Page MenuHomeVyOS Platform
Feed All Stories

Today

jack9603301 changed the status of T2898: Support NDP proxy, a subtask of T2518: Support NAT for ipv6(NPT), from Open to In progress.
Sat, Sep 19, 9:39 AM · VyOS 1.3 Equuleus
jack9603301 changed the status of T2898: Support NDP proxy from Open to In progress.
Sat, Sep 19, 9:39 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 updated the task description for T2898: Support NDP proxy.
Sat, Sep 19, 7:21 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

I can't find how to enable ipv6 connection tracking. Recompiling and modifying the linux kernel switch does not seem to see the module loaded. I think the current nat66 has completed 90%, and only need to implement ndp proxy to make it work normally.

Sat, Sep 19, 7:20 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

set interfaces ethernet eth0 ip proxy-arp

Sat, Sep 19, 7:17 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

I think we do need it, we can’t let users manage all IP manually unless we implement stateful NAT66

Sat, Sep 19, 7:15 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
c-po added a comment to T2898: Support NDP proxy.

set interfaces ethernet eth0 ip proxy-arp

Sat, Sep 19, 6:57 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 triaged T2898: Support NDP proxy as Normal priority.
Sat, Sep 19, 6:41 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 claimed T2898: Support NDP proxy.
Sat, Sep 19, 6:40 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 updated the task description for T2898: Support NDP proxy.
Sat, Sep 19, 6:30 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a project to T2898: Support NDP proxy: VyOS 1.2 Crux.
Sat, Sep 19, 6:29 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

Beeing stateless or statefull both should work. We can add a CLI node for the proxy.ndp option like we have for proxy arp on ipv4, no big deal.

Sat, Sep 19, 5:29 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 created T2898: Support NDP proxy.
Sat, Sep 19, 3:59 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus

Yesterday

syncer changed the subtype of T2713: VyOS must not change permissions on files in /config/auth from "Task" to "Bug".
Fri, Sep 18, 8:13 PM · VyOS 1.3 Equuleus
syncer archived VyOS 1.2 Crux (VyOS 1.2.6).
Fri, Sep 18, 7:58 PM
s.lorente created T2897: Remove cluster command in Crux.
Fri, Sep 18, 7:49 PM
diekos updated the task description for T2896: set ip route 0.0.0.0/0 dhcp-interface eth0.
Fri, Sep 18, 6:56 PM · VyOS 1.3 Equuleus
diekos created T2896: set ip route 0.0.0.0/0 dhcp-interface eth0.
Fri, Sep 18, 6:55 PM · VyOS 1.3 Equuleus
Viacheslav added a comment to T2806: ipsec generates false warning on commit when local prefix is sourced from loopback.

Let's check and table "local"
PR https://github.com/vyos/vyatta-cfg-vpn/pull/37

Fri, Sep 18, 6:21 PM
Viacheslav created T2895: VPN IPsec "leftsubnet" declared 2 times.
Fri, Sep 18, 6:09 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
Cheeze_It added a comment to T1316: Support for IS-IS .

@Viacheslav, I am unsure if you're able to finish the template and/or work on it more but if you guys ever choose to complete it and add it into rolling then I can test it out in my lab.

Fri, Sep 18, 5:32 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).
In T2518#75586, @c-po wrote:

Beeing stateless or statefull both should work. We can add a CLI node for the proxy.ndp option like we have for proxy arp on ipv4, no big deal.

Fri, Sep 18, 2:56 PM · VyOS 1.3 Equuleus
c-po added a comment to T2518: Support NAT for ipv6(NPT).

Beeing stateless or statefull both should work. We can add a CLI node for the proxy.ndp option like we have for proxy arp on ipv4, no big deal.

Fri, Sep 18, 2:49 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

This is a milestone, which means we have to decide whether to use stateful or stateless

Fri, Sep 18, 1:58 PM · VyOS 1.3 Equuleus
JessterSB added a comment to T2518: Support NAT for ipv6(NPT).

I worked with @jack9603301 and discovered [1] that stateless NAT66 depends on IPv6 neighbor proxy, otherwise VyOS will not respond to IPv6 neighbor discovery broadcasts.

Fri, Sep 18, 1:55 PM · VyOS 1.3 Equuleus
SrividyaA added a comment to T2861: route-map "set community additive" not working correctly.

Tested in LTS 1.2.5 and latest rolling release, where it is not allowing to add the AA:NN along with Additive

Fri, Sep 18, 1:13 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

It is confirmed that there is a bug in the implementation, but no solution has been found yet. In the nat66 rule, the prefix translation is indeed performed in the expected behavior, but the upstream device cannot return the data packet from the specific prefix. If the community has a good solution, please let me know

Fri, Sep 18, 11:45 AM · VyOS 1.3 Equuleus
jack9603301 changed the status of T2518: Support NAT for ipv6(NPT) from On hold to In progress.
Fri, Sep 18, 10:50 AM · VyOS 1.3 Equuleus
Dmitry added a parent task for T1251: IKEv2 Agile VPN Support: T2816: Rewrite IPsec scripts with the new XML/Python approach.
Fri, Sep 18, 10:41 AM · VyOS 1.3 Equuleus
Dmitry added a subtask for T2816: Rewrite IPsec scripts with the new XML/Python approach: T1251: IKEv2 Agile VPN Support.
Fri, Sep 18, 10:41 AM · VyOS 1.3 Equuleus
Dmitry closed T945: Unable to change configuration after changing it from script (vbash + script-template) as Resolved.

Marked as resolved

Fri, Sep 18, 8:48 AM · VyOS 1.3 Equuleus

Thu, Sep 17

c-po triaged T2894: bond: lacp: member interfaces get removed once bond interface has vlans configured as Unbreak Now! priority.
Thu, Sep 17, 7:28 PM · VyOS 1.3 Equuleus
c-po created T2894: bond: lacp: member interfaces get removed once bond interface has vlans configured.
Thu, Sep 17, 7:28 PM · VyOS 1.3 Equuleus
Dmitry changed the status of T2891: Support to change ring-buffers from CLI from Open to Needs testing.

Thanks, let's merge it only after 1.2.6 release

Thu, Sep 17, 5:55 PM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.3 Equuleus
c-po added a comment to T2891: Support to change ring-buffers from CLI.

No objection

Thu, Sep 17, 5:23 PM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.3 Equuleus
Dmitry added a comment to T2891: Support to change ring-buffers from CLI.

Can we add this implementation for crux in the old style?
https://github.com/DmitriyEshenko/vyatta-cfg-system/commit/0adc41a62b6d532da7c4b47cb5da920d1ed39664

Thu, Sep 17, 12:48 PM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.3 Equuleus
Dmitry added a project to T2891: Support to change ring-buffers from CLI: VyOS 1.2 Crux (VyOS 1.2.7).
Thu, Sep 17, 12:46 PM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.3 Equuleus
zsdc closed T2888: Cloud-init images refuse to work with network-based datasource such as Ec2 or OpenStack (but do work with OpenStack's config drive) as Invalid.

The main reason for such issues is missing a good one instructions on how to build a proper one image.

Thu, Sep 17, 12:21 PM · VyOS 1.3 Equuleus
s.lorente created T2893: Remove broken MSS-clamping old command.
Thu, Sep 17, 11:46 AM
s.lorente triaged T2892: Remove command: "set firewall options interface <interface> disable" as Low priority.
Thu, Sep 17, 10:41 AM
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).
Thu, Sep 17, 5:03 AM · VyOS 1.3 Equuleus
JessterSB added a comment to T2518: Support NAT for ipv6(NPT).

@jack9603301 Here is R1

Thu, Sep 17, 3:00 AM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

Please give the configuration of R1 so that I can immediately test your topology in the simulation environment

Thu, Sep 17, 2:50 AM · VyOS 1.3 Equuleus

Wed, Sep 16

JessterSB added a comment to T2518: Support NAT for ipv6(NPT).

Hey guys, I am testing nat66 from @jack9603301 which @c-po provided the ISO for me today (VyOS 1.3-nat66-202009161808)

Wed, Sep 16, 10:50 PM · VyOS 1.3 Equuleus
Dmitry claimed T2891: Support to change ring-buffers from CLI.
Wed, Sep 16, 7:32 PM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.3 Equuleus
Dmitry created T2891: Support to change ring-buffers from CLI.
Wed, Sep 16, 7:32 PM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.3 Equuleus
kroy added a comment to T2875: Cannot add WiFi interface to Bridge.
set interfaces bridge br0 member interface wlan0
Wed, Sep 16, 7:17 PM · VyOS 1.3 Equuleus
Viacheslav added a comment to T2890: NAT error adding translation address range.

Duplicate T2539

Wed, Sep 16, 6:24 PM · VyOS 1.3 Equuleus
bamu created T2890: NAT error adding translation address range.
Wed, Sep 16, 6:18 PM · VyOS 1.3 Equuleus
c-po closed T2887: WiFi ht40+ channel width is not set in hostaptd.conf as Resolved.
Wed, Sep 16, 5:46 PM · VyOS 1.3 Equuleus
c-po changed the status of T2887: WiFi ht40+ channel width is not set in hostaptd.conf from Open to In progress.
Wed, Sep 16, 5:34 PM · VyOS 1.3 Equuleus
c-po closed T2886: RADIUS authentication broken only returns operator level as Resolved.
Wed, Sep 16, 4:56 PM · VyOS 1.3 Equuleus
Viacheslav created T2889: Service SNMP doesn't start after adding new addresses.
Wed, Sep 16, 3:13 PM · VyOS 1.2 Crux
c-po added a comment to T2886: RADIUS authentication broken only returns operator level.

Add a smoketest to check if the required config options are present in the kernel configuration to prevent this in the future.

Wed, Sep 16, 3:02 PM · VyOS 1.3 Equuleus
c-po changed the status of T2886: RADIUS authentication broken only returns operator level from Open to In progress.
Wed, Sep 16, 2:59 PM · VyOS 1.3 Equuleus
sempervictus created T2888: Cloud-init images refuse to work with network-based datasource such as Ec2 or OpenStack (but do work with OpenStack's config drive).
Wed, Sep 16, 2:34 PM · VyOS 1.3 Equuleus
c-po claimed T2887: WiFi ht40+ channel width is not set in hostaptd.conf.
Wed, Sep 16, 5:56 AM · VyOS 1.3 Equuleus
c-po created T2887: WiFi ht40+ channel width is not set in hostaptd.conf.
Wed, Sep 16, 5:56 AM · VyOS 1.3 Equuleus

Tue, Sep 15

c-po updated the task description for T2886: RADIUS authentication broken only returns operator level.
Tue, Sep 15, 5:17 PM · VyOS 1.3 Equuleus
c-po updated the task description for T2886: RADIUS authentication broken only returns operator level.
Tue, Sep 15, 5:16 PM · VyOS 1.3 Equuleus
c-po updated the task description for T2886: RADIUS authentication broken only returns operator level.
Tue, Sep 15, 5:04 PM · VyOS 1.3 Equuleus
c-po created T2886: RADIUS authentication broken only returns operator level.
Tue, Sep 15, 5:03 PM · VyOS 1.3 Equuleus
c-po closed T2515: Ethernet interface is automatically disabled when removing it from bond as Resolved.
Tue, Sep 15, 4:56 PM · VyOS 1.3 Equuleus
jestabro changed the status of T2885: configd: print commit errors to config session terminal, a subtask of T2582: Script daemon to offload processing during commit, from In progress to Needs testing.
Tue, Sep 15, 4:31 PM · VyOS 1.3 Equuleus
jestabro changed the status of T2885: configd: print commit errors to config session terminal from In progress to Needs testing.
Tue, Sep 15, 4:31 PM · VyOS 1.3 Equuleus
sempervictus claimed T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.
Tue, Sep 15, 4:09 PM · VyOS 1.3 Equuleus
sempervictus changed Difficulty level from unknown to hard on T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.
Tue, Sep 15, 4:08 PM · VyOS 1.3 Equuleus
sempervictus updated the task description for T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.
Tue, Sep 15, 4:08 PM · VyOS 1.3 Equuleus
c-po claimed T2515: Ethernet interface is automatically disabled when removing it from bond.
Tue, Sep 15, 3:59 PM · VyOS 1.3 Equuleus
c-po closed T2882: DHCP client on bond interfaces not working as Invalid.
Tue, Sep 15, 3:57 PM · VyOS 1.3 Equuleus
c-po added a comment to T2882: DHCP client on bond interfaces not working.

Yeah - its a bug when used in EVE-ng - closing

Tue, Sep 15, 3:57 PM · VyOS 1.3 Equuleus
sempervictus added a comment to T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.

While i appreciate that you have an opinion of what's "best," i'm not re-summarizing 10+y of Linux out-of-tree history to spoon feed someone data they can, and should (like good engineers do), acquire on their own. Several of those patches are simply in-tree integrations for things currently built and packaged as kmods by VyOS on an LTS tree, the rest are well documented long running projects of their own which one must research and review the source code for anyway to properly understand their function and benefit.

Tue, Sep 15, 3:29 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.

It’s best to provide links to related descriptions instead of asking everyone to search for the related details and patch implementations you describe

Tue, Sep 15, 3:13 PM · VyOS 1.3 Equuleus
jestabro changed the status of T2885: configd: print commit errors to config session terminal, a subtask of T2582: Script daemon to offload processing during commit, from Open to In progress.
Tue, Sep 15, 2:56 PM · VyOS 1.3 Equuleus
jestabro changed the status of T2885: configd: print commit errors to config session terminal from Open to In progress.
Tue, Sep 15, 2:56 PM · VyOS 1.3 Equuleus
jestabro added a subtask for T2582: Script daemon to offload processing during commit: T2885: configd: print commit errors to config session terminal.
Tue, Sep 15, 2:56 PM · VyOS 1.3 Equuleus
jestabro added a parent task for T2885: configd: print commit errors to config session terminal: T2582: Script daemon to offload processing during commit.
Tue, Sep 15, 2:56 PM · VyOS 1.3 Equuleus
jestabro triaged T2885: configd: print commit errors to config session terminal as Normal priority.
Tue, Sep 15, 2:56 PM · VyOS 1.3 Equuleus
sempervictus created T2884: Upstream Kernel Patches from Semper Victus Linux Hardened Tree.
Tue, Sep 15, 1:39 PM · VyOS 1.3 Equuleus
jestabro added a comment to T2865: boot problem beginning with VyOS 1.3-rolling-202009011736.

@querubin thanks for the info; that requirement should not persist, as current work should lessen the overhead. I'll link the task back here when defined.

Tue, Sep 15, 1:10 PM · VyOS 1.3 Equuleus
Viacheslav added a comment to T2882: DHCP client on bond interfaces not working.

I think it was a bug with virtio drivers and bonding.

Tue, Sep 15, 9:56 AM · VyOS 1.3 Equuleus
Viacheslav added a comment to T2882: DHCP client on bond interfaces not working.

I can't reproduce it

Tue, Sep 15, 8:58 AM · VyOS 1.3 Equuleus
querubin added a comment to T2865: boot problem beginning with VyOS 1.3-rolling-202009011736.

Tried the latest rolling. It boots/runs if you give it 768MB of memory.
At 512MB it hangs as before. I guess minimum requirements will be
changing.

Tue, Sep 15, 8:39 AM · VyOS 1.3 Equuleus

Mon, Sep 14

syncer renamed T2883: op-mode reset vpn command shows wrong completion from Reset vpn commands show wrong complation to op-mode reset vpn command shows wrong completion.
Mon, Sep 14, 9:37 PM · VyOS 1.2 Crux
Dmitry created T2883: op-mode reset vpn command shows wrong completion.
Mon, Sep 14, 9:13 PM · VyOS 1.2 Crux
c-po changed the status of T2882: DHCP client on bond interfaces not working from Open to Confirmed.
Mon, Sep 14, 6:16 PM · VyOS 1.3 Equuleus
c-po created T2882: DHCP client on bond interfaces not working.
Mon, Sep 14, 6:16 PM · VyOS 1.3 Equuleus
jestabro added a comment to T2865: boot problem beginning with VyOS 1.3-rolling-202009011736.

@querubin Thank you for the detailed results --- firstly, these issues may be overdetermined due to several updates earlier this month; one notable issue is that we had moved to a 5.x series kernel, which showed several problems re QAT support, and an identified kernel bug. We have reverted to 4.19 as of yesterday until the next LTS kernel is available. I would suggest trying the most recent rolling, and then we will diagnose any persistent issues.

Mon, Sep 14, 4:06 PM · VyOS 1.3 Equuleus
banditos13 added a comment to T2881: Bug in weigt calculation for failover mode.

In failover mode only one active channel with "best parameters" can by used for connections

Mon, Sep 14, 3:03 PM · VyOS 1.3 Equuleus
Viacheslav added a comment to T2881: Bug in weigt calculation for failover mode.

@banditos13 Can you describe more details?
What is the bug and how to reproduce it?

Mon, Sep 14, 2:09 PM · VyOS 1.3 Equuleus
Viacheslav closed T2301: Delete PBR vyatta_policy_ref as Resolved.

Was fixed with https://phabricator.vyos.net/R6:0ecfe5a6d11065388714b0ef21de532f88774357 and T1241

Mon, Sep 14, 2:01 PM · VyOS 1.3 Equuleus
Viacheslav added a comment to T2868: Tcp-mss option in policy calls kernel-panic.
Mon, Sep 14, 10:36 AM · VyOS 1.3 Equuleus
banditos13 created T2881: Bug in weigt calculation for failover mode.
Mon, Sep 14, 8:18 AM · VyOS 1.3 Equuleus
Viacheslav added a comment to T2868: Tcp-mss option in policy calls kernel-panic.

Still present in the latest rolling

Mon, Sep 14, 7:47 AM · VyOS 1.3 Equuleus
Viacheslav added a comment to T2874: Add MTU and TCP-MSS discovery tool.

PR https://github.com/vyos/vyos-1x/pull/545

Mon, Sep 14, 7:30 AM · VyOS 1.3 Equuleus
c-po closed T2880: Update Linux Kernel to v4.19.145 as Resolved.
Mon, Sep 14, 6:11 AM · VyOS 1.3 Equuleus
c-po closed T2879: Cleanup 4.19.144 kernel configuration as Resolved.
Mon, Sep 14, 6:11 AM · VyOS 1.3 Equuleus
c-po closed T2864: Wireguard IPv6 Link-Local Addresses Cannot Be Disabled as Invalid.
Mon, Sep 14, 3:42 AM · VyOS 1.3 Equuleus
c-po added a comment to T2864: Wireguard IPv6 Link-Local Addresses Cannot Be Disabled.

Fixed together with T2863 in commit https://github.com/vyos/vyos-1x/commit/d49845421dbd8d0f470b7122022543eb45d10b7a

Mon, Sep 14, 3:41 AM · VyOS 1.3 Equuleus
c-po closed T2872: "Show log" for nat and openvpn got inter-mixed as Resolved.
Mon, Sep 14, 3:39 AM · VyOS 1.3 Equuleus