Hi @francis the latest FRR version lacks support for Cisco authentication https://github.com/FRRouting/frr/blob/master/nhrpd/nhrp_peer.c#L1212
- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
Feed Search
Jun 6 2021
Jun 6 2021
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 5 2021
Jun 5 2021
Jun 4 2021
Jun 4 2021
c-po closed T3595: Cannot create new VTI interface, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.123 / 5.10.41 to Update Linux Kernel to v5.4.124 / 5.10.42.
c-po moved T3195: Add support for cisco style GRE keepalives from Open to Backlog on the VyOS 1.4 Sagitta board.
c-po changed the status of T3195: Add support for cisco style GRE keepalives from Open to Needs testing.
c-po moved T3195: Add support for cisco style GRE keepalives from Need Triage to Backlog on the VyOS 1.3 Equuleus board.
c-po moved T3592: Set default TTL 64 for tunnels from Need Triage to Finished on the VyOS 1.3 Equuleus board.
c-po moved T3592: Set default TTL 64 for tunnels from Open to Finished on the VyOS 1.4 Sagitta board.
c-po moved T3594: Disable by default service strongswan-starter from Open to Finished on the VyOS 1.4 Sagitta board.
c-po committed rVYOSONEX5a029892e97a: tunnels: T3592: Set default TTL to 64 (authored by sever-sever <[email protected]>).
c-po moved T3132: Enable egress flow accounting from Need Triage to Finished on the VyOS 1.3 Equuleus board.
c-po committed rVYOSONEX77866ccb1619: flow-accounting: T3132: fix egress iptables chain (authored by jpbede).
Jun 3 2021
Jun 3 2021
Yes, also this part will be migrated in the next couple of weeks as we plan to get rid of all legacy code in the 1.4 release cycle.
c-po changed the status of T3595: Cannot create new VTI interface, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, from Open to Confirmed.
Jun 1 2021
Jun 1 2021
Why not use the mentioned method of sysctl`
@shaferstockton can you please post your entire generated openvpn.conf file?
c-po closed T3594: Disable by default service strongswan-starter, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
I can not reproduce the issue using the following command sequence using VyOS 1.4-rolling-202106010417:
May 31 2021
May 31 2021
May 30 2021
May 30 2021
c-po moved T3524: Please implement bgp graceful-shutdown from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.8) board.
c-po moved T3524: Please implement bgp graceful-shutdown from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Turns out this was actually a very small change in the old framework - implemented also on 1.3 and backported to 1.2.8
c-po moved T3524: Please implement bgp graceful-shutdown from Open to Finished on the VyOS 1.4 Sagitta board.
c-po moved T2641: Rewrite vpn ipsec OP commands in new style XML syntax from Open to Finished on the VyOS 1.4 Sagitta board.
c-po moved T3590: bgp: add option for limiting maximum number of prefixes to be sent to a peer from Open to Finished on the VyOS 1.4 Sagitta board.
c-po updated the task description for T3590: bgp: add option for limiting maximum number of prefixes to be sent to a peer.
c-po closed T3590: bgp: add option for limiting maximum number of prefixes to be sent to a peer, a subtask of T2174: Rewrite protocol BGP to new XML/Python style, as Resolved.
c-po closed T2641: Rewrite vpn ipsec OP commands in new style XML syntax, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
c-po edited projects for T3093: Add xml for vpn ipsec, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
c-po closed T3093: Add xml for vpn ipsec, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Also mentioned here: https://forum.vyos.io/t/roadwarrior-config-with-ikev2-and-different-user-groups/2457
Maybe a completion helper could work here, too?
c-po moved T3589: op-mode: support clearing out logfiles from CLI from Open to Finished on the VyOS 1.4 Sagitta board.
c-po moved T3589: op-mode: support clearing out logfiles from CLI from Need Triage to Finished on the VyOS 1.3 Equuleus board.
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
c-po triaged T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan as Normal priority.
c-po changed the status of T3587: Intel QAT support is broken on VyOS 1.4 due to a Kernel Crash from Open to In progress.
May 29 2021
May 29 2021
c-po moved T1995: "show vpn ike sa" command always show child-sas as down from Backport Candidates to Finished on the VyOS 1.4 Sagitta board.
c-po moved T3258: ethernet smoke test damaged from Backlog to Finished on the VyOS 1.4 Sagitta board.
c-po moved T3374: IPv6 GRE Tunnel issues from In Progress to Finished on the VyOS 1.4 Sagitta board.
c-po moved T3321: Bgp not possible to use internal|external remote as from Backlog to Finished on the VyOS 1.4 Sagitta board.
c-po moved T3404: Exception thrown when executing configuration load from Backlog to Finished on the VyOS 1.4 Sagitta board.
c-po moved T483: Add google-authenticator 2fa from Backlog to Finished on the VyOS 1.4 Sagitta board.
c-po moved T3179: Add the ability to generate a support file from Backlog to Finished on the VyOS 1.4 Sagitta board.
c-po moved T3385: Support for disabling ARP responses from Backlog to Finished on the VyOS 1.4 Sagitta board.
c-po moved T3241: Allow configuration of XAuth on IPsec Tunnels from Backlog to Finished on the VyOS 1.4 Sagitta board.
c-po edited projects for T2816: Rewrite IPsec scripts with the new XML/Python approach, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
c-po changed the status of T2816: Rewrite IPsec scripts with the new XML/Python approach from In progress to Needs testing.
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.122 / 5.10.40 to Update Linux Kernel to v5.4.123 / 5.10.41.
c-po added a parent task for T2173: Add the ability to use VRF on VTI interfaces: T1888: Update to StrongSwan 5.9.1.