Page MenuHomeVyOS Platform
Feed All Stories

Oct 11 2017

syncer assigned T422: Packages server and downloads should be available via HTTPS to dmbaturin.

Should we just add letsencrypt ?

Oct 11 2017, 8:54 PM · Infrastructure
syncer added a comment to T342: PPTP and VRRP combination issue.

@EinHander can you confirm same behaviour on 1.2 ?

Oct 11 2017, 8:53 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer edited projects for T342: PPTP and VRRP combination issue, added: VyOS 1.2 Crux; removed VyOS 1.1.x.

Please use transition scripts as suggested by @aopdal
Moving this to 1.2 roadmap

Oct 11 2017, 8:53 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer assigned T337: 'show vpn ipsec sa' output wrong when remote or local prefix not in system subnet to JulesT.

@c-po wondering if this something that was fixed by you previously?

Oct 11 2017, 8:51 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer closed T397: SNMPd - High load, doesnt work. as Invalid.

Got no follow up,
closing this

Oct 11 2017, 8:50 PM · Invalid
syncer moved T407: BGP type 2 length 3294 is too large, attribute total length is 2303. attr_endp is 0x7f9e0bbb56cd. endp is 0x7f9e0bbb52e6 from Need Triage to Backlog on the VyOS 1.2 Crux board.
Oct 11 2017, 8:49 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer assigned T407: BGP type 2 length 3294 is too large, attribute total length is 2303. attr_endp is 0x7f9e0bbb56cd. endp is 0x7f9e0bbb52e6 to Unknown Object (User).

Here is patch:
diff --git a/bgpd/bgp_aspath.c b/bgpd/bgp_aspath.c

Oct 11 2017, 8:49 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer moved T422: Packages server and downloads should be available via HTTPS from Need Triage to Backlog on the VyOS 1.1.x board.
Oct 11 2017, 7:59 PM · Infrastructure
beamerblvd added a comment to T35: Add IPv6 firewall network groups.

I'd like to get some clarity on this, if possible. Will VyOS's firewall features just not work at all with IPv6? Or will it work, but you have to use something other than groups? Importantly: Is it still possible for me to secure my network if I enable IPv6?

Oct 11 2017, 7:39 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
beamerblvd added a comment to T422: Packages server and downloads should be available via HTTPS.

Comment by @beamerblvd on 2016-01-24:

Oct 11 2017, 7:17 PM · Infrastructure
beamerblvd created T422: Packages server and downloads should be available via HTTPS.
Oct 11 2017, 7:17 PM · Infrastructure
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

The above completes the migration of content and all comments for Bugzilla issue 112.

Oct 11 2017, 7:04 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by Daniel Corbe on 2016-01-12:

Oct 11 2017, 6:58 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by Brett Lykins on 2015-09-28:

Oct 11 2017, 6:58 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by Jason Nadeau on 2015-09-27:

Oct 11 2017, 6:57 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by Patrick van Staveren on 2015-09-25:

Oct 11 2017, 6:56 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by Jeremy Church on 2015-08-24:

Oct 11 2017, 6:55 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by Steve Froelich on 2015-08-21:

Oct 11 2017, 6:55 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by Aaron Von Gauss on 2015-05-03:

Oct 11 2017, 6:54 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by @dmbaturin on 2015-05-03:

Oct 11 2017, 6:54 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd updated subscribers of T421: Add Pv6 prefix delegation support.

Comment by @darkdragon-001 on 2015-04-19:

Oct 11 2017, 6:53 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by Aaron Von Gauss on 2015-03-27:

Oct 11 2017, 6:52 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by Kouak on 2015-03-18:

Oct 11 2017, 6:52 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by @beamerblvd on 2015-03-06:

Oct 11 2017, 6:51 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by Kouak on 2015-03-05:

Oct 11 2017, 6:50 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by @beamerblvd on 2015-03-05:

Oct 11 2017, 6:50 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by @beamerblvd on 2015-03-03:

Oct 11 2017, 6:49 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd updated subscribers of T421: Add Pv6 prefix delegation support.

Comment by @dmbaturin on 2014-10-07:

Oct 11 2017, 6:49 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to T421: Add Pv6 prefix delegation support.

Comment by Ryan Holt posted on 2014-09-02:

Oct 11 2017, 6:48 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd created T421: Add Pv6 prefix delegation support.
Oct 11 2017, 6:48 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
beamerblvd added a comment to Q112: Can we please get a mapping, or redirects, from Bugzilla to Phabricator? (Answer 155).

So is the correct course of action for me to create a new issue and manually copy over the contents of the issue and all of the comments?

Oct 11 2017, 6:42 PM
syncer added a comment to Q112: Can we please get a mapping, or redirects, from Bugzilla to Phabricator? (Answer 155).

@beamerblvd no migration was done.

Oct 11 2017, 6:22 PM
246tnt created T419: Support setting dstport for VXLAN interfaces.
Oct 11 2017, 3:54 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
beamerblvd added a comment to Q112: Can we please get a mapping, or redirects, from Bugzilla to Phabricator? (Answer 155).

Okay, so I want to make sure I'm clear on something. We have not migrated any issues over? Or we have migrated some, but not others?

Oct 11 2017, 2:21 PM
higebu added a comment to T164: Create image for MicroSoft Azure.

waagent log

Oct 11 2017, 1:54 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3), Hyper-V/Azure Support
higebu added a comment to T164: Create image for MicroSoft Azure.

my azure image works on azure too. the image is here: https://dev.vyos.jp/vyos/dev-images/vyos_azure_image.img
and walinuxagent is running on it. I'm checking walinuxagent status.

Oct 11 2017, 1:47 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3), Hyper-V/Azure Support
higebu added a comment to T164: Create image for MicroSoft Azure.

https://www.reddit.com/r/networking/comments/75c30y/create_a_static_public_ip_address_for_home_use/

Oct 11 2017, 1:42 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3), Hyper-V/Azure Support

Oct 10 2017

syncer closed Q112: Can we please get a mapping, or redirects, from Bugzilla to Phabricator? as resolved.
Oct 10 2017, 11:55 PM · VyOS 1.1.x
dmbaturin added Q112: Can we please get a mapping, or redirects, from Bugzilla to Phabricator? (Answer 155).
Oct 10 2017, 9:56 PM
beamerblvd asked Q112: Can we please get a mapping, or redirects, from Bugzilla to Phabricator?.
Oct 10 2017, 9:01 PM · VyOS 1.1.x
syncer closed T389: Virtio SCSI is missing in kernel as Resolved.
Oct 10 2017, 3:56 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer moved T389: Virtio SCSI is missing in kernel from In Progress to 1.1.8 on the VyOS 1.1.x board.
Oct 10 2017, 3:56 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer closed T416: IKEv2 VTI Site-to-Site VPN between Cisco IOS-XE 16.3.1a and VyOS 1.1.7 not working (IKEv1 working ok) as Wontfix.

We will not address this in 1.1.x
please retest on 1.2. and reopen ticket or create new one

Oct 10 2017, 3:55 PM · Rejected
c-po added a comment to T414: Remove the telnet service and make sure old configs that use it still load.

BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. That means there is just a single BusyBox binary, but that single binary acts like a large number of utilities. This allows BusyBox to be smaller since all the built-in utility programs (we call them applets) can share code for many common operations.

Oct 10 2017, 2:33 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Oct 9 2017

syncer added a comment to T414: Remove the telnet service and make sure old configs that use it still load.

+1 for removal of telnet

Oct 9 2017, 3:54 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
elbuit added a comment to T414: Remove the telnet service and make sure old configs that use it still load.

Well, I think that if someone has a system with only telnet as a remote access method, it could be anoying to update and realize that you have lost any chance to remote access.
I vote to maintain or add a script that convert telnet to ssh configuration.

Oct 9 2017, 3:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T414: Remove the telnet service and make sure old configs that use it still load.

+1 for removal

Oct 9 2017, 2:58 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
mickvav added a comment to T414: Remove the telnet service and make sure old configs that use it still load.

Well, may be we just have to either:

Oct 9 2017, 10:46 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
mickvav added a comment to T417: Allow bonding non-ethernet interfaces.

If you have a lab to try - may be you can just copy

Oct 9 2017, 10:39 AM · VyOS 1.5 Circinus
mickvav created T418: Add html entities encoding for options field.
Oct 9 2017, 8:51 AM · VyOS 1.5 Circinus, vyatta-cfg-system
c-po added a comment to T414: Remove the telnet service and make sure old configs that use it still load.

As VyOS fully re-uses Debian packages it is not possible to enable any given applet inside Busybox. To get this enabled, VyOS has to maintain a forked version of the Debian busybox packages which makes life only harder.

Oct 9 2017, 2:29 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Oct 8 2017

sebastianm updated the task description for T417: Allow bonding non-ethernet interfaces.
Oct 8 2017, 6:00 PM · VyOS 1.5 Circinus
sebastianm updated the task description for T417: Allow bonding non-ethernet interfaces.
Oct 8 2017, 6:00 PM · VyOS 1.5 Circinus
sebastianm created T417: Allow bonding non-ethernet interfaces.
Oct 8 2017, 5:59 PM · VyOS 1.5 Circinus
syncer triaged T416: IKEv2 VTI Site-to-Site VPN between Cisco IOS-XE 16.3.1a and VyOS 1.1.7 not working (IKEv1 working ok) as Low priority.

I will advise to try latest rolling release from here
dev.packages.vyos.net/iso/current/amd64/

Oct 8 2017, 1:43 PM · Rejected
xomka686 created T416: IKEv2 VTI Site-to-Site VPN between Cisco IOS-XE 16.3.1a and VyOS 1.1.7 not working (IKEv1 working ok) .
Oct 8 2017, 1:37 PM · Rejected
syncer closed T403: Outstanding CVEs - Other as Resolved.
Oct 8 2017, 1:29 PM · VyOS 1.1.x (1.1.8)
UnicronNL moved T403: Outstanding CVEs - Other from Backlog to Finished on the VyOS 1.1.x (1.1.8) board.
Oct 8 2017, 1:28 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 8 2017, 1:27 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 8 2017, 1:21 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 8 2017, 1:14 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 8 2017, 1:11 PM · VyOS 1.1.x (1.1.8)

Oct 7 2017

volga629 created T415: Beta ISO VTI Tunnel.
Oct 7 2017, 8:12 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
elbuit created T414: Remove the telnet service and make sure old configs that use it still load.
Oct 7 2017, 7:02 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Oct 6 2017

syncer assigned T341: WOL Tools in base image to UnicronNL.

@UnicronNL please add package
https://packages.debian.org/search?keywords=wakeonlan
This is client tool (to wake up servers/hosts) we will be adding op mode command for it

Oct 6 2017, 10:18 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Oct 5 2017

UnicronNL added a comment to T410: dnsmasq in 1.1.x is outdated and vulnerable to many CVEs.

added jessie one. https://github.com/vyos/dnsmasq
need to test in 1.1.8 rc1

Oct 5 2017, 8:54 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), VyOS 1.1.x (1.1.8)
UnicronNL closed T205: Kernel privilege excalation CVE-2016-8655 as Resolved.
Oct 5 2017, 8:51 PM · VyOS 1.1.x (1.1.8)
UnicronNL closed T329: add phabricator.vyos.net paste app as valid destination for show tech-support save-uncompressed as Resolved.
Oct 5 2017, 8:43 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
UnicronNL closed T358: add option to set phabricator api token as Resolved.
Oct 5 2017, 8:42 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), VyOS 1.1.x (1.1.8)
UnicronNL closed T358: add option to set phabricator api token, a subtask of T329: add phabricator.vyos.net paste app as valid destination for show tech-support save-uncompressed, as Resolved.
Oct 5 2017, 8:42 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Oct 4 2017

UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 4 2017, 8:22 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 4 2017, 8:07 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 4 2017, 8:07 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 4 2017, 7:14 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 4 2017, 6:47 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 4 2017, 6:45 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 4 2017, 6:44 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated the task description for T403: Outstanding CVEs - Other.
Oct 4 2017, 6:43 PM · VyOS 1.1.x (1.1.8)
syncer added a member for Sentrium: Unknown Object (User).
Oct 4 2017, 5:33 PM
Tania created T413: Make a schema for op mode.
Oct 4 2017, 5:29 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
dponzone added a comment to T244: Issue with recursive static routing.

I see your point, but generally, you want to use uRPF by receiving a BGP feed with prefixes to block, with a specific next hop, so you need to statically route this nexthop to blackhole, so all the prefixes are blackholed and uRPF can kick in.

Oct 4 2017, 2:13 PM · Rejected
Unknown Object (User) added a comment to T244: Issue with recursive static routing.

As most of network internals inferred from Linux kernel, there is no direct way to achieve what you want.
You messing two different things as uRPF and recursive lookup. First works fine, second impossible.

Oct 4 2017, 1:52 PM · Rejected
dponzone added a comment to T244: Issue with recursive static routing.

Does that mean uRPF is useless in VyOS, or is there a workaround I failed to find ?

Oct 4 2017, 1:13 PM · Rejected
Unknown Object (User) added a comment to T244: Issue with recursive static routing.

@dponzone check this thread, https://superuser.com/questions/1229275/linux-static-recursive-routes-not-supported
it will not work in a way you willing to have

Oct 4 2017, 10:56 AM · Rejected
dponzone added a comment to T244: Issue with recursive static routing.

The version and the relevant lines of configuration are at the beginning.
Am I missing something ?

Oct 4 2017, 9:33 AM · Rejected
syncer added a comment to T244: Issue with recursive static routing.

No version
No config
You have some task to accomplish and it not works as you need.

Oct 4 2017, 9:29 AM · Rejected
dmbaturin created T412: Add rsync to the list of squid safe ports.
Oct 4 2017, 7:42 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
dmbaturin created T411: Squid is not functional due to legacy config statements that are no longer working in Squid3.
Oct 4 2017, 7:40 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
dponzone reopened T244: Issue with recursive static routing as "Open".
Oct 4 2017, 5:52 AM · Rejected
dponzone added a comment to T244: Issue with recursive static routing.

I am sorry, this is bug, I hardly see why it should be a support question.

Oct 4 2017, 5:52 AM · Rejected

Oct 3 2017

syncer assigned T410: dnsmasq in 1.1.x is outdated and vulnerable to many CVEs to UnicronNL.

@UnicronNL @dmbaturin
can we just rebuild fresh from wheeze?

Oct 3 2017, 10:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), VyOS 1.1.x (1.1.8)
syncer edited projects for T410: dnsmasq in 1.1.x is outdated and vulnerable to many CVEs, added: VyOS 1.2 Crux, VyOS 1.1.x (1.1.8); removed VyOS 1.1.x.
Oct 3 2017, 10:37 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), VyOS 1.1.x (1.1.8)
dmbaturin added a comment to T354: Outstanding CVEs - StrongSwan.

@UnicronNL The debian repo for helium is here: http://dev.packages.vyos.net/legacy/repos/debian/helium/

Oct 3 2017, 7:39 PM · vyatta-strongswan, VyOS 1.1.x (1.1.8)
UnicronNL added a comment to T354: Outstanding CVEs - StrongSwan.

@higebu @syncer squeeze is added to ci, only there is no repo to upload.

Oct 3 2017, 6:54 PM · vyatta-strongswan, VyOS 1.1.x (1.1.8)
UnicronNL updated subscribers of T403: Outstanding CVEs - Other.

@dmbaturin @syncer Where can i find the lithium repo?

Oct 3 2017, 6:51 PM · VyOS 1.1.x (1.1.8)
UnicronNL updated subscribers of T355: Outstanding CVEs - OpenVPN.

@dmbaturin @syncer Where can i find the lithium repo?

Oct 3 2017, 6:50 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), openvpn
jbrown updated the answer details for Q111: Any plans to backport dnsmasq? (Answer 154).
Oct 3 2017, 3:36 PM
jbrown created T410: dnsmasq in 1.1.x is outdated and vulnerable to many CVEs.
Oct 3 2017, 3:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), VyOS 1.1.x (1.1.8)
jbrown closed Q111: Any plans to backport dnsmasq? as resolved.
Oct 3 2017, 3:34 PM · VyOS 1.1.x
jbrown added Q111: Any plans to backport dnsmasq? (Answer 154).
Oct 3 2017, 3:34 PM