In T4164#116547, @mTx87 wrote:seems like policy based routing not working.
- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
Feed All Stories
All Stories
All Stories
Jan 13 2022
Jan 13 2022
johannrichard added a comment to T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf`.
mTx87 added a comment to T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf`.
moved my comment to a new bug request to keep this one here clean.
Viacheslav changed the status of T4177: Strip-private doesn't work for service monitoring from Open to In progress.
GitHub <[email protected]> committed rVYOSONEXb34c9664ba69: Merge pull request #1162 from sever-sever/T3872 (authored by c-po).
Any updates? No one?
Jan 13 2022, 3:56 AM · Bugs, VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.1), Restricted Project, openvpn
Jan 12 2022
Jan 12 2022
but wasn't necessary on VyOS 1.4-rolling-202109280217
so I guess changes to FRR that are the cause right?
Add neighbors to their proper afi:
Viacheslav moved T4161: Policy route-map - Incorrect value help for local preference from Open to Finished on the VyOS 1.4 Sagitta board.
Viacheslav moved T4162: VPN ipsec ike-group - Incorrect value help for ikev2-reauth from Open to Finished on the VyOS 1.4 Sagitta board.
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.169 / 5.10.89 to Update Linux Kernel to v5.4.171 / 5.10.91.
GitHub <[email protected]> committed rVYOSONEXddc7a0cc5378: Merge pull request #1161 from sarthurdev/firewall (authored by c-po).
- Incorrect custom scripts data if used tunX interfaces
- Allow inputs.ethtool only on Ethernet interfaces, by default it tries to get statistics from each interface, template
Jan 12 19:37:30 r11-roll telegraf[7703]: 2022-01-12T17:37:30Z E! [inputs.ethtool] Error in plugin: dum0 stats: operation not supported Jan 12 19:37:30 r11-roll telegraf[7703]: 2022-01-12T17:37:30Z E! [inputs.ethtool] Error in plugin: gretap0 driver: operation not supported Jan 12 19:37:30 r11-roll telegraf[7703]: 2022-01-12T17:37:30Z E! [inputs.ethtool] Error in plugin: gre0 driver: operation not supported Jan 12 19:37:30 r11-roll telegraf[7703]: 2022-01-12T17:37:30Z E! [inputs.ethtool] Error in plugin: erspan0 driver: operation not supported
Incorrect custom scripts data if used 'tun' interface
https://github.com/vyos/vyos-1x/blob/current/src/etc/telegraf/custom_scripts/show_interfaces_input_filter.py
Viacheslav moved T4152: NHRP shortcut-target holding-time does not work from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
sarthurdev changed the status of T2199: Rewrite firewall in new XML/Python style from Open to Needs testing.
Viacheslav edited projects for T4168: IPsec VPN is impossible to restart when DMVPN is configured, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus.
Viacheslav changed the status of T3872: Add configurable telegraf monitoring service from Open to Needs testing.
Viacheslav changed the status of T4173: Wan Load Balancing - Error on firewall NAT rules from In progress to Needs testing.
Viacheslav changed the status of T4173: Wan Load Balancing - Error on firewall NAT rules from Open to In progress.
Viacheslav moved T4152: NHRP shortcut-target holding-time does not work from Open to Finished on the VyOS 1.4 Sagitta board.
Viacheslav changed the status of T4168: IPsec VPN is impossible to restart when DMVPN is configured from Open to In progress.
yes, you are right:
sarthurdev changed the status of T4160: Firewall - Error in rules that matches everything except something from In progress to Needs testing.
Viacheslav closed T4174: Validation fails when entering port range with upper port 65535, a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Viacheslav closed T4174: Validation fails when entering port range with upper port 65535 as Resolved.
sarthurdev moved T4131: Show firewall group incorrect format members from Open to In Progress on the VyOS 1.4 Sagitta board.
sarthurdev moved T4137: Firewall group configuration allows to set incorrect port range and invalid port from Open to In Progress on the VyOS 1.4 Sagitta board.
sarthurdev moved T4144: Firewall address-group - Improve error messages from Open to In Progress on the VyOS 1.4 Sagitta board.
sarthurdev moved T4148: Firewall - Error messages not that clear as it were in old firewall from Open to In Progress on the VyOS 1.4 Sagitta board.
sarthurdev moved T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases from Open to In Progress on the VyOS 1.4 Sagitta board.
sarthurdev moved T4160: Firewall - Error in rules that matches everything except something from Open to In Progress on the VyOS 1.4 Sagitta board.
Unknown Object (User) changed the status of T4167: DMVPN apply wrong param on the first configuration from In progress to Needs testing.
Unknown Object (User) added a comment to T4100: Firewall increase maximum number of rules.
Jan 11 2022
Jan 11 2022
sarthurdev changed the status of T4160: Firewall - Error in rules that matches everything except something from Open to In progress.
Forgot that my PR for WLB was still a draft. That the jump does seem to be created properly with this PR in place.
That build at 08:11 UTC was a couple of hours before the commit was merged: https://github.com/vyos/vyos-1x/commit/f97144259335102c3d96b232cbb0af4970120d62
yes , i'm using this version :
Unknown Object (User) added a comment to T4167: DMVPN apply wrong param on the first configuration.
Seems to be working on my latest build?
Unknown Object (User) changed the status of T4167: DMVPN apply wrong param on the first configuration from Open to In progress.
I've checked with this new build , it works with validator ranges/port :
GitHub <[email protected]> committed rVYOSONEX968afb9e67a2: Merge pull request #1160 from bjw-s/T4174 (authored by c-po).
Bᴇʀɴᴅ Sᴄʜᴏʀɢᴇʀs <[email protected]> committed rVYOSONEX4793e2fc0baf: firewall: validators: T4174: Correct upper port range boundary.
GitHub <[email protected]> committed rVYOSONEXb55ac8e2c06c: Merge pull request #1159 from sarthurdev/firewall (authored by c-po).
bjw-s updated the task description for T4174: Validation fails when entering port range with upper port 65535.
I've been testing and it works :
Nicolas Fort <[email protected]> committed rVYOSONEX1b8f421727ee: ike-group: T4162: Correct helper description for ikev2-reauth.
GitHub <[email protected]> committed rVYOSONEX24954d470102: Merge pull request #1157 from nicolas-fort/T4162 (authored by c-po).
GitHub <[email protected]> committed rVYOSONEX2b51513cf251: Merge pull request #1158 from sarthurdev/firewall (authored by c-po).
sarthurdev changed the status of T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf` from Open to Needs testing.
Thanks, I really like the include idea and have implemented it in the attached PR. Also added a check in firewall.py to reload policy-route script to keep any group changes updated.
sarthurdev changed the status of T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails, a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
sarthurdev changed the status of T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails from Open to Needs testing.
PR removes the empty line when there are no group members, also adds a warning message when empty groups are used in rules.
sarthurdev changed the status of T4131: Show firewall group incorrect format members from Open to Needs testing.
@Viacheslav Not using exact ipset format, however addresses are sorted and output one per line.
sarthurdev changed the status of T4144: Firewall address-group - Improve error messages from In progress to Needs testing.
Should resolve the rest of the error messages.
well , I think it should be something like this :
c-po changed the status of T4171: Interface config migration error on 1.2.8 -> 1.4 upgrade from Open to In progress.
erkin closed T3950: CLI backtrace on update if DNS not defined , a subtask of T3356: Script for remote file transfers, as Resolved.
Chained exceptions are covered too (and backported to Equuleus).
c-po committed rVYOSONEXd5775339f9d1: remote: T3950: Gracefully handle chained exceptions (authored by erkin).