Page MenuHomeVyOS Platform
Feed All Stories

Apr 27 2024

syncer closed T6271: Please delete my account as Resolved.

Your account had associated activities so as per GDPR, it was anonymized instead

Apr 27 2024, 9:42 AM
syncer updated the task description for T6271: Please delete my account.
Apr 27 2024, 9:42 AM
anon3fe35 updated anon3fe35.
Apr 27 2024, 9:39 AM
anonuser445y6 updated anonuser445y6.
Apr 27 2024, 9:38 AM
anonuser35hww45 updated anonuser35hww45.
Apr 27 2024, 9:36 AM
syncer reassigned T2192: Create common crypto library for creation/verification/management of RSA/EC/SSH keys, certificates, requests, etc. from syncer to sarthurdev.
Apr 27 2024, 5:26 AM

Apr 26 2024

GitHub <noreply@github.com> committed rVYOSONEXbc5e7ba65b85: Merge pull request #3370 from vyos/mergify/bp/equuleus/pr-3066 (authored by c-po).
Apr 26 2024, 6:54 PM
GitHub <noreply@github.com> committed rVYOSONEXf980f8b8010a: Merge pull request #3365 from vyos/mergify/bp/sagitta/pr-3316 (authored by c-po).
Apr 26 2024, 6:34 PM
c-po committed rVYOSONEXb75e0ba0a297: vyos-hostsd: T4270: resolve only hostname without domain name to 127.0.1.1.
Apr 26 2024, 6:33 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX1b985d2c82ec: vyos-hostsd: T4270: resolve only hostname without domain name to 127.0.1.1 (authored by c-po).
Apr 26 2024, 6:27 PM
Embezzle closed T6259: PKI: Support RFC822 (email) names in SAN as Resolved.

Tested as working in: VyOS 1.5-rolling-202404250020

Apr 26 2024, 6:03 PM · VyOS 1.5 Circinus
sarthurdev changed the status of T6257: Add op mode commands for dynamic firewall address groups from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/3369

Apr 26 2024, 5:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6267: Improve commit failure messages for wireless interface configuration.

PR https://github.com/vyos/vyos-1x/pull/3368

vyos@r4# compare 
[interfaces]
+ wireless wlan0 {
+     address "192.0.2.5/32"
+ }
Apr 26 2024, 3:02 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6269: Polixy route "set table" option is not working correctly.

PR: https://github.com/vyos/vyos-1x/pull/3367

Apr 26 2024, 2:21 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
a.apostoliuk created T6273: Hyphens and underscores are considered invalid in PPPoE access-concentrator names.
Apr 26 2024, 1:44 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav assigned T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS to c-po.
Apr 26 2024, 1:44 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)
a.apostoliuk triaged T6272: PPPoE configuration does not load after deleting a PPPoE interface from the system as High priority.
Apr 26 2024, 1:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav assigned T6271: Please delete my account to syncer.
Apr 26 2024, 1:38 PM
Viacheslav closed T6270: L2TP - Outside address as Wontfix.

It is impossible to set several addresses, but it is possible 0.0.0.0
Limits of the accel-ppp

Apr 26 2024, 1:37 PM · VyOS 1.5 Circinus
a.apostoliuk created T6272: PPPoE configuration does not load after deleting a PPPoE interface from the system.
Apr 26 2024, 1:34 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
anon3fe35 created T6271: Please delete my account.
Apr 26 2024, 1:32 PM
joseph.oshaughnessy created T6270: L2TP - Outside address .
Apr 26 2024, 1:26 PM · VyOS 1.5 Circinus
aga updated aga.
Apr 26 2024, 1:13 PM
Viacheslav triaged T6269: Polixy route "set table" option is not working correctly as Normal priority.
Apr 26 2024, 12:47 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T4529: Backtrace for config-archive when netwofrk is not configured as Not Applicable.

looks good for VyOS 1.5-rolling-202404260019 and VyOS 1.4-stable-202404120309

vyos@r4# set system config-management commit-archive location scp://vyos:vyos@192.168.255.11/tmp/
vyos@r4# 
[edit]
vyos@r4# commit
Archiving config...
  scp://192.168.255.11/tmp/ Unable to upload "scp://vyos:vyos@192.168.255.11/tmp//config.boot-r4.vyos.local.20240426_153518": [Errno 101] Network is unreachable
run-parts: /etc/commit/post-hooks.d/02vyos-commit-archive exited with return code 1
[edit]
vyos@r4#
Apr 26 2024, 12:46 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T6269: Polixy route "set table" option is not working correctly from Open to In progress.
Apr 26 2024, 12:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort created T6269: Polixy route "set table" option is not working correctly.
Apr 26 2024, 12:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav moved T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 26 2024, 12:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)
Viacheslav edited projects for T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS, added: VyOS 1.4 Sagitta (1.4.0-epa3); removed VyOS 1.4 Sagitta.
Apr 26 2024, 12:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)
Viacheslav added a comment to T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS.

It looks working on VyOS 1.5-rolling-202404260019

set system domain-name 'vyos.local'
set system host-name 'r4'
set system static-host-mapping host-name r4.vyos.local inet '100.64.0.14'
Apr 26 2024, 12:05 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)
syncer claimed T6268: Please delete my account.
Apr 26 2024, 10:46 AM
anonuser35hww45 created T6268: Please delete my account.
Apr 26 2024, 9:22 AM
Unknown Object (User) added a comment to T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error.

So if all packages needed are in fact the vyos-build/packages then this should be fairly simple to build and make your own APT repo off of.

Apr 26 2024, 8:49 AM · VyOS 1.4 Sagitta
Apachez added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

Perhaps those changes should be within the firewall context?

Apr 26 2024, 8:09 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
adestis added a comment to T6040: Implement a firewall blacklisting solution.

Hi Giggum,
our previous solution was IPv4 only and not so nice integrated in VyOS,
therefore there are several reasons why a rework is a good idea.

Apr 26 2024, 7:28 AM · VyOS Rolling
Viacheslav added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

Im thinking since sysctl can be changed after the system have completed its boot shouldnt the "system sysctl" be runned among the last tasks according to "/usr/libexec/vyos/priority.py", which would also fix this issue ?

Apr 26 2024, 6:45 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Giggum added a comment to T6040: Implement a firewall blacklisting solution.

@adestis did your previous solution account for non-IP address characters in a given blocklist? For example the https://www.spamhaus.org/drop/dropv6.txt list has a bunch of stuff that would need to be ignored.

Apr 26 2024, 2:06 AM · VyOS Rolling

Apr 25 2024

Apachez added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

Im thinking since sysctl can be changed after the system have completed its boot shouldnt the "system sysctl" be runned among the last tasks according to "/usr/libexec/vyos/priority.py", which would also fix this issue ?

Apr 25 2024, 10:22 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
marekm added a comment to T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error.

If all of this would be done by the build script (download sources, apply patches, build binary packages and copy them to a local filesystem) there would be no problem.
I can't even see the list of packages in that 403 Forbidden repo - all of it blocked completely, not just access to binary packages.

Apr 25 2024, 6:45 PM · VyOS 1.4 Sagitta
syncer added a comment to T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error.

Good.
So, all code is in github.
you need to spend bit of time and learn how to build packages and make them into repo
after you point vyos-build to that repo and good to go
it's time consuming, but once you have set it up, after it will not require that much time

Apr 25 2024, 5:53 PM · VyOS 1.4 Sagitta
Viacheslav moved T6263: Commit failures when trying to set an IGMP group with source address on an interface from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 25 2024, 5:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T6263: Commit failures when trying to set an IGMP group with source address on an interface as Resolved.
Apr 25 2024, 5:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
GitHub <noreply@github.com> committed rVYOSONEX854864f0dffe: Merge pull request #3366 from vyos/mergify/bp/sagitta/pr-3363 (authored by c-po).
Apr 25 2024, 5:45 PM
GitHub <noreply@github.com> committed rVYOSONEX9291c34a301c: Merge pull request #3362 from vyos/mergify/bp/sagitta/pr-3361 (authored by c-po).
Apr 25 2024, 5:37 PM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX7824097396ca: T6263: Groups 224.0.0.0/24 are reserved and cannot be joined (authored by Viacheslav).
Apr 25 2024, 5:37 PM
Viacheslav committed rVYOSONEXc8f9acf5d918: T6263: Groups 224.0.0.0/24 are reserved and cannot be joined.
Apr 25 2024, 5:37 PM
GitHub <noreply@github.com> committed rVYOSONEXaa15f74818ca: Merge pull request #3363 from sever-sever/T6263 (authored by c-po).
Apr 25 2024, 5:37 PM
Viacheslav changed the status of T840: VRRP V3 backup router sending ND RA from Open to Needs testing.
Apr 25 2024, 5:36 PM · VyOS Rolling
Viacheslav added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

@Apachez, there is no easy way to fix anything related to sysctl, until one component depends on another.
Especially, for example, if we have to deal with "dynamic" interfaces.
Globally, this task is still open and could contain subtasks.
Thanks!

Apr 25 2024, 5:24 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav updated subscribers of T6266: Firewall flowtable ability to set timeout for TCP and UDP flow.

Possibly would make sense for CLI to fall under firewall global-options?

Apr 25 2024, 5:07 PM · VyOS Rolling
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX8c5c3bc48f76: qos: T4248: Allow to remove the only rule from the qos class (authored by khramshinr <khramshinr@gmail.com>).
Apr 25 2024, 3:32 PM
khramshinr <khramshinr@gmail.com> committed rVYOSONEXda40bd2b2a82: qos: T4248: Allow to remove the only rule from the qos class.
Apr 25 2024, 3:31 PM
GitHub <noreply@github.com> committed rVYOSONEXb8c5c0c3b74f: Merge pull request #3316 from HollyGurza/T4248 (authored by dmbaturin).
Apr 25 2024, 3:31 PM
Apachez added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

Note that "base_reachable_time_ms" is still valid while "base_reachable_time" is obsolete.

Apr 25 2024, 2:56 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro changed the status of T6206: L2tp smoketest fails if vyos-configd is running from Resolved to Unknown Status.
Apr 25 2024, 2:50 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
jestabro closed T5660: Remove redundant calls to config dependency scripts, a subtask of T4820: Support for inter-config-mode script dependencies, as Unknown Status.
Apr 25 2024, 2:49 PM · VyOS 1.4 Sagitta
jestabro closed T5660: Remove redundant calls to config dependency scripts, a subtask of T5644: Firewall groups deletion can break config, as Unknown Status.
Apr 25 2024, 2:49 PM · VyOS 1.5 Circinus
jestabro closed T5660: Remove redundant calls to config dependency scripts as Unknown Status.
Apr 25 2024, 2:49 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro closed T5839: Remove trivial redundancies in calls to config dependency scripts, a subtask of T5660: Remove redundant calls to config dependency scripts, as Unknown Status.
Apr 25 2024, 2:48 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jestabro closed T5839: Remove trivial redundancies in calls to config dependency scripts as Unknown Status.
Apr 25 2024, 2:48 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev moved T6241: Updating CRL in "pki" config does not update OpenVPN from Open to In Progress on the VyOS 1.5 Circinus board.
Apr 25 2024, 2:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
sarthurdev moved T6241: Updating CRL in "pki" config does not update OpenVPN from Need Triage to In Progress on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 25 2024, 2:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
marekm added a comment to T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error.

OK, so where can I find the source (without the artwork) with the necessary patches and working build scripts (to build from the LTS, not rolling branch - just to be clear)? No problem to use my own CPU cycles and bandwidth and disk space, I can wait longer for the build to finish, sometimes (on sunny days) I even have some free electricity :) - in fact I would even prefer to build the binaries myself (of any packages not directly copied from Debian) rather than trust an external repo. And no problem, you've just got the 868th star from me, I simply didn't know this is something that matters. I have never distributed the LTS images to third parties, just using them internally. Yes, for some small scale production use (single-person business, running a very small local ISP for a few hundreds of customers) as a BGP router and PPPoE server (the latter replacing MikroTik because of their unfinished IPv6 support), not big enough to be able to afford a subscription.

Apr 25 2024, 2:34 PM · VyOS 1.4 Sagitta
dmbaturin placed T861: add secure boot support up for grabs.
Apr 25 2024, 2:22 PM · VyOS Rolling, VyOS 1.5 Circinus
sarthurdev added a comment to T6266: Firewall flowtable ability to set timeout for TCP and UDP flow.

Possibly would make sense for CLI to fall under firewall global-options?

Apr 25 2024, 2:03 PM · VyOS Rolling
sarthurdev claimed T6257: Add op mode commands for dynamic firewall address groups.
Apr 25 2024, 1:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav updated the task description for T6265: Firewall flowtable should allow ethernet only interfaces.
Apr 25 2024, 1:16 PM · VyOS 1.5 Circinus
syncer changed the status of T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error from Invalid to Wontfix.

When we say build from the source, we mean build from the source
see https://blog.vyos.io/community-contributors-userbase-and-lts-builds

Apr 25 2024, 1:12 PM · VyOS 1.4 Sagitta
Viacheslav closed T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error as Invalid.

Stay tuned; check our blog post.

Apr 25 2024, 1:06 PM · VyOS 1.4 Sagitta
SrividyaA triaged T6267: Improve commit failure messages for wireless interface configuration as Normal priority.
Apr 25 2024, 12:16 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav changed the subtype of T6265: Firewall flowtable should allow ethernet only interfaces from "Task" to "Enhancement".
Apr 25 2024, 12:14 PM · VyOS 1.5 Circinus
Viacheslav updated the task description for T6265: Firewall flowtable should allow ethernet only interfaces.
Apr 25 2024, 12:14 PM · VyOS 1.5 Circinus
SrividyaA created T6267: Improve commit failure messages for wireless interface configuration.
Apr 25 2024, 12:12 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav triaged T6266: Firewall flowtable ability to set timeout for TCP and UDP flow as Wishlist priority.
Apr 25 2024, 12:11 PM · VyOS Rolling
Viacheslav created T6266: Firewall flowtable ability to set timeout for TCP and UDP flow.
Apr 25 2024, 12:11 PM · VyOS Rolling
Viacheslav added a comment to T5794: Flowtable with Bond Race.

Allowing only ethernet interface task https://vyos.dev/T6265
After adding check, this task can be closed

Apr 25 2024, 10:47 AM · VyOS Rolling, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
Viacheslav triaged T6265: Firewall flowtable should allow ethernet only interfaces as Normal priority.
Apr 25 2024, 10:46 AM · VyOS 1.5 Circinus
marekm added a comment to T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error.

Sorry about the priority, but it may be quite serious for those who will lose access due to end of program "images for donations" on May 1, and would like to be able to build stable images from source.

Apr 25 2024, 10:04 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

Will be available in the next rolling release.

Apr 25 2024, 9:56 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6263: Commit failures when trying to set an IGMP group with source address on an interface.

PR https://github.com/vyos/vyos-1x/pull/3363

Apr 25 2024, 9:55 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
syncer lowered the priority of T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error from Urgent! to Normal.
Apr 25 2024, 9:44 AM · VyOS 1.4 Sagitta
marekm added a comment to T6249: ISO builder fails because of changed buster-backport repository.

Unfortunately not yet resolved for 1.4 - now reported separately here https://vyos.dev/T6264

Apr 25 2024, 9:43 AM · VyOS 1.3 Equuleus (1.3.6)
marekm triaged T6264: ISO builder fails to build 1.4 because of sagitta-packages repo 403 error as Urgent! priority.
Apr 25 2024, 9:41 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T6263: Commit failures when trying to set an IGMP group with source address on an interface from Open to In progress.
Apr 25 2024, 9:29 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXec94901d7c87: T6258: Add sysctl base-reachable-time for IPv6 (authored by Viacheslav).
Apr 25 2024, 9:16 AM
Viacheslav committed rVYOSONEX0bf4b570fe2d: T6258: Add sysctl base-reachable-time for IPv6.
Apr 25 2024, 9:13 AM
GitHub <noreply@github.com> committed rVYOSONEX13af058504c6: Merge pull request #3361 from sever-sever/T6258 (authored by dmbaturin).
Apr 25 2024, 9:13 AM
Viacheslav added a comment to T6263: Commit failures when trying to set an IGMP group with source address on an interface.

The group 224.0.0.0/24 is reserved

r4(config)# interface eth2
r4(config-if)# ip igmp join 224.0.0.0 224.0.0.10
% Configuration failed.
Apr 25 2024, 8:53 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

PR https://github.com/vyos/vyos-1x/pull/3361

vyos@r4# set interfaces ethernet eth2 ipv6 base-reachable-time 28
[edit]
vyos@r4# commit
[edit]
vyos@r4# 
[edit]
vyos@r4# sudo sysctl net.ipv6.neigh.eth2.base_reachable_time_ms
net.ipv6.neigh.eth2.base_reachable_time_ms = 28000
[edit]
vyos@r4# 
vyos@r4# cat /proc/sys/net/ipv6/neigh/eth2/base_reachable_time_ms 
28000
[edit]
vyos@r4#
Apr 25 2024, 8:28 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
syncer lowered the priority of T6117: Bug in cloud-init when MTU in network_data.json is set to 'null' from High to Normal.
Apr 25 2024, 8:06 AM · VyOS Rolling, Bugs
syncer closed T6249: ISO builder fails because of changed buster-backport repository as Resolved.
Apr 25 2024, 7:55 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav moved T5833: Not all AFIs are compatible with VRF from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
Apr 25 2024, 7:27 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T5833: Not all AFIs are compatible with VRF as Resolved.
Apr 25 2024, 7:26 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.
Apr 25 2024, 7:15 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
canoziia added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

This sysctl option is deprecated

DEPRECATED PARAMETERS         top

       The base_reachable_time and retrans_time are deprecated.  The
       sysctl command does not allow changing values of these
       parameters.  Users who insist to use deprecated kernel interfaces
       should push values to /proc file system by other means.  For
       example:

       echo 256 > /proc/sys/net/ipv6/neigh/eth0/base_reachable_time

I propose to add new option under interface

set interfaces ethernet eth1 ip[v6] base-reachable-time xxx
Apr 25 2024, 7:09 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

This sysctl option is deprecated https://man7.org/linux/man-pages/man8/sysctl.8.html

DEPRECATED PARAMETERS         top
Apr 25 2024, 7:02 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
canoziia added a comment to T6258: Add IPv6 base-reachable-time option to interfaces.

Hi everyone, I think I found the simplest configuration that can reproduce this problem. If we set up firewall and use this command(set system sysctl parameter net.ipv6.neigh.eth3/2) in configuration at the same time, an error message will show when startup.
This is an example

set firewall
set interfaces ethernet eth0 address 'xxx.xxx.184.32/24'
set interfaces ethernet eth0 hw-id 'xx:xx:xx:xx:xx:50'
set interfaces ethernet eth1 hw-id 'xx:xx:xx:xx:xx:ba'
set interfaces ethernet eth1 vif 2
set interfaces loopback lo
set protocols static route xxx.xxx.0.0/0 next-hop xxx.xxx.184.1
set service ntp allow-client xxxxxx 'xxx.xxx.0.0/0'
set service ntp allow-client xxxxxx '::/0'
set service ntp server xxxxx.tld
set service ntp server xxxxx.tld
set service ntp server xxxxx.tld
set service ssh
set system config-management commit-revisions '100'
set system conntrack modules ftp
set system conntrack modules h323
set system conntrack modules nfs
set system conntrack modules pptp
set system conntrack modules sip
set system conntrack modules sqlnet
set system conntrack modules tftp
set system console device ttyS0 speed '115200'
set system host-name xxxxxx
set system login user xxxxxx authentication encrypted-password xxxxxx
set system sysctl parameter net.ipv6.neigh.eth1/2.base_reachable_time_ms value '14400000'
set system syslog global facility all level 'info'
set system syslog global facility local7 level 'debug'

If delete the first line (set firewall), system will start normally without error message.

Apr 25 2024, 3:46 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 24 2024

marekm added a comment to T6249: ISO builder fails because of changed buster-backport repository.

Meanwhile, trying to build 1.4 fails for a different reason - Debian 12 (bookworm) is still where it was, but sagitta-packages.vyos.net gives a 403 error:

Apr 24 2024, 7:36 PM · VyOS 1.3 Equuleus (1.3.6)
GitHub <noreply@github.com> committed rVYOSONEX018b940f685b: Merge pull request #3360 from vyos/mergify/bp/sagitta/pr-3359 (authored by dmbaturin).
Apr 24 2024, 7:22 PM
Unknown Object (User) added a comment to T6256: Replace deprecated ISC dhcp-relay (EOL) with something else.

So most likely we will have to find another implementation.

Apr 24 2024, 6:53 PM · VyOS Rolling