Page MenuHomeVyOS Platform
Feed All Stories

Sep 4 2019

c-po added a comment to T1633: Cannot bridge interfaces.

The documentation is also correct. Please not that there are two git branches for the documentation, current and equuleus. You send me the VyOS 1.2.2 crux link. I gave you the upcoming VyOS 1.2 equuleus link.

Sep 4 2019, 1:57 PM · VyOS 1.3 Equuleus (1.3.0)
hexes added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

Thanks, I'll try to figure it out. What do you think about openvpn:openvpn?

Sep 4 2019, 1:53 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1631: Multiple push-route options cause error generating openvpn configuration.

This is actually a duplicate of T1617.

Sep 4 2019, 12:58 PM · VyOS 1.3 Equuleus (1.3.0)
fadly.tabrani changed the subtype of T1633: Cannot bridge interfaces from "Bug" to "Task".

Thanks! Should update the documentation @ https://vyos.readthedocs.io/en/latest/interfaces/bridging.html

Sep 4 2019, 12:45 PM · VyOS 1.3 Equuleus (1.3.0)
jdevincentis added a comment to T1631: Multiple push-route options cause error generating openvpn configuration.

I'm aware, I'm testing it since 1.2 has an unresolvable bug (due to the age of the distribution it's built on) in the isc-dhcp-relay package.

Sep 4 2019, 12:37 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1633: Cannot bridge interfaces as Invalid.
Sep 4 2019, 12:37 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1633: Cannot bridge interfaces.

The bahavior has changed, see https://vyos.readthedocs.io/en/equuleus/interfaces/bridging.html and T1556

Sep 4 2019, 12:36 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1631: Multiple push-route options cause error generating openvpn configuration.

1.3 rolling is not recommended for users - its pre-alpha.

Sep 4 2019, 12:35 PM · VyOS 1.3 Equuleus (1.3.0)
fadly.tabrani created T1633: Cannot bridge interfaces.
Sep 4 2019, 12:32 PM · VyOS 1.3 Equuleus (1.3.0)
jdevincentis added a comment to T1631: Multiple push-route options cause error generating openvpn configuration.

Just noticed you used VyOS 1.2-rolling-201909040337, this is for 1.3 rolling.

Sep 4 2019, 12:19 PM · VyOS 1.3 Equuleus (1.3.0)
jdevincentis added a comment to T1631: Multiple push-route options cause error generating openvpn configuration.
Sep 4 2019, 12:14 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1631: Multiple push-route options cause error generating openvpn configuration.

@jdevincentis is this a custom build? Using VyOS 1.2-rolling-201909040337 I can not reproduce the issue with:

Sep 4 2019, 12:10 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T1632: OpenVPN 'push' options with quotes.
Sep 4 2019, 7:22 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a subtask for T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python: T1631: Multiple push-route options cause error generating openvpn configuration.
Sep 4 2019, 7:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a parent task for T1631: Multiple push-route options cause error generating openvpn configuration: T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python.
Sep 4 2019, 7:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T1631: Multiple push-route options cause error generating openvpn configuration from Open to In progress.
Sep 4 2019, 7:20 AM · VyOS 1.3 Equuleus (1.3.0)
syncer closed T1543: Add a source address/interface option for commit archive connections as Resolved.
Sep 4 2019, 1:31 AM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer closed T1605: L2tp over IPsec not working in Crux as Resolved.
Sep 4 2019, 1:31 AM · VyOS 1.2 Crux (VyOS 1.2.3)
jdevincentis created T1632: OpenVPN 'push' options with quotes.
Sep 4 2019, 12:18 AM · VyOS 1.3 Equuleus (1.3.0)
jdevincentis created T1631: Multiple push-route options cause error generating openvpn configuration.
Sep 4 2019, 12:04 AM · VyOS 1.3 Equuleus (1.3.0)

Sep 3 2019

kroy added a comment to T1629: IP addresses configured on vif-s interfaces are not added to the system.

I took a look, but was unable to figure out how to finagle VyOS to fix it.

Sep 3 2019, 7:19 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed Difficulty level from normal to hard on T1628: Adopt WireGuard configuration script to new vyos.ifconfig class.
Sep 3 2019, 6:12 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

The config generator would need to be adopted https://github.com/vyos/vyos-1x/blob/current/src/conf_mode/interface-openvpn.py and the wrapper script added. I have no time before tomorrow, sorry

Sep 3 2019, 5:30 PM · VyOS 1.3 Equuleus (1.3.0)
hexes added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

And may be change nobody:nogroup to openvpn:openvpn? It's more clear, i think...

Sep 3 2019, 4:41 PM · VyOS 1.3 Equuleus (1.3.0)
hexes added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

How can I help you to fix it? In this article https://community.openvpn.net/openvpn/wiki/UnprivilegedUser looks like it's not so hard...

Sep 3 2019, 4:40 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1628: Adopt WireGuard configuration script to new vyos.ifconfig class.

That will be a complete rewrite, since the interface name is now readable via VYOS_TAGNODE_VALUE, that affects get_config() quite a lot and will reduce the number of code line significantly. The flip side of the coin is, that the current code was running pretty reliable, so I will release small updates while adopting to see if I break anything configure outside of my test environment.

Sep 3 2019, 4:32 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1448: Permissions after image update .

Please test with latest rolling and not a custom build.

Sep 3 2019, 4:18 PM · Rejected
c-po added a parent task for T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes: T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python.
Sep 3 2019, 4:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a subtask for T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python: T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.
Sep 3 2019, 4:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.
Sep 3 2019, 4:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.

When the site looses connection and thus a SIGUSR21 is sent to OpenVPN to restart internally the priviledges have dropped and yes, /sbin/ip can't be called again.

Sep 3 2019, 4:16 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1565: [wireguard] - use VYOS_TAGNODE_VALUE to determine changed tagNodes as Invalid.

Duplicate: T1628

Sep 3 2019, 3:45 PM · VyOS 1.3 Equuleus (1.3.0)
hexes updated the task description for T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.
Sep 3 2019, 3:32 PM · VyOS 1.3 Equuleus (1.3.0)
hexes created T1630: OpenVPN after changing it from root to nobody (unprivileged user) cant add routes.
Sep 3 2019, 3:29 PM · VyOS 1.3 Equuleus (1.3.0)
c-po moved T1629: IP addresses configured on vif-s interfaces are not added to the system from Need Triage to VyOS 1.2.4 on the VyOS 1.2 Crux board.
Sep 3 2019, 2:59 PM · VyOS 1.3 Equuleus (1.3.0)
c-po assigned T1629: IP addresses configured on vif-s interfaces are not added to the system to dmbaturin.
Sep 3 2019, 2:59 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1629: IP addresses configured on vif-s interfaces are not added to the system.
Sep 3 2019, 2:58 PM · VyOS 1.3 Equuleus (1.3.0)
hexes added a comment to T1448: Permissions after image update .

Or may be you could tell me where I can include this commands? Also I need to setup correct owners for /config/user-data/zabbix/ dir, there is zabbix-proxy DB...

Sep 3 2019, 2:55 PM · Rejected
hexes added a comment to T1448: Permissions after image update .

how could I show it to you? Which version have you try to update? I think simple chown in update script could fix it!
Also i think it could be compare with changing of list of users and thous IDs:
Old system list:

Sep 3 2019, 2:33 PM · Rejected
c-po assigned T1628: Adopt WireGuard configuration script to new vyos.ifconfig class to hagbard.
Sep 3 2019, 12:01 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1628: Adopt WireGuard configuration script to new vyos.ifconfig class.
Sep 3 2019, 12:01 PM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T1627: Rewrite wireless interface in new style XML syntax.
Sep 3 2019, 10:21 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1627: Rewrite wireless interface in new style XML syntax.
Sep 3 2019, 10:21 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T1564: BGP IPv6 only peer-group not supported.
Sep 3 2019, 9:02 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T1564: BGP IPv6 only peer-group not supported.
Sep 3 2019, 9:01 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T1626: BGP exchanges prefixes without specified address-family.
Sep 3 2019, 8:49 AM · VyOS 1.3 Equuleus (1.3.0), test
c-po created T1626: BGP exchanges prefixes without specified address-family.
Sep 3 2019, 8:49 AM · VyOS 1.3 Equuleus (1.3.0), test

Sep 2 2019

Unknown Object (User) added a comment to T1349: L2TP remote-access vpn terminated and not showing as connected.

Hello @Merijn, do you have possibility provide logs while this issue appear and client try connect to l2tp server?
As example show log tail 100 | strip-private

Sep 2 2019, 7:01 PM · VyOS 1.3 Equuleus (1.3.0), test
jjakob added a comment to T1620: Leases in "show dhcp server leases" lose Pool and Hostname after some time.

Here's the sanitized dhcp-server config.

Sep 2 2019, 7:00 PM · VyOS 1.3 Equuleus (1.3.6)
c-po added a comment to T1624: Failed to set up config session.

Should be fixed in next rolling release by: https://github.com/vyos/vyatta-cfg/commit/710728ee8eb6def82f9a142468960f6985dcf4e8

Sep 2 2019, 6:43 PM · VyOS 1.3 Equuleus (1.3.0)
jjakob added a comment to T1620: Leases in "show dhcp server leases" lose Pool and Hostname after some time.

On my routers they are definitely missing from /config/dhcpd.leases. I have some static host mappings in the config too. I also confirmed the "on commit set shared-networkname" line is in dhcpd.conf.

Sep 2 2019, 6:07 PM · VyOS 1.3 Equuleus (1.3.6)
Unknown Object (User) added a comment to T1563: DNAT configuration issue.

Hello @hexes, do you have D-NAT rules for destination port 9786 on external ip? Can you give me advanced info how I can reproduce this?
Also you can masking config with command show ... | strip-private . I need all firewall and nat rules.
ps:/ In my test lab I can't reproduce this issue.

Sep 2 2019, 4:43 PM · Invalid
Unknown Object (User) added a comment to T1620: Leases in "show dhcp server leases" lose Pool and Hostname after some time.

Hello, @jjakob . I cannot reproduce this issue on VyOS 1.2-rolling-201908311322. Can you give more details and configuration commands?
Did you use for ipv4 show dhcp server leases and for ipv6 run show dhcpv6 server leases ?

Sep 2 2019, 1:35 PM · VyOS 1.3 Equuleus (1.3.6)
alkersan closed T1621: Rewrite the rest of trivial vyatta-op commands to new syntax, a subtask of T689: Converting simple op-mode commands from vyatta-op to new syntax, as Resolved.
Sep 2 2019, 9:26 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alkersan closed T1621: Rewrite the rest of trivial vyatta-op commands to new syntax as Resolved.
Sep 2 2019, 9:26 AM · VyOS 1.3 Equuleus (1.3.0)

Sep 1 2019

dmbaturin added a subtask for T1625: Update validation rules for OSPF max-metric values: T1209: OSPF max-metric values over 100 cause commit errors.
Sep 1 2019, 9:00 PM
dmbaturin added a parent task for T1209: OSPF max-metric values over 100 cause commit errors: T1625: Update validation rules for OSPF max-metric values.
Sep 1 2019, 9:00 PM · VyOS 1.2 Crux (VyOS 1.2.3)
dmbaturin created T1625: Update validation rules for OSPF max-metric values.
Sep 1 2019, 8:59 PM
dmbaturin renamed T1209: OSPF max-metric values over 100 cause commit errors from OSPF max-metric configuration not supported to OSPF max-metric values over 100 cause commit errors.
Sep 1 2019, 8:56 PM · VyOS 1.2 Crux (VyOS 1.2.3)
dmbaturin closed T1209: OSPF max-metric values over 100 cause commit errors as Resolved.

As a stopgap measure that allows old config to load, I've made the script cap it at 100:

Sep 1 2019, 8:55 PM · VyOS 1.2 Crux (VyOS 1.2.3)
c-po triaged T1624: Failed to set up config session as Unbreak Now! priority.
Sep 1 2019, 4:36 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1624: Failed to set up config session.
Sep 1 2019, 4:36 PM · VyOS 1.3 Equuleus (1.3.0)
alkersan updated the task description for T1623: Systemd reports dependency cycle during boot.
Sep 1 2019, 1:05 PM · VyOS 1.2 Crux (VyOS 1.2.3)
alkersan created T1623: Systemd reports dependency cycle during boot.
Sep 1 2019, 1:03 PM · VyOS 1.2 Crux (VyOS 1.2.3)
c-po added a comment to T1557: Create generic abstraction for configuring interfaces e.g. IP address.

@hagbard not a problem. Looks like we now go the "our own lib" way as pyroute2 has some flaws. DHCP is already fix and I continue improve the script and remove redundant code before it will be extended to support VLAN/bonding.

Sep 1 2019, 8:03 AM · VyOS 1.3 Equuleus (1.3.0)

Aug 31 2019

hagbard added a comment to T1557: Create generic abstraction for configuring interfaces e.g. IP address.

@c-po sorry was camping in a remote area without cell coverage. What's the way we go then? I'll look tomorrow, eventually Tuesday next week into the dhcp stuff.

Aug 31 2019, 11:40 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro changed the status of T1622: Add failsafe and back trace to boot config loader from Open to In progress.
Aug 31 2019, 11:01 PM · VyOS 1.3 Equuleus (1.3.0)
dmbaturin added a project to T1209: OSPF max-metric values over 100 cause commit errors: VyOS 1.2 Crux (VyOS 1.2.3).
Aug 31 2019, 9:30 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer reassigned T1169: LLDP potentially broken from matt.webb to Unknown Object (User).
Aug 31 2019, 9:04 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
syncer removed a project from T1209: OSPF max-metric values over 100 cause commit errors: VyOS 1.2 Crux (VyOS 1.2.3).
Aug 31 2019, 8:57 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer moved T1542: static-host-mapping entries broken after reboot from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Aug 31 2019, 8:56 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer moved T1543: Add a source address/interface option for commit archive connections from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Aug 31 2019, 8:56 PM · VyOS 1.2 Crux (VyOS 1.2.3)
dmbaturin closed T1542: static-host-mapping entries broken after reboot, a subtask of T1598: New implementation of the resolv.conf and hosts update mechanism, as Resolved.
Aug 31 2019, 8:56 PM · VyOS 1.2 Crux (VyOS 1.2.3)
dmbaturin closed T1542: static-host-mapping entries broken after reboot as Resolved.
Aug 31 2019, 8:56 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer closed T1275: Kernel Oops running VyOS 1.2 as Resolved.
Aug 31 2019, 8:56 PM
dmbaturin changed the status of T1543: Add a source address/interface option for commit archive connections from Open to Needs testing.

Cherry-picked into crux.

Aug 31 2019, 8:56 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer removed a project from T1297: Add GARP settings to VRRP/keepalived: VyOS 1.2 Crux (VyOS 1.2.3).

@zsdc please follow up on this

Aug 31 2019, 8:55 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
syncer added a comment to T1311: WAN load-balancing can't flush connections when conntrack-sync is enabled.

@zsdc can you follow up on this

Aug 31 2019, 8:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.3 Equuleus (1.3.7), test
syncer removed a project from T1311: WAN load-balancing can't flush connections when conntrack-sync is enabled: VyOS 1.2 Crux (VyOS 1.2.3).
Aug 31 2019, 8:54 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.3 Equuleus (1.3.7), test
syncer moved T1392: Large firewall rulesets cause the system to lose configuration and crash at startup from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Aug 31 2019, 8:53 PM · VyOS 1.2 Crux (VyOS 1.2.5)
syncer changed the status of T1392: Large firewall rulesets cause the system to lose configuration and crash at startup from Needs testing to Backport candidate.
Aug 31 2019, 8:53 PM · VyOS 1.2 Crux (VyOS 1.2.5)
syncer moved T1430: Add options for custom DHCP client-id and hostname from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Aug 31 2019, 8:51 PM · VyOS 1.2 Crux (VyOS 1.2.4)
syncer moved T1430: Add options for custom DHCP client-id and hostname from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Aug 31 2019, 8:51 PM · VyOS 1.2 Crux (VyOS 1.2.4)
syncer added a project to T1430: Add options for custom DHCP client-id and hostname: VyOS 1.3 Equuleus.
Aug 31 2019, 8:50 PM · VyOS 1.2 Crux (VyOS 1.2.4)
dmbaturin closed T1531: Several bugs in cluster configuration, a subtask of T1598: New implementation of the resolv.conf and hosts update mechanism, as Resolved.
Aug 31 2019, 8:50 PM · VyOS 1.2 Crux (VyOS 1.2.3)
dmbaturin closed T1531: Several bugs in cluster configuration as Resolved.
Aug 31 2019, 8:50 PM · VyOS 1.2 Crux (VyOS 1.2.3)
dmbaturin added a subtask for T1598: New implementation of the resolv.conf and hosts update mechanism: T1531: Several bugs in cluster configuration.
Aug 31 2019, 8:50 PM · VyOS 1.2 Crux (VyOS 1.2.3)
dmbaturin added a parent task for T1531: Several bugs in cluster configuration: T1598: New implementation of the resolv.conf and hosts update mechanism.
Aug 31 2019, 8:50 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer assigned T1452: accel-pppoe - add vendor option to shaper to dmbaturin.
Aug 31 2019, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.5)
syncer moved T1452: accel-pppoe - add vendor option to shaper from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Aug 31 2019, 8:49 PM · VyOS 1.2 Crux (VyOS 1.2.5)
syncer changed the status of T1421: OpenVPN client push-route stopped working, needs added quotes to fix from Backport pending to Needs testing.
Aug 31 2019, 8:48 PM · VyOS 1.2 Crux (VyOS 1.2.4)
syncer moved T1543: Add a source address/interface option for commit archive connections from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Aug 31 2019, 8:46 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer moved T1543: Add a source address/interface option for commit archive connections from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Aug 31 2019, 8:46 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer moved T1351: accel-pppoe adding CIDR based IP pool option from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Aug 31 2019, 8:45 PM · VyOS 1.2 Crux (VyOS 1.2.4)
syncer moved T1376: Incorrect DHCP lease counting from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Aug 31 2019, 8:43 PM · VyOS 1.2 Crux (VyOS 1.2.5)
syncer moved T1376: Incorrect DHCP lease counting from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Aug 31 2019, 8:43 PM · VyOS 1.2 Crux (VyOS 1.2.5)
syncer moved T1440: Creating two DHCPv6 shared-network-names with the same subnet is allowed, causes dhcpd to fail to start. from Finished to In Progress on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Aug 31 2019, 8:42 PM · VyOS 1.3 Equuleus (1.3.0)
rgrant added a comment to T1468: BGP route-reflector-client config erroneously claims remote-as is incorrect.

Thanks!!!! I'll test it once it's pulled...

Aug 31 2019, 8:42 PM · VyOS 1.2 Crux (VyOS 1.2.3)
syncer moved T1440: Creating two DHCPv6 shared-network-names with the same subnet is allowed, causes dhcpd to fail to start. from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.3) board.
Aug 31 2019, 8:42 PM · VyOS 1.3 Equuleus (1.3.0)
syncer moved T1440: Creating two DHCPv6 shared-network-names with the same subnet is allowed, causes dhcpd to fail to start. from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Aug 31 2019, 8:41 PM · VyOS 1.3 Equuleus (1.3.0)