Page MenuHomeVyOS Platform

xrpixer (Jordan Weaver)
User

Projects

User does not belong to any projects.

User Details

User Since
Sep 6 2016, 2:54 PM (397 w, 3 d)

Recent Activity

Jan 13 2023

xrpixer created T4936: Certificate Auto Enrollment via SCEP.
Jan 13 2023, 4:48 AM · VyOS 1.5 Circinus

Nov 26 2019

xrpixer added a comment to T1361: VRRP Starts After FRR, Creating Inconsistent Routes -.

This appears to be fixed in 1.2.4 EPA1.

Nov 26 2019, 4:55 AM · VyOS 1.2 Crux (VyOS 1.2.4)

Jul 12 2019

xrpixer added a comment to T1157: Static route not reachable through VRRP address.

@bmtauer is this still a problem for you?

Jul 12 2019, 3:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

May 2 2019

xrpixer created T1362: Incorrect handling of special characters in VRRP passwords.
May 2 2019, 3:37 AM · VyOS 1.2 Crux (VyOS 1.2.3)
xrpixer created T1361: VRRP Starts After FRR, Creating Inconsistent Routes -.
May 2 2019, 3:25 AM · VyOS 1.2 Crux (VyOS 1.2.4)

Feb 14 2019

xrpixer closed T1245: Cannot Clamp MSS on Transient Bridge Interfaces - Turn On br_netfilter as Resolved.
Feb 14 2019, 7:48 PM · VyOS 1.2 Crux (VyOS 1.2.1)
xrpixer added a comment to T1245: Cannot Clamp MSS on Transient Bridge Interfaces - Turn On br_netfilter.

The last rolling worked great. Saw the module was loaded on boot and MSS was clamped correctly.
Thanks!

Feb 14 2019, 7:46 PM · VyOS 1.2 Crux (VyOS 1.2.1)

Feb 13 2019

xrpixer added a comment to T1245: Cannot Clamp MSS on Transient Bridge Interfaces - Turn On br_netfilter.

Thank you!
I'll test the next rolling asap and report back.

Feb 13 2019, 10:33 PM · VyOS 1.2 Crux (VyOS 1.2.1)
xrpixer added a comment to T1245: Cannot Clamp MSS on Transient Bridge Interfaces - Turn On br_netfilter.

Yes! That's what i need.
In my script above i had to put modprobe br_netfilter so it loads on system boot.

modprobe br_netfilter
iptables -t mangle -I POSTROUTING -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1400

If we could have br_netfilter loaded on boot in the image that would be great and would fix this problem.

Feb 13 2019, 5:13 PM · VyOS 1.2 Crux (VyOS 1.2.1)
xrpixer renamed T1245: Cannot Clamp MSS on Transient Bridge Interfaces - Turn On br_netfilter from Cannot Clamp MSS on Virtual Machine to Cannot Clamp MSS on Transient Bridge Interfaces - Turn On br_netfilter.
Feb 13 2019, 3:28 PM · VyOS 1.2 Crux (VyOS 1.2.1)
xrpixer added a comment to T1245: Cannot Clamp MSS on Transient Bridge Interfaces - Turn On br_netfilter.

Sorry i'm not sure we're on the same page.

Feb 13 2019, 3:26 PM · VyOS 1.2 Crux (VyOS 1.2.1)
xrpixer added a comment to T1245: Cannot Clamp MSS on Transient Bridge Interfaces - Turn On br_netfilter.

@c-po thanks for mentioning the PPPoE connection, really got me thinking about the word POSTROUTING!
The solution is this -

Feb 13 2019, 5:41 AM · VyOS 1.2 Crux (VyOS 1.2.1)
xrpixer added a comment to T1245: Cannot Clamp MSS on Transient Bridge Interfaces - Turn On br_netfilter.
In T1245#32694, @c-po wrote:

Your second command does kot specify any output interface whereas the first command speciefies tun0. Especially on ESXi you see almost no difference compared ro a vietual Box.

I myself run 1.2.0 in both a Physical and ESXi instance on PPPoE and use the clamping commands successfully on both nodes

Feb 13 2019, 5:00 AM · VyOS 1.2 Crux (VyOS 1.2.1)

Feb 12 2019

xrpixer created T1245: Cannot Clamp MSS on Transient Bridge Interfaces - Turn On br_netfilter in the S1 VyOS Public space.
Feb 12 2019, 8:50 PM · VyOS 1.2 Crux (VyOS 1.2.1)

Jan 11 2019

xrpixer added a comment to T1068: Completion data buffer is too small.

Since the vyos-build readme was updated, i was able to update and test the change I requested above.
It fixes the issue presented above.

Jan 11 2019, 5:55 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Nov 30 2018

xrpixer created T1068: Completion data buffer is too small.
Nov 30 2018, 6:12 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Oct 17 2018

xrpixer added a comment to T100: Create image for Google Compute Engine.

Any further action on this?
I can't find any public images and this thread is a bit lacking in information.

Oct 17 2018, 5:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9), Google Cloud Platform Support
xrpixer added a comment to T534: VPN/IPSEC/BGP/DPD - unknown bug, tunnel and interfaces up, but no traffic.

@mario is your ike-lifetime correct? That looks really short for an aws tunnel.
Otherwise yeah, I'd try with 1.2.

Oct 17 2018, 1:50 PM · Rejected

May 25 2018

xrpixer added a watcher for Google Cloud Platform Support : xrpixer.
May 25 2018, 9:10 PM

Feb 11 2018

sebastianm awarded T535: Ability to add tun interfaces to br groups a Like token.
Feb 11 2018, 10:26 PM · Restricted Project

Feb 6 2018

xrpixer created T538: Support for network mapping in NAT.
Feb 6 2018, 4:17 AM · VyOS 1.4 Sagitta

Feb 4 2018

xrpixer added a comment to T534: VPN/IPSEC/BGP/DPD - unknown bug, tunnel and interfaces up, but no traffic.

So just to be clear,

Feb 4 2018, 10:13 PM · Rejected
xrpixer created T535: Ability to add tun interfaces to br groups.
Feb 4 2018, 9:43 PM · Restricted Project

Feb 1 2018

xrpixer closed T532: arp-monitor on bond interface does not commit as Resolved.
Feb 1 2018, 5:03 AM · VyOS 1.1.x
xrpixer added a comment to T532: arp-monitor on bond interface does not commit.

Sorry for the late response on this.

Feb 1 2018, 5:03 AM · VyOS 1.1.x
xrpixer added a comment to Q125: routing.

Why is this tagged under 1.2.x? You stated you're on version 1.1.8.

Feb 1 2018, 4:17 AM · VyOS 1.2 Crux

Jan 28 2018

xrpixer created T532: arp-monitor on bond interface does not commit.
Jan 28 2018, 1:54 AM · VyOS 1.1.x

Sep 6 2016

xrpixer added Q39: How to force source address over IPsec site-to-site VPN? (Answer 79).
Sep 6 2016, 2:59 PM