Page MenuHomeVyOS Platform
Feed All Stories

Jun 18 2022

dongjunbo created T4469: Build Azure image by follow offical build instruction Error .
Jun 18 2022, 3:05 AM
jestabro claimed T4467: Validator Does Not Accept Signed Numbers.
Jun 18 2022, 12:59 AM · VyOS 1.4 Sagitta
jestabro added a comment to T4467: Validator Does Not Accept Signed Numbers.

PR: https://github.com/vyos/vyos-utils/pull/4
Adding the additional validator to policy.xml.in allows the smoketest (above) to pass.

Jun 18 2022, 12:55 AM · VyOS 1.4 Sagitta

Jun 17 2022

jestabro added a comment to T4467: Validator Does Not Accept Signed Numbers.

One approach is linked below; to be discussed before PR.
https://github.com/vyos/vyos-utils/compare/master...jestabro:increment-decrement?expand=1

Jun 17 2022, 5:31 PM · VyOS 1.4 Sagitta
blackhole added a comment to T4362: Wan Load Balancing - Can't create routing tables.

I hope it can be found. I have been banging my head against the wall with this issue :( and it's hurting.

Jun 17 2022, 1:56 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4362: Wan Load Balancing - Can't create routing tables.

load-balancing wan completely broken with nexthop dhcp for 1.4 (it happens after first reboot or renew)
The script gets empty values there https://github.com/vyos/vyatta-wanloadbalance/blob/a831f22d4c34bf947b0335e55573280b75c2bde0/src/lbdecision.cc#L180
So ip route replace table is never executed
Why does it get an empty value?
It parse lease file https://github.com/vyos/vyatta-wanloadbalance/blob/a831f22d4c34bf947b0335e55573280b75c2bde0/src/lbdata.cc#L335-L341
option new_routers and in 1.4 the file looks as

Jun 17 2022, 1:43 PM · VyOS 1.4 Sagitta
Viacheslav closed T4209: Firewall incorrect handler for recent count and time as Resolved.
Jun 17 2022, 10:02 AM · VyOS 1.4 Sagitta

Jun 16 2022

fernando closed T4352: wan-load balance - priority traffic rule doesn't work as Resolved.

i've checked this issues, it seems to be solved . I think that it was solved for another task. I used the following vyos version :

Jun 16 2022, 10:30 PM · VyOS 1.4 Sagitta
florin added a comment to T4466: intel i225-v nic does not detect link after boot.

I'm also trying to get this up and running. The latest 5.4 kernel fixes this issue, but other issues remain, like bridging not working.
Instead of backporting the driver, I ended up backporting the lataest 5.10 kernel to the 1.3 branch.

Jun 16 2022, 8:44 PM · VyOS 1.3 Equuleus
c-po committed rVYOSONEXa92e6b272b17: smoketest: policy: T4467: validate relative route-map metric.
Jun 16 2022, 7:32 PM
c-po committed rVYOSONEX894f2dc05b0c: vyos.ifconfig: T4384: fix file permission (664) on interface.py.
Jun 16 2022, 6:48 PM
v.huti added a comment to T4462: FRR operational-data pagination.

Ongoing activity:

1. Stabilization
-  I have seen a corner case that would crash inside the northbound callbacks.
-  I can see some validation failure logs, although the resulting output seems good for me.
-  Daniil was concerned about memory leaks associated with iteration state.
   After additional research - this is not a problem, but I can imagine cases where we would
   fail to handle a malformed XPath and leak resources on the stuck unwinding
   I need to do some testing with Valgrind.
2. Scale testing
3. Async support for multiple vtysh clients. The current demo assumes that there is only one client.
   I want to map the iteration state to the vtysh client/socket so multiple requests may be executed in parallel
4. A debugging instruction
   I have used some complicated debugging flow when merging the feature.
   This should be useful for other (non-C) devs.
5. Finishing the documentation
6. advanced XPath filtering support?
Jun 16 2022, 1:50 PM · VyOS Rolling
v.huti added a comment to T4462: FRR operational-data pagination.

Recently, I had a conversation with the VMware team lead - Pushpasis Sarkar.
He has described the ongoing development and explained the use case they are interested in.
From the conversation:

1. The latest proposal draft: 
   Page 72-73 `Retrieve Operational Data - Retrieving Containers and Leaf members`
   Page 84-85 `Retrieve Operational Data - Retrieving Large List elements` + comments
   Page 86 `Retrieve Operational Data - Retrieving Containers and Leaf members` + comments.
Jun 16 2022, 1:29 PM · VyOS Rolling
v.huti updated the task description for T4462: FRR operational-data pagination.
Jun 16 2022, 12:39 PM · VyOS Rolling
angelnu added a comment to T1311: WAN load-balancing can't flush connections when conntrack-sync is enabled.

I have also hit this into the latest rolling version:

Jun 16 2022, 10:39 AM · VyOS 1.3 Equuleus (1.3.9), VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, test
Viacheslav moved T4468: web-proxy source group cannot start with a number bug from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 16 2022, 9:11 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4468: web-proxy source group cannot start with a number bug.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1364

Jun 16 2022, 9:11 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a project to T4468: web-proxy source group cannot start with a number bug: VyOS 1.3 Equuleus (1.3.2).
Jun 16 2022, 8:57 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXfbd3bef2248d: webproxy: T4468: Fix regex for squidguard source-group.
Jun 16 2022, 8:55 AM
GitHub <noreply@github.com> committed rVYOSONEXfc5c0d5975a0: Merge pull request #1363 from sever-sever/T4468 (authored by c-po).
Jun 16 2022, 8:55 AM
Viacheslav added a comment to T3813: Some custom sysctl parameters can't be applied bug.

I think it should check this parameter per commit and it is a bug with validation as we don't have a tunnel interface yet
But after commit it will be valid value

Jun 16 2022, 8:50 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Viacheslav added a comment to T4468: web-proxy source group cannot start with a number bug.

PR https://github.com/vyos/vyos-1x/pull/1363

vyos@r14# set service webproxy url-filtering squidguard source-group fdsf-dg
[edit]
vyos@r14#
Jun 16 2022, 8:41 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav changed the status of T4468: web-proxy source group cannot start with a number bug from Open to In progress.
Jun 16 2022, 8:37 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4468: web-proxy source group cannot start with a number bug.

It seems issue with this validator https://github.com/vyos/vyos-1x/blob/1978946312a36f4913e1e5ea7754668b1c653d09/interface-definitions/service_webproxy.xml.in#L487

Jun 16 2022, 8:08 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Nova_Logic created T4468: web-proxy source group cannot start with a number bug.
Jun 16 2022, 7:49 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEX1978946312a3: dhclient: T2393: introduce 20 seconds stop timeout - required for smoketesting….
Jun 16 2022, 7:33 AM
c-po triaged T4467: Validator Does Not Accept Signed Numbers as Normal priority.
Jun 16 2022, 7:06 AM · VyOS 1.4 Sagitta
c-po added a comment to T4467: Validator Does Not Accept Signed Numbers.

route-maps support a relative adjustment of the metric (https://github.com/vyos/vyos-1x/blob/current/interface-definitions/policy.xml.in#L1402-L1417)

Jun 16 2022, 7:06 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3070: Firewall going OOM, possible related to nftables migration.

@kroy Are you still having trouble with it?

Jun 16 2022, 6:45 AM · VyOS 1.3 Equuleus (1.3.4)
trae32566 created T4467: Validator Does Not Accept Signed Numbers.
Jun 16 2022, 6:44 AM · VyOS 1.4 Sagitta
danhusan created T4466: intel i225-v nic does not detect link after boot.
Jun 16 2022, 6:43 AM · VyOS 1.3 Equuleus
Viacheslav closed T4246: Failed to delete vrrp transition-script as Invalid.
Jun 16 2022, 6:43 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T3866: Configs with DNS forwarding listening on OpenVPN interfaces or interfaces without a fixed address cannot be migrated to the new syntax as Resolved.
Jun 16 2022, 6:41 AM · VyOS 1.3 Equuleus (1.3.0)

Jun 15 2022

sarthurdev changed the status of T4435: Policy route and firewall - error when using undefined group from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1362

Jun 15 2022, 9:15 PM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX34db435e7a74: firewall: T4147: Use named sets for firewall groups.
Jun 15 2022, 6:03 PM
sarthurdev committed rVYOSONEX7e59b2a3f31e: firewall: T970: Use set prefix to domain groups.
Jun 15 2022, 6:03 PM
GitHub <noreply@github.com> committed rVYOSONEXeab402588696: Merge pull request #1361 from sarthurdev/firewall_named (authored by c-po).
Jun 15 2022, 6:03 PM
Viacheslav closed T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration as Not Applicable.
Jun 15 2022, 3:28 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
Viacheslav closed T515: Complete the documentation on the suggested Python / XML config framework, a subtask of T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration, as Not Applicable.
Jun 15 2022, 3:28 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
Viacheslav closed T515: Complete the documentation on the suggested Python / XML config framework as Not Applicable.
Jun 15 2022, 3:28 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
Viacheslav closed T514: Concentration and streamlining of Python / XML config framework documentation, a subtask of T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration, as Not Applicable.
Jun 15 2022, 3:27 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
Viacheslav closed T514: Concentration and streamlining of Python / XML config framework documentation as Not Applicable.
Jun 15 2022, 3:27 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
Viacheslav closed T1890: Metatask: rewrite flow-accounting to XML and Python, a subtask of T3355: Remove all remaining legacy Vyatta code, as Resolved.
Jun 15 2022, 3:21 PM · VyOS Rolling
Viacheslav closed T1890: Metatask: rewrite flow-accounting to XML and Python as Resolved.
Jun 15 2022, 3:21 PM · VyOS 1.3 Equuleus (1.3.0)
n.fort closed T4450: Route-map - Extend options for ip|ipv6 address match as Resolved.
Jun 15 2022, 3:03 PM · VyOS 1.4 Sagitta
n.fort closed T4449: Route-map - Extend options for ip next-hop match as Resolved.
Jun 15 2022, 3:03 PM · VyOS 1.4 Sagitta
n.fort closed T990: Make DNAT/SNAT a valid state in firewall rules. as Resolved.
Jun 15 2022, 3:02 PM · VyOS 1.4 Sagitta, test
sarthurdev changed the status of T4147: New Firewall Implementation - proposed changes on group implementation from In progress to Needs testing.
Jun 15 2022, 1:33 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4147: New Firewall Implementation - proposed changes on group implementation.

PR: https://github.com/vyos/vyos-1x/pull/1361

Jun 15 2022, 1:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T1375: Add clear dhcp server lease function.

PR https://github.com/vyos/vyos-1x/pull/1360

Jun 15 2022, 12:40 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX74b24c5f5fcc: Improve IPsec help strings.
Jun 15 2022, 6:01 AM
GitHub <noreply@github.com> committed rVYOSONEX609a3abb3d9b: Merge pull request #1359 from dmbaturin/help-proofreading-1 (authored by c-po).
Jun 15 2022, 6:01 AM
Viacheslav added a project to T1375: Add clear dhcp server lease function: VyOS 1.4 Sagitta.
Jun 15 2022, 1:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

Jun 14 2022

n.fort added a comment to T4460: nhrp not starting due to missing cisco-authentication value.

Since in previous version set protocols nhrp tunnel tun0 cisco-authentication "" was allowed, a migration script is required. Otherwise, when upgrading, configuration fails.

Jun 14 2022, 2:54 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
Viacheslav moved T4380: Feature Request: ocserv: 2FA OTP key generator in VyOS CLI from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 14 2022, 1:05 PM · VyOS 1.4 Sagitta
Viacheslav moved T4420: Feature Request: ocserv: show configured 2FA OTP key from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 14 2022, 1:04 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4420: Feature Request: ocserv: show configured 2FA OTP key: VyOS 1.4 Sagitta.
Jun 14 2022, 1:04 PM · VyOS 1.4 Sagitta

Jun 13 2022

Viacheslav added a comment to T1237: Static Route Path Monitoring, failover.

PR https://github.com/vyos/vyos-1x/pull/1358

set protocols failover route 203.0.113.1/32 next-hop 192.168.100.1 check target '192.168.100.1'
set protocols failover route 203.0.113.1/32 next-hop 192.168.100.1 check timeout '10'
set protocols failover route 203.0.113.1/32 next-hop 192.168.100.1 check type 'icmp'
set protocols failover route 203.0.113.1/32 next-hop 192.168.100.1 interface 'eth1'
set protocols failover route 203.0.113.1/32 next-hop 192.168.100.1 metric '2'
Jun 13 2022, 4:56 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4147: New Firewall Implementation - proposed changes on group implementation from Open to In progress.

Working on moving groups to named set as part of a refactor in some firewall code.

Jun 13 2022, 12:11 PM · VyOS 1.4 Sagitta

Jun 12 2022

sarthurdev committed rVYOSONEX8ba45cfcc1cc: firewall: T4299: Add support for GeoIP filtering.
Jun 12 2022, 7:32 AM
GitHub <noreply@github.com> committed rVYOSONEX59526a8adca2: Merge pull request #1357 from sarthurdev/geoip (authored by c-po).
Jun 12 2022, 7:32 AM
panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

Thanks for the pointer, but I think it should still be considered a "bug" that you can no longer use an empty group (I'm just going to assume that this would apply to any kind of group, but most are probably using this for host/network groups, as this is where it would be most useful). Judging from the comments in T4147, I'm clearly not the only one who was taking advantage of managing sets outside of the system. Alas, my boot times for 1.4 (what this discussion is about) are not really valid, as my configuration didn't really get migrated from 1.3.1->1.4, or better said, it doesn't actually commit, and I actually ended up with a mostly empty firewall config on boot, which is perhaps why its booting so quickly now.

Jun 12 2022, 7:09 AM · VyOS 1.3 Equuleus (1.3.6)
Unknown Object (User) closed T4380: Feature Request: ocserv: 2FA OTP key generator in VyOS CLI as Resolved.

Tested with VyOS 1.4-rolling-202206100921
Works as expected
Described in the documentation

Jun 12 2022, 5:16 AM · VyOS 1.4 Sagitta
Unknown Object (User) closed T4420: Feature Request: ocserv: show configured 2FA OTP key as Resolved.

Tested in VyOS 1.4-rolling-202206100921

Jun 12 2022, 5:04 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4457: L2TP/IPSec Remote Access VPN does not work as expected in 1.3.1-S1.

The problem seems to be in these lines:

Jun 12 2022, 3:56 AM · VyOS 1.3 Equuleus ( 1.3.1)

Jun 11 2022

n.fort renamed T4435: Policy route and firewall - error when using undefined group from Policy route without defined port-group error to Policy route and firewall - error when using undefined group.
Jun 11 2022, 11:19 AM · VyOS 1.4 Sagitta
n.fort added a comment to T4435: Policy route and firewall - error when using undefined group.

Extra checks are needed not only when attaching a policy route to an interface, but also when attaching firewall.
For example:

vyos@vyos# set firewall name FOO rule 10 action accept 
[edit]
vyos@vyos# set firewall name FOO rule 10 destination group address-group NOAG
[edit]
vyos@vyos# commit
Jun 11 2022, 11:15 AM · VyOS 1.4 Sagitta
dmbaturin created 1.3.1.
Jun 11 2022, 8:40 AM
dmbaturin edited a custom field on T3686: Bridging OpenVPN tap with no local-address breaks.
Jun 11 2022, 8:38 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin renamed T3380: "show vpn ike sa" does not display IPv6 peers from Show vpn ike sa with IPv6 remote peer to "show vpn ike sa" does not display IPv6 peers.
Jun 11 2022, 8:37 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Jun 10 2022

sarthurdev changed the status of T4299: Firewall - GeoIP filtering from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1357

Jun 10 2022, 11:02 PM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX9791258d7d53: firewall: T478: Add support for nesting groups.
Jun 10 2022, 7:28 PM
GitHub <noreply@github.com> committed rVYOSONEXfe18efba34c5: Merge pull request #1356 from sarthurdev/nested_groups (authored by c-po).
Jun 10 2022, 7:28 PM
sarthurdev changed the status of T478: Firewall address group (multi and nesting), a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Jun 10 2022, 7:23 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev changed the status of T478: Firewall address group (multi and nesting) from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1356

Jun 10 2022, 7:23 PM · VyOS 1.4 Sagitta
c-po moved T4434: DMVPN: cisco-authentication password length is 8 characters from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po moved T4436: BGP/VRF - not enable peer on address-family from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po moved T4437: flow-accounting: support IPv6 flow collectors from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po moved T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails from In Progress to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po moved T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases from In Progress to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po moved T4345: New firewall code does not accept "rate/time interval" syntax used in old config from In Progress to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po moved T4144: Firewall address-group - Improve error messages from In Progress to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po moved T4301: The "arp-monitor" option in bonding interface settings does not work from In Progress to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po moved T4444: sstp: Feature request. Port number changing support from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po moved T4448: rip: add support for explicit version selection from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po moved T2473: Xml for EIGRP [conf_mode] from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po moved T4465: node.def generation misses whitespace on multiple use of <path> from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po closed T4465: node.def generation misses whitespace on multiple use of <path> as Resolved.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po closed T4465: node.def generation misses whitespace on multiple use of <path>, a subtask of T4284: QoS: rewrite to XML and Python, as Resolved.
Jun 10 2022, 6:31 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX2f4031c810a2: scripts: T4465: node.def generation requires whitespace on multiple use of….
Jun 10 2022, 6:31 PM
c-po changed the status of T4465: node.def generation misses whitespace on multiple use of <path> from Open to In progress.
Jun 10 2022, 6:29 PM · VyOS 1.4 Sagitta
c-po changed the status of T4465: node.def generation misses whitespace on multiple use of <path>, a subtask of T4284: QoS: rewrite to XML and Python, from Open to In progress.
Jun 10 2022, 6:29 PM · VyOS 1.4 Sagitta
c-po created T4465: node.def generation misses whitespace on multiple use of <path>.
Jun 10 2022, 6:29 PM · VyOS 1.4 Sagitta
n.fort committed rVYOSONEX81a269d2d7ac: Firewall:T4458: Add ttl match option in firewall.
Jun 10 2022, 6:19 PM
GitHub <noreply@github.com> committed rVYOSONEXc3275306ce56: Merge pull request #1355 from nicolas-fort/T4458-ipv4-ttl (authored by c-po).
Jun 10 2022, 6:19 PM
n.fort changed the status of T4460: nhrp not starting due to missing cisco-authentication value from Open to Needs testing.
Jun 10 2022, 6:13 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
Viacheslav committed rVYOSONEXa03b89039266: op-mode: T4429: Ability to detect external IP address.
Jun 10 2022, 6:08 PM
GitHub <noreply@github.com> committed rVYOSONEX299e16aae6d2: Merge pull request #1326 from sever-sever/T4429 (authored by c-po).
Jun 10 2022, 6:08 PM
c-po committed rVYOSONEX18b303734d84: xml: drop not always applicable REQUIRED suffix from completion help string.
Jun 10 2022, 6:08 PM
c-po added a reverting change for rVYOSONEX6f818ee9033e: dmvpn: nhrp: T4434: secret length can not exceed 8 characters: rVYOSONEX884cd2519515: Revert "dmvpn: nhrp: T4434: secret length can not exceed 8 characters".
Jun 10 2022, 6:00 PM