Page MenuHomeVyOS Platform
Feed All Stories

Jan 1 2022

dcplaya created T4127: Upgrading from pre-certstore image to certstore image does not handle CA files with multiple certs.
Jan 1 2022, 11:09 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
c-po committed rVYOSONEX901e40dc3b52: nat: T2199: rename iptables -> nftables variable prefix.
Jan 1 2022, 9:54 AM

Dec 31 2021

sarthurdev committed rVYOSONEX85710cee8fe9: firewall: T2199: Migrate firewall op-mode to XML/Python.
Dec 31 2021, 6:35 PM
sarthurdev committed rVYOSONEXfdeba8da3e99: firewall: T2199: Migrate firewall to XML/Python.
Dec 31 2021, 6:35 PM
sarthurdev committed rVYOSONEX3ebb08893b4b: zone-policy: T2199: Migrate zone-policy op-mode to XML/Python.
Dec 31 2021, 6:35 PM
sarthurdev committed rVYOSONEXc7cf7b941445: zone-policy: T2199: Migrate zone-policy to XML/Python.
Dec 31 2021, 6:35 PM
sarthurdev committed rVYOSONEXdcd202aeeb89: policy: T2199: Migrate policy route op-mode to XML/Python.
Dec 31 2021, 6:35 PM
sarthurdev committed rVYOSONEXf86041de88c3: policy: T2199: Migrate policy route to XML/Python.
Dec 31 2021, 6:35 PM
sarthurdev committed rVYOSONEX28b285b4791a: zone_policy: T3873: Implement intra-zone-filtering.
Dec 31 2021, 6:35 PM
c-po committed rVYOSONEX0091f6080181: Merge branch 'firewall' of https://github.com/sarthurdev/vyos-1x into current.
Dec 31 2021, 6:35 PM
c-po changed the status of T4121: Nameservers from DHCP client cannot be used in specific cases from In progress to Needs testing.
Dec 31 2021, 5:37 PM · VyOS 1.3 Equuleus (1.3.4)
c-po committed rVYOSONEX42a43b1c572f: smoketest: ipsec: make use of setUpClass().
Dec 31 2021, 4:01 PM
c-po committed rVYOSONEXc5f118b3af48: smoketest: ipsec: T4126: verify configured priority.
Dec 31 2021, 4:01 PM
Viacheslav renamed T4126: Ability to set priority to site to site IPSec vpn tunnels from Ability to set priority to site to site IPSec tunnels to Ability to set priority to site to site IPSec vpn tunnels.
Dec 31 2021, 3:45 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4126: Ability to set priority to site to site IPSec vpn tunnels from Open to Needs testing.

It can't be implemented in 1.3, as it doesn't use swanctl.conf for peers configuration
I didn't find this option for ipsec.conf

Dec 31 2021, 3:45 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX78494fe6de53: ipsec: T4126: Ability to set priorities for installed policy.
Dec 31 2021, 3:29 PM
GitHub <[email protected]> committed rVYOSONEXdcf8baa5b304: Merge pull request #1129 from sever-sever/T4126 (authored by c-po).
Dec 31 2021, 3:29 PM
Viacheslav added a comment to T4126: Ability to set priority to site to site IPSec vpn tunnels.

PR https://github.com/vyos/vyos-1x/pull/1129

set vpn ipsec site-to-site peer 192.0.2.14 tunnel 0 local prefix '172.16.0.0/24'
set vpn ipsec site-to-site peer 192.0.2.14 tunnel 0 priority '100'
set vpn ipsec site-to-site peer 192.0.2.14 tunnel 0 remote prefix '10.0.0.0/24'
Dec 31 2021, 3:11 PM · VyOS 1.4 Sagitta
fernando added a comment to T4125: Feature Request: bridge STP BPDU translation.

I want to leave a comment , it's also common that customers don't know that PVST is enabled by default (and send bpdu peer VLANS), So it's possible to mitigate it also using nf rules , below leave a example:

Dec 31 2021, 2:59 PM
Viacheslav claimed T4126: Ability to set priority to site to site IPSec vpn tunnels.
Dec 31 2021, 1:52 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4126: Ability to set priority to site to site IPSec vpn tunnels.
Dec 31 2021, 1:32 PM · VyOS 1.4 Sagitta
Viacheslav created T4126: Ability to set priority to site to site IPSec vpn tunnels.
Dec 31 2021, 1:24 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4125: Feature Request: bridge STP BPDU translation from "Task" to "Feature Request".
Dec 31 2021, 12:11 PM
Viacheslav added a comment to T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID.

How about starting with a simple interface and allowing to set interface for binding address?

set high-availability vrrp group foo address 203.0.113.1 interface ethX      
Possible completions:
 > ethN         Interfcae used to assign virtual address
 > eth0         
 > eth1         
 > eth2
Dec 31 2021, 12:09 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav moved T4081: VRRP health-check script stops working when setting up a sync group from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Dec 31 2021, 11:04 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav edited projects for T4081: VRRP health-check script stops working when setting up a sync group, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus (1.3.0).
Dec 31 2021, 11:04 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4081: VRRP health-check script stops working when setting up a sync group as Resolved.
Dec 31 2021, 11:04 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXda7248337aa0: keepalived: T4081: Fix health-checking when syn-group is used.
Dec 31 2021, 9:36 AM
GitHub <[email protected]> committed rVYOSONEX02dfd272ad99: Merge pull request #1122 from sever-sever/T4081-equ (authored by dmbaturin).
Dec 31 2021, 9:36 AM
c-po committed rVYOSONEXb468930a61d4: firewall: xml: T4100: increase maximum number of rules to 999999.
Dec 31 2021, 8:11 AM
SrividyaA placed T4115: reboot in <x> not working as expected up for grabs.
Dec 31 2021, 8:00 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po triaged T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID as Low priority.
Dec 31 2021, 8:00 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a comment to T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID.

This sounds like a "peer-link" or "heartbeat-link" between two VyOS boxes. I have yet no idea how the CLI could look like, maybe you have one?

Dec 31 2021, 7:59 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po committed rVYOSONEXad9289163aff: snmp: T4124: remove snmp.py from vyos-configd.
Dec 31 2021, 7:55 AM
Unknown Object (User) created T4125: Feature Request: bridge STP BPDU translation.
Dec 31 2021, 3:56 AM

Dec 30 2021

c-po closed T4124: snmp: migrate to get_config_dict() as Resolved.
Dec 30 2021, 8:39 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXc0d4a61047b7: smoketest: snmp: T4124: locally connect to SNMP service and retrieve data.
Dec 30 2021, 8:38 PM
c-po committed rVYOSONEX566f7f2401b7: snmp: T4124: migrate to get_config_dict().
Dec 30 2021, 8:38 PM
c-po updated the task description for T4124: snmp: migrate to get_config_dict().
Dec 30 2021, 8:32 PM · VyOS 1.4 Sagitta
c-po moved T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Dec 30 2021, 8:02 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.164 / 5.10.88 to Update Linux Kernel to v5.4.169 / 5.10.89.
Dec 30 2021, 8:01 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po claimed T4124: snmp: migrate to get_config_dict().
Dec 30 2021, 6:40 PM · VyOS 1.4 Sagitta
c-po created T4124: snmp: migrate to get_config_dict().
Dec 30 2021, 6:40 PM · VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T4117: Does not possible to configure PoD/CoA for L2TP vpn from In progress to Needs testing.
Dec 30 2021, 5:27 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
zsdc changed the status of T4113: Incorrect GRUB configuration parsing from Open to In progress.

Suggested fix: https://github.com/vyos/vyatta-op/pull/52

Dec 30 2021, 5:21 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Kim Hagen <[email protected]> committed rVYOSONEX1a9c14790440: dhclient: T4121: Fixed resolv.conf generation at early boot stage (authored by zsdc).
Dec 30 2021, 4:02 PM
zsdc committed rVYOSONEXce77935eeeab: dhclient: T4121: Fixed resolv.conf generation at early boot stage.
Dec 30 2021, 4:00 PM
GitHub <[email protected]> committed rVYOSONEX8d99fe401731: Merge pull request #1128 from zdc/T4121-sagitta (authored by UnicronNL).
Dec 30 2021, 4:00 PM
Unknown Object (User) committed rVYOSONEX94ee47fdf975: l2tp-server: T4117: Add dae-server configuration to template.
Dec 30 2021, 2:13 PM
GitHub <[email protected]> committed rVYOSONEXb7b5eecd30c7: Merge pull request #1125 from DmitriyEshenko/eq-1x-29122021-01 (authored by dmbaturin).
Dec 30 2021, 2:13 PM
aha added a comment to T4120: [VXLAN] add ability to set multiple unicast-remotes.

Problem (2) with multiple IPv6 remotes fixed.

Dec 30 2021, 11:19 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
bbabich created T4123: checksum file fails to download from AWS S3 in rolling-release.
Dec 30 2021, 6:22 AM · VyOS 1.4 Sagitta
aha added a comment to T4120: [VXLAN] add ability to set multiple unicast-remotes.

During multiple tests on my testlab I found two (or three) possible bugs:
1.)
vyos-cli does not prevent to mix IPv4 and IPv6 remotes. Mixing them is not possible with vxlan.

Dec 30 2021, 12:13 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Dec 29 2021

zsdc added a comment to T4121: Nameservers from DHCP client cannot be used in specific cases.

PR to fix the problem: https://github.com/vyos/vyos-1x/pull/1128
It is compatible with both 1.3 and 1.4, so can be cherry-picked from sagitta to equuleus.

Dec 29 2021, 11:12 PM · VyOS 1.3 Equuleus (1.3.4)
Andreas <[email protected]> committed rVYOSONEX76a917281ddb: webproxy: T4116: Ability to listen on IPv6 addresses.
Dec 29 2021, 8:15 PM
GitHub <[email protected]> committed rVYOSONEX78ad5ce69e6f: Merge pull request #1126 from justsecure/current (authored by c-po).
Dec 29 2021, 8:15 PM
jestabro closed T4086: system login banner is not removed on deletion. as Resolved.
Dec 29 2021, 8:13 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
olofl created T4122: interface ip address config missing after upgrade from 1.2.8 to 1.3.0 (when redirect is configured?).
Dec 29 2021, 8:13 PM · VyOS 1.3 Equuleus (1.3.3)
jestabro committed rVYOSONEX8341dbb811ab: configd: T4086: use 'copy' on mutable global var default_config_data.
Dec 29 2021, 8:12 PM
jestabro moved T4086: system login banner is not removed on deletion. from Open to Finished on the VyOS 1.4 Sagitta board.
Dec 29 2021, 8:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
jestabro committed rVYOSONEXd2ca2ac1cf9c: configd: T4086: use 'copy' on mutable global var default_config_data.
Dec 29 2021, 8:07 PM
jestabro added a comment to T4086: system login banner is not removed on deletion..

This is a mutability issue: since under vyos-configd the script is loaded as module, global variables persist, however:

Dec 29 2021, 7:37 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
SrividyaA added a comment to T4115: reboot in <x> not working as expected.

The error is received when the input for minutes is provided in three digits.

Dec 29 2021, 7:35 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
zsdc changed the status of T4121: Nameservers from DHCP client cannot be used in specific cases from Open to In progress.
Dec 29 2021, 7:33 PM · VyOS 1.3 Equuleus (1.3.4)
zsdc created T4121: Nameservers from DHCP client cannot be used in specific cases.
Dec 29 2021, 7:32 PM · VyOS 1.3 Equuleus (1.3.4)
SrividyaA claimed T4115: reboot in <x> not working as expected.
Dec 29 2021, 7:11 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T4023: Add grepcidr or similar functionality as Resolved.

@insignia96 Will be present in the next rolling release.

Dec 29 2021, 6:57 PM · VyOS 1.4 Sagitta
Viacheslav closed T3671: Webproxy not functional in 1.2.8 update as Resolved.
Dec 29 2021, 6:27 PM · VyOS 1.2 Crux (VyOS 1.2.9)
n.fort renamed T2498: Expected error when deleting vif that has dhcp-server configured from Cannot remove interface vif used by dhcpd to Expected error when deleting vif that has dhcp-server configured.
Dec 29 2021, 6:15 PM · VyOS Rolling
n.fort added a comment to T2498: Expected error when deleting vif that has dhcp-server configured.

Configuration tested on 1.3 and 1.4 version.

Dec 29 2021, 6:13 PM · VyOS Rolling
Viacheslav reopened T2498: Expected error when deleting vif that has dhcp-server configured as "Open".

Re-opened as this task regarding dhcp-server, not dhcp-client

Dec 29 2021, 5:48 PM · VyOS Rolling
aha added a comment to T4120: [VXLAN] add ability to set multiple unicast-remotes.

PR started:
https://github.com/vyos/vyos-1x/pull/1127

Dec 29 2021, 5:30 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T2498: Expected error when deleting vif that has dhcp-server configured as Not Applicable.

Fixed VyOS 1.3.0:

vyos@r4# run show conf com | match dhcp
set interfaces ethernet eth2 vif 35 address 'dhcp'
[edit]
vyos@r4# run show int
Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface        IP Address                        S/L  Description
---------        ----------                        ---  -----------
eth0             192.168.122.14/24                 u/u  WAN
eth1             203.0.113.14/24                   u/u  Lan
                 192.0.2.14/24                          
eth2             -                                 u/u  
eth2.35          10.0.2.10/24                      u/u
Dec 29 2021, 5:14 PM · VyOS Rolling
aha created T4120: [VXLAN] add ability to set multiple unicast-remotes.
Dec 29 2021, 4:43 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a project to T2700: Redirecting traffic from PPPoE interface to IFB fails: VyOS 1.4 Sagitta.

To reproduce:

set interfaces ethernet eth2 vif 35
set interfaces pppoe pppoe0 authentication password 'MYPASSWORD'
set interfaces pppoe pppoe0 authentication user 'MYUSER'
set interfaces pppoe pppoe0 default-route 'force'
set interfaces pppoe pppoe0 mtu '1492'
set interfaces pppoe pppoe0 redirect 'ifb0'
set interfaces pppoe pppoe0 source-interface 'eth2.35'
set interfaces pppoe pppoe0 traffic-policy out 'OUT2'
set interfaces input ifb0

Commit:

vyos@r11-roll# commit
[ interfaces pppoe pppoe0 redirect ifb0 ]
Cannot find device "pppoe0"
tc qdisc ingress failed at /opt/vyatta/sbin/vyatta-qos.pl line 334.
Dec 29 2021, 4:05 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav closed T2695: Flow-accounting bug with subinterfaces as Resolved.
Dec 29 2021, 4:00 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav moved T2400: OpenVPN: dont restart server if no need from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Dec 29 2021, 3:59 PM · VyOS 1.3 Equuleus ( 1.3.1)
Viacheslav closed T2400: OpenVPN: dont restart server if no need, a subtask of T3995: OpenVPN: do not stop/start service on configuration change, as Resolved.
Dec 29 2021, 3:58 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T2400: OpenVPN: dont restart server if no need as Resolved.

Fixed in eceaa3a7

Dec 29 2021, 3:58 PM · VyOS 1.3 Equuleus ( 1.3.1)
RyVolodya added a comment to T4111: IPSec generates wrong configuration colons for IPv6 peers.

Test version:
VyOS 1.4-rolling-202112290317
Result:

Dec 29 2021, 3:56 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID: VyOS 1.4 Sagitta.
Dec 29 2021, 3:55 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4111: IPSec generates wrong configuration colons for IPv6 peers as Resolved.
Dec 29 2021, 3:54 PM · VyOS 1.4 Sagitta
aha added a comment to T4116: Webproxy/Squid not working with IPv6 listen-address.

Never done this before. I hope that PR is correct:
https://github.com/vyos/vyos-1x/pull/1126

Dec 29 2021, 3:35 PM · VyOS 1.4 Sagitta
Viacheslav closed T2922: The `vpn ipsec logging log-modes` miss the IPSec daemons state check as Resolved.
Dec 29 2021, 2:52 PM · VyOS 1.3 Equuleus ( 1.3.1)
Viacheslav added a comment to T4116: Webproxy/Squid not working with IPv6 listen-address.

Just fork the repository vyos-1x and create a PR with propper commit format.
https://docs.vyos.io/en/equuleus/contributing/development.html#fork-repository-and-submit-patch
https://github.com/vyos/vyos-1x/blob/current/CONTRIBUTING.md

Dec 29 2021, 2:33 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4085: Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict.

Related task https://phabricator.vyos.net/T4119

Dec 29 2021, 2:33 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Unknown Object (User) edited projects for T4119: Issue with l2tp remote-access ipv6 configuration, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Dec 29 2021, 2:32 PM · VyOS 1.4 Sagitta
Unknown Object (User) created T4119: Issue with l2tp remote-access ipv6 configuration.
Dec 29 2021, 2:30 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4117: Does not possible to configure PoD/CoA for L2TP vpn.

PR https://github.com/vyos/vyos-1x/pull/1125

Dec 29 2021, 2:09 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
dmbaturin created T4118: IPsec syntax overhaul.
Dec 29 2021, 1:59 PM · VyOS 1.4 Sagitta
dmbaturin committed rVYOSONEX6414138a9c5b: Improve IPsec help strings.
Dec 29 2021, 1:43 PM
dmbaturin committed rVYOSONEX07f680c5ee94: More consise consistent help strings for listen-address commands.
Dec 29 2021, 1:43 PM
dmbaturin committed rVYOSONEX2865bcc11a4b: Improve tunnel interface help strings.
Dec 29 2021, 1:43 PM
Unknown Object (User) changed the status of T4117: Does not possible to configure PoD/CoA for L2TP vpn from Open to In progress.
Dec 29 2021, 1:32 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Unknown Object (User) created T4117: Does not possible to configure PoD/CoA for L2TP vpn.
Dec 29 2021, 1:32 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
aha added a comment to T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0.

Maybe "is_addr_assigned" on "python/vyos/validate.py" needs to be patched too.
When I set "listen-address fe80::abc2%eth0" to service tftp-server then "is_addr_assigned" got called and run into an error:

Dec 29 2021, 1:04 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
aha created T4116: Webproxy/Squid not working with IPv6 listen-address.
Dec 29 2021, 12:52 PM · VyOS 1.4 Sagitta
olofl created T4115: reboot in <x> not working as expected.
Dec 29 2021, 11:38 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Unknown Object (User) created T4114: Allow software running as systemd service write coredumps.
Dec 29 2021, 10:58 AM
aha added a comment to T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0.

At the moment I am testing the patch with some common services and found a tiny issue inside the auto completion feature.

Dec 29 2021, 8:31 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta