Page MenuHomeVyOS Platform
Feed Search

Sep 25 2019

hagbard added a comment to T1572: Wireguard keyPair per interface.

There is no such thing like separate identities. You can either decrypt a package or you can't, that's about it. You basically have to hand out more public keys, you have to maintain more keys. As I mentioned before I only see currently disadvantages so far. However the user can chose what way to go and multiple options are always good. If it helps you, well that's nice to hear.

Sep 25 2019, 5:47 PM · VyOS 1.3 Equuleus (1.3.0)
jonaswre added a comment to T1572: Wireguard keyPair per interface.

It's not so much the implementation as I wrote before, it just doesn't seem beneficial. It gets implemented anyway, but I try to understand why a user would like to use that. The private key is by the way no identity and also won't interfere with multiple VPN peers if you are using only one pk. On IP:12345 arrives an encrypted packet, it is simply decrypted using your pk. If it works it's given to your kernel netlink interface as far as I recall and routed there, so no verification of the private key anywhere. If it can't be decrypted, it's discarded. If you have multiple wg interfaces, your 'crypto routing' either allows the traffic to the peer or discards it if it doesn't fit, the private key has nothing to do with that, since the public key of your peer is used to encrypt it. Summary, I still cna't see any benefit having that, which doesn't mean that I won't implement it.

Sep 25 2019, 4:56 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1299: Allow SNMPd to be extended with custom scripts as Resolved.
Sep 25 2019, 3:49 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard moved T1672: Wireguard keys not automatically moved from In Progress to Finished on the VyOS 1.3 Equuleus board.
Sep 25 2019, 3:41 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1672: Wireguard keys not automatically moved as Resolved.
Sep 25 2019, 3:41 PM · VyOS 1.3 Equuleus (1.3.0)
trae32566 added a comment to T1183: BFD Support via FRR.

This feature is currently in the 1.2 rolling release.

Sep 25 2019, 2:06 PM · VyOS 1.2 Crux (VyOS 1.2.4)
adestis added a comment to T1183: BFD Support via FRR.

It would be awsome if the feature could also be made available in the next VyOS 1.2.x version.
Because it likely takes a lot more time until version 1.3 gets released.

Sep 25 2019, 7:30 AM · VyOS 1.2 Crux (VyOS 1.2.4)

Sep 24 2019

hagbard moved T1635: Rewrite interface pseudo-ethernet in new XML/Python style from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Sep 24 2019, 10:47 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard moved T1672: Wireguard keys not automatically moved from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Sep 24 2019, 10:47 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard moved T1681: cleanup wireguard code since tagnodes are now visible from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Sep 24 2019, 10:46 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1681: cleanup wireguard code since tagnodes are now visible from In progress to Needs testing.

https://github.com/vyos/vyos-1x/commit/c6e9285262ddd762aac96ad3fa30d63cdeb2c6f2

Sep 24 2019, 8:39 PM · VyOS 1.3 Equuleus (1.3.0)
kroy added a comment to T1020: OSPF Stops distributing default route after a while.

Can confirm. All my routing tables now have 0.0.0.0/0, no matter what the device is. This is just in 1.2.3.

Sep 24 2019, 3:17 PM · VyOS 1.2 Crux (VyOS 1.2.5)
rherold added a comment to T1020: OSPF Stops distributing default route after a while.

Seems that it s merged an in 1.2.3 it looks in the moment good for me:

Sep 24 2019, 3:06 PM · VyOS 1.2 Crux (VyOS 1.2.5)
zsdc assigned T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred to Unknown Object (User).
Sep 24 2019, 10:17 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po added a comment to T1507: cli: logical redundancy with boolean type.

Unfortunately we have multiple commands like this.

Sep 24 2019, 6:22 AM · VyOS 1.3 Equuleus (1.3.0)
syncer added a project to T1507: cli: logical redundancy with boolean type: VyOS 1.3 Equuleus.
Sep 24 2019, 2:31 AM · VyOS 1.3 Equuleus (1.3.0)

Sep 23 2019

Unknown Object (User) added a comment to T1169: LLDP potentially broken.

Exist interesting moment when LLDPD communicate with cisco ios, after 1 min 55 second LLDPD in VyOS forget cisco device, but cisco device send LLDP (with ethertype encapsulated in vlan 1 0x8100). However LLDPD in VyOS remember mikrotik and other VyOS router, which directly connected, and which also transmit LLDP. I was try using and new version LLDPD which build for myself, but same result.
After adding vlan 1 on directly connected interface with cisco device LLDPD in VyOS, R1 don't forget it.

Sep 23 2019, 11:06 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
maznu added a comment to T1679: during bootup: invalid literal for int() with base 10.

That's fixed the problem we had, but we've encountered some other strangeness.

Sep 23 2019, 10:27 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1681: cleanup wireguard code since tagnodes are now visible from Open to In progress.
Sep 23 2019, 8:10 PM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T1682: Migrate to new Jenkins Pipeline script.
Sep 23 2019, 7:32 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T1682: Migrate to new Jenkins Pipeline script from Open to In progress.
Sep 23 2019, 7:32 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1682: Migrate to new Jenkins Pipeline script.
Sep 23 2019, 7:30 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1681: cleanup wireguard code since tagnodes are now visible.
Sep 23 2019, 7:24 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T1681: cleanup wireguard code since tagnodes are now visible.
Sep 23 2019, 7:24 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1680: DHCP client does not release IP address on exit/deletion, a subtask of T1557: Create generic abstraction for configuring interfaces e.g. IP address, as Resolved.
Sep 23 2019, 7:21 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1680: DHCP client does not release IP address on exit/deletion as Resolved.
Sep 23 2019, 7:21 PM · VyOS 1.3 Equuleus (1.3.0)
c-po triaged T1680: DHCP client does not release IP address on exit/deletion as High priority.
Sep 23 2019, 7:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T1680: DHCP client does not release IP address on exit/deletion, a subtask of T1557: Create generic abstraction for configuring interfaces e.g. IP address, from Open to In progress.
Sep 23 2019, 7:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T1680: DHCP client does not release IP address on exit/deletion from Open to In progress.
Sep 23 2019, 7:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1680: DHCP client does not release IP address on exit/deletion.
Sep 23 2019, 7:17 PM · VyOS 1.3 Equuleus (1.3.0)
kroy added a comment to T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.

At this point I've moved all my ASAs to VyOS, and all my tunnels to Wireguard. Unfortunately I cannot test this setup anymore.

Sep 23 2019, 4:49 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Unknown Object (User) added a comment to T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.

Do you still have that problem?
Did you see EwaldvanGeffen's message?
Do you have any comment on it?

Sep 23 2019, 4:29 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
maznu added a comment to T1679: during bootup: invalid literal for int() with base 10.

Thank you, @c-po, I'll go deploy it now, then! :-)

Sep 23 2019, 4:18 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1679: during bootup: invalid literal for int() with base 10.

https://downloads.vyos.io/rolling/current/amd64/vyos-1.2-rolling-201909231545-amd64.iso

Sep 23 2019, 4:15 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1679: during bootup: invalid literal for int() with base 10.

ISO rebuild triggered

Sep 23 2019, 4:01 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1679: during bootup: invalid literal for int() with base 10.

It's in 1.2 rolling too, but the iso has to rebuild. You can alternatively download and manually install http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyos-1x/vyos-1x_1.3.0-16_all.deb.

Sep 23 2019, 3:44 PM · VyOS 1.3 Equuleus (1.3.0)
maznu added a comment to T1679: during bootup: invalid literal for int() with base 10.

Has this been merged into 1.2, or just 1.3? Because all of the 1.2-rolling images currently available from downloads.vyos.io right now have this bug in them :-(

Sep 23 2019, 3:42 PM · VyOS 1.3 Equuleus (1.3.0)
maznu added a comment to T1237: Static Route Path Monitoring, failover.

MikroTik RouterOS supports something like this:

Sep 23 2019, 3:34 PM · VyOS 1.4 Sagitta
maznu added a comment to T732: Netflow: generate ASNs from the uacctd BGP thread..

Why does this BGP neighbor need to be configred in the VyOS CLI? Wouldn't it be added automatically as a side-effect of wanting netflow data to have ASNs? Maybe add a flag to netflow, for those of us who are carrying full tables.

Sep 23 2019, 3:31 PM
hagbard closed T1679: during bootup: invalid literal for int() with base 10 as Resolved.

https://github.com/vyos/vyos-1x/commit/eed2ba5379067ba3ef3a7b9eef72b8252958e766

Sep 23 2019, 3:18 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1679: during bootup: invalid literal for int() with base 10.
Sep 23 2019, 3:18 PM · VyOS 1.3 Equuleus (1.3.0)
maznu added a comment to T1514: Add ability to restart frr processes.

Having had bgpd peg a core to 100% (for no discernible reason), I'd welcome the ability to give quag^WFRR a kick, rather than rebooting the entire VyOS box.

Sep 23 2019, 3:14 PM · VyOS 1.3 Equuleus (1.3.0)
maznu added a comment to T1520: Advanced network monitoring: nTop or similar.

We run ntop on a separate device, and export netflow data to the ntop/nprobe box from our routers (VyOS included). Would that work in your scenario too?

Sep 23 2019, 3:12 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard edited projects for T1679: during bootup: invalid literal for int() with base 10, added: VyOS 1.3 Equuleus; removed VyOS 1.2 Crux.
Sep 23 2019, 3:10 PM · VyOS 1.3 Equuleus (1.3.0)
avanier added a comment to T1030: Upgrade ddclient from 3.8.2 to 3.9.0 (support Cloudflare API v4).

To elaborate on what was written above, in the case of amd64 packages, a package more recent than 3.8.2 is not available from the debian.org repository as there are no more recent releases. The official SourceForge project has been marked as unmaintained by its owner wimpunk, and 3.8.2 was the last release.

Sep 23 2019, 1:30 AM · VyOS 1.2 Crux (VyOS 1.2.4)

Sep 22 2019

Unknown Object (User) added a comment to T1169: LLDP potentially broken.

Hello @kroy I trying test your issue in lab and some question about rfc4957, Does LLDP should see more one neighbour? In my Lab all directly connected devices filter ethertype LLDP (0x88cc) for passthrough. Can you explain, how exactly connected R1,R2,R3,R4? In one switch?

Sep 22 2019, 10:58 PM · VyOS 1.3 Equuleus (1.3.0-epa1)

Sep 21 2019

hard added a comment to T1083: Implement persistent/random address and port mapping options for NAT rules.

Created pull request

Sep 21 2019, 8:37 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
trae32566 added a comment to T1183: BFD Support via FRR.

Just some feedback here, but this has been working flawlessly in all my environments so far for BGP, OSPF, and OSPFv3 ... you guys are awesome!

Sep 21 2019, 6:47 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hard added a comment to T1083: Implement persistent/random address and port mapping options for NAT rules.

Almost done, also implemented 'random' flag, looks ok? or change name? for example - flag, or flags

Sep 21 2019, 6:33 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
vindenesen added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

Using 1.2-rolling-201909210810, it has happened to me.

Sep 21 2019, 6:28 PM · VyOS 1.3 Equuleus (1.3.0)
c-po edited projects for T1675: OpenVPN - Specify minimum TLS version, added: VyOS 1.3 Equuleus; removed VyOS 1.2 Crux.
Sep 21 2019, 8:06 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1677: Support configuration of Ethernet SMP affinity in new Python/XML implementation.
Sep 21 2019, 7:55 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1637: Rewrite ethernet interface in new style XML syntax, a subtask of T1579: Rewrite all interface types in new XML/Python style, as Resolved.
Sep 21 2019, 7:55 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1637: Rewrite ethernet interface in new style XML syntax as Resolved.
Sep 21 2019, 7:55 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T1676: [equuleus] buster: update GRUB boot parameters during upgrade, a subtask of T476: Update the base system to Debian 10 (Buster), as Resolved.
Sep 21 2019, 12:09 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
jestabro closed T1676: [equuleus] buster: update GRUB boot parameters during upgrade as Resolved.
Sep 21 2019, 12:09 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro added a subtask for T476: Update the base system to Debian 10 (Buster): T1676: [equuleus] buster: update GRUB boot parameters during upgrade.
Sep 21 2019, 12:07 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
jestabro added a parent task for T1676: [equuleus] buster: update GRUB boot parameters during upgrade: T476: Update the base system to Debian 10 (Buster).
Sep 21 2019, 12:07 AM · VyOS 1.3 Equuleus (1.3.0)

Sep 20 2019

jestabro changed the status of T1676: [equuleus] buster: update GRUB boot parameters during upgrade from Open to In progress.
Sep 20 2019, 9:44 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T1602: equuleus: buster: add live build apt options for choosing vyos packages, a subtask of T476: Update the base system to Debian 10 (Buster), as Resolved.
Sep 20 2019, 9:29 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
jestabro closed T1602: equuleus: buster: add live build apt options for choosing vyos packages as Resolved.
Sep 20 2019, 9:29 PM · VyOS 1.3 Equuleus (1.3.0)
hard added a watcher for VyOS 1.3 Equuleus: hard.
Sep 20 2019, 9:14 PM
c-po added a comment to T1673: vif bridge-group not migrated to bridge member interface.

Please add the config here as text so it can be easily extracted. Image hosting services tend to not store information forever.

Sep 20 2019, 6:03 AM · VyOS 1.3 Equuleus (1.3.0)
kroy closed T1638: vyos-hostsd not setting system domain name , a subtask of T1598: New implementation of the resolv.conf and hosts update mechanism, as Resolved.
Sep 20 2019, 12:44 AM · VyOS 1.2 Crux (VyOS 1.2.3)

Sep 19 2019

hagbard added a comment to T1672: Wireguard keys not automatically moved.

Would be very nice, I tested with an old one already, but want to make sure I haven't uncovered side effects.

Sep 19 2019, 9:26 PM · VyOS 1.3 Equuleus (1.3.0)
mb300sd added a comment to T1672: Wireguard keys not automatically moved.

Already fixed manually, but I can test on yesterday's vm backup if needed.

Sep 19 2019, 9:15 PM · VyOS 1.3 Equuleus (1.3.0)
mb300sd added a comment to T1673: vif bridge-group not migrated to bridge member interface.

Not sure what you mean by pre and post-commit config blocks.

Sep 19 2019, 8:43 PM · VyOS 1.3 Equuleus (1.3.0)
c-po edited a custom field on T1666: Deleting a bond will place member interfaces into A/D state.
Sep 19 2019, 8:23 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1666: Deleting a bond will place member interfaces into A/D state, a subtask of T1614: Rewrite bonding interface in new style XML syntax, as Resolved.
Sep 19 2019, 8:23 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1666: Deleting a bond will place member interfaces into A/D state as Resolved.
Sep 19 2019, 8:23 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1672: Wireguard keys not automatically moved from In progress to Needs testing.

https://github.com/vyos/vyos-1x/commit/eb9c6ff745fc5d4e23c224a441874ae6fcf97ac5
@mb300sd Tomorrows rolling will have the fix applied.

Sep 19 2019, 8:20 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T1673: vif bridge-group not migrated to bridge member interface.
Sep 19 2019, 8:17 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1672: Wireguard keys not automatically moved from Confirmed to In progress.
Sep 19 2019, 8:07 PM · VyOS 1.3 Equuleus (1.3.0)
mb300sd created T1674: Support [virtual] dvd device in add system image.
Sep 19 2019, 8:02 PM
hagbard triaged T1672: Wireguard keys not automatically moved as Normal priority.
Sep 19 2019, 7:39 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard edited projects for T1672: Wireguard keys not automatically moved, added: VyOS 1.3 Equuleus; removed VyOS 1.2 Crux.
Sep 19 2019, 7:39 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1671: rewrite udev script logic /lib/udev/vyatta_net_name.

https://phabricator.vyos.net/T1499

Sep 19 2019, 6:49 PM · VyOS 1.3 Equuleus (1.3.6)
hagbard claimed T1671: rewrite udev script logic /lib/udev/vyatta_net_name.
Sep 19 2019, 5:32 PM · VyOS 1.3 Equuleus (1.3.6)
hagbard created T1671: rewrite udev script logic /lib/udev/vyatta_net_name.
Sep 19 2019, 5:32 PM · VyOS 1.3 Equuleus (1.3.6)
jjakob added a comment to T1416: 2 dhcp server run in failover mode can't sync hostname with each other.

@thinkl33t you can run your own DNS server with dynamic update functionality, vyos's dhcp server will write the hostnames to it. Doing that is outside the scope of vyos though, and you'd have to think of security, e.g. can a rogue dhcp client DNS spoof your hostnames to do a MITM attack. Systems that do do dyn-dns updates, for example FreeIPA, usually use some sort of pre-shared keys/certificates on the clients (for authentication) and limit the scope to IP updates on preexisting hostnames only, they don't allow adding arbitrary hostnames. At least I'd limit the scope to add all dynamic dns updates to a single zone predefined expressly for that purpose, and not use that zone for any security-critical applications, like logging in to services or doing unauthenticated connections, where a MITM may scrape your sensitive data. I'd only do dyn-dns hostnames from dhcp on a DHCP network where I'm absolutely sure no rogue client could gain access to it, via the network or physically, and that is almost never useful.

Sep 19 2019, 4:33 PM · VyOS 1.2 Crux (VyOS 1.2.5)
hagbard changed the status of T1635: Rewrite interface pseudo-ethernet in new XML/Python style, a subtask of T1579: Rewrite all interface types in new XML/Python style, from Open to In progress.
Sep 19 2019, 4:10 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1635: Rewrite interface pseudo-ethernet in new XML/Python style from Open to In progress.
Sep 19 2019, 4:10 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard moved T1664: Ipoe with bond per vlan don't work from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Sep 19 2019, 3:19 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a project to T1664: Ipoe with bond per vlan don't work: VyOS 1.3 Equuleus.
Sep 19 2019, 3:19 PM · VyOS 1.3 Equuleus (1.3.0)
thinkl33t added a comment to T1416: 2 dhcp server run in failover mode can't sync hostname with each other.
In T1416#40429, @zsdc wrote:

@thinkl33t, recommended way is using dynamic-dns-update, all other ways are not recommended to use at this moment.

Sep 19 2019, 11:15 AM · VyOS 1.2 Crux (VyOS 1.2.5)

Sep 18 2019

kroy created T1669: Stacking routers, for centralized management.
Sep 18 2019, 11:33 PM
rherold added a comment to T1020: OSPF Stops distributing default route after a while.

Seems that upstream did not backport the fixes to the stable version's. So it is only included in frr 7.2.
I asked them for backport.

Sep 18 2019, 9:52 PM · VyOS 1.2 Crux (VyOS 1.2.5)
hagbard closed T1597: /usr/sbin/rsyslogd after deleting "system syslog" as Unknown Status.
Sep 18 2019, 6:33 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po added a comment to T1666: Deleting a bond will place member interfaces into A/D state.

Okay, the old vyatta-bonding.pl executed the following code when a bond member has been removed:

Sep 18 2019, 5:38 AM · VyOS 1.3 Equuleus (1.3.0)

Sep 17 2019

Unknown Object (User) closed T239: Improve documentation for the firewall all-ping setting as Resolved.
Sep 17 2019, 4:03 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Unknown Object (User) added a comment to T239: Improve documentation for the firewall all-ping setting.

PR merged.

Sep 17 2019, 4:03 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin created T1667: Add a tool for automatically importing old style command definitions into XML.
Sep 17 2019, 3:21 PM · VyOS 1.3 Equuleus (1.3.6)
Unknown Object (User) added a comment to T1421: OpenVPN client push-route stopped working, needs added quotes to fix.

This issue don't reproduces at 1.2.2 and 1.2.3-epa1. As for rolling release after T1548, seems all correct and works.

set interfaces openvpn vtun0 server push-route '100.64.0.0/24'
set interfaces openvpn vtun0 server push-route '172.16.41.0/24'
set interfaces openvpn vtun0 server push-route '172.16.42.0/24'
vyos@vyos# sudo cat /opt/vyatta/etc/openvpn/openvpn-vtun0.conf | grep push
push "route 100.64.0.0 255.255.255.0"
push "route 172.16.41.0 255.255.255.0"
push "route 172.16.42.0 255.255.255.0"

on client

vyos@vyos-rtr01# run show ip route | grep vtun0
S>* 10.23.0.0/16 [1/0] is directly connected, vtun0, 00:03:25
C>* 10.23.1.1/32 is directly connected, vtun0, 00:03:25
K>* 100.64.0.0/24 [0/0] via 10.23.1.1, vtun0, 00:03:25
K>* 172.16.41.0/24 [0/0] via 10.23.1.1, vtun0, 00:03:25
K>* 172.16.42.0/24 [0/0] via 10.23.1.1, vtun0, 00:03:25

@kronenpj can you try last rolling release for confirm this?

Sep 17 2019, 12:21 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po closed T1525: OpenVPN server clients disconnected after 60 mins as Invalid.
Sep 17 2019, 3:41 AM · VyOS 1.3 Equuleus (1.3.0)

Sep 16 2019

Unknown Object (User) added a comment to T1525: OpenVPN server clients disconnected after 60 mins.

I have just sent a Pull Request to clarify on the manual how tricky openvpn-option --reneg-sec can be.

Sep 16 2019, 11:40 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1040: rc.local is executed too early as Resolved.

@rcit Lot's of development underway and since I wasn't able to reproduce it anymoe, I thought I ask, Feel free to reopen if the issue re-occurs.

Sep 16 2019, 6:08 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po claimed T1666: Deleting a bond will place member interfaces into A/D state.
Sep 16 2019, 5:55 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1666: Deleting a bond will place member interfaces into A/D state.
Sep 16 2019, 4:28 PM · VyOS 1.3 Equuleus (1.3.0)
rcit added a comment to T1040: rc.local is executed too early.

@hagbard I don't know if this is somehow relevant regarding VyOS 1.3, but i have tested it with VyOS 1.2.3-epa1 just today and it works perfectly.

Sep 16 2019, 3:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Unknown Object (User) added a comment to T239: Improve documentation for the firewall all-ping setting.

Thank you Taras. Pull request sent.
https://github.com/vyos/vyos-documentation/pull/103

Sep 16 2019, 2:33 PM · VyOS 1.3 Equuleus (1.3.0-epa1)