Page MenuHomeVyOS Platform
Feed All Stories

Jun 9 2024

marekm added a comment to T6450: Use http instead of https for rolling apt repo access.

@blueish - thanks! Yes, apt-mirror works now - but will it continue to work with the new storage too?
BTW, good to see "deb-src" - but only a few source packages are in there. I think it would be great to have corresponding source for all these *.deb packages in the Debian source package format, then anyone who wants to contribute will be able to use dpkg-buildpackage to rebuild them.

Jun 9 2024, 11:32 PM
c-po added a comment to T6407: ipsec profile generation error.

Please share the output of dpkg -l | grep vyos-1x

Jun 9 2024, 9:05 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po added a comment to T6464: sstpc: interface not restarted when updating SSL certificate via PKI.

https://github.com/vyos/vyos-1x/pull/3613

Jun 9 2024, 7:00 PM · VyOS 1.4 Sagitta (1.4.1)
c-po changed the status of T6464: sstpc: interface not restarted when updating SSL certificate via PKI from Open to In progress.
Jun 9 2024, 6:49 PM · VyOS 1.4 Sagitta (1.4.1)
c-po created T6464: sstpc: interface not restarted when updating SSL certificate via PKI.
Jun 9 2024, 6:48 PM · VyOS 1.4 Sagitta (1.4.1)
c-po updated the task description for T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs.
Jun 9 2024, 6:14 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po added a comment to T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs.

https://github.com/vyos/vyos-1x/pull/3611

Jun 9 2024, 6:13 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
pavel-altair added a comment to T6407: ipsec profile generation error.
vyos@vyos# show vpn ipsec | commands 
set esp-group vpn lifetime '3600'
set esp-group vpn pfs 'enable'
set esp-group vpn proposal 10 encryption 'aes128gcm128'
set esp-group vpn proposal 10 hash 'sha256'
set ike-group vpn key-exchange 'ikev2'
set ike-group vpn lifetime '7200'
set ike-group vpn proposal 10 dh-group '14'
set ike-group vpn proposal 10 encryption 'aes128gcm128'
set ike-group vpn proposal 10 hash 'sha256'
set interface 'eth0'
set options virtual-ip
set remote-access connection support authentication client-mode 'eap-mschapv2'
set remote-access connection support authentication local-id 'ipsec.somedomain'
set remote-access connection support authentication local-users username test password 'test'
set remote-access connection support authentication server-mode 'x509'
set remote-access connection support authentication x509 ca-certificate 'isrgrootx1'
set remote-access connection support authentication x509 ca-certificate 'lets-encrypt-r3'
set remote-access connection support authentication x509 certificate 'vpn2'
set remote-access connection support description 'support remote access'
set remote-access connection support esp-group 'vpn'
set remote-access connection support ike-group 'vpn'
set remote-access connection support local-address 'ip on eth0'
set remote-access connection support pool 'support'
set remote-access pool support name-server '1.1.1.1'
set remote-access pool support name-server '9.9.9.9'
set remote-access pool support prefix '192.168.120.64/27'
[edit]
vyos@vyos#
Jun 9 2024, 6:12 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po added a comment to T6407: ipsec profile generation error.

Please share your full ipsec configuration

Jun 9 2024, 6:02 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po claimed T6463: reverse-proxy: service not reloaded when updating SSL certificate via PKI.
Jun 9 2024, 6:01 PM · VyOS 1.4 Sagitta (1.4.1)
c-po created T6463: reverse-proxy: service not reloaded when updating SSL certificate via PKI.
Jun 9 2024, 6:01 PM · VyOS 1.4 Sagitta (1.4.1)
pavel-altair added a comment to T6407: ipsec profile generation error.
vyos@vyos:~$ generate ipsec profile windows-remote-access support remote ipsec.somedomain 
Traceback (most recent call last):
  File "/usr/libexec/vyos/op_mode/ikev2_profile_generator.py", line 154, in <module>
    cert = load_certificate(pki['certificate'][cert_name]['certificate'])
                            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^
KeyError: 'certificate'
vyos@vyos:~$ show ver
Version:          VyOS 1.5-rolling-202406060020
Release train:    current
Release flavor:   generic
Jun 9 2024, 6:01 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po closed T6281: Wireguard does not pass traffic if VRFs are used as Invalid.
Jun 9 2024, 5:43 PM · VyOS 1.5 Circinus
c-po added a comment to T6281: Wireguard does not pass traffic if VRFs are used.

Reporter action missing - running this setup in production so does not feel like a bug.

Jun 9 2024, 5:43 PM · VyOS 1.5 Circinus
c-po changed the status of T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs from Open to In progress.
Jun 9 2024, 5:29 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po created T6462: wireless: add op-mode command for hostapd and wpa_supplicant logs.
Jun 9 2024, 5:29 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEX2d98f3b17e11: Merge pull request #3608 from vyos/mergify/bp/sagitta/pr-3596 (authored by c-po).
Jun 9 2024, 3:02 PM
GitHub <[email protected]> committed rVYOSONEXd296f1b15058: Merge pull request #3605 from vyos/mergify/bp/sagitta/pr-3598 (authored by c-po).
Jun 9 2024, 3:02 PM
GitHub <[email protected]> committed rVYOSONEX723e2ab61480: Merge pull request #3604 from vyos/mergify/bp/sagitta/pr-3592 (authored by c-po).
Jun 9 2024, 3:02 PM
GitHub <[email protected]> committed rVYOSONEX23d02fae78b0: Merge pull request #3603 from vyos/mergify/bp/sagitta/pr-3589 (authored by c-po).
Jun 9 2024, 3:01 PM
GitHub <[email protected]> committed rVYOSONEX264037d4cc3d: Merge pull request #3602 from vyos/mergify/bp/sagitta/pr-3573 (authored by c-po).
Jun 9 2024, 3:01 PM
c-po moved T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate from Backlog to In Progress on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 9 2024, 12:47 PM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate from Open to Finished on the VyOS 1.5 Circinus board.
Jun 9 2024, 12:47 PM · VyOS 1.4 Sagitta (1.4.1)
c-po edited projects for T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate, added: VyOS 1.4 Sagitta (1.4.1); removed VyOS 1.4 Sagitta (1.4.0).
Jun 9 2024, 12:47 PM · VyOS 1.4 Sagitta (1.4.1)
c-po added a comment to T6424: ipsec: op-mode command to generate client profiles should honor common name of the CA node that signed the server certificate.

https://github.com/vyos/vyos-1x/pull/3610

Jun 9 2024, 12:47 PM · VyOS 1.4 Sagitta (1.4.1)
c-po added a comment to T6407: ipsec profile generation error.

This was merged Thu May 30 16:35:43 2024 +0200 and your image is from 2024-05-30.

Jun 9 2024, 11:21 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
aztec102 added a comment to T5169: Add CGNAT Carrier-Grade NAT based on nftables.

Good afternoon I heard that the solution based on nftables is no longer new, but you took it as a basis.
At the same time, I heard that VyOS added support for VPP. Maybe it makes sense to use two implementations?
I don’t want to offend you in any way, I appreciate everything you do.
https://s3-docs.fd.io/vpp/22.06/cli-reference/clis/clicmd_src_plugins_nat_det44.html

Jun 9 2024, 9:57 AM · VyOS Rolling, VyOS 1.5 Circinus
Embezzle changed the status of T6454: Explicitly set the default reverse proxy mode to HTTP from In progress to Needs testing.
Jun 9 2024, 9:51 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
talmakion added a comment to T4667: DMVPN IPSec allows cleartext GRE over the internet when reconnecting.

I may have figured something out in https://vyos.dev/T4694.

Jun 9 2024, 9:49 AM · VyOS Rolling, Bugs
talmakion added a comment to T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.

It looks like outbound encap can be matched via routing expressions:

Jun 9 2024, 9:39 AM · VyOS 1.4 Sagitta (1.4.0-GA)
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXba9b1723f90d: T6449: added pr update trigger (#3596) (authored by Vijayakumar A <[email protected]>).
Jun 9 2024, 9:25 AM
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX29ae4044a6d4: T6449: added pr update trigger (#3596) (authored by Vijayakumar A <[email protected]>).
Jun 9 2024, 9:25 AM
GitHub <[email protected]> committed rVYOSONEX395bd4eb850f: T6449: added pr update trigger (#3596) (authored by Vijayakumar A <[email protected]>).
Jun 9 2024, 9:24 AM
c-po moved T6460: Showing DHCPv6 leases can fail due to DUID parsing issues from Backlog to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 9 2024, 8:10 AM · VyOS 1.4 Sagitta (1.4.1)
c-po closed T6460: Showing DHCPv6 leases can fail due to DUID parsing issues as Resolved.
Jun 9 2024, 8:10 AM · VyOS 1.4 Sagitta (1.4.1)
GitHub <[email protected]> committed rVYOSONEXc4a3a55516cf: Merge pull request #3600 from nvollmar/T6460 (authored by c-po).
Jun 9 2024, 8:09 AM
nvollmar committed rVYOSONEX253bf3437117: T6460: fixes duid formatting.
Jun 9 2024, 8:09 AM
Vijayakumar created T6461: Create a workflow, that checks existence of codeowners file in repo, if not create one..
Jun 9 2024, 8:08 AM · GitHub Infrastructure
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXed291814eb8b: reverse-proxy: T6454: Set default value of http for haproxy mode (authored by Embezzle).
Jun 9 2024, 7:17 AM
c-po moved T6454: Explicitly set the default reverse proxy mode to HTTP from Backlog to In Progress on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 9 2024, 7:17 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po moved T6454: Explicitly set the default reverse proxy mode to HTTP from Open to Finished on the VyOS 1.5 Circinus board.
Jun 9 2024, 7:17 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
c-po added a project to T6454: Explicitly set the default reverse proxy mode to HTTP: VyOS 1.4 Sagitta (1.4.1).
Jun 9 2024, 7:17 AM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
GitHub <[email protected]> committed rVYOSONEXbd8016060c8f: Merge pull request #3598 from Embezzle/T6454 (authored by c-po).
Jun 9 2024, 7:17 AM
Embezzle committed rVYOSONEX60d7c0ecaff4: reverse-proxy: T6454: Set default value of http for haproxy mode.
Jun 9 2024, 7:17 AM
Vijayakumar updated the task description for T6449: PR title/commit message check workfow to add comment to PR incase of title is not compliant.
Jun 9 2024, 6:58 AM · GitHub Infrastructure
c-po committed rVYOSONEX6ec4be553be8: xml: T6423: enforce priority on nodes having an owner (authored by natali-rs1985).
Jun 9 2024, 6:50 AM
c-po moved T6423: Require command definition nodes that have an owner to also have a priority from Backlog to In Progress on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 9 2024, 6:29 AM · VyOS 1.4 Sagitta (1.4.1)
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX5793af2132e9: grub: T6453: Fixed GRUB variables parsing (authored by zsdc).
Jun 9 2024, 6:29 AM
c-po added a project to T6423: Require command definition nodes that have an owner to also have a priority: VyOS 1.5 Circinus.
Jun 9 2024, 6:29 AM · VyOS 1.4 Sagitta (1.4.1)
c-po edited projects for T6423: Require command definition nodes that have an owner to also have a priority, added: VyOS 1.4 Sagitta (1.4.1); removed VyOS 1.5 Circinus, VyOS 1.4 Sagitta.
Jun 9 2024, 6:29 AM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6423: Require command definition nodes that have an owner to also have a priority from Open to Finished on the VyOS 1.5 Circinus board.
Jun 9 2024, 6:29 AM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6453: GRUB variables with `=` in a value are parsed improperly from Backlog to In Progress on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 9 2024, 6:28 AM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6453: GRUB variables with `=` in a value are parsed improperly from In Progress to Finished on the VyOS 1.5 Circinus board.
Jun 9 2024, 6:28 AM · VyOS 1.4 Sagitta (1.4.1)
c-po edited projects for T6453: GRUB variables with `=` in a value are parsed improperly, added: VyOS 1.4 Sagitta (1.4.1); removed VyOS 1.4 Sagitta.
Jun 9 2024, 6:28 AM · VyOS 1.4 Sagitta (1.4.1)
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXdfca15cda0ca: xml: T6423: enforce priority on nodes having an owner (authored by natali-rs1985).
Jun 9 2024, 6:27 AM
c-po assigned T6401: Attempts to delete vlan-to-vni option causes an unhandled exception to talmakion.
Jun 9 2024, 6:26 AM · VyOS 1.4 Sagitta (1.4.1)
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX083e15c224be: vxlan: T6401: Avoid calling get_vxlan_vni_filter() unless we need it (authored by Andrew Topp <[email protected]>).
Jun 9 2024, 6:25 AM
c-po moved T6401: Attempts to delete vlan-to-vni option causes an unhandled exception from Finished to In Progress on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 9 2024, 6:25 AM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6401: Attempts to delete vlan-to-vni option causes an unhandled exception from Backlog to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 9 2024, 6:25 AM · VyOS 1.4 Sagitta (1.4.1)
c-po edited projects for T6401: Attempts to delete vlan-to-vni option causes an unhandled exception, added: VyOS 1.4 Sagitta (1.4.1); removed VyOS 1.4 Sagitta.
Jun 9 2024, 6:25 AM · VyOS 1.4 Sagitta (1.4.1)
c-po moved T6401: Attempts to delete vlan-to-vni option causes an unhandled exception from Open to Finished on the VyOS 1.5 Circinus board.
Jun 9 2024, 6:25 AM · VyOS 1.4 Sagitta (1.4.1)
talmakion added a comment to T6456: "monitor traffic" incorrectly consumes some arguments.

PR created: https://github.com/vyos/vyos-1x/pull/3601

Jun 9 2024, 2:07 AM · VyOS 1.5 Circinus

Jun 8 2024

nvollmar added a comment to T6460: Showing DHCPv6 leases can fail due to DUID parsing issues.

Created a PR with a fix

Jun 8 2024, 10:12 PM · VyOS 1.4 Sagitta (1.4.1)
nvollmar added a comment to T6460: Showing DHCPv6 leases can fail due to DUID parsing issues.

Added an example how to reproduce it

Jun 8 2024, 9:53 PM · VyOS 1.4 Sagitta (1.4.1)
nvollmar updated the task description for T6460: Showing DHCPv6 leases can fail due to DUID parsing issues.
Jun 8 2024, 9:53 PM · VyOS 1.4 Sagitta (1.4.1)
nvollmar added a comment to T6460: Showing DHCPv6 leases can fail due to DUID parsing issues.

Currently I'm not sure, might be related to changes from T4519

Jun 8 2024, 9:34 PM · VyOS 1.4 Sagitta (1.4.1)
fernando added a comment to T6460: Showing DHCPv6 leases can fail due to DUID parsing issues.

please , Could you share configuration on how to replicate it ? it's also here the guideline about report a bug :

Jun 8 2024, 9:19 PM · VyOS 1.4 Sagitta (1.4.1)
nvollmar created T6460: Showing DHCPv6 leases can fail due to DUID parsing issues.
Jun 8 2024, 9:11 PM · VyOS 1.4 Sagitta (1.4.1)
nvollmar closed T6459: Showing DHCPv6 leases fails as Invalid.
Jun 8 2024, 9:10 PM · VyOS 1.4 Sagitta (1.4.0)
nvollmar created T6459: Showing DHCPv6 leases fails.
Jun 8 2024, 9:09 PM · VyOS 1.4 Sagitta (1.4.0)
fmertz created T6458: Extend support for Lanner appliances with serial LCDs.
Jun 8 2024, 7:54 PM · VyOS Rolling
Apachez added a comment to T6457: Update strip-private function to improve op command output for IPs.

The suggested change as in matching number of "x" with number of characters in each octet/hextet in the IPv4/IPv6 address will be less anonymizing than todays method.

Jun 8 2024, 7:17 PM · VyOS Rolling, Bugs
L0crian updated the task description for T6457: Update strip-private function to improve op command output for IPs.
Jun 8 2024, 6:39 PM · VyOS Rolling, Bugs
L0crian created T6457: Update strip-private function to improve op command output for IPs.
Jun 8 2024, 6:37 PM · VyOS Rolling, Bugs
syncer added a comment to T6450: Use http instead of https for rolling apt repo access.

@blueish want to do a docs article for this?

Jun 8 2024, 6:35 PM
blueish added a comment to T6450: Use http instead of https for rolling apt repo access.

If you can use the APT then you can create mirror as well - the same way APT talks to the repository. There is no need for additional protocols like rsync.

Jun 8 2024, 6:26 PM
L0crian added a comment to T6455: Add Support for ZeroTier.

Draft PR Added: https://github.com/vyos/vyos-1x/pull/3599

Jun 8 2024, 5:42 PM · VyOS Rolling
talmakion created T6456: "monitor traffic" incorrectly consumes some arguments.
Jun 8 2024, 3:23 PM · VyOS 1.5 Circinus
L0crian claimed T6455: Add Support for ZeroTier.
Jun 8 2024, 2:18 PM · VyOS Rolling
L0crian created T6455: Add Support for ZeroTier.
Jun 8 2024, 2:17 PM · VyOS Rolling
syncer set Forum thread to https://forum.vyos.io/t/thinking-about-system-name-server-and-vrfs/14656 on T5371: "system name-server" is not vrf aware.
Jun 8 2024, 10:25 AM · VyOS Rolling, Bugs

Jun 7 2024

syncer moved T5633: op-cmd: Interrupting the "tech-support report" command generates error from Open to Backlog on the VyOS 1.5 Circinus board.
Jun 7 2024, 8:16 PM · Bugs, VyOS 1.4 Sagitta (1.4.0), VyOS Rolling, Restricted Project, VyOS 1.5 Circinus
Viacheslav assigned T5633: op-cmd: Interrupting the "tech-support report" command generates error to Giggum.
Jun 7 2024, 7:33 PM · Bugs, VyOS 1.4 Sagitta (1.4.0), VyOS Rolling, Restricted Project, VyOS 1.5 Circinus
Giggum added a comment to T5633: op-cmd: Interrupting the "tech-support report" command generates error.

Can this be assigned to me please, will give it a go.

Jun 7 2024, 5:45 PM · Bugs, VyOS 1.4 Sagitta (1.4.0), VyOS Rolling, Restricted Project, VyOS 1.5 Circinus
L0crian added a comment to T6452: Add missing QoS Op Mode Commands.

Added PR: https://github.com/vyos/vyos-1x/pull/3591

Jun 7 2024, 3:05 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1), VyOS Rolling
syncer closed T6446: Display the support URL from image build data in LTS builds as Resolved.
Jun 7 2024, 2:51 PM · VyOS 1.4 Sagitta (1.4.1), VyOS 1.5 Circinus
HollyGurza moved T5756: L2TP RADIUS backup and weight settings from Open to Finished on the VyOS 1.5 Circinus board.
Jun 7 2024, 1:48 PM · Restricted Project, VyOS 1.5 Circinus
HollyGurza closed T5756: L2TP RADIUS backup and weight settings as Resolved.
Jun 7 2024, 1:48 PM · Restricted Project, VyOS 1.5 Circinus
fatred added a comment to T6403: nat64 input validation required.

Will pull that on Sunday and give it a try, thanks!

Jun 7 2024, 1:47 PM · VyOS 1.5 Circinus
HollyGurza moved T6354: Get rid of the custom boot type check in version.py from Open to Finished on the VyOS 1.5 Circinus board.
Jun 7 2024, 1:46 PM · VyOS 1.5 Circinus
HollyGurza closed T6354: Get rid of the custom boot type check in version.py as Resolved.
Jun 7 2024, 1:46 PM · VyOS 1.5 Circinus
HollyGurza moved T4576: vpn l2tp logging level configuration from Need Triage to Finished on the VyOS 1.4 Sagitta (1.4.0-GA) board.
Jun 7 2024, 1:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza moved T4576: vpn l2tp logging level configuration from In Progress to Finished on the VyOS 1.5 Circinus board.
Jun 7 2024, 1:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza closed T4576: vpn l2tp logging level configuration as Resolved.
Jun 7 2024, 1:43 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza moved T5786: Add set/show system image to /image endpoint from Open to Finished on the VyOS 1.5 Circinus board.
Jun 7 2024, 1:42 PM · VyOS 1.5 Circinus
HollyGurza closed T5786: Add set/show system image to /image endpoint as Resolved.
Jun 7 2024, 1:42 PM · VyOS 1.5 Circinus
zsdc committed rVYOSONEXd3acecdf129c: grub: T6453: Fixed GRUB variables parsing.
Jun 7 2024, 1:21 PM
GitHub <[email protected]> committed rVYOSONEXa79c094c3b0a: Merge pull request #3592 from zdc/T6453-circinus (authored by dmbaturin).
Jun 7 2024, 1:21 PM
Vijayakumar added a comment to T6449: PR title/commit message check workfow to add comment to PR incase of title is not compliant.

Required updates in reusable workflows done.
Please approve/merge https://github.com/vyos/vyos-1x/pull/3596

Jun 7 2024, 12:36 PM · GitHub Infrastructure
GitHub <[email protected]> committed rVYOSONEXffd97555a2de: T6449: added pr update trigger (authored by Vijayakumar A <[email protected]>).
Jun 7 2024, 12:34 PM