Page MenuHomeVyOS Platform
Feed All Stories

May 6 2022

GitHub <[email protected]> committed rVYOSONEXfb48da5f61da: Merge pull request #1316 from srividya0208/T4381 (authored by c-po).
May 6 2022, 3:03 PM
Viacheslav changed the status of T4410: Telegraf - Output to Splunk from Open to Needs testing.
May 6 2022, 11:57 AM · VyOS 1.4 Sagitta
Viacheslav created T4418: Telegraf - output Plugin azure-data-explorer.
May 6 2022, 11:52 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4417: VRRP doesn't start with conntrack-sync.

Try to delete sync-group, as you use only one group

May 6 2022, 4:16 AM · VyOS 1.4 Sagitta

May 5 2022

skor created T4417: VRRP doesn't start with conntrack-sync.
May 5 2022, 7:05 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX55d2ee80dcdd: op-mode: T4416: Rewrite 'traceroute' op-command and expand available options… (authored by 3roin <[email protected]>).
May 5 2022, 5:15 PM
Viacheslav committed rVYOSONEX80e3120d7945: monitoring: T4410: Add telegraf output Plugin http for Splunk.
May 5 2022, 5:07 PM
GitHub <[email protected]> committed rVYOSONEXc1757b0f420b: Merge pull request #1312 from sever-sever/T4410 (authored by c-po).
May 5 2022, 5:07 PM
c-po closed T4414: Add route-map "as-path prepend last-as x" option as Resolved.
May 5 2022, 4:50 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXa177f40a841b: smoketest: do not auto-load big firewall config on smoketest.
May 5 2022, 4:46 PM
c-po committed rVYOSONEX799b7f511248: policy: T4414: add support for route-map "as-path prepend last-as x".
May 5 2022, 4:46 PM
c-po added a comment to T4414: Add route-map "as-path prepend last-as x" option.

Implemented as set policy route-map FOO rule 10 set as-path prepend-last-as 2

May 5 2022, 4:44 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T4315: Telegraf - Output to prometheus, added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus ( 1.3.1).
May 5 2022, 4:21 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4315: Telegraf - Output to prometheus.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1315

May 5 2022, 4:21 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
zsdc changed the status of T4415: Include license/copyright files in the image but remove user documentation from /usr/share/doc to reduce its size from Open to In progress.

PR for 1.3: https://github.com/vyos/vyos-build/pull/231
PR for 1.4: https://github.com/vyos/vyos-build/pull/230

May 5 2022, 1:33 PM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav assigned T4414: Add route-map "as-path prepend last-as x" option to c-po.
May 5 2022, 12:41 PM · VyOS 1.4 Sagitta
Viacheslav moved T4315: Telegraf - Output to prometheus from Open to Finished on the VyOS 1.4 Sagitta board.
May 5 2022, 12:30 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
e.khudiyev created T4416: Convert 'traceroute' operation to the new syntax and expand available options using python.
May 5 2022, 12:21 PM · VyOS 1.4 Sagitta
zsdc created T4415: Include license/copyright files in the image but remove user documentation from /usr/share/doc to reduce its size.
May 5 2022, 9:35 AM · VyOS 1.3 Equuleus (1.3.2)
Viacheslav added a comment to T4414: Add route-map "as-path prepend last-as x" option.

In 1.4 it working

set policy route-map FOO rule 10 action 'permit'
set policy route-map FOO rule 10 set as-path-prepend 'last-as 2'
May 5 2022, 8:53 AM · VyOS 1.4 Sagitta
Viacheslav created T4414: Add route-map "as-path prepend last-as x" option.
May 5 2022, 8:50 AM · VyOS 1.4 Sagitta
dmbaturin created T4413: Add an API endpoint with basic system stats.
May 5 2022, 7:33 AM · VyOS 1.4 Sagitta
dtoux added a comment to T4405: DHCP client sometimes ignores `no-default-route` option of an interface.

I've creatred a pull request for the above - https://github.com/vyos/vyos-1x/pull/1313

May 5 2022, 5:55 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

May 4 2022

c-po updated the task description for T4412: commit archive: reboot not working with sftp.
May 4 2022, 8:10 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po updated the task description for T4412: commit archive: reboot not working with sftp.
May 4 2022, 8:09 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po assigned T4412: commit archive: reboot not working with sftp to erkin.
May 4 2022, 8:02 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po updated the task description for T4412: commit archive: reboot not working with sftp.
May 4 2022, 8:01 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po created T4412: commit archive: reboot not working with sftp.
May 4 2022, 7:59 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
dtoux updated the task description for T4405: DHCP client sometimes ignores `no-default-route` option of an interface.
May 4 2022, 6:38 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4410: Telegraf - Output to Splunk.

PR https://github.com/vyos/vyos-1x/pull/1312

May 4 2022, 6:15 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4411: Add migration for service monitoring telegraf influxdb from Add migration for service monitoring influxdb to Add migration for service monitoring telegraf influxdb.
May 4 2022, 4:53 PM · VyOS 1.4 Sagitta
Viacheslav created T4411: Add migration for service monitoring telegraf influxdb.
May 4 2022, 4:52 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4315: Telegraf - Output to prometheus from In progress to Needs testing.
May 4 2022, 4:15 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav created T4410: Telegraf - Output to Splunk.
May 4 2022, 4:09 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4362: Wan Load Balancing - Can't create routing tables.

I can't reproduce it
With such configuration all works fine VyOS 1.4-rolling-202204300743:

set load-balancing wan interface-health eth4 failure-count '5'
set load-balancing wan interface-health eth4 nexthop 'dhcp'
set load-balancing wan interface-health eth4 success-count '1'
set load-balancing wan interface-health eth4 test 10 target '192.0.2.40'
set load-balancing wan interface-health eth5 failure-count '5'
set load-balancing wan interface-health eth5 nexthop 'dhcp'
set load-balancing wan interface-health eth5 success-count '1'
set load-balancing wan interface-health eth5 test 10 target '192.0.2.50'
set load-balancing wan interface-health eth6 failure-count '5'
set load-balancing wan interface-health eth6 nexthop 'dhcp'
set load-balancing wan interface-health eth6 success-count '1'
set load-balancing wan interface-health eth6 test 10 target '192.0.2.60'
set load-balancing wan rule 10 failover
set load-balancing wan rule 10 inbound-interface 'eth7'
set load-balancing wan rule 10 interface eth4
set load-balancing wan rule 10 interface eth5
set load-balancing wan rule 10 interface eth6
set load-balancing wan rule 10 protocol 'all'
set load-balancing wan sticky-connections
May 4 2022, 10:35 AM · VyOS 1.4 Sagitta
aserkin created T4409: route received via Framed-Route radius attribute is installed into default table when terminating connection to VRF.
May 4 2022, 7:56 AM
Viacheslav added a comment to T4408: Add sshguard to protect against brut-forces.

Configuration

# cat /etc/sshguard/sshguard.conf 
#### REQUIRED CONFIGURATION ####
# Full path to backend executable (required, no default)
BACKEND="/usr/lib/x86_64-linux-gnu/sshg-fw-nft-sets"
May 4 2022, 3:19 AM · VyOS 1.4 Sagitta
Viacheslav created T4408: Add sshguard to protect against brut-forces.
May 4 2022, 3:06 AM · VyOS 1.4 Sagitta

May 3 2022

blackhole added a comment to T4362: Wan Load Balancing - Can't create routing tables.

If it helps, I am also getting the exact same errors and problems, would love to see this working please

May 3 2022, 11:57 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4380: Feature Request: ocserv: 2FA OTP key generator in VyOS CLI from In progress to Needs testing.
May 3 2022, 7:36 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX5ceabd78f1cc: monitoring: T4315: Add telegraf output plugin prometheus-client.
May 3 2022, 7:13 PM
GitHub <[email protected]> committed rVYOSONEX0400f96c003c: Merge pull request #1310 from sever-sever/T4315 (authored by c-po).
May 3 2022, 7:13 PM
zsdc changed the status of T4407: Network-config v2 is broken in Cloud-init 22.1 and VyOS 1.3 from Open to Needs testing.

Resolved in https://github.com/vyos/vyos-cloud-init/pull/54

May 3 2022, 3:55 PM · VyOS 1.3 Equuleus (1.3.4)
zsdc created T4407: Network-config v2 is broken in Cloud-init 22.1 and VyOS 1.3.
May 3 2022, 3:45 PM · VyOS 1.3 Equuleus (1.3.4)
dmbaturin created T4406: Make an API endpoint for for anonymous host info retrieval (e.g. by a login page).
May 3 2022, 2:39 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling, Restricted Project
dtoux added a comment to T4405: DHCP client sometimes ignores `no-default-route` option of an interface.

Also, these routes getting an administrative distance of 1, which is impossible to override. I believe the default route from DHCP normally has 210 which is manageable. So, the quick workaround could be increasing distance of these routes.

May 3 2022, 2:28 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dtoux added a comment to T4405: DHCP client sometimes ignores `no-default-route` option of an interface.
r24:/home/dtoubelis# cat /var/lib/dhcp/dhclient_eth4.leases
lease {
  interface "eth4";
  fixed-address 100.123.57.53;
  option subnet-mask 255.192.0.0;
  option relay-agent-information 1:4:0:0:4:cf:5:4:64:40:0:1:97:8:1:0:14:ed:0:0:14:ed:98:0;
  option dhcp-lease-time 300;
  option routers 100.64.0.1;
  option dhcp-message-type 5;
  option domain-name-servers 1.1.1.1,8.8.8.8;
  option dhcp-server-identifier 100.64.0.1;
  option interface-mtu 1500;
  option rfc3442-classless-static-routes 32,192,168,100,1,0,0,0,0,32,34,120,255,244,0,0,0,0,0,100,64,0,1;
  renew 2 2022/05/03 12:42:00;
  rebind 2 2022/05/03 12:44:26;
  expire 2 2022/05/03 12:45:04;
}
lease {
  interface "eth4";
  fixed-address 100.123.57.53;
  option subnet-mask 255.192.0.0;
  option relay-agent-information 1:4:0:0:4:cf:5:4:64:40:0:1:97:8:1:0:14:ed:0:0:14:ed:98:0;
  option dhcp-lease-time 300;
  option routers 100.64.0.1;
  option dhcp-message-type 5;
  option domain-name-servers 1.1.1.1,8.8.8.8;
  option dhcp-server-identifier 100.64.0.1;
  option interface-mtu 1500;
  option rfc3442-classless-static-routes 32,192,168,100,1,0,0,0,0,32,34,120,255,244,0,0,0,0,0,100,64,0,1;
  renew 2 2022/05/03 12:46:34;
  rebind 2 2022/05/03 12:48:50;
  expire 2 2022/05/03 12:49:28;
}
lease {
  interface "eth4";
  fixed-address 100.123.57.53;
  option subnet-mask 255.192.0.0;
  option relay-agent-information 1:4:0:0:4:cf:5:4:64:40:0:1:97:8:1:0:14:ed:0:0:14:ed:98:0;
  option dhcp-lease-time 300;
  option routers 100.64.0.1;
  option dhcp-message-type 5;
  option domain-name-servers 1.1.1.1,8.8.8.8;
  option dhcp-server-identifier 100.64.0.1;
  option interface-mtu 1500;
  option rfc3442-classless-static-routes 32,192,168,100,1,0,0,0,0,32,34,120,255,244,0,0,0,0,0,100,64,0,1;
  renew 2 2022/05/03 12:51:33;
  rebind 2 2022/05/03 12:53:25;
  expire 2 2022/05/03 12:54:03;
}
...
}
May 3 2022, 2:22 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4315: Telegraf - Output to prometheus.

Prometheus server pulls information correctly

prometheus.png (1×2 px, 1 MB)

May 3 2022, 9:58 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav closed T4395: Extend show vpn debug as Resolved.
May 3 2022, 7:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4405: DHCP client sometimes ignores `no-default-route` option of an interface.

Could you also provide cat /var/lib/dhcp/dhclient_eth4.leases ?
no-default-route ignore just option routers and don't touch other options like classless-static-routes
https://github.com/vyos/vyos-1x/blob/2c29a3b3b46c7570f4a509f413b208348c0ce647/data/templates/dhcp-client/ipv4.tmpl#L18-L19

May 3 2022, 7:08 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dtoux added a comment to T4405: DHCP client sometimes ignores `no-default-route` option of an interface.

Below is a packet capture from DHCP exchange:


It seems that option 121 has more than one route. Could this be causing the abnormal behavior?

May 3 2022, 4:44 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dtoux created T4405: DHCP client sometimes ignores `no-default-route` option of an interface.
May 3 2022, 4:16 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav changed the status of T4404: Container is not deleted from Open to Needs testing.
May 3 2022, 1:10 AM · VyOS 1.4 Sagitta
Viacheslav created T4404: Container is not deleted.
May 3 2022, 12:14 AM · VyOS 1.4 Sagitta

May 2 2022

Viacheslav added a comment to T4315: Telegraf - Output to prometheus.

PR
https://github.com/vyos/vyos-1x/pull/1310

May 2 2022, 7:40 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po added a comment to T4385: bgp: peer-group member cannot override remote-as of peer-group.

We also need to verify remote-as in v6only or interface definitions:

May 2 2022, 6:20 PM · VyOS 1.4 Sagitta
c-po reopened T4385: bgp: peer-group member cannot override remote-as of peer-group as "In progress".
May 2 2022, 6:19 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4315: Telegraf - Output to prometheus from Open to In progress.
May 2 2022, 12:51 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
wornet-mwo added a comment to T4403: Charon hangs at 100% CPU when many routes are present.

Done some further research about rt_netlink and charon relationship. As described in the docs of Strongswan the option charon.process_route = no helps and is a good workaround if the destination is always reachable over a known specific interface (i think it can be an issue if wan load-balancing etc. is used).

May 2 2022, 12:23 PM · vyos-strongswan
wornet-mwo created T4403: Charon hangs at 100% CPU when many routes are present.
May 2 2022, 10:25 AM · vyos-strongswan
v.huti added a comment to T4394: Improve VYOS_DEBUG profiling support.

There was some effort to introduce profiling into the system before, but nothing was developed.
The ticket was opened to verify that the timing values displayed in /var/log/vyatta are correct.
The vyos-debug flag enables tracing for actions described in the templates.
This will be a step-by-step walkthrough of the system profiling, as I have found this to have a bunch of non-obvious technical nuances that might get you stuck.

May 2 2022, 8:55 AM · VyOS Rolling
c-po committed rVYOSONEX318f81cba207: ipsec: T4353: bugfix template extension.
May 2 2022, 4:33 AM
c-po committed rVYOSONEX1566998a17e7: T2216: file is called container.py.
May 2 2022, 4:26 AM

May 1 2022

c-po committed rVYOSONEXd956fda57f32: accel-ppp: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX5ec208ed9ee0: http: api: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXf38ce741c285: system-logs: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX01bdf2dfdb09: openconnect: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXb6a307424451: igmp-proxy: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX780d4fe16cd8: syslog: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX644a0fe475b1: pppoe: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX4400d11709a8: nhrp: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX1b80aec26798: firewall: zone: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXe3c657e9f4d8: lcd: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX5271cf5bfec2: vrrp: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX9eab0cdd0bbe: firewall: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX59290c857237: system-options: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX0565b602ac8c: router-advert: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX8abb6c0a7473: ids: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX8b0ee4d17279: mdns-repeater: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX49b1afc25b73: ipsec: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX992c84749366: vrf: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX3f657383cdd9: login: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXe0f1e495b81c: flow-accounting: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXc621175631ab: serial-console: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXeafe13ace604: webproxy: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX7c71e956e8e1: telegraf: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po closed T4353: Add Jinja2 linter to vyos-1x build process as Resolved.
May 1 2022, 7:12 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX5ffbd74baee4: snmp: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXf0a13824f39f: lldp: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEX92f266b733a5: tftp-server: T4353: fix Jinja2 linting errors.
May 1 2022, 7:12 PM
c-po committed rVYOSONEXe6af32344b16: container: T4353: fix Jinja2 linting errors.
May 1 2022, 7:11 PM
c-po committed rVYOSONEX827cefbcbfa2: conserver: T4353: fix Jinja2 linting errors.
May 1 2022, 7:11 PM
c-po committed rVYOSONEXa30209ae0be3: conntrackd: T4353: fix Jinja2 linting errors.
May 1 2022, 7:11 PM
c-po committed rVYOSONEX2f507669fd7f: conntrack: T4353: fix Jinja2 linting errors.
May 1 2022, 7:11 PM
c-po committed rVYOSONEX578ce55e5688: bcast-relay: T4353: fix Jinja2 linting errors.
May 1 2022, 7:11 PM
c-po closed T4363: salt-minion: default mine_interval option is not set as Resolved.
May 1 2022, 7:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po moved T4363: salt-minion: default mine_interval option is not set from In Progress to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
May 1 2022, 7:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po committed rVYOSONEX8526c25ef9a8: salt-minion: T4363: mine_interval option is not set.
May 1 2022, 1:06 PM
c-po committed rVYOSONEX07ce7e8639d9: smoketest: salt: T4363: add initial testcase.
May 1 2022, 1:06 PM
GitHub <[email protected]> committed rVYOSONEX2c29a3b3b46c: Merge pull request #1284 from c-po/t4363-salt-equuleus (authored by c-po).
May 1 2022, 1:06 PM