In T915#73587, @Cheeze_It wrote:One thing I did notice that did not work (and I think this would more or less be due to other options that can be enabled that FRR currently doesn't have yet) was that LSP pings from the Junipers directly connected to the Vyos VM failed but that's due to a specific corner case. FRR currently doesn't support explicit null in LDP, and Vyos doesn't have it implemented. However that shouldn't cause a problem in the current role that Vyos has. As an MPLS P Vyos works absolutely how it needs to. This seems to have a fix in FRR 7.4 as well per note "Ingress packets coming through broken LSP are no longer dropped." I would say that for what it's worth....I think we're good here. I think that the new additions are working as expected. So I am unsure if the ordered label allocation will be added later when things are moved to FRR 7.4, or if you'll put in that now @Viacheslav. But for what it is, MPLS support with LDP is verifiably working as it should be per the implementation in FRR 7.3.1. Thank you sir :)
- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
Feed All Stories
All Stories
All Stories
Jun 15 2024
Jun 15 2024
c-po committed rVYOSONEXdcb5d50abd66: T6487: updated central workflows to use current branch (authored by Vijayakumar).
GitHub <[email protected]> committed rVYOSONEX5d46c64a3041: Merge pull request #3648 from vyos/mergify/bp/sagitta/pr-3647 (authored by c-po).
c-po committed rVYOSONEX36fa614b02f8: T6487: updated central workflows to use current branch (authored by Vijayakumar).
c-po changed the status of T6489: Add/Improve support for CLI config scripts that change the underlayin actual configuration and make them work with vyos-configd from Open to In progress.
c-po moved T6484: Smoketest fails: fastnetmon killed due to OOM from Finished to In Progress on the VyOS 1.4 Sagitta (1.4.1) board.
c-po moved T6484: Smoketest fails: fastnetmon killed due to OOM from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
Jun 14 2024
Jun 14 2024
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX833b33403f17: op-mode: T6480: must call pki.py helper as root to work with ACME certificates (authored by c-po).
GitHub <[email protected]> committed rVYOSONEXf3d3b0fc0280: Merge pull request #3645 from c-po/pki-T6480 (authored by c-po).
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEX015bd0c75970: op-mode: T6407: "generate pki" missed to mangle in ACME certificates when… (authored by c-po).
GitHub <[email protected]> committed rVYOSONEXcbb22347f7e5: Merge pull request #3646 from c-po/pki-T6407 (authored by c-po).
I sure hope this custom waagent build will be removed once the upstream (debian packages) have been updated with this fix.
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXff4582c30b25: T6487: updated central workflows to use current branch (authored by Vijayakumar).
Mergify <37929162+mergify[bot]@users.noreply.github.com> committed rVYOSONEXc47d65157c28: T6487: updated central workflows to use current branch (authored by Vijayakumar).
GitHub <[email protected]> committed rVYOSONEX9d5f2dca9c0a: Merge pull request #3647 from vyos/T6487-update-central-workflow-branch (authored by c-po).
You are right @blueish, better to spend time on something more meaningful
@syncer I could try. I'm just not sure what the motivation/use-case would be? I can think only of very specific cases where someone would want to do mirror thus I'm not sure if it justifies the existence in the docs. Someone may want to have local mirror if they do a lot of reruns of the image build process but that's seems like very much edge-case.
c-po moved T6484: Smoketest fails: fastnetmon killed due to OOM from Backlog to In Progress on the VyOS 1.4 Sagitta (1.4.1) board.
c-po moved T6484: Smoketest fails: fastnetmon killed due to OOM from Open to Finished on the VyOS 1.5 Circinus board.
c-po changed the status of T6484: Smoketest fails: fastnetmon killed due to OOM from Open to In progress.
GitHub <[email protected]> committed rVYOSONEXa7608991a8b3: Merge pull request #3609 from vyos/mergify/bp/equuleus/pr-3596 (authored by c-po).
Vijayakumar closed T6476: add sonar workflow to vyos-1x current, a subtask of T6309: Check code quality with CodeQL, as Resolved.
Vijayakumar closed T6469: Remove J2Lint workflow from vyos-1x, a subtask of T6309: Check code quality with CodeQL, as Resolved.
Viacheslav triaged T6486: Generate openvpn client-config ignores configured protocol type as Normal priority.
I can now reproduce the issue. The reason I was unable to reproduce this was I missed out that you use an ACME certificate
c-po changed the status of T6480: PermissionError: [Errno 13] Permission denied: '/config/auth/letsencrypt/live/..../cert.pem from Open to In progress.
There is another incompatibility:
The first step in support this is to build the kernel modules thunderbolt and thunderbolt-net.
vyos@vyos:~$ generate ipsec profile windows-remote-access support remote ipsec.somedomain
Traceback (most recent call last):
File "/usr/libexec/vyos/op_mode/ikev2_profile_generator.py", line 153, in <module>
cert_data = load_certificate(pki['certificate'][cert_name]['certificate'])
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^
KeyError: 'certificate'
vyos@vyos:~$ show ver | match Version:
Version: VyOS 1.5-rolling-202406130020
vyos@vyos:~$While I think the mismatch between PBR-addressable RTs and VRF RTs is a bit odd, the PR's been rejected and could be addressed differently in any case. In the meantime, VRFs with RTs 100-200 are targetable by PBR.
Jun 13 2024
Jun 13 2024
here we can add some prevention to raise error, to avoid that someone uses in EBGP a profile to IBGP, because, the problem is under FRR which syntax brakes the frr-cli.
You are correct, it was a misconfiguration, but there is no way to remove the error.
You need to remove the whole BGP in order to correct the mistake.
How did you manage to revert the error?
This is not the latest image. Please use 1.5-rolling-202406130020
c-po moved T6473: bgp: missing completion helper for peer-groups inside a VRF from In Progress to Finished on the VyOS 1.4 Sagitta (1.4.1) board.
There is no need for set pki letsencrypt or set pki acme as a PEM wil always be provided and we have a common PEM framework.
I've tested it, the problem here is because you change a wrong local role , in your configuration is a rs-client ( IBGP relationship) but when you move to rs-server ( only works with EBGP , this attribute reflect EBGP routes to bgp router clients ) , so, that it's reason why you are not allowed to change :
VyOS :
vyos@vyos# run show configuration commands | match bgp set protocols bgp neighbor 10.88.88.255 address-family ipv4-unicast set protocols bgp neighbor 10.88.88.255 peer-group 'FAST' set protocols bgp peer-group FAST capability dynamic set protocols bgp peer-group FAST graceful-restart 'enable' set protocols bgp peer-group FAST local-role rs-client set protocols bgp peer-group FAST password 'F@st123!' set protocols bgp peer-group FAST remote-as '211186' set protocols bgp peer-group FAST update-source '10.88.88.2' set protocols bgp system-as '211186' [edit] vyos@vyos# delete protocols bgp peer-group FAST local-role rs-client [edit] vyos@vyos# commit [edit]
syncer triaged T6473: bgp: missing completion helper for peer-groups inside a VRF as Normal priority.
natali-rs1985 changed the status of T5810: Add support for RPKI source ip from In progress to On hold.
Have to pospone it untill upgrade FRRouting to version 10.1
GitHub <[email protected]> committed rVYOSONEX64d67529c341: Merge pull request #3643 from HollyGurza/T5725-equuleus (authored by dmbaturin).
khramshinr <[email protected]> committed rVYOSONEXaec27085df23: T5725: Improve protocol IS-IS config validation.
GitHub <[email protected]> committed rVYOSONEX1abf323d378b: Merge pull request #3639 from natali-rs1985/T5487-current (authored by dmbaturin).
zsdc moved T6038: Losing default route after first reboot (cloud-init & DHCP) from In Progress to Finished on the VyOS 1.5 Circinus board.
zsdc closed T6038: Losing default route after first reboot (cloud-init & DHCP), a subtask of T5907: cloud-init root task for 1.5 and 1.4 , as Resolved.
Andrew Topp <[email protected]> committed rVYOSONEXe74859243042: T6456: Convert "monitor traffic" to modern op-mode wrapper.
GitHub <[email protected]> committed rVYOSONEXe1916a16627f: Merge pull request #3601 from talmakion/bugfix/T6456 (authored by dmbaturin).
zsdc closed T5351: VyOS deployed with cloud-init improperly saves config.boot, a subtask of T5907: cloud-init root task for 1.5 and 1.4 , as Resolved.
The only reason I see why this can happen is that the config.boot format can be unexpected. But this should not happen anymore, because now Cloud-init always runs migrations before doing any work, which should always add required metadata if the original file is a valid VyOS config.
GitHub <[email protected]> committed rVYOSONEXc4269a9ddb03: Merge pull request #3590 from talmakion/feature/T6045 (authored by dmbaturin).
zsdc added a comment to T6405: Add disk_setup and mounts in vyos cloud-init config under cloud_init_modules .
I tend to say that this is not necessary and very dangerous. These modules can easily destroy the VyOS filesystem when used improperly.
c-po changed the status of T861: add secure boot support, a subtask of T858: Full UEFI support, from Open to Confirmed.
L0crian placed T5931: Add option to append route-target when adding additional imports up for grabs.
syncer triaged T6483: Please include corresponding source packages for all .deb packages in APT repo as Wishlist priority.
Viacheslav renamed T6482: LLDP shows description instead of remote port from LLDP shows description instread of remote port to LLDP shows description instead of remote port.
I think this one would be fixed by my PR for https://vyos.dev/T6045
natali-rs1985 changed the status of T3202: Enable wireguard debug messages by default from Open to In progress.
natali-rs1985 changed the status of T6012: Ability to have IPv6 nexthops for IPv4 static routes from In progress to Open.
natali-rs1985 changed the status of T6012: Ability to have IPv6 nexthops for IPv4 static routes from Open to In progress.
GitHub <[email protected]> committed rVYOSONEX31f8e5ec6a75: Merge pull request #3644 from natali-rs1985/T6227-current (authored by c-po).
GitHub <[email protected]> committed rVYOSONEX95b62fbc35b3: Merge pull request #3640 from vyos/mergify/bp/sagitta/pr-3638 (authored by c-po).
@bernhardschmidt Are you able to share the relevant pieces of your VXLAN and VRF config as well?