Page MenuHomeVyOS Platform

vyatta-vrrpProject
ActivePublic

Members

  • This project does not have any members.
  • View All

Watchers

  • This project does not have any watchers.
  • View All

Details

Description

VyOS VRRP

Recent Activity

Fri, Apr 12

dmbaturin removed a project from T5745: conntrack-sync: Multiprimary setups for HA/VRRP: VyOS 1.4 Sagitta.
Fri, Apr 12, 3:14 PM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync

Thu, Apr 11

Viacheslav placed T5745: conntrack-sync: Multiprimary setups for HA/VRRP up for grabs.
Thu, Apr 11, 10:17 AM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync

Tue, Apr 9

Viacheslav added a comment to T5745: conntrack-sync: Multiprimary setups for HA/VRRP.

https://conntrack-tools.netfilter.org/manual.html#sync-aa

conntrackd allows you to deploy an symmetric Active-Active setup based on a static approach. For example, assume that you have two virtual IPs, vIP1 and vIP2, and two firewall replicas, FW1 and FW2. You can give the virtual vIP1 to the firewall FW1 and the vIP2 to the FW2.
Tue, Apr 9, 3:58 PM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync

Jan 19 2024

Viacheslav changed the status of T5745: conntrack-sync: Multiprimary setups for HA/VRRP from Open to Needs reporter action.
Jan 19 2024, 10:43 PM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync
Viacheslav added a comment to T5745: conntrack-sync: Multiprimary setups for HA/VRRP.

@I-n-d-y Try to get it working without VyOS CLI.
Provide the required contrack config. As I'm not sure that it will work correctly at all.

Jan 19 2024, 10:23 PM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync

Nov 16 2023

I-n-d-y added a comment to T5745: conntrack-sync: Multiprimary setups for HA/VRRP.

I have a similar setup where I have two VyOS VMs used as VPN routers with some firewalling enabled. Since I use OSPF for dynamic routing I am not able to synchronize the sessions between both routers so in case one VPN router fails the other one can't take over flawlessly. Having conntrack-sync configuration separated from VRRP would be a great benefit.

Nov 16 2023, 8:19 AM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync
syncer assigned T5745: conntrack-sync: Multiprimary setups for HA/VRRP to Viacheslav.
Nov 16 2023, 1:20 AM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync

Nov 15 2023

Viacheslav added a project to T5745: conntrack-sync: Multiprimary setups for HA/VRRP: VyOS 1.5 Circinus.
Nov 15 2023, 8:10 PM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync
qdrddr created T5745: conntrack-sync: Multiprimary setups for HA/VRRP.
Nov 15 2023, 7:30 PM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync

Nov 23 2022

roedie closed T4526: keepalived-fifo.py unable to load config as Resolved.
Nov 23 2022, 6:23 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta

Oct 30 2022

roedie added a comment to T4526: keepalived-fifo.py unable to load config.

Done: https://github.com/vyos/vyos-1x/pull/1630

Oct 30 2022, 2:53 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta

Oct 10 2022

roedie reopened T4526: keepalived-fifo.py unable to load config as "Backport pending".
Oct 10 2022, 9:18 AM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
roedie added a comment to T4526: keepalived-fifo.py unable to load config.

@florin If this is needed I'll make a pull request coming week.

Oct 10 2022, 9:17 AM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta

Oct 9 2022

florin added a comment to T4526: keepalived-fifo.py unable to load config.

I think this needs to be backported to 1.3 too

Oct 9 2022, 9:14 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta

Sep 17 2022

roedie moved T4526: keepalived-fifo.py unable to load config from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Sep 17 2022, 8:34 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta

Sep 8 2022

roedie closed T4526: keepalived-fifo.py unable to load config as Resolved.

I've tested this and it seems to work correctly.

Sep 8 2022, 5:11 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta

Aug 29 2022

syncer edited projects for T1588: VRRP failed to start if any of its interaces not exist, added: VyOS 1.3 Equuleus (1.3.0); removed VyOS 1.3 Equuleus.
Aug 29 2022, 12:33 PM · VyOS 1.3 Equuleus (1.3.0), vyatta-vrrp
Viacheslav changed the status of T4526: keepalived-fifo.py unable to load config from Open to Needs testing.
Aug 29 2022, 10:51 AM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta

Aug 22 2022

roedie added a comment to T4526: keepalived-fifo.py unable to load config.

https://github.com/vyos/vyos-1x/pull/1486 try#2

Aug 22 2022, 7:51 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
roedie added a comment to T4526: keepalived-fifo.py unable to load config.

I've create a PR which does the retry part. It retries 10 time every 0.5 seconds until it succeeds or it's out of retries.

Aug 22 2022, 4:14 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
krox2 added a comment to T4526: keepalived-fifo.py unable to load config.

This is what I did (forgot to write it here) with the difference that my sleep timer is 60s as my config has many lines.
Would be good to have this fixed properly.

Aug 22 2022, 2:55 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta
roedie added a comment to T4526: keepalived-fifo.py unable to load config.

The problem here seems to be that keepalived is started before the complete commit is finished. So conf.get_config_dict() fails to get the config.

Aug 22 2022, 2:21 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta

Jul 11 2022

krox2 created T4526: keepalived-fifo.py unable to load config.
Jul 11 2022, 3:07 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta

Nov 23 2020

c-po moved T1588: VRRP failed to start if any of its interaces not exist from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Nov 23 2020, 5:20 PM · VyOS 1.3 Equuleus (1.3.0), vyatta-vrrp

Oct 19 2020

Viacheslav closed T1588: VRRP failed to start if any of its interaces not exist as Resolved.
vyos@r4-roll# run show version
Oct 19 2020, 5:58 PM · VyOS 1.3 Equuleus (1.3.0), vyatta-vrrp

Jun 20 2020

c-po renamed T1538: Update conntrack-sync packages to fix VRRP issues from conntrack-sync no longer works with VRRP/high-availability to Update conntrack-sync packages to fix VRRP issues.
Jun 20 2020, 11:59 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T1538: Update conntrack-sync packages to fix VRRP issues from Open to In progress.
Jun 20 2020, 11:59 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

Picking up on the build issue

Jun 20 2020, 11:58 AM · VyOS 1.3 Equuleus (1.3.0)

Jun 14 2020

c-po claimed T1538: Update conntrack-sync packages to fix VRRP issues.
Jun 14 2020, 8:19 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a project to T1538: Update conntrack-sync packages to fix VRRP issues: VyOS 1.3 Equuleus.
Jun 14 2020, 8:11 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.
Jun 14 2020, 8:10 PM · VyOS 1.3 Equuleus (1.3.0)
xrobau placed T1538: Update conntrack-sync packages to fix VRRP issues up for grabs.
Jun 14 2020, 8:02 PM · VyOS 1.3 Equuleus (1.3.0)

Apr 10 2020

jjakob added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

It's best if we just use packages targeted for buster, not another debian release. I suggest you create PRs for all pathches needed (in addition to the one you already submitted) in Debian's PTS for buster's conntrack-tools, and then ask them to make a new release with those patches included.

Apr 10 2020, 3:56 PM · VyOS 1.3 Equuleus (1.3.0)
elbandi added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

The new conntract package depend in newer libnetfilter. but you dont need to rebuild the package, just download the debs.

Apr 10 2020, 3:03 PM · VyOS 1.3 Equuleus (1.3.0)

Apr 8 2020

jjakob added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

There was a new upstream release 1.4.6 7 days ago, but that shouldn't make it to debian stable (buster). Only the patch done by elbandi via PR could get released as 1.4.5-3, but it hasn't been yet. We could make a backport of 1.4.6 into buster-backports and add a custom apt pin for the package. (I'd rather not go the backport route, as that means the backporter needs to always update the upload for security fixes, rather I'd add all patches for bugs into 1.4.5 for buster and ask for a new buster release).

Apr 8 2020, 10:28 PM · VyOS 1.3 Equuleus (1.3.0)

Mar 19 2020

jjakob added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

I opened the PR for our custom build of the package in vyos-build as well: https://github.com/vyos/vyos-build/pulls. I was waiting on testing results from anyone, but I went and tested it myself. The basic functionality works, I couldn't test the above bug. If it's merged and the new package build is added to CI, the above debian PR isn't needed (or our custom build isn't).

Mar 19 2020, 4:34 PM · VyOS 1.3 Equuleus (1.3.0)

Mar 17 2020

elbandi added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

https://salsa.debian.org/pkg-netfilter-team/pkg-conntrack-tools/-/merge_requests/1
if he merge the PR, we can use it!

Mar 17 2020, 8:07 PM · VyOS 1.3 Equuleus (1.3.0)

Mar 16 2020

xrobau triaged T1538: Update conntrack-sync packages to fix VRRP issues as Normal priority.
Mar 16 2020, 1:43 AM · VyOS 1.3 Equuleus (1.3.0)
xrobau added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

Reopened, confirmed broken again.

Mar 16 2020, 1:41 AM · VyOS 1.3 Equuleus (1.3.0)
xrobau reopened T1538: Update conntrack-sync packages to fix VRRP issues as "Open".
Mar 16 2020, 1:41 AM · VyOS 1.3 Equuleus (1.3.0)

Mar 1 2020

jjakob added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

https://github.com/jjakob/vyos-build/tree/conntrack-tools-wip builds conntrack-tools from upstream git snapshot 20200301.

Mar 1 2020, 4:51 PM · VyOS 1.3 Equuleus (1.3.0)

Feb 28 2020

jjakob added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

@cpo I think you need to add it to CI in addition to vyos-build

Feb 28 2020, 10:55 PM · VyOS 1.3 Equuleus (1.3.0)
elbandi added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

That's bad, because debian stable (=buster) is fixing security bugs only. They will not fix/add this patches to conntrack package, they leave conntrack buggy. So you sould build an own conntrack-tools package for 1.3 too :( If not, vyos will be less good software.

Feb 28 2020, 10:34 PM · VyOS 1.3 Equuleus (1.3.0)
jjakob added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

Upstream still hasn't made a release with this patch: https://git.netfilter.org/conntrack-tools/commit/?id=c12fa8df76752b0a011430f069677b52e4dad164
So we could wait on upstream to release it and debian to package it, or build our own as we used to in 1.2.
It would be better to ask upstream to make a release as there's less work for us.

Feb 28 2020, 10:34 PM · VyOS 1.3 Equuleus (1.3.0)
jjakob added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

We don't build conntrack-tools in 1.3 (current/equuleus) any more, upstream Debian Buster conntrack and conntrackd packages are used. So as upstream gets patched, we'll pull in those patches automatically.
If I see things correctly, there are references to conntrack-tools in the build scripts that still need to be removed.

Feb 28 2020, 9:57 PM · VyOS 1.3 Equuleus (1.3.0)

Feb 20 2020

elbandi added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

It's an upstream bug as @xrobau said. vyos dev sould upgrade https://github.com/vyos/conntrack-tools repo, and apply this patch:
https://git.netfilter.org/conntrack-tools/commit/?id=c12fa8df76752b0a011430f069677b52e4dad164

Feb 20 2020, 1:56 PM · VyOS 1.3 Equuleus (1.3.0)

Feb 2 2020

trae32566 added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

Confirmed here as well, I had a working config back on 1.2.3 and it broke when I upgraded to 1.3. This is what happens when I try to commit:

Feb 2 2020, 4:10 AM · VyOS 1.3 Equuleus (1.3.0)

Jan 24 2020

mbailey added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

Confirming that I also report this on 1.3-rolling-202001240217. Just upgraded this morning and I see the same unknown layer 3 protocol error as reported.

Jan 24 2020, 1:50 PM · VyOS 1.3 Equuleus (1.3.0)
_mrplow added a comment to T1538: Update conntrack-sync packages to fix VRRP issues.

This issue is still present in 1.3-rolling-202001240217

Jan 24 2020, 1:26 PM · VyOS 1.3 Equuleus (1.3.0)

Dec 31 2019

zsdc changed the status of T1588: VRRP failed to start if any of its interaces not exist from Open to In progress.
Dec 31 2019, 9:20 PM · VyOS 1.3 Equuleus (1.3.0), vyatta-vrrp