Page MenuHomeVyOS Platform

GurliGebis (Bjarke Istrup Pedersen)
User

Projects

User does not belong to any projects.

User Details

User Since
Nov 8 2023, 9:59 AM (24 w, 3 d)

Recent Activity

Wed, Apr 24

GurliGebis added a comment to T6256: Replace deprecated ISC dhcp-relay (EOL) with something else.

So most likely we will have to find another implementation.

Wed, Apr 24, 6:53 PM · VyOS 1.5 Circinus

Mon, Apr 22

GurliGebis added a comment to T6256: Replace deprecated ISC dhcp-relay (EOL) with something else.

I just did a quick search - it doesn't seem like dnsmasq supports option 82 when acting like a relay.

Mon, Apr 22, 10:36 AM · VyOS 1.5 Circinus

Sat, Apr 20

GurliGebis added a comment to T6256: Replace deprecated ISC dhcp-relay (EOL) with something else.

They switched to the OpenBSD fork of dhcrelay (I still have a router running OPNsense to test some stuff) 🙂

Sat, Apr 20, 2:06 PM · VyOS 1.5 Circinus
GurliGebis added a comment to T6256: Replace deprecated ISC dhcp-relay (EOL) with something else.

While I do somewhat agree on that, having more than one to choose from, for everything, is going to be a maintenance nightmare.
If you have just 5 things with 2 packages to choose from, you already have 32 different combinations to support.
Having something else than everyone else sounds great, but again, people are not going to switch due to a vuln being found - they are going to push for a fix for it instead.

Sat, Apr 20, 9:51 AM · VyOS 1.5 Circinus
GurliGebis added a comment to T6256: Replace deprecated ISC dhcp-relay (EOL) with something else.

Depending on how BSD dependent the OpenBSD one is, that might be the easiest drop-in replacement.
Otherwise I would suggest going for dnsmasq, since it is quiet small and well maintained. (not saying the other projects aren't being maintained, but I don't know about them)

Sat, Apr 20, 9:44 AM · VyOS 1.5 Circinus
GurliGebis added a comment to T5755: Running set pki ca NAME certificate with a name with spaces breaks the config.

I just built and tested with the latest sagitta commits, and it is preventing it now as expected.
So I would say it can be closed as fixed, since it has been fixed some time between November and now.

Sat, Apr 20, 9:04 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sun, Apr 7

GurliGebis added a comment to T5873: ipsec remote access VPN: support VTI interfaces.

Great 😃

Sun, Apr 7, 5:49 AM · VyOS 1.5 Circinus

Wed, Apr 3

GurliGebis added a comment to T5873: ipsec remote access VPN: support VTI interfaces.

Just wondering - is it possible to add a vti interface to a zone in the firewall?
How would one go about using this with the zone based firewall? 🙂

Wed, Apr 3, 10:12 PM · VyOS 1.5 Circinus

Jan 29 2024

GurliGebis created T6002: When using git as config-management commit-archive, comment is not used as commit message.
Jan 29 2024, 9:54 PM · VyOS 1.5 Circinus

Jan 12 2024

GurliGebis added a comment to T5928: Configuration fails to load on boot if offloading has VLAN interfaces defined.

I just did a test - without the VLAN interfaces added, the VLAN traffic is still offloaded.
So the CLI should be updated to prevent VLAN's from being added (since it doesn't make any sense to add them, since they work when the parent interface is added)

Jan 12 2024, 9:19 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
GurliGebis added a comment to T5928: Configuration fails to load on boot if offloading has VLAN interfaces defined.

The issue is only on boot, if after booting you run the load command, it loads fine and commit works without any issues.

Jan 12 2024, 3:12 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
GurliGebis added a comment to T5928: Configuration fails to load on boot if offloading has VLAN interfaces defined.

Booting now gives this:

Jan 12 2024, 3:09 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
GurliGebis added a comment to T5928: Configuration fails to load on boot if offloading has VLAN interfaces defined.

Just thinking aloud - could it be the period that is causing issues with the loading?

Jan 12 2024, 2:06 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
GurliGebis created T5928: Configuration fails to load on boot if offloading has VLAN interfaces defined.
Jan 12 2024, 2:00 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Jan 4 2024

GurliGebis added a comment to T3984: Ability to disable all logs.

Mounting a ram disk on top should be pretty easy.
The question is, how much ram should be allocated for this, and how to make sure it doesn't run out of space.
I am no expert in logrotate, but it sounds like it should be able to do it.

Jan 4 2024, 5:58 PM · VyOS 1.5 Circinus

Dec 18 2023

GurliGebis added a comment to T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.

Excellent; thanks @GurliGebis! I built 1.4 today and confirmed it's working as expected.

As far as I'm concerned, this issue is now resolved and the ticket can now be closed.

Dec 18 2023, 9:14 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Dec 15 2023

GurliGebis added a comment to T4502: Consider implementing (NAT/other) flow table offload.

Pull requests for 1.4 backport: https://github.com/vyos/vyos-1x/pull/2641

Dec 15 2023, 11:34 AM · VyOS 1.4 Sagitta

Dec 14 2023

GurliGebis added a comment to T4502: Consider implementing (NAT/other) flow table offload.

I have implemented this - PR: https://github.com/vyos/vyos-1x/pull/2638

Dec 14 2023, 9:24 PM · VyOS 1.4 Sagitta

Dec 9 2023

GurliGebis created T5813: Update from mounted ISO.
Dec 9 2023, 8:10 PM · VyOS 1.5 Circinus
GurliGebis added a comment to T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.

I have create a PR for backporting this to 1.4 : https://github.com/vyos/vyos-1x/pull/2597

Dec 9 2023, 4:27 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Dec 8 2023

GurliGebis added a comment to T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.

@n.fort I have a branch with a backport of this for 1.4 (needs manual changes).

Dec 8 2023, 8:33 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Nov 24 2023

GurliGebis added a comment to T5754: Update to StrongSwan 5.9.11.

Backport to 1.4?

Nov 24 2023, 9:29 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus

Nov 23 2023

GurliGebis added a comment to T5775: Migrated Firewall Global State Policy ineffective on latest firewall zone config.

I agree, without it, you end up repeating yourself alot, with the established, related and invalid rules.
As long as they are applied before the zone specific rules (which is how I guess it used to work), it makes sense.

Nov 23 2023, 11:15 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Nov 18 2023

GurliGebis added a comment to T2405: archive to GIT or other platform .

Can this get backported to 1.4?

Nov 18 2023, 9:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Nov 17 2023

GurliGebis added a comment to T5754: Update to StrongSwan 5.9.11.

Hey @fernando - yes, I tested it with two routers in a test environment, with the following setup: https://docs.vyos.io/en/latest/configuration/vpn/site2site_ipsec.html

Nov 17 2023, 9:29 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus

Nov 16 2023

GurliGebis created T5755: Running set pki ca NAME certificate with a name with spaces breaks the config.
Nov 16 2023, 9:13 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
GurliGebis added a comment to T5754: Update to StrongSwan 5.9.11.

PR: https://github.com/vyos/vyos-build/pull/457

Nov 16 2023, 8:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
GurliGebis created T5754: Update to StrongSwan 5.9.11.
Nov 16 2023, 8:49 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus