I think it is necessary to show this kind information . it should use tools/service as netflow/ipfix . for example:
- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
All Stories
Feb 14 2022
works as expected:
sure, I'll test 1.4 rolling
but if this feature simply adds "dev XXX" to virtual_address in vrrp config that shouldn't break much
@Alexey.Kirillov it required more tests and responses from 1.4
Could you test it?
I can't get your configuration, how does should work without the declaration source or remote address?
I think I'm experiencing this same issue. I just tried upgrading a VPN server running 1.3-rolling-202001260217 to 1.3.0 LTS. As this is a production server (albeit a secondary/backup server) I've reverted to the old version of VyOS, and it looks like a fix is already on its way, so I just wanted to add my info to the ticket.
Feb 13 2022
Is there any chance to backport this to 1.3x ?
It makes migration from cluster way easier.
@Viacheslav As I said: every rolling version of VyOS 1.3 branch starting from mid-January. I built ISO several times during this month. Last one I tried today (built today). All of them behave like this in my two different routers. Last time ocserv worked was middle of December build.
Which version?
Feb 12 2022
Feb 11 2022
@Scoopta Can you check your configuration with the next rolling release?
@hensur Could you create a PR for 1.3?
Checked in VyOS 1.3-stable-202202101926
Feb 10 2022
Issue can be triggered also with a reduced CLI config, just run this multiple times:
I'm able to reproduce this with 1.4, using the new config structure:
I will close this. It turns out the root cause is related to this other bug I filed:
There is an example of a working configuration:
set interfaces openvpn vtun10 authentication password xxxxxx set interfaces openvpn vtun10 authentication username xxxxxx set interfaces openvpn vtun10 device-type 'tun' set interfaces openvpn vtun10 encryption cipher 'aes256' set interfaces openvpn vtun10 hash 'sha512' set interfaces openvpn vtun10 mode 'client' set interfaces openvpn vtun10 openvpn-option '--config /config/auth/nord/included_config.conf' set interfaces openvpn vtun10 persistent-tunnel set interfaces openvpn vtun10 protocol 'udp' set interfaces openvpn vtun10 remote-host 'xxx.xxx.218.155' set interfaces openvpn vtun10 remote-port '1194' set interfaces openvpn vtun10 tls ca-cert-file xxxxxx
Feb 9 2022
we found an error when we tried to upload the configuration using the frr.reload.py . I did an issues request to FRR with this problem ,here is the case:
I checked in the OpenVPN network lab.
Version:
Version: VyOS 1.3.0 Release train: equuleus
Configuration:
vyos@vyos# show interfaces openvpn vtun0 set interfaces openvpn vtun0 encryption cipher 'aes256gcm' set interfaces openvpn vtun0 hash 'sha512' set interfaces openvpn vtun0 local-host '192.168.122.100' set interfaces openvpn vtun0 local-port '1194' set interfaces openvpn vtun0 mode 'server' set interfaces openvpn vtun0 openvpn-option '--client-to-client' set interfaces openvpn vtun0 openvpn-option '--verb 9' set interfaces openvpn vtun0 openvpn-option '--mute 10' set interfaces openvpn vtun0 openvpn-option '--dev vtun0' set interfaces openvpn vtun0 openvpn-option '--ifconfig-pool-persist ipp.txt' set interfaces openvpn vtun0 openvpn-option '--status openvpn2.log' set interfaces openvpn vtun0 openvpn-option '--user nobody --group nogroup' set interfaces openvpn vtun0 openvpn-option '--persist-key --persist-tun' set interfaces openvpn vtun0 openvpn-option '--keepalive 10 120' set interfaces openvpn vtun0 persistent-tunnel set interfaces openvpn vtun0 protocol 'udp' set interfaces openvpn vtun0 server max-connections '5' set interfaces openvpn vtun0 server name-server '1.1.1.1' set interfaces openvpn vtun0 server push-route 10.10.10.0/24 set interfaces openvpn vtun0 server subnet '10.10.20.0/24' set interfaces openvpn vtun0 server topology 'subnet' set interfaces openvpn vtun0 tls ca-cert-file '/config/auth/openvpn/ca.crt' set interfaces openvpn vtun0 tls cert-file '/config/auth/openvpn/central.crt' set interfaces openvpn vtun0 tls dh-file '/config/auth/openvpn/dh.pem' set interfaces openvpn vtun0 tls key-file '/config/auth/openvpn/central.key' set interfaces openvpn vtun0 use-lzo-compression
After rebooting, the OpenVPN configuration is saved:
@Scoopta I can't get your configuration, how does should work without the declaration source or remote address?
There is a template that generates OpenVPN site-to-site configuration https://github.com/vyos/vyos-1x/blob/9910020ae6ef37964c97bb28b6b1d84f8227650b/data/templates/openvpn/server.conf.tmpl#L143-L147
To reproduce in 1.4
set interfaces bridge br3 member interface vtun2 set interfaces openvpn vtun2 device-type 'tap' set interfaces openvpn vtun2 mode 'site-to-site' set interfaces openvpn vtun2 persistent-tunnel set interfaces openvpn vtun2 shared-secret-key 'foo' set pki openvpn shared-secret foo key '190696ff2244ca9ce8d5bef8718c58881fe8df8e3519c8bf6ede49108c97a5d9456db648d8c5ca953bb19d21978527a742497426313e614640d037ffffa4980be315e193727ebfb28f3725b779e2d3309ad6f8c939363f7fc14a0080c81e3faf4b053661c81c3003ddabeb87ac8611b81718956b7325f03978c74f502b39965f0d788b21b4370f6a625e3098f8d71ff3e653f50c54b424c511cba78871b38337237830a34266aa9558cd69c68ded89f7f0a82f94b5b87200c7ea05edb14a806e9e4998b00dc2895d976c0e506a6a06056745bca6ce1d2a5c95a51a1460e3080c7743eecbcee9d2c4f89d9e1b59f44484e43591f43bf713255b5de13ae8500620' set pki openvpn shared-secret foo version '1'
Commit:
Traceback (most recent call last):
File "/usr/libexec/vyos/conf_mode/interfaces-openvpn.py", line 663, in <module>
verify(c)
File "/usr/libexec/vyos/conf_mode/interfaces-openvpn.py", line 228, in verify
if len([addr for addr in openvpn['local_address'] if is_ipv4(addr)]) > 1:
KeyError: 'local_address'It can be fixed in thoses PR's:
https://github.com/vyos/vyos-1x/pull/1210
https://github.com/vyos/vyos-1x/pull/1211
T4230