Page MenuHomeVyOS Platform

lucasec (Lucas Christian)
User

Projects

User does not belong to any projects.

User Details

User Since
Apr 2 2019, 2:39 AM (290 w, 4 d)

Recent Activity

Aug 20 2024

lucasec closed T6183: OpenVPN IPv6 server: Unable to establish connection without local-host parameter as Resolved.

Merged PR https://github.com/vyos/vyos-1x/pull/3975

Aug 20 2024, 5:48 AM · VyOS 1.5 Circinus
lucasec reopened T6183: OpenVPN IPv6 server: Unable to establish connection without local-host parameter as "Open".
Aug 20 2024, 5:48 AM · VyOS 1.5 Circinus
lucasec committed rVYOSONEX18ea3673a105: T6183: interfaces openvpn: suppport specifying IP protocol version.
Aug 20 2024, 5:25 AM

Aug 19 2024

lucasec added a comment to T6550: Adding the possibility to configure RSS under the interface.

Another note—our current RPS implementation intentionally excludes core 0 from packet processing. If we want the default RSS behavior to mimic, this might mean we should be using N-1 queues where N is the number of cores. Whether this makes sense to carry over to RSS I'll leave open for debate.

Aug 19 2024, 10:39 PM · VyOS 1.5 Circinus
lucasec added a comment to T6550: Adding the possibility to configure RSS under the interface.

Should RSS/ntuple be the default or should it be an opt-in "offload" setting?

Aug 19 2024, 10:37 PM · VyOS 1.5 Circinus
lucasec added a comment to T6663: interfaces ethernet offload: support Receive Side Scaling (RSS).

Ack, I'm inclined to close this as a duplicate. What's the best way to mark the ticket?

Aug 19 2024, 10:31 PM · VyOS 1.5 Circinus
lucasec updated the task description for T6663: interfaces ethernet offload: support Receive Side Scaling (RSS).
Aug 19 2024, 6:33 AM · VyOS 1.5 Circinus
lucasec changed Issue type from unspecified to feature on T6663: interfaces ethernet offload: support Receive Side Scaling (RSS).
Aug 19 2024, 6:23 AM · VyOS 1.5 Circinus
lucasec created T6663: interfaces ethernet offload: support Receive Side Scaling (RSS).
Aug 19 2024, 6:23 AM · VyOS 1.5 Circinus
lucasec created T6662: "could not change "ethX" flow control setting!".
Aug 19 2024, 6:05 AM · Restricted Project, VyOS 1.5 Circinus
lucasec created T6661: suricata: certain offload types should be disabled when interface is used.
Aug 19 2024, 5:40 AM · VyOS 1.5 Circinus

Aug 18 2024

lucasec closed T6659: suricata: multiple interfaces use same af_packet cluster_id, leading to crash as Resolved.

Merged PR: https://github.com/vyos/vyos-1x/pull/3992

Aug 18 2024, 5:13 AM · VyOS 1.5 Circinus

Aug 16 2024

lucasec added a comment to T3871: Resolve unexpected interface name reordering.

I took some time to re-test this on recent rolling releases and it seemed mostly positive.

Aug 16 2024, 7:02 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)
lucasec created T6659: suricata: multiple interfaces use same af_packet cluster_id, leading to crash.
Aug 16 2024, 5:11 AM · VyOS 1.5 Circinus

Aug 13 2024

lucasec closed T6648: dhcpv6-server: common-options does not support all DHCP options as Resolved.
Aug 13 2024, 3:48 AM · VyOS 1.5 Circinus
lucasec added a comment to T6177: Intel QAT causes CPU runaway/stall with ipsec VPN.

I've seen this a few times on the most recent 1.5x rolling releases. So far every stack trace has included the xfrm_input kernel function, so this tells me it is likely specific to when QAT is combined with the VTI feature (which switched from the vti interface type to xfrm type in 1.4).

Aug 13 2024, 3:39 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus

Aug 12 2024

lucasec changed the status of T6648: dhcpv6-server: common-options does not support all DHCP options from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/3970

Aug 12 2024, 2:35 AM · VyOS 1.5 Circinus

Aug 11 2024

lucasec created T6648: dhcpv6-server: common-options does not support all DHCP options.
Aug 11 2024, 10:18 PM · VyOS 1.5 Circinus

Aug 10 2024

lucasec changed the status of T6630: ntp: support hardware timestamp offload and other mechanisms to improve accuracy from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/3966

Aug 10 2024, 8:05 AM · VyOS 1.5 Circinus

Aug 1 2024

lucasec created T6630: ntp: support hardware timestamp offload and other mechanisms to improve accuracy.
Aug 1 2024, 9:22 PM · VyOS 1.5 Circinus
lucasec committed rVYOSONEX4d2c89dcd50d: T5873: vpn ipsec remote-access: support VTI interfaces.
Aug 1 2024, 11:08 AM
lucasec committed rVYOSONEX50cf1746d3ab: T5873: vpn ipsec remote-access: improve child ESP session naming.
Aug 1 2024, 11:08 AM
lucasec committed rVYOSONEX376e2d898f26: T5873: vpn ipsec: re-write of ipsec updown hook.
Aug 1 2024, 11:08 AM
lucasec committed rVYOSONEX404b641121d3: T5873: vpn ipsec: ignore dhcp/vti settings when connection disabled.
Aug 1 2024, 11:08 AM
lucasec committed rVYOSONEXe97d86e619e1: T6617: T6618: vpn ipsec remote-access: fix profile generators.
Aug 1 2024, 5:50 AM

Jul 31 2024

lucasec added a comment to T6177: Intel QAT causes CPU runaway/stall with ipsec VPN.

I was hoping some combination of the newer QAT driver 4.24 and newer kernel in the latest rolling releases might fix this... but seemingly not.

Jul 31 2024, 6:20 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus

Jul 30 2024

lucasec changed the status of T6618: ipsec: remote access VPN: "generate ipsec profile windows-remote-access" broken from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/3903

Jul 30 2024, 7:29 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS Rolling, VyOS 1.5 Circinus
lucasec changed the status of T6617: ipsec: remote access VPN: "generate ipsec profile ios-remote-access" wrong profile for x509 auth from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/3903

Jul 30 2024, 7:29 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS Rolling, VyOS 1.5 Circinus

Jul 29 2024

lucasec created T6618: ipsec: remote access VPN: "generate ipsec profile windows-remote-access" broken.
Jul 29 2024, 8:31 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS Rolling, VyOS 1.5 Circinus
lucasec created T6617: ipsec: remote access VPN: "generate ipsec profile ios-remote-access" wrong profile for x509 auth.
Jul 29 2024, 8:27 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS Rolling, VyOS 1.5 Circinus
lucasec changed Version from - to dates all the way back to 1.3.5 on T6616: vyos-hostsd reloads pdns-recursor frequently, even when no config change.
Jul 29 2024, 5:34 AM · VyOS 1.5 Circinus
lucasec updated the task description for T6616: vyos-hostsd reloads pdns-recursor frequently, even when no config change.
Jul 29 2024, 5:34 AM · VyOS 1.5 Circinus
lucasec created T6616: vyos-hostsd reloads pdns-recursor frequently, even when no config change.
Jul 29 2024, 5:32 AM · VyOS 1.5 Circinus

Jul 22 2024

lucasec committed rVYOSONEX23a3419d5121: T6599: ipsec: fix incorect default behavior for dead-peer-detection.
Jul 22 2024, 10:24 AM
lucasec committed rVYOSONEXfd5d7ff0b4fd: T6599: ipsec: support disabling rekey of CHILD_SA..
Jul 22 2024, 10:24 AM

Jul 21 2024

lucasec changed the status of T6599: ipsec: support disabling rekey of CHILD_SA from Open to In progress.
Jul 21 2024, 5:02 AM · VyOS 1.4 Sagitta (1.4.1), VyOS Rolling, VyOS 1.5 Circinus
lucasec claimed T6599: ipsec: support disabling rekey of CHILD_SA.
Jul 21 2024, 5:02 AM · VyOS 1.4 Sagitta (1.4.1), VyOS Rolling, VyOS 1.5 Circinus
lucasec created T6599: ipsec: support disabling rekey of CHILD_SA.
Jul 21 2024, 2:28 AM · VyOS 1.4 Sagitta (1.4.1), VyOS Rolling, VyOS 1.5 Circinus

Jul 16 2024

lucasec changed the status of T5873: ipsec remote access VPN: support VTI interfaces from Open to In progress.

PR: https://github.com/vyos/vyos-1x/pull/3221

Jul 16 2024, 9:38 PM · VyOS Rolling, VyOS 1.5 Circinus

Jul 7 2024

lucasec added a comment to T921: Encrypted DNS.

There are two possible places where encrypted DNS support might be desired in a standard setup where VyOS is hosting a local resolver/recursor:

Jul 7 2024, 3:11 AM · VyOS 1.4 Sagitta (1.4.0-GA)

Apr 15 2024

lucasec added a comment to T6241: Updating CRL in "pki" config does not update OpenVPN.

I even commented on that issue…
It would seem my memory ages out after 3 years 🤣

Apr 15 2024, 7:41 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 14 2024

lucasec created T6241: Updating CRL in "pki" config does not update OpenVPN.
Apr 14 2024, 11:55 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
lucasec renamed T6177: Intel QAT causes CPU runaway/stall with ipsec VPN from CPU runaway/stall possibly related to Strongswan to Intel QAT causes CPU runaway/stall with ipsec VPN.
Apr 14 2024, 11:36 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
lucasec added a comment to T6177: Intel QAT causes CPU runaway/stall with ipsec VPN.

My system finally crashed again today. I found a workload that generates enough traffic over the VPN to reliably re-produce.

Apr 14 2024, 7:20 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus

Apr 12 2024

lucasec committed rVYOSONEX840ab82e8821: T5872: fix ipsec dhclient hook uses "exit" instead of "return".
Apr 12 2024, 6:30 PM
lucasec committed rVYOSONEXecc83562b4d7: T5871: ipsec remote access VPN: specify "cacerts" for client auth..
Apr 12 2024, 5:09 AM

Apr 7 2024

lucasec added a comment to T5873: ipsec remote access VPN: support VTI interfaces.

Hi -- this works. The VTI interface is just another interface so you can add it to a firewall zone just as you would an Ethernet interface. This can be done with existing site-to-site ipsec VTIs today. I also do it with OpenVPN interfaces for remote access on some of my installations.

Apr 7 2024, 1:57 AM · VyOS Rolling, VyOS 1.5 Circinus

Mar 28 2024

lucasec closed T5872: ipsec remote access VPN: support dhcp-interface as Resolved.
Mar 28 2024, 6:28 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
lucasec committed rVYOSONEXf7834324d3d9: T5872: ipsec remote access VPN: support dhcp-interface..
Mar 28 2024, 4:08 PM
lucasec committed rVYOSONEXcd8ef21f280f: T5872: fix ipsec dhclient exit hook.
Mar 28 2024, 4:08 PM
lucasec committed rVYOSONEX92012a0b3db8: T5872: further fixes to ipsec dhcp exit hook.
Mar 28 2024, 4:08 PM
lucasec committed rVYOSONEX679b78356cbd: T5872: re-write exit hook to always regenerate config.
Mar 28 2024, 4:08 PM

Mar 27 2024

lucasec created T6177: Intel QAT causes CPU runaway/stall with ipsec VPN.
Mar 27 2024, 4:45 PM · Restricted Project, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus

Mar 12 2024

lucasec closed T6114: dhcpv6-server migration script 4-to-5 errors out as Resolved.
Mar 12 2024, 4:44 PM
lucasec committed rVYOSONEX246b3e17e067: T6114: fix broken migration dhcpv6-server 4-to-5.
Mar 12 2024, 12:06 PM

Mar 11 2024

lucasec created T6114: dhcpv6-server migration script 4-to-5 errors out.
Mar 11 2024, 6:23 AM

Dec 30 2023

lucasec committed rVYOSONEX656934e85cee: T5870: ipsec remote access VPN: add x509 ("pubkey") authentication..
Dec 30 2023, 9:57 PM

Dec 29 2023

lucasec created T5874: ipsec site-to-site: Support binding multiple tunnels to one VTI, customizing local and remote traffic selectors.
Dec 29 2023, 6:24 AM · VyOS Rolling, VyOS 1.5 Circinus
lucasec updated the task description for T5873: ipsec remote access VPN: support VTI interfaces.
Dec 29 2023, 6:05 AM · VyOS Rolling, VyOS 1.5 Circinus
lucasec created T5873: ipsec remote access VPN: support VTI interfaces.
Dec 29 2023, 6:03 AM · VyOS Rolling, VyOS 1.5 Circinus
lucasec renamed T5872: ipsec remote access VPN: support dhcp-interface from ipsec remote access VPN: support dhcp to ipsec remote access VPN: support dhcp-interface.
Dec 29 2023, 6:00 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
lucasec created T5872: ipsec remote access VPN: support dhcp-interface.
Dec 29 2023, 6:00 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
lucasec created T5871: ipsec remote access VPN: specify "cacerts" to disambiguate mulitple remote access configurations.
Dec 29 2023, 5:59 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
lucasec created T5870: ipsec remote access VPN: add x509 ("pubkey") authentication.
Dec 29 2023, 5:55 AM · VyOS 1.4 Sagitta (1.4.0-epa2)

Jan 23 2023

lucasec added a comment to T2486: DNS records set via 'system static-host-mapping' return NXDOMAIN from 'service dns forwarding' after a request to a forwarded zone.

For completeness let me link this back to discussion here: https://github.com/vyos/vyos-1x/pull/1024#issuecomment-1399908479
TL;DR I do not believe this bug needs to be re-opened, what was likely identified is a different, unrelated, limitation of pdns-recursor that affects the newer authoritative DNS functionality.

Jan 23 2023, 7:36 AM · VyOS 1.3 Equuleus (1.3.0)

Apr 5 2022

lucasec created T4345: New firewall code does not accept "rate/time interval" syntax used in old config.
Apr 5 2022, 10:36 PM · VyOS 1.4 Sagitta

Dec 9 2021

lucasec committed rVYOSONEX9386ac0e3d7f: Fix error when no domains are defined.
Dec 9 2021, 2:52 PM
lucasec committed rVYOSONEX36e5f07f8dda: T562: Config syntax for defining DNS forward authoritative zones.
Dec 9 2021, 2:52 PM
lucasec committed rVYOSONEXd6a79444ff13: Fix default values.
Dec 9 2021, 2:52 PM
lucasec committed rVYOSONEX98704f45a4d2: Don't generate NTA when zone is disabled.
Dec 9 2021, 2:52 PM

Oct 12 2021

lucasec added a comment to T562: PDNS: Add support for authoritative dns server.

PR: https://github.com/vyos/vyos-1x/pull/1024

Oct 12 2021, 7:28 AM · VyOS 1.4 Sagitta

Oct 11 2021

lucasec added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

Obviously in a perfect world we get "unique" and "stable". I do think giving stability priority makes sense.

Oct 11 2021, 8:05 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta

Oct 10 2021

lucasec added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

I surveyed all the hardware I have to see what kind of UUIDs they report:

Oct 10 2021, 11:37 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta

Oct 5 2021

lucasec added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

Yeah, that seems reasonable to me. I would prefer not add clutter to the system node if it can be avoided.

Oct 5 2021, 6:21 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
lucasec added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

That seems fair, basically make the DUID generation deterministic. There is some defined structure to the DUID format, I think this would be a "type 3 DUID" per this document: https://www.juniper.net/documentation/en_US/junose15.1/topics/concept/dhcp-unique-id-servers-clients-overview.html.

Oct 5 2021, 5:23 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta

Oct 3 2021

lucasec created T3885: dhcpv6-pd: randomly generated DUID is not persisted.
Oct 3 2021, 7:20 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta

Sep 27 2021

lucasec added a comment to T3861: PKI: changing certificates, keys, crls does not "regenerate" the on-disk certificates.

Adding a few notes here:

  • The ideal behavior probably depends on which PKI elements are changed and what services depend on them.
  • E.g. OpenVPN does not require a server restart for a CRL change (see https://openvpn.net/community-resources/controlling-a-running-openvpn-process/), but changing the CA or server cert/key would require a restart.
  • It seems like there are some swanctrl commands that can conditionally reload parts of the config too without taking all tunnels down
  • The former might be useful if you need to renew server certs or something like that and want to do so with the minimal impact
Sep 27 2021, 4:45 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA)

Sep 20 2021

lucasec committed rVYOSONEXd768aee9bd93: ipsec: T1441: Clean up vti-up-down script for XFRM interfaces.
Sep 20 2021, 5:39 AM

Sep 19 2021

lucasec committed rVYOSONEX60f34805d729: T3840: Allow larger DNS forwarding cache sizes.
Sep 19 2021, 7:01 AM
lucasec added a comment to T3840: dns forwarding: Cache size should allow values > 10k.

Pull request: https://github.com/vyos/vyos-1x/pull/1010

Sep 19 2021, 4:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec changed Difficulty level from unknown to easy on T3840: dns forwarding: Cache size should allow values > 10k.
Sep 19 2021, 4:29 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec claimed T3840: dns forwarding: Cache size should allow values > 10k.
Sep 19 2021, 4:21 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec created T3840: dns forwarding: Cache size should allow values > 10k.
Sep 19 2021, 4:21 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Sep 17 2021

lucasec added a comment to T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified.

Tested on latest build VyOS 1.4-rolling-202109160217 and confirmed it is adding the remote id attribute by default as expected. Connections establish without issue.

Sep 17 2021, 4:02 AM · VyOS 1.4 Sagitta

Sep 15 2021

lucasec assigned T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified to c-po.
Sep 15 2021, 5:57 AM · VyOS 1.4 Sagitta
lucasec created T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified.
Sep 15 2021, 5:57 AM · VyOS 1.4 Sagitta

Sep 14 2021

lucasec added a comment to T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta.

Booted my host with 1.4-rolling-202109140217 and confirmed pfs enabled is now generating the expected swanctl.conf file to match the old behavior. If I don't report back in exactly an hour from now that my tunnels died, we can assume the fix works.

Sep 14 2021, 5:03 AM · VyOS 1.4 Sagitta

Sep 13 2021

lucasec assigned T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta to c-po.
Sep 13 2021, 7:20 AM · VyOS 1.4 Sagitta
lucasec created T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta.
Sep 13 2021, 7:20 AM · VyOS 1.4 Sagitta
lucasec added a comment to T3827: interfaces migration script fails on AWS hosts.

Note: config versions were added to the default configs here https://github.com/vyos/vyos-build/commit/23639568a945f19471af88547dab45b87bbd642d, but the current vyos-build-ami replaces the default file with its own that hasn't been modified to add the versioning comment yet. That can probably be fixed whenever that repo is updated for equuleus (I have my own patched local branch that I could publish if desired).

Sep 13 2021, 12:44 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
lucasec updated subscribers of T3827: interfaces migration script fails on AWS hosts.

cc: @c-po maybe this was a side effect of unifying the two parsers

Sep 13 2021, 12:20 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
lucasec created T3827: interfaces migration script fails on AWS hosts.
Sep 13 2021, 12:16 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta

Sep 11 2021

lucasec added a comment to T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface.

FYI, if your OpenVPN config relies on cert files or anything you uploaded into the config directory, you may need to change the owner to the openvpn user or widen file permissions. Oddly this only seems to affect equuleus, not sagitta (OpenVPN seems fine reading files owned by "root" out of "/config/auth").

Sep 11 2021, 8:58 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Nov 14 2020

lucasec added a comment to T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.

Your revert appears to do the trick. Image booted fine with QAT enabled, and "show system acceleration qat status" shows the QAT device came up fine and is running happily.

Nov 14 2020, 6:21 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 12 2020

lucasec added a comment to T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.

Sure—if you want to drop me an image I can try it out. I do have a working vyos-build as well, I can also try and produce my own with that change backed out when I get some time towards the end of the week.

Nov 12 2020, 4:23 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 10 2020

lucasec added a comment to T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.

I will perform a few additional tests tomorrow with the oldest available rolling releases (looks like October 13th as of writing). Will see if I can binary search my way to when things broke.

Nov 10 2020, 7:27 AM · VyOS 1.3 Equuleus (1.3.0)
lucasec updated the task description for T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.
Nov 10 2020, 7:22 AM · VyOS 1.3 Equuleus (1.3.0)
lucasec added a comment to T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.

A few updates... the failure still occurs on latest rolling. Similar outcome—the kernel panics and dumps a stacktrace during the initial boot-up configure process. However, this issue goes back further than I expected (and initially expressed in the ticket). I goofed up in my testing of 1.3-rolling-202010260327 by booting with a default config file without the QAT option.

Nov 10 2020, 7:21 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 3 2020

lucasec created T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.
Nov 3 2020, 5:11 AM · VyOS 1.3 Equuleus (1.3.0)

Oct 27 2020

lucasec closed T2961: Support "stateless" DHCP-v6 (information-request) clients as Resolved.
Oct 27 2020, 7:01 PM