Page MenuHomeVyOS Platform

cwadge (Chris Wadge)
User

Projects

User does not belong to any projects.

User Details

User Since
Nov 13 2017, 9:38 PM (336 w, 10 h)

Recent Activity

Jan 18 2019

cwadge added a comment to T422: Packages server and downloads should be available via HTTPS.

I didn't notice that this was still open, I can confirm the HTTPS method works as expected from VyOS 1.1.8 and later.

Jan 18 2019, 12:24 AM · Infrastructure

Oct 24 2018

cwadge added a comment to T902: VyOS 1.2.0-rc2 fails to load configuration when conntrack modules are disabled in config.

Interestingly, disabling particular modules works fine in 1.1.8 regardless of whether NAT or firewall policies were in place.

Oct 24 2018, 4:51 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Oct 22 2018

cwadge added a comment to T902: VyOS 1.2.0-rc2 fails to load configuration when conntrack modules are disabled in config.

It seems that in RC3 no conntrack settings work at all, causing the configuration loading to fail. For instance,

Oct 22 2018, 11:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Oct 21 2018

cwadge added a comment to T902: VyOS 1.2.0-rc2 fails to load configuration when conntrack modules are disabled in config.

I'll try to repro on RC3 and update the ticket from there. Thanks!

Oct 21 2018, 4:45 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Oct 14 2018

cwadge added a comment to T902: VyOS 1.2.0-rc2 fails to load configuration when conntrack modules are disabled in config.

Changed description, as this is also present in RC2.

Oct 14 2018, 7:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
cwadge added a comment to T901: Vyatta firewall service (vyatta-router.service) times out with zone-based policies.

Do you experience this now? How many rules / what hardware may I ask?

Oct 14 2018, 7:00 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc4)
cwadge renamed T902: VyOS 1.2.0-rc2 fails to load configuration when conntrack modules are disabled in config from VyOS 1.2.0-rc1 fails to load configuration when conntrack modules are disabled in config to VyOS 1.2.0-rc2 fails to load configuration when conntrack modules are disabled in config.
Oct 14 2018, 6:46 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
cwadge created T902: VyOS 1.2.0-rc2 fails to load configuration when conntrack modules are disabled in config.
Oct 14 2018, 6:45 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
cwadge created T901: Vyatta firewall service (vyatta-router.service) times out with zone-based policies.
Oct 14 2018, 6:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc4)

Dec 19 2017

cwadge added a comment to T422: Packages server and downloads should be available via HTTPS.

Awesome. :) Let me know if you ever need an extra pair of hands on the infrastructure front.

Dec 19 2017, 8:17 PM · Infrastructure
cwadge added a comment to T422: Packages server and downloads should be available via HTTPS.

If you can at least get a strong hash sum of the ISO from the master, that should be sufficient regardless of where the binary is downloaded from. Of course, if the master is compromised, all bets are off.

Dec 19 2017, 8:08 PM · Infrastructure
cwadge added a comment to T422: Packages server and downloads should be available via HTTPS.

This begs the question about the mirror mechanism. My mirror supports TLS, but most don't.

Dec 19 2017, 7:56 PM · Infrastructure

Dec 16 2017

cwadge added a comment to T429: Pi-Hole or similar feature.

Sorry for the unsolicited feedback, but... BUT... ;-) Honestly, I think the way the Pi-Hole stack is put together does not lend itself well to a firmware-like platform like VyOS. In fact, personally I can't even suggest it for anything more than home use. Frankly, it's a bit cludgy on the back-end. Further, it increases the potential attack surface of your router, which is in general bad security practice. IMO the best course, even if by some twist of fate Pi-Hole WAS integrated into VyOS, would be to run Pi-Hole as a separate service. DNS is one of those things that's easy to run alongside routers; there's no compelling reason I can think of to run it ON the router. Buy a $35 Pi, run a tiny VM on existing hardware, etc. and serve that DNS server to DHCP clients via VyOS. That's my $0.02, adjusted for inflation.

Dec 16 2017, 11:11 AM · Rejected

Nov 28 2017

cwadge added a comment to V5: Should we keep web proxy functionality in base 1.2/1.3/2.0?.

Web proxies are relatively complex by nature and offer an attractive attack surface. I don't like having such software on routers at all, even if they are properly maintained. Better to relegate this functionality to a system which is external to the router.

Nov 28 2017, 11:34 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
cwadge triaged T455: Add haveged package as Wishlist priority.
Nov 28 2017, 4:10 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc4)

Nov 13 2017

cwadge created T455: Add haveged package.
Nov 13 2017, 10:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc4)