Page MenuHomeVyOS Platform
Feed Advanced Search

Apr 9 2024

Viacheslav added a comment to T2801: conntrack-tools flooding logs.

@tjh Any updates?
By the way there is a new option

vyos@r4# set service conntrack-sync disable-syslog 
[edit]
vyos@r4#
Apr 9 2024, 4:04 PM · VyOS 1.4 Sagitta (1.4.0-epa1), VyOS 1.3 Equuleus (1.3.7)
Viacheslav added a comment to T5745: conntrack-sync: Multiprimary setups for HA/VRRP.

https://conntrack-tools.netfilter.org/manual.html#sync-aa

conntrackd allows you to deploy an symmetric Active-Active setup based on a static approach. For example, assume that you have two virtual IPs, vIP1 and vIP2, and two firewall replicas, FW1 and FW2. You can give the virtual vIP1 to the firewall FW1 and the vIP2 to the FW2.
Apr 9 2024, 3:58 PM · VyOS 1.5 Circinus, vyatta-vrrp, vyatta-conntrack-sync
n.fort added a subtask for T5938: Migration fail root task for 1.4-rc: T6216: Firewall group names that contain the '+' character break the config.
Apr 9 2024, 12:20 PM · VyOS 1.4 Sagitta (1.4.0-GA)
n.fort added a parent task for T6216: Firewall group names that contain the '+' character break the config: T5938: Migration fail root task for 1.4-rc.
Apr 9 2024, 12:20 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T6216: Firewall group names that contain the '+' character break the config from Open to Confirmed.
Apr 9 2024, 12:11 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort created T6216: Firewall group names that contain the '+' character break the config.
Apr 9 2024, 12:11 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6213: Validations in firewall groups mistakenly reject correct configurations.

PR: https://github.com/vyos/vyos-1x/pull/3281

Apr 9 2024, 11:13 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Giggum updated the task description for T6123: Limit NTP allow-client config to internal addresses by default.
Apr 9 2024, 12:36 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Giggum updated the task description for T6123: Limit NTP allow-client config to internal addresses by default.
Apr 9 2024, 12:18 AM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus

Apr 8 2024

Giggum added a comment to T6099: Suppress unsupported interfaces from appearing in messages log by Telegraf .

@Giggum Can you check it in 1.5?

Yeah sure thing I can do that. Will I be able to roll back from the latest 1.5 to the version of 1.4 rolling I’m on after testing is complete or will the config mess up?

Apr 8 2024, 11:17 PM · VyOS 1.5 Circinus
n.fort moved T6068: Support active-active and active-passive high availability modes in DHCP server from Need Triage to Finished on the VyOS 1.5 Circinus board.
Apr 8 2024, 12:04 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort moved T6068: Support active-active and active-passive high availability modes in DHCP server from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Apr 8 2024, 12:03 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort closed T6068: Support active-active and active-passive high availability modes in DHCP server as Resolved.
Apr 8 2024, 12:03 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T6213: Validations in firewall groups mistakenly reject correct configurations from Open to In progress.
Apr 8 2024, 11:12 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort created T6213: Validations in firewall groups mistakenly reject correct configurations.
Apr 8 2024, 11:11 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 7 2024

Viacheslav added a project to T5169: Add CGNAT Carrier-Grade NAT based on nftables: VyOS 1.5 Circinus.
Apr 7 2024, 8:27 PM · VyOS 1.5 Circinus
c-po updated the task description for T5475: Analyse if forked live-boot package can be dropped.
Apr 7 2024, 7:02 PM · VyOS 1.5 Circinus
c-po closed T6205: ipoe: error in migration script logic while renaming mac-address to mac, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
Apr 7 2024, 6:59 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav changed the status of T1641: VRRP conntrack-sync dropping packets passing through the router from Open to Needs reporter action.

@Daya @trae32566 Any updates?

Apr 7 2024, 5:20 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav placed T3159: L2TP MTU mismatch between client and server up for grabs.
Apr 7 2024, 5:11 PM · VyOS 1.3 Equuleus (1.3.8), VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a comment to T5966: Adjust dynamic dns configuration address subpath to be more intuitive and other op-mode adjustments.

@indrajitr Can we close it?

Apr 7 2024, 5:06 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav added a comment to T5959: Streamline dns forwarding service.

@indrajitr Can we close it?

Apr 7 2024, 5:05 PM · VyOS 1.4 Sagitta (1.4.0-epa2)
Viacheslav changed the status of T4588: BGP Peer Group Scaling issues from Open to Needs reporter action.
Apr 7 2024, 5:03 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav closed T6039: cloud-init DNS search-domain causes configuration migration/validation error, a subtask of T5907: cloud-init root task for 1.5 and 1.4 , as Resolved.
Apr 7 2024, 4:54 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav closed T6039: cloud-init DNS search-domain causes configuration migration/validation error as Resolved.
Apr 7 2024, 4:54 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T5907: cloud-init root task for 1.5 and 1.4 : T6112: Cloud Init Ordering Incorrect.
Apr 7 2024, 4:45 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
Viacheslav added a parent task for T6112: Cloud Init Ordering Incorrect: T5907: cloud-init root task for 1.5 and 1.4 .
Apr 7 2024, 4:45 PM · VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav added a comment to T6099: Suppress unsupported interfaces from appearing in messages log by Telegraf .

@Giggum Can you check it on 1.5?

Apr 7 2024, 3:56 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T5810: Add support for RPKI source ip.

It is easy to add
In FRR it looks like:

r4(config-rpki)# rpki cache 192.0.2.1 8888 
  SSH_UNAME   SSH user name
  preference  Preference of the cache server
  source      Configure source IP address of RPKI connection
Apr 7 2024, 3:22 PM · Restricted Project, VyOS 1.5 Circinus
Viacheslav added a comment to T5169: Add CGNAT Carrier-Grade NAT based on nftables.

PoC PR https://github.com/vyos/vyos-1x/pull/3274

set nat cgnat pool external ext1 external-port-range '1024-65535'
set nat cgnat pool external ext1 per-user-limit port '1000'
set nat cgnat pool external ext1 range 192.0.2.222/32
set nat cgnat pool internal int1 range '100.64.0.0/28'
set nat cgnat rule 10 source pool 'int1'
set nat cgnat rule 10 translation pool 'ext1'
Apr 7 2024, 2:36 PM · VyOS 1.5 Circinus
daknob added a comment to T5810: Add support for RPKI source ip.

For me personally this change makes sense: a router has multiple interfaces, the Source IP is selected in different ways, and especially for RPKI servers outside the network (public ones), this could even break connectivity. Vendors like Juniper had this issue and eventually added the option, which means probably VyOS will benefit too, especially since "it's just setting a value in FRR's config"™ (famous last words ;).

Apr 7 2024, 1:05 PM · Restricted Project, VyOS 1.5 Circinus
Loremo added a comment to T5810: Add support for RPKI source ip.

Yes and no. Even before I created this ticket, I tried a small test locally. Unfortunately, I was not able to get the tests to run (even without my changes).

Apr 7 2024, 12:45 PM · Restricted Project, VyOS 1.5 Circinus
daknob added a comment to T5810: Add support for RPKI source ip.

@Loremo I think this contribution would be valuable. Have you made any progress with your PR?

Apr 7 2024, 11:39 AM · Restricted Project, VyOS 1.5 Circinus
GurliGebis added a comment to T5873: ipsec remote access VPN: support VTI interfaces.

Great 😃

Apr 7 2024, 5:49 AM · VyOS 1.5 Circinus
lucasec added a comment to T5873: ipsec remote access VPN: support VTI interfaces.

Hi -- this works. The VTI interface is just another interface so you can add it to a firewall zone just as you would an Ethernet interface. This can be done with existing site-to-site ipsec VTIs today. I also do it with OpenVPN interfaces for remote access on some of my installations.

Apr 7 2024, 1:57 AM · VyOS 1.5 Circinus
Fr0stedD0nut added a comment to T5432: Add grub-settings to system section in VyOS config-mode.

This would be really useful. As per: https://forum.vyos.io/t/other-than-console-how-to-pass-grub-parameter-pcie-aspm-off/14203

Apr 7 2024, 12:27 AM · VyOS 1.5 Circinus

Apr 6 2024

jestabro closed T6203: Remove references to the obsolete vyos.xml module (superseded by vyos.xml_ref), a subtask of T5319: Remove remaining workarounds for incorrect defaults, as Resolved.
Apr 6 2024, 2:54 PM · VyOS 1.4 Sagitta
jestabro closed T6203: Remove references to the obsolete vyos.xml module (superseded by vyos.xml_ref), a subtask of T5218: Revise vyos xml lib for bug fixes and extensions, as Resolved.
Apr 6 2024, 2:54 PM · VyOS 1.4 Sagitta
theflakes updated the task description for T6210: Support configuring sys-nice capability for containers.
Apr 6 2024, 2:43 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
theflakes created T6210: Support configuring sys-nice capability for containers.
Apr 6 2024, 2:36 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus

Apr 5 2024

jestabro changed the status of T6203: Remove references to the obsolete vyos.xml module (superseded by vyos.xml_ref), a subtask of T5218: Revise vyos xml lib for bug fixes and extensions, from Open to Backport candidate.
Apr 5 2024, 7:46 PM · VyOS 1.4 Sagitta
jestabro changed the status of T6203: Remove references to the obsolete vyos.xml module (superseded by vyos.xml_ref), a subtask of T5319: Remove remaining workarounds for incorrect defaults, from Open to Backport candidate.
Apr 5 2024, 7:46 PM · VyOS 1.4 Sagitta
c-po closed T6089: [1.3.6->1.4.0-epa1 Migration] "ospf passive-interface default" incorrectly added, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
Apr 5 2024, 4:11 PM · VyOS 1.4 Sagitta (1.4.0-GA)
jestabro added a subtask for T4516: Rewrite system image manipulation tools in Python: T6207: image-tools: restore ability to copy config.boot.default on image install.
Apr 5 2024, 3:57 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort changed the status of T6205: ipoe: error in migration script logic while renaming mac-address to mac, a subtask of T5938: Migration fail root task for 1.4-rc, from Open to Confirmed.
Apr 5 2024, 2:59 PM · VyOS 1.4 Sagitta (1.4.0-GA)
a.apostoliuk added a subtask for T5938: Migration fail root task for 1.4-rc: T6205: ipoe: error in migration script logic while renaming mac-address to mac.
Apr 5 2024, 1:05 PM · VyOS 1.4 Sagitta (1.4.0-GA)
natali-rs1985 changed the status of T1244: Add support for StartupResync in conntrack-sync from Open to In progress.
Apr 5 2024, 10:47 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.3 Equuleus (1.3.7)
HollyGurza added a comment to T5124: Python3 deprecation distutils.version import LooseVersion.

about vyos-1x:
current and sagitta don't use distutils, I found this only for equuleus
https://github.com/vyos/vyos-1x/blob/ae96118ec38c4064552889aea5e50023a66aac1e/src/conf_mode/nat.py#L21
https://github.com/vyos/vyos-1x/blob/ae96118ec38c4064552889aea5e50023a66aac1e/smoketest/scripts/cli/test_system_login.py#L23

Apr 5 2024, 9:22 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
Viacheslav closed T4504: Segment routing v6 as Invalid.

We are currently using FRR segment routing set protocols segment-routing srv6
For now, it could be closed

Apr 5 2024, 7:59 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
HollyGurza claimed T5124: Python3 deprecation distutils.version import LooseVersion.
Apr 5 2024, 7:50 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
HollyGurza added a comment to T5124: Python3 deprecation distutils.version import LooseVersion.

fix for vyos-build: https://github.com/vyos/vyos-build/pull/549

Apr 5 2024, 6:47 AM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 4 2024

dmbaturin added a project to T876: L2TP/IPSEC Client: VyOS 1.5 Circinus.
Apr 4 2024, 10:36 PM · VyOS 1.5 Circinus
dmbaturin added a project to T6080: Default NTP server settings: Restricted Project.
Apr 4 2024, 10:33 PM · Restricted Project, VyOS 1.4 Sagitta
dmbaturin added projects to T5022: VRRP add mail notification: VyOS 1.5 Circinus, Restricted Project.
Apr 4 2024, 10:23 PM · Restricted Project, VyOS 1.5 Circinus
dmbaturin added a project to T4564: Root task for rewriting [op-mode] to vyos.opmode format: VyOS 1.5 Circinus.
Apr 4 2024, 10:05 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
dmbaturin added a project to T4548: GRUB loader configuration rework: VyOS 1.5 Circinus.
Apr 4 2024, 10:03 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
dmbaturin added a project to T4504: Segment routing v6: VyOS 1.5 Circinus.
Apr 4 2024, 10:02 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
dmbaturin added a project to T4406: Make an API endpoint for for anonymous host info retrieval (e.g. by a login page): Restricted Project.
Apr 4 2024, 10:01 PM · Restricted Project, VyOS 1.5 Circinus
dmbaturin added a project to T4393: sstp: add support for configuring host-name (SNI): Restricted Project.
Apr 4 2024, 10:00 PM · VyOS 1.4 Sagitta (1.4.0-GA)
dmbaturin edited projects for T4318: Add delete_tag to configtree.py, added: Restricted Project, VyOS 1.5 Circinus; removed VyOS 1.3 Equuleus (1.3.7).
Apr 4 2024, 10:00 PM · VyOS 1.5 Circinus, Restricted Project
dmbaturin removed a project from T3843: l2tp configuration not cleared after delete: VyOS 1.3 Equuleus (1.3.7).
Apr 4 2024, 9:59 PM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
dmbaturin merged T3337: Add possibility to serve static DNS zones from the router into T562: PDNS: Add support for authoritative dns server.
Apr 4 2024, 9:54 PM · VyOS 1.4 Sagitta
dmbaturin added a project to T3202: Enable wireguard debug messages by default: Restricted Project.
Apr 4 2024, 9:46 PM · VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project, VyOS 1.5 Circinus
dmbaturin added a project to T2288: Include iprange package in Vyos: Restricted Project.
Apr 4 2024, 8:14 PM · Restricted Project, VyOS 1.5 Circinus
jestabro added a subtask for T5319: Remove remaining workarounds for incorrect defaults: T6203: Remove references to the obsolete vyos.xml module (superseded by vyos.xml_ref).
Apr 4 2024, 8:01 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T5218: Revise vyos xml lib for bug fixes and extensions: T6203: Remove references to the obsolete vyos.xml module (superseded by vyos.xml_ref).
Apr 4 2024, 8:01 PM · VyOS 1.4 Sagitta
dmbaturin closed T788: Nightly builds are not signed as Resolved.

They are signed with minisign now.

Apr 4 2024, 7:54 PM · VyOS 1.5 Circinus
dmbaturin added a project to T621: Allow image pruning by list index.: Restricted Project.
Apr 4 2024, 7:52 PM · VyOS 1.5 Circinus, Restricted Project
dmbaturin added a project to T6144: Update system image without enough space for the files can to break the system: Restricted Project.
Apr 4 2024, 7:48 PM · VyOS 1.4 Sagitta (1.4.0-GA), Restricted Project
dmbaturin closed T6139: Fix generate qcow2 from iso got error on repo https://github.com/vyos/vyos-vm-images as Wontfix.

This will be handled by the redesigned flavor system soon (T3664).

Apr 4 2024, 7:48 PM · VyOS 1.4 Sagitta
dmbaturin closed T6115: Build from Git tags fail as Resolved.
Apr 4 2024, 7:45 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
dmbaturin closed T5711: Put the version data file inside the ISO image as Resolved.
Apr 4 2024, 7:42 PM · VyOS 1.4 Sagitta
dmbaturin closed T5672: Remove the old-style command definition importer as Resolved.
Apr 4 2024, 7:41 PM · VyOS 1.4 Sagitta
dmbaturin closed T5639: Group vyos-1x dependencies by their VyOS components and specify their purpose as Resolved.
Apr 4 2024, 7:41 PM · VyOS 1.4 Sagitta
dmbaturin closed T5638: Add support for requiring numeric values to be ranges rather than single numbers as Resolved.
Apr 4 2024, 7:41 PM · VyOS 1.4 Sagitta
dmbaturin closed T5634: Remove support for Blowfish and DES from OpenVPN as Resolved.
Apr 4 2024, 7:40 PM · VyOS 1.4 Sagitta
dmbaturin closed T5582: Add a command to force NTP sync as Resolved.
Apr 4 2024, 7:36 PM · VyOS 1.4 Sagitta
c-po changed the status of T6089: [1.3.6->1.4.0-epa1 Migration] "ospf passive-interface default" incorrectly added, a subtask of T5938: Migration fail root task for 1.4-rc, from Open to In progress.
Apr 4 2024, 7:02 PM · VyOS 1.4 Sagitta (1.4.0-GA)
HollyGurza added a comment to T6166: Allow the user to specify tech support report output location.

https://github.com/vyos/vyos-1x/pull/3242

Apr 4 2024, 9:56 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
HollyGurza changed the status of T6166: Allow the user to specify tech support report output location from Open to In progress.
Apr 4 2024, 9:52 AM · VyOS 1.4 Sagitta (1.4.0-epa3)
natali-rs1985 claimed T5364: Make it possible to set the PADO delay to 0.
Apr 4 2024, 9:30 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 3 2024

GurliGebis added a comment to T5873: ipsec remote access VPN: support VTI interfaces.

Just wondering - is it possible to add a vti interface to a zone in the firewall?
How would one go about using this with the zone based firewall? 🙂

Apr 3 2024, 10:12 PM · VyOS 1.5 Circinus
Fr0stedD0nut added a comment to T4930: Allow WireGuard peers via DNS hostname.

Does anyone have any thoughts on the best place to start adding this functionality / design ideas for this feature?

Apr 3 2024, 8:59 PM · VyOS 1.5 Circinus
Viacheslav closed T6200: Error on adding a wildcard interface as Invalid.
Apr 3 2024, 7:12 PM · VyOS 1.4 Sagitta
n.fort added a comment to T6068: Support active-active and active-passive high availability modes in DHCP server.

PR for Sagitta: https://github.com/vyos/vyos-1x/pull/3239

Apr 3 2024, 6:09 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
n.fort added a comment to T6200: Error on adding a wildcard interface.

Try with:

Apr 3 2024, 6:08 PM · VyOS 1.4 Sagitta
marcomuskus created T6200: Error on adding a wildcard interface.
Apr 3 2024, 3:52 PM · VyOS 1.4 Sagitta
dmbaturin closed T6198: configverify: add common helper for PKI certificate validation, a subtask of T5894: Extend get_config_dict() with additional parameter with_pki that defaults to False, as Resolved.
Apr 3 2024, 6:08 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Apr 2 2024

Giggum added a comment to T6123: Limit NTP allow-client config to internal addresses by default.

Related to https://vyos.dev/T6080

Apr 2 2024, 8:23 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
c-po moved T6198: configverify: add common helper for PKI certificate validation from Need Triage to Finished on the VyOS 1.5 Circinus board.
Apr 2 2024, 5:03 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po added a comment to T6198: configverify: add common helper for PKI certificate validation.

https://github.com/vyos/vyos-1x/pull/3236

Apr 2 2024, 4:36 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po claimed T6198: configverify: add common helper for PKI certificate validation.
Apr 2 2024, 4:31 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
c-po created T6198: configverify: add common helper for PKI certificate validation.
Apr 2 2024, 4:31 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando closed T6151: BGP VRF route-leaking does not work when the next-hop is a recursive route as Resolved.
Apr 2 2024, 12:37 PM · VyOS 1.4 Sagitta (1.4.0-epa3)
fernando added a comment to T6151: BGP VRF route-leaking does not work when the next-hop is a recursive route.

this new command was merge in order to solved this problem :

vyos@vrf-test:~$ show configuration commands | match disable
set protocols bgp parameters disable-ebgp-connected-route-check
Apr 2 2024, 12:36 PM · VyOS 1.4 Sagitta (1.4.0-epa3)

Apr 1 2024

robertoberto closed T6194: dhcp range exclude improve documentation as Invalid.
Always exclude this address from any defined range. This address will never be assigned by the DHCP server.

Ok, it will exclude in any range.
Forget about it

Apr 1 2024, 3:02 PM · VyOS 1.4 Sagitta
robertoberto created T6194: dhcp range exclude improve documentation .
Apr 1 2024, 1:17 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T6033: hsflowd fails to start when using a tunnel interface.

@ServerForge It is question for hsflowd
You can open the issue on their git repo

Apr 1 2024, 7:09 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus
ServerForge added a comment to T6033: hsflowd fails to start when using a tunnel interface.

Its no longer failing to start, but it seems to be only capturing inbound traffic on the tunnel, no outbound. I'm also observing this behavior on vlan interfaces, IE bond0.10.

Apr 1 2024, 12:25 AM · VyOS 1.4 Sagitta (1.4.0-epa3), VyOS 1.5 Circinus

Mar 31 2024

Viacheslav added a comment to T5169: Add CGNAT Carrier-Grade NAT based on nftables.

Proposed CLI:

set nat cgnat pool external <external> range 192.0.2.0/30 seq 1
set nat cgnat pool external <external> range 192.0.2.128-192.0.2.132 seq 2
set nat cgnat pool external <external> per-user-limit port 1024
set nat cgnat pool external <external> global-port-range 1024-65535
set nat cgnat pool internal <internal> range 100.64.1.0/24
Mar 31 2024, 1:10 PM · VyOS 1.5 Circinus