Page MenuHomeVyOS Platform
Feed All Stories

Oct 18 2022

jack9603301 updated the task description for T4756: General applications that support SOCAT.
Oct 18 2022, 6:13 AM

Oct 17 2022

c-po committed rVYOSONEX8403848a338d: login: 2fa: T874: fix PAM string during ISO build.
Oct 17 2022, 6:50 PM
Viacheslav updated the task description for T4712: Collaborative Protection Profile cPP for Network Devices root task.
Oct 17 2022, 2:12 PM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Viacheslav updated subscribers of T4720: Ability to configure SSH HostKeyAlgorithms.
Oct 17 2022, 1:42 PM · VyOS 1.4 Sagitta
Viacheslav claimed T4720: Ability to configure SSH HostKeyAlgorithms.
Oct 17 2022, 12:25 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4720: Ability to configure SSH HostKeyAlgorithms, a subtask of T4712: Collaborative Protection Profile cPP for Network Devices root task, from Open to In progress.
Oct 17 2022, 12:25 PM · VyOS Rolling, VyOS 1.5 Circinus (1.5-stream-2025-Q4)
Viacheslav changed the status of T4720: Ability to configure SSH HostKeyAlgorithms from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/1601

set service ssh hostkey-algorithm 'sk-ssh-ed25519@openssh.com'
set service ssh hostkey-algorithm 'ssh-rsa'
Oct 17 2022, 12:25 PM · VyOS 1.4 Sagitta
aserkin added a comment to T4731: excessive FRR logs about non-existent VRFs.

Added more bgpd/ospfd events to the log. The VRF Id seem to be correct. But the events look curious. After session start the interface is first created in vrf default (vrf default, id:0) followed by bgpd/ospfd events, then accel-ppp process moves it to destination vrf (vrf client, id:5) which is follwed by the bgpd/ospfd errors.
Finally, with more or less than 5000 sessions bgpd accidentally becomes unresponsive and utilizes 200% cpu (8 cores are used on VM). Accel-pppd process having all network destinations unreachable also goes unresponsive a bit later.
After that we have to reboot.

Oct 17 2022, 12:11 PM · VyOS Rolling, Bugs
jestabro committed rVYOSONEX8cafffff3169: graphql: T4753: generalize system_status to composite_{query,mutation}.
Oct 17 2022, 11:27 AM
GitHub <noreply@github.com> committed rVYOSONEX414f435d5090: Merge pull request #1600 from jestabro/gql-composite (authored by jestabro).
Oct 17 2022, 11:27 AM
jestabro claimed T3909: Add ability to upload scripts via API.
Oct 17 2022, 10:46 AM · VyOS Rolling
jack9603301 created T4756: General applications that support SOCAT.
Oct 17 2022, 10:31 AM
Viacheslav updated the task description for T4755: Configure unsuccessful logon attempts.
Oct 17 2022, 10:30 AM · VyOS Rolling
Viacheslav created T4755: Configure unsuccessful logon attempts.
Oct 17 2022, 10:03 AM · VyOS Rolling
Viacheslav updated subscribers of T3909: Add ability to upload scripts via API.
Oct 17 2022, 9:35 AM · VyOS Rolling
Viacheslav added a comment to T4487: Create container without downloaded image wrong behavior.

@CuBiC3D There is a comment of the commit https://github.com/vyos/vyos-1x/commit/373227e717fac82af5ea8d71e611a3df1c59054e

Oct 17 2022, 9:23 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T4752: ICMP redirects not working / not properly configured: VyOS 1.3 Equuleus (1.3.3).
Oct 17 2022, 9:08 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Viacheslav closed T4725: Unable to reset vpn IPsec peer as Resolved.
Oct 17 2022, 9:00 AM · VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T4734: Feature Request: openvpn: add OTP 2FA support.
Oct 17 2022, 7:34 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T4752: ICMP redirects not working / not properly configured: VyOS 1.4 Sagitta.
Oct 17 2022, 6:50 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
c-po committed rVYOSONEX288d917b7c87: xdp: T4284: libbpf-dev/libbpf0 is only available for VyOS on amd64.
Oct 17 2022, 6:01 AM
Cheeze_It closed T4739: ISIS and OSPF segment routing being refactored as Unknown Status.
Oct 17 2022, 5:21 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4739: ISIS and OSPF segment routing being refactored.

I am finding out, it seems OSPF SR doesn't work properly :(

Oct 17 2022, 5:19 AM · VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T4754: Improvement: system login: show configured 2FA OTP key.
Oct 17 2022, 12:46 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Unknown Object (User) claimed T4754: Improvement: system login: show configured 2FA OTP key.
Oct 17 2022, 12:45 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Unknown Object (User) created T4754: Improvement: system login: show configured 2FA OTP key.
Oct 17 2022, 12:45 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Unknown Object (User) changed the subtype of T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI from "Task" to "Enhancement".
Oct 17 2022, 12:38 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI.

https://github.com/vyos/vyos-1x/pull/1599

Oct 17 2022, 12:34 AM · VyOS 1.4 Sagitta

Oct 16 2022

MrLenin updated MrLenin.
Oct 16 2022, 11:52 PM
Cheeze_It added a comment to T4739: ISIS and OSPF segment routing being refactored.

Here is ISIS segment routing working:

Oct 16 2022, 10:55 PM · VyOS 1.4 Sagitta
syncer added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

Basically,
all commercial hooks need to be implemented

Oct 16 2022, 10:21 PM · VyOS 1.5 Circinus
syncer raised the priority of T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6) from Wishlist to High.
Oct 16 2022, 10:20 PM · VyOS 1.5 Circinus
c-po committed rVYOSONEXb147c020bae0: xdp: T4284: migrate to Debian libbpf.
Oct 16 2022, 8:04 PM
jestabro renamed T4753: Extend automatic generation of schema to query SystemStatus from Extend automatic generation of shcema to query SystemStatus to Extend automatic generation of schema to query SystemStatus.
Oct 16 2022, 7:25 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4738: Extend automatic generation of schema definition files to native configsession functions; use single resolver/directive: T4753: Extend automatic generation of schema to query SystemStatus.
Oct 16 2022, 7:25 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4753: Extend automatic generation of schema to query SystemStatus: T4738: Extend automatic generation of schema definition files to native configsession functions; use single resolver/directive.
Oct 16 2022, 7:25 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T4753: Extend automatic generation of schema to query SystemStatus.
Oct 16 2022, 7:24 PM · VyOS 1.4 Sagitta
jestabro triaged T4753: Extend automatic generation of schema to query SystemStatus as Normal priority.
Oct 16 2022, 7:24 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX3978dd30e50a: login: 2fa: T874: fix PAM string generation on multiple package installations.
Oct 16 2022, 2:40 PM
thetooth added a comment to T4470: Rewrite load-balancing wan to XML/Python.

I have been thinking about this over the weekend and looked into your failover implementation, there's nothing wrong with it and should serve most peoples needs. That said I am not too good with python so it was more straight forward to start from scratch.

Oct 16 2022, 2:29 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
aderouineau added a comment to T4123: checksum file fails to download from AWS S3 in rolling-release.

I confirm this is still an issue in 1.4-rolling-202207250217 trying to download 1.4-rolling-202210150526:

Oct 16 2022, 3:25 AM · VyOS 1.4 Sagitta

Oct 15 2022

tioan added a comment to T4741: set firewall zone Local local-zone failed.

@SrividyaA
The documentation at https://docs.vyos.io/en/latest/configuration/firewall/zone.html currently contains the following regarding local-zone:

Oct 15 2022, 9:32 PM · VyOS 1.4 Sagitta
CuBiC3D added a comment to T4487: Create container without downloaded image wrong behavior.

Why does the image has to be added manually and can not be pulled from the registry if not locally available?

Oct 15 2022, 5:35 PM · VyOS 1.4 Sagitta
dex created T4752: ICMP redirects not working / not properly configured.
Oct 15 2022, 11:00 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Unknown Object (User) claimed T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI.
Oct 15 2022, 6:57 AM · VyOS 1.4 Sagitta
Unknown Object (User) created T4751: Feature Request: system login: 2FA OTP key generator in VyOS CLI.
Oct 15 2022, 6:13 AM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXf12c0e4f426b: ddclient: T4743: Add option for IPv6 Dynamic DNS.
Oct 15 2022, 4:22 AM
GitHub <noreply@github.com> committed rVYOSONEXec202631ccb8: Merge pull request #1579 from sever-sever/T4743 (authored by Viacheslav).
Oct 15 2022, 4:22 AM
Cheeze_It changed the status of T4739: ISIS and OSPF segment routing being refactored from In progress to Needs testing.
Oct 15 2022, 4:00 AM · VyOS 1.4 Sagitta

Oct 14 2022

dmbaturin committed rVYOSONEXba8099518353: ci: T4748: add a CI action to check pull request title.
Oct 14 2022, 8:49 PM
GitHub <noreply@github.com> committed rVYOSONEX813236e6ca26: Merge pull request #1588 from dmbaturin/pr-title-check (authored by jestabro).
Oct 14 2022, 8:49 PM
jestabro closed T4749: Use config_dict for conf_mode http-api.py as Resolved.
Oct 14 2022, 8:29 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEX1c429074def5: http-api: T4749: transition to config_dict.
Oct 14 2022, 8:29 PM
GitHub <noreply@github.com> committed rVYOSONEX326c43632b94: Merge pull request #1597 from jestabro/http-api-config-dict (authored by jestabro).
Oct 14 2022, 8:29 PM
Viacheslav changed the status of T4533: Radius clients don’t have simple permissions from Open to Needs testing.
Oct 14 2022, 6:30 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav moved T4533: Radius clients don’t have simple permissions from Open to Backport Candidates on the VyOS 1.4 Sagitta board.
Oct 14 2022, 6:24 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX372ccffe5bd1: T4533: Allow basic permissions to unprivileged RADIUS users.
Oct 14 2022, 6:21 PM
GitHub <noreply@github.com> committed rVYOSONEX78f6b2fee6f1: Merge pull request #1598 from sever-sever/T4533 (authored by c-po).
Oct 14 2022, 6:20 PM
c-po committed rVYOSONEX80d258f1ad6d: login: 2fa: T874: remove unused code path for global 1fa settings.
Oct 14 2022, 6:16 PM
Viacheslav added a comment to T4533: Radius clients don’t have simple permissions.

PR https://github.com/vyos/vyos-1x/pull/1598

Oct 14 2022, 6:11 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po committed rVYOSONEXda535ef5697f: login: 2fa: T874: fix Google authenticator issues.
Oct 14 2022, 6:03 PM
jestabro edited a custom field on T4749: Use config_dict for conf_mode http-api.py.
Oct 14 2022, 4:33 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3905: Add NAS-Identifier for system login.

@adaker
Could you describe the check/test procedure, how to test that all works as you expected?

Oct 14 2022, 2:44 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Unknown Object (User) added a comment to T4750: Support of higher level SSH keys (sk-ssh-ed25519).

Ah, yea that is true.
They are enabled by default.

Oct 14 2022, 12:58 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4750: Support of higher level SSH keys (sk-ssh-ed25519).

I mean Linux man https://man7.org/linux/man-pages/man5/sshd_config.5.html

HostKeyAlgorithms
        Specifies the host key signature algorithms that the server
        offers.  The default for this option is:
Oct 14 2022, 12:49 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4750: Support of higher level SSH keys (sk-ssh-ed25519).

What do you mean by "enable by default"?
The issue is that, right now, we are unable to add these kind of ssh keys because the cli won't let you define the type.

Oct 14 2022, 12:38 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4750: Support of higher level SSH keys (sk-ssh-ed25519).

Also, it should be enabled by default (at least in ssh documentation)
Could you check it?

Oct 14 2022, 12:36 PM · VyOS 1.4 Sagitta
Viacheslav closed T4672: RADIUS server disable does not work as Resolved.
Oct 14 2022, 12:32 PM · VyOS 1.4 Sagitta
Unknown Object (User) closed T4750: Support of higher level SSH keys (sk-ssh-ed25519) as Resolved.

My fault. Sorry.

Oct 14 2022, 12:31 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4750: Support of higher level SSH keys (sk-ssh-ed25519).

We already have task T4720

Oct 14 2022, 12:29 PM · VyOS 1.4 Sagitta
Unknown Object (User) edited a custom field on T4750: Support of higher level SSH keys (sk-ssh-ed25519).
Oct 14 2022, 11:57 AM · VyOS 1.4 Sagitta
Unknown Object (User) created T4750: Support of higher level SSH keys (sk-ssh-ed25519).
Oct 14 2022, 11:56 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4725: Unable to reset vpn IPsec peer from In progress to Needs testing.
Oct 14 2022, 9:52 AM · VyOS 1.4 Sagitta
Cheeze_It committed rVYOSONEX57dd8a257052: T4739: ISIS segment routing being refactored.
Oct 14 2022, 9:29 AM
Cheeze_It committed rVYOSONEXe3d66e7eb61c: T4739: OSPF segment routing being refactored.
Oct 14 2022, 9:29 AM
GitHub <noreply@github.com> committed rVYOSONEX427ea592ae8d: Merge pull request #1595 from Cheeze-It/current (authored by c-po).
Oct 14 2022, 9:29 AM
Viacheslav committed rVYOSONEXf089aa624e07: T4725: Fix Regex for correctly reset IPsec peers.
Oct 14 2022, 9:26 AM
GitHub <noreply@github.com> committed rVYOSONEX783f5e24b1c5: Merge pull request #1596 from sever-sever/T4725 (authored by c-po).
Oct 14 2022, 9:26 AM
Viacheslav changed the status of T4725: Unable to reset vpn IPsec peer from Open to In progress.
Oct 14 2022, 8:18 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4725: Unable to reset vpn IPsec peer.

PR https://github.com/vyos/vyos-1x/pull/1596

vyos@r14:~$ show vpn ipsec sa 
Connection         State    Uptime    Bytes In/Out    Packets In/Out    Remote address    Remote ID    Proposal
-----------------  -------  --------  --------------  ----------------  ----------------  -----------  ---------------------------------------
OFFICE-B-tunnel-0  up       4s        0B/0B           0/0               192.0.2.2         192.0.2.2    AES_CBC_256/HMAC_SHA2_256_128/MODP_1024
vyos@r14:~$ 
vyos@r14:~$ 
vyos@r14:~$ reset vpn ipsec-peer OFFICE-B 
closing CHILD_SA OFFICE-B-tunnel-0{16} with SPIs cc364877_i (0 bytes) c521f540_o (0 bytes) and TS 192.168.0.0/24 === 10.0.0.0/21
CHILD_SA {16} closed successfully
generating QUICK_MODE request 1449430238 [ HASH SA No KE ID ID ]
sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (332 bytes)
received packet: from 192.0.2.2[500] to 192.0.2.1[500] (332 bytes)
parsed QUICK_MODE response 1449430238 [ HASH SA No KE ID ID ]
selected proposal: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_1024/NO_EXT_SEQ
CHILD_SA OFFICE-B-tunnel-0{17} established with SPIs cd451e27_i cfb63c3c_o and TS 192.168.0.0/24 === 10.0.0.0/21
generating QUICK_MODE request 1449430238 [ HASH ]
sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (76 bytes)
connection 'OFFICE-B-tunnel-0' established successfully
Peer reset result: success
vyos@r14:~$
Oct 14 2022, 8:18 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4739: ISIS and OSPF segment routing being refactored.

Put in hopefully the last PR for this here, https://github.com/vyos/vyos-1x/pull/1595

Oct 14 2022, 3:01 AM · VyOS 1.4 Sagitta
Cheeze_It renamed T4739: ISIS and OSPF segment routing being refactored from ISIS segment routing being refactored to ISIS and OSPF segment routing being refactored.
Oct 14 2022, 2:58 AM · VyOS 1.4 Sagitta

Oct 13 2022

jestabro changed the status of T4749: Use config_dict for conf_mode http-api.py from Open to In progress.
Oct 13 2022, 8:21 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T2958: DHCP server doesn't work from a live CD from "Task" to "Bug".
Oct 13 2022, 4:03 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav edited projects for T3011: router becomes unreachable for few minutes when vti interfaces goes down, added: VyOS 1.4 Sagitta; removed vyos-frr.
Oct 13 2022, 4:03 PM · VyOS 1.4 Sagitta
Viacheslav closed T3057: Document GRE-Bridge in 1.3 once fixed as Not Applicable.
Oct 13 2022, 4:02 PM · Restricted Project
Viacheslav added a project to T2113: OpenVPN Options error: you cannot use --verify-x509-name with --compat-names or --no-name-remapping: VyOS 1.4 Sagitta.
Oct 13 2022, 3:59 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.3 Equuleus (1.3.7), openvpn
Viacheslav changed the status of T3965: arm: Extend configure scripts to allow for arm builds from Open to Needs testing.
Oct 13 2022, 3:58 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4252: `show configuration json` (op mode) and `show | json` (conf mode) represent multi-value nodes differently: VyOS 1.4 Sagitta.
Oct 13 2022, 3:57 PM · VyOS Rolling, Restricted Project
Viacheslav added a project to T4303: BGP neighbor interface v6only fails to commit: VyOS 1.4 Sagitta.

I can't reproduce this bug with the latest rolling

vyos@r14# run show conf com | match bgp
set protocols bgp address-family ipv4-unicast redistribute connected
set protocols bgp neighbor eth1 interface remote-as '65001'
set protocols bgp neighbor eth1 interface v6only peer-group 'SPING'
set protocols bgp peer-group SPING address-family ipv4-unicast
set protocols bgp peer-group SPING address-family ipv6-unicast
set protocols bgp peer-group SPING capability extended-nexthop
set protocols bgp peer-group SPING password 'foo'
set protocols bgp system-as '65001'
Oct 13 2022, 3:55 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T3909: Add ability to upload scripts via API: VyOS 1.4 Sagitta.
Oct 13 2022, 3:43 PM · VyOS Rolling
Viacheslav added a project to T3905: Add NAS-Identifier for system login: VyOS 1.4 Sagitta.
Oct 13 2022, 3:42 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav closed T3767: SUPPLY CHAIN MANAGEMENT AND as Invalid.
Oct 13 2022, 3:41 PM
Viacheslav changed the status of T3721: ARM64: 1.4: Fastnetmon in current is a precompiled custom "blob" and amd64 only. (blocks all arm64 builds) from Open to Needs testing.
Oct 13 2022, 3:40 PM
Viacheslav added a project to T3652: BGP handshake with cisco router ends in timeout: VyOS 1.4 Sagitta.

@ernstjo Can you reproduce it again?

Oct 13 2022, 3:38 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T3625: Configuring and deletting DHCP Server, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux.
Oct 13 2022, 3:36 PM · VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav changed the subtype of T3501: Allow using more than one tuned profile from "Task" to "Feature Request".
Oct 13 2022, 3:32 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Viacheslav moved T4343: Expose powerdns network-timeout for service dns forwarding from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 13 2022, 3:30 PM · VyOS 1.4 Sagitta
Viacheslav closed T4343: Expose powerdns network-timeout for service dns forwarding as Resolved.
Oct 13 2022, 3:30 PM · VyOS 1.4 Sagitta
Viacheslav moved T4274: Extend OpenConnect RADIUS Timeout to Permit 2FA Entry from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 13 2022, 3:27 PM · VyOS 1.4 Sagitta