Page MenuHomeVyOS Platform
Feed Search

Jun 2 2024

syncer merged T140: commit archive to git into T2405: commit archive to GIT.
Jun 2 2024, 1:58 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
syncer placed T140: commit archive to git up for grabs.
Jun 2 2024, 1:56 PM · VyOS 1.5 Circinus
syncer reopened T140: commit archive to git, a subtask of T139: Commit archive backends, as Open.
Jun 2 2024, 1:55 PM · VyOS Rolling
syncer reopened T140: commit archive to git as "Open".
Jun 2 2024, 1:55 PM · VyOS 1.5 Circinus
syncer updated the task description for T139: Commit archive backends.
Jun 2 2024, 1:54 PM · VyOS Rolling
syncer lowered the priority of T28: Add auto provisioning from Normal to Wishlist.
Jun 2 2024, 1:50 PM · Bugs, VyOS Rolling
syncer placed T28: Add auto provisioning up for grabs.
Jun 2 2024, 1:50 PM · Bugs, VyOS Rolling
L0crian added a comment to T6338: Ability to use per-user traffic shaper or policy limits based on the network.

NFT rate-limiting is effectively a policer instead of a shaper, so I don't think it'd be a good way to accomplish this. All drops would be aggressive and not tail-drops.

Jun 2 2024, 1:41 PM · VyOS Rolling
syncer triaged T6434: Support additional health check protocols in reverse-proxy as Normal priority.
Jun 2 2024, 1:38 PM · VyOS 1.5 Circinus
syncer moved T6434: Support additional health check protocols in reverse-proxy from Open to Backlog on the VyOS 1.5 Circinus board.
Jun 2 2024, 1:37 PM · VyOS 1.5 Circinus
Embezzle changed the status of T6434: Support additional health check protocols in reverse-proxy from Open to In progress.
Jun 2 2024, 12:29 PM · VyOS 1.5 Circinus
Embezzle created T6434: Support additional health check protocols in reverse-proxy.
Jun 2 2024, 12:28 PM · VyOS 1.5 Circinus
Apachez added a comment to T6433: Allow custom packages survive upgrades.

Also the config section could perhaps be name "custom" (with subsections) so that section will survive an upgrade aswell - otherwise config lines will vanish during boot/commit.

Jun 2 2024, 12:17 PM · Restricted Project, VyOS Rolling
syncer triaged T6433: Allow custom packages survive upgrades as Wishlist priority.
Jun 2 2024, 9:00 AM · Restricted Project, VyOS Rolling
syncer created T6433: Allow custom packages survive upgrades.
Jun 2 2024, 8:48 AM · Restricted Project, VyOS Rolling

Jun 1 2024

Viacheslav closed T6418: reverse-proxy: backend http-check CLI option not honored as Invalid.

Duplicate

Jun 1 2024, 1:05 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav triaged T6423: Require command definition nodes that have an owner to also have a priority as Wishlist priority.
Jun 1 2024, 1:03 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav changed the status of T6422: Ability to configure multiple NS records in the authoritative DNS server configuration from Open to Needs testing.
Jun 1 2024, 1:03 PM · Restricted Project, VyOS Rolling
talmakion added a comment to T6401: Attempts to delete vlan-to-vni option causes an unhandled exception.

On testing, it looks like vyos.utils.network.get_vxlan_vni_filter() doesn't know how to handle when there are no vni filters installed.

Jun 1 2024, 12:39 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav moved T6409: Remove unused parameter node from reverse-proxy backend from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
Jun 1 2024, 11:21 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a project to T6409: Remove unused parameter node from reverse-proxy backend: VyOS 1.4 Sagitta (1.4.0-GA).
Jun 1 2024, 11:21 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav triaged T6430: Allow larger table ids in policy route as Normal priority.
Jun 1 2024, 11:21 AM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Viacheslav triaged T6431: monitor traceroute broken VRF support as Normal priority.
Jun 1 2024, 11:16 AM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav changed the status of T6403: nat64 input validation required from Open to In progress.
Jun 1 2024, 11:15 AM · VyOS 1.5 Circinus
talmakion added a comment to T6403: nat64 input validation required.

I've created a quick PR to give sane feedback from the validator: https://github.com/vyos/vyos-1x/pull/3572

Jun 1 2024, 10:56 AM · VyOS 1.5 Circinus

May 31 2024

bernhardschmidt created T6431: monitor traceroute broken VRF support.
May 31 2024, 8:48 PM · VyOS 1.4 Sagitta (1.4.1)
fernando changed the status of T6429: bug - isis metric-style not applied configuration from Open to In progress.
May 31 2024, 7:53 PM · VyOS 1.4 Sagitta (1.4.1)
fernando added a comment to T6429: bug - isis metric-style not applied configuration.

PR : https://github.com/vyos/vyos-1x/pull/3571

May 31 2024, 7:53 PM · VyOS 1.4 Sagitta (1.4.1)
bernhardschmidt updated the task description for T6430: Allow larger table ids in policy route.
May 31 2024, 7:39 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
bernhardschmidt created T6430: Allow larger table ids in policy route.
May 31 2024, 7:27 PM · VyOS 1.5 Circinus (1.5-stream-2025-Q2), VyOS Rolling
Embezzle closed T6409: Remove unused parameter node from reverse-proxy backend as Resolved.

Tested as working in: VyOS 1.5-rolling-202405310019

May 31 2024, 5:00 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
fernando claimed T6429: bug - isis metric-style not applied configuration.
May 31 2024, 4:12 PM · VyOS 1.4 Sagitta (1.4.1)
fernando created T6429: bug - isis metric-style not applied configuration.
May 31 2024, 4:12 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav changed the status of T6157: Can not create two GRE tunnels to the same DST but from different SRC addresses from Open to In progress.
May 31 2024, 12:37 PM · Bugs, VyOS 1.4 Sagitta (1.4.1)
fernando changed the status of T5307: QoS - traffic-class-map services from In progress to Needs testing.
May 31 2024, 12:36 PM · VyOS 1.5 Circinus
talmakion added a comment to T6157: Can not create two GRE tunnels to the same DST but from different SRC addresses.

I've created a PR for this that fixed a mistake with my original patch: https://github.com/vyos/vyos-1x/pull/3570

May 31 2024, 11:58 AM · Bugs, VyOS 1.4 Sagitta (1.4.1)
pavel-altair reopened T6407: ipsec profile generation error as "Open".
May 31 2024, 11:49 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
pavel-altair added a comment to T6407: ipsec profile generation error.

In https://github.com/vyos/vyos-rolling-nightly-builds/releases/tag/1.5-rolling-202405301617 wrote

May 31 2024, 11:48 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
natali-rs1985 changed the status of T6423: Require command definition nodes that have an owner to also have a priority from Open to In progress.
May 31 2024, 11:11 AM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav triaged T6425: WiFi: Beamformer support for 802.11ac (VHT at 5GHz) is broken as Normal priority.
May 31 2024, 9:21 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po assigned T6396: MINOR Typo: set system conntrack timeout custom ipv4 rule X to Giggum.
May 31 2024, 4:17 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

May 30 2024

alainlamar updated the task description for T6425: WiFi: Beamformer support for 802.11ac (VHT at 5GHz) is broken.
May 30 2024, 7:56 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
alainlamar updated the task description for T6425: WiFi: Beamformer support for 802.11ac (VHT at 5GHz) is broken.
May 30 2024, 7:55 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
alainlamar edited projects for T6425: WiFi: Beamformer support for 802.11ac (VHT at 5GHz) is broken, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta (1.4.0).
May 30 2024, 7:47 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
alainlamar edited projects for T6425: WiFi: Beamformer support for 802.11ac (VHT at 5GHz) is broken, added: VyOS 1.4 Sagitta (1.4.0); removed VyOS 1.4 Sagitta (1.4.0-epa3).
May 30 2024, 7:46 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
alainlamar added a project to T6425: WiFi: Beamformer support for 802.11ac (VHT at 5GHz) is broken: VyOS 1.4 Sagitta (1.4.0-epa3).
May 30 2024, 7:45 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
alainlamar updated the task description for T6425: WiFi: Beamformer support for 802.11ac (VHT at 5GHz) is broken.
May 30 2024, 7:22 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po closed T6407: ipsec profile generation error as Resolved.
May 30 2024, 7:02 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po closed T6419: reverse-proxy: full CA chain is not build when verifying backend server as Resolved.
May 30 2024, 7:02 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T6419: reverse-proxy: full CA chain is not build when verifying backend server from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 30 2024, 7:02 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po closed T6421: host-name has no explicit priority to be set on system boot as Resolved.
May 30 2024, 7:02 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
c-po moved T6407: ipsec profile generation error from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 30 2024, 7:01 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po moved T6421: host-name has no explicit priority to be set on system boot from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 30 2024, 7:01 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
c-po moved T6421: host-name has no explicit priority to be set on system boot from Open to Finished on the VyOS 1.5 Circinus board.
May 30 2024, 7:01 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
Embezzle changed the status of T6409: Remove unused parameter node from reverse-proxy backend from In progress to Needs testing.
May 30 2024, 6:03 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
alainlamar updated the task description for T6425: WiFi: Beamformer support for 802.11ac (VHT at 5GHz) is broken.
May 30 2024, 3:39 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
alainlamar updated the task description for T6425: WiFi: Beamformer support for 802.11ac (VHT at 5GHz) is broken.
May 30 2024, 3:38 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
alainlamar created T6425: WiFi: Beamformer support for 802.11ac (VHT at 5GHz) is broken.
May 30 2024, 3:38 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po updated subscribers of T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate.
May 30 2024, 2:59 PM · VyOS 1.4 Sagitta (1.4.1)
c-po changed the status of T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate from Open to Confirmed.
May 30 2024, 2:35 PM · VyOS 1.4 Sagitta (1.4.1)
c-po changed the status of T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate, a subtask of T6407: ipsec profile generation error, from Open to Confirmed.
May 30 2024, 2:35 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po claimed T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate.
May 30 2024, 2:34 PM · VyOS 1.4 Sagitta (1.4.1)
c-po created T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate.
May 30 2024, 2:34 PM · VyOS 1.4 Sagitta (1.4.1)
c-po updated the task description for T6423: Require command definition nodes that have an owner to also have a priority.
May 30 2024, 2:31 PM · VyOS 1.4 Sagitta (1.4.1)
c-po created T6423: Require command definition nodes that have an owner to also have a priority.
May 30 2024, 2:29 PM · VyOS 1.4 Sagitta (1.4.1)
haimg claimed T6422: Ability to configure multiple NS records in the authoritative DNS server configuration.
May 30 2024, 1:27 PM · Restricted Project, VyOS Rolling
haimg edited a custom field on T6422: Ability to configure multiple NS records in the authoritative DNS server configuration.
May 30 2024, 1:27 PM · Restricted Project, VyOS Rolling
haimg created T6422: Ability to configure multiple NS records in the authoritative DNS server configuration.
May 30 2024, 1:26 PM · Restricted Project, VyOS Rolling
pavel-altair added a comment to T6417: Common storage location for accounts for different VPNs.
set resource-group username-group <my-users> username user01 password '09078081'
set resource-group username-group <my-users> username user02 password 'fmndskl82'

set service pppoe-server authentication local-users username-group 'my-users'
set vpn l2tp remote-access authentication local-users username-group 'my-users'
set vpn sstp authentication local-users username-group 'my-users'
set vpn openconnect authentication local-users username-group 'my-users'

Looks like what I was talking about

May 30 2024, 12:32 PM · VyOS Rolling
Viacheslav added a comment to T6417: Common storage location for accounts for different VPNs.

Need a general place to store accounts for VPN; whether it is a local radius server or chap-secrets file(this option seems simpler and more correct) is not so important.
A separate radius server is another point of failure and a separate infrastructure object. Wants to have a boxed solution where everything is available at once

May 30 2024, 10:07 AM · VyOS Rolling
c-po moved T6407: ipsec profile generation error from Open to Finished on the VyOS 1.5 Circinus board.
May 30 2024, 9:29 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po added a comment to T6407: ipsec profile generation error.

https://github.com/vyos/vyos-1x/pull/3552

May 30 2024, 9:28 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po added a comment to T6407: ipsec profile generation error.

Apple IOS now recognizes multiple CAs inside the profile

May 30 2024, 9:26 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po added a comment to T6407: ipsec profile generation error.

With this change all CAs in the list are rendered into the template.

May 30 2024, 9:05 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po added a project to T6407: ipsec profile generation error: VyOS 1.4 Sagitta (1.4.0-GA).
May 30 2024, 8:13 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
pavel-altair added a comment to T6417: Common storage location for accounts for different VPNs.

It is not clear why it should be ignored? If they should be ignored they must not be in the CLI at all.
Why not use RADIUS authentication for it?

Do I get it wrong? Local RADIUS server seems like overhead here. Are we talking about the local “chap-secrets” file that can be reused by other daemons or RADIUS?
Clarify please the feature request.

Need a general place to store accounts for VPN; whether it is a local radius server or chap-secrets file(this option seems simpler and more correct) is not so important.
A separate radius server is another point of failure and a separate infrastructure object. Wants to have a boxed solution where everything is available at once

May 30 2024, 7:49 AM · VyOS Rolling
Viacheslav triaged T6419: reverse-proxy: full CA chain is not build when verifying backend server as Normal priority.
May 30 2024, 7:47 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po updated the task description for T6421: host-name has no explicit priority to be set on system boot.
May 30 2024, 7:31 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
c-po changed the status of T6421: host-name has no explicit priority to be set on system boot from Open to In progress.
May 30 2024, 7:30 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
c-po created T6421: host-name has no explicit priority to be set on system boot.
May 30 2024, 7:30 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a comment to T6418: reverse-proxy: backend http-check CLI option not honored.

The similar task T6409

May 30 2024, 5:56 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav moved T6402: Invalid variables referenced in reverse proxy validation from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 30 2024, 5:55 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav moved T6402: Invalid variables referenced in reverse proxy validation from Open to Finished on the VyOS 1.5 Circinus board.
May 30 2024, 5:55 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

May 29 2024

Viacheslav added a comment to T6417: Common storage location for accounts for different VPNs.

It is not clear why it should be ignored? If they should be ignored they must not be in the CLI at all.
Why not use RADIUS authentication for it?

May 29 2024, 11:30 PM · VyOS Rolling
c-po updated the task description for T6419: reverse-proxy: full CA chain is not build when verifying backend server.
May 29 2024, 9:37 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T6419: reverse-proxy: full CA chain is not build when verifying backend server from Open to Finished on the VyOS 1.5 Circinus board.
May 29 2024, 9:31 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T6419: reverse-proxy: full CA chain is not build when verifying backend server from Need Triage to In Progress on the VyOS 1.4 Sagitta (1.4.0-GA) board.
May 29 2024, 9:30 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po edited projects for T6419: reverse-proxy: full CA chain is not build when verifying backend server, added: VyOS 1.4 Sagitta (1.4.0-GA); removed VyOS 1.4 Sagitta.
May 29 2024, 9:30 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po added a comment to T6419: reverse-proxy: full CA chain is not build when verifying backend server.

https://github.com/vyos/vyos-1x/pull/3546

May 29 2024, 9:30 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Embezzle closed T6402: Invalid variables referenced in reverse proxy validation as Resolved.

Tested as working in: VyOS 1.5-rolling-202405280020

May 29 2024, 9:10 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po changed the status of T6419: reverse-proxy: full CA chain is not build when verifying backend server from Open to In progress.
May 29 2024, 8:32 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po created T6419: reverse-proxy: full CA chain is not build when verifying backend server.
May 29 2024, 8:32 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po assigned T6418: reverse-proxy: backend http-check CLI option not honored to Viacheslav.
May 29 2024, 8:16 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po created T6418: reverse-proxy: backend http-check CLI option not honored.
May 29 2024, 8:16 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
fernando closed T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr as Resolved.
May 29 2024, 5:57 PM · VyOS 1.4 Sagitta (1.4.1)
fernando added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

@mersl thanks for confirm.

May 29 2024, 5:57 PM · VyOS 1.4 Sagitta (1.4.1)
pavel-altair added a comment to T6417: Common storage location for accounts for different VPNs.

It probably cannot be a universal solution due to specific per-user options.
For example, for opencoonect, you can add otp if you want on a per-user basis and not do it for other users.

vyos@r4# set vpn openconnect authentication local-users username foo 
Possible completions:
   disable              Disable instance
 > otp                  2FA OTP authentication parameters
   password             Password used for authentication

Another case specific client IP address or rate limit

vyos@r4# set vpn sstp authentication local-users username foo 
Possible completions:
   disable              Disable instance
   password             Password for authentication
 > rate-limit           Upload/Download speed limits
   static-ip            Static client IP address (default: *)

Though it could be only for accel-ppp based configuration sstp/l2tp/pptp

specific per-user options can ignored if the protocol does not support them

May 29 2024, 5:43 PM · VyOS Rolling
mersl added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

just some show commands with test results on my lab

May 29 2024, 5:04 PM · VyOS 1.4 Sagitta (1.4.1)
mersl added a comment to T6332: IPv6-only ISIS (or, in general, dual topology) is not working with other devices running frr.

very cool! I just rebuild a 1.5-rolling and upgraded my lab router and voila - works as expected ;-)

May 29 2024, 4:41 PM · VyOS 1.4 Sagitta (1.4.1)
Viacheslav triaged T6417: Common storage location for accounts for different VPNs as Wishlist priority.

It probably cannot be a universal solution due to specific per-user options.
For example, for opencoonect, you can add otp if you want on a per-user basis and not do it for other users.

vyos@r4# set vpn openconnect authentication local-users username foo 
Possible completions:
   disable              Disable instance
 > otp                  2FA OTP authentication parameters
   password             Password used for authentication
May 29 2024, 4:19 PM · VyOS Rolling