Page MenuHomeVyOS Platform
Feed Advanced Search

Jan 21 2019

hagbard added a comment to T1178: Scheduled script breaks ability to modify configuration.

I'm going to implement it into the configuration, which will assure that is it going to be the last step executed after a reboot.

Jan 21 2019, 5:21 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard edited projects for T894: DHCP not renewed after switching network, added: VyOS 1.2 Crux (VyOS 1.2.0-GA); removed VyOS 1.2 Crux (VyOS 1.2.0-EPA3).
Jan 21 2019, 5:19 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 18 2019

hagbard added a comment to T1184: wireguard - extend documentation with the show interface wireguard commands.

wireguard identifies peers on their key, improve the command for sh int wireguard wg01 peers etc. so that the peer name from the config is visible as well.

Jan 18 2019, 9:07 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard added a comment to T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.

@ekim https://downloads.vyos.io/rolling/current/amd64/vyos-1.2.0-rolling%2B201901181924-amd64.iso should address the dhcp issue, can you please test? I only tested on VMs yet.

Jan 18 2019, 7:07 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T894: DHCP not renewed after switching network from In progress to Needs testing.

@yun https://downloads.vyos.io/rolling/current/amd64/vyos-1.2.0-rolling%2B201901181924-amd64.iso should address that issue, can you please test? I only tested on VMs yet.

Jan 18 2019, 7:07 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T894: DHCP not renewed after switching network, a subtask of T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient, from In progress to Needs testing.
Jan 18 2019, 7:07 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard triaged T1184: wireguard - extend documentation with the show interface wireguard commands as Low priority.
Jan 18 2019, 6:05 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard claimed T1184: wireguard - extend documentation with the show interface wireguard commands.
Jan 18 2019, 6:05 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard created T1184: wireguard - extend documentation with the show interface wireguard commands.
Jan 18 2019, 6:05 PM · VyOS 1.3 Equuleus (1.3.0-epa1)

Jan 17 2019

hagbard added a comment to T894: DHCP not renewed after switching network.

pending ci netplugd integration, local tests were quite successful, I think it can be release into rolling in the next few days.

Jan 17 2019, 8:10 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T894: DHCP not renewed after switching network from Open to In progress.
Jan 17 2019, 8:09 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T894: DHCP not renewed after switching network, a subtask of T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient, from Open to In progress.
Jan 17 2019, 8:09 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard claimed T894: DHCP not renewed after switching network.
Jan 17 2019, 8:09 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard closed T1028: Suspending and resuming VyOS in VMware will result in loss of static ip addresses as Resolved.
Jan 17 2019, 7:57 PM · VyOS 1.3 Equuleus (1.3.7), test
hagbard claimed T1028: Suspending and resuming VyOS in VMware will result in loss of static ip addresses.

http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyos-vmwaretools-scripts/vyos-vmwaretools-scripts_1.0-1_all.deb

Jan 17 2019, 6:08 PM · VyOS 1.3 Equuleus (1.3.7), test

Jan 16 2019

hagbard added a comment to T894: DHCP not renewed after switching network.

T1181 will fix that issue.

Jan 16 2019, 11:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a subtask for T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient: T894: DHCP not renewed after switching network.
Jan 16 2019, 11:37 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a parent task for T894: DHCP not renewed after switching network: T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.
Jan 16 2019, 11:37 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.

All right @ekim I have that feature working in an experimental package. If you want to test it you can build it from here:
https://github.com/hagbard-01/vyos-netplug via dpkg-buildpackage -b -tc -uc -us and install it on any rolling iso. I used the latest for my tests, but it should work on older ones too. It will still take a little time to have that pushed into the normal build process, since it requires some integration work.

Jan 16 2019, 11:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.

@ekim Yeah, that is a known issue I was looking into a while ago already. disable/enable in eth interfaces should now work in the latest rolling, the plug-in and unplug will still need a little. I'll keep this task here open for it.

Jan 16 2019, 5:53 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T166: NPTv6 is broken in the rolling release 999.201609170235 .

I think I know what you mean now, it also starts translating the global address on the external interface. Can you send a PR for the changes you've made please?

Jan 16 2019, 12:02 AM · VyOS 1.2 Crux (VyOS 1.2.1)

Jan 15 2019

hagbard added a comment to T166: NPTv6 is broken in the rolling release 999.201609170235 .

At the first quick review it works:

Jan 15 2019, 11:52 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard added a comment to T166: NPTv6 is broken in the rolling release 999.201609170235 .

@Merijn I haven't added anything. I just tested nptv6 and it was working as expected. I used your setup you have initially posted, I just used a different interface for the outgoing traffic. I confirmed via tcpdump that NAT did work.

Jan 15 2019, 10:06 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard claimed T1178: Scheduled script breaks ability to modify configuration.
Jan 15 2019, 9:15 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard moved T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient from Need Triage to In Progress on the VyOS 1.2 Crux board.
Jan 15 2019, 8:41 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard renamed T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient from Stagnant IP on DHCP interface to disable/enable interface with dhcp ip assignement fails to restart dhclient.
Jan 15 2019, 8:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient from Open to Needs testing.
Jan 15 2019, 8:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.

@ekim I think I found it. When I put the interface into disabled mode and then delete disabled, the dhcp client isn't started anymore if the address is supposed to be received via dhcp, correct?

Jan 15 2019, 8:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard claimed T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.
Jan 15 2019, 7:55 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard added a comment to T1181: disable/enable interface with dhcp ip assignement fails to restart dhclient.

Have you checked on the server DHCP server side for issues?

Jan 15 2019, 7:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T166: NPTv6 is broken in the rolling release 999.201609170235 from Open to Needs testing.

I've tested it without doing anything on the code and everything is working properly.

Jan 15 2019, 6:58 PM · VyOS 1.2 Crux (VyOS 1.2.1)
hagbard closed T1026: Removing tunnel deletes all tunnels? as Resolved.
Jan 15 2019, 5:48 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard closed T1135: "firewall send-redirects enable" works only after switching from disabled state on running system as Resolved.
Jan 15 2019, 5:48 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 11 2019

hagbard added a comment to T1026: Removing tunnel deletes all tunnels?.

That's all to test. I did test it based on the config you provide above, I just want to see if there are any corner case I did not consider.

Jan 11 2019, 6:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 10 2019

hagbard added a comment to T1166: Flow-accounting not working with PPPoE interfaces.

I got a bit further. uacctd seems to have an issue, I started manually pmacctd on pppoe0 and everything is working well. Uacctd shows that it gets hit with something when I check via strace, but it doesn't show anything.

Jan 10 2019, 7:59 PM · VyOS 1.3 Equuleus (1.3.7), test

Jan 8 2019

hagbard closed T1107: Grub: no input from serial console (menu doesn't respond to keystrokes) as Resolved.

merged and closed on @kroy 's behalf. (https://phabricator.vyos.net/R5:749d923ee9704624a476bef17d66d752aff6bf0d)
thx @kroy

Jan 8 2019, 10:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard changed the status of T1135: "firewall send-redirects enable" works only after switching from disabled state on running system from In progress to Needs testing.
Jan 8 2019, 10:28 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

The latest rolling has now 'net.ipv4.conf.all.send_redirects = 0', can you please test if that would solve that issue?

Jan 8 2019, 10:23 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

But wouldn't that be a n SA issue in strongswan?
Found their bugreports, I think the best and safest way is to turn redirects entirely off and set an option in interfaces to turn it on. That way we can assure that a warning messages is also read and understood. agree?

Jan 8 2019, 9:07 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

Hmm, I don't like the leaking part :D (I doubt that it will be unecrypted, but haven't tested it yet) . Per default redirects are enabled on every interface, which is the default.

Jan 8 2019, 8:42 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

@zsdc if I understand you correctly, you want that /proc/sys/net/ipv4/conf/all/send_redirects is always 0 unless configured on purpose, correct?
Per default router should do that.

Jan 8 2019, 6:02 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard changed the status of T1135: "firewall send-redirects enable" works only after switching from disabled state on running system from Open to In progress.
Jan 8 2019, 5:48 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 7 2019

hagbard changed the status of T1026: Removing tunnel deletes all tunnels? from In progress to Needs testing.
Jan 7 2019, 11:21 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1026: Removing tunnel deletes all tunnels?.

Sorry for the delay @Barrysdca , please test the rolling release January 8th. or alternativly you can install http://dev.packages.vyos.net/repositories/current/vyos/pool/main/v/vyatta-cfg-system/vyatta-cfg-system_0.20.44+vyos2+current17_amd64.deb as well, which should fix the issue.
Please provide feedback as soon as you can, I tested the config you have posted above and everything appears to be working well now with the new package.

Jan 7 2019, 11:21 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard changed the status of T1026: Removing tunnel deletes all tunnels? from On hold to In progress.
Jan 7 2019, 10:29 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard closed T1131: open-vm-tools causing 100% CPU load as Resolved.

https://phabricator.vyos.net/R3:15a9a405e03165b798776b9f779426bdfa779d03

Jan 7 2019, 9:44 PM · VyOS 1.2 Crux (VyOS 1.2.2)
hagbard changed the status of T1166: Flow-accounting not working with PPPoE interfaces from Open to Confirmed.
Jan 7 2019, 9:40 PM · VyOS 1.3 Equuleus (1.3.7), test
hagbard added a project to T1166: Flow-accounting not working with PPPoE interfaces: VyOS 1.2 Crux (VyOS 1.2.0-EPA3).
Jan 7 2019, 9:38 PM · VyOS 1.3 Equuleus (1.3.7), test
hagbard closed T1168: Upgrade from 1.1.8 to 1.2-EPA2 fails for "vpn ipsec logging log-modes all" as Resolved.

https://github.com/vyos/vyatta-cfg-vpn/commit/8365c04cccb6e0216b048ca30e289081f0c0ae44
https://github.com/vyos/vyos-1x/commit/ac7c868dcba4dd6738eb0087c4f414b92bf10c9d

Jan 7 2019, 9:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard changed the status of T1168: Upgrade from 1.1.8 to 1.2-EPA2 fails for "vpn ipsec logging log-modes all" from Open to In progress.
Jan 7 2019, 7:27 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard claimed T1166: Flow-accounting not working with PPPoE interfaces.
Jan 7 2019, 4:32 PM · VyOS 1.3 Equuleus (1.3.7), test
hagbard added a comment to T1131: open-vm-tools causing 100% CPU load.

@syncer I was thinking to add a cli menu for vmwaretoolsd mitgation like these things. It seems that not many were affected by that but if there is anything in the cli available, it can configure the toolsd to prevent things like that plus the toolsd has tons of options. So, I'm not really sure how I should go forward with this one.

Jan 7 2019, 12:10 AM · VyOS 1.2 Crux (VyOS 1.2.2)
hagbard closed T1162: WireGuard: Unable to modify tunnels - KeyError: 'state' as Resolved.
Jan 7 2019, 12:07 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1162: WireGuard: Unable to modify tunnels - KeyError: 'state'.

Next rolling will have the fix applied:
https://github.com/vyos/vyos-1x/commit/76fe726e3530158ee175d34b9cb74209ccca2345

Jan 7 2019, 12:07 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 6 2019

hagbard changed the status of T1162: WireGuard: Unable to modify tunnels - KeyError: 'state' from Open to In progress.
Jan 6 2019, 11:43 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard claimed T1162: WireGuard: Unable to modify tunnels - KeyError: 'state'.
Jan 6 2019, 9:58 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1161: Does Vyos take advantage of linux's improved security features?.

@c-po I have access to it, let me know if you need a pdf out of it.

Jan 6 2019, 5:49 PM · VyOS 1.5 Circinus

Jan 5 2019

hagbard closed T1152: VyOS inside virtualbox for testing as Invalid.
Jan 5 2019, 12:19 AM · Rejected

Jan 3 2019

hagbard added a comment to T1144: Wiki is too hard to contribute to due to aggressive anti-spam measures.

I stumbled over the same issue and since then I contribute to @UnicronNL and @c-po documentation. I think the old wiki will go away at one point, have a look at the github link @c-po posted above, it's also way easier to maintain the new documentation.

Jan 3 2019, 5:56 PM · Restricted Project
hagbard claimed T1152: VyOS inside virtualbox for testing .

Hi @rherold , these messages are verbose debug messages, change to virtio-net or to a different emulated driver to have them disappear. In general I recommend to use the virtio one which has a better performance too compared to emulated ones, plus less complex code. (https://github.com/MorteNoir1/virtualbox_e1000_0day)

Jan 3 2019, 5:52 PM · Rejected

Dec 31 2018

hagbard created T1145: shutdown event being ignored by latest rolling.
Dec 31 2018, 7:40 PM · VyOS 1.3 Equuleus (1.3.0-epa1)

Dec 29 2018

hagbard changed the status of T1131: open-vm-tools causing 100% CPU load from Open to In progress.
Dec 29 2018, 7:09 PM · VyOS 1.2 Crux (VyOS 1.2.2)
hagbard added a comment to T1131: open-vm-tools causing 100% CPU load.

Thanks for testing that guys.

Dec 29 2018, 6:25 PM · VyOS 1.2 Crux (VyOS 1.2.2)

Dec 28 2018

hagbard added a comment to T1131: open-vm-tools causing 100% CPU load.

@MrXermon , yes that sounds reasonable. I found in the code that they limit it to 100 routes, can you please try the following:
(https://github.com/vmware/open-vm-tools/blob/master/open-vm-tools/lib/include/conf.h#L138)

Dec 28 2018, 7:00 PM · VyOS 1.2 Crux (VyOS 1.2.2)
hagbard added a comment to T1026: Removing tunnel deletes all tunnels?.

Hi @Barrysdca did you have a chance to test again?

Dec 28 2018, 6:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1131: open-vm-tools causing 100% CPU load.

Hi @danhusan, did you ever try another poll value, like 3 secs or 5 or anything like that? If set to 0, the host system won't show you any updated meta data, like if you change the ip address etc.
(https://github.com/vmware/open-vm-tools/blob/master/open-vm-tools/services/plugins/guestInfo/guestInfoServer.c#L1662)
I'm therefore not entirely sure if that should be treated as a special case scenario (we could publish a kb if you run into that condition), or if it is a general issue since you 2 were the only ones experience that issue as far as I know.
I'm also not sure it only is triggered by your situation (full bgp table) or if it can happen on other occasions as well, if you came across more issues regarding that value, please let me know.

Dec 28 2018, 6:07 PM · VyOS 1.2 Crux (VyOS 1.2.2)

Dec 27 2018

hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

I have a look into it but I doubt that this will be an issue. Charon is usually taking care of the routes if an IPSec tunnel has been established and you have a valid SA. The redirects from the settings above shouldn't interferer with it at all. If a mode tunnel is being used with public IPs, the packets will leave the system unencrypted anyway as long as no valid SA exists, so they will go the default route. I'll check if the perl script is actually changing these settings, that would be not so nice since you will face a race condition which would explain why I can't reproduce your issue, since I never tested with a working IPSec tunnel :). I'm having the flu right now, so please give me a few days to have a look.

Dec 27 2018, 6:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Dec 26 2018

hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

Can you check ig you have any postscripts running or any manual sysctl variable set? Or do you experience that on new insatllations?

Dec 26 2018, 10:37 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard closed T1136: Typo in BGP CLI as Resolved.
Dec 26 2018, 10:36 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA2)
hagbard claimed T1131: open-vm-tools causing 100% CPU load.
Dec 26 2018, 10:35 PM · VyOS 1.2 Crux (VyOS 1.2.2)

Dec 25 2018

hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

Yes, that's correct. When I enable redirects, it automatically disables receive redirects, which I didn't know but makes sense.
I have only set the redirect and dhcp on eth0, commit && save and rebooted, all looks good.

Dec 25 2018, 5:36 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

I still have no luck reproducing it, I loaded your config on a vm, runni9ng the smae version as you do but if I enable and disable redirects it switches between 1 and 0, as expected.

Dec 25 2018, 1:52 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Dec 24 2018

hagbard closed T1134: vyatta-cfg is unable to build on jessie as Resolved.
Dec 24 2018, 6:15 PM
hagbard added a comment to T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.

@zsdc I can't reproduce it, can you please share your config? I have only enable send redirects set, nothing else in the config and everything works like expected. I suspect that something is overwriting your variables. We'll find out.

Dec 24 2018, 6:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard claimed T1135: "firewall send-redirects enable" works only after switching from disabled state on running system.
Dec 24 2018, 6:00 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Dec 18 2018

hagbard changed the status of T989: Add support for IPoE server from On hold to In progress.
Dec 18 2018, 7:17 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard changed the status of T989: Add support for IPoE server, a subtask of T742: Replace poptop and xl2tpd with accel-ppp, from On hold to In progress.
Dec 18 2018, 7:17 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard closed T1102: Disabling rp_filter don't work as Resolved.

Next rolling release tonight will have the bugfix in place. Thanks for reporting.

Dec 18 2018, 7:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T1102: Disabling rp_filter don't work from On hold to In progress.
Dec 18 2018, 6:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T1026: Removing tunnel deletes all tunnels? from In progress to On hold.
Dec 18 2018, 6:06 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1026: Removing tunnel deletes all tunnels?.

@Barrysdca Can you please test with the latest rolling release, please?

Dec 18 2018, 6:05 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard reassigned T1028: Suspending and resuming VyOS in VMware will result in loss of static ip addresses from hagbard to Unknown Object (User).

@Unicron Can you please integrate the package below into ci?
https://github.com/vyos/vyos-vmwaretools-scripts

Dec 18 2018, 6:05 PM · VyOS 1.3 Equuleus (1.3.7), test

Dec 17 2018

hagbard added a comment to T1052: ISO compilation error.

@hexes Should be fixed now. (https://downloads.vyos.io/rolling/current/amd64/vyos-1.2.0-rolling%2B201812171828-amd64.iso)

Dec 17 2018, 5:55 PM · build-iso
hagbard closed T1103: adding 'set interfaces wireguard wg01 ip and ipv6' options as Resolved.

https://phabricator.vyos.net/R11:9e03aa762bac9919db2dae774062b179f9478b70

Dec 17 2018, 5:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
hagbard closed T1103: adding 'set interfaces wireguard wg01 ip and ipv6' options, a subtask of T1063: Routing protocol and QoS templates are missing in the wireguard CLI, as Resolved.
Dec 17 2018, 5:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)

Dec 14 2018

hagbard added a comment to T1102: Disabling rp_filter don't work.

Uh, yeah, that sucks. I'm implementing the kernel variables for wireguard at the moment and have a look into the other interfaces after that.

Dec 14 2018, 5:56 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Dec 13 2018

hagbard added a comment to T1063: Routing protocol and QoS templates are missing in the wireguard CLI.

@runar I should have something ready tomorrow or at the weekend at the latest you could test for IPv4. I basically started implementing the 'set interfaces <intf> ip' options including the kernel vars which you can set on other interfaces since wireguard is using that interface and looks like a normal network interface to the kernel.

Dec 13 2018, 11:31 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
hagbard changed the status of T1103: adding 'set interfaces wireguard wg01 ip and ipv6' options from Open to In progress.
Dec 13 2018, 9:23 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
hagbard added a comment to T1102: Disabling rp_filter don't work.

Ahh, I think I found it. Usually sysctl sets it to 1, or at least it must have that done in 1.1. I think the command should be called then enable-arp-filter to correct it.

Dec 13 2018, 7:22 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
hagbard changed the status of T1063: Routing protocol and QoS templates are missing in the wireguard CLI from Open to In progress.
Dec 13 2018, 6:26 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
hagbard changed the status of T1102: Disabling rp_filter don't work from Open to On hold.

Unless I misunderstood you, int(0) does disable (no source validation) rp_filter.

Dec 13 2018, 6:26 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Dec 12 2018

hagbard added a comment to T1063: Routing protocol and QoS templates are missing in the wireguard CLI.

After playing around with it, I think I create an extra script just for that task, it'll be easier to maintain until that parts are moved out to 'set protocol'.

Dec 12 2018, 11:28 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
hagbard added a comment to T1063: Routing protocol and QoS templates are missing in the wireguard CLI.

Oh I see, so it would be then in /opt/vyatta/share/vyatta-cfg/templates/interfaces/wireguard/node.tag/ip/ospf/cost/node.def.
What do you mean with moving it into the protocol subtree?
I also would then handle it within the wireguard code, like I did for the firewall stuff.
(https://github.com/vyos/vyos-1x/commit/51f61991092a163f680e4ec8f122e73f4074ddf9)
Let me know what you think, would be just an extra node and leavenode to handle.

Dec 12 2018, 9:09 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
hagbard added a comment to T1026: Removing tunnel deletes all tunnels?.

Hi @Barrysdca , can you please test if the issue persists with https://downloads.vyos.io/rolling/current/amd64/vyos-1.2.0-rolling%2B201812120337-amd64.iso
I tested it on the image and it appears that I can't reproduce it anymore.

Dec 12 2018, 8:13 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard changed the status of T1026: Removing tunnel deletes all tunnels? from Open to In progress.
Dec 12 2018, 7:59 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
hagbard added a comment to T1063: Routing protocol and QoS templates are missing in the wireguard CLI.

@runar How do you set it on other interfaces?

Dec 12 2018, 6:58 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
hagbard closed T1048: [IPSec] Protocol all does not work in IPSec Tunnel as Resolved.

the new syntax is being applied to the config file.

Dec 12 2018, 6:57 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
hagbard closed T1065: PPPoE MTU on boot up as Resolved.

I've tested it successfully multiple times and pushed the fix upstream, the configured MTU is now being requested with the first PADI.

Dec 12 2018, 6:56 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
hagbard closed T1087: Firewall commands are missing in wireguard interface CLI as Resolved.

Thanks for testing and confirming. @trystan

Dec 12 2018, 6:21 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
hagbard added a comment to T1065: PPPoE MTU on boot up.

All right, thanks bunch. I think I found the issue but before I expose it into the image, I'd like to test with you the functionality.

Dec 12 2018, 12:05 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)