Page MenuHomeVyOS Platform
Feed All Stories

Jan 4 2022

Unknown Object (User) renamed T4085: Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict from Rewrite l2tp/pptp remote access to get_config_dict to Rewrite L2TP/PPTP/SSTP/PPPoE services to get_config_dict.
Jan 4 2022, 1:23 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
Viacheslav renamed T4134: Incorrect firewall protocol completion help uppercase and duplicates from Some firewall protocol completion help in uppercase to Incorrect firewall protocol completion help uppercase and duplicates.
Jan 4 2022, 1:21 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4134: Incorrect firewall protocol completion help uppercase and duplicates from Open to In progress.
Jan 4 2022, 12:26 PM · VyOS 1.4 Sagitta
Viacheslav claimed T4134: Incorrect firewall protocol completion help uppercase and duplicates.
Jan 4 2022, 12:26 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4138: NAT configuration allows to set incorrect port range and invalid port from NAT configuration allows to set incorrect port range to NAT configuration allows to set incorrect port range and invalid port.
Jan 4 2022, 12:14 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4137: Firewall group configuration allows to set incorrect port range and invalid port from Firewall group configuration allows incorrect port range to Firewall group configuration allows to set incorrect port range and invalid port.
Jan 4 2022, 12:12 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4137: Firewall group configuration allows to set incorrect port range and invalid port.
Jan 4 2022, 12:10 PM · VyOS 1.4 Sagitta
Viacheslav created T4138: NAT configuration allows to set incorrect port range and invalid port.
Jan 4 2022, 12:05 PM · VyOS 1.4 Sagitta
Viacheslav created T4137: Firewall group configuration allows to set incorrect port range and invalid port.
Jan 4 2022, 12:00 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4132: Impossible to show a specific firewall group.

PR https://github.com/vyos/vyos-1x/pull/1131

vyos@r11-roll:~$ show firewall group 
Possible completions:
  <Enter>       Execute the current command
  FOO           Show firewall group
  FOO2
  NETV6
  PORTGRP
Jan 4 2022, 11:47 AM · VyOS 1.4 Sagitta
Viacheslav claimed T4132: Impossible to show a specific firewall group.
Jan 4 2022, 11:37 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4131: Show firewall group incorrect format members.

In 1.3 it looks like just ipset -L:

vyos@r4:~$ show firewall group 
Name       : FOO2
Type       : address
References : none
Members    :
             203.0.113.3
Jan 4 2022, 9:53 AM · VyOS 1.4 Sagitta
c-po added a comment to T4131: Show firewall group incorrect format members.

Can you please add output from VyOS 1.3 as reference?

Jan 4 2022, 6:52 AM · VyOS 1.4 Sagitta
syncer merged T4136: Firewall State Policy entries fail to load. into T4130: Firewall state policy errors chain.
Jan 4 2022, 1:19 AM · VyOS 1.4 Sagitta
syncer merged task T4136: Firewall State Policy entries fail to load. into T4130: Firewall state policy errors chain.
Jan 4 2022, 1:18 AM · VyOS 1.4 Sagitta
sarthurdev added a comment to T4136: Firewall State Policy entries fail to load..

Duplicate of T4130

Jan 4 2022, 12:45 AM · VyOS 1.4 Sagitta
JamesGreenlee created T4136: Firewall State Policy entries fail to load..
Jan 4 2022, 12:36 AM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4130: Firewall state policy errors chain from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1130

Jan 4 2022, 12:14 AM · VyOS 1.4 Sagitta

Jan 3 2022

sarthurdev changed the status of T4130: Firewall state policy errors chain from Open to In progress.
Jan 3 2022, 9:58 PM · VyOS 1.4 Sagitta
Viacheslav closed T4065: IPSEC configuration error: connection to unix:///var/run/charon.ctl failed: No such file or directory as Resolved.

Fixed in https://github.com/vyos/vyatta-cfg-vpn/pull/56

Jan 3 2022, 9:09 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3914: VRRP rfc3768-compatibility doesn't work with unicast peers.

Maybe fixed in T4128

Jan 3 2022, 9:05 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav renamed T4135: Declare zone policy firewall without local zone errors from Declare zone policy firewall without local zone erros to Declare zone policy firewall without local zone errors.
Jan 3 2022, 8:02 PM · VyOS 1.4 Sagitta
Viacheslav created T4135: Declare zone policy firewall without local zone errors.
Jan 3 2022, 8:00 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4133: Firewall network group error with zone-based firewall rules from Firewall network group error to Firewall network group error with zone-based firewall rules.
Jan 3 2022, 7:47 PM · VyOS 1.4 Sagitta, VyConf
Viacheslav added a comment to T4133: Firewall network group error with zone-based firewall rules.

To reproduce it should be zone-policy firewall rules, for example:

Jan 3 2022, 7:46 PM · VyOS 1.4 Sagitta, VyConf
c-po assigned T4133: Firewall network group error with zone-based firewall rules to sarthurdev.
Jan 3 2022, 7:39 PM · VyOS 1.4 Sagitta, VyConf
c-po changed the status of T3924: VRRP stops working with VRF from Confirmed to Needs testing.
Jan 3 2022, 7:20 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav created T4134: Incorrect firewall protocol completion help uppercase and duplicates.
Jan 3 2022, 7:16 PM · VyOS 1.4 Sagitta
n.fort created T4133: Firewall network group error with zone-based firewall rules.
Jan 3 2022, 7:08 PM · VyOS 1.4 Sagitta, VyConf
c-po added a comment to T4130: Firewall state policy errors chain.

Comparing the old iptables firewall it will look like this:

Jan 3 2022, 7:00 PM · VyOS 1.4 Sagitta
n.fort added a comment to T3435: NAT rules show corruption.

Error still present on VyOS 1.4-rolling-202201020317

Jan 3 2022, 6:57 PM · VyOS 1.4 Sagitta
Viacheslav created T4132: Impossible to show a specific firewall group.
Jan 3 2022, 6:56 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4131: Show firewall group incorrect format members.
Jan 3 2022, 6:53 PM · VyOS 1.4 Sagitta
Viacheslav created T4131: Show firewall group incorrect format members.
Jan 3 2022, 6:45 PM · VyOS 1.4 Sagitta
c-po claimed T3924: VRRP stops working with VRF.
Jan 3 2022, 6:18 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a comment to T3924: VRRP stops working with VRF.

keepalived was upgraded to include the above mentioned commits.

Jan 3 2022, 6:18 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po assigned T4130: Firewall state policy errors chain to sarthurdev.
Jan 3 2022, 6:13 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4130: Firewall state policy errors chain from Firewall state policy erros chain to Firewall state policy errors chain.
Jan 3 2022, 5:56 PM · VyOS 1.4 Sagitta
Viacheslav created T4130: Firewall state policy errors chain.
Jan 3 2022, 5:41 PM · VyOS 1.4 Sagitta
dcplaya created T4129: Certstore only accepts `PKCS#8` cert types .
Jan 3 2022, 5:38 PM · VyOS 1.4 Sagitta
dcplaya added a comment to T4127: Upgrading from pre-certstore image to certstore image does not handle CA files with multiple certs.

I was able to test and get a screenshot of the exact error eapol spits out when using certstore as well.

Jan 3 2022, 5:35 PM · VyOS 1.4 Sagitta
c-po closed T4128: keepalived: Upgrade package to add VRF support, a subtask of T3924: VRRP stops working with VRF, as Resolved.
Jan 3 2022, 5:29 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po closed T4128: keepalived: Upgrade package to add VRF support as Resolved.
Jan 3 2022, 5:28 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po created T4128: keepalived: Upgrade package to add VRF support.
Jan 3 2022, 5:28 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4052: Validator return traceback on VRRP configuration with the script path not in config dir as Resolved.
Jan 3 2022, 5:17 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav changed the status of T4110: [IPV6-SSH/DNS} enable IPv6 link local adresses as listen-address %eth0 from In progress to Needs testing.
Jan 3 2022, 3:10 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4126: Ability to set priority to site to site IPSec vpn tunnels as Resolved.
Jan 3 2022, 9:16 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4120: [VXLAN] add ability to set multiple unicast-remotes from Open to In progress.
Jan 3 2022, 9:14 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a comment to T3976: Missing prefix-list and access-list option from ipv6 route-map.

@egoistdream Just check when this feature was merged. It was implemented in FRR 24th of November, but the latest FRR release was 9th of November
https://frrouting.org/release/8.1/

Jan 3 2022, 9:03 AM
Unknown Object (User) added a comment to T4081: VRRP health-check script stops working when setting up a sync group.

Checked in 1.3-rolling-202201030317, health-check works

Jan 3 2022, 7:44 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Jan 2 2022

egoistdream added a comment to T3976: Missing prefix-list and access-list option from ipv6 route-map.

Still the same on vyos-1.4-rolling-202201020317-amd64.iso

Jan 2 2022, 9:53 PM

Jan 1 2022

dcplaya created T4127: Upgrading from pre-certstore image to certstore image does not handle CA files with multiple certs.
Jan 1 2022, 11:09 PM · VyOS 1.4 Sagitta

Dec 31 2021

c-po changed the status of T4121: Nameservers from DHCP client cannot be used in specific cases from In progress to Needs testing.
Dec 31 2021, 5:37 PM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav renamed T4126: Ability to set priority to site to site IPSec vpn tunnels from Ability to set priority to site to site IPSec tunnels to Ability to set priority to site to site IPSec vpn tunnels.
Dec 31 2021, 3:45 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4126: Ability to set priority to site to site IPSec vpn tunnels from Open to Needs testing.

It can't be implemented in 1.3, as it doesn't use swanctl.conf for peers configuration
I didn't find this option for ipsec.conf

Dec 31 2021, 3:45 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4126: Ability to set priority to site to site IPSec vpn tunnels.

PR https://github.com/vyos/vyos-1x/pull/1129

set vpn ipsec site-to-site peer 192.0.2.14 tunnel 0 local prefix '172.16.0.0/24'
set vpn ipsec site-to-site peer 192.0.2.14 tunnel 0 priority '100'
set vpn ipsec site-to-site peer 192.0.2.14 tunnel 0 remote prefix '10.0.0.0/24'
Dec 31 2021, 3:11 PM · VyOS 1.4 Sagitta
fernando added a comment to T4125: Feature Request: bridge STP BPDU translation.

I want to leave a comment , it's also common that customers don't know that PVST is enabled by default (and send bpdu peer VLANS), So it's possible to mitigate it also using nf rules , below leave a example:

Dec 31 2021, 2:59 PM · VyOS 1.5 Circinus
Viacheslav claimed T4126: Ability to set priority to site to site IPSec vpn tunnels.
Dec 31 2021, 1:52 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T4126: Ability to set priority to site to site IPSec vpn tunnels.
Dec 31 2021, 1:32 PM · VyOS 1.4 Sagitta
Viacheslav created T4126: Ability to set priority to site to site IPSec vpn tunnels.
Dec 31 2021, 1:24 PM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4125: Feature Request: bridge STP BPDU translation from "Task" to "Feature Request".
Dec 31 2021, 12:11 PM · VyOS 1.5 Circinus
Viacheslav added a comment to T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID.

How about starting with a simple interface and allowing to set interface for binding address?

set high-availability vrrp group foo address 203.0.113.1 interface ethX      
Possible completions:
 > ethN         Interfcae used to assign virtual address
 > eth0         
 > eth1         
 > eth2
Dec 31 2021, 12:09 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav moved T4081: VRRP health-check script stops working when setting up a sync group from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Dec 31 2021, 11:04 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav edited projects for T4081: VRRP health-check script stops working when setting up a sync group, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus (1.3.0).
Dec 31 2021, 11:04 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T4081: VRRP health-check script stops working when setting up a sync group as Resolved.
Dec 31 2021, 11:04 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
SrividyaA placed T4115: reboot in <x> not working as expected up for grabs.
Dec 31 2021, 8:00 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
c-po triaged T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID as Low priority.
Dec 31 2021, 8:00 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a comment to T1972: Allow setting interface name for virtual_ipaddress in VRRP VRID.

This sounds like a "peer-link" or "heartbeat-link" between two VyOS boxes. I have yet no idea how the CLI could look like, maybe you have one?

Dec 31 2021, 7:59 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Unknown Object (User) created T4125: Feature Request: bridge STP BPDU translation.
Dec 31 2021, 3:56 AM · VyOS 1.5 Circinus

Dec 30 2021

c-po closed T4124: snmp: migrate to get_config_dict() as Resolved.
Dec 30 2021, 8:39 PM · VyOS 1.4 Sagitta
c-po updated the task description for T4124: snmp: migrate to get_config_dict().
Dec 30 2021, 8:32 PM · VyOS 1.4 Sagitta
c-po moved T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Dec 30 2021, 8:02 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.164 / 5.10.88 to Update Linux Kernel to v5.4.169 / 5.10.89.
Dec 30 2021, 8:01 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po claimed T4124: snmp: migrate to get_config_dict().
Dec 30 2021, 6:40 PM · VyOS 1.4 Sagitta
c-po created T4124: snmp: migrate to get_config_dict().
Dec 30 2021, 6:40 PM · VyOS 1.4 Sagitta
Unknown Object (User) changed the status of T4117: Does not possible to configure PoD/CoA for L2TP vpn from In progress to Needs testing.
Dec 30 2021, 5:27 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
zsdc changed the status of T4113: Incorrect GRUB configuration parsing from Open to In progress.

Suggested fix: https://github.com/vyos/vyatta-op/pull/52

Dec 30 2021, 5:21 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
aha added a comment to T4120: [VXLAN] add ability to set multiple unicast-remotes.

Problem (2) with multiple IPv6 remotes fixed.

Dec 30 2021, 11:19 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
bbabich created T4123: checksum file fails to download from AWS S3 in rolling-release.
Dec 30 2021, 6:22 AM · VyOS 1.4 Sagitta
aha added a comment to T4120: [VXLAN] add ability to set multiple unicast-remotes.

During multiple tests on my testlab I found two (or three) possible bugs:
1.)
vyos-cli does not prevent to mix IPv4 and IPv6 remotes. Mixing them is not possible with vxlan.

Dec 30 2021, 12:13 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Dec 29 2021

zsdc added a comment to T4121: Nameservers from DHCP client cannot be used in specific cases.

PR to fix the problem: https://github.com/vyos/vyos-1x/pull/1128
It is compatible with both 1.3 and 1.4, so can be cherry-picked from sagitta to equuleus.

Dec 29 2021, 11:12 PM · VyOS 1.3 Equuleus (1.3.4)
jestabro closed T4086: system login banner is not removed on deletion. as Resolved.
Dec 29 2021, 8:13 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
olofl created T4122: interface ip address config missing after upgrade from 1.2.8 to 1.3.0 (when redirect is configured?).
Dec 29 2021, 8:13 PM · VyOS 1.3 Equuleus (1.3.3)
jestabro moved T4086: system login banner is not removed on deletion. from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Dec 29 2021, 8:08 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
jestabro added a comment to T4086: system login banner is not removed on deletion..

This is a mutability issue: since under vyos-configd the script is loaded as module, global variables persist, however:

Dec 29 2021, 7:37 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
SrividyaA added a comment to T4115: reboot in <x> not working as expected.

The error is received when the input for minutes is provided in three digits.

Dec 29 2021, 7:35 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
zsdc changed the status of T4121: Nameservers from DHCP client cannot be used in specific cases from Open to In progress.
Dec 29 2021, 7:33 PM · VyOS 1.3 Equuleus (1.3.4)
zsdc created T4121: Nameservers from DHCP client cannot be used in specific cases.
Dec 29 2021, 7:32 PM · VyOS 1.3 Equuleus (1.3.4)
SrividyaA claimed T4115: reboot in <x> not working as expected.
Dec 29 2021, 7:11 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav closed T4023: Add grepcidr or similar functionality as Resolved.

@insignia96 Will be present in the next rolling release.

Dec 29 2021, 6:57 PM · VyOS 1.4 Sagitta
Viacheslav closed T3671: Webproxy not functional in 1.2.8 update as Resolved.
Dec 29 2021, 6:27 PM · VyOS 1.2 Crux (VyOS 1.2.9)
n.fort renamed T2498: Expected error when deleting vif that has dhcp-server configured from Cannot remove interface vif used by dhcpd to Expected error when deleting vif that has dhcp-server configured.
Dec 29 2021, 6:15 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta
n.fort added a comment to T2498: Expected error when deleting vif that has dhcp-server configured.

Configuration tested on 1.3 and 1.4 version.

Dec 29 2021, 6:13 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta
Viacheslav reopened T2498: Expected error when deleting vif that has dhcp-server configured as "Open".

Re-opened as this task regarding dhcp-server, not dhcp-client

Dec 29 2021, 5:48 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta
aha added a comment to T4120: [VXLAN] add ability to set multiple unicast-remotes.

PR started:
https://github.com/vyos/vyos-1x/pull/1127

Dec 29 2021, 5:30 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T2498: Expected error when deleting vif that has dhcp-server configured as Resolved N/A.

Fixed VyOS 1.3.0:

vyos@r4# run show conf com | match dhcp
set interfaces ethernet eth2 vif 35 address 'dhcp'
[edit]
vyos@r4# run show int
Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface        IP Address                        S/L  Description
---------        ----------                        ---  -----------
eth0             192.168.122.14/24                 u/u  WAN
eth1             203.0.113.14/24                   u/u  Lan
                 192.0.2.14/24                          
eth2             -                                 u/u  
eth2.35          10.0.2.10/24                      u/u
Dec 29 2021, 5:14 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta
aha created T4120: [VXLAN] add ability to set multiple unicast-remotes.
Dec 29 2021, 4:43 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav added a project to T2700: Redirecting traffic from PPPoE interface to IFB fails: VyOS 1.4 Sagitta.

To reproduce:

set interfaces ethernet eth2 vif 35
set interfaces pppoe pppoe0 authentication password 'MYPASSWORD'
set interfaces pppoe pppoe0 authentication user 'MYUSER'
set interfaces pppoe pppoe0 default-route 'force'
set interfaces pppoe pppoe0 mtu '1492'
set interfaces pppoe pppoe0 redirect 'ifb0'
set interfaces pppoe pppoe0 source-interface 'eth2.35'
set interfaces pppoe pppoe0 traffic-policy out 'OUT2'
set interfaces input ifb0

Commit:

vyos@r11-roll# commit
[ interfaces pppoe pppoe0 redirect ifb0 ]
Cannot find device "pppoe0"
tc qdisc ingress failed at /opt/vyatta/sbin/vyatta-qos.pl line 334.
Dec 29 2021, 4:05 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project
Viacheslav closed T2695: Flow-accounting bug with subinterfaces as Resolved.
Dec 29 2021, 4:00 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav moved T2400: OpenVPN: dont restart server if no need from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Dec 29 2021, 3:59 PM · VyOS 1.3 Equuleus ( 1.3.1)