Page MenuHomeVyOS Platform
Feed All Stories

Fri, Nov 18

jestabro added a subtask for T4552: Unable to reset IPsec IPv6 peer: T4829: Tunnel argument to 'reset_peer' in ipsec.py should have type hint Optional.
Fri, Nov 18, 10:21 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4829: Tunnel argument to 'reset_peer' in ipsec.py should have type hint Optional: T4552: Unable to reset IPsec IPv6 peer.
Fri, Nov 18, 10:21 PM · VyOS 1.4 Sagitta
jestabro triaged T4829: Tunnel argument to 'reset_peer' in ipsec.py should have type hint Optional as Normal priority.
Fri, Nov 18, 10:20 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4552: Unable to reset IPsec IPv6 peer: T4828: Raise appropriate op-mode errors in ipsec.py 'reset_peer'.
Fri, Nov 18, 10:15 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4828: Raise appropriate op-mode errors in ipsec.py 'reset_peer': T4552: Unable to reset IPsec IPv6 peer.
Fri, Nov 18, 10:15 PM · VyOS 1.4 Sagitta
jestabro added a comment to T4828: Raise appropriate op-mode errors in ipsec.py 'reset_peer'.

https://github.com/vyos/vyos-1x/pull/1665

Fri, Nov 18, 10:14 PM · VyOS 1.4 Sagitta
jestabro triaged T4828: Raise appropriate op-mode errors in ipsec.py 'reset_peer' as Normal priority.
Fri, Nov 18, 10:06 PM · VyOS 1.4 Sagitta
fernando added a comment to T4827: route-map issues , not load configuration FRR.

as we talked , this behavior is the same on vyos1.3.x/frr7.5.x . the main difference is that on vyos-cli doesn't add this command .

Fri, Nov 18, 10:06 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T973: Create Prometheus Exporter for VyOS .
In T973#137840, @elico wrote:

@Viacheslav I want to test this, what should be done?

Fri, Nov 18, 9:25 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav added a comment to T4720: Ability to configure SSH HostKeyAlgorithms.

@Arc771 Thanks, Could you check it in the next rolling release after 20221118?

Fri, Nov 18, 8:42 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4826: Wrong key type is used for SSH SK public keys from Open to Needs testing.

@DerEnderKeks Could you check it in the next rolling release after 20221118?

Fri, Nov 18, 8:40 PM · VyOS 1.4 Sagitta
jestabro closed T4821: Correct calling of config mode script dependencies from firewall.py as Resolved.
Fri, Nov 18, 6:11 PM · VyOS 1.4 Sagitta
jestabro closed T4821: Correct calling of config mode script dependencies from firewall.py, a subtask of T4820: Support for inter-config-mode script dependencies, as Resolved.
Fri, Nov 18, 6:11 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4826: Wrong key type is used for SSH SK public keys.

PR https://github.com/vyos/vyos-1x/pull/1664

Fri, Nov 18, 2:15 PM · VyOS 1.4 Sagitta
elico added a comment to T973: Create Prometheus Exporter for VyOS .

@Viacheslav I want to test this, what should be done?

Fri, Nov 18, 12:33 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T4819: Allow printing Warning messages in multiple lines with \n from In progress to Needs testing.
Fri, Nov 18, 12:25 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4827: route-map issues , not load configuration FRR.

A possible reason is an action deny and state continue that doesn't make sense and can't pass FRR validation
FRR

Fri, Nov 18, 11:10 AM · VyOS 1.4 Sagitta

Thu, Nov 17

fernando created T4827: route-map issues , not load configuration FRR.
Thu, Nov 17, 11:04 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4826: Wrong key type is used for SSH SK public keys.

I guess it was implemented in the T4750
Should be easy to fix

Thu, Nov 17, 9:12 PM · VyOS 1.4 Sagitta
c-po added a comment to T4284: QoS: rewrite to XML and Python.

Draft PR https://github.com/vyos/vyos-1x/pull/1663

Thu, Nov 17, 9:05 PM · VyOS 1.4 Sagitta
c-po closed T4750: Support of higher level SSH keys (sk-ssh-ed25519) as Resolved.
Thu, Nov 17, 9:05 PM · VyOS 1.4 Sagitta
pasik added a comment to T4776: NVME storage is not detected properly during installation.

@marc_s thanks for testing !

Thu, Nov 17, 5:49 PM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
TheSin- added a comment to T4797: External address/network lists for firewall (Local and remote).

Added file:// parser to vyos.remote.download and used that to simplify the code, no need to check if it's local now.

Thu, Nov 17, 4:20 PM · VyOS 1.4 Sagitta
TheSin- updated the task description for T4797: External address/network lists for firewall (Local and remote).
Thu, Nov 17, 4:19 PM · VyOS 1.4 Sagitta
DerEnderKeks created T4826: Wrong key type is used for SSH SK public keys.
Thu, Nov 17, 1:54 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T4824: PBR/FW rulesets are ignored in rfc3768-compatibility VRRP setups, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus.
Thu, Nov 17, 9:59 AM · VyOS 1.3 Equuleus (1.3.3)
jestabro changed the status of T4821: Correct calling of config mode script dependencies from firewall.py, a subtask of T4820: Support for inter-config-mode script dependencies, from Open to Needs testing.
Thu, Nov 17, 1:09 AM · VyOS 1.4 Sagitta
jestabro changed the status of T4821: Correct calling of config mode script dependencies from firewall.py from Open to Needs testing.
Thu, Nov 17, 1:09 AM · VyOS 1.4 Sagitta
jestabro added a comment to T4821: Correct calling of config mode script dependencies from firewall.py.

PR:
https://github.com/vyos/vyos-1x/pull/1662

Thu, Nov 17, 12:59 AM · VyOS 1.4 Sagitta
jestabro renamed T4821: Correct calling of config mode script dependencies from firewall.py from Fix calling of config mode script dependencies from firewall.py to Correct calling of config mode script dependencies from firewall.py.
Thu, Nov 17, 12:43 AM · VyOS 1.4 Sagitta

Wed, Nov 16

syncer raised the priority of T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP from Wishlist to Normal.

Now as linux-cp available we can consider adding support

Wed, Nov 16, 9:29 PM · VyOS 1.4 Sagitta
syncer added a comment to T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP.

https://www.youtube.com/watch?v=D7PF1cOAAUk&ab_channel=DENOG

Wed, Nov 16, 9:27 PM · VyOS 1.4 Sagitta
syncer merged task T893: Add support for VPP into T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP.
Wed, Nov 16, 9:27 PM · VyOS 1.4 Sagitta
syncer merged T893: Add support for VPP into T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP.
Wed, Nov 16, 9:27 PM · VyOS 1.4 Sagitta
TheSin- added a comment to T4794: show firewall name <name> - Can't use .items() on a list.

thank you

Wed, Nov 16, 7:32 PM · VyOS 1.4 Sagitta
roedie added a comment to T4794: show firewall name <name> - Can't use .items() on a list.

https://github.com/vyos/vyos-1x/pull/1661

Wed, Nov 16, 7:30 PM · VyOS 1.4 Sagitta
fernando added a subtask for T4686: Provides support for veth: T4825: interfaces veth/veth-pairs -standalone used.
Wed, Nov 16, 3:51 PM · VyOS 1.4 Sagitta
fernando added a parent task for T4825: interfaces veth/veth-pairs -standalone used: T4686: Provides support for veth.
Wed, Nov 16, 3:51 PM · VyOS 1.4 Sagitta
fernando created T4825: interfaces veth/veth-pairs -standalone used.
Wed, Nov 16, 3:47 PM · VyOS 1.4 Sagitta
fernando created T4824: PBR/FW rulesets are ignored in rfc3768-compatibility VRRP setups.
Wed, Nov 16, 12:42 PM · VyOS 1.3 Equuleus (1.3.3)
chesskuo added a comment to T4118: IPsec syntax overhaul.

Hello sir,

Wed, Nov 16, 10:03 AM · VyOS 1.4 Sagitta
chesskuo created T4823: swanctl.conf is broken when ipsec site-to-site peer set..
Wed, Nov 16, 9:57 AM · VyOS 1.4 Sagitta

Tue, Nov 15

mcbridematt added a comment to T4822: vyatta-cfg-system: install correct version of GRUB for architecture (arm64).

Pull request: https://github.com/vyos/vyatta-cfg-system/pull/189

Tue, Nov 15, 11:31 PM
mcbridematt created T4822: vyatta-cfg-system: install correct version of GRUB for architecture (arm64).
Tue, Nov 15, 11:24 PM
Cheeze_It added a comment to T4739: ISIS and OSPF segment routing being refactored.

We figured out the problem. So for OSPF segment routing to work we need to enable opaque LSA capabilities. So by default VyOS doesn't have opaque LSAs (type 9, type 10, type 11) enabled. So after checking the configuration for the OSPF FRR template I noticed that the actual command to enable opaque LSAs is broken because it's not in the OSPF FRR template. Once we fix that, we'll have working OSPF segment routing.

Tue, Nov 15, 10:37 PM · VyOS 1.4 Sagitta
jestabro added a parent task for T4821: Correct calling of config mode script dependencies from firewall.py: T4820: Support for inter-config-mode script dependencies.
Tue, Nov 15, 10:13 PM · VyOS 1.4 Sagitta
jestabro added a subtask for T4820: Support for inter-config-mode script dependencies: T4821: Correct calling of config mode script dependencies from firewall.py.
Tue, Nov 15, 10:13 PM · VyOS 1.4 Sagitta
jestabro triaged T4821: Correct calling of config mode script dependencies from firewall.py as Normal priority.
Tue, Nov 15, 10:13 PM · VyOS 1.4 Sagitta
jestabro triaged T4820: Support for inter-config-mode script dependencies as Normal priority.
Tue, Nov 15, 10:07 PM · VyOS 1.4 Sagitta
a.apostoliuk renamed T4819: Allow printing Warning messages in multiple lines with \n from Allow printing Warning and Critical messages in multiple lines with \n to Allow printing Warning messages in multiple lines with \n.
Tue, Nov 15, 2:43 PM · VyOS 1.4 Sagitta
jestabro closed T4808: Add details of configtree operations to migration log as Resolved.
Tue, Nov 15, 2:37 PM · VyOS 1.4 Sagitta
Arc771 added a comment to T4720: Ability to configure SSH HostKeyAlgorithms.

First of all, sorry for my late reply. I was on vacation and stayed away from IT for a bit ;)

Tue, Nov 15, 2:32 PM · VyOS 1.4 Sagitta
a.apostoliuk changed the status of T4819: Allow printing Warning messages in multiple lines with \n from Open to In progress.
Tue, Nov 15, 1:59 PM · VyOS 1.4 Sagitta
a.apostoliuk claimed T4819: Allow printing Warning messages in multiple lines with \n.
Tue, Nov 15, 1:58 PM · VyOS 1.4 Sagitta
a.apostoliuk created T4819: Allow printing Warning messages in multiple lines with \n.
Tue, Nov 15, 1:58 PM · VyOS 1.4 Sagitta
e-zann added a watcher for VyOS 1.4 Sagitta: e-zann.
Tue, Nov 15, 11:59 AM
e-zann removed a watcher for VyOS 1.4 Sagitta: e-zann.
Tue, Nov 15, 11:59 AM

Mon, Nov 14

egoistdream updated the task description for T4818: IPv6 NDP not working everytime.
Mon, Nov 14, 7:08 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
egoistdream edited projects for T4818: IPv6 NDP not working everytime, added: VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.4).
Mon, Nov 14, 7:05 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
egoistdream created T4818: IPv6 NDP not working everytime.
Mon, Nov 14, 6:34 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T4812: IPsec ability to show all configured connections.

PR https://github.com/vyos/vyos-1x/pull/1657

[email protected]:~$ show vpn ipsec connections 
Connection         State        Type    Remote address    Local TS        Remote TS    Proposal
-----------------  -----------  ------  ----------------  --------------  -----------  ---------------------------------------
OFFICE-B           established  IKEv1   192.0.2.2         -               -            AES_CBC/256/HMAC_SHA2_256_128/MODP_1024
OFFICE-B-tunnel-0  up           IPsec   192.0.2.2         192.168.0.0/24  10.0.0.0/21  AES_CBC/256/HMAC_SHA2_256_128/MODP_1024
OFFICE-B-tunnel-1  down         IPsec   192.0.2.2         192.168.1.0/24  10.0.0.0/21  -
OFFICE-B-tunnel-2  down         IPsec   192.0.2.2         192.168.2.0/24  10.0.0.0/21  -
OFFICE-C           down         IKEv1   192.0.2.2         -               -            -
OFFICE-C-tunnel-0  down         IPsec   192.0.2.2         192.168.5.0/24  10.0.0.0/21  -
[email protected]:~$
Mon, Nov 14, 5:03 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
dmbaturin added a comment to T4816: IPv4-mapped and IPv4-compatible IPv6 addresses not valid anymore.

@rcit I can assure you were never planned to explicitly disallow embedded IPv4 notation. Moreover, I thought the current validator supports it, even though we didn't have tests for it. I'll take a look!

Mon, Nov 14, 4:00 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
rherold created T4817: Please add support for RFC 9234.
Mon, Nov 14, 3:13 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4789: Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from In progress to Needs testing.
Mon, Nov 14, 3:09 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4789: Ability to get L2TP/PPTP/SSTP sessions info in a machine readable format from In progress to Needs testing.
Mon, Nov 14, 3:09 PM · VyOS 1.4 Sagitta
Viacheslav edited projects for T4816: IPv4-mapped and IPv4-compatible IPv6 addresses not valid anymore, added: VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.
Mon, Nov 14, 2:58 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
fernando changed the status of T4813: L3VPN over GRE Tunnels from In progress to Needs testing.
Mon, Nov 14, 11:37 AM · VyOS 1.4 Sagitta
rcit created T4816: IPv4-mapped and IPv4-compatible IPv6 addresses not valid anymore.
Mon, Nov 14, 11:00 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
vfreex added a comment to T4815: Fix various name server config issues.

Created PR to fix this: https://github.com/vyos/vyos-1x/pull/1656
This issue also exists in 1.3 though I didn't backport it.

Mon, Nov 14, 3:07 AM · VyOS 1.4 Sagitta
vfreex created T4815: Fix various name server config issues.
Mon, Nov 14, 3:03 AM · VyOS 1.4 Sagitta

Sun, Nov 13

syncer triaged T4813: L3VPN over GRE Tunnels as Normal priority.
Sun, Nov 13, 7:23 PM · VyOS 1.4 Sagitta
fernando added a comment to T4813: L3VPN over GRE Tunnels .

https://github.com/vyos/vyos-1x/pull/1655

Sun, Nov 13, 5:16 PM · VyOS 1.4 Sagitta
Viacheslav updated subscribers of T4502: Consider implementing (NAT/other) flow table offload.
Sun, Nov 13, 4:37 PM · VyOS 1.4 Sagitta
fernando changed the status of T4813: L3VPN over GRE Tunnels from Open to In progress.
Sun, Nov 13, 2:08 PM · VyOS 1.4 Sagitta

Sat, Nov 12

initramfs closed T4814: Regression in bundled powerdns version as Resolved.

I seem to have jumped the gun a bit as the issue seems to have been resolved via:

Sat, Nov 12, 5:24 PM · VyOS 1.4 Sagitta
initramfs added a comment to T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.

@c-po I think the reason you're seeing the old name of 'pdns-r/worker' is due to a packaging regression described in T4814. All the latest builds of vyos 1.4 seem to be providing powerdns 4.4 instead of the expected 4.8. Since this issue and corresponding bugfix only pertains to powerdns >= 4.8, the issue would not be visible if powerdns is downgraded to 4.4.

Sat, Nov 12, 4:50 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
initramfs created T4814: Regression in bundled powerdns version.
Sat, Nov 12, 4:47 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4812: IPsec ability to show all configured connections, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, from Open to In progress.
Sat, Nov 12, 5:30 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4812: IPsec ability to show all configured connections from Open to In progress.
Sat, Nov 12, 5:30 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
initramfs added a comment to T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.

Just as a point of additional reference, I've bisected the PowerDNS source code to see where the change from 'pdns-r/worker' to something else occurred and successfully found that commit 69b39198 in the repository changes the thread names away from the prefix of 'pdns-r'. Since that change, the string pdns-r/ no longer exists in the source code. The aforementioned commit is included in the following tags:

Sat, Nov 12, 3:12 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)

Fri, Nov 11

sdev added a comment to T4605: Firewall change default table names.

PR for policy route refactor updates to vyos_mangle: https://github.com/vyos/vyos-1x/pull/1654

Fri, Nov 11, 4:49 PM · VyOS 1.4 Sagitta
fernando claimed T4813: L3VPN over GRE Tunnels .
Fri, Nov 11, 4:46 PM · VyOS 1.4 Sagitta
fernando created T4813: L3VPN over GRE Tunnels .
Fri, Nov 11, 4:45 PM · VyOS 1.4 Sagitta
hard added a comment to T4502: Consider implementing (NAT/other) flow table offload.

or maybe better add this subsection in firewall section?

Fri, Nov 11, 9:27 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4807: Need to fix traceroute help completion, a subtask of T4496: ping vrf help does not list VRFs, from In progress to Needs testing.
Fri, Nov 11, 8:18 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4807: Need to fix traceroute help completion from In progress to Needs testing.
Fri, Nov 11, 8:18 AM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4810: Op-mode show/monitor log pppoe interface does not show any logs from Open to Needs testing.
Fri, Nov 11, 8:17 AM · VyOS 1.4 Sagitta

Thu, Nov 10

Viacheslav added a parent task for T4812: IPsec ability to show all configured connections: T4564: Root task for rewriting [op-mode] to vyos.opmode format.
Thu, Nov 10, 7:41 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a subtask for T4564: Root task for rewriting [op-mode] to vyos.opmode format: T4812: IPsec ability to show all configured connections.
Thu, Nov 10, 7:41 PM · VyOS 1.4 Sagitta
Viacheslav created T4812: IPsec ability to show all configured connections.
Thu, Nov 10, 7:40 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort edited projects for T4153: Monitor bandwidth-test initiate not working, added: VyOS 1.3 Equuleus (1.3.3); removed VyOS 1.3 Equuleus (1.3.2).
Thu, Nov 10, 2:19 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort edited projects for T4153: Monitor bandwidth-test initiate not working, added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus (1.3.0).
Thu, Nov 10, 12:34 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
n.fort reopened T4153: Monitor bandwidth-test initiate not working as "Backport candidate".
Thu, Nov 10, 12:30 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
sajiby3k updated the task description for T4811: Webproxy bypassing cli command missing.
Thu, Nov 10, 12:26 PM · VyOS 1.3 Equuleus
sajiby3k created T4811: Webproxy bypassing cli command missing.
Thu, Nov 10, 12:25 PM · VyOS 1.3 Equuleus
initramfs added a comment to T4810: Op-mode show/monitor log pppoe interface does not show any logs.

Relevant PR:

Thu, Nov 10, 7:52 AM · VyOS 1.4 Sagitta
initramfs created T4810: Op-mode show/monitor log pppoe interface does not show any logs.
Thu, Nov 10, 7:46 AM · VyOS 1.4 Sagitta
initramfs added a comment to T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.

Hmm, I can't seem to reproduce that name with "pdns-recursor/now 4.8.0~beta1-1pdns.bullseye amd64" or "pdns-recursor/now 4.8.0~beta2-1pdns.bullseye amd64" both in a live bare-metal system or in a VM. Both versions return pdns_recursor for me when printed from p.name(). The worker thread names (as listed from ps or htop) also don't match: "rec/web+stat" and "rec/taskThread", not that either of these are returned by p.name().

Thu, Nov 10, 7:31 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po added a comment to T4799: PowerDNS >= 4.7 does not get reloaded by vyos-hostsd.

We use p.name from process_iter and it returns pdns-r/worker. That‘s why I have reverted the commits as in the latest 1.4 VyOS iso with PDNS 4.8 beta it‘s how they names the worker thread

Thu, Nov 10, 6:49 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)

Wed, Nov 9

TheSin- added a comment to T4797: External address/network lists for firewall (Local and remote).

list/lists in config and op-mode now moved to external-list

Wed, Nov 9, 9:48 PM · VyOS 1.4 Sagitta