Page MenuHomeVyOS Platform
Feed All Stories

Feb 21 2021

c-po removed a subtask for T2579: The root task for VRF features: T2271: OSPF: add per VRF instance support.
Feb 21 2021, 8:48 AM · VyOS 1.3 Equuleus (1.3.6)
c-po removed a parent task for T2271: OSPF: add per VRF instance support: T2579: The root task for VRF features.
Feb 21 2021, 8:48 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a parent task for T2271: OSPF: add per VRF instance support: T3344: Per VRF dynamic routing support.
Feb 21 2021, 8:47 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a subtask for T3344: Per VRF dynamic routing support: T2271: OSPF: add per VRF instance support.
Feb 21 2021, 8:47 AM · VyOS 1.4 Sagitta
c-po changed the status of T3344: Per VRF dynamic routing support from Open to In progress.
Feb 21 2021, 8:46 AM · VyOS 1.4 Sagitta

Feb 20 2021

c-po changed the status of T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500 from Needs testing to Backport pending.
Feb 20 2021, 7:53 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500 from In progress to Needs testing.
Feb 20 2021, 7:53 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T3229: Ethtool CLI Integration.
Feb 20 2021, 6:55 PM · VyOS 1.5 Circinus
c-po added a comment to T3200: LRO can't be tuned off on KVM.

Which VyOS CLI command enables LRO?

Feb 20 2021, 6:50 PM · VyOS 1.3 Equuleus (1.3.0)
SrividyaA added a comment to T3317: OpenVPN config issue.

Hi, I have tried these set of configuration and the openvpn connection was up and working fine.

Feb 20 2021, 3:48 PM · VyOS 1.3 Equuleus (1.3.0)
erkin closed T2647: ipsec disableuniqreqids generate a wrong ipsec.conf as Resolved.
Feb 20 2021, 12:38 AM · VyOS 1.2 Crux (VyOS 1.2.7)

Feb 19 2021

zsdc changed the status of T3338: Some Cloud-Init configurations can prevent login on the router from Open to Confirmed.

I would like to solve this in the next way. I will:

  1. Add verification to our config module to avoid impossible configurations.
  2. Add IPv6 gateway processing (how could I miss this? Cannot imagine...).
Feb 19 2021, 11:29 PM · VyOS 1.4 Sagitta
zsdc added a comment to T3337: Add possibility to serve static DNS zones from the router.

I saw multiple times configs with a firewall section that contains about a thousand lines, so I do not think that DNS records are something size-critical that deserves additional config files.
I believe that keeping config parts outside the config.boot is a bad idea in general that against our main benefit - single config for everything.

Feb 19 2021, 10:45 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
c-po updated subscribers of T3337: Add possibility to serve static DNS zones from the router.

at first glance this looks very interesting. Befor this can be added I would like to give the following comments:

  • adding a cli node that passes raw config values from cli to the daemon is bad (we inherited this for dhcp and openvpn and it caused more harm then good in the last 2 years) - is this mandatory?
  • even dns using A, AAAA, PTR upper case types we should keep the CLI lowercase - this can be easily handled within the Jinja2 template.
  • having > 20 dns records here could really bleow up the CLI, maybe we should thing about loading the zone from a file @zdc @dmbaturin @jestabro?
Feb 19 2021, 9:52 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
c-po closed T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment, a subtask of T2174: Rewrite protocol BGP to new XML/Python style, as Resolved.
Feb 19 2021, 8:40 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment as Resolved.
Feb 19 2021, 8:40 PM · VyOS 1.4 Sagitta
c-po added a comment to T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment.

Thank you for giving out bleeding edge codebase a spin - I will check this out.

Feb 19 2021, 7:23 PM · VyOS 1.4 Sagitta
c-po claimed T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment.
Feb 19 2021, 7:22 PM · VyOS 1.4 Sagitta
c-po added a comment to T3330: Bgp capability orf prefix-list fail.

Can we also extend the available BGP smoketests to test this?

Feb 19 2021, 7:20 PM · VyOS 1.4 Sagitta
Unknown Object (User) closed T3343: Wrong output conntrack-sync status as Invalid.
Feb 19 2021, 6:05 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) edited projects for T3343: Wrong output conntrack-sync status, added: VyOS 1.2 Crux (VyOS 1.2.7); removed VyOS 1.2 Crux.
Feb 19 2021, 6:00 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) changed the status of T3343: Wrong output conntrack-sync status from Open to In progress.
Feb 19 2021, 6:00 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) created T3343: Wrong output conntrack-sync status.
Feb 19 2021, 5:57 PM · VyOS 1.2 Crux (VyOS 1.2.7)
Viacheslav changed the status of T3330: Bgp capability orf prefix-list fail, a subtask of T2174: Rewrite protocol BGP to new XML/Python style, from Open to Needs testing.
Feb 19 2021, 5:19 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav changed the status of T3330: Bgp capability orf prefix-list fail from Open to Needs testing.
Feb 19 2021, 5:19 PM · VyOS 1.4 Sagitta
tom.siewert added a comment to T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment.

I just tried to set up a new router using /31 transfer networks and this also fails with the same error (no BGP unnumbered).

Feb 19 2021, 5:10 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3327: OSPFv3: Cannot add dummy interface.

@ernstjo I can't reproduce it in VyOS 1.4-rolling-202102190541

Feb 19 2021, 4:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3322: Bgp neighbor timers not applyed to FRR config.

PR https://github.com/vyos/vyos-1x/pull/737

Feb 19 2021, 3:09 PM · VyOS 1.4 Sagitta
Viacheslav renamed T3322: Bgp neighbor timers not applyed to FRR config from Bgp timers not applyed to FRR config to Bgp neighbor timers not applyed to FRR config.
Feb 19 2021, 2:52 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3331: Bgp unsuppress-map should be as "value leafNode", a subtask of T2174: Rewrite protocol BGP to new XML/Python style, from Open to Needs testing.
Feb 19 2021, 1:02 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav changed the status of T3331: Bgp unsuppress-map should be as "value leafNode" from Open to Needs testing.
Feb 19 2021, 1:02 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3330: Bgp capability orf prefix-list fail.

PR https://github.com/vyos/vyos-1x/pull/736

Feb 19 2021, 12:03 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3330: Bgp capability orf prefix-list fail.

Template generate wrong value
https://github.com/vyos/vyos-1x/blob/current/data/templates/frr/bgp.frr.tmpl#L112

Feb 19 2021, 11:25 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3331: Bgp unsuppress-map should be as "value leafNode".

PR https://github.com/vyos/vyos-1x/pull/735

Feb 19 2021, 11:08 AM · VyOS 1.4 Sagitta
Viacheslav claimed T3331: Bgp unsuppress-map should be as "value leafNode".
Feb 19 2021, 10:52 AM · VyOS 1.4 Sagitta
haakon.nore added a comment to T3341: Wrong behavior of the "reset vpn ipsec-peer XXX tunnel XXX" command.

I can confirm it is broken for

reset vpn ipsec-peer XXX

too when you run policy-based VPNs.
Peer reset log:

Feb 19 2021, 10:46 AM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0-epa3)
Viacheslav closed T2061: protocol logs not sent to remote syslog as Resolved.
Feb 19 2021, 10:36 AM · VyOS 1.2 Crux (VyOS 1.2.7)
maznu added a comment to T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500.

Sure thing:

Feb 19 2021, 7:47 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500.

A verify() step will be added to prevent certain configurations when a specific type of driver is used. In this case if the xen driver is used, and MTU is > 1500 and sg is not set, a ConfigError() will be raised.

Feb 19 2021, 7:41 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500 from Open to In progress.
Feb 19 2021, 7:38 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3326: OSPFv3: Cannot add L2TPv3 interface as Resolved.
Feb 19 2021, 7:37 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
pasik added a comment to T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts.

Thanks a lot @jestabro ! I'll give it a go with the latest version(s).

Feb 19 2021, 7:16 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
maznu renamed T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500 from Must set "scattergather" offload before MTU to On xen-netback interfaces must set "scattergather" offload before MTU>1500.
Feb 19 2021, 5:00 AM · VyOS 1.3 Equuleus (1.3.0)
maznu updated the task description for T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500.
Feb 19 2021, 4:59 AM · VyOS 1.3 Equuleus (1.3.0)
maznu updated the task description for T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500.
Feb 19 2021, 4:57 AM · VyOS 1.3 Equuleus (1.3.0)
maznu created T3342: On xen-netback interfaces must set "scattergather" offload before MTU>1500.
Feb 19 2021, 4:51 AM · VyOS 1.3 Equuleus (1.3.0)

Feb 18 2021

wsapplegate added a comment to T3337: Add possibility to serve static DNS zones from the router.

Oh, actually I just noticed this was a duplicate of T562, I should have posted there. Sorry about that :-(

Feb 18 2021, 11:50 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
wsapplegate added a comment to T3338: Some Cloud-Init configurations can prevent login on the router.
In T3338#87652, @zsdc wrote:

Can you share details about your hypervisor and datasource? Also as the full Cloud-init log (/var/log/cloud-init.log)?

Feb 18 2021, 11:12 PM · VyOS 1.4 Sagitta
olofl added a comment to T3341: Wrong behavior of the "reset vpn ipsec-peer XXX tunnel XXX" command.

I believe this is the behavior in 1.2.6 aswell?
And I think its not even possible to reset one peer?
So, reset vpn ipsec-peer XXX is broken
as well as reset vpn ipsec-peer XXX tunnel YYY

Feb 18 2021, 10:45 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0-epa3)
jestabro changed Is it a breaking change? from none to compatible on T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts.
Feb 18 2021, 9:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro closed T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts as Resolved.
Feb 18 2021, 9:47 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro moved T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts from In Progress to Finished on the VyOS 1.3 Equuleus board.
Feb 18 2021, 9:47 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro moved T3302: Make vyos-configd relay stdout from scripts to the user's console from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Feb 18 2021, 8:09 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro changed the status of T3302: Make vyos-configd relay stdout from scripts to the user's console, a subtask of T2347: During commit, any script output directed to stdout will contain path, from In progress to Backport candidate.
Feb 18 2021, 8:09 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro changed the status of T3302: Make vyos-configd relay stdout from scripts to the user's console from In progress to Backport candidate.
Feb 18 2021, 8:08 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
zsdc created T3341: Wrong behavior of the "reset vpn ipsec-peer XXX tunnel XXX" command.
Feb 18 2021, 7:39 PM · VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.3 Equuleus (1.3.0-epa3)
c-po added a comment to T3340: Add dhcp-helper package to replace ISC DHCP Relay.

If this package supports all existing setups and the GRE usecase I see no reason to not replace it. @basalblas PR is happily accepted.

Feb 18 2021, 7:36 PM · VyOS 1.5 Circinus
zsdc claimed T3338: Some Cloud-Init configurations can prevent login on the router.

Can you share details about your hypervisor and datasource? Also as the full Cloud-init log (/var/log/cloud-init.log)?
Either datasource generates a wrong config, either the format is not well described in the Cloud-init documentation - there noted that: "gateway: IPv4 address of the default gateway for this subnet". I more believe in the wrong documentation, but would be better to check.
Independently of this all, the situation is not good, because we need to verify values that put into config. So, this will be fixed in one or another way (proper adding or drop), when we figure out details.

Feb 18 2021, 7:35 PM · VyOS 1.4 Sagitta
c-po renamed T3238: Update Linux Kernel to v4.19.178 from Update Linux Kernel to v4.19.169 to Update Linux Kernel to v4.19.176.
Feb 18 2021, 5:50 PM · VyOS 1.2 Crux (VyOS 1.2.7)
c-po updated the task description for T3238: Update Linux Kernel to v4.19.178.
Feb 18 2021, 5:50 PM · VyOS 1.2 Crux (VyOS 1.2.7)
jack9603301 added a comment to T2898: Support NDP proxy.

So I'm unsure how to rewrite that in a clean way, and I would appreciate your and @c-po's opinions on the subject

Feb 18 2021, 5:17 PM · VyOS 1.4 Sagitta
basalblas added a comment to T377: DHCP-relay agent package replacement.

dhcp-helper is working perfectly fine with GRE tunnels, see my feature request https://phabricator.vyos.net/T3340

Feb 18 2021, 3:44 PM · VyOS 1.5 Circinus
basalblas added a project to T3340: Add dhcp-helper package to replace ISC DHCP Relay: VyOS 1.3 Equuleus.
Feb 18 2021, 3:42 PM · VyOS 1.5 Circinus
basalblas added a comment to T3340: Add dhcp-helper package to replace ISC DHCP Relay.

Keep in mind you cannot run dhcp-helper and ISC DHCP server at the same time on a single router. The Vyos CLI should not allow this.

Feb 18 2021, 3:35 PM · VyOS 1.5 Circinus
basalblas created T3340: Add dhcp-helper package to replace ISC DHCP Relay.
Feb 18 2021, 1:40 PM · VyOS 1.5 Circinus
jestabro moved T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts from Backport Candidates to In Progress on the VyOS 1.3 Equuleus board.
Feb 18 2021, 12:44 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
dmbaturin renamed T2759: validate-value prints error messages from validators that fail even if overall validation succeeds from XML: router-advert, bgp: multiple different validators cause error message to pop up even if syntax is valid to validate-value prints error messages from validators that fail even if overall validation succeeds.
Feb 18 2021, 12:44 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
dmbaturin merged task T3321: Bgp not possible to use internal|external remote as into T2759: validate-value prints error messages from validators that fail even if overall validation succeeds.
Feb 18 2021, 12:43 PM · VyOS 1.4 Sagitta
dmbaturin merged T3321: Bgp not possible to use internal|external remote as into T2759: validate-value prints error messages from validators that fail even if overall validation succeeds.
Feb 18 2021, 12:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
jestabro moved T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Feb 18 2021, 12:43 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro moved T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts from Need Triage to Backport Candidates on the VyOS 1.3 Equuleus board.
Feb 18 2021, 12:42 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro added a project to T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts: VyOS 1.4 Sagitta.
Feb 18 2021, 12:41 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
dmbaturin added a comment to T3321: Bgp not possible to use internal|external remote as.

Well, they do work together.

Feb 18 2021, 12:38 PM · VyOS 1.4 Sagitta
wsapplegate added a comment to T2898: Support NDP proxy.

@wsapplegate Have you finished a patch yet?

Feb 18 2021, 11:17 AM · VyOS 1.4 Sagitta
wsapplegate created T3339: Cloud-Init domain search setting not applied.
Feb 18 2021, 10:17 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
wsapplegate created T3338: Some Cloud-Init configurations can prevent login on the router.
Feb 18 2021, 10:02 AM · VyOS 1.4 Sagitta
jack9603301 added a project to T2898: Support NDP proxy: VyOS 1.4 Sagitta.
Feb 18 2021, 9:50 AM · VyOS 1.4 Sagitta
jack9603301 reopened T2898: Support NDP proxy, a subtask of T2518: Support NAT for ipv6(NPT), as Open.
Feb 18 2021, 9:47 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta (1.4.0)
jack9603301 reopened T2898: Support NDP proxy as "Open".
Feb 18 2021, 9:47 AM · VyOS 1.4 Sagitta
jack9603301 reopened T2898: Support NDP proxy, a subtask of T3089: Migrate port mirroring to vyos-1x and support two-way traffic mirroring, as Open.
Feb 18 2021, 9:47 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 updated subscribers of T2898: Support NDP proxy.

@c-po What do you think?

Feb 18 2021, 9:47 AM · VyOS 1.4 Sagitta
wsapplegate added a comment to T2898: Support NDP proxy.
In T2898#80264, @c-po wrote:

That we can deal with later on when it‘s needed

Feb 18 2021, 9:26 AM · VyOS 1.4 Sagitta
wsapplegate created T3337: Add possibility to serve static DNS zones from the router.
Feb 18 2021, 8:47 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.98 / 5.10.16 to Update Linux Kernel to v5.4.99 / 5.10.17.
Feb 18 2021, 7:40 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
jack9603301 updated the task description for T3316: Use Kea DHCP(v6) instead of ISC DHCP(v6).
Feb 18 2021, 7:40 AM · VyOS 1.5 Circinus
wsapplegate added a comment to T3326: OSPFv3: Cannot add L2TPv3 interface.

Yep, got bitten by that too. It's due to some interface types being absent from src/validators/interface-name. Luckily, the solution is pretty easy, here's a patch which adds l2tpeth and friends to that validator:

Feb 18 2021, 6:35 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
wsapplegate created T3336: Spurious error message at boot due to module not loaded early.
Feb 18 2021, 6:27 AM · VyOS 1.4 Sagitta
wsapplegate updated the task description for T3335: Some OSPFv3 show commands do not work.
Feb 18 2021, 6:07 AM · VyOS 1.4 Sagitta
wsapplegate updated the task description for T3334: Changing serial settings from a serial console ends session abruptly.
Feb 18 2021, 6:02 AM · VyOS 1.4 Sagitta
wsapplegate created T3335: Some OSPFv3 show commands do not work.
Feb 18 2021, 5:44 AM · VyOS 1.4 Sagitta
wsapplegate updated the task description for T3334: Changing serial settings from a serial console ends session abruptly.
Feb 18 2021, 4:51 AM · VyOS 1.4 Sagitta
wsapplegate updated the task description for T3334: Changing serial settings from a serial console ends session abruptly.
Feb 18 2021, 4:50 AM · VyOS 1.4 Sagitta
wsapplegate created T3334: Changing serial settings from a serial console ends session abruptly.
Feb 18 2021, 4:49 AM · VyOS 1.4 Sagitta

Feb 17 2021

Viacheslav added a subtask for T2174: Rewrite protocol BGP to new XML/Python style: T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment.
Feb 17 2021, 8:20 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a parent task for T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment: T2174: Rewrite protocol BGP to new XML/Python style.
Feb 17 2021, 8:20 PM · VyOS 1.4 Sagitta
jestabro added a comment to T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts.

@pasik I should have a fix committed soon; thanks for the report !

Feb 17 2021, 7:29 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
pasik added a comment to T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts.

Good job debugging the issue @varesa and @jestabro ! It looks like the actual cause for the deadlock was found already..

Feb 17 2021, 5:56 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
SrividyaA created T3333: "show vpn ipsec sa" reports ESP tunnels to be up when they are not..
Feb 17 2021, 5:28 PM · VyOS 1.2 Crux (VyOS 1.2.8)
tom.siewert created T3332: BGP unnumbered - UnboundLocalError: local variable 'peer_group' referenced before assignment.
Feb 17 2021, 4:58 PM · VyOS 1.4 Sagitta
jestabro changed the status of T3259: many dnat rules makes the vyos http api crash, even showConfig op timeouts from Open to In progress.
Feb 17 2021, 4:50 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta