Page MenuHomeVyOS Platform
Feed Advanced Search

Sep 16 2016

rps added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@EwaldvanGeffen have you given the method I described a try on VyOS? I know it works on EdgeOS and pre- 6.4 releases of Vyatta and honestly haven't tested it on VyOS because it's not something I have a need for... so it very well could work differently/be broken on VyOS, but that would be surprising.

Sep 16 2016, 11:24 AM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
rps added a comment to Q50: Any hope for DPDK?.

@mickvav I think when people ask "does it support DPDK" it's because they've read that using DPDK will allow forwarding and possible filtering and NATing of traffic at 10 Gbps+ rates. VyOS offering some DPDK stuff and saying "mission accomplished" would leave a bad taste in people's mouths the same way CloudRouter is claiming DPDK support when it's only for bridged traffic.

Sep 16 2016, 11:03 AM · VyOS 1.2 Crux, VyOS 2.0.x
mickvav added a comment to Q50: Any hope for DPDK?.

Well, I think this question can't be correctly answered until it is correctly stated. So I suggest waiting @Caesar305 for some clarifications. @rps 's answer implies that "support" means "ALL the routing stack works over dpdk" which seems to be really far now. But another option is the ability to run specific dpdk software on dedicated ports (e.g. traffic generator software for load testing of external equipment or high performance network sniffer) - this task seems to be achievable, if it's requested and donated for :)

Sep 16 2016, 10:40 AM · VyOS 1.2 Crux, VyOS 2.0.x

Sep 15 2016

EwaldvanGeffen added a comment to Q52: Integrate Vyos with standalone web filtering device?.

Short answer: not really.

Sep 15 2016, 4:40 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
syncer added a comment to Q50: Any hope for DPDK?.

@rps
i guess you can put this as answer and we can mark it as solved

Sep 15 2016, 11:44 AM · VyOS 1.2 Crux, VyOS 2.0.x
rps added a comment to Q50: Any hope for DPDK?.

"DPDK support" involved a lot of low-level contributions to a lot of different projects. Essentially you need to re-implement major parts of Linux on a case-by-case basis which is outside of the scope for VyOS right now.

Sep 15 2016, 10:53 AM · VyOS 1.2 Crux, VyOS 2.0.x
rps added a comment to Q52: Integrate Vyos with standalone web filtering device?.

You can use policy routing to match HTTP and HTTPS traffic and point it at a next-hop that is an external transparent proxy.

Sep 15 2016, 10:34 AM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
mickvav created T153: Deal with web gui.
Sep 15 2016, 7:50 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), VyOS TestLab

Sep 14 2016

syncer added a comment to T151: Prepare generic presentation/talk.

Agree, we can do some slides for that purpose
i mean that people can add reporters and own companies as needed

Sep 14 2016, 8:53 PM · Invalid
dmbaturin added a comment to T151: Prepare generic presentation/talk.

Maybe really generic one should not reference specific companies, not sure.

Sep 14 2016, 8:50 PM · Invalid
syncer created T151: Prepare generic presentation/talk.
Sep 14 2016, 8:49 PM · Invalid
syncer updated subscribers of T149: IPv6 support in OpenVPN tunnel.

@afics this ticket at least have description
i will merge all to one soon

Sep 14 2016, 1:28 PM · VyOS 1.3 Equuleus (1.3.0-epa1), openvpn

Sep 12 2016

syncer added projects to T149: IPv6 support in OpenVPN tunnel: VyOS 1.1.x (1.1.8), VyOS 2.0.x.
Sep 12 2016, 4:20 PM · VyOS 1.3 Equuleus (1.3.0-epa1), openvpn
hmkias added a comment to Q52: Integrate Vyos with standalone web filtering device?.

Thanks both.
As suggested, is there a way to check the device is live and then forward traffic or do a fallback to another device.

Sep 12 2016, 9:52 AM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
mickvav added a comment to Q50: Any hope for DPDK?.

Hm, I belive it should be relatively easy to make vyos "forget" about some interfaces, on which you plan to use your separate dpdk-enabled software and to just compile dpdk into main distribution. Is it enough for your needs, @Caesar305 or you need some specific application or you are talking about making all firewall stuff work over dpdk (which sounds like A VERY VERY HUGE task)?

Sep 12 2016, 9:48 AM · VyOS 1.2 Crux, VyOS 2.0.x
mickvav added a comment to Q52: Integrate Vyos with standalone web filtering device?.

And if you have any other known https destinations with different port numbers - redirect corresponding traffic explicitly.

Sep 12 2016, 9:41 AM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

Sep 11 2016

EwaldvanGeffen added a comment to Q52: Integrate Vyos with standalone web filtering device?.

You would have to forward traffic to your device. Preferably it handles all types of traffic. Otherwise you can forward dport 443 towards a specific IP.

Sep 11 2016, 6:27 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
dmbaturin added a comment to T142: DSA-3659-1.

Anything local should hardly be considered high priority, but the first one is remote. We definitely should include the fix in the 1.1.8

Sep 11 2016, 10:56 AM · VyOS 1.1.x (1.1.8)
oliveriandrea added a comment to T142: DSA-3659-1.

Opinion: Yes, 1.1.8.

Sep 11 2016, 9:38 AM · VyOS 1.1.x (1.1.8)
whiskeyalpharomeo added a comment to T142: DSA-3659-1.

Opinion: Yes, 1.1.8.

Sep 11 2016, 2:21 AM · VyOS 1.1.x (1.1.8)
job added a comment to T143: Add support for Large BGP Community.

Keep in mind that the specification has not yet been standardised. If you commit to implementing, make sure you only release it as a 'beta' or 'test release'.

Sep 11 2016, 12:04 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)

Sep 10 2016

Caesar305 added a comment to T143: Add support for Large BGP Community.

Interested in this too. We will be multi-homing soon and requesting an AS number from ARIN. I doubt we will be getting a 2-byte ASN.

Sep 10 2016, 11:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)

Sep 9 2016

syncer changed the visibility for Q50: Any hope for DPDK?.
Sep 9 2016, 4:31 PM · VyOS 1.2 Crux, VyOS 2.0.x
syncer changed the visibility for Q52: Integrate Vyos with standalone web filtering device?.
Sep 9 2016, 4:30 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

Sep 5 2016

job added a comment to T143: Add support for Large BGP Community.

Let me know if you require any additional information. I'm happy to help you with interop testing

Sep 5 2016, 11:05 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)
syncer assigned T143: Add support for Large BGP Community to dmbaturin.

@dmbaturin what do you think?

Sep 5 2016, 5:05 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)

Sep 4 2016

syncer updated subscribers of T110: Ability to store SSH keys out of the config.

@whiskeyalpharomeo maybe in your scope of interest

Sep 4 2016, 7:32 PM · VyOS 1.5 Circinus
syncer assigned T142: DSA-3659-1 to dmbaturin.

@dmbaturin is this good reason for 1.1.8 ?

Sep 4 2016, 7:18 PM · VyOS 1.1.x (1.1.8)
mickvav created T142: DSA-3659-1.
Sep 4 2016, 6:27 PM · VyOS 1.1.x (1.1.8)
Unknown Object (User) added a comment to T31: Add VRF support.

@whiskeyalpharomeo you can do that already with the existing CLI.

Sep 4 2016, 6:02 PM · VyOS 1.3 Equuleus (1.3.0-epa1)

Sep 3 2016

syncer updated subscribers of T141: TACACS+ Support.

Welcome @whiskeyalpharomeo !
No code required(but of course welcomed if any)
After all this project not only about the code!
I like to think that is about giving access to advanced networking to everyone out there!
Since it not like 10 years ago, now technology(hardware) more accessible

Sep 3 2016, 4:09 PM · VyOS 1.4 Sagitta
whiskeyalpharomeo changed the edit policy for T141: TACACS+ Support.
Sep 3 2016, 3:37 PM · VyOS 1.4 Sagitta
whiskeyalpharomeo added a comment to T31: Add VRF support.

Absent full vrf or vrf-lite behavior, there is a means of achieving a subset of this behavior using only iptables.

Sep 3 2016, 3:34 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
whiskeyalpharomeo added a comment to T5: command logging (local and remote).

This is part of a broader AAA activity, such as TACACS+ and/or RADIUS integration for system level administration.

Sep 3 2016, 3:28 PM · VyOS 1.5 Circinus
whiskeyalpharomeo created T141: TACACS+ Support.
Sep 3 2016, 3:11 PM · VyOS 1.4 Sagitta

Sep 2 2016

yun added a comment to T56: Add pkcs11 support to OpenVPN interfaces.

It would be nice if this was available in the next release. Happy to receive any feedback if I need to improve the patch.

Sep 2 2016, 2:47 PM · Invalid

Sep 1 2016

246tnt added a comment to T132: Allow route-map to set "src".

I pushed the priority changes I had to do on my T132 branch.

Sep 1 2016, 1:51 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Aug 25 2016

oliveriandrea added a comment to T128: DNS forwarding service listens-on inexistent interfaces.

As it is now it can not break the config, that is why "wontfix".
If we block it then configs that have non existent interfaces in them (due to breakage or removed and forgot to remove from dns forwarding) will fail at boot.

Aug 25 2016, 11:42 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
UnicronNL added a comment to T128: DNS forwarding service listens-on inexistent interfaces.

As it is now it can not break the config, that is why "wontfix".
If we block it then configs that have non existent interfaces in them (due to breakage or removed and forgot to remove from dns forwarding) will fail at boot.

Aug 25 2016, 10:46 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
oliveriandrea reopened T128: DNS forwarding service listens-on inexistent interfaces as "Open".

As @UnicronNL says, lines about nonexistent interfaces have no effect on dnsmasq functionality.

But what's worse, is that making it a commit fail will break the configs of those people who carelessly left a nonexistent interface in their DNS forwarding config, it will fail to load at boot time after upgrade.

As much as I hate generating configs that make no sense, leaving those people with potentially inaccessible systems after they upgrade (DNS loads before SSH AFAIR) is not an acceptable cost of somewhat tidier generated configs.

Aug 25 2016, 8:45 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Aug 24 2016

dmbaturin closed T128: DNS forwarding service listens-on inexistent interfaces as Wontfix.

As @UnicronNL says, lines about nonexistent interfaces have no effect on dnsmasq functionality.

Aug 24 2016, 5:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Aug 23 2016

UnicronNL closed T74: Fix VRRP in nightly development builds as Resolved.

https://github.com/vyos/vyatta-vrrp/commit/86a3e32d367c6936fe424d6aace06ea7262f4300

Aug 23 2016, 8:27 AM · VyOS 1.1.x (1.1.8)
UnicronNL claimed T74: Fix VRRP in nightly development builds.
Aug 23 2016, 8:26 AM · VyOS 1.1.x (1.1.8)

Aug 22 2016

syncer added projects to T134: If default boot image differs from currently running image, check configurations for differences and alert user: VyOS 1.1.x (1.1.8), VyOS 2.0.x.

@dmbaturin is about unsaved changes indication
@jeffbearer system loads last saved config

Aug 22 2016, 9:33 PM · VyOS 1.3 Equuleus (1.3.8)
mickvav added a comment to T132: Allow route-map to set "src".

Can you push your recent changes to github?

Aug 22 2016, 3:27 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
246tnt added a comment to T132: Allow route-map to set "src".

Changing the priorities, I managed to make it work and it's loaded fine on reboot.

Aug 22 2016, 2:43 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
mickvav added a comment to T132: Allow route-map to set "src".

You need "create" section in your templates/policy/route-map/node.tag/rule/node.tag/set/src/node.def to make things survive reboots, I think.

Aug 22 2016, 2:29 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Aug 21 2016

syncer triaged T120: Native LibreNMS support as Wishlist priority.
Aug 21 2016, 5:03 PM · Rejected

Aug 17 2016

246tnt added a comment to T132: Allow route-map to set "src".

Ok, so the main issue is that the route-map is only applied to routes installed _after_ it's been setup ... so you have to remove / readd all the static routes which obviously doesn't work when you reboot :(

Aug 17 2016, 3:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
246tnt added a comment to T132: Allow route-map to set "src".

This is my attempt :

Aug 17 2016, 2:23 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
246tnt updated the task description for T132: Allow route-map to set "src".
Aug 17 2016, 1:57 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
syncer triaged T132: Allow route-map to set "src" as Normal priority.
Aug 17 2016, 1:55 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Aug 16 2016

jinho added a watcher for VyOS 2.0.x: jinho.
Aug 16 2016, 5:54 PM

Aug 14 2016

syncer triaged T128: DNS forwarding service listens-on inexistent interfaces as High priority.
Aug 14 2016, 1:30 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer updated subscribers of T129: Lithium does not commit boot configuration.
Aug 14 2016, 1:30 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
oliveriandrea created T129: Lithium does not commit boot configuration.
Aug 14 2016, 12:53 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
oliveriandrea created T128: DNS forwarding service listens-on inexistent interfaces.
Aug 14 2016, 10:08 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
oliveriandrea created T127: Double quotes in openvpn-option.
Aug 14 2016, 9:44 AM · Invalid

Aug 13 2016

gaztel added a watcher for VyOS 2.0.x: gaztel.
Aug 13 2016, 10:21 AM

Aug 11 2016

aopdal added a comment to T74: Fix VRRP in nightly development builds.

vyos@r1-80001# run sh ver

Aug 11 2016, 10:45 AM · VyOS 1.1.x (1.1.8)

Aug 10 2016

davidhoa added a watcher for VyOS 2.0.x: davidhoa.
Aug 10 2016, 4:39 AM

Aug 7 2016

syncer added a comment to T118: Native Zabbix Support.

@higebu seems correct.
It will be a good start

Aug 7 2016, 2:37 PM · Restricted Project, VyOS 1.4 Sagitta
higebu added a comment to T118: Native Zabbix Support.

We need this? https://github.com/hiroyuki-sato/vyos-cfg-zabbix-agent

Aug 7 2016, 2:35 PM · Restricted Project, VyOS 1.4 Sagitta
syncer created T120: Native LibreNMS support.
Aug 7 2016, 12:57 PM · Rejected
syncer created T119: SNMP improvements.
Aug 7 2016, 12:24 PM · Rejected
syncer created T118: Native Zabbix Support.
Aug 7 2016, 12:13 PM · Restricted Project, VyOS 1.4 Sagitta

Aug 6 2016

jhendryUK added a watcher for VyOS 2.0.x: jhendryUK.
Aug 6 2016, 6:54 PM

Aug 4 2016

syncer created T110: Ability to store SSH keys out of the config.
Aug 4 2016, 10:52 PM · VyOS 1.5 Circinus

Jul 12 2016

syncer closed Q5: non inbox drivers for network devices in VyOS as resolved.
Jul 12 2016, 8:49 PM · VyOS 2.0.x, VyOS 1.1.x

Jul 10 2016

MikeLupe created T102: Add a command like "set service dns dynamic http-request url ...".
Jul 10 2016, 11:48 AM · VyOS 1.3 Equuleus (1.3.8)

Jun 29 2016

engyanw added a watcher for VyOS 2.0.x: engyanw.
Jun 29 2016, 12:01 AM

Jun 27 2016

syncer closed Q10: ARM architecture? as resolved.
Jun 27 2016, 12:07 PM · VyOS 2.0.x
syncer closed Q7: simple or advanced OVA/OVF distribution? as resolved.
Jun 27 2016, 12:03 PM · VyOS 2.0.x, VyOS 1.1.x
syncer added a comment to Q7: simple or advanced OVA/OVF distribution?.

confirmed, works just fine of free esxi

Jun 27 2016, 12:02 PM · VyOS 2.0.x, VyOS 1.1.x
syncer changed the visibility for Q6: UI if do it, how it should look like? .
Jun 27 2016, 12:01 PM · VyOS 1.2 Crux, VyOS 2.0.x
syncer added projects to Q4: VyOS CLI startup: VyOS 1.1.x (1.1.8), VyOS 2.0.x.
Jun 27 2016, 12:00 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8), VyConf
syncer closed Q15: SIP related functionality in VyOS as resolved.
Jun 27 2016, 11:46 AM · VyOS 2.0.x, VyOS 1.1.x

Jun 21 2016

kmpm added a watcher for VyOS 2.0.x: kmpm.
Jun 21 2016, 9:20 AM

Jun 20 2016

RafPe added a watcher for VyOS 2.0.x: RafPe.
Jun 20 2016, 2:52 PM

Jun 1 2016

EwaldvanGeffen added a comment to T75: NetFlow have impact on performance.

I think we can choose how to implement it. We can apply it as a default entry in one of the vyos chains or let the user-decide. The advantage with the latter is that both implementations can co-exist for a while. With the former solution I would remove the old implementation to not confuse the user.

Jun 1 2016, 5:18 PM · VyOS 1.3 Equuleus (1.3.8)
mickvav added a comment to T75: NetFlow have impact on performance.

Hm, as ipt-netflow is actually a firewall target, it looks like it's configuration logic should be slightly different from pmacct's one.
Looks like there should be some service level config tree, specifying module load parameters, like

Jun 1 2016, 4:26 PM · VyOS 1.3 Equuleus (1.3.8)
syncer added a comment to T75: NetFlow have impact on performance.

@afics thanks, i merged it to this one

Jun 1 2016, 1:58 PM · VyOS 1.3 Equuleus (1.3.8)
syncer merged T33: Add support for ipt-netflow, a faster/high performance Netflow collector into T75: NetFlow have impact on performance.
Jun 1 2016, 1:57 PM · VyOS 1.3 Equuleus (1.3.8)
Unknown Object (User) added a comment to T75: NetFlow have impact on performance.

Related/duplicate: T33.

Jun 1 2016, 1:55 PM · VyOS 1.3 Equuleus (1.3.8)

May 31 2016

mickvav added a comment to T75: NetFlow have impact on performance.

I had to disable dkms there
https://github.com/mickvav/ipt-netflow-code
And if anyone is interested - I also have xtables-addons compilable against vyos kernel (it has several interesting firewall features - such as geoip and ipmark) - https://github.com/mickvav/xtables-addons

May 31 2016, 4:12 PM · VyOS 1.3 Equuleus (1.3.8)
mickvav added a comment to T75: NetFlow have impact on performance.

Well, I have ipt-netflow on self-rebuilt vyos kernel, no problems with performance. But I have no vyos-related scripts for interaction with this module.

May 31 2016, 4:03 PM · VyOS 1.3 Equuleus (1.3.8)
UnicronNL added a comment to T74: Fix VRRP in nightly development builds.

These should be gone now.

May 31 2016, 5:58 AM · VyOS 1.1.x (1.1.8)

May 30 2016

syncer updated the task description for T75: NetFlow have impact on performance.
May 30 2016, 2:17 PM · VyOS 1.3 Equuleus (1.3.8)
syncer created T75: NetFlow have impact on performance.
May 30 2016, 2:16 PM · VyOS 1.3 Equuleus (1.3.8)
mickvav added a comment to T74: Fix VRRP in nightly development builds.

And some more, on the machine with working config:

May 30 2016, 11:52 AM · VyOS 1.1.x (1.1.8)
mickvav added a comment to T74: Fix VRRP in nightly development builds.

Ok, now works, but I've got some strange notices on "show vrrp" :

May 30 2016, 11:01 AM · VyOS 1.1.x (1.1.8)
mickvav created T74: Fix VRRP in nightly development builds.
May 30 2016, 6:30 AM · VyOS 1.1.x (1.1.8)

May 26 2016

fatihusta added a watcher for VyOS 2.0.x: fatihusta.
May 26 2016, 12:24 PM

May 21 2016

UnicronNL added a comment to T69: Kill off floppy support..

https://github.com/vyos/vyatta-cfg-system/commit/b66cc78521db17628efa3dd27766527816c170cc

May 21 2016, 4:11 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
UnicronNL closed T69: Kill off floppy support. as Resolved.
May 21 2016, 4:09 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
UnicronNL added a comment to T69: Kill off floppy support..

Makes code simpler and easier to read. Makes kernel a bit smaller (leave out floppy module)
Makes booting a little bit faster.

May 21 2016, 2:47 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
mickvav added a comment to T69: Kill off floppy support..

Why should we remove support for obsolete features, which do not break anything?

May 21 2016, 2:35 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
UnicronNL created T69: Kill off floppy support..
May 21 2016, 1:36 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

May 18 2016

adestis created T68: VyOS SDN support (openconfig, netconf, telemetry).
May 18 2016, 6:29 PM · Rejected

May 14 2016

syncer triaged T47: Some pull requests - please, route them. as Normal priority.
May 14 2016, 10:06 PM · VyOS 2.0.x