vyos_vpn_conf3 KBDownload
File added.- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Feed Advanced Search
Advanced Search
Advanced Search
Feb 12 2018
Feb 12 2018
Feb 11 2018
Feb 11 2018
sebastianm edited projects for T424: Advertisement of Multiple Paths in BGP (capability 69), added: VyOS 1.1.x; removed VyOS 1.2 Crux.
@sergei yes, please put it here for records
I found VPN tunnel with esp lifetime of 43200 sec (12 hrs) is stable. Can share my config if necessary.
Feb 10 2018
Feb 10 2018
Found workaround for ESP lifetime issue, need monitoring for 24 hrs to verify.
@sergei can you check 1.2 behaviour too please
Feb 6 2018
Feb 6 2018
Feb 1 2018
Feb 1 2018
@xrpixer thank you very much for the clarification. Hopefully other users can benefit from it, too.
Sorry for the late response on this.
Jan 29 2018
Jan 29 2018
@xrpixer thanks for submitting. Any change you could double check it on a recent nightly build of VyOs 1.2.x? => https://downloads.vyos.io/?dir=rolling/current/amd64
Jan 28 2018
Jan 28 2018
Jan 21 2018
Jan 21 2018
c-po moved T523: Forwarder listening on port 53/tcp from Need Triage to Finished on the VyOS 1.2 Crux board.
Already triggered CI builds su it will be in tonights version.
Ah ok, sorry, i'm bit slow today.
Awesome!
Nope, this is the output after binding it to eth0 only. It always binds to the loopback interface!
so it still there ?
weird thing
After adding the bind-interfacesparameter to the configuration, movng the configuration file from /etc/dnsmasq.conf to /etc/dnsmasq.d/vyos.conf and switching to systemd, this is the result:
Jan 20 2018
Jan 20 2018
Yes, can do
Jan 17 2018
Jan 17 2018
Want to look into that?
Jan 16 2018
Jan 16 2018
pers.edwin updated the task description for T522: Removing interface from bridge results in error & config / system state mismatch.
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
With prefix delegation you have a static prefix on your inside, but the "wan" interface on the router is using DHCP.
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
With prefix delegation you have a static prefix on your inside, but the "wan" interface on the router is using DHCP.
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
Without routing you probably can't get it to work. Are your addresses managed from Comcast using prefix delegation?
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
@beamerblvd have you added routes for your vif 100,200 and 900 in your "COMCAST BUSINESS IP GATEWAY"?
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
@beamerblvd have you added routes for your vif 100,200 and 900 in your "COMCAST BUSINESS IP GATEWAY"?
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
So the attempts with /56 and /60 were part of my hundreds of different combinations/attempts to get this to work. I have one /56 assigned to me (2603:xxxx:xxxx:8700::/56) with one gateway assigned to me (2603:xxxx:xxxx:8700:7454:7dff:feb1:d391). Skipping the WAN for just a second because I believe(d) it to need different configuration, I expected to be able to break that /56 up into /64s and use them like so:
elico added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
I am willing to give some advice but it's an issue to understand your infrastructure based on a very fuzzy set of details.
The basic rule of thumb that I can think of is that you cannot assign ip addresses with the same or overlapping prefix on two interfaces and route between them.
I do not know if the VyOS kernel supports IPV6 NAT feature but this should be a very last resort for specific scenarios.
If you need some examples on how IPv6 prefixes are being used you can try to peek at some IPv6 brokers such as Hurricane Electric.
They give you a very specific IPv6 address and prefix for the WAN side with a specific default route,
Then they give you a different prefix to assign the internal network which is behind the main gateway.
Is your setup different then what HE offers?
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
Perhaps you could make a drawing of what you try to get working? With proper interface naming etc. eth0 - wan, eth1 - dmz, eth2 - lan or whatever you are using. It makes it easier to understand what you try to do. And for the interfaces why do you want to use the /60?
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
Maybe this is relevant? https://phabricator.vyos.net/T421
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
Maybe this is relevant? https://phabricator.vyos.net/T421
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
So, I ended up handling my IPv4 addresses using 1:1 NAT. It works, and I don't love it, but I think it's the best it's going to get with Comcast's clunky static IP infrastructure. But I'm having no luck with IPv6, and could really use some help with someone who understand's static IPv6 and VyOS a little better. I have a static IPv6 prefix, and I need to statically assign some of those to public-facing servers behind my firewall/router, but it's like pulling teeth from a rhinoceros.
Jan 1 2018
Jan 1 2018
beamerblvd updated the question details for Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
Dec 31 2017
Dec 31 2017
Dec 29 2017
Dec 29 2017
Uhmm, I guess, we may have a hard row to hoe here:
Dec 27 2017
Dec 27 2017
Triggered Jenkins build https://ci.vyos.net/job/vyatta-cfg-system/281/changes, will be in the next nightly build
c-po moved T496: RAID1 install with 60 MB diagnositcs partition from In Progress to Finished on the VyOS 1.2 Crux board.
c-po moved T496: RAID1 install with 60 MB diagnositcs partition from Backlog to In Progress on the VyOS 1.2 Crux board.
c-po moved T496: RAID1 install with 60 MB diagnositcs partition from Need Triage to Backlog on the VyOS 1.2 Crux board.
c-po changed the status of T496: RAID1 install with 60 MB diagnositcs partition from Open to In progress.
maybe it can have something to do with old vyatta appliances, not sure.
i agree with you @c-po, in case we may need something like that, we can reinvent the wheel later.
A FAT16 partition is created that is not formated? As It's also broken in 1.1.8 and nobody knows what it does I opt for removal of this "feature"
Dec 21 2017
Dec 21 2017
syncer moved T426: CVE-2017-13077 - Update wpa_supplicant from In Progress to Finished on the VyOS 1.2 Crux board.
Use "set load-balancing wan sticky-connections inbound".
Use "set load-balancing wan sticky-connections inbound"
@dmbaturin any comments on this?
Dec 11 2017
Dec 11 2017
Anyone having any ideas to how to solve this problem?
Dec 10 2017
Dec 10 2017
@dmbaturin do you know what is for?
Dec 9 2017
Dec 9 2017
Dec 4 2017
Dec 4 2017
Nov 27 2017
Nov 27 2017
This is a drawing of my current lab environment.
Nov 26 2017
Nov 26 2017
syncer assigned T466: Ipsec/l2tp remote access stops working after reboot (when vrrp is present in the configuration). to UnicronNL.
@Unicron check please
Nov 21 2017
Nov 21 2017
Nov 18 2017
Nov 18 2017
krdx updated the task description for T466: Ipsec/l2tp remote access stops working after reboot (when vrrp is present in the configuration)..
Nov 16 2017
Nov 16 2017
Nov 14 2017
Nov 14 2017
The lldpd package had really insufficient dependencies, it didn't even list libssl. This is why it wasn't rebuilt, we used apt-cache rdepend to find the packages that depend on libssl0.9.8, and due to missing dependencies this one didn't show up.
Nov 13 2017
Nov 13 2017
@UnicronNL can you rebuild it ?
Nov 10 2017
Nov 10 2017
I've done pkg-release in that package to include the latest commits into debian changelog and update the package version (helium4 now).
dmbaturin added a comment to T449: Commit fails if OpenVPN is setup in server mode and there are clients with fixed IP addresses.
The issue was with variable scoping, the variable for server subnet that was supposed to be global was instead updated in the local scope.
Nov 9 2017
Nov 9 2017
@UnicronNL Just to make sure, the package included in helium now is also patched?
Nov 8 2017
Nov 8 2017
syncer moved T426: CVE-2017-13077 - Update wpa_supplicant from Need Triage to In Progress on the VyOS 1.2 Crux board.
Nov 7 2017
Nov 7 2017
This did the trick. Just build a fresh ISO:
https://github.com/vyos/vyos-build/commit/e5259ccb17e93e110d1dcdeb98f4dc1b9d1df192
This seems to have done the trick thanks.
@UnicronNL maybe this will fix this issue:
Nov 3 2017
Nov 3 2017
Our nightly builds ships wpasupplicant 2.3-1+deb8u4, according to https://www.debian.org/security/2017/dsa-3999 it's fixed in 2.3-1+deb8u5.
Nov 1 2017
Nov 1 2017
Thank you Fatihusta, dmbaturin.
If you want multiple interfaces with the same properties as the loopback, use dummy interfaces.
Hi
You can use dummy interface.
It's like a loopback interface.
Oct 26 2017
Oct 26 2017
syncer added a comment to T428: Current 1.1.7 AMI doesn't fetch SSH public key from the EC2 environment.
@jbeisser cloud init was integrated much later and still require testing
1.2 will be using cloud-init for that purpose