Page MenuHomeVyOS Platform
Feed All Stories

Mar 14 2023

Viacheslav added a comment to T5085: ospfv3 route-map not applied in FRR configuration.

Will be fixed in the next rolling release

Mar 14 2023, 12:54 PM · VyOS 1.4 Sagitta
pavel_odintsov added a comment to T5086: Integrate hsflowd for sflow accounting.

In pcap mode when sampling is set to value larger then 1 hsflowd uses kernel based sampling available on kernels starting from 3.16

Mar 14 2023, 12:11 PM · VyOS 1.4 Sagitta
pavel_odintsov added a comment to T5086: Integrate hsflowd for sflow accounting.

I think NFLOG and TCP can be dropped for sure.

Mar 14 2023, 11:57 AM · VyOS 1.4 Sagitta
GitHub <[email protected]> committed rVYOSONEXc5ee06af8cb0: Merge pull request #1888 from sever-sever/T5085 (authored by c-po).
Mar 14 2023, 11:50 AM
Viacheslav committed rVYOSONEXadd5eaeecacb: T5085: Fix ipv6 route-map for ospfv3.
Mar 14 2023, 11:50 AM
Viacheslav added a comment to T5086: Integrate hsflowd for sflow accounting.

Jenkins job looks simple

git clone https://github.com/sflow/host-sflow
make deb FEATURES="NFLOG PCAP TCP DBUS SYSTEMD"
Mar 14 2023, 11:47 AM · VyOS 1.4 Sagitta
pavel_odintsov added a comment to T3721: ARM64: 1.4: Fastnetmon in current is a precompiled custom "blob" and amd64 only. (blocks all arm64 builds).

Hello! We have plans to add official ARM64 builds in near future.

Mar 14 2023, 11:44 AM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav added a comment to T5085: ospfv3 route-map not applied in FRR configuration.

PR https://github.com/vyos/vyos-1x/pull/1888

set policy route-map RMAP6 rule 10 action 'deny'
set policy route-map RMAP6 rule 10 match ip address prefix-len '0'
set protocols ospfv3 route-map 'RMAP6'
Mar 14 2023, 11:18 AM · VyOS 1.4 Sagitta
Viacheslav created T5086: Integrate hsflowd for sflow accounting.
Mar 14 2023, 11:01 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5085: ospfv3 route-map not applied in FRR configuration from Open to In progress.
Mar 14 2023, 9:51 AM · VyOS 1.4 Sagitta
hcuk94 added a comment to T1229: Add support for unencrypted L2TPv2 client connections.

Just adding my +1 for this feature, would be very useful.
If I get time in the coming weeks/months I will try and pick up on the analysis where @njh left off.

Mar 14 2023, 8:22 AM · VyOS Rolling
klipz added a comment to T5055: Firewall - Add packet type matcher (pkttype).

@n.fort A quick test of this against latest rolling looks like it's working as expected for general firewall rules:

Mar 14 2023, 1:35 AM · VyOS 1.4 Sagitta
mas90 created T5085: ospfv3 route-map not applied in FRR configuration.
Mar 14 2023, 1:28 AM · VyOS 1.4 Sagitta

Mar 13 2023

Viacheslav committed rVYOSONEX4351d6cebd29: T2516: Exclude veth interfaces from duplex and speed check.
Mar 13 2023, 6:38 PM
GitHub <[email protected]> committed rVYOSONEXc614e8cfd5c2: Merge pull request #1886 from sever-sever/T2516 (authored by c-po).
Mar 13 2023, 6:38 PM
n.fort changed the status of T5050: Firewall - Add options for logging packets from Confirmed to In progress.
Mar 13 2023, 5:51 PM · VyOS 1.4 Sagitta
Solideco added a comment to T5022: VRRP add mail notification.

I agree that the Keepalivd SMTP implementation is lacking authentication.

Mar 13 2023, 4:37 PM · VyOS Rolling, Restricted Project
n.fort changed the status of T5055: Firewall - Add packet type matcher (pkttype) from In progress to Needs testing.
Mar 13 2023, 3:44 PM · VyOS 1.4 Sagitta
marc_s added a comment to T4362: Wan Load Balancing - Can't create routing tables.

@Viacheslav I may be on to something. It's related to the order of execution of the DHCP client exit hook scripts in /etc/dhcp/dhclient-exit-hooks.d.

Mar 13 2023, 3:12 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2516: vyos-container: cannot configure ethernet interface.

PR for 1.4 https://github.com/vyos/vyos-1x/pull/1886

vyos@91800359325b# set interfaces ethernet eth0 address 192.0.2.5/24
[edit]
vyos@91800359325b# commit
[ interfaces ethernet eth0 ]
sudo: unable to resolve host 91800359325b: System error
Mar 13 2023, 1:38 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T2516: vyos-container: cannot configure ethernet interface from Needs testing to In progress.
Mar 13 2023, 1:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a project to T2516: vyos-container: cannot configure ethernet interface: VyOS 1.4 Sagitta.
Mar 13 2023, 1:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
marc_s added a comment to T4362: Wan Load Balancing - Can't create routing tables.

Also see https://forum.vyos.io/t/1-4-rolling-route-table-for-wan-load-balancing-not-created/.

Mar 13 2023, 11:23 AM · VyOS 1.4 Sagitta
a.apostoliuk closed T5074: Show IPSEC SA failed if remote access IKEv2 vpn is used. as Resolved.
Mar 13 2023, 10:18 AM · VyOS 1.4 Sagitta
a.apostoliuk moved T5074: Show IPSEC SA failed if remote access IKEv2 vpn is used. from Open to Finished on the VyOS 1.4 Sagitta board.
Mar 13 2023, 10:17 AM · VyOS 1.4 Sagitta
Viacheslav closed T4973: show dhcp server leases error for lease time 4294967295 as Resolved.
Mar 13 2023, 10:02 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5084: Interfrace negotiation may not work on some platforms.
Mar 13 2023, 9:48 AM · VyOS Rolling, Restricted Project
Viacheslav created T5084: Interfrace negotiation may not work on some platforms.
Mar 13 2023, 9:47 AM · VyOS Rolling, Restricted Project
aserkin added a comment to T5077: routes completely dropped from the node while running L2TP LNS service.

Actually only multihop BGP peers go down. Others are up, but the routes received from them does not go to kernel, so the connectivity drops.
Latest techsupport: https://oc.cpm.ru/index.php/s/Fg9FfoOatihBOrQ
The system was alive more than 12 hours, but crashed the same way as before.

Mar 13 2023, 8:23 AM · Restricted Project

Mar 12 2023

c-po committed rVYOSONEX7d8db105fa7f: Debian: bump compat (debian helper) version 10 -> 12.
Mar 12 2023, 7:29 PM
stepler added a comment to T5080: Disable conntrack by default.

I don't think this ever worked as intended: see T3275#103228, vyos-build PR 185, and T3821.

Mar 12 2023, 3:16 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
penetal created T5083: extend interface schema to include which parameters are required.
Mar 12 2023, 8:56 AM · VyOS Rolling
c-po claimed T5082: container: switch to netavark network stack.
Mar 12 2023, 7:49 AM · VyOS 1.4 Sagitta
c-po created T5082: container: switch to netavark network stack.
Mar 12 2023, 7:49 AM · VyOS 1.4 Sagitta
c-po added a reverting change for rVYOSONEX9ed4113d6c48: Debian: T2216: add netavark dependency for podman containers: rVYOSONEXf4f034283880: Revert "Debian: T2216: add netavark dependency for podman containers".
Mar 12 2023, 7:34 AM
c-po committed rVYOSONEXf4f034283880: Revert "Debian: T2216: add netavark dependency for podman containers".
Mar 12 2023, 7:34 AM
c-po changed the status of T5047: Recreate only a specific container from Open to In progress.
Mar 12 2023, 7:24 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

Mar 11 2023

Cheeze_It claimed T5081: ISIS and OSPF syncronization with IGP-LDP sync.
Mar 11 2023, 10:42 PM · VyOS 1.4 Sagitta
Cheeze_It created T5081: ISIS and OSPF syncronization with IGP-LDP sync.
Mar 11 2023, 10:38 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX75c940e12358: container: T5003: add dependency on fuse-overlayfs.
Mar 11 2023, 10:29 PM
c-po closed T5076: CI/CD: Docker container is bloated by legacy and conflicting dependencies as Resolved.
Mar 11 2023, 10:26 PM · VyOS 1.4 Sagitta
c-po moved T5076: CI/CD: Docker container is bloated by legacy and conflicting dependencies from Open to Finished on the VyOS 1.4 Sagitta board.
Mar 11 2023, 10:26 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXf2f086567a3d: keepalived: T5003: remove Debian default config path from ConditionFileNotEmpty.
Mar 11 2023, 10:18 PM
c-po committed rVYOSONEX9ed4113d6c48: Debian: T2216: add netavark dependency for podman containers.
Mar 11 2023, 8:44 PM
c-po committed rVYOSONEXd59af7458f48: keepalived: T5003: move to Debian upstream version.
Mar 11 2023, 7:42 PM
c-po committed rVYOSONEXfa645fef28ca: Debian: remove python3-pyhumps from build dependencies, provided via pip in….
Mar 11 2023, 7:42 PM
sarthurdev claimed T5080: Disable conntrack by default.
Mar 11 2023, 3:40 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev created T5080: Disable conntrack by default.
Mar 11 2023, 3:39 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 10 2023

c-po committed rVYOSONEX1be5cba3636c: openvpn: xml: T1843: re-use generic username and password building block.
Mar 10 2023, 8:34 PM
c-po committed rVYOSONEX18f0f12d6176: rpki: xml: T3255: re-use generic username building block.
Mar 10 2023, 8:34 PM
c-po committed rVYOSONEX0850cc549b48: system: proxy: xml: T1843: re-use generic username and password building block.
Mar 10 2023, 8:34 PM
c-po updated subscribers of T5022: VRRP add mail notification.

after an internal discussion we came to the conslusion that keepalived SMTP implementation is incomplete (e.g. it lacks authentication). In order to still support your request we think we should enable support of 3rd party configurations placed in e.g. /etc/keepalived/conf.d.

Mar 10 2023, 8:25 PM · VyOS Rolling, Restricted Project
n.fort committed rVYOSONEX16c494c2f136: T5055: Firewall: add packet-type matcher in firewall and route policy.
Mar 10 2023, 8:22 PM
GitHub <[email protected]> committed rVYOSONEX5d4908288931: Merge pull request #1871 from nicolas-fort/T5055 (authored by c-po).
Mar 10 2023, 8:22 PM
c-po moved T4959: Add container registry authentication config for containers from Open to Finished on the VyOS 1.4 Sagitta board.
Mar 10 2023, 8:19 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po changed the status of T4959: Add container registry authentication config for containers from In progress to Needs testing.
Mar 10 2023, 8:19 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T5079: xml: schema extension to support defaultValues on tagNodes from Open to Finished on the VyOS 1.4 Sagitta board.
Mar 10 2023, 8:19 PM · VyOS 1.4 Sagitta
c-po added a project to T5079: xml: schema extension to support defaultValues on tagNodes: VyOS 1.3 Equuleus (1.3.3).
Mar 10 2023, 8:18 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXfe82d86d3e87: container: T4959: add registry authentication option.
Mar 10 2023, 8:17 PM
c-po committed rVYOSONEXb4af532dd531: schema: T5079: extension to support defaultValues on tagNodes.
Mar 10 2023, 8:17 PM
c-po changed Difficulty level from unknown to easy on T5079: xml: schema extension to support defaultValues on tagNodes.
Mar 10 2023, 7:27 PM · VyOS 1.4 Sagitta
c-po changed the status of T5079: xml: schema extension to support defaultValues on tagNodes, a subtask of T4959: Add container registry authentication config for containers, from Open to In progress.
Mar 10 2023, 7:27 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po changed the status of T5079: xml: schema extension to support defaultValues on tagNodes from Open to In progress.
Mar 10 2023, 7:27 PM · VyOS 1.4 Sagitta
c-po created T5079: xml: schema extension to support defaultValues on tagNodes.
Mar 10 2023, 7:27 PM · VyOS 1.4 Sagitta
MartB added a comment to T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).

@sdev just for clarification do you mean "deleted" as in only existing entries but new ones will work or completely deleted?
Im asking because I do use keas global, subnet, pool and class option-data support extensively outside of vyos.
If this would stay/become a part of vyos that would be great!

Mar 10 2023, 5:27 PM · VyOS 1.5 Circinus
c-po committed rVYOSONEX6bfeb43b0cfe: xml: bgp: T5070: split out CLI definitions to include files which can be reused.
Mar 10 2023, 2:56 PM
Viacheslav committed rVYOSONEX9701cbe89dbb: T5058: Fix range_to_regex list argument.
Mar 10 2023, 2:16 PM
GitHub <[email protected]> committed rVYOSONEXeb4d0ac46bf4: Merge pull request #1884 from sever-sever/T5058 (authored by c-po).
Mar 10 2023, 2:16 PM
Viacheslav added a comment to T5058: Extend template filter range_to_regex.

PR https://github.com/vyos/vyos-1x/pull/1884

>>> range_to_regex(['10-20', '22-35', '50'])
'(1\\d|20|2[2-9]|3[0-5]|50)'
>>>
Mar 10 2023, 2:05 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5070: show bgp nexthop unavailable in VRF from Open to Needs testing.
Mar 10 2023, 1:02 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5074: Show IPSEC SA failed if remote access IKEv2 vpn is used. from In progress to Needs testing.
Mar 10 2023, 12:40 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXf28c6531c8f8: graphql: T5068: generate client operations for code generation tools.
Mar 10 2023, 12:28 PM
GitHub <[email protected]> committed rVYOSONEX29d27c392274: Merge pull request #1876 from jestabro/codegen (authored by c-po).
Mar 10 2023, 12:28 PM
Viacheslav changed the status of T4973: show dhcp server leases error for lease time 4294967295 from In progress to Needs testing.

Will be fixed in the next rolling release

Mar 10 2023, 12:02 PM · VyOS 1.4 Sagitta
tfiebig committed rVYOSONEX4cdf1386840e: T5070: Added show bgp martian/show bgp nexthop to bgp in vrf.
Mar 10 2023, 12:01 PM
GitHub <[email protected]> committed rVYOSONEX684b30a16c61: Merge pull request #1880 from ichdasich/add_bgp_nexthop_to_vrf (authored by c-po).
Mar 10 2023, 12:01 PM
Viacheslav committed rVYOSONEX77448e1d5ece: T4973: DHCP server fix output for long leases.
Mar 10 2023, 12:01 PM
GitHub <[email protected]> committed rVYOSONEX284820582938: Merge pull request #1883 from sever-sever/T4973 (authored by c-po).
Mar 10 2023, 12:01 PM
a.apostoliuk committed rVYOSONEX72ef87421bd4: util: T5074: Fixed decoding of certificate value to UTF-8 string.
Mar 10 2023, 12:00 PM
GitHub <[email protected]> committed rVYOSONEXcb8006da2a84: Merge pull request #1882 from aapostoliuk/T5074-sagitta (authored by c-po).
Mar 10 2023, 12:00 PM
tfiebig added a comment to T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes'.

Wanted to have the ticketid to write the right commit message right away. Diff is here: https://github.com/vyos/vyos-1x/compare/current...ichdasich:vyos-1x:filtered_routes

Mar 10 2023, 11:51 AM · VyOS 1.4 Sagitta
tfiebig created T5078: VyOS BGP does not support 'show bgp neighbors $NB filtered-routes'.
Mar 10 2023, 11:50 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5058: Extend template filter range_to_regex.

If we add vlan to range we get error

set service ipoe-server authentication mode 'noauth'
set service ipoe-server client-ip-pool name POOL1 gateway-address '192.0.2.1'
set service ipoe-server client-ip-pool name POOL1 subnet '192.0.2.0/24'
set service ipoe-server interface eth1 vlan '2000-3000'
commit
set service ipoe-server interface eth1 vlan '50'
commit

The second commit:

Mar 10 2023, 10:18 AM · VyOS 1.4 Sagitta
Viacheslav reopened T5058: Extend template filter range_to_regex as "Needs testing".
Mar 10 2023, 10:16 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4925: Need to add the possibility to configure Pseudo-Random Functions (PRF) in IKEv2 from Open to In progress.
Mar 10 2023, 9:35 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk added a project to T4925: Need to add the possibility to configure Pseudo-Random Functions (PRF) in IKEv2: VyOS 1.3 Equuleus (1.3.3).
Mar 10 2023, 9:35 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
a.apostoliuk reopened T4925: Need to add the possibility to configure Pseudo-Random Functions (PRF) in IKEv2 as "Open".
Mar 10 2023, 9:34 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX36fea4cb4956: T5033: Ability to generate muliple keys from a file or link.
Mar 10 2023, 9:21 AM
GitHub <[email protected]> committed rVYOSONEXa3b16a483140: Merge pull request #1859 from sever-sever/T5033-eq (authored by Viacheslav).
Mar 10 2023, 9:21 AM
Viacheslav changed the status of T4973: show dhcp server leases error for lease time 4294967295 from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/1883

Mar 10 2023, 9:20 AM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5074: Show IPSEC SA failed if remote access IKEv2 vpn is used. from Open to In progress.
Mar 10 2023, 8:18 AM · VyOS 1.4 Sagitta
a.apostoliuk claimed T5074: Show IPSEC SA failed if remote access IKEv2 vpn is used..
Mar 10 2023, 8:18 AM · VyOS 1.4 Sagitta
aserkin created T5077: routes completely dropped from the node while running L2TP LNS service.
Mar 10 2023, 7:44 AM · Restricted Project
Viacheslav renamed T4973: show dhcp server leases error for lease time 4294967295 from show dhcp server leases error for static entries to show dhcp server leases error for lease time 4294967295.
Mar 10 2023, 7:12 AM · VyOS 1.4 Sagitta

Mar 9 2023

klipz updated subscribers of T5055: Firewall - Add packet type matcher (pkttype).

@n.fort @Viacheslav
Here is an example of what I am after for DNAT rule, specifically, using meta pkttype:

Mar 9 2023, 7:31 PM · VyOS 1.4 Sagitta
c-po changed the status of T5076: CI/CD: Docker container is bloated by legacy and conflicting dependencies from Open to In progress.
Mar 9 2023, 7:06 PM · VyOS 1.4 Sagitta
c-po created T5076: CI/CD: Docker container is bloated by legacy and conflicting dependencies.
Mar 9 2023, 7:06 PM · VyOS 1.4 Sagitta
c-po closed T4952: Improve interface completion helper CLI experience as Resolved.
Mar 9 2023, 6:43 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXfe4da6288649: xml: T4952: improve interface completion helper CLI experience.
Mar 9 2023, 6:41 PM
sarthurdev committed rVYOSONEX25b64f32a22c: qos: T5018: Fix interface tc qdisc cleanup.
Mar 9 2023, 6:38 PM