Page MenuHomeVyOS Platform
Feed Search

Sep 11 2018

c-po committed rVYOSONEXbfedcd4c7965: snmp.py: proper creation of non network bound SNMP communities.
Sep 11 2018, 7:26 AM

Sep 10 2018

c-po committed rVYOSONEX9fde738774b8: snmp.py: improve JINJA2 template robustness.
Sep 10 2018, 4:25 PM
c-po added a comment to T826: L2TP/IPSec broken in latest rolling release.

There you go: http://www.mybll.net/vyos-1.2.0-rolling+201808230337-amd64.iso

Sep 10 2018, 9:36 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Sep 7 2018

c-po added a comment to T826: L2TP/IPSec broken in latest rolling release.

After a successfull connection I see the spawned process:

root      2595  0.0  0.0   4332   124 pts/1    Ss+  22:58   0:00 /usr/sbin/xl2tpd
root      2868  0.5  0.2  26108  2484 pts/1    S+   22:59   0:00  \_ /usr/sbin/pppd passive nodetach 10.255.255.0:172.16.222.1 refuse-pap auth name VyattaL2TPServer debug file /etc/ppp/options.xl2tpd /dev/pts/1
Sep 7 2018, 9:03 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T826: L2TP/IPSec broken in latest rolling release.

Okay, I narrowed it down even further:

Sep 7 2018, 8:55 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T836: syslog messages split accross multiple files.

Thanks! Sounds like a proper fix to me.

Sep 7 2018, 8:44 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po assigned T836: syslog messages split accross multiple files to hagbard.
Sep 7 2018, 7:30 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po created T836: syslog messages split accross multiple files.
Sep 7 2018, 7:30 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Sep 6 2018

c-po added a comment to Q147: Automatically delete old logs.

I‘m using VyOS 1.2.x wirh a 4GB HDD on ESXi

Sep 6 2018, 5:53 PM · VyConf
c-po added Q147: Automatically delete old logs (Answer 213).
Sep 6 2018, 4:38 PM
c-po added a comment to T826: L2TP/IPSec broken in latest rolling release.

Issue was introduced between those two images:

Sep 6 2018, 4:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po closed T831: NTP daemon won't synchronize with "restrict default ignore" as Resolved.
Sep 6 2018, 3:52 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Sep 5 2018

c-po committed rVYOSONEX37bc4c58de27: T831: ntp.py: fix restrict configuration keyword to allow clients to sync up.
Sep 5 2018, 8:24 PM
c-po added a comment to T831: NTP daemon won't synchronize with "restrict default ignore".

I guess then it was "broken" all the time

Sep 5 2018, 8:22 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T831: NTP daemon won't synchronize with "restrict default ignore".

Does downstreaming work when you configure set system ntp allow-clients address?

Sep 5 2018, 8:06 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Sep 4 2018

c-po created T828: Specify RADIUS source ip for PPP and L2TP connections.
Sep 4 2018, 5:49 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc7)
c-po committed rVYOSONEX93f6b6a3b23f: dhcp_server.py: bugfix pool assignment.
Sep 4 2018, 5:42 AM

Sep 3 2018

c-po added a comment to T685: Python environment lacks definition of vyos_libexec_dir when calling os.system().

@dmbaturin the "workaround" and implementation is IMHO super bad (https://github.com/vyos/vyos-1x/blob/current/src/conf_mode/snmp.py#L808-L813) as it uses /opt/vyatta/sbin/my_set or /opt/vyatta/sbin/my_delete.

Sep 3 2018, 12:54 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po added a comment to T685: Python environment lacks definition of vyos_libexec_dir when calling os.system().

Yes, just pass the variable on calls to os.system()

Sep 3 2018, 5:07 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Sep 2 2018

c-po edited projects for T826: L2TP/IPSec broken in latest rolling release, added: VyOS 1.2 Crux; removed VyOS 1.2 Crux (VyOS 1.2.0-rc1).
Sep 2 2018, 2:53 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po triaged T826: L2TP/IPSec broken in latest rolling release as High priority.
Sep 2 2018, 2:53 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po updated the task description for T826: L2TP/IPSec broken in latest rolling release.
Sep 2 2018, 2:50 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po updated the task description for T826: L2TP/IPSec broken in latest rolling release.
Sep 2 2018, 2:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po created T826: L2TP/IPSec broken in latest rolling release.
Sep 2 2018, 2:31 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po edited projects for T825: Remove deprecated "set system package", added: VyOS 1.2 Crux; removed VyOS 1.2 Crux (VyOS 1.2.0-rc1).
Sep 2 2018, 11:33 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po closed T825: Remove deprecated "set system package" as Resolved.
Sep 2 2018, 11:32 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po committed rVYOSONEXc49ec1392ba6: T825: add system 8-to-9 migration script.
Sep 2 2018, 11:30 AM
c-po claimed T825: Remove deprecated "set system package".
Sep 2 2018, 11:28 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po triaged T825: Remove deprecated "set system package" as Normal priority.
Sep 2 2018, 11:12 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po created T825: Remove deprecated "set system package".
Sep 2 2018, 11:11 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po committed rVYOSONEX0a1f99d8d611: mdns_repeater: add 'disable' option.
Sep 2 2018, 10:25 AM
c-po committed rVYOSONEX4532e0bad920: mdns_repeater: cleanup python implementation.
Sep 2 2018, 10:25 AM

Sep 1 2018

c-po closed T819: Patch kernel against spectre V2 as Resolved.
Sep 1 2018, 7:51 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T819: Patch kernel against spectre V2.
cpo@LR1:~$ cat /sys/devices/system/cpu/vulnerabilities/spectre_v2
Mitigation: Full generic retpoline, IBPB, IBRS_FW
Sep 1 2018, 7:51 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po moved T820: IPSec charon running even without active VPN configuration from Need Triage to Backlog on the VyOS 1.2 Crux board.
Sep 1 2018, 7:36 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po edited projects for T769: StrongSWAN starts when "vpn ipsec" is not present in the config, added: VyOS 1.2 Crux; removed VyOS 1.2 Crux (VyOS 1.2.0-rc1).
Sep 1 2018, 7:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9)
c-po added a subtask for T769: StrongSWAN starts when "vpn ipsec" is not present in the config: T820: IPSec charon running even without active VPN configuration.
Sep 1 2018, 7:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9)
c-po added a parent task for T820: IPSec charon running even without active VPN configuration: T769: StrongSWAN starts when "vpn ipsec" is not present in the config.
Sep 1 2018, 7:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po updated the task description for T769: StrongSWAN starts when "vpn ipsec" is not present in the config.
Sep 1 2018, 7:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9)
c-po created T820: IPSec charon running even without active VPN configuration.
Sep 1 2018, 7:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po moved T739: flow-accounting stops from In Progress to Finished on the VyOS 1.2 Crux board.
Sep 1 2018, 7:25 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct
c-po committed rVYOSONEX6b7c267de327: snmp.py: improve daemon startup.
Sep 1 2018, 7:20 PM
c-po changed the status of T819: Patch kernel against spectre V2 from Open to In progress.
Sep 1 2018, 6:29 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T592: lldpcli: unknown command from argument 1: `#`.

Even happens without any argument:

cpo@LR1# sudo /usr/sbin/lldpd -d
2018-09-01T20:12:53 [WARN/lldpctl] unknown command from argument 1: `#`
2018-09-01T20:12:53 [WARN/lldpctl] unknown command from argument 1: `#`
Sep 1 2018, 6:13 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po added a comment to T592: lldpcli: unknown command from argument 1: `#`.

Happens too when started by hand, where 172.16.254.35 is the management address

Sep 1 2018, 6:11 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po closed T733: Regression: Python snmp configuration parser doesn't set 'community6' SNMP fields as Resolved.
Sep 1 2018, 3:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po closed T757: Rewrite 'service dns dynamic' in new XML style format as Resolved.
Sep 1 2018, 3:07 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T794: openvpn configuration - not important, just for beauty :).

The user/password thing is closed. The Port issue seems to not be easy. Will be easier with a vyos-1x rewrite

Sep 1 2018, 3:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc4)
c-po added a comment to T815: Add DHCPv6 server prefix-delegation support.

IPv6 DHCP

Sep 1 2018, 3:02 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po closed T731: Use of uninitialized value $cur_tty in concatenation (.) or string at /etc/commit/post-hooks.d/10vyatta-log-commit.pl line 47. as Resolved.
Sep 1 2018, 3:00 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po moved T787: DMVPN on 1.2.0 from Need Triage to In Progress on the VyOS 1.2 Crux board.
Sep 1 2018, 2:43 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T787: DMVPN on 1.2.0.

Just tried your configuration and adopted it to my LAB. I can't reproduce your issue.

Sep 1 2018, 2:42 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po updated the task description for T739: flow-accounting stops.
Sep 1 2018, 2:26 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct
c-po added a comment to T739: flow-accounting stops.

Done!

Sep 1 2018, 2:25 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct
c-po closed T817: Update pmacct from 1.6.2 to 1.7.0 as Resolved.
Sep 1 2018, 2:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), pmacct
c-po closed T817: Update pmacct from 1.6.2 to 1.7.0, a subtask of T739: flow-accounting stops, as Resolved.
Sep 1 2018, 2:24 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct
c-po added a comment to T817: Update pmacct from 1.6.2 to 1.7.0.

Done https://github.com/vyos/pmacct/commit/22b9be62d8e1eba71db8391fe86ad95181645887

Sep 1 2018, 2:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), pmacct
c-po moved T817: Update pmacct from 1.6.2 to 1.7.0 from Need Triage to In Progress on the VyOS 1.2 Crux board.
Sep 1 2018, 2:23 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), pmacct
c-po added a comment to T786: new style xml and conf-mode scripts: posibillity to add tagNode value as parameter to conf-script.

I had the exact same problem for the service broadcast-relay code. I did a cleanup on the youthful folly. Resulting in this issue going away (https://github.com/vyos/vyos-1x/commit/fd1eabe72862ec364643a61cb94b21c330a385f5#diff-e27a1d5bf8f371aae9da8bbd36e674d0).

Sep 1 2018, 2:14 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po moved T739: flow-accounting stops from Need Triage to In Progress on the VyOS 1.2 Crux board.
Sep 1 2018, 2:03 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct
c-po added a comment to T739: flow-accounting stops.
snaplen (-L) [GLOBAL, NO_NFACCTD]
Desc
specifies the maximum number of bytes to capture for each packet. This directive has key importance when enabling both classification and connection tracking engines. In fact, some protocols (mostly text-based eg.: RTSP, SIP, etc.) benefit of extra bytes because they give more chances to successfully track data streams spawned by control channel. But it must be also noted that capturing larger packet portion require more resources. The right value need to be traded-off. In case classification is enabled, values under 200 bytes are often meaningless. 500-750 bytes are enough even for text based protocols. Default snaplen values are ok if classification is disabled. For uacctd daemon, this option doesn't apply to packet snapshot length but rather to the Netlink socket read buffer size. This should be reasonably large - at least 4KB, which is the default value. For large uacctd_nl_size values snaplen could be further increased.
Sep 1 2018, 1:57 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct
c-po added a comment to T739: flow-accounting stops.

It just died with this log:

Sep 1 2018, 1:45 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct
c-po added a comment to T739: flow-accounting stops.

You could also alter the file /etc/default/uacctd and add -d into DAEMON_OPTS and restart flow-acounting

Sep 1 2018, 1:38 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct
c-po updated subscribers of T818: SNMP v3 - remove required engineid from user node.

@Line2 @begetan I added both of you as you seem to use SNMP (probably with v3). What's your opinion on this?

Sep 1 2018, 1:02 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po added a subtask for T652: Rewrite service snmp in new style XML interface definition: T818: SNMP v3 - remove required engineid from user node.
Sep 1 2018, 1:01 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a parent task for T818: SNMP v3 - remove required engineid from user node: T652: Rewrite service snmp in new style XML interface definition.
Sep 1 2018, 1:00 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po claimed T818: SNMP v3 - remove required engineid from user node.
Sep 1 2018, 1:00 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po updated the task description for T818: SNMP v3 - remove required engineid from user node.
Sep 1 2018, 1:00 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po created T818: SNMP v3 - remove required engineid from user node.
Sep 1 2018, 1:00 PM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po committed rVYOSONEXd48e5d8d1963: snmp.py: beautify generated snmp.conf #2.
Sep 1 2018, 12:58 PM
c-po committed rVYOSONEXbfde18e1064d: snmp.py: bugfix - CLI client community node was not processed.
Sep 1 2018, 12:48 PM
c-po committed rVYOSONEXbd2f3a42ec9f: snmp.py: bugfix writing rocommunity string in config.
Sep 1 2018, 12:48 PM
c-po committed rVYOSONEXa5b70e5a9176: snmp.py: beautify generated snmp.conf.
Sep 1 2018, 12:48 PM
c-po committed rVYOSONEX1117cf40eb99: T771: snmp.px: reduce syslog noise.
Sep 1 2018, 12:24 PM
c-po edited projects for T771: SNMP: reduce logging noise, added: VyOS 1.2 Crux (VyOS 1.2.0-rc1); removed VyOS 1.2 Crux.
Sep 1 2018, 12:23 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po closed T771: SNMP: reduce logging noise as Resolved.
Sep 1 2018, 12:23 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T771: SNMP: reduce logging noise.

Starting with this daemon config reduces the logging entries dramatically:

Sep 1 2018, 11:42 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po changed the status of T817: Update pmacct from 1.6.2 to 1.7.0 from Open to In progress.
Sep 1 2018, 11:06 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), pmacct
c-po added a comment to T739: flow-accounting stops.

@panachoi maybe this upgrade helps

Sep 1 2018, 10:54 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct
c-po closed T632: Switch to multi node configuration for additional SSH options introduced in 1.2.x as Resolved.
Sep 1 2018, 9:37 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po closed T632: Switch to multi node configuration for additional SSH options introduced in 1.2.x, a subtask of T631: Rewrite SSH configuration as XML interface definition, as Resolved.
Sep 1 2018, 9:37 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po updated the task description for T816: ipaddrcheck / libcidr but on IPv6 network validation.
Sep 1 2018, 8:06 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
c-po assigned T816: ipaddrcheck / libcidr but on IPv6 network validation to dmbaturin.
Sep 1 2018, 8:05 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
c-po created T816: ipaddrcheck / libcidr but on IPv6 network validation.
Sep 1 2018, 8:04 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Aug 31 2018

c-po moved T815: Add DHCPv6 server prefix-delegation support from Need Triage to Backlog on the VyOS 1.2 Crux board.
Aug 31 2018, 8:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po created T815: Add DHCPv6 server prefix-delegation support.
Aug 31 2018, 8:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po closed T811: Rewrite 'service dhcpv6-server' in new XML style format as Resolved.
Aug 31 2018, 8:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po committed rVYOSONEX81e1cf8dbf02: Merge branch 'dhcpv6-server-rewrite' into current.
Aug 31 2018, 8:34 PM
c-po committed rVYOSONEX8a5c00e897a9: T811: dhcpv6_server.py: add missing validators when comitting config changes.
Aug 31 2018, 8:34 PM
c-po committed rVYOSONEX91c3b8bdd9f7: dhcp_server.py: cleanup.
Aug 31 2018, 8:34 PM
c-po committed rVYOSONEX6ff335b675f1: bcast_relay.py: remove obsolete import statement.
Aug 31 2018, 8:34 PM
c-po committed rVYOSONEX6ba2186d7aad: vyos: package: bugfix in validate.py for is_subnet_connected().
Aug 31 2018, 8:34 PM
c-po committed rVYOSONEX9a16fd2cdb81: T778: dhcpv6-server: XML and Python rewrite.
Aug 31 2018, 8:34 PM
c-po closed T812: DHCPv6 static mapping breaks DHCP service as Resolved.
Aug 31 2018, 8:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po closed T812: DHCPv6 static mapping breaks DHCP service, a subtask of T811: Rewrite 'service dhcpv6-server' in new XML style format, as Resolved.
Aug 31 2018, 8:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T812: DHCPv6 static mapping breaks DHCP service.

fixed in XML/python rewrite

Aug 31 2018, 8:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po moved T811: Rewrite 'service dhcpv6-server' in new XML style format from In Progress to Finished on the VyOS 1.2 Crux board.
Aug 31 2018, 8:33 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Aug 30 2018

c-po committed rVYOSONEXc16a8fcb9dca: dhcp_server.py: rework verify() error messages/error checking.
Aug 30 2018, 8:08 PM
c-po committed rVYOSONEXb8baf2191062: vyos: package: extend validator by is_subnet_connected().
Aug 30 2018, 8:08 PM
c-po committed rVYOSONEXe30cb0076185: snmp.py: only write 'oldEngineID' to config if v3 is enabled.
Aug 30 2018, 7:53 AM