Feed Advanced Search

Jan 8 2017

rps added a comment to V3: Tag node syntax for VyOS 2.0.

With respect to the concerns I mentioned above, I've voted no.

Jan 8 2017, 6:46 PM · VyOS 2.0.x, VyConf
rps added a comment to V3: Tag node syntax for VyOS 2.0.

I keep coming back to a sense that dramatic syntax changes are very damaging and disruptive to users. My fear is that we'll be spending years explaining to people that they're looking at old documentation or examples and that they don't have their curly braces in the right place. Or that we'll alienate a segment of our user base that is averse to change.

Jan 8 2017, 3:08 PM · VyOS 2.0.x, VyConf

Jan 5 2017

rps added a comment to V3: Tag node syntax for VyOS 2.0.

I haven't voted yet because I haven't decided ... It's a big change.

Jan 5 2017, 2:44 PM · VyOS 2.0.x, VyConf
rps added a comment to V3: Tag node syntax for VyOS 2.0.

From a parsing perspective the only challenge tag nodes present is that you can't easily distinguish between "key value" and "key tag" without context. "key" and "key tag value" are fine. Using a ":" you get "key: value" vs "key tag" which removes the ambiguity.

Jan 5 2017, 1:45 PM · VyOS 2.0.x, VyConf
rps added a comment to V3: Tag node syntax for VyOS 2.0.

The XORP configuration syntax (which Vyatta initially built upon) solves the parsing issue with the simple introduction of a ":" as a delimiter between keys and values.

Jan 5 2017, 1:21 PM · VyOS 2.0.x, VyConf

Sep 23 2016

rps added a comment to Q56: nDPI integration, what is required?.

It looks interesting and I think QoS is a good application of nDPI. I'm a little nervous about what the performance and stability implications are. Not having looked into it much is it implemented as a module that could be disabled if needed?

Sep 23 2016, 12:03 AM · VyOS 1.1.x (1.1.8)

Sep 19 2016

rps added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@hmkias Patch Squid for what?

Sep 19 2016, 4:31 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
rps added a comment to Q50: Any hope for DPDK?.

I'll make a move here and suggest that until FOSS projects to implement DPDK support see more maturity that VyOS doesn't go down the rabbit hole of that for now; I think a side project, maybe "HP-VyOS" (for High-Performance VyOS) take on trying to build a version of VyOS that can leverage experimental code like DPDK or VPP.

Sep 19 2016, 1:57 PM · VyOS 1.2.x, VyOS 2.0.x
rps added a comment to Q52: Integrate Vyos with standalone web filtering device?.

In theory, you could have the web filter be a pair of servers using VRRP.

Sep 19 2016, 1:39 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

Sep 16 2016

rps added a comment to Q50: Any hope for DPDK?.

@mickvav I think you're misunderstanding the benefit of DPDK. It's essentially fastpath for Intel-based platforms and if implimented correctly can be the difference between 10 Gbps and 100 Gbps on the same hardware. Obviously being able to scale VyOS to that level would be game-changing. It's important, just likely not in scope for VyOS at this time ...

Sep 16 2016, 10:13 PM · VyOS 1.2.x, VyOS 2.0.x
rps added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@EwaldvanGeffen have you given the method I described a try on VyOS? I know it works on EdgeOS and pre- 6.4 releases of Vyatta and honestly haven't tested it on VyOS because it's not something I have a need for... so it very well could work differently/be broken on VyOS, but that would be surprising.

Sep 16 2016, 11:24 AM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
rps added a comment to T82: packets leak un-natted.

I've added a quick note in the SNAT section of the Wiki to explain this. Feel free to edit if it seems unclear or could be worded better.

Sep 16 2016, 11:22 AM · VyOS 1.1.x (1.1.8)
rps added a comment to Q50: Any hope for DPDK?.

@mickvav I think when people ask "does it support DPDK" it's because they've read that using DPDK will allow forwarding and possible filtering and NATing of traffic at 10 Gbps+ rates. VyOS offering some DPDK stuff and saying "mission accomplished" would leave a bad taste in people's mouths the same way CloudRouter is claiming DPDK support when it's only for bridged traffic.

Sep 16 2016, 11:03 AM · VyOS 1.2.x, VyOS 2.0.x

Sep 15 2016

rps added a comment to Q50: Any hope for DPDK?.

"DPDK support" involved a lot of low-level contributions to a lot of different projects. Essentially you need to re-implement major parts of Linux on a case-by-case basis which is outside of the scope for VyOS right now.

Sep 15 2016, 10:53 AM · VyOS 1.2.x, VyOS 2.0.x
rps added a comment to Q52: Integrate Vyos with standalone web filtering device?.

You can use policy routing to match HTTP and HTTPS traffic and point it at a next-hop that is an external transparent proxy.

Sep 15 2016, 10:34 AM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
rps added a comment to T82: packets leak un-natted.

Can we move this to "wontfix". This is the normal behavior of Linux and doing any sort of global drop of invalid state traffic by default is not a realistic change.

Sep 15 2016, 10:29 AM · VyOS 1.1.x (1.1.8)
rps added a comment to T35: Add IPv6 firewall network groups.

After VRRPv3 (with some intelligent way to handle radvd) this is the major blocker for using VyOS as a production IPv6 firewall in my environment.

Sep 15 2016, 10:25 AM · VyOS 1.2.x (VyOS 1.2.0 LTS Lithium)
rps awarded T35: Add IPv6 firewall network groups a Like token.
Sep 15 2016, 10:19 AM · VyOS 1.2.x (VyOS 1.2.0 LTS Lithium)
rps awarded T105: VRRPv3 support (VRRP for IPv6) a Like token.
Sep 15 2016, 10:16 AM · VyOS 1.2.x