Page MenuHomeVyOS Platform
Feed All Stories

Jan 9 2022

Viacheslav committed rVYOSONEXfb464f0b7654: keepalived: T4150: Fix template option conntrack_sync_group.
Jan 9 2022, 7:52 PM
GitHub <[email protected]> committed rVYOSONEX897510fe6fdf: Merge pull request #1142 from sever-sever/T4150 (authored by c-po).
Jan 9 2022, 7:52 PM
Viacheslav committed rVYOSONEXd997874deb61: nhrp: T4152: Fix template holding-time for nhrp.
Jan 9 2022, 7:46 PM
GitHub <[email protected]> committed rVYOSONEX17ea91accc4b: Merge pull request #1145 from sever-sever/T4152 (authored by c-po).
Jan 9 2022, 7:46 PM
Viacheslav updated subscribers of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases .
Jan 9 2022, 7:43 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases from "Task" to "Bug".
Jan 9 2022, 7:40 PM · VyOS 1.4 Sagitta
n.fort added a comment to T3115: Add support for firewall on L3 VIF bridge interface.

Filtering tested on version 1.4-rolling-202201060842

Jan 9 2022, 7:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
hensur added a comment to T2898: Support NDP proxy.

I revisited this in: https://github.com/vyos/vyos-1x/pull/1147

Jan 9 2022, 6:43 PM · VyOS 1.4 Sagitta
johannrichard updated the task description for T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases .
Jan 9 2022, 6:32 PM · VyOS 1.4 Sagitta
johannrichard created T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases .
Jan 9 2022, 6:30 PM · VyOS 1.4 Sagitta
aha added a comment to T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0.

@Viacheslav Yes, You're right.
in.tftpd got started (but only a few seconds).

Jan 9 2022, 6:22 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
n.fort added a comment to T4072: Feature Request: Firewall on bridge interfaces.

Scenario proposed by @NikolayP gives next content in table ip filter:

Jan 9 2022, 6:18 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3706: Add proper priorities for systemd daemons.

A simple check works fine:
Set 20% quota for snmpd
And check it with script:

#!/usr/bin/env bash
Jan 9 2022, 5:12 PM · Bugs, VyOS Rolling
Viacheslav added a comment to T3706: Add proper priorities for systemd daemons.

https://www.freedesktop.org/software/systemd/man/systemd.resource-control.html

Jan 9 2022, 4:53 PM · Bugs, VyOS Rolling
Viacheslav changed the status of T3774: atop logs are not limited in size from In progress to Needs testing.
Jan 9 2022, 4:39 PM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav closed T3822: OpenVPN processes do not have permission to read key files generated with `run generate openvpn key` as Resolved.

It was fixed in above commits, wrong testing form my site.

Jan 9 2022, 4:28 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0.

@aha As I see tftp can't bind ipv6 link local address:

Jan 9 2022, 3:54 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav edited projects for T3299: Allow the web proxy service to listen on all IP addresses, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus (1.3.0).
Jan 9 2022, 2:56 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T3299: Allow the web proxy service to listen on all IP addresses.

Cherry-pick PR https://github.com/vyos/vyos-1x/pull/1146

Jan 9 2022, 2:56 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4100: Firewall increase maximum number of rules.

It requires checking for 1.3 as it was changed and it uses the old backend on Perl (links above).

Jan 9 2022, 2:31 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
n.fort added a comment to T4100: Firewall increase maximum number of rules.
vyos@vyos# run show config comm | grep fire
set firewall name FOO default-action 'accept'
set firewall name FOO rule 10 action 'accept'
set firewall name FOO rule 10 source address '198.51.100.0/24'
set firewall name FOO rule 999997 action 'drop'
set firewall name FOO rule 999997 source address '203.0.113.0/24'
[edit]
Jan 9 2022, 2:24 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4153: Monitor bandwidth-test initiate not working.

It seems -V option:

Jan 9 2022, 2:24 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort added a comment to T4100: Firewall increase maximum number of rules.
Jan 9 2022, 2:20 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a project to T4154: Error add second gre tunnel with the same source interface: VyOS 1.3 Equuleus ( 1.3.1).
Jan 9 2022, 2:08 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav created T4154: Error add second gre tunnel with the same source interface.
Jan 9 2022, 2:08 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
n.fort created T4153: Monitor bandwidth-test initiate not working.
Jan 9 2022, 2:06 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav moved T4142: Input ifbX interfaces not displayed in op-mode from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 9 2022, 2:02 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4142: Input ifbX interfaces not displayed in op-mode as Resolved.
Jan 9 2022, 2:01 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4152: NHRP shortcut-target holding-time does not work.

PR for 1.3 https://github.com/vyos/vyos-nhrp/pull/7

Jan 9 2022, 1:50 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4152: NHRP shortcut-target holding-time does not work.

PR for 1.4 https://github.com/vyos/vyos-1x/pull/1145

Jan 9 2022, 12:42 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4152: NHRP shortcut-target holding-time does not work from Open to In progress.
Jan 9 2022, 12:19 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4100: Firewall increase maximum number of rules.

Check a real generated firewall iptables/nftables config
As 10000 it is the latest default rule, so your rules can be applied after default action with seq 10000

Jan 9 2022, 9:36 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4087: IPsec IKE-group proposals limit of 10 pieces from Open to Needs testing.
Jan 9 2022, 7:45 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a project to T4087: IPsec IKE-group proposals limit of 10 pieces : VyOS 1.4 Sagitta.

Could you also create a pr for 1.4?
Or 1.4 doesn’t have such limits?

Jan 9 2022, 7:44 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)
Viacheslav added a comment to T4072: Feature Request: Firewall on bridge interfaces.

Does it work with vlan bridges T3115?

Jan 9 2022, 7:40 AM · VyOS 1.4 Sagitta
nikeshhajari created T4152: NHRP shortcut-target holding-time does not work.
Jan 9 2022, 6:39 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
erkin added a comment to T4038: Rewrite `vyatta-image-tools.pl` in Python.

Some notes:

  1. The old syntax is quite terrible. It breaks if an image is named disk-install or running or any remote protocol. There needs to be a cleaner syntax for it, such as copy file from image My-Image/usr/local/foo to path /tmp/foo or show file in remote ftp://ftp.example.net/foo.
  2. 'Image tools' isn't exactly a descriptive name for it. It does four operations:
    • show: List files in a directory, or spit information about a file followed by its contents (hexdump if it's binary).
    • copy: Copy a file or directory from one place to another (it can merge directories).
    • delete: Deletes a file or directory (doesn't work remotely).
    • update and updateone: Updates an image's config directory with rsync (the only part directly related to image manipulation). This is actually called clone in the CLI.
  3. show, copy and delete should probably be moved to a separate (new) module related to file operations (and coupled with vyos.remote) whilst update needs to become its own thing (a helper script, perhaps).
Jan 9 2022, 5:16 AM · Restricted Project, VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4100: Firewall increase maximum number of rules.

Tested in VyOS 1.3-rolling-202201030317 & 1.4-rolling-202201070726

Jan 9 2022, 3:50 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Jan 8 2022

hensur added a comment to T4151: IPV6 local PBR Support.

PR: https://github.com/vyos/vyos-1x/pull/1144

Jan 8 2022, 9:51 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav reopened T4100: Firewall increase maximum number of rules as "Needs testing".

@NikolayP Could you test if all works fine?
Check the real generated firewal rules.

Jan 8 2022, 8:04 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4116: Webproxy/Squid not working with IPv6 listen-address as Resolved.
Jan 8 2022, 8:01 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T840: VRRP V3 backup router sending ND RA.

Is it an actual task? If yes, can someone explain which configuration you expect from keepalived.conf or radvd.conf?
As I see PR 9aad6f was merged.

Jan 8 2022, 6:42 PM · VyOS Rolling
Viacheslav moved T4100: Firewall increase maximum number of rules from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 8 2022, 6:09 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4100: Firewall increase maximum number of rules as Resolved.
Jan 8 2022, 6:09 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID.

PR https://github.com/vyos/vyos-1x/pull/1143

Jan 8 2022, 2:09 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T4150: VRRP with conntrack-sync does not work.

PR https://github.com/vyos/vyos-1x/pull/1142

Jan 8 2022, 11:19 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4150: VRRP with conntrack-sync does not work from "Task" to "Bug".
Jan 8 2022, 10:51 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4150: VRRP with conntrack-sync does not work from Open to In progress.
Jan 8 2022, 10:50 AM · VyOS 1.4 Sagitta
Viacheslav edited projects for T4151: IPV6 local PBR Support, added: VyOS 1.4 Sagitta; removed VyOS 1.1.x.

It requires option -6
For example:

sudo ip -6 rule add prio 10 from de:de::1 lookup 5

Show v6 rules:

vyos@r11-roll# sudo ip -6 rule show
0:	from all lookup local
10:	from de:de::1 lookup 5
32766:	from all lookup main
[edit]
vyos@r11-roll#
Jan 8 2022, 10:25 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4150: VRRP with conntrack-sync does not work.

The situation has not changed in VyOS 1.4-rolling-202201070726

Jan 8 2022, 4:36 AM · VyOS 1.4 Sagitta

Jan 7 2022

hensur claimed T4151: IPV6 local PBR Support.
Jan 7 2022, 11:49 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
hensur created T4151: IPV6 local PBR Support.
Jan 7 2022, 11:48 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po committed rVYOSONEXb4ac2f6479bb: xml: nat: use generic bulding block for rule description.
Jan 7 2022, 9:06 PM
c-po committed rVYOSONEXb9c2ce3e3589: xml: firewall: T4130: add protocol completion helper all and tcp_udp.
Jan 7 2022, 9:06 PM
c-po committed rVYOSONEXc3f417986c8a: Debian: T4133: add required nfct package dependency.
Jan 7 2022, 9:06 PM
Viacheslav moved T3924: VRRP stops working with VRF from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 7 2022, 11:02 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) created T4150: VRRP with conntrack-sync does not work.
Jan 7 2022, 8:08 AM · VyOS 1.4 Sagitta
Unknown Object (User) closed T3924: VRRP stops working with VRF as Resolved.

Tested in VyOS 1.4-rolling-202201060842
Works

Jan 7 2022, 1:30 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Jan 6 2022

fernando created T4149: [Firewall-IPV6] Error delete Fw rules on VIF/INT.
Jan 6 2022, 9:39 PM · VyOS 1.4 Sagitta
n.fort created T4148: Firewall - Error messages not that clear as it were in old firewall.
Jan 6 2022, 6:56 PM · VyOS 1.4 Sagitta
jestabro added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

@rps this did not make it into 1.3.0, but was discussed recently and will be addressed; it is, as you point out, a regrettable omission in functionality

Jan 6 2022, 6:56 PM
c-po committed rVYOSONEX5b9edbc220de: vrrp: T4141: bugfix missing {% if %} clause when adding sync-groups.
Jan 6 2022, 6:45 PM
c-po edited projects for T4141: Set high-availability vrrp sync-group without members error, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus.
Jan 6 2022, 6:37 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXfab311fa3c79: op-mode: T4142: Fix for show input ifbX interfaces.
Jan 6 2022, 6:36 PM
GitHub <[email protected]> committed rVYOSONEX64349844b98f: Merge pull request #1141 from sever-sever/T4142-equ (authored by c-po).
Jan 6 2022, 6:36 PM
n.fort created T4147: New Firewall Implementation - proposed changes on group implementation.
Jan 6 2022, 6:00 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4109: Extend high-availability/keepalived for support virtual-server lb from In progress to Needs testing.
Jan 6 2022, 5:41 PM · VyOS 1.4 Sagitta
rps added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Do we know if this made it into the 1.3.0 release or is this now a 1.4 issue?

Jan 6 2022, 5:39 PM
sarthurdev moved T4133: Firewall network group error with zone-based firewall rules from Open to In Progress on the VyOS 1.4 Sagitta board.
Jan 6 2022, 5:27 PM · VyOS 1.4 Sagitta, VyConf
sarthurdev moved T4145: Conntrack table not showing after firewall rewriting from Open to In Progress on the VyOS 1.4 Sagitta board.
Jan 6 2022, 5:26 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4145: Conntrack table not showing after firewall rewriting from Open to Needs testing.
Jan 6 2022, 4:21 PM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4145: Conntrack table not showing after firewall rewriting.

Updates the vyatta-conntrack package to work without legacy firewall and fixes the op-mode commands. Should also fix some conntrack functionality (untested).

Jan 6 2022, 3:23 PM · VyOS 1.4 Sagitta
jestabro closed T4146: Nginx should not listen on port 80 as Unknown Status.
Jan 6 2022, 2:21 PM · VyOS 1.3 Equuleus (1.3.5)
jestabro committed rVYOSONEX2c6fe0aeef09: https: T4146: do not listen on port 80.
Jan 6 2022, 2:11 PM
jestabro moved T3785: Add unicode support to configtree backend from Open to Finished on the VyOS 1.4 Sagitta board.
Jan 6 2022, 1:56 PM · VyOS 1.3 Equuleus (1.3.2)
jestabro closed T3785: Add unicode support to configtree backend, a subtask of T2941: Using a non-ASCII character in the description field causes UnicodeDecodeError in configsource.py, as Unknown Status.
Jan 6 2022, 1:56 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jestabro closed T3785: Add unicode support to configtree backend as Unknown Status.
Jan 6 2022, 1:56 PM · VyOS 1.3 Equuleus (1.3.2)
jestabro updated the task description for T3785: Add unicode support to configtree backend.
Jan 6 2022, 1:55 PM · VyOS 1.3 Equuleus (1.3.2)
jestabro triaged T4146: Nginx should not listen on port 80 as Normal priority.
Jan 6 2022, 1:41 PM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav renamed T4145: Conntrack table not showing after firewall rewriting from Conntrack table not showing after firewall after firewall rewriting to Conntrack table not showing after firewall rewriting.
Jan 6 2022, 12:22 PM · VyOS 1.4 Sagitta
Viacheslav created T4145: Conntrack table not showing after firewall rewriting.
Jan 6 2022, 12:07 PM · VyOS 1.4 Sagitta
n.fort updated the task description for T4144: Firewall address-group - Improve error messages.
Jan 6 2022, 11:49 AM · VyOS 1.4 Sagitta
n.fort created T4144: Firewall address-group - Improve error messages.
Jan 6 2022, 11:49 AM · VyOS 1.4 Sagitta
Viacheslav assigned T3914: VRRP rfc3768-compatibility doesn't work with unicast peers to c-po.

Fixed for 1.4 in T4128 with update "keepalived".
In 1.3 we don't update this pkg and it still has this bug.

Jan 6 2022, 11:32 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) created T4143: Wrong section for Cloud-init User-Data for OVA images.
Jan 6 2022, 11:15 AM
Viacheslav closed T4130: Firewall state policy errors chain as Resolved.
Jan 6 2022, 11:14 AM · VyOS 1.4 Sagitta
Viacheslav closed T4135: Declare zone policy firewall without local zone errors as Resolved.
Jan 6 2022, 11:10 AM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEX79f6f7061c0c: firewall: zone-policy: T4133: Prevent firewall from trying to clean-up zone….
Jan 6 2022, 8:28 AM
GitHub <[email protected]> committed rVYOSONEX83f281c9a3c6: Merge pull request #1139 from sarthurdev/firewall (authored by c-po).
Jan 6 2022, 8:28 AM
c-po closed T4141: Set high-availability vrrp sync-group without members error as Resolved.
Jan 6 2022, 8:26 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po committed rVYOSONEX0a91c5de32b5: vrrp: T4141: bugfix missing {% if %} clause when adding sync-groups.
Jan 6 2022, 8:26 AM
jestabro committed rVYOSONEX5b8550dc1837: config: T3785: drop restriction to ascii in decode.
Jan 6 2022, 1:31 AM

Jan 5 2022

jestabro added a comment to T3785: Add unicode support to configtree backend.

relaxes the condition to escape non-ascii bytes. Updating the commit id in the Dockerfile and relaxing the ascii restriction in configsource.py will allow unicode chars in config.

Jan 5 2022, 6:34 PM · VyOS 1.3 Equuleus (1.3.2)
sarthurdev changed the status of T4133: Firewall network group error with zone-based firewall rules from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1139

Jan 5 2022, 5:10 PM · VyOS 1.4 Sagitta, VyConf
Viacheslav moved T4142: Input ifbX interfaces not displayed in op-mode from Open to Backport Candidates on the VyOS 1.4 Sagitta board.
Jan 5 2022, 4:20 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX5fdf4e598834: op-mode: T4142: Fix for show input ifbX interfaces.
Jan 5 2022, 4:13 PM
GitHub <[email protected]> committed rVYOSONEXe4b368b10aee: Merge pull request #1138 from sever-sever/T4142 (authored by jestabro).
Jan 5 2022, 4:13 PM
Viacheslav added a comment to T4142: Input ifbX interfaces not displayed in op-mode.

PR https://github.com/vyos/vyos-1x/pull/1138

vyos@r11-roll:~$ show interfaces input 
Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface        IP Address                        S/L  Description
---------        ----------                        ---  -----------
ifb0             -                                 u/u  FOO
ifb1             -                                 u/u  FOO1
vyos@r11-roll:~$
Jan 5 2022, 4:07 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a project to T4142: Input ifbX interfaces not displayed in op-mode: VyOS 1.3 Equuleus ( 1.3.1).
Jan 5 2022, 3:47 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T4142: Input ifbX interfaces not displayed in op-mode from Open to In progress.
Jan 5 2022, 3:42 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta