4 2019, 1:38 PM · VyOS 1.2 Crux (VyOS 1.2.4)
Viacheslav updated the task description for T1711: BGP - migrate from tagNode to node (remove ASN from tagNode).
Oct 4 2019, 8:51 AM · VyOS 1.4 Sagitta
olofl added a comment to T1123: Inconsistency in community-list naming validation.

Any reason extcommunity-list and community-list doesnt support the same naming scheme?

Oct 4 2019, 8:04 AM · VyOS 1.3 Equuleus (1.3.0-epa1), test
c-po committed rVYOSONEX5848a4d6095e: dhcp-server: T1707: remove DHCP static-mappings from address pool.
Oct 4 2019, 7:47 AM
c-po committed rVYOSONEX562354209847: dhcp-server: only import ip_address and ip_network from ipaddress class.
Oct 4 2019, 7:47 AM
c-po committed rVYOSONEX1182b44e6c90: dhcp-server: T1707: bugfix on subsequent DHCP exclude addresses.
Oct 4 2019, 7:47 AM
c-po committed rVYOSONEX6f954ab56768: dhcp-server: T1707: remove DHCP static-mappings from address pool.
Oct 4 2019, 7:36 AM
c-po committed rVYOSONEXbdf890cca401: dhcp-server: only import ip_address and ip_network from ipaddress class.
Oct 4 2019, 7:36 AM
c-po committed rVYOSONEX0f0f9f2835cf: dhcp-server: T1707: bugfix on subsequent DHCP exclude addresses.
Oct 4 2019, 7:36 AM
adestis added a comment to T1183: BFD Support via FRR.

Hi trae32566

Oct 4 2019, 6:46 AM · VyOS 1.2 Crux (VyOS 1.2.4)
Viacheslav created T1711: BGP - migrate from tagNode to node (remove ASN from tagNode).
Oct 4 2019, 5:35 AM · VyOS 1.4 Sagitta

Oct 3 2019

hagbard moved T1700: Wireguard FQDN endpoint doesn't work after reboot from In Progress to Finished on the VyOS 1.3 Equuleus board.
Oct 3 2019, 5:39 PM · Rejected
hagbard moved T1700: Wireguard FQDN endpoint doesn't work after reboot from Backlog to Finished on the VyOS 1.2 Crux board.
Oct 3 2019, 5:39 PM · Rejected
hagbard closed T1700: Wireguard FQDN endpoint doesn't work after reboot as Wontfix.
Oct 3 2019, 5:38 PM · Rejected
c-po added a comment to T1707: DHCP static mapping and exclude address not working.

I can confirm the issue. Actually it boils down to two individual ones.

Oct 3 2019, 4:16 PM · VyOS 1.2 Crux (VyOS 1.2.4)
jestabro changed the status of T1710: [equuleus] buster: add patch to fix live-build missing key error from Open to Needs testing.
Oct 3 2019, 3:28 PM · VyOS 1.3 Equuleus (1.3.0)
c-po renamed T1707: DHCP static mapping and exclude address not working from DHCP static mapping work wrong to DHCP static mapping and exclude address not working.
Oct 3 2019, 11:23 AM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po closed T1689: "reset openvpn" op-mode command should terminate and restart OpenVPN process, a subtask of T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python, as Resolved.
Oct 3 2019, 9:56 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1689: "reset openvpn" op-mode command should terminate and restart OpenVPN process as Resolved.
Oct 3 2019, 9:56 AM · VyOS 1.3 Equuleus (1.3.0)
c-po committed rVYOSONEX08b60ba1ccbb: OpenVPN: T1689: Add full restart on 'reset openvpn interface <interface>'.
Oct 3 2019, 9:56 AM
c-po claimed T1689: "reset openvpn" op-mode command should terminate and restart OpenVPN process.
Oct 3 2019, 9:56 AM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T1496: Separate rolling release and LTS kernel builds from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Oct 3 2019, 9:04 AM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po changed the status of T1496: Separate rolling release and LTS kernel builds, a subtask of T1682: Migrate to new Jenkins Pipeline script, from Open to In progress.
Oct 3 2019, 9:04 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T1496: Separate rolling release and LTS kernel builds from Open to In progress.
Oct 3 2019, 9:04 AM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po moved T1709: Update WireGuard to 0.0.20190913 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Oct 3 2019, 9:04 AM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po edited projects for T1709: Update WireGuard to 0.0.20190913, added: VyOS 1.2 Crux (VyOS 1.2.4); removed VyOS 1.2 Crux.
Oct 3 2019, 9:03 AM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po claimed T1708: Update Rolling Release Kernel to 4.19.76.
Oct 3 2019, 9:03 AM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po created T1709: Update WireGuard to 0.0.20190913.
Oct 3 2019, 9:03 AM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po created T1708: Update Rolling Release Kernel to 4.19.76.
Oct 3 2019, 9:02 AM · VyOS 1.2 Crux (VyOS 1.2.4)
Unknown Object (User) updated subscribers of T1514: Add ability to restart frr processes.

We have had ticket ID 481: How to restart OSPF?

Oct 3 2019, 1:34 AM · VyOS 1.3 Equuleus (1.3.0)

Oct 2 2019

c-po added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

It is an upstream issue so I agree totally in closing as wonˋt fix

Oct 2 2019, 11:25 PM · Rejected
hagbard added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

Shall I close it as won't fix, given the fact that it is an upstream issue. Anything build around it, is in my opinion just a kludge, unless we would go with a separate daemon which can check and re-establish connections if they fail. The danger is that vyos becomes then more a server than a router. As workaround, a cronjob could do that as well, either setting an option via cli (wg-heartbeat or so since keepalive is a wg option already), which drops a cronjob onto the box and checks the wg endpoint periodically, if it fails it just calls diable/enable and checks again for X times, before it sleeps for let's say 24hs or so. @kroy would something like acronjob help you? Could be also set as a @reboot job and once the traffic flows it kicks itself out. Just wanna throw out ideas here.

Oct 2 2019, 7:18 PM · Rejected
c-po claimed T1707: DHCP static mapping and exclude address not working.
Oct 2 2019, 6:12 AM · VyOS 1.2 Crux (VyOS 1.2.4)

Oct 1 2019

lbv2rus created T1707: DHCP static mapping and exclude address not working.
Oct 1 2019, 10:54 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard closed T1706: wireguard broken in latest rolling as Resolved.
Oct 1 2019, 7:53 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1706: wireguard broken in latest rolling.

https://github.com/vyos/vyos-1x/commit/cf499f958423919264884e9f1c5c1b593fd9de0e next rolling will have it fixed.

Oct 1 2019, 7:53 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard committed rVYOSONEXcf499f958423: [wireguard] - T1706: wireguard broken in latest rolling.
Oct 1 2019, 7:52 PM
hagbard moved T1706: wireguard broken in latest rolling from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Oct 1 2019, 7:42 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1706: wireguard broken in latest rolling.

They have been committed at the same time, while I was using the current version if ifconfig.py and new one was published.
https://github.com/vyos/vyos-1x/commit/c24eb48c54b562fe7f78cdda82f2e245e9ab8506

Oct 1 2019, 7:39 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1706: wireguard broken in latest rolling.

Reason for the break is a different commit:

Oct 1 2019, 7:06 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard renamed T1706: wireguard broken in latest rolling from wigreuard broken in latest rolling to wireguard broken in latest rolling.
Oct 1 2019, 7:05 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1706: wireguard broken in latest rolling.
Oct 1 2019, 6:55 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T1706: wireguard broken in latest rolling.
Oct 1 2019, 6:55 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX46895f5a527f: Merge pull request #144 from jestabro/rev-load-config (authored by dmbaturin).
Oct 1 2019, 4:27 PM
hagbard added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

FYI: https://git.zx2c4.com/wg-dynamic/about/docs/idea.md

Oct 1 2019, 3:37 PM · Rejected
c-po added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

The Linux kernel has embedded name resolution, maybe this can be added to WireGuard itself. Its better then we design a patch for it.

Oct 1 2019, 3:37 PM · Rejected
hagbard added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

reverted the commit. I'm not sure if a daemon would be a good idea. Another option is to allow only IP's entered via cli or checking the name whenever wg is executed, resolve the name and send it to hostd to get it written to /etc/host. That would solve at least the issue at reboot and in most cases the correct IP should be in /etc/hosts.

Oct 1 2019, 3:29 PM · Rejected
hagbard committed rVYOSONEXab6d6ec47c8e: Revert "wireguard: T1700 - Wireguard FQDN endpoint doesn't work after reboot".
Oct 1 2019, 3:25 PM
hagbard added a reverting change for rVYOSONEXdaf2e29e3693: wireguard: T1700 - Wireguard FQDN endpoint doesn't work after reboot: rVYOSONEXab6d6ec47c8e: Revert "wireguard: T1700 - Wireguard FQDN endpoint doesn't work after reboot".
Oct 1 2019, 3:25 PM
runar added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

@kroy just to be clear, i'm not against using dns as endpoint for wireguard.. i'm for it, because i have the same issue as you do, but what i'm against is the way to getting there. As the wireguard protocol does not support dns in it self using this method is a loosing game.. what i'm not against is writing a daemon that does the name resolution for you when it comes available.. and available could mean after 1sec, 1m, 1h or even longer after the system is booted.. this daemon also could do re-resolving when the peer is down and the dns has changed...

Oct 1 2019, 2:48 PM · Rejected
kroy added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

This is going to become more and more of a problem as wireguard adoption continues. Most major Wireguard VPN services provide a FQDN as their endpoint, not IP:

Oct 1 2019, 1:58 PM · Rejected
fvbrasileiro created T1705: High CPU usage by bgpd when snmp is active.
Oct 1 2019, 12:30 PM · VyOS 1.2 Crux (VyOS 1.2.4)
runar added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

As for openvpn i dont know, but if the app itself does dns queries on connect it will work quite fint (as i think it does)

Oct 1 2019, 6:54 AM · Rejected
runar added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

As i tried to say, this fix will only work in some scenarios, and this comes down to the implementation of the app were configuring. And to be clear, wireguard does NOT support dns, but the wg config utillity does. On execution time it reads the dns name and tries to resolve it once, and only once. When it fails things would not work.. this is the same with eg. Nhrp that works exactly the same.. using this has raise conditions with getting ip up and running and not only on the host file. We do not wait for dhcp to delegate an address or dns servers.. these could come many ms/sec after wireguard is configured.. this is even true in the case when you change the priority.. and the length of the config/execution time also comes in as an parameter in this raise condition.. so, if you ask me, revert the priority and instead create a dns daemon thing that could read the config and populate the entry when it has failed.

Oct 1 2019, 6:53 AM · Rejected
danfaulknor awarded T160: Support NAT64 a Like token.
Oct 1 2019, 6:29 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

Shouldn‘t OpenVPN have a similar problem?

Oct 1 2019, 6:28 AM · Rejected
kroy added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

This should be reverted, as the change is breaking. After more testing, I found some problems due to things like static routing being applied before wireguard now. So the wireguard tunnel works, but in some cases any routing that shouldbe going over the tunnel does not work.

Oct 1 2019, 1:20 AM · Rejected

Sep 30 2019

hagbard closed T1684: Unable to enable IPv6 autoconf on PPPoE as Unknown Status.
Sep 30 2019, 10:20 PM · VyOS 1.2 Crux (VyOS 1.2.3)
hagbard added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyos-1x/vyos-1x_1.3.0-16_all.deb or next rolling release should fix the issue.

Sep 30 2019, 10:20 PM · Rejected
hagbard moved T1700: Wireguard FQDN endpoint doesn't work after reboot from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Sep 30 2019, 10:18 PM · Rejected
hagbard changed the status of T1700: Wireguard FQDN endpoint doesn't work after reboot from Open to Needs testing.
Sep 30 2019, 10:18 PM · Rejected
hagbard triaged T1700: Wireguard FQDN endpoint doesn't work after reboot as Normal priority.
Sep 30 2019, 10:18 PM · Rejected
hagbard committed rVYOSONEXdaf2e29e3693: wireguard: T1700 - Wireguard FQDN endpoint doesn't work after reboot.
Sep 30 2019, 10:17 PM
hagbard claimed T1700: Wireguard FQDN endpoint doesn't work after reboot.
Sep 30 2019, 10:14 PM · Rejected
kroy added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

Yep. Changing the priority fixes the issue completely

Sep 30 2019, 9:55 PM · Rejected
hagbard added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

@kroy You can quickly test it via setting Priority to 999 in /opt/vyatta/share/vyatta-cfg/templates/interfaces/wireguard/node.def. It's currently 459. Let me know your results, please.

Sep 30 2019, 9:30 PM · Rejected
kroy added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

@runar This isn't a routing issue though.

Sep 30 2019, 8:31 PM · Rejected
hagbard moved T1684: Unable to enable IPv6 autoconf on PPPoE from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Sep 30 2019, 7:22 PM · VyOS 1.2 Crux (VyOS 1.2.3)
hagbard moved T1684: Unable to enable IPv6 autoconf on PPPoE from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Sep 30 2019, 7:22 PM · VyOS 1.2 Crux (VyOS 1.2.3)
hagbard changed the status of T1684: Unable to enable IPv6 autoconf on PPPoE from Open to Needs testing.

https://github.com/vyos/vyatta-cfg-op-pppoe/commit/195a478b7d826ec7ff1652b99abc75d49161a882

Sep 30 2019, 7:00 PM · VyOS 1.2 Crux (VyOS 1.2.3)
vindenesen changed the status of T1704: OpenVPN - Add support for ncp-ciphers from Open to In progress.
Sep 30 2019, 6:43 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen created T1704: OpenVPN - Add support for ncp-ciphers.
Sep 30 2019, 6:42 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen closed T1688: OpenVPN - Add new cipher aes-(128|192|256)-gcm as Resolved.
Sep 30 2019, 6:38 PM · VyOS 1.3 Equuleus (1.3.0)
GitHub <noreply@github.com> committed rVYOSONEX9a4eab94d76c: Merge pull request #143 from vindenesen/current-T1688 (authored by c-po).
Sep 30 2019, 6:30 PM
vindenesen changed the status of T1688: OpenVPN - Add new cipher aes-(128|192|256)-gcm from Open to In progress.
Sep 30 2019, 6:28 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen added a comment to T1688: OpenVPN - Add new cipher aes-(128|192|256)-gcm.

Pull request created: https://github.com/vyos/vyos-1x/pull/143

Sep 30 2019, 6:27 PM · VyOS 1.3 Equuleus (1.3.0)
runar added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

Changing the priority will only change a portion of this. It.. could fix the situation there the user have static ip and a default route, but will not give effect when the user has dhcp or uses bgp el.. so my wote goes to not changing priorities on this. This is a loosing race as long as we dont have a daemon el. That manages the connections..

Sep 30 2019, 5:44 PM · Rejected
c-po added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

Could we raise WireGuard Priority to 999? So it is launched very late?

Sep 30 2019, 5:21 PM · Rejected
hagbard added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

There is not really an up or down, there is only a verified handshake and the transferred bytes. If you haven't sent and received anything, the interface is in 'unknown' state in terms of wireguard, even if it's 'up' if you look via iproute2. All can could do it checking if the endpoint resolves and if it does, send a packet and see if the handshake completes.

Sep 30 2019, 5:06 PM · Rejected
kroy added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

Changing when the tunnel comes up isn’t an option? For whatever reason the tunnel comes up before DNS resolution works. Using a hostname when the system is running works perfectly

Sep 30 2019, 4:22 PM · Rejected
hagbard added a comment to T1703: Macvlan PPPoE support .

Can you please clarify. What is Vif mode dialing and what has a vlan id to do with multiple physical lines? Does that mean your problem is solved?

Sep 30 2019, 4:18 PM · VyOS 1.3 Equuleus (1.3.0)
sunser added a comment to T1703: Macvlan PPPoE support .

Tested, if using Vif requires more physical lines, and switches can use Vif mode PPPoE dialing, using macvlan does not require additional equipment

Sep 30 2019, 4:15 PM · VyOS 1.3 Equuleus (1.3.0)
syncer closed T1642: BGP configuration error when using remove-private-as as Resolved.
Sep 30 2019, 4:07 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer moved T1642: BGP configuration error when using remove-private-as from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Sep 30 2019, 4:07 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer moved T1642: BGP configuration error when using remove-private-as from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Sep 30 2019, 4:07 PM · VyOS 1.2 Crux (VyOS 1.2.3)