Page MenuHomeVyOS Platform
Feed All Stories

Feb 5 2019

syncer edited projects for T1230: Improving Boot Time for Large Firewall Configurations, added: VyOS 1.2 Crux (VyOS 1.2.2); removed VyOS 1.2 Crux.
Feb 5 2019, 2:17 PM · VyOS 1.3 Equuleus (1.3.6)
syncer triaged T1209: OSPF max-metric values over 100 cause commit errors as Normal priority.
Feb 5 2019, 2:16 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer changed the status of T1209: OSPF max-metric values over 100 cause commit errors from Open to In progress.
Feb 5 2019, 2:16 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer edited projects for T1208: 'install images' fails on removable storage, added: VyOS 1.3 Equuleus; removed VyOS 1.2 Crux.
Feb 5 2019, 2:15 PM · VyOS 1.3 Equuleus (1.3.0)
syncer edited projects for T1232: template.ovf has an incorrect parent id preventing it from loading in vCenter, added: VyOS 1.3 Equuleus; removed VyOS 1.2 Crux.
Feb 5 2019, 2:15 PM · Rejected
syncer moved T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups from Needs Triage to In Progress on the VyOS 1.2 Crux (VyOS 1.2.2) board.
Feb 5 2019, 2:14 PM · VyOS 1.3 Equuleus (1.3.8)
syncer reopened T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups as "In progress".
Feb 5 2019, 2:14 PM · VyOS 1.3 Equuleus (1.3.8)
syncer closed T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups as Resolved.
Feb 5 2019, 2:14 PM · VyOS 1.3 Equuleus (1.3.8)
syncer edited projects for T1051: Update openvpn to support TLS 1.2, added: VyOS 1.2 Crux (VyOS 1.2.2); removed VyOS 1.2 Crux (VyOS 1.2.0-GA).
Feb 5 2019, 2:13 PM · VyOS 1.2 Crux (VyOS 1.2.2)
syncer edited projects for T1148: epa2 BGP peers initiate before config is fully loaded, routes leak., added: VyOS 1.2 Crux (VyOS 1.2.2); removed VyOS 1.2 Crux (VyOS 1.2.0-GA).
Feb 5 2019, 2:13 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer created VyOS 1.2 Crux (VyOS 1.2.3).
Feb 5 2019, 2:11 PM
syncer created VyOS 1.2 Crux (VyOS 1.2.2).
Feb 5 2019, 2:11 PM
ddiguru created T1232: template.ovf has an incorrect parent id preventing it from loading in vCenter.
Feb 5 2019, 1:43 PM · Rejected
Maltahl added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

@Maltahl Let me know if you still need help, please. I put the task meanwhile on-hold.

Feb 5 2019, 1:24 PM · Invalid
c-po closed T1231: Remove “service dns dynamic“ cache file on node change/delete as Resolved.
Feb 5 2019, 6:47 AM · VyOS 1.2 Crux (VyOS 1.2.1)
c-po updated the task description for T1231: Remove “service dns dynamic“ cache file on node change/delete.
Feb 5 2019, 6:34 AM · VyOS 1.2 Crux (VyOS 1.2.1)
c-po renamed T1231: Remove “service dns dynamic“ cache file on node change/delete from Remove ddclient cache file on delete to Remove “service dns dynamic“ cache file on node change/delete.
Feb 5 2019, 6:04 AM · VyOS 1.2 Crux (VyOS 1.2.1)
c-po created T1231: Remove “service dns dynamic“ cache file on node change/delete.
Feb 5 2019, 6:03 AM · VyOS 1.2 Crux (VyOS 1.2.1)

Feb 4 2019

hagbard changed the status of T1226: Wireguard not working between vyos routers 1.2.0 from In progress to On hold.
Feb 4 2019, 9:38 PM · Invalid
hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

@Maltahl Let me know if you still need help, please. I put the task meanwhile on-hold.

Feb 4 2019, 9:37 PM · Invalid
EwaldvanGeffen added a comment to T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.

Configured protocols does not match Proposed protocols. Try without pfs configuration on the VyOS side.

Feb 4 2019, 9:14 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
rps added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

My fault for not having the time to test this as one of the users who has a need for RFC compliant VRRP. The use of + for interface matching is less than ideal but if we do so we should take care to recommend that use of 802.1Q VLAN sub-interfaces not make use of the parent (untagged) interface else traffic matching will not be obvious.

Feb 4 2019, 8:35 PM · VyOS 1.3 Equuleus (1.3.8)
rps created T1230: Improving Boot Time for Large Firewall Configurations.
Feb 4 2019, 8:28 PM · VyOS 1.3 Equuleus (1.3.6)
hagbard closed T1225: wireguard implement 'set int wireguard wg0 peer name disable' to disable single peers as Resolved.

http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyos-1x/vyos-1x_1.2.0-12_all.deb next rolling release has it.

Feb 4 2019, 8:26 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard changed the status of T1226: Wireguard not working between vyos routers 1.2.0 from Open to In progress.
Feb 4 2019, 6:04 PM · Invalid
cmonck added a comment to T848: OpenNHRP / DMVPN not working in HUB mode.

Change your OSPF network type to broadcast. I had the exact same issue with a Cisco 877 Client with a VYOS hub.

Feb 4 2019, 10:27 AM · Invalid
c-po updated subscribers of T314: Unable to apply MSS Clamp with VyOS configuration.

So this problem still exists but I have no clue where to add it in our source @dmbaturin @UnicronNL

Feb 4 2019, 1:01 AM · VyOS 1.2 Crux (VyOS 1.2.2)

Feb 3 2019

kmpm removed a watcher for Active contributors: kmpm.
Feb 3 2019, 5:55 PM
njh updated the task description for T1229: Add support for unencrypted L2TPv2 client connections.
Feb 3 2019, 5:36 PM · VyOS 1.5 Circinus
njh updated the task description for T1229: Add support for unencrypted L2TPv2 client connections.
Feb 3 2019, 5:18 PM · VyOS 1.5 Circinus
njh created T1229: Add support for unencrypted L2TPv2 client connections.
Feb 3 2019, 5:17 PM · VyOS 1.5 Circinus
c-po added a comment to T1213: ddclient not functional.

Ah, there was a similar issue with dhcp last couple of weeks where quotes broke the config (T1129). Can you try using &nbsp instead of your whitespace?

Feb 3 2019, 3:49 PM · VyOS 1.2 Crux (VyOS 1.2.1)
mdsmds added a comment to T1213: ddclient not functional.

if we use a more simply string without blank as e.g.

skip "yourIP"

all seems OK. So I think there is some problem in parsing a whole quoted string.

Feb 3 2019, 12:03 PM · VyOS 1.2 Crux (VyOS 1.2.1)
mdsmds added a comment to T1213: ddclient not functional.

just what I've post
dynamic {

interface eth1 {
    service dyndns {
        host-name xxxxx.mine.nu
        host-name yyyyy.dnsalias.com
        login someuser
        password somepsw
    }
    use-web {
        skip "this is your IP"
        url http://www.web.net/GetRemoteIP.asp
    }
}

}

Feb 3 2019, 11:16 AM · VyOS 1.2 Crux (VyOS 1.2.1)
cmonck created T1228: pppoe default-route force option not working (Rel 1.2.0-rc11).
Feb 3 2019, 11:00 AM · VyOS 1.2 Crux (VyOS 1.2.5)

Feb 2 2019

Maltahl added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

@Maltahl Did you try the same with the rolling release? I don't see any issue with your config in particular, did you check that the wg traffic is actually getting to your router02?

Feb 2 2019, 9:49 PM · Invalid
hagbard added a comment to T1218: Static routes not being applied in 1.2 Release.

Hmm, I have 7.1-dev-1~debian8+1 on a rolling and 3 blackhole routes and no issues at all.

Feb 2 2019, 7:06 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard claimed T1226: Wireguard not working between vyos routers 1.2.0.
Feb 2 2019, 5:29 PM · Invalid
hagbard added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

@Maltahl Did you try the same with the rolling release? I don't see any issue with your config in particular, did you check that the wg traffic is actually getting to your router02?

Feb 2 2019, 5:28 PM · Invalid
c-po added a comment to T1213: ddclient not functional.

Con you provide a configuration to reproduce the issue?

Feb 2 2019, 4:26 PM · VyOS 1.2 Crux (VyOS 1.2.1)
mdsmds reopened T1213: ddclient not functional as "Open".

server OK but now we get ERROR:
Feb 2 16:51:21 VyosCP ddclient[5968]: FAILED: updating is: notfqdn: A Fully-Qualified Domain Name was not provided
Feb 2 16:56:21 VyosCP ddclient[5968]: WARNING: file /var/cache/ddclient/ddclient.cache, line 5: Invalid Value for keyword 'ip' = ''
Feb 2 16:56:22 VyosCP ddclient[5968]: FAILED: updating is: notfqdn: A Fully-Qualified Domain Name was not provided
Feb 2 17:05:28 VyosCP ddclient[4710]: WARNING: file /var/cache/ddclient/ddclient.cache, line 5: Invalid Value for keyword 'ip' = ''
Feb 2 17:05:36 VyosCP ddclient[4710]: FAILED: updating is: notfqdn: A Fully-Qualified Domain Name was not provided

Feb 2 2019, 4:12 PM · VyOS 1.2 Crux (VyOS 1.2.1)
runar added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

That is not how wireguard works ? that is how ipsec and openvpn works.

This is how ipv4 works :) and have nothing to do with wireguard, ipsec etc. Actually the config you have applied eill in some situations work, but that relies on the handling of the packets inside the kernel and is not following the tcp/ip principles... If you take a look on the quick start guide on the wireguard webpage you se it there aswell... https://www.wireguard.com/quickstart/.

Feb 2 2019, 3:34 PM · Invalid
Maltahl added a comment to T1226: Wireguard not working between vyos routers 1.2.0.
In T1226#32008, @runar wrote:

Hi! I see that your tunnels does not resides inside the same subnet, one devise is '10.0.90.1/24' and the other one '10.0.100.1/24'.. please move one of then to ip .2 in the subnet belonging to the other router.

Feb 2 2019, 3:16 PM · Invalid
primoz added a comment to T1218: Static routes not being applied in 1.2 Release.

After some more playing with it ... it solves the problem reproducibly to have staticd=yes included and NOT have the null route anywhere.

Feb 2 2019, 1:15 PM · VyOS 1.2 Crux (VyOS 1.2.1)
primoz added a comment to T1218: Static routes not being applied in 1.2 Release.

It solved it for me yesterday. After some more playing today this now seems to be a frr bug.

Feb 2 2019, 12:30 PM · VyOS 1.2 Crux (VyOS 1.2.1)
dmbaturin added a comment to T1218: Static routes not being applied in 1.2 Release.

@primoz Adding staticd to the daemons config fixes the issue reproducibly on affected systems, even after reboot?

Feb 2 2019, 12:05 PM · VyOS 1.2 Crux (VyOS 1.2.1)
SteveP added a comment to T1066: Missing NICs.

I have done a bit more work on this problem and, correct me if I'm wrong, I no longer think it is driver related.

Feb 2 2019, 11:30 AM · VyOS 1.2 Crux (VyOS 1.2.1)
mschmidt72 created T1227: rip PW can't be set at interface config.
Feb 2 2019, 10:59 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po added a comment to T1218: Static routes not being applied in 1.2 Release.

I can confirm this. 1.2.0-EPA3 does not have thisbissue but 1.2.0 has it.

Feb 2 2019, 9:53 AM · VyOS 1.2 Crux (VyOS 1.2.1)
runar added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Hi! I see that your tunnels does not resides inside the same subnet, one devise is '10.0.90.1/24' and the other one '10.0.100.1/24'.. please move one of then to ip .2 in the subnet belonging to the other router.

Feb 2 2019, 7:48 AM · Invalid
dsummers added a comment to T1051: Update openvpn to support TLS 1.2.

Does this mean it can now listen on "outer" transport IPv6 addresses now that it is using 2.4.0 (even if it is just a special "option" and not yet in the VyOS CLI)?

Feb 2 2019, 5:54 AM · VyOS 1.2 Crux (VyOS 1.2.2)

Feb 1 2019

Maltahl added a comment to T1226: Wireguard not working between vyos routers 1.2.0.

Forgot to add version for both routers, sorry.

Feb 1 2019, 11:36 PM · Invalid
Maltahl created T1226: Wireguard not working between vyos routers 1.2.0.
Feb 1 2019, 11:31 PM · Invalid
kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

There might actually be a bit of a deeper problem here, somewhat conditional on some static interface routing. On an broken system, it does say something about staticd starting

Feb 1 2019, 9:59 PM · VyOS 1.2 Crux (VyOS 1.2.1)
Maltahl added a comment to T1218: Static routes not being applied in 1.2 Release.

Wierd, i cannot reproduce this on LTS 1.2.0 on both baremetal and virtual instances.

Feb 1 2019, 9:57 PM · VyOS 1.2 Crux (VyOS 1.2.1)
primoz added a comment to T1218: Static routes not being applied in 1.2 Release.

to /etc/frr/daemons (+ restarting frr) seems to fix this.

Feb 1 2019, 9:20 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard triaged T1225: wireguard implement 'set int wireguard wg0 peer name disable' to disable single peers as Normal priority.
Feb 1 2019, 7:00 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard claimed T1225: wireguard implement 'set int wireguard wg0 peer name disable' to disable single peers .
Feb 1 2019, 6:59 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard created T1225: wireguard implement 'set int wireguard wg0 peer name disable' to disable single peers .
Feb 1 2019, 6:59 PM · VyOS 1.2 Crux (VyOS 1.2.1)
syncer moved T1224: UDP brodacast relay configs are not generated correctly from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.1) board.
Feb 1 2019, 2:24 AM · VyOS 1.2 Crux (VyOS 1.2.1)
dmbaturin changed Why the issue appeared? from none to implementation-mistake on T1224: UDP brodacast relay configs are not generated correctly.
Feb 1 2019, 2:23 AM · VyOS 1.2 Crux (VyOS 1.2.1)
dmbaturin closed T1224: UDP brodacast relay configs are not generated correctly as Resolved.
Feb 1 2019, 2:23 AM · VyOS 1.2 Crux (VyOS 1.2.1)
dmbaturin created T1224: UDP brodacast relay configs are not generated correctly.
Feb 1 2019, 2:16 AM · VyOS 1.2 Crux (VyOS 1.2.1)
dmbaturin added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

@jmlccdmd Ok, I'll re-test with in/out then.

Feb 1 2019, 2:13 AM · VyOS 1.3 Equuleus (1.3.8)
hexes triaged T1223: Zabbix Proxy crash on actual version of VyOS as Normal priority.
Feb 1 2019, 12:40 AM · Active contributors

Jan 31 2019

hagbard changed the status of T1051: Update openvpn to support TLS 1.2 from Open to Needs testing.

@thinkl33t Would you mind testing your use case with https://downloads.vyos.io/rolling/current/amd64/vyos-1.2.0-rolling%2B201901312041-amd64.iso or later? This iso is using the bpo package of openvpn (2.4.0).

Jan 31 2019, 8:14 PM · VyOS 1.2 Crux (VyOS 1.2.2)
hagbard added a comment to T1051: Update openvpn to support TLS 1.2.

@thinkl33t http://dev.packages.vyos.net/repositories/current/vyos/pool/main/o/openvpn/openvpn_2.4.0-6+deb9u1~bpo8+1_amd64.deb

Jan 31 2019, 7:41 PM · VyOS 1.2 Crux (VyOS 1.2.2)
c-po added a comment to T1214: Add `ipaddrcheck` to the packages directory.

Package needs to be build from source. There are already some packages which we build that way like libyang or librtr so not a big deal.

Jan 31 2019, 6:27 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
daniil updated the task description for T1222: OSPF routing problem - route looping.
Jan 31 2019, 4:56 PM · VyOS 1.3 Equuleus (1.3.0-epa1), vyos-frr
daniil updated the task description for T1222: OSPF routing problem - route looping.
Jan 31 2019, 4:55 PM · VyOS 1.3 Equuleus (1.3.0-epa1), vyos-frr
daniil updated the task description for T1222: OSPF routing problem - route looping.
Jan 31 2019, 4:53 PM · VyOS 1.3 Equuleus (1.3.0-epa1), vyos-frr
daniil created T1222: OSPF routing problem - route looping.
Jan 31 2019, 4:41 PM · VyOS 1.3 Equuleus (1.3.0-epa1), vyos-frr
daniil changed Difficulty level from unknown to easy on T1220: Show transceiver information from plugin modules, e.g SFP+, QSFP.
Jan 31 2019, 1:47 PM · VyOS 1.2 Crux (VyOS 1.2.6)
patrickbrandao created T1221: BGP - Default route injection is not processed by the specific route-map in the S1 VyOS Public space.
Jan 31 2019, 12:56 PM · VyOS 1.2 Crux (VyOS 1.2.6)
daniil created T1220: Show transceiver information from plugin modules, e.g SFP+, QSFP.
Jan 31 2019, 10:25 AM · VyOS 1.2 Crux (VyOS 1.2.6)
daniil updated subscribers of T1219: Redundant active-active configuration, asymmetric routing and conntrack-sync cache.
Jan 31 2019, 10:24 AM · VyOS 1.2 Crux (VyOS 1.2.6), vyatta-conntrack-sync
njh added a comment to T1214: Add `ipaddrcheck` to the packages directory.

Change was reverted because "libcidr-dev is not available until Debian Buster thus the container can't be built"

Jan 31 2019, 9:20 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
njh reopened T1214: Add `ipaddrcheck` to the packages directory as "Open".
Jan 31 2019, 9:18 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
daniil changed Difficulty level from unknown to easy on T1219: Redundant active-active configuration, asymmetric routing and conntrack-sync cache.
Jan 31 2019, 8:46 AM · VyOS 1.2 Crux (VyOS 1.2.6), vyatta-conntrack-sync
daniil created T1219: Redundant active-active configuration, asymmetric routing and conntrack-sync cache.
Jan 31 2019, 8:34 AM · VyOS 1.2 Crux (VyOS 1.2.6), vyatta-conntrack-sync
kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

And more info:

Jan 31 2019, 1:11 AM · VyOS 1.2 Crux (VyOS 1.2.1)
kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

I tracked down what is causing this.

Jan 31 2019, 1:01 AM · VyOS 1.2 Crux (VyOS 1.2.1)

Jan 30 2019

hagbard closed T1217: 1.2.0 LTS cant delete wireguard wg0 interface as Resolved.

http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyos-1x/vyos-1x_1.2.0-11_all.deb or next rolling release will have the fix.

Jan 30 2019, 11:36 PM · VyOS 1.2 Crux (VyOS 1.2.1)
syncer changed the status of T1218: Static routes not being applied in 1.2 Release from Open to Confirmed.
Jan 30 2019, 11:10 PM · VyOS 1.2 Crux (VyOS 1.2.1)
syncer assigned T1218: Static routes not being applied in 1.2 Release to dmbaturin.
Jan 30 2019, 11:10 PM · VyOS 1.2 Crux (VyOS 1.2.1)
syncer moved T1217: 1.2.0 LTS cant delete wireguard wg0 interface from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.1) board.
Jan 30 2019, 11:04 PM · VyOS 1.2 Crux (VyOS 1.2.1)
syncer edited projects for T1217: 1.2.0 LTS cant delete wireguard wg0 interface, added: VyOS 1.2 Crux (VyOS 1.2.1); removed VyOS 1.2 Crux.
Jan 30 2019, 11:03 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard added a comment to T1217: 1.2.0 LTS cant delete wireguard wg0 interface.

Fix: https://github.com/vyos/vyos-1x/commit/2f70340179a64d5936c32cc3c0d6d7f6f04054d0 applied, pkg build currently running.

Jan 30 2019, 11:02 PM · VyOS 1.2 Crux (VyOS 1.2.1)
kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

Too add, routes are present in FRR

Jan 30 2019, 10:58 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard changed the status of T1217: 1.2.0 LTS cant delete wireguard wg0 interface from Confirmed to In progress.
Jan 30 2019, 10:54 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard added a comment to T1217: 1.2.0 LTS cant delete wireguard wg0 interface.

Bug confirmed.

Jan 30 2019, 10:49 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard changed the status of T1217: 1.2.0 LTS cant delete wireguard wg0 interface from Open to Confirmed.
Jan 30 2019, 10:48 PM · VyOS 1.2 Crux (VyOS 1.2.1)
kroy created T1218: Static routes not being applied in 1.2 Release.
Jan 30 2019, 10:44 PM · VyOS 1.2 Crux (VyOS 1.2.1)
Maltahl added a comment to T1217: 1.2.0 LTS cant delete wireguard wg0 interface.
fma@glos1ce1dk:~$ sh ver
Version:          VyOS 1.2.0
Built by:         Sentrium S.L.
Built on:         Sun 27 Jan 2019 19:08 UTC
Build ID:         795d6338-c1ce-4ebb-992f-d064f5af9309
Jan 30 2019, 10:36 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard added a comment to T1217: 1.2.0 LTS cant delete wireguard wg0 interface.

I can't replicate it, but I'm using also the rolling release.
Can you please provide the output of:

Jan 30 2019, 10:31 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard claimed T1217: 1.2.0 LTS cant delete wireguard wg0 interface.
Jan 30 2019, 10:23 PM · VyOS 1.2 Crux (VyOS 1.2.1)
Maltahl created T1217: 1.2.0 LTS cant delete wireguard wg0 interface.
Jan 30 2019, 10:07 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard added a comment to T1051: Update openvpn to support TLS 1.2.

@c-po imported and test against latest rolling, I couldn't find any issue with 2.4.

Jan 30 2019, 8:15 PM · VyOS 1.2 Crux (VyOS 1.2.2)
amcmillen created T1216: EAP-TTLS-PAP support for RADIUS.
Jan 30 2019, 8:08 PM · VyOS 1.5 Circinus
njh created T1215: Should the vyatta-cfg-firewall control file list vyatta-wirelessmodem in Replaces?.
Jan 30 2019, 6:42 PM · VyOS 1.3 Equuleus (1.3.8)