Page MenuHomeVyOS Platform
Feed Advanced Search

Dec 11 2018

aopdal added a comment to T1095: Connection tracking NAT / FIREWALL.

The workaround using /config/scripts/vyatta-postconfig-bootup.script works nice. It is probably more user friendly if it is configurable in cli.

Dec 11 2018, 8:06 PM
aopdal added a comment to T1095: Connection tracking NAT / FIREWALL.
set firewall name IN-ETH0 rule 70 helper ftp

Is a good approach i think. When all are going to use encrypted ftp the helper can't be used, but for now I have some customers who don't want to find their passive ports. So I must get the helper going ...

Dec 11 2018, 5:16 PM
aopdal added a comment to T1095: Connection tracking NAT / FIREWALL.
Dec 11 16:22:02 nat-router kernel: [IN-ETH0-9999-D] IN=eth0 OUT=eth1 MAC=00:0c:29:32:f0:3b:80:2a:a8:8d:dc:64:08:00 SRC=188.94.220.38 DST=172.16.1.10 LEN=52 TOS=0x00 PREC=0x00 TTL=121 ID=26075 DF PROTO=TCP SPT=22154 DPT=30010 WINDOW=65535 RES=0x00 SYN URGP=0
Dec 11 16:22:05 nat-router kernel: [IN-ETH0-9999-D] IN=eth0 OUT=eth1 MAC=00:0c:29:32:f0:3b:80:2a:a8:8d:dc:64:08:00 SRC=188.94.220.38 DST=172.16.1.10 LEN=52 TOS=0x00 PREC=0x00 TTL=121 ID=26106 DF PROTO=TCP SPT=22154 DPT=30010 WINDOW=65535 RES=0x00 SYN URGP=0
Dec 11 2018, 3:30 PM
aopdal created T1095: Connection tracking NAT / FIREWALL.
Dec 11 2018, 1:28 PM

Nov 23 2018

aopdal created T1035: SNMP BGP 32 bit AS number fail.
Nov 23 2018, 12:31 PM · VyOS 1.3 Equuleus (1.3.7)

Oct 10 2018

aopdal added a comment to T882: 1.2-rc1 frr table default route bug.

Working with only static and OSPF + static route.

Oct 10 2018, 7:08 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
aopdal added a comment to T882: 1.2-rc1 frr table default route bug.

Looks like this is working now on my two routers using this feature - good work!

Oct 10 2018, 7:05 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Oct 9 2018

aopdal added a comment to T882: 1.2-rc1 frr table default route bug.

This bug is in effect also without using dynamic routing.

Oct 9 2018, 11:51 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Oct 2 2018

aopdal created T869: rsyslog configuration typo.
Oct 2 2018, 7:36 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Sep 26 2018

aopdal created T863: Increase igmp_max_memberships in the S1 VyOS Public space.
Sep 26 2018, 7:13 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc4)

Sep 25 2018

aopdal added a comment to Q116: Howto perform IGMP memebership management? (Answer 167).

I have upgraded this router to :

Sep 25 2018, 8:07 AM
aopdal added a comment to T840: VRRP V3 backup router sending ND RA.

@rps I think this is a bug, because this behavior is not by design - it just to happen ;-) . You may call i a design bug.

Sep 25 2018, 6:56 AM · VyOS 1.3 Equuleus (1.3.7), test

Sep 20 2018

aopdal added a comment to T856: upgrade from 1.1.8 to 1.2.0-rolling breaks OSPF area-type NSSA.

If you need config samples for testing I'm happy to provide it. Or tell me when to retest.

Sep 20 2018, 1:02 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
aopdal created T856: upgrade from 1.1.8 to 1.2.0-rolling breaks OSPF area-type NSSA.
Sep 20 2018, 12:27 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Sep 11 2018

aopdal created T840: VRRP V3 backup router sending ND RA.
Sep 11 2018, 9:01 AM · VyOS 1.3 Equuleus (1.3.7), test

May 30 2018

aopdal added a comment to T666: Define new VRRP syntax.

For the VRRP group running IPv6 you need 'vrrp_version 3' at least in the keepalived config.

May 30 2018, 7:54 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

May 14 2018

aopdal added a comment to T616: Migrate to keepalived 2.x (including IPv6 VRRP).

I think option 2 is the best, but keep in mind the VRRP version is 3, and it support both IPv4 and IPv6.

May 14 2018, 8:04 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Mar 12 2018

aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

@rps RA and VRRPv3 is quite a complex "thing". And it's easy to make something which don't work. If you have more than one VRRP group running on a network segment, only one of the groups should do RA. The most difficult case to solve may be if you run two routers with two groups on the same interface to do some kind of load balancing and also want to do RA. This may require configuration of RA on the VRRP group. But if you don't run VRRP you must configure RA directly on the interface.

Mar 12 2018, 9:29 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Mar 8 2018

aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

The showstopper for me to upgrade to 1.2 with current aproach is the configuration statement (in keepalived configuration)

Mar 8 2018, 10:28 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Feb 27 2018

aopdal removed a member for Active contributors: aopdal.
Feb 27 2018, 3:05 PM

Jan 16 2018

aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

With prefix delegation you have a static prefix on your inside, but the "wan" interface on the router is using DHCP.

Jan 16 2018, 2:14 PM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

Without routing you probably can't get it to work. Are your addresses managed from Comcast using prefix delegation?

Jan 16 2018, 1:36 PM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

@beamerblvd have you added routes for your vif 100,200 and 900 in your "COMCAST BUSINESS IP GATEWAY"?

Jan 16 2018, 1:23 PM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

Perhaps you could make a drawing of what you try to get working? With proper interface naming etc. eth0 - wan, eth1 - dmz, eth2 - lan or whatever you are using. It makes it easier to understand what you try to do. And for the interfaces why do you want to use the /60?

Jan 16 2018, 7:43 AM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

Maybe this is relevant? https://phabricator.vyos.net/T421

Jan 16 2018, 7:17 AM · VyOS 1.1.x

Dec 22 2017

aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

@syncer
Use the configurations I provided and observe the packets the router is sending out.
In the nightly build the router is sending out using the IPv6 group address
Up to 1.1.8 the router is sending out using the IPv4 group address
This makes upgrades impossible
Using VRRPv2 with both IPv4 and IPv6 virtual addresses in the same VRRP instance is only possible due to a bug in the 1.2.19 keepalived

Dec 22 2017, 12:33 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

On two debian 8 test VM I compiled keepalived 1.3.9 without any errors. It may be a good thing to get this latest version for our new implementation.

Dec 22 2017, 11:28 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

The current implementation is working on keepalived 1.2.19 (from 2015.07.07). In 1.2.20 (from 2016-04-02) a lot of bugs are fixed and the possibility to use IPv6 in VRRPv2 is gone.
When implementing IPv6 / VRRPv3 we should probably base the implementation on a newer version of keepalived.

Dec 22 2017, 9:23 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

Testing on

Dec 22 2017, 8:07 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Dec 18 2017

aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

Does anyone have any ideas how to get VRRPv3 in 1.2?
If we could conclude on the approach we could go further by describing cli commands, make out how the upgrade should be done, create documentation and so on.

Dec 18 2017, 9:55 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Dec 11 2017

aopdal added a comment to Q116: Howto perform IGMP memebership management? (Answer 167).

But should it be configurable using cli?
Should there be a warning when adding a interface and no buffer is available?
Should there be some smartness created for avoiding the "no buffer" event?

Dec 11 2017, 1:36 PM
aopdal added a comment to Q116: Howto perform IGMP memebership management?.

Anyone having any ideas to how to solve this problem?

Dec 11 2017, 11:13 AM · VyOS 1.2 Crux, VyOS 1.1.x

Dec 1 2017

aopdal added a comment to T306: Migration from vyatta-quagga to FRR.

We are hit by bugs in the OSPF of Quagga which are not fixed in newer versions, but are fixed in FRR. Most of my stuff is working. Getting up to date on Quagga is probably also quite some job, and from the testing perspective it's just the same. Everything must be tested... From the design and documentation perspective we need to put down some more work if we are using FRR.

Dec 1 2017, 8:54 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), vyos-frr
aopdal added a comment to T306: Migration from vyatta-quagga to FRR.

@dmbaturin is there a (estimated/proposed) releasedate on 1.2.0?

Dec 1 2017, 7:56 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), vyos-frr

Nov 30 2017

aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

Using two debian VM i have played around with this today.
I have been using debian 9.2 and keepalived v1.3.2

Nov 30 2017, 2:40 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
aopdal added a comment to T459: VRRP not working..

@mdsmds If you have a mixed environment running with VRRP, just comment out the offending line in the 32Bit router and you are good.

Nov 30 2017, 12:15 PM · Rejected
aopdal added a comment to T459: VRRP not working..

It looks like this https://github.com/vyos/vyatta-vrrp/commit/dfbc742a6454388aa6a2523541a170c01fc42533#diff-7a3c3afc4665f422017c25f832c9c28b

Nov 30 2017, 9:01 AM · Rejected

Nov 29 2017

aopdal added a comment to T459: VRRP not working..

/opt/vyatta/sbin/vyatta-keepalived.pl in the 32-bit build writes the native_ipv6 line to the configuration.

Nov 29 2017, 1:03 PM · Rejected
aopdal added a comment to T459: VRRP not working..

For some reason the 32 bit build add native_ipv6 to the configuration in /etc/keepalived/keepalived.conf

Nov 29 2017, 11:51 AM · Rejected
aopdal added a comment to T306: Migration from vyatta-quagga to FRR.

Are we going for FRR in 1.2, or are we going to keep Quagga?
I'm just wondering what I should test ;-)

Nov 29 2017, 9:20 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), vyos-frr

Nov 28 2017

aopdal added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

But if you run:

Nov 28 2017, 5:30 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Nov 27 2017

aopdal added a comment to T459: VRRP not working..

Using hello-source-address does not help either...

Nov 27 2017, 3:52 PM · Rejected
aopdal added a comment to T459: VRRP not working..

The 32 bit build is using IPv6 VRRP address and 64 bit build is using IPv4 VRRP address

Nov 27 2017, 3:42 PM · Rejected
aopdal added a comment to V5: Should we keep web proxy functionality in base 1.2/1.3/2.0?.

With limited people in the project I think the "core" features for a router should be of priority. A lot of things is nice to have, but we need to have a good router.
IPv6 with VRRP, connection tracking, updated routing engine, IPv6 PD is stuff we need and requires a lot of design, implementation, testing and documentation.

Nov 27 2017, 1:38 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
aopdal added a comment to Q116: Howto perform IGMP memebership management?.

This is a drawing of my current lab environment.

Nov 27 2017, 1:20 PM · VyOS 1.2 Crux, VyOS 1.1.x
aopdal asked Q116: Howto perform IGMP memebership management?.
Nov 27 2017, 1:18 PM · VyOS 1.2 Crux, VyOS 1.1.x

Nov 7 2017

aopdal added a comment to T306: Migration from vyatta-quagga to FRR.

I have upgraded my "parallel" universe. It look like redistribute static does not work.

Nov 7 2017, 2:29 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), vyos-frr

Oct 27 2017

aopdal added a comment to T14: Provide VMware OVF and OVA.

Optimize a routers defaults should be targeted to the usecase of a router and not for some special use.
If you want to use a vyos as a VPN concentrator - well then configure if for this case. If the defaults are not optimized for general purpose, then you must tweak it for the "main usecase" as a router.

Oct 27 2017, 6:41 AM · VyOS 1.2 Crux (VyOS 1.2.1)

Oct 26 2017

aopdal added a comment to T14: Provide VMware OVF and OVA.

I'm upgrading my vmware cluster with vyos routers and are doing some tests. My production environment is running on 1.1.7.

Oct 26 2017, 1:50 PM · VyOS 1.2 Crux (VyOS 1.2.1)

Aug 3 2017

aopdal added a comment to T342: PPTP and VRRP combination issue.

I'm using pptp and also IPSEC VPN in combination with VRRP. It works for me, but you must restart the service when a router becomes VRRP master. And you need to create a VRRP sync-group so all interfaces are master on one router. I'm using preempt false to avoid the service to be moved (and restarted) more than necessary.

Aug 3 2017, 10:42 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

May 26 2017

aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

Is there any progress on this? Is there any design documents in progress?

May 26 2017, 10:09 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Dec 20 2016

aopdal added a comment to T161: VyOS 1.2 (jessie) testing spreadsheet.

I could participate in a meeting next week, this week is "getting ready for Christmas" week ;-)

Dec 20 2016, 2:17 PM · Invalid
aopdal added a comment to T161: VyOS 1.2 (jessie) testing spreadsheet.

I like to participate in the testing. But I think we need to break down the point in a bit more specific tests. We should also have requirements which state what is pass / fail. And we should probably create specific test descriptions ant test cases which could be automated.

Dec 20 2016, 1:52 PM · Invalid

Aug 11 2016

aopdal added a comment to T74: Fix VRRP in nightly development builds.

vyos@r1-80001# run sh ver

Aug 11 2016, 10:45 AM · VyOS 1.1.x (1.1.8)

Apr 27 2016

aopdal added a comment to T49: Kernel NFS server support.

Why would anybody want to use a router as a "small server"? General Linux distributions have everything you need for a small server.

Apr 27 2016, 6:33 AM · Rejected