Page MenuHomeVyOS Platform
Feed All Stories

Oct 30 2020

c-po closed T2969: OpenVPN: command_set on interface is not applied, if interface doesn't come up in commit, a subtask of T2994: Migrate OpenVPN interfaces to get_config_dict() syntax, as Resolved.
Oct 30 2020, 6:03 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2969: OpenVPN: command_set on interface is not applied, if interface doesn't come up in commit.

Closing in favor of T2994 - please try tomorrows rolling release. If there are new bugs (which might always happen on rewrites) please file a new Bug report and I try to fix them ASAP.

Oct 30 2020, 6:03 PM · VyOS 1.3 Equuleus (1.3.0)
c-po merged T2950: DHCP server cannot start on live CD into T2958: DHCP server doesn't work from a live CD.
Oct 30 2020, 5:53 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
c-po merged task T2950: DHCP server cannot start on live CD into T2958: DHCP server doesn't work from a live CD.
Oct 30 2020, 5:53 PM · VyOS 1.3 Equuleus (1.3.0)
c-po assigned T3021: We shouldn't be using pool.ntp.org to syncer.
Oct 30 2020, 5:52 PM · VyOS 1.3 Equuleus (1.3.0)
c-po renamed T3005: Intel: update out-of-tree drivers, i40e driver warning from i40e driver warning to Intel: update out-of-tree drivers, i40e driver warning.
Oct 30 2020, 4:04 PM · VyOS 1.3 Equuleus (1.3.0)
rizkidtn added a comment to T1289: route-map set route-type blackhole.

Like this?

vyos@r4-roll# set policy route-map FJFFJJF rule 10 set ip-next-hop 
Possible completions:
   <x.x.x.x>    IP address

where x.x.x.x route to blackhole?

Oct 30 2020, 2:05 PM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav added a comment to T1289: route-map set route-type blackhole.

Like this?

Oct 30 2020, 11:07 AM · VyOS 1.3 Equuleus (1.3.5)
rizkidtn added a comment to T1289: route-map set route-type blackhole.

The usual procedure is to create a route-map that sets the nexthop to a blackholed address if the advertisment has a specific community string set.
So when a customer advertises an address (rather a /32 network) to you with that string set, it automatically ends up blackholed.

Do you just want a shortcut for that, or you are having issues with community string-based approach?

Oct 30 2020, 10:59 AM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav added a comment to T1518: Removing full OSPF protocol is not possible.

This logic does not allow for the complete removal of the protocol.
https://github.com/vyos/vyatta-cfg-quagga/blob/32cbb1e5059c6c27449b7013f790aff1c50a9831/templates/protocols/ospf/passive-interface/node.def#L29-L35

Oct 30 2020, 10:53 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T2258: VRF route leaking from BGP.

@Azayaka do you mean import routes to a specific table? T3032
Can you check it with the next rolling release?

Oct 30 2020, 10:28 AM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav added a comment to T1289: route-map set route-type blackhole.

@rizkidtn Update, please your request. Is the community works for you for blackholing?

Oct 30 2020, 10:24 AM · VyOS 1.3 Equuleus (1.3.5)
Viacheslav closed T2790: Add ability to set ipv6 protocol route-map for OSPFv3 as Resolved.
Oct 30 2020, 10:07 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T2424: Ability to choose the direction of Mirroring.

I found some interesting information, it seems that inbound/outbound port mirroring can be achieved

Oct 30 2020, 9:51 AM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav added a comment to T3031: Error in Equuleus' help for IPv6 ECMP.

PR https://github.com/vyos/vyos-1x/pull/588

Oct 30 2020, 9:27 AM · vyatta-cfg-system
Viacheslav claimed T3031: Error in Equuleus' help for IPv6 ECMP.
Oct 30 2020, 9:22 AM · vyatta-cfg-system
c-po closed T3033: Update Linux Kernel to v4.19.154 as Resolved.
Oct 30 2020, 9:15 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3033: Update Linux Kernel to v4.19.154.
Oct 30 2020, 9:15 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav changed the status of T3032: Ability to "set table" in the policy route-map from Open to Needs testing.
Oct 30 2020, 9:06 AM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a comment to T3032: Ability to "set table" in the policy route-map.

PR https://github.com/vyos/vyatta-cfg-quagga/pull/56

Oct 30 2020, 9:04 AM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav created T3032: Ability to "set table" in the policy route-map.
Oct 30 2020, 7:29 AM · VyOS 1.2 Crux (VyOS 1.2.8)
SrividyaA added a comment to T3017: bridge will lose the tuntap member after reboots.

Can you please share the entire configuration and version of the VyOS to reproduce the issue in the lab.

Oct 30 2020, 6:28 AM · Invalid

Oct 29 2020

Unknown Object (User) created T3031: Error in Equuleus' help for IPv6 ECMP.
Oct 29 2020, 8:32 PM · vyatta-cfg-system
c-po added a comment to T2587: Cannot enable the interface when the MTU is set to less than 1280.

set interfaces ethernet eth1 ipv6 address no-default-link-local is the right command, yes

Oct 29 2020, 4:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2587: Cannot enable the interface when the MTU is set to less than 1280.

Bug ;) will be fixed soon

Oct 29 2020, 4:26 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3030: Support ERSPAN Tunnel Protocol.

Yes, but iptables tee seems to support packet copy of various rules

Oct 29 2020, 4:26 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3030: Support ERSPAN Tunnel Protocol.

Do you mean that?

set interfaces ethernet eth1 mirror
Oct 29 2020, 4:15 PM · VyOS 1.4 Sagitta
jack9603301 triaged T3030: Support ERSPAN Tunnel Protocol as Wishlist priority.
Oct 29 2020, 3:58 PM · VyOS 1.4 Sagitta
jack9603301 created T3030: Support ERSPAN Tunnel Protocol.
Oct 29 2020, 3:57 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2387: Create XML scheme for [conf_mode] BGP .
  1. Not all interfaces can be used as "update-source"

Missed "vti | dum | lo" etc.
https://github.com/vyos/vyos-1x/blob/current/interface-definitions/protocols-bgp.xml.in#L639

Oct 29 2020, 2:49 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro claimed T2847: System freezes after attempting commit with insufficient memory.
Oct 29 2020, 1:43 PM · VyOS 1.3 Equuleus
Viacheslav added a comment to T2850: Add BGP template for FRR.

PR https://github.com/vyos/vyos-1x/pull/587
Fix the FRR template for new bgp implementation.

Oct 29 2020, 12:51 PM · VyOS 1.3 Equuleus (1.3.0)
cjeanneret added a comment to T3029: Generated NGINX configuration is wrong for the redirection (http -> https).

Pull request is up: https://github.com/vyos/vyos-1x/pull/586

Oct 29 2020, 11:06 AM · VyOS 1.3 Equuleus (1.3.0)
cjeanneret claimed T3029: Generated NGINX configuration is wrong for the redirection (http -> https).
Oct 29 2020, 11:00 AM · VyOS 1.3 Equuleus (1.3.0)
cjeanneret created T3029: Generated NGINX configuration is wrong for the redirection (http -> https).
Oct 29 2020, 10:59 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2587: Cannot enable the interface when the MTU is set to less than 1280.

How to do it?

Oct 29 2020, 6:54 AM · VyOS 1.3 Equuleus (1.3.0)

Oct 28 2020

zsdc changed the status of T3028: Create a default user when metadata is not available (for Cloud-init builds) from In progress to Needs testing.
Oct 28 2020, 10:40 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2587: Cannot enable the interface when the MTU is set to less than 1280.

You actually can when setting ipv6 disable-link-local addressing on the particular interface.

Oct 28 2020, 8:38 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2995: Enhancements/bugfixes for vyos_dict_search() as Resolved.
Oct 28 2020, 6:25 PM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T2995: Enhancements/bugfixes for vyos_dict_search().
Oct 28 2020, 6:25 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2968: Add support for Intel Atom C2000 series QAT as Resolved.
Oct 28 2020, 6:21 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2630: Allow Interface MTU over 9000 as Resolved.
Oct 28 2020, 6:06 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2630: Allow Interface MTU over 9000.
vyos@vyos# set interfaces ethernet eth2 mtu 16000
[edit]
vyos@vyos# commit
[ interfaces ethernet eth2 ]
Interface MTU too high, maximum supported MTU is 9000!
Oct 28 2020, 6:05 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2630: Allow Interface MTU over 9000.
Oct 28 2020, 5:49 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3027: Unable to update system Signature check FAILED as Resolved.
Oct 28 2020, 4:28 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3027: Unable to update system Signature check FAILED.

The root cause for this is the sha256 checksum file itself. It contains the hash and the filename. When running sha256 --check during the upgrade it expects the "real" filename when calculating and verifying the hash. The real filename differs when using the vyos-rolling-latest.iso symlink on the webserver as it will tell the running VyOS installation a different filename and the validation fails. This is now fixed by not depending on the filename when verifying the has. We simply calculate the hash of the downloaded file and compare it to the hash we saved inside the checksum file and totally ignore the filename itself.

Oct 28 2020, 4:25 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T3027: Unable to update system Signature check FAILED.
Oct 28 2020, 4:22 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T2631: l2tp, sstp, pptp add option to disable radius accounting as Resolved.
Oct 28 2020, 4:00 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav updated the task description for T3027: Unable to update system Signature check FAILED.
Oct 28 2020, 3:55 PM · VyOS 1.3 Equuleus (1.3.0)
klase added a comment to T2631: l2tp, sstp, pptp add option to disable radius accounting.

I have tested both SSTP and L2TP and it works as expected - thank you for this addition!

Oct 28 2020, 2:12 PM · VyOS 1.3 Equuleus (1.3.0)
zsdc changed the status of T3028: Create a default user when metadata is not available (for Cloud-init builds) from Open to In progress.
Oct 28 2020, 2:08 PM · VyOS 1.3 Equuleus (1.3.0)
zsdc created T3028: Create a default user when metadata is not available (for Cloud-init builds).
Oct 28 2020, 2:08 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav changed the status of T3027: Unable to update system Signature check FAILED from Open to Confirmed.
Oct 28 2020, 1:01 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav created T3027: Unable to update system Signature check FAILED.
Oct 28 2020, 1:00 PM · VyOS 1.3 Equuleus (1.3.0)

Oct 27 2020

Cheeze_It added a comment to T915: MPLS Support.

Put in a PR to separate hello/hold timers for IPv4 and IPv6. Added IPv6 timers.

Oct 27 2020, 11:54 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
klase added a comment to T2631: l2tp, sstp, pptp add option to disable radius accounting.

I will check it tomorrow and verify operation. Thank you!

Oct 27 2020, 7:55 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T2587: Cannot enable the interface when the MTU is set to less than 1280 as Resolved.

Fixed

vyos@r4-roll# run show version
Oct 27 2020, 7:28 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2631: l2tp, sstp, pptp add option to disable radius accounting.

@klase Check these options in the next rolling release (after 20201027)

Oct 27 2020, 7:15 PM · VyOS 1.3 Equuleus (1.3.0)
lucasec closed T2961: Support "stateless" DHCP-v6 (information-request) clients as Resolved.
Oct 27 2020, 7:01 PM
lucasec closed T2964: pdns_recursor should support explicitly configuring query source address as Resolved.
Oct 27 2020, 7:01 PM
jestabro closed T2582: Script daemon to offload processing during commit as Resolved.
Oct 27 2020, 6:25 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T2885: configd: print commit errors to config session terminal as Resolved.
Oct 27 2020, 6:25 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T2885: configd: print commit errors to config session terminal, a subtask of T2582: Script daemon to offload processing during commit, as Resolved.
Oct 27 2020, 6:25 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T2808: Add smoketest to ensure script consistency with config daemon, a subtask of T2582: Script daemon to offload processing during commit, as Resolved.
Oct 27 2020, 6:25 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T2808: Add smoketest to ensure script consistency with config daemon as Resolved.
Oct 27 2020, 6:25 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro added a comment to T3003: Extend smoketest framework to allow loading an arbitrary config file.

https://github.com/vyos/vyos-1x/pull/583
https://github.com/vyos/vyos-build/pull/129

Oct 27 2020, 6:18 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2638: FRR: New framework for configuring FRR .

FRR doesn't delete isis configuration related "interfaces" with

delete protocols isis foo interface eth1

protocol "isisd" in the test was added here https://github.com/vyos/vyos-1x/pull/483/files#diff-060cdf269ea89160caa0deaebe8e323f0559aa6dfd19e5634a33634f3e38e461R72

Oct 27 2020, 6:04 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a project to T2933: VRRP add option virtual_ipaddress_excluded: Restricted Project.
Oct 27 2020, 5:58 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
Viacheslav closed T2938: Adding remote Syslog RFC5424 compatibility as Resolved.
Oct 27 2020, 5:57 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3014: Clear under op mode and conf mode act differently. Uniting them.

@kroy What PR?

Oct 27 2020, 5:56 PM · VyOS 1.3 Equuleus (1.3.6)
jestabro closed T3026: qemu: update script for deprecated ssh_host_port_min/max as Resolved.
Oct 27 2020, 5:38 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T3026: qemu: update script for deprecated ssh_host_port_min/max, a subtask of T2792: Failed to run `sudo make qemu` with vyos-build container due to the change of packer, as Resolved.
Oct 27 2020, 5:38 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro added a parent task for T3026: qemu: update script for deprecated ssh_host_port_min/max: T2792: Failed to run `sudo make qemu` with vyos-build container due to the change of packer.
Oct 27 2020, 5:18 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro added a subtask for T2792: Failed to run `sudo make qemu` with vyos-build container due to the change of packer: T3026: qemu: update script for deprecated ssh_host_port_min/max.
Oct 27 2020, 5:18 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro created T3026: qemu: update script for deprecated ssh_host_port_min/max.
Oct 27 2020, 5:18 PM · VyOS 1.3 Equuleus (1.3.0)
cjeanneret added a comment to T3023: Add a Let's Encrypt client in the base image.

sounds good - would be good having some other options than just domain-name and email, but that's another story :). I'll follow the other task then!

Oct 27 2020, 5:13 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2387: Create XML scheme for [conf_mode] BGP .

PR https://github.com/vyos/vyos-1x/pull/584

Oct 27 2020, 5:01 PM · VyOS 1.3 Equuleus (1.3.0)
hiroyuki-sato closed T3025: [doc] incorrect git clone command in documentation. as Resolved.

It already fixed in the master branch.
https://github.com/hiroyuki-sato/vyos-documentation/commit/8587946d16aaae6f5495c1e591220f88005cd276

Oct 27 2020, 1:22 PM
SrividyaA closed T2924: Using 'set src' in a route-map invalidates it as part of a subsequent boot-up as Resolved.

Resolved in T2985

Oct 27 2020, 1:16 PM · VyOS 1.3 Equuleus (1.3.0)
hiroyuki-sato triaged T3025: [doc] incorrect git clone command in documentation. as Low priority.
Oct 27 2020, 1:08 PM
Viacheslav closed T1721: Recursive Next Hop not updated for static routes as Resolved.

@SrividyaA Thanks.

Oct 27 2020, 12:43 PM · VyOS 1.3 Equuleus (1.3.0)
SrividyaA added a comment to T1721: Recursive Next Hop not updated for static routes.

I have tested on this rolling release VyOS 1.3-rolling-202010231135 and created a lab setup similar to the reporter's setup.

Oct 27 2020, 12:08 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T3019: incorrect display of the description in the firewall section as Invalid.

@craterman it seems bug with your resolution.

Oct 27 2020, 6:53 AM · VyOS 1.3 Equuleus (1.3.0), vyatta-cfg-firewall

Oct 26 2020

jestabro added a comment to T3023: Add a Let's Encrypt client in the base image.
set service https certificates certbot

domain-name(s) should contain the desired server-name. A rewrite is in progress in:
https://phabricator.vyos.net/T2289

Oct 26 2020, 8:32 PM · VyOS 1.3 Equuleus (1.3.0)
cjeanneret added a comment to T3023: Add a Let's Encrypt client in the base image.

@jestabro hmmm I don't see that "certbot" in the completion - running on rolling 1.3... ? In fact, nodes "certificates" and "certbot" are not shown here:
set service https
Possible completions:
> api VyOS HTTP API configuration
> api-restrict Restrict api proxy to subset of virtual hosts
> certificates TLS certificates
+> virtual-host Identifier for virtual host

Oct 26 2020, 8:23 PM · VyOS 1.3 Equuleus (1.3.0)
liljenstolpe added a comment to T3008: Migrate from ntpd to chronyd.

I've been running chronyd for some time in a number of environments without any noticeable issues. I do think the clock on the hosts seems to be a bit more stable, but not something that is overly remarkable one way or the other. I'd have no problem with the change.

Oct 26 2020, 8:18 PM · VyOS 1.4 Sagitta
liljenstolpe created T3024: DHCPv6 PD configuration doesn't really render an expected behavior.
Oct 26 2020, 8:13 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro added a comment to T3023: Add a Let's Encrypt client in the base image.

It exists:
https://phabricator.vyos.net/T1585

Oct 26 2020, 8:12 PM · VyOS 1.3 Equuleus (1.3.0)
cjeanneret created T3023: Add a Let's Encrypt client in the base image.
Oct 26 2020, 8:10 PM · VyOS 1.3 Equuleus (1.3.0)
cjeanneret created T3022: Allow to provide custom TLS certificates for the HTTP virtual hosts.
Oct 26 2020, 8:05 PM · VyOS 1.5 Circinus
liljenstolpe created T3021: We shouldn't be using pool.ntp.org.
Oct 26 2020, 8:02 PM · VyOS 1.3 Equuleus (1.3.0)
cjeanneret changed the status of T3020: The "scp" example is wrong in the bash-completion for "set system config-management commit-archive location" from Open to In progress.
Oct 26 2020, 7:30 PM · VyOS 1.3 Equuleus (1.3.5)
cjeanneret created T3020: The "scp" example is wrong in the bash-completion for "set system config-management commit-archive location".
Oct 26 2020, 7:11 PM · VyOS 1.3 Equuleus (1.3.5)
Cheeze_It added a comment to T915: MPLS Support.

I put a request on this up top. We'll get to it eventually, but I was hoping we could put it like this:

Oct 26 2020, 6:48 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
craterman created T3019: incorrect display of the description in the firewall section.
Oct 26 2020, 6:24 PM · VyOS 1.3 Equuleus (1.3.0), vyatta-cfg-firewall
craterman added a comment to T915: MPLS Support.

Can you add this commands

Oct 26 2020, 5:39 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
jestabro changed the status of T3003: Extend smoketest framework to allow loading an arbitrary config file from In progress to Needs testing.

This still needs to be integrated into check-qemu-install before PR:
https://github.com/vyos/vyos-1x/compare/current...jestabro:vyos-configtest

Oct 26 2020, 2:44 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2982: show protocols bfd command parse failure.

PR for crux https://github.com/vyos/vyos-1x/pull/582

Oct 26 2020, 1:13 PM · Ready for Crux (1.2.x), VyOS 1.2 Crux
Magnum created T3018: Unclear behaviour when configuring vif and vif-s interfaces.
Oct 26 2020, 1:07 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jingyun created T3017: bridge will lose the tuntap member after reboots.
Oct 26 2020, 11:51 AM · Invalid