Page MenuHomeVyOS Platform
Feed Search

Dec 15 2022

initramfs claimed T4882: Missing ICMPv6 type names in firewall configuration.

Relevant PR:

Dec 15 2022, 11:31 AM · VyOS 1.4 Sagitta
initramfs created T4882: Missing ICMPv6 type names in firewall configuration.
Dec 15 2022, 11:23 AM · VyOS 1.4 Sagitta
initramfs closed T4671: linux-firmware package is missing symlinks defined in WHENCE file as Resolved.
Dec 15 2022, 11:17 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs added a comment to T4878: Any interface bonding changes cause interface flapping.

@zsdc Yeah I see the bug now, I made the assumption that the config level by default was set to the bond (i.e. interfaces bonding bondX), good catch. Tested in a VM and I can confirm no regression in existing bonding behavior.

Dec 15 2022, 11:03 AM · VyOS 1.4 Sagitta
zsdc changed the status of T4878: Any interface bonding changes cause interface flapping from Confirmed to In progress.

I agree that internal logic can be better, but I think that in this specific case the problem is much simpler: https://github.com/vyos/vyos-1x/pull/1708

Dec 15 2022, 9:50 AM · VyOS 1.4 Sagitta
zsdc changed the status of T4878: Any interface bonding changes cause interface flapping from Open to Confirmed.
Dec 15 2022, 8:57 AM · VyOS 1.4 Sagitta
initramfs added a comment to T4878: Any interface bonding changes cause interface flapping.

I couldn't find an effective way to get all the new members added to the bond via config at commit-time without comparing the members to the running/effective config (the function leaf_node_changed() only gets the removed interfaces). Not doing so either causes runtime commit failures (where the bond fails to add/remove members) or boot failures (where the bond fails to add all it's members on boot).

Dec 15 2022, 8:56 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T2044: RPKI doesn't boot properly: VyOS 1.4 Sagitta.
Dec 15 2022, 8:31 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav updated subscribers of T4856: DHCP-client exit hook for IPsec is incorrect.
Dec 15 2022, 8:28 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4846: L3VPN- network command doesn't install direct connected prefix.

Did you tried no bgp network import-check ?

Dec 15 2022, 7:08 AM · VyOS 1.4 Sagitta

Dec 14 2022

fernando added a comment to T4846: L3VPN- network command doesn't install direct connected prefix.

FRR issues regarding this incorrect behavior ,

Dec 14 2022, 9:28 PM · VyOS 1.4 Sagitta
jestabro renamed T4880: Expose 'add/delete container image' in HTTP-API from Expose 'add/delete containter image' in HTTP-API to Expose 'add/delete container image' in HTTP-API.
Dec 14 2022, 7:50 PM · VyOS 1.4 Sagitta
jestabro closed T4881: Return opmode.Error on openconnect.py show_sessions as Resolved.
Dec 14 2022, 7:46 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4881: Return opmode.Error on openconnect.py show_sessions.

PR: https://github.com/vyos/vyos-1x/pull/1707

Dec 14 2022, 5:51 PM · VyOS 1.4 Sagitta
jestabro triaged T4881: Return opmode.Error on openconnect.py show_sessions as Normal priority.
Dec 14 2022, 5:45 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4879: IPSec migration failed with missing remote-id: VyOS 1.4 Sagitta.

Related task IPsec syntax overhaul T4118

Dec 14 2022, 4:24 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4878: Any interface bonding changes cause interface flapping.
Dec 14 2022, 3:49 PM · VyOS 1.4 Sagitta
Viacheslav updated subscribers of T4878: Any interface bonding changes cause interface flapping.
Dec 14 2022, 3:46 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4878: Any interface bonding changes cause interface flapping.
Dec 14 2022, 3:37 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4878: Any interface bonding changes cause interface flapping.
Dec 14 2022, 3:34 PM · VyOS 1.4 Sagitta
jestabro triaged T4880: Expose 'add/delete container image' in HTTP-API as Normal priority.
Dec 14 2022, 3:33 PM · VyOS 1.4 Sagitta
jestabro closed T4875: Replace Python validator 'interface-name' to avoid Python startup cost, a subtask of T4795: Cleanup custom python validators, as Unknown Status.
Dec 14 2022, 3:09 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro closed T4875: Replace Python validator 'interface-name' to avoid Python startup cost as Unknown Status.
Dec 14 2022, 3:09 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro added a project to T4875: Replace Python validator 'interface-name' to avoid Python startup cost: VyOS 1.3 Equuleus (1.3.3).
Dec 14 2022, 3:09 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro closed T4798: Migrate the file-exists validator away from Python, a subtask of T4795: Cleanup custom python validators, as Unknown Status.
Dec 14 2022, 3:09 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro closed T4798: Migrate the file-exists validator away from Python as Unknown Status.
Dec 14 2022, 3:09 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav created T4878: Any interface bonding changes cause interface flapping.
Dec 14 2022, 2:27 PM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4877: Need verification in using import vrf and import vpn, export vpn commands from Open to In progress.
Dec 14 2022, 1:34 PM · VyOS 1.4 Sagitta
a.apostoliuk claimed T4877: Need verification in using import vrf and import vpn, export vpn commands.
Dec 14 2022, 1:33 PM · VyOS 1.4 Sagitta
a.apostoliuk created T4877: Need verification in using import vrf and import vpn, export vpn commands.
Dec 14 2022, 1:22 PM · VyOS 1.4 Sagitta

Dec 13 2022

Viacheslav changed the status of T4838: Vagrant auth failure on new vagrant images? from Open to In progress.
Dec 13 2022, 10:25 AM

Dec 12 2022

fernando renamed T4876: mpls - LSP broken on FRR 8.4.1 from mpls - lsp broke on FRR 8.4.1 to mpls - LSP broken on FRR 8.4.1.
Dec 12 2022, 11:12 PM · VyOS 1.4 Sagitta
fernando updated the task description for T4876: mpls - LSP broken on FRR 8.4.1.
Dec 12 2022, 9:12 PM · VyOS 1.4 Sagitta
fernando added a parent task for T4876: mpls - LSP broken on FRR 8.4.1: T4846: L3VPN- network command doesn't install direct connected prefix.
Dec 12 2022, 9:07 PM · VyOS 1.4 Sagitta
fernando added a subtask for T4846: L3VPN- network command doesn't install direct connected prefix: T4876: mpls - LSP broken on FRR 8.4.1.
Dec 12 2022, 9:07 PM · VyOS 1.4 Sagitta
fernando created T4876: mpls - LSP broken on FRR 8.4.1.
Dec 12 2022, 9:06 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4795: Cleanup custom python validators: T4875: Replace Python validator 'interface-name' to avoid Python startup cost.
Dec 12 2022, 6:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
jestabro added a parent task for T4875: Replace Python validator 'interface-name' to avoid Python startup cost: T4795: Cleanup custom python validators.
Dec 12 2022, 6:54 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro triaged T4875: Replace Python validator 'interface-name' to avoid Python startup cost as Normal priority.
Dec 12 2022, 6:53 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
zsdc changed Issue type from improvement to bug on T4857: SNMP - Implement FRR SNMP recommendations.
Dec 12 2022, 1:46 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4873: Option to define source IP for rsyslog.

As I understand it is impossible directly with config option but possible with module omudpspoof

Dec 12 2022, 9:16 AM · VyOS 1.4 Sagitta (1.4.2), VyOS 1.5 Circinus, VyOS Rolling
Viacheslav closed T4861: Openconnect restart on adding users - Aborts all active connections as Resolved.
Dec 12 2022, 8:58 AM · VyOS 1.4 Sagitta
klase added a comment to T4861: Openconnect restart on adding users - Aborts all active connections.

It works. The user connections persist over a reload and configuration changes causes a reload instead of a restart!
Thank you.

Dec 12 2022, 7:26 AM · VyOS 1.4 Sagitta

Dec 11 2022

c-po moved T4671: linux-firmware package is missing symlinks defined in WHENCE file from Need Triage to Backlog on the VyOS 1.3 Equuleus (1.3.3) board.
Dec 11 2022, 7:37 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po added a comment to T4792: Add SSTP VPN client.
vyos@vyos# show interfaces sstpc
 sstpc sstpc10 {
     authentication {
         password vyos
         user vyos
     }
     server sstp.vyos.net
     ssl {
         ca-certificate VyOS-CA
     }
 }
Dec 11 2022, 7:29 PM · VyOS 1.4 Sagitta
c-po changed the status of T4792: Add SSTP VPN client from Open to Needs testing.
Dec 11 2022, 7:28 PM · VyOS 1.4 Sagitta

Dec 10 2022

jestabro closed T4872: Op-mode show openvpn misses a case when parsing for tunnel IP, a subtask of T4381: OpenVPN: Add "Tunnel IP" column in "show openvpn server" operational command, as Unknown Status.
Dec 10 2022, 11:13 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro closed T4872: Op-mode show openvpn misses a case when parsing for tunnel IP as Unknown Status.
Dec 10 2022, 11:13 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro updated the task description for T4872: Op-mode show openvpn misses a case when parsing for tunnel IP.
Dec 10 2022, 10:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro updated the task description for T4872: Op-mode show openvpn misses a case when parsing for tunnel IP.
Dec 10 2022, 9:43 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T4873: Option to define source IP for rsyslog.
Dec 10 2022, 12:37 AM · VyOS 1.4 Sagitta (1.4.2), VyOS 1.5 Circinus, VyOS Rolling
Unknown Object (User) created T4873: Option to define source IP for rsyslog.
Dec 10 2022, 12:36 AM · VyOS 1.4 Sagitta (1.4.2), VyOS 1.5 Circinus, VyOS Rolling

Dec 9 2022

jestabro added a comment to T4872: Op-mode show openvpn misses a case when parsing for tunnel IP.

PR:
https://github.com/vyos/vyos-1x/pull/1703

Dec 9 2022, 10:46 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro added a subtask for T4381: OpenVPN: Add "Tunnel IP" column in "show openvpn server" operational command: T4872: Op-mode show openvpn misses a case when parsing for tunnel IP.
Dec 9 2022, 9:23 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro added a parent task for T4872: Op-mode show openvpn misses a case when parsing for tunnel IP: T4381: OpenVPN: Add "Tunnel IP" column in "show openvpn server" operational command.
Dec 9 2022, 9:22 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro changed Version from vyos-1.4, vyos-1.3.3 to vyos-1.4, vyos-1.3.2 on T4872: Op-mode show openvpn misses a case when parsing for tunnel IP.
Dec 9 2022, 9:22 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro triaged T4872: Op-mode show openvpn misses a case when parsing for tunnel IP as Normal priority.
Dec 9 2022, 9:22 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav created T4871: show pki output indentation issues.
Dec 9 2022, 7:30 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav renamed T4870: Containers switch to using overlay driver for podman storage from Switch to using overlay driver for docker storage to Containers switch to using overlay driver for podman storage.
Dec 9 2022, 7:20 PM · VyOS 1.4 Sagitta
tgnthump added a comment to T4870: Containers switch to using overlay driver for podman storage.

Started a PR for this: https://github.com/vyos/vyos-1x/pull/1702

Dec 9 2022, 6:55 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4870: Containers switch to using overlay driver for podman storage: VyOS 1.4 Sagitta.
Dec 9 2022, 6:51 PM · VyOS 1.4 Sagitta
Viacheslav closed T4865: container impossible to generate local image from a file if it requires install some pkgs as Resolved.
Dec 9 2022, 5:16 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4865: container impossible to generate local image from a file if it requires install some pkgs.

PR https://github.com/vyos/vyos-1x/pull/1701

Dec 9 2022, 3:41 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4865: container impossible to generate local image from a file if it requires install some pkgs from Open to In progress.
Dec 9 2022, 1:13 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4861: Openconnect restart on adding users - Aborts all active connections.

@klase It is already in the latest rolling release. Could you re-check?

Dec 9 2022, 12:26 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4867: "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors.
Dec 9 2022, 12:09 PM · VyOS Rolling
Viacheslav added a parent task for T4867: "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Dec 9 2022, 12:09 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4868: L2TP ppp-options ipv6 does not work without ipv6 pool but should.

PR https://github.com/vyos/vyos-1x/pull/1700

Dec 9 2022, 10:17 AM · VyOS 1.4 Sagitta
ssasso added a comment to T4838: Vagrant auth failure on new vagrant images?.

https://github.com/vyos/vyos-vm-images/pull/35

Dec 9 2022, 10:10 AM
Viacheslav renamed T4868: L2TP ppp-options ipv6 does not work without ipv6 pool but should from L2TP ppp-oprions ipv6 does not work without ipv6 pool but should to L2TP ppp-options ipv6 does not work without ipv6 pool but should.
Dec 9 2022, 10:05 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4867: "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors.

This works,
but if this is the new syntax the cli needs some cleanup.

Dec 9 2022, 9:56 AM · VyOS 1.4 Sagitta
Viacheslav claimed T4868: L2TP ppp-options ipv6 does not work without ipv6 pool but should.
Dec 9 2022, 9:51 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4868: L2TP ppp-options ipv6 does not work without ipv6 pool but should from Open to In progress.
Dec 9 2022, 9:51 AM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4868: L2TP ppp-options ipv6 does not work without ipv6 pool but should.
Dec 9 2022, 9:15 AM · VyOS 1.4 Sagitta
Viacheslav created T4868: L2TP ppp-options ipv6 does not work without ipv6 pool but should.
Dec 9 2022, 9:14 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4117: Does not possible to configure PoD/CoA for L2TP vpn from In progress to Needs testing.
Dec 9 2022, 8:51 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
ssasso added a comment to T4838: Vagrant auth failure on new vagrant images?.

According to this https://forum.vyos.io/t/vagrant-auth-failure-on-new-vagrant-images/9871/2
This issue is due to T874.
My understanding is that is not changeable, so my proposal is to add the "vagrant insecure key" for the vyos user during the vagrant box creation.

Dec 9 2022, 8:34 AM
Viacheslav added a comment to T4867: "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors.

use the next syntax

show bgp ipv4 neighbors x.x.x.x advertised-routes
Dec 9 2022, 6:53 AM · VyOS 1.4 Sagitta
Unknown Object (User) created T4867: "show bgp neighbors ... advertised-routes" and some other commands fail for IPv4 neighbors.
Dec 9 2022, 1:17 AM · VyOS 1.4 Sagitta

Dec 8 2022

jestabro renamed T4866: Rewrite show_interfaces to standardized form from Rewrite show_interfaces to standardized format to Rewrite show_interfaces to standardized form.
Dec 8 2022, 7:53 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4866: Rewrite show_interfaces to standardized form.
Dec 8 2022, 7:52 PM · VyOS Rolling
jestabro added a parent task for T4866: Rewrite show_interfaces to standardized form: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Dec 8 2022, 7:52 PM · VyOS 1.4 Sagitta
jestabro triaged T4866: Rewrite show_interfaces to standardized form as Normal priority.
Dec 8 2022, 7:52 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4770: Rewrite OpenVPN op-mode to vyos.opmode format.

PR for show/reset functions:
https://github.com/vyos/vyos-1x/pull/1699

Dec 8 2022, 6:12 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4865: container impossible to generate local image from a file if it requires install some pkgs.
Dec 8 2022, 3:14 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4865: container impossible to generate local image from a file if it requires install some pkgs.
Dec 8 2022, 3:11 PM · VyOS 1.4 Sagitta
Viacheslav created T4865: container impossible to generate local image from a file if it requires install some pkgs.
Dec 8 2022, 3:10 PM · VyOS 1.4 Sagitta
Viacheslav updated subscribers of T4863: need an option for route policy to apply to dynamic interfaces l2tp*/ipoe*/pppoe* (for TCP MSS setting).
Dec 8 2022, 2:52 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4117: Does not possible to configure PoD/CoA for L2TP vpn.

fix for 1.4 PR https://github.com/vyos/vyos-1x/pull/1698

vyos@r14# cat /run/accel-pppd/l2tp.conf | grep dae-s
dae-server=127.0.0.1:1700,testing123
[edit]
vyos@r14#
Dec 8 2022, 1:23 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a project to T4117: Does not possible to configure PoD/CoA for L2TP vpn: VyOS 1.4 Sagitta.
Dec 8 2022, 12:17 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4861: Openconnect restart on adding users - Aborts all active connections from In progress to Needs testing.
Dec 8 2022, 3:53 AM · VyOS 1.4 Sagitta

Dec 7 2022

dcplaya added a comment to T4864: `show firewall` command errors.

I can confirm the firewall errors are fixed in the newest rolling VyOS 1.4-rolling-202212070318

Dec 7 2022, 12:48 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4861: Openconnect restart on adding users - Aborts all active connections.

PR https://github.com/vyos/vyos-1x/pull/1696

Dec 7 2022, 12:41 PM · VyOS 1.4 Sagitta
aserkin added a comment to T4863: need an option for route policy to apply to dynamic interfaces l2tp*/ipoe*/pppoe* (for TCP MSS setting).

Yes they are. 192.168.101.10 - is an ip of vpn remote access subscriber. He's connected to interface l2tp0 (accel-ppp). And i'm just trying to open tcp connection to port 80 on client from peer node.

Dec 7 2022, 11:17 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4863: need an option for route policy to apply to dynamic interfaces l2tp*/ipoe*/pppoe* (for TCP MSS setting).

@aserkin Thanks
Do l2tp clients in the network 192.168.101.x ? And you are trying to connect to some web resource behind l2tp?

Dec 7 2022, 10:58 AM · VyOS 1.4 Sagitta
aserkin added a comment to T4863: need an option for route policy to apply to dynamic interfaces l2tp*/ipoe*/pppoe* (for TCP MSS setting).

The firewall settings does not seem to catch the traffic going out of l2tp* interfaces.

admin@vyos-lns-1:~$ show config commands |grep firewall
set firewall interface l2tp* out name 'nodefw'
set firewall log-martians 'disable'
set firewall name nodefw rule 100 action 'accept'
set firewall name nodefw rule 100 protocol 'tcp'
set firewall name nodefw rule 100 tcp flags syn
set firewall name nodefw rule 100 tcp mss '1300'
Dec 7 2022, 10:44 AM · VyOS 1.4 Sagitta
aserkin added a comment to T4863: need an option for route policy to apply to dynamic interfaces l2tp*/ipoe*/pppoe* (for TCP MSS setting).

Oops. Thank you Nicolas.
Suddenly found myself far behind the current rolling release. Will upgrade first.

Dec 7 2022, 8:39 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4861: Openconnect restart on adding users - Aborts all active connections from Open to In progress.
Dec 7 2022, 8:18 AM · VyOS 1.4 Sagitta
klase added a comment to T4861: Openconnect restart on adding users - Aborts all active connections.

I have made the change in my configuration and tested as many configuration changes as I could (I have not tested radius authentication, and other options that are not valid in my setup) and it seems to work with this change without any unwanted side effects.

Dec 7 2022, 8:03 AM · VyOS 1.4 Sagitta

Dec 6 2022

Viacheslav added a comment to T4837: Expose "show ip route summary" in the op mode API.

@dmbaturin It shows only IPv4 routes
Could you also add IPv6?

Dec 6 2022, 11:51 PM · VyOS 1.4 Sagitta