Page MenuHomeVyOS Platform
Feed All Stories

Jan 16 2018

beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
In Q122, @aopdal wrote:

With prefix delegation you have a static prefix on your inside, but the "wan" interface on the router is using DHCP.

Jan 16 2018, 2:17 PM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

With prefix delegation you have a static prefix on your inside, but the "wan" interface on the router is using DHCP.

Jan 16 2018, 2:14 PM · VyOS 1.1.x
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
In Q122, @aopdal wrote:

Are your addresses managed from Comcast using prefix delegation?

Jan 16 2018, 1:53 PM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

Without routing you probably can't get it to work. Are your addresses managed from Comcast using prefix delegation?

Jan 16 2018, 1:36 PM · VyOS 1.1.x
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
In Q122, @aopdal wrote:

@beamerblvd have you added routes for your vif 100,200 and 900 in your "COMCAST BUSINESS IP GATEWAY"?

Jan 16 2018, 1:29 PM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

@beamerblvd have you added routes for your vif 100,200 and 900 in your "COMCAST BUSINESS IP GATEWAY"?

Jan 16 2018, 1:23 PM · VyOS 1.1.x
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

So the attempts with /56 and /60 were part of my hundreds of different combinations/attempts to get this to work. I have one /56 assigned to me (2603:xxxx:xxxx:8700::/56) with one gateway assigned to me (2603:xxxx:xxxx:8700:7454:7dff:feb1:d391). Skipping the WAN for just a second because I believe(d) it to need different configuration, I expected to be able to break that /56 up into /64s and use them like so:

Jan 16 2018, 1:15 PM · VyOS 1.1.x
elico added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

I am willing to give some advice but it's an issue to understand your infrastructure based on a very fuzzy set of details.
The basic rule of thumb that I can think of is that you cannot assign ip addresses with the same or overlapping prefix on two interfaces and route between them.
I do not know if the VyOS kernel supports IPV6 NAT feature but this should be a very last resort for specific scenarios.
If you need some examples on how IPv6 prefixes are being used you can try to peek at some IPv6 brokers such as Hurricane Electric.
They give you a very specific IPv6 address and prefix for the WAN side with a specific default route,
Then they give you a different prefix to assign the internal network which is behind the main gateway.
Is your setup different then what HE offers?

Jan 16 2018, 12:08 PM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

Perhaps you could make a drawing of what you try to get working? With proper interface naming etc. eth0 - wan, eth1 - dmz, eth2 - lan or whatever you are using. It makes it easier to understand what you try to do. And for the interfaces why do you want to use the /60?

Jan 16 2018, 7:43 AM · VyOS 1.1.x
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.
In Q122, @aopdal wrote:

Maybe this is relevant? https://phabricator.vyos.net/T421

Jan 16 2018, 7:26 AM · VyOS 1.1.x
aopdal added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

Maybe this is relevant? https://phabricator.vyos.net/T421

Jan 16 2018, 7:17 AM · VyOS 1.1.x
beamerblvd added a comment to Q122: How to properly configure multiple static IPv4 WAN addresses and IPv6 prefix to internal DHCP and static hosts.

So, I ended up handling my IPv4 addresses using 1:1 NAT. It works, and I don't love it, but I think it's the best it's going to get with Comcast's clunky static IP infrastructure. But I'm having no luck with IPv6, and could really use some help with someone who understand's static IPv6 and VyOS a little better. I have a static IPv6 prefix, and I need to statically assign some of those to public-facing servers behind my firewall/router, but it's like pulling teeth from a rhinoceros.

Jan 16 2018, 5:08 AM · VyOS 1.1.x
genta added a comment to T91: Memory leak in the Perl bindings for CStore (Vyatta::Config).

I've found memory leak bug in Cstore perl binding (perlxs).
This binding is a part of vyatta-cfg.

Jan 16 2018, 3:24 AM · VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jan 15 2018

vovakononov1 asked Q123: ip unnumbered/Super VLAN.
Jan 15 2018, 11:55 AM · VyOS 2.0.x, VyOS 1.3 Equuleus, VyOS 1.2 Crux

Jan 14 2018

syncer added a comment to T452: WiFi: Enable support for 5GHz AccesPoints with DFS.

That is fine, maybe with exception for some nasty vulnerabilities, however we also not disappear
just handy to have someone dedicated to wireless (almost separate world)
Thank you!

Jan 14 2018, 8:44 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar added a comment to T452: WiFi: Enable support for 5GHz AccesPoints with DFS.

@syncer thanks for the offer :)

Jan 14 2018, 8:01 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T516: Make Python / XML code development more testable as Normal priority.
Jan 14 2018, 6:37 PM · VyOS 1.3 Equuleus (1.3.0-epa1), Restricted Project
syncer triaged T515: Complete the documentation on the suggested Python / XML config framework as Normal priority.
Jan 14 2018, 5:51 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
syncer triaged T514: Concentration and streamlining of Python / XML config framework documentation as Normal priority.
Jan 14 2018, 5:50 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
syncer triaged T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration as Normal priority.
Jan 14 2018, 5:49 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
syncer moved T512: New package versions not synced to http://dev.packages.vyos.net from Need Triage to Finished on the VyOS 1.2 Crux board.
Jan 14 2018, 5:45 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer closed T512: New package versions not synced to http://dev.packages.vyos.net as Resolved.

@c-po i think this was fixed by @dmbaturin
marking as solved, if not, reopen

Jan 14 2018, 5:45 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer closed T507: vyatta-cfg-system -> SSH: Failure to correctly alter Ciphers and MACs as Resolved.
Jan 14 2018, 5:42 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
syncer triaged T506: Support CIDR notation in firewall address-group as Wishlist priority.
Jan 14 2018, 5:40 PM · Invalid
syncer added a comment to T452: WiFi: Enable support for 5GHz AccesPoints with DFS.

@alainlamar by any chance you want to be maintainer of wireless subsystem ? :)
It looks like you both have knowledge and real life use case and that make it whole easier

Jan 14 2018, 5:24 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar renamed T521: Network services may fail if vyatta-router.service startup takes longer than a few seconds from Network services may fail if vyatta-router.service startup takes longe rthan a few seconds to Network services may fail if vyatta-router.service startup takes longer than a few seconds.
Jan 14 2018, 4:49 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
alainlamar renamed T521: Network services may fail if vyatta-router.service startup takes longer than a few seconds from Network Services start before vyatta-router.service is started to Network services may fail if vyatta-router.service startup takes longe rthan a few seconds.
Jan 14 2018, 4:49 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
alainlamar created T521: Network services may fail if vyatta-router.service startup takes longer than a few seconds.
Jan 14 2018, 4:47 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 14 2018, 1:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jan 13 2018

alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 13 2018, 1:10 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 13 2018, 12:57 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 13 2018, 12:54 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 13 2018, 12:47 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jan 12 2018

agustafson added a comment to T383: snmpd messages in log with nightly "vyos-999.201709032137-amd64.iso".

I am seeing similar messages in 1.1.8.

Jan 12 2018, 5:46 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9)
shamidrasool updated the answer details for Q117: Instructions to build VyOS 1.2 from sources with frr (Answer 169).
Jan 12 2018, 7:21 AM
dmbaturin created T520: Build scripts should use a load balanced Debian mirror.
Jan 12 2018, 4:01 AM · Infrastructure

Jan 11 2018

dmbaturin closed T519: Make vyos package mirror configurable in build scripts as Resolved.
Jan 11 2018, 6:51 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
dmbaturin added a comment to T422: Packages server and downloads should be available via HTTPS.

The downloads.vyos.io is now using mandatory HTTPS. On the dev.packages.vyos.net, HTTPS is optional. To declare this closed, we need someone to independently verify that ISO build works with HTTPS for them.

Jan 11 2018, 6:01 AM · Infrastructure
dmbaturin created T519: Make vyos package mirror configurable in build scripts.
Jan 11 2018, 5:12 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jan 7 2018

alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 7 2018, 10:12 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 7 2018, 9:05 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 7 2018, 8:50 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated subscribers of T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration.

@c-po thanks for pointing me to the interface definitions!

Jan 7 2018, 8:30 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
alainlamar updated the task description for T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration.
Jan 7 2018, 8:29 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
c-po added a comment to T518: Move VyOS configuration syntax from Bash and node.def to XML.

@alainlamar nice work digging!

Jan 7 2018, 8:14 PM · Invalid
alainlamar added a comment to T517: Rewrite the wireless interface configuration in the new style (python + XML).

I found an example file in vyatta-lldp:

Jan 7 2018, 8:01 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
alainlamar added a comment to T518: Move VyOS configuration syntax from Bash and node.def to XML.

I found an example XML tag config file in vyatta-lldp:

Jan 7 2018, 7:58 PM · Invalid
alainlamar created T518: Move VyOS configuration syntax from Bash and node.def to XML.
Jan 7 2018, 7:45 PM · Invalid
alainlamar created T517: Rewrite the wireless interface configuration in the new style (python + XML).
Jan 7 2018, 7:40 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 7 2018, 6:26 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 7 2018, 6:21 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 7 2018, 6:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 7 2018, 6:14 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 7 2018, 6:10 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 7 2018, 6:09 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 7 2018, 5:48 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar updated the task description for T452: WiFi: Enable support for 5GHz AccesPoints with DFS.
Jan 7 2018, 5:37 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
squeeby added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

I'm using ntop-ng + nprobe.

Jan 7 2018, 1:28 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
alainlamar changed the visibility for T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration.
Jan 7 2018, 12:52 PM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
alainlamar updated the task description for T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration.
Jan 7 2018, 10:57 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
alainlamar updated the task description for T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration.
Jan 7 2018, 10:53 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
alainlamar created T516: Make Python / XML code development more testable.
Jan 7 2018, 10:52 AM · VyOS 1.3 Equuleus (1.3.0-epa1), Restricted Project
alainlamar created T515: Complete the documentation on the suggested Python / XML config framework.
Jan 7 2018, 10:50 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
alainlamar created T514: Concentration and streamlining of Python / XML config framework documentation.
Jan 7 2018, 10:48 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
alainlamar added projects to T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration: VyOS 1.2 Crux, Restricted Project.
Jan 7 2018, 10:42 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
alainlamar updated subscribers of T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration.
Jan 7 2018, 10:19 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
alainlamar created T513: Docs for devs: How to use Python, XML et al instead of Bash and Perl for VyOS configuration.
Jan 7 2018, 10:16 AM · VyOS 1.3 Equuleus (1.3.0), Restricted Project
c-po moved T341: WOL Tools in base image from Backlog to In Progress on the VyOS 1.2 Crux board.
Jan 7 2018, 8:26 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po updated subscribers of T341: WOL Tools in base image.

@syncer tools added to base image. This would be perfect for a vyos-1x op mode command. Unfortunately I was not able to build a working template with the relax-ng templates (lack of xml/relax-ng) knowledge. @dmbaturin maybe you can help?

Jan 7 2018, 8:26 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jan 6 2018

syncer added a project to T508: ISC DHCP incorrect UDP checksum generation: vyatta-dhcp3.
Jan 6 2018, 11:16 PM · VyOS 1.3 Equuleus (1.3.0-epa1), vyatta-dhcp3
syncer triaged T508: ISC DHCP incorrect UDP checksum generation as Normal priority.
Jan 6 2018, 11:13 PM · VyOS 1.3 Equuleus (1.3.0-epa1), vyatta-dhcp3
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

@squeeby which sflow collector do you use? Is there one you can recommend?

Jan 6 2018, 11:02 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po updated the task description for T512: New package versions not synced to http://dev.packages.vyos.net.
Jan 6 2018, 9:56 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po moved T379: UDP Broadcast Packet Relay from In Progress to Finished on the VyOS 1.2 Crux board.
Jan 6 2018, 9:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T379: UDP Broadcast Packet Relay.

Rewrote the scripts using vyos-1x and Python. This is now functioning on my routers.

Jan 6 2018, 9:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po created T512: New package versions not synced to http://dev.packages.vyos.net.
Jan 6 2018, 11:52 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po closed T509: vyos-build: VyOS Images have stopped building as Resolved.
Jan 6 2018, 8:13 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T509: vyos-build: VyOS Images have stopped building.

Working again

Jan 6 2018, 8:12 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jan 5 2018

jantman added a comment to V2: Should VyOS-specific shell be the login shell in VyOS 2.0?.

I like the way it works now, but honestly as long as I can get to both the CLI and the OS shell somehow (with a command), I don't really care which is the default.

Jan 5 2018, 11:11 PM · VyOS 2.0.x
c-po moved T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown from In Progress to Finished on the VyOS 1.2 Crux board.
Jan 5 2018, 8:12 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po moved T510: vyos-1x generated crontab nodes missleading from In Progress to Finished on the VyOS 1.2 Crux board.
Jan 5 2018, 8:12 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

Merged into vyatta-netflow package and will be included in tonights build.

Jan 5 2018, 8:07 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
squeeby added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

Looks good!

Jan 5 2018, 3:20 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

Ok, next try: https://www.mybll.net/vyatta-netflow_ver02_all.deb

Jan 5 2018, 3:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
squeeby added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

This appears to operate as expected.

Jan 5 2018, 2:58 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

Could you alter the file manually to get a working state and pass it to me by e.g. pasting it here or a https://pastebin.com/ link? Then I could regenerate a package for testing. This would help me a lot as I do not have any flow collector.

Jan 5 2018, 2:43 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
squeeby added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

So by reverting, the file /opt/vyatta/sbin/vyatta-netflow.pl contains:

328 sub acct_add_nflog_target {
329     my ($intf) = @_;
330
331     my ($table_chain) = acct_get_table_chain();
332     while (my ($chain, $table) = each(%$table_chain)) {
333         my $cmd = "iptables -t $table -I $chain 1 -i $intf -j NFLOG" ." --nflog-group 2";
334         if (defined $nflog_range) {
335             $cmd .= " --nflog-range $nflog_range";
336         }
337         if (defined $nflog_threshold) {
338             $cmd .= " --nflog-threshold $nflog_threshold";
339         }
340         my $ret = system($cmd);
341         if ($ret >> 8) {
342             die "Error: [$cmd] failed - $?\n";
343         }
344     }
345 }
Jan 5 2018, 2:18 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

You can revert by switching back to the official VyOS package.

Jan 5 2018, 2:13 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
squeeby added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

Do you know how I can restore the previous version so I can see if it was this package that changed it?

Jan 5 2018, 1:59 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

Strange. I only changed /opt/vyatta/sbin/vyatta-netflow.pl to your recommendation.

Jan 5 2018, 9:32 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
squeeby added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

I applied your patch but now iptables has reverted to using the ULOG target instead of NFLOG:

squeeb@gw1# commit
[ system flow-accounting interface eth2 ]
iptables: No chain/target/match by that name.
Error: [iptables -t raw -I VYATTA_CT_PREROUTING_HOOK 1 -i eth2 -j ULOG --ulog-nlgroup 2 --ulog-cprange 64 --ulog-qthreshold 10] failed - 256
Jan 5 2018, 7:50 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po moved T510: vyos-1x generated crontab nodes missleading from Need Triage to In Progress on the VyOS 1.2 Crux board.
Jan 5 2018, 6:51 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

@squeeby do you mind verifying the following package containing your fix:

Jan 5 2018, 6:50 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
squeeby added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

Changing the following lines to the excerpt below in /opt/vyatta/sbin/vyatta-netflow.pl seems to work:

Jan 5 2018, 1:51 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
squeeby added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.
# show system flow-accounting
 interface pppoe0
 interface eth2.2
 interface eth2.3
 sflow {
     agent-address 192.168.64.1
     sampling-rate 10
     server 192.168.64.10 {
         port 2055
     }
 }
Jan 5 2018, 1:38 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jan 4 2018

c-po triaged T510: vyos-1x generated crontab nodes missleading as Normal priority.
Jan 4 2018, 11:34 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po created T510: vyos-1x generated crontab nodes missleading.
Jan 4 2018, 11:33 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
Tanuki added a watcher for vyos-frr: Tanuki.
Jan 4 2018, 3:15 AM

Jan 3 2018

netravnen added a watcher for VyOS 2.0.x: netravnen.
Jan 3 2018, 3:22 PM
netravnen added a watcher for vyos-frr: netravnen.
Jan 3 2018, 3:18 PM