Page MenuHomeVyOS Platform
Feed All Stories

Nov 16 2023

c-po closed T5738: Extend XML building blocks as Resolved.
Nov 16 2023, 2:43 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
GitHub <[email protected]> committed rVYOSONEXcab0d62af86c: Merge pull request #2496 from vyos/mergify/bp/sagitta/pr-2481 (authored by c-po).
Nov 16 2023, 2:43 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXe0efc61a6ffc: smoketest: Extend HTTP-API tests (authored by Viacheslav).
Nov 16 2023, 2:31 PM
GitHub <[email protected]> committed rVYOSONEX4131b6cb6b63: Merge pull request #2481 from sever-sever/smoketest-api (authored by c-po).
Nov 16 2023, 2:30 PM
Viacheslav committed rVYOSONEX15b5ede2cdd6: smoketest: Extend HTTP-API tests.
Nov 16 2023, 2:30 PM
GitHub <[email protected]> committed rVYOSONEXccf8a0a0466c: Merge pull request #2494 from vyos/mergify/bp/sagitta/pr-2491 (authored by c-po).
Nov 16 2023, 2:17 PM
giuavo added a comment to T5722: Commit failure when trying to add a route in failover if the gateway is not in the same interface network.

I would like to contribute with a PR about this. At the same, time I would need some guidance on identifying the conditions requiring the onlink option to be added.

Nov 16 2023, 1:56 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
JeffWDH added a comment to T3983: show pki certificate Doesnt show x509 certificates.

https://github.com/vyos/vyos-1x/pull/2495

Nov 16 2023, 1:32 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po committed rVYOSONEXbd873274d462: T5747: op-mode add MAC and MTU for show interfaces summary (authored by Viacheslav).
Nov 16 2023, 1:27 PM
a.hajiyev changed the status of T2816: Rewrite IPsec scripts with the new XML/Python approach from Needs testing to In progress.
Nov 16 2023, 1:23 PM · VyOS 1.4 Sagitta
n.fort changed the status of T4072: Feature Request: Firewall on bridge interfaces from Needs testing to In progress.
Nov 16 2023, 1:20 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T1549: ipsec ikev2 multi usergroup roadwarrior configuration.

As I undestand it is possible now to create multiple auth ID's

vyos@r4# set vpn ipsec authentication psk FOO id 
Possible completions:
   <text>               ID used for authentication

Not sure about other options.

Nov 16 2023, 1:18 PM
Viacheslav added a project to T5747: op-mode add MAC VRF and MTU for show interfaces summary: VyOS 1.4 Sagitta.
Nov 16 2023, 1:09 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX59b57b97f80f: T5747: op-mode add MAC and MTU for show interfaces summary (authored by Viacheslav).
Nov 16 2023, 1:06 PM
GitHub <[email protected]> committed rVYOSONEX181c8d5c5715: Merge pull request #2491 from sever-sever/T5747 (authored by c-po).
Nov 16 2023, 1:05 PM
Viacheslav committed rVYOSONEXdc3906f04fbf: T5747: op-mode add MAC and MTU for show interfaces summary.
Nov 16 2023, 1:05 PM
Viacheslav renamed T5747: op-mode add MAC VRF and MTU for show interfaces summary from op-mode add MAC and MTU for show interfaces to op-mode add MAC VRF and MTU for show interfaces summary.
Nov 16 2023, 12:53 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.hajiyev added a comment to T2816: Rewrite IPsec scripts with the new XML/Python approach.

Tested in VyOS 1.4-rolling-202311100309 (AES)

Nov 16 2023, 11:59 AM · VyOS 1.4 Sagitta
GitHub <[email protected]> committed rVYOSONEXc1754c4c0610: Merge pull request #2493 from vyos/mergify/bp/sagitta/pr-2490 (authored by c-po).
Nov 16 2023, 11:30 AM
a.hajiyev added a comment to T2816: Rewrite IPsec scripts with the new XML/Python approach.

Tested in VyOS 1.4-rolling-202311100309 (3DES)

Nov 16 2023, 11:30 AM · VyOS 1.4 Sagitta
Viacheslav closed T5689: FRR 9.0.1 in VyOS current segfaults on show rpki prefix $prefix as Resolved.
Nov 16 2023, 10:31 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav changed the status of T5689: FRR 9.0.1 in VyOS current segfaults on show rpki prefix $prefix from Open to Needs testing.
Nov 16 2023, 10:30 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav closed T5726: HTTPS API image cannot be updated as Resolved.
Nov 16 2023, 9:42 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
a.hajiyev removed a project from T3763: wireguard checks if port already binding: VyOS 1.4 Sagitta.
Nov 16 2023, 8:50 AM · VyOS 1.4 Sagitta
a.hajiyev added a comment to T3763: wireguard checks if port already binding.

In VyOS 1.3.4
Configs:

Nov 16 2023, 8:50 AM · VyOS 1.4 Sagitta
I-n-d-y added a comment to T5745: conntrack-sync: Multiprimary setups for HA/VRRP.

I have a similar setup where I have two VyOS VMs used as VPN routers with some firewalling enabled. Since I use OSPF for dynamic routing I am not able to synchronize the sessions between both routers so in case one VPN router fails the other one can't take over flawlessly. Having conntrack-sync configuration separated from VRRP would be a great benefit.

Nov 16 2023, 8:19 AM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync
a.hajiyev added a comment to T3763: wireguard checks if port already binding.

I tested in VyOS 1.4-rolling-202311100309

Nov 16 2023, 8:16 AM · VyOS 1.4 Sagitta
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXdc80f64212a7: op-mode: vrf: T5150: add "show vrf vni" and "show vrf <name> vni" commands (authored by c-po).
Nov 16 2023, 7:35 AM
c-po committed rVYOSONEX2fb763ffbc5c: op-mode: vrf: T5150: add "show vrf vni" and "show vrf <name> vni" commands.
Nov 16 2023, 7:34 AM
GitHub <[email protected]> committed rVYOSONEXc3d96163b3e6: Merge pull request #2490 from c-po/op-mode-vni-t5150 (authored by c-po).
Nov 16 2023, 7:34 AM
Unknown Object (User) added a comment to T4940: Interface debugging.

https://github.com/vyos/vyos-1x/pull/2492
for equuleus

Nov 16 2023, 4:48 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
a.hajiyev closed T3638: Passwords With Dollar Sign Set Incorrectly as Resolved.
Nov 16 2023, 4:17 AM · VyOS 1.4 Sagitta
a.hajiyev added a comment to T3638: Passwords With Dollar Sign Set Incorrectly.

Tested in VyOS 1.4-rolling-202311100309
Tried with single quotes: ''

Nov 16 2023, 4:01 AM · VyOS 1.4 Sagitta
syncer assigned T5745: conntrack-sync: Multiprimary setups for HA/VRRP to Viacheslav.
Nov 16 2023, 1:20 AM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync
wildebeest52 added a comment to T5742: Define port-group as a oneliner instead of multiline.

This can be done in other areas such as firewall rules already:

Nov 16 2023, 1:14 AM · VyOS 1.5 Circinus
Viacheslav assigned T5748: Tunnel class Interface method get_mac() returns IP address for the tunnel interface to c-po.
Nov 16 2023, 12:09 AM · VyOS 1.5 Circinus
Viacheslav created T5748: Tunnel class Interface method get_mac() returns IP address for the tunnel interface.
Nov 16 2023, 12:09 AM · VyOS 1.5 Circinus

Nov 15 2023

Viacheslav added a comment to T5747: op-mode add MAC VRF and MTU for show interfaces summary.

PR https://github.com/vyos/vyos-1x/pull/2491

vyos@r4# run show interfaces summary 
Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface    IP Address         MAC                VRF        MTU  S/L    Description
-----------  -----------------  -----------------  -------  -----  -----  -------------
dum0         203.0.113.1/32     96:44:ad:c5:a1:a5  default   1500  u/u
eth0         192.168.122.14/24  52:54:00:f1:fd:77  default   1500  u/u    WAN
eth1         192.0.2.1/24       52:54:00:04:33:2b  foo       1500  u/u    LAN-eth1
eth1v10v4    10.10.10.10/24     00:00:5e:00:01:0a  foo       1500  u/u
eth2         -                  52:54:00:40:2e:af  default   1504  u/u    LAN-eth2
eth3         -                  52:54:00:09:a4:b4  default   1500  A/D
eth4         -                  52:54:00:2c:51:09  default   1500  A/D
eth5         -                  52:54:00:f3:1d:e8  default   1500  A/D
lo           127.0.0.1/8        00:00:00:00:00:00  default  65536  u/u
             ::1/128
Nov 15 2023, 11:55 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav claimed T5747: op-mode add MAC VRF and MTU for show interfaces summary.
Nov 15 2023, 10:00 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav created T5747: op-mode add MAC VRF and MTU for show interfaces summary.
Nov 15 2023, 9:58 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
watson.ash added a comment to T5728: Improve compatibility between OpenVPN on VyOS 1.5 and OpenVPN Connect Client.

looks great from my perspective (I've just updated our nodes. Tested on Community Edition client on windows and Connect V3 client on windows and Tunnelblick on Mac all working as expected. (I tested with; 1.5-rolling-202311150738).
nice work!

Nov 15 2023, 9:22 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a project to T5745: conntrack-sync: Multiprimary setups for HA/VRRP: VyOS 1.5 Circinus.
Nov 15 2023, 8:10 PM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync
Viacheslav created T5746: Firewall extend GeoIP match ASN.
Nov 15 2023, 8:10 PM · VyOS 1.5 Circinus
Viacheslav closed T5677: show lldp neighbors generates TypeError when neighbor has no `descr` as Resolved.
Nov 15 2023, 7:53 PM · VyOS 1.5 Circinus
qdrddr created T5745: conntrack-sync: Multiprimary setups for HA/VRRP.
Nov 15 2023, 7:30 PM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync
c-po committed rVYOSONEX101a0f0f003b: pim6: T5733: add missing FRR PIM6 related features.
Nov 15 2023, 7:24 PM
c-po committed rVYOSONEXb9493ce110fb: pim: T5733: incorporate feedback from peer review.
Nov 15 2023, 7:24 PM
c-po committed rVYOSONEXce21078a9835: pim: T5733: fix CLI level of global PIM commands.
Nov 15 2023, 7:24 PM
c-po committed rVYOSONEXc139f40e51c8: igmp: T5736: support per interface "disable" CLI node.
Nov 15 2023, 7:24 PM
c-po committed rVYOSONEX383231dae8c0: igmp: T5736: migrate "protocols igmp" to "protocols pim".
Nov 15 2023, 7:24 PM
c-po committed rVYOSONEX46bb847933c8: pim: T5733: rename watermark-warn -> watermark-warning.
Nov 15 2023, 7:24 PM
c-po committed rVYOSONEXb8bd0a1739c4: pim: T5733: split out XML definitions to be re-used by pim6.
Nov 15 2023, 7:24 PM
c-po committed rVYOSONEX6b44aa069265: pim: T5733: add missing FRR PIM related features.
Nov 15 2023, 7:24 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX00d0984cea30: pim6: T5733: add missing FRR PIM6 related features (authored by c-po).
Nov 15 2023, 7:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXb2d446963680: pim: T5733: incorporate feedback from peer review (authored by c-po).
Nov 15 2023, 7:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXc1279a0faf64: pim: T5733: fix CLI level of global PIM commands (authored by c-po).
Nov 15 2023, 7:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXdb08071f28d0: igmp: T5736: support per interface "disable" CLI node (authored by c-po).
Nov 15 2023, 7:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX234e643d3cd4: igmp: T5736: migrate "protocols igmp" to "protocols pim" (authored by c-po).
Nov 15 2023, 7:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXf42ae2c900a3: pim: T5733: rename watermark-warn -> watermark-warning (authored by c-po).
Nov 15 2023, 7:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXe68d8d7b69d5: pim: T5733: split out XML definitions to be re-used by pim6 (authored by c-po).
Nov 15 2023, 7:22 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXa78037d0c3eb: pim: T5733: add missing FRR PIM related features (authored by c-po).
Nov 15 2023, 7:22 PM
qdrddr added a comment to T5425: enable VRF for conntrack-sync.

Created a related feature request but for VRRP here
https://vyos.dev/T5745

Nov 15 2023, 6:14 PM · VyOS 1.5 Circinus, vyatta-conntrack-sync
Viacheslav moved T5732: generate firewall rule-resequence drops geoip country-code from output from Open to Finished on the VyOS 1.4 Sagitta board.
Nov 15 2023, 5:59 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a project to T5732: generate firewall rule-resequence drops geoip country-code from output: VyOS 1.4 Sagitta.
Nov 15 2023, 5:59 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
qdrddr added a comment to T5044: High Availability in DHCPv6 -ISC DHCP Failover/Kea.

to keep track of this request on git
https://github.com/vyos/vyos-1x/pull/1960

Nov 15 2023, 5:56 PM · VyOS 1.5 Circinus
JeffWDH closed T5661: Add show show ssh dynamic-protection attacker and show log ssh dynamic-protection as Resolved.
Nov 15 2023, 5:56 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.5)
JeffWDH closed T5732: generate firewall rule-resequence drops geoip country-code from output as Resolved.
Nov 15 2023, 5:53 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
JeffWDH added a comment to T5732: generate firewall rule-resequence drops geoip country-code from output.

Fix was merged into 1.4 and 1.5.

Nov 15 2023, 5:53 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEX7b0eaba2d365: Merge pull request #2487 from vyos/mergify/bp/sagitta/pr-2486 (authored by dmbaturin).
Nov 15 2023, 5:49 PM
c-po committed rVYOSONEX9abc02edcc23: pim: T5733: add missing FRR PIM related features.
Nov 15 2023, 5:21 PM
c-po committed rVYOSONEXc5e2c25f8968: pim: T5733: split out XML definitions to be re-used by pim6.
Nov 15 2023, 5:21 PM
c-po committed rVYOSONEX45ea9ed72ee1: pim: T5733: rename watermark-warn -> watermark-warning.
Nov 15 2023, 5:21 PM
c-po committed rVYOSONEXdd13213ae94f: pim: T5733: fix CLI level of global PIM commands.
Nov 15 2023, 5:21 PM
c-po committed rVYOSONEXbc83fb097719: igmp: T5736: migrate "protocols igmp" to "protocols pim".
Nov 15 2023, 5:21 PM
c-po committed rVYOSONEX403d2ffd6e46: pim6: T5733: add missing FRR PIM6 related features.
Nov 15 2023, 5:21 PM
c-po committed rVYOSONEX6ce2ecb10884: igmp: T5736: support per interface "disable" CLI node.
Nov 15 2023, 5:21 PM
c-po committed rVYOSONEX64b4cfc71d40: pim: T5733: incorporate feedback from peer review.
Nov 15 2023, 5:21 PM
GitHub <[email protected]> committed rVYOSONEXe085f3e6c21a: Merge pull request #2476 from c-po/frr-pim-T5733 (authored by c-po).
Nov 15 2023, 5:21 PM
Viacheslav added a project to T3983: show pki certificate Doesnt show x509 certificates: VyOS 1.5 Circinus.
Nov 15 2023, 4:47 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
I-n-d-y added a comment to T5425: enable VRF for conntrack-sync.

I had entered the command as you have suggested and I think it's working somehow.

Nov 15 2023, 4:44 PM · VyOS 1.5 Circinus, vyatta-conntrack-sync
Viacheslav added a comment to T5743: HTTPS API ability to import PKI certificates.

Obviously, it does not work.
https://github.com/sever-sever/vyos-1x/tree/T5743
https://github.com/sever-sever/vyos-1x/commit/e3767cb7deb8c0e8f9be2c452a74dabb537ed89a

Nov 15 2023, 4:34 PM · VyOS 1.5 Circinus
JeffWDH added a comment to T3983: show pki certificate Doesnt show x509 certificates.

This is still an issue in 1.5. I tried importing a cert signed by my own CA and got the same error.

Nov 15 2023, 4:33 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav updated the task description for T5743: HTTPS API ability to import PKI certificates.
Nov 15 2023, 4:23 PM · VyOS 1.5 Circinus
Viacheslav changed the status of T5726: HTTPS API image cannot be updated from Open to Needs testing.
Nov 15 2023, 4:09 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav created T5744: PKI import OpenVPN shared key includess unexpected BEGIN and END.
Nov 15 2023, 4:08 PM · Restricted Project, VyOS 1.5 Circinus
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX67836889216e: T5732: generate firewall rule-resequence drops geoip country-code from output (authored by JeffWDH).
Nov 15 2023, 3:33 PM
GitHub <[email protected]> committed rVYOSONEXaa7a5131a5d1: T5732: generate firewall rule-resequence drops geoip country-code from output (authored by JeffWDH).
Nov 15 2023, 3:33 PM
GitHub <[email protected]> committed rVYOSONEX0cc409787389: Merge pull request #2486 from JeffWDH/current (authored by Viacheslav).
Nov 15 2023, 3:33 PM
GitHub <[email protected]> committed rVYOSONEXf021386b8860: Merge pull request #2474 from vyos/mergify/bp/sagitta/pr-2435 (authored by c-po).
Nov 15 2023, 3:05 PM
GitHub <[email protected]> committed rVYOSONEX8c222c3848fe: Merge pull request #2484 from vyos/mergify/bp/sagitta/pr-2479 (authored by c-po).
Nov 15 2023, 3:04 PM
Viacheslav changed the status of T5732: generate firewall rule-resequence drops geoip country-code from output from Open to In progress.
Nov 15 2023, 1:26 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEX525d3364aa1a: Merge pull request #2485 from vyos/mergify/bp/sagitta/pr-2483 (authored by c-po).
Nov 15 2023, 12:58 PM
JeffWDH added a comment to T5732: generate firewall rule-resequence drops geoip country-code from output.

https://github.com/vyos/vyos-1x/pull/2486

Nov 15 2023, 12:34 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
a.hajiyev closed T1276: dhcp relay + VLAN fails as Resolved.
Nov 15 2023, 12:11 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, test
a.hajiyev closed T5665: radius user not working as Resolved.
Nov 15 2023, 12:09 PM · VyOS 1.4 Sagitta
zsdc added a member for Maintainers: a.hajiyev.
Nov 15 2023, 11:57 AM
n.fort committed rVYOSONEX9e053268355f: T5729: T5590: T5616: backport to sagita fwall marks, fix on firewall logs….
Nov 15 2023, 11:48 AM
GitHub <[email protected]> committed rVYOSONEX5ea97243eb50: Merge pull request #2478 from nicolas-fort/T5729-Sagitta (authored by c-po).
Nov 15 2023, 11:48 AM
Viacheslav created T5743: HTTPS API ability to import PKI certificates.
Nov 15 2023, 11:36 AM · VyOS 1.5 Circinus
Viacheslav moved T5726: HTTPS API image cannot be updated from Open to Finished on the VyOS 1.5 Circinus board.

PR for 1.5
https://github.com/vyos/vyos-1x/pull/2483

Nov 15 2023, 10:02 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta