Page MenuHomeVyOS Platform

Apachez (Apachez)
User

Projects

User does not belong to any projects.

User Details

User Since
Jul 2 2023, 10:05 PM (34 w, 6 d)

Recent Activity

Yesterday

Apachez added a comment to T6088: Configuration corrupted after saving and powercut or force reboot.

Instead of that sysrq stuff, how does it work if you try these 3 tests?

Sat, Mar 2, 1:12 PM · VyOS 1.3 Equuleus (1.3.7)

Fri, Mar 1

Apachez added a comment to T6085: VTI interfaces are in UP state by default.

If the peer reconnects after the first disconnect - does the local VTI interface go "UP" again?

Fri, Mar 1, 10:19 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Tue, Feb 27

Apachez added a comment to T5080: Conntrack enabled by default.

How do one re-open? :-)

Tue, Feb 27, 5:00 PM · VyOS 1.4 Sagitta
Apachez added a comment to T6073: Conntrack/NAT not being disabled when VRFs are defined.

Similar task:

Tue, Feb 27, 4:59 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T6071: firewall: CLI description limit of 256 characters cause config upgrade issues.

While at it having a description for a firewall rule within the firewall itself thats longer than 256 is just "wrong" IMHO aka "you are doing it wrong".

Tue, Feb 27, 9:15 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Mon, Feb 26

Apachez added a comment to T5619: Update the Intel ixgbe driver due to issues with Intel X533.

Unfortunately I haven't seen this before, for me this choice of using the out-of-tree driver is extremely wrong!

Most of the community's development is done on the mainline kernel driver (where among other things I'm working on sending patches to improve the ixgbe driver), if there are issues in the mainline driver they should be reported or resolved with a patch to be applied in vyos downstream and then send it to the Intel-wired-lan mailing list.

Please @samip537 can you tell me in a short list what exactly problems you encounter with the mainline Linux driver?

Mon, Feb 26, 6:06 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sat, Feb 24

Apachez added a comment to T5388: Something is fishy with commit and boot times when more than a few hundred static routes are being used.

Adding https://forum.vyos.io/t/quick-and-dirty-benchmark-of-cores-vs-mhz/13831/ for reference which also concludes that something is off with the commit and boot times of VyOS.

Sat, Feb 24, 12:10 PM · VyOS 1.4 Sagitta

Mon, Feb 19

Apachez added a comment to T5549: Result of system audit by Lynis.

Its mainly a headsup for maintainers to go through the report and fix whats possible.

Mon, Feb 19, 8:25 AM · VyOS 1.4 Sagitta

Sat, Feb 3

Apachez added a comment to T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.

Its not clear if its fixed or not:

Sat, Feb 3, 4:26 PM · VyOS 1.4 Sagitta (1.4.0-epa), Restricted Project

Jan 28 2024

Apachez created T5995: Kernel NIC-drivers for Huawei NICs are not properly enabled.
Jan 28 2024, 12:55 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Jan 27 2024

Apachez added a comment to T5990: Intel 25G E810 kernel ice driver does not work with LLDP.

Same as with https://vyos.dev/T5619.

Jan 27 2024, 2:04 PM · VyOS 1.3 Equuleus (1.3.7)

Jan 23 2024

Apachez added a comment to T5979: Add configurable kernel boot parameters.

Related?

Jan 23 2024, 4:30 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Jan 20 2024

Apachez added a comment to T5572: Add capability for sending Gratuitous ARP (GARP) and the equal for IPv6.

Again, notifing upstream (or downstream) is not only about VRRP.

Jan 20 2024, 9:55 AM · VyOS 1.5 Circinus
Apachez added a comment to T5572: Add capability for sending Gratuitous ARP (GARP) and the equal for IPv6.

GARP is needed for VRRP but the GARP setting is also needed when doing NAT.

Jan 20 2024, 9:24 AM · VyOS 1.5 Circinus
Apachez added a comment to T3984: Ability to disable all logs.

Logrotate just renames the logs so that doesnt bring many writes.

Jan 20 2024, 9:12 AM · VyOS 1.4 Sagitta

Jan 18 2024

Apachez added a comment to T5509: Add capability to add firewall rules similar to CoPP through VyOS configuration.
set firewall auto-ruleset ssh-server enable
set firewall auto-ruleset ssh-server interface 'eth7 eth8'
Jan 18 2024, 9:25 PM · VyOS 1.4 Sagitta

Jan 17 2024

Apachez added a comment to T5835: UPnP port mapping / rule installation fails.

Personally I would prefer that the "automagic" firewall ruleset would be done optionally through method described in:

Jan 17 2024, 11:51 AM · VyOS 1.4 Sagitta (1.4.0-epa), VyOS 1.5 Circinus

Jan 16 2024

Apachez added a comment to T5940: [1.3.5 -> 1.4.0-RC1 Migration] commit-archive Fails to Migrate.

Another good thing is that any logging can be done without spoling the user/pass which otherwise is the case with todays oneliner approach.

Jan 16 2024, 11:45 AM · VyOS 1.4 Sagitta (1.4.0-epa)
Apachez created T5950: Communicate with UPS for monitoring and clean shutdown.
Jan 16 2024, 4:51 AM · VyOS 1.5 Circinus
Apachez created T5949: Disable USB autosuspend.
Jan 16 2024, 4:08 AM · VyOS 1.5 Circinus

Jan 10 2024

Apachez added a comment to T3984: Ability to disable all logs.

Could for example be that set system options logtoram enables the feature while set system options logtoram size 32M sets the desired size where the default is 32M or whatever would be needed as a sane minimum.

Jan 10 2024, 12:40 AM · VyOS 1.4 Sagitta

Jan 9 2024

Apachez added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

On the other hand I would expect someone aka the admin who will configure an enterprise firewall such as VyOS could be called to have at least SOME basic knowledge and also some interest to read the documentation on how to configure the firewall.

Jan 9 2024, 11:01 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Jan 7 2024

Apachez added a comment to T5898: Replace partprobe with partx due to unable to install VyOS.

How come partprobe fails but not partx?

Jan 7 2024, 5:42 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Jan 6 2024

Apachez added a comment to T5902: http: remove virtual-host configuration in webserver.

Having support for vhost is handy when you dont want just to blindly share a single documentroot but have the ability to use multiple at a single host.

Jan 6 2024, 10:50 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Jan 5 2024

Apachez added a comment to T5593: Further shrink VyOS imagesize.

Hopefully this can be resolved for VyOS 2.0 in the future...

Jan 5 2024, 1:01 PM · VyOS 2.0.x
Apachez added a comment to T5622: Command 'add system upgrade' uses local script instead of updated script provided by ISO.

Hopefully this can be resolved for VyOS 2.0 in the future...

Jan 5 2024, 1:01 PM · VyOS 2.0.x

Jan 4 2024

Apachez added a comment to T3984: Ability to disable all logs.
set system options logtoram
Jan 4 2024, 5:53 PM · VyOS 1.4 Sagitta

Jan 1 2024

Apachez added a comment to T5881: IPv6 addresses jumbled in flow accounting.

Yes but "2602:fcad:2:fffe:5054:ff" is a valid host in your case?

Jan 1 2024, 7:14 AM · VyOS 1.4 Sagitta (1.4.0-epa), VyOS 1.3 Equuleus (1.3.7)

Dec 31 2023

Apachez added a comment to T5881: IPv6 addresses jumbled in flow accounting.

You mean that for SRC_IP you expect it to be "2602:fcad:2:fffe:5054:ff" and not "14d:63f:2602:fcad:2:fffe:5054:ff" ?

Dec 31 2023, 11:36 PM · VyOS 1.4 Sagitta (1.4.0-epa), VyOS 1.3 Equuleus (1.3.7)
Apachez added a comment to T5879: tunnel: sourceing from dynamic pppoe0 interface will fail on reboots.

Related to the list provided in https://vyos.dev/T5706 ?

Dec 31 2023, 12:25 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Dec 27 2023

Apachez added a comment to T5860: Enhance strip-private to output more readable config.

Instead of "TEST-NET-X" and "TEST-IP-X" it could use "REPLACED-NET-X" and "REPLACED-IP-X" or such (where X defines the unique item thats being replaced).

Dec 27 2023, 11:03 AM · VyOS 1.5 Circinus
Apachez created T5860: Enhance strip-private to output more readable config.
Dec 27 2023, 11:01 AM · VyOS 1.5 Circinus

Dec 25 2023

Apachez added a comment to T5566: Be able to disable 802.3az/EEE (energy efficient ethernet) for a particular interface.

I think its a bit odd to completely disable EEE where the solution would be to disable EEE by default but having the config option to adjust for EEE if wanted.

Dec 25 2023, 12:13 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Dec 20 2023

Apachez added a comment to T5835: UPnP port mapping / rule installation fails.

Also while at it, the smoketests regarding UPnP should probably be updated by this task aswell since they claim everything is OK:

Dec 20 2023, 9:37 AM · VyOS 1.4 Sagitta (1.4.0-epa), VyOS 1.5 Circinus

Dec 13 2023

Apachez added a comment to T5822: Integration for Secure60 SIEM.

Wouldnt this rather be a task for secure60 to add compatability to parse and understand snmp and syslog received from a VyOS device?

Dec 13 2023, 8:34 AM · VyOS 1.5 Circinus

Dec 12 2023

Apachez added a comment to T5818: interface name mixup at boot (same PCI address).

"hw-id" should define which physical interface is mapped to which ethX VyOS interface.

Dec 12 2023, 3:08 PM · VyOS 1.4 Sagitta

Dec 3 2023

Apachez added a comment to T5759: Change VXLAN default MTU to 1500 bytes.

Wouldnt this break things with compatibility with other vendors?

Dec 3 2023, 11:25 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Nov 18 2023

Apachez added a comment to T5757: Embedded: Allow ethernet names lanX, wan, sfpX.

I agree, even if its "odd" at first sight I like that all interfaces are named ethX within VyOS and then its a matter to map each to physical interface by hw-id (which is done automagically during first install but can be remapped if wanted).

Nov 18 2023, 2:06 PM · VyOS 1.5 Circinus
Apachez added a comment to T5757: Embedded: Allow ethernet names lanX, wan, sfpX.

Does all the interfaces at bananapi represent a hw-id which can be used to map to the ethX syntax of VyOS?

Nov 18 2023, 4:03 AM · VyOS 1.5 Circinus

Nov 15 2023

Apachez created T5742: Define port-group as a oneliner instead of multiline.
Nov 15 2023, 4:11 AM · VyOS 1.5 Circinus

Nov 14 2023

Apachez added a comment to T5167: Add a simple file server.

The fear of having the HTTP-API part of nginx compromised by another virtualhost config (as in they are sharing the same process) should be overcome by having a dedicated config file and start a 2nd nginx process.

Nov 14 2023, 12:36 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Nov 13 2023

Apachez added a comment to T5167: Add a simple file server.

I would vote for that (using nginx as backend since it already exists).

Nov 13 2023, 12:10 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Nov 12 2023

Apachez added a comment to T5167: Add a simple file server.

Instead of "file-server" I think "http-server" would be a better name or even "web-server" in this context.

Nov 12 2023, 3:05 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Nov 10 2023

Apachez created T5730: Add ability for VyOS to sendmail.
Nov 10 2023, 2:01 PM · VyOS 1.5 Circinus

Nov 8 2023

Apachez closed T5693: Adding variable vyos_persistence_dir (and improve variable vyos_rootfs_dir) as Resolved.

Verified with VyOS 1.5-rolling-202311081451.

Nov 8 2023, 6:06 PM · VyOS 1.5 Circinus

Nov 6 2023

Apachez added a comment to T5471: Conntrack logging doesnt seem to be working.

I would mainly want to log new conntrack entries for various reasons.

Nov 6 2023, 9:27 PM · VyOS 1.4 Sagitta

Nov 4 2023

Apachez added a comment to T5713: strip-private doesn't strip string after "secret".

Do you have any example of in which context that exists?

Nov 4 2023, 6:44 PM · VyOS 1.5 Circinus
Apachez added a comment to T5706: Systemd-udevd high CPU utilization for multiple dynamic ppp/l2tp/ipoe interfaces .

In that PR, shouldnt also ifb* be included?

Nov 4 2023, 1:37 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Nov 3 2023

Apachez added a comment to T5706: Systemd-udevd high CPU utilization for multiple dynamic ppp/l2tp/ipoe interfaces .

Shouldnt dummy* and some others be excluded aswell?

Nov 3 2023, 9:48 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5698: EVPN ESI Multihoming.

@shthead: Im talking about features in VyOS. I dont care what others such as Juniper does or doesnt do.

Nov 3 2023, 12:51 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Nov 2 2023

Apachez added a comment to T5698: EVPN ESI Multihoming.

@shthead: Yes but when it comes to multihoming there are some additional settings that should exist aswell:

Nov 2 2023, 8:40 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 29 2023

Apachez added a comment to T5698: EVPN ESI Multihoming.

Both single-active and all-active should be supported when it comes to EVPN Multihoming.

Oct 29 2023, 1:36 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez created T5696: Make it possible to shutdown/suspend/disable VLAN 1.
Oct 29 2023, 5:54 AM · VyOS 1.5 Circinus

Oct 28 2023

Apachez added a comment to T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.

Original template /usr/share/vyos/templates/chrony/chrony.conf.j2 (just the allow and listen sections):

Oct 28 2023, 3:51 AM · VyOS 1.5 Circinus
Apachez added a comment to T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.

Turns out that the output of bindaddress will be broken unless put in a loop even if a single entry the only allowed entry.

Oct 28 2023, 3:26 AM · VyOS 1.5 Circinus
Apachez claimed T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.
Oct 28 2023, 3:04 AM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

Since the root cause for this task have been identified and fixed by the reporting user (and the task is set to invalid) I have created another task for the spinoff regarding cleaning up of the template used by chronyd:

Oct 28 2023, 3:03 AM · VyOS 1.5 Circinus
Apachez created T5694: NTP should always be allowed from localhost and bindaddress/binddevice can only exist once.
Oct 28 2023, 3:01 AM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

As it seems according to https://manpages.debian.org/bookworm/chrony/chrony.conf.5.en.html both bindaddress and binddevice can only be specified once.

Oct 28 2023, 2:51 AM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

Ahh yes, I think there is another task in here regarding adding firewall rules by default to the firewall to avoid situations like this :-)

Oct 28 2023, 2:38 AM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

I added the above modifications to /usr/share/vyos/templates/chrony/chrony.conf.j2 and rebooted VyOS 1.5-rolling-202310240118.

Oct 28 2023, 2:36 AM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

I havent been using ninja2 scripting previously but Im guessing something like this would be needed:

Oct 28 2023, 2:01 AM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

Here is the output of sudo ls -la /run/chrony (just booted up so drift will probably missing for some time):

Oct 28 2023, 1:47 AM · VyOS 1.5 Circinus
Apachez added a comment to T5595: Multicast - PIM bfd feature enable .

Any docs or example on how bfd interacts with pim?

Oct 28 2023, 1:24 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Oct 27 2023

Apachez added a comment to T5690: Change to definition of environment variable 'vyos_rootfs_dir' is incorrect.

PR created: https://github.com/vyos/vyatta-op/pull/79

Oct 27 2023, 4:09 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5693: Adding variable vyos_persistence_dir (and improve variable vyos_rootfs_dir).

PR created: https://github.com/vyos/vyatta-op/pull/79

Oct 27 2023, 4:07 PM · VyOS 1.5 Circinus
Apachez added a comment to T5691: `show ntp` not working.

How is your current ntp configuration (as outputed by show config commands)?

Oct 27 2023, 3:12 PM · VyOS 1.5 Circinus
Apachez added a comment to T5686: Loss of connectivity on dhcp enabled ethernet interfaces after abrupt link restarts.

I would still recommend you to try to test to put a L2-switch between your 5G-router and the VyOS box and see if that resolves the situation.

Oct 27 2023, 3:06 PM · VyOS 1.5 Circinus
Apachez claimed T5693: Adding variable vyos_persistence_dir (and improve variable vyos_rootfs_dir).
Oct 27 2023, 2:39 PM · VyOS 1.5 Circinus
Apachez created T5693: Adding variable vyos_persistence_dir (and improve variable vyos_rootfs_dir).
Oct 27 2023, 2:39 PM · VyOS 1.5 Circinus
Apachez added a comment to T5690: Change to definition of environment variable 'vyos_rootfs_dir' is incorrect.

One way however to make the variable more robust in case there are for whatever reason more than one squashfs mounted object available is to select the one who is "loop0".

Oct 27 2023, 2:30 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5690: Change to definition of environment variable 'vyos_rootfs_dir' is incorrect.

Looking through https://vyos.dev/T5457 I now get what you meant by "re-broke it".

Oct 27 2023, 2:23 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5690: Change to definition of environment variable 'vyos_rootfs_dir' is incorrect.

But before the revert by T5690 today T5440 worked perfectly fine so what was "re-broken"?

Oct 27 2023, 2:16 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5690: Change to definition of environment variable 'vyos_rootfs_dir' is incorrect.

So in short https://vyos.dev/T5440 will be broken again?

Oct 27 2023, 10:37 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5686: Loss of connectivity on dhcp enabled ethernet interfaces after abrupt link restarts.

Does your 5G-modem do any NAT on its own or does it just forward the DHCP to the ISP?

Oct 27 2023, 4:35 AM · VyOS 1.5 Circinus

Oct 26 2023

Apachez added a comment to T5687: Implement ECS settings for PowerDNS recursor.

For the record.

Oct 26 2023, 5:18 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 25 2023

Apachez added a comment to T5686: Loss of connectivity on dhcp enabled ethernet interfaces after abrupt link restarts.

To verify that it isnt something in your 5G modem that triggers this behaviour try to put a L2-switch in between and then simulate a link failure between VyOS and this L2-switch and see how things behaves?

Oct 25 2023, 9:30 PM · VyOS 1.5 Circinus
Apachez added a comment to T5676: NAT66 source rule with negation source/destination prefix causes TypeError.

Plenty of nat66 related errors from last nightly build:

Oct 25 2023, 1:56 AM · VyOS 1.5 Circinus

Oct 24 2023

Apachez added a comment to T5564: Both show firewall group and show firewall summary fails.

Using VyOS 1.5-rolling-202310220123.

Oct 24 2023, 2:28 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez added a comment to T5675: 'show configuration all' is no different from 'show configuration'.

I think the commit made by yzguy is referencing the wrong task-id.

Oct 24 2023, 2:08 PM · VyOS 1.5 Circinus

Oct 22 2023

Apachez added a comment to T5673: Enable `CONFIG_DEBUG_INFO_DWARF5` and `CONFIG_DEBUG_INFO_BTF` in the Linux kernel.

Should debug code really be part of production releases?

Oct 22 2023, 8:48 AM · VyOS 1.4 Sagitta

Oct 21 2023

Apachez claimed T5641: Enable compression of kernel modules.
Oct 21 2023, 3:51 PM · VyOS 1.5 Circinus

Oct 18 2023

Apachez added a comment to T5665: radius user not working.

What if you install the same version again but as a new boot name?

Oct 18 2023, 9:50 AM · VyOS 1.4 Sagitta

Oct 17 2023

Apachez added a comment to T5663: pmacct package contains unwanted data.

Out of the blue it looks like some compile thats gone wrong?

Oct 17 2023, 5:42 PM · VyOS 1.5 Circinus
Apachez added a comment to T5663: pmacct package contains unwanted data.

What is the exact path within the chroot directory?

Oct 17 2023, 4:55 PM · VyOS 1.5 Circinus

Oct 16 2023

Apachez added a comment to T5634: Remove support for Blowfish and DES from OpenVPN.

Still fails:

Oct 16 2023, 2:36 AM · VyOS 1.4 Sagitta

Oct 14 2023

Apachez added a comment to T5653: Command to display fingerprint.

I think it should be included, its often used during generation in Debian among other distros.

Oct 14 2023, 7:52 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Oct 12 2023

Apachez added a comment to T5651: chain FW_CONNTRACK incorrectly use accept as action.

Then this task can be set to closed and invalid :-)

Oct 12 2023, 6:54 PM · VyOS 1.5 Circinus
Apachez added a comment to T5498: fsck during boot doesnt work.

PR updated: https://github.com/vyos/vyos-build/pull/435

Oct 12 2023, 6:46 PM · VyOS 1.4 Sagitta
Apachez reopened T5651: chain FW_CONNTRACK incorrectly use accept as action as "Open".

But the NAT_CONNTRACK and WLB_CONNTRACK chains are never evaluted because FW_CONNTRACK always set action to accept?

Oct 12 2023, 6:18 PM · VyOS 1.5 Circinus
Apachez created T5651: chain FW_CONNTRACK incorrectly use accept as action.
Oct 12 2023, 5:05 PM · VyOS 1.5 Circinus

Oct 10 2023

Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

I assume this will end up in config mode aswell before this task can be set to resolved?

Oct 10 2023, 10:33 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5497: Add ability to resequence rule numbers for firewall.

The syntax seems to have changed from "produce" to "generate" during this task?

Oct 10 2023, 5:46 AM · VyOS 1.4 Sagitta
Apachez attached a referenced file: F3877170: T5549_Lynis_audit_system_231010.txt.gz.
Oct 10 2023, 5:40 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5549: Result of system audit by Lynis.

Updated scan performed on VyOS 1.5-rolling-202310090023 (see attached file).

Oct 10 2023, 5:39 AM · VyOS 1.4 Sagitta
Apachez added a comment to T5471: Conntrack logging doesnt seem to be working.

show conntrack statistics still fails in VyOS 1.5-rolling-202310090023:

Oct 10 2023, 5:28 AM · VyOS 1.4 Sagitta
Apachez closed T5479: Helper leftovers found in nftables (firewall) even with all helpers disabled as Resolved.

Seems to be fixed in VyOS 1.5-rolling-202310090023:

Oct 10 2023, 5:25 AM · VyOS 1.4 Sagitta
Apachez assigned T5559: Selective proxy-arp/proxy-ndp when doing SNAT/DNAT to Viacheslav.
Oct 10 2023, 5:18 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Apachez added a comment to T5564: Both show firewall group and show firewall summary fails.

Problem remains with "N/D" is being used in show firewall groups instead of "None".

Oct 10 2023, 5:15 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Apachez closed T5489: Change to BBR as TCP congestion control, or at least make it an config option as Resolved.

Verified in VyOS 1.5-rolling-202310090023:

Oct 10 2023, 5:03 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta