Page MenuHomeVyOS Platform
Feed Advanced Search

Mar 29 2023

klipz added a comment to T5055: Firewall - Add packet type matcher (pkttype).

@n.fort In that case then this functionality does seem to be working as designed, even if the pkttype matcher isn't behaving exactly as I expected it to for "host".

Mar 29 2023, 12:59 AM · VyOS 1.4 Sagitta
klipz changed Version from - to 1.4 on T5119: "fib" statement support for firewall and nat configuration.
Mar 29 2023, 12:37 AM · VyOS 1.5 Circinus
klipz created T5119: "fib" statement support for firewall and nat configuration.
Mar 29 2023, 12:36 AM · VyOS 1.5 Circinus

Mar 19 2023

klipz added a comment to T5055: Firewall - Add packet type matcher (pkttype).

@n.fort
My judgement may have been too hasty. The commands are accepted by VyOS configure, but it looks like the meta pkttype host is being ignored by my new nftables rules. That is, all IP addresses are matching, not just actual VyOS host router IP addresses.

Mar 19 2023, 7:06 PM · VyOS 1.4 Sagitta

Mar 15 2023

klipz added a comment to T5055: Firewall - Add packet type matcher (pkttype).

@n.fort I was too impatient to wait for a rolling build so I ran my own build of current post-merge.

Mar 15 2023, 3:33 AM · VyOS 1.4 Sagitta

Mar 14 2023

klipz added a comment to T5055: Firewall - Add packet type matcher (pkttype).

@n.fort A quick test of this against latest rolling looks like it's working as expected for general firewall rules:

Mar 14 2023, 1:35 AM · VyOS 1.4 Sagitta

Mar 9 2023

klipz updated subscribers of T5055: Firewall - Add packet type matcher (pkttype).

@n.fort @Viacheslav
Here is an example of what I am after for DNAT rule, specifically, using meta pkttype:

Mar 9 2023, 7:31 PM · VyOS 1.4 Sagitta

Mar 6 2023

klipz added a comment to T5055: Firewall - Add packet type matcher (pkttype).

@n.fort I apologize for the late entry here - could this also be exposed for NAT rules?
Edit: wow you guys worked so fast on this it got pulled before I could add this request :D

Mar 6 2023, 7:17 PM · VyOS 1.4 Sagitta

Feb 17 2022

klipz added a comment to T4240: Cannot add wlan0 to bridge via configure.

@c-po Thank you for the work on this.

Feb 17 2022, 1:20 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)

Jan 17 2022

klipz added a comment to T4139: Wireless interface member of a bridge.

I experience the same problem of VyOS failing to add wlan0 to bridge, which persists in all 1.3-epa and 1.3-LTS versions, as well as 1.4 nightly builds.

Jan 17 2022, 5:19 PM · VyOS 1.3 Equuleus (1.3.6)

Oct 30 2021

klipz added a comment to T3654: 1.2.7 - OpenVPN tunnel interface disappears on virtualized VyOS router/ESXi host.

@Viacheslav Yes, I have updated the system to 1.2.8-LTS. I will let you know if the disappearing openvpn tun interface reoccurs.

Oct 30 2021, 4:20 PM · VyOS 1.2 Crux (VyOS 1.2.9)

Aug 1 2021

klipz added a comment to T2326: Migrate NHRP(DMVPN) to FRR.

I agree it would be nice to have the Cisco Auth functionality, however, the original author of opennhrp themselves recommend using FRR nhrpd instead where possible. It appears that most effort going forward will be put into FRR's nhrpd, and not the original opennhrp.

Aug 1 2021, 2:09 AM · VyOS 1.5 Circinus

Jul 31 2021

klipz added a comment to T2326: Migrate NHRP(DMVPN) to FRR.

@c-po @Viacheslav
Further news on this topic - FRR 8.0 released yesterday (7/29) which includes the aforementioned nhrpd multicast improvements, among a lot of other nice things:

Jul 31 2021, 2:49 AM · VyOS 1.5 Circinus

Jun 27 2021

klipz created T3654: 1.2.7 - OpenVPN tunnel interface disappears on virtualized VyOS router/ESXi host.
Jun 27 2021, 8:26 PM · VyOS 1.2 Crux (VyOS 1.2.9)

Apr 15 2021

klipz added a comment to T2326: Migrate NHRP(DMVPN) to FRR.

@c-po There is some recent news on FRR's NHRPD and multicast support it seems, please see here:

Apr 15 2021, 1:53 AM · VyOS 1.5 Circinus

Apr 3 2021

klipz added a comment to T1311: WAN load-balancing can't flush connections when conntrack-sync is enabled.

@syncer
Sorry to dredge up an old bug, but I believe I've hit this today on 1.2.7-LTS myself. Per @zsdc's original description, It seems that when you configure:

Apr 3 2021, 7:58 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.3 Equuleus (1.3.7), test

Apr 16 2019

alexandrestein awarded T738: Add local-port and resolver port options for powerdns in CLI configuration tree a Like token.
Apr 16 2019, 9:35 AM · VyOS 1.3 Equuleus (1.3.4)

Jul 10 2018

klipz created T738: Add local-port and resolver port options for powerdns in CLI configuration tree.
Jul 10 2018, 1:09 AM · VyOS 1.3 Equuleus (1.3.4)