Page MenuHomeVyOS Platform
Feed All Stories

Sep 28 2019

c-po updated the task description for T1512: vyos 1.2 openvpn client names with spaces created incorrectly.
Sep 28 2019, 7:39 AM · VyOS 1.3 Equuleus (1.3.0), openvpn
c-po added a subtask for T1682: Migrate to new Jenkins Pipeline script: T1496: Separate rolling release and LTS kernel builds.
Sep 28 2019, 7:14 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a parent task for T1496: Separate rolling release and LTS kernel builds: T1682: Migrate to new Jenkins Pipeline script.
Sep 28 2019, 7:14 AM · VyOS 1.2 Crux (VyOS 1.2.4)
c-po claimed T1496: Separate rolling release and LTS kernel builds.
Sep 28 2019, 7:13 AM · VyOS 1.2 Crux (VyOS 1.2.4)

Sep 27 2019

hagbard closed T1681: cleanup wireguard code since tagnodes are now visible as Resolved.
Sep 27 2019, 7:05 PM · VyOS 1.3 Equuleus (1.3.0)
c-po placed T1627: Rewrite wireless interface in new style XML syntax up for grabs.
Sep 27 2019, 7:04 PM · VyOS 1.3 Equuleus (1.3.0)
c-po updated subscribers of T1627: Rewrite wireless interface in new style XML syntax.

@alainlamar as you seem to be the VyOS Wireless expert, you know why we have VLAN support on it?

Sep 27 2019, 7:00 PM · VyOS 1.3 Equuleus (1.3.0)
syncer added a comment to T465: ZeroTier integration.

sorry, but their licensing model incompatible with what we do.

Sep 27 2019, 6:38 PM · Rejected
jdrews added a comment to T465: ZeroTier integration.

ZeroTier was added to the Ubiquiti EdgeRouter (which runs a vyatta fork) as a demo. Relevant to this thread:
https://blog.kruyt.org/zerotier-on-edgerouter-p2/

Sep 27 2019, 6:28 PM · Rejected
c-po closed T1695: Syntax error in interface-dummy.py as Resolved.
Sep 27 2019, 5:33 PM · VyOS 1.3 Equuleus (1.3.0)
bmtauer added a comment to T1157: Static route not reachable through VRRP address.

Yes, this _was_ still a problem but the workaround solves the issue for
me. I've been able to upgrade the 1.1.8 instances to 1.2.3 after adding
this extra interface route.

Sep 27 2019, 5:25 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
vindenesen added a comment to T1696: NTP - Tests fail when building vyos-1x.

Pull request created: https://github.com/vyos/vyos-1x/pull/141

Sep 27 2019, 5:00 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen changed the status of T1696: NTP - Tests fail when building vyos-1x from Open to In progress.
Sep 27 2019, 4:57 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen created T1696: NTP - Tests fail when building vyos-1x.
Sep 27 2019, 4:57 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen changed the status of T1695: Syntax error in interface-dummy.py from Open to In progress.

Pull request created: https://github.com/vyos/vyos-1x/pull/140

Sep 27 2019, 4:56 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen created T1695: Syntax error in interface-dummy.py.
Sep 27 2019, 4:50 PM · VyOS 1.3 Equuleus (1.3.0)
phoenix updated the task description for T1694: NTPd: Do not listen on all interfaces by default.
Sep 27 2019, 11:14 AM · VyOS 1.2 Crux (VyOS 1.2.4)
phoenix created T1694: NTPd: Do not listen on all interfaces by default.
Sep 27 2019, 11:02 AM · VyOS 1.2 Crux (VyOS 1.2.4)
mb300sd added a comment to T1672: Wireguard keys not automatically moved.

Been pretty busy lately, but ran a quick test tonight. Wireguard keys are properly moved in my VM.

Sep 27 2019, 3:54 AM · VyOS 1.3 Equuleus (1.3.0)
DWilly92 created T1693: DNS Forwarding Services not responding with Allow-From.
Sep 27 2019, 2:26 AM · VyOS 1.3 Equuleus (1.3.0)

Sep 26 2019

hagbard triaged T1684: Unable to enable IPv6 autoconf on PPPoE as Normal priority.
Sep 26 2019, 10:22 PM · VyOS 1.2 Crux (VyOS 1.2.3)
hagbard claimed T1684: Unable to enable IPv6 autoconf on PPPoE.
Sep 26 2019, 10:21 PM · VyOS 1.2 Crux (VyOS 1.2.3)
c-po claimed T1627: Rewrite wireless interface in new style XML syntax.
Sep 26 2019, 8:31 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a subtask for T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python: T1691: OpenVPN - Commiting config when OpenVPN peer/server not available makes commit hang.
Sep 26 2019, 7:49 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a parent task for T1691: OpenVPN - Commiting config when OpenVPN peer/server not available makes commit hang: T1548: Rewrite OpenVPN interface/op-commands in new style XML/Python.
Sep 26 2019, 7:49 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1691: OpenVPN - Commiting config when OpenVPN peer/server not available makes commit hang as Resolved.
Sep 26 2019, 7:49 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1692: ipoe-server verify function error as Resolved.

https://github.com/vyos/vyos-1x/commit/9b55f7c7b9ecc49e6efe075ad24a54baff719e8e

Sep 26 2019, 6:38 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1690: restart op-mode commands for 'service (pppoe|ipoe)-server' as Resolved.

https://github.com/vyos/vyos-1x/commit/6956bfe0620638adbad36f8cdf6d312884ba82ff
https://github.com/vyos/vyos-1x/commit/0c6faf26823fb984b3e0a77ee014e20661163e44

Sep 26 2019, 6:36 PM · VyOS 1.3 Equuleus (1.3.0)
c-po claimed T1691: OpenVPN - Commiting config when OpenVPN peer/server not available makes commit hang.
Sep 26 2019, 6:15 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1692: ipoe-server verify function error from Open to In progress.
Sep 26 2019, 6:12 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T1692: ipoe-server verify function error.
Sep 26 2019, 6:12 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen updated the task description for T1691: OpenVPN - Commiting config when OpenVPN peer/server not available makes commit hang.
Sep 26 2019, 5:50 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen renamed T1691: OpenVPN - Commiting config when OpenVPN peer/server not available makes commit hang from OpenVPN - Commiting config when OpenVPN peer/server not available hangs to OpenVPN - Commiting config when OpenVPN peer/server not available makes commit hang.
Sep 26 2019, 5:46 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen created T1691: OpenVPN - Commiting config when OpenVPN peer/server not available makes commit hang.
Sep 26 2019, 5:46 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed Difficulty level from unknown to easy on T1690: restart op-mode commands for 'service (pppoe|ipoe)-server'.
Sep 26 2019, 5:44 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1690: restart op-mode commands for 'service (pppoe|ipoe)-server' from Open to In progress.
Sep 26 2019, 5:30 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard triaged T1690: restart op-mode commands for 'service (pppoe|ipoe)-server' as Normal priority.
Sep 26 2019, 5:30 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T1690: restart op-mode commands for 'service (pppoe|ipoe)-server'.
Sep 26 2019, 5:30 PM · VyOS 1.3 Equuleus (1.3.0)
c-po triaged T1689: "reset openvpn" op-mode command should terminate and restart OpenVPN process as Low priority.
Sep 26 2019, 5:14 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1689: "reset openvpn" op-mode command should terminate and restart OpenVPN process.
Sep 26 2019, 5:14 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard renamed T1682: Migrate to new Jenkins Pipeline script from Migrate to new Jenkins Pieline script to Migrate to new Jenkins Pipeline script.
Sep 26 2019, 4:25 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing.
Sep 26 2019, 4:03 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
vindenesen claimed T1688: OpenVPN - Add new cipher aes-(128|192|256)-gcm.
Sep 26 2019, 1:52 PM · VyOS 1.3 Equuleus (1.3.0)
vindenesen created T1688: OpenVPN - Add new cipher aes-(128|192|256)-gcm.
Sep 26 2019, 1:51 PM · VyOS 1.3 Equuleus (1.3.0)
Woodster1975 closed T1687: Compare function producing error as Resolved.

I have rebuilt the router and this appears to be working as expected now. Marking as resolved.

Sep 26 2019, 9:10 AM · Invalid
Woodster1975 created T1687: Compare function producing error.
Sep 26 2019, 8:51 AM · Invalid
Unknown Object (User) added a comment to T1686: Spam.
Sep 26 2019, 6:01 AM
runar closed T1686: Spam as Invalid.
Sep 26 2019, 5:14 AM
runar renamed T1686: Spam from Arlo Customer Support Number to Spam.
Sep 26 2019, 5:13 AM
Unknown Object (User) updated the task description for T1686: Spam.
Sep 26 2019, 5:07 AM
Unknown Object (User) updated the task description for T1686: Spam.
Sep 26 2019, 5:07 AM
Unknown Object (User) updated the task description for T1686: Spam.
Sep 26 2019, 5:06 AM
Unknown Object (User) updated the task description for T1686: Spam.
Sep 26 2019, 5:06 AM
Unknown Object (User) created T1686: Spam.
Sep 26 2019, 5:05 AM

Sep 25 2019

Unknown Object (User) changed the status of T1685: Improvement cli ethernet helper for vif/vif-s/vif-c from Open to Needs testing.

PR 138

Sep 25 2019, 10:58 PM
Unknown Object (User) triaged T1685: Improvement cli ethernet helper for vif/vif-s/vif-c as Low priority.
Sep 25 2019, 10:54 PM
hagbard added a comment to T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing.

I've tested it and can't reproduce. There are a few issues in the debian files and autoreconf, but other than that everything seems to work just fine.

Sep 25 2019, 9:35 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
hagbard added a comment to T1572: Wireguard keyPair per interface.

There is no such thing like separate identities. You can either decrypt a package or you can't, that's about it. You basically have to hand out more public keys, you have to maintain more keys. As I mentioned before I only see currently disadvantages so far. However the user can chose what way to go and multiple options are always good. If it helps you, well that's nice to hear.

Sep 25 2019, 5:47 PM · VyOS 1.3 Equuleus (1.3.0)
jonaswre added a comment to T1572: Wireguard keyPair per interface.

It's not so much the implementation as I wrote before, it just doesn't seem beneficial. It gets implemented anyway, but I try to understand why a user would like to use that. The private key is by the way no identity and also won't interfere with multiple VPN peers if you are using only one pk. On IP:12345 arrives an encrypted packet, it is simply decrypted using your pk. If it works it's given to your kernel netlink interface as far as I recall and routed there, so no verification of the private key anywhere. If it can't be decrypted, it's discarded. If you have multiple wg interfaces, your 'crypto routing' either allows the traffic to the peer or discards it if it doesn't fit, the private key has nothing to do with that, since the public key of your peer is used to encrypt it. Summary, I still cna't see any benefit having that, which doesn't mean that I won't implement it.

Sep 25 2019, 4:56 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1299: Allow SNMPd to be extended with custom scripts as Resolved.
Sep 25 2019, 3:49 PM · VyOS 1.2 Crux (VyOS 1.2.4)
hagbard moved T1672: Wireguard keys not automatically moved from In Progress to Finished on the VyOS 1.3 Equuleus board.
Sep 25 2019, 3:41 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard closed T1672: Wireguard keys not automatically moved as Resolved.
Sep 25 2019, 3:41 PM · VyOS 1.3 Equuleus (1.3.0)
trae32566 added a comment to T1183: BFD Support via FRR.

This feature is currently in the 1.2 rolling release.

Sep 25 2019, 2:06 PM · VyOS 1.2 Crux (VyOS 1.2.4)
danfaulknor created T1684: Unable to enable IPv6 autoconf on PPPoE.
Sep 25 2019, 9:25 AM · VyOS 1.2 Crux (VyOS 1.2.3)
adestis added a comment to T1183: BFD Support via FRR.

It would be awsome if the feature could also be made available in the next VyOS 1.2.x version.
Because it likely takes a lot more time until version 1.3 gets released.

Sep 25 2019, 7:30 AM · VyOS 1.2 Crux (VyOS 1.2.4)

Sep 24 2019

hagbard moved T1635: Rewrite interface pseudo-ethernet in new XML/Python style from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Sep 24 2019, 10:47 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard moved T1672: Wireguard keys not automatically moved from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Sep 24 2019, 10:47 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard moved T1681: cleanup wireguard code since tagnodes are now visible from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Sep 24 2019, 10:46 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1681: cleanup wireguard code since tagnodes are now visible from In progress to Needs testing.

https://github.com/vyos/vyos-1x/commit/c6e9285262ddd762aac96ad3fa30d63cdeb2c6f2

Sep 24 2019, 8:39 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T1678: hostfile-update missing line feed.

PR https://github.com/vyos/vyos-1x/pull/137, using vyos-hostsd-client instead of typical adding record to /etc/hosts

Sep 24 2019, 5:03 PM · VyOS 1.2 Crux (VyOS 1.2.4)
Unknown Object (User) claimed T1678: hostfile-update missing line feed.
Sep 24 2019, 4:09 PM · VyOS 1.2 Crux (VyOS 1.2.4)
kroy added a comment to T1020: OSPF Stops distributing default route after a while.

Can confirm. All my routing tables now have 0.0.0.0/0, no matter what the device is. This is just in 1.2.3.

Sep 24 2019, 3:17 PM · VyOS 1.2 Crux (VyOS 1.2.5)
rherold added a comment to T1020: OSPF Stops distributing default route after a while.

Seems that it s merged an in 1.2.3 it looks in the moment good for me:

Sep 24 2019, 3:06 PM · VyOS 1.2 Crux (VyOS 1.2.5)
uranru created T1683: Difficulty monitoring VyOS through SNMP.
Sep 24 2019, 11:48 AM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
srgjp added a comment to T1560: "set load-balancing wan rule 0" causes segfault and prevents load balancing from starting.

reproduced on 1.2-rolling-201909100338

Sep 24 2019, 11:03 AM · VyOS 1.2 Crux (VyOS 1.2.4)
zsdc assigned T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred to Unknown Object (User).
Sep 24 2019, 10:17 AM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po added a comment to T1507: cli: logical redundancy with boolean type.

Unfortunately we have multiple commands like this.

Sep 24 2019, 6:22 AM · VyOS 1.3 Equuleus (1.3.0)
syncer added a project to T1507: cli: logical redundancy with boolean type: VyOS 1.3 Equuleus.
Sep 24 2019, 2:31 AM · VyOS 1.3 Equuleus (1.3.0)
dmbaturin edited projects for T1638: vyos-hostsd not setting system domain name , added: VyOS 1.2 Crux (VyOS 1.2.4); removed VyOS 1.2 Crux (VyOS 1.2.3).
Sep 24 2019, 1:53 AM · VyOS 1.2 Crux (VyOS 1.2.4)

Sep 23 2019

Unknown Object (User) updated the name of F411016: LLDP_sch1.png from "Снимок экрана 2019-09-24 в 1.59.25.png" to "LLDP_sch1.png".
Sep 23 2019, 11:09 PM
Unknown Object (User) added a comment to T1169: LLDP potentially broken.

Exist interesting moment when LLDPD communicate with cisco ios, after 1 min 55 second LLDPD in VyOS forget cisco device, but cisco device send LLDP (with ethertype encapsulated in vlan 1 0x8100). However LLDPD in VyOS remember mikrotik and other VyOS router, which directly connected, and which also transmit LLDP. I was try using and new version LLDPD which build for myself, but same result.
After adding vlan 1 on directly connected interface with cisco device LLDPD in VyOS, R1 don't forget it.

Sep 23 2019, 11:06 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
maznu added a comment to T1679: during bootup: invalid literal for int() with base 10.

That's fixed the problem we had, but we've encountered some other strangeness.

Sep 23 2019, 10:27 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard changed the status of T1681: cleanup wireguard code since tagnodes are now visible from Open to In progress.
Sep 23 2019, 8:10 PM · VyOS 1.3 Equuleus (1.3.0)
danhusan added a comment to T1219: Redundant active-active configuration, asymmetric routing and conntrack-sync cache.

Bump

Sep 23 2019, 7:58 PM · VyOS 1.2 Crux (VyOS 1.2.6), vyatta-conntrack-sync
c-po updated the task description for T1682: Migrate to new Jenkins Pipeline script.
Sep 23 2019, 7:32 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T1682: Migrate to new Jenkins Pipeline script from Open to In progress.
Sep 23 2019, 7:32 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1682: Migrate to new Jenkins Pipeline script.
Sep 23 2019, 7:30 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard claimed T1681: cleanup wireguard code since tagnodes are now visible.
Sep 23 2019, 7:24 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard created T1681: cleanup wireguard code since tagnodes are now visible.
Sep 23 2019, 7:24 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1680: DHCP client does not release IP address on exit/deletion, a subtask of T1557: Create generic abstraction for configuring interfaces e.g. IP address, as Resolved.
Sep 23 2019, 7:21 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1680: DHCP client does not release IP address on exit/deletion as Resolved.
Sep 23 2019, 7:21 PM · VyOS 1.3 Equuleus (1.3.0)
c-po triaged T1680: DHCP client does not release IP address on exit/deletion as High priority.
Sep 23 2019, 7:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T1680: DHCP client does not release IP address on exit/deletion, a subtask of T1557: Create generic abstraction for configuring interfaces e.g. IP address, from Open to In progress.
Sep 23 2019, 7:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T1680: DHCP client does not release IP address on exit/deletion from Open to In progress.
Sep 23 2019, 7:17 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T1680: DHCP client does not release IP address on exit/deletion.
Sep 23 2019, 7:17 PM · VyOS 1.3 Equuleus (1.3.0)
kroy added a comment to T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.

At this point I've moved all my ASAs to VyOS, and all my tunnels to Wireguard. Unfortunately I cannot test this setup anymore.

Sep 23 2019, 4:49 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Unknown Object (User) added a comment to T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.

Do you still have that problem?
Did you see EwaldvanGeffen's message?
Do you have any comment on it?

Sep 23 2019, 4:29 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
maznu added a comment to T1679: during bootup: invalid literal for int() with base 10.

Thank you, @c-po, I'll go deploy it now, then! :-)

Sep 23 2019, 4:18 PM · VyOS 1.3 Equuleus (1.3.0)
hagbard added a comment to T1679: during bootup: invalid literal for int() with base 10.

https://downloads.vyos.io/rolling/current/amd64/vyos-1.2-rolling-201909231545-amd64.iso

Sep 23 2019, 4:15 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1679: during bootup: invalid literal for int() with base 10.

ISO rebuild triggered

Sep 23 2019, 4:01 PM · VyOS 1.3 Equuleus (1.3.0)