Page MenuHomeVyOS Platform
Feed Search

Aug 14 2022

dmbaturin edited projects for T4094: Missed conntrack-sync failover-mechanism cluster, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.2).
Aug 14 2022, 6:30 PM · VyOS 1.4 Sagitta
dmbaturin edited projects for T4190: Add commit comment to the configuration API., added: VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.2).
Aug 14 2022, 6:23 PM
dmbaturin edited projects for T4222: Support for TWAMP as round-trip metric, added: VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.2).
Aug 14 2022, 6:21 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
dmbaturin edited projects for T4238: Support for overriding XML properties in the template preprocessor, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.2).
Aug 14 2022, 6:18 PM
dmbaturin changed the status of T4260: Extend vyos.configdict.node_changed() to support recursiveness, a subtask of T4203: Reconfigure DHCP client interface causes brief outages, from Unknown Status to Resolved.
Aug 14 2022, 6:16 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
dmbaturin changed the status of T4260: Extend vyos.configdict.node_changed() to support recursiveness, a subtask of T4235: Add config tree diff algorithm, from Unknown Status to Resolved.
Aug 14 2022, 6:16 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
dmbaturin edited projects for T4291: Consolidate component version read/write functions, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.2).
Aug 14 2022, 6:13 PM · VyOS 1.4 Sagitta
dmbaturin edited projects for T4292: Rewrite vyatta-save-config.pl to Python, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.2).
Aug 14 2022, 6:13 PM · VyOS 1.4 Sagitta
dmbaturin edited projects for T4295: Use config_tree instead of legacy loadFile in vyos-load-config.py, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.2).
Aug 14 2022, 6:13 PM · VyOS 1.4 Sagitta
dmbaturin edited projects for T4316: Update save-config/load-config, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.2).
Aug 14 2022, 6:10 PM · VyOS Rolling
dmbaturin renamed T4572: Add an option to force interface MTU to the value received from DHCP from Add an option to force interface MTU to the value received by DHCP to Add an option to force interface MTU to the value received from DHCP.
Aug 14 2022, 5:42 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
dmbaturin renamed T4572: Add an option to force interface MTU to the value received from DHCP from Remove default values in MTU nodes to Add an option to force interface MTU to the value received by DHCP.
Aug 14 2022, 5:42 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
jagekurt added a comment to T4609: Unable to Restart Container VyOS 1.4.

Great, thanks

Aug 14 2022, 2:49 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4609: Unable to Restart Container VyOS 1.4.

It seems after this commit https://github.com/vyos/vyos-1x/commit/08cb762347208b21a8cbf81f7b35707d7e6dd4ac
I’ll take a look later

Aug 14 2022, 2:40 PM · VyOS 1.4 Sagitta
jagekurt created T4609: Unable to Restart Container VyOS 1.4.
Aug 14 2022, 1:42 PM · VyOS 1.4 Sagitta
syncer edited projects for T3976: Missing prefix-list and access-list option from ipv6 route-map, added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus (1.3.0-epa3).
Aug 14 2022, 1:06 PM

Aug 13 2022

sempervictus added a comment to T4607: Configuration commit fails on kernel 5.15 (and likely others) in libboost's filesystem::copy_file from EXEDEV on the FUSE UnionFS mounts.

Got the PR working:

image.png (1×1 px, 206 KB)

Aug 13 2022, 10:57 PM · VyOS 1.4 Sagitta
sempervictus added a comment to T4607: Configuration commit fails on kernel 5.15 (and likely others) in libboost's filesystem::copy_file from EXEDEV on the FUSE UnionFS mounts.

Using the pull requests filesystem copy, same place, new error:

vyos@vyos-515:~$ cat /var/log/vyatta/*log
cp[/opt/vyatta/config/tmp/new_config_1615]->[/opt/vyatta/config/tmp/tmp_1615/work]
cp w->tw failed[unknown exception]
cp[/opt/vyatta/config/tmp/new_config_2665]->[/opt/vyatta/config/tmp/tmp_2665/work]
cp w->tw failed[unknown exception]
vyos@vyos-515:~$ dpkg -l|grep vyatta-cfg
ii  libvyatta-cfg-dev                    0.102.0+vyos2+current5              amd64        libvyatta-cfg development package
ii  libvyatta-cfg1                       0.102.0+vyos2+current5              amd64        vyatta-cfg back-end library
ii  libvyatta-cfg1-dbgsym                0.102.0+vyos2+current5              amd64        debug symbols for libvyatta-cfg1
ii  vyatta-cfg                           0.102.0+vyos2+current5              amd64        VyOS configuration system
ii  vyatta-cfg-dbgsym                    0.102.0+vyos2+current5              amd64        debug symbols for vyatta-cfg
ii  vyatta-cfg-qos                       0.15.42+vyos2+current1              all          VyOS Qos configuration templates/scripts
ii  vyatta-cfg-system                    0.20.44+vyos2+current22             amd64        VyOS system-level configuration
vyos@vyos-515:~$ uname -r
5.15.59-amd64-vyos-sv
vyos@vyos-515:~$

If Linux maintainers backport the delta causing this to 5.10, it could become a rather pressing concern, but for now merely a show-stopper in terms of moving past 5.10LTS.

Aug 13 2022, 5:38 PM · VyOS 1.4 Sagitta
sempervictus added a comment to T4607: Configuration commit fails on kernel 5.15 (and likely others) in libboost's filesystem::copy_file from EXEDEV on the FUSE UnionFS mounts.

Created a pull request implementing a rudimentary fall-through-on-exception to standard API from the Boost version @ https://github.com/vyos/vyatta-cfg/pull/49
Have not built it yet, nor am i a formal C++ developer (hackers are informal everything developers and rarely formal anything developers), so would appreciate eyes on and sanity checks.
Exception can probably be scoped better to only trip on EXEDEV but i dont see a logical problem with falling-through like this on other errors (is this a bad assumption?).

Aug 13 2022, 3:45 PM · VyOS 1.4 Sagitta
Viacheslav created T4608: IPSec shows only one IKE for the same peer.
Aug 13 2022, 1:03 PM · Bugs, VyOS Rolling
Viacheslav added a comment to T538: Support for network mapping in NAT.

PR https://github.com/vyos/vyos-1x/pull/1466
Let me know if there is what you are expecting,
requires more tests

set nat static rule 10 destination address '10.0.1.1'
set nat static rule 10 inbound-interface 'eth0'
set nat static rule 10 translation address '192.168.1.1'
Aug 13 2022, 12:21 AM · VyOS 1.4 Sagitta

Aug 12 2022

Viacheslav added a comment to T3670: Option to disable HTTP port 80 redirect.

@artooro Did you try listen-port option for this case?

set service https api gql
set service https api keys id KID key 'foo'
set service https api socket
set service https virtual-host foo listen-port '2580'

Check:

vyos@r14# sudo netstat -tulpn | grep nginx
tcp        0      0 0.0.0.0:2580            0.0.0.0:*               LISTEN      3570/nginx: master  
tcp6       0      0 :::2580                 :::*                    LISTEN      3570/nginx: master  
[edit]
vyos@r14#
Aug 12 2022, 7:37 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4122: interface ip address config missing after upgrade from 1.2.8 to 1.3.0 (when redirect is configured?).

@n.fort Create please PR for 1.3

Aug 12 2022, 7:18 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav closed T4603: Need a config option to specify NAS-IP-Address for vpn l2tp as Resolved.
Aug 12 2022, 7:13 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4607: Configuration commit fails on kernel 5.15 (and likely others) in libboost's filesystem::copy_file from EXEDEV on the FUSE UnionFS mounts: VyOS 1.4 Sagitta.
Aug 12 2022, 2:59 PM · VyOS 1.4 Sagitta

Aug 11 2022

jestabro claimed T4597: Check bind port before assign service HTTPS API and openconnect.
Aug 11 2022, 2:19 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4603: Need a config option to specify NAS-IP-Address for vpn l2tp from In progress to Needs testing.

@aserkin Will be present in the next rolling release.

Aug 11 2022, 11:28 AM · VyOS 1.4 Sagitta
Boman created T4606: monitor nat destination translation shows missing script.
Aug 11 2022, 11:17 AM · VyOS 1.4 Sagitta
Viacheslav updated subscribers of T4605: Firewall change default table names.
Aug 11 2022, 10:06 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4605: Firewall change default table names.
Aug 11 2022, 9:48 AM · VyOS 1.4 Sagitta
Viacheslav created T4605: Firewall change default table names.
Aug 11 2022, 9:46 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4470: Rewrite load-balancing wan to XML/Python: T114: Allow wan load-balancing rules to match against groups.
Aug 11 2022, 8:37 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Viacheslav added a parent task for T114: Allow wan load-balancing rules to match against groups: T4470: Rewrite load-balancing wan to XML/Python.
Aug 11 2022, 8:36 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q3), VyOS Rolling
Viacheslav added a comment to T4374: ipv6 address drops from interface, but network still active.

@ajgnet Could you show routes after this bug?

sudo ip -6 route show
sudo ip -6 route get 2607:f8b0:4006:80d::200e
Aug 11 2022, 7:37 AM · VyOS 1.4 Sagitta

Aug 10 2022

Viacheslav closed T4408: Add sshguard to protect against brut-forces as Resolved.
Aug 10 2022, 10:24 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4485: OpenVPN: Allow multiple CAs certificates from In progress to Needs testing.
Aug 10 2022, 10:21 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4595: DPD interval and timeout do not work in DMVPN.

PR https://github.com/vyos/vyos-1x/pull/1465

Aug 10 2022, 10:01 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4603: Need a config option to specify NAS-IP-Address for vpn l2tp.

PR https://github.com/vyos/vyos-1x/pull/1464

Aug 10 2022, 9:07 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4603: Need a config option to specify NAS-IP-Address for vpn l2tp from Open to In progress.
Aug 10 2022, 8:23 PM · VyOS 1.4 Sagitta
m4rcu5 added a comment to T4602: DHCP `ping-check` enabled by default.

I've verified this behavior with 1.4-rolling-202207290217 and 1.4-rolling-202204250217.

Aug 10 2022, 8:19 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4118: IPsec syntax overhaul.

PR https://github.com/vyos/vyos-1x/pull/1463
PR https://github.com/vyos/vyatta-cfg-system/pull/184

Aug 10 2022, 8:08 PM · VyOS 1.4 Sagitta
aserkin added a comment to T4603: Need a config option to specify NAS-IP-Address for vpn l2tp.

Hi Viacheslav
Sorry, i probably misspelled the config option. Actually it's availabe at [radius] section of accel-ppp.conf.
Below is the [radius] section from my /run/accel-pppd/l2tp.conf after i changed
/usr/libexec/vyos/conf_mode/vpn_l2tp.py:

Aug 10 2022, 5:14 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4602: DHCP `ping-check` enabled by default.

What version you are using?

Aug 10 2022, 3:44 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4603: Need a config option to specify NAS-IP-Address for vpn l2tp: VyOS 1.4 Sagitta.
Aug 10 2022, 11:28 AM · VyOS 1.4 Sagitta
ovallaste created T4604: bgpd eats huge amount of memory (about 500Megs a day).
Aug 10 2022, 8:42 AM · VyOS 1.4 Sagitta
ovallaste added a watcher for VyOS 1.4 Sagitta: ovallaste.
Aug 10 2022, 8:17 AM

Aug 9 2022

m4rcu5 added a comment to T4602: DHCP `ping-check` enabled by default.

Allow me to proof the opposite.

Aug 9 2022, 8:23 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4602: DHCP `ping-check` enabled by default.

As remarked and as expected, this option is not enable by default.
Proofs:

  • Fist scenario: no ping-check option introduced in configuration:
Aug 9 2022, 5:05 PM · VyOS 1.4 Sagitta
ajgnet added a comment to T2518: Add support for IPv6 NAT (NPTv6).

@ajgnet If you have a way to limit the dynamic prefix to a known prefix, then using 1:1 NAT66 prefix translation should work (only the host segment is dynamic)

Yes, would be great to fully support dynamic prefix when the prefix is not known

Aug 9 2022, 1:30 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets.

Will be fixed in https://github.com/vyos/vyos-1x/pull/1458

Aug 9 2022, 12:07 PM · VyOS 1.4 Sagitta
n.fort changed the status of T4598: nat66 - Add exclude options, a subtask of T2518: Add support for IPv6 NAT (NPTv6), from In progress to Needs testing.
Aug 9 2022, 10:40 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T4598: nat66 - Add exclude options from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1461

Aug 9 2022, 10:39 AM · VyOS 1.4 Sagitta

Aug 8 2022

Viacheslav added a comment to T4602: DHCP `ping-check` enabled by default.

ping-check shouldn't be allowed by default
To enable it you have to set set service dhcp-server shared-network-name Lan01 ping-check
There is no configuration in generated .conf:

vyos@r14# cat /run/dhcp-server/dhcpd.conf | grep ping
[edit]
vyos@r14#
Aug 8 2022, 8:28 PM · VyOS 1.4 Sagitta
m4rcu5 created T4602: DHCP `ping-check` enabled by default.
Aug 8 2022, 6:37 PM · VyOS 1.4 Sagitta
n.fort added a subtask for T2518: Add support for IPv6 NAT (NPTv6): T4598: nat66 - Add exclude options.
Aug 8 2022, 11:01 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a parent task for T4598: nat66 - Add exclude options: T2518: Add support for IPv6 NAT (NPTv6).
Aug 8 2022, 11:01 AM · VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4537: MACsec not working with cipher gcm-aes-256.

I have tested macsec with gcm-aes-256. It works. (1.4-rolling-202208080217)

Aug 8 2022, 7:53 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4538: Macsec does not work correctly when the interface status changes..

I have tested on 1.4-rolling-202208080217.
The first problem was fixed.
The second problem is not fixed

Aug 8 2022, 7:49 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav closed T4586: Add to NAT66: SNAT destination address and DNAT source address. as Resolved.
Aug 8 2022, 7:31 AM · VyOS 1.4 Sagitta

Aug 7 2022

Unknown Object (User) created T4601: dhcp : relay agent IP address issue..
Aug 7 2022, 10:48 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
RyVolodya added a comment to T4598: nat66 - Add exclude options.

Hello, This functionality for nat66 is described here:
https://phabricator.vyos.net/T4586

Aug 7 2022, 11:12 AM · VyOS 1.4 Sagitta

Aug 6 2022

jack9603301 created T4599: run vyos in lxc/lxd.
Aug 6 2022, 5:57 PM
jack9603301 added a comment to T4598: nat66 - Add exclude options.

hi, you can set this to a subtask of my task

Aug 6 2022, 3:31 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4596: "show openconnect-server sessions" command does not work in the openconnect module.

PR https://github.com/vyos/vyos-1x/pull/1462

Aug 6 2022, 10:18 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4596: "show openconnect-server sessions" command does not work in the openconnect module, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 6 2022, 9:48 AM · VyOS Rolling
Viacheslav changed the status of T4596: "show openconnect-server sessions" command does not work in the openconnect module from Open to In progress.
Aug 6 2022, 9:48 AM · VyOS 1.4 Sagitta

Aug 5 2022

Viacheslav updated subscribers of T4597: Check bind port before assign service HTTPS API and openconnect.
Aug 5 2022, 3:48 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4597: Check bind port before assign service HTTPS API and openconnect.

PR checks if openconnect port is listened by another service https://github.com/vyos/vyos-1x/pull/1460

Aug 5 2022, 3:47 PM · VyOS 1.4 Sagitta
n.fort changed the status of T4598: nat66 - Add exclude options from Open to In progress.
Aug 5 2022, 3:16 PM · VyOS 1.4 Sagitta
n.fort claimed T4598: nat66 - Add exclude options.
Aug 5 2022, 3:15 PM · VyOS 1.4 Sagitta
n.fort created T4598: nat66 - Add exclude options.
Aug 5 2022, 3:15 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4597: Check bind port before assign service HTTPS API and openconnect from Open to In progress.
Aug 5 2022, 2:26 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4589: BGP listen limit Increase via CLI command.

It is already present in 1.4

vyos@r14:~$ show conf com | match bgp
set protocols bgp listen limit '1000'
set protocols bgp listen range 192.0.2.0/24 peer-group 'FOO'
set protocols bgp local-as '65001'
set protocols bgp peer-group FOO remote-as '65001'
Aug 5 2022, 12:39 PM · VyOS 1.4 Sagitta (1.4.0-GA)
zsdc changed the status of T4589: BGP listen limit Increase via CLI command from Open to Confirmed.
Aug 5 2022, 12:16 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav created T4597: Check bind port before assign service HTTPS API and openconnect.
Aug 5 2022, 11:40 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4596: "show openconnect-server sessions" command does not work in the openconnect module.
Aug 5 2022, 10:43 AM · VyOS Rolling
Viacheslav added a parent task for T4596: "show openconnect-server sessions" command does not work in the openconnect module: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Aug 5 2022, 10:43 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4596: "show openconnect-server sessions" command does not work in the openconnect module.

It appeared after this commit
It doesn't like this check https://github.com/vyos/vyos-1x/blob/2a10ffa4b5074be27458159fa94d6227d0e5c7f7/src/op_mode/openconnect-control.py#L63-L65
Check root user https://github.com/vyos/vyos-1x/blob/2a10ffa4b5074be27458159fa94d6227d0e5c7f7/python/vyos/util.py#L625-L626

Aug 5 2022, 10:04 AM · VyOS 1.4 Sagitta
a.apostoliuk created T4596: "show openconnect-server sessions" command does not work in the openconnect module.
Aug 5 2022, 8:14 AM · VyOS 1.4 Sagitta
a.apostoliuk created T4595: DPD interval and timeout do not work in DMVPN.
Aug 5 2022, 7:21 AM · VyOS 1.4 Sagitta

Aug 4 2022

HON added a comment to T2408: DHCP Relay upstream and downstream interfaces.

Would it be an option to instead just add new listen-interface and upstream-interface statements, same as for dhcp-relay6? Then keep interface completely unchanged to avoid breaking weird usages, but add some deprecation notice to the CLI.

Aug 4 2022, 8:27 PM · VyOS 1.4 Sagitta
n.fort added a comment to T2408: DHCP Relay upstream and downstream interfaces.

Currently thinking on how to implement this.
One option could be:

Aug 4 2022, 8:11 PM · VyOS 1.4 Sagitta
n.fort added a project to T2408: DHCP Relay upstream and downstream interfaces: VyOS 1.4 Sagitta.
Aug 4 2022, 7:59 PM · VyOS 1.4 Sagitta
c-po closed T4257: Discussion on changing BGP autonomous system number syntax as Resolved.
Aug 4 2022, 7:27 PM · VyOS 1.4 Sagitta
Nova_Logic renamed T4587: wan load balance issues with 3 or more WANs from wan load balance issues with 3 WANs to wan load balance issues with 3 or more WANs.
Aug 4 2022, 6:55 PM · Bugs, VyOS Rolling
jack9603301 added a comment to T2898: Support NDP proxy.

@hensur You haven't dealt with this for a long time

Aug 4 2022, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4572: Add an option to force interface MTU to the value received from DHCP from Confirmed to Needs testing.
Aug 4 2022, 3:11 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav changed the status of T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS Rolling
Viacheslav changed the status of T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4594: Rewrite op-mode IPsec to vyos.opmode format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS Rolling
Viacheslav changed the status of T4594: Rewrite op-mode IPsec to vyos.opmode format from Open to In progress.
Aug 4 2022, 1:54 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4586: Add to NAT66: SNAT destination address and DNAT source address. from Open to Needs testing.
Aug 4 2022, 1:50 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4594: Rewrite op-mode IPsec to vyos.opmode format.

PR https://github.com/vyos/vyos-1x/pull/1458
Formatted output

vyos@r14:~$ show vpn ipsec sa
Connection                 State    Uptime    Bytes In/Out    Packets In/Out    Remote address    Remote ID    Proposal
-------------------------  -------  --------  --------------  ----------------  ----------------  -----------  ---------------------------------------
peer_2001-db8--2_tunnel_0  up       9m15s     0B/0B           0/0               2001:db8::2       2001:db8::2  AES_CBC_256/HMAC_SHA2_256_128/MODP_2048
peer_2001-db8--2_tunnel_0  up       24m9s     0B/0B           0/0               2001:db8::2       2001:db8::2  AES_CBC_256/HMAC_SHA2_256_128/MODP_2048
vyos@r14:~$
Aug 4 2022, 1:18 PM · VyOS 1.4 Sagitta
Viacheslav created T4594: Rewrite op-mode IPsec to vyos.opmode format.
Aug 4 2022, 10:11 AM · VyOS 1.4 Sagitta
ssasso added a comment to T4593: Upgrade strongswan to 5.9.8.

From the strongswan 5.9.6 changelog:

Actively initiating duplicate CHILD_SAs within the same IKE_SA is now largely prevented. This can happen if trap policies are installed and an IKE_SA with its CHILD_SAs is reestablished (e.g. with break-before-make reauthentication or dpd_action=restart). This does not prevent duplicates if they are initiated by the two peers concurrently.
Aug 4 2022, 7:15 AM · VyOS 1.4 Sagitta
ssasso updated the task description for T4593: Upgrade strongswan to 5.9.8.
Aug 4 2022, 7:12 AM · VyOS 1.4 Sagitta
ssasso created T4593: Upgrade strongswan to 5.9.8.
Aug 4 2022, 7:10 AM · VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.204 / 5.10.129 to Update Linux Kernel to v5.4.208 / 5.10.135.
Aug 4 2022, 6:34 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4592: macsec: can not create two interfaces using the same source-interface from Need Triage to In Progress on the VyOS 1.3 Equuleus (1.3.2) board.
Aug 4 2022, 6:30 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4592: macsec: can not create two interfaces using the same source-interface from Open to Finished on the VyOS 1.4 Sagitta board.
Aug 4 2022, 6:30 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta