Page MenuHomeVyOS Platform
Feed All Stories

May 4 2022

Viacheslav added a comment to T4362: Wan Load Balancing - Can't create routing tables.

I can't reproduce it
With such configuration all works fine VyOS 1.4-rolling-202204300743:

set load-balancing wan interface-health eth4 failure-count '5'
set load-balancing wan interface-health eth4 nexthop 'dhcp'
set load-balancing wan interface-health eth4 success-count '1'
set load-balancing wan interface-health eth4 test 10 target '192.0.2.40'
set load-balancing wan interface-health eth5 failure-count '5'
set load-balancing wan interface-health eth5 nexthop 'dhcp'
set load-balancing wan interface-health eth5 success-count '1'
set load-balancing wan interface-health eth5 test 10 target '192.0.2.50'
set load-balancing wan interface-health eth6 failure-count '5'
set load-balancing wan interface-health eth6 nexthop 'dhcp'
set load-balancing wan interface-health eth6 success-count '1'
set load-balancing wan interface-health eth6 test 10 target '192.0.2.60'
set load-balancing wan rule 10 failover
set load-balancing wan rule 10 inbound-interface 'eth7'
set load-balancing wan rule 10 interface eth4
set load-balancing wan rule 10 interface eth5
set load-balancing wan rule 10 interface eth6
set load-balancing wan rule 10 protocol 'all'
set load-balancing wan sticky-connections
May 4 2022, 10:35 AM · VyOS 1.4 Sagitta
aserkin created T4409: route received via Framed-Route radius attribute is installed into default table when terminating connection to VRF.
May 4 2022, 7:56 AM · VyOS 1.5 Circinus (2025.11)
Viacheslav added a comment to T4408: Add sshguard to protect against brut-forces.

Configuration

# cat /etc/sshguard/sshguard.conf 
#### REQUIRED CONFIGURATION ####
# Full path to backend executable (required, no default)
BACKEND="/usr/lib/x86_64-linux-gnu/sshg-fw-nft-sets"
May 4 2022, 3:19 AM · VyOS 1.4 Sagitta
Viacheslav created T4408: Add sshguard to protect against brut-forces.
May 4 2022, 3:06 AM · VyOS 1.4 Sagitta

May 3 2022

blackhole added a comment to T4362: Wan Load Balancing - Can't create routing tables.

If it helps, I am also getting the exact same errors and problems, would love to see this working please

May 3 2022, 11:57 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4380: Feature Request: ocserv: 2FA OTP key generator in VyOS CLI from In progress to Needs testing.
May 3 2022, 7:36 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX5ceabd78f1cc: monitoring: T4315: Add telegraf output plugin prometheus-client.
May 3 2022, 7:13 PM
GitHub <noreply@github.com> committed rVYOSONEX0400f96c003c: Merge pull request #1310 from sever-sever/T4315 (authored by c-po).
May 3 2022, 7:13 PM
zsdc changed the status of T4407: Network-config v2 is broken in Cloud-init 22.1 and VyOS 1.3 from Open to Needs testing.

Resolved in https://github.com/vyos/vyos-cloud-init/pull/54

May 3 2022, 3:55 PM · VyOS 1.3 Equuleus (1.3.4)
zsdc created T4407: Network-config v2 is broken in Cloud-init 22.1 and VyOS 1.3.
May 3 2022, 3:45 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin created T4406: Make an API endpoint for for anonymous host info retrieval (e.g. by a login page).
May 3 2022, 2:39 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling, Restricted Project
dtoux added a comment to T4405: DHCP client sometimes ignores `no-default-route` option of an interface.

Also, these routes getting an administrative distance of 1, which is impossible to override. I believe the default route from DHCP normally has 210 which is manageable. So, the quick workaround could be increasing distance of these routes.

May 3 2022, 2:28 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dtoux added a comment to T4405: DHCP client sometimes ignores `no-default-route` option of an interface.
r24:/home/dtoubelis# cat /var/lib/dhcp/dhclient_eth4.leases
lease {
  interface "eth4";
  fixed-address 100.123.57.53;
  option subnet-mask 255.192.0.0;
  option relay-agent-information 1:4:0:0:4:cf:5:4:64:40:0:1:97:8:1:0:14:ed:0:0:14:ed:98:0;
  option dhcp-lease-time 300;
  option routers 100.64.0.1;
  option dhcp-message-type 5;
  option domain-name-servers 1.1.1.1,8.8.8.8;
  option dhcp-server-identifier 100.64.0.1;
  option interface-mtu 1500;
  option rfc3442-classless-static-routes 32,192,168,100,1,0,0,0,0,32,34,120,255,244,0,0,0,0,0,100,64,0,1;
  renew 2 2022/05/03 12:42:00;
  rebind 2 2022/05/03 12:44:26;
  expire 2 2022/05/03 12:45:04;
}
lease {
  interface "eth4";
  fixed-address 100.123.57.53;
  option subnet-mask 255.192.0.0;
  option relay-agent-information 1:4:0:0:4:cf:5:4:64:40:0:1:97:8:1:0:14:ed:0:0:14:ed:98:0;
  option dhcp-lease-time 300;
  option routers 100.64.0.1;
  option dhcp-message-type 5;
  option domain-name-servers 1.1.1.1,8.8.8.8;
  option dhcp-server-identifier 100.64.0.1;
  option interface-mtu 1500;
  option rfc3442-classless-static-routes 32,192,168,100,1,0,0,0,0,32,34,120,255,244,0,0,0,0,0,100,64,0,1;
  renew 2 2022/05/03 12:46:34;
  rebind 2 2022/05/03 12:48:50;
  expire 2 2022/05/03 12:49:28;
}
lease {
  interface "eth4";
  fixed-address 100.123.57.53;
  option subnet-mask 255.192.0.0;
  option relay-agent-information 1:4:0:0:4:cf:5:4:64:40:0:1:97:8:1:0:14:ed:0:0:14:ed:98:0;
  option dhcp-lease-time 300;
  option routers 100.64.0.1;
  option dhcp-message-type 5;
  option domain-name-servers 1.1.1.1,8.8.8.8;
  option dhcp-server-identifier 100.64.0.1;
  option interface-mtu 1500;
  option rfc3442-classless-static-routes 32,192,168,100,1,0,0,0,0,32,34,120,255,244,0,0,0,0,0,100,64,0,1;
  renew 2 2022/05/03 12:51:33;
  rebind 2 2022/05/03 12:53:25;
  expire 2 2022/05/03 12:54:03;
}
...
}
May 3 2022, 2:22 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4315: Telegraf - Output to prometheus.

Prometheus server pulls information correctly

prometheus.png (1×2 px, 1 MB)

May 3 2022, 9:58 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav closed T4395: Extend show vpn debug as Resolved.
May 3 2022, 7:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4405: DHCP client sometimes ignores `no-default-route` option of an interface.

Could you also provide cat /var/lib/dhcp/dhclient_eth4.leases ?
no-default-route ignore just option routers and don't touch other options like classless-static-routes
https://github.com/vyos/vyos-1x/blob/2c29a3b3b46c7570f4a509f413b208348c0ce647/data/templates/dhcp-client/ipv4.tmpl#L18-L19

May 3 2022, 7:08 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dtoux added a comment to T4405: DHCP client sometimes ignores `no-default-route` option of an interface.

Below is a packet capture from DHCP exchange:


It seems that option 121 has more than one route. Could this be causing the abnormal behavior?

May 3 2022, 4:44 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dtoux created T4405: DHCP client sometimes ignores `no-default-route` option of an interface.
May 3 2022, 4:16 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav changed the status of T4404: Container is not deleted from Open to Needs testing.
May 3 2022, 1:10 AM · VyOS 1.4 Sagitta
Viacheslav created T4404: Container is not deleted.
May 3 2022, 12:14 AM · VyOS 1.4 Sagitta

May 2 2022

Viacheslav added a comment to T4315: Telegraf - Output to prometheus.

PR
https://github.com/vyos/vyos-1x/pull/1310

May 2 2022, 7:40 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po added a comment to T4385: bgp: peer-group member cannot override remote-as of peer-group.

We also need to verify remote-as in v6only or interface definitions:

May 2 2022, 6:20 PM · VyOS 1.4 Sagitta
c-po reopened T4385: bgp: peer-group member cannot override remote-as of peer-group as "In progress".
May 2 2022, 6:19 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4315: Telegraf - Output to prometheus from Open to In progress.
May 2 2022, 12:51 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
wornet-mwo added a comment to T4403: Charon hangs at 100% CPU when many routes are present.

Done some further research about rt_netlink and charon relationship. As described in the docs of Strongswan the option charon.process_route = no helps and is a good workaround if the destination is always reachable over a known specific interface (i think it can be an issue if wan load-balancing etc. is used).

May 2 2022, 12:23 PM · vyos-strongswan
wornet-mwo created T4403: Charon hangs at 100% CPU when many routes are present.
May 2 2022, 10:25 AM · vyos-strongswan
v.huti added a comment to T4394: Improve VYOS_DEBUG profiling support.

There was some effort to introduce profiling into the system before, but nothing was developed.
The ticket was opened to verify that the timing values displayed in /var/log/vyatta are correct.
The vyos-debug flag enables tracing for actions described in the templates.
This will be a step-by-step walkthrough of the system profiling, as I have found this to have a bunch of non-obvious technical nuances that might get you stuck.

May 2 2022, 8:55 AM · VyOS Rolling
c-po committed rVYOSONEX318f81cba207: ipsec: T4353: bugfix template extension.
May 2 2022, 4:33 AM
c-po committed rVYOSONEX1566998a17e7: T2216: file is called container.py.
May 2 2022, 4:26 AM

May 1 2022

c-po committed rVYOSONEXd956fda57f32: accel-ppp: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX5ec208ed9ee0: http: api: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXf38ce741c285: system-logs: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX01bdf2dfdb09: openconnect: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXb6a307424451: igmp-proxy: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX780d4fe16cd8: syslog: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX644a0fe475b1: pppoe: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX4400d11709a8: nhrp: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX1b80aec26798: firewall: zone: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXe3c657e9f4d8: lcd: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX5271cf5bfec2: vrrp: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX9eab0cdd0bbe: firewall: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX59290c857237: system-options: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX0565b602ac8c: router-advert: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX8abb6c0a7473: ids: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX8b0ee4d17279: mdns-repeater: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX49b1afc25b73: ipsec: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX992c84749366: vrf: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX3f657383cdd9: login: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXe0f1e495b81c: flow-accounting: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXc621175631ab: serial-console: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXeafe13ace604: webproxy: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX7c71e956e8e1: telegraf: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po closed T4353: Add Jinja2 linter to vyos-1x build process as Resolved.
May 1 2022, 7:12 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX5ffbd74baee4: snmp: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXf0a13824f39f: lldp: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX92f266b733a5: tftp-server: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXe6af32344b16: container: T4353: fix Jinja2 linting errors.
May 1 2022, 7:11 PM
c-po committed rVYOSONEX827cefbcbfa2: conserver: T4353: fix Jinja2 linting errors.
May 1 2022, 7:11 PM
c-po committed rVYOSONEXa30209ae0be3: conntrackd: T4353: fix Jinja2 linting errors.
May 1 2022, 7:11 PM
c-po committed rVYOSONEX2f507669fd7f: conntrack: T4353: fix Jinja2 linting errors.
May 1 2022, 7:11 PM
c-po committed rVYOSONEX578ce55e5688: bcast-relay: T4353: fix Jinja2 linting errors.
May 1 2022, 7:11 PM
c-po closed T4363: salt-minion: default mine_interval option is not set as Resolved.
May 1 2022, 7:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po moved T4363: salt-minion: default mine_interval option is not set from In Progress to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
May 1 2022, 7:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po committed rVYOSONEX8526c25ef9a8: salt-minion: T4363: mine_interval option is not set.
May 1 2022, 1:06 PM
c-po committed rVYOSONEX07ce7e8639d9: smoketest: salt: T4363: add initial testcase.
May 1 2022, 1:06 PM
GitHub <noreply@github.com> committed rVYOSONEX2c29a3b3b46c: Merge pull request #1284 from c-po/t4363-salt-equuleus (authored by c-po).
May 1 2022, 1:06 PM
dmbaturin renamed T4402: OpenVPN client-ip-pool option is broken from OpenVPN ifconfig-pool option is broken to OpenVPN client-ip-pool option is broken.
May 1 2022, 12:13 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
dmbaturin created T4402: OpenVPN client-ip-pool option is broken.
May 1 2022, 11:56 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
c-po closed T4369: OpenVPN: daemon not restarted on changes to "openvpn-option" CLI node as Resolved.
May 1 2022, 6:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4369: OpenVPN: daemon not restarted on changes to "openvpn-option" CLI node from Open to Finished on the VyOS 1.4 Sagitta board.
May 1 2022, 6:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4369: OpenVPN: daemon not restarted on changes to "openvpn-option" CLI node from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
May 1 2022, 6:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

Apr 30 2022

zsdc created T4401: Networking needs to be reset during config boot (in some environments).
Apr 30 2022, 7:04 PM · VyOS Rolling, Bugs
c-po committed rVYOSONEX9beeba732c26: firewall: T1230: fix validator for service alias names (e.g. ssmtp).
Apr 30 2022, 4:37 PM
c-po committed rVYOSONEX42e823b82365: smoketest: import large firewall config from T1230.
Apr 30 2022, 4:10 PM
c-po committed rVYOSONEX4d679b2150f2: vyos-configd: enable firewall support.
Apr 30 2022, 1:22 PM
c-po committed rVYOSONEX605f400418a1: op-mode: container: T2216: remove duplicate log node.
Apr 30 2022, 6:12 AM

Apr 29 2022

c-po committed rVYOSONEX598e88f6d0e6: vyos.configdict: T4369: add is_node_changed() helper.
Apr 29 2022, 7:36 PM
c-po committed rVYOSONEXdde78e8024de: openvpn: T4369: enforce daemon-restart on openvpn-option CLI change.
Apr 29 2022, 7:36 PM
GitHub <noreply@github.com> committed rVYOSONEXc9e362224a72: Merge pull request #1308 from c-po/t4369-openvpn-equuleus (authored by c-po).
Apr 29 2022, 7:36 PM
c-po committed rVYOSONEX8ec6910fb838: T2216: containers need to be added via "add container image" in advance before….
Apr 29 2022, 6:54 PM
c-po committed rVYOSONEX80ecb1b7aaab: xml: T4047: use full string match in the regex validator.
Apr 29 2022, 6:54 PM
c-po added a project to T4369: OpenVPN: daemon not restarted on changes to "openvpn-option" CLI node: VyOS 1.3 Equuleus (1.3.2).
Apr 29 2022, 6:07 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4366: geneve: interface is removed on changes to e.g. description as Resolved.
Apr 29 2022, 6:02 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po moved T4366: geneve: interface is removed on changes to e.g. description from In Progress to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Apr 29 2022, 6:01 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po closed T4388: dhcp-server: missing constraint on tftp-server-name option as Resolved.
Apr 29 2022, 6:01 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4388: dhcp-server: missing constraint on tftp-server-name option from In Progress to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Apr 29 2022, 6:01 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEX52155b9086fa: smoketest: add basic QoS configuration.
Apr 29 2022, 5:54 PM
n.fort reassigned T4377: generate tech-support archive includes previous archives from n.fort to Unknown Object (User).
Apr 29 2022, 10:31 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
n.fort claimed T4377: generate tech-support archive includes previous archives.
Apr 29 2022, 10:19 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
Unknown Object (User) added a comment to T4377: generate tech-support archive includes previous archives.

https://github.com/vyos/vyatta-op/pull/55

Apr 29 2022, 3:23 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)

Apr 28 2022

fernando added a comment to T4399: nhrp - add or delete nhrp tunnel restart opennhrp process.

I've tried with a new spoke and I can't seem to register using `reload-or-restart', although it resolved the lost connectivity issues the opennhrp process needs a full restart. however, if you restart opennhrp daemon it causes different issues and usually the spoke loses connection.

## hub
Apr 28 2022, 8:57 PM · VyOS 1.4 Sagitta (1.4.3)
c-po committed rVYOSONEX6bb409f397b4: geneve: T4366: prevent interface re-creation on nasic parameter change.
Apr 28 2022, 6:01 PM
GitHub <noreply@github.com> committed rVYOSONEX2a2bb78fb1dc: Merge pull request #1286 from c-po/t4633-geneve-equuleus (authored by c-po).
Apr 28 2022, 6:01 PM
c-po committed rVYOSONEXadf057efbe2c: dhcp: T4388: missing constraint on tftp-server-name option.
Apr 28 2022, 6:00 PM
GitHub <noreply@github.com> committed rVYOSONEXaf04f7148972: Merge pull request #1297 from c-po/t4388-dhcp-equuleus (authored by c-po).
Apr 28 2022, 6:00 PM
c-po committed rVYOSONEX3910cb51e3ad: configd: eanble other missed out services.
Apr 28 2022, 1:04 PM
c-po committed rVYOSONEX63f8ee6de3d8: arp: T4397: bump component version number.
Apr 28 2022, 1:04 PM
c-po committed rVYOSONEXb1772a82e560: system-proxy: T1741: migrate to get_config_dict().
Apr 28 2022, 1:04 PM
c-po committed rVYOSONEXb0aeb2a9c196: arp: T4397: change CLI syntax to support interface and VRF bound ARP entries.
Apr 28 2022, 1:04 PM
fernando changed the status of T4399: nhrp - add or delete nhrp tunnel restart opennhrp process from Open to Needs testing.
Apr 28 2022, 11:51 AM · VyOS 1.4 Sagitta (1.4.3)