Page MenuHomeVyOS Platform
Feed Search

Jan 18 2022

sarthurdev changed the status of T1292: Issues while deleting all rules from a firewall from Open to Needs testing.

Fixed in 1.4 PR: https://github.com/vyos/vyos-1x/pull/1176

Jan 18 2022, 1:45 PM · VyOS 1.4 Sagitta
c-po added a comment to T4187: XDP broken for VLAN/vif interfaces with hardware offloading.

The XDP proof of concept program that is availbale in 1.4 does not support 802.1q - those headers are not parsed and processed.

Jan 18 2022, 5:42 AM · VyOS 1.4 Sagitta
c-po changed the status of T4187: XDP broken for VLAN/vif interfaces with hardware offloading from Open to Confirmed.
Jan 18 2022, 5:41 AM · VyOS 1.4 Sagitta
c-po added a comment to T4189: Ability to set dns forwarding in vrf.

What would be the use-case? We can start PDNS in one VRF context only.

Jan 18 2022, 5:40 AM · VyOS 1.4 Sagitta
c-po changed the status of T3700: Support VLAN tunnel mapping of VLAN aware bridges, a subtask of T3137: Let VLAN aware bridge approach the behavior of professional equipment, from In progress to On hold.
Jan 18 2022, 5:26 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po changed the status of T3700: Support VLAN tunnel mapping of VLAN aware bridges from In progress to On hold.
Jan 18 2022, 5:26 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T2762: VRF: when SSHd is VRF bound all commands are executed in VRF context: VyOS 1.4 Sagitta.
Jan 18 2022, 2:28 AM · VyOS Rolling

Jan 17 2022

Viacheslav updated the task description for T4191: Lost access to host after VRF re-creating.
Jan 17 2022, 8:12 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav created T4191: Lost access to host after VRF re-creating.
Jan 17 2022, 8:09 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
sarthurdev closed T4188: Firewall does not correctly handle conntracking as Invalid.

You need to remove the state new match on the rule and it'll work.

Jan 17 2022, 7:54 PM · VyOS 1.4 Sagitta
c-po closed T3164: console-server ssh does not work with RADIUS PAM auth as Resolved.
Jan 17 2022, 7:22 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po moved T3164: console-server ssh does not work with RADIUS PAM auth from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 17 2022, 7:22 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.171 / 5.10.91 to Update Linux Kernel to v5.4.172 / 5.10.92.
Jan 17 2022, 6:05 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
n.fort added a comment to T4173: Wan Load Balancing - Error on firewall NAT rules.

Tested and working as expected on VyOS 1.4-rolling-202201150317

Jan 17 2022, 3:48 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4189: Ability to set dns forwarding in vrf.

There are some issues with powerdns in vrf context.

Jan 17 2022, 12:59 PM · VyOS 1.4 Sagitta
UnicronNL created T4190: Add commit comment to the configuration API..
Jan 17 2022, 12:34 PM
sarthurdev added a comment to T4178: policy based routing tcp flags issue.

Included those flags in PR: https://github.com/vyos/vyos-1x/pull/1174

Jan 17 2022, 11:29 AM · VyOS 1.4 Sagitta
n.fort added a comment to T4178: policy based routing tcp flags issue.

Think 2 flag options should be added.
According to nft wiki these are all the flags that nft could match: tcp flags { fin, syn, rst, psh, ack, urg, ecn, cwr}

Jan 17 2022, 11:23 AM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3873: Zone based Firewall - Filter traffic in same zone.

Included in PR: https://github.com/vyos/vyos-1x/pull/1174

Jan 17 2022, 11:08 AM · VyOS 1.4 Sagitta
Viacheslav created T4189: Ability to set dns forwarding in vrf.
Jan 17 2022, 11:02 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4100: Firewall increase maximum number of rules.

It is a different task, it extends only the range which you can to use for rule numbers.
For example, if you want 3 rules
Rule 100, rule 1000, rule 10000 etc.
Accepting time it is another task. B.t.w firewall was rewritten in 1.4, I hope that commit time was decreased.

Jan 17 2022, 10:18 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
FileGo created T4188: Firewall does not correctly handle conntracking.
Jan 17 2022, 6:43 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4100: Firewall increase maximum number of rules.

I think we will have a problem with such a large number of rules. Now, if there are 1500 vyos rules, it takes 30 minutes to load. If there are 999999 rules, it will take a very long time to load.

Jan 17 2022, 12:53 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
bbabich created T4187: XDP broken for VLAN/vif interfaces with hardware offloading.
Jan 17 2022, 12:47 AM · VyOS 1.4 Sagitta

Jan 16 2022

sarthurdev changed the status of T3873: Zone based Firewall - Filter traffic in same zone from Open to In progress.

Thanks, will include a fix in a PR shortly

Jan 16 2022, 9:43 PM · VyOS 1.4 Sagitta
c-po moved T3164: console-server ssh does not work with RADIUS PAM auth from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 16 2022, 8:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
c-po changed the status of T3164: console-server ssh does not work with RADIUS PAM auth from Open to Needs testing.
Jan 16 2022, 8:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
n.fort added a comment to T4160: Firewall - Error in rules that matches everything except something.

I can see the fix, but now trying invert selection on tcp flags doesn't work

Jan 16 2022, 4:07 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4186: Firewall icmp type - Offered options not supported.

PR: https://github.com/vyos/vyos-1x/pull/1173

Jan 16 2022, 3:47 PM · VyOS 1.4 Sagitta
n.fort claimed T4186: Firewall icmp type - Offered options not supported.
Jan 16 2022, 2:09 PM · VyOS 1.4 Sagitta
n.fort created T4186: Firewall icmp type - Offered options not supported.
Jan 16 2022, 2:09 PM · VyOS 1.4 Sagitta
n.fort added a comment to T3873: Zone based Firewall - Filter traffic in same zone.

Testing this feature in VyOS 1.4-rolling-202201100317 I'm getting some unexpected behavior.
Config:

Jan 16 2022, 1:41 PM · VyOS 1.4 Sagitta
c-po added a comment to T3700: Support VLAN tunnel mapping of VLAN aware bridges.

For full support we need this added to FRR: https://github.com/FRRouting/frr/pull/9204

Jan 16 2022, 11:02 AM · VyOS 1.4 Sagitta

Jan 15 2022

Viacheslav moved T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from Open to Finished on the VyOS 1.4 Sagitta board.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1172

Jan 15 2022, 4:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0 as Resolved.
Jan 15 2022, 3:52 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4183: IPv6 link-local address not accepted as wireguard peer as Resolved.
Jan 15 2022, 3:52 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.

PR https://github.com/vyos/vyos-1x/pull/1171

Jan 15 2022, 3:47 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav renamed T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from NTP allow-clients address doesn't work to NTP allow-clients address doesn't work it allows to use ntp server for all addresses.
Jan 15 2022, 3:32 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from "Task" to "Bug".
Jan 15 2022, 3:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from Open to In progress.
Jan 15 2022, 3:14 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1170

Jan 15 2022, 3:13 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1170

Jan 15 2022, 3:12 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav reopened T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0 as "In progress".
Jan 15 2022, 3:01 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav reopened T4183: IPv6 link-local address not accepted as wireguard peer as "In progress".
Jan 15 2022, 1:30 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav moved T4150: VRRP with conntrack-sync does not work from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 15 2022, 1:28 PM · VyOS 1.4 Sagitta
Viacheslav closed T4183: IPv6 link-local address not accepted as wireguard peer as Resolved.
Jan 15 2022, 11:49 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) closed T4150: VRRP with conntrack-sync does not work as Resolved.

Re-tested in VyOS 1.4-rolling-202201140317
Now it works, thank you!

Jan 15 2022, 12:45 AM · VyOS 1.4 Sagitta

Jan 14 2022

Viacheslav changed the status of T4172: Patch ndppd to not read route table if there are no auto prefixes from Open to In progress.
Jan 14 2022, 9:14 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4183: IPv6 link-local address not accepted as wireguard peer from Open to In progress.
Jan 14 2022, 9:01 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

PR https://github.com/vyos/vyos-1x/pull/1169

Jan 14 2022, 9:01 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4182: Show vrrp if vrrp not configured bug as Resolved.
Jan 14 2022, 8:23 PM · VyOS 1.4 Sagitta
Viacheslav closed T4179: Add op-mode CLI for show high-availability virtual-server as Resolved.
Jan 14 2022, 8:22 PM · VyOS 1.4 Sagitta
Viacheslav closed T4177: Strip-private doesn't work for service monitoring as Resolved.
Jan 14 2022, 8:22 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4150: VRRP with conntrack-sync does not work.

@NikolayP Could you re-test it?

Jan 14 2022, 8:19 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2199: Rewrite firewall in new XML/Python style: T3762: Support network and address groups for policy ipv6-route.
Jan 14 2022, 8:18 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav added a parent task for T3762: Support network and address groups for policy ipv6-route: T2199: Rewrite firewall in new XML/Python style.
Jan 14 2022, 8:18 PM · VyOS 1.4 Sagitta
Viacheslav closed T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID as Resolved.
Jan 14 2022, 8:11 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav edited projects for T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus (1.3.0).
Jan 14 2022, 8:09 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.

Some detail here T1280

Jan 14 2022, 2:25 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
johannrichard added a comment to T2199: Rewrite firewall in new XML/Python style.

@sdev: in your original commit for this task, recent rules are somehow semi-discarded (the time/counter condition will not be written out; however, the action will be written out) because of an apparent problem with nftables in this area.

Jan 14 2022, 10:10 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
Unknown Object (User) updated the task description for T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.
Jan 14 2022, 10:01 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
odhnera added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

Thanks; I just tested commenting out line 5 of that file, and it successfully works around the issue, allowing me to set a link-local IPv6 address as my endpoint. The wireguard connection itself also works, and I can pass traffic.

Jan 14 2022, 1:08 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

@odhnera Try to comment or delete the validation string and restart vyos-configd service

Jan 14 2022, 12:15 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Jan 13 2022

odhnera added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

Getting link-local addresses to work would probably be very low-priority, but I did run into an extremely niche case where I wanted to do that. It's not the type of situation that would happen in a production environment, but I was running VyOS on a computer tethered via ethernet to an Android-based phone, and I wanted to connect to a wireguard peer running on the phone. Modern version of Android randomize the IPv4 address of their tethered interface on each reboot, but their link-local IPv6 address remains the same, making it more convenient to use it.

Jan 13 2022, 11:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4183: IPv6 link-local address not accepted as wireguard peer.

Link-local addresses with %ethX are not accepted in any protocols/peers/etc. A few services are allowed to set them as listen like ssh/dns at the moment.
Is there a real use case why you need it on wireguard interfaces?

Jan 13 2022, 11:23 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4183: IPv6 link-local address not accepted as wireguard peer from "Bug" to "Feature Request".
Jan 13 2022, 11:19 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4025: OpenVPN server with TAP interface, client didn’t see network.

It generates by openvpn, maybe something new in the new OpenVPN version
So I see only one option - add mode server-bridge

Jan 13 2022, 11:02 PM · Bugs, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1), Restricted Project, openvpn
odhnera created T4183: IPv6 link-local address not accepted as wireguard peer.
Jan 13 2022, 10:05 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav assigned T4181: Firewall ipv6-network-group - incorrect description on helper to fernando.
Jan 13 2022, 8:34 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4178: policy based routing tcp flags issue from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1167

Jan 13 2022, 8:29 PM · VyOS 1.4 Sagitta
Viacheslav closed T4109: Extend high-availability/keepalived for support virtual-server lb as Resolved.
Jan 13 2022, 8:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4182: Show vrrp if vrrp not configured bug.

PR https://github.com/vyos/vyos-1x/pull/1166

Jan 13 2022, 8:20 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4182: Show vrrp if vrrp not configured bug from Open to In progress.
Jan 13 2022, 7:51 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T2898: Support NDP proxy.

@hensur I'm glad you reimplemented this feature. Come on

Jan 13 2022, 7:44 PM · VyOS 1.4 Sagitta
jack9603301 added a project to T2898: Support NDP proxy: VyOS 1.4 Sagitta.
Jan 13 2022, 7:43 PM · VyOS 1.4 Sagitta
Viacheslav created T4182: Show vrrp if vrrp not configured bug.
Jan 13 2022, 7:42 PM · VyOS 1.4 Sagitta
jack9603301 assigned T2898: Support NDP proxy to hensur.
Jan 13 2022, 7:41 PM · VyOS 1.4 Sagitta
jack9603301 changed the status of T2898: Support NDP proxy, a subtask of T2518: Add support for IPv6 NAT (NPTv6), from Open to In progress.
Jan 13 2022, 7:41 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
jack9603301 changed the status of T2898: Support NDP proxy from Open to In progress.
Jan 13 2022, 7:40 PM · VyOS 1.4 Sagitta
fernando added a comment to T4181: Firewall ipv6-network-group - incorrect description on helper .

PR: https://github.com/vyos/vyos-1x/pull/1168/

Jan 13 2022, 7:22 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4179: Add op-mode CLI for show high-availability virtual-server from Open to In progress.
Jan 13 2022, 7:15 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4179: Add op-mode CLI for show high-availability virtual-server.

PR https://github.com/vyos/vyos-1x/pull/1164

Jan 13 2022, 7:15 PM · VyOS 1.4 Sagitta
fernando created T4181: Firewall ipv6-network-group - incorrect description on helper .
Jan 13 2022, 6:54 PM · VyOS 1.4 Sagitta
johannrichard added a comment to T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases .

See comment in T4164: is working now.

Jan 13 2022, 4:52 PM · VyOS 1.4 Sagitta
johannrichard added a comment to T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.

See comment in T4164: my config runs through easily now.

Jan 13 2022, 4:52 PM · VyOS 1.4 Sagitta
johannrichard added a comment to T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf`.

@sdev this (and the other fixes) look promising: after upgrading to the latest rolling release from 13.1.2022, both the example provided in the ticket as well as my config (a copy of my production setup with rules covering PBR, empty groups, references to "defines" in PBR rules) ran through easily. My production config created no errors when loading the config after the update.

Jan 13 2022, 4:49 PM · VyOS 1.4 Sagitta
zsdc created T4180: Support for QoS Policy Propagation via BGP (QPPB).
Jan 13 2022, 2:51 PM · VyOS Rolling
Viacheslav created T4179: Add op-mode CLI for show high-availability virtual-server.
Jan 13 2022, 1:42 PM · VyOS 1.4 Sagitta
Viacheslav closed T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0 as Resolved.
Jan 13 2022, 1:26 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
sarthurdev changed the status of T4178: policy based routing tcp flags issue from Open to In progress.

Thanks for the report, working on the fix now.

Jan 13 2022, 11:55 AM · VyOS 1.4 Sagitta
mTx87 added a project to T4178: policy based routing tcp flags issue: VyOS 1.4 Sagitta.
Jan 13 2022, 11:50 AM · VyOS 1.4 Sagitta
johannrichard added a comment to T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf`.
In T4164#116547, @mTx87 wrote:

seems like policy based routing not working.

Jan 13 2022, 11:38 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4177: Strip-private doesn't work for service monitoring.

PR https://github.com/vyos/vyos-1x/pull/1163

Jan 13 2022, 9:53 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
mTx87 added a comment to T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf`.

moved my comment to a new bug request to keep this one here clean.

Jan 13 2022, 9:41 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4177: Strip-private doesn't work for service monitoring from Open to In progress.
Jan 13 2022, 9:38 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav closed T4175: BGP configuration failed as Resolved.

T3741

Jan 13 2022, 9:18 AM · VyOS 1.4 Sagitta
hexes added a comment to T4025: OpenVPN server with TAP interface, client didn’t see network.

Any updates? No one?

Jan 13 2022, 3:56 AM · Bugs, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1), Restricted Project, openvpn
Viacheslav updated subscribers of T4177: Strip-private doesn't work for service monitoring.
Jan 13 2022, 1:17 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav created T4177: Strip-private doesn't work for service monitoring.
Jan 13 2022, 1:16 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T3872: Add configurable telegraf monitoring service.

PR https://github.com/vyos/vyos-1x/pull/1162

Jan 13 2022, 1:12 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta