Page MenuHomeVyOS Platform
Feed All Stories

Dec 21 2021

Viacheslav moved T3435: NAT rules show corruption from Finished to In Progress on the VyOS 1.4 Sagitta board.

There is still another bug:

set nat destination rule 120 destination address '203.0.113.1'
set nat destination rule 120 inbound-interface 'eth0'
set nat destination rule 120 protocol 'tcp'
set nat destination rule 120 translation address '192.0.2.40'
Dec 21 2021, 9:58 AM · VyOS 1.4 Sagitta
Viacheslav reopened T3435: NAT rules show corruption as "Needs testing".
Dec 21 2021, 9:56 AM · VyOS 1.4 Sagitta
Viacheslav closed T3435: NAT rules show corruption as Resolved.
Dec 21 2021, 9:16 AM · VyOS 1.4 Sagitta
Viacheslav created T4089: Show nat destination rules shows ip address instead of interface 'any'.
Dec 21 2021, 9:09 AM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX458e0c5c6172: nat: T3435: Fix for op-mode concatenate str.
Dec 21 2021, 9:05 AM
GitHub <[email protected]> committed rVYOSONEX9275fd942cef: Merge pull request #1114 from sever-sever/T3435-nat (authored by c-po).
Dec 21 2021, 9:05 AM
Viacheslav edited a custom field on T3435: NAT rules show corruption.
Dec 21 2021, 8:53 AM · VyOS 1.4 Sagitta
Viacheslav lowered the priority of T3435: NAT rules show corruption from High to Normal.
Dec 21 2021, 8:52 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3435: NAT rules show corruption.

PR https://github.com/vyos/vyos-1x/pull/1114

vyos@r11-roll:~$ show nat destination rules 
Rule       Destination                                        Translation                                        Inbound Interface
----       -----------                                        -----------                                        -----------------
100        port 3389                                          192.0.2.40 port 80                                 eth0      
vyos@r11-roll:~$
Dec 21 2021, 8:52 AM · VyOS 1.4 Sagitta
Viacheslav closed T4083: Cluster heartbeat doesn't start b.c lack of directory /run/heartbeat/ as Resolved.
Dec 21 2021, 8:26 AM · VyOS 1.4 Sagitta
xrobau added a comment to T4017: Adding firewall port ranges makes commit/boot MASSIVELY slow.

I'm going to do what I suggested.

Dec 21 2021, 3:50 AM
Unknown Object (User) added a comment to T4078: A hybrid of "network-group" and "address-group"..

@adestis thank you. This issue isn't critical. It's more for to improve the design and for convenience of our customers.
You can use /32 to add a host, but we have to have the opportunity to add hosts without masks.
For example, if you need to create a group consisting of 1000 (or more random hosts), it's more convenient to use configuration without masks.

Dec 21 2021, 12:11 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta

Dec 20 2021

UnicronNL added a comment to T4086: system login banner is not removed on deletion..

@c-po I will check it!

Dec 20 2021, 10:02 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T4086: system login banner is not removed on deletion..

@UnicronNL can you rechecknon todays rolling image? It behaved differently for me

Dec 20 2021, 9:13 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
UnicronNL added a comment to T4086: system login banner is not removed on deletion..

I set the banners via set system login pre-login 'test' and/or set system login post-login 'test'
and then the banners are set. (and the default is overwritten)

Dec 20 2021, 8:48 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po lowered the priority of T4086: system login banner is not removed on deletion. from Normal to Low.
Dec 20 2021, 8:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T4086: system login banner is not removed on deletion. from Open to Needs testing.
Dec 20 2021, 8:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T4086: system login banner is not removed on deletion..

Well deleting the login banner results in the "default" behavior as expected.

Dec 20 2021, 8:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po claimed T4086: system login banner is not removed on deletion..
Dec 20 2021, 6:26 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po closed T4088: Fix typo in login banner as Resolved.
Dec 20 2021, 6:26 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T4088: Fix typo in login banner from Open to Finished on the VyOS 1.4 Sagitta board.
Dec 20 2021, 6:25 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po committed rVYOSONEXeacc2f5e0210: T4088: login banner: Typo in completion help of banner types (authored by SrividyaA).
Dec 20 2021, 6:25 PM
c-po moved T4088: Fix typo in login banner from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0) board.
Dec 20 2021, 6:25 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
SrividyaA committed rVYOSONEXb47e54a84ad9: T4088: login banner: Typo in completion help of banner types.
Dec 20 2021, 6:15 PM
GitHub <[email protected]> committed rVYOSONEX8655699ba3f3: Merge pull request #1113 from srividya0208/T4088 (authored by c-po).
Dec 20 2021, 6:15 PM
Viacheslav added a comment to T4083: Cluster heartbeat doesn't start b.c lack of directory /run/heartbeat/.

PR https://github.com/vyos/vyatta-cluster/pull/5

Dec 20 2021, 5:10 PM · VyOS 1.4 Sagitta
Viacheslav claimed T4083: Cluster heartbeat doesn't start b.c lack of directory /run/heartbeat/.
Dec 20 2021, 4:54 PM · VyOS 1.4 Sagitta
daniil added a comment to T4030: SR-IOV and interface renaming bug .

Similar problem:

Dec 20 2021, 3:22 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4087: IPsec IKE-group proposals limit of 10 pieces from "Task" to "Feature Request".
Dec 20 2021, 1:18 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a comment to T4087: IPsec IKE-group proposals limit of 10 pieces .

There is a reason https://github.com/vyos/vyatta-cfg-vpn/blob/de19cb9b03b78c4e3da93e014764bb2400ffe8a6/scripts/vpn-config.pl#L34

Dec 20 2021, 1:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
SrividyaA created T4088: Fix typo in login banner.
Dec 20 2021, 8:13 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
adestis added a comment to T4078: A hybrid of "network-group" and "address-group"..

@m.korobeinikov why not use network group with /32 host addresses ?

Dec 20 2021, 7:41 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
SrividyaA added a comment to T4086: system login banner is not removed on deletion..

The custom banner is removed after the deletion operation. But it shows the default banner:

Dec 20 2021, 7:37 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) updated subscribers of T4087: IPsec IKE-group proposals limit of 10 pieces .

@Viacheslav found the source of the restriction:

Dec 20 2021, 6:30 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Unknown Object (User) created T4087: IPsec IKE-group proposals limit of 10 pieces .
Dec 20 2021, 2:51 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)

Dec 19 2021

UnicronNL triaged T4086: system login banner is not removed on deletion. as Normal priority.
Dec 19 2021, 4:59 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) changed the status of T4085: Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict from Open to In progress.
Dec 19 2021, 3:25 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Unknown Object (User) created T4085: Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict.
Dec 19 2021, 3:25 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
SrividyaA added a comment to T3435: NAT rules show corruption.

It gives a different error when the translation port option is configured for both the source and destination nat:

Dec 19 2021, 11:18 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXb9a639380790: T4070: natv4: Add "any" for inbound-interface list (authored by SrividyaA).
Dec 19 2021, 10:04 AM
SrividyaA committed rVYOSONEXbd53db9eb63b: T4070: natv4: Add "any" for inbound-interface list.
Dec 19 2021, 10:03 AM
GitHub <[email protected]> committed rVYOSONEX7b37b836db55: Merge pull request #1112 from srividya0208/T4070 (authored by c-po).
Dec 19 2021, 10:03 AM
SrividyaA added a comment to T4070: NATv4 : inbound-interface type "any" is missing..

submitted this PR: https://github.com/vyos/vyos-1x/pull/1112

Dec 19 2021, 10:03 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX0f04c1cd73fa: vxlan: T3700: add support for Generic Protocol extension (VXLAN-GPE).
Dec 19 2021, 9:39 AM
c-po changed the status of T3700: Support VLAN tunnel mapping of VLAN aware bridges from Open to In progress.
Dec 19 2021, 7:26 AM · VyOS 1.4 Sagitta
c-po changed the status of T3700: Support VLAN tunnel mapping of VLAN aware bridges, a subtask of T3137: Let VLAN aware bridge approach the behavior of professional equipment, from Open to In progress.
Dec 19 2021, 7:26 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po claimed T3700: Support VLAN tunnel mapping of VLAN aware bridges.
Dec 19 2021, 7:26 AM · VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX0e4840724193: T4084: dehardcode the post-login banner.
Dec 19 2021, 4:21 AM
dmbaturin committed rVYOSONEX4957ef1bd8f1: T4084: dehardcode the post-login banner.
Dec 19 2021, 4:13 AM
dmbaturin created T4084: Dehardcode the default login banner.
Dec 19 2021, 4:06 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
dmbaturin closed T3912: Use a more informative default post-login banner as Resolved.
Dec 19 2021, 4:03 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Dec 18 2021

dmbaturin created 1.3.0.
Dec 18 2021, 6:03 PM
danhusan added a comment to T3913: VRF traffic fails after upgrade from 1.3.0-RC6 to 1.3.0-EPA1/2.

Can also confirm that 1.3.0-epa3 is broken, so something must have changed between epa3 and 202112180443.

Dec 18 2021, 5:35 PM · VyOS 1.3 Equuleus (1.3.0)
danhusan added a comment to T3913: VRF traffic fails after upgrade from 1.3.0-RC6 to 1.3.0-EPA1/2.

Tried 1.3-beta-202112180443, seems to be working as it should now.

Dec 18 2021, 3:23 PM · VyOS 1.3 Equuleus (1.3.0)
dennymartten updated dennymartten.
Dec 18 2021, 3:59 AM

Dec 17 2021

zsdc committed rVYOSONEXac73200e4f0c: logs: T3774: Added CLI options to control atop logs rotation.
Dec 17 2021, 7:08 PM
zsdc committed rVYOSONEX89fdb4fbfa05: logs: T3774: Improved logs CLI.
Dec 17 2021, 7:08 PM
zsdc committed rVYOSONEXa22ba14999a3: logs: T3774: Improved logs config rendering.
Dec 17 2021, 7:08 PM
zsdc committed rVYOSONEX945ab070b72e: logs: T3774: Added new CLI item.
Dec 17 2021, 7:08 PM
zsdc committed rVYOSONEX86bbab75ae41: logs: T3774: Optimization for logrotate configs.
Dec 17 2021, 7:08 PM
GitHub <[email protected]> committed rVYOSONEXda3e558992df: Merge pull request #1103 from zdc/T3774-sagitta (authored by c-po).
Dec 17 2021, 7:08 PM
c-po closed T4059: VRRP sync-group transition script does not persist after reboot as Resolved.
Dec 17 2021, 7:04 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
Viacheslav created T4083: Cluster heartbeat doesn't start b.c lack of directory /run/heartbeat/.
Dec 17 2021, 3:16 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4081: VRRP health-check script stops working when setting up a sync group.

Yes, but sync-groups dont have health-check scripts.
The best solution, in this case, is to implement health-check features for sync-group and do migration script.
We should not use health-check configured for a group if this group belongs to a sync-group

Dec 17 2021, 12:19 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a comment to T4081: VRRP health-check script stops working when setting up a sync group.

sync-groups habe transition scripts, too

Dec 17 2021, 12:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
trae32566 added a comment to T3628: commit-archive source-address Interface Broken.
Dec 17 2021, 10:46 AM · VyOS 1.4 Sagitta
trae32566 reopened T3628: commit-archive source-address Interface Broken, a subtask of T3356: Script for remote file transfers, as Open.
Dec 17 2021, 9:31 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
trae32566 reopened T3628: commit-archive source-address Interface Broken as "Open".
Dec 17 2021, 9:31 AM · VyOS 1.4 Sagitta
trae32566 added a comment to T3628: commit-archive source-address Interface Broken.

Still broken:

trae@cr01b-vyos:~$ show conf com | grep arch
set service dhcp-server shared-network-name INT subnet 192.168.1.0/24 domain-search 'int.trae32566.org'
set service dhcp-server shared-network-name INT subnet 192.168.1.0/24 domain-search 'ipa.trae32566.org'
set service dhcp-server shared-network-name INT subnet 192.168.1.0/24 domain-search 'trae32566.org'
set system config-management commit-archive location 'sftp://USER:[email protected]:/int/cr01b-vyos'                                                                          
set system config-management commit-archive source-address 'lo'
set system domain-search domain 'int.trae32566.org'
set system domain-search domain 'ipa.trae32566.org'
set system domain-search domain 'trae32566.org'
trae@cr01b-vyos:~$ configure
[edit]
trae@cr01b-vyos# set system host-name temp
[edit]
trae@cr01b-vyos# commit
Using source address lo
Archiving config...
  sftp://stor01z-rh8.int.trae32566.org:/int/cr01b-vyos Traceback (most recent call last):
  File "<string>", line 1, in <module>
  File "/usr/lib/python3/dist-packages/vyos/remote.py", line 312, in upload
    urlc(urlstring, *args, **kwargs).upload(local_path)
  File "/usr/lib/python3/dist-packages/vyos/remote.py", line 202, in upload
    with self._establish() as ssh, ssh.open_sftp() as sftp:
  File "/usr/lib/python3/dist-packages/vyos/remote.py", line 189, in _establish
    sock = socket.create_connection((self.hostname, self.port), socket.getdefaulttimeout(), self.source)
  File "/usr/lib/python3.9/socket.py", line 843, in create_connection
    raise err
  File "/usr/lib/python3.9/socket.py", line 830, in create_connection
    sock.bind(source_address)
socket.gaierror: [Errno -5] No address associated with hostname
[edit]

This is on 1.4-rolling-202112160318

Dec 17 2021, 9:30 AM · VyOS 1.4 Sagitta
Viacheslav assigned T4082: Add op mode command to restart ldpd to devon.
Dec 17 2021, 7:26 AM · VyOS 1.3 Equuleus (1.3.0)
devon committed rVYOSONEX0ef775ab6563: Add restart ldp command.
Dec 17 2021, 4:49 AM
GitHub <[email protected]> committed rVYOSONEXbccb6398ed28: Merge pull request #1111 from devon-mar/restart-ldpd (authored by dmbaturin).
Dec 17 2021, 4:49 AM
devon added a comment to T4082: Add op mode command to restart ldpd.

I've opened a PR: https://github.com/vyos/vyos-1x/pull/1111

Dec 17 2021, 4:47 AM · VyOS 1.3 Equuleus (1.3.0)
devon created T4082: Add op mode command to restart ldpd.
Dec 17 2021, 4:39 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T4081: VRRP health-check script stops working when setting up a sync group.

Didn't notice this message, thanks!
Maybe we should add a corresponding sync_group command to the CLI?

Dec 17 2021, 3:30 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) closed T3176: Ordering of ports on EdgeCore SAF51015I is mixed up? as Resolved.

I ve check this situation on VyOS 1.3(beta-202112120443) and 1.4(rolling-202112160318) (platform SAF51015I) and interfases didont confus.

Dec 17 2021, 1:57 AM · VyOS 1.3 Equuleus (1.3.0)

Dec 16 2021

jestabro moved T4076: Allow setting CORS options in HTTP API from Backport Candidates to Finished on the VyOS 1.4 Sagitta board.
Dec 16 2021, 6:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro changed the status of T4076: Allow setting CORS options in HTTP API from Unknown Status to Resolved.
Dec 16 2021, 6:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro committed rVYOSONEXe671c4b33157: http-api: T4076: allow setting CORS option 'Access-Control-Allow-Origin'.
Dec 16 2021, 6:13 PM
Unknown Object (User) changed the status of T4081: VRRP health-check script stops working when setting up a sync group from Open to Confirmed.

When sync group configure the keepalived report to log, looks like we need to use this script on sync_group

Dec 16 15:22:53 vyos Keepalived_vrrp[4766]: Warning - script healthcheck_XXX is not used
Dec 16 2021, 5:27 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
erkin committed rVYOSONEX713c969d7472: T3354: Backport strip-private script.
Dec 16 2021, 4:51 PM
GitHub <[email protected]> committed rVYOSONEX98396247fcba: Merge pull request #1110 from erkin/equuleus (authored by dmbaturin).
Dec 16 2021, 4:51 PM
erkin removed a project from T936: Reimplementation of tech-support diagnostic file generation: VyOS 1.3 Equuleus (1.3.0).

I'm not happy with the current one. Ideally, I'd like to rewrite it in Python using better diagnostic collection tools. I don't see it happening in 1.3.0, however.

Dec 16 2021, 4:34 PM · test, VyOS 1.4 Sagitta
erkin closed T2651: Generate CLI abstraction for options passed to CURL and SSH client, a subtask of T3356: Script for remote file transfers, as Not Applicable.
Dec 16 2021, 4:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T2651: Generate CLI abstraction for options passed to CURL and SSH client as Not Applicable.

This is no longer relevant now that curl has been almost entirely removed from the interface. Source addresses and such can be set for commit-archive, and authentication variables are set individually for each session.

Dec 16 2021, 4:32 PM · VyOS 1.3 Equuleus (1.3.0)
erkin changed the status of T3821: Add latest versions to default config files from In progress to On hold.
Dec 16 2021, 4:22 PM · VyOS 1.5 Circinus
erkin added a comment to T3506: Migrate loadkey command to op-mode.

I'm going to delete loadkey from 1.4 some time after 1.3 comes out.

Dec 16 2021, 4:21 PM · VyOS 1.4 Sagitta
erkin closed T4037: HTTP transfers do not follow redirects as Resolved.

I assumed the last element of .history[] is the final URL, so I had it display .history[-1]; but it turns out it overwrites .url with the final destination and only keeps the previous redirects in .history[]. Now it just displays .url if .history[] is not empty.

Dec 16 2021, 4:19 PM · VyOS 1.4 Sagitta
erkin closed T2615: Provide an explicit option for server fingerprint in commit archive, and make insecure the default, a subtask of T2651: Generate CLI abstraction for options passed to CURL and SSH client, as Resolved.
Dec 16 2021, 4:18 PM · VyOS 1.3 Equuleus (1.3.0)
erkin closed T2615: Provide an explicit option for server fingerprint in commit archive, and make insecure the default as Resolved.

The way it's done right now is like this:

Dec 16 2021, 4:18 PM · VyOS 1.3 Equuleus (1.3.0)
erkin closed T3378: commit-archive source-address broken for IPv6 addresses, a subtask of T3356: Script for remote file transfers, as Resolved.
Dec 16 2021, 4:11 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3378: commit-archive source-address broken for IPv6 addresses as Resolved.

curl is no longer relevant as it was superseded by the new remote module.

Dec 16 2021, 4:11 PM · VyOS 1.3 Equuleus (1.3.0)
erkin closed T3556: Commit-archive via scp causes 100% CPU on boot, a subtask of T3356: Script for remote file transfers, as Resolved.
Dec 16 2021, 4:10 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3556: Commit-archive via scp causes 100% CPU on boot as Resolved.

Assuming it does not (and I can't replicate this), since the responsible code was rewritten in November to properly use low-level sockets. Let me know if it still persists and I'll try to poke around Paramiko for performance bottlenecks.

Dec 16 2021, 4:10 PM · VyOS 1.4 Sagitta
erkin triaged T4038: Rewrite `vyatta-image-tools.pl` in Python as Low priority.
Dec 16 2021, 4:07 PM · Restricted Project, VyOS 1.4 Sagitta
erkin raised the priority of T3354: Convert strip-private script from Perl to Python from Wishlist to Low.
Dec 16 2021, 4:07 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin reopened T3354: Convert strip-private script from Perl to Python, a subtask of T3355: Remove all remaining legacy Vyatta code, as In progress.
Dec 16 2021, 4:06 PM · VyOS Rolling
erkin reopened T3354: Convert strip-private script from Perl to Python as "In progress".

Going to backport this to 1.3 as well.

Dec 16 2021, 4:06 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin committed rVYOSONEX5074fed63efc: T3356: Backport remote module.
Dec 16 2021, 3:42 PM
GitHub <[email protected]> committed rVYOSONEXecec222a6dac: Merge pull request #1108 from erkin/equuleus (authored by dmbaturin).
Dec 16 2021, 3:42 PM