Page MenuHomeVyOS Platform
Feed All Stories

Jun 7 2021

trae32566 created T3604: Changing BGP Neighbor Peer-Group Association Causes Routing Subsystem Failure.
Jun 7 2021, 8:31 PM
trae32566 added a comment to T3602: Renaming BGP Peer Groups Leaves Router Broken.

This is indeed fixed!

Jun 7 2021, 8:27 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T3358: VRRP: Is it necessary to support switches between master and backup with script? as Invalid.

@arvin This functions in all versions of VyOS.

Jun 7 2021, 7:08 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the subtype of T2763: New SNMP resource request - SNMP over TCP from "Task" to "Feature Request".
Jun 7 2021, 6:35 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
UnicronNL claimed T3339: Cloud-Init domain search setting not applied.
Jun 7 2021, 6:32 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav added a comment to T2855: disabled vti interfaces still working.

I can't reproduce it in 1.2.7 and VyOS 1.3-beta-202105272051

Jun 7 2021, 6:25 PM · VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a comment to T3017: bridge will lose the tuntap member after reboots.

@jingyun Can you describe steps on how to reproduce it? Or re-check it.
My test config after reboot works fine

set interfaces bridge br0 member interface tun0
set interfaces tunnel tun0 encapsulation 'gre-bridge'
set interfaces tunnel tun0 local-ip '100.64.0.1'
set interfaces tunnel tun0 remote-ip '100.64.0.254'
Jun 7 2021, 6:08 PM · Invalid
Viacheslav moved T3138: ddclient improperly updated when apply rfc2136 config from Need Triage to Backport Candidates on the VyOS 1.4 Sagitta board.
Jun 7 2021, 5:20 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po closed T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 7 2021, 5:10 PM · VyOS 1.4 Sagitta
c-po closed T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan as Resolved.
Jun 7 2021, 5:10 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 7 2021, 5:09 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3602: Renaming BGP Peer Groups Leaves Router Broken, a subtask of T3182: Main blocker Task for FRR 7.4/7.5 series update, from Open to Needs testing.
Jun 7 2021, 4:40 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the status of T3602: Renaming BGP Peer Groups Leaves Router Broken from Open to Needs testing.
Jun 7 2021, 4:40 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav closed T3516: FRR 7.5 adds a second route when you attempt to change a static route distance instead of overwriting the old route, a subtask of T3182: Main blocker Task for FRR 7.4/7.5 series update, as Resolved.
Jun 7 2021, 4:39 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T3516: FRR 7.5 adds a second route when you attempt to change a static route distance instead of overwriting the old route as Resolved.
Jun 7 2021, 4:39 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav claimed T3602: Renaming BGP Peer Groups Leaves Router Broken.
Jun 7 2021, 4:35 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3602: Renaming BGP Peer Groups Leaves Router Broken.

PR https://github.com/vyos/vyatta-cfg-quagga/pull/81

Jun 7 2021, 4:20 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a subtask for T3182: Main blocker Task for FRR 7.4/7.5 series update: T3602: Renaming BGP Peer Groups Leaves Router Broken.
Jun 7 2021, 2:44 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav added a parent task for T3602: Renaming BGP Peer Groups Leaves Router Broken: T3182: Main blocker Task for FRR 7.4/7.5 series update.
Jun 7 2021, 2:44 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3602: Renaming BGP Peer Groups Leaves Router Broken.

https://github.com/vyos/vyatta-cfg-quagga/blob/fef5870b764e6166b639043fadb9317c8a49881d/scripts/bgp/vyatta-bgp.pl#L621-L625
https://github.com/vyos/vyatta-cfg-quagga/blob/fef5870b764e6166b639043fadb9317c8a49881d/scripts/bgp/vyatta-bgp.pl#L802-L806

Jun 7 2021, 2:31 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

In the crux.

set system conntrack timeout custom rule 10 destination address '203.0.113.74'
set system conntrack timeout custom rule 10 destination port '80'
set system conntrack timeout custom rule 10 protocol tcp established '300'
set system conntrack timeout custom rule 10 source address '192.0.2.168'

commit

vyos@r2-lts# commit
[ system conntrack hash-size 32768 ]
Updated conntrack hash size. This change will take affect when the system is rebooted.
Jun 7 2021, 12:39 PM · VyOS 1.4 Sagitta
anthr76 added a comment to T3600: DHCP Interface static route breaks PBR.

It looks like your assessment is correct. It also seems like next-hop IP would be sufficient as well if I wasn't dealing with dynamic WAN IPs. For the moment I'm sticking with interface instead of dhcp-interface. The related issue you sent seems exactly related to this.

Jun 7 2021, 11:55 AM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T3505: Commits do not respect changes in FRR that are not stored in a config: T3600: DHCP Interface static route breaks PBR.
Jun 7 2021, 9:17 AM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3600: DHCP Interface static route breaks PBR: T3505: Commits do not respect changes in FRR that are not stored in a config.
Jun 7 2021, 9:17 AM · VyOS 1.4 Sagitta
sarthurdev added a comment to T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.

Clarifying as requested by c-po:

Jun 7 2021, 9:12 AM · VyOS 1.4 Sagitta
vindenesen added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

I believe I have found out why modification/deletion of rules fails. This is the rule definition in iptables:

Jun 7 2021, 9:10 AM · VyOS 1.4 Sagitta
trae32566 created T3602: Renaming BGP Peer Groups Leaves Router Broken.
Jun 7 2021, 8:39 AM · VyOS 1.3 Equuleus (1.3.0)

Jun 6 2021

fernando added a comment to T3600: DHCP Interface static route breaks PBR.

I think it is also related https://phabricator.vyos.net/T3522

Jun 6 2021, 9:53 PM · VyOS 1.4 Sagitta
fernando added a comment to T3600: DHCP Interface static route breaks PBR.

I have checked that functionality , i can replicate the issues .although there is a workaround if you "set protocols static table 11 route 0.0.0.0/0 dhcp-interface " any interfaces , it doesn't see in your table ( table 10 /11 ) we can see theses routes in the default table , let me show :

Jun 6 2021, 9:50 PM · VyOS 1.4 Sagitta
c-po closed T842: Adopt VyOS CLI to latest StrongSwan options and deprecated Keywords, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 6 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po closed T842: Adopt VyOS CLI to latest StrongSwan options and deprecated Keywords, a subtask of T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan, as Resolved.
Jun 6 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po closed T842: Adopt VyOS CLI to latest StrongSwan options and deprecated Keywords as Resolved.
Jun 6 2021, 5:35 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 6 2021, 5:17 PM · VyOS 1.4 Sagitta
erkin claimed T3459: Inform the user when unable to install outdated image.
Jun 6 2021, 2:21 PM · VyOS 1.4 Sagitta
UnicronNL triaged T3601: Error in ssh keys for vmware cloud-init if ssh keys is left empty. as Normal priority.
Jun 6 2021, 1:09 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 6 2021, 9:11 AM · VyOS 1.4 Sagitta

Jun 5 2021

anthr76 created T3600: DHCP Interface static route breaks PBR.
Jun 5 2021, 11:41 PM · VyOS 1.4 Sagitta

Jun 4 2021

sarthurdev changed the status of T3599: Migrate NHRP to XML/Python from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/865

Jun 4 2021, 9:55 PM · VyOS 1.4 Sagitta
c-po added a comment to T3040: NHRP IPv6 Support.

Hi @francis the latest FRR version lacks support for Cisco authentication https://github.com/FRRouting/frr/blob/master/nhrpd/nhrp_peer.c#L1212

Jun 4 2021, 6:33 PM · VyOS 1.5 Circinus
c-po closed T3595: Cannot create new VTI interface, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Jun 4 2021, 5:34 PM · VyOS 1.4 Sagitta
c-po closed T3595: Cannot create new VTI interface as Resolved.
Jun 4 2021, 5:34 PM · VyOS 1.4 Sagitta
c-po updated the task description for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 4 2021, 5:33 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T3599: Migrate NHRP to XML/Python from Open to In progress.
Jun 4 2021, 5:28 PM · VyOS 1.4 Sagitta
francis added a comment to T3040: NHRP IPv6 Support.

@c-po with this merge on FRR https://github.com/FRRouting/frr/pull/8153#event-4589485067 is migration possible? Possibly related to https://phabricator.vyos.net/T2326

Jun 4 2021, 4:45 PM · VyOS 1.5 Circinus
francis added a comment to T2326: Migrate NHRP(DMVPN) to FRR.
Jun 4 2021, 4:44 PM · VyOS 1.5 Circinus
jack9603301 added a comment to T3596: Support wide-dhcp6-relay.

I wonder why this is flagged only as refactoring bit you open an entire new CLI tree.

Jun 4 2021, 2:34 PM · VyOS 1.5 Circinus
c-po added a comment to T3596: Support wide-dhcp6-relay.

Hi Jack,

Jun 4 2021, 2:04 PM · VyOS 1.5 Circinus
jack9603301 added a comment to T3596: Support wide-dhcp6-relay.

PR draft: https://github.com/vyos/vyos-1x/pull/863

Jun 4 2021, 1:08 PM · VyOS 1.5 Circinus
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.123 / 5.10.41 to Update Linux Kernel to v5.4.124 / 5.10.42.
Jun 4 2021, 12:55 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po moved T3195: Add support for cisco style GRE keepalives from Need Triage to Backlog on the VyOS 1.4 Sagitta board.
Jun 4 2021, 12:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po changed the status of T3195: Add support for cisco style GRE keepalives from Open to Needs testing.
Jun 4 2021, 12:52 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T3195: Add support for cisco style GRE keepalives from Need Triage to Backlog on the VyOS 1.3 Equuleus board.
Jun 4 2021, 12:51 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po moved T3592: Set default TTL 64 for tunnels from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 4 2021, 12:51 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3592: Set default TTL 64 for tunnels from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Jun 4 2021, 12:50 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3594: Disable by default service strongswan-starter from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Jun 4 2021, 12:50 PM · VyOS 1.4 Sagitta
c-po closed T3592: Set default TTL 64 for tunnels as Resolved.
Jun 4 2021, 12:50 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po moved T3132: Enable egress flow accounting from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Jun 4 2021, 12:39 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po added a project to T3132: Enable egress flow accounting: VyOS 1.3 Equuleus.
Jun 4 2021, 12:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Jun 3 2021

fernando added a comment to T3578: Prefix-List(6) update cause empty prefix-list(6).

Sorry for confusing with the status of the ticket , I wanted to put in pending . I was trying to replicate the issues in a lab environment but it wasn't possible , let me show :

Jun 3 2021, 10:52 PM · VyOS 1.4 Sagitta
rpeterson changed the status of T3233: Interface redirect to dum0 from Invalid to Resolved.

I got it to work with version 1.4-rolling-202105291042. Here's the configuration that works:

Jun 3 2021, 9:59 PM · VyOS 1.4 Sagitta
jpbede added a comment to T3132: Enable egress flow accounting.

@tuxis-ie found the issue. Used the wrong iptables chain. See https://github.com/vyos/vyos-1x/pull/864

Jun 3 2021, 4:37 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 changed Difficulty level from normal to hard on T3116: Support back-end L4 level load balancing.
Jun 3 2021, 4:10 PM · VyOS 1.4 Sagitta
dmbaturin changed Is it a breaking change? from none to behavior on T3592: Set default TTL 64 for tunnels.
Jun 3 2021, 3:59 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sarthurdev created T3598: DMVPN/IPSec does not work with upstream Strongswan 5.9.
Jun 3 2021, 2:32 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
jpbede added a comment to T3132: Enable egress flow accounting.

@tuxis-ie thanks for testing this out. Will check this.

Jun 3 2021, 1:57 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T3593: PPPoE server called-sid format does not work from In progress to Backport candidate.

Please, backport it to 1.3 rolling https://phabricator.vyos.net/rVYOSONEX4b646c1fb31a1a9f9c9d1658734d478fed5f19f1

Jun 3 2021, 12:36 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
RyVolodya added a comment to T3593: PPPoE server called-sid format does not work.

This bag is present in VyOS version 1.3-beta-202105271929

Jun 3 2021, 12:34 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jack9603301 changed the subtype of T3596: Support wide-dhcp6-relay from "Bug" to "Feature Request".
Jun 3 2021, 11:21 AM · VyOS 1.5 Circinus
jack9603301 changed the subtype of T3596: Support wide-dhcp6-relay from "Feature Request" to "Bug".
Jun 3 2021, 10:45 AM · VyOS 1.5 Circinus
vindenesen added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

I tried to create a custom timeout rule for tcp port 80. First I assumed that everything was fine since the first commit succeeded without error messages. But when I wanted to alter the rule, it failed. Below you see an example where I first create a rule, and then try to delete it. Afterwards any commits regarding custom timeouts fails.

Jun 3 2021, 8:30 AM · VyOS 1.4 Sagitta
c-po added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

Yes, also this part will be migrated in the next couple of weeks as we plan to get rid of all legacy code in the 1.4 release cycle.

Jun 3 2021, 7:42 AM · VyOS 1.4 Sagitta
c-po changed the status of T3595: Cannot create new VTI interface, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, from Open to Confirmed.
Jun 3 2021, 7:40 AM · VyOS 1.4 Sagitta
c-po changed the status of T3595: Cannot create new VTI interface from Open to Confirmed.
Jun 3 2021, 7:40 AM · VyOS 1.4 Sagitta
c-po claimed T3595: Cannot create new VTI interface.
Jun 3 2021, 7:38 AM · VyOS 1.4 Sagitta
jack9603301 closed T3384: Support UDP bandwidth testing as Resolved.
Jun 3 2021, 6:53 AM · VyOS 1.4 Sagitta
vindenesen added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

Will the custom timeout feature also be implemented in the python code? This is an option in the perl flavour (but doesn't actually work in 1.3 RC4).

Jun 3 2021, 6:37 AM · VyOS 1.4 Sagitta

Jun 2 2021

Viacheslav added a comment to T3595: Cannot create new VTI interface.

It seems after that commit
but it is not a root case

Jun 2 2021, 7:54 PM · VyOS 1.4 Sagitta
Viacheslav added a subtask for T2816: Rewrite IPsec scripts with the new XML/Python approach: T3595: Cannot create new VTI interface.
Jun 2 2021, 7:52 PM · VyOS 1.4 Sagitta
Viacheslav added a parent task for T3595: Cannot create new VTI interface: T2816: Rewrite IPsec scripts with the new XML/Python approach.
Jun 2 2021, 7:52 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T3595: Cannot create new VTI interface, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Jun 2 2021, 7:51 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T3597: Add tunnels FOO over UDP (FOU).
Jun 2 2021, 7:33 PM · VyOS 1.5 Circinus
Viacheslav created T3597: Add tunnels FOO over UDP (FOU).
Jun 2 2021, 5:08 PM · VyOS 1.5 Circinus
jack9603301 changed the subtype of T3596: Support wide-dhcp6-relay from "Task" to "Feature Request".
Jun 2 2021, 4:46 PM · VyOS 1.5 Circinus
jack9603301 claimed T3596: Support wide-dhcp6-relay.
Jun 2 2021, 2:54 PM · VyOS 1.5 Circinus
jack9603301 created T3596: Support wide-dhcp6-relay.
Jun 2 2021, 2:53 PM · VyOS 1.5 Circinus
erkin changed the status of T3556: Commit-archive via scp causes 100% CPU on boot from Open to Needs testing.
Jun 2 2021, 9:57 AM · VyOS 1.4 Sagitta
erkin changed the status of T3556: Commit-archive via scp causes 100% CPU on boot, a subtask of T3356: Script for remote file transfers, from Open to Needs testing.
Jun 2 2021, 9:57 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin changed the status of T3563: commit-archive breaks with IPv6 source addresses, a subtask of T3356: Script for remote file transfers, from Needs testing to In progress.
Jun 2 2021, 9:53 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin changed the status of T3563: commit-archive breaks with IPv6 source addresses from Needs testing to In progress.
Jun 2 2021, 9:53 AM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T3546: Add support for running scripts on PPPoE server session events.

Extended scripts receive from PPPoE daemon the following variables:

$1 - Interface name
$4 - Tunnel GW IP address
$5 - Delegated IP address to the client
$6 - Calling Station ID (MAC)

For example, how to get received RADIUS attributes
note: In this case, Filter-Id attribute used as an indicator for block user adding to ipset

configure
set firewall group address-group blocked 
commit
Jun 2 2021, 8:44 AM · VyOS 1.3 Equuleus (1.3.4)
erkin changed the status of T2855: disabled vti interfaces still working from Open to Needs testing.

Waiting for T3595 to clear up before I can test this on rolling release.

Jun 2 2021, 8:40 AM · VyOS 1.2 Crux (VyOS 1.2.8)
erkin created T3595: Cannot create new VTI interface.
Jun 2 2021, 8:07 AM · VyOS 1.4 Sagitta
erkin changed the status of T2911: new pppoe warnings recently from Open to Needs testing.
Jun 2 2021, 7:38 AM
erkin closed T3233: Interface redirect to dum0 as Invalid.

I cannot replicate this bug in a clean install of 1.4-rolling-202105291042.

vyos@vyos# set interfaces dummy dum0 address 192.168.201.1/24
[edit]
vyos@vyos# commit
[edit]

Either there's something in your config meddling with the interface creation or (most likely) this bug was solved in the main branch since then.

Jun 2 2021, 7:34 AM · VyOS 1.4 Sagitta
tuxis-ie added a comment to T3132: Enable egress flow accounting.

We upgraded to 1.3.0-rc4 last night and enabled enable-egress, which indeed sends out egress traffic as well. However, the macaddresses are all zero:

Jun 2 2021, 7:06 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Jun 1 2021

c-po added a subtask for T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan: T842: Adopt VyOS CLI to latest StrongSwan options and deprecated Keywords.
Jun 1 2021, 8:46 PM · VyOS 1.4 Sagitta
c-po added a parent task for T842: Adopt VyOS CLI to latest StrongSwan options and deprecated Keywords: T3588: IPSec: migrate no longer available options from CLI which are now hardcoded/enabled in strongSwan.
Jun 1 2021, 8:46 PM · VyOS 1.4 Sagitta
ernstjo added a comment to T3578: Prefix-List(6) update cause empty prefix-list(6).

I can reproduce the issue on our productive route in following way:

Jun 1 2021, 7:42 PM · VyOS 1.4 Sagitta
c-po added a comment to T3195: Add support for cisco style GRE keepalives.

Why not use the mentioned method of sysctl`

Jun 1 2021, 7:16 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
c-po added a comment to T3214: OpenVPN IPv6 fixes.

@shaferstockton can you please post your entire generated openvpn.conf file?

Jun 1 2021, 7:12 PM · VyOS 1.5 Circinus