Feed All Stories

Yesterday

DR_D_WEB updated the task description for T429: Pi-Hole or similar feature.
Sun, Oct 22, 9:54 PM · VyOS 2.0.x
syncer moved T52: Q26 pull request seems to be tested at least. from Backlog to Finished on the VyOS 1.1.x (1.1.8) board.
Sun, Oct 22, 8:31 PM · VyOS 1.1.x (1.1.8)
UnicronNL closed T52: Q26 pull request seems to be tested at least. as Resolved.

added to helium branch

Sun, Oct 22, 8:28 PM · VyOS 1.1.x (1.1.8)
UnicronNL moved T410: dnsmasq in 1.1.x is outdated and vulnerable to many CVEs from Backlog to Finished on the VyOS 1.1.x (1.1.8) board.
Sun, Oct 22, 8:17 PM · VyOS 1.1.x (1.1.8), VyOS 1.2.x
syncer moved T354: Outstanding CVEs - StrongSwan from In Progress to Finished on the VyOS 1.1.x (1.1.8) board.
Sun, Oct 22, 8:15 PM · vyatta-strongswan, VyOS 1.1.x (1.1.8)
UnicronNL closed T354: Outstanding CVEs - StrongSwan as Resolved.
Sun, Oct 22, 8:14 PM · vyatta-strongswan, VyOS 1.1.x (1.1.8)
DR_D_WEB triaged T429: Pi-Hole or similar feature as Wishlist priority.
Sun, Oct 22, 7:11 PM · VyOS 2.0.x
DR_D_WEB created T429: Pi-Hole or similar feature.
Sun, Oct 22, 2:49 PM · VyOS 2.0.x

Sat, Oct 21

dmbaturin added a comment to T428: Current 1.1.7 AMI doesn't fetch SSH public key from the EC2 environment.

An AMI updated by hand was submitted to Amazon for testing.

Sat, Oct 21, 11:47 AM · VyOS 1.2.x, VyOS 1.1.x
dmbaturin created T428: Current 1.1.7 AMI doesn't fetch SSH public key from the EC2 environment.
Sat, Oct 21, 11:47 AM · VyOS 1.2.x, VyOS 1.1.x

Fri, Oct 20

syncer reassigned T385: Integrate pmacct 1.6+ into the current branch from dmbaturin to UnicronNL.

@UnicronNL can you pickup this from @dmbaturin

Fri, Oct 20, 10:16 PM · pmacct, VyOS 1.2.x
syncer added a comment to T46: Add support for extended community lists..

@dmbaturin tells that this does not work as expected
so i suggest reopen this task

Fri, Oct 20, 10:20 AM · VyOS 1.2.x

Thu, Oct 19

sebastianm awarded T426: CVE-2017-13077 - Update wpa_supplicant a Like token.
Thu, Oct 19, 12:03 PM · wpa, VyOS 2.0.x, VyOS 1.2.x, VyOS 1.1.x
higebu added a comment to T164: Create image for MicroSoft Azure.
Thu, Oct 19, 9:08 AM · VyOS 1.2.x, Hyper-V/Azure Support
MoyHaj added a comment to T164: Create image for MicroSoft Azure.

Hi, can you please share the VHD file as well?

Thu, Oct 19, 1:34 AM · VyOS 1.2.x, Hyper-V/Azure Support

Wed, Oct 18

mpoublon added a comment to T407: BGP type 2 length 3294 is too large, attribute total length is 2303. attr_endp is 0x7f9e0bbb56cd. endp is 0x7f9e0bbb52e6.

The proposed "maximum-paths" looks to set the maximum number of paths for equal cost routing and not limit the long AS path that causes the noted log entry. I used the following in a production network to work around the issue:

Wed, Oct 18, 9:02 PM · VyOS 1.2.x, VyOS 1.1.x
TomekC added a comment to T14: Provide VMware OVF and OVA.

VyOS version 1.1.7 works very well with vmware and with network card vmxnet3, but for high performance on that platform you need do some system tunning.
Have you got any plan to add that performance tunning to default vmware image?

Wed, Oct 18, 7:25 AM · VyOS 1.2.x
panachoi triaged T427: Wireguard support as Wishlist priority.
Wed, Oct 18, 6:40 AM · VyOS 2.0.x
panachoi created T427: Wireguard support.
Wed, Oct 18, 6:40 AM · VyOS 2.0.x
dsummers added a comment to T149: IPv6 support in OpenVPN tunnel.

Latest version of OpenVPN is 2.4.4 and has multiple new features.

Wed, Oct 18, 3:53 AM · VyOS 1.2.x

Tue, Oct 17

sebastianm added a comment to T417: Allow bonding non-ethernet interfaces.

I tried to get this working on a good known OpenVPN TAP configuration. I can confirm that it's flaky and will require additional debugging.

Tue, Oct 17, 6:09 PM · VyOS 1.2.x
marcello.lodi added a watcher for VyOS 2.0.x: marcello.lodi.
Tue, Oct 17, 4:56 PM
marcello.lodi removed a watcher for VyOS 2.0.x: marcello.lodi.
Tue, Oct 17, 4:55 PM
marcello.lodi added a watcher for VyOS 2.0.x: marcello.lodi.
Tue, Oct 17, 4:55 PM
mickvav created T426: CVE-2017-13077 - Update wpa_supplicant.
Tue, Oct 17, 5:36 AM · wpa, VyOS 2.0.x, VyOS 1.2.x, VyOS 1.1.x

Mon, Oct 16

mmateuslima added a comment to T407: BGP type 2 length 3294 is too large, attribute total length is 2303. attr_endp is 0x7f9e0bbb56cd. endp is 0x7f9e0bbb52e6.
  1. set protocols bgp 262766 maximum-paths ebgp 75
Mon, Oct 16, 4:30 PM · VyOS 1.2.x, VyOS 1.1.x
dmbaturin added a comment to T142: DSA-3659-1.

Thanks, I'm looking at it now.

Mon, Oct 16, 9:24 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
genta added a comment to T142: DSA-3659-1.

Hello,
I've just sent a pull-request related for this topic.
Please check them when you have time.

Mon, Oct 16, 9:20 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
llluuu added a watcher for VyOS 2.0.x: llluuu.
Mon, Oct 16, 8:10 AM

Sun, Oct 15

syncer edited projects for T14: Provide VMware OVF and OVA, added: VyOS 1.2.x; removed VyOS 1.1.x (1.1.8).

Moving this to 1.2 branch
lets implement changes proposed earlier

Sun, Oct 15, 9:16 PM · VyOS 1.2.x
shidiq added a comment to T407: BGP type 2 length 3294 is too large, attribute total length is 2303. attr_endp is 0x7f9e0bbb56cd. endp is 0x7f9e0bbb52e6.

i still confuse how to patch it, please explain more. thanks

Sun, Oct 15, 9:32 AM · VyOS 1.2.x, VyOS 1.1.x

Sat, Oct 14

mmateuslima added a comment to T407: BGP type 2 length 3294 is too large, attribute total length is 2303. attr_endp is 0x7f9e0bbb56cd. endp is 0x7f9e0bbb52e6.

No, I got the patch for this patch, how should I proceed? I have some sessions with this problem.

Sat, Oct 14, 4:19 PM · VyOS 1.2.x, VyOS 1.1.x

Fri, Oct 13

syncer triaged T425: AWS CloudWatch monitoring scripts as Wishlist priority.
Fri, Oct 13, 12:01 PM · AWS Support, VyOS 1.2.x
syncer moved T425: AWS CloudWatch monitoring scripts from Need Triage to Backlog on the VyOS 1.2.x board.
Fri, Oct 13, 12:01 PM · AWS Support, VyOS 1.2.x
syncer created T425: AWS CloudWatch monitoring scripts.
Fri, Oct 13, 12:01 PM · AWS Support, VyOS 1.2.x
Zer0t3ch added a comment to T421: VyOS lacks DHCPv6-PD (Prefix delegation) length / IA_PD support.

This is definitely very important. I'm on AT&T UVerse, and I can't plausibly use VyOS for my network without support for DHCPv6-PD. I don't even need auto-configuration of RAs on the LAN ports if that would be difficult, but I at least need the support to request the prefixes in order to get them routed to my internal router.

Fri, Oct 13, 11:09 AM · VyOS 1.2.x
sebastianm updated the task description for T424: Advertisement of Multiple Paths in BGP (capability 69).
Fri, Oct 13, 10:55 AM · VyOS 1.2.x
sebastianm created T424: Advertisement of Multiple Paths in BGP (capability 69).
Fri, Oct 13, 10:55 AM · VyOS 1.2.x
c-po added a comment to T337: 'show vpn ipsec sa' output wrong when remote or local prefix not in system subnet.

@syncer this was actually done by @JulesT. Thank you @JulesT.

Fri, Oct 13, 7:41 AM · VyOS 1.2.x

Thu, Oct 12

dmbaturin created T423: No completion for uncommited IKE and ESP groups.
Thu, Oct 12, 11:32 PM · VyOS 1.1.x (1.1.8)
sebastianm added a comment to T417: Allow bonding non-ethernet interfaces.

Also, it doesn't seem to work because vtun0 is not coming up -- but that seems to be related to my specific config.

Thu, Oct 12, 10:09 PM · VyOS 1.2.x
sebastianm added a comment to T417: Allow bonding non-ethernet interfaces.

Well, I'd like to use bonding with round-robin load balancing over two VDSL2 uplinks to same provider with the same latency (my ISP wants a business account for MLPPP).

Thu, Oct 12, 10:08 PM · VyOS 1.2.x
EwaldvanGeffen added a comment to T375: WAN failover, not to balance the load.

Run tcpdump on your WAN with filter ICMP to confirm probing goes haywire; should be pretty easy to spot as you employed four different targets.

Thu, Oct 12, 10:07 PM · VyOS 1.2.x
dmbaturin added a comment to T417: Allow bonding non-ethernet interfaces.

The only remotely sensible use case I can see is active/standby bonding of L2 VPNs to provide redundant paths. But then again, the real answer to this is distributed switches such as openvswitch.

Thu, Oct 12, 9:57 PM · VyOS 1.2.x
EwaldvanGeffen added a comment to T417: Allow bonding non-ethernet interfaces.

I've tried to attain this holy grail of combining VPNs to gain a faster more reliable link. Although my environment where multiple consumer WAN links with different specs. Yours seem to be more uniform/easier to handle so you might get away easier.

Thu, Oct 12, 9:48 PM · VyOS 1.2.x
dmbaturin added a comment to T87: VTI interface and BGP update-source bug.

BGP configuration is definitely loaded after VTI configuration is loaded.

Thu, Oct 12, 9:32 PM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
beamerblvd added a comment to T421: VyOS lacks DHCPv6-PD (Prefix delegation) length / IA_PD support.

@syncer, yep, looks like that is the Deb package for https://roy.marples.name/projects/dhcpcd. This is the client that Daniel Corbe and I had recommended be switched to.

Thu, Oct 12, 7:18 PM · VyOS 1.2.x
syncer added a comment to T421: VyOS lacks DHCPv6-PD (Prefix delegation) length / IA_PD support.

Thanks for transfering this.
it looks like good candidate
https://packages.debian.org/jessie/dhcpcd5
@dmbaturin already looked at it last year, but it seems it was without pd support than
Now, however, it looks like they added support for it and we maybe should consider it as main candidate

Thu, Oct 12, 6:43 PM · VyOS 1.2.x
syncer removed a project from T33: Add support for ipt-netflow, a faster/high performance Netflow collector: VyOS 1.1.x (1.1.8).
Thu, Oct 12, 10:46 AM
sebastianm added a comment to T417: Allow bonding non-ethernet interfaces.

Looks like it works! I've added a static route for 8.8.4.4 to the OVH gateway (that's being routed to the bond0 interface with interface-route) and I can ping it :^)

Thu, Oct 12, 10:01 AM · VyOS 1.2.x
sebastianm added a comment to T417: Allow bonding non-ethernet interfaces.

I've copied it and I can set bond-group on the OpenVPN interface. I'll check if it actually works in a minute.

Thu, Oct 12, 9:39 AM · VyOS 1.2.x
sebastianm added a comment to T109: VyOS Can Loose Parts Of Its Config On Reboot - In Certain Situations.

This also happens with the DHCP server configuration if the DHCP subnet is different than the one used on the LAN interface (when it's configured with VRRP by following the VRRP tutorial on the VyOS wiki).

Thu, Oct 12, 9:38 AM · VyOS 1.2.x
syncer assigned T87: VTI interface and BGP update-source bug to dmbaturin.
Thu, Oct 12, 8:10 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
syncer moved T191: Add route-map set as-path exclude option from Needs Triage to Finished on the VyOS 1.1.x (1.1.8) board.
Thu, Oct 12, 7:44 AM · VyOS 1.1.x (1.1.8)
syncer moved T202: Cannot apply qos to l2tpv3 and dummy links from Need Triage to Finished on the VyOS 1.2.x board.
Thu, Oct 12, 7:43 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
syncer moved T202: Cannot apply qos to l2tpv3 and dummy links from Backlog to Finished on the VyOS 1.1.x (1.1.8) board.
Thu, Oct 12, 7:43 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
syncer added a project to T202: Cannot apply qos to l2tpv3 and dummy links: VyOS 1.2.x.
Thu, Oct 12, 7:43 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
syncer moved T64: Add support for named {,extended} community-lists from Backlog to Finished on the VyOS 1.1.x (1.1.8) board.
Thu, Oct 12, 7:42 AM · VyOS 1.1.x (1.1.8)
syncer moved T204: Merge fix for clustering bug "vyatta-cluster: wait for link up on clustering for up to 10 seconds" in 1.1.8 from In Progress to Finished on the VyOS 1.1.x (1.1.8) board.
Thu, Oct 12, 7:42 AM · VyOS 1.1.x (1.1.8)
syncer added a comment to T373: incorporate cloud-init development into main project.

@higebu already have images with it, because we phase out 1.1.x i think it should be ok

Thu, Oct 12, 7:41 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
syncer moved T198: l2tpv3 instance not reconfigured when changing session-id or tunnel-id parameters from Needs Triage to Finished on the VyOS 1.1.x (1.1.8) board.
Thu, Oct 12, 7:40 AM · VyOS 1.1.x (1.1.8)
syncer moved T199: openVPN client/server bridge : need to specify server subnet. from Need Triage to Finished on the VyOS 1.2.x board.
Thu, Oct 12, 7:39 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
syncer added a project to T199: openVPN client/server bridge : need to specify server subnet.: VyOS 1.2.x.
Thu, Oct 12, 7:39 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
syncer moved T199: openVPN client/server bridge : need to specify server subnet. from Needs Triage to Finished on the VyOS 1.1.x (1.1.8) board.
Thu, Oct 12, 7:38 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
dmbaturin closed T199: openVPN client/server bridge : need to specify server subnet. as Resolved.

Fixed in both 1.1.8 and current.

Thu, Oct 12, 6:18 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
dmbaturin renamed T198: l2tpv3 instance not reconfigured when changing session-id or tunnel-id parameters from l2tpv3 instance not reconfigured when changing parameters to l2tpv3 instance not reconfigured when changing session-id or tunnel-id parameters .
Thu, Oct 12, 5:53 AM · VyOS 1.1.x (1.1.8)
dmbaturin closed T198: l2tpv3 instance not reconfigured when changing session-id or tunnel-id parameters as Resolved.

Well spotted! Fixed the typos.

Thu, Oct 12, 5:51 AM · VyOS 1.1.x (1.1.8)
dmbaturin added a comment to T373: incorporate cloud-init development into main project.

Should we add it to 1.1.8? It's a pretty big change, I'm not sure if it should be in a maintenance rather than a major release.

Thu, Oct 12, 5:38 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
dmbaturin closed T204: Merge fix for clustering bug "vyatta-cluster: wait for link up on clustering for up to 10 seconds" in 1.1.8 as Resolved.

The commit is indeed in helium now.

Thu, Oct 12, 5:36 AM · VyOS 1.1.x (1.1.8)
dmbaturin closed T64: Add support for named {,extended} community-lists as Resolved.

Imported it to 1.1.8: https://github.com/vyos/vyatta-cfg-quagga/commit/973afef2f599538ccda19a2befcf16e6730eaad2

Thu, Oct 12, 5:32 AM · VyOS 1.1.x (1.1.8)
dmbaturin closed T202: Cannot apply qos to l2tpv3 and dummy links as Resolved.

That commit was in helium as well, but the real issue was in the debian install file: those paths were missing from it, so templates were generated but not included in the package.

Thu, Oct 12, 5:30 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
dmbaturin renamed T202: Cannot apply qos to l2tpv3 and dummy links from Cannot apply qos to l2tpv3 links to Cannot apply qos to l2tpv3 and dummy links.
Thu, Oct 12, 5:27 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
dmbaturin closed T191: Add route-map set as-path exclude option as Resolved.

Imported into 1.1.8

Thu, Oct 12, 5:18 AM · VyOS 1.1.x (1.1.8)
tdale added a comment to T397: SNMPd - High load, doesnt work..

Works in nightly built but now Netflow is broken in the nightly build :(

Thu, Oct 12, 2:22 AM · VyOS 1.1.x

Wed, Oct 11

syncer moved T358: add option to set phabricator api token from In Progress to Finished on the VyOS 1.1.x (1.1.8) board.
Wed, Oct 11, 11:08 PM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
syncer moved T329: add phabricator.vyos.net paste app as valid destination for show tech-support save-uncompressed from In Progress to Finished on the VyOS 1.1.x (1.1.8) board.
Wed, Oct 11, 11:08 PM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
syncer added a comment to T373: incorporate cloud-init development into main project.

@higebu can you add it for 1.1.8 (along with all required software like awscli) into 1.1.8 please

Wed, Oct 11, 10:15 PM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
syncer assigned T328: review output for show tech-support command to c-po.

@c-po i will agree with your approach
i will ask to keep package versions output

Wed, Oct 11, 10:11 PM · VyOS 1.1.x (1.1.8), VyOS 1.2.x
syncer moved T328: review output for show tech-support command from Need Triage to Backlog on the VyOS 1.2.x board.
Wed, Oct 11, 10:10 PM · VyOS 1.1.x (1.1.8), VyOS 1.2.x
syncer moved T328: review output for show tech-support command from Needs Triage to Backlog on the VyOS 1.1.x (1.1.8) board.
Wed, Oct 11, 10:10 PM · VyOS 1.1.x (1.1.8), VyOS 1.2.x
syncer moved T410: dnsmasq in 1.1.x is outdated and vulnerable to many CVEs from Needs Triage to Backlog on the VyOS 1.1.x (1.1.8) board.
Wed, Oct 11, 10:09 PM · VyOS 1.1.x (1.1.8), VyOS 1.2.x
syncer added a project to T408: Improve the AMI build scripts: AWS Support.
Wed, Oct 11, 10:08 PM · AWS Support, VyOS 1.1.x, build-ami, VyOS 1.2.x
syncer updated the task description for T408: Improve the AMI build scripts.
Wed, Oct 11, 10:07 PM · AWS Support, VyOS 1.1.x, build-ami, VyOS 1.2.x
syncer moved T408: Improve the AMI build scripts from Need Triage to In Progress on the VyOS 1.2.x board.
Wed, Oct 11, 10:06 PM · AWS Support, VyOS 1.1.x, build-ami, VyOS 1.2.x
syncer moved T408: Improve the AMI build scripts from Need Triage to In Progress on the VyOS 1.1.x board.
Wed, Oct 11, 10:06 PM · AWS Support, VyOS 1.1.x, build-ami, VyOS 1.2.x
syncer edited projects for T408: Improve the AMI build scripts, added: VyOS 1.1.x; removed VyOS 1.1.x (1.1.8).
Wed, Oct 11, 10:06 PM · AWS Support, VyOS 1.1.x, build-ami, VyOS 1.2.x
syncer reassigned T142: DSA-3659-1 from higebu to UnicronNL.

@UnicronNL can you add

Wed, Oct 11, 10:05 PM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
syncer closed T219: Disable sync driver in open-vm-tools to avoid problems with snapshots as Resolved.
Wed, Oct 11, 10:02 PM · VyOS 1.1.x (1.1.8), open-vm-tools
syncer moved T232: Install fails if hard drive previously contained GPT label from Need Triage to Backlog on the VyOS 1.2.x board.
Wed, Oct 11, 9:41 PM · VyOS 1.2.x, VyOS 1.1.x
syncer moved T232: Install fails if hard drive previously contained GPT label from Need Triage to Backlog on the VyOS 1.1.x board.
Wed, Oct 11, 9:41 PM · VyOS 1.2.x, VyOS 1.1.x
syncer added a comment to T232: Install fails if hard drive previously contained GPT label.

@UnicronNL or better add this to installer part

Wed, Oct 11, 9:41 PM · VyOS 1.2.x, VyOS 1.1.x
syncer edited projects for T109: VyOS Can Loose Parts Of Its Config On Reboot - In Certain Situations, added: VyOS 1.2.x; removed VyOS 1.1.x.

Assuming that 1.2 affected in same way,
moving it to 1.2 and suggest work on fix there

Wed, Oct 11, 9:40 PM · VyOS 1.2.x
syncer closed T244: Issue with recursive static routing as Wontfix.
Wed, Oct 11, 9:38 PM · VyOS 1.1.x
syncer reassigned T252: [Revise] Bug 183 - VTI will not be up automatic when IPsec SA up. from syncer to dmbaturin.

@dmbaturin now as we have bugzilla back, can you check this one ?

Wed, Oct 11, 9:36 PM · VyOS 1.2.x, VyOS 1.1.x
syncer assigned T332: Keepalived Race Condition with Keepalived 1.2.2 on Vyos 1.1.7 to dmbaturin.

@dmbaturin can we update keepalived to fresh version in 1.1.x
or should we drop mark this as wontfix in 1.1.x?

Wed, Oct 11, 9:07 PM · VyOS 1.1.x
syncer moved T337: 'show vpn ipsec sa' output wrong when remote or local prefix not in system subnet from Need Triage to Backlog on the VyOS 1.2.x board.
Wed, Oct 11, 9:04 PM · VyOS 1.2.x
syncer edited projects for T337: 'show vpn ipsec sa' output wrong when remote or local prefix not in system subnet, added: VyOS 1.2.x; removed VyOS 1.1.x.

Moving this to 1.2 than.
Let's fix it there

Wed, Oct 11, 9:04 PM · VyOS 1.2.x
JulesT added a comment to T337: 'show vpn ipsec sa' output wrong when remote or local prefix not in system subnet.

Certainly not fixed in 1.1.x - but I'll see what I can do with it. 1.2 has such completely different handling that I couldn't even guess what it does. I'll have to work out a lab to reproduce it. Might get to it at the weekend.

Wed, Oct 11, 9:02 PM · VyOS 1.2.x
beamerblvd added a comment to T422: Packages server and downloads should be available via HTTPS.
In T422#8426, @syncer wrote:

Should we just add letsencrypt ?

Wed, Oct 11, 9:02 PM · Infrastructure
syncer edited projects for T336: OSPF Neighbor Flapping, added: VyOS 1.2.x; removed VyOS 1.1.x.

Will recommend retest with 1.2 nightlies

Wed, Oct 11, 8:58 PM · VyOS 1.2.x