Page MenuHomeVyOS Platform
Feed Advanced Search

Sep 2 2016

yun added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

It would be nice if this was available in the next release. Happy to receive any feedback if I need to improve the patch.

Sep 2 2016, 2:47 PM · Invalid

Sep 1 2016

246tnt added a comment to T132: Allow route-map to set "src".

I pushed the priority changes I had to do on my T132 branch.

Sep 1 2016, 1:51 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Aug 25 2016

oliveriandrea added a comment to T128: DNS forwarding service listens-on inexistent interfaces.

As it is now it can not break the config, that is why "wontfix".
If we block it then configs that have non existent interfaces in them (due to breakage or removed and forgot to remove from dns forwarding) will fail at boot.

Aug 25 2016, 11:42 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
UnicronNL added a comment to T128: DNS forwarding service listens-on inexistent interfaces.

As it is now it can not break the config, that is why "wontfix".
If we block it then configs that have non existent interfaces in them (due to breakage or removed and forgot to remove from dns forwarding) will fail at boot.

Aug 25 2016, 10:46 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
oliveriandrea reopened T128: DNS forwarding service listens-on inexistent interfaces as "Open".

As @UnicronNL says, lines about nonexistent interfaces have no effect on dnsmasq functionality.

But what's worse, is that making it a commit fail will break the configs of those people who carelessly left a nonexistent interface in their DNS forwarding config, it will fail to load at boot time after upgrade.

As much as I hate generating configs that make no sense, leaving those people with potentially inaccessible systems after they upgrade (DNS loads before SSH AFAIR) is not an acceptable cost of somewhat tidier generated configs.

Aug 25 2016, 8:45 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Aug 24 2016

dmbaturin closed T128: DNS forwarding service listens-on inexistent interfaces as Wontfix.

As @UnicronNL says, lines about nonexistent interfaces have no effect on dnsmasq functionality.

Aug 24 2016, 5:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Aug 23 2016

UnicronNL closed T74: Fix VRRP in nightly development builds as Resolved.

https://github.com/vyos/vyatta-vrrp/commit/86a3e32d367c6936fe424d6aace06ea7262f4300

Aug 23 2016, 8:27 AM · VyOS 1.1.x (1.1.8)
UnicronNL claimed T74: Fix VRRP in nightly development builds.
Aug 23 2016, 8:26 AM · VyOS 1.1.x (1.1.8)

Aug 22 2016

syncer added projects to T134: If default boot image differs from currently running image, check configurations for differences and alert user: VyOS 1.1.x (1.1.8), VyOS 2.0.x.

@dmbaturin is about unsaved changes indication
@jeffbearer system loads last saved config

Aug 22 2016, 9:33 PM · VyOS 1.3 Equuleus (1.3.8)
mickvav added a comment to T132: Allow route-map to set "src".

Can you push your recent changes to github?

Aug 22 2016, 3:27 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
246tnt added a comment to T132: Allow route-map to set "src".

Changing the priorities, I managed to make it work and it's loaded fine on reboot.

Aug 22 2016, 2:43 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
mickvav added a comment to T132: Allow route-map to set "src".

You need "create" section in your templates/policy/route-map/node.tag/rule/node.tag/set/src/node.def to make things survive reboots, I think.

Aug 22 2016, 2:29 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Aug 21 2016

syncer triaged T120: Native LibreNMS support as Wishlist priority.
Aug 21 2016, 5:03 PM · Rejected

Aug 17 2016

246tnt added a comment to T132: Allow route-map to set "src".

Ok, so the main issue is that the route-map is only applied to routes installed _after_ it's been setup ... so you have to remove / readd all the static routes which obviously doesn't work when you reboot :(

Aug 17 2016, 3:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
246tnt added a comment to T132: Allow route-map to set "src".

This is my attempt :

Aug 17 2016, 2:23 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
246tnt updated the task description for T132: Allow route-map to set "src".
Aug 17 2016, 1:57 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
syncer triaged T132: Allow route-map to set "src" as Normal priority.
Aug 17 2016, 1:55 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Aug 16 2016

jinho added a watcher for VyOS 2.0.x: jinho.
Aug 16 2016, 5:54 PM

Aug 14 2016

syncer triaged T128: DNS forwarding service listens-on inexistent interfaces as High priority.
Aug 14 2016, 1:30 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer updated subscribers of T129: Lithium does not commit boot configuration.
Aug 14 2016, 1:30 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
oliveriandrea created T129: Lithium does not commit boot configuration.
Aug 14 2016, 12:53 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
oliveriandrea created T128: DNS forwarding service listens-on inexistent interfaces.
Aug 14 2016, 10:08 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
oliveriandrea created T127: Double quotes in openvpn-option.
Aug 14 2016, 9:44 AM · Invalid

Aug 13 2016

gaztel added a watcher for VyOS 2.0.x: gaztel.
Aug 13 2016, 10:21 AM

Aug 11 2016

aopdal added a comment to T74: Fix VRRP in nightly development builds.

vyos@r1-80001# run sh ver

Aug 11 2016, 10:45 AM · VyOS 1.1.x (1.1.8)

Aug 10 2016

davidhoa added a watcher for VyOS 2.0.x: davidhoa.
Aug 10 2016, 4:39 AM

Aug 7 2016

syncer added a comment to T118: Native Zabbix Support.

@higebu seems correct.
It will be a good start

Aug 7 2016, 2:37 PM · Restricted Project, VyOS 1.4 Sagitta
higebu added a comment to T118: Native Zabbix Support.

We need this? https://github.com/hiroyuki-sato/vyos-cfg-zabbix-agent

Aug 7 2016, 2:35 PM · Restricted Project, VyOS 1.4 Sagitta
syncer created T120: Native LibreNMS support.
Aug 7 2016, 12:57 PM · Rejected
syncer created T119: SNMP improvements.
Aug 7 2016, 12:24 PM · Rejected
syncer created T118: Native Zabbix Support.
Aug 7 2016, 12:13 PM · Restricted Project, VyOS 1.4 Sagitta

Aug 6 2016

jhendryUK added a watcher for VyOS 2.0.x: jhendryUK.
Aug 6 2016, 6:54 PM

Aug 4 2016

syncer created T110: Ability to store SSH keys out of the config.
Aug 4 2016, 10:52 PM · VyOS 1.5 Circinus

Jul 12 2016

syncer closed Q5: non inbox drivers for network devices in VyOS as resolved.
Jul 12 2016, 8:49 PM · VyOS 2.0.x, VyOS 1.1.x

Jul 10 2016

MikeLupe created T102: Add a command like "set service dns dynamic http-request url ...".
Jul 10 2016, 11:48 AM · VyOS 1.3 Equuleus (1.3.8)

Jun 29 2016

engyanw added a watcher for VyOS 2.0.x: engyanw.
Jun 29 2016, 12:01 AM

Jun 27 2016

syncer closed Q10: ARM architecture? as resolved.
Jun 27 2016, 12:07 PM · VyOS 2.0.x
syncer closed Q7: simple or advanced OVA/OVF distribution? as resolved.
Jun 27 2016, 12:03 PM · VyOS 2.0.x, VyOS 1.1.x
syncer added a comment to Q7: simple or advanced OVA/OVF distribution?.

confirmed, works just fine of free esxi

Jun 27 2016, 12:02 PM · VyOS 2.0.x, VyOS 1.1.x
syncer changed the visibility for Q6: UI if do it, how it should look like? .
Jun 27 2016, 12:01 PM · VyOS 1.2 Crux, VyOS 2.0.x
syncer added projects to Q4: VyOS CLI startup: VyOS 1.1.x (1.1.8), VyOS 2.0.x.
Jun 27 2016, 12:00 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8), VyConf
syncer closed Q15: SIP related functionality in VyOS as resolved.
Jun 27 2016, 11:46 AM · VyOS 2.0.x, VyOS 1.1.x

Jun 21 2016

kmpm added a watcher for VyOS 2.0.x: kmpm.
Jun 21 2016, 9:20 AM

Jun 20 2016

RafPe added a watcher for VyOS 2.0.x: RafPe.
Jun 20 2016, 2:52 PM

Jun 1 2016

EwaldvanGeffen added a comment to T75: NetFlow have impact on performance.

I think we can choose how to implement it. We can apply it as a default entry in one of the vyos chains or let the user-decide. The advantage with the latter is that both implementations can co-exist for a while. With the former solution I would remove the old implementation to not confuse the user.

Jun 1 2016, 5:18 PM · VyOS 1.3 Equuleus (1.3.8)
mickvav added a comment to T75: NetFlow have impact on performance.

Hm, as ipt-netflow is actually a firewall target, it looks like it's configuration logic should be slightly different from pmacct's one.
Looks like there should be some service level config tree, specifying module load parameters, like

Jun 1 2016, 4:26 PM · VyOS 1.3 Equuleus (1.3.8)
syncer added a comment to T75: NetFlow have impact on performance.

@afics thanks, i merged it to this one

Jun 1 2016, 1:58 PM · VyOS 1.3 Equuleus (1.3.8)
syncer merged T33: Add support for ipt-netflow, a faster/high performance Netflow collector into T75: NetFlow have impact on performance.
Jun 1 2016, 1:57 PM · VyOS 1.3 Equuleus (1.3.8)
Unknown Object (User) added a comment to T75: NetFlow have impact on performance.

Related/duplicate: T33.

Jun 1 2016, 1:55 PM · VyOS 1.3 Equuleus (1.3.8)

May 31 2016

mickvav added a comment to T75: NetFlow have impact on performance.

I had to disable dkms there
https://github.com/mickvav/ipt-netflow-code
And if anyone is interested - I also have xtables-addons compilable against vyos kernel (it has several interesting firewall features - such as geoip and ipmark) - https://github.com/mickvav/xtables-addons

May 31 2016, 4:12 PM · VyOS 1.3 Equuleus (1.3.8)
mickvav added a comment to T75: NetFlow have impact on performance.

Well, I have ipt-netflow on self-rebuilt vyos kernel, no problems with performance. But I have no vyos-related scripts for interaction with this module.

May 31 2016, 4:03 PM · VyOS 1.3 Equuleus (1.3.8)
UnicronNL added a comment to T74: Fix VRRP in nightly development builds.

These should be gone now.

May 31 2016, 5:58 AM · VyOS 1.1.x (1.1.8)

May 30 2016

syncer updated the task description for T75: NetFlow have impact on performance.
May 30 2016, 2:17 PM · VyOS 1.3 Equuleus (1.3.8)
syncer created T75: NetFlow have impact on performance.
May 30 2016, 2:16 PM · VyOS 1.3 Equuleus (1.3.8)
mickvav added a comment to T74: Fix VRRP in nightly development builds.

And some more, on the machine with working config:

May 30 2016, 11:52 AM · VyOS 1.1.x (1.1.8)
mickvav added a comment to T74: Fix VRRP in nightly development builds.

Ok, now works, but I've got some strange notices on "show vrrp" :

May 30 2016, 11:01 AM · VyOS 1.1.x (1.1.8)
mickvav created T74: Fix VRRP in nightly development builds.
May 30 2016, 6:30 AM · VyOS 1.1.x (1.1.8)

May 26 2016

fatihusta added a watcher for VyOS 2.0.x: fatihusta.
May 26 2016, 12:24 PM

May 21 2016

UnicronNL added a comment to T69: Kill off floppy support..

https://github.com/vyos/vyatta-cfg-system/commit/b66cc78521db17628efa3dd27766527816c170cc

May 21 2016, 4:11 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
UnicronNL closed T69: Kill off floppy support. as Resolved.
May 21 2016, 4:09 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
UnicronNL added a comment to T69: Kill off floppy support..

Makes code simpler and easier to read. Makes kernel a bit smaller (leave out floppy module)
Makes booting a little bit faster.

May 21 2016, 2:47 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
mickvav added a comment to T69: Kill off floppy support..

Why should we remove support for obsolete features, which do not break anything?

May 21 2016, 2:35 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
UnicronNL created T69: Kill off floppy support..
May 21 2016, 1:36 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

May 18 2016

adestis created T68: VyOS SDN support (openconfig, netconf, telemetry).
May 18 2016, 6:29 PM · Rejected

May 14 2016

syncer triaged T47: Some pull requests - please, route them. as Normal priority.
May 14 2016, 10:06 PM · VyOS 2.0.x
syncer triaged T64: Add support for named {,extended} community-lists as Wishlist priority.
May 14 2016, 10:06 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc4)

May 13 2016

syncer lowered the priority of T53: Serial console - related code needs to be adjusted from inittab to systemctl from High to Normal.
May 13 2016, 12:10 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), VyOS 2.0.x

May 11 2016

jrodrigo added a watcher for VyOS 2.0.x: jrodrigo.
May 11 2016, 10:27 AM

May 10 2016

syncer added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

@dmbaturin can you take a look and merge this patch ?

May 10 2016, 12:15 PM · Invalid
yun added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

I already have a working patch for my own setup, I attached it:

May 10 2016, 8:25 AM · Invalid

May 9 2016

syncer lowered the priority of T49: Kernel NFS server support from High to Wishlist.

Changing this to wishlist,
@dmbaturin please comment your view of this
Thanks

May 9 2016, 10:00 PM · Rejected
syncer triaged T51: Add support for an included dns recursor as Wishlist priority.

Hello,
we considering a possibility to add DNS recursor,
however, for now, there is no ETA for that functionality.

May 9 2016, 9:56 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T56: Add pkcs11 support to OpenVPN interfaces as Wishlist priority.

@dmbaturin this should be not hard to implement, correct?

May 9 2016, 9:51 PM · Invalid
syncer removed a project from T52: Q26 pull request seems to be tested at least.: VyOS TestLab.
May 9 2016, 2:20 AM · VyOS 1.1.x (1.1.8)

May 4 2016

mdsmds created T58: "monitor firewall name <name>" does not monitor any firewall-log-entry.
May 4 2016, 11:42 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Apr 28 2016

mickvav added a comment to T53: Serial console - related code needs to be adjusted from inittab to systemctl.

About systemd there is another point - if you look into systemd default setup (/lib/systemd/system/[email protected]), you can find that it's default setup is rather clever - it takes advantage from agetty's ability to automatically select console baud rate. But current vyos configuration scheme insists on some fixed baud rate. So, we also have options:

  1. (simple) Remove speed option or ignore it. + allows usage of upstream systemd configuration
  2. Alter systemd configuration to use fixed speed from config.
  3. Modify speed to accept list of possible speeds, e.g.
speed "9600[,38400...]"
Apr 28 2016, 12:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), VyOS 2.0.x
dmbaturin added a comment to T53: Serial console - related code needs to be adjusted from inittab to systemctl.

For the jessie branch, we are likely staying with systemd, so systemd-related code will have to be added anyway.
Whether to remove the inittab-related code or not, not sure. I don't think we should implement both right away, but if we leave some room for extending it to support other init systems, it should be fine I think.

Apr 28 2016, 11:04 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), VyOS 2.0.x
mickvav created T53: Serial console - related code needs to be adjusted from inittab to systemctl.
Apr 28 2016, 10:49 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), VyOS 2.0.x
mickvav added projects to T52: Q26 pull request seems to be tested at least.: VyOS 2.0.x, VyOS 1.1.x, VyOS TestLab.

Looks like this simple patch is ready for production. Backing idea - quagga has route-map to filter routes, going to be installed from ospf into kernel table, but we had no way to install it in vyos config. This patch creates 'router ospf route-map NAME' vyos configuration command, which maps into 'ip protocol ospf route-map NAME' quagga configuration mode command. The development was discussed under Q26.

Apr 28 2016, 10:03 AM · VyOS 1.1.x (1.1.8)

Apr 27 2016

syncer updated subscribers of T49: Kernel NFS server support.

@mickvav exactly, we looking to provide some support in that direction
@aopdal, I understand your concerns, but also don't find limiting users as something good,
@UnicronNL ported 1.2 to clearfog pro device, NFS server will be a good addition there for example,
we also talked about SIP functionality, all that Network Functions.
It does not about create multi-purpose distro, more like provide ability to build customized images

Apr 27 2016, 10:10 PM · Rejected
mickvav added a comment to T49: Kernel NFS server support.

Well, I think that anyone, who really needs some specific feature set, nfs server, samba server, whatever, can make and maintain his own fork of vyos-build and it has (almost) no problem to build a speific iso himself.

Apr 27 2016, 6:49 AM · Rejected
aopdal added a comment to T49: Kernel NFS server support.

Why would anybody want to use a router as a "small server"? General Linux distributions have everything you need for a small server.

Apr 27 2016, 6:33 AM · Rejected

Apr 26 2016

mickvav closed T47: Some pull requests - please, route them. as Resolved.

Looks like it's closed mostly.

Apr 26 2016, 1:45 PM · VyOS 2.0.x

Apr 21 2016

syncer updated subscribers of T49: Kernel NFS server support.

@EwaldvanGeffen
i will be happy to have ability add nfs/nettalk/cifs
for that type of home appliances, not sure how we should handle such deviations
I believe we should not be restrictive in this matter

Apr 21 2016, 4:10 PM · Rejected
EwaldvanGeffen added a comment to T49: Kernel NFS server support.

I think its outside our scope. vyos is a network appliance. it provides services to transfer network traffic or services essential to transfer traffic (dns, dhcp). nfs does touch this aspect at all. Neighter would a radius service but that would enable pppoe-server or hostapd,... to move traffic. Nfs is not a requirement for any deamon to move traffic. ergo outside thhe scope.

Apr 21 2016, 10:26 AM · Rejected

Apr 20 2016

Reuuke added a comment to T49: Kernel NFS server support.
In T49#768, @mickvav wrote:
In T49#766, @mickvav wrote:

I think Reukke will answer himself, but as for me - typical use-case is a small server, acting as all-in-one solution for small linux workgroup. E.g. a router, ldap-authentication server, common files storage and a web site ;). It would be hard to maintain and keep secure, but it's possible.
N.B. Persomally I need nfs client and I'll double check, whether it's enabled in my branch tomorrow...

Apr 20 2016, 5:42 AM · Rejected

Apr 19 2016

mickvav added a comment to T49: Kernel NFS server support.
In T49#766, @mickvav wrote:

I think Reukke will answer himself, but as for me - typical use-case is a small server, acting as all-in-one solution for small linux workgroup. E.g. a router, ldap-authentication server, common files storage and a web site ;). It would be hard to maintain and keep secure, but it's possible.
N.B. Persomally I need nfs client and I'll double check, whether it's enabled in my branch tomorrow...

Apr 19 2016, 8:50 PM · Rejected
mickvav added a comment to T49: Kernel NFS server support.

I think Reukke will answer himself, but as for me - typical use-case is a small server, acting as all-in-one solution for small linux workgroup. E.g. a router, ldap-authentication server, common files storage and a web site ;). It would be hard to maintain and keep secure, but it's possible.
N.B. Persomally I need mfs client and I'll double check, whether it's enabled in my branch tomorrow...

Apr 19 2016, 8:48 PM · Rejected
EwaldvanGeffen added a comment to T49: Kernel NFS server support.

Could you give an example of an use-case? Because I think this choice was very much by-design.

Apr 19 2016, 8:41 PM · Rejected
Reuuke updated the task description for T49: Kernel NFS server support.
Apr 19 2016, 2:56 PM · Rejected
Reuuke updated the task description for T49: Kernel NFS server support.
Apr 19 2016, 2:55 PM · Rejected
Reuuke created T49: Kernel NFS server support.
Apr 19 2016, 2:36 PM · Rejected

Apr 13 2016

murmaider added a comment to T26: Update Quagga - CVE-2016-2342.

Where is the updated vyatta-quagga packages ?

Apr 13 2016, 5:42 AM · VyOS 1.1.x (1.1.8), VyOS 2.0.x

Apr 12 2016

Itty added a comment to Q5: non inbox drivers for network devices in VyOS.
Apr 12 2016, 6:27 PM · VyOS 2.0.x, VyOS 1.1.x

Apr 11 2016

dmbaturin changed the status of T25: No debian/control in vyos-kernel from Resolved to Wontfix.

It is normal. In the debian way of doing things, debian/control of the kernel package is produced by running "debian/rules debian/control" (sic!), as it's architecture-dependent.

Apr 11 2016, 7:07 PM · Rejected
mickvav closed T25: No debian/control in vyos-kernel as Resolved.
Apr 11 2016, 6:22 PM · Rejected
mickvav updated the task description for T47: Some pull requests - please, route them..
Apr 11 2016, 6:20 PM · VyOS 2.0.x
mickvav created T47: Some pull requests - please, route them..
Apr 11 2016, 12:21 PM · VyOS 2.0.x

Apr 6 2016

Pretwolk added a watcher for VyOS 2.0.x: Pretwolk.
Apr 6 2016, 5:34 PM

Apr 1 2016

mickvav added a comment to T31: Add VRF support.

If this will be included, someone has to make deep testing of quagga vrf-related patchset. Looks like it's described here: http://permalink.gmane.org/gmane.network.quagga.devel/11770 but I'm not sure, whether it's included in upstream quagga or not.

Apr 1 2016, 9:01 AM · VyOS 1.3 Equuleus (1.3.0-epa1)