Page MenuHomeVyOS Platform
Feed All Stories

Tue, Jan 11

sdev changed the status of T4160: Firewall - Error in rules that matches everything except something from Open to In progress.
Tue, Jan 11, 11:25 PM · VyOS 1.4 Sagitta
sdev added a comment to T4173: Wan Load Balancing - Error on firewall NAT rules.

Forgot that my PR for WLB was still a draft. That the jump does seem to be created properly with this PR in place.

Tue, Jan 11, 11:07 PM · VyOS 1.4 Sagitta
sdev added a comment to T4144: Firewall address-group - Improve error messages.

That build at 08:11 UTC was a couple of hours before the commit was merged: https://github.com/vyos/vyos-1x/commit/f97144259335102c3d96b232cbb0af4970120d62

Tue, Jan 11, 10:02 PM · VyOS 1.4 Sagitta
fernando added a comment to T4144: Firewall address-group - Improve error messages.

yes , i'm using this version :

Tue, Jan 11, 8:38 PM · VyOS 1.4 Sagitta
Dmitry added a comment to T4167: DMVPN apply wrong param on the first configuration.

PR https://github.com/vyos/vyos-opennhrp/pull/3

Tue, Jan 11, 8:27 PM · VyOS 1.3 Equuleus
sdev added a comment to T4144: Firewall address-group - Improve error messages.

Seems to be working on my latest build?

Tue, Jan 11, 8:21 PM · VyOS 1.4 Sagitta
Dmitry changed the status of T4167: DMVPN apply wrong param on the first configuration from Open to In progress.
Tue, Jan 11, 8:08 PM · VyOS 1.3 Equuleus
fernando added a comment to T4144: Firewall address-group - Improve error messages.

I've checked with this new build , it works with validator ranges/port :

Tue, Jan 11, 8:06 PM · VyOS 1.4 Sagitta
bjw-s claimed T4174: Validation fails when entering port range with upper port 65535.

PR: https://github.com/vyos/vyos-1x/pull/1160

Tue, Jan 11, 7:47 PM · VyOS 1.4 Sagitta
bjw-s updated the task description for T4174: Validation fails when entering port range with upper port 65535.
Tue, Jan 11, 7:46 PM · VyOS 1.4 Sagitta
bjw-s created T4174: Validation fails when entering port range with upper port 65535.
Tue, Jan 11, 7:35 PM · VyOS 1.4 Sagitta
fernando closed T4149: [Firewall-IPV6] Error delete Fw rules on VIF/INT as Resolved.
Tue, Jan 11, 6:34 PM · VyOS 1.4 Sagitta
fernando added a comment to T4149: [Firewall-IPV6] Error delete Fw rules on VIF/INT.

I've been testing and it works :

Tue, Jan 11, 6:33 PM · VyOS 1.4 Sagitta
sdev changed the status of T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf` from Open to Needs testing.

Thanks, I really like the include idea and have implemented it in the attached PR. Also added a check in firewall.py to reload policy-route script to keep any group changes updated.

Tue, Jan 11, 2:51 PM · VyOS 1.4 Sagitta
sdev changed the status of T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails, a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Tue, Jan 11, 2:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sdev changed the status of T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails from Open to Needs testing.

PR removes the empty line when there are no group members, also adds a warning message when empty groups are used in rules.

Tue, Jan 11, 2:48 PM · VyOS 1.4 Sagitta
sdev changed the status of T4131: Show firewall group incorrect format members from Open to Needs testing.

@Viacheslav Not using exact ipset format, however addresses are sorted and output one per line.

Tue, Jan 11, 2:46 PM · VyOS 1.4 Sagitta
sdev changed the status of T4144: Firewall address-group - Improve error messages from In progress to Needs testing.

Should resolve the rest of the error messages.

Tue, Jan 11, 2:45 PM · VyOS 1.4 Sagitta
n.fort created T4173: Wan Load Balancing - Error on firewall NAT rules.
Tue, Jan 11, 2:17 PM · VyOS 1.4 Sagitta
jestabro closed T4166: Debug output missing when frr.py called under vyos-configd as Resolved.
Tue, Jan 11, 1:00 PM · VyOS 1.4 Sagitta
fernando added a comment to T4163: [BMP-BGP] Routing monitoring feature.

well , I think it should be something like this :

Tue, Jan 11, 12:48 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4162: VPN ipsec ike-group - Incorrect value help for ikev2-reauth.

PR: https://github.com/vyos/vyos-1x/pull/1157

Tue, Jan 11, 12:33 PM · VyOS 1.4 Sagitta
hensur added a comment to T4172: Patch ndppd to not read route table if there are no auto prefixes.

PR: https://github.com/vyos/vyos-build/pull/212

Tue, Jan 11, 12:23 PM · VyOS 1.4 Sagitta
hensur created T4172: Patch ndppd to not read route table if there are no auto prefixes.
Tue, Jan 11, 12:20 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4151: IPV6 local PBR Support: VyOS 1.3 Equuleus ( 1.3.1).
Tue, Jan 11, 11:48 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po changed the status of T4171: Interface config migration error on 1.2.8 -> 1.4 upgrade from Open to In progress.
Tue, Jan 11, 11:03 AM · VyOS 1.4 Sagitta
c-po claimed T4171: Interface config migration error on 1.2.8 -> 1.4 upgrade.
Tue, Jan 11, 10:45 AM · VyOS 1.4 Sagitta
c-po created T4171: Interface config migration error on 1.2.8 -> 1.4 upgrade.
Tue, Jan 11, 10:44 AM · VyOS 1.4 Sagitta
erkin closed T3950: CLI backtrace on update if DNS not defined , a subtask of T3356: Script for remote file transfers, as Resolved.
Tue, Jan 11, 9:59 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin closed T3950: CLI backtrace on update if DNS not defined as Resolved.

Chained exceptions are covered too (and backported to Equuleus).

Tue, Jan 11, 9:59 AM · VyOS 1.4 Sagitta
c-po closed T4170: Rename "policy ipv6-route" -> "policy route6" as Resolved.
Tue, Jan 11, 9:29 AM · VyOS 1.4 Sagitta
c-po claimed T4170: Rename "policy ipv6-route" -> "policy route6".
Tue, Jan 11, 9:16 AM · VyOS 1.4 Sagitta
c-po created T4170: Rename "policy ipv6-route" -> "policy route6".
Tue, Jan 11, 9:15 AM · VyOS 1.4 Sagitta
c-po renamed T4169: INVALID from BGP: Add support for "nexthop-self force" to INVALID.
Tue, Jan 11, 8:59 AM · VyOS 1.3 Equuleus ( 1.3.1)
c-po added a comment to T4169: INVALID.

Invalid - already available - I looked into an 1.2.8 image.

Tue, Jan 11, 8:59 AM · VyOS 1.3 Equuleus ( 1.3.1)
erkin reopened T3950: CLI backtrace on update if DNS not defined , a subtask of T3356: Script for remote file transfers, as In progress.
Tue, Jan 11, 8:58 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
erkin reopened T3950: CLI backtrace on update if DNS not defined as "In progress".
Tue, Jan 11, 8:58 AM · VyOS 1.4 Sagitta
c-po created T4169: INVALID.
Tue, Jan 11, 8:58 AM · VyOS 1.3 Equuleus ( 1.3.1)
Dmitry assigned T4168: Does not possible to reset VPN properly when DMVPN configured to Viacheslav.
Tue, Jan 11, 8:28 AM · VyOS 1.3 Equuleus ( 1.3.1)
Dmitry created T4168: Does not possible to reset VPN properly when DMVPN configured.
Tue, Jan 11, 8:27 AM · VyOS 1.3 Equuleus ( 1.3.1)
Dmitry created T4167: DMVPN apply wrong param on the first configuration.
Tue, Jan 11, 8:08 AM · VyOS 1.3 Equuleus
imathew added a comment to T3662: Container configuration upgrade destroys system.

Hi, I've just submitted a pull request (https://github.com/vyos/vyos-1x/pull/1154) to hopefully complete this bugfix.

Tue, Jan 11, 3:42 AM · VyOS 1.4 Sagitta

Mon, Jan 10

jestabro triaged T4166: Debug output missing when frr.py called under vyos-configd as Normal priority.
Mon, Jan 10, 10:50 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4163: [BMP-BGP] Routing monitoring feature.

@fernando Thanks, do you have any idea about syntax?

Mon, Jan 10, 10:13 PM · VyOS 1.4 Sagitta
Viacheslav created T4165: Delete custom conntrack timeout firewall bug.
Mon, Jan 10, 10:00 PM · VyOS 1.3 Equuleus
Viacheslav changed the status of T4152: NHRP shortcut-target holding-time does not work from In progress to Needs testing.
Mon, Jan 10, 9:40 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
johannrichard updated the task description for T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf`.
Mon, Jan 10, 9:34 PM · VyOS 1.4 Sagitta
johannrichard created T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf`.
Mon, Jan 10, 9:22 PM · VyOS 1.4 Sagitta
sdev changed the status of T4144: Firewall address-group - Improve error messages from Open to In progress.

IPv4 address range error messages are included in PR: https://github.com/vyos/vyos-1x/pull/1152

Mon, Jan 10, 9:09 PM · VyOS 1.4 Sagitta
sdev changed the status of T4148: Firewall - Error messages not that clear as it were in old firewall from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1152

Mon, Jan 10, 9:04 PM · VyOS 1.4 Sagitta
sdev changed the status of T4137: Firewall group configuration allows to set incorrect port range and invalid port from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1152

Mon, Jan 10, 9:02 PM · VyOS 1.4 Sagitta
fernando added a comment to T4163: [BMP-BGP] Routing monitoring feature.

this PR https://github.com/vyos/vyos-1x/pull/1088 only include how to enable daemon , but it doesn't add VyOS-cli commands in BGP (the daemon only allows you to enable it).

Mon, Jan 10, 8:43 PM · VyOS 1.4 Sagitta
c-po added a comment to T3579: Rewrite vyatta-conntrack in new XML and Python flavour.

@vindenesen that is a bug I have also seen in the old iptables based implementation. Can you please file a bug report towards VyOS 1.2 and 1.3?

Mon, Jan 10, 8:38 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4163: [BMP-BGP] Routing monitoring feature.

There is PR which includes this feature https://github.com/vyos/vyos-1x/pull/1088

Mon, Jan 10, 8:17 PM · VyOS 1.4 Sagitta
fernando created T4163: [BMP-BGP] Routing monitoring feature.
Mon, Jan 10, 8:05 PM · VyOS 1.4 Sagitta
Viacheslav assigned T4162: VPN ipsec ike-group - Incorrect value help for ikev2-reauth to n.fort.
Mon, Jan 10, 6:49 PM · VyOS 1.4 Sagitta
n.fort created T4162: VPN ipsec ike-group - Incorrect value help for ikev2-reauth.
Mon, Jan 10, 6:48 PM · VyOS 1.4 Sagitta
sdev changed the status of T4149: [Firewall-IPV6] Error delete Fw rules on VIF/INT from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1151

Mon, Jan 10, 6:40 PM · VyOS 1.4 Sagitta
sdev changed the status of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases , a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Mon, Jan 10, 6:40 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sdev changed the status of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases from Open to Needs testing.

Thanks for catching that!

Mon, Jan 10, 6:40 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4161: Policy route-map - Incorrect value help for local preference.

PR: https://github.com/vyos/vyos-1x/pull/1150

Mon, Jan 10, 6:21 PM · VyOS 1.4 Sagitta
sdev changed the status of T4149: [Firewall-IPV6] Error delete Fw rules on VIF/INT from Open to In progress.
Mon, Jan 10, 5:53 PM · VyOS 1.4 Sagitta
syncer added a member for Maintainers: sdev.
Mon, Jan 10, 5:52 PM
Viacheslav assigned T4161: Policy route-map - Incorrect value help for local preference to n.fort.
Mon, Jan 10, 5:07 PM · VyOS 1.4 Sagitta
n.fort created T4161: Policy route-map - Incorrect value help for local preference.
Mon, Jan 10, 5:06 PM · VyOS 1.4 Sagitta
n.fort created T4160: Firewall - Error in rules that matches everything except something.
Mon, Jan 10, 4:51 PM · VyOS 1.4 Sagitta
n.fort closed T3115: Add support for firewall on L3 VIF bridge interface as Resolved.
Mon, Jan 10, 3:36 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
n.fort added a comment to T3115: Add support for firewall on L3 VIF bridge interface.

Previous example was expanded, in order to test filtering between native bridge interface and vlans interface on bridge.
Filtering rules:

  • Filter traffic from vlan br0.55 to br0.66
  • Filter traffic from vlan1 to br0.55
  • Allow all
Mon, Jan 10, 3:32 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
hensur added a comment to T3818: BGP export route-map only works after bgpd restart.

I'm experiencing this with a custom ISO built from the stable 1.3 sources. Haven't done further debugging yet, a bgpd restart helped every time.

Mon, Jan 10, 3:09 PM · VyOS 1.4 Sagitta
NikolayP added a comment to T4100: Firewall increase maximum number of rules.

In 1.3 (VyOS 1.3-rolling-202201030317) the rules are handled correctly (except for the numbers in description).

Mon, Jan 10, 12:35 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav moved T3299: Webproxy is prohibited from listening on all IP addresses from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Mon, Jan 10, 9:32 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
Viacheslav closed T3299: Webproxy is prohibited from listening on all IP addresses as Resolved.
Mon, Jan 10, 9:32 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
nikeshhajari closed T4158: Add support for "ip nhrp registration no-unique" from FRR as Invalid.
Mon, Jan 10, 6:23 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
nikeshhajari added a comment to T4158: Add support for "ip nhrp registration no-unique" from FRR.

Ah! ok, I will close this. Looking at the man pages, seems like open nhrp doesn't have a no-unique registration feature?

Mon, Jan 10, 6:23 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T4158: Add support for "ip nhrp registration no-unique" from FRR.

We don’t use frr nhrpd, more details T2326
We use opennhrp

Mon, Jan 10, 6:17 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
johannrichard added a comment to T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.

I just realize it's getting more complicated as python/vyos/firewall.py will later write out the rules for these empty groups and when reading-them in, nftables will complain (again) when trying to resolve them, e.g.

Mon, Jan 10, 3:06 AM · VyOS 1.4 Sagitta
erkin added a comment to T4038: Rewrite `vyatta-image-tools.pl` in Python.

Pythonic reimplementation complete. Now only the XML op-mode definition and the auto-complete script remain.

Mon, Jan 10, 2:51 AM · VyOS 1.4 Sagitta
johannrichard renamed T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails from Rewrite firewall in new XML/Python style: Empty firewall group (address, network & port) generate invalid nftables config, commit fails to Empty firewall group (address, network & port) generates invalid nftables config, commit fails.
Mon, Jan 10, 2:25 AM · VyOS 1.4 Sagitta
johannrichard added a comment to T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.

To my understanding, the template data/templates/firewall/nftables.tmpl is probably the culprit, as it doesn't check whether group_conf.address (and similarly the others) has any elements at all and introduces the offending white-space:

Mon, Jan 10, 2:25 AM · VyOS 1.4 Sagitta
johannrichard added a subtask for T2199: Rewrite firewall in new XML/Python style: T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.
Mon, Jan 10, 2:12 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
johannrichard added a parent task for T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails: T2199: Rewrite firewall in new XML/Python style.
Mon, Jan 10, 2:12 AM · VyOS 1.4 Sagitta
johannrichard created T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails.
Mon, Jan 10, 2:12 AM · VyOS 1.4 Sagitta

Sun, Jan 9

nikeshhajari created T4158: Add support for "ip nhrp registration no-unique" from FRR.
Sun, Jan 9, 11:57 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T4156: Adding DHCP Option 13 (bootfile-size).

In ISC dhcpd this corresponds to the boot-size option http://www.ipamworldwide.com/ipam/isc-dhcpv4-options.html

Sun, Jan 9, 8:36 PM · VyOS 1.4 Sagitta
tacerus triaged T4157: Add jinja2 to pip test requirements as Low priority.
Sun, Jan 9, 8:35 PM
tacerus triaged T4156: Adding DHCP Option 13 (bootfile-size) as Low priority.
Sun, Jan 9, 8:05 PM · VyOS 1.4 Sagitta
johannrichard added a subtask for T2199: Rewrite firewall in new XML/Python style: T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases .
Sun, Jan 9, 7:59 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
johannrichard added a parent task for T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases : T2199: Rewrite firewall in new XML/Python style.
Sun, Jan 9, 7:59 PM · VyOS 1.4 Sagitta
c-po moved T3924: VRRP stops working with VRF from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Sun, Jan 9, 7:58 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po changed Why the issue appeared? from none to third-party on T3924: VRRP stops working with VRF.
Sun, Jan 9, 7:58 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a project to T3924: VRRP stops working with VRF: VyOS 1.3 Equuleus ( 1.3.1).
Sun, Jan 9, 7:58 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po moved T4141: Set high-availability vrrp sync-group without members error from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Sun, Jan 9, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po moved T4128: keepalived: Upgrade package to add VRF support from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Sun, Jan 9, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a project to T4128: keepalived: Upgrade package to add VRF support: VyOS 1.3 Equuleus ( 1.3.1).
Sun, Jan 9, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a parent task for T4128: keepalived: Upgrade package to add VRF support: T3914: vrrp rfc3768-compatibility doesn't work with unicast peers.
Sun, Jan 9, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a subtask for T3914: vrrp rfc3768-compatibility doesn't work with unicast peers: T4128: keepalived: Upgrade package to add VRF support.
Sun, Jan 9, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po added a comment to T3914: vrrp rfc3768-compatibility doesn't work with unicast peers.

Package upgraded

Sun, Jan 9, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po closed T3914: vrrp rfc3768-compatibility doesn't work with unicast peers as Resolved.
Sun, Jan 9, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po moved T3914: vrrp rfc3768-compatibility doesn't work with unicast peers from Need Triage to Finished on the VyOS 1.3 Equuleus ( 1.3.1) board.
Sun, Jan 9, 7:57 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
c-po edited projects for T3914: vrrp rfc3768-compatibility doesn't work with unicast peers, added: VyOS 1.3 Equuleus ( 1.3.1); removed VyOS 1.3 Equuleus (1.3.0).
Sun, Jan 9, 7:53 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta