Page MenuHomeVyOS Platform

dutty (Petr)
User

Projects

User does not belong to any projects.

User Details

User Since
Oct 3 2021, 7:26 PM (132 w, 4 d)

Recent Activity

Mar 6 2024

dutty added a comment to T6103: DHCP-server bootfile-name double slash syntax weird behaviour.

Yes, boot\x86\wdsnbp.com is a proper filename, and this further correctly translates to double backslash in the dhcp.conf file at /run/dhcp-server/dhcpd.conf, as I noted. Why it is so, explained for example here: https://www.linkedin.com/pulse/quit-thinking-look-matthew-topper
And with such a setting network boot works just fine.
The problem is that after each reboot the vyos configuration scripts, I guess, double the number of backslashes in the config, that further leads to doubling them in the dhcp.conf. And on, and on. This actually breaks the network boot, and manual intervention is required after each router reboot.

Mar 6 2024, 11:29 AM · vyatta-cfg-dhcp-server
dutty created T6103: DHCP-server bootfile-name double slash syntax weird behaviour.
Mar 6 2024, 10:33 AM · vyatta-cfg-dhcp-server

Jan 10 2024

dutty added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

On the other hand I would expect someone aka the admin who will configure an enterprise firewall such as VyOS could be called to have at least SOME basic knowledge and also some interest to read the documentation on how to configure the firewall.

Jan 10 2024, 7:21 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Jan 9 2024

dutty added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

As a side comment, the new firewall system allows more granular control and sometimes may simplify configuration. It follows better the lower level logic of nftables.

Jan 9 2024, 9:57 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dutty added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

Yes, I agree with that, readability will be better if everything is in order.

Jan 9 2024, 9:42 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dutty added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.

@n.fort
Looks like 1) and 2) is correct, as well as 'Action=accept in vyos command shall remain as accept in nftables'.
However, the 3) is not obvious to me. As long as all rules with Action=Accept in both IN and OUT chains will migrate to Action=return, looks like there should be no difference in order, other than probably for performance reason.

Jan 9 2024, 9:33 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Dec 10 2023

dutty added a comment to T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.
Dec 10 2023, 10:42 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dutty created T5814: VyOS 1.3 to 1.4 LTS Firewall ruleset migration script breaks configuration.
Dec 10 2023, 10:24 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Aug 27 2023

dutty created T5517: Equuleus ISO build fails.
Aug 27 2023, 11:55 AM · VyOS 1.3 Equuleus

May 29 2023

dutty added a comment to T5243: Default route is inactive if an interface has multiple ip addresses of the same subnet in 1.3.2 Equuleus.

@zsdc I built the image now, and it works as expected. The issue looks resolved. Thank you.

May 29 2023, 11:43 AM · VyOS 1.3 Equuleus (1.3.3)

May 28 2023

dutty added a comment to T5243: Default route is inactive if an interface has multiple ip addresses of the same subnet in 1.3.2 Equuleus.

Yes, T4737 looks the same.

May 28 2023, 8:06 AM · VyOS 1.3 Equuleus (1.3.3)
dutty added a comment to T5243: Default route is inactive if an interface has multiple ip addresses of the same subnet in 1.3.2 Equuleus.

Maybe the related bug described in T4737
Could you show a version of FRR?

show version all | match frr
May 28 2023, 7:35 AM · VyOS 1.3 Equuleus (1.3.3)

May 27 2023

dutty created T5243: Default route is inactive if an interface has multiple ip addresses of the same subnet in 1.3.2 Equuleus.
May 27 2023, 7:15 PM · VyOS 1.3 Equuleus (1.3.3)

Feb 17 2022

dutty added a comment to T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.

I just built ISO from the 1.3 branch and tried (1.3-rolling-202202171824). ocserv works normal. The issue is probably resolved.
Thank you.

Feb 17 2022, 7:16 PM · VyOS 1.3 Equuleus ( 1.3.1)

Feb 13 2022

dutty added a comment to T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.

@Viacheslav As I said: every rolling version of VyOS 1.3 branch starting from mid-January. I built ISO several times during this month. Last one I tried today (built today). All of them behave like this in my two different routers. Last time ocserv worked was middle of December build.

Feb 13 2022, 5:46 PM · VyOS 1.3 Equuleus ( 1.3.1)
dutty updated the task description for T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.
Feb 13 2022, 2:08 PM · VyOS 1.3 Equuleus ( 1.3.1)
dutty updated the task description for T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.
Feb 13 2022, 1:55 PM · VyOS 1.3 Equuleus ( 1.3.1)
dutty created T4241: ocserv openconnect looks broken in recent bulds of 1.3 Equuleus.
Feb 13 2022, 1:04 PM · VyOS 1.3 Equuleus ( 1.3.1)

Oct 23 2021

dutty renamed T3934: Openconnect VPN broken: ocserv-worker general protection fault on client connect from ocserv-worker general protection fault on client connect to Openconnect VPN broken: ocserv-worker general protection fault on client connect.
Oct 23 2021, 12:19 PM · VyOS 1.3 Equuleus (1.3.0)
dutty added a comment to T3934: Openconnect VPN broken: ocserv-worker general protection fault on client connect.

Same as T3919

Oct 23 2021, 9:30 AM · VyOS 1.3 Equuleus (1.3.0)
dutty added a comment to T3919: Openconnect VPN broken on 1.3-epa2.

I confirm. Same as T3934

Oct 23 2021, 9:23 AM
dutty updated the task description for T3934: Openconnect VPN broken: ocserv-worker general protection fault on client connect.
Oct 23 2021, 9:18 AM · VyOS 1.3 Equuleus (1.3.0)
dutty updated the task description for T3934: Openconnect VPN broken: ocserv-worker general protection fault on client connect.
Oct 23 2021, 9:08 AM · VyOS 1.3 Equuleus (1.3.0)
dutty created T3934: Openconnect VPN broken: ocserv-worker general protection fault on client connect.
Oct 23 2021, 9:04 AM · VyOS 1.3 Equuleus (1.3.0)