Page MenuHomeVyOS Platform
Feed All Stories

Dec 23 2017

c-po changed the status of T285: Add flag for DNSmasq to query all dns servers from Open to In progress.
Dec 23 2017, 1:40 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T419: Support setting dstport for VXLAN interfaces.

The VXLAN RFC states:

Dec 23 2017, 1:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
c-po added a comment to T419: Support setting dstport for VXLAN interfaces.
cpo@CR1# set interfaces vxlan vxlan1 remote
Possible completions:
   <x.x.x.x>    Remote address of this VXLAN tunnel
Dec 23 2017, 8:04 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Dec 22 2017

c-po added a comment to T359: command "monitor interface" is unable to filter traffic.

What would be a filter that is not working?

Dec 22 2017, 6:20 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T504: Commit archive via IPv6 not works.

Please wait for todays build and test again. Thanks for your support!

Dec 22 2017, 5:09 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T504: Commit archive via IPv6 not works.

IPv6 address in scp://<user>:<passwd>@[IPv6-address]/<dir> looks like not properly escaped. Should be \[IPv6-address\].

Dec 22 2017, 5:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

@syncer
Use the configurations I provided and observe the packets the router is sending out.
In the nightly build the router is sending out using the IPv6 group address
Up to 1.1.8 the router is sending out using the IPv4 group address
This makes upgrades impossible
Using VRRPv2 with both IPv4 and IPv6 virtual addresses in the same VRRP instance is only possible due to a bug in the 1.2.19 keepalived

Dec 22 2017, 12:33 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

On two debian 8 test VM I compiled keepalived 1.3.9 without any errors. It may be a good thing to get this latest version for our new implementation.

Dec 22 2017, 11:28 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer added a comment to T105: VRRPv3 support (VRRP for IPv6).

@aopdal can you please provide relevant information and not just bunch of already known info?
We need description of problem and how to reproduce it, not comments from captain obvious

Dec 22 2017, 11:11 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

The current implementation is working on keepalived 1.2.19 (from 2015.07.07). In 1.2.20 (from 2016-04-02) a lot of bugs are fixed and the possibility to use IPv6 in VRRPv2 is gone.
When implementing IPv6 / VRRPv3 we should probably base the implementation on a newer version of keepalived.

Dec 22 2017, 9:23 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
aopdal added a comment to T105: VRRPv3 support (VRRP for IPv6).

Testing on

Dec 22 2017, 8:07 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer changed the status of T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown from Open to In progress.

Please test latest nightly builds and report back

Dec 22 2017, 12:26 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer closed T385: Integrate pmacct 1.6+ into the current branch as Resolved.
Dec 22 2017, 12:26 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), pmacct
syncer merged T454: flow-accounting broken into T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.
Dec 22 2017, 12:24 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer merged task T454: flow-accounting broken into T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.
Dec 22 2017, 12:24 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer closed T104: Hierarchy plugin for mediawiki as Wontfix.

that is obsolete

Dec 22 2017, 12:23 AM · Rejected

Dec 21 2017

syncer triaged T359: command "monitor interface" is unable to filter traffic as Low priority.
Dec 21 2017, 9:58 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer closed T361: "make iso" fails with a "command not found" error if live-build is not installed as Resolved.
Dec 21 2017, 9:57 PM
syncer triaged T365: OVS as replacement of Linux bridge as Wishlist priority.
Dec 21 2017, 9:57 PM · VyOS 1.5 Circinus
syncer triaged T366: SNMP Query for BGP Tunnels Returns IPv4 Tunnels Only as Normal priority.

@c-po i should get router with v6 and snmp
will ping you once it up

Dec 21 2017, 9:57 PM · VyOS 1.4 Sagitta
syncer triaged T371: Add command alias configuration node as Wishlist priority.
Dec 21 2017, 9:56 PM · Invalid
syncer triaged T374: Different default IKE DH Group behaviour between v1.1.7 and v999 Nightlies as Low priority.
Dec 21 2017, 9:55 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc7)
syncer triaged T375: WAN failover, not to balance the load as Low priority.

@EwaldvanGeffen can i mark this as solved?

Dec 21 2017, 9:54 PM · VyOS 1.5 Circinus
syncer triaged T377: DHCP-relay agent package replacement as Low priority.
Dec 21 2017, 9:52 PM · VyOS 1.5 Circinus
syncer triaged T379: UDP Broadcast Packet Relay as Low priority.
Dec 21 2017, 9:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T381: config nodes for EasyRSA CAs as Wishlist priority.
Dec 21 2017, 9:51 PM · VyOS 1.4 Sagitta
syncer triaged T383: snmpd messages in log with nightly "vyos-999.201709032137-amd64.iso" as Normal priority.
Dec 21 2017, 9:50 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9)
syncer closed T390: SNMP ERROR as Wontfix.

can't reproduce

Dec 21 2017, 9:50 PM · Rejected
syncer closed T402: Nightly build is broken due to "dpkg: error processing archive /var/cache/apt/archives/vyos-1x_1.0.1_all.deb" as Resolved.

i think it's solved by now, if not, please reopen

Dec 21 2017, 9:49 PM
syncer triaged T405: Add binaries for lcdproc as Wishlist priority.
Dec 21 2017, 9:48 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer triaged T406: VPN configuration error: IPv6 over IPv4 IPsec is not supported when using IPv6 ONLY tunnel. as Low priority.
Dec 21 2017, 9:47 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer triaged T407: BGP type 2 length 3294 is too large, attribute total length is 2303. attr_endp is 0x7f9e0bbb56cd. endp is 0x7f9e0bbb52e6 as Normal priority.
Dec 21 2017, 9:45 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T409: VyOS OSPF doesn't send LS update on flapping interface as Low priority.
Dec 21 2017, 9:45 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc8)
syncer closed T411: Squid is not functional due to legacy config statements that are no longer working in Squid3 as Resolved.
Dec 21 2017, 9:44 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer closed T412: Add rsync to the list of squid safe ports as Resolved.
Dec 21 2017, 9:43 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T415: Beta ISO VTI Tunnel as Wishlist priority.
Dec 21 2017, 9:41 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T417: Allow bonding non-ethernet interfaces as Wishlist priority.
Dec 21 2017, 9:40 PM · VyOS 1.5 Circinus
syncer triaged T418: Add html entities encoding for options field as Wishlist priority.
Dec 21 2017, 9:39 PM · VyOS 1.5 Circinus, vyatta-cfg-system
syncer assigned T419: Support setting dstport for VXLAN interfaces to c-po.

can you add required nodes for this maybe
@UnicronNL please assist

Dec 21 2017, 9:38 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer triaged T421: Add Pv6 prefix delegation support as Normal priority.
Dec 21 2017, 9:37 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer triaged T424: Advertisement of Multiple Paths in BGP (capability 69) as Wishlist priority.
Dec 21 2017, 9:36 PM · VyOS 1.1.x
syncer removed a project from T426: CVE-2017-13077 - Update wpa_supplicant: VyOS 1.1.x.
Dec 21 2017, 9:26 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa
syncer moved T426: CVE-2017-13077 - Update wpa_supplicant from In Progress to Finished on the VyOS 1.2 Crux board.
Dec 21 2017, 9:25 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa
syncer closed T426: CVE-2017-13077 - Update wpa_supplicant as Resolved.
Dec 21 2017, 9:25 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), wpa
syncer changed the visibility for T430: It's not possible to configure openvpn client ip address in server mode.
Dec 21 2017, 9:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), vyatta-openvpn, openvpn
syncer triaged T430: It's not possible to configure openvpn client ip address in server mode as Low priority.
Dec 21 2017, 9:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), vyatta-openvpn, openvpn
syncer triaged T439: local PBR support as Normal priority.
Dec 21 2017, 9:23 PM · VyOS 1.4 Sagitta
syncer triaged T440: VTI/IPSec with dynamic peer as Normal priority.
Dec 21 2017, 9:22 PM · VyOS 1.3 Equuleus (1.3.6)
syncer triaged T446: Flow accounting enhancements: pre/post NAT, ingress/egress as Wishlist priority.
Dec 21 2017, 9:22 PM · VyOS 1.4 Sagitta
syncer assigned T453: Qos/Match.pm shaper max-length to dmbaturin.

@dmbaturin please review and merge in

Dec 21 2017, 9:21 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T458: Disabling the in-memory table plugin has no effect as Low priority.
Dec 21 2017, 9:18 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc8)
syncer triaged T460: VRRP transition scripts no longer get executed as Normal priority.
Dec 21 2017, 9:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T461: Central user/key management through JumpCloud as Wishlist priority.
Dec 21 2017, 9:16 PM · VyOS 1.5 Circinus
syncer triaged T462: Make sure automatically run scripts are executed with vyattacfg GID as Normal priority.
Dec 21 2017, 9:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T464: network groups with same name. as Low priority.
Dec 21 2017, 9:15 PM · Rejected
syncer triaged T478: Firewall address group (multi and nesting) as Wishlist priority.
Dec 21 2017, 9:14 PM · VyOS 1.4 Sagitta
syncer triaged T480: Error if no serial interface is present (/dev/ttyS0: not a tty) as Wishlist priority.

i removed serial device in OVA

Dec 21 2017, 9:13 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer assigned T481: traffic-policy limiter is broken to dmbaturin.

@dmbaturin @UnicronNL please review and merge in

Dec 21 2017, 9:12 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T482: SNMP: non verbose error message on wrong listen-address as Normal priority.
Dec 21 2017, 9:12 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc4)
syncer triaged T483: Add google-authenticator 2fa as Wishlist priority.
Dec 21 2017, 9:11 PM · VyOS 1.4 Sagitta
syncer assigned T484: Rules can't be deleted from firewall rule sets used in zone policies to dmbaturin.

@dmbaturin can you merge it in

Dec 21 2017, 9:11 PM · VyOS 1.2 Crux (VyOS 1.2.1)
syncer triaged T485: iBGP recursive route via OSPF-learned loopback next-hop selects (wrong) interface next-hop as Normal priority.
Dec 21 2017, 9:10 PM · Invalid
syncer triaged T486: Static IPv6 default route via OSPFv3-learned loopback is not activated as Low priority.
Dec 21 2017, 9:09 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, test
syncer closed T489: Loadbalance as Wontfix.

Use "set load-balancing wan sticky-connections inbound".

Dec 21 2017, 9:09 PM · Rejected
syncer triaged T488: GRUB can't boot from software RAID as Normal priority.
Dec 21 2017, 9:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer closed T487: VyOS 1.1.8 vlan + pppoe traffic shaping as Wontfix.

Use "set load-balancing wan sticky-connections inbound"

Dec 21 2017, 9:08 PM · Rejected
syncer triaged T490: policy route path-MTU clamping as Low priority.
Dec 21 2017, 9:06 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc4)
syncer triaged T494: fq-codel not available on 1.1.8 as Low priority.

@dmbaturin any comments on this?

Dec 21 2017, 9:05 PM · Rejected
syncer triaged T495: IPSec / Charon deprecated keywods as Low priority.
Dec 21 2017, 9:05 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T496: RAID1 install with 60 MB diagnositcs partition as Low priority.
Dec 21 2017, 9:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer moved T504: Commit archive via IPv6 not works from Need Triage to Backlog on the VyOS 1.2 Crux board.
Dec 21 2017, 8:28 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer assigned T504: Commit archive via IPv6 not works to c-po.

@c-po can you look into this please

Dec 21 2017, 8:28 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer created T504: Commit archive via IPv6 not works.
Dec 21 2017, 8:27 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
srmumtaz asked Q120: trap ospfTrapIfSateChange trap sent: x.x.x.x now Down after a few hours.
Dec 21 2017, 7:28 PM · VyOS 1.1.x
srmumtaz updated the question details for Q119: error ospftrapifstatechange after a few hours.
Dec 21 2017, 7:21 PM · VyOS 1.2 Crux
srmumtaz asked Q119: error ospftrapifstatechange after a few hours.
Dec 21 2017, 7:20 PM · VyOS 1.2 Crux
syncer triaged T503: dnsmasq listen on tcp port on not selected interfaces as Normal priority.
Dec 21 2017, 4:05 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer created T503: dnsmasq listen on tcp port on not selected interfaces.
Dec 21 2017, 4:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
dmbaturin added a comment to T500: arp_filter blocks ARPs for VRRP virtual addresses in 1.2.x.

I'll check, meanwhile, could you verify that you still see this issue in the latest build?

Dec 21 2017, 2:34 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer moved T266: Create image of VyOS 1.2.0 for Amazon Web Services from Need Triage to Backlog on the VyOS 1.2 Crux board.
Dec 21 2017, 1:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), AWS Support
syncer added a comment to T105: VRRPv3 support (VRRP for IPv6).

@aopdal try latest nightly as we pushed changes related to vrrp

Dec 21 2017, 1:23 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer closed T342: PPTP and VRRP combination issue as Resolved.
Dec 21 2017, 1:19 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
UnicronNL closed T501: Add patched radvd to 1.2 as Resolved.

package is now in the vyos repo and used in images

Dec 21 2017, 8:02 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), radvd
elico added a comment to V5: Should we keep web proxy functionality in base 1.2/1.3/2.0?.

@syncer I am the unofficial maintainer of the Squid-Cache RPM's and DEB packages and doing it for more then 4 years now.
These days network routers are actually Route Servers and only the low cost devices doesn't contains any form of proxy functionality on them.
If you need a simple IP router you don't need it and this is most of the use cases of YVOS to my knowledge.
However we might be able to compromise on something in the middle instead of ditching it or other proxies.
Squid-Cache is good for caching but very old so for filtering there are couple other more efficient solutions and also the nature of the Internet HTTP world have changed so caching is good only for very specific purposes...
So I think that it would be a nice to have but if it's possible to allow the admin configure Squid or another proxy outside of the configuration shell it would be a better solution.
Also if you want to intercept traffic into squid you can just use DNAT rules.

Dec 21 2017, 7:43 AM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
cuban asked Q118: IPv6 system name-server.
Dec 21 2017, 1:24 AM · VyOS 1.1.x

Dec 20 2017

syncer created T501: Add patched radvd to 1.2.
Dec 20 2017, 2:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), radvd

Dec 19 2017

alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Dec 19 2017, 9:25 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T422: Packages server and downloads should be available via HTTPS as Low priority.
Dec 19 2017, 9:23 PM · Infrastructure
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Dec 19 2017, 9:22 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
elico added a comment to Q56: nDPI integration, what is required?.

@mickvav What's the status of 1.2.0-x? is there a build node\vm\container I can experiment building nDPI support?

Dec 19 2017, 9:13 PM · VyOS 1.1.x (1.1.8)
alainlamar added a comment to V5: Should we keep web proxy functionality in base 1.2/1.3/2.0?.

I use squid as a caching proxy to very considerably speed up patching and non-encrypted static web content. I also use the blacklists which are updated every day. While VyOS with Squid and Wifi is a very good integrated router for home and SOHO, I also use it as building bloc for sample firewalls you encounter in corporate environments in several showcases.

Dec 19 2017, 9:09 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
cwadge added a comment to T422: Packages server and downloads should be available via HTTPS.

Awesome. :) Let me know if you ever need an extra pair of hands on the infrastructure front.

Dec 19 2017, 8:17 PM · Infrastructure
syncer added a comment to T422: Packages server and downloads should be available via HTTPS.

It will be sooner or later ;)

Dec 19 2017, 8:14 PM · Infrastructure
beamerblvd added a comment to T422: Packages server and downloads should be available via HTTPS.

That's true, I would use a TLS mirror with a SHA-256 hash from the master. But I'd also want the master to be TLS.

Dec 19 2017, 8:13 PM · Infrastructure
cwadge added a comment to T422: Packages server and downloads should be available via HTTPS.

If you can at least get a strong hash sum of the ISO from the master, that should be sufficient regardless of where the binary is downloaded from. Of course, if the master is compromised, all bets are off.

Dec 19 2017, 8:08 PM · Infrastructure
beamerblvd added a comment to T422: Packages server and downloads should be available via HTTPS.

We should probably put in the mirror documentation that new mirrors must support TLS and existing mirrors are strongly urged to add support for TLS. However, to be clear, wanting a secure source for my downloads, I won't download from a mirror, because there's a lower level of trust. In fact, given a mirror with TLS and a the master source without TLS, I would chose the master source every time.

Dec 19 2017, 8:02 PM · Infrastructure
syncer changed the status of T422: Packages server and downloads should be available via HTTPS from Open to In progress.
Dec 19 2017, 7:57 PM · Infrastructure
cwadge added a comment to T422: Packages server and downloads should be available via HTTPS.

This begs the question about the mirror mechanism. My mirror supports TLS, but most don't.

Dec 19 2017, 7:56 PM · Infrastructure
syncer assigned T500: arp_filter blocks ARPs for VRRP virtual addresses in 1.2.x to dmbaturin.
Dec 19 2017, 4:57 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
rconan created T500: arp_filter blocks ARPs for VRRP virtual addresses in 1.2.x.
Dec 19 2017, 4:45 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)