Feed All Stories

Today

runar added a comment to T786: new style xml and conf-mode scripts: posibillity to add tagNode value as parameter to conf-script.

To do the same example as it is running in the current-rolling devel i have reverted my patch:

Sat, Aug 18, 7:11 PM · VyOS 1.2.x
runar added a comment to T786: new style xml and conf-mode scripts: posibillity to add tagNode value as parameter to conf-script.

The current implementation of the config interpretor does not work that way.
It is correct that your config script needs to take account of all added/removed config within your tagNode, but the script will actually run once for every tagNode instance you define.
let me take an easy example:

Sat, Aug 18, 6:56 PM · VyOS 1.2.x
hagbard added a comment to T786: new style xml and conf-mode scripts: posibillity to add tagNode value as parameter to conf-script.

I'm not sure if I did understand the issue correctly, however I don't think it's a good idea. Tag nodes can be nested and you need to figure out if a change happened anyway, so the script runs only once anyway.
Since you mention wireguard, let take me that as an example.

Sat, Aug 18, 5:35 PM · VyOS 1.2.x
hagbard closed T750: Hostname defaults to "debian" after applying rolling update as Resolved.

Tested it today again with 1.2.0-rolling+201808181101, no issues anymore.

Sat, Aug 18, 4:57 PM · VyOS 1.2.x
syncer moved T783: implement persistent-keepalive for wireguard from Needs Triage to Finished on the VyOS 1.2.x (VyOS 1.2.0-rc1) board.
Sat, Aug 18, 3:49 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard closed T783: implement persistent-keepalive for wireguard as Resolved.
Sat, Aug 18, 3:47 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard closed T783: implement persistent-keepalive for wireguard, a subtask of T427: Wireguard support, as Resolved.
Sat, Aug 18, 3:47 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
msbone added a comment to T377: DHCP-relay agent package replacement.

A newer version of isc-dhcrelay should solve this. Tested by installing 4.3.5 on rolling

Sat, Aug 18, 3:47 PM · VyOS 1.2.x
runar added a comment to T787: DMVPN on 1.2.0.

after intense searching i came across this:

Sat, Aug 18, 10:52 AM · VyOS 1.2.x
runar created T787: DMVPN on 1.2.0.
Sat, Aug 18, 9:16 AM · VyOS 1.2.x
c-po added a comment to T782: Cleanup dhcp-server configuration.

If we'd use

range {
    start 172.16.0.1
    stop 172.16.0.250
}

this would be transparent for IPv4 and IPv6

Sat, Aug 18, 9:07 AM · VyOS 1.2.x
c-po moved T782: Cleanup dhcp-server configuration from Need Triage to In Progress on the VyOS 1.2.x board.
Sat, Aug 18, 9:06 AM · VyOS 1.2.x

Yesterday

runar created T786: new style xml and conf-mode scripts: posibillity to add tagNode value as parameter to conf-script.
Fri, Aug 17, 11:25 PM · VyOS 1.2.x
hagbard added a comment to T427: Wireguard support.

Found a possible bug when you remove keppalive, the wg device show still as configured with keepalive, I have to check if that is actually true and if so I need to ping upstream and let them know.

Fri, Aug 17, 10:06 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard changed the status of T779: adding /etc/modprobe/wireguard.conf to https://github.com/vyos/vyos-wireguard from Open to In progress.
Fri, Aug 17, 7:49 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard changed the status of T779: adding /etc/modprobe/wireguard.conf to https://github.com/vyos/vyos-wireguard, a subtask of T427: Wireguard support, from Open to In progress.
Fri, Aug 17, 7:49 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard added a comment to T427: Wireguard support.

T783 and making endpoint optional is currently reviewed by the maintainers.

Fri, Aug 17, 7:48 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard changed the status of T783: implement persistent-keepalive for wireguard from Open to In progress.
Fri, Aug 17, 7:36 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard changed the status of T783: implement persistent-keepalive for wireguard, a subtask of T427: Wireguard support, from Open to In progress.
Fri, Aug 17, 7:36 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
c-po updated the task description for T782: Cleanup dhcp-server configuration.
Fri, Aug 17, 7:33 PM · VyOS 1.2.x
c-po updated the task description for T782: Cleanup dhcp-server configuration.
Fri, Aug 17, 7:26 PM · VyOS 1.2.x
c-po updated the task description for T782: Cleanup dhcp-server configuration.
Fri, Aug 17, 7:16 PM · VyOS 1.2.x
vas-ast added a comment to T427: Wireguard support.

@hagbard
Good. There is no urgency.

Fri, Aug 17, 6:45 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
alkersan changed the status of T784: Bring back update dns dynamic operation from Open to In progress.
Fri, Aug 17, 6:43 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard triaged T783: implement persistent-keepalive for wireguard as Normal priority.
Fri, Aug 17, 6:33 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard added a comment to T427: Wireguard support.

@vast-ast
Already fixed in my branch, since it's a minor change. I have the keepalive option on my plate as well as the show command. I was just on vacation for a week and didn't have much time to contribute. How urgent do you need persistent-keepalive?

Fri, Aug 17, 6:32 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
c-po created T782: Cleanup dhcp-server configuration.
Fri, Aug 17, 5:49 PM · VyOS 1.2.x
vas-ast added a comment to T427: Wireguard support.

@hagbard
This is not critical, but it would be convenient to save the tun interface without specifying a peer. Now validation does not allow this. One of the cases, when we prepared the server, and then we automate the addition and removal of the peer (my case), or we want to do this later for some other reason.

Fri, Aug 17, 4:47 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard reassigned T774: write wiki documentation from hagbard to mrjones.

Let me know if you need any help with it or have any questions.
I'm going to change the endpoint parameter to an optional parameter.
https://www.wireguard.com/#conceptual-overview may help you as well.

Fri, Aug 17, 4:34 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard updated subscribers of T779: adding /etc/modprobe/wireguard.conf to https://github.com/vyos/vyos-wireguard.

https://github.com/vyos/vyos-wireguard is just copied, not forked. Anything else inside is/was unmodified. I can had 3 lines to have the module loaded at boot time, but in general I don't feel very happy with the package and it's maintenance.
How do you usually backport packages in general and track patches and the such?
Should it be re-debianized and produce the vyos-wireguard-tools etc. instead of wireguard-tools?
Who is maintaining it, like adding the patches, testing etc.?

Fri, Aug 17, 4:32 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
hagbard added a comment to T427: Wireguard support.

Thx @vas-ast, it's not only when you run via NAT, it's in general if you act as the server. I'm going to fix that, that was the first implementation I was happy to have that release to the public. Your input is always valuable, so if you find more, please don't hesitate to report here.
Thanks again.

Fri, Aug 17, 4:24 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
mrjones added a comment to T774: write wiki documentation.

I would like to contribute

Fri, Aug 17, 12:42 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
vas-ast added a comment to T427: Wireguard support.
In T427#17621, @hagbard wrote:

All right pull request opened. I'm going to enhance a few parts, like the endpoint format check, show status etc., but as mentioned above I won't have much time next week and it seemed everyone needed it quickly.
I've rebuilt the iso, rebuilt vyos-1x and used the follwing config:

host01:

set interfaces wireguard wg01 address '10.2.2.1/24'
set interfaces wireguard wg01 description 'wg02-test'
set interfaces wireguard wg01 listen-port '12345'
set interfaces wireguard wg01 peer 7QQU75St+Kr4+B097E7qzMv0PbBtbvLCyGCpTwRxBEI= allowed-ips '10.1.1.0/24'
set interfaces wireguard wg01 peer 7QQU75St+Kr4+B097E7qzMv0PbBtbvLCyGCpTwRxBEI= endpoint '192.168.0.130:12345'
set protocols static interface-route 10.1.1.0/24 next-hop-interface wg01

host02:
set interfaces wireguard wg01 address '10.1.1.1/24'
set interfaces wireguard wg01 description 'wg01-test'
set interfaces wireguard wg01 listen-port '12345'
set interfaces wireguard wg01 peer z80pwzfFfwfte3p06iIVVBDPfUL+MSH0dL9I33nJzTo= allowed-ips '10.2.2.0/24'
set interfaces wireguard wg01 peer z80pwzfFfwfte3p06iIVVBDPfUL+MSH0dL9I33nJzTo= endpoint '192.168.0.113:12345'
set protocols static interface-route 10.2.2.0/24 next-hop-interface wg01

You'll need:
https://github.com/vyos/vyos-1x/pull/27/files
https://github.com/vyos/vyos-build/pull/22

and the config above. You can add multiple endpoints and peers to a wg device, or multiple wg devices with single or multiple peers. So far all working as long as you set your route. I did basic IPv6 tests as well, ss the main functionality should be working well.
I'm going to open a subtask for documentation, I need to create first an account for the wiki etc.

Fri, Aug 17, 12:18 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
shadowyw created T781: VyOS 1.2 does not work with AWS VPN gateway, but some configuration works fine on VyOS 1.1.8.
Fri, Aug 17, 11:08 AM · VyOS 1.2.x

Thu, Aug 16

binaryanomaly added a comment to T750: Hostname defaults to "debian" after applying rolling update.

@hagbard I don't have a running vyos instance where I could verify immediately. But if it's not reproduceable anymore by following the steps I described then I'd assume it's fixed?

Thu, Aug 16, 6:20 PM · VyOS 1.2.x

Wed, Aug 15

hagbard added a comment to T750: Hostname defaults to "debian" after applying rolling update.

@binaryanomaly
Hi, is that still an issue? I tried to reproduce it today and used all of the August rolling images, but can't reproduce it anymore.

Wed, Aug 15, 4:50 PM · VyOS 1.2.x
hagbard triaged T779: adding /etc/modprobe/wireguard.conf to https://github.com/vyos/vyos-wireguard as Normal priority.
Wed, Aug 15, 4:34 PM · VyOS 1.2.x (VyOS 1.2.0-rc1)
c-po moved T419: Support setting dstport for VXLAN interfaces from In Progress to Backlog on the VyOS 1.2.x board.
Wed, Aug 15, 9:54 AM · VyOS 1.2.x
c-po moved T778: Rewrite 'service dhcp-server' in new XML style format from Need Triage to In Progress on the VyOS 1.2.x board.
Wed, Aug 15, 9:54 AM · VyOS 1.2.x
c-po changed the status of T778: Rewrite 'service dhcp-server' in new XML style format from Open to In progress.
Wed, Aug 15, 9:54 AM · VyOS 1.2.x
c-po created T778: Rewrite 'service dhcp-server' in new XML style format.
Wed, Aug 15, 9:54 AM · VyOS 1.2.x
c-po reopened T776: Update VyOS Kernel to latest 4.14.62 as "In progress".
Wed, Aug 15, 9:52 AM · VyOS 1.2.x (VyOS 1.2.0-rc1)
c-po reopened T702: set system flow-accounting netflow source-ip failed as "In progress".
Wed, Aug 15, 9:52 AM · VyOS 1.2.x (VyOS 1.2.0-rc1)
c-po closed T702: set system flow-accounting netflow source-ip failed as Resolved.
Wed, Aug 15, 9:51 AM · VyOS 1.2.x (VyOS 1.2.0-rc1)
c-po closed T776: Update VyOS Kernel to latest 4.14.62 as Resolved.
Wed, Aug 15, 9:50 AM · VyOS 1.2.x (VyOS 1.2.0-rc1)
c-po moved T776: Update VyOS Kernel to latest 4.14.62 from In Progress to Finished on the VyOS 1.2.x board.
Wed, Aug 15, 9:50 AM · VyOS 1.2.x (VyOS 1.2.0-rc1)
mpoublon updated the task description for T777: Misleading Help Text for IPSEC Connection Type.
Wed, Aug 15, 3:15 AM · VyOS 1.1.x (1.1.8)
mpoublon updated the task description for T777: Misleading Help Text for IPSEC Connection Type.
Wed, Aug 15, 3:14 AM · VyOS 1.1.x (1.1.8)
mpoublon created T777: Misleading Help Text for IPSEC Connection Type.
Wed, Aug 15, 3:13 AM · VyOS 1.1.x (1.1.8)

Tue, Aug 14

c-po added a comment to T739: flow-accounting stops.

Now using the following config, unfortunately my routers don't have that much traffic:

Tue, Aug 14, 6:36 PM · pmacct, VyOS 1.2.x
Diffusion added a commit to T10: Make phabricator allow everyone create tasks: Unknown Object (Diffusion Commit).
Tue, Aug 14, 5:59 PM · Infrastructure

Query Overheated

Most objects matching your query are not visible to you, so filtering results is taking a long time. Only some results are shown. Refine your query to find results more quickly.