Page MenuHomeVyOS Platform
Feed All Stories

Sun, Feb 21

c-po removed a subtask for T2579: The root task for VRF features.: T2271: OSPF: add per VRF instance support.
Sun, Feb 21, 8:48 AM · VyOS 1.3 Equuleus
c-po removed a parent task for T2271: OSPF: add per VRF instance support: T2579: The root task for VRF features..
Sun, Feb 21, 8:48 AM · VyOS 1.3 Equuleus
c-po added a parent task for T2271: OSPF: add per VRF instance support: T3344: Per VRF dynamic routing support.
Sun, Feb 21, 8:47 AM · VyOS 1.3 Equuleus
c-po added a subtask for T3344: Per VRF dynamic routing support: T2271: OSPF: add per VRF instance support.
Sun, Feb 21, 8:47 AM · VyOS 1.4 Sagitta
c-po changed the status of T3344: Per VRF dynamic routing support from Open to In progress.
Sun, Feb 21, 8:46 AM · VyOS 1.4 Sagitta

Sat, Feb 20

c-po changed the status of T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500 from Needs testing to Backport pending.
Sat, Feb 20, 7:53 PM · VyOS 1.3 Equuleus
c-po changed the status of T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500 from In progress to Needs testing.
Sat, Feb 20, 7:53 PM · VyOS 1.3 Equuleus
c-po claimed T3229: Ethtool CLI Integration.
Sat, Feb 20, 6:55 PM · VyOS 1.4 Sagitta
c-po added a comment to T3200: LRO can't be tuned off on KVM.

Which VyOS CLI command enables LRO?

Sat, Feb 20, 6:50 PM · VyOS 1.3 Equuleus
SrividyaA added a comment to T3317: OpenVPN config issue.

Hi, I have tried these set of configuration and the openvpn connection was up and working fine.

Sat, Feb 20, 3:48 PM · VyOS 1.3 Equuleus
erkin closed T2647: ipsec disableuniqreqids generate a wrong ipsec.conf as Resolved.
Sat, Feb 20, 12:38 AM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.3 Equuleus

Fri, Feb 19

zsdc changed the status of T3338: Some Cloud-Init configurations can prevent login on the router from Open to Confirmed.

I would like to solve this in the next way. I will:

  1. Add verification to our config module to avoid impossible configurations.
  2. Add IPv6 gateway processing (how could I miss this? Cannot imagine...).
Fri, Feb 19, 11:29 PM · VyOS 1.4 Sagitta
zsdc added a comment to T3337: Add possibility to serve static DNS zones from the router.

I saw multiple times configs with a firewall section that contains about a thousand lines, so I do not think that DNS records are something size-critical that deserves additional config files.
I believe that keeping config parts outside the config.boot is a bad idea in general that against our main benefit - single config for everything.

Fri, Feb 19, 10:45 PM · VyOS 1.4 Sagitta
c-po updated subscribers of T3337: Add possibility to serve static DNS zones from the router.

at first glance this looks very interesting. Befor this can be added I would like to give the following comments:

  • adding a cli node that passes raw config values from cli to the daemon is bad (we inherited this for dhcp and openvpn and it caused more harm then good in the last 2 years) - is this mandatory?
  • even dns using A, AAAA, PTR upper case types we should keep the CLI lowercase - this can be easily handled within the Jinja2 template.
  • having > 20 dns records here could really bleow up the CLI, maybe we should thing about loading the zone from a file @zdc @dmbaturin @jestabro?
Fri, Feb 19, 9:52 PM · VyOS 1.4 Sagitta
c-po closed T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment, a subtask of T2174: Rewrite protocol BGP to new XML/Python style, as Resolved.
Fri, Feb 19, 8:40 PM · VyOS 1.3 Equuleus
c-po closed T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment as Resolved.
Fri, Feb 19, 8:40 PM · VyOS 1.4 Sagitta
c-po added a comment to T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment.

Thank you for giving put bleeding edge codebase a spin - I will check this out.

Fri, Feb 19, 7:23 PM · VyOS 1.4 Sagitta
c-po claimed T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment.
Fri, Feb 19, 7:22 PM · VyOS 1.4 Sagitta
c-po added a comment to T3330: Bgp capability orf prefix-list fail.

Can we also extend the available BGP smoketests to test this?

Fri, Feb 19, 7:20 PM · VyOS 1.4 Sagitta
Dmitry closed T3343: Wrong output conntrack-sync status as Invalid.
Fri, Feb 19, 6:05 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Dmitry edited projects for T3343: Wrong output conntrack-sync status, added: VyOS 1.2 Crux (VyOS 1.2.7); removed VyOS 1.2 Crux.
Fri, Feb 19, 6:00 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Dmitry changed the status of T3343: Wrong output conntrack-sync status from Open to In progress.
Fri, Feb 19, 6:00 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Dmitry created T3343: Wrong output conntrack-sync status.
Fri, Feb 19, 5:57 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Viacheslav changed the status of T3330: Bgp capability orf prefix-list fail, a subtask of T2174: Rewrite protocol BGP to new XML/Python style, from Open to Needs testing.
Fri, Feb 19, 5:19 PM · VyOS 1.3 Equuleus
Viacheslav changed the status of T3330: Bgp capability orf prefix-list fail from Open to Needs testing.
Fri, Feb 19, 5:19 PM · VyOS 1.4 Sagitta
tom.siewert added a comment to T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment.

I just tried to set up a new router using /31 transfer networks and this also fails with the same error (no BGP unnumbered).

Fri, Feb 19, 5:10 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3327: OSPFv3: Cannot add dummy interface.

@ernstjo I can't reproduce it in VyOS 1.4-rolling-202102190541

Fri, Feb 19, 4:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3322: Bgp neighbor timers not applyed to FRR config.

PR https://github.com/vyos/vyos-1x/pull/737

Fri, Feb 19, 3:09 PM · VyOS 1.4 Sagitta
Viacheslav renamed T3322: Bgp neighbor timers not applyed to FRR config from Bgp timers not applyed to FRR config to Bgp neighbor timers not applyed to FRR config.
Fri, Feb 19, 2:52 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3331: Bgp unsuppress-map should be as "value leafNode", a subtask of T2174: Rewrite protocol BGP to new XML/Python style, from Open to Needs testing.
Fri, Feb 19, 1:02 PM · VyOS 1.3 Equuleus
Viacheslav changed the status of T3331: Bgp unsuppress-map should be as "value leafNode" from Open to Needs testing.
Fri, Feb 19, 1:02 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3330: Bgp capability orf prefix-list fail.

PR https://github.com/vyos/vyos-1x/pull/736

Fri, Feb 19, 12:03 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3330: Bgp capability orf prefix-list fail.

Template generate wrong value
https://github.com/vyos/vyos-1x/blob/current/data/templates/frr/bgp.frr.tmpl#L112

Fri, Feb 19, 11:25 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3331: Bgp unsuppress-map should be as "value leafNode".

PR https://github.com/vyos/vyos-1x/pull/735

Fri, Feb 19, 11:08 AM · VyOS 1.4 Sagitta
Viacheslav claimed T3331: Bgp unsuppress-map should be as "value leafNode".
Fri, Feb 19, 10:52 AM · VyOS 1.4 Sagitta
haakon.nore added a comment to T3341: Wrong behavior of the "reset vpn ipsec-peer XXX tunnel XXX" command.

I can confirm it is broken for

reset vpn ipsec-peer XXX

too when you run policy-based VPNs.
Peer reset log:

Fri, Feb 19, 10:46 AM · VyOS 1.4 Sagitta
Viacheslav closed T2061: protocol logs not sent to remote syslog as Resolved.
Fri, Feb 19, 10:36 AM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.3 Equuleus
maznu added a comment to T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500.

Sure thing:

Fri, Feb 19, 7:47 AM · VyOS 1.3 Equuleus
c-po added a comment to T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500.

A verify() step will be added to prevent certain configurations when a specific type of driver is used. In this case if the xen driver is used, and MTU is > 1500 and sg is not set, a ConfigError() will be raised.

Fri, Feb 19, 7:41 AM · VyOS 1.3 Equuleus
c-po changed the status of T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500 from Open to In progress.
Fri, Feb 19, 7:38 AM · VyOS 1.3 Equuleus
c-po closed T3326: OSPFv3: Cannot add L2TPv3 interface as Resolved.
Fri, Feb 19, 7:37 AM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
pasik added a comment to T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts.

Thanks a lot @jestabro ! I'll give it a go with the latest version(s).

Fri, Feb 19, 7:16 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
maznu renamed T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500 from Must set "scattergather" offload before MTU to On xen-netback interfaces must set "scattergather" offload before MTU>1500.
Fri, Feb 19, 5:00 AM · VyOS 1.3 Equuleus
maznu updated the task description for T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500.
Fri, Feb 19, 4:59 AM · VyOS 1.3 Equuleus
maznu updated the task description for T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500.
Fri, Feb 19, 4:57 AM · VyOS 1.3 Equuleus
maznu created T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500.
Fri, Feb 19, 4:51 AM · VyOS 1.3 Equuleus

Thu, Feb 18

wsapplegate added a comment to T3337: Add possibility to serve static DNS zones from the router.

Oh, actually I just noticed this was a duplicate of T562, I should have posted there. Sorry about that :-(

Thu, Feb 18, 11:50 PM · VyOS 1.4 Sagitta
wsapplegate added a comment to T3338: Some Cloud-Init configurations can prevent login on the router.
In T3338#87652, @zsdc wrote:

Can you share details about your hypervisor and datasource? Also as the full Cloud-init log (/var/log/cloud-init.log)?

Thu, Feb 18, 11:12 PM · VyOS 1.4 Sagitta
olofl added a comment to T3341: Wrong behavior of the "reset vpn ipsec-peer XXX tunnel XXX" command.

I believe this is the behavior in 1.2.6 aswell?
And I think its not even possible to reset one peer?
So, reset vpn ipsec-peer XXX is broken
as well as reset vpn ipsec-peer XXX tunnel YYY

Thu, Feb 18, 10:45 PM · VyOS 1.4 Sagitta
jestabro changed Is it a breaking change? from none to compatible on T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts.
Thu, Feb 18, 9:48 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
jestabro closed T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts as Resolved.
Thu, Feb 18, 9:47 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
jestabro moved T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts from In Progress to Finished on the VyOS 1.3 Equuleus board.
Thu, Feb 18, 9:47 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
jestabro moved T3302: Make vyos-configd relay stdout from scripts to the user's console from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Thu, Feb 18, 8:09 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
jestabro changed the status of T3302: Make vyos-configd relay stdout from scripts to the user's console, a subtask of T2347: During commit, any script output directed to stdout will contain path, from In progress to Backport candidate.
Thu, Feb 18, 8:09 PM · VyOS 1.3 Equuleus
jestabro changed the status of T3302: Make vyos-configd relay stdout from scripts to the user's console from In progress to Backport candidate.
Thu, Feb 18, 8:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
zsdc created T3341: Wrong behavior of the "reset vpn ipsec-peer XXX tunnel XXX" command.
Thu, Feb 18, 7:39 PM · VyOS 1.4 Sagitta
c-po added a comment to T3340: Add dhcp-helper package to replace ISC DHCP Relay.

If this package supports all existing setups and the GRE usecase I see no reason to not replace it. @basalblas PR is happily accepted.

Thu, Feb 18, 7:36 PM · VyOS 1.3 Equuleus, vyatta-cfg-dhcp-relay, VyConf
zsdc claimed T3338: Some Cloud-Init configurations can prevent login on the router.

Can you share details about your hypervisor and datasource? Also as the full Cloud-init log (/var/log/cloud-init.log)?
Either datasource generates a wrong config, either the format is not well described in the Cloud-init documentation - there noted that: "gateway: IPv4 address of the default gateway for this subnet". I more believe in the wrong documentation, but would be better to check.
Independently of this all, the situation is not good, because we need to verify values that put into config. So, this will be fixed in one or another way (proper adding or drop), when we figure out details.

Thu, Feb 18, 7:35 PM · VyOS 1.4 Sagitta
c-po renamed T3238: Update Linux Kernel to v4.19.178 from Update Linux Kernel to v4.19.169 to Update Linux Kernel to v4.19.176.
Thu, Feb 18, 5:50 PM · VyOS 1.2 Crux (VyOS 1.2.7)
c-po updated the task description for T3238: Update Linux Kernel to v4.19.178.
Thu, Feb 18, 5:50 PM · VyOS 1.2 Crux (VyOS 1.2.7)
jack9603301 added a comment to T2898: Support NDP proxy.

So I'm unsure how to rewrite that in a clean way, and I would appreciate your and @c-po's opinions on the subject

Thu, Feb 18, 5:17 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
basalblas added a comment to T377: DHCP-relay agent package replacement.

dhcp-helper is working perfectly fine with GRE tunnels, see my feature request https://phabricator.vyos.net/T3340

Thu, Feb 18, 3:44 PM · VyOS 1.4 Sagitta
basalblas added a project to T3340: Add dhcp-helper package to replace ISC DHCP Relay: VyOS 1.3 Equuleus.
Thu, Feb 18, 3:42 PM · VyOS 1.3 Equuleus, vyatta-cfg-dhcp-relay, VyConf
basalblas added a comment to T3340: Add dhcp-helper package to replace ISC DHCP Relay.

Keep in mind you cannot run dhcp-helper and ISC DHCP server at the same time on a single router. The Vyos CLI should not allow this.

Thu, Feb 18, 3:35 PM · VyOS 1.3 Equuleus, vyatta-cfg-dhcp-relay, VyConf
basalblas created T3340: Add dhcp-helper package to replace ISC DHCP Relay.
Thu, Feb 18, 1:40 PM · VyOS 1.3 Equuleus, vyatta-cfg-dhcp-relay, VyConf
jestabro moved T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts from Backport Candidates to In Progress on the VyOS 1.3 Equuleus board.
Thu, Feb 18, 12:44 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
dmbaturin renamed T2759: validate-value prints error messages from validators that fail even if overall validation succeeds from XML: router-advert, bgp: multiple different validators cause error message to pop up even if syntax is valid to validate-value prints error messages from validators that fail even if overall validation succeeds.
Thu, Feb 18, 12:44 PM · VyOS 1.3 Equuleus
dmbaturin merged task T3321: Bgp not possible to use internal|external remote as into T2759: validate-value prints error messages from validators that fail even if overall validation succeeds.
Thu, Feb 18, 12:43 PM · VyOS 1.4 Sagitta
dmbaturin merged T3321: Bgp not possible to use internal|external remote as into T2759: validate-value prints error messages from validators that fail even if overall validation succeeds.
Thu, Feb 18, 12:43 PM · VyOS 1.3 Equuleus
jestabro moved T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Thu, Feb 18, 12:43 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
jestabro moved T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts from Need Triage to Backport Candidates on the VyOS 1.3 Equuleus board.
Thu, Feb 18, 12:42 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
jestabro added a project to T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts: VyOS 1.4 Sagitta.
Thu, Feb 18, 12:41 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
dmbaturin added a comment to T3321: Bgp not possible to use internal|external remote as.

Well, they do work together.

Thu, Feb 18, 12:38 PM · VyOS 1.4 Sagitta
wsapplegate added a comment to T2898: Support NDP proxy.

@wsapplegate Have you finished a patch yet?

Thu, Feb 18, 11:17 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
wsapplegate created T3339: Cloud-Init domain search setting not applied.
Thu, Feb 18, 10:17 AM
wsapplegate created T3338: Some Cloud-Init configurations can prevent login on the router.
Thu, Feb 18, 10:02 AM · VyOS 1.4 Sagitta
jack9603301 added a project to T2898: Support NDP proxy: VyOS 1.4 Sagitta.
Thu, Feb 18, 9:50 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
jack9603301 reopened T2898: Support NDP proxy, a subtask of T2518: Support NAT for ipv6(NPT), as Open.
Thu, Feb 18, 9:47 AM · VyOS 1.4 Sagitta
jack9603301 reopened T2898: Support NDP proxy as "Open".
Thu, Feb 18, 9:47 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
jack9603301 reopened T2898: Support NDP proxy, a subtask of T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring, as Open.
Thu, Feb 18, 9:47 AM · VyOS 1.3 Equuleus
jack9603301 updated subscribers of T2898: Support NDP proxy.

@c-po @runar What do you think?

Thu, Feb 18, 9:47 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
wsapplegate added a comment to T2898: Support NDP proxy.
In T2898#80264, @c-po wrote:

That we can deal with later on when it‘s needed

Thu, Feb 18, 9:26 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
wsapplegate created T3337: Add possibility to serve static DNS zones from the router.
Thu, Feb 18, 8:47 AM · VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.102 / 5.10.20 from Update Linux Kernel to v5.4.98 / 5.10.16 to Update Linux Kernel to v5.4.99 / 5.10.17.
Thu, Feb 18, 7:40 AM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
jack9603301 updated the task description for T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).
Thu, Feb 18, 7:40 AM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
wsapplegate added a comment to T3326: OSPFv3: Cannot add L2TPv3 interface.

Yep, got bitten by that too. It's due to some interface types being absent from src/validators/interface-name. Luckily, the solution is pretty easy, here's a patch which adds l2tpeth and friends to that validator:

Thu, Feb 18, 6:35 AM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
wsapplegate created T3336: Spurious error message at boot due to module not loaded early.
Thu, Feb 18, 6:27 AM · VyOS 1.4 Sagitta
wsapplegate updated the task description for T3335: Some OSPFv3 show commands do not work.
Thu, Feb 18, 6:07 AM · VyOS 1.4 Sagitta
wsapplegate updated the task description for T3334: Changing serial settings from a serial console ends session abruptly.
Thu, Feb 18, 6:02 AM · VyOS 1.4 Sagitta
wsapplegate created T3335: Some OSPFv3 show commands do not work.
Thu, Feb 18, 5:44 AM · VyOS 1.4 Sagitta
wsapplegate updated the task description for T3334: Changing serial settings from a serial console ends session abruptly.
Thu, Feb 18, 4:51 AM · VyOS 1.4 Sagitta
wsapplegate updated the task description for T3334: Changing serial settings from a serial console ends session abruptly.
Thu, Feb 18, 4:50 AM · VyOS 1.4 Sagitta
wsapplegate created T3334: Changing serial settings from a serial console ends session abruptly.
Thu, Feb 18, 4:49 AM · VyOS 1.4 Sagitta

Wed, Feb 17

Viacheslav added a subtask for T2174: Rewrite protocol BGP to new XML/Python style: T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment.
Wed, Feb 17, 8:20 PM · VyOS 1.3 Equuleus
Viacheslav added a parent task for T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment: T2174: Rewrite protocol BGP to new XML/Python style.
Wed, Feb 17, 8:20 PM · VyOS 1.4 Sagitta
jestabro added a comment to T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts.

@pasik I should have a fix committed soon; thanks for the report !

Wed, Feb 17, 7:29 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
pasik added a comment to T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts.

Good job debugging the issue @varesa and @jestabro ! It looks like the actual cause for the deadlock was found already..

Wed, Feb 17, 5:56 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
SrividyaA created T3333: "show vpn ipsec sa" reports ESP tunnels to be up when they are not..
Wed, Feb 17, 5:28 PM · VyOS 1.4 Sagitta, VyOS 1.2 Crux
tom.siewert created T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment.
Wed, Feb 17, 4:58 PM · VyOS 1.4 Sagitta
jestabro changed the status of T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts from Open to In progress.
Wed, Feb 17, 4:50 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus