Page MenuHomeVyOS Platform
Feed All Stories

Oct 14 2021

c-po added a comment to T3801: containers: do not use podman CLI to create container networks.

Yes, closing this ...

Oct 14 2021, 6:41 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3702: Policy: Allow routing by fwmark from Open to Needs testing.
Oct 14 2021, 6:14 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta
Viacheslav added a comment to T3801: containers: do not use podman CLI to create container networks.

@c-po Is it already implemented with commit https://github.com/vyos/vyos-1x/commit/ae2dc55aa68679e828d4bb133fc515172c081d0f ?

Oct 14 2021, 5:36 PM · VyOS 1.4 Sagitta
Viacheslav closed T3811: NAT (op_mode): NAT op_mode command fails. as Resolved.

Fixed, VyOS 1.4-rolling-202110130217

vyos@r1-roll:~$ show nat source rules 
Rule       Source                                             Translation                                        Outbound Interface
----       ------                                             -----------                                        ------------------
3          192.168.0.0/24                                     masquerade                                         eth0
Oct 14 2021, 5:30 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T3810: webproxy squidguard rules don't work properly after rewriting to python. .
Oct 14 2021, 5:15 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav updated the task description for T3810: webproxy squidguard rules don't work properly after rewriting to python. .
Oct 14 2021, 5:15 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
UnicronNL closed T3908: [CLOUDINIT] if the fqdn has no domain name cloudinit will fail to run as Invalid.

Is a double task, it looks like the package is not update upstream.

Oct 14 2021, 3:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
UnicronNL created T3908: [CLOUDINIT] if the fqdn has no domain name cloudinit will fail to run.
Oct 14 2021, 3:01 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
jestabro added a comment to T3876: Replace vyos-netplug with a VyOS link state monitor service.

Work in progress:
https://github.com/vyos/vyos-1x/compare/current...jestabro:linkstate
https://github.com/vyos/vyos-build/compare/current...jestabro:linkstate

Oct 14 2021, 1:38 PM · VyOS 1.5 Circinus
n.fort added a comment to T3907: Firewall - Set log levels.

Maybe, but if the effort is made in order to be able to configure log level, it would be good that it can be set in different levels.
I'm thinking in a mix scenario, where majority of rules may log with info/debug level (for example default accept rules), while other rules may need a warning/error level (some drop rules).

Oct 14 2021, 1:00 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3907: Firewall - Set log levels.

As for me, it should be configured in the global firewall log level, not per rule.

set firewall log-level x
Oct 14 2021, 12:52 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3832: Allow to set DHCP client-id in hexadecimal format.

PR https://github.com/vyos/vyos-1x/pull/1026

Oct 14 2021, 12:43 PM · VyOS 1.4 Sagitta
n.fort created T3907: Firewall - Set log levels.
Oct 14 2021, 12:31 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3832: Allow to set DHCP client-id in hexadecimal format from Open to In progress.
Oct 14 2021, 12:19 PM · VyOS 1.4 Sagitta
Viacheslav reassigned T3865: loadkey command help text missing escape sequence from Viacheslav to chaya2z.

PR https://github.com/vyos/vyatta-cfg-system/pull/170

Oct 14 2021, 10:22 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3865: loadkey command help text missing escape sequence from Open to In progress.
Oct 14 2021, 10:15 AM · VyOS 1.4 Sagitta
Viacheslav moved T3763: wireguard checks if port already binding from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 14 2021, 9:07 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3906: [Traffic Control] Invalid Port Configuration Still Commits.

The real bug is it shouldn't allow port-range values as it is not implemented.
Or just add this feature T2798

Oct 14 2021, 8:55 AM · Known issue, VyOS 1.4 Sagitta
trae32566 created T3906: [Traffic Control] Invalid Port Configuration Still Commits.
Oct 14 2021, 8:28 AM · Known issue, VyOS 1.4 Sagitta
trae32566 awarded T2798: Allow port range in tc filter a Like token.
Oct 14 2021, 8:13 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta, vyatta-cfg-qos
SquirePug added a comment to T3896: Extend ocserv support to allow for per-group configs.

For this we create text files as the group-config includes (they contain route and other per group config directives, generally around security).

Oct 14 2021, 7:05 AM · VyOS 1.4 Sagitta
adaker created T3905: Add NAS-Identifier for system login.
Oct 14 2021, 1:00 AM · VyOS 1.4 Sagitta

Oct 13 2021

Georgiy-Tugai awarded T3008: Migrate from ntpd to chronyd a Like token.
Oct 13 2021, 3:39 PM · VyOS 1.4 Sagitta
Georgiy-Tugai added a comment to T3008: Migrate from ntpd to chronyd.

图片.png (754×1 px, 114 KB)

图片.png (499×1 px, 60 KB)

Does anyone understand the meaning of these performance data? I don’t know the unit of these data

Oct 13 2021, 3:38 PM · VyOS 1.4 Sagitta
c-po closed T3904: NTP pool associations silently fail as Resolved.
Oct 13 2021, 12:08 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3904: NTP pool associations silently fail from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 13 2021, 12:08 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3904: NTP pool associations silently fail from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 13 2021, 12:08 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po changed the status of T3904: NTP pool associations silently fail from Open to In progress.
Oct 13 2021, 12:03 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
Georgiy-Tugai created T3904: NTP pool associations silently fail.
Oct 13 2021, 11:21 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
FileGo added a comment to T3902: Firewall does not load on boot, address-group not found, even though it exists.

If I change the double-quotes to single-quotes for all the rules in that firewall, I get this (no changes detected):

Oct 13 2021, 9:25 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
c-po closed T3277: DNS Forwarding - reverse zones as Resolved.
Oct 13 2021, 7:38 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3277: DNS Forwarding - reverse zones from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 13 2021, 7:38 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3277: DNS Forwarding - reverse zones from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 13 2021, 7:38 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po assigned T3277: DNS Forwarding - reverse zones to hard.
Oct 13 2021, 7:34 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta

Oct 12 2021

Viacheslav moved T3868: Regex and/or wildcard not accepted with large-community-list from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 12 2021, 6:43 PM · VyOS 1.4 Sagitta
Viacheslav closed T3868: Regex and/or wildcard not accepted with large-community-list as Resolved.

@foxbox Will be fixed in the next rolling release.

Oct 12 2021, 6:43 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3868: Regex and/or wildcard not accepted with large-community-list.

PR https://github.com/vyos/vyos-1x/pull/1025

Oct 12 2021, 6:25 PM · VyOS 1.4 Sagitta
Hydra166 added a comment to T3891: X550-T2/Possibly other X550/X540 cards no link on VyOS.

Messaged

Oct 12 2021, 5:13 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3868: Regex and/or wildcard not accepted with large-community-list from Open to In progress.
Oct 12 2021, 4:44 PM · VyOS 1.4 Sagitta
Viacheslav moved T3881: Wrong description for container section restart from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 12 2021, 4:15 PM · VyOS 1.4 Sagitta
Viacheslav closed T3881: Wrong description for container section restart as Resolved.
Oct 12 2021, 4:15 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T3478: Radius from Open to Needs testing.
Oct 12 2021, 4:01 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3478: Radius.

@BiMW Can you re-check it?

Oct 12 2021, 4:01 PM · VyOS 1.4 Sagitta
Viacheslav closed T3701: ipoe server fails to start when configuring radius dynamic-author on ipoe as Resolved.

Not reproducible, VyOS 1.4-rolling-202109300217

set service ipoe-server authentication radius dynamic-author key 'ssss'
set service ipoe-server authentication radius dynamic-author server '192.168.122.11'
set service ipoe-server authentication radius nas-ip-address '192.168.122.11'
set service ipoe-server authentication radius server 192.168.122.11 key 'ciscoradiuskey'
set service ipoe-server interface eth1 client-subnet '192.0.2.0/24'
Oct 12 2021, 3:22 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3902: Firewall does not load on boot, address-group not found, even though it exists.

@FileGo Can you replace double-quotes with single-quotes?

Oct 12 2021, 2:52 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav created T3903: Containers: after command "reboot" the host system will reboot after 1.5 minutes.
Oct 12 2021, 2:47 PM · VyOS 1.4 Sagitta
FileGo created T3902: Firewall does not load on boot, address-group not found, even though it exists.
Oct 12 2021, 1:48 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav closed T3216: Removal of restricted-shell broke configure mode for RADIUS users, a subtask of T671: Identify and remove dead code, as Resolved.
Oct 12 2021, 11:13 AM · VyOS 1.4 Sagitta (1.4.0-epa1)
Viacheslav closed T3216: Removal of restricted-shell broke configure mode for RADIUS users as Resolved.

Fixed

sever@sever:~$ ssh [email protected]
Oct 12 2021, 11:13 AM · VyOS 1.4 Sagitta
lucasec added a comment to T562: PDNS: Add support for authoritative dns server.

PR: https://github.com/vyos/vyos-1x/pull/1024

Oct 12 2021, 7:28 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T3896: Extend ocserv support to allow for per-group configs: VyOS 1.4 Sagitta.
Oct 12 2021, 6:11 AM · VyOS 1.4 Sagitta
PeppyH added a comment to T3896: Extend ocserv support to allow for per-group configs.

@SquirePug Can you share more details, which templates and parameters did you edit?

Oct 12 2021, 5:03 AM · VyOS 1.4 Sagitta

Oct 11 2021

Viacheslav closed T2607: Support for pppoe-server radius mode auth and config radius accouting port as Resolved.

Present in 1.4 and 1.3.0-epa1

set service pppoe-server authentication radius server 192.0.2.1 acct-port
Possible completions:
   <1-65535>    Numeric IP port (default: 1813)
Oct 11 2021, 7:28 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3510: RADIUS usersname is not shown on CLI.

@c-po in 1.3.0-epa1 works fine.

Oct 11 2021, 5:53 PM · VyOS 1.4 Sagitta
c-po added a comment to T3510: RADIUS usersname is not shown on CLI.

What about 1.3.0-epa1?

Oct 11 2021, 2:49 PM · VyOS 1.4 Sagitta
Viacheslav reopened T3510: RADIUS usersname is not shown on CLI as "Open".

Re-opened, the same bug in VyOS 1.4-rolling-202109300217

sever@sever:~/docker$ ssh [email protected]
Oct 11 2021, 1:24 PM · VyOS 1.4 Sagitta
Viacheslav created T3901: Help values do not work for RADIUS authentication users.
Oct 11 2021, 12:50 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3896: Extend ocserv support to allow for per-group configs.

@SquirePug Can you share more details, which templates and parameters did you edit?

Oct 11 2021, 11:16 AM · VyOS 1.4 Sagitta
Unknown Object (User) updated the task description for T3900: Add support for raw tables to firewall.
Oct 11 2021, 9:25 AM · VyOS 1.5 Circinus
Viacheslav triaged T3900: Add support for raw tables to firewall as Wishlist priority.
Oct 11 2021, 9:23 AM · VyOS 1.5 Circinus
Unknown Object (User) created T3900: Add support for raw tables to firewall.
Oct 11 2021, 8:36 AM · VyOS 1.5 Circinus
lucasec added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

Obviously in a perfect world we get "unique" and "stable". I do think giving stability priority makes sense.

Oct 11 2021, 8:05 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
Viacheslav added a comment to T3897: Dynamic DNS doesn't work with IPv6 addresses.

PR https://github.com/vyos/vyos-1x/pull/1022

Oct 11 2021, 6:46 AM · VyOS 1.4 Sagitta
c-po added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

@lucasec the reason for switching to the platform UUID instead of building up out own one was that it was not "unique".

Oct 11 2021, 6:10 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.150 / 5.10.70 to Update Linux Kernel to v5.4.152 / 5.10.72.
Oct 11 2021, 6:07 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

Oct 10 2021

lucasec added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

I surveyed all the hardware I have to see what kind of UUIDs they report:

Oct 10 2021, 11:37 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po closed T3750: pdns-recursor 4.4 issue with dont-query and private DNS servers, a subtask of T3882: Upgrade PowerDNs recursor to 4.5 series, as Resolved.
Oct 10 2021, 5:09 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po closed T3750: pdns-recursor 4.4 issue with dont-query and private DNS servers as Resolved.
Oct 10 2021, 5:09 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po closed T3899: Add support for hd44780 LCD displays, a subtask of T2564: Extend VyOS to support appliance LCDs, as Resolved.
Oct 10 2021, 5:08 PM · VyOS 1.2 Crux (VyOS 1.2.7)
c-po moved T3899: Add support for hd44780 LCD displays from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 10 2021, 5:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po closed T3899: Add support for hd44780 LCD displays as Resolved.
Oct 10 2021, 5:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po moved T3899: Add support for hd44780 LCD displays from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 10 2021, 5:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po changed the status of T3899: Add support for hd44780 LCD displays from Open to In progress.
Oct 10 2021, 5:06 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po closed T3885: dhcpv6-pd: randomly generated DUID is not persisted as Resolved.
Oct 10 2021, 4:06 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3885: dhcpv6-pd: randomly generated DUID is not persisted from Backlog to Finished on the VyOS 1.4 Sagitta board.
Oct 10 2021, 4:06 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3885: dhcpv6-pd: randomly generated DUID is not persisted from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 10 2021, 4:06 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

Implemented in

Oct 10 2021, 4:06 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po added a comment to T3885: dhcpv6-pd: randomly generated DUID is not persisted.

The DUID is presented in binary inside /var/lib/dhcpv6/dhcp6c_duid to read it back into ASCII use: hexdump -e '"%07.7_ax " 1/2 "%04x" " " 14/1 "%02x:" "\n"' /var/lib/dhcpv6/dhcp6c_duid

Oct 10 2021, 7:47 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta

Oct 9 2021

trae32566 created T3898: [RADIUS] - Reverse DNS Lookup Failing .
Oct 9 2021, 10:52 PM · VyOS 1.4 Sagitta
c-po added a comment to T3090: Move 'adjust-mss' firewall options to the interface section..

You are right @NikolayP but opening an entire subtree might be a bit of overkill.

Oct 9 2021, 5:02 PM · VyOS 1.4 Sagitta
c-po added a comment to T3879: GPG key verification fails when upgrading from a 1.3 beta version.

Unfortunately reverting back the public key did not lead to any good results either.

Oct 9 2021, 7:04 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po raised the priority of T3879: GPG key verification fails when upgrading from a 1.3 beta version from High to Urgent!.
Oct 9 2021, 7:02 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po closed T3894: Tunnel Commit Failed if system does not have `eth0` as Resolved.
Oct 9 2021, 6:40 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3894: Tunnel Commit Failed if system does not have `eth0` from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 9 2021, 6:40 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3894: Tunnel Commit Failed if system does not have `eth0` from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 9 2021, 6:40 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po changed Difficulty level from unknown to easy on T3894: Tunnel Commit Failed if system does not have `eth0`.
Oct 9 2021, 6:38 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po edited projects for T3894: Tunnel Commit Failed if system does not have `eth0`, added: VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2); removed VyOS 1.3 Equuleus.
Oct 9 2021, 6:38 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po claimed T3894: Tunnel Commit Failed if system does not have `eth0`.
Oct 9 2021, 5:56 AM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta

Oct 8 2021

c-po claimed T3879: GPG key verification fails when upgrading from a 1.3 beta version.
Oct 8 2021, 7:35 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)
c-po closed T3893: MGRE Tunnel commit crash If sit tunnel available as Resolved.
Oct 8 2021, 7:20 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3893: MGRE Tunnel commit crash If sit tunnel available from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.0-epa2) board.
Oct 8 2021, 7:20 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3893: MGRE Tunnel commit crash If sit tunnel available from Need Triage to 1.3.0-epa2 on the VyOS 1.3 Equuleus board.
Oct 8 2021, 7:19 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
c-po moved T3893: MGRE Tunnel commit crash If sit tunnel available from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Oct 8 2021, 7:19 PM · VyOS 1.3 Equuleus (1.3.0-epa2), VyOS 1.4 Sagitta
fernando added a comment to T3655: NAT Problem with VRF.

not yet , we 've been trying with different CT but it's not solve the main problem . I understand that disabling conntrack is not possible because is used for nat.

Oct 8 2021, 5:22 PM · VyOS 1.5 Circinus, Known issue, VyOS 1.4 Sagitta
Viacheslav claimed T3897: Dynamic DNS doesn't work with IPv6 addresses.
Oct 8 2021, 4:17 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T3897: Dynamic DNS doesn't work with IPv6 addresses from "Bug" to "Feature Request".
Oct 8 2021, 3:17 PM · VyOS 1.4 Sagitta
Viacheslav renamed T3897: Dynamic DNS doesn't work with IPv6 addresses from Dynamic DNS doesn't work with IPv6 addresses bug. to Dynamic DNS doesn't work with IPv6 addresses.
Oct 8 2021, 3:17 PM · VyOS 1.4 Sagitta
Viacheslav created T3897: Dynamic DNS doesn't work with IPv6 addresses.
Oct 8 2021, 2:56 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T3090: Move 'adjust-mss' firewall options to the interface section..

Perhaps the command should be changed a bit
MSS is a property of the TCP protocol, not IP:

Oct 8 2021, 12:23 PM · VyOS 1.4 Sagitta
williemmiller updated williemmiller.
Oct 8 2021, 8:29 AM