Page MenuHomeVyOS Platform
Feed Advanced Search

Nov 13 2023

n.fort added a comment to T5616: Firewall mark - Add capabilities for matching firewall mark.

PR for Sagitta: https://github.com/vyos/vyos-1x/pull/2478

Nov 13 2023, 6:59 PM · VyOS 1.5 Circinus
n.fort changed the status of T5729: Firewall, nat and policy route - Switch to valueless from In progress to Needs testing.
Nov 13 2023, 9:33 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Nov 10 2023

n.fort changed the status of T5729: Firewall, nat and policy route - Switch to valueless from Open to In progress.
Nov 10 2023, 11:47 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort created T5729: Firewall, nat and policy route - Switch to valueless.
Nov 10 2023, 11:47 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Nov 8 2023

n.fort closed T4864: `show firewall` command errors as Resolved.

Command show zone-policy is no longer available in 1.4, and neither in 1.5
I'm closing this task.

Nov 8 2023, 7:26 PM · VyOS 1.4 Sagitta
n.fort closed T5513: Anomalies in show firewall command after refactoring as Resolved.
Nov 8 2023, 7:08 PM · VyOS 1.4 Sagitta
n.fort closed T5541: Zone-Based Firewalling in VyOS Sagitta 1.4 as Resolved.

I'm marking this one as resolved since ZBF was already re-introduced.

Nov 8 2023, 7:07 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort added a comment to T5550: Source validation on interface does not work properly.

Can we mark this one as resolved for 1.5? Seems it wasn't back-ported yet to Saggita @sdev

Nov 8 2023, 7:04 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort closed T5564: Both show firewall group and show firewall summary fails as Resolved.
Nov 8 2023, 6:58 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Nov 6 2023

n.fort added a comment to T5471: Conntrack logging doesnt seem to be working.

Does anyone knows real scenario where permanently storing/saving this logs are required?
Yes, this feature is not working on 1.4, neither on 1.5
But I can't think on a real case where this logs are needed. I know that keeping information of NAT for certain ISP is mandatory due lo legal requirements. But writing a log entry for every conntrack status change seems like it will flood logs, and may consume more resources than expected.
With usage of netflow/slflow, maybe this required information can be obtained in the netflow collector, and do not increase load on vyos router.

Nov 6 2023, 5:56 PM · VyOS 1.4 Sagitta (1.4.0-GA), VyOS 1.5 Circinus
n.fort added a comment to T5541: Zone-Based Firewalling in VyOS Sagitta 1.4.

PR: https://github.com/vyos/vyos-1x/pull/2441

Nov 6 2023, 3:34 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort added a comment to T5541: Zone-Based Firewalling in VyOS Sagitta 1.4.

Working on it! Thanks for the details!

Nov 6 2023, 9:39 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Nov 2 2023

n.fort changed the status of T5513: Anomalies in show firewall command after refactoring from Open to In progress.
Nov 2 2023, 9:07 PM · VyOS 1.4 Sagitta
n.fort added a comment to T5541: Zone-Based Firewalling in VyOS Sagitta 1.4.

Good to know it worked @marc_s . Thanks for letting us know!

Nov 2 2023, 9:00 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
marc_s awarded T5541: Zone-Based Firewalling in VyOS Sagitta 1.4 a Love token.
Nov 2 2023, 6:14 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort added a comment to T5705: rsyslog - Not working when using facility=all.

PR: https://github.com/vyos/vyos-1x/pull/2424

Nov 2 2023, 9:30 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Nov 1 2023

n.fort changed the status of T5705: rsyslog - Not working when using facility=all from Confirmed to In progress.
Nov 1 2023, 5:08 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort changed the status of T5705: rsyslog - Not working when using facility=all from Open to Confirmed.
Nov 1 2023, 2:29 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort created T5705: rsyslog - Not working when using facility=all.
Nov 1 2023, 2:29 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 26 2023

n.fort closed T5594: VRRP - Error if using IPv6 Link Local as hello source address as Resolved.
Oct 26 2023, 7:06 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus
n.fort closed T5600: Firewall - Remove or extend constraint on 'interface-name' as Resolved.
Oct 26 2023, 7:04 PM · VyOS 1.5 Circinus
n.fort changed the status of T5681: Interface match - Simplified and unified cli from In progress to Needs testing.
Oct 26 2023, 12:19 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T5643: NAT - Allow interface groups on nat rules from In progress to Needs testing.

This error was already fixed in https://github.com/vyos/vyos-1x/pull/2406

Oct 26 2023, 12:18 PM · VyOS 1.5 Circinus
n.fort added a comment to T5681: Interface match - Simplified and unified cli.

PR for op-mode command that fits new cli: https://github.com/vyos/vyos-1x/pull/2408

Oct 26 2023, 10:26 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5513: Anomalies in show firewall command after refactoring.

PR: https://github.com/vyos/vyos-1x/pull/2408

Oct 26 2023, 10:25 AM · VyOS 1.4 Sagitta
n.fort added a comment to T5564: Both show firewall group and show firewall summary fails.

PR: https://github.com/vyos/vyos-1x/pull/2408

Oct 26 2023, 10:25 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Oct 25 2023

n.fort added a comment to T5681: Interface match - Simplified and unified cli.

PR: https://github.com/vyos/vyos-1x/pull/2406

Oct 25 2023, 12:11 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Oct 24 2023

n.fort changed the status of T5681: Interface match - Simplified and unified cli from Open to In progress.
Oct 24 2023, 2:52 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort created T5681: Interface match - Simplified and unified cli.
Oct 24 2023, 2:52 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T5680: Allow selecting mac-groups in bridge firewall from Open to Confirmed.
Oct 24 2023, 1:21 PM · Restricted Project, VyOS 1.5 Circinus

Oct 23 2023

n.fort closed T5637: Firewall default-action log as Resolved.

For RQ for Sagitta: https://github.com/vyos/vyos-1x/pull/2399

Oct 23 2023, 4:58 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T5564: Both show firewall group and show firewall summary fails from Needs testing to In progress.

1.5 should not have such issues.
1.4: op-mode should be working as expected. Backport for https://github.com/vyos/vyos-1x/pull/2344 failed. I'll submit PR for 1.4 for such feature.

Oct 23 2023, 11:33 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Oct 20 2023

n.fort added a comment to T5541: Zone-Based Firewalling in VyOS Sagitta 1.4.

PR for Saggita: https://github.com/vyos/vyos-1x/pull/2388

Oct 20 2023, 8:22 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 13 2023

n.fort changed the status of T5541: Zone-Based Firewalling in VyOS Sagitta 1.4 from Open to In progress.
Oct 13 2023, 2:10 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Oct 11 2023

n.fort changed the status of T5644: Firewall groups deletion can break config from Open to Confirmed.
Oct 11 2023, 10:22 AM · VyOS 1.5 Circinus
n.fort created T5644: Firewall groups deletion can break config.
Oct 11 2023, 10:20 AM · VyOS 1.5 Circinus

Oct 10 2023

n.fort changed the status of T5643: NAT - Allow interface groups on nat rules from Confirmed to In progress.
Oct 10 2023, 6:18 PM · VyOS 1.5 Circinus
n.fort added a comment to T5643: NAT - Allow interface groups on nat rules.

PR: https://github.com/vyos/vyos-1x/pull/2355

Oct 10 2023, 6:18 PM · VyOS 1.5 Circinus
n.fort changed the status of T5643: NAT - Allow interface groups on nat rules from Open to Confirmed.
Oct 10 2023, 10:40 AM · VyOS 1.5 Circinus
n.fort created T5643: NAT - Allow interface groups on nat rules.
Oct 10 2023, 10:40 AM · VyOS 1.5 Circinus
n.fort closed T5014: Destination NAT - Add Load Balancing capabilities as Resolved.
Oct 10 2023, 10:37 AM · VyOS 1.4 Sagitta
n.fort added a comment to T5564: Both show firewall group and show firewall summary fails.

Once PR https://github.com/vyos/vyos-1x/pull/2344 is merged, counters and logs for default action should be available once again.

Oct 10 2023, 10:08 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5497: Add ability to resequence rule numbers for firewall.

It's an op-mode command, so it does not changes configuration. User may get something different from what he expected, so at least on this very first attempt of re-generating and re-ordering firewall rules, it's done in op-mode command with no impact on running configuration.

Oct 10 2023, 10:00 AM · VyOS 1.4 Sagitta (1.4.0-epa1)

Oct 6 2023

n.fort changed the status of T5637: Firewall default-action log from Confirmed to In progress.
Oct 6 2023, 2:42 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5637: Firewall default-action log.

PR: https://github.com/vyos/vyos-1x/pull/2344

Oct 6 2023, 2:42 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort changed the status of T5637: Firewall default-action log from Open to Confirmed.
Oct 6 2023, 12:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort created T5637: Firewall default-action log.
Oct 6 2023, 12:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort closed T5096: Change 'accept' firewall rule action from 'return' to 'accept' as Resolved.

Closing this one, because it's already implemented

Oct 6 2023, 11:59 AM · VyOS 1.4 Sagitta

Oct 3 2023

n.fort changed the status of T5616: Firewall mark - Add capabilities for matching firewall mark from In progress to Needs testing.
Oct 3 2023, 7:02 PM · VyOS 1.5 Circinus
n.fort changed the status of T5600: Firewall - Remove or extend constraint on 'interface-name' from In progress to Needs testing.
Oct 3 2023, 7:02 PM · VyOS 1.5 Circinus
n.fort closed T5579: Log firewall - Wrong command after firewall refactor, a subtask of T5160: Firewall refactor, as Resolved.
Oct 3 2023, 7:01 PM · VyOS 1.4 Sagitta
n.fort closed T5579: Log firewall - Wrong command after firewall refactor as Resolved.
Oct 3 2023, 7:01 PM · VyOS 1.5 Circinus
n.fort closed T5561: NAT - Inbound or outbound interface should not be mandatory as Resolved.
Oct 3 2023, 7:00 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort closed T5553: Firewall - Add action continue as Resolved.
Oct 3 2023, 7:00 PM · VyOS 1.4 Sagitta
n.fort closed T5250: Firewall - show firewall group as Resolved.
Oct 3 2023, 6:58 PM · VyOS 1.4 Sagitta

Sep 29 2023

n.fort added a comment to T5621: Show uncommited "commands" (compare | commands).

You mean this existing option, or I am missing something?

vyos@vyos-suri:~$ conf
[edit]
vyos@vyos-suri# set int eth eth0 description TEST
[edit]
vyos@vyos-suri# set serv ssh port 8877
[edit]
vyos@vyos-suri# set system host-name foo
[edit]
vyos@vyos-suri# compare 
[interfaces ethernet eth0]
+ description "TEST"
[service ssh]
+ port "8877"
[system]
- host-name "vyos-suri"
+ host-name "foo"
Sep 29 2023, 10:43 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sep 27 2023

n.fort renamed T5616: Firewall mark - Add capabilities for matching firewall mark from Firewall marl - Add capabilities for matching firewall mark to Firewall mark - Add capabilities for matching firewall mark.
Sep 27 2023, 5:48 PM · VyOS 1.5 Circinus
n.fort added a comment to T5616: Firewall mark - Add capabilities for matching firewall mark.

PR: https://github.com/vyos/vyos-1x/pull/2314

Sep 27 2023, 5:48 PM · VyOS 1.5 Circinus

Sep 26 2023

n.fort changed the status of T5616: Firewall mark - Add capabilities for matching firewall mark from Open to Confirmed.
Sep 26 2023, 12:11 PM · VyOS 1.5 Circinus
n.fort created T5616: Firewall mark - Add capabilities for matching firewall mark.
Sep 26 2023, 12:11 PM · VyOS 1.5 Circinus

Sep 21 2023

n.fort changed the status of T5594: VRRP - Error if using IPv6 Link Local as hello source address from In progress to Needs testing.
Sep 21 2023, 11:48 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus
n.fort added a comment to T5600: Firewall - Remove or extend constraint on 'interface-name'.

PR: https://github.com/vyos/vyos-1x/pull/2300

Sep 21 2023, 11:25 AM · VyOS 1.5 Circinus

Sep 19 2023

n.fort renamed T5600: Firewall - Remove or extend constraint on 'interface-name' from Firewall - Remove contraint on 'interface-name' to Firewall - Remove or extend constraint on 'interface-name'.
Sep 19 2023, 6:16 PM · VyOS 1.5 Circinus
n.fort changed the status of T5600: Firewall - Remove or extend constraint on 'interface-name' from Open to In progress.
Sep 19 2023, 5:56 PM · VyOS 1.5 Circinus
n.fort created T5600: Firewall - Remove or extend constraint on 'interface-name'.
Sep 19 2023, 5:56 PM · VyOS 1.5 Circinus

Sep 18 2023

n.fort changed the status of T5590: Firewall "log enable" logs every packet from Confirmed to In progress.
Sep 18 2023, 6:12 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5590: Firewall "log enable" logs every packet.

PR: https://github.com/vyos/vyos-1x/pull/2283

Sep 18 2023, 6:06 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
n.fort added a comment to T5594: VRRP - Error if using IPv6 Link Local as hello source address.

PR for latest: https://github.com/vyos/vyos-1x/pull/2281
PR for Equuleus: https://github.com/vyos/vyos-1x/pull/2282

Sep 18 2023, 2:09 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus
n.fort changed the status of T5594: VRRP - Error if using IPv6 Link Local as hello source address from Open to In progress.
Sep 18 2023, 1:18 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus
n.fort created T5594: VRRP - Error if using IPv6 Link Local as hello source address.
Sep 18 2023, 1:18 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.5 Circinus
n.fort changed the status of T5590: Firewall "log enable" logs every packet from Open to Confirmed.
Sep 18 2023, 12:57 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Sep 14 2023

n.fort changed the status of T5579: Log firewall - Wrong command after firewall refactor, a subtask of T5160: Firewall refactor, from Confirmed to In progress.
Sep 14 2023, 6:45 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5579: Log firewall - Wrong command after firewall refactor from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/2268

Sep 14 2023, 6:45 PM · VyOS 1.5 Circinus

Sep 13 2023

n.fort added a subtask for T5160: Firewall refactor: T5579: Log firewall - Wrong command after firewall refactor.
Sep 13 2023, 3:07 PM · VyOS 1.4 Sagitta
n.fort added a parent task for T5579: Log firewall - Wrong command after firewall refactor: T5160: Firewall refactor.
Sep 13 2023, 3:07 PM · VyOS 1.5 Circinus
n.fort changed the status of T5579: Log firewall - Wrong command after firewall refactor from Open to Confirmed.
Sep 13 2023, 3:07 PM · VyOS 1.5 Circinus
n.fort created T5579: Log firewall - Wrong command after firewall refactor.
Sep 13 2023, 3:07 PM · VyOS 1.5 Circinus
n.fort changed the status of T5561: NAT - Inbound or outbound interface should not be mandatory from Confirmed to In progress.

PR: https://github.com/vyos/vyos-1x/pull/2253

Sep 13 2023, 10:47 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta

Sep 12 2023

n.fort removed a project from T4072: Feature Request: Firewall on bridge interfaces: VyOS 1.3 Equuleus (1.3.5).
Sep 12 2023, 12:16 PM · VyOS 1.4 Sagitta
n.fort changed the status of T4072: Feature Request: Firewall on bridge interfaces from In progress to Needs testing.

op-mode: https://github.com/vyos/vyos-1x/pull/2242

Sep 12 2023, 10:17 AM · VyOS 1.4 Sagitta

Sep 11 2023

n.fort added a comment to T5564: Both show firewall group and show firewall summary fails.

N/D == not defined

Sep 11 2023, 9:54 AM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus

Sep 8 2023

n.fort changed the status of T5561: NAT - Inbound or outbound interface should not be mandatory from Open to Confirmed.
Sep 8 2023, 10:48 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort created T5561: NAT - Inbound or outbound interface should not be mandatory.
Sep 8 2023, 10:47 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort closed T4356: DHCP v6 client only supports single interface configuration as Resolved.

I'm closing this one. No news in the last year, and the tests I've done last month were ok.

Sep 8 2023, 10:12 AM · VyOS 1.4 Sagitta
n.fort closed T5450: Firewall interface group - Allow inverted matcher as Resolved.
Sep 8 2023, 10:04 AM · VyOS 1.4 Sagitta
n.fort closed T5460: Firewall - remove config-trap as Resolved.
Sep 8 2023, 10:04 AM · VyOS 1.4 Sagitta
n.fort closed T5502: Firewall - wrong parser for inbound and/or outbound interface as Resolved.
Sep 8 2023, 10:03 AM · VyOS 1.4 Sagitta
n.fort changed the status of T4072: Feature Request: Firewall on bridge interfaces from Open to In progress.
Sep 8 2023, 10:02 AM · VyOS 1.4 Sagitta
n.fort changed the status of T5553: Firewall - Add action continue from Confirmed to In progress.
Sep 8 2023, 10:01 AM · VyOS 1.4 Sagitta
n.fort added a comment to T5553: Firewall - Add action continue.

Feature included in: https://github.com/vyos/vyos-1x/pull/2222

Sep 8 2023, 10:01 AM · VyOS 1.4 Sagitta

Sep 7 2023

n.fort added a comment to T4072: Feature Request: Firewall on bridge interfaces.

PR: https://github.com/vyos/vyos-1x/pull/2222

Sep 7 2023, 8:47 PM · VyOS 1.4 Sagitta

Sep 6 2023

n.fort changed the status of T5553: Firewall - Add action continue from Open to Confirmed.
Sep 6 2023, 5:39 PM · VyOS 1.4 Sagitta
n.fort created T5553: Firewall - Add action continue.
Sep 6 2023, 5:39 PM · VyOS 1.4 Sagitta

Sep 5 2023

n.fort added a comment to T5482: Chrony NTP Server Fails To Sync Time.

Are you using vrf? Maybe it's an issue and router can't resolve dns for ntp servers

Sep 5 2023, 2:11 PM · VyOS 1.4 Sagitta
n.fort claimed T4072: Feature Request: Firewall on bridge interfaces.
Sep 5 2023, 9:40 AM · VyOS 1.4 Sagitta

Aug 30 2023

n.fort added a comment to T5496: `show firewall` error.

Adding geo-ip and fqnd too:
https://github.com/vyos/vyos-1x/pull/2188

Aug 30 2023, 10:27 PM · Restricted Project, VyOS 1.4 Sagitta
n.fort changed the status of T5496: `show firewall` error from Open to Needs testing.
Aug 30 2023, 1:54 PM · Restricted Project, VyOS 1.4 Sagitta
n.fort changed the status of T5513: Anomalies in show firewall command after refactoring from Open to Needs testing.
Aug 30 2023, 1:54 PM · VyOS 1.4 Sagitta
n.fort changed the status of T5250: Firewall - show firewall group from In progress to Needs testing.
Aug 30 2023, 1:53 PM · VyOS 1.4 Sagitta
n.fort added a comment to T5513: Anomalies in show firewall command after refactoring.

Fixed on this op-mode commands were introduced on PR https://github.com/vyos/vyos-1x/pull/2186

Aug 30 2023, 1:53 PM · VyOS 1.4 Sagitta