Page MenuHomeVyOS Platform
Feed All Stories

Jul 28 2023

jestabro closed T5317: configtree: remove mutable references, a subtask of T5316: configtree: use a single pass of the diff algorithm, as Resolved.
Jul 28 2023, 4:49 PM · VyOS 1.4 Sagitta
jestabro closed T5317: configtree: remove mutable references as Resolved.
Jul 28 2023, 4:49 PM · VyOS 1.4 Sagitta
jestabro closed T5316: configtree: use a single pass of the diff algorithm as Resolved.
Jul 28 2023, 4:49 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXe310cb6e194b: configtree: T5316: use single-pass to drop trim function.
Jul 28 2023, 4:40 PM
zsdc changed the status of T5410: Improve `utils.convert.convert_data()` to process all stdtypes from Open to In progress.

PR: https://github.com/vyos/vyos-1x/pull/2117

Jul 28 2023, 2:45 PM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5413: Deny the opportunity to use one public/private key pair on both wireguard peers. from Open to In progress.
Jul 28 2023, 1:50 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
a.apostoliuk triaged T5413: Deny the opportunity to use one public/private key pair on both wireguard peers. as Normal priority.
Jul 28 2023, 1:50 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav closed T5401: Using load config restarts containers every time as Invalid.

You skip this warning and delte version number line

// Warning: Do not remove the following line
// vyos-config-version: "bgp@4:broadcast-relay@1:cluster@1:config-management@1:conntrack@3:conntrack-sync@2:container@1:dhcp-relay@2:dhcp-server@6:dhcpv6-server@1:dns-dynamic@1:dns-forwarding@4:firewall@10:flow-accounting@1:https@4:ids@1:interfaces@29:ipoe-server@1:ipsec@12:isis@3:l2tp@4:lldp@1:mdns@1:monitoring@1:nat@5:nat66@1:ntp@2:openconnect@2:ospf@2:policy@5:pppoe-server@6:pptp@2:qos@2:quagga@11:rip@1:rpki@1:salt@1:snmp@3:ssh@2:sstp@4:system@26:vrf@3:vrrp@4:vyos-accel-ppp@2:wanloadbalance@3:webproxy@2"
// Release version: 1.4-rolling-202307090317
Jul 28 2023, 10:31 AM · VyOS 1.4 Sagitta
m4rcu5 closed T4602: DHCP `ping-check` enabled by default as Resolved.

I've recently migrated from a PCEngines APU2C4 to a Wyse 5070 with a X520 card, as well as upgrading to VyOS 1.4-rolling-202305081003
After which I was unable to reproduce this issue. Roaming now works fine without the ICMP check.

Jul 28 2023, 10:28 AM · VyOS 1.4 Sagitta

Jul 27 2023

c-po committed rVYOSONEX2015717bdc87: T5411: add additional monitor log targets.
Jul 27 2023, 8:04 PM
jestabro added a subtask for T4820: Support for inter-config-mode script dependencies: T5412: Add support for extending config-mode dependencies in supplemental package.
Jul 27 2023, 6:58 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T5412: Add support for extending config-mode dependencies in supplemental package: T4820: Support for inter-config-mode script dependencies.
Jul 27 2023, 6:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro added a subtask for T5403: Add support for extending xml cache : T5412: Add support for extending config-mode dependencies in supplemental package.
Jul 27 2023, 6:56 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T5412: Add support for extending config-mode dependencies in supplemental package: T5403: Add support for extending xml cache .
Jul 27 2023, 6:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jestabro triaged T5412: Add support for extending config-mode dependencies in supplemental package as Normal priority.
Jul 27 2023, 6:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po changed the status of T5411: Remove old background monitoring implementation, a subtask of T3355: Remove all remaining legacy Vyatta code, from Open to In progress.
Jul 27 2023, 6:52 PM · VyOS Rolling
c-po changed the status of T5411: Remove old background monitoring implementation from Open to In progress.
Jul 27 2023, 6:52 PM · VyOS 1.4 Sagitta
c-po created T5411: Remove old background monitoring implementation.
Jul 27 2023, 6:52 PM · VyOS 1.4 Sagitta
Viacheslav closed T5368: FastNetmon service ids ddos-protection add support sflow mode as Resolved.
Jul 27 2023, 6:00 PM · VyOS 1.4 Sagitta
zsdc created T5410: Improve `utils.convert.convert_data()` to process all stdtypes.
Jul 27 2023, 4:20 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXbd4bb4f869d6: T5368: service ids ddos-protection add support sflow mode.
Jul 27 2023, 4:10 PM
GitHub <noreply@github.com> committed rVYOSONEXb76f103317b5: Merge pull request #2105 from sever-sever/T5368 (authored by dmbaturin).
Jul 27 2023, 4:10 PM
a.apostoliuk changed the status of T5409: Add 'set interfaces wireguard wgX threaded' from Open to In progress.
Jul 27 2023, 3:01 PM · VyOS 1.4 Sagitta
a.apostoliuk created T5409: Add 'set interfaces wireguard wgX threaded'.
Jul 27 2023, 3:00 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXfe821df79b74: T5258: git Actions use ubuntu-22.04 for PR conflicts checker.
Jul 27 2023, 2:41 PM
GitHub <noreply@github.com> committed rVYOSONEXc91089b40866: Merge pull request #2115 from sever-sever/T5258-eq (authored by dmbaturin).
Jul 27 2023, 2:41 PM
SrividyaA committed rVYOSONEXf0a630cce26a: T5127: vpnv4/vpnv6 : warning for router-id.
Jul 27 2023, 2:12 PM
GitHub <noreply@github.com> committed rVYOSONEXef6cc1f32566: Merge pull request #2114 from srividya0208/T5252 (authored by c-po).
Jul 27 2023, 2:12 PM
jestabro added a comment to T5403: Add support for extending xml cache .

PR:
https://github.com/vyos/vyos-1x/pull/2116

Jul 27 2023, 1:23 PM · VyOS 1.4 Sagitta
n.fort claimed T5406: "update webproxy blacklists" fails when vrf is being configured.
Jul 27 2023, 10:11 AM · VyOS 1.4 Sagitta
sarthurdev added a comment to T5404: Ability to completely disable firewall/conntrack.

It is a bug that it’s on by default, see other task. Will be fixed after new firewall refactor is merged.

Jul 27 2023, 9:31 AM · VyOS 1.4 Sagitta
c-po added a comment to T4974: OpenVPN- Data Channel Offload(DCO).

From the VyOS documentation and https://community.openvpn.net/openvpn/wiki/DataChannelOffload

Jul 27 2023, 9:26 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5404: Ability to completely disable firewall/conntrack.

Then how come conntrack modules are loaded (and there is content in the ruleset "sudo nft -s list ruleset") when I have no firewall rules configured?

Jul 27 2023, 9:25 AM · VyOS 1.4 Sagitta
c-po added a comment to T4974: OpenVPN- Data Channel Offload(DCO).

CLI adjusted to:

Jul 27 2023, 9:23 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX3de59f1365e5: wwan: T3795: remove superfluous call to set_level().
Jul 27 2023, 9:18 AM
c-po committed rVYOSONEX32b9ac3653fa: openvpn: T4974: move CLI node "enable-dco" -> "offload dco" to match other….
Jul 27 2023, 9:18 AM
c-po committed rVYOSONEX341a84240e6d: openvpn: T4974: restructure get_config().
Jul 27 2023, 9:18 AM
Viacheslav awarded T5403: Add support for extending xml cache a Like token.
Jul 27 2023, 9:06 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5404: Ability to completely disable firewall/conntrack.

Conntrack should be disabled by default https://vyos.dev/T5080

Jul 27 2023, 9:03 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5408: 15-16 tacacs folders under /home directory.

It is not a bug.
It is the implementation of TACACS authentication https://github.com/vyos/vyos-1x/pull/2038
https://github.com/vyos/vyos-1x/blob/fa07179ae7f1dc07e6ccc1b20d2b81384b6efe07/debian/vyos-1x.postinst#L47-L52

Jul 27 2023, 8:56 AM · VyOS 1.4 Sagitta
a.hajiyev created T5408: 15-16 tacacs folders under /home directory.
Jul 27 2023, 8:00 AM · VyOS 1.4 Sagitta
jvoss created T5407: Static routes pointed to container networks fail to persist after reboot.
Jul 27 2023, 2:53 AM · VyOS 1.4 Sagitta
Apachez created T5406: "update webproxy blacklists" fails when vrf is being configured.
Jul 27 2023, 2:43 AM · VyOS 1.4 Sagitta
Apachez created T5405: Add VRF support for "update geoip".
Jul 27 2023, 2:37 AM · VyOS Rolling
Apachez created T5404: Ability to completely disable firewall/conntrack.
Jul 27 2023, 2:24 AM · VyOS 1.4 Sagitta

Jul 26 2023

c-po closed T4974: OpenVPN- Data Channel Offload(DCO) as Resolved.
Jul 26 2023, 9:15 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXfa07179ae7f1: openvpn: T4974: dynamically load/unload kernel module.
Jul 26 2023, 9:14 PM
c-po committed rVYOSONEX9e0a9b7df3d7: openvpn: T4974: do not automatically load the DCO module.
Jul 26 2023, 8:29 PM
c-po closed T5365: Container systemd units require authentication as Resolved.
Jul 26 2023, 7:47 PM · VyOS 1.4 Sagitta
jestabro changed the status of T5403: Add support for extending xml cache from Open to In progress.
Jul 26 2023, 6:51 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5399: "show ntp" fails when vrf is being configured.

Tested and verified as described in the pull request:

Jul 26 2023, 5:55 PM · VyOS 1.4 Sagitta
Apachez added a comment to rVYOSONEX5f2e9cb81d89: T5154: NTP: allow maximum of one ipv4 and one ipv6 address on parameter <listen….

Oh, and the reason for why using chrony instead of ntpsec is?

Jul 26 2023, 5:52 PM
n.fort added a comment to rVYOSONEX5f2e9cb81d89: T5154: NTP: allow maximum of one ipv4 and one ipv6 address on parameter <listen….

Why this limit?

Example: I have 5 interfaces and want to let NTP-clients sync to my VyOS device on 3 of them (which is their default gateway on each network).

With this change this wont be possible unless I enable firewall rules or am I missing something here?

Jul 26 2023, 5:45 PM
Apachez added a comment to rVYOSONEX5f2e9cb81d89: T5154: NTP: allow maximum of one ipv4 and one ipv6 address on parameter <listen….

Why this limit?

Jul 26 2023, 5:00 PM
n.fort committed rVYOSONEX5f2e9cb81d89: T5154: NTP: allow maximum of one ipv4 and one ipv6 address on parameter <listen….
Jul 26 2023, 4:50 PM
GitHub <noreply@github.com> committed rVYOSONEXfc35434bfb0d: Merge pull request #2078 from nicolas-fort/T5154 (authored by Viacheslav).
Jul 26 2023, 4:50 PM
jack9603301 added a comment to T5341: Improve CLI for high-availability virtual-server to work with multiple ports.
Jul 26 2023, 4:49 PM · VyOS 1.4 Sagitta
n.fort added a comment to T5399: "show ntp" fails when vrf is being configured.

Thanks for testing and submitting PR

Jul 26 2023, 1:37 PM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5402: VRRP router with rfc3768-compatibility sends multiple ARP replies from Open to In progress.
Jul 26 2023, 12:17 PM · VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
a.apostoliuk created T5402: VRRP router with rfc3768-compatibility sends multiple ARP replies .
Jul 26 2023, 12:17 PM · VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav closed T5398: FRR mangles container network interface names as Resolved.
Jul 26 2023, 12:01 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5399: "show ntp" fails when vrf is being configured from Open to Needs testing.
Jul 26 2023, 12:01 PM · VyOS 1.4 Sagitta
Apachez committed rVYOSONEXb3eaa3c11a37: T5399: VRF-support for show ntp.
Jul 26 2023, 11:48 AM
GitHub <noreply@github.com> committed rVYOSONEX6a1a687f8b8f: Merge pull request #2112 from Apachez-/T5399 (authored by c-po).
Jul 26 2023, 11:48 AM
Apachez added a comment to T5399: "show ntp" fails when vrf is being configured.

Pull request created: https://github.com/vyos/vyos-1x/pull/2112

Jul 26 2023, 9:51 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5399: "show ntp" fails when vrf is being configured.

There is this line in the code https://github.com/vyos/vyos-1x/blob/688755a988e233e221bf920e391e35d5ddc9cb56/src/op_mode/show_ntp.sh#L21

Jul 26 2023, 7:56 AM · VyOS 1.4 Sagitta
yzguy added a comment to T5401: Using load config restarts containers every time.

https://github.com/vyos/vyos-1x/pull/2111

Jul 26 2023, 4:32 AM · VyOS 1.4 Sagitta
yzguy created T5401: Using load config restarts containers every time.
Jul 26 2023, 3:11 AM · VyOS 1.4 Sagitta
yzguy updated subscribers of T5365: Container systemd units require authentication.

@c-po just added the sudo on a live box to test the changes and I can confirm that fixes it. No auth prompt when doing a load config.
Now I did notice that every time I do a load config it runs that migration script which stops/starts the container which is not ideal.

Jul 26 2023, 2:23 AM · VyOS 1.4 Sagitta

Jul 25 2023

Apachez added a comment to T5399: "show ntp" fails when vrf is being configured.

I can confirm that altering line 21 as suggested fixes this issue.

Jul 25 2023, 11:29 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5398: FRR mangles container network interface names from Open to Needs testing.
Jul 25 2023, 9:28 PM · VyOS 1.4 Sagitta
jvoss committed rVYOSONEX20ac831df73a: static: T5398: do not mangle interface names in FRR.
Jul 25 2023, 9:26 PM
GitHub <noreply@github.com> committed rVYOSONEX688755a988e2: Merge pull request #2110 from jvoss/frr_static_interface_mangle (authored by c-po).
Jul 25 2023, 9:26 PM
c-po added a comment to T4974: OpenVPN- Data Channel Offload(DCO).

We probably wan't to load/unload the Kernel Module given what the user want's to do

Jul 25 2023, 9:15 PM · VyOS 1.4 Sagitta
c-po closed T5377: ospf: add graceful restart FRR feature (RFC 3623) as Resolved.
Jul 25 2023, 9:13 PM · VyOS 1.4 Sagitta
jvoss claimed T5398: FRR mangles container network interface names.

https://github.com/vyos/vyos-1x/pull/2110

Jul 25 2023, 9:05 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5116: Better VRF support.

Out of the blue it seems like "network namespaces" would solve alot of current VRF compatability issues within VyOS:

Jul 25 2023, 8:34 PM · VyOS Rolling
c-po committed rVYOSONEXc473f6475f90: container: T5365: ensure container mogration systemd steps are run with sudo.
Jul 25 2023, 8:21 PM
jestabro triaged T5400: Move libvyosconfig build out of the Docker image as Wishlist priority.
Jul 25 2023, 8:00 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
zsdc committed rVYOSONEX494729145397: remote: T4412: Improved error handling for uploads/downloads.
Jul 25 2023, 7:48 PM
GitHub <noreply@github.com> committed rVYOSONEX8966841cdfe7: Merge pull request #2109 from zdc/T4412-sagitta (authored by c-po).
Jul 25 2023, 7:47 PM
Apachez added a comment to T5371: "system name-server" is not vrf aware.

Workaround until "system name-server" becomes vrf aware seems to be to change context into vrf INTERNET and then do a ping with VRF syntax like so:

Jul 25 2023, 7:42 PM · VyOS Rolling, Bugs
Apachez added a comment to T5374: Ability to set 24-hour time format.

I would vote for:

Jul 25 2023, 7:40 PM · VyOS 1.4 Sagitta
1vivy added a comment to T5387: dhcp6c: add a no release option.

PR: https://github.com/vyos/vyos-1x/pull/2108
PR: https://github.com/vyos/vyos-build/pull/372

Jul 25 2023, 6:32 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
1vivy changed the status of T5387: dhcp6c: add a no release option from Open to Confirmed.
Jul 25 2023, 6:28 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
n.fort added a comment to T5399: "show ntp" fails when vrf is being configured.

Can you check changing

Jul 25 2023, 5:07 PM · VyOS 1.4 Sagitta
yzguy updated the task description for T5365: Container systemd units require authentication.
Jul 25 2023, 4:13 PM · VyOS 1.4 Sagitta
yzguy updated the task description for T5365: Container systemd units require authentication.
Jul 25 2023, 4:06 PM · VyOS 1.4 Sagitta
yzguy updated the task description for T5365: Container systemd units require authentication.
Jul 25 2023, 4:05 PM · VyOS 1.4 Sagitta
yzguy updated the task description for T5365: Container systemd units require authentication.
Jul 25 2023, 3:54 PM · VyOS 1.4 Sagitta
yzguy updated the task description for T5365: Container systemd units require authentication.
Jul 25 2023, 3:50 PM · VyOS 1.4 Sagitta
yzguy updated the task description for T5365: Container systemd units require authentication.
Jul 25 2023, 3:38 PM · VyOS 1.4 Sagitta
Apachez created T5399: "show ntp" fails when vrf is being configured.
Jul 25 2023, 3:35 PM · VyOS 1.4 Sagitta
yzguy updated the task description for T5365: Container systemd units require authentication.
Jul 25 2023, 3:21 PM · VyOS 1.4 Sagitta
yzguy updated the task description for T5365: Container systemd units require authentication.
Jul 25 2023, 3:18 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5398: FRR mangles container network interface names.

@jvoss Add the PR, please
Thanks.

Jul 25 2023, 1:55 PM · VyOS 1.4 Sagitta
jvoss added a comment to T5398: FRR mangles container network interface names.

Spot on Viacheslav! That absolutely resolved the issue, thanks! I was initially thinking it might have been the key_mangling option. Glad to see there is another option here.

Jul 25 2023, 1:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5398: FRR mangles container network interface names.

Try to add no_tag_node_value_mangle there https://github.com/vyos/vyos-1x/blob/20b7155f4140f54cf7669256160b6fedd8c1ab7a/src/conf_mode/protocols_static.py#L50

Jul 25 2023, 1:11 PM · VyOS 1.4 Sagitta
Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Doing some more digging it turned out that VyOS doesnt support nested routing so the gateway must be reachable (at least IP-address wise) through a physical interface - I have updated the script in the original post to adjust for that (added variable GATEWAY).

Jul 25 2023, 1:04 PM · VyOS Rolling, Bugs
Viacheslav added a comment to T5222: Add load-balancing reverse-proxy based on haproxy .

@dongjunbo It requires more tests and reviews

Jul 25 2023, 12:59 PM · VyOS 1.4 Sagitta