Page MenuHomeVyOS Platform
Feed All Stories

Oct 26 2023

a-bali added a comment to T5687: Implement ECS settings for PowerDNS recursor.

I would just expose these 3 options as-is.

Oct 26 2023, 1:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
SrividyaA closed T5606: IPSec VPN: Allow multiple CAs certificates as Resolved.
Oct 26 2023, 12:52 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
SrividyaA added a comment to T5606: IPSec VPN: Allow multiple CAs certificates.

Yes, it does. thank you

Oct 26 2023, 12:52 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev closed T3509: No BCP38 for IPv6 on VyOS as Resolved.
Oct 26 2023, 12:49 PM · VyOS 1.4 Sagitta
sarthurdev closed T5558: Update config test to check resulting migrations as Resolved.
Oct 26 2023, 12:48 PM · VyOS 1.5 Circinus
sarthurdev closed T5568: Install image from live ISO always defaults boot to KVM entry as Resolved.
Oct 26 2023, 12:48 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
tfiebig triaged T5689: FRR 9.0.1 in VyOS current segfaults on show rpki prefix $prefix as High priority.
Oct 26 2023, 12:47 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
sarthurdev added a comment to T5606: IPSec VPN: Allow multiple CAs certificates.

@SrividyaA Can you confirm this is working as you expect?

Oct 26 2023, 12:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev closed T4309: Support network/address-groups and ipv6-network/ipv6-address-groups in "conntrack ignore" as Resolved.
Oct 26 2023, 12:41 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a project to T4309: Support network/address-groups and ipv6-network/ipv6-address-groups in "conntrack ignore": VyOS 1.5 Circinus.
Oct 26 2023, 12:41 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev moved T4903: Support IPv6 addresses in "set system conntrack ignore" from Finished to Backlog on the VyOS 1.4 Sagitta board.
Oct 26 2023, 12:40 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev moved T4903: Support IPv6 addresses in "set system conntrack ignore" from Open to Finished on the VyOS 1.5 Circinus board.
Oct 26 2023, 12:40 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a project to T4903: Support IPv6 addresses in "set system conntrack ignore": VyOS 1.5 Circinus.
Oct 26 2023, 12:40 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev closed T4903: Support IPv6 addresses in "set system conntrack ignore" as Resolved.
Oct 26 2023, 12:39 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev added a comment to T5550: Source validation on interface does not work properly.

@a.apostoliuk Can you confirm this is working as expected?

Oct 26 2023, 12:38 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
sarthurdev closed T5571: Firewall does not delete networks from the table raw as Resolved.
Oct 26 2023, 12:37 PM · VyOS 1.5 Circinus
sarthurdev closed T5598: unknown parameter 'nf_conntrack_helper' ignored as Resolved.
Oct 26 2023, 12:36 PM · VyOS 1.5 Circinus
n.fort changed the status of T5681: Interface match - Simplified and unified cli from In progress to Needs testing.
Oct 26 2023, 12:19 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T5643: NAT - Allow interface groups on nat rules from In progress to Needs testing.

This error was already fixed in https://github.com/vyos/vyos-1x/pull/2406

Oct 26 2023, 12:18 PM · VyOS 1.5 Circinus
fernando added a comment to T5357: Policy: BGP communities fail to apply when loaded from config file.

@jvoss thanks to confirm !

Oct 26 2023, 10:53 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
a.apostoliuk closed T5684: services using VRF generates the error "Failed to load BPF prog: 'Operation not permitted'" when the system boots. as Resolved.
Oct 26 2023, 10:42 AM · VyOS 1.3 Equuleus
n.fort added a comment to T5681: Interface match - Simplified and unified cli.

PR for op-mode command that fits new cli: https://github.com/vyos/vyos-1x/pull/2408

Oct 26 2023, 10:26 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5513: Anomalies in show firewall command after refactoring.

PR: https://github.com/vyos/vyos-1x/pull/2408

Oct 26 2023, 10:25 AM · VyOS 1.4 Sagitta
n.fort added a comment to T5564: Both show firewall group and show firewall summary fails.

PR: https://github.com/vyos/vyos-1x/pull/2408

Oct 26 2023, 10:25 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.apostoliuk changed the status of T5688: Create the same view of pool configuration for all accel-ppp services, a subtask of T4085: Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict, from Open to In progress.
Oct 26 2023, 9:56 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
a.apostoliuk changed the status of T5688: Create the same view of pool configuration for all accel-ppp services from Open to In progress.
Oct 26 2023, 9:56 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.apostoliuk added a subtask for T4085: Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict: T5688: Create the same view of pool configuration for all accel-ppp services.
Oct 26 2023, 9:55 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
a.apostoliuk added a parent task for T5688: Create the same view of pool configuration for all accel-ppp services: T4085: Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict.
Oct 26 2023, 9:55 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.apostoliuk created T5688: Create the same view of pool configuration for all accel-ppp services.
Oct 26 2023, 9:54 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.apostoliuk claimed T4085: Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict.
Oct 26 2023, 8:00 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav moved T5683: reverse-proxy pki filenames mismatch from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 26 2023, 7:26 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav closed T5683: reverse-proxy pki filenames mismatch as Resolved.
Oct 26 2023, 7:26 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5684: services using VRF generates the error "Failed to load BPF prog: 'Operation not permitted'" when the system boots. from In progress to Needs testing.
Oct 26 2023, 7:17 AM · VyOS 1.3 Equuleus
Viacheslav closed T5357: Policy: BGP communities fail to apply when loaded from config file as Invalid.
Oct 26 2023, 7:12 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T5687: Implement ECS settings for PowerDNS recursor.

Do you have any idea for CLI?

Oct 26 2023, 7:09 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
a-bali created T5687: Implement ECS settings for PowerDNS recursor.
Oct 26 2023, 5:50 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX6c514d793b73: Merge pull request #2407 from vyos/mergify/bp/sagitta/pr-2405 (authored by Viacheslav).
Oct 26 2023, 2:38 AM
jvoss added a comment to T5357: Policy: BGP communities fail to apply when loaded from config file.

Hi @fernando. I can confirm this behavior is still working correctly after this was merged:

Oct 26 2023, 1:09 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 25 2023

Apachez added a comment to T5686: Loss of connectivity on dhcp enabled ethernet interfaces after abrupt link restarts.

To verify that it isnt something in your 5G modem that triggers this behaviour try to put a L2-switch in between and then simulate a link failure between VyOS and this L2-switch and see how things behaves?

Oct 25 2023, 9:30 PM · VyOS Rolling, Bugs
ishan created T5686: Loss of connectivity on dhcp enabled ethernet interfaces after abrupt link restarts.
Oct 25 2023, 8:24 PM · VyOS Rolling, Bugs
fernando changed the status of T5357: Policy: BGP communities fail to apply when loaded from config file from Open to Needs testing.
Oct 25 2023, 7:39 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
fernando added a comment to T5357: Policy: BGP communities fail to apply when loaded from config file.

I've tested this issues in our lasted rolling-realese , after last commit , it seems works without problems :

vyos@vyos# load test.conf
Loading configuration from 'test.conf'
Load complete. Use 'commit' to make changes effective.
[edit]
vyos@vyos# compare
[policy]
+ route-map TEST {
+     rule 10 {
+         action "permit"
+         set {
+             community {
+                 add "65001:1"
+             }
+             large-community {
+                 add "4200000000:100:1"
+             }
+         }
+     }
+ }
Oct 25 2023, 7:38 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort committed rVYOSONEX51abbc0f1b2c: T5681: Firewall,Nat and Nat66: simplified and standarize interface matcher….
Oct 25 2023, 6:30 PM
GitHub <noreply@github.com> committed rVYOSONEXef55eab3c7cd: Merge pull request #2406 from nicolas-fort/T5681 (authored by c-po).
Oct 25 2023, 6:30 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXc8e81bb9c978: T5683: Fix reverse-proxy PKI filenames mismatch (authored by Viacheslav).
Oct 25 2023, 6:26 PM
Viacheslav committed rVYOSONEX0431f1b32c1f: T5683: Fix reverse-proxy PKI filenames mismatch.
Oct 25 2023, 6:25 PM
GitHub <noreply@github.com> committed rVYOSONEX73eb7777a5d3: Merge pull request #2405 from sever-sever/T5683 (authored by c-po).
Oct 25 2023, 6:25 PM
I-n-d-y added a project to T5679: DHCP relay not working when same interface is used as listen- and downstream-interface: VyOS 1.4 Sagitta.
Oct 25 2023, 3:29 PM
Viacheslav added a project to T5685: Keepalived VRRP prefix is not necessary for the virtual address: VyOS 1.4 Sagitta.
Oct 25 2023, 2:34 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav created T5685: Keepalived VRRP prefix is not necessary for the virtual address.
Oct 25 2023, 2:34 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.apostoliuk updated the task description for T5684: services using VRF generates the error "Failed to load BPF prog: 'Operation not permitted'" when the system boots..
Oct 25 2023, 2:25 PM · VyOS 1.3 Equuleus
a.apostoliuk updated the task description for T5684: services using VRF generates the error "Failed to load BPF prog: 'Operation not permitted'" when the system boots..
Oct 25 2023, 2:25 PM · VyOS 1.3 Equuleus
a.apostoliuk changed the status of T5684: services using VRF generates the error "Failed to load BPF prog: 'Operation not permitted'" when the system boots. from Open to In progress.
Oct 25 2023, 2:23 PM · VyOS 1.3 Equuleus
a.apostoliuk created T5684: services using VRF generates the error "Failed to load BPF prog: 'Operation not permitted'" when the system boots..
Oct 25 2023, 2:22 PM · VyOS 1.3 Equuleus
c-po committed rVYOSONEXa2614284eff7: bridge: T5670: add missing constraint on "member interface" node.
Oct 25 2023, 12:41 PM
GitHub <noreply@github.com> committed rVYOSONEXab98f66de7ee: Merge pull request #2402 from c-po/equuleus-t5670 (authored by dmbaturin).
Oct 25 2023, 12:41 PM
c-po committed rVYOSONEX4d1fc6e91aef: vrf: netns: T3829: T31: priority needs to be after netns.
Oct 25 2023, 12:40 PM
c-po committed rVYOSONEXa0addeeb6b28: smoketest: T3829: rename netns test to match current branch.
Oct 25 2023, 12:40 PM
GitHub <noreply@github.com> committed rVYOSONEXbc65c2d9f9b1: Merge pull request #2401 from c-po/sagitta-t3829-t31 (authored by dmbaturin).
Oct 25 2023, 12:40 PM
GitHub <noreply@github.com> committed rVYOSONEX35cde6f533eb: Merge pull request #2404 from vyos/mergify/bp/sagitta/pr-2323 (authored by dmbaturin).
Oct 25 2023, 12:40 PM
n.fort added a comment to T5681: Interface match - Simplified and unified cli.

PR: https://github.com/vyos/vyos-1x/pull/2406

Oct 25 2023, 12:11 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.hajiyev added a comment to T5665: radius user not working.

Used one of the latest rolling releases.
Configured the Radius server and VyOS

Oct 25 2023, 11:15 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5683: reverse-proxy pki filenames mismatch.

PR https://github.com/vyos/vyos-1x/pull/2405

Oct 25 2023, 10:31 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav changed the status of T5683: reverse-proxy pki filenames mismatch from Open to In progress.
Oct 25 2023, 10:10 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX438eb7ad6a9e: T5497: Add ability to resequence rule numbers for firewall (authored by JeffWDH).
Oct 25 2023, 9:08 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX47d9109d0d49: T5497: Add ability to resequence rule numbers for firewall (authored by JeffWDH).
Oct 25 2023, 9:07 AM
Viacheslav assigned T5676: NAT66 source rule with negation source/destination prefix causes TypeError to n.fort.
Oct 25 2023, 6:22 AM · VyOS 1.5 Circinus
c-po added a comment to T5670: bridge: missing member interface validator.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/2402

Oct 25 2023, 4:48 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5670: bridge: missing member interface validator from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.5) board.
Oct 25 2023, 4:36 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T5670: bridge: missing member interface validator from Open to Finished on the VyOS 1.4 Sagitta board.
Oct 25 2023, 4:36 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jamcole created T5683: reverse-proxy pki filenames mismatch.
Oct 25 2023, 3:23 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
yzguy added a comment to T5643: NAT - Allow interface groups on nat rules.

This is causing smoketests on the nightly builds to fail

Oct 25 2023, 2:06 AM · VyOS 1.5 Circinus
yzguy added a comment to T5676: NAT66 source rule with negation source/destination prefix causes TypeError.
DEBUG - Traceback (most recent call last):
DEBUG -   File "/usr/libexec/vyos/conf_mode/nat66.py", line 127, in <module>
DEBUG -     generate(c)
DEBUG -   File "/usr/libexec/vyos/conf_mode/nat66.py", line 101, in generate
DEBUG -     render(nftables_nat66_config, 'firewall/nftables-nat66.j2', nat, permission=0o755)
DEBUG -   File "/usr/lib/python3/dist-packages/vyos/template.py", line 142, in render
DEBUG -     rendered = render_to_string(template, content, formater, location)
DEBUG -                ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
DEBUG -   File "/usr/lib/python3/dist-packages/vyos/template.py", line 111, in render_to_string
DEBUG -     rendered = template.render(content)
DEBUG -                ^^^^^^^^^^^^^^^^^^^^^^^^
DEBUG -   File "/usr/lib/python3/dist-packages/jinja2/environment.py", line 1301, in render
DEBUG -     self.environment.handle_exception()
DEBUG -   File "/usr/lib/python3/dist-packages/jinja2/environment.py", line 936, in handle_exception
DEBUG -     raise rewrite_traceback_stack(source=source)
DEBUG -   File "/usr/share/vyos/templates/firewall/nftables-nat66.j2", line 28, in top-level template code
DEBUG -     {{ config | nat_rule(rule, 'source', ipv6=True) }}
DEBUG -     ^^^^^^^^^^^^^^^^^^^^^^^^^
DEBUG -   File "/usr/lib/python3/dist-packages/vyos/template.py", line 660, in nat_rule
DEBUG -     return parse_nat_rule(rule_conf, rule_id, nat_type, ipv6)
DEBUG -            ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
DEBUG -   File "/usr/lib/python3/dist-packages/vyos/nat.py", line 58, in parse_nat_rule
DEBUG -     oiface = rule_conf['outbound_interface']['interface_group']
DEBUG -              ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^
DEBUG - TypeError: string indices must be integers, not 'str'
Oct 25 2023, 2:03 AM · VyOS 1.5 Circinus
Apachez added a comment to T5676: NAT66 source rule with negation source/destination prefix causes TypeError.

Plenty of nat66 related errors from last nightly build:

Oct 25 2023, 1:56 AM · VyOS 1.5 Circinus

Oct 24 2023

fernando added a project to T5307: QoS - traffic-class-map services : VyOS 1.5 Circinus.
Oct 24 2023, 8:40 PM · VyOS 1.5 Circinus
fernando added a comment to T5307: QoS - traffic-class-map services .

exactly , i'll give an example of what is the improving (or new cli) , we have a policy where we can mach different DSCPs associate with REAL TIME or VIOCE . Current in our cli , it would be something like this :

Oct 24 2023, 8:36 PM · VyOS 1.5 Circinus
n.fort committed rVYOSONEXa9e93ef54bd3: T5637: Firewall: add new rule at the end of base chains for default-actions..
Oct 24 2023, 6:53 PM
GitHub <noreply@github.com> committed rVYOSONEXcb912e98de3b: Merge pull request #2399 from nicolas-fort/T5637-sagitta (authored by dmbaturin).
Oct 24 2023, 6:53 PM
Viacheslav added a project to T5682: create more robust access controls for sshd and snmpd: VyOS 1.5 Circinus.
Oct 24 2023, 4:33 PM · VyOS Rolling
danhusan created T5682: create more robust access controls for sshd and snmpd.
Oct 24 2023, 4:21 PM · VyOS Rolling
n.fort changed the status of T5681: Interface match - Simplified and unified cli from Open to In progress.
Oct 24 2023, 2:52 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort created T5681: Interface match - Simplified and unified cli.
Oct 24 2023, 2:52 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5564: Both show firewall group and show firewall summary fails.

Using VyOS 1.5-rolling-202310220123.

Oct 24 2023, 2:28 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5675: 'show configuration all' is no different from 'show configuration'.

I think the commit made by yzguy is referencing the wrong task-id.

Oct 24 2023, 2:08 PM · VyOS Rolling, Bugs
n.fort changed the status of T5680: Allow selecting mac-groups in bridge firewall from Open to Confirmed.
Oct 24 2023, 1:21 PM · Restricted Project, VyOS 1.5 Circinus
a.hajiyev added a comment to T4867: "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors.

Checked in VyOS 1.4-rolling-202310030309

Oct 24 2023, 10:30 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T3722: op-mode IPSec show vpn ike sa always shows L-TIME 0: VyOS 1.5 Circinus.
Oct 24 2023, 6:21 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.5 Circinus
a.hajiyev added a comment to T3722: op-mode IPSec show vpn ike sa always shows L-TIME 0.

LEFT router configuration

Oct 24 2023, 6:17 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.5 Circinus
Viacheslav added a comment to T5307: QoS - traffic-class-map services .

So, do you want to add a new syntax to archive the same behavior that we have for qos policy ?

Oct 24 2023, 6:16 AM · VyOS 1.5 Circinus
Viacheslav closed T5198: Firewall global settings no showing as Invalid.

The global state-policy was dropped from CLI.
Close it for now.

Oct 24 2023, 6:07 AM · VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX94c98a787172: T5643: nat: add interface-groups to nat. Use same cli structure for interface… (authored by n.fort).
Oct 24 2023, 4:19 AM
n.fort committed rVYOSONEX2f2c3fa22478: T5643: nat: add interface-groups to nat. Use same cli structure for interface….
Oct 24 2023, 4:17 AM
GitHub <noreply@github.com> committed rVYOSONEX90bcb2f96f32: Merge pull request #2355 from nicolas-fort/T5643 (authored by c-po).
Oct 24 2023, 4:17 AM

Oct 23 2023

fernando added a comment to T5337: MPLS/BGP: Route leak does not happen from the VPNv4 table to specific vrf.

this case was resolved lasted configuration done .

Oct 23 2023, 7:51 PM · VyOS 1.4 Sagitta
fernando closed T5337: MPLS/BGP: Route leak does not happen from the VPNv4 table to specific vrf as Resolved.
Oct 23 2023, 7:51 PM · VyOS 1.4 Sagitta
ishan created T5680: Allow selecting mac-groups in bridge firewall .
Oct 23 2023, 7:36 PM · Restricted Project, VyOS 1.5 Circinus
fernando added a comment to T5307: QoS - traffic-class-map services .

this task is a re-definition from a traffic class , I think it could be more clear if we separate tc-filter in a class-map , so we can define different profiles in our cli based on services :

Oct 23 2023, 7:28 PM · VyOS 1.5 Circinus
I-n-d-y created T5679: DHCP relay not working when same interface is used as listen- and downstream-interface.
Oct 23 2023, 7:24 PM
n.fort closed T5637: Firewall default-action log as Resolved.

For RQ for Sagitta: https://github.com/vyos/vyos-1x/pull/2399

Oct 23 2023, 4:58 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <noreply@github.com> committed rVYOSONEXb15dbec9b5df: Merge pull request #2397 from vyos/mergify/bp/sagitta/pr-2395 (authored by dmbaturin).
Oct 23 2023, 3:12 PM