debootstrap.log33 KBDownload
- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
Feed All Stories
All Stories
All Stories
Jan 26 2022
Jan 26 2022
Jan 25 2022
Jan 25 2022
Is it the same task T4138 ?
Viacheslav changed the status of T4138: NAT configuration allows to set incorrect port range and invalid port from Open to In progress.
GitHub <[email protected]> committed rVYOSONEX5177313cfc12: Merge pull request #1189 from sever-sever/T3872 (authored by c-po).
I had forgotten about the recent syntax and it was merged in a broken state (https://github.com/vyos/vyos-1x/blob/current/python/vyos/firewall.py#L164). We should try and find a remedy, or remove it from CLI.
Viacheslav changed the status of T4196: DHCP server client-prefix-length parameter results in non-functional leases from In progress to Needs testing.
PR https://github.com/vyos/vyos-1x/pull/1190
set policy prefix-list TST_PRF_LST rule 10 action 'permit' set policy prefix-list TST_PRF_LST rule 10 prefix '10.5.5.0/24' set policy prefix-list TST_PRF_LST rule 20 action 'permit' set policy prefix-list TST_PRF_LST rule 20 prefix '10.6.6.0/24' set policy prefix-list TST_PRF_LST rule 30 action 'permit' set policy prefix-list TST_PRF_LST rule 30 prefix '10.6.6.0/24'
Viacheslav updated the task description for T4209: Firewall incorrect handler for recent count and time.
Viacheslav updated the task description for T4209: Firewall incorrect handler for recent count and time.
Try to dump traffic from the required interface
For first do these changes as in commit
Try policy local route, for example:
set policy local-route rule 10 set table 111 set policy local-route rule 10 source 192.0.2.0/24
The main reason:
@Rhongomiant Am I understanding correctly that you don't see the default route in table 111?
Viacheslav updated the task description for T4207: Policy Based Route Issue with Rules for Multiple Tables.
GitHub <[email protected]> committed rVYOSONEX3249d761843c: Merge pull request #1188 from sever-sever/T4205 (authored by c-po).
@sdev Thanks
Jan 24 2022
Jan 24 2022
goodNETnick <[email protected]> committed rVYOSONEX97aca4001263: DHCP: T4196: fix client-prefix-length parameter.
GitHub <[email protected]> committed rVYOSONEXc50dc1217d0d: Merge pull request #1187 from goodNETnick/dhcp-client-prefix_1.3 (authored by c-po).
Task already implemented:
Unknown Object (User) changed the status of T4204: Update Accel-PPP to a newer revision from In progress to Needs testing.
Unknown Object (User) added a comment to T4204: Update Accel-PPP to a newer revision.
PR current - https://github.com/vyos/vyos-build/pull/214
PR equuleus - https://github.com/vyos/vyos-build/pull/215
Unknown Object (User) changed the status of T4204: Update Accel-PPP to a newer revision from Open to In progress.
Unknown Object (User) created T4204: Update Accel-PPP to a newer revision.
Unknown Object (User) updated the task description for T4072: Feature Request: Firewall on bridge interfaces.
Unknown Object (User) added a comment to T4196: DHCP server client-prefix-length parameter results in non-functional leases.
PR for 1.3:
https://github.com/vyos/vyos-1x/pull/1187
@artooro It still accepts type-name.
Jan 23 2022
Jan 23 2022
@n.fort I just built a fresh image and tested. The first thing I noticed is that icmpv6 now only accepts integers while previously it accepted names. I'm assuming this is a purposeful design change where users now have to set type-name instead.
The any option has been removed, which I suspect is OK as you'd simply leave it unset if you want to accept all icmp types.
Overall this should eliminate the user confusion so I think it's a good change.
Tested on VyOS 1.4-rolling-202201230317
@artooro , please try again using latest version -> vyos-1.4-rolling-202201230317-amd64.iso
Just tested, and for me, it's working as expected.
PR that solves this issue: https://github.com/vyos/vyos-1x/pull/1184
n.fort added a comment to T4021: Long commit time on bridge interface with 1-4094 allowed VLAN tags.
On VyOS 1.4-rolling-202201230317.
Commands:
Tested on latest VyOS 1.4-rolling-202201230317
Jan 22 2022
Jan 22 2022
GitHub <[email protected]> committed rVYOSONEX221aee86f4d4: Merge pull request #1186 from nicolas-fort/T4153 (authored by c-po).
n.fort added a comment to T4138: NAT configuration allows to set incorrect port range and invalid port.
Error still present on VyOS 1.4-rolling-202201180317
n.fort added a comment to T4202: NFT: Zone policies fail to apply when "l2tp+" is in the interface list.
Wildcard + should be replaces with *, according to nft man page:
c-po changed the status of T4203: Reconfigure DHCP client interface causes brief outages from Open to Confirmed.
sarthurdev committed rVYOSONEX3e4f2f577746: Firewall: T4186: Correct icmp type-name options for firewall rules (authored by Nicolas Fort <[email protected]>).
sarthurdev committed rVYOSONEXd0cfd9758bab: Firewall: T4186: typo correction on address-mask-reply description (authored by Nicolas Fort <[email protected]>).
sarthurdev committed rVYOSONEX3e55af0ccdf0: Firewall: T4186: Adding icmpv6 corrections, in corcondancy of what was done for… (authored by Nicolas Fort <[email protected]>).
GitHub <[email protected]> committed rVYOSONEX3b7629eaa4c8: Merge pull request #1184 from sarthurdev/firewall_icmp (authored by c-po).
@hensur See PR, I implemented a merge script and provided three solutions.
Jan 21 2022
Jan 21 2022
artooro closed T4200: Assigning ipv6-name to interface is not generating nftables rules as Resolved.
artooro added a comment to T4200: Assigning ipv6-name to interface is not generating nftables rules.
Confirmed, I just built a new image using 1.4-rolling-202201212148 and I can no longer reproduce the issue.
PR + migration: https://github.com/vyos/vyos-1x/pull/1184
In T4199#117215, @n.fort wrote:
Loading address group described in task and then printing, works OK.
Tested on VyOS 1.4-rolling-202201180317 and working as expected.
Seems solved, Not reproducible on VyOS 1.4-rolling-202201180317
n.fort changed the status of T4199: Commit failed when setting icmpv6 type any from In progress to Confirmed.
Did did work as expeced
vyos@vyos# run show config comm | grep fire set firewall ipv6-name FOO rule 10 action 'accept' set firewall ipv6-name FOO rule 10 icmpv6 type 'echo-request' set firewall ipv6-name FOO rule 10 protocol 'ipv6-icmp'
Also, while matching parameters valid in nftables, such as echo-reply, commit fails too:
GitHub <[email protected]> committed rVYOSONEXf791d3ef4c33: Merge pull request #1183 from hensur/current-ipv6-local-route (authored by c-po).
Should be fixed with https://github.com/vyos/vyos-1x/pull/1183
Bug related: https://phabricator.vyos.net/T4186
sarthurdev changed the status of T4199: Commit failed when setting icmpv6 type any from Open to In progress.
sarthurdev added a comment to T4200: Assigning ipv6-name to interface is not generating nftables rules.
I can't reproduce this issue on latest rolling
I'm looking into it. From the logs it seems like for src in (pbr[rule_rm][rule]['source'] or ['']) doesn't work if 'source' doesn't exist.
goodNETnick <[email protected]> committed rVYOSONEX28a92e75cf93: DHCP: T4196: fix client-prefix-length parameter.
GitHub <[email protected]> committed rVYOSONEXec5eb00bd83a: Merge pull request #1180 from goodNETnick/dhcp-client-prefix (authored by c-po).
@hensur Smoketest failed.
Unknown Object (User) added a comment to T4154: Error add second gre tunnel with the same source interface.
(VyOS 1.4-rolling-202201200814) - The same.
Unknown Object (User) added a comment to T4137: Firewall group configuration allows to set incorrect port range and invalid port.
I ve testet it on (Version:VyOS 1.4-rolling-202201200814). It seems well.
Unknown Object (User) added a comment to T4115: reboot in <x> not working as expected.
I ve tested this scenario on VyOS 1.4-rolling-202201200814, as said Srividya you can choose minutes betwen 1-99.
If this is critical, you can expand the range by opening a "feature request".
Jan 20 2022
Jan 20 2022
c-po closed T4171: Interface config migration error on 1.2.8 -> 1.4 upgrade, a subtask of T3871: Resolve unexpected interface name reordering, as Resolved.
Seems to have fixed it