Page MenuHomeVyOS Platform
Feed Advanced Search

Sep 25 2022

ajgnet updated the task description for T4710: show openvpn server occasionally returns IndexError: list index out of range.
Sep 25 2022, 6:30 PM · VyOS 1.4 Sagitta

Sep 24 2022

ajgnet created T4710: show openvpn server occasionally returns IndexError: list index out of range.
Sep 24 2022, 9:53 PM · VyOS 1.4 Sagitta

Aug 9 2022

ajgnet added a comment to T2518: Support NAT for ipv6(NPT).

@ajgnet If you have a way to limit the dynamic prefix to a known prefix, then using 1:1 NAT66 prefix translation should work (only the host segment is dynamic)

Yes, would be great to fully support dynamic prefix when the prefix is not known

Aug 9 2022, 1:30 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0)

Apr 24 2022

ajgnet triaged T4392: Multiline login banner text reports error on commit as Low priority.
Apr 24 2022, 11:11 AM · VyOS 1.4 Sagitta

Apr 23 2022

ajgnet added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

Confirmed working.

Apr 23 2022, 8:50 PM · VyOS 1.3 Equuleus (1.3.0)
ajgnet added a comment to T4386: Applying limiter on traffic-policy "in" fails, incorrectly reports mirror or redirect policy in use.

Confirmed working. Awesome

Apr 23 2022, 5:03 PM · VyOS 1.4 Sagitta

Apr 22 2022

ajgnet changed Issue type from internal to feature on T4387: Create additional smoketests for multiwan PBR & load-balanced configurations .
Apr 22 2022, 12:19 AM · VyOS 1.4 Sagitta
ajgnet triaged T4387: Create additional smoketests for multiwan PBR & load-balanced configurations as Normal priority.
Apr 22 2022, 12:19 AM · VyOS 1.4 Sagitta
ajgnet triaged T4386: Applying limiter on traffic-policy "in" fails, incorrectly reports mirror or redirect policy in use as Normal priority.
Apr 22 2022, 12:04 AM · VyOS 1.4 Sagitta
ajgnet created T4386: Applying limiter on traffic-policy "in" fails, incorrectly reports mirror or redirect policy in use.
Apr 22 2022, 12:04 AM · VyOS 1.4 Sagitta

Apr 21 2022

ajgnet updated the task description for T4383: Flow Accounting returns permission error and fails to start.
Apr 21 2022, 12:46 AM · VyOS 1.4 Sagitta
ajgnet created T4383: Flow Accounting returns permission error and fails to start.
Apr 21 2022, 12:32 AM · VyOS 1.4 Sagitta

Apr 20 2022

ajgnet added a comment to T4362: Wan Load Balancing - Can't create routing tables.

Confirming the same.

Apr 20 2022, 12:54 PM · VyOS 1.4 Sagitta

Apr 19 2022

ajgnet updated the task description for T4378: Unable to submit wildcard ("*.example.com") A or AAAA records in dns forwarder.
Apr 19 2022, 5:01 PM · VyOS 1.4 Sagitta
ajgnet created T4378: Unable to submit wildcard ("*.example.com") A or AAAA records in dns forwarder.
Apr 19 2022, 4:59 PM · VyOS 1.4 Sagitta
ajgnet added a comment to T4376: DNAT with multiwan and policy routing, incoming connections only work on primary interface.

Tested, does not work. Even with all firewall rules removed.

Apr 19 2022, 2:14 PM · VyOS 1.4 Sagitta
ajgnet added a comment to T4375: hairpin nat (nat reflector) "hijacks" all outgoing traffic on specified port to any destination.

Is there a way to get this to work with a dhcp assigned WAN address?

Apr 19 2022, 2:05 PM · VyOS 1.4 Sagitta
ajgnet created T4376: DNAT with multiwan and policy routing, incoming connections only work on primary interface.
Apr 19 2022, 11:27 AM · VyOS 1.4 Sagitta
ajgnet created T4375: hairpin nat (nat reflector) "hijacks" all outgoing traffic on specified port to any destination.
Apr 19 2022, 9:53 AM · VyOS 1.4 Sagitta
ajgnet updated the task description for T4374: ipv6 address drops from interface, but network still active.
Apr 19 2022, 9:45 AM · VyOS 1.4 Sagitta
ajgnet created T4374: ipv6 address drops from interface, but network still active.
Apr 19 2022, 9:21 AM · VyOS 1.4 Sagitta

Apr 7 2022

ajgnet added a comment to T2943: Wireguard allow use of hostname as endpoint.

Trying to configure a wireguard peer with a dns name as remote endpoint. I understand this is not supported, but I see many references to creating a post-boot script to do this. Any working examples? Thank you

Apr 7 2022, 10:21 PM · VyOS 1.2 Crux

Apr 6 2022

ajgnet added a comment to T2518: Support NAT for ipv6(NPT).

Is there a way to get this to work with a dynamically assigned /64 PD from my ISP?

Apr 6 2022, 9:42 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0)

Aug 18 2020

ajgnet added a comment to T2760: In a load-balanced multi-wan configuration with DHCP assigned addresses, IPsec "dhcp-interface" does not work.

Enabling sticky connections had no effect in my testing. The only temporary solution was T2747. Unfortunately, this solution no longer works once the IP address changes on a DHCP-assigned interface.

Aug 18 2020, 12:42 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.3 Equuleus (1.3.7)

Aug 10 2020

ajgnet added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

Additionally, sometimes the Peer ID and Local ID are not correctly formatted. for example:

Aug 10 2020, 4:21 PM · VyOS 1.3 Equuleus (1.3.0)
ajgnet created T2776: QAT acceleration not working for IPSec AES-128 (CBC) / SHA256 tunnel .
Aug 10 2020, 1:55 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Aug 9 2020

ajgnet created T2775: QAT acceleration for OpenVPN.
Aug 9 2020, 4:21 PM · VyOS 1.5 Circinus

Aug 7 2020

ajgnet added a comment to T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic.

Sure thing. Note my configuration contains some table maps that I have set up to route VPN traffic, and certain source IPs through specific interfaces. But there is no effect on the load-balancer when these sections are removed. Thank you.

Aug 7 2020, 4:08 PM · VyOS 1.5 Circinus

Aug 5 2020

ajgnet added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

I suspect this could be related to displaying a peer with a hostname that contains a dash, such as, "abc-peer12.dyndns.org." Or, possibly a string matching error getting thrown off by "AES_GCM_16_128/MODP_2048"

Aug 5 2020, 5:38 PM · VyOS 1.3 Equuleus (1.3.0)
ajgnet added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

The IKE SA appears down in your second example?

Aug 5 2020, 5:02 PM · VyOS 1.3 Equuleus (1.3.0)

Aug 4 2020

ajgnet created T2760: In a load-balanced multi-wan configuration with DHCP assigned addresses, IPsec "dhcp-interface" does not work.
Aug 4 2020, 10:14 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.3 Equuleus (1.3.7)

Jul 31 2020

ajgnet created T2748: "show vpn ike sa" shows state "down" when tunnel is up.
Jul 31 2020, 1:55 AM · VyOS 1.3 Equuleus (1.3.0)

Jul 30 2020

ajgnet updated the task description for T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic.
Jul 30 2020, 11:54 PM · VyOS 1.5 Circinus
ajgnet created T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic.
Jul 30 2020, 11:52 PM · VyOS 1.5 Circinus