Page MenuHomeVyOS Platform
Feed All Stories

Jul 20 2022

dmbaturin committed rVYOSONEXf9e835c41643: T2719: fix unused imports.
Jul 20 2022, 8:33 PM
GitHub <[email protected]> committed rVYOSONEXf424d84f4179: Merge pull request #1351 from dmbaturin/genop (authored by jestabro).
Jul 20 2022, 8:33 PM
n.fort placed T4475: route-map does not support ipv6 peer up for grabs.
Jul 20 2022, 5:16 PM · VyOS 1.3 Equuleus (1.3.4)
n.fort added a comment to T4475: route-map does not support ipv6 peer.

Modyfing file pointed by @Viacheslav , makes ipv6 peer option available.
But while testing config, it's not possible to insert an ipv6 address: validator rejects input.
Validator used: syntax:expression: exec "/opt/vyatta/sbin/vyatta-policy.pl --check-peer-syntax $VAR(@)"; "peer must be either an IP or local"

Jul 20 2022, 5:10 PM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav moved T4475: route-map does not support ipv6 peer from Open to Finished on the VyOS 1.4 Sagitta board.
Jul 20 2022, 4:32 PM · VyOS 1.3 Equuleus (1.3.4)
purpendicular created T4549: Email notification functionality.
Jul 20 2022, 4:27 PM · VyOS Rolling
daniil closed T4056: Traffic policy not set in live configuration as Resolved.
Jul 20 2022, 3:45 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav added a comment to T4056: Traffic policy not set in live configuration.

@daniil Could you re-check it?

Jul 20 2022, 3:44 PM · vyatta-cfg, VyOS 1.4 Sagitta
Viacheslav added a comment to T4537: MACsec not working with cipher gcm-aes-256.

It seems wpa_supplicant doesn't support GCM-AES-256
https://w1.fi/wpa_supplicant/devel/dir_4261af1259721e3e39e0d2dd7354b511.html

Jul 20 2022, 3:31 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4545: Rewrite show nat source rules.

PR https://github.com/vyos/vyos-1x/pull/1420

Jul 20 2022, 1:04 PM · VyOS 1.4 Sagitta
zsdc created T4548: GRUB loader configuration rework.
Jul 20 2022, 12:01 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav updated the task description for T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets.
Jul 20 2022, 11:46 AM · VyOS 1.4 Sagitta
Viacheslav created T4547: Show vpn ipsec sa show unexpected prefix 'B' in packets.
Jul 20 2022, 11:42 AM · VyOS 1.4 Sagitta
a.apostoliuk added a comment to T4537: MACsec not working with cipher gcm-aes-256.

I have just tested it again. Macsec does not work.

Jul 20 2022, 10:52 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
goodNETnick <[email protected]> committed rVYOSONEXd59c232a6fbf: route-map: T4542: match prefix-len BGP notice.
Jul 20 2022, 9:37 AM
GitHub <[email protected]> committed rVYOSONEX38d753f83088: Merge pull request #1419 from goodNETnick/rm-pref-len (authored by c-po).
Jul 20 2022, 9:37 AM
Unknown Object (User) added a comment to T4542: route-map: "match prefix-len" incorrect behavior.

PR with notice:
https://github.com/vyos/vyos-1x/pull/1419

Jul 20 2022, 9:26 AM · VyOS 1.4 Sagitta

Jul 19 2022

zsdc changed the status of T4546: Does not connect Cisco spoke to VyOS hub. from Confirmed to In progress.

PR for 1.4: https://github.com/vyos/vyos-1x/pull/1418

Jul 19 2022, 7:16 PM · VyOS 1.4 Sagitta
zsdc changed the status of T4546: Does not connect Cisco spoke to VyOS hub. from Open to Confirmed.
Jul 19 2022, 7:01 PM · VyOS 1.4 Sagitta
RyVolodya created T4546: Does not connect Cisco spoke to VyOS hub..
Jul 19 2022, 6:58 PM · VyOS 1.4 Sagitta
Viacheslav claimed T4545: Rewrite show nat source rules.
Jul 19 2022, 5:04 PM · VyOS 1.4 Sagitta
Viacheslav created T4545: Rewrite show nat source rules.
Jul 19 2022, 5:04 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T4544: Generate schema definitions from standardized op-mode scripts.
Jul 19 2022, 1:28 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T3993: Extend HTTP API GraphQL support: T4544: Generate schema definitions from standardized op-mode scripts.
Jul 19 2022, 1:09 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4544: Generate schema definitions from standardized op-mode scripts: T3993: Extend HTTP API GraphQL support.
Jul 19 2022, 1:09 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4544: Generate schema definitions from standardized op-mode scripts: T2719: Standardized op mode script structure.
Jul 19 2022, 1:07 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T2719: Standardized op mode script structure: T4544: Generate schema definitions from standardized op-mode scripts.
Jul 19 2022, 1:07 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
jestabro triaged T4544: Generate schema definitions from standardized op-mode scripts as Normal priority.
Jul 19 2022, 1:06 PM · VyOS 1.4 Sagitta
zsdc triaged T4542: route-map: "match prefix-len" incorrect behavior as Low priority.
Jul 19 2022, 12:41 PM · VyOS 1.4 Sagitta
zsdc changed the status of T4542: route-map: "match prefix-len" incorrect behavior from Open to Confirmed.

This is a behavior "by design". The prefix-len option cannot be used for BGP routes. We should add this notice to the CLI.
Check: http://docs.frrouting.org/en/latest/routemap.html#clicmd-match-ip-address-prefix-len-0-32

Jul 19 2022, 12:41 PM · VyOS 1.4 Sagitta
Viacheslav created T4543: Show source nat statistics shows incorrect interface.
Jul 19 2022, 12:07 PM · VyOS 1.4 Sagitta
aalmenar added a comment to T160: Support NAT64.

While i like the inclusion of NAT64 inside vyos (And the effort vfreex has made), i believe that tayga is not the way to go, it was last updated on 2010-12-12 according to the readme in it. Jool on the other hand has a bigger throughput being kernel module. The only issue i believe is the module compilation cause configuration is quite easy.

Jul 19 2022, 11:05 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
c-po added a comment to T4542: route-map: "match prefix-len" incorrect behavior.

Can you check with the latest rolling release? it uses FRR 8.3

Jul 19 2022, 9:21 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4542: route-map: "match prefix-len" incorrect behavior.

Probably a problem with FRR

Jul 19 2022, 6:59 AM · VyOS 1.4 Sagitta
Unknown Object (User) renamed T4542: route-map: "match prefix-len" incorrect behavior from route-map: "match prefix-len" does not function correctly to route-map: "match prefix-len" incorrect behavior.
Jul 19 2022, 6:55 AM · VyOS 1.4 Sagitta
Unknown Object (User) created T4542: route-map: "match prefix-len" incorrect behavior.
Jul 19 2022, 6:52 AM · VyOS 1.4 Sagitta
c-po added a comment to T4515: Reduce telegraf binary size.

Will be fixed in the next rolling release. Thanks!

Jul 19 2022, 6:33 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEX0c10980c37d2: smoketest: telegraf: use generic service availability check.
Jul 19 2022, 6:32 AM
c-po added a comment to T4533: Radius clients don’t have simple permissions.

@dannyvanderaa this is true - but as of VyOS 1.3 there is no longer an operator mode due to security issues. Operator level was removed, it will come back once the entire codebase rewrite is complete.

Jul 19 2022, 6:27 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dannyvanderaa added a comment to T4533: Radius clients don’t have simple permissions.

Several access levels are required on our end. In my opinion an operator / read only user should also be able to perform some basic commands (like ping and arp)

Jul 19 2022, 5:34 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

Jul 18 2022

c-po committed rVYOSONEX82d8494d349e: macsec: T4537: support online ciper and source-interface re-configuration.
Jul 18 2022, 9:48 PM
c-po committed rVYOSONEX393355f7feaa: macsec: T4537: allow 32-byte keys for gcm-aes-256.
Jul 18 2022, 9:48 PM
c-po added a comment to T4537: MACsec not working with cipher gcm-aes-256.

Also cipher changes require a reboot. Nice bug - thanks for this riddle ;)

Jul 18 2022, 8:34 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po claimed T4537: MACsec not working with cipher gcm-aes-256.
Jul 18 2022, 8:27 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
l.austenfeld added a comment to T4515: Reduce telegraf binary size.

This change currently removes the nstat plugin which is used in the configuration (https://github.com/vyos/vyos-1x/blob/current/data/templates/monitoring/telegraf.j2#L108).
This results in telegraf crashing on startup. Adding the plugin back to the https://github.com/vyos/vyos-build/blob/current/packages/telegraf/plugins/inputs/all/all.go file fixes this (Tested by compiling a patched package and installing it on a broken install).
As far as I can tell this is the only missing plugin.

Jul 18 2022, 6:06 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4537: MACsec not working with cipher gcm-aes-256.

Also, there are no any Inbound/Outbound packets with aes-256

vyos@r14:~$ sudo ip -s macsec show
7: macsec1: protect on validate strict sc off sa off encrypt off send_sci on end_station off scb off replay off 
    cipher suite: GCM-AES-256, using ICV length 16
    TXSC: eeb5e212f04f0001 on SA 0
    stats: OutPktsUntagged InPktsUntagged OutPktsTooLong InPktsNoTag InPktsBadTag InPktsUnknownSCI InPktsNoSCI InPktsOverrun
                         0              0              0           0            0                0           0             0
    stats: OutPktsProtected OutPktsEncrypted OutOctetsProtected OutOctetsEncrypted
                          0                0                  0                  0
    offload: off 
vyos@r14:~$

But service starts without issues:

vyos@r14:~$ sudo systemctl status [email protected]
● [email protected] - WPA supplicant daemon (macsec-specific version)
     Loaded: loaded (/lib/systemd/system/[email protected]; disabled; vendor preset: enabled)
     Active: active (running) since Mon 2022-07-18 20:07:16 EEST; 18min ago
   Main PID: 1802 (wpa_supplicant)
      Tasks: 1 (limit: 9411)
     Memory: 4.4M
        CPU: 101ms
     CGroup: /system.slice/system-wpa_supplicant\x2dmacsec.slice/[email protected]
             └─1802 /sbin/wpa_supplicant -c/run/wpa_supplicant/vxlan1.conf -Dmacsec_linux -ivxlan1
Jul 18 2022, 5:42 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEXfc395620cc8d: bgp: T4490: check peer-group for AFI/SAFI before issuing warning.
Jul 18 2022, 3:58 PM
c-po added a comment to T4490: BGP- warning message that AFI/SAFI is needed to establish the neighborship.
set protocols bgp local-as 200
set protocols bgp peer-group foo remote-as external
set protocols bgp peer-group foo address-family ipv4-unicast  ipv6-unicast
set protocols bgp neighbor 1.1.1.1 peer-group foo
commit
Jul 18 2022, 3:46 PM · VyOS 1.4 Sagitta
c-po added a comment to T4541: Improve `strip-private` to make stripped configs reproducible.

This might confuse the users as now there is sensitive information again, but a different one.

Jul 18 2022, 11:53 AM · VyOS Rolling
zsdc created T4541: Improve `strip-private` to make stripped configs reproducible.
Jul 18 2022, 11:47 AM · VyOS Rolling
c-po closed T4539: qat: update Intel QuickAssist release version 1.7.L.4.16.0-00017, a subtask of T3318: Update Linux Kernel to v5.4.208 / 5.10.142, as Resolved.
Jul 18 2022, 11:33 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4539: qat: update Intel QuickAssist release version 1.7.L.4.16.0-00017 as Resolved.
Jul 18 2022, 11:33 AM · VyOS 1.4 Sagitta
c-po closed T4540: firmware: update to Linux release 20220708, a subtask of T3318: Update Linux Kernel to v5.4.208 / 5.10.142, as Resolved.
Jul 18 2022, 11:32 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4540: firmware: update to Linux release 20220708 as Resolved.
Jul 18 2022, 11:32 AM · VyOS 1.4 Sagitta
c-po created T4540: firmware: update to Linux release 20220708.
Jul 18 2022, 11:29 AM · VyOS 1.4 Sagitta
c-po created T4539: qat: update Intel QuickAssist release version 1.7.L.4.16.0-00017.
Jul 18 2022, 11:27 AM · VyOS 1.4 Sagitta
c-po closed T4228: bond: OS error thrown when two bonds use the same member as Resolved.
Jul 18 2022, 11:21 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po closed T4522: bond: add ability to specify mii monitor interval via CLI as Resolved.
Jul 18 2022, 11:21 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4525: Delete interface from VRF and add it to bonding error as Resolved.
Jul 18 2022, 11:21 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4525: Delete interface from VRF and add it to bonding error from Open to Finished on the VyOS 1.4 Sagitta board.
Jul 18 2022, 11:21 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4534: bond: bridge: error out if member interface is assigned to a VRF instance as Resolved.
Jul 18 2022, 11:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4534: bond: bridge: error out if member interface is assigned to a VRF instance, a subtask of T4525: Delete interface from VRF and add it to bonding error, as Resolved.
Jul 18 2022, 11:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po closed T4521: bond: ARP monitor interval is not configured despite set via CLI as Resolved.
Jul 18 2022, 11:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4521: bond: ARP monitor interval is not configured despite set via CLI from In Progress to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Jul 18 2022, 11:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4522: bond: add ability to specify mii monitor interval via CLI from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Jul 18 2022, 11:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4525: Delete interface from VRF and add it to bonding error from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Jul 18 2022, 11:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T2763: New SNMP resource request - SNMP over TCP from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Jul 18 2022, 11:20 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T4532: Flow-accounting IPv6 server/receiver bug from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Jul 18 2022, 11:20 AM · VyOS 1.3 Equuleus (1.3.2)
c-po moved T4534: bond: bridge: error out if member interface is assigned to a VRF instance from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Jul 18 2022, 11:19 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
a.apostoliuk updated the task description for T4538: Macsec does not work correctly when the interface status changes..
Jul 18 2022, 11:18 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
a.apostoliuk created T4538: Macsec does not work correctly when the interface status changes..
Jul 18 2022, 11:17 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po committed rVYOSONEX3907233b51e7: smoketest: bond: add testcase for source-interface re-use.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEX84f2c0bf4731: bond: T4521: ARP monitor interval is not configured despite set via CLI.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEXd88912616a7d: smoketest: bond: add testcase for conflicting bridge member.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEX872423e103a7: bond: T1557: re-add miimon configuration - lost in translation.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEXd5ed752207bb: smoketest: bond: remove second instance of layer2+3 hash-policy test.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEX905fe01e1d9b: vyos.configdict(): T4228: is_member() must use the "real" hardware interface.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEX3bcc6df1a917: vyos.configdict(): T4228: is_member() must split VLAN interfaces.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEX57d54b249ff0: bond: T4522: add ability to specify mii monitor interval via CLI.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEX3a1c690e22e3: vrf: T4527: Prevent to create VRF with reserved names (authored by Viacheslav).
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEX51455fc033cd: smoketest: bridge: also test QinQ bridge member interfaces.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEX37416e650399: vyos.configdict(): T4228: is_member() must return member interface config dict.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEX752ddaff0a80: bond: bridge: T4534: error out if member interface is assigned to a VRF instance.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEX8bbde6597951: bond: T4525: fix adding member interface to bond after removing VRF.
Jul 18 2022, 11:13 AM
c-po committed rVYOSONEX6f53eb48d5c9: interfaces: T4525: interfaces can not be member of a bridge/bond and a VRF.
Jul 18 2022, 11:13 AM
GitHub <[email protected]> committed rVYOSONEX91efb252a73a: Merge pull request #1406 from c-po/equuleus-interface-fixes (authored by dmbaturin).
Jul 18 2022, 11:13 AM
diekos added a comment to T3435: NAT rules show corruption.

Confirmed to work correctly on version VyOS 1.4-rolling-202207180802.

Jul 18 2022, 11:09 AM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX7094674f13d8: smoketest: T4532: Fix for smoketest flow-accounting.
Jul 18 2022, 11:01 AM
GitHub <[email protected]> committed rVYOSONEX0665732aa917: Merge pull request #1415 from sever-sever/T4532-eq-smoketest (authored by dmbaturin).
Jul 18 2022, 11:01 AM
c-po closed T4535: FRR: upgrade to stable/8.3 version as Resolved.
Jul 18 2022, 10:34 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4533: Radius clients don’t have simple permissions.

As I know we have not access by level for now, maybe we should keep shell:priv-lvl=15 by default?

Jul 18 2022, 10:21 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav closed T4523: OP-mode Extend conntrack output to get marks, zones and directions as Resolved.
Jul 18 2022, 8:54 AM · VyOS 1.4 Sagitta
Viacheslav closed T4371: Copy contribution guideline from vyos-1x as Resolved.

Done https://github.com/vyos/vyos-vm-images/commit/bafe06bbbf4d67a98c78c01f1cef379eb6d13fa1

Jul 18 2022, 8:48 AM · Restricted Project
daniil changed the status of T4030: SR-IOV and interface renaming bug from Open to Blocked.

Duplicate T3871

Jul 18 2022, 8:38 AM · VyOS 1.4 Sagitta
c-po added a comment to T4533: Radius clients don’t have simple permissions.

It is operator level, that shouldn’t have permission for configurations. Only basic diagnostics (op-mode)

Jul 18 2022, 8:35 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po reopened T4170: Rename "policy ipv6-route" -> "policy route6" as "In progress".
Jul 18 2022, 7:41 AM · VyOS 1.4 Sagitta
c-po added a comment to T4170: Rename "policy ipv6-route" -> "policy route6".

This seems to be more inconsistent than it has been before.

Jul 18 2022, 7:41 AM · VyOS 1.4 Sagitta
a.apostoliuk created T4537: MACsec not working with cipher gcm-aes-256.
Jul 18 2022, 7:40 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4327: Ethernet interface configuration fails on Hyper-V due to speed/duplex/autoneg ethtool command error.

It works fine with my environment. With the new image too:
VyOS 1.4-rolling-202207160217

Jul 18 2022, 7:17 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4533: Radius clients don’t have simple permissions.

It is operator level, that shouldn’t have permission for configurations. Only basic diagnostics (op-mode)

Jul 18 2022, 6:53 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta