Page MenuHomeVyOS Platform
Feed Search

Dec 24 2020

jack9603301 triaged T3150: When configuring QoS, the setting procedure of port mirroring is wrong as High priority.
Dec 24 2020, 3:42 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 changed the status of T3150: When configuring QoS, the setting procedure of port mirroring is wrong from Open to In progress.
Dec 24 2020, 3:42 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 created T3150: When configuring QoS, the setting procedure of port mirroring is wrong.
Dec 24 2020, 3:42 AM · VyOS 1.3 Equuleus (1.3.0)

Dec 23 2020

hagbard claimed T3148: Kernel support for APU2 and 3.
Dec 23 2020, 8:52 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T3148: Kernel support for APU2 and 3.
Dec 23 2020, 8:52 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2838: Ethernet device names changing, multiple hw-id being added.

I got this when several times change boot with

set system image default-boot

1.2.6 => 1.3 => 1.2.6 => 1.3

Dec 23 2020, 5:34 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T2376: /config/user-data and "preserved during image upgrade!".

I successfully update the image from 1.2.6-s1 to VyOS 1.3-rolling-202012231522

Dec 23 2020, 4:14 PM · VyOS 1.2 Crux
c-po closed T3145: Update Linux Kernel to v5.4.85 as Resolved.
Dec 23 2020, 3:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3139: Cannot create bond SR-IOV XCP-ng X540-T2.

Thanks for the feedback and telling us about how to solve this issue.

Dec 23 2020, 1:44 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3147: Upgrade to SaltStack version 3002.2 as Resolved.
Dec 23 2020, 11:29 AM · VyOS 1.3 Equuleus (1.3.0)
c-po triaged T3147: Upgrade to SaltStack version 3002.2 as Low priority.
Dec 23 2020, 11:04 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3147: Upgrade to SaltStack version 3002.2 from Open to In progress.
Dec 23 2020, 11:04 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3147: Upgrade to SaltStack version 3002.2.
Dec 23 2020, 11:03 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T3143: OpenVPN server: Push route config format is wrong as Resolved.

Successfully tested on 1.3-rolling-202012230217

Dec 23 2020, 10:40 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2045: Can't commit due to with the same name, but different firewall groups types.

The main problem is that you use the same name for different group types.

Dec 23 2020, 10:32 AM · VyOS 1.3 Equuleus (1.3.6)
c-po closed T3146: Upgrade FRR from 7.4 -> 7.5 version incl. new libyang as Resolved.
Dec 23 2020, 10:21 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2288: Include iprange package in Vyos.

@tjh How you want to integrate it with CLI or use it as a separate pkg?

Dec 23 2020, 8:18 AM · Restricted Project, VyOS 1.5 Circinus
Viacheslav closed T3139: Cannot create bond SR-IOV XCP-ng X540-T2 as Invalid.
Dec 23 2020, 8:03 AM · VyOS 1.3 Equuleus (1.3.0)

Dec 22 2020

francescocarzaniga added a comment to T3139: Cannot create bond SR-IOV XCP-ng X540-T2.

The issue turned out to be at the host level. By default SR-IOV VFs are not allowed to change their own mac addresses or send packets with a different mac address, and since this is required for LACP bonding the configuration would just fail.

Dec 22 2020, 11:14 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2419: Cannot change udp-fragmentation-offload.

@robertoberto Can you provide next commands?

show interfaces ethernet eth0 physical
sudo ethtool -k eth0 | grep offload
Dec 22 2020, 6:36 PM
Cheeze_It added a comment to T915: MPLS Support.

Put in a PR to add LDP ordered control operation for LDP.

Dec 22 2020, 6:23 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po added a comment to T2206: Split WireGuard endpoint into proper host and port nodes.
[email protected]# commit
Both Wireguard port and address must be defined for peer "foo" if either one of them is set!
Dec 22 2020, 5:42 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2444: Remove keepalived in favor of FRR for VRRP.

@primoz What are the benefits?

Dec 22 2020, 4:50 PM
Viacheslav closed T1316: Support for IS-IS as Resolved.
Dec 22 2020, 4:45 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T2573: BFD op-mode commands are broken, a subtask of T2322: CLI [op-mode] bugs. Root task, as Resolved.
Dec 22 2020, 4:45 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T2573: BFD op-mode commands are broken as Resolved.
Dec 22 2020, 4:45 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.2 Crux
Viacheslav closed T2495: Add xml for ISIS [conf_mode], a subtask of T1316: Support for IS-IS , as Resolved.
Dec 22 2020, 4:05 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T2495: Add xml for ISIS [conf_mode] as Resolved.
Dec 22 2020, 4:05 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T2940: Update FRR to 7.4 as Resolved.
Dec 22 2020, 2:46 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2859: show nat source translation - Errors out.

PR https://github.com/vyos/vyos-1x/pull/656

Dec 22 2020, 2:45 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3137: Let VLAN aware bridge approach the behavior of professional equipment.

https://github.com/vyos/vyatta-cfg-system/pull/134

Dec 22 2020, 2:42 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po claimed T3146: Upgrade FRR from 7.4 -> 7.5 version incl. new libyang.
Dec 22 2020, 2:20 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3146: Upgrade FRR from 7.4 -> 7.5 version incl. new libyang.
Dec 22 2020, 2:20 PM · VyOS 1.3 Equuleus (1.3.0)
vegardx added a comment to T2206: Split WireGuard endpoint into proper host and port nodes.

This breaks with common configuration patterns/naming in Wireguard. Nobody will know what you're talking about when you say address and port in this context. And the CLI helpers adds documentation that would lead you to believe you are listening for connections, see line 105 in nterface-definitions/interfaces-wireguard.xml.in.

Dec 22 2020, 1:32 PM · VyOS 1.3 Equuleus (1.3.0)
pengshao82 added a comment to T3134: DHCPv6 DUID configuration node missing.

dhcpcd is a pretty good alternative. Well maintained and popularly used by many. I used it in a plain Linux router project and it was good enough for my use cases.

Dec 22 2020, 1:08 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2061: protocol logs not sent to remote syslog.

PR for crux https://github.com/vyos/vyos-build/pull/138

Dec 22 2020, 12:54 PM · VyOS 1.2 Crux (VyOS 1.2.7)
c-po created T3145: Update Linux Kernel to v5.4.85.
Dec 22 2020, 12:50 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3144: Support op-mode command to release DHCP leases.
Dec 22 2020, 12:41 PM · VyOS 1.3 Equuleus (1.3.4)
c-po added a comment to T3134: DHCPv6 DUID configuration node missing.

It still would be nice though. ANy other good IPv6 DHCP clients out there?

Dec 22 2020, 12:41 PM · VyOS 1.3 Equuleus (1.3.0)
pengshao82 added a comment to T3134: DHCPv6 DUID configuration node missing.

Yeah also it looks like wide is hardcoded to support only type 1 DUID (LLT) anyway.... so probably it wasn't accidentally "forgotten" in 1.3 migration that someone probably has realized it wasn't viable to support it... Thanks :)

Dec 22 2020, 11:18 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3134: DHCPv6 DUID configuration node missing.

Undortunately it only worked in 50% of the cases properly. Also there is only one global duid file so you can not have multiple duids (one per each interface).

Dec 22 2020, 11:10 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 moved T3137: Let VLAN aware bridge approach the behavior of professional equipment from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Dec 22 2020, 9:29 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added a comment to T2206: Split WireGuard endpoint into proper host and port nodes.

@vagardx thank you for this rant.

Dec 22 2020, 8:47 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T3142: OpenVPN op-command completion fails due to missing status file as Resolved.
Dec 22 2020, 8:42 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) renamed T3142: OpenVPN op-command completion fails due to missing status file from OpenVPN up-command completion issue to OpenVPN op-command completion issue.
Dec 22 2020, 8:41 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) changed the status of T3143: OpenVPN server: Push route config format is wrong from In progress to Needs testing.
Dec 22 2020, 8:34 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 updated the task description for T3137: Let VLAN aware bridge approach the behavior of professional equipment.
Dec 22 2020, 5:37 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 renamed T3137: Let VLAN aware bridge approach the behavior of professional equipment from When the bridge is a VLAN-aware bridge, the parent interface of the bridge can be set with an address to When setting a VLAN-aware bridge, the VLAN ID of the parent interface is always 1.
Dec 22 2020, 5:36 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
pengshao82 added a comment to T3134: DHCPv6 DUID configuration node missing.

Sorry I am confused. I took a brief look at the code of dhcp6c and it appears manually modifying the dhcp6c_duid file should be able to keep the change persistent: https://github.com/jinmei/wide-dhcpv6/blob/24ee2a4f0009bc6ac9bd0b7b737aef93a4aa9905/common.c#L992. Did I miss anything? Thanks :)

Dec 22 2020, 1:59 AM · VyOS 1.3 Equuleus (1.3.0)

Dec 21 2020

pengshao82 added a comment to T3134: DHCPv6 DUID configuration node missing.

Accidentally deleted the comment. Is there plan to migrated to dhcpcd instead? dhcpcd has good ipv6 support and being actively maintained too. Thanks.

Dec 21 2020, 9:53 PM · VyOS 1.3 Equuleus (1.3.0)
pengshao82 added a comment to T3134: DHCPv6 DUID configuration node missing.
Dec 21 2020, 9:51 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) changed the status of T3143: OpenVPN server: Push route config format is wrong from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/655

Dec 21 2020, 6:54 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) claimed T3143: OpenVPN server: Push route config format is wrong.
Dec 21 2020, 6:28 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) created T3143: OpenVPN server: Push route config format is wrong.
Dec 21 2020, 6:28 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) changed the status of T3142: OpenVPN op-command completion fails due to missing status file from Open to Needs testing.
Dec 21 2020, 5:58 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) claimed T3142: OpenVPN op-command completion fails due to missing status file.
Dec 21 2020, 11:03 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) created T3142: OpenVPN op-command completion fails due to missing status file.
Dec 21 2020, 11:00 AM · VyOS 1.3 Equuleus (1.3.0)
vegardx added a comment to T2206: Split WireGuard endpoint into proper host and port nodes.

This breaks with standard configuration convention in Wireguard. Also, no documentation has been updated to reflect this breaking change.

Dec 21 2020, 10:39 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2216: Containerized third-party applications for VyOS.

I want to know the behavior of the implementation when upgrading the vyos version

Dec 21 2020, 10:36 AM · VyOS 1.4 Sagitta
vegardx added a comment to T1807: Improve WireGuard CLI "endpoint" on.
Dec 21 2020, 10:32 AM · VyOS 1.3 Equuleus (1.3.0)

Dec 20 2020

c-po added a comment to T3134: DHCPv6 DUID configuration node missing.

It looks like wide dhcp client does not support setting the DUID as it is overwritten again after a restart :(

Dec 20 2020, 4:04 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3140: Relax "ethernet offload-options" CLI definition, a subtask of T1637: Rewrite ethernet interface in new style XML syntax, as Resolved.
Dec 20 2020, 2:31 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3140: Relax "ethernet offload-options" CLI definition as Resolved.
Dec 20 2020, 2:31 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3140: Relax "ethernet offload-options" CLI definition, a subtask of T1637: Rewrite ethernet interface in new style XML syntax, from Open to In progress.
Dec 20 2020, 1:44 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3140: Relax "ethernet offload-options" CLI definition from Open to In progress.
Dec 20 2020, 1:44 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3140: Relax "ethernet offload-options" CLI definition.
Dec 20 2020, 1:44 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3131: Typo in ipsec preshared-secret help as Resolved.
Dec 20 2020, 12:34 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3134: DHCPv6 DUID configuration node missing as Resolved.
Dec 20 2020, 11:56 AM · VyOS 1.3 Equuleus (1.3.0)

Dec 19 2020

francescocarzaniga updated the task description for T3139: Cannot create bond SR-IOV XCP-ng X540-T2.
Dec 19 2020, 11:53 PM · VyOS 1.3 Equuleus (1.3.0)
francescocarzaniga added a comment to T3139: Cannot create bond SR-IOV XCP-ng X540-T2.
Dec 19 2020, 11:08 PM · VyOS 1.3 Equuleus (1.3.0)
francescocarzaniga created T3139: Cannot create bond SR-IOV XCP-ng X540-T2.
Dec 19 2020, 10:40 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2216: Containerized third-party applications for VyOS.

PR https://github.com/vyos/vyos-build/pull/137
PR https://github.com/vyos/vyos-1x/pull/651

Dec 19 2020, 6:50 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T3137: Let VLAN aware bridge approach the behavior of professional equipment.

PR: https://github.com/vyos/vyos-1x/pull/650

Dec 19 2020, 6:37 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 changed the status of T3137: Let VLAN aware bridge approach the behavior of professional equipment from Confirmed to In progress.
Dec 19 2020, 2:38 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 edited a custom field on T3137: Let VLAN aware bridge approach the behavior of professional equipment.
Dec 19 2020, 1:27 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 claimed T3137: Let VLAN aware bridge approach the behavior of professional equipment.
Dec 19 2020, 1:07 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 changed the status of T3137: Let VLAN aware bridge approach the behavior of professional equipment from Open to Confirmed.
Dec 19 2020, 1:06 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 created T3137: Let VLAN aware bridge approach the behavior of professional equipment.
Dec 19 2020, 1:06 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Cheeze_It added a comment to T915: MPLS Support.

Put in a PR to add op commands for LDP.

Dec 19 2020, 3:39 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Dec 18 2020

SrividyaA added a comment to T3131: Typo in ipsec preshared-secret help.

PR:

Dec 18 2020, 10:57 AM · VyOS 1.3 Equuleus (1.3.0)
SrividyaA updated the task description for T3131: Typo in ipsec preshared-secret help.
Dec 18 2020, 10:56 AM · VyOS 1.3 Equuleus (1.3.0)
SrividyaA removed a project from T3131: Typo in ipsec preshared-secret help: VyOS 1.2 Crux.
Dec 18 2020, 10:55 AM · VyOS 1.3 Equuleus (1.3.0)

Dec 17 2020

c-po updated the task description for T3134: DHCPv6 DUID configuration node missing.
Dec 17 2020, 7:50 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T3134: DHCPv6 DUID configuration node missing.
Dec 17 2020, 7:49 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3134: DHCPv6 DUID configuration node missing.
Dec 17 2020, 7:49 PM · VyOS 1.3 Equuleus (1.3.0)
sempervictus added a comment to T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.

So how are userspace packages for this sort of stuff handled? I assume we need to itemize out individual phabricator tickets?
Off the top of my head, relevant things to add to uspace would be:

  1. eoip binary
  2. eoip CLI wrapper
  3. Xtables userspace with GeoIP table data and updater script (we would need to figure out how to deal with rule placement for persistence)
  4. Xtables-related CLI for firewall matching on GeoIP, DNS, etc
  5. Xtables-related CLI for firewall actions to TARPIT or DELUDE
  6. UKSM userspace (or just wrappers for the sysfs interface in CLI)
  7. Hardened Malloc with system-wide LD_PRELOAD or maintain a vyos-specific libc package with it built-in
Dec 17 2020, 7:04 PM · VyOS Rolling
c-po added a comment to T2666: Packet Processing with eBPF and XDP.

The CLI command set interfaces ethernet <interface> offload-options xdp enables the XDP generic mode on the given interface.

Dec 17 2020, 6:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2666: Packet Processing with eBPF and XDP from Open to Needs testing.
Dec 17 2020, 6:15 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T2036: Open Connect VPN Server () support as Resolved.
Dec 17 2020, 8:31 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T2810: Docs for vpn anyconnect-server, a subtask of T2036: Open Connect VPN Server () support, as Resolved.
Dec 17 2020, 8:31 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T2810: Docs for vpn anyconnect-server as Resolved.
Dec 17 2020, 8:31 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project

Dec 16 2020

Viacheslav assigned T3131: Typo in ipsec preshared-secret help to SrividyaA.
Dec 16 2020, 4:10 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a project to T3131: Typo in ipsec preshared-secret help: VyOS 1.3 Equuleus.
Dec 16 2020, 4:07 PM · VyOS 1.3 Equuleus (1.3.0)
vlesk added a comment to T3124: Cannot add user to group via configuration.

Ok. I will try to use containers, this good idea.
Containers will be more predictable and stable I suppose.

Dec 16 2020, 9:26 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3124: Cannot add user to group via configuration.

@vlesk once container support is added you have a better way by usibg a dedicates container on your VyOS installation.

Dec 16 2020, 7:17 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3124: Cannot add user to group via configuration.

If your device supports virtualization, you can consider running both VyOS and cups servers in KVM (there are many open source projects that can do this, such as Proxmox Ve)

Dec 16 2020, 7:07 AM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T2666: Packet Processing with eBPF and XDP.
Dec 16 2020, 7:00 AM · VyOS 1.3 Equuleus (1.3.0)
vlesk added a comment to T3124: Cannot add user to group via configuration.

Yes I know that I must install printer driver. I successfully solved this problem long time ago by using additional partition. And YES I KNOW that VyOS is not a general server operating system. But some time convenient use ONE universal host instead two or more.

Dec 16 2020, 6:34 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3124: Cannot add user to group via configuration.

Why install the remote print sharing service on the router and use cups, you must install the printer driver on the cups server to make it work. VyOS is not a general server operating system, so you should install cups on a physical server or virtual server

Dec 16 2020, 4:41 AM · VyOS 1.3 Equuleus (1.3.0)
vlesk added a comment to T3124: Cannot add user to group via configuration.

I prefer build images with some additional packages, such as cups. For example in order to administer printer I should add user to group lpadmin. In releases 1.2.x it was easy, but now I necessary after each update do it manually.

Dec 16 2020, 4:38 AM · VyOS 1.3 Equuleus (1.3.0)