Page MenuHomeVyOS Platform
Feed Advanced Search

Feb 12 2018

sergei added a comment to T542: IKE DPD timer value .

File added.

Feb 12 2018, 9:18 PM

Feb 11 2018

sebastianm edited projects for T424: Advertisement of Multiple Paths in BGP (capability 69), added: VyOS 1.1.x; removed VyOS 1.2 Crux.
Feb 11 2018, 10:26 PM · VyOS 1.1.x
syncer added a comment to T542: IKE DPD timer value .

@sergei yes, please put it here for records

Feb 11 2018, 12:45 PM
sergei added a comment to T542: IKE DPD timer value .

I found VPN tunnel with esp lifetime of 43200 sec (12 hrs) is stable. Can share my config if necessary.

Feb 11 2018, 12:44 PM

Feb 10 2018

syncer added a project to T542: IKE DPD timer value : VyOS 1.2 Crux.
Feb 10 2018, 2:18 PM
sergei added a comment to T542: IKE DPD timer value .

Found workaround for ESP lifetime issue, need monitoring for 24 hrs to verify.

Feb 10 2018, 2:10 PM
syncer triaged T542: IKE DPD timer value as Normal priority.
Feb 10 2018, 12:50 PM
syncer added a comment to T542: IKE DPD timer value .

@sergei can you check 1.2 behaviour too please

Feb 10 2018, 12:50 PM
syncer added a parent task for T542: IKE DPD timer value : Unknown Object (Maniphest Task).
Feb 10 2018, 12:49 PM
sergei created T542: IKE DPD timer value .
Feb 10 2018, 12:46 PM

Feb 6 2018

beamerblvd asked Q129: Is `sysctl -w net.ipv6.conf.eth0.accept_ra=2` still necessary?.
Feb 6 2018, 2:12 AM · VyOS 1.1.x

Feb 1 2018

c-po added a comment to T532: arp-monitor on bond interface does not commit.

@xrpixer thank you very much for the clarification. Hopefully other users can benefit from it, too.

Feb 1 2018, 6:38 AM · VyOS 1.1.x
xrpixer closed T532: arp-monitor on bond interface does not commit as Resolved.
Feb 1 2018, 5:03 AM · VyOS 1.1.x
xrpixer added a comment to T532: arp-monitor on bond interface does not commit.

Sorry for the late response on this.

Feb 1 2018, 5:03 AM · VyOS 1.1.x

Jan 29 2018

c-po added a comment to T532: arp-monitor on bond interface does not commit.

@xrpixer thanks for submitting. Any change you could double check it on a recent nightly build of VyOs 1.2.x? => https://downloads.vyos.io/?dir=rolling/current/amd64

Jan 29 2018, 7:39 AM · VyOS 1.1.x

Jan 28 2018

xrpixer created T532: arp-monitor on bond interface does not commit.
Jan 28 2018, 1:54 AM · VyOS 1.1.x

Jan 21 2018

c-po moved T523: Forwarder listening on port 53/tcp from Need Triage to Finished on the VyOS 1.2 Crux board.
Jan 21 2018, 4:24 PM · VyOS 1.1.x (1.1.8)
c-po added a comment to T523: Forwarder listening on port 53/tcp.

Already triggered CI builds su it will be in tonights version.

Jan 21 2018, 4:23 PM · VyOS 1.1.x (1.1.8)
syncer added a comment to T523: Forwarder listening on port 53/tcp.

Ah ok, sorry, i'm bit slow today.
Awesome!

Jan 21 2018, 4:21 PM · VyOS 1.1.x (1.1.8)
c-po added a comment to T523: Forwarder listening on port 53/tcp.

Nope, this is the output after binding it to eth0 only. It always binds to the loopback interface!

Jan 21 2018, 4:19 PM · VyOS 1.1.x (1.1.8)
syncer added a comment to T523: Forwarder listening on port 53/tcp.

so it still there ?
weird thing

Jan 21 2018, 4:11 PM · VyOS 1.1.x (1.1.8)
c-po added a comment to T523: Forwarder listening on port 53/tcp.

After adding the bind-interfacesparameter to the configuration, movng the configuration file from /etc/dnsmasq.conf to /etc/dnsmasq.d/vyos.conf and switching to systemd, this is the result:

Jan 21 2018, 4:09 PM · VyOS 1.1.x (1.1.8)

Jan 20 2018

c-po added a comment to T523: Forwarder listening on port 53/tcp.

Yes, can do

Jan 20 2018, 2:12 PM · VyOS 1.1.x (1.1.8)

Jan 17 2018

syncer assigned T523: Forwarder listening on port 53/tcp to c-po.

Want to look into that?

Jan 17 2018, 6:21 PM · VyOS 1.1.x (1.1.8)
syncer created T523: Forwarder listening on port 53/tcp.
Jan 17 2018, 6:20 PM · VyOS 1.1.x (1.1.8)

Jan 16 2018

agustafson asked Q124: Slow response from show commands when using Intel g73131 and SNMP.
Jan 16 2018, 10:43 PM · VyOS 1.1.x
pers.edwin updated the task description for T522: Removing interface from bridge results in error & config / system state mismatch.
Jan 16 2018, 2:58 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)
pers.edwin created T522: Removing interface from bridge results in error & config / system state mismatch.
Jan 16 2018, 2:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
In Q122, @aopdal wrote:

With prefix delegation you have a static prefix on your inside, but the "wan" interface on the router is using DHCP.

Jan 16 2018, 2:17 PM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

With prefix delegation you have a static prefix on your inside, but the "wan" interface on the router is using DHCP.

Jan 16 2018, 2:14 PM · VyOS 1.1.x
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
In Q122, @aopdal wrote:

Are your addresses managed from Comcast using prefix delegation?

Jan 16 2018, 1:53 PM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

Without routing you probably can't get it to work. Are your addresses managed from Comcast using prefix delegation?

Jan 16 2018, 1:36 PM · VyOS 1.1.x
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
In Q122, @aopdal wrote:

@beamerblvd have you added routes for your vif 100,200 and 900 in your "COMCAST BUSINESS IP GATEWAY"?

Jan 16 2018, 1:29 PM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

@beamerblvd have you added routes for your vif 100,200 and 900 in your "COMCAST BUSINESS IP GATEWAY"?

Jan 16 2018, 1:23 PM · VyOS 1.1.x
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

So the attempts with /56 and /60 were part of my hundreds of different combinations/attempts to get this to work. I have one /56 assigned to me (2603:xxxx:xxxx:8700::/56) with one gateway assigned to me (2603:xxxx:xxxx:8700:7454:7dff:feb1:d391). Skipping the WAN for just a second because I believe(d) it to need different configuration, I expected to be able to break that /56 up into /64s and use them like so:

Jan 16 2018, 1:15 PM · VyOS 1.1.x
elico added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

I am willing to give some advice but it's an issue to understand your infrastructure based on a very fuzzy set of details.
The basic rule of thumb that I can think of is that you cannot assign ip addresses with the same or overlapping prefix on two interfaces and route between them.
I do not know if the VyOS kernel supports IPV6 NAT feature but this should be a very last resort for specific scenarios.
If you need some examples on how IPv6 prefixes are being used you can try to peek at some IPv6 brokers such as Hurricane Electric.
They give you a very specific IPv6 address and prefix for the WAN side with a specific default route,
Then they give you a different prefix to assign the internal network which is behind the main gateway.
Is your setup different then what HE offers?

Jan 16 2018, 12:08 PM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

Perhaps you could make a drawing of what you try to get working? With proper interface naming etc. eth0 - wan, eth1 - dmz, eth2 - lan or whatever you are using. It makes it easier to understand what you try to do. And for the interfaces why do you want to use the /60?

Jan 16 2018, 7:43 AM · VyOS 1.1.x
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
In Q122, @aopdal wrote:

Maybe this is relevant? https://phabricator.vyos.net/T421

Jan 16 2018, 7:26 AM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

Maybe this is relevant? https://phabricator.vyos.net/T421

Jan 16 2018, 7:17 AM · VyOS 1.1.x
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

So, I ended up handling my IPv4 addresses using 1:1 NAT. It works, and I don't love it, but I think it's the best it's going to get with Comcast's clunky static IP infrastructure. But I'm having no luck with IPv6, and could really use some help with someone who understand's static IPv6 and VyOS a little better. I have a static IPv6 prefix, and I need to statically assign some of those to public-facing servers behind my firewall/router, but it's like pulling teeth from a rhinoceros.

Jan 16 2018, 5:08 AM · VyOS 1.1.x

Jan 1 2018

beamerblvd updated the question details for Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
Jan 1 2018, 2:45 AM · VyOS 1.1.x

Dec 31 2017

beamerblvd asked Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
Dec 31 2017, 11:25 PM · VyOS 1.1.x
alainlamar triaged T505: Hostapd cannot log as Low priority.
Dec 31 2017, 1:37 PM · VyOS 1.3 Equuleus (1.3.0-epa1)

Dec 29 2017

alainlamar added a comment to T505: Hostapd cannot log.

Uhmm, I guess, we may have a hard row to hoe here:

Dec 29 2017, 12:11 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
alainlamar updated the task description for T505: Hostapd cannot log.
Dec 29 2017, 12:00 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
alainlamar updated the task description for T505: Hostapd cannot log.
Dec 29 2017, 11:59 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
alainlamar created T505: Hostapd cannot log.
Dec 29 2017, 11:57 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Dec 27 2017

c-po added a comment to T496: RAID1 install with 60 MB diagnositcs partition.

Triggered Jenkins build https://ci.vyos.net/job/vyatta-cfg-system/281/changes, will be in the next nightly build

Dec 27 2017, 10:42 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po moved T496: RAID1 install with 60 MB diagnositcs partition from In Progress to Finished on the VyOS 1.2 Crux board.
Dec 27 2017, 10:36 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po moved T496: RAID1 install with 60 MB diagnositcs partition from Backlog to In Progress on the VyOS 1.2 Crux board.
Dec 27 2017, 11:57 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po moved T496: RAID1 install with 60 MB diagnositcs partition from Need Triage to Backlog on the VyOS 1.2 Crux board.
Dec 27 2017, 11:56 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po changed the status of T496: RAID1 install with 60 MB diagnositcs partition from Open to In progress.
Dec 27 2017, 11:49 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer added a comment to T496: RAID1 install with 60 MB diagnositcs partition.

maybe it can have something to do with old vyatta appliances, not sure.
i agree with you @c-po, in case we may need something like that, we can reinvent the wheel later.

Dec 27 2017, 11:11 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T496: RAID1 install with 60 MB diagnositcs partition.

A FAT16 partition is created that is not formated? As It's also broken in 1.1.8 and nobody knows what it does I opt for removal of this "feature"

Dec 27 2017, 11:09 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Dec 21 2017

syncer triaged T407: BGP type 2 length 3294 is too large, attribute total length is 2303. attr_endp is 0x7f9e0bbb56cd. endp is 0x7f9e0bbb52e6 as Normal priority.
Dec 21 2017, 9:45 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer moved T426: CVE-2017-13077 - Update wpa_supplicant from In Progress to Finished on the VyOS 1.2 Crux board.
Dec 21 2017, 9:25 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa
syncer closed T426: CVE-2017-13077 - Update wpa_supplicant as Resolved.
Dec 21 2017, 9:25 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa
syncer triaged T464: network groups with same name. as Low priority.
Dec 21 2017, 9:15 PM · Rejected
syncer closed T489: Loadbalance as Wontfix.

Use "set load-balancing wan sticky-connections inbound".

Dec 21 2017, 9:09 PM · Rejected
syncer closed T487: VyOS 1.1.8 vlan + pppoe traffic shaping as Wontfix.

Use "set load-balancing wan sticky-connections inbound"

Dec 21 2017, 9:08 PM · Rejected
syncer triaged T494: fq-codel not available on 1.1.8 as Low priority.

@dmbaturin any comments on this?

Dec 21 2017, 9:05 PM · Rejected
syncer triaged T496: RAID1 install with 60 MB diagnositcs partition as Low priority.
Dec 21 2017, 9:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
srmumtaz asked Q120: trap ospfTrapIfSateChange trap sent: x.x.x.x now Down after a few hours.
Dec 21 2017, 7:28 PM · VyOS 1.1.x
cuban asked Q118: IPv6 system name-server.
Dec 21 2017, 1:24 AM · VyOS 1.1.x

Dec 11 2017

aopdal added a comment to Q116: Howto perform IGMP memebership management?.

Anyone having any ideas to how to solve this problem?

Dec 11 2017, 11:13 AM · VyOS 1.2 Crux, VyOS 1.1.x

Dec 10 2017

syncer updated subscribers of T496: RAID1 install with 60 MB diagnositcs partition.

@dmbaturin do you know what is for?

Dec 10 2017, 11:29 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po created T496: RAID1 install with 60 MB diagnositcs partition.
Dec 10 2017, 11:26 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Dec 9 2017

jbrodriguez created T494: fq-codel not available on 1.1.8.
Dec 9 2017, 10:53 AM · Rejected

Dec 4 2017

thanos_nm created T489: Loadbalance.
Dec 4 2017, 7:27 PM · Rejected
thanos_nm created T487: VyOS 1.1.8 vlan + pppoe traffic shaping.
Dec 4 2017, 4:12 PM · Rejected

Nov 27 2017

aopdal added a comment to Q116: Howto perform IGMP memebership management?.

This is a drawing of my current lab environment.

Nov 27 2017, 1:20 PM · VyOS 1.2 Crux, VyOS 1.1.x
aopdal asked Q116: Howto perform IGMP memebership management?.
Nov 27 2017, 1:18 PM · VyOS 1.2 Crux, VyOS 1.1.x

Nov 26 2017

syncer assigned T466: Ipsec/l2tp remote access stops working after reboot (when vrrp is present in the configuration). to UnicronNL.

@Unicron check please

Nov 26 2017, 6:21 PM · Rejected
syncer assigned T469: Problem after commit with errors to dmbaturin.
Nov 26 2017, 6:18 PM · VyOS 1.3 Equuleus (1.3.4), test
syncer closed Q78: L2TPv3 over IPSEC configuration where one of the sites is using a Dynamic IP address as resolved.
Nov 26 2017, 6:04 PM · VyOS 1.1.x, VyOS 1.2 Crux
syncer closed Q103: Is there a comprehensive list of all VyOS commands? as resolved.
Nov 26 2017, 5:59 PM · VyOS 1.1.x

Nov 21 2017

krzysztof_p created T469: Problem after commit with errors.
Nov 21 2017, 4:38 PM · VyOS 1.3 Equuleus (1.3.4), test

Nov 18 2017

krdx updated the task description for T466: Ipsec/l2tp remote access stops working after reboot (when vrrp is present in the configuration)..
Nov 18 2017, 12:51 AM · Rejected
krdx created T466: Ipsec/l2tp remote access stops working after reboot (when vrrp is present in the configuration)..
Nov 18 2017, 12:45 AM · Rejected

Nov 16 2017

olofl created T464: network groups with same name. .
Nov 16 2017, 8:51 AM · Rejected

Nov 14 2017

dmbaturin added a comment to T456: lldpd is broken on 1.1.8.

The lldpd package had really insufficient dependencies, it didn't even list libssl. This is why it wasn't rebuilt, we used apt-cache rdepend to find the packages that depend on libssl0.9.8, and due to missing dependencies this one didn't show up.

Nov 14 2017, 3:46 PM · Rejected

Nov 13 2017

syncer assigned T456: lldpd is broken on 1.1.8 to UnicronNL.

@UnicronNL can you rebuild it ?

Nov 13 2017, 11:15 PM · Rejected
jbrown created T456: lldpd is broken on 1.1.8.
Nov 13 2017, 10:41 PM · Rejected

Nov 10 2017

dmbaturin closed T449: Commit fails if OpenVPN is setup in server mode and there are clients with fixed IP addresses as Resolved.
Nov 10 2017, 4:20 PM · VyOS 1.1.x
dmbaturin added a comment to T426: CVE-2017-13077 - Update wpa_supplicant.

I've done pkg-release in that package to include the latest commits into debian changelog and update the package version (helium4 now).

Nov 10 2017, 1:17 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa
dmbaturin added a comment to T449: Commit fails if OpenVPN is setup in server mode and there are clients with fixed IP addresses.

The issue was with variable scoping, the variable for server subnet that was supposed to be global was instead updated in the local scope.

Nov 10 2017, 5:11 AM · VyOS 1.1.x
dmbaturin created T449: Commit fails if OpenVPN is setup in server mode and there are clients with fixed IP addresses.
Nov 10 2017, 4:10 AM · VyOS 1.1.x

Nov 9 2017

dmbaturin added a comment to T426: CVE-2017-13077 - Update wpa_supplicant.

@UnicronNL Just to make sure, the package included in helium now is also patched?

Nov 9 2017, 3:53 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa

Nov 8 2017

syncer removed a project from T426: CVE-2017-13077 - Update wpa_supplicant: VyOS 2.0.x.
Nov 8 2017, 10:56 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa
syncer moved T426: CVE-2017-13077 - Update wpa_supplicant from Need Triage to In Progress on the VyOS 1.2 Crux board.
Nov 8 2017, 10:55 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa

Nov 7 2017

c-po updated subscribers of T426: CVE-2017-13077 - Update wpa_supplicant.

This did the trick. Just build a fresh ISO:

Nov 7 2017, 8:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa
UnicronNL added a comment to T426: CVE-2017-13077 - Update wpa_supplicant.

https://github.com/vyos/vyos-build/commit/e5259ccb17e93e110d1dcdeb98f4dc1b9d1df192
This seems to have done the trick thanks.

Nov 7 2017, 9:06 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa
c-po updated subscribers of T426: CVE-2017-13077 - Update wpa_supplicant.

@UnicronNL maybe this will fix this issue:

Nov 7 2017, 7:08 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa

Nov 3 2017

c-po added a comment to T426: CVE-2017-13077 - Update wpa_supplicant.

Our nightly builds ships wpasupplicant 2.3-1+deb8u4, according to https://www.debian.org/security/2017/dsa-3999 it's fixed in 2.3-1+deb8u5.

Nov 3 2017, 4:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa

Nov 1 2017

syncer closed T442: Allow more than one loopback interface. as Wontfix.
Nov 1 2017, 5:18 PM · Rejected
Zulzig added a comment to T442: Allow more than one loopback interface..

Thank you Fatihusta, dmbaturin.

Nov 1 2017, 5:02 PM · Rejected
dmbaturin added a comment to T442: Allow more than one loopback interface..

If you want multiple interfaces with the same properties as the loopback, use dummy interfaces.

Nov 1 2017, 4:59 PM · Rejected
fatihusta added a comment to T442: Allow more than one loopback interface..

Hi
You can use dummy interface.
It's like a loopback interface.

Nov 1 2017, 4:58 PM · Rejected
Zulzig created T442: Allow more than one loopback interface..
Nov 1 2017, 4:52 PM · Rejected

Oct 26 2017

syncer added a comment to T428: Current 1.1.7 AMI doesn't fetch SSH public key from the EC2 environment.

@jbeisser cloud init was integrated much later and still require testing
1.2 will be using cloud-init for that purpose

Oct 26 2017, 6:48 PM · VyOS 1.1.x (1.1.8)