Page MenuHomeVyOS Platform
Feed All Stories

Jan 11 2022

c-po committed rVYOSONEXb5b9685c37aa: remote: T3950: Gracefully handle chained exceptions (authored by erkin).
Jan 11 2022, 9:35 AM
c-po closed T4170: Rename "policy ipv6-route" -> "policy route6" as Resolved.
Jan 11 2022, 9:29 AM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX54675c2cc9aa: policy: T4170: rename "policy ipv6-route" -> "policy route6".
Jan 11 2022, 9:28 AM
c-po committed rVYOSONEXe89f48269e96: policy: T2199: add missing rule constraints.
Jan 11 2022, 9:28 AM
c-po claimed T4170: Rename "policy ipv6-route" -> "policy route6".
Jan 11 2022, 9:16 AM · VyOS 1.4 Sagitta
c-po created T4170: Rename "policy ipv6-route" -> "policy route6".
Jan 11 2022, 9:15 AM · VyOS 1.4 Sagitta
c-po renamed T4169: INVALID from BGP: Add support for "nexthop-self force" to INVALID.
Jan 11 2022, 8:59 AM · VyOS 1.3 Equuleus ( 1.3.1)
c-po added a comment to T4169: INVALID.

Invalid - already available - I looked into an 1.2.8 image.

Jan 11 2022, 8:59 AM · VyOS 1.3 Equuleus ( 1.3.1)
erkin reopened T3950: CLI backtrace on update if DNS not defined , a subtask of T3356: Script for remote file transfers, as In progress.
Jan 11 2022, 8:58 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin reopened T3950: CLI backtrace on update if DNS not defined as "In progress".
Jan 11 2022, 8:58 AM · VyOS 1.4 Sagitta
c-po created T4169: INVALID.
Jan 11 2022, 8:58 AM · VyOS 1.3 Equuleus ( 1.3.1)
Unknown Object (User) assigned T4168: IPsec VPN is impossible to restart when DMVPN is configured to Viacheslav.
Jan 11 2022, 8:28 AM · VyOS 1.3 Equuleus ( 1.3.1)
Unknown Object (User) created T4168: IPsec VPN is impossible to restart when DMVPN is configured.
Jan 11 2022, 8:27 AM · VyOS 1.3 Equuleus ( 1.3.1)
Unknown Object (User) created T4167: DMVPN apply wrong param on the first configuration.
Jan 11 2022, 8:08 AM · VyOS 1.3 Equuleus (1.3.0)
jestabro committed rVYOSONEXcb797395a4df: frr: T4166: move log debug setting to init function for vyos-configd.
Jan 11 2022, 7:22 AM
GitHub <[email protected]> committed rVYOSONEXc0d65731d904: Merge pull request #1153 from jestabro/frr_debug (authored by c-po).
Jan 11 2022, 7:22 AM
GitHub <[email protected]> committed rVYOSONEX142c976ca4b3: containers: T2216: bugfix host networking on image upgrade (authored by Mathew Inkson <[email protected]>).
Jan 11 2022, 7:21 AM
GitHub <[email protected]> committed rVYOSONEX1a33b2f6db47: Merge pull request #1154 from imathew/current (authored by c-po).
Jan 11 2022, 7:21 AM
imathew added a comment to T3662: Container configuration upgrade destroys system.

Hi, I've just submitted a pull request (https://github.com/vyos/vyos-1x/pull/1154) to hopefully complete this bugfix.

Jan 11 2022, 3:42 AM · VyOS 1.4 Sagitta

Jan 10 2022

jestabro triaged T4166: Debug output missing when frr.py called under vyos-configd as Normal priority.
Jan 10 2022, 10:50 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEXbb76e8d7f163: nat: T2199: dry-run newly generated config before install.
Jan 10 2022, 10:28 PM
c-po committed rVYOSONEX76d912d63ca4: conntrack: T3579: dry-run newly generated config before install.
Jan 10 2022, 10:18 PM
Viacheslav added a comment to T4163: [BMP-BGP] Routing monitoring feature.

@fernando Thanks, do you have any idea about syntax?

Jan 10 2022, 10:13 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po committed rVYOSONEX9bc2f5db25c7: conntrack: T3579: prepare for "conntrack timeout custom rule" CLI commands.
Jan 10 2022, 10:06 PM
Viacheslav created T4165: Custom conntrack rules cannot be deleted.
Jan 10 2022, 10:00 PM · VyOS 1.3 Equuleus ( 1.3.1)
Viacheslav changed the status of T4152: NHRP shortcut-target holding-time does not work from In progress to Needs testing.
Jan 10 2022, 9:40 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
johannrichard updated the task description for T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf`.
Jan 10 2022, 9:34 PM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEXa5ad98b2307a: firewall: validators: T2199: Improve port validation.
Jan 10 2022, 9:32 PM
sarthurdev committed rVYOSONEXda370b63b266: validators: T4148: Add text output when validators fail.
Jan 10 2022, 9:32 PM
sarthurdev committed rVYOSONEX0a0e7d789e7e: validators: Stricter checking on port-range validator.
Jan 10 2022, 9:32 PM
GitHub <[email protected]> committed rVYOSONEX465939d9c9b4: Merge pull request #1152 from sarthurdev/firewall_validators (authored by c-po).
Jan 10 2022, 9:32 PM
c-po committed rVYOSONEXfd1b1ff19b0f: conntrack: T3579: make the timeout tree re-usable as XML include.
Jan 10 2022, 9:27 PM
johannrichard created T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf`.
Jan 10 2022, 9:22 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4144: Firewall address-group - Improve error messages from Open to In progress.

IPv4 address range error messages are included in PR: https://github.com/vyos/vyos-1x/pull/1152

Jan 10 2022, 9:09 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4148: Firewall - Error messages not that clear as it were in old firewall from Open to Needs testing.

Error for rule being in use when deleting base node was fixed in https://github.com/vyos/vyos-1x/pull/1151

Jan 10 2022, 9:04 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4137: Firewall group configuration allows to set incorrect port range and invalid port from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1152

Jan 10 2022, 9:02 PM · VyOS 1.4 Sagitta
fernando added a comment to T4163: [BMP-BGP] Routing monitoring feature.

this PR https://github.com/vyos/vyos-1x/pull/1088 only include how to enable daemon , but it doesn't add VyOS-cli commands in BGP (the daemon only allows you to enable it).

Jan 10 2022, 8:43 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po committed rVYOSONEX062762154ae1: conntrack: T3579: use "notrack" over "return" in nft statements.
Jan 10 2022, 8:42 PM
c-po added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

@Viacheslav / @vindenesen that is a bug I have also seen in the old iptables based implementation. Can you please file a bug report towards VyOS 1.2 and 1.3?

Jan 10 2022, 8:38 PM · VyOS 1.4 Sagitta
c-po committed rVYOSONEX05b5d09ca70c: conntrack: T3579: migrate "conntrack ignore" tree to vyos-1x and nftables.
Jan 10 2022, 8:32 PM
Viacheslav added a comment to T4163: [BMP-BGP] Routing monitoring feature.

There is PR which includes this feature https://github.com/vyos/vyos-1x/pull/1088

Jan 10 2022, 8:17 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
fernando created T4163: [BMP-BGP] Routing monitoring feature.
Jan 10 2022, 8:05 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav assigned T4162: VPN ipsec ike-group - Incorrect value help for ikev2-reauth to n.fort.
Jan 10 2022, 6:49 PM · VyOS 1.4 Sagitta
n.fort created T4162: VPN ipsec ike-group - Incorrect value help for ikev2-reauth.
Jan 10 2022, 6:48 PM · VyOS 1.4 Sagitta
sarthurdev committed rVYOSONEXdeb9bfa02863: policy: T4155: Fix using incorrect table variable.
Jan 10 2022, 6:42 PM
sarthurdev committed rVYOSONEX67ab81546856: firewall: 4149: Fix verify steps being bypassed when base node is removed.
Jan 10 2022, 6:42 PM
GitHub <[email protected]> committed rVYOSONEX436805a69df3: Merge pull request #1151 from sarthurdev/firewall (authored by c-po).
Jan 10 2022, 6:42 PM
sarthurdev changed the status of T4149: [Firewall-IPV6] Error delete Fw rules on VIF/INT from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1151

Jan 10 2022, 6:40 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases , a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Jan 10 2022, 6:40 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
sarthurdev changed the status of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases from Open to Needs testing.

Thanks for catching that!

Jan 10 2022, 6:40 PM · VyOS 1.4 Sagitta
GitHub <[email protected]> committed rVYOSONEX4ade92549616: Merge pull request #1150 from nicolas-fort/T4161 (authored by c-po).
Jan 10 2022, 6:38 PM
Nicolas Fort <[email protected]> committed rVYOSONEX8dfde277c90c: policy: T4161: Set correct description for local-preference.
Jan 10 2022, 6:38 PM
n.fort added a comment to T4161: Policy route-map - Incorrect value help for local preference.

PR: https://github.com/vyos/vyos-1x/pull/1150

Jan 10 2022, 6:21 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4149: [Firewall-IPV6] Error delete Fw rules on VIF/INT from Open to In progress.
Jan 10 2022, 5:53 PM · VyOS 1.4 Sagitta
syncer added a member for Maintainers: sarthurdev.
Jan 10 2022, 5:52 PM
Viacheslav assigned T4161: Policy route-map - Incorrect value help for local preference to n.fort.
Jan 10 2022, 5:07 PM · VyOS 1.4 Sagitta
n.fort created T4161: Policy route-map - Incorrect value help for local preference.
Jan 10 2022, 5:06 PM · VyOS 1.4 Sagitta
n.fort created T4160: Firewall - Error in rules that matches everything except something.
Jan 10 2022, 4:51 PM · VyOS 1.4 Sagitta
n.fort closed T3115: Add support for firewall on L3 VIF bridge interface as Resolved.
Jan 10 2022, 3:36 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
n.fort added a comment to T3115: Add support for firewall on L3 VIF bridge interface.

Previous example was expanded, in order to test filtering between native bridge interface and vlans interface on bridge.
Filtering rules:

  • Filter traffic from vlan br0.55 to br0.66
  • Filter traffic from vlan1 to br0.55
  • Allow all
Jan 10 2022, 3:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
hensur added a comment to T3818: BGP export route-map only works after bgpd restart.

I'm experiencing this with a custom ISO built from the stable 1.3 sources. Haven't done further debugging yet, a bgpd restart helped every time.

Jan 10 2022, 3:09 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4100: Firewall increase maximum number of rules.

In 1.3 (VyOS 1.3-rolling-202201030317) the rules are handled correctly (except for the numbers in description).

Jan 10 2022, 12:35 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav moved T3299: Allow the web proxy service to listen on all IP addresses from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 10 2022, 9:32 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav changed the status of T3299: Allow the web proxy service to listen on all IP addresses from Unknown Status to Resolved.
Jan 10 2022, 9:32 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXaa438129337c: squid: T3299: Add listen address 0.0.0.0 (authored by sever-sever <[email protected]>).
Jan 10 2022, 9:02 AM
GitHub <[email protected]> committed rVYOSONEX1ddbbe90b32e: Merge pull request #1146 from sever-sever/T3299-equ (authored by c-po).
Jan 10 2022, 9:02 AM
nikeshhajari closed T4158: Add support for "ip nhrp registration no-unique" from FRR as Invalid.
Jan 10 2022, 6:23 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
nikeshhajari added a comment to T4158: Add support for "ip nhrp registration no-unique" from FRR.

Ah! ok, I will close this. Looking at the man pages, seems like open nhrp doesn't have a no-unique registration feature?

Jan 10 2022, 6:23 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T4158: Add support for "ip nhrp registration no-unique" from FRR.

We don’t use frr nhrpd, more details T2326
We use opennhrp

Jan 10 2022, 6:17 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
johannrichard added a comment to T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.

I just realize it's getting more complicated as python/vyos/firewall.py will later write out the rules for these empty groups and when reading-them in, nftables will complain (again) when trying to resolve them, e.g.

Jan 10 2022, 3:06 AM · VyOS 1.4 Sagitta
erkin added a comment to T4038: Rewrite `vyatta-image-tools.pl` in Python.

Pythonic reimplementation complete. Now only the XML op-mode definition and the auto-complete script remain.

Jan 10 2022, 2:51 AM · Restricted Project, VyOS 1.4 Sagitta
johannrichard renamed T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails from Rewrite firewall in new XML/Python style: Empty firewall group (address, network & port) generate invalid nftables config, commit fails to Empty firewall group (address, network & port) generates invalid nftables config, commit fails.
Jan 10 2022, 2:25 AM · VyOS 1.4 Sagitta
johannrichard added a comment to T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.

To my understanding, the template data/templates/firewall/nftables.tmpl is probably the culprit, as it doesn't check whether group_conf.address (and similarly the others) has any elements at all and introduces the offending white-space:

Jan 10 2022, 2:25 AM · VyOS 1.4 Sagitta
johannrichard added a subtask for T2199: Rewrite firewall in new XML/Python style: T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.
Jan 10 2022, 2:12 AM · VyOS 1.4 Sagitta (1.4.0-epa2)
johannrichard added a parent task for T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails: T2199: Rewrite firewall in new XML/Python style.
Jan 10 2022, 2:12 AM · VyOS 1.4 Sagitta
johannrichard created T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.
Jan 10 2022, 2:12 AM · VyOS 1.4 Sagitta

Jan 9 2022

nikeshhajari created T4158: Add support for "ip nhrp registration no-unique" from FRR.
Jan 9 2022, 11:57 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
teadur committed rVYOSONEX7c1ea983c455: T4157: Add jinja2 to test-requirements.txt.
Jan 9 2022, 10:39 PM
GitHub <[email protected]> committed rVYOSONEXa9033074f6d7: Merge pull request #1149 from tacerus/pip (authored by dmbaturin).
Jan 9 2022, 10:39 PM
Viacheslav committed rVYOSONEX66d59d9e393c: vrrp: T1972: Ability to set IP address on not vrrp interface.
Jan 9 2022, 8:45 PM
GitHub <[email protected]> committed rVYOSONEXdfb2b58e00ea: Merge pull request #1143 from sever-sever/T1972 (authored by c-po).
Jan 9 2022, 8:45 PM
c-po added a comment to T4156: Adding DHCP Option 13 (bootfile-size).

In ISC dhcpd this corresponds to the boot-size option http://www.ipamworldwide.com/ipam/isc-dhcpv4-options.html

Jan 9 2022, 8:36 PM · VyOS 1.4 Sagitta
tacerus triaged T4157: Add jinja2 to pip test requirements as Low priority.
Jan 9 2022, 8:35 PM · VyOS 1.4 Sagitta
tacerus triaged T4156: Adding DHCP Option 13 (bootfile-size) as Low priority.
Jan 9 2022, 8:05 PM · VyOS 1.4 Sagitta
johannrichard added a subtask for T2199: Rewrite firewall in new XML/Python style: T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases .
Jan 9 2022, 7:59 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
johannrichard added a parent task for T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases : T2199: Rewrite firewall in new XML/Python style.
Jan 9 2022, 7:59 PM · VyOS 1.4 Sagitta
c-po moved T3924: VRRP stops working with VRF from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 9 2022, 7:58 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po edited a custom field on T3924: VRRP stops working with VRF.
Jan 9 2022, 7:58 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a project to T3924: VRRP stops working with VRF: VyOS 1.3 Equuleus ( 1.3.1).
Jan 9 2022, 7:58 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po moved T4141: Set high-availability vrrp sync-group without members error from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po moved T4128: keepalived: Upgrade package to add VRF support from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a project to T4128: keepalived: Upgrade package to add VRF support: VyOS 1.3 Equuleus ( 1.3.1).
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a parent task for T4128: keepalived: Upgrade package to add VRF support: T3914: VRRP rfc3768-compatibility doesn't work with unicast peers.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a subtask for T3914: VRRP rfc3768-compatibility doesn't work with unicast peers: T4128: keepalived: Upgrade package to add VRF support.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a comment to T3914: VRRP rfc3768-compatibility doesn't work with unicast peers.

Package upgraded

Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po closed T3914: VRRP rfc3768-compatibility doesn't work with unicast peers as Resolved.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po moved T3914: VRRP rfc3768-compatibility doesn't work with unicast peers from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Jan 9 2022, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po committed rVYOSONEX5931d2530e9a: keepalived: T4128: add missing keepalived.service file.
Jan 9 2022, 7:56 PM
c-po committed rVYOSONEX1bb6b4458aa6: keepalived: T4128: add systemd option Type=simple.
Jan 9 2022, 7:56 PM
c-po edited projects for T3914: VRRP rfc3768-compatibility doesn't work with unicast peers, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus (1.3.0).
Jan 9 2022, 7:53 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta