Page MenuHomeVyOS Platform
Feed All Stories

Nov 4 2021

c-po added a parent task for T3967: Feature Request: BGP conditional advertisement: T3753: frr: upgrade to stable/8.1 release train.
Nov 4 2021, 5:24 PM
c-po added a subtask for T3753: frr: upgrade to stable/8.1 release train: T3967: Feature Request: BGP conditional advertisement.
Nov 4 2021, 5:24 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3931: SSTP doesn't work after rewriting to PKI, a subtask of T3642: PKI configuration, from Confirmed to Needs testing.
Nov 4 2021, 4:24 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav changed the status of T3931: SSTP doesn't work after rewriting to PKI from Confirmed to Needs testing.
Nov 4 2021, 4:24 PM · VyOS 1.4 Sagitta
Viacheslav assigned T3931: SSTP doesn't work after rewriting to PKI to sarthurdev.
Nov 4 2021, 4:23 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3969: Container incorrect raiseError format if network doesn't exist.

PR https://github.com/vyos/vyos-1x/pull/1065

Nov 4 2021, 3:55 PM · VyOS 1.4 Sagitta
Viacheslav claimed T3969: Container incorrect raiseError format if network doesn't exist.
Nov 4 2021, 3:38 PM · VyOS 1.4 Sagitta
Viacheslav created T3969: Container incorrect raiseError format if network doesn't exist.
Nov 4 2021, 3:38 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T3968: Add network type ptp (veth) for containers.
Nov 4 2021, 2:08 PM · VyOS Rolling
Viacheslav updated the task description for T3968: Add network type ptp (veth) for containers.
Nov 4 2021, 2:04 PM · VyOS Rolling
Viacheslav created T3968: Add network type ptp (veth) for containers.
Nov 4 2021, 2:04 PM · VyOS Rolling
erkin claimed T3962: Image cannot be built without open-vm-tools.
Nov 4 2021, 12:38 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po closed T3964: SSTP: local-user static-ip CLI node accepts invalid IPv4 addresses as Resolved.
Nov 4 2021, 10:57 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEX8dcb08991679: sstp: accel-ppp: T3964: add missing input validator for static-ip assignment.
Nov 4 2021, 10:55 AM
GitHub <[email protected]> committed rVYOSONEX8bfece476c09: Merge pull request #1063 from vyos/t3964-add-missing-validator (authored by c-po).
Nov 4 2021, 10:55 AM
Unknown Object (User) changed the status of T3294: Images for Dell VEP platform use no default baud rate for this platform from Open to Confirmed.
Nov 4 2021, 8:58 AM · VyOS 1.2 Crux (VyOS 1.2.9)
Unknown Object (User) created T3967: Feature Request: BGP conditional advertisement.
Nov 4 2021, 5:34 AM

Nov 3 2021

blackhole added a comment to T375: WAN failover, not to balance the load.

Can I please check if this may have any resolution in the near future?
I am hoping to rely on this but at the moment it just load balances instead of fail over and that gets very very expensive when the backup is an ethernet port based 4G modem.

Nov 3 2021, 10:21 PM · Restricted Project, VyOS Rolling
Kim Hagen <[email protected]> committed rVYOSONEXfe9936ee2b06: openvpn: T3966: OpenVPN fix the smoketests.
Nov 3 2021, 8:41 PM
GitHub <[email protected]> committed rVYOSONEX5181fb7facfa: Merge pull request #1064 from UnicronNL/current (authored by UnicronNL).
Nov 3 2021, 8:41 PM
UnicronNL created T3966: OpenVPN fix the smoketests.
Nov 3 2021, 8:27 PM · VyOS 1.4 Sagitta
runar claimed T3965: arm: Extend configure scripts to allow for arm builds.
Nov 3 2021, 8:13 PM · VyOS 1.4 Sagitta
runar created T3965: arm: Extend configure scripts to allow for arm builds.
Nov 3 2021, 8:00 PM · VyOS 1.4 Sagitta
GitHub <[email protected]> committed rVYOSONEXb8f702bc7b6e: sstp: accel-ppp: T3964: add missing input validator for static-ip assignment (authored by c-po).
Nov 3 2021, 7:03 PM
c-po committed rVYOSONEX8ec9a2dc7c14: sstp: T2566: use XML defaultValue over Jinja2 hardcoded value.
Nov 3 2021, 6:58 PM
c-po committed rVYOSONEX2ed561e249e7: sstp: T2566: Fix to allow IPv6 only pools (authored by Viacheslav).
Nov 3 2021, 6:57 PM
c-po committed rVYOSONEX01ed77040ec9: sstp: T2566: use XML defaultValue over Jinja2 hardcoded value.
Nov 3 2021, 6:55 PM
c-po updated the task description for T3964: SSTP: local-user static-ip CLI node accepts invalid IPv4 addresses.
Nov 3 2021, 6:54 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po claimed T3964: SSTP: local-user static-ip CLI node accepts invalid IPv4 addresses.
Nov 3 2021, 6:53 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po created T3964: SSTP: local-user static-ip CLI node accepts invalid IPv4 addresses.
Nov 3 2021, 6:53 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin changed the status of T3950: CLI backtrace on update if DNS not defined from Open to In progress.
Nov 3 2021, 6:42 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXdd036c62d137: sstp: T2566: Fix to allow IPv6 only pools.
Nov 3 2021, 6:30 PM
GitHub <[email protected]> committed rVYOSONEX7a7233a52895: Merge pull request #1060 from sever-sever/T2566 (authored by c-po).
Nov 3 2021, 6:30 PM
c-po added a comment to T3936: [Feature] - DHCP Option 82 Support.

Any idea how you would like the CLI to look like for option 82 support?

Nov 3 2021, 6:27 PM · VyOS Rolling
c-po assigned T3950: CLI backtrace on update if DNS not defined to erkin.
Nov 3 2021, 6:14 PM · VyOS 1.4 Sagitta
c-po changed the status of T3510: RADIUS usersname is not shown on CLI from Open to Needs testing.
Nov 3 2021, 6:14 PM · VyOS 1.4 Sagitta
c-po added a comment to T3510: RADIUS usersname is not shown on CLI.

I use Microsoft NPS and it feels correct for me:

Nov 3 2021, 6:13 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T2281: DHCP and Static IPs on Same Interface from In progress to Needs testing.
Nov 3 2021, 5:58 PM · VyOS 1.4 Sagitta
c-po added a comment to T2869: Intel ethernet driver defaults sub-optimal.

I also have some of those APU4 devices and they work actually pretty good. The reasons for those "low" defaults are actually not from VyOS but from the Linux Kernel itself.

Nov 3 2021, 5:46 PM
c-po closed T3952: Add sh bgp ipv4/ipv6 vpn command as Resolved.
Nov 3 2021, 5:40 PM · VyOS 1.4 Sagitta
c-po moved T3960: FRR Misconfig when using multiple VRF VNI from Open to Backlog on the VyOS 1.4 Sagitta board.
Nov 3 2021, 5:40 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX05fccc464d71: interfaces: T2281: Ability to set static and DHCP addr on same interface.
Nov 3 2021, 5:38 PM
GitHub <[email protected]> committed rVYOSONEXc605e211584b: Merge pull request #1058 from sever-sever/T2281 (authored by c-po).
Nov 3 2021, 5:38 PM
sarthurdev committed rVYOSONEXa63aa6129324: sstp: T3931: Fixes PKI integration with SSTP.
Nov 3 2021, 5:32 PM
GitHub <[email protected]> committed rVYOSONEXc59e558f1ebc: Merge pull request #1062 from sarthurdev/T3931 (authored by c-po).
Nov 3 2021, 5:32 PM
jb.vedel added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Same issue for me, i use the last RC 1.3 release (manualy builded yesterday).
Will you correct this bug until the LTS release ?

Nov 3 2021, 1:32 PM
sarthurdev added a comment to T3931: SSTP doesn't work after rewriting to PKI.

PR: https://github.com/vyos/vyos-1x/pull/1062

Nov 3 2021, 1:31 PM · VyOS 1.4 Sagitta
haakon.nore awarded T3294: Images for Dell VEP platform use no default baud rate for this platform a Like token.
Nov 3 2021, 1:12 PM · VyOS 1.2 Crux (VyOS 1.2.9)
Unknown Object (User) edited projects for T3294: Images for Dell VEP platform use no default baud rate for this platform, added: VyOS 1.2 Crux (VyOS 1.2.9); removed VyOS 1.2 Crux.
Nov 3 2021, 1:03 PM · VyOS 1.2 Crux (VyOS 1.2.9)
dmbaturin closed T3610: DHCP-Server creation for not primary IP address fails as Resolved.
Nov 3 2021, 12:35 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
zsdc assigned T3913: VRF traffic fails after upgrade from 1.3.0-RC6 to 1.3.0-EPA1/2 to Unknown Object (User).
Nov 3 2021, 11:15 AM · VyOS 1.3 Equuleus (1.3.0)
zsdc assigned T3902: Firewall does not load on boot, address-group not found, even though it exists to Unknown Object (User).
Nov 3 2021, 11:14 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
zsdc assigned T3960: FRR Misconfig when using multiple VRF VNI to Unknown Object (User).
Nov 3 2021, 11:13 AM · VyOS 1.4 Sagitta
zsdc edited a custom field on T3844: dmvpn doesn't work together with l2tp.
Nov 3 2021, 11:12 AM · VyOS 1.2 Crux (VyOS 1.2.9)
zsdc changed the status of T3844: dmvpn doesn't work together with l2tp from Open to On hold.

The problem exists because of the IKEv1 limitation - peer ID is unknown at the authentication stage. Since, both DMVPN and L2TP are configured for any remote peer address, one of them intercepts customers of the other one during authentication because it is not possible to find out which service will be connected after Phase 1.

Nov 3 2021, 11:11 AM · VyOS 1.2 Crux (VyOS 1.2.9)
zsdc added a comment to T3919: Openconnect VPN broken on 1.3-epa2.

Technically, the other one is a duplicate, but there are more details already.

Nov 3 2021, 11:02 AM
zsdc merged T3919: Openconnect VPN broken on 1.3-epa2 into T3934: Openconnect VPN broken: ocserv-worker general protection fault on client connect.
Nov 3 2021, 11:00 AM · VyOS 1.3 Equuleus (1.3.0)
zsdc merged task T3919: Openconnect VPN broken on 1.3-epa2 into T3934: Openconnect VPN broken: ocserv-worker general protection fault on client connect.
Nov 3 2021, 11:00 AM
zsdc reopened T3934: Openconnect VPN broken: ocserv-worker general protection fault on client connect as "Confirmed".
Nov 3 2021, 11:00 AM · VyOS 1.3 Equuleus (1.3.0)
zsdc merged task T3934: Openconnect VPN broken: ocserv-worker general protection fault on client connect into T3919: Openconnect VPN broken on 1.3-epa2.
Nov 3 2021, 10:59 AM · VyOS 1.3 Equuleus (1.3.0)
zsdc merged T3934: Openconnect VPN broken: ocserv-worker general protection fault on client connect into T3919: Openconnect VPN broken on 1.3-epa2.
Nov 3 2021, 10:59 AM
olofl added a comment to T3963: Deleting "le 64" from prefix-list6 does render any change.

Im not sure its possible to delete the "le" part from vtysh cli? I tried running no ipv6 prefix-list PUBLIC-IPV6 seq 10 permit 2001:db8::/32 le 64 from vtysh, but it never removed le part.

Nov 3 2021, 9:16 AM · VyOS 1.3 Equuleus (1.3.6)
olofl created T3963: Deleting "le 64" from prefix-list6 does render any change.
Nov 3 2021, 9:03 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav closed T3932: L2TP Configuration with WAN interface DHCP assigned IP address as Invalid.
Nov 3 2021, 8:27 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3932: L2TP Configuration with WAN interface DHCP assigned IP address.

@sajiby3k you can use 0.0.0.0

set vpn l2tp remote-access outside-address '0.0.0.0'
Nov 3 2021, 8:27 AM · VyOS 1.3 Equuleus (1.3.0)
dmbaturin edited a custom field on T3962: Image cannot be built without open-vm-tools.
Nov 3 2021, 6:35 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
dmbaturin claimed T3962: Image cannot be built without open-vm-tools.
Nov 3 2021, 6:35 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
dmbaturin created T3962: Image cannot be built without open-vm-tools.
Nov 3 2021, 6:34 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Nov 2 2021

zsdc added a comment to T3771: DHCPv6 server prefix delegation - dynamically add route to delegated prefix via requesting router.

After the investigation, we figured out that it is possible to get the prefix and link-local address during the DHCP commit procedure.
The statement

log(info, binary-to-ascii(16, 8, ":", substring(option dhcp6.ia-pd, 24, 17)));

will give us the next info:

dhcpd[1568]: 40:20:1:ca:fe:11:11:ff:ff:0:0:0:0:0:0:0:0

So, a prefix can be extracted. Also, a link-local address may be generated from the MAC address extracted from the DHCP packet structure.

Nov 2 2021, 6:12 PM · VyOS 1.5 Circinus
Viacheslav added a subtask for T3642: PKI configuration: T3931: SSTP doesn't work after rewriting to PKI.
Nov 2 2021, 5:25 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav added a parent task for T3931: SSTP doesn't work after rewriting to PKI: T3642: PKI configuration.
Nov 2 2021, 5:25 PM · VyOS 1.4 Sagitta
SrividyaA added a comment to T3796: Wireguard interfaces are not shown in op-mode.

Submitted this PR https://github.com/vyos/vyos-1x/pull/1061 to fix the op command.

Nov 2 2021, 5:23 PM · VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav created T3961: Generate PKI expect 2 character country code.
Nov 2 2021, 5:17 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a comment to T3960: FRR Misconfig when using multiple VRF VNI.

Possibly unrelated, but I'll leave it here

frr-reload output:   0 /usr/lib/frr/frr-reload.py:851: SyntaxWarning: "is not" with a literal. Did you mean "!="?
frr-reload output:   1   if line is not "exit-vrf":
frr-reload output:   2 2021-11-02 18:33:34,225  INF
Nov 2 2021, 5:10 PM · VyOS 1.4 Sagitta
Fieldwork updated Fieldwork.
Nov 2 2021, 4:20 PM
Viacheslav added a comment to T2566: sstp not able to run tunnels ipv6 only.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1060

set vpn sstp authentication local-users username foo password 'bar'
set vpn sstp authentication local-users username foo2 password 'bar2'
set vpn sstp authentication mode 'local'
set vpn sstp client-ipv6-pool prefix 2001:db8::/48
set vpn sstp gateway-address '192.168.122.14'
set vpn sstp ppp-options ipv4 'deny'
set vpn sstp ppp-options ipv6 'allow'
set vpn sstp ssl ca-cert-file '/config/user-data/sstp/ca.crt'
set vpn sstp ssl cert-file '/config/user-data/sstp/server.crt'
set vpn sstp ssl key-file '/config/user-data/sstp/server.key'

Check sessions:

vyos@r4-epa2:~$ show sstp-server s
sessions    statistics  
vyos@r4-epa2:~$ show sstp-server sessions 
ifname | username |          ip           |          ip6          | ip6-dp |   calling-sid   | rate-limit | state  |  uptime  | rx-bytes | tx-bytes 
--------+----------+-----------------------+-----------------------+--------+-----------------+------------+--------+----------+----------+----------
 sstp0  | foo2     | 2001:db8:0:0:200::/64 | 2001:db8:0:0:200::/64 |        | 192.168.122.222 |            | active | 00:00:09 | 735 B    | 506 B
vyos@r4-epa2:~$
Nov 2 2021, 3:19 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
ssasso added a comment to T3960: FRR Misconfig when using multiple VRF VNI.

Additional note: this, of course, breaks the 'red' vrf connectivity.
If I manually add, using vtysh, the

vrf red
 vni 3000

everything on the 'red' vrf works fine.

Nov 2 2021, 2:31 PM · VyOS 1.4 Sagitta
ssasso created T3960: FRR Misconfig when using multiple VRF VNI.
Nov 2 2021, 2:14 PM · VyOS 1.4 Sagitta
fernando added a comment to T3959: MPLS L3VPN IPv6 address-family over IPv4 MPLS backbone.

Yes, It seems that rfc doesn't work , also I found this issues :
https://github.com/FRRouting/frr/issues/5824

Nov 2 2021, 1:37 PM · VyOS Rolling
dmbaturin added a comment to T3835: vyos router 1.2.7 snmp Dos bug.

@zoenan7 Sorry for the late reply! Yes, I got your email and could reproduce the crash using your PoC.

Nov 2 2021, 11:26 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T3822: OpenVPN processes do not have permission to read key files generated with `run generate openvpn key`.

Still not fixed VyOS 1.3-beta-202110300342:

vyos@r4-epa2:~$ generate openvpn key foo
Generating OpenVPN key to /config/auth/foo
Your new local OpenVPN key has been generated
vyos@r4-epa2:~$ 
vyos@r4-epa2:~$ ls -la /config/auth/
total 12
drwxrwsr-x 2 root vyattacfg 4096 Nov  2 09:00 .
drwxrwxr-x 7 root vyattacfg 4096 Nov  2 08:54 ..
-rw------- 1 root vyattacfg  636 Nov  2 09:00 foo
vyos@r4-epa2:~$
Nov 2 2021, 9:03 AM · VyOS 1.3 Equuleus (1.3.0)
syncer lowered the priority of T3864: Add Edgecore build to VyOS 1.3 Equuleus from High to Normal.
Nov 2 2021, 8:51 AM · VyOS 1.3 Equuleus (1.3.0)
syncer changed the subtype of T3864: Add Edgecore build to VyOS 1.3 Equuleus from "Task" to "Enhancement".
Nov 2 2021, 8:51 AM · VyOS 1.3 Equuleus (1.3.0)
syncer updated the image for VyOS 1.3 Equuleus (1.3.0-epa3) from F1983296: profile to F2021087: profile.
Nov 2 2021, 8:40 AM
syncer updated the image for VyOS 1.3 Equuleus (1.3.0-epa2) from F1983298: profile to F2021085: profile.
Nov 2 2021, 8:40 AM
syncer archived VyOS 1.3 Equuleus (1.3.0-epa1).
Nov 2 2021, 8:39 AM
syncer updated the image for VyOS 1.3 Equuleus (1.3.0-epa1) from F1983325: profile to F2021082: profile.
Nov 2 2021, 8:39 AM
syncer updated the image for VyOS 1.3 Equuleus (1.3.0) from F2021076: profile to F2021080: profile.
Nov 2 2021, 8:39 AM
Unknown Object (User) added a comment to T3959: MPLS L3VPN IPv6 address-family over IPv4 MPLS backbone.

Mentioned here (FRRouting):
BGP vpnv6 next hop address maybe error?

Nov 2 2021, 8:23 AM · VyOS Rolling
syncer set the image for VyOS 1.3 Equuleus (1.3.0) to F2021076: profile.
Nov 2 2021, 8:16 AM
Unknown Object (User) created T3959: MPLS L3VPN IPv6 address-family over IPv4 MPLS backbone.
Nov 2 2021, 8:07 AM · VyOS Rolling

Nov 1 2021

syncer edited projects for T1262: dhcp requested WAN ip address doesn't get search parameter in /etc/resolv.conf in 1.2.0-rolling+201902210337, added: VyOS 1.3 Equuleus (1.3.0); removed VyOS 1.3 Equuleus (1.3.0-epa3).
Nov 1 2021, 10:12 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project, VyOS 1.2 Crux (VyOS 1.2.9), test
syncer edited projects for T2116: Processing configuration via Cloud-init User-Data, added: VyOS 1.3 Equuleus (1.3.0); removed VyOS 1.3 Equuleus (1.3.0-epa3).
Nov 1 2021, 10:12 PM · VyOS 1.3 Equuleus (1.3.6)
syncer edited projects for T2117: Update Cloud-init version and actualize our changes to it, added: VyOS 1.3 Equuleus (1.3.0); removed VyOS 1.3 Equuleus (1.3.0-epa3).
Nov 1 2021, 10:12 PM
syncer edited projects for T3410: Unsafe processing of special characters in CLI autocomplete, added: VyOS 1.3 Equuleus (1.3.0); removed VyOS 1.3 Equuleus (1.3.0-epa3).
Nov 1 2021, 10:12 PM · Bugs, VyOS 1.5 Circinus, VyOS Rolling
syncer edited projects for T3770: BGP neighbor not generating the correct frr configuration when moved to peer-group, added: VyOS 1.3 Equuleus (1.3.0); removed VyOS 1.3 Equuleus (1.3.0-epa3).
Nov 1 2021, 10:12 PM · VyOS 1.3 Equuleus (1.3.7)
syncer edited projects for T3774: atop logs are not limited in size, added: VyOS 1.3 Equuleus (1.3.0); removed VyOS 1.3 Equuleus (1.3.0-epa3).
Nov 1 2021, 10:12 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
syncer edited projects for T3706: Add proper priorities for systemd daemons, added: VyOS 1.3 Equuleus (1.3.0); removed VyOS 1.3 Equuleus (1.3.0-epa3).
Nov 1 2021, 10:12 PM · Bugs, VyOS Rolling
syncer edited projects for T3854: Missing op-mode commands for conntrack-sync, added: VyOS 1.3 Equuleus (1.3.0); removed VyOS 1.3 Equuleus (1.3.0-epa3).
Nov 1 2021, 10:12 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
syncer edited projects for T3824: Ethernet offload options are not populated in new installs, added: VyOS 1.3 Equuleus (1.3.0); removed VyOS 1.3 Equuleus (1.3.0-epa3).
Nov 1 2021, 10:12 PM