Page MenuHomeVyOS Platform
Feed Search

Jul 1 2021

c-po moved T3083: Add feature event-handler from Open to Backlog on the VyOS 1.4 Sagitta board.
Jul 1 2021, 9:11 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

Jun 30 2021

fernando added a comment to T3655: NAT doesn't work correctly with VRF.

Hi ruben

Jun 30 2021, 10:52 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po changed the status of T3658: Add support for dhcpdv6 fixed-prefix6 from In progress to Needs testing.
Jun 30 2021, 6:43 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3658: Add support for dhcpdv6 fixed-prefix6 from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 30 2021, 6:43 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3658: Add support for dhcpdv6 fixed-prefix6 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 30 2021, 6:42 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
stepler added a comment to T3658: Add support for dhcpdv6 fixed-prefix6.

PR https://github.com/vyos/vyos-1x/pull/902
PR https://github.com/vyos/vyos-documentation/pull/561

Jun 30 2021, 5:23 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
stepler updated the task description for T3658: Add support for dhcpdv6 fixed-prefix6.
Jun 30 2021, 5:18 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
stepler changed the status of T3658: Add support for dhcpdv6 fixed-prefix6 from Open to In progress.
Jun 30 2021, 3:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
stepler created T3658: Add support for dhcpdv6 fixed-prefix6.
Jun 30 2021, 3:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
rherold added a comment to T3655: NAT doesn't work correctly with VRF.

It seems that what I thought is true:

Jun 30 2021, 2:17 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
rherold added a comment to T3655: NAT doesn't work correctly with VRF.

could this help https://patchwork.ozlabs.org/project/netfilter-devel/patch/776b8819c85c83088478b933a35691133055347a.1430733932.git.daniel@iogearbox.net ?

Jun 30 2021, 2:04 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
rherold added a comment to T3655: NAT doesn't work correctly with VRF.

as I wrote on slack, from my point of view it is a kernel problem. It seems that the conntrack in the kernel detects the packets eben if they come in on an input interface in default and so
the nat code won'T match cause for conntrack the outgoing interface is still eth0 which is in vrf OOBM instead pppoe0.

Jun 30 2021, 1:59 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando added a comment to T3655: NAT doesn't work correctly with VRF.

Hi ruben,

Jun 30 2021, 12:21 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Jun 29 2021

Unknown Object (User) changed the status of T3593: PPPoE server called-sid format does not work from Unknown Status to Resolved.
Jun 29 2021, 6:42 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Unknown Object (User) added projects to T3405: PPPoE server unit-cache: VyOS 1.3 Equuleus, Restricted Project.
Jun 29 2021, 6:13 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project, VyOS 1.4 Sagitta
jestabro updated the task description for T3651: Move certbot request to op-mode.
Jun 29 2021, 2:04 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
ropeguru added a comment to T1229: Add support for unencrypted L2TPv2 client connections.

Should I hold out any hope for this to be implemented? Still willing to help test and do whatever I can to get this in.

Jun 29 2021, 12:41 PM · VyOS Rolling
sarthurdev changed the status of T3642: PKI configuration, a subtask of T2799: VyOS Certificates Manager, from Open to In progress.
Jun 29 2021, 12:37 PM · VyOS 1.3 Equuleus (1.3.6)
zsdc assigned T3655: NAT doesn't work correctly with VRF to fernando.
Jun 29 2021, 12:06 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Jun 28 2021

Viacheslav changed the subtype of T3655: NAT doesn't work correctly with VRF from "Task" to "Bug".
Jun 28 2021, 5:56 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav added a comment to T3076: Router reboot adds unwanted 'conntrack-sync mcast-group '225.0.0.50'' line to configuration.

For 1.2.7 it adds unexpected multicast group per "save"
Configs for reproduce:

Jun 28 2021, 5:46 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T3045: Changes to Conntrack-Sync don't apply correctly (Mutlicast->UDP).

To reproduce (VyOS 1.3-beta-202106271614):

Jun 28 2021, 5:00 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.2 Crux (VyOS 1.2.9)
stepler added a comment to T3240: Support per-interface DHCPv6 DUIDs.

Verified working in GNS3 on 1.3.0-rc4. Note that /var/lib/dhcpv6/dhcp6c_duid is not used if send client-id is configured.

Jun 28 2021, 5:00 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a project to T3045: Changes to Conntrack-Sync don't apply correctly (Mutlicast->UDP): VyOS 1.2 Crux (VyOS 1.2.8).
Jun 28 2021, 4:46 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav edited projects for T3045: Changes to Conntrack-Sync don't apply correctly (Mutlicast->UDP), added: VyOS 1.3 Equuleus; removed VyOS 1.2 Crux.
Jun 28 2021, 4:45 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a subtask for T3076: Router reboot adds unwanted 'conntrack-sync mcast-group '225.0.0.50'' line to configuration: T3045: Changes to Conntrack-Sync don't apply correctly (Mutlicast->UDP).
Jun 28 2021, 4:45 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav edited projects for T3076: Router reboot adds unwanted 'conntrack-sync mcast-group '225.0.0.50'' line to configuration, added: VyOS 1.2 Crux (VyOS 1.2.8), VyOS 1.3 Equuleus; removed VyOS 1.2 Crux.
Jun 28 2021, 4:05 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Matwolf added a comment to T941: BGP neighbours with IPv6 link-local addresses.

Hi, any updates on this?

Jun 28 2021, 10:00 AM · VyOS 1.3 Equuleus (1.3.9), test

Jun 27 2021

UnicronNL closed T3653: Cloudinit subnet error if a cidr (/24) is used instead of a subnet mask (255.255.255.0) as Resolved.
Jun 27 2021, 6:54 PM · VyOS 1.2 Crux (VyOS 1.2.8)
UnicronNL updated the task description for T3653: Cloudinit subnet error if a cidr (/24) is used instead of a subnet mask (255.255.255.0).
Jun 27 2021, 3:19 PM · VyOS 1.2 Crux (VyOS 1.2.8)
UnicronNL triaged T3653: Cloudinit subnet error if a cidr (/24) is used instead of a subnet mask (255.255.255.0) as Urgent! priority.
Jun 27 2021, 3:18 PM · VyOS 1.2 Crux (VyOS 1.2.8)
c-po added a comment to T2770: Allow any character to be used in the SNMP community field.

What would be the "full set" up supported characters? If I remember correctly this regex is inherited from VyOS 1.1

Jun 27 2021, 7:42 AM · VyOS Rolling
c-po moved T2770: Allow any character to be used in the SNMP community field from Open to Backlog on the VyOS 1.4 Sagitta board.
Jun 27 2021, 7:42 AM · VyOS Rolling
c-po moved T3651: Move certbot request to op-mode from Open to Backlog on the VyOS 1.4 Sagitta board.
Jun 27 2021, 7:42 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
raphielscape added a comment to T2869: Intel ethernet driver defaults sub-optimal.

For RPS, we maybe can adapt https://github.com/bhuanand/rps-rfs-configuration to VyOS?

Jun 27 2021, 12:03 AM

Jun 26 2021

jestabro added a subtask for T2289: Denest cerbot certificate configuration from service https: T3651: Move certbot request to op-mode.
Jun 26 2021, 6:52 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
jestabro added a parent task for T3651: Move certbot request to op-mode: T2289: Denest cerbot certificate configuration from service https.
Jun 26 2021, 6:52 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
jestabro created T3651: Move certbot request to op-mode.
Jun 26 2021, 6:51 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta

Jun 25 2021

c-po closed T3650: OpenVPN: Upgrade package to 2.5.1 before releasing VyOS 1.3.0 as Resolved.
Jun 25 2021, 5:28 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T3650: OpenVPN: Upgrade package to 2.5.1 before releasing VyOS 1.3.0 from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 25 2021, 5:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T3650: OpenVPN: Upgrade package to 2.5.1 before releasing VyOS 1.3.0.
Jun 25 2021, 5:26 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3650: OpenVPN: Upgrade package to 2.5.1 before releasing VyOS 1.3.0 from Open to In progress.
Jun 25 2021, 5:20 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3650: OpenVPN: Upgrade package to 2.5.1 before releasing VyOS 1.3.0.
Jun 25 2021, 5:20 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3649: Add bonding additional hash-policy as Resolved.
Jun 25 2021, 4:58 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3649: Add bonding additional hash-policy from Open to Finished on the VyOS 1.4 Sagitta board.
Jun 25 2021, 4:58 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3649: Add bonding additional hash-policy from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 25 2021, 4:58 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T3649: Add bonding additional hash-policy.

PR https://github.com/vyos/vyos-1x/pull/898

Jun 25 2021, 3:35 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T3649: Add bonding additional hash-policy from Open to In progress.
Jun 25 2021, 8:49 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Unknown Object (User) created T3649: Add bonding additional hash-policy.
Jun 25 2021, 8:48 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Jun 24 2021

Viacheslav added a comment to T2661: SSTP wrong certificates check.

@Dmitry Is it an actual task? Code was rewritten.

Jun 24 2021, 8:38 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T2722: get_config_dict() and key_mangling=('-', '_') will alter CLI data for tagNodes as Resolved.

Already fixed with "no_tag_node_value_mangle=True"
https://github.com/vyos/vyos-1x/blob/705eddbc7a2caf09c37ecafb27418a764217975a/python/vyos/config.py#L218

Jun 24 2021, 8:33 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a project to T2770: Allow any character to be used in the SNMP community field: VyOS 1.4 Sagitta.
Jun 24 2021, 8:17 PM · VyOS Rolling
Viacheslav added a project to T2778: Migrate "system syslog" to get_config_dict() to support new features: VyOS 1.4 Sagitta.
Jun 24 2021, 8:10 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T2773: EIGRP support for VRF: VyOS 1.4 Sagitta.
Jun 24 2021, 8:10 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2773: EIGRP support for VRF.

Eigrp in the FRR doesn't work correctly.
The routes still live even if neighbors in a shutdown state.

Jun 24 2021, 8:09 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2771: BGP VPNv4 & VPNv6 Address Family Support.

@Cheeze_It can you re-check it?

Jun 24 2021, 8:04 PM · VyOS 1.3 Equuleus (1.3.5)
c-po added a parent task for T1512: vyos 1.2 openvpn client names with spaces created incorrectly: T3641: Upgrade base system from Debian Buster -> Debian Bullseye.
Jun 24 2021, 7:12 PM · VyOS 1.3 Equuleus (1.3.0), openvpn
Viacheslav added a comment to T3640: Allow resetting Wireguard interface.

There is a link to the existing code for configuration mode, not pr.
So we can to add the op-mode function to re-add/reset with a similar logic. Only thoughts

Jun 24 2021, 11:02 AM
mrozentsvayg added a comment to T3240: Support per-interface DHCPv6 DUIDs.

Not working for me as expected in 1.3.0-rc4
In my current working configuration, the duid is in the /var/lib/dhcpv6/dhcp6c_duid file (29 bytes).

Jun 24 2021, 3:00 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Jun 23 2021

hagbard added a comment to T3640: Allow resetting Wireguard interface.
Jun 23 2021, 7:13 PM
Viacheslav added a comment to T3638: Passwords With Dollar Sign Set Incorrectly.

Not sure about double quotes, but for example for cloud-init configs, it is necessary to use single quotes.
Ideally, the configuration should look like in show configuration commands

Jun 23 2021, 6:51 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3640: Allow resetting Wireguard interface.

I think it will be enough to remove the peer and add again.
@hagbard what do you think?
https://github.com/vyos/vyos-1x/blob/d48dddab0509e562209adfb115b0e691b8e47f54/python/vyos/ifconfig/wireguard.py#L197

Jun 23 2021, 6:41 PM
Viacheslav added a project to T1877: Feature Request: Allow NAT to use network and address groups: VyOS 1.4 Sagitta.
Jun 23 2021, 5:06 PM · VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.127 / 5.10.45 to Update Linux Kernel to v5.4.128 / 5.10.46.
Jun 23 2021, 4:54 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T3643: show vpn ipsec sa doesn't show tunnels in "down" state.

PR https://github.com/vyos/vyos-1x/pull/897
Fix path for swanctl.conf file

Jun 23 2021, 3:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
raphielscape added a comment to T3640: Allow resetting Wireguard interface.

Wireguard has no link states on the interface, the ip command just does an 'administrative' up down, which won't start a renegotiation. The policy description (remove peer) needs to be removed from the wg interface and re-added, otherwise you need to wait until wg tries to rekey which will then eventually renegotiate the entire connection.
The removal was as far as I recall part of the original vyos code, so it may have been removed at one point, I haven't looked into the code yet.

For NAT, try setting persistent-keepalive, that is supposed to keep the NAT entry active, even if you have no traffic for the tunnel.

Jun 23 2021, 3:14 PM
MaxiM added a comment to T1200: SNMP GET broken at least for BGP4-MIB.

@MaxiM In which exact version was a different behavior?

Jun 23 2021, 2:15 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.6)
hagbard added a comment to T3640: Allow resetting Wireguard interface.

Wireguard has no link states on the interface, the ip command just does an 'administrative' up down, which won't start a renegotiation. The policy description (remove peer) needs to be removed from the wg interface and re-added, otherwise you need to wait until wg tries to rekey which will then eventually renegotiate the entire connection.
The removal was as far as I recall part of the original vyos code, so it may have been removed at one point, I haven't looked into the code yet.

Jun 23 2021, 1:49 PM
raphielscape added a comment to T3640: Allow resetting Wireguard interface.
In T3640#96876, @c-po wrote:

If your host is behind NAT, could it possibly be that the NAT translation entry expired?

Does the following work:

ip link set dev wg0 down; ip link set dev wg0 up

Jun 23 2021, 6:23 AM
trae32566 added a comment to T3638: Passwords With Dollar Sign Set Incorrectly.

Try to set single quotes.

Jun 23 2021, 3:31 AM · VyOS 1.4 Sagitta

Jun 22 2021

fernando added a comment to T3638: Passwords With Dollar Sign Set Incorrectly.

yes, I am using the following version :

Jun 22 2021, 7:28 PM · VyOS 1.4 Sagitta
c-po added a comment to T3640: Allow resetting Wireguard interface.

If your host is behind NAT, could it possibly be that the NAT translation entry expired?

Jun 22 2021, 4:56 PM
Viacheslav closed T3582: 'delete log file' does not work as Resolved.
Jun 22 2021, 4:23 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav edited projects for T3582: 'delete log file' does not work, added: VyOS 1.2 Crux (VyOS 1.2.8); removed VyOS 1.2 Crux (VyOS 1.2.7).
Jun 22 2021, 4:22 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a comment to T1790: OSPF Exchanged Routes marked as invalid when run through a GRE PTMP/PTP OSPF between peers .

@SquirePug Can you check 1.2.7 release?

Jun 22 2021, 3:51 PM
raphielscape added a comment to T3640: Allow resetting Wireguard interface.

We don't use any configuration file for it, so I think we can't use wg-quick
We use "wg set"

$ sudo wg set --help
Usage: wg set <interface> [listen-port <port>] [fwmark <mark>] [private-key <file path>] [peer <base64 public key> [remove] [preshared-key <file path>] [endpoint <ip>:<port>] [persistent-keepalive <interval seconds>] [allowed-ips <ip1>/<cidr1>[,<ip2>/<cidr2>]...] ]...
Jun 22 2021, 3:37 PM
Viacheslav added a comment to T2892: Remove command: "set firewall options interface <interface> disable".

I don't see the reason to delete the "disable" option, as it uses for adjust-mss and adjust-mss6.
And you need temporarily disable it.

Jun 22 2021, 1:03 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav reassigned T3629: IPoE server shifting address in the range from Viacheslav to Unknown Object (User).
Jun 22 2021, 12:46 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T3629: IPoE server shifting address in the range as Resolved.
Jun 22 2021, 12:45 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav assigned T3643: show vpn ipsec sa doesn't show tunnels in "down" state to sarthurdev.
Jun 22 2021, 10:59 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a comment to T3638: Passwords With Dollar Sign Set Incorrectly.

Try to set single quotes.

Jun 22 2021, 10:13 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3643: show vpn ipsec sa doesn't show tunnels in "down" state.

Different format

vyos@r1-roll:~$ show vpn ipsec sa
Connection                State    Uptime    Bytes In/Out    Packets In/Out    Remote address    Remote ID    Proposal
------------------------  -------  --------  --------------  ----------------  ----------------  -----------  ----------
peer_192-0-2-2_tunnel_1   down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_10  down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_11  down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_12  down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_13  down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_14  down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_15  down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_16  down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_17  down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_18  down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_19  down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_2   down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_20  down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_3   down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_4   down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_5   down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_6   down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_7   down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_8   down     N/A       N/A             N/A               N/A               N/A          N/A
peer_192-0-2-2_tunnel_9   down     N/A       N/A             N/A               N/A               N/A          N/A
vyos@r1-roll:~$
Jun 22 2021, 10:07 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
trae32566 added a comment to T3638: Passwords With Dollar Sign Set Incorrectly.

Confirmed that's what is happening:

vyos@cr01a-vyos# TEST='variable'
[edit]
vyos@cr01a-vyos# set system login user vyos authentication plaintext-password HqNzXaK27k19$TEST
[edit]
vyos@cr01a-vyos# comp
[edit system login user vyos authentication]
+plaintext-password HqNzXaK27k19variable
Jun 22 2021, 8:35 AM · VyOS 1.4 Sagitta
trae32566 added a comment to T3638: Passwords With Dollar Sign Set Incorrectly.

@fernando Are you sure you're testing this on 1.3?

vyos@cr01a-vyos# run show ver
Jun 22 2021, 8:25 AM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3643: show vpn ipsec sa doesn't show tunnels in "down" state.

PR: https://github.com/vyos/vyos-1x/pull/894

Jun 22 2021, 7:44 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Jun 21 2021

fernando added a comment to T3638: Passwords With Dollar Sign Set Incorrectly.

I 've been checking this behavior with a different password , also I used the same password as you . But I couldn't reproduce the issue , both cases i add $ in the word and change the hash, let me show :

Jun 21 2021, 11:20 PM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3643: show vpn ipsec sa doesn't show tunnels in "down" state: T2816: Rewrite IPsec scripts with the new XML/Python approach.
Jun 21 2021, 8:57 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav updated the task description for T3643: show vpn ipsec sa doesn't show tunnels in "down" state.
Jun 21 2021, 8:56 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav renamed T3643: show vpn ipsec sa doesn't show tunnels in "down" state from show vpn ipsec sa doesn't show tunnel in "down" state to show vpn ipsec sa doesn't show tunnels in "down" state.
Jun 21 2021, 8:47 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav created T3643: show vpn ipsec sa doesn't show tunnels in "down" state.
Jun 21 2021, 8:46 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a subtask for T2799: VyOS Certificates Manager: T3642: PKI configuration.
Jun 21 2021, 6:08 PM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T3640: Allow resetting Wireguard interface.

We don't use any configuration file for it, so I think we can't use wg-quick
We use "wg set"

$ sudo wg set --help
Usage: wg set <interface> [listen-port <port>] [fwmark <mark>] [private-key <file path>] [peer <base64 public key> [remove] [preshared-key <file path>] [endpoint <ip>:<port>] [persistent-keepalive <interval seconds>] [allowed-ips <ip1>/<cidr1>[,<ip2>/<cidr2>]...] ]...
Jun 21 2021, 4:26 PM
raphielscape added a comment to T3640: Allow resetting Wireguard interface.

Is it helps in your case?

set interfaces wireguard wg0 disable 
commit
del interfaces wireguard wg0 disable 
commit

There is no any native command for reset wireguard interface in Linux (as I know). Also, we don't use any daemons which we can restart to "re-establish" session.
Is one host behind nat?

Jun 21 2021, 3:46 PM
erkin renamed T3378: commit-archive source-address broken for IPv6 addresses from commit-archive source-address Broken to commit-archive source-address broken for IPv6 addresses.
Jun 21 2021, 3:39 PM · VyOS 1.3 Equuleus (1.3.0)
erkin changed the subtype of T3378: commit-archive source-address broken for IPv6 addresses from "Task" to "Bug".
Jun 21 2021, 3:38 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3640: Allow resetting Wireguard interface.

Is it helps in your case?

set interfaces wireguard wg0 disable 
commit
del interfaces wireguard wg0 disable 
commit

There is no any native command for reset wireguard interface in Linux (as I know). Also, we don't use any daemons which we can restart to "re-establish" session.
Is one host behind nat?

Jun 21 2021, 2:48 PM

Jun 20 2021

raphielscape created T3640: Allow resetting Wireguard interface.
Jun 20 2021, 2:03 PM
c-po moved T1522: If a config session is not close cleanly, the unionfs-mount is not cleaned up from Open to Backlog on the VyOS 1.4 Sagitta board.
Jun 20 2021, 11:59 AM · Restricted Project, VyOS 1.5 Circinus
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.126 / 5.10.44 to Update Linux Kernel to v5.4.127 / 5.10.45.
Jun 20 2021, 11:59 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
erkin changed the subtype of T1522: If a config session is not close cleanly, the unionfs-mount is not cleaned up from "Task" to "Bug".
Jun 20 2021, 10:57 AM · Restricted Project, VyOS 1.5 Circinus