Page MenuHomeVyOS Platform

tjh (Tim Harman)
Sir Chicken

Projects

User does not belong to any projects.

User Details

User Since
Mar 27 2020, 9:54 PM (222 w, 3 d)

I'm a bit of an idiot.

Recent Activity

Tue, Jun 25

tjh added a comment to T6313: Add "NAT" to "generate" command for rule resequence.

Thanks so much @HollyGurza !!!

Tue, Jun 25, 12:22 AM · VyOS 1.5 Circinus

May 25 2024

tjh created T6396: MINOR Typo: set system conntrack timeout custom ipv4 rule X.
May 25 2024, 5:04 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

May 15 2024

tjh created T6345: Source NAT Port Mapping setting of Fully-Random is superfluous in Kernels 5.0 onwards.
May 15 2024, 10:14 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
tjh added a comment to T6336: `set system option kernel disable-mitigations` not applied on upgrade.

@jestabro Thanks for the detailed explanation. If I'd been a proper tester I should have just rebooted it a second time! I think the current solution is fine as long as it's mentioned in release/upgrade notes somewhere. It really is only a performance tweak, it doesn't impact functionality. Thanks again.

May 15 2024, 1:43 AM · VyOS 1.4 Sagitta (1.4.0-GA)

May 14 2024

tjh updated the task description for T6336: `set system option kernel disable-mitigations` not applied on upgrade.
May 14 2024, 11:02 PM · VyOS 1.4 Sagitta (1.4.0-GA)
tjh created T6336: `set system option kernel disable-mitigations` not applied on upgrade.
May 14 2024, 11:02 PM · VyOS 1.4 Sagitta (1.4.0-GA)

May 8 2024

tjh created T6313: Add "NAT" to "generate" command for rule resequence.
May 8 2024, 12:11 AM · VyOS 1.5 Circinus

Apr 22 2024

tjh added a comment to T6253: no-default-route not being honoured.

Just as another data-point - I have found that leaving the DHCP lease to auto-renew itself (not me doing it manually) that it doesn't then add it to the routing table.
i.e. at the moment my DHCP client is still connected, but there's no default via the DHCP session at the moment.

Apr 22 2024, 3:49 AM · VyOS 1.4 Sagitta (1.4.0-GA)

Apr 20 2024

tjh updated the task description for T6253: no-default-route not being honoured.
Apr 20 2024, 2:13 AM · VyOS 1.4 Sagitta (1.4.0-GA)
tjh updated the task description for T6253: no-default-route not being honoured.
Apr 20 2024, 2:05 AM · VyOS 1.4 Sagitta (1.4.0-GA)
tjh triaged T6253: no-default-route not being honoured as Normal priority.
Apr 20 2024, 2:05 AM · VyOS 1.4 Sagitta (1.4.0-GA)

Apr 18 2024

tjh added a comment to T6248: <device> ip source-validation 'strict' - doesn't set /proc/sys/net/ipv4/conf/<device>/rp_filter.

Closed invalid - this is done with nftables now.

Apr 18 2024, 10:09 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
tjh closed T6248: <device> ip source-validation 'strict' - doesn't set /proc/sys/net/ipv4/conf/<device>/rp_filter as Invalid.
Apr 18 2024, 10:08 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
tjh created T6248: <device> ip source-validation 'strict' - doesn't set /proc/sys/net/ipv4/conf/<device>/rp_filter.
Apr 18 2024, 12:41 AM · VyOS 1.4 Sagitta (1.4.0-epa2)

Apr 17 2024

tjh updated the task description for T6244: Improve formatting in "show system uptime".
Apr 17 2024, 9:11 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
tjh assigned T6244: Improve formatting in "show system uptime" to c-po.
Apr 17 2024, 9:02 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
tjh created T6244: Improve formatting in "show system uptime".
Apr 17 2024, 9:00 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 12 2024

tjh added a comment to T2288: Include iprange package in Vyos.

No, this isn't required in 1.4, the script I was using isn't compatible with nftables and the built in support for GeoLocation enabled services is a better solution.
This one can be closed as well, thanks.

Apr 12 2024, 9:17 PM · Restricted Project, VyOS 1.5 Circinus

Apr 10 2024

tjh added a comment to T2801: conntrack-tools flooding logs.

Sorry guys - I'm on 1.4-epa2 these days but aren't doing VRRP/Conntrack sync anymore.

Apr 10 2024, 5:27 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)

Mar 29 2024

tjh added a comment to T6022: set system image default-boot.

line 107: available_images: list[str] = annotated_list(grub.version_list())
Should be: available_images: list[str] = grub.version_list()

Mar 29 2024, 9:36 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Mar 25 2024

tjh added a comment to T6138: Conntrack table op-mode fails with flowtable offload entries.

This is still an issue for 1.4.0-epa2.

Mar 25 2024, 4:10 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 21 2024

tjh added a comment to T6140: After running a while the default routing failed on vyos 1.4 epa1&epa2 with pppoe0 enabled.

Does the problem only appear after your 5am reboot every day?

Mar 21 2024, 2:29 AM · VyOS 1.4 Sagitta (1.4.0-GA)

Feb 8 2024

tjh added a comment to T5750: Upgrade from 1.3.4 to 1.4 Rolling fails QoS.

Thanks Team! Luv Ya!

Feb 8 2024, 7:03 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Jan 9 2024

tjh added a comment to T2801: conntrack-tools flooding logs.

I stopped using conntrack-sync before I moved to 1.3 (which I am currently running) so I can't confirm either way.
I expect it's no longer an issue though and this task can be closed.

Jan 9 2024, 9:17 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)

Dec 18 2023

tjh added a comment to T2288: Include iprange package in Vyos.

Forgot to ever reply to this - I just wanted it added as a standard debian package so that scripts that depend on it can have it available without needing to be installed seperately.

Dec 18 2023, 12:30 AM · Restricted Project, VyOS 1.5 Circinus
tjh added a comment to T2835: "show system-integrity" reports lots of wrong timestamp packages with v1.2.6-epa1.

Think this can be closed - there's no such command in 1.3 is there?

Dec 18 2023, 12:29 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.2 Crux

Nov 17 2023

tjh added a comment to T5750: Upgrade from 1.3.4 to 1.4 Rolling fails QoS.

This is on a virtio interface:

Nov 17 2023, 4:54 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
tjh added a comment to T5750: Upgrade from 1.3.4 to 1.4 Rolling fails QoS.

Simple reproducer - doesn't need to be an upgrade, just apply this to 1.4

Nov 17 2023, 4:51 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Nov 16 2023

tjh added a comment to T5750: Upgrade from 1.3.4 to 1.4 Rolling fails QoS.

Things to note that I'm not sure if they play a part:

Nov 16 2023, 6:38 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
tjh updated the task description for T5750: Upgrade from 1.3.4 to 1.4 Rolling fails QoS.
Nov 16 2023, 6:22 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
tjh added a comment to T5750: Upgrade from 1.3.4 to 1.4 Rolling fails QoS.

Nov 16 2023, 6:21 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
tjh created T5750: Upgrade from 1.3.4 to 1.4 Rolling fails QoS.
Nov 16 2023, 6:14 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 18 2023

tjh added a comment to T5630: pppoe: allow to specify MRU in addition to already configurable MTU.

Furher to this, manually setting "mru 1500" gives me my 1500 MTU back again.

Oct 18 2023, 5:46 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
tjh added a comment to T5630: pppoe: allow to specify MRU in addition to already configurable MTU.

The new MRU config in 1.3.4 seems to have caused my MTU to be lower.

Oct 18 2023, 5:38 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sep 1 2022

tjh added a comment to T4059: VRRP sync-group transition script does not persist after reboot.

I also notice looking at the backup after another reboot:

Sep 1 2022, 4:14 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
tjh added a comment to T4059: VRRP sync-group transition script does not persist after reboot.

I hate to drag up an old ticket, but I've just encountered this issue.
A freshly built VyOS 1.3-rolling-202209010158

Sep 1 2022, 3:26 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)

Aug 20 2022

tjh added a comment to T4412: commit archive: reboot not working with sftp.

I can confirm this has been the reason I've had issues upgrading from 1.2.x to 1.3.x.
Removing this statement before attempting, I can now upgrade from 1.2 to 1.3 smoothly, no OOM errors or other problems.

Aug 20 2022, 1:46 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta

Nov 16 2021

fortinj1354 awarded T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS a Like token.
Nov 16 2021, 6:24 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)

Mar 21 2021

tjh added a comment to T2835: "show system-integrity" reports lots of wrong timestamp packages with v1.2.6-epa1.

This is still an issue with 1.2.7-epa1

Mar 21 2021, 5:11 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.2 Crux

Mar 17 2021

tjh added a comment to T2801: conntrack-tools flooding logs.

This is still a problem, I have just upgraded from 1.2.6-S1 to 1.2.7-epa1 and had two conntrackd's running on the primary router.

Mar 17 2021, 6:01 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
tjh closed T2977: Permissions Denied doing "show conntrack-sync status" on backup router as Resolved.
Mar 17 2021, 6:01 PM
tjh added a comment to T2977: Permissions Denied doing "show conntrack-sync status" on backup router.

This is now fixed in 1.2.7-epa1

Mar 17 2021, 6:00 PM
tjh closed T3367: 1.2.6-S1 -> 1.2.7-epa1 fails - broken system as Resolved.
Mar 17 2021, 5:59 PM
tjh added a comment to T3367: 1.2.6-S1 -> 1.2.7-epa1 fails - broken system.

So I have found a workaround/fix for this.

Mar 17 2021, 5:59 PM

Mar 11 2021

tjh added a comment to T3367: 1.2.6-S1 -> 1.2.7-epa1 fails - broken system.

Same issue. I'm happy to send my config file (not publically) for further debug if that'll help?

Mar 11 2021, 5:40 PM
tjh added a comment to T3367: 1.2.6-S1 -> 1.2.7-epa1 fails - broken system.

Sure thing, I'll try it again tomorrow.

Mar 11 2021, 8:55 AM

Mar 10 2021

tjh added a comment to T3367: 1.2.6-S1 -> 1.2.7-epa1 fails - broken system.

Is there anything else I can do to help debug this issue?

Mar 10 2021, 9:50 PM

Feb 27 2021

tjh created T3367: 1.2.6-S1 -> 1.2.7-epa1 fails - broken system.
Feb 27 2021, 8:31 PM

Nov 20 2020

tjh added a comment to T2977: Permissions Denied doing "show conntrack-sync status" on backup router.

I just saw the patch above for how to fix this and yes, with that line changed to sudo it now works correctly.
Thanks!

Nov 20 2020, 12:23 AM
tjh created T3076: Router reboot adds unwanted 'conntrack-sync mcast-group '225.0.0.50'' line to configuration.
Nov 20 2020, 12:20 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Nov 4 2020

tjh created T3045: Changes to Conntrack-Sync don't apply correctly (Mutlicast->UDP).
Nov 4 2020, 3:17 AM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.2 Crux (VyOS 1.2.9)

Oct 14 2020

tjh created T2977: Permissions Denied doing "show conntrack-sync status" on backup router.
Oct 14 2020, 12:41 AM

Oct 1 2020

tjh created T2949: Vyos 1.2.6-S1 DNS Server does not restart automatically on commit.
Oct 1 2020, 5:59 PM · VyOS 1.2 Crux (VyOS 1.2.7)

Sep 23 2020

tjh added a comment to T2801: conntrack-tools flooding logs.

Additionally, it only happens after a system image upgrade - it doesn't seem to happen if you reboot again after that.

Sep 23 2020, 5:19 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
tjh added a comment to T2801: conntrack-tools flooding logs.

So I just hit this bug again upgrading from 1.2.6-epa1 to 1.2.6.

Sep 23 2020, 10:00 AM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)

Aug 28 2020

tjh updated the task description for T2835: "show system-integrity" reports lots of wrong timestamp packages with v1.2.6-epa1.
Aug 28 2020, 1:10 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.2 Crux
tjh created T2835: "show system-integrity" reports lots of wrong timestamp packages with v1.2.6-epa1.
Aug 28 2020, 1:09 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.2 Crux

Aug 19 2020

tjh added a comment to T2801: conntrack-tools flooding logs.

So I fixed this on my setup by kill -9 conntrackd
and then sudo /etc/init.d/conntrackd start

Aug 19 2020, 11:44 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)

Aug 15 2020

tjh created T2801: conntrack-tools flooding logs.
Aug 15 2020, 8:42 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)

Jun 17 2020

tjh added a comment to T1938: syslog doesn't start automatically.

Hmmm is it the fact I have a remote syslog configured that triggers this bug?
I didn't realise that, I'll have to remove it and see if it helps.
It's very frustrating not having the firewall logs available to view.

Jun 17 2020, 4:15 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)
tjh added a comment to T2478: login radius: use NAS-IP-Address if defined source address.

For what little to no weight my opinion matters, I also agree that this should be backported to Crux.
As I've bashed my head into it testing :-)

Jun 17 2020, 4:14 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)

Jun 8 2020

richardpowellus awarded T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS a Like token.
Jun 8 2020, 7:01 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)

Apr 24 2020

tjh added a comment to T1938: syslog doesn't start automatically.

@jjakob No, it's not logged in the journal either:

Apr 24 2020, 8:52 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)

Apr 16 2020

tjh created T2307: monitor dhcp reports "tail: DHCP: unrecognized file system type 0x794c7630 for ‘/var/log/messages’".
Apr 16 2020, 11:07 PM · VyOS 1.2 Crux
tjh added a comment to T1938: syslog doesn't start automatically.

Some other people reporting similar here.

Apr 16 2020, 6:30 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)

Apr 15 2020

tjh added a comment to T508: ISC DHCP incorrect UDP checksum generation.

I'm seeing this in Vyos 1.2.5 just released:

Apr 15 2020, 2:32 AM · VyOS 1.3 Equuleus (1.3.0-epa1), vyatta-dhcp3
tjh added a comment to T1938: syslog doesn't start automatically.

I've just encountered this bug with Vyos 1.2.5 (final, official ISO)

Apr 15 2020, 1:55 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.6)

Apr 14 2020

tjh created T2288: Include iprange package in Vyos.
Apr 14 2020, 12:58 AM · Restricted Project, VyOS 1.5 Circinus

Apr 13 2020

tjh updated the task description for T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS.
Apr 13 2020, 6:51 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)
tjh created T2279: Router resolves as 127.0.1.1 when using Router's Recursive DNS.
Apr 13 2020, 4:43 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus, VyOS 1.3 Equuleus (1.3.7)

Apr 9 2020

tjh added a comment to T2261: "client-config-dir" not being set for openvpn.

It would appear this commit is the source of the problem - client-config-dir was removed but I don't see anywhere it's re-added.

Apr 9 2020, 8:11 PM · VyOS 1.3 Equuleus (1.3.0)
tjh updated the task description for T2261: "client-config-dir" not being set for openvpn.
Apr 9 2020, 7:29 PM · VyOS 1.3 Equuleus (1.3.0)
tjh created T2261: "client-config-dir" not being set for openvpn.
Apr 9 2020, 7:28 PM · VyOS 1.3 Equuleus (1.3.0)
tjh added a comment to T2248: PPPoE Broken in Latest 1.3 Rolling (1.3-rolling-202004070629).

Thank you @c-po - I can confirm removal of connect-on-demand fixes the problem.
I was under the, obviously mistaken, impression that I needed that command for PPPoE to self-establish on reboot. But I obviously don't as I've just rebooted with the latest 1.3-rolling-202004090909 and it's connected straight away and is working.

Apr 9 2020, 6:55 PM · VyOS 1.3 Equuleus (1.3.0)

Apr 8 2020

tjh updated the task description for T2248: PPPoE Broken in Latest 1.3 Rolling (1.3-rolling-202004070629).
Apr 8 2020, 9:25 PM · VyOS 1.3 Equuleus (1.3.0)
tjh added a comment to T2248: PPPoE Broken in Latest 1.3 Rolling (1.3-rolling-202004070629).

Please find below, with some comments redacted.

Apr 8 2020, 8:50 PM · VyOS 1.3 Equuleus (1.3.0)
tjh updated tjh.
Apr 8 2020, 8:16 PM
tjh added a comment to T2248: PPPoE Broken in Latest 1.3 Rolling (1.3-rolling-202004070629).

The only major differences I've noticed are the kernel versions:

Apr 8 2020, 8:13 PM · VyOS 1.3 Equuleus (1.3.0)
tjh created T2248: PPPoE Broken in Latest 1.3 Rolling (1.3-rolling-202004070629).
Apr 8 2020, 8:11 PM · VyOS 1.3 Equuleus (1.3.0)