Page MenuHomeVyOS Platform
Feed Advanced Search

Jan 26 2019

syncer added a project to T1206: Commit revisions are not rotated: VyOS-1.2.0-GA.
Jan 26 2019, 10:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer closed T1157: Static route not reachable through VRRP address as Resolved.
Jan 26 2019, 10:14 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer closed T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups as Resolved.
Jan 26 2019, 10:14 PM · VyOS 1.3 Equuleus (1.3.7)
syncer closed T113: Support for custom MAC addresses on a per-VLAN basis as Resolved.
Jan 26 2019, 10:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin closed T1206: Commit revisions are not rotated as Resolved.
Jan 26 2019, 10:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin moved T1206: Commit revisions are not rotated from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 26 2019, 10:03 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin moved T1157: Static route not reachable through VRRP address from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 26 2019, 10:03 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin moved T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 26 2019, 10:03 PM · VyOS 1.3 Equuleus (1.3.7)
dmbaturin moved T113: Support for custom MAC addresses on a per-VLAN basis from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 26 2019, 10:03 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin created T1206: Commit revisions are not rotated.
Jan 26 2019, 9:50 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer added a project to T865: Add initial RPKI support: VyOS-1.2.0-GA.
Jan 26 2019, 8:55 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin edited projects for T865: Add initial RPKI support, added: VyOS 1.2 Crux (VyOS 1.2.0-GA); removed VyOS 1.2 Crux (VyOS 1.2.0-EPA3).
Jan 26 2019, 8:54 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer changed the status of T1157: Static route not reachable through VRRP address from On hold to Needs testing.
Jan 26 2019, 8:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer moved T1169: LLDP potentially broken from Finished to In Progress on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 26 2019, 8:10 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer added a project to T1169: LLDP potentially broken: VyOS-1.2.0-GA.
Jan 26 2019, 8:10 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer added a project to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes: VyOS-1.2.0-GA.
Jan 26 2019, 7:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy added a comment to T1169: LLDP potentially broken.

THis shows up in the logs:

Jan 26 2019, 7:09 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
kroy added a comment to T1169: LLDP potentially broken.

Unfortunately that seems to have made the problem worse. Before, at least each host was seeing one other host. Now most of them see no hosts.

Jan 26 2019, 7:07 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard closed T1193: libvyosconfig parser cannot handle top level leaf and tag nodes as Resolved.
Jan 26 2019, 6:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

Rebuilding iso, once it finished it will have the correct version.
[...]
Get:152 http://dev.packages.vyos.net/repositories/current/vyos/ current/main libvyosconfig0 amd64 0.0.6 [841 kB]
[...]
Will test it from the iso, just for peace of mind.

Jan 26 2019, 5:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard claimed T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

Dev.packages has 0.0.06, so something goes sideways during build process, I will work on that and test. I'll take the task back and close it when resolved in ci (looking into it right now). I manually installed the package and everything works as expected.

Jan 26 2019, 5:26 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

Still same issue on 1.2.0-rolling+201901250337.

Jan 26 2019, 5:21 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin changed the status of T1157: Static route not reachable through VRRP address from Open to On hold.

Ok, I've re-tested everything one more time to be sure. I can confirm the somewhat strange (though technically correct) behaviour of blackhole routes: they become ECMP routes if there's another route of the same distance. I would expect normal routes to override them in that case, but the kernel is following its hard and fast rule that two routes with the same distance automatically become ECMP routes, that behaviour is counter-intuitive but consistent.

Jan 26 2019, 4:39 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
runar added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Until we redesign the firewall CLI, I'm making the rules match eth0+ instead. I hope the performance impact will not be too high.

Jan 26 2019, 4:17 PM · VyOS 1.3 Equuleus (1.3.7)
dmbaturin moved T1193: libvyosconfig parser cannot handle top level leaf and tag nodes from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 26 2019, 3:54 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin moved T1169: LLDP potentially broken from Backlog to In Progress on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 26 2019, 3:54 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

@jmlccdmd I've been testing it with EPA3 and friday's nightly build.

Jan 26 2019, 3:54 PM · VyOS 1.3 Equuleus (1.3.7)
hagbard added a comment to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

Nice! I will test it tomorrow for sure.

Jan 26 2019, 2:28 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy added a comment to T1169: LLDP potentially broken.

Sure. I'll set a reminder to check it out tomorrow when I have a free minute. Thanks

Jan 26 2019, 2:25 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin added a comment to T1169: LLDP potentially broken.

I've built lldpd 1.0.3, much newer than that from jessie. Luckily, the maintainer keep Debian packaging in the official repository, so it wasn't much effort to do.

Jan 26 2019, 2:24 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin closed T1204: LLDP reports VyOS version as "unknown" as Resolved.
Jan 26 2019, 2:23 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
jmlccdmd added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

I'm very interested, what is the latest image number? I will test it.

Jan 26 2019, 2:19 AM · VyOS 1.3 Equuleus (1.3.7)
dmbaturin created T1204: LLDP reports VyOS version as "unknown".
Jan 26 2019, 2:18 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin changed the status of T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups from In progress to Needs testing.

Ok, more interesting than that. In the latest image, the setup just works as described with RFC-compliant VRRP:

Jan 26 2019, 2:06 AM · VyOS 1.3 Equuleus (1.3.7)
dmbaturin added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

This problem is specific to RFC-compliant VRRP setups. Firewall design in VyOS is rather unfortunate in that rulesets are bound to interfaces. If you assign it to eth0, a rule with -i eth0 -j MyRuleset is created. RFC-compliant (shared MAC) VRRP uses those eth0v1 etc. interfaces, but since from netfilter's point of view eth0 and eth0v1 are different interfaces, those rules are never reached.

Jan 26 2019, 1:13 AM · VyOS 1.3 Equuleus (1.3.7)
dmbaturin renamed T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups from Firewall rule set ignored in VRRP setup to Firewall rulesets are ignored in RFC-compliant VRRP setups.
Jan 26 2019, 1:08 AM · VyOS 1.3 Equuleus (1.3.7)
dmbaturin changed the status of T1193: libvyosconfig parser cannot handle top level leaf and tag nodes from Confirmed to Needs testing.

This issue uncovered more. The parser was written under an assumption that "bare" leaf and tag nodes at the top level are not allowed. In fact, while VyOS config never have them, it's by convention rather than by design, if you create a command definition for one (set foo bar), it works just fine. So, to be consistent with the original parser, the new parser should allow them.
I've removed the restriction on the grammar to allow them (see https://github.com/vyos/libvyosconfig/commit/1dd05b330f3adfe828ba3ca4c71db2e12b8968f6), and now run show configuration commands seems to work with "partial" configs just fine. The change appears to have no ill effects on parsing "normal" config, according to my testing.

Jan 26 2019, 1:04 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin renamed T1193: libvyosconfig parser cannot handle top level leaf and tag nodes from Command "run show configuration commands" generates an error if not on the top level in config mode to libvyosconfig parser cannot handle top level leaf and tag nodes.
Jan 26 2019, 12:03 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 25 2019

dmbaturin closed T1203: Webproxy 1 to 2 migration fails if proxy-bypass is not configured as Resolved.
Jan 25 2019, 11:42 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin created T1203: Webproxy 1 to 2 migration fails if proxy-bypass is not configured.
Jan 25 2019, 11:31 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy added a comment to T1178: Scheduled script breaks ability to modify configuration.

Sorry. Spent the week restoring almost half a petabyte of data from backups due to a ZFS crash.

Jan 25 2019, 8:21 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard closed T1178: Scheduled script breaks ability to modify configuration as Resolved.
Jan 25 2019, 8:07 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

Anyone?

Jan 25 2019, 6:13 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer moved T1169: LLDP potentially broken from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 25 2019, 2:11 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer moved T1157: Static route not reachable through VRRP address from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 25 2019, 2:11 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer moved T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 25 2019, 2:11 PM · VyOS 1.3 Equuleus (1.3.7)
syncer moved T113: Support for custom MAC addresses on a per-VLAN basis from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 25 2019, 2:11 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer moved T1193: libvyosconfig parser cannot handle top level leaf and tag nodes from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 25 2019, 2:11 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer moved T567: support for Nutanix AHV from Needs Triage to In Progress on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 25 2019, 2:11 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA), Nutanix
syncer renamed VyOS 1.2 Crux (VyOS 1.2.0-GA) from VyOS 1.2.0-CRUX-GA to VyOS 1.2.0-GA.
Jan 25 2019, 2:06 PM

Jan 24 2019

Merijn added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

@jmlccdmd
I added a second router and configured conntrack-sync.
Failover and preempt failback works correct.
Both routers show statistics for the firewall rules

Jan 24 2019, 9:50 PM · VyOS 1.3 Equuleus (1.3.7)
bmtauer added a comment to T1157: Static route not reachable through VRRP address.

The problem discussed here sounds remarkably similar to what I'm seeing: https://github.com/FRRouting/frr/issues/2230

Jan 24 2019, 7:53 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
bmtauer added a comment to T1157: Static route not reachable through VRRP address.

I've tried several variations on the VRRP configuration, and it doesn't seem to make any difference. As far as I can tell, nothing is wrong with VRRP. It is only relevant as a source for change in the routing table. I can demonstrate the problem on a single instance with no VRRP.

Jan 24 2019, 12:21 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 23 2019

hagbard reassigned T1193: libvyosconfig parser cannot handle top level leaf and tag nodes from hagbard to dmbaturin.
Jan 23 2019, 8:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

Found the bug, https://github.com/hagbard-01/vyos-1x/releases/download/1.2.0-10/vyos-1x_1.2.0-10_all.deb should fix it. As soon as You guys can confirm, I push it upstream.

Jan 23 2019, 7:56 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

@c-po All right, found it. Try it without arguments, then it ends up just as */5 * * * * root /usr/bin/logger which causes the issue. That shouldn't be too hard to fix, the existence of the cronjobfile after a reboot without the save command however is a longer journey.

Jan 23 2019, 6:32 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

Thanks that helps, I gotta review. Remote authenticated users would act like local ones by the way, pam would resolve it or if it can't be resolved, con exits with 1.

Jan 23 2019, 6:07 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
jmlccdmd added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

No, it does not work. The problem persist.

Jan 23 2019, 1:11 PM · VyOS 1.3 Equuleus (1.3.7)
c-po added a comment to T1178: Scheduled script breaks ability to modify configuration.

Nope, I used:

Jan 23 2019, 8:06 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

@c-po
*/5 * * * * cpo sg vyattacfg "/usr/bin/logger foo"

Jan 23 2019, 7:44 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
c-po added a comment to T1178: Scheduled script breaks ability to modify configuration.

@hagbard I replaced vyos user with another one. Also image corporate setups where RADIUS is used for authing and there are no local users.

Jan 23 2019, 7:34 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

I had to pass on libvyos and OCAML, just reading and understanding a few lines took me forever. What would be the fix?

Jan 23 2019, 6:41 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
dmbaturin added a comment to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes.

I suppose I can port the fix for |commands to it.

Jan 23 2019, 12:22 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer added a project to T1193: libvyosconfig parser cannot handle top level leaf and tag nodes: VyOS 1.2 Crux (VyOS 1.2.0-GA).
Jan 23 2019, 12:20 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 22 2019

hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

All right, can you please test: https://github.com/hagbard-01/vyos-1x/releases/download/1.2.0-10/vyos-1x_1.2.0-10_all.deb

Jan 22 2019, 10:26 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

OK, so the issue happens only if a) the cronjobs was executed by root and b) it modifies the config (which gets then rewritten via union-fs). I created another user called test01, the user vyos has a cron job in his name, regardless what user (test01 or vyos) the script runs, all stays healthy. As soon as the script is triggered via root, you can't set anything in your running config due to the permission changes I wrote yesterday.

Jan 22 2019, 8:42 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
Merijn added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

But if you run only on the first router, including the VRRP setup it does not work?

Jan 22 2019, 7:39 PM · VyOS 1.3 Equuleus (1.3.7)
jmlccdmd added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

With the exact same setup, I diabled vrrp on my second routers, the one in standby, with these commands :

Jan 22 2019, 7:37 PM · VyOS 1.3 Equuleus (1.3.7)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

Thanks for confirming. With 2 users, you may encounter always the issue that a cronjob locks up your ability to change the config afterwards. For now the manual workaround should help you, I'm going to revert my changes from yesterday and return to the drawing board.

Jan 22 2019, 6:35 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy added a comment to T1178: Scheduled script breaks ability to modify configuration.

Yeah. I remove the initial vyos user and add an admin and an ansible user. The admin is just for consistency across different devices.

Jan 22 2019, 6:28 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer moved T894: DHCP not renewed after switching network from In Progress to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 22 2019, 6:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard closed T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient as Resolved.

Thx for testing.

Jan 22 2019, 6:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard closed T894: DHCP not renewed after switching network as Resolved.

Fixed via T1181

Jan 22 2019, 6:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard closed T894: DHCP not renewed after switching network, a subtask of T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient, as Resolved.
Jan 22 2019, 6:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

I wouldn't execute a scheduled script. Thats all. Do you recreate then a different user? Since all users have admin privs, the probem with the change permissions will persist. Actually makes it works, one user can block the other. So, I have to find something else out.

Jan 22 2019, 6:13 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy added a comment to T1178: Scheduled script breaks ability to modify configuration.

@hagbard I remove/change the vyos user too. So it's definitely a breaking change.

Jan 22 2019, 4:41 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

@cpo it would just exit 1. I gotta look into the possibility to see the commit user, I was under the assumption that the vyos user always exists. If there are multiple (at least 2 different) and the cron runs a root or the user (the one which did not setup the job), it will disable any config for all other users, since the filesystem permissions change. ACL's would be something which can solve it, but I have to verify it. I'll keep this task open to track it. Do you just replace the vyos user, or are you using root only in your config?

Jan 22 2019, 4:38 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
kmpm added a comment to T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.

vyos-1.2.0-rolling+201901181924-amd64.iso fixed it for me.

Jan 22 2019, 11:52 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer merged T1191: Ethernet interface with dhcp does not re-enable correctly after disable. into T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.
Jan 22 2019, 10:39 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
c-po added a comment to T1178: Scheduled script breaks ability to modify configuration.

Depending on the task which needs to be executed a script might need to be run as root.

Jan 22 2019, 6:50 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 21 2019

hagbard assigned T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups to Merijn.
Jan 21 2019, 10:11 PM · VyOS 1.3 Equuleus (1.3.7)
hagbard moved T894: DHCP not renewed after switching network from Needs Triage to In Progress on the VyOS 1.2 Crux (VyOS 1.2.0-GA) board.
Jan 21 2019, 10:06 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T894: DHCP not renewed after switching network.

@yun can you please test with the latest rolling?

Jan 21 2019, 10:06 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

@kroy install http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyos-1x/vyos-1x_1.2.0-10_all.deb and try again, I have the changes in that package and tonights rolling will have it too. I couldn't find anywhere a requirement that the cronjobs need root, so I switched it to always run as vyos which keeps the file system permissions intact. Test it on a test machine first, but it should now do what you want, I used your script code from above, but didn't have any real ospf adjacency with any other route, but that shouldn't matter at all. Let me know the results please.

Jan 21 2019, 9:20 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

OK, I think I found it, however so far I can only give you a quick workaround rather than solving it.
Short explanation, if you setup cron, your script is executed as root which changes the permissions for the configs on union-fs and the directories, that's why already a set fails, it can't simply write as user vyos to the directory.
To get your stuff working, try the following (preferably on a test box, I used the rolling from tonight but any 1.2 image should work if it's not older than 3 months or so)

Jan 21 2019, 8:41 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

The 'commit' causes the issue, but right now I'm not sure why.

Jan 21 2019, 8:03 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy added a comment to T1178: Scheduled script breaks ability to modify configuration.

The latest rolling did seem to correct the base problem. That being cron scripts running breaking the ability to edit config afterwards.

Jan 21 2019, 6:45 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.
In T1178#30992, @kroy wrote:

@hagbard Note that a reboot does fix the ability to edit configuration again until the next time the cron script runs.

Jan 21 2019, 6:13 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T1178: Scheduled script breaks ability to modify configuration from Open to Needs testing.
Jan 21 2019, 6:09 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.
Jan 21 2019, 6:09 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy added a comment to T1178: Scheduled script breaks ability to modify configuration.

@hagbard Note that a reboot does fix the ability to edit configuration again until the next time the cron script runs.

Jan 21 2019, 5:26 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

I'm going to implement it into the configuration, which will assure that is it going to be the last step executed after a reboot.

Jan 21 2019, 5:21 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard edited projects for T894: DHCP not renewed after switching network, added: VyOS 1.2 Crux (VyOS 1.2.0-GA); removed VyOS 1.2 Crux (VyOS 1.2.0-EPA3).
Jan 21 2019, 5:19 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
UnicronNL closed T1188: dmvpn typo in dead-peer-detection as Resolved.
Jan 21 2019, 11:27 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
zsdc added a comment to T1157: Static route not reachable through VRRP address.

OK, things is more clearly now.
If you don't have any L2-filters between eth1 interfaces of VyOS instances I could recommend you first to change configuration to something like this (based on your configuration from first message):
Router 1:

Jan 21 2019, 9:42 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
Merijn added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

@jmlccdmd
I have recreated your setup with Vyos 1.2.0-rc10 and it seems to be working correctly

Jan 21 2019, 9:37 AM · VyOS 1.3 Equuleus (1.3.7)

Jan 20 2019

UnicronNL updated subscribers of T1186: Setup DMVPN cannot work.

@bjtangseng This is definitely a NAT issue, if i change the local_ts = dynamic[gre] in /etc/swanctl/swanctl.conf to local_ts = *.*.*.*/32[gre] i can replicate the error you get.

Jan 20 2019, 8:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
bjtangseng added a comment to T1186: Setup DMVPN cannot work.

If you can see issue "T1100: Spoke site dynamic IP over NAT connect to Hub site."

Jan 20 2019, 12:18 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer edited projects for T113: Support for custom MAC addresses on a per-VLAN basis, added: VyOS 1.2 Crux (VyOS 1.2.0-GA); removed VyOS 1.2 Crux (VyOS 1.2.0-EPA3).
Jan 20 2019, 12:17 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
syncer triaged T1178: Scheduled script breaks ability to modify configuration as High priority.
Jan 20 2019, 12:06 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)