Page MenuHomeVyOS Platform

fernando (maidana)
User

Projects

User Details

User Since
May 11 2021, 12:36 PM (124 w, 2 d)

Recent Activity

Wed, Sep 20

fernando added a project to T5487: OPENVPN -DEPRECATED OPTION: --cipher: VyOS 1.3 Equuleus (1.3.5).
Wed, Sep 20, 2:55 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta

Mon, Sep 18

fernando claimed T5595: Multicast - PIM bfd feature enable .
Mon, Sep 18, 5:16 PM · VyOS 1.5 Circinus
fernando created T5595: Multicast - PIM bfd feature enable .
Mon, Sep 18, 5:16 PM · VyOS 1.5 Circinus

Wed, Sep 13

fernando added a comment to T4919: TPM-backed config encryption.

@sdev greats !!!

Wed, Sep 13, 4:39 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Tue, Sep 12

fernando changed the status of T3655: NAT Problem with VRF from Backport candidate to Needs testing.
Tue, Sep 12, 6:59 PM · VyOS 1.5 Circinus, Known issue, VyOS 1.4 Sagitta
fernando added a comment to T3655: NAT Problem with VRF.

command on 1.5 :

Tue, Sep 12, 6:36 PM · VyOS 1.5 Circinus, Known issue, VyOS 1.4 Sagitta
fernando changed the status of T3655: NAT Problem with VRF from In progress to Backport candidate.
Tue, Sep 12, 4:17 PM · VyOS 1.5 Circinus, Known issue, VyOS 1.4 Sagitta
fernando updated subscribers of T3655: NAT Problem with VRF.

@vfreex I've tested in my labs related this issues , I can confirm that it work as expected . this original zone solved the problem when there was a src-nat /dst-nat with different VRFs or leaking with them ,Thanks you for this contribution .

Tue, Sep 12, 4:16 PM · VyOS 1.5 Circinus, Known issue, VyOS 1.4 Sagitta

Wed, Sep 6

fernando updated subscribers of T4919: TPM-backed config encryption.

@sdev take a look over these repository :

Wed, Sep 6, 1:28 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Mon, Sep 4

fernando changed the status of T5547: ISIS: The L1-2 router cannot advertise L1 routes into L2 from Open to Confirmed.
Mon, Sep 4, 1:37 PM · VyOS 1.4 Sagitta
fernando created T5547: ISIS: The L1-2 router cannot advertise L1 routes into L2.
Mon, Sep 4, 1:36 PM · VyOS 1.4 Sagitta

Wed, Aug 30

fernando changed the status of T5526: Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax from Open to Confirmed.
Wed, Aug 30, 6:06 PM · VyOS 1.3 Equuleus (1.3.5)
fernando created T5526: Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax.
Wed, Aug 30, 6:05 PM · VyOS 1.3 Equuleus (1.3.5)

Aug 28 2023

fernando closed T2296: Upgrade WALinux to 2.2.41 as Resolved.
Aug 28 2023, 3:38 PM · VyOS 1.3 Equuleus (1.3.4)
fernando added a comment to T2296: Upgrade WALinux to 2.2.41.

we have a version updated , this case should be closed:

azureuser@vyos-support:~$ sudo /usr/sbin/waagent -version
WALinuxAgent-2.2.45 running on debian 10.12
Python: 3.7.3
Goal state agent: 2.2.45
Aug 28 2023, 3:37 PM · VyOS 1.3 Equuleus (1.3.4)

Aug 23 2023

fernando closed T5466: L3VPN - label allocation mode as Resolved.
Aug 23 2023, 1:32 PM · VyOS 1.4 Sagitta
fernando added a comment to T5466: L3VPN - label allocation mode .

I've tested our last rolling-realase , it's working as expected :

Aug 23 2023, 1:31 PM · VyOS 1.4 Sagitta

Aug 18 2023

fernando added a comment to T5481: Upgrade bug.

I couldn't open those files, but it can be related our firewall refactor :

Aug 18 2023, 9:21 PM · VyOS 1.4 Sagitta
fernando changed the status of T5487: OPENVPN -DEPRECATED OPTION: --cipher from Open to Confirmed.
Aug 18 2023, 8:07 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
fernando added a comment to T5487: OPENVPN -DEPRECATED OPTION: --cipher.

I confirm this warning message , although, on Linux doesn't affect or at least with our server/client work as expected :

Aug 18 2023, 8:05 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta

Aug 17 2023

fernando created T5487: OPENVPN -DEPRECATED OPTION: --cipher.
Aug 17 2023, 4:06 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta

Aug 16 2023

fernando updated the task description for T5484: set extcommunity - just allow one extend community.
Aug 16 2023, 8:29 PM · VyOS 1.3 Equuleus (1.3.5)
fernando created T5484: set extcommunity - just allow one extend community.
Aug 16 2023, 7:41 PM · VyOS 1.3 Equuleus (1.3.5)
fernando changed the status of T5466: L3VPN - label allocation mode from Open to In progress.
Aug 16 2023, 6:55 PM · VyOS 1.4 Sagitta
fernando added a comment to T5466: L3VPN - label allocation mode .

PR https://github.com/vyos/vyos-1x/pull/2152

Aug 16 2023, 6:55 PM · VyOS 1.4 Sagitta

Aug 15 2023

fernando added a comment to T5160: Firewall refactor.

yes, but it's in process to merge : https://github.com/vyos/vyos-documentation/pull/1035

Aug 15 2023, 11:31 PM · VyOS 1.4 Sagitta
fernando added a comment to T5481: Upgrade bug.

Could you share the full configuration ? so we can analyze what is the source of this problem .

Aug 15 2023, 9:48 PM · VyOS 1.4 Sagitta

Aug 11 2023

fernando claimed T5466: L3VPN - label allocation mode .
Aug 11 2023, 8:00 PM · VyOS 1.4 Sagitta
fernando created T5466: L3VPN - label allocation mode .
Aug 11 2023, 7:59 PM · VyOS 1.4 Sagitta
fernando added a comment to T5456: Add alias for "show ipv6 bgp".

Adding comments : maybe discontinue show ip bgp gives some issues / problems with automation tools (ansible o some custom script)While thinking out loud, it can be useful for new users create to alias.

Aug 11 2023, 7:49 PM · VyOS 1.4 Sagitta
fernando added a comment to T5456: Add alias for "show ipv6 bgp".

show ip bgp is an old command, it comes from quagga ...So in my point of view , adding more command to do the same , could generate more confusion . show bgp address-family should be used.

Aug 11 2023, 12:09 PM · VyOS 1.4 Sagitta

Aug 7 2023

fernando added a comment to T660: 802.1p CoS priority support.

information that can be useful for this feature request :

Aug 7 2023, 5:31 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta

Aug 2 2023

fernando added a comment to T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.

cool! it's interesting understand this complex scenery and how it works an real environment ,Additionally, the way it handle the zebra with the next-hop group ,int fact , I genuinely appreciate your valuable feedback so far!

Aug 2 2023, 2:11 PM · VyOS 1.4 Sagitta
fernando added a comment to T5424: Routes vanishes when using FRR with ECMP and one of the ECMP paths is no longer available.

as I recall ,this case can be associate with this task : https://vyos.dev/T5077

Aug 2 2023, 1:18 PM · VyOS 1.4 Sagitta

Aug 1 2023

fernando closed T5339: Geneve interface - option to use IPv4 as inner protocol as Resolved.
Aug 1 2023, 1:33 PM · VyOS 1.4 Sagitta
fernando added a comment to T5339: Geneve interface - option to use IPv4 as inner protocol .

yes , sorry!

Aug 1 2023, 1:33 PM · VyOS 1.4 Sagitta

Jul 21 2023

fernando added a comment to T4974: OpenVPN- Data Channel Offload(DCO).

PR : https://github.com/vyos/vyos-1x/pull/2107/commits

Jul 21 2023, 9:49 PM · VyOS 1.4 Sagitta

Jul 19 2023

fernando changed the status of T4974: OpenVPN- Data Channel Offload(DCO) from Open to Needs testing.
Jul 19 2023, 6:20 PM · VyOS 1.4 Sagitta
fernando added a comment to T4974: OpenVPN- Data Channel Offload(DCO).

@c-po thanks for compiled the kernel module and @spion06 for your contribution script , now we've DCO rolling releases starting on 1.4-rolling-202307190317

Jul 19 2023, 6:20 PM · VyOS 1.4 Sagitta

Jul 12 2023

fernando added a comment to T5337: MPLS/BGP: Route leak does not happen from the VPNv4 table to specific vrf.

I've summited an issues case on FRR , where explain the problematic :

Jul 12 2023, 8:52 PM · VyOS 1.4 Sagitta

Jul 11 2023

fernando added a comment to T5337: MPLS/BGP: Route leak does not happen from the VPNv4 table to specific vrf.

well , I've had an idea how to make a workaround , I've used explicit-null label to add next-hop from the network-address connected sudo ip route add 10.0.0.1/32 encap mpls 0 via 10.0.0.2 dev eth1

Jul 11 2023, 12:05 AM · VyOS 1.4 Sagitta

Jul 10 2023

fernando changed the status of T5337: MPLS/BGP: Route leak does not happen from the VPNv4 table to specific vrf from Open to Confirmed.
Jul 10 2023, 9:27 PM · VyOS 1.4 Sagitta
fernando added a comment to T5337: MPLS/BGP: Route leak does not happen from the VPNv4 table to specific vrf.

I've done extra test , I confirm this behavior is associated transport label that can't be allocated when using interfaces directed connected to created ldp session without IGP protocols(ospf/isis) . let's see what is going on :

Jul 10 2023, 9:15 PM · VyOS 1.4 Sagitta

Jul 5 2023

fernando added a comment to T5339: Geneve interface - option to use IPv4 as inner protocol .

basic configuration :

Jul 5 2023, 3:31 PM · VyOS 1.4 Sagitta
fernando changed the status of T5339: Geneve interface - option to use IPv4 as inner protocol from In progress to Needs testing.
Jul 5 2023, 3:30 PM · VyOS 1.4 Sagitta
fernando changed the status of T5339: Geneve interface - option to use IPv4 as inner protocol from Open to In progress.
Jul 5 2023, 1:13 PM · VyOS 1.4 Sagitta
fernando added a comment to T5339: Geneve interface - option to use IPv4 as inner protocol .

PR : https://github.com/vyos/vyos-1x/pull/2073

Jul 5 2023, 1:13 PM · VyOS 1.4 Sagitta

Jul 4 2023

fernando claimed T5339: Geneve interface - option to use IPv4 as inner protocol .
Jul 4 2023, 8:35 PM · VyOS 1.4 Sagitta
fernando created T5339: Geneve interface - option to use IPv4 as inner protocol .
Jul 4 2023, 8:34 PM · VyOS 1.4 Sagitta

Jun 21 2023

fernando renamed T5307: QoS - traffic-class-map services from Qos - traffic-class-map services to QoS - traffic-class-map services .
Jun 21 2023, 11:09 PM · VyOS 1.4 Sagitta
fernando added a comment to T5276: QOS- inbound shapper attached on VLANs not working..

you are right , I seems to be working :

Jun 21 2023, 9:12 PM · VyOS 1.4 Sagitta
fernando created T5307: QoS - traffic-class-map services .
Jun 21 2023, 9:01 PM · VyOS 1.4 Sagitta
fernando added a comment to T5071: QOS-Rewrite: DSCP match missing.

I've tested it, but it works partially... if you have more than a match (for example, the same class id if necessary to match more than one DSCP),it brakes the configuration again :

Jun 21 2023, 8:06 PM · VyOS 1.4 Sagitta

Jun 15 2023

fernando added a comment to T5266: QoS- HTB error when match with a dscp parameter for queue-type 'priority'.

I've found the reason why this command fails, it' happens because the logic to match the dscp parameter is missing. So, it tries to apply the basic policy with the tc filter parameters by default :

Jun 15 2023, 12:33 AM · VyOS 1.4 Sagitta

Jun 9 2023

fernando added a comment to T5276: QOS- inbound shapper attached on VLANs not working..

https://vyos.dev/T5048

Jun 9 2023, 3:13 PM · VyOS 1.4 Sagitta
fernando created T5276: QOS- inbound shapper attached on VLANs not working..
Jun 9 2023, 3:04 PM · VyOS 1.4 Sagitta

Jun 7 2023

fernando added a comment to T5266: QoS- HTB error when match with a dscp parameter for queue-type 'priority'.

https://vyos.dev/T5048

Jun 7 2023, 9:32 PM · VyOS 1.4 Sagitta
fernando created T5266: QoS- HTB error when match with a dscp parameter for queue-type 'priority'.
Jun 7 2023, 9:31 PM · VyOS 1.4 Sagitta

Jun 1 2023

fernando added a comment to T5252: Route distinguisher and route targets changing upon adding interface to new VRF.

this issues was resolved on https://vyos.dev/T5127. It happens when FRR tries to calculate the auto-rd per vrf . it can be solved by using router-id on each vrf or interface dummy in the VRFs ,

Jun 1 2023, 7:12 PM · VyOS 1.4 Sagitta
fernando closed T5127: VPNv4/VPNv6 routes are not reinstalled following link flap as Resolved.
Jun 1 2023, 7:07 PM · VyOS 1.4 Sagitta

May 24 2023

fernando added a comment to T5238: interface virtual-etherne - error when it doesn't use a peer .

Thanks Viacheslav , for this clarification . Veths /Netns are strong powerful , using this technology we can use to join different hypervisor or bridge technology . leave some example namespaces /veth / bridging.

May 24 2023, 4:16 PM · VyOS 1.4 Sagitta

May 23 2023

fernando created T5238: interface virtual-etherne - error when it doesn't use a peer .
May 23 2023, 8:00 PM · VyOS 1.4 Sagitta
fernando created T5237: interfaces virtual-ethernet - Extend capabilitys of Vlans/QinQ.
May 23 2023, 7:29 PM · VyOS 1.4 Sagitta

May 17 2023

fernando added a comment to T3655: NAT Problem with VRF.

I've done test , regarding the original issues that it was nat+route-leaking (default + foo) , which is working on the last rolling (VyOS 1.4-rolling-202305140317). however, I've tried some test using two vrf+route-leaking and NAT , I can replicated the issue:

May 17 2023, 3:19 PM · VyOS 1.5 Circinus, Known issue, VyOS 1.4 Sagitta

May 8 2023

fernando closed T5212: snmp community name -error with special carracter as Resolved.
May 8 2023, 7:20 PM · VyOS 1.3 Equuleus
fernando created T5212: snmp community name -error with special carracter .
May 8 2023, 7:07 PM · VyOS 1.3 Equuleus

May 6 2023

fernando updated subscribers of T4974: OpenVPN- Data Channel Offload(DCO).

thanks for the contribution , I've done some test , it seems to work like a champ . @dmbaturin @c-po this script to do the steps necessary to compile the kernel module to use ovpn-dco . Could you check if it's correct or something needs to be improved :

May 6 2023, 5:07 PM · VyOS 1.4 Sagitta

Apr 21 2023

fernando added a comment to T5161: BFD Static Route Monitoring.

bfd is able to monitoring static routes , using profiles and multi-hop to reached a peer :

Apr 21 2023, 6:24 PM · VyOS 1.4 Sagitta
fernando added a comment to T5161: BFD Static Route Monitoring.

PR https://github.com/vyos/vyos-1x/pull/1967

Apr 21 2023, 6:21 PM · VyOS 1.4 Sagitta

Apr 14 2023

fernando changed the status of T5161: BFD Static Route Monitoring from Open to In progress.
Apr 14 2023, 5:31 PM · VyOS 1.4 Sagitta
fernando claimed T5161: BFD Static Route Monitoring.
Apr 14 2023, 5:31 PM · VyOS 1.4 Sagitta
fernando created T5161: BFD Static Route Monitoring.
Apr 14 2023, 5:31 PM · VyOS 1.4 Sagitta

Apr 13 2023

fernando added a comment to T425: AWS CloudWatch monitoring scripts.

Thanks for clarifying. Yes , I also saw the possibility of extending role based IAM to add on-premise image (that could be interesting for VyOS).

Apr 13 2023, 7:35 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support
fernando added a comment to T5155: restart bgp daemon throws route-map error.

Could you share configuration ? where attached RM and BGP settings:

Apr 13 2023, 7:16 PM · VyOS 1.4 Sagitta
fernando added a comment to T425: AWS CloudWatch monitoring scripts.

@unity when you need AWS credential , will they be automatically deployed from SSM or will we have to add those credentials in the virtual machine? ? shouldn't aws-cli be integrated?

Apr 13 2023, 3:30 PM · VyOS 1.3 Equuleus (1.3.3), AWS Support
fernando closed T4939: VRRP command no-preempt not work as expected as Resolved.
Apr 13 2023, 12:04 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)

Apr 12 2023

fernando added a comment to T4939: VRRP command no-preempt not work as expected.

PR 1.3 https://github.com/vyos/vyos-1x/pull/1951

Apr 12 2023, 12:45 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)

Apr 11 2023

fernando added a comment to T4939: VRRP command no-preempt not work as expected.

Yes, I forgot to add this task. I'll make the PR

Apr 11 2023, 12:05 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)

Mar 31 2023

fernando claimed T5132: Operational command "show isis vrf XXX route | neighbord" aren't working .
Mar 31 2023, 10:40 PM · VyOS 1.4 Sagitta
fernando triaged T5132: Operational command "show isis vrf XXX route | neighbord" aren't working as Low priority.
Mar 31 2023, 4:22 PM · VyOS 1.4 Sagitta
fernando closed T5131: Operational command "show isis segment-routing prefix-sids" isn't working as Resolved.
Mar 31 2023, 3:33 PM
fernando added a comment to T5131: Operational command "show isis segment-routing prefix-sids" isn't working .

merge done, it fixed the issues :

Mar 31 2023, 3:33 PM
fernando added a comment to T5127: VPNv4/VPNv6 routes are not reinstalled following link flap.

sorry , but it seems files doesn't share .

Mar 31 2023, 1:24 PM · VyOS 1.4 Sagitta

Mar 30 2023

fernando changed the status of T5131: Operational command "show isis segment-routing prefix-sids" isn't working from Open to In progress.
Mar 30 2023, 11:03 PM
fernando added a comment to T5131: Operational command "show isis segment-routing prefix-sids" isn't working .

PR :https://github.com/vyos/vyos-1x/pull/1924

Mar 30 2023, 11:02 PM
fernando claimed T5131: Operational command "show isis segment-routing prefix-sids" isn't working .
Mar 30 2023, 8:38 PM
fernando triaged T5131: Operational command "show isis segment-routing prefix-sids" isn't working as Low priority.
Mar 30 2023, 8:38 PM
fernando added a comment to T5097: the operational command "show interfaces ethernet ethx" doesn't reflect a call to 'clear counters'.

confirm, it's working :

Mar 30 2023, 2:30 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
fernando added a comment to T5127: VPNv4/VPNv6 routes are not reinstalled following link flap.

I would like to make some question. this prefix 10.0.0.0/24 on PE2 is a connected network or learned from another routing protocol (static or BGP)

Mar 30 2023, 12:09 PM · VyOS 1.4 Sagitta

Mar 29 2023

fernando added a comment to T5123: Display route originator in show ospf table command.

cool , it could be useful.

Mar 29 2023, 6:42 PM · VyOS 1.4 Sagitta
fernando triaged T5123: Display route originator in show ospf table command as Wishlist priority.
Mar 29 2023, 3:30 PM · VyOS 1.4 Sagitta
fernando added a comment to T5123: Display route originator in show ospf table command.

I don't see it as bug , this information can be obtained from OSPF database using LSA or summary:

Mar 29 2023, 3:21 PM · VyOS 1.4 Sagitta
fernando closed T4876: mpls - LSP broken on FRR 8.4.1, a subtask of T4846: L3VPN- network command doesn't install direct connected prefix, as Resolved.
Mar 29 2023, 2:47 PM · VyOS 1.4 Sagitta
fernando closed T4876: mpls - LSP broken on FRR 8.4.1 as Resolved.
Mar 29 2023, 2:47 PM · VyOS 1.4 Sagitta
fernando added a comment to T4876: mpls - LSP broken on FRR 8.4.1.

frr 8.5 LSP is working as expected:

Mar 29 2023, 2:47 PM · VyOS 1.4 Sagitta
fernando closed T4846: L3VPN- network command doesn't install direct connected prefix as Resolved.
Mar 29 2023, 1:25 PM · VyOS 1.4 Sagitta
fernando added a comment to T4846: L3VPN- network command doesn't install direct connected prefix.

this fix was added 8.5 :

vyos@cust-pe2:~$ show bgp ipv4 vpn 172.16.80.0/24
BGP routing table entry for 1:2:172.16.80.0/24, version 0
not allocated
Paths: (1 available, no best path)
  Not advertised to any peer
  Local
    0.0.0.0 from 0.0.0.0 (1.1.1.1) vrf customer(6) announce-nh-self
      Origin IGP, metric 0, weight 32768, invalid, sourced, local
      Extended Community: RT:1:2
      Originator: 1.1.1.1
      Remote label: 80
      Last update: Wed Mar 29 13:17:24 202
Mar 29 2023, 1:25 PM · VyOS 1.4 Sagitta

Mar 17 2023

fernando created T5097: the operational command "show interfaces ethernet ethx" doesn't reflect a call to 'clear counters'.
Mar 17 2023, 4:32 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus

Mar 8 2023

fernando added a comment to T5045: BFD is not starting after upgrade to 1.4-rolling-202302150317.

Great project! As I understand it, you're using BGP label-unicast to transport labels, and I'm curious about the operating systems your PEs/Ps are running on - are they Cisco, Juniper, or other vendors? I'm particularly interested in learning about the interoperability between different vendors so that I can incorporate it into my testing. @aserkin

Mar 8 2023, 1:14 PM · VyOS 1.4 Sagitta

Mar 3 2023

fernando added a comment to T3655: NAT Problem with VRF.

it doesn't seem the same problem as here, this logic that was applied over this version was vrf not on the table . Could you share full configuration ? there is some point over vrfs / vrf default /leaking that are not clear. So I can replicate the scenery and we see what is going on .

Mar 3 2023, 3:14 PM · VyOS 1.5 Circinus, Known issue, VyOS 1.4 Sagitta