Page MenuHomeVyOS Platform
Feed Search

Aug 25 2021

c-po updated the task description for T3776: Rename FRR daemon restart op-mode commands.
Aug 25 2021, 12:36 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po changed the status of T3776: Rename FRR daemon restart op-mode commands from Open to In progress.
Aug 25 2021, 12:35 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po closed T1514: Add ability to restart frr processes as Resolved.
Aug 25 2021, 12:28 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1514: Add ability to restart frr processes.

Tested working on 1.3.0-rc6

Aug 25 2021, 12:28 PM · VyOS 1.3 Equuleus (1.3.0)
olivier.hault added a comment to T970: Support matching domain name in firewall rules.

+1 for 1.4

Aug 25 2021, 8:15 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po moved T3165: Split node.def generation process into "generic" and "specific" stages from Open to Backlog on the VyOS 1.4 Sagitta board.
Aug 25 2021, 8:11 AM
c-po moved T3773: Delete the "show system integrity" command (to prepare for a re-implementation) from Open to Backlog on the VyOS 1.4 Sagitta board.
Aug 25 2021, 8:11 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Aug 24 2021

c-po merged T3360: Op command 'show interfaces' does not display VRRP VIP into T3772: VRRP virtual interfaces are not shown in show interfaces.
Aug 24 2021, 8:21 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po merged task T3360: Op command 'show interfaces' does not display VRRP VIP into T3772: VRRP virtual interfaces are not shown in show interfaces.
Aug 24 2021, 8:21 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a comment to T3772: VRRP virtual interfaces are not shown in show interfaces.

Similar task T3360

Aug 24 2021, 5:40 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
zsdc created T3774: atop logs are not limited in size.
Aug 24 2021, 5:15 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po closed T3772: VRRP virtual interfaces are not shown in show interfaces as Resolved.
Aug 24 2021, 2:55 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po claimed T3772: VRRP virtual interfaces are not shown in show interfaces.
Aug 24 2021, 2:50 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po changed the status of T3772: VRRP virtual interfaces are not shown in show interfaces from Open to Confirmed.
Aug 24 2021, 2:29 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po added a comment to T3772: VRRP virtual interfaces are not shown in show interfaces.
[email protected]:~$ show interfaces vrrp
Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface        IP Address                        S/L  Description
---------        ----------                        ---  -----------
eth1v10          10.1.1.1/24                       u/u
Aug 24 2021, 2:29 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
dmbaturin created T3773: Delete the "show system integrity" command (to prepare for a re-implementation).
Aug 24 2021, 2:23 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
dmbaturin created T3772: VRRP virtual interfaces are not shown in show interfaces.
Aug 24 2021, 1:36 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Aug 23 2021

lundgrenolof created T3770: BGP neighbor not generating the correct frr configuration when moved to peer-group.
Aug 23 2021, 7:54 AM · VyOS 1.3 Equuleus (1.3.7)
c-po reopened T3165: Split node.def generation process into "generic" and "specific" stages as "Confirmed".
Aug 23 2021, 7:52 AM
c-po closed T2555: XML op-mode generation scripts silently discard XML nodes, a subtask of T3165: Split node.def generation process into "generic" and "specific" stages, as Resolved.
Aug 23 2021, 7:52 AM
c-po closed T2555: XML op-mode generation scripts silently discard XML nodes as Resolved.
Aug 23 2021, 7:52 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Aug 22 2021

c-po closed T3765: container: additional op-mode commands, a subtask of T2216: Containerized third-party applications for VyOS, as Resolved.
Aug 22 2021, 6:59 PM · VyOS 1.4 Sagitta
c-po closed T3165: Split node.def generation process into "generic" and "specific" stages as Unknown Status.
Aug 22 2021, 6:58 PM

Aug 21 2021

yun closed T3682: Remove running dhclient from ether-resume.py as Resolved.

Confirmed fixed, static address is correctly assigned after resume. Tested with vyos-1.3-beta-202108192027-amd64.iso

Aug 21 2021, 2:18 PM · VyOS 1.3 Equuleus (1.3.0)
yun closed T3681: Stray compiled Python objects break the VMware virtual machine resume script as Resolved.

Confirmed fixed, tested with vyos-1.3-beta-202108192027-amd64.iso

Aug 21 2021, 2:15 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS 1.4 Sagitta (1.4.3), VyOS Rolling

Aug 20 2021

jestabro added a project to T1950: Store VyOS configuration syntax version data in JSON file: test.
Aug 20 2021, 8:03 PM · VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
jestabro closed T1950: Store VyOS configuration syntax version data in JSON file as Resolved.
Aug 20 2021, 8:02 PM · VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
jestabro closed T1950: Store VyOS configuration syntax version data in JSON file, a subtask of T688: Move component versions used for config migration purposes into vyos-1x, as Resolved.
Aug 20 2021, 8:02 PM · VyOS 1.3 Equuleus (1.3.0), test
jestabro moved T1950: Store VyOS configuration syntax version data in JSON file from Backport Candidates to Finished on the VyOS 1.3 Equuleus board.
Aug 20 2021, 8:02 PM · VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
jestabro moved T1950: Store VyOS configuration syntax version data in JSON file from Finished to Backport Candidates on the VyOS 1.3 Equuleus board.
Aug 20 2021, 7:20 PM · VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
jestabro moved T1950: Store VyOS configuration syntax version data in JSON file from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 20 2021, 7:20 PM · VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
jestabro added a project to T1950: Store VyOS configuration syntax version data in JSON file: VyOS 1.4 Sagitta.
Aug 20 2021, 7:20 PM · VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
jestabro added a parent task for T1950: Store VyOS configuration syntax version data in JSON file: T688: Move component versions used for config migration purposes into vyos-1x.
Aug 20 2021, 6:43 PM · VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
jestabro added a subtask for T688: Move component versions used for config migration purposes into vyos-1x: T1950: Store VyOS configuration syntax version data in JSON file.
Aug 20 2021, 6:43 PM · VyOS 1.3 Equuleus (1.3.0), test
jestabro reopened T1950: Store VyOS configuration syntax version data in JSON file as "Open".

The json file containing the system component version information was previously an artifact of the XML syntaxVersion implementation; with revisions to the latter in place for 1.4, and initial implementation removed for 1.3, the json file will now be dumped during migration.

Aug 20 2021, 6:43 PM · VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta

Aug 19 2021

jestabro renamed T3768: Remove early syntaxVersion implementation from Remove early syntaxVersion implementation from 1.3 to Remove early syntaxVersion implementation.
Aug 19 2021, 4:15 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jestabro closed T3732: override-default helper should support adding defaultValues to default less nodes as Resolved.
Aug 19 2021, 3:40 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jestabro changed the status of T1962: Add syntax version to schema, a subtask of T1950: Store VyOS configuration syntax version data in JSON file, from Unknown Status to Resolved.
Aug 19 2021, 3:37 PM · VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
jestabro changed the status of T1962: Add syntax version to schema from Unknown Status to Resolved.
Aug 19 2021, 3:37 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro added a parent task for T3768: Remove early syntaxVersion implementation: T3474: Revisit storing syntax version of interface definitions in XML file.
Aug 19 2021, 3:36 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jestabro created T3768: Remove early syntaxVersion implementation.
Aug 19 2021, 3:35 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jestabro closed T2759: validate-value prints error messages from validators that fail even if overall validation succeeds as Resolved.
Aug 19 2021, 3:29 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
jestabro closed T3574: Add constraintGroup for combining validators with logical AND as Resolved.
Aug 19 2021, 3:29 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro changed the status of T3234: multi_to_list fails in certain cases, with root cause an element redundancy in XML interface-definitions from Unknown Status to Resolved.
Aug 19 2021, 3:27 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po added a comment to T3724: Allow setting host-name in l2tp section of accel-ppp.

Another option (which I use) is to specify --sysctl net.ipv6.conf.lo.disable_ipv6=0 during the container startup.

Aug 19 2021, 10:45 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3763: wireguard checks if port already binding from Need Triage to Backlog on the VyOS 1.3 Equuleus board.
Aug 19 2021, 10:42 AM · VyOS 1.4 Sagitta
c-po moved T690: Allow OpenVPN servers to push routes with custom metric values from Open to In Progress on the VyOS 1.4 Sagitta board.
Aug 19 2021, 8:53 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Aug 18 2021

c-po added a comment to T3708: isisd and gre-bridge commit error.

HI @Viacheslav, this works even in 1.3, your problem is that you need to merge it with isis['FOO'] and not isis.

Aug 18 2021, 6:19 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po updated the task description for T3765: container: additional op-mode commands.
Aug 18 2021, 3:42 PM · VyOS 1.4 Sagitta
c-po created T3765: container: additional op-mode commands.
Aug 18 2021, 3:41 PM · VyOS 1.4 Sagitta
c-po added a comment to T3763: wireguard checks if port already binding.

+1

Aug 18 2021, 3:03 PM · VyOS 1.4 Sagitta
dtoux added a comment to T3537: Unable to override the default OSPFv3 link cost for wireguard interface.

Sounds good to me.

Aug 18 2021, 1:13 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav updated the task description for T3763: wireguard checks if port already binding.
Aug 18 2021, 10:26 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T3763: wireguard checks if port already binding.
Aug 18 2021, 10:15 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T3763: wireguard checks if port already binding.
Aug 18 2021, 10:15 AM · VyOS 1.4 Sagitta
Viacheslav created T3763: wireguard checks if port already binding.
Aug 18 2021, 10:10 AM · VyOS 1.4 Sagitta
Viacheslav closed T3537: Unable to override the default OSPFv3 link cost for wireguard interface as Resolved.

I close the task, because it can't be reproducible in 1.3.0-rc5
Re-open it, if necessary with described step by step how to reproduce it.
Or open a new one.

Aug 18 2021, 9:47 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T3708: isisd and gre-bridge commit error.

from vyos.xml import defaults doesn't work for 1.3 correctly, for some reason it gets 2 isis process with same name "FOO"
https://github.com/sever-sever/vyos-1x/commit/7b0a33618bfa1d1ef99b9744ed1ded49a2c832af

[email protected]# compare 
[edit protocols]
+isis FOO {
+    interface tun0 {
+    }
+    net 49.0001.0000.0011.0001.00
+}
[edit]
[email protected]# commit
[ protocols isis FOO ]
{'FOO': {'interface': {'tun0': {}}, 'net': '49.0001.0000.0011.0001.00'},
 'lsp_mtu': '1497'}
Only one isis process can be defined
Aug 18 2021, 9:33 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav placed T3708: isisd and gre-bridge commit error up for grabs.
Aug 18 2021, 9:27 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Aug 17 2021

dtoux added a comment to T3552: BFD does not work with OSPFv3 via wireguard.

Any news on this?

Aug 17 2021, 5:26 PM
dtoux added a comment to T3537: Unable to override the default OSPFv3 link cost for wireguard interface.

I haven't tested it directly but I haven't experienced this problem while working on the configuration changes. I don't have much time right now, so I can't test the exact scenario.

Aug 17 2021, 4:01 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav closed T1643: Deleting all firewall zones failed and locked out box, a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Aug 17 2021, 4:00 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav closed T1643: Deleting all firewall zones failed and locked out box as Resolved.

Not reproducible, tested on "1.3-beta-202108151336"

Aug 17 2021, 4:00 PM · VyOS 1.3 Equuleus (1.3.0), test
ciprian.craciun added a comment to T1753: Configuring `ip source-validation loose` doesn't properly configure `sysctl`.

@Viacheslav Sorry for the long delay in replying.

Aug 17 2021, 2:56 PM · Bugs, VyOS 1.5 Circinus
Viacheslav added a comment to T1753: Configuring `ip source-validation loose` doesn't properly configure `sysctl`.
  1. Bug, values on interfaces are overwritten after firewall global parameters.

By default:

[email protected]# sudo sysctl -a | grep "\.rp_filter"
net.ipv4.conf.all.rp_filter = 0
net.ipv4.conf.default.rp_filter = 0
net.ipv4.conf.eth0.rp_filter = 0
net.ipv4.conf.eth1.rp_filter = 0
net.ipv4.conf.eth2.rp_filter = 0
net.ipv4.conf.lo.rp_filter = 0
net.ipv4.conf.vtun10.rp_filter = 0

Set value for the interface eth2 value "loose"

[email protected]# set interfaces ethernet eth2 ip source-validation 'loose'
[edit]
[email protected]# commit
[email protected]# sudo sysctl -a | grep "\.rp_filter"
net.ipv4.conf.all.rp_filter = 0
net.ipv4.conf.default.rp_filter = 0
net.ipv4.conf.eth0.rp_filter = 0
net.ipv4.conf.eth1.rp_filter = 0
net.ipv4.conf.eth2.rp_filter = 2
net.ipv4.conf.lo.rp_filter = 0
net.ipv4.conf.vtun10.rp_filter = 0
Aug 17 2021, 1:37 PM · Bugs, VyOS 1.5 Circinus
Viacheslav added a comment to T1349: L2TP remote-access vpn terminated and not showing as connected.

@Merijn Any updates?

Aug 17 2021, 12:53 PM · VyOS 1.3 Equuleus (1.3.0), test
Viacheslav added a comment to T1487: DNS (pdns_recursor) stats logs not saved to disk.

@c-po Can we close it?

Aug 17 2021, 12:47 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav closed T508: ISC DHCP incorrect UDP checksum generation as Resolved.

Not more actual for 1.3, as it used isc-dhcp-client/isc-dhcp-relay/isc-dhcp-server 4.4.1-2
I can't find in logs something like bad udp checksums

Aug 17 2021, 12:46 PM · VyOS 1.3 Equuleus (1.3.0-epa1), vyatta-dhcp3
c-po added a comment to T1487: DNS (pdns_recursor) stats logs not saved to disk.

From the manual:

Aug 17 2021, 12:06 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
c-po added a comment to T1550: Add support for Large BGP Community show commands.

VyOS 1.3.0-rc6 (upcoming) and 1.4 have the following commands available:

Aug 17 2021, 11:51 AM · VyOS 1.3 Equuleus (1.3.0), test
Viacheslav added a comment to T1487: DNS (pdns_recursor) stats logs not saved to disk.

Do we need to set this option configurable?
We have an option --disable-syslog so for enable logging it should be --enable-syslog

Aug 17 2021, 11:06 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav added a comment to T1925: DMVPN is always listed as down in "show vpn ipsec sa".

SA only with hub, output correct

vyos@spoke1:~$ show vpn ipsec sa
Connection    State    Uptime    Bytes In/Out    Packets In/Out    Remote address    Remote ID    Proposal
------------  -------  --------  --------------  ----------------  ----------------  -----------  ----------------------------------
dmvpn         up       16m24s    2K/2K           24/23             192.0.2.1         N/A          AES_CBC_256/HMAC_SHA1_96/MODP_1024
vyos@spoke1:~$ 
vyos@spoke1:~$ 
vyos@spoke1:~$ sudo swanctl -l
dmvpn-NHRPVPN-tun100: #1, ESTABLISHED, IKEv1, 2bc867b1ca327379_i* c85b15462b657b03_r
  local  '100.64.1.11' @ 100.64.1.11[500]
  remote '192.0.2.1' @ 192.0.2.1[500]
  AES_CBC-256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
  established 1001s ago, rekeying in 2400s
  dmvpn: #1, reqid 1, INSTALLED, TRANSPORT, ESP:AES_CBC-256/HMAC_SHA1_96/MODP_1024
    installed 1001s ago, rekeying in 505s, expires in 979s
    in  cb2b55ee,   3044 bytes,    24 packets,    91s ago
    out cb3647d6,   2474 bytes,    23 packets,    91s ago
    local  100.64.1.11/32[gre]
    remote 192.0.2.1/32[gre]
vyos@spoke1:~$
Aug 17 2021, 9:46 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T1925: DMVPN is always listed as down in "show vpn ipsec sa".

Tested on VyOS 1.3.0-rc5

Aug 17 2021, 9:40 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T2525: OSPFv3 missing route map, not establishing as Resolved.

Not reproducible update from 1.2.4 to 1.3-rc5
1.2.4 config

set interfaces ethernet eth1 bond-group bond0
set interfaces ethernet eth1 bond-group bond0
set interfaces bonding bond0 vif 29 address '192.168.159.167/31'
set interfaces bonding bond0 vif 29 address 'fd12:45:fff:29::2/126'
set interfaces bonding bond0 vif 29 description 'Point to Point - DMZ'
set interfaces bonding bond0 vif 29 ip ospf dead-interval '20'
set interfaces bonding bond0 vif 29 ip ospf hello-interval '10'
set interfaces bonding bond0 vif 29 ip ospf priority '220'
set interfaces bonding bond0 vif 29 ip ospf retransmit-interval '5'
set interfaces bonding bond0 vif 29 ip ospf transmit-delay '1'
set interfaces bonding bond0 vif 29 ipv6 dup-addr-detect-transmits '1'
set interfaces bonding bond0 vif 29 ipv6 ospfv3 cost '1'
set interfaces bonding bond0 vif 29 ipv6 ospfv3 dead-interval '20'
set interfaces bonding bond0 vif 29 ipv6 ospfv3 hello-interval '10'
set interfaces bonding bond0 vif 29 ipv6 ospfv3 instance-id '0'
set interfaces bonding bond0 vif 29 ipv6 ospfv3 priority '220'
set interfaces bonding bond0 vif 29 ipv6 ospfv3 retransmit-interval '5'
set interfaces bonding bond0 vif 29 ipv6 ospfv3 transmit-delay '1'
set interfaces bonding bond0 vif 29 mtu '1500'
set interfaces loopback lo address 'fd12:45::14/128'
set policy route-map OSPF-Filter description 'This route map will apply to outgoing routes sent via OSPF'
set policy route-map OSPF-Filter rule 10 action 'permit'
set policy route-map OSPF-Filter rule 10 description 'Only permit loopback interface'
set policy route-map OSPF-Filter rule 10 match interface 'lo'
set policy route-map OSPF-Filter rule 100 action 'deny'
set policy route-map OSPF-Filter rule 100 description 'Default deny'
set protocols ospfv3 area 0.0.0.0 interface 'lo'
set protocols ospfv3 area 0.0.0.0 interface 'bond0.29'
set protocols ospfv3 area 0.0.0.0 range fd12:45:fff:29::/126
set protocols ospfv3 parameters router-id '192.168.159.241'
set protocols ospfv3 redistribute connected route-map 'OSPF-Filter'
Aug 17 2021, 8:08 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav closed T1550: Add support for Large BGP Community show commands as Resolved.

Large-community and large-community-list it is different functions.
It seems all works fine

Aug 17 2021, 7:50 AM · VyOS 1.3 Equuleus (1.3.0), test
Viacheslav changed the status of T690: Allow OpenVPN servers to push routes with custom metric values from Open to Needs testing.
Aug 17 2021, 7:34 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T690: Allow OpenVPN servers to push routes with custom metric values.

@darkdragon-001 It will be available in the next rolling release, can you test it?

Aug 17 2021, 7:33 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Aug 16 2021

Viacheslav closed T1594: l2tpv3 error on IPv6 local-ip as Resolved.
Aug 16 2021, 9:19 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta, test
Viacheslav added a comment to T690: Allow OpenVPN servers to push routes with custom metric values.

PR for current https://github.com/vyos/vyos-1x/pull/974

Aug 16 2021, 8:39 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
m.cremers added a comment to T3734: Move EVPN VRF up in FRR config.

Might be good to have a workaround in VyOS in the mean time

Aug 16 2021, 4:47 PM · VyOS 1.4 Sagitta
c-po added a comment to T3734: Move EVPN VRF up in FRR config.

Thank's for opening an upstream bug

Aug 16 2021, 4:39 PM · VyOS 1.4 Sagitta
c-po reopened T3734: Move EVPN VRF up in FRR config as "On hold".
Aug 16 2021, 4:39 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T690: Allow OpenVPN servers to push routes with custom metric values: VyOS 1.4 Sagitta.
Aug 16 2021, 4:20 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
zsdc closed T3735: Configuration with multiple network addresses of firewall network-group via colud-init fails as Resolved.

Thank you for testing! The change was backported to 1.3 and 1.2.

Aug 16 2021, 12:35 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav moved T3738: openvpn fails if server and authentication are configured from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Aug 16 2021, 9:40 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav closed T3738: openvpn fails if server and authentication are configured as Resolved.

Fixed, 1.3-beta-202108151336

[email protected]# run show conf com | match openvpn
set interfaces openvpn vtun10 encryption cipher 'aes256'
set interfaces openvpn vtun10 hash 'sha512'
set interfaces openvpn vtun10 local-host '192.168.122.14'
set interfaces openvpn vtun10 local-port '1194'
set interfaces openvpn vtun10 mode 'server'
set interfaces openvpn vtun10 persistent-tunnel
set interfaces openvpn vtun10 protocol 'udp'
set interfaces openvpn vtun10 server client client1 ip '10.10.0.10'
set interfaces openvpn vtun10 server domain-name 'vyos.net'
set interfaces openvpn vtun10 server max-connections '250'
set interfaces openvpn vtun10 server name-server '172.16.254.30'
set interfaces openvpn vtun10 server subnet '10.10.0.0/24'
set interfaces openvpn vtun10 server topology 'subnet'
set interfaces openvpn vtun10 tls ca-cert-file '/config/auth/ca.crt'
set interfaces openvpn vtun10 tls cert-file '/config/auth/central.crt'
set interfaces openvpn vtun10 tls dh-file '/config/auth/dh.pem'
set interfaces openvpn vtun10 tls key-file '/config/auth/central.key'
set interfaces openvpn vtun10 tls tls-version-min '1.0'
set interfaces openvpn vtun10 use-lzo-compression
[edit]
[email protected]#
[email protected]# set interfaces openvpn vtun10 authentication username foo
[edit]
[email protected]# commit
Aug 16 2021, 9:40 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Viacheslav added a project to T1024: Policy Based Routing by DSCP: VyOS 1.4 Sagitta.
Aug 16 2021, 6:01 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

Aug 15 2021

m.cremers updated the task description for T3734: Move EVPN VRF up in FRR config.
Aug 15 2021, 7:13 PM · VyOS 1.4 Sagitta
m.cremers added a comment to T3734: Move EVPN VRF up in FRR config.

I have just opened a GitHub issue for this at FRR as well: https://github.com/FRRouting/frr/issues/9405

Aug 15 2021, 7:11 PM · VyOS 1.4 Sagitta
m.cremers added a comment to T3734: Move EVPN VRF up in FRR config.

Just checked, the behaviour for this bug is still the same.

Aug 15 2021, 6:35 PM · VyOS 1.4 Sagitta
c-po closed T3756: VyOS generates invalid QR code for wireguard clients as Resolved.
Aug 15 2021, 3:22 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
erkin closed T3275: Disable conntrack helpers by default as Resolved.
Aug 15 2021, 10:55 AM · VyOS 1.5 Circinus

Aug 14 2021

c-po closed T3745: op-mode IPSec show vpn ipse sa sorting as Resolved.
Aug 14 2021, 6:17 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
erkin closed T1083: Implement persistent/random address and port mapping options for NAT rules, a subtask of T2198: Rewrite NAT in new XML/Python style, as Resolved.
Aug 14 2021, 5:54 PM · VyOS 1.3 Equuleus (1.3.0)
erkin closed T1083: Implement persistent/random address and port mapping options for NAT rules, a subtask of T3710: Upgrade the kernel in 1.3 to 5.10, as Resolved.
Aug 14 2021, 5:54 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
erkin closed T1083: Implement persistent/random address and port mapping options for NAT rules as Resolved.

I can confirm that this works fine on the latest 1.3 nightly.

Aug 14 2021, 5:54 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
c-po moved T3745: op-mode IPSec show vpn ipse sa sorting from Open to In Progress on the VyOS 1.4 Sagitta board.
Aug 14 2021, 5:51 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
erkin claimed T1083: Implement persistent/random address and port mapping options for NAT rules.
Aug 14 2021, 5:16 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0), test, VyOS 1.4 Sagitta
c-po changed the status of T3745: op-mode IPSec show vpn ipse sa sorting from Open to Needs testing.
Aug 14 2021, 5:02 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
erkin closed T521: Network services may fail if vyatta-router.service startup takes longer than a few seconds as Resolved.

I cannot replicate this in 1.2.8 or 1.3.0-rc5. No matter how long vyos-router.service (even absurdly high times) stalls, ssh.service happily starts. This was probably resolved a long time ago, making this a ghost bug.

Aug 14 2021, 4:39 PM · VyOS 1.3 Equuleus (1.3.0-epa1)