Page MenuHomeVyOS Platform

fernando (maidana)
User

Projects

User Details

User Since
May 11 2021, 12:36 PM (157 w, 4 d)

Recent Activity

Sun, May 12

fernando closed T6303: Allow configuring system MAC address on bonding interfaces with LACP as Resolved.
Sun, May 12, 11:53 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Sat, May 11

fernando added a comment to T6306: EVPN-MH - missing options in uplink ports .

I've tested and now is working correctly :

Sat, May 11, 7:52 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
fernando added a comment to T6303: Allow configuring system MAC address on bonding interfaces with LACP.

add documentation : https://github.com/vyos/vyos-documentation/pull/1444

Sat, May 11, 5:42 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Sat, May 4

fernando changed the status of T6306: EVPN-MH - missing options in uplink ports from Open to Confirmed.
Sat, May 4, 7:18 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
fernando created T6306: EVPN-MH - missing options in uplink ports .
Sat, May 4, 7:15 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
fernando added a comment to T6303: Allow configuring system MAC address on bonding interfaces with LACP.

PR https://github.com/vyos/vyos-1x/pull/3410

Sat, May 4, 5:36 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Fri, May 3

fernando changed the status of T6303: Allow configuring system MAC address on bonding interfaces with LACP from Open to In progress.
Fri, May 3, 2:04 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando claimed T6303: Allow configuring system MAC address on bonding interfaces with LACP.
Fri, May 3, 2:04 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando created T6303: Allow configuring system MAC address on bonding interfaces with LACP.
Fri, May 3, 2:03 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Sat, Apr 20

fernando closed T6252: GRE tunnels don't allow configuring MTU larger than 8024 as Resolved.
Sat, Apr 20, 12:03 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando added a comment to T6252: GRE tunnels don't allow configuring MTU larger than 8024.

PR: https://github.com/vyos/vyos-1x/pull/3333

Sat, Apr 20, 12:01 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Fri, Apr 19

fernando claimed T6252: GRE tunnels don't allow configuring MTU larger than 8024.
Fri, Apr 19, 9:10 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando created T6252: GRE tunnels don't allow configuring MTU larger than 8024.
Fri, Apr 19, 9:10 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 2 2024

fernando closed T6151: BGP VRF route-leaking does not work when the next-hop is a recursive route as Resolved.
Apr 2 2024, 12:37 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando added a comment to T6151: BGP VRF route-leaking does not work when the next-hop is a recursive route.

this new command was merge in order to solved this problem :

vyos@vrf-test:~$ show configuration commands | match disable
set protocols bgp parameters disable-ebgp-connected-route-check
Apr 2 2024, 12:36 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 29 2024

fernando added a comment to T6151: BGP VRF route-leaking does not work when the next-hop is a recursive route.

PR:https://github.com/vyos/vyos-1x/pull/3212

Mar 29 2024, 6:33 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando claimed T6151: BGP VRF route-leaking does not work when the next-hop is a recursive route.
Mar 29 2024, 12:57 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Mar 21 2024

fernando changed the status of T6151: BGP VRF route-leaking does not work when the next-hop is a recursive route from Open to Confirmed.
Mar 21 2024, 3:46 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Feb 22 2024

fernando created T6054: load-balancing wan - doesn't configure a list of ports .
Feb 22 2024, 10:40 PM · VyOS 1.4 Sagitta (1.4.0-epa2)

Jan 31 2024

fernando added a comment to T5997: Support ssl backends on reverse-proxy.

it think that we can use also something similar to what we use ocserv to generate ssl certificates:

Jan 31 2024, 6:10 PM · VyOS 1.5 Circinus

Jan 30 2024

fernando added a comment to T5930: vrf - route-leak not work using route-target both command..

it makes seens , agree with add a Config Error to do not allow both options simultaneously ,.

Jan 30 2024, 6:21 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Jan 29 2024

fernando added a comment to T6001: Add option to enable resolve-via-default.

as I mentioned , it was added in 9.1 as default behavior :

Jan 29 2024, 6:53 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
fernando added a comment to T6001: Add option to enable resolve-via-default.

this command was added by default in FRR , but it's supported on lasted version (9.1):

Jan 29 2024, 5:46 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus

Jan 12 2024

fernando created T5930: vrf - route-leak not work using route-target both command..
Jan 12 2024, 3:33 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Jan 10 2024

fernando added a comment to T1369: GCP Networking Failure.

i've re-checked with the new image from GCP and new cloud-init version , it seems to be working as expexted :

Jan 10 2024, 8:27 PM · VyOS 1.3 Equuleus (1.3.6), test

Dec 27 2023

fernando added a comment to T5715: IPSec VPN: restart vpn is not working.

this fix is not merge yet : https://github.com/vyos/vyatta-op-vpn/pull/37

Dec 27 2023, 8:12 PM · VyOS 1.3 Equuleus (1.3.6)

Dec 15 2023

fernando added a comment to T5796: Openconnect - HTTPS security headers are missing.

some improvements were added in this task , enable or disable the http security headers in the openconnect configuration :

Dec 15 2023, 6:55 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Dec 13 2023

fernando added a comment to T4163: [BMP-BGP] Routing monitoring feature.

when it's merge , I will test with the controller to see if we are able to get BMP with the new FRR version.

Dec 13 2023, 10:26 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
fernando changed the status of T4163: [BMP-BGP] Routing monitoring feature from Open to Needs testing.
Dec 13 2023, 10:08 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Dec 4 2023

fernando added a comment to T5796: Openconnect - HTTPS security headers are missing.

PR 1.3 : https://github.com/vyos/vyos-1x/pull/2572

Dec 4 2023, 8:01 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fernando added a comment to T5796: Openconnect - HTTPS security headers are missing.

tested on 1.5/1.4 :

Dec 4 2023, 6:46 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fernando changed the status of T5796: Openconnect - HTTPS security headers are missing from In progress to Needs testing.
Dec 4 2023, 6:45 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Dec 2 2023

fernando added a comment to T5796: Openconnect - HTTPS security headers are missing.

PR 1.5/1.4 : https://github.com/vyos/vyos-1x/pull/2564

Dec 2 2023, 5:56 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fernando changed the status of T5796: Openconnect - HTTPS security headers are missing from Open to In progress.
Dec 2 2023, 12:36 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fernando claimed T5796: Openconnect - HTTPS security headers are missing.
Dec 2 2023, 12:01 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Dec 1 2023

fernando created T5796: Openconnect - HTTPS security headers are missing.
Dec 1 2023, 2:57 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Nov 17 2023

fernando changed the status of T5754: Update to StrongSwan 5.9.11 from Open to Needs testing.

Do you tested it ? using our current rolling-release

Nov 17 2023, 6:01 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus
fernando triaged T5754: Update to StrongSwan 5.9.11 as Normal priority.
Nov 17 2023, 5:42 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.5 Circinus

Nov 13 2023

fernando closed T5563: container: Container environment variable cannot be set as Resolved.
Nov 13 2023, 2:53 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
fernando added a comment to T5595: Multicast - PIM bfd feature enable .

I'll hava a lab with PIM SSM and BFD , I'll update our documentation with those feature with example.

Nov 13 2023, 11:57 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Nov 8 2023

fernando changed the status of T5563: container: Container environment variable cannot be set from Open to Needs testing.

I've tested this flag in both version 1.4 / 1.5 , it seems to work as expected :

Nov 8 2023, 7:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
fernando added a project to T5563: container: Container environment variable cannot be set: VyOS 1.5 Circinus.
Nov 8 2023, 7:50 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
fernando closed T5648: ldpd neighbour template errors as Resolved.
Nov 8 2023, 7:07 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fernando added a comment to T5648: ldpd neighbour template errors.

tested on 1.4-rolling-202311080309

Nov 8 2023, 7:07 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Nov 6 2023

fernando changed the subtype of T5717: ospfv3 - add allow to set metric-type to ospf redistribution while frr docs says its possible. from "Bug" to "Feature Request".
Nov 6 2023, 8:06 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
fernando renamed T5717: ospfv3 - add allow to set metric-type to ospf redistribution while frr docs says its possible. from Vyos 1.5-rolling-202310060022 doesnt allow to set metric-type to ospf redistribution while frr docs says its possible. to ospfv3 - add allow to set metric-type to ospf redistribution while frr docs says its possible..
Nov 6 2023, 8:02 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
fernando added a comment to T5717: ospfv3 - add allow to set metric-type to ospf redistribution while frr docs says its possible..

it's not a bug, this command are able in ospf :

Nov 6 2023, 7:59 PM · VyOS 1.4 Sagitta (1.4.0-epa2), VyOS 1.5 Circinus
fernando added a comment to T5648: ldpd neighbour template errors.

@devon

Nov 6 2023, 7:50 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fernando added a comment to T5648: ldpd neighbour template errors.

after merge this ldp bug fixed , I saw that now it's already working . Could you check it ? I've tested on a lab and it seems to work :

Nov 6 2023, 7:49 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fernando closed T5705: rsyslog - Not working when using facility=all as Resolved.
Nov 6 2023, 7:13 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
fernando added a comment to T5705: rsyslog - Not working when using facility=all.

tested /resolved

Nov 6 2023, 7:13 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 27 2023

fernando added a comment to T5595: Multicast - PIM bfd feature enable .

PR : https://github.com/vyos/vyos-1x/pull/2411

Oct 27 2023, 11:54 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Oct 26 2023

fernando added a comment to T5357: Policy: BGP communities fail to apply when loaded from config file.

@jvoss thanks to confirm !

Oct 26 2023, 10:53 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 25 2023

fernando changed the status of T5357: Policy: BGP communities fail to apply when loaded from config file from Open to Needs testing.
Oct 25 2023, 7:39 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
fernando added a comment to T5357: Policy: BGP communities fail to apply when loaded from config file.

I've tested this issues in our lasted rolling-realese , after last commit , it seems works without problems :

vyos@vyos# load test.conf
Loading configuration from 'test.conf'
Load complete. Use 'commit' to make changes effective.
[edit]
vyos@vyos# compare
[policy]
+ route-map TEST {
+     rule 10 {
+         action "permit"
+         set {
+             community {
+                 add "65001:1"
+             }
+             large-community {
+                 add "4200000000:100:1"
+             }
+         }
+     }
+ }
Oct 25 2023, 7:38 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 24 2023

fernando added a project to T5307: QoS - traffic-class-map services : VyOS 1.5 Circinus.
Oct 24 2023, 8:40 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
fernando added a comment to T5307: QoS - traffic-class-map services .

exactly , i'll give an example of what is the improving (or new cli) , we have a policy where we can mach different DSCPs associate with REAL TIME or VIOCE . Current in our cli , it would be something like this :

Oct 24 2023, 8:36 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Oct 23 2023

fernando added a comment to T5337: MPLS/BGP: Route leak does not happen from the VPNv4 table to specific vrf.

this case was resolved lasted configuration done .

Oct 23 2023, 7:51 PM · VyOS 1.4 Sagitta
fernando closed T5337: MPLS/BGP: Route leak does not happen from the VPNv4 table to specific vrf as Resolved.
Oct 23 2023, 7:51 PM · VyOS 1.4 Sagitta
fernando added a comment to T5307: QoS - traffic-class-map services .

this task is a re-definition from a traffic class , I think it could be more clear if we separate tc-filter in a class-map , so we can define different profiles in our cli based on services :

Oct 23 2023, 7:28 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
fernando closed T5667: BGP label-unicast - enable ecmp as Resolved.
Oct 23 2023, 11:40 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Oct 22 2023

fernando added a comment to T5674: AWS add Simple Systems Manager (SSM) Agent .

I think we can do something similar to it : https://alestic.com/2018/12/aws-ssm-parameter-store-git-key/

Oct 22 2023, 1:35 PM · VyOS 1.5 Circinus

Oct 20 2023

fernando changed the status of T5667: BGP label-unicast - enable ecmp from Open to Needs testing.
Oct 20 2023, 3:28 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fernando added a comment to T5667: BGP label-unicast - enable ecmp .

PR 1.5 : https://github.com/vyos/vyos-1x/pull/2385

Oct 20 2023, 3:27 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Oct 18 2023

fernando claimed T5667: BGP label-unicast - enable ecmp .
Oct 18 2023, 9:37 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fernando renamed T5667: BGP label-unicast - enable ecmp from BG to BGP label-unicast - enable ecmp .
Oct 18 2023, 6:46 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fernando created T5667: BGP label-unicast - enable ecmp .
Oct 18 2023, 6:21 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Oct 4 2023

fernando closed T3655: NAT doesn't work correctly with VRF as Resolved.
Oct 4 2023, 7:54 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando added a comment to T3655: NAT doesn't work correctly with VRF.

for me , it's ok . I didn't see another issue related it . we can close

Oct 4 2023, 7:44 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Oct 2 2023

fernando created T5627: Multicast - PIM prune state timers expire with time longer to remove a mroute.
Oct 2 2023, 2:55 PM · VyOS 1.3 Equuleus (1.3.8)

Sep 20 2023

fernando added a project to T5487: OPENVPN -DEPRECATED OPTION: --cipher: VyOS 1.3 Equuleus (1.3.5).
Sep 20 2023, 2:55 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus, Restricted Project

Sep 18 2023

fernando claimed T5595: Multicast - PIM bfd feature enable .
Sep 18 2023, 5:16 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
fernando created T5595: Multicast - PIM bfd feature enable .
Sep 18 2023, 5:16 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Sep 13 2023

fernando added a comment to T4919: TPM-backed config encryption.

@sdev greats !!!

Sep 13 2023, 4:39 PM · VyOS 1.5 Circinus

Sep 12 2023

fernando changed the status of T3655: NAT doesn't work correctly with VRF from Backport candidate to Needs testing.
Sep 12 2023, 6:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando added a comment to T3655: NAT doesn't work correctly with VRF.

command on 1.5 :

Sep 12 2023, 6:36 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando changed the status of T3655: NAT doesn't work correctly with VRF from In progress to Backport candidate.
Sep 12 2023, 4:17 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando updated subscribers of T3655: NAT doesn't work correctly with VRF.

@vfreex I've tested in my labs related this issues , I can confirm that it work as expected . this original zone solved the problem when there was a src-nat /dst-nat with different VRFs or leaking with them ,Thanks you for this contribution .

Sep 12 2023, 4:16 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Sep 6 2023

fernando updated subscribers of T4919: TPM-backed config encryption.

@sdev take a look over these repository :

Sep 6 2023, 1:28 PM · VyOS 1.5 Circinus

Sep 4 2023

fernando changed the status of T5547: ISIS: The L1-2 router cannot advertise L1 routes into L2 from Open to Confirmed.
Sep 4 2023, 1:37 PM · VyOS 1.4 Sagitta (1.4.0-GA), Known issue
fernando created T5547: ISIS: The L1-2 router cannot advertise L1 routes into L2.
Sep 4 2023, 1:36 PM · VyOS 1.4 Sagitta (1.4.0-GA), Known issue

Aug 30 2023

fernando changed the status of T5526: Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax from Open to Confirmed.
Aug 30 2023, 6:06 PM · VyOS 1.3 Equuleus (1.3.8)
fernando created T5526: Clarify the error message when trying to set an interface as a BGP peer group using the wrong syntax.
Aug 30 2023, 6:05 PM · VyOS 1.3 Equuleus (1.3.8)

Aug 28 2023

fernando closed T2296: Upgrade WALinux to 2.2.41 as Resolved.
Aug 28 2023, 3:38 PM · VyOS 1.3 Equuleus (1.3.4)
fernando added a comment to T2296: Upgrade WALinux to 2.2.41.

we have a version updated , this case should be closed:

azureuser@vyos-support:~$ sudo /usr/sbin/waagent -version
WALinuxAgent-2.2.45 running on debian 10.12
Python: 3.7.3
Goal state agent: 2.2.45
Aug 28 2023, 3:37 PM · VyOS 1.3 Equuleus (1.3.4)

Aug 23 2023

fernando closed T5466: L3VPN - label allocation mode as Resolved.
Aug 23 2023, 1:32 PM · VyOS 1.4 Sagitta
fernando added a comment to T5466: L3VPN - label allocation mode .

I've tested our last rolling-realase , it's working as expected :

Aug 23 2023, 1:31 PM · VyOS 1.4 Sagitta

Aug 18 2023

fernando added a comment to T5481: Upgrade bug.

I couldn't open those files, but it can be related our firewall refactor :

Aug 18 2023, 9:21 PM · VyOS 1.4 Sagitta
fernando changed the status of T5487: OPENVPN -DEPRECATED OPTION: --cipher from Open to Confirmed.
Aug 18 2023, 8:07 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus, Restricted Project
fernando added a comment to T5487: OPENVPN -DEPRECATED OPTION: --cipher.

I confirm this warning message , although, on Linux doesn't affect or at least with our server/client work as expected :

Aug 18 2023, 8:05 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus, Restricted Project

Aug 17 2023

fernando created T5487: OPENVPN -DEPRECATED OPTION: --cipher.
Aug 17 2023, 4:06 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus, Restricted Project

Aug 16 2023

fernando updated the task description for T5484: set extcommunity - just allow one extend community.
Aug 16 2023, 8:29 PM · VyOS 1.3 Equuleus (1.3.8)
fernando created T5484: set extcommunity - just allow one extend community.
Aug 16 2023, 7:41 PM · VyOS 1.3 Equuleus (1.3.8)
fernando changed the status of T5466: L3VPN - label allocation mode from Open to In progress.
Aug 16 2023, 6:55 PM · VyOS 1.4 Sagitta
fernando added a comment to T5466: L3VPN - label allocation mode .

PR https://github.com/vyos/vyos-1x/pull/2152

Aug 16 2023, 6:55 PM · VyOS 1.4 Sagitta

Aug 15 2023

fernando added a comment to T5160: Firewall refactor.

yes, but it's in process to merge : https://github.com/vyos/vyos-documentation/pull/1035

Aug 15 2023, 11:31 PM · VyOS 1.4 Sagitta
fernando added a comment to T5481: Upgrade bug.

Could you share the full configuration ? so we can analyze what is the source of this problem .

Aug 15 2023, 9:48 PM · VyOS 1.4 Sagitta

Aug 11 2023

fernando claimed T5466: L3VPN - label allocation mode .
Aug 11 2023, 8:00 PM · VyOS 1.4 Sagitta
fernando created T5466: L3VPN - label allocation mode .
Aug 11 2023, 7:59 PM · VyOS 1.4 Sagitta
fernando added a comment to T5456: Add alias for "show ipv6 bgp".

Adding comments : maybe discontinue show ip bgp gives some issues / problems with automation tools (ansible o some custom script)While thinking out loud, it can be useful for new users create to alias.

Aug 11 2023, 7:49 PM · VyOS 1.4 Sagitta