Page MenuHomeVyOS Platform
Feed Search

May 16 2024

natali-rs1985 changed the status of T6348: SNAT op-mode fails with flowtable offload entries from Open to In progress.
May 16 2024, 11:09 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav triaged T6350: CGNAT add op-mode to get current port allocation mapping as Wishlist priority.
May 16 2024, 10:38 AM · VyOS 1.5 Circinus
Viacheslav created T6350: CGNAT add op-mode to get current port allocation mapping.
May 16 2024, 10:38 AM · VyOS 1.5 Circinus
Viacheslav updated the task description for T6348: SNAT op-mode fails with flowtable offload entries.
May 16 2024, 10:20 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav triaged T6348: SNAT op-mode fails with flowtable offload entries as Normal priority.
May 16 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav updated the task description for T6348: SNAT op-mode fails with flowtable offload entries.
May 16 2024, 10:17 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav created T6348: SNAT op-mode fails with flowtable offload entries.
May 16 2024, 10:16 AM · Restricted Project, VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a subtask for T5169: Add CGNAT Carrier-Grade NAT based on nftables: T6347: CGNAT external pools containing dashes cause Traceback error.
May 16 2024, 9:38 AM · VyOS Rolling, VyOS 1.5 Circinus
Viacheslav added a parent task for T6347: CGNAT external pools containing dashes cause Traceback error: T5169: Add CGNAT Carrier-Grade NAT based on nftables.
May 16 2024, 9:38 AM · VyOS 1.5 Circinus
Viacheslav triaged T6347: CGNAT external pools containing dashes cause Traceback error as Normal priority.
May 16 2024, 9:37 AM · VyOS 1.5 Circinus
Viacheslav created T6347: CGNAT external pools containing dashes cause Traceback error.
May 16 2024, 9:37 AM · VyOS 1.5 Circinus
Viacheslav changed the status of T6058: Commit-Archive Save doesn't use https_proxy from Needs reporter action to Open.
May 16 2024, 7:55 AM · VyOS Rolling, Bugs
modzilla99 added a comment to T6058: Commit-Archive Save doesn't use https_proxy.

sorry for the late reply.You don't need any special commands. The only thing you have to set is the proxy and the commit archive.

May 16 2024, 7:42 AM · VyOS Rolling, Bugs
c-po closed T6333: non-free-firmware to trixie as Resolved.
May 16 2024, 5:26 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po moved T6333: non-free-firmware to trixie from Open to Finished on the VyOS 1.5 Circinus board.
May 16 2024, 5:26 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po moved T6333: non-free-firmware to trixie from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0) board.
May 16 2024, 5:26 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po added a project to T6333: non-free-firmware to trixie: VyOS 1.4 Sagitta (1.4.0).
May 16 2024, 5:26 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po added a comment to T6346: Boot to multi-user.target instead of graphical.target.

https://github.com/vyos/vyos-build/pull/624

May 16 2024, 5:24 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po updated the task description for T6346: Boot to multi-user.target instead of graphical.target.
May 16 2024, 5:23 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po claimed T6346: Boot to multi-user.target instead of graphical.target.
May 16 2024, 5:22 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
c-po created T6346: Boot to multi-user.target instead of graphical.target.
May 16 2024, 5:22 AM · VyOS 1.4 Sagitta (1.4.0), VyOS 1.5 Circinus
zsdc moved T6038: Losing default route after first reboot (cloud-init & DHCP) from Need Triage to In Progress on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 16 2024, 12:30 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
zsdc changed the status of T6038: Losing default route after first reboot (cloud-init & DHCP), a subtask of T5907: cloud-init root task for 1.5 and 1.4 , from Open to Needs testing.
May 16 2024, 12:30 AM · VyOS Rolling
zsdc changed the status of T6038: Losing default route after first reboot (cloud-init & DHCP) from Open to Needs testing.

@thannaske it would be very nice if you could re-check now this with VyOS 1.5. It should be fixed by https://github.com/vyos/vyos-cloud-init/commit/70304ff90d931265cb736ace692967242c9b9729

May 16 2024, 12:30 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

May 15 2024

syncer closed T4909: Rewrite the NTP op mode in the new format as Resolved.
May 15 2024, 7:21 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
syncer closed T4909: Rewrite the NTP op mode in the new format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
May 15 2024, 7:21 PM · VyOS Rolling
syncer added a project to T4909: Rewrite the NTP op mode in the new format: VyOS 1.5 Circinus.
May 15 2024, 7:21 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
L0crian added a comment to T6335: Add/update EVPN op commands.

PR: https://github.com/vyos/vyos-1x/pull/3458

May 15 2024, 7:08 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
jestabro changed the status of T3876: Replace vyos-netplug with a VyOS link state monitor service from In progress to On hold.

This was a worthwhile investigation, with the goal of using Cython as a method of easily wrapping the standard netlink headers. Although workable, it appeared more trouble than it's worth, as one still has to cheat to navigate e.g. pass by reference (1), and limitations of Cython at the time (2). A much better approach would be a standard Python extension module ... set to 'on hold' for reference and until we have a plan for development, as has been recently discussed.

May 15 2024, 5:33 PM · VyOS 1.5 Circinus
rob created T6342: Extend xml definitions with 'docs' information.
May 15 2024, 2:27 PM · VyOS Rolling
rob created T6341: Implement documention output for commands on the CLI.
May 15 2024, 2:20 PM · VyOS Rolling
evgbondarenko closed T6340: Test task as Not Applicable.
May 15 2024, 2:12 PM · VyOS 1.5 Circinus
evgbondarenko claimed T6340: Test task.
May 15 2024, 2:11 PM · VyOS 1.5 Circinus
Unknown Object (User) created T6340: Test task.
May 15 2024, 2:02 PM · VyOS 1.5 Circinus
natali-rs1985 claimed T5487: OPENVPN -DEPRECATED OPTION: --cipher.
May 15 2024, 12:31 PM · VyOS 1.5 Circinus, Restricted Project
dmbaturin renamed T6339: Display the flavor name and build comment in "show version" from Display the flavor name in "show version" to Display the flavor name and build comment in "show version".
May 15 2024, 12:28 PM · VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin created T6339: Display the flavor name and build comment in "show version".
May 15 2024, 11:52 AM · VyOS 1.4 Sagitta (1.4.0-GA)
masterit added a comment to T5647: Extend failover route functionality to use dynamically assigned interface next hops.

Is there any movement on implementing this? As per T2760 this is the only way to resolve IPsec on dynamic ip's

May 15 2024, 11:46 AM · VyOS Rolling
syncer moved T5566: Disable 802.3az/EEE (energy efficient ethernet) from Finished to Open on the VyOS 1.5 Circinus board.
May 15 2024, 10:28 AM
syncer placed T5566: Disable 802.3az/EEE (energy efficient ethernet) up for grabs.
May 15 2024, 10:28 AM
syncer reopened T5566: Disable 802.3az/EEE (energy efficient ethernet) as "Open".
May 15 2024, 10:28 AM
syncer moved T5900: Improve reliability of the vyos powerdns recursor implementation from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
May 15 2024, 10:14 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
Viacheslav moved T5900: Improve reliability of the vyos powerdns recursor implementation from Open to Finished on the VyOS 1.5 Circinus board.
May 15 2024, 10:14 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
syncer edited projects for T5900: Improve reliability of the vyos powerdns recursor implementation, added: VyOS 1.4 Sagitta (1.4.0-epa3); removed VyOS 1.4 Sagitta.
May 15 2024, 10:14 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
Viacheslav closed T5900: Improve reliability of the vyos powerdns recursor implementation as Resolved.
May 15 2024, 10:14 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
syncer moved T5566: Disable 802.3az/EEE (energy efficient ethernet) from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-epa3) board.
May 15 2024, 10:02 AM
syncer changed the status of T5566: Disable 802.3az/EEE (energy efficient ethernet) from Unknown Status to Resolved.
May 15 2024, 10:02 AM
syncer moved T6335: Add/update EVPN op commands from Open to 1.4.0-GA on the VyOS 1.4 Sagitta board.
May 15 2024, 9:33 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
syncer edited projects for T2004: BGP FQDN capability not sending domain name, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 15 2024, 9:32 AM · VyOS 1.4 Sagitta (1.4.0), Bugs
syncer edited projects for T2207: IPv6 route install failed, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 15 2024, 9:31 AM
syncer edited projects for T2287: LLDP not working on X710 adapter, i40e driver, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 15 2024, 9:31 AM · VyOS 1.4 Sagitta (1.4.0), VyOS Rolling, VyOS 1.5 Circinus
syncer edited projects for T2840: "startup-beep" beeps too early, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 15 2024, 9:31 AM · VyOS Rolling
syncer edited projects for T3529: vyos.frr class has no support for multi-line modify_section, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 15 2024, 9:31 AM
syncer edited projects for T5892: container network interface and policy fails to apply after reboot, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 15 2024, 9:31 AM · VyOS Rolling, Bugs
syncer edited projects for T6058: Commit-Archive Save doesn't use https_proxy, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 15 2024, 9:30 AM · VyOS Rolling, Bugs
syncer edited projects for T2468: Passwords with special characters fail in commit-archive, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 15 2024, 9:30 AM · VyOS Rolling, Bugs
syncer edited projects for T6101: IPsec some proposal combinations could be invalid and the service strongswan stops, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 15 2024, 9:30 AM · VyOS 1.5 Circinus, VyOS Rolling
syncer edited projects for T6097: vrf_zones blocking ipv6 traffic, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 15 2024, 9:30 AM · VyOS 1.4 Sagitta (1.4.4), VyOS Rolling, VyOS 1.5 Circinus
syncer edited projects for T6122: Protocols under VRF config run in a single pass against their conf_mode scripts, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0-epa1).
May 15 2024, 9:30 AM · VyOS Rolling
syncer moved T5069: bgp large-community-list regex validation incomplete from 1.4.0-epa3 to 1.4.0-GA on the VyOS 1.4 Sagitta board.
May 15 2024, 9:30 AM · VyOS 1.4 Sagitta (1.4.4), VyOS 1.5 Circinus (1.5-stream-2025-Q3), VyOS Rolling
syncer moved T5487: OPENVPN -DEPRECATED OPTION: --cipher from 1.4.0-epa3 to 1.4.0-GA on the VyOS 1.4 Sagitta board.
May 15 2024, 9:30 AM · VyOS 1.5 Circinus, Restricted Project
syncer moved T5752: Check compatibility of new image tools with XCP-NG images from 1.4.0-epa3 to 1.4.0-GA on the VyOS 1.4 Sagitta board.
May 15 2024, 9:30 AM · VyOS 1.4 Sagitta (1.4.0-GA)
syncer moved T6300: [1.3->1.4 Migration] An empty interface configuration drops all interfaces configuration from 1.4.0-epa3 to 1.4.0-GA on the VyOS 1.4 Sagitta board.
May 15 2024, 9:29 AM · Bugs, VyOS 1.4 Sagitta (1.4.1)
syncer moved T6301: DHCPv6 client address causes long commits from 1.4.0-epa3 to 1.4.0-GA on the VyOS 1.4 Sagitta board.
May 15 2024, 9:29 AM · Bugs, VyOS Rolling
syncer moved T6038: Losing default route after first reboot (cloud-init & DHCP) from 1.4.0-epa3 to 1.4.0-GA on the VyOS 1.4 Sagitta board.
May 15 2024, 9:29 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
syncer moved T6290: SNMPD show logs systemstats_linux: unexpected header length from 1.4.0-epa3 to 1.4.0-GA on the VyOS 1.4 Sagitta board.
May 15 2024, 9:29 AM · VyOS Rolling, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
syncer moved T6320: WiFi: Enable support for 6GHz AccesPoints from 1.4.0 to 1.4.0-GA on the VyOS 1.4 Sagitta board.
May 15 2024, 9:29 AM · VyOS Rolling, VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
Viacheslav triaged T6338: Ability to use per-user traffic shaper or policy limits based on the network as Wishlist priority.
May 15 2024, 8:01 AM · VyOS Rolling
Viacheslav created T6338: Ability to use per-user traffic shaper or policy limits based on the network.
May 15 2024, 8:00 AM · VyOS Rolling

May 14 2024

florin closed T6334: [Feature] Support unsigned vyos mirrors for builds as Not Applicable.

seems rather useless now :)

May 14 2024, 7:43 PM
florin added a comment to T6334: [Feature] Support unsigned vyos mirrors for builds.

I'm just using this for my home lab :) - that's a great suggestion @Rain I shall use that!

May 14 2024, 7:28 PM
Rain added a comment to T6334: [Feature] Support unsigned vyos mirrors for builds.

Since the --vyos-mirror string is copied directly, you can simply prepend it with [trusted=yes]; a new flag isn't really necessary:

May 14 2024, 7:18 PM
c-po added a project to T6290: SNMPD show logs systemstats_linux: unexpected header length: VyOS 1.4 Sagitta (1.4.0-epa3).
May 14 2024, 5:26 PM · VyOS Rolling, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
c-po edited a custom field on T6290: SNMPD show logs systemstats_linux: unexpected header length.
May 14 2024, 5:26 PM · VyOS Rolling, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
c-po added a comment to T6290: SNMPD show logs systemstats_linux: unexpected header length.

https://github.com/net-snmp/net-snmp/issues/786

May 14 2024, 5:26 PM · VyOS Rolling, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1)
syncer closed T3420: Support UPNP protocol as Invalid.

Implementation never worked

May 14 2024, 4:58 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

If you are really that curious, I can attach a screenshot.

May 14 2024, 4:04 PM
dylanneild added a comment to T5835: UPnP port mapping / rule installation fails.

If someone wants, I can probably unearth my patches to 1.4 and miniupnpd to make it all work. It was technically functional and worked as expected. I just don't have the time or patience to deal with getting it merged/integrated back into the project.

May 14 2024, 3:59 PM
dmbaturin added a comment to T5835: UPnP port mapping / rule installation fails.

Out of curiosity, will the details of the poll be public or the results being shared transparently?

May 14 2024, 3:48 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

A bunch to unpack here.
[...]

May 14 2024, 3:41 PM
L0crian updated the task description for T6335: Add/update EVPN op commands.
May 14 2024, 3:36 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

Created a poll for maintainers on this topic, and we will go with the decision made.

May 14 2024, 3:36 PM
dylanneild added a comment to T5835: UPnP port mapping / rule installation fails.

A bunch to unpack here.

May 14 2024, 3:33 PM
L0crian renamed T6335: Add/update EVPN op commands from Add/updateEVPN op commands to Add/update EVPN op commands.
May 14 2024, 2:57 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

go learn how cheap cameras open firewalls via UPnP and make them available on the internet without people being aware of that

or how malware exfiltrates data via port 443 because enterprises can't reliably block outbound traffic on that port.

May 14 2024, 2:48 PM
L0crian created T6335: Add/update EVPN op commands.
May 14 2024, 2:42 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

If you know how to test it will be great to test it. If no one needs it even for tests, what are we talking about?

May 14 2024, 2:29 PM
syncer added a comment to T5835: UPnP port mapping / rule installation fails.

Created a poll for maintainers on this topic, and we will go with the decision made.

May 14 2024, 2:27 PM
syncer added a comment to T5835: UPnP port mapping / rule installation fails.
In T5835#187936, @simplysoft wrote:

Yes, that is exactly the point. Glad you did not suggest to remove the NAT capability of vyos because it could be used to bypass security or is not appropriate for an "enterprise"

May 14 2024, 2:24 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.
In T5835#187933, @simplysoft wrote:

A firewall is doing exactly this all the time when using NAT, autonomously opening ports via call from internal networks (aka internal originated traffic) to allow responses to reach the originator. Enterprises might have some strict outbound rules. For UPnP is exactly the same, an enterprise would have strict rules which services are allowed to open ports.

Not if it's not configured to do so.

May 14 2024, 2:20 PM
Viacheslav added a comment to T5835: UPnP port mapping / rule installation fails.
In T5835#187933, @simplysoft wrote:

I'm not sure if that summary from you @Viacheslav is fully reflecting the current state.
I'm also not sure if the original implementation never worked, might very well have been broken while refactoring some vyos internals how the firewall is structured, but I guess you should have a better understanding of (the history of) your product. Otherwise I would be very surprised if a broken feature got into your product without every working / being tested.

May 14 2024, 2:18 PM
syncer added a comment to T5835: UPnP port mapping / rule installation fails.
In T5835#187933, @simplysoft wrote:

A firewall is doing exactly this all the time when using NAT, autonomously opening ports via call from internal networks (aka internal originated traffic) to allow responses to reach the originator. Enterprises might have some strict outbound rules. For UPnP is exactly the same, an enterprise would have strict rules which services are allowed to open ports.

Not if it's not configured to do so.

May 14 2024, 2:07 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

I'm not sure if that summary from you @Viacheslav is fully reflecting the current state.
I'm also not sure if the original implementation never worked, might very well have been broken while refactoring some vyos internals how the firewall is structured, but I guess you should have a better understanding of (the history of) your product. Otherwise I would be very surprised if a broken feature got into your product without every working / being tested.

May 14 2024, 2:03 PM
syncer added a comment to T5835: UPnP port mapping / rule installation fails.

I fail to comprehend how a firewall that autonomously opens ports via calls from internal networks is appropriate for an enterprise.
Indeed there are some use cases but this functionality can be used by malicious code and allow bypass security configuration that is enforced otherwise

May 14 2024, 1:13 PM
Viacheslav added a comment to T5835: UPnP port mapping / rule installation fails.

In summary, it works with custom scripts and patches, but it still does not work from CLI (not fully integrated)
The scripts that should be involved are in the repo https://github.com/miniupnp/miniupnp/tree/miniupnpd_2_3_3/miniupnpd/netfilter_nft/scripts
Until we do not have them and they do not communicate with the firewall, the feature does not work.
A patch is attached in several posts above https://vyos.dev/T5835#174066

May 14 2024, 12:40 PM
n.fort changed the status of T3900: Add support for raw tables to firewall from Open to In progress.
May 14 2024, 12:31 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2)
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

Does it work now?

May 14 2024, 11:04 AM
syncer added a comment to T5835: UPnP port mapping / rule installation fails.

Does it work now?

May 14 2024, 10:43 AM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

One reasons it is rarely seen is as most are not aware of it being used undercover and when not being present, nothing necessarily brakes (due to fallback to other mechanisms). For some home routers we saw this was an undocumented "feature" that you did not have any control over, more recent & reasonable implementation we have seen allow you to enable or disable it (but nothing much more like fine grained permissions)

May 14 2024, 10:36 AM
Apachez added a comment to T5835: UPnP port mapping / rule installation fails.

I have rarely seen UPnP in enterprise environments and rarely at home even if the main purpose is to use it at home and let applications backdoor your firewall (which often is a bad thing in enterprise evironments).

May 14 2024, 10:23 AM