Page MenuHomeVyOS Platform
Feed Advanced Search

Apr 20 2018

Line2 added a comment to T606: Error in DNS Forwarder listen-on.

I have updated to V1.2.0-rolling+201804200337. After that the configuration node 'service dns forwarding' has disappeared from the config tree.
I reconfigured this and the 'listen on'-part is ok now. Thanks for fixing this one Christian.

Apr 20 2018, 5:34 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Apr 19 2018

Line2 added a comment to T606: Error in DNS Forwarder listen-on.

I just tried. The config tree looks like before:

Apr 19 2018, 3:26 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
Line2 created T606: Error in DNS Forwarder listen-on.
Apr 19 2018, 6:51 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Apr 3 2018

Line2 closed T477: Strongswan issue #1220 (packet loss on AWS) as Resolved.

This Tasks seems to be resolved since kernel 4.14, as the xen netfront bug in kernel is fixed in this version (https://patchwork.kernel.org/patch/9338979/).
I tested with latest nightly on AWS. No packetloss anymore with AES!

Apr 3 2018, 7:49 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA)

Feb 8 2018

Line2 added a comment to T475: IPSec set log-mode broken.

I also tried without edit mode like this with same result:

Feb 8 2018, 9:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
Line2 added a comment to T475: IPSec set log-mode broken.

I just tested on VyOS 999.201802080337 with same result:

Feb 8 2018, 8:21 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Nov 27 2017

Line2 added a comment to T475: IPSec set log-mode broken.
vyos@vyos-test# ls -al /run
total 56
drwxr-xr-x 25 root     root       900 Nov 27 21:29 .
drwxr-xr-x  1 root     root      4096 Nov 24 20:22 ..
drwxr-xr-x  2 root     root        40 Nov 24 20:23 agentx
-rw-r--r--  1 root     root         5 Nov 24 20:22 atd.pid
drwxr-xr-x  2 root     root        80 Nov 24 20:22 blkid
srwxrwx---  1 root     root         0 Nov 27 21:29 charon.ctl
-rw-r--r--  1 root     root         6 Nov 27 21:29 charon.pid
srwxrwx---  1 root     root         0 Nov 27 21:29 charon.vici
-rw-r--r--  1 root     root         5 Nov 24 20:22 crond.pid
Nov 27 2017, 9:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
Line2 added a comment to T475: IPSec set log-mode broken.

that's exactly how i tested before. All other vpn config was done before and is running fine (commit and saved). As soon as i change (set or delete) something at 'vpn ipsec logging log-level' oder vpn ipsec logging log-modes' I get this message:

Nov 27 2017, 8:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
Line2 added a comment to T475: IPSec set log-mode broken.

yes that's the version I tested on

Nov 27 2017, 7:25 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
Line2 added a comment to T475: IPSec set log-mode broken.

thanks @c-po.
I don't know what other information could be relevant. It's an instance on AWS. Nothing special before. The log-modes are set after the error messages. I can say that. Look at this here:

Nov 27 2017, 7:00 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Nov 26 2017

Line2 created T477: Strongswan issue #1220 (packet loss on AWS).
Nov 26 2017, 7:44 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
Line2 created T475: IPSec set log-mode broken.
Nov 26 2017, 11:13 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Nov 19 2017

Line2 added a comment to T440: VTI/IPSec with dynamic peer.

Thanks Brandon for your findings. IPSec with dynamic peer is no problem in VyOS. We use some of that with x.509 auth. Only VTI with dynamic peer is not allowed by VyOS. Do you know more about VTI and dynamic peer with strongswan on other linux installations (not VyOS)? Is it possible there?

Nov 19 2017, 3:39 PM · VyOS 1.3 Equuleus (1.3.6)

Oct 30 2017

Line2 added a comment to T440: VTI/IPSec with dynamic peer.

VyOS doesn't allow this configuration variant. You get an appropriate message if you try. In EdgeOS it's the same. I don't know if it's possible in Strongswan V5.3.5.

Oct 30 2017, 4:17 PM · VyOS 1.3 Equuleus (1.3.6)
Line2 created T440: VTI/IPSec with dynamic peer.
Oct 30 2017, 2:54 PM · VyOS 1.3 Equuleus (1.3.6)

Sep 4 2017

Line2 added a comment to T383: snmpd messages in log with nightly "vyos-999.201709032137-amd64.iso".

no problem:

Sep 4 2017, 11:45 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9)
Line2 created T383: snmpd messages in log with nightly "vyos-999.201709032137-amd64.iso".
Sep 4 2017, 11:26 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9)

Jul 28 2017

Line2 added a comment to T346: Fix various 'show vpn' commands that no longer function correctly .

Hi Jules

Jul 28 2017, 1:20 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
Line2 added a comment to T346: Fix various 'show vpn' commands that no longer function correctly .

is your fix already in 'vyos-999.201707272138-amd64.iso'? I get in this version:

Jul 28 2017, 9:39 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jul 27 2017

Line2 added a comment to Q107: Suggestion for adding functionality global group.

I can support this idea. It's quite usual on other routers or firewalls to have global objects, you define once and use it in firewall, nat, policy routing...

Jul 27 2017, 8:00 PM · VyOS 1.2 Crux

Jun 26 2017

Line2 added a watcher for AWS Support: Line2.
Jun 26 2017, 8:36 AM
Line2 added a watcher for VyOS 1.2 Crux: Line2.
Jun 26 2017, 8:33 AM