Page MenuHomeVyOS Platform
Feed All Stories

Jan 26 2022

al-pankov added a comment to T4211: Vyos arm64-latest build issue with libc6 pkg.

Jan 26 2022, 8:32 AM · VyOS 1.4 Sagitta, vyos-build
al-pankov created T4211: Vyos arm64-latest build issue with libc6 pkg.
Jan 26 2022, 8:31 AM · VyOS 1.4 Sagitta, vyos-build

Jan 25 2022

Viacheslav added a comment to T4210: NAT source/destination negated ports throws an error.

Is it the same task T4138 ?

Jan 25 2022, 8:43 PM · VyOS 1.4 Sagitta
sarthurdev created T4210: NAT source/destination negated ports throws an error.
Jan 25 2022, 7:56 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4138: NAT configuration allows to set incorrect port range and invalid port.

PR https://github.com/vyos/vyos-1x/pull/1191

Jan 25 2022, 7:16 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4138: NAT configuration allows to set incorrect port range and invalid port from Open to In progress.
Jan 25 2022, 7:06 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXceb52d57e965: monitoring: T3872: Delete iptables input plugin as we use nft.
Jan 25 2022, 6:40 PM
GitHub <[email protected]> committed rVYOSONEX5177313cfc12: Merge pull request #1189 from sever-sever/T3872 (authored by c-po).
Jan 25 2022, 6:40 PM
sarthurdev added a comment to T4209: Firewall incorrect handler for recent count and time.

I had forgotten about the recent syntax and it was merged in a broken state (https://github.com/vyos/vyos-1x/blob/current/python/vyos/firewall.py#L164). We should try and find a remedy, or remove it from CLI.

Jan 25 2022, 5:23 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4196: DHCP server client-prefix-length parameter results in non-functional leases from In progress to Needs testing.
Jan 25 2022, 4:31 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
Viacheslav added a comment to T4194: prefix-list no check for duplicate entries.

PR https://github.com/vyos/vyos-1x/pull/1190

set policy prefix-list TST_PRF_LST rule 10 action 'permit'
set policy prefix-list TST_PRF_LST rule 10 prefix '10.5.5.0/24'
set policy prefix-list TST_PRF_LST rule 20 action 'permit'
set policy prefix-list TST_PRF_LST rule 20 prefix '10.6.6.0/24'
set policy prefix-list TST_PRF_LST rule 30 action 'permit'
set policy prefix-list TST_PRF_LST rule 30 prefix '10.6.6.0/24'
Jan 25 2022, 4:25 PM · VyOS 1.4 Sagitta
Viacheslav assigned T4209: Firewall incorrect handler for recent count and time to sarthurdev.
Jan 25 2022, 2:07 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4209: Firewall incorrect handler for recent count and time.
Jan 25 2022, 11:51 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4209: Firewall incorrect handler for recent count and time.
Jan 25 2022, 11:50 AM · VyOS 1.4 Sagitta
Viacheslav created T4209: Firewall incorrect handler for recent count and time.
Jan 25 2022, 11:47 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4208: Issues With More than Two Default Route Paths.

Try to dump traffic from the required interface

Jan 25 2022, 10:32 AM · VyOS 1.3 Equuleus (1.3.7)
Viacheslav updated the task description for T4208: Issues With More than Two Default Route Paths.
Jan 25 2022, 10:26 AM · VyOS 1.3 Equuleus (1.3.7)
Viacheslav added a comment to T4207: Policy Based Route Issue with Rules for Multiple Tables.

For first do these changes as in commit
Try policy local route, for example:

set policy local-route rule 10 set table 111
set policy local-route rule 10 source 192.0.2.0/24
Jan 25 2022, 10:25 AM · Bugs, VyOS 1.3 Equuleus (1.3.8)
Viacheslav added a comment to T4206: Policy Based Routing with DHCP Interface Issue.

The main reason:

Jan 25 2022, 10:05 AM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav added a comment to T4206: Policy Based Routing with DHCP Interface Issue.

@Rhongomiant Am I understanding correctly that you don't see the default route in table 111?

Jan 25 2022, 9:50 AM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav updated the task description for T4207: Policy Based Route Issue with Rules for Multiple Tables.
Jan 25 2022, 9:44 AM · Bugs, VyOS 1.3 Equuleus (1.3.8)
Viacheslav updated the task description for T4206: Policy Based Routing with DHCP Interface Issue.
Jan 25 2022, 9:38 AM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav closed T4205: Disable Debian Version in SSH (DebianBanner->no) as Resolved.
Jan 25 2022, 9:14 AM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX10fb7f4c6d07: sshd: T4205: Hide extra version suffix "Debian".
Jan 25 2022, 8:55 AM
GitHub <[email protected]> committed rVYOSONEX3249d761843c: Merge pull request #1188 from sever-sever/T4205 (authored by c-po).
Jan 25 2022, 8:55 AM
Viacheslav added a comment to T4205: Disable Debian Version in SSH (DebianBanner->no).

PR https://github.com/vyos/vyos-1x/pull/1188

Jan 25 2022, 8:53 AM · VyOS 1.4 Sagitta
Viacheslav closed T4131: Show firewall group incorrect format members as Resolved.

@sdev Thanks

Jan 25 2022, 8:19 AM · VyOS 1.4 Sagitta
Rhongomiant created T4208: Issues With More than Two Default Route Paths.
Jan 25 2022, 5:00 AM · VyOS 1.3 Equuleus (1.3.7)
Rhongomiant created T4207: Policy Based Route Issue with Rules for Multiple Tables.
Jan 25 2022, 4:33 AM · Bugs, VyOS 1.3 Equuleus (1.3.8)
Rhongomiant created T4206: Policy Based Routing with DHCP Interface Issue.
Jan 25 2022, 4:08 AM · VyOS 1.3 Equuleus (1.3.2)

Jan 24 2022

Unknown Object (User) closed T4204: Update Accel-PPP to a newer revision as Resolved.
Jan 24 2022, 10:01 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
drixter created T4205: Disable Debian Version in SSH (DebianBanner->no).
Jan 24 2022, 8:38 PM · VyOS 1.4 Sagitta
goodNETnick <[email protected]> committed rVYOSONEX97aca4001263: DHCP: T4196: fix client-prefix-length parameter.
Jan 24 2022, 6:59 PM
GitHub <[email protected]> committed rVYOSONEXc50dc1217d0d: Merge pull request #1187 from goodNETnick/dhcp-client-prefix_1.3 (authored by c-po).
Jan 24 2022, 6:59 PM
n.fort closed T1795: Commit rollback by timeout as Resolved.

Task already implemented:

Jan 24 2022, 6:56 PM · VyOS 1.4 Sagitta, Global Notifications
Unknown Object (User) changed the status of T4204: Update Accel-PPP to a newer revision from In progress to Needs testing.
Jan 24 2022, 8:30 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4204: Update Accel-PPP to a newer revision.

PR current - https://github.com/vyos/vyos-build/pull/214
PR equuleus - https://github.com/vyos/vyos-build/pull/215

Jan 24 2022, 8:29 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T4204: Update Accel-PPP to a newer revision from Open to In progress.
Jan 24 2022, 8:21 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) created T4204: Update Accel-PPP to a newer revision.
Jan 24 2022, 8:20 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T4072: Feature Request: Firewall on bridge interfaces.
Jan 24 2022, 5:29 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4196: DHCP server client-prefix-length parameter results in non-functional leases.

PR for 1.3:
https://github.com/vyos/vyos-1x/pull/1187

Jan 24 2022, 1:46 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
n.fort added a comment to T4199: Commit failed when setting icmpv6 type any.

@artooro It still accepts type-name.

Jan 24 2022, 12:08 AM · VyOS 1.4 Sagitta

Jan 23 2022

artooro added a comment to T4199: Commit failed when setting icmpv6 type any.

@n.fort I just built a fresh image and tested. The first thing I noticed is that icmpv6 now only accepts integers while previously it accepted names. I'm assuming this is a purposeful design change where users now have to set type-name instead.
The any option has been removed, which I suspect is OK as you'd simply leave it unset if you want to accept all icmp types.
Overall this should eliminate the user confusion so I think it's a good change.

Jan 23 2022, 8:17 PM · VyOS 1.4 Sagitta
n.fort closed T4181: Firewall ipv6-network-group - incorrect description on helper as Resolved.

Tested on VyOS 1.4-rolling-202201230317

Jan 23 2022, 2:17 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4199: Commit failed when setting icmpv6 type any.

@artooro , please try again using latest version -> vyos-1.4-rolling-202201230317-amd64.iso
Just tested, and for me, it's working as expected.
PR that solves this issue: https://github.com/vyos/vyos-1x/pull/1184

Jan 23 2022, 2:12 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4021: Long commit time on bridge interface with 1-4094 allowed VLAN tags.

On VyOS 1.4-rolling-202201230317.
Commands:

Jan 23 2022, 2:00 PM · VyOS 1.4 Sagitta
n.fort closed T4186: Firewall icmp type - Offered options not supported as Resolved.
Jan 23 2022, 12:39 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4186: Firewall icmp type - Offered options not supported.

Tested on latest VyOS 1.4-rolling-202201230317

Jan 23 2022, 12:38 PM · VyOS 1.4 Sagitta

Jan 22 2022

Nicolas Fort <[email protected]> committed rVYOSONEX60d3e93c33df: bandwidth-test: T4153: Fixed bandwidth-test initiate, which was not working….
Jan 22 2022, 10:34 PM
GitHub <[email protected]> committed rVYOSONEX221aee86f4d4: Merge pull request #1186 from nicolas-fort/T4153 (authored by c-po).
Jan 22 2022, 10:34 PM
n.fort added a comment to T4138: NAT configuration allows to set incorrect port range and invalid port.

Error still present on VyOS 1.4-rolling-202201180317

Jan 22 2022, 2:37 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4153: Monitor bandwidth-test initiate not working.

PR: https://github.com/vyos/vyos-1x/pull/1186

Jan 22 2022, 2:14 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort claimed T4153: Monitor bandwidth-test initiate not working.
Jan 22 2022, 1:09 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort closed T4173: Wan Load Balancing - Error on firewall NAT rules as Resolved.
Jan 22 2022, 12:49 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4115: reboot in <x> not working as expected.
Jan 22 2022, 12:26 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
n.fort added a comment to T4202: NFT: Zone policies fail to apply when "l2tp+" is in the interface list.

Wildcard + should be replaces with *, according to nft man page:

Jan 22 2022, 11:20 AM · VyOS 1.4 Sagitta
c-po changed the status of T4203: Reconfigure DHCP client interface causes brief outages from Open to Confirmed.
Jan 22 2022, 9:08 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po created T4203: Reconfigure DHCP client interface causes brief outages.
Jan 22 2022, 9:07 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX958c887f9c01: firewall: T4130: Use correct table to check for state policy rule.
Jan 22 2022, 7:55 AM
sarthurdev committed rVYOSONEX4f8f49c9945a: firewall: T4186: ICMP/v6 migrations.
Jan 22 2022, 7:55 AM
sarthurdev committed rVYOSONEXe31493c32d0e: firewall: T2199: Verify correct ICMP protocol for ipv4/ipv6.
Jan 22 2022, 7:55 AM
sarthurdev committed rVYOSONEX3e4f2f577746: Firewall: T4186: Correct icmp type-name options for firewall rules (authored by Nicolas Fort <[email protected]>).
Jan 22 2022, 7:55 AM
sarthurdev committed rVYOSONEXd0cfd9758bab: Firewall: T4186: typo correction on address-mask-reply description (authored by Nicolas Fort <[email protected]>).
Jan 22 2022, 7:55 AM
sarthurdev committed rVYOSONEX3e55af0ccdf0: Firewall: T4186: Adding icmpv6 corrections, in corcondancy of what was done for… (authored by Nicolas Fort <[email protected]>).
Jan 22 2022, 7:55 AM
GitHub <[email protected]> committed rVYOSONEX3b7629eaa4c8: Merge pull request #1184 from sarthurdev/firewall_icmp (authored by c-po).
Jan 22 2022, 7:55 AM
jack9603301 added a comment to T2898: Support NDP proxy.

@hensur See PR, I implemented a merge script and provided three solutions.

Jan 22 2022, 6:36 AM · VyOS 1.4 Sagitta
kroy created T4202: NFT: Zone policies fail to apply when "l2tp+" is in the interface list.
Jan 22 2022, 4:53 AM · VyOS 1.4 Sagitta

Jan 21 2022

artooro closed T4200: Assigning ipv6-name to interface is not generating nftables rules as Resolved.
Jan 21 2022, 10:35 PM · VyOS 1.4 Sagitta
artooro added a comment to T4200: Assigning ipv6-name to interface is not generating nftables rules.

Confirmed, I just built a new image using 1.4-rolling-202201212148 and I can no longer reproduce the issue.

Jan 21 2022, 10:34 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4186: Firewall icmp type - Offered options not supported.

PR + migration: https://github.com/vyos/vyos-1x/pull/1184

Jan 21 2022, 10:08 PM · VyOS 1.4 Sagitta
artooro added a comment to T4199: Commit failed when setting icmpv6 type any.
Jan 21 2022, 9:42 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4131: Show firewall group incorrect format members.

Loading address group described in task and then printing, works OK.

Jan 21 2022, 6:52 PM · VyOS 1.4 Sagitta
n.fort closed T4144: Firewall address-group - Improve error messages as Resolved.
Jan 21 2022, 6:44 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4144: Firewall address-group - Improve error messages.

Tested on VyOS 1.4-rolling-202201180317 and working as expected.

Jan 21 2022, 6:44 PM · VyOS 1.4 Sagitta
n.fort closed T4133: Firewall network group error with zone-based firewall rules as Resolved.
Jan 21 2022, 6:35 PM · VyOS 1.4 Sagitta, VyConf
n.fort added a comment to T4133: Firewall network group error with zone-based firewall rules.

Seems solved, Not reproducible on VyOS 1.4-rolling-202201180317

Jan 21 2022, 6:35 PM · VyOS 1.4 Sagitta, VyConf
n.fort changed the status of T4199: Commit failed when setting icmpv6 type any from In progress to Confirmed.
Jan 21 2022, 6:20 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4199: Commit failed when setting icmpv6 type any.

Did did work as expeced

vyos@vyos# run show config comm | grep fire
set firewall ipv6-name FOO rule 10 action 'accept'
set firewall ipv6-name FOO rule 10 icmpv6 type 'echo-request'
set firewall ipv6-name FOO rule 10 protocol 'ipv6-icmp'
Jan 21 2022, 6:03 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4199: Commit failed when setting icmpv6 type any.

Also, while matching parameters valid in nftables, such as echo-reply, commit fails too:

Jan 21 2022, 4:29 PM · VyOS 1.4 Sagitta
Viacheslav closed T4137: Firewall group configuration allows to set incorrect port range and invalid port as Resolved.
Jan 21 2022, 4:22 PM · VyOS 1.4 Sagitta
n.fort created T4201: Firewall - ICMPv6 matches not working as expected on 1.3.0.
Jan 21 2022, 4:20 PM · VyOS 1.3 Equuleus (1.3.0)
hensur committed rVYOSONEX2e4bceee568d: policy: T4151: Bugfix policy ipv6-local-route.
Jan 21 2022, 1:51 PM
GitHub <[email protected]> committed rVYOSONEXf791d3ef4c33: Merge pull request #1183 from hensur/current-ipv6-local-route (authored by c-po).
Jan 21 2022, 1:51 PM
hensur added a comment to T4151: IPV6 local PBR Support.

Should be fixed with https://github.com/vyos/vyos-1x/pull/1183

Jan 21 2022, 12:29 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
n.fort added a comment to T4199: Commit failed when setting icmpv6 type any.

Bug related: https://phabricator.vyos.net/T4186

Jan 21 2022, 12:27 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4199: Commit failed when setting icmpv6 type any from Open to In progress.
Jan 21 2022, 12:22 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4200: Assigning ipv6-name to interface is not generating nftables rules.

I can't reproduce this issue on latest rolling

Jan 21 2022, 12:03 PM · VyOS 1.4 Sagitta
hensur added a comment to T4151: IPV6 local PBR Support.

I'm looking into it. From the logs it seems like for src in (pbr[rule_rm][rule]['source'] or ['']) doesn't work if 'source' doesn't exist.

Jan 21 2022, 9:44 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
goodNETnick <[email protected]> committed rVYOSONEX28a92e75cf93: DHCP: T4196: fix client-prefix-length parameter.
Jan 21 2022, 7:59 AM
GitHub <[email protected]> committed rVYOSONEXec5eb00bd83a: Merge pull request #1180 from goodNETnick/dhcp-client-prefix (authored by c-po).
Jan 21 2022, 7:59 AM
Viacheslav added a comment to T4151: IPV6 local PBR Support.

@hensur Smoketest failed.

Jan 21 2022, 7:12 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4154: Error add second gre tunnel with the same source interface.

(VyOS 1.4-rolling-202201200814) - The same.

Jan 21 2022, 2:39 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4137: Firewall group configuration allows to set incorrect port range and invalid port.

I ve testet it on (Version:VyOS 1.4-rolling-202201200814). It seems well.

Jan 21 2022, 2:21 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4115: reboot in <x> not working as expected.

I ve tested this scenario on VyOS 1.4-rolling-202201200814, as said Srividya you can choose minutes betwen 1-99.
If this is critical, you can expand the range by opening a "feature request".

Jan 21 2022, 12:52 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Jan 20 2022

c-po closed T4171: Interface config migration error on 1.2.8 -> 1.4 upgrade, a subtask of T3871: Resolve unexpected interface name reordering, as Resolved.
Jan 20 2022, 7:45 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
c-po closed T4171: Interface config migration error on 1.2.8 -> 1.4 upgrade as Resolved.
Jan 20 2022, 7:45 PM · VyOS 1.4 Sagitta
c-po added a subtask for T3871: Resolve unexpected interface name reordering: T4171: Interface config migration error on 1.2.8 -> 1.4 upgrade.
Jan 20 2022, 7:45 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
c-po added a parent task for T4171: Interface config migration error on 1.2.8 -> 1.4 upgrade: T3871: Resolve unexpected interface name reordering.
Jan 20 2022, 7:45 PM · VyOS 1.4 Sagitta
c-po added a comment to T4171: Interface config migration error on 1.2.8 -> 1.4 upgrade.

Seems to have fixed it

Jan 20 2022, 7:44 PM · VyOS 1.4 Sagitta
jestabro committed rVYOSONEXa41826759ae7: interface-names: T3871: use tempfile during virtual migration.
Jan 20 2022, 7:44 PM