Page MenuHomeVyOS Platform
Feed All Stories

Thu, Sep 15

c-po closed T4696: Extend bgp parameters for bgp bestpath peer-type multipath-relax as Resolved.
Thu, Sep 15, 12:33 PM · VyOS 1.4 Sagitta
c-po changed the status of T4696: Extend bgp parameters for bgp bestpath peer-type multipath-relax from Open to In progress.
Thu, Sep 15, 12:14 PM · VyOS 1.4 Sagitta
c-po closed T4691: Upgrade Linux Kernel to latest 5.15.y train as Resolved.
Thu, Sep 15, 12:13 PM · VyOS 1.4 Sagitta
dmbaturin deleted 1.3.2.
Thu, Sep 15, 10:43 AM · VyOS 1.3 Equuleus
dmbaturin created an object: 1.3.2.
Thu, Sep 15, 10:42 AM · VyOS 1.3 Equuleus (1.3.2)
aalmenar created T4696: Extend bgp parameters for bgp bestpath peer-type multipath-relax.
Thu, Sep 15, 9:52 AM · VyOS 1.4 Sagitta
jack9603301 added a comment to T4689: Support RFS(Receive Flow Steering).

https://github.com/vyos/vyos-1x/pull/1535

Thu, Sep 15, 9:44 AM · VyOS 1.4 Sagitta
NikolayP added a comment to T874: Support for Two Factor Authentication for CLI access via Google Authenticator.

PR adding libpam-google-authenticator package to VyOS:
https://github.com/vyos/vyos-1x/pull/1541

Thu, Sep 15, 5:57 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

It seems that we have two constraints here.

Thu, Sep 15, 4:35 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Made a fix and now we have:

Thu, Sep 15, 4:32 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Let me see if I can fix it.

Thu, Sep 15, 4:06 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Doing further testing, it seems adding the explicit-null broke the configuration:

Thu, Sep 15, 3:59 AM · VyOS 1.4 Sagitta
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Good news. It seems the patch worked properly. Here we show MPLS labels generated via segment routing for the prefix command:

Thu, Sep 15, 3:57 AM · VyOS 1.4 Sagitta

Wed, Sep 14

Viacheslav changed the status of T4680: Telegraf prometheus-client listen-address invalid format from Open to In progress.
Wed, Sep 14, 7:31 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4685: Interface does not exist on boot when used as inbound-interface for local policy route from Open to Needs testing.
Wed, Sep 14, 7:28 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4695: Add 'es' and 'jp106' keymap option keyboard-layout from In progress to Needs testing.
Wed, Sep 14, 7:21 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4687: Canot change configuration after image update from 202207220217 to 202209090217.

As I mentioned above, use it before the configuration, it described in the doc

#!/bin/vbash
Wed, Sep 14, 7:17 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4693: ISIS segment routing was broken... from Open to Needs testing.
Wed, Sep 14, 7:12 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.

Interesting article on how and when to match ipsec options: https://thermalcircle.de/doku.php?id=blog:linux:nftables_demystifying_ipsec_expressions

Wed, Sep 14, 6:18 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.

There is PR https://github.com/vyos/vyos-1x/pull/1516 but it brakes all GRE traffic

Wed, Sep 14, 6:04 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4695: Add 'es' and 'jp106' keymap option keyboard-layout.

PR https://github.com/vyos/vyos-1x/pull/1540

Wed, Sep 14, 5:51 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4695: Add 'es' and 'jp106' keymap option keyboard-layout from Open to In progress.
Wed, Sep 14, 5:29 PM · VyOS 1.4 Sagitta
Viacheslav renamed T4695: Add 'es' and 'jp106' keymap option keyboard-layout from Add 'es' and 'jp106' keymap to Add 'es' and 'jp106' keymap option keyboard-layout.
Wed, Sep 14, 5:28 PM · VyOS 1.4 Sagitta
Viacheslav created T4695: Add 'es' and 'jp106' keymap option keyboard-layout.
Wed, Sep 14, 5:28 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1539

Wed, Sep 14, 3:17 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
lferrarotti added a comment to T3424: PPPoE IA-PD doesn't work in VRF.

Hi all,

Wed, Sep 14, 3:09 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.

Do you have a proposed cli format?

Wed, Sep 14, 2:22 PM · VyOS 1.4 Sagitta
jmarmorato created T4694: Allow VyOS Firewall to Match Outbound IPSec Traffic.
Wed, Sep 14, 1:40 PM · VyOS 1.4 Sagitta
nickomarsa updated nickomarsa.
Wed, Sep 14, 4:31 AM
Cheeze_It added a comment to T4693: ISIS segment routing was broken....

Added a pull request for this fix.

Wed, Sep 14, 2:48 AM · VyOS 1.4 Sagitta
xPakrikx added a comment to T4687: Canot change configuration after image update from 202207220217 to 202209090217.

Nope, i use CLI for configuration and script for vrrp (wireguard interface enable/disable)

Wed, Sep 14, 12:45 AM · VyOS 1.4 Sagitta

Tue, Sep 13

Cheeze_It created T4693: ISIS segment routing was broken....
Tue, Sep 13, 11:52 PM · VyOS 1.4 Sagitta
c-po added a comment to T2913: Failure to install fpm while building builder docker image.

Fix for 1.3 https://github.com/vyos/vyos-build/pull/261

Tue, Sep 13, 7:47 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
c-po edited projects for T2913: Failure to install fpm while building builder docker image, added: VyOS 1.2 Crux (VyOS 1.2.8), VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.2 Crux.
Tue, Sep 13, 7:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
c-po changed the status of T2913: Failure to install fpm while building builder docker image from Open to In progress.
Tue, Sep 13, 7:45 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
absolutesantaja created T4692: Docker Builds of Equuleus Fail - public_suffix requires Ruby version >= 2.6.
Tue, Sep 13, 5:05 PM · VyOS 1.3 Equuleus
absolutesantaja added a comment to T2913: Failure to install fpm while building builder docker image.

This is also an issue on the 1.3.x builds due to a similar issue. See https://github.com/jordansissel/fpm/issues/1923

Tue, Sep 13, 5:00 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.2 Crux (VyOS 1.2.8)
Viacheslav added a subtask for T2199: Rewrite firewall in new XML/Python style: T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.
Tue, Sep 13, 1:03 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a parent task for T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups: T2199: Rewrite firewall in new XML/Python style.
Tue, Sep 13, 1:02 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

It should be possible in https://github.com/vyos/vyos-1x/pull/1534

set firewall interface ethXvX
Tue, Sep 13, 11:08 AM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T4687: Canot change configuration after image update from 202207220217 to 202209090217.

It seems you use some custom scripts for configuration
You have to use

if [ "$(id -g -n)" != 'vyattacfg' ] ; then
    exec sg vyattacfg -c "/bin/vbash $(readlink -f $0) [email protected]"
fi

before your configuration script

Tue, Sep 13, 11:04 AM · VyOS 1.4 Sagitta
c-po updated the task description for T4691: Upgrade Linux Kernel to latest 5.15.y train.
Tue, Sep 13, 6:44 AM · VyOS 1.4 Sagitta
c-po moved T4691: Upgrade Linux Kernel to latest 5.15.y train from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Tue, Sep 13, 6:43 AM · VyOS 1.4 Sagitta
c-po changed the status of T4691: Upgrade Linux Kernel to latest 5.15.y train from Open to In progress.
Tue, Sep 13, 6:43 AM · VyOS 1.4 Sagitta
c-po created T4691: Upgrade Linux Kernel to latest 5.15.y train.
Tue, Sep 13, 6:43 AM · VyOS 1.4 Sagitta

Mon, Sep 12

sdev added a comment to T2199: Rewrite firewall in new XML/Python style.

Refactor PR: https://github.com/vyos/vyos-1x/pull/1534

Mon, Sep 12, 7:16 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
sdev added a comment to T4605: Firewall change default table names.

PR for filter tables: https://github.com/vyos/vyos-1x/pull/1534

Mon, Sep 12, 7:15 PM · VyOS 1.4 Sagitta
zsdc added a comment to T2189: Adding a large port-range will take ~ 20 minutes to commit.

Should be fixed in https://github.com/vyos/vyatta-cfg-firewall/pull/34

Mon, Sep 12, 5:58 PM · VyOS 1.3 Equuleus (1.3.3)
jestabro closed T4690: Update GraphQL resolver for 'SystemStatus' following changes to 'show_uptime' op-mode script as Resolved.
Mon, Sep 12, 3:56 PM · VyOS 1.4 Sagitta
jestabro changed the status of T4690: Update GraphQL resolver for 'SystemStatus' following changes to 'show_uptime' op-mode script from Open to In progress.
Mon, Sep 12, 3:19 PM · VyOS 1.4 Sagitta
c-po closed T4170: Rename "policy ipv6-route" -> "policy route6" as Resolved.
Mon, Sep 12, 7:16 AM · VyOS 1.4 Sagitta
c-po added a comment to T4170: Rename "policy ipv6-route" -> "policy route6".

Already renamed:

Mon, Sep 12, 7:16 AM · VyOS 1.4 Sagitta
c-po closed T4617: VRF specification is needed for telegraf prometheus-client listen-address <address> as Resolved.
Mon, Sep 12, 7:00 AM · VyOS 1.4 Sagitta
c-po closed T4647: Add Google Virtual NIC (gVNIC) support as Resolved.
Mon, Sep 12, 6:57 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po renamed T3318: Update Linux Kernel to v5.4.208 / 5.10.142 from Update Linux Kernel to v5.4.208 / 5.10.135 to Update Linux Kernel to v5.4.208 / 5.10.142.
Mon, Sep 12, 6:56 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
jack9603301 moved T4689: Support RFS(Receive Flow Steering) from In Progress to Finished on the VyOS 1.4 Sagitta board.
Mon, Sep 12, 6:53 AM · VyOS 1.4 Sagitta
jack9603301 changed the status of T4689: Support RFS(Receive Flow Steering) from In progress to Needs testing.
Mon, Sep 12, 6:53 AM · VyOS 1.4 Sagitta

Sun, Sep 11

jack9603301 added a comment to T4689: Support RFS(Receive Flow Steering).

PR: https://github.com/vyos/vyos-1x/pull/1533

Sun, Sep 11, 7:09 PM · VyOS 1.4 Sagitta
jack9603301 changed the status of T4689: Support RFS(Receive Flow Steering) from Open to In progress.
Sun, Sep 11, 4:38 PM · VyOS 1.4 Sagitta
jack9603301 claimed T4689: Support RFS(Receive Flow Steering).
Sun, Sep 11, 4:37 PM · VyOS 1.4 Sagitta
jack9603301 moved T4689: Support RFS(Receive Flow Steering) from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Sun, Sep 11, 4:37 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T4689: Support RFS(Receive Flow Steering).
Sun, Sep 11, 2:44 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T4689: Support RFS(Receive Flow Steering).
Sun, Sep 11, 2:41 PM · VyOS 1.4 Sagitta
jack9603301 renamed T4689: Support RFS(Receive Flow Steering) from Support RFS to Support RFS(Receive Flow Steering).
Sun, Sep 11, 2:39 PM · VyOS 1.4 Sagitta
jack9603301 created T4689: Support RFS(Receive Flow Steering).
Sun, Sep 11, 2:39 PM · VyOS 1.4 Sagitta
initramfs updated the task description for T4688: Add support for customizing packet verdict actions in limiter traffic policy.
Sun, Sep 11, 12:38 PM · VyOS 1.3 Equuleus (1.3.3)
initramfs created T4688: Add support for customizing packet verdict actions in limiter traffic policy.
Sun, Sep 11, 12:23 PM · VyOS 1.3 Equuleus (1.3.3)

Sat, Sep 10

syncer reassigned T4443: Wan Load Balancing Multiple Regressions from dmbaturin to Viacheslav.
Sat, Sep 10, 10:36 PM · VyOS 1.3 Equuleus (1.3.3)
roedie added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.
In T1185#133944, @sdev wrote:

A similar syntax change is in progress as part of a larger firewall refactor. It should reach the 1.4 branch in a week or so. It should allow for any valid existing interface name.

Sat, Sep 10, 6:31 PM · VyOS 1.3 Equuleus (1.3.3)
sdev added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Just a suggestion, would it be a weird idea to move the firewall config from the interface section to the firewall section? A bit like the zone config. So something like:

set firewall local interface eth0 name <firewall-filter>
set firewall in interface eth0 name <firewall-filter>
set firewall out interface eth0 name <firewall-filter>
set firewall local interface bond0.10v22v6 ipv6-name <firewall-filter>

The problem is that using zone-policy firewall is a bit overkill for a pure router or even a router with async routing. In which scenario I guess only the local variant would be useful.

Sat, Sep 10, 6:23 PM · VyOS 1.3 Equuleus (1.3.3)
roedie added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Or, come to think, some free from of set interfaces unknown <typeyourownname> firewall local name <ruleset> where you can only config stuff that doesn't really depend on an interface.

Sat, Sep 10, 6:17 PM · VyOS 1.3 Equuleus (1.3.3)
roedie added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Just a suggestion, would it be a weird idea to move the firewall config from the interface section to the firewall section? A bit like the zone config. So something like:

Sat, Sep 10, 6:09 PM · VyOS 1.3 Equuleus (1.3.3)
jack9603301 changed the subtype of T4659: Use vtysh to display bridge and some interface parameter information from "Task" to "Feature Request".
Sat, Sep 10, 3:10 PM · VyOS 1.4 Sagitta
xPakrikx created T4687: Canot change configuration after image update from 202207220217 to 202209090217.
Sat, Sep 10, 3:10 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T4686: Provides support for veth.
Sat, Sep 10, 2:31 PM · VyOS 1.4 Sagitta
jack9603301 changed the subtype of T4686: Provides support for veth from "Task" to "Feature Request".
Sat, Sep 10, 2:22 PM · VyOS 1.4 Sagitta
jack9603301 added a subtask for T3829: Support separated TCP/IP stack via "ip netns": T4686: Provides support for veth.
Sat, Sep 10, 2:20 PM · VyOS 1.4 Sagitta
jack9603301 added a parent task for T4686: Provides support for veth: T3829: Support separated TCP/IP stack via "ip netns".
Sat, Sep 10, 2:20 PM · VyOS 1.4 Sagitta
jack9603301 created T4686: Provides support for veth.
Sat, Sep 10, 12:59 PM · VyOS 1.4 Sagitta
NikolayP added a comment to T874: Support for Two Factor Authentication for CLI access via Google Authenticator.

First we need to include the "google-authenticator" in our build

Sat, Sep 10, 1:57 AM · VyOS 1.4 Sagitta
NikolayP claimed T874: Support for Two Factor Authentication for CLI access via Google Authenticator.
Sat, Sep 10, 1:54 AM · VyOS 1.4 Sagitta
initramfs updated the task description for T4685: Interface does not exist on boot when used as inbound-interface for local policy route.
Sat, Sep 10, 1:47 AM · VyOS 1.4 Sagitta

Fri, Sep 9

initramfs created T4685: Interface does not exist on boot when used as inbound-interface for local policy route.
Fri, Sep 9, 11:17 PM · VyOS 1.4 Sagitta
zsdc changed the status of T2189: Adding a large port-range will take ~ 20 minutes to commit from Open to In progress.
Fri, Sep 9, 8:12 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T4684: Rewrite show ip route by protocol to vyos.opmode format.

/usr/libexec/vyos/op_mode/route.py already exists but without an execution flag
PR https://github.com/vyos/vyos-1x/pull/1531

Fri, Sep 9, 3:13 PM · VyOS 1.4 Sagitta
Viacheslav created T4684: Rewrite show ip route by protocol to vyos.opmode format.
Fri, Sep 9, 2:39 PM · VyOS 1.4 Sagitta
jestabro closed T4681: Complete standardization of show_uptime.py, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Fri, Sep 9, 12:59 PM · VyOS 1.4 Sagitta
jestabro closed T4681: Complete standardization of show_uptime.py as Resolved.
Fri, Sep 9, 12:59 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4681: Complete standardization of show_uptime.py.
Fri, Sep 9, 12:59 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4681: Complete standardization of show_uptime.py: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Fri, Sep 9, 12:59 PM · VyOS 1.4 Sagitta
jestabro closed T4682: Rewrite 'show system storage' in standardized format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Fri, Sep 9, 12:58 PM · VyOS 1.4 Sagitta
jestabro closed T4682: Rewrite 'show system storage' in standardized format as Resolved.
Fri, Sep 9, 12:58 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4682: Rewrite 'show system storage' in standardized format.
Fri, Sep 9, 12:58 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4682: Rewrite 'show system storage' in standardized format: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Fri, Sep 9, 12:58 PM · VyOS 1.4 Sagitta
NceAirport removed a watcher for VyOS 1.3 Equuleus (1.3.2): NceAirport.
Fri, Sep 9, 12:16 PM
zsdc added a comment to T4647: Add Google Virtual NIC (gVNIC) support.

I am suggesting marking this task as "Resolved" because the driver works by himself and NIC can be used with a proper configuration.

Fri, Sep 9, 11:35 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address.

PR https://github.com/vyos/vyos-1x/pull/1530

Fri, Sep 9, 10:49 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4679: OpenVPN site-to-site incorrect check for IPv6 local and remote address from Open to In progress.

The real check without IPv4 local/remote:

[email protected]# commit
[ interfaces openvpn vtun2 ]
Fri, Sep 9, 10:30 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs created T4683: Add kitty-terminfo package to build.
Fri, Sep 9, 10:20 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4672: RADIUS server disable does not work from Open to Needs testing.
Fri, Sep 9, 6:53 AM · VyOS 1.4 Sagitta