Page MenuHomeVyOS Platform
Feed Advanced Search

Aug 24 2020

ronie added a comment to T2772: BGP Route Distinguisher & Route Target Extended Community.

@ronie can you build an example with frr?

Aug 24 2020, 5:47 PM · VyOS 1.3 Equuleus

Aug 20 2020

ronie added a comment to T320: ospf does not redistribute connected routes associated with virtuan tunnel interfaces.

In this lab I used VyOS 1.3-rolling-202008170118. The connected routes redistributed in OSPF at HUB are being properly exchanged to WAN router, including the route to the virtual tunnel interface vti50.

Aug 20 2020, 5:24 AM · VyOS 1.3 Equuleus

Aug 19 2020

ronie renamed T2807: IPv6 Link-Local Address - Automatically generation/configuration on GRE Interfaces from IPv6 Link-Local Address - Automatically generation/configuration on Interfaces to IPv6 Link-Local Address - Automatically generation/configuration on GRE Interfaces.
Aug 19 2020, 2:55 PM · VyOS 1.3 Equuleus
ronie added a comment to T2802: Tunnel interface does not apply EUI-64 IPv6 Address.

In VyOS 1.3-rolling-202008170118 the interfaces do not generate/get the configured IPv6-EUI Address, as in the image:

Aug 19 2020, 2:36 PM · VyOS 1.3 Equuleus
ronie added a comment to T2807: IPv6 Link-Local Address - Automatically generation/configuration on GRE Interfaces.

In version VyOS 1.3-rolling-202008170118 physical interfaces have an automatic generated IPv6 Link-Local Address set, though Tunnel interfaces does not have it and it is necessary to set manually an IPv6 Link-Local Address ramdomly created. Tunnel interfaces also do not present a Layer-2 address from which a Link-Local IPv6 could be derived.

Aug 19 2020, 2:32 PM · VyOS 1.3 Equuleus
ronie added a comment to T2807: IPv6 Link-Local Address - Automatically generation/configuration on GRE Interfaces.

https://forum.vyos.io/t/ospfv3-not-working-over-gre-tunnel/5805/8

Aug 19 2020, 1:54 PM · VyOS 1.3 Equuleus

Aug 17 2020

ronie updated the task description for T2802: Tunnel interface does not apply EUI-64 IPv6 Address.
Aug 17 2020, 5:37 PM · VyOS 1.3 Equuleus
ronie updated the task description for T2807: IPv6 Link-Local Address - Automatically generation/configuration on GRE Interfaces.
Aug 17 2020, 5:32 PM · VyOS 1.3 Equuleus
ronie added a comment to T2802: Tunnel interface does not apply EUI-64 IPv6 Address.

Tunnel Interfaces also do not generate/configure a Link-Local IPv6. It looks like Tunnel interfaces do not have any MAC Address associated to it.

Aug 17 2020, 2:40 PM · VyOS 1.3 Equuleus
ronie changed Is it a breaking change? from none to behavior on T2807: IPv6 Link-Local Address - Automatically generation/configuration on GRE Interfaces.
Aug 17 2020, 2:01 PM · VyOS 1.3 Equuleus
ronie created T2807: IPv6 Link-Local Address - Automatically generation/configuration on GRE Interfaces.
Aug 17 2020, 2:00 PM · VyOS 1.3 Equuleus
ronie added a comment to T486: Static IPv6 default route via OSPFv3-learned loopback is not activated.

It seems that making the tunnel connection a Stub Area would reach the same design goal without relying on a recursive static route, but it also seems that this feature is not supported in OSPFv3 by now. I´ve opened the following feature requests: https://phabricator.vyos.net/T2804 & https://phabricator.vyos.net/T2803 .

Aug 17 2020, 8:37 AM · VyOS 1.3 Equuleus
ronie created T2804: OSPFv3 Stub / NSSA [no summary].
Aug 17 2020, 8:28 AM · VyOS 1.3 Equuleus
ronie added a comment to T486: Static IPv6 default route via OSPFv3-learned loopback is not activated.

I´ve tyred to reproduce this scenario with VyOS 1.3-rolling-202007300117.
The static-default-route is correctly installed in the routing table after rebooting the router.

Aug 17 2020, 4:16 AM · VyOS 1.3 Equuleus
ronie updated subscribers of T2803: OSPFv3 - Default-Information Originate [always].
Aug 17 2020, 12:05 AM · VyOS 1.3 Equuleus
ronie created T2803: OSPFv3 - Default-Information Originate [always].
Aug 17 2020, 12:02 AM · VyOS 1.3 Equuleus

Aug 16 2020

ronie added a comment to T486: Static IPv6 default route via OSPFv3-learned loopback is not activated.
Aug 16 2020, 11:42 PM · VyOS 1.3 Equuleus
ronie created T2802: Tunnel interface does not apply EUI-64 IPv6 Address.
Aug 16 2020, 6:40 PM · VyOS 1.3 Equuleus

Aug 11 2020

ronie added a comment to T2786: OSPF Interface Cost.

@ronie For OSPF bandwidth use command:

vyos@r4-roll# set interfaces ethernet eth0 ip ospf bandwidth 
Possible completions:
   <1-100000>   Bandwidth in megabits/sec (for calculating OSPF cost)

@Viacheslav I supposed that by default Ethernet Interfaces/10Mbits should be assigned a cost of 10 without changing any parameter. So it is not a bug? Should I cancel this request?

Not speed interface.

Aug 11 2020, 8:20 PM · VyOS 1.3 Equuleus
ronie created T2787: OSPF auto-cost reference-bandwidth bandwidth command support.
Aug 11 2020, 1:45 PM · VyOS 1.3 Equuleus
ronie created T2786: OSPF Interface Cost.
Aug 11 2020, 1:36 PM · VyOS 1.3 Equuleus

Aug 10 2020

ronie added a comment to T2227: MPLS documentation.

In general, Service Providers implement IS-IS, not OSPF, as IGP in the Core. Maybe it is a good idea to develop VYOS support to IS-IS in order to make it more attractive as an immediate solution as P router to SPs.


In this lab OSPF is being used as IGP. Cisco routers are being implemented as PE/LSRs, because VYOS are not able to perform this role yet.
Everything is working from the Control Plane standpoint (VPNv4 addresses are exchanged and redistributed into OSPF).
OSPF reconverges in a strange way, as if the metric/cost were different (lower) over VYOS routers. After reviewing the configurations and activating MPLS LDP correctly between Cisco and VYOS routers, connectivity issues are solved.

Aug 10 2020, 8:52 PM · VyOS 1.3 Equuleus
ronie added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

It seems a parser issue. We are reviewing the script https://github.com/vyos/vyatta-op-vpn/blob/current/scripts/vyatta-op-vpn.pl

Aug 10 2020, 4:14 PM · VyOS 1.3 Equuleus
ronie added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

When the configuration provided is reproduced, the problem occurs: show ike sa is "down" while show ipsec sa is "up".

Aug 10 2020, 3:45 PM · VyOS 1.3 Equuleus

Aug 7 2020

ronie created T2773: EIGRP support for VRF.
Aug 7 2020, 8:03 PM · VyOS 1.3 Equuleus
ronie added a comment to T2772: BGP Route Distinguisher & Route Target Extended Community.

Route Distinguisher & Route Targets are, in general, configured under VRF proccess. Below a sample of how this configurations would looks like:

Aug 7 2020, 7:57 PM · VyOS 1.3 Equuleus
ronie updated subscribers of T2772: BGP Route Distinguisher & Route Target Extended Community.
Aug 7 2020, 7:55 PM · VyOS 1.3 Equuleus
ronie created T2772: BGP Route Distinguisher & Route Target Extended Community.
Aug 7 2020, 7:53 PM · VyOS 1.3 Equuleus
ronie added a comment to T2771: BGP VPNv4 & VPNv6 Address Family Support.

Bellow a sample of how BGP VPNv4 and VPNv6 AF configuration looks like:

Aug 7 2020, 7:46 PM · VyOS 1.3 Equuleus
ronie created T2771: BGP VPNv4 & VPNv6 Address Family Support.
Aug 7 2020, 7:38 PM · VyOS 1.3 Equuleus
ronie added a comment to T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic.

Could you please provide full configuration or at least protocol section configuration?

Aug 7 2020, 3:57 PM · VyOS 1.3 Equuleus

Aug 5 2020

ronie added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

I´ve used the version of the software: VyOS 1.3-rolling-202007300117.
As I´ve used GRE tunnels it does not simulates the same scenario reported, which uses pure IPsec. I will configure IPsec tunnels over physical interfaces and log the results here again.

Aug 5 2020, 11:35 PM · VyOS 1.3 Equuleus
ronie added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

vyos@HUB-2# sh vpn
ipsec {

esp-group MyESPGroup {
    proposal 1 {
        encryption aes256
        hash md5
    }
}
ike-group MyIKEGroup {
    proposal 1 {
        dh-group 2
        encryption aes256
        hash md5
    }
}
ipsec-interfaces {
    interface eth0.100
}
site-to-site {
    peer 169.254.100.1 {
        authentication {
            mode pre-shared-secret
            pre-shared-secret MYSECRETKEY
        }
        default-esp-group MyESPGroup
        ike-group MyIKEGroup
        local-address 169.254.100.6
        tunnel 20 {
            protocol gre
        }
    }
}

}
[edit]

Aug 5 2020, 4:59 PM · VyOS 1.3 Equuleus
ronie added a comment to T2748: "show vpn ike sa" shows state "down" when tunnel is up.

I´ve configured a simple P-2P IPsec/GRE Tunnel and the command shows IKE and IPsec SAs UP:

Aug 5 2020, 4:58 PM · VyOS 1.3 Equuleus