Page MenuHomeVyOS Platform
Feed Search

Jun 10 2021

Viacheslav added a parent task for T3613: Selectors for route-based IPsec tunnel (vti): T2816: Rewrite IPsec scripts with the new XML/Python approach.
Jun 10 2021, 8:36 PM · VyOS 1.4 Sagitta
krox2 updated the task description for T3613: Selectors for route-based IPsec tunnel (vti).
Jun 10 2021, 8:19 PM · VyOS 1.4 Sagitta
krox2 updated the task description for T3613: Selectors for route-based IPsec tunnel (vti).
Jun 10 2021, 8:18 PM · VyOS 1.4 Sagitta
krox2 created T3613: Selectors for route-based IPsec tunnel (vti).
Jun 10 2021, 8:17 PM · VyOS 1.4 Sagitta
Viacheslav closed T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting as Resolved.
Jun 10 2021, 8:16 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav closed T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 10 2021, 8:16 PM · VyOS 1.4 Sagitta
Viacheslav moved T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting from Backport Candidates to Finished on the VyOS 1.3 Equuleus board.
Jun 10 2021, 8:16 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po changed the status of T3250: PPPoE server: wrong local usernames from Unknown Status to Resolved.
Jun 10 2021, 7:24 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3250: PPPoE server: wrong local usernames from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2021, 7:24 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3250: PPPoE server: wrong local usernames from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 10 2021, 7:24 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro added a comment to T3250: PPPoE server: wrong local usernames.

Already backported: ff7b2b0e62510ef8de28c9c4bfa34badeabec775

Jun 10 2021, 6:59 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T2717: Wrong DHCP server pool size in statistics from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2021, 5:52 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po moved T2717: Wrong DHCP server pool size in statistics from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 10 2021, 5:52 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po moved T2717: Wrong DHCP server pool size in statistics from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.8) board.
Jun 10 2021, 5:52 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po added projects to T2717: Wrong DHCP server pool size in statistics: VyOS 1.4 Sagitta, VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.8).
Jun 10 2021, 5:51 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po closed T3138: ddclient improperly updated when apply rfc2136 config as Resolved.
Jun 10 2021, 5:49 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3138: ddclient improperly updated when apply rfc2136 config from Backport Candidates to Finished on the VyOS 1.4 Sagitta board.
Jun 10 2021, 5:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3138: ddclient improperly updated when apply rfc2136 config from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 10 2021, 5:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.124 / 5.10.42 to Update Linux Kernel to v5.4.125 / 5.10.43.
Jun 10 2021, 5:14 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po changed the status of T3611: WWAN interface (MC7710) no longer works on Kernel 5.10 from Open to In progress.
Jun 10 2021, 5:10 PM · VyOS 1.4 Sagitta
c-po created T3611: WWAN interface (MC7710) no longer works on Kernel 5.10.
Jun 10 2021, 5:10 PM · VyOS 1.4 Sagitta
c-po added a comment to T3250: PPPoE server: wrong local usernames.

no_tag_node_value_mangle=True does not exist on VyOS 1.3, thus a backport is currently not possible. @jestabro can we backport this?

Jun 10 2021, 5:06 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
trae32566 closed T2645: Editing route-map action requires adding a new rule as Resolved.
Jun 10 2021, 4:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
tsantiago.work added a comment to T2645: Editing route-map action requires adding a new rule.

@Viacheslav This is confirmed fixed, I'm guessing it got fixed during the period between reporting it and now.

Jun 10 2021, 4:46 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a comment to T2645: Editing route-map action requires adding a new rule.

I can't reproduce it, VyOS 1.3-beta-202106081558

set policy prefix-list FOO rule 10 action 'permit'
set policy prefix-list FOO rule 10 prefix '0.0.0.0/0'
set policy route-map FOO rule 10 action 'permit'
set policy route-map FOO rule 10 match ip address prefix-list 'FOO'
set policy route-map FOO rule 10 set distance '220'
set policy route-map FOO rule 1000 action 'permit'
Jun 10 2021, 11:55 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Jun 9 2021

Viacheslav added a comment to T3610: DHCP-Server creation for not primary IP address fails.

@n.fort You can try to replace True with False there (1.3 and 1.4). But it needs more tests. In some cases, it was some bugs with the DHCP server and not the primary address.
https://github.com/vyos/vyos-1x/blob/5d068442cf7b1863724c83168176ce2940a023fe/src/conf_mode/dhcp_server.py#L237

Jun 9 2021, 6:52 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
Viacheslav moved T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting from Need Triage to Backport Candidates on the VyOS 1.3 Equuleus board.
Jun 9 2021, 5:02 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav moved T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting from Backport Candidates to Finished on the VyOS 1.4 Sagitta board.
Jun 9 2021, 5:02 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a comment to T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting.

VyOS 1.3-beta-202106081558
Works as expected.

Jun  9 19:57:38 r4-1 charon: 13[CFG] no IKE_SA named 'peer-192.0.2.2-tunnel-0' found
Jun  9 19:57:38 r4-1 charon: 14[CFG] received stroke: initiate 'peer-192.0.2.2-tunnel-0'
Jun  9 19:57:38 r4-1 charon: 06[IKE] <peer-192.0.2.2-tunnel-0|4> initiating Main Mode IKE_SA peer-192.0.2.2-tunnel-0[4] to 192.0.2.2
Jun  9 19:57:38 r4-1 charon: 06[ENC] <peer-192.0.2.2-tunnel-0|4> generating ID_PROT request 0 [ SA V V V V V ]
Jun  9 19:57:38 r4-1 charon: 06[NET] <peer-192.0.2.2-tunnel-0|4> sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (180 bytes)
Jun  9 19:57:38 r4-1 charon: 07[NET] <peer-192.0.2.2-tunnel-0|4> received packet: from 192.0.2.2[500] to 192.0.2.1[500] (160 bytes)
Jun  9 19:57:38 r4-1 charon: 07[ENC] <peer-192.0.2.2-tunnel-0|4> parsed ID_PROT response 0 [ SA V V V V ]
Jun  9 19:57:38 r4-1 charon: 07[IKE] <peer-192.0.2.2-tunnel-0|4> received XAuth vendor ID
Jun  9 19:57:38 r4-1 charon: 07[IKE] <peer-192.0.2.2-tunnel-0|4> received DPD vendor ID
Jun  9 19:57:38 r4-1 charon: 07[IKE] <peer-192.0.2.2-tunnel-0|4> received FRAGMENTATION vendor ID
Jun  9 19:57:38 r4-1 charon: 07[IKE] <peer-192.0.2.2-tunnel-0|4> received NAT-T (RFC 3947) vendor ID
Jun  9 19:57:38 r4-1 charon: 07[CFG] <peer-192.0.2.2-tunnel-0|4> selected proposal: IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
Jun  9 19:57:38 r4-1 charon: 07[ENC] <peer-192.0.2.2-tunnel-0|4> generating ID_PROT request 0 [ KE No NAT-D NAT-D ]
Jun  9 19:57:38 r4-1 charon: 07[NET] <peer-192.0.2.2-tunnel-0|4> sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (244 bytes)
Jun  9 19:57:38 r4-1 charon: 05[NET] <peer-192.0.2.2-tunnel-0|4> received packet: from 192.0.2.2[500] to 192.0.2.1[500] (244 bytes)
Jun  9 19:57:38 r4-1 charon: 05[ENC] <peer-192.0.2.2-tunnel-0|4> parsed ID_PROT response 0 [ KE No NAT-D NAT-D ]
Jun  9 19:57:38 r4-1 charon: 05[ENC] <peer-192.0.2.2-tunnel-0|4> generating ID_PROT request 0 [ ID HASH N(INITIAL_CONTACT) ]
Jun  9 19:57:38 r4-1 charon: 05[NET] <peer-192.0.2.2-tunnel-0|4> sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (108 bytes)
Jun  9 19:57:38 r4-1 charon: 08[NET] <peer-192.0.2.2-tunnel-0|4> received packet: from 192.0.2.2[500] to 192.0.2.1[500] (76 bytes)
Jun  9 19:57:38 r4-1 charon: 08[ENC] <peer-192.0.2.2-tunnel-0|4> parsed ID_PROT response 0 [ ID HASH ]
Jun  9 19:57:38 r4-1 charon: 08[IKE] <peer-192.0.2.2-tunnel-0|4> IKE_SA peer-192.0.2.2-tunnel-0[4] established between 192.0.2.1[192.0.2.1]...192.0.2.2[192.0.2.2]
Jun  9 19:57:38 r4-1 charon: 08[IKE] <peer-192.0.2.2-tunnel-0|4> scheduling reauthentication in 2524s
Jun  9 19:57:38 r4-1 charon: 08[IKE] <peer-192.0.2.2-tunnel-0|4> maximum IKE_SA lifetime 3064s
Jun  9 19:57:38 r4-1 charon: 08[ENC] <peer-192.0.2.2-tunnel-0|4> generating QUICK_MODE request 364019988 [ HASH SA No KE ID ID ]
Jun  9 19:57:38 r4-1 charon: 08[NET] <peer-192.0.2.2-tunnel-0|4> sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (316 bytes)
Jun  9 19:57:38 r4-1 charon: 09[NET] <peer-192.0.2.2-tunnel-0|4> received packet: from 192.0.2.2[500] to 192.0.2.1[500] (316 bytes)
Jun  9 19:57:38 r4-1 charon: 09[ENC] <peer-192.0.2.2-tunnel-0|4> parsed QUICK_MODE response 364019988 [ HASH SA No KE ID ID ]
Jun  9 19:57:38 r4-1 charon: 09[CFG] <peer-192.0.2.2-tunnel-0|4> selected proposal: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1024/NO_EXT_SEQ
Jun  9 19:57:38 r4-1 charon: 09[IKE] <peer-192.0.2.2-tunnel-0|4> CHILD_SA peer-192.0.2.2-tunnel-0{1} established with SPIs cb0aa83a_i c728156c_o and TS 10.1.0.0/24 === 10.2.3.0/24
Jun  9 19:57:38 r4-1 charon: 09[ENC] <peer-192.0.2.2-tunnel-0|4> generating QUICK_MODE request 364019988 [ HASH ]
Jun  9 19:57:38 r4-1 charon: 09[NET] <peer-192.0.2.2-tunnel-0|4> sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (60 bytes)
[email protected]:~$
Jun 9 2021, 4:59 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a comment to T2855: disabled vti interfaces still working.

Ok it already fixed in 1.3 T2916 and can be migrated to crux

Jun 9 2021, 4:27 PM · VyOS 1.2 Crux (VyOS 1.2.8)
n.fort created T3610: DHCP-Server creation for not primary IP address fails.
Jun 9 2021, 3:35 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
jestabro added a comment to T3574: Add constraintGroup for combining validators with logical AND.

Draft PRs:
https://github.com/vyos/vyos-utils/pull/1
https://github.com/vyos/vyos-1x/pull/869

Jun 9 2021, 1:08 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Harliff added a comment to T2855: disabled vti interfaces still working.

I can't reproduce it in 1.2.7

Jun 9 2021, 8:48 AM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav closed T3602: Renaming BGP Peer Groups Leaves Router Broken, a subtask of T3182: Main blocker Task for FRR 7.4/7.5 series update, as Resolved.
Jun 9 2021, 7:02 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Jun 8 2021

c-po updated the task description for T2816: Rewrite IPsec scripts with the new XML/Python approach.
Jun 8 2021, 5:53 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T3608: Standardize warnings from configure scripts.
Jun 8 2021, 4:50 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
jestabro triaged T3608: Standardize warnings from configure scripts as Normal priority.
Jun 8 2021, 4:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
erkin changed the status of T3378: commit-archive source-address broken for IPv6 addresses, a subtask of T3356: Script for remote file transfers, from Open to Needs testing.
Jun 8 2021, 2:31 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin changed the status of T3378: commit-archive source-address broken for IPv6 addresses from Open to Needs testing.

This is resolved for 1.4. Do you still have this problem in 1.3 as of RC4? If so, I'll need to backport the changes.

Jun 8 2021, 2:31 PM · VyOS 1.3 Equuleus (1.3.0)
erkin closed T3563: commit-archive breaks with IPv6 source addresses, a subtask of T3356: Script for remote file transfers, as Resolved.
Jun 8 2021, 2:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3563: commit-archive breaks with IPv6 source addresses as Resolved.
Jun 8 2021, 2:20 PM · VyOS 1.4 Sagitta
Viacheslav moved T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting from Open to Backport Candidates on the VyOS 1.4 Sagitta board.
Jun 8 2021, 10:53 AM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a project to T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting: VyOS 1.2 Crux (VyOS 1.2.8).
Jun 8 2021, 10:49 AM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav changed the status of T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, from Open to Needs testing.
Jun 8 2021, 9:14 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting from Open to Needs testing.
Jun 8 2021, 9:14 AM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po closed T3605: Allow to set prefer-global for ipv6-next-hop as Resolved.
Jun 8 2021, 6:25 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3605: Allow to set prefer-global for ipv6-next-hop from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 8 2021, 6:25 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3605: Allow to set prefer-global for ipv6-next-hop from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 8 2021, 6:25 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added projects to T3605: Allow to set prefer-global for ipv6-next-hop: VyOS 1.3 Equuleus, VyOS 1.4 Sagitta.
Jun 8 2021, 6:25 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po closed T3607: [route-map] set ipv6 next-hop prefer-global as Resolved.
Jun 8 2021, 6:24 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3607: [route-map] set ipv6 next-hop prefer-global from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 8 2021, 6:23 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3607: [route-map] set ipv6 next-hop prefer-global from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 8 2021, 6:23 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added a project to T3607: [route-map] set ipv6 next-hop prefer-global: VyOS 1.3 Equuleus.
Jun 8 2021, 6:23 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po assigned T3607: [route-map] set ipv6 next-hop prefer-global to fernando.
Jun 8 2021, 6:18 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po closed T3289: No description for node "service" conf-mode as Resolved.
Jun 8 2021, 6:17 AM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.4 Sagitta
c-po changed the status of T3289: No description for node "service" conf-mode from Confirmed to In progress.
Jun 8 2021, 5:59 AM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.4 Sagitta

Jun 7 2021

fernando renamed T3607: [route-map] set ipv6 next-hop prefer-global from [route-mapset ipv6 next-hop prefer-global to [route-map] set ipv6 next-hop prefer-global.
Jun 7 2021, 11:59 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
fernando created T3607: [route-map] set ipv6 next-hop prefer-global.
Jun 7 2021, 11:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav moved T3289: No description for node "service" conf-mode from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 7 2021, 11:15 PM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.4 Sagitta
Viacheslav closed T3455: system users can not be added in "edit" as Resolved.
Jun 7 2021, 11:12 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the status of T3461: OpenConnect Server redundancy check from Unknown Status to Resolved.
Jun 7 2021, 11:10 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav created T3606: SNMP unknown notification OID.
Jun 7 2021, 10:37 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting.

PR https://github.com/vyos/vyos-build/pull/169

Jun  8 00:59:20 r1-roll ipsec_starter[2373]: charon (2374) started after 400 ms
Jun  8 00:59:20 r1-roll charon: 05[CFG] received stroke: add connection 'peer-192.0.2.2-tunnel-0'
Jun  8 00:59:20 r1-roll charon: 05[CFG] added configuration 'peer-192.0.2.2-tunnel-0'
Jun  8 00:59:20 r1-roll charon: 07[CFG] received stroke: initiate 'peer-192.0.2.2-tunnel-0'
Jun  8 00:59:20 r1-roll charon: 07[IKE] <peer-192.0.2.2-tunnel-0|1> initiating Main Mode IKE_SA peer-192.0.2.2-tunnel-0[1] to 192.0.2.2
Jun  8 00:59:20 r1-roll charon: 07[ENC] <peer-192.0.2.2-tunnel-0|1> generating ID_PROT request 0 [ SA V V V V V ]
Jun  8 00:59:20 r1-roll charon: 07[NET] <peer-192.0.2.2-tunnel-0|1> sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (180 bytes)
Jun  8 00:59:20 r1-roll charon: 09[NET] <peer-192.0.2.2-tunnel-0|1> received packet: from 192.0.2.2[500] to 192.0.2.1[500] (160 bytes)
Jun  8 00:59:20 r1-roll charon: 09[ENC] <peer-192.0.2.2-tunnel-0|1> parsed ID_PROT response 0 [ SA V V V V ]
Jun  8 00:59:20 r1-roll charon: 09[IKE] <peer-192.0.2.2-tunnel-0|1> received XAuth vendor ID
Jun  8 00:59:20 r1-roll charon: 09[IKE] <peer-192.0.2.2-tunnel-0|1> received DPD vendor ID
Jun  8 00:59:20 r1-roll charon: 09[IKE] <peer-192.0.2.2-tunnel-0|1> received FRAGMENTATION vendor ID
Jun  8 00:59:20 r1-roll charon: 09[IKE] <peer-192.0.2.2-tunnel-0|1> received NAT-T (RFC 3947) vendor ID
Jun  8 00:59:20 r1-roll charon: 09[CFG] <peer-192.0.2.2-tunnel-0|1> selected proposal: IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
Jun  8 00:59:20 r1-roll charon: 09[ENC] <peer-192.0.2.2-tunnel-0|1> generating ID_PROT request 0 [ KE No NAT-D NAT-D ]
Jun  8 00:59:20 r1-roll charon: 09[NET] <peer-192.0.2.2-tunnel-0|1> sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (244 bytes)
Jun  8 00:59:20 r1-roll charon: 10[NET] <peer-192.0.2.2-tunnel-0|1> received packet: from 192.0.2.2[500] to 192.0.2.1[500] (244 bytes)
Jun  8 00:59:20 r1-roll charon: 10[ENC] <peer-192.0.2.2-tunnel-0|1> parsed ID_PROT response 0 [ KE No NAT-D NAT-D ]
Jun  8 00:59:20 r1-roll charon: 10[ENC] <peer-192.0.2.2-tunnel-0|1> generating ID_PROT request 0 [ ID HASH N(INITIAL_CONTACT) ]
Jun  8 00:59:20 r1-roll charon: 10[NET] <peer-192.0.2.2-tunnel-0|1> sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (108 bytes)
Jun  8 00:59:20 r1-roll charon: 11[NET] <peer-192.0.2.2-tunnel-0|1> received packet: from 192.0.2.2[500] to 192.0.2.1[500] (76 bytes)
Jun  8 00:59:20 r1-roll charon: 11[ENC] <peer-192.0.2.2-tunnel-0|1> parsed ID_PROT response 0 [ ID HASH ]
Jun  8 00:59:20 r1-roll charon: 11[IKE] <peer-192.0.2.2-tunnel-0|1> IKE_SA peer-192.0.2.2-tunnel-0[1] established between 192.0.2.1[192.0.2.1]...192.0.2.2[192.0.2.2]
Jun  8 00:59:20 r1-roll charon: 11[IKE] <peer-192.0.2.2-tunnel-0|1> scheduling rekeying in 2720s
Jun  8 00:59:20 r1-roll charon: 11[IKE] <peer-192.0.2.2-tunnel-0|1> maximum IKE_SA lifetime 3260s
Jun  8 00:59:20 r1-roll charon: 11[ENC] <peer-192.0.2.2-tunnel-0|1> generating QUICK_MODE request 3783917425 [ HASH SA No KE ID ID ]
Jun  8 00:59:20 r1-roll charon: 11[NET] <peer-192.0.2.2-tunnel-0|1> sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (316 bytes)
Jun  8 00:59:20 r1-roll charon: 12[NET] <peer-192.0.2.2-tunnel-0|1> received packet: from 192.0.2.2[500] to 192.0.2.1[500] (316 bytes)
Jun  8 00:59:20 r1-roll charon: 12[ENC] <peer-192.0.2.2-tunnel-0|1> parsed QUICK_MODE response 3783917425 [ HASH SA No KE ID ID ]
Jun  8 00:59:20 r1-roll charon: 12[CFG] <peer-192.0.2.2-tunnel-0|1> selected proposal: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1024/NO_EXT_SEQ
Jun  8 00:59:20 r1-roll charon: 12[IKE] <peer-192.0.2.2-tunnel-0|1> CHILD_SA peer-192.0.2.2-tunnel-0{1} established with SPIs c4d940b7_i c9a69e83_o and TS 10.1.0.0/24 === 10.2.3.0/24
Jun  8 00:59:20 r1-roll charon: 12[ENC] <peer-192.0.2.2-tunnel-0|1> generating QUICK_MODE request 3783917425 [ HASH ]
Jun  8 00:59:20 r1-roll charon: 12[NET] <peer-192.0.2.2-tunnel-0|1> sending packet: from 192.0.2.1[500] to 192.0.2.2[500] (60 bytes)
Jun 7 2021, 10:22 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a project to T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting: VyOS 1.4 Sagitta.
Jun 7 2021, 8:50 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav closed T3358: VRRP: Is it necessary to support switches between master and backup with script? as Invalid.

@arvin This functions in all versions of VyOS.

Jun 7 2021, 7:08 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T2763: New SNMP resource request - SNMP over TCP from "Task" to "Feature Request".
Jun 7 2021, 6:35 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
UnicronNL claimed T3339: Cloud-Init domain search setting not applied.
Jun 7 2021, 6:32 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav added a comment to T2855: disabled vti interfaces still working.

I can't reproduce it in 1.2.7 and VyOS 1.3-beta-202105272051

Jun 7 2021, 6:25 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a comment to T3017: bridge will lose the tuntap member after reboots.

@jingyun Can you describe steps on how to reproduce it? Or re-check it.
My test config after reboot works fine

set interfaces bridge br0 member interface tun0
set interfaces tunnel tun0 encapsulation 'gre-bridge'
set interfaces tunnel tun0 local-ip '100.64.0.1'
set interfaces tunnel tun0 remote-ip '100.64.0.254'
Jun 7 2021, 6:08 PM · Invalid
Viacheslav moved T3138: ddclient improperly updated when apply rfc2136 config from Open to Backport Candidates on the VyOS 1.4 Sagitta board.
Jun 7 2021, 5:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po closed T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 7 2021, 5:10 PM · VyOS 1.4 Sagitta
c-po closed T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan as Resolved.
Jun 7 2021, 5:10 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 7 2021, 5:09 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3602: Renaming BGP Peer Groups Leaves Router Broken, a subtask of T3182: Main blocker Task for FRR 7.4/7.5 series update, from Open to Needs testing.
Jun 7 2021, 4:40 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T3516: FRR 7.5 adds a second route when you attempt to change a static route distance instead of overwriting the old route, a subtask of T3182: Main blocker Task for FRR 7.4/7.5 series update, as Resolved.
Jun 7 2021, 4:39 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a subtask for T3182: Main blocker Task for FRR 7.4/7.5 series update: T3602: Renaming BGP Peer Groups Leaves Router Broken.
Jun 7 2021, 2:44 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

In the crux.

set system conntrack timeout custom rule 10 destination address '203.0.113.74'
set system conntrack timeout custom rule 10 destination port '80'
set system conntrack timeout custom rule 10 protocol tcp established '300'
set system conntrack timeout custom rule 10 source address '192.0.2.168'

commit

vyos@r2-lts# commit
[ system conntrack hash-size 32768 ]
Updated conntrack hash size. This change will take affect when the system is rebooted.
Jun 7 2021, 12:39 PM · VyOS 1.4 Sagitta
anthr76 added a comment to T3600: DHCP Interface static route breaks PBR.

It looks like your assessment is correct. It also seems like next-hop IP would be sufficient as well if I wasn't dealing with dynamic WAN IPs. For the moment I'm sticking with interface instead of dhcp-interface. The related issue you sent seems exactly related to this.

Jun 7 2021, 11:55 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T3505: Commits do not respect changes in FRR that are not stored in a config: T3600: DHCP Interface static route breaks PBR.
Jun 7 2021, 9:17 AM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a parent task for T3600: DHCP Interface static route breaks PBR: T3505: Commits do not respect changes in FRR that are not stored in a config.
Jun 7 2021, 9:17 AM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.

Clarifying as requested by c-po:

Jun 7 2021, 9:12 AM · VyOS 1.4 Sagitta
vindenesen added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

I believe I have found out why modification/deletion of rules fails. This is the rule definition in iptables:

Jun 7 2021, 9:10 AM · VyOS 1.4 Sagitta

Jun 6 2021

fernando added a comment to T3600: DHCP Interface static route breaks PBR.

I think it is also related https://phabricator.vyos.net/T3522

Jun 6 2021, 9:53 PM · VyOS 1.4 Sagitta
fernando added a comment to T3600: DHCP Interface static route breaks PBR.

I have checked that functionality , i can replicate the issues .although there is a workaround if you "set protocols static table 11 route 0.0.0.0/0 dhcp-interface " any interfaces , it doesn't see in your table ( table 10 /11 ) we can see theses routes in the default table , let me show :

Jun 6 2021, 9:50 PM · VyOS 1.4 Sagitta
c-po closed T842: Adopt VyOS CLI to latest StrongSwan options and deprecated Keywords, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 6 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po closed T842: Adopt VyOS CLI to latest StrongSwan options and deprecated Keywords, a subtask of T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan, as Resolved.
Jun 6 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po closed T842: Adopt VyOS CLI to latest StrongSwan options and deprecated Keywords as Resolved.
Jun 6 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 6 2021, 5:17 PM · VyOS 1.4 Sagitta
erkin claimed T3459: Inform the user when unable to install outdated image.
Jun 6 2021, 2:21 PM · VyOS 1.4 Sagitta
UnicronNL triaged T3601: Error in ssh keys for vmware cloud-init if ssh keys is left empty. as Normal priority.
Jun 6 2021, 1:09 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 6 2021, 9:11 AM · VyOS 1.4 Sagitta

Jun 5 2021

anthr76 created T3600: DHCP Interface static route breaks PBR.
Jun 5 2021, 11:41 PM · VyOS 1.4 Sagitta

Jun 4 2021

sarthurdev changed the status of T3599: Migrate NHRP to XML/Python from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/865

Jun 4 2021, 9:55 PM · VyOS 1.4 Sagitta
c-po closed T3595: Cannot create new VTI interface, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 4 2021, 5:34 PM · VyOS 1.4 Sagitta
c-po closed T3595: Cannot create new VTI interface as Resolved.
Jun 4 2021, 5:34 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 4 2021, 5:33 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T3599: Migrate NHRP to XML/Python from Open to In progress.
Jun 4 2021, 5:28 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T3596: Support wide-dhcp6-relay.

I wonder why this is flagged only as refactoring bit you open an entire new CLI tree.

Jun 4 2021, 2:34 PM
c-po added a comment to T3596: Support wide-dhcp6-relay.

Hi Jack,

Jun 4 2021, 2:04 PM
jack9603301 added a comment to T3596: Support wide-dhcp6-relay.

PR draft: https://github.com/vyos/vyos-1x/pull/863

Jun 4 2021, 1:08 PM