Page MenuHomeVyOS Platform
Feed All Stories

Aug 1 2020

xcme updated the task description for T2754: PBR doesn't work with VRRP.
Aug 1 2020, 6:44 PM
xcme created T2754: PBR doesn't work with VRRP.
Aug 1 2020, 6:41 PM
c-po closed T2690: Add VRF support to the add system image command, a subtask of T2753: Rewrite "add system image" op mode commands in XML, as Resolved.
Aug 1 2020, 12:31 PM · VyOS 1.3 Equuleus
c-po closed T2690: Add VRF support to the add system image command as Resolved.
Aug 1 2020, 12:31 PM · VyOS 1.3 Equuleus
c-po added a comment to T2690: Add VRF support to the add system image command.

@moepman please checkout the next rolling ISO - at least it works as expected in my LAB

Aug 1 2020, 12:31 PM · VyOS 1.3 Equuleus
c-po changed the status of T2690: Add VRF support to the add system image command, a subtask of T2753: Rewrite "add system image" op mode commands in XML, from Open to In progress.
Aug 1 2020, 12:08 PM · VyOS 1.3 Equuleus
c-po changed the status of T2690: Add VRF support to the add system image command from Open to In progress.
Aug 1 2020, 12:08 PM · VyOS 1.3 Equuleus
jack9603301 updated the task description for T2518: Support NAT for ipv6(NPT).
Aug 1 2020, 10:32 AM · VyOS 1.3 Equuleus
c-po closed T2753: Rewrite "add system image" op mode commands in XML as Resolved.
Aug 1 2020, 10:27 AM · VyOS 1.3 Equuleus
jack9603301 updated the task description for T2518: Support NAT for ipv6(NPT).
Aug 1 2020, 10:17 AM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

@thomas-mangin Maybe it's better to discuss it here

Aug 1 2020, 10:14 AM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).
Aug 1 2020, 10:06 AM · VyOS 1.3 Equuleus
jack9603301 updated subscribers of T2518: Support NAT for ipv6(NPT).

@thomas-mangin As mentioned in my comments, I refer to the configuration structure of H3C. In the original command structure, nptv6 does not support the division of SNAT and DNAT. In order to implement nat66, I separated it for the following reasons:

Aug 1 2020, 10:00 AM · VyOS 1.3 Equuleus
c-po added a parent task for T2690: Add VRF support to the add system image command: T2753: Rewrite "add system image" op mode commands in XML.
Aug 1 2020, 9:53 AM · VyOS 1.3 Equuleus
c-po added a subtask for T2753: Rewrite "add system image" op mode commands in XML: T2690: Add VRF support to the add system image command.
Aug 1 2020, 9:53 AM · VyOS 1.3 Equuleus
c-po created T2753: Rewrite "add system image" op mode commands in XML.
Aug 1 2020, 9:53 AM · VyOS 1.3 Equuleus
c-po added a comment to T2690: Add VRF support to the add system image command.

When connected via SSH to the router in question every command is run inside the VRF, thus a regular add system image will already run in the VRF. Nevertheless it would make sense to execute the command from another VRF.

Aug 1 2020, 9:40 AM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

It is hoped that this implementation can make the prefix translation work again. Refer to the relevant operation of H3C equipment and fully support nat66

Aug 1 2020, 9:07 AM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

I don't use this kind of tool to test his nftables policy, but I'm used to testing it by manually configuring nftables and replacing my nftables template file with that of the vyos system. Vyos did not report errors during its build configuration.

Aug 1 2020, 9:05 AM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

@c-po The related nftables policy in the local environment test did not find syntax problems, only need to be tested to verify the effectiveness of the function, so I call it experimental support.

Aug 1 2020, 9:02 AM · VyOS 1.3 Equuleus
c-po added a comment to T2518: Support NAT for ipv6(NPT).

I ask myself if it not would make more sense to get the prefix translation working again and then add new features here?

Aug 1 2020, 8:53 AM · VyOS 1.3 Equuleus
jack9603301 triaged T2518: Support NAT for ipv6(NPT) as Normal priority.
Aug 1 2020, 8:52 AM · VyOS 1.3 Equuleus
c-po closed T2752: Exception when configuring unavailable ethernet interface as Resolved.
Aug 1 2020, 8:51 AM · VyOS 1.3 Equuleus
jack9603301 updated the task description for T2518: Support NAT for ipv6(NPT).
Aug 1 2020, 8:41 AM · VyOS 1.3 Equuleus
c-po changed the status of T2752: Exception when configuring unavailable ethernet interface from Open to In progress.
Aug 1 2020, 8:41 AM · VyOS 1.3 Equuleus
c-po created T2752: Exception when configuring unavailable ethernet interface.
Aug 1 2020, 8:41 AM · VyOS 1.3 Equuleus
c-po closed T2751: Update Linux Kernel to v4.19.136 as Resolved.
Aug 1 2020, 8:33 AM · VyOS 1.3 Equuleus
c-po created T2751: Update Linux Kernel to v4.19.136.
Aug 1 2020, 8:33 AM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2715: Duplicate address detection option supporting ARP.

@c-po Can you take a look at this PR for me?

Aug 1 2020, 3:12 AM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2724: Support for IPv6 Toolset.

@c-po Can you take a look at this PR for me? At present, the command implementation of ndptool send has been canceled

Aug 1 2020, 3:12 AM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

This PR will provide experimental nat66 support, which needs to be tested

Aug 1 2020, 3:05 AM · VyOS 1.3 Equuleus

Jul 31 2020

starcraft66 added a comment to T2623: Creating sit tunnel fails with “Can not set “local” for tunnel sit tun1 at tunnel creation”.

@SrividyaA I just upgraded to the latest rolling image (1.3-rolling-202007311330) and I can still reproduce the exact same issue with the config above. Here's output from show log.

Jul 31 2020, 6:15 PM · VyOS 1.3 Equuleus
marcelocsilva added a comment to T2749: Setting ethx configuration issue..

Will do, working on it...let you know as soon as I finished this weekend.

Jul 31 2020, 5:39 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2749: Setting ethx configuration issue..

Maybe I just didn't encounter it. In short, please try the latest version first. If this problem still exists, please provide the detailed configuration and environment information of the error to facilitate the recurrence and troubleshooting of community members

Jul 31 2020, 5:27 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2749: Setting ethx configuration issue..

Please try the latest version of the image, I have not encountered similar problems at present

Jul 31 2020, 5:26 PM · VyOS 1.3 Equuleus
marcelocsilva added a comment to T2749: Setting ethx configuration issue..

Jack, I' am aware regarding SSH protocol to manage it remotely, I work with, but the point is:

Jul 31 2020, 5:22 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2749: Setting ethx configuration issue..

I don't understand what you mean. If you use the SSH protocol remotely, you should be able to automatically resume the connection within the allowable time of the protocol. However, if the time is exceeded, you may need to wait for the network connection to recover and reopen the SSH connection.

Jul 31 2020, 5:03 PM · VyOS 1.3 Equuleus
thomas-mangin added a comment to T2750: Use m4 as a template processor.

And there are some PR pending on that exact code ..

Jul 31 2020, 4:55 PM · VyOS 1.3 Equuleus
thomas-mangin added a comment to T2750: Use m4 as a template processor.

If anything this code could/should be extracted in an internal library and then a tool created to replace what we have so the behaviour is consistent in both cases.

Jul 31 2020, 4:50 PM · VyOS 1.3 Equuleus
thomas-mangin added a comment to T2750: Use m4 as a template processor.

There is now some python XML code to parse the XML. m4 is not a nice tool. If better pre-processing is required, which I would not argue for, please explain the issue you are trying to solve.

Jul 31 2020, 4:48 PM · VyOS 1.3 Equuleus
jjakob triaged T2750: Use m4 as a template processor as Wishlist priority.
Jul 31 2020, 4:31 PM · VyOS 1.3 Equuleus
marcelocsilva created T2749: Setting ethx configuration issue..
Jul 31 2020, 4:19 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

@c-po According to H3C, the relevant operations are as follows:

Jul 31 2020, 4:02 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

@c-po According to H3C and the third-party information on the Internet, NPT is also called nat66. Nat66 is actually the SNAT and DNAT implementation of IPv6, and implements 1-to-1 mapping and prefix address translation. Since there is no separate configuration directory for these two directions in the configuration, this draft implements two directions. Tomorrow, we will try to modify the configuration path according to the document of H3C device, add the diff of the draft, and then propose Submit merger request.

Jul 31 2020, 3:40 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

@c-po It has been revised as follows:

Jul 31 2020, 3:25 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).
Jul 31 2020, 2:55 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).
Jul 31 2020, 2:27 PM · VyOS 1.3 Equuleus
zsdc changed the status of T2726: Allow to use all supported SSH key types in Cloud-init from Open to In progress.
Jul 31 2020, 2:25 PM · VyOS 1.3 Equuleus
zsdc changed the status of T2703: VMWare OVA won't deploy an ed25519 key, a subtask of T2726: Allow to use all supported SSH key types in Cloud-init, from Open to In progress.
Jul 31 2020, 2:25 PM · VyOS 1.3 Equuleus
zsdc changed the status of T2703: VMWare OVA won't deploy an ed25519 key from Open to In progress.
Jul 31 2020, 2:25 PM · VyOS 1.2 Crux
c-po added a comment to T2518: Support NAT for ipv6(NPT).

Well I would just have plumbed up the commands locally before doing any templating. Please keep us updated if it works.

Jul 31 2020, 2:04 PM · VyOS 1.3 Equuleus
zsdc assigned T2748: "show vpn ike sa" shows state "down" when tunnel is up to ronie.
Jul 31 2020, 12:24 PM · VyOS 1.3 Equuleus
zsdc assigned T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic to ronie.
Jul 31 2020, 12:23 PM · VyOS 1.3 Equuleus
jack9603301 changed the status of T2518: Support NAT for ipv6(NPT) from Open to In progress.
Jul 31 2020, 11:00 AM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

I didn't get any specific help. The modified pudding was set up based on the trial and limited third-party data here, and it needs to be fully tested.

Jul 31 2020, 10:57 AM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

@c-po This is a simple draft of my current implementation of NPT. At present, I haven't tested it, and I haven't applied for merger. I can send it here for some discussion.

Jul 31 2020, 10:54 AM · VyOS 1.3 Equuleus
ajgnet created T2748: "show vpn ike sa" shows state "down" when tunnel is up.
Jul 31 2020, 1:55 AM · VyOS 1.3 Equuleus

Jul 30 2020

ajgnet updated the task description for T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic.
Jul 30 2020, 11:54 PM · VyOS 1.3 Equuleus
ajgnet created T2747: "enable-local-traffic" has no effect in load-balancing to redirect local traffic.
Jul 30 2020, 11:52 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2746: IPv6 link-local addresses not configured.

No I didn't, sorry. I'll test it and see :)

Jul 30 2020, 10:25 PM · VyOS 1.3 Equuleus
c-po added a comment to T2746: IPv6 link-local addresses not configured.

Have you tested the latest codebase? It more or less follows your design for the member ports.

Jul 30 2020, 10:07 PM · VyOS 1.3 Equuleus
jjakob added a comment to T2746: IPv6 link-local addresses not configured.

This is not enough, bridge and bond members also didn't get IPv6 link-locals in the previous implementation. To have them is incorrect and a security risk.

Jul 30 2020, 9:37 PM · VyOS 1.3 Equuleus
c-po added a comment to T2741: DHCPv6-PD breaks interface config if it refers to VLAN interfaces.

The last bug mentioned could be due to: https://phabricator.vyos.net/T2746

Jul 30 2020, 9:36 PM
c-po closed T2746: IPv6 link-local addresses not configured, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, as Resolved.
Jul 30 2020, 9:33 PM · VyOS 1.3 Equuleus
c-po closed T2746: IPv6 link-local addresses not configured as Resolved.
Jul 30 2020, 9:33 PM · VyOS 1.3 Equuleus
c-po changed the status of T2746: IPv6 link-local addresses not configured, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, from Open to In progress.
Jul 30 2020, 9:12 PM · VyOS 1.3 Equuleus
c-po changed the status of T2746: IPv6 link-local addresses not configured from Open to In progress.
Jul 30 2020, 9:12 PM · VyOS 1.3 Equuleus
c-po created T2746: IPv6 link-local addresses not configured.
Jul 30 2020, 9:12 PM · VyOS 1.3 Equuleus
c-po closed T679: SNMPv3 tsm Warning: Unknown token: localCert, a subtask of T652: Rewrite service snmp in new style XML interface definition, as Wontfix.
Jul 30 2020, 9:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
c-po closed T679: SNMPv3 tsm Warning: Unknown token: localCert as Wontfix.
Jul 30 2020, 9:04 PM · VyOS 1.3 Equuleus
c-po added a comment to T679: SNMPv3 tsm Warning: Unknown token: localCert.

TSM support has been droppen in 1.3

Jul 30 2020, 9:04 PM · VyOS 1.3 Equuleus
c-po closed T2745: router-advert: migrate to get_config_dict() as Resolved.
Jul 30 2020, 8:56 PM · VyOS 1.3 Equuleus
c-po changed the status of T2745: router-advert: migrate to get_config_dict() from Open to In progress.
Jul 30 2020, 8:26 PM · VyOS 1.3 Equuleus
c-po created T2745: router-advert: migrate to get_config_dict().
Jul 30 2020, 8:26 PM · VyOS 1.3 Equuleus
dmbaturin changed the status of T2728: Protocol option ignored for IPSec peers in transport mode from In progress to Needs testing.
Jul 30 2020, 5:08 PM · VyOS 1.2 Crux (VyOS 1.2.6), VyOS 1.3 Equuleus
c-po closed T2678: High RAM usage on SSH logins with lots of IPv6 routes in the routing table. as Resolved.
Jul 30 2020, 5:06 PM · VyOS 1.3 Equuleus
c-po claimed T2741: DHCPv6-PD breaks interface config if it refers to VLAN interfaces.
Jul 30 2020, 5:06 PM
thomas-mangin added a comment to T2214: BGP peers dropping randomly.

related to T1699

Jul 30 2020, 3:08 PM · VyOS 1.2 Crux
dmbaturin closed T2701: `vpn ipsec pfs enable` doesn't work with IKE groups as Resolved.
Jul 30 2020, 2:57 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.6)
Dmitry claimed T2333: Increase default sysctl values.
Jul 30 2020, 2:53 PM · VyOS 1.3 Equuleus
dmbaturin added a project to T2333: Increase default sysctl values: VyOS 1.2 Crux (VyOS 1.2.6).
Jul 30 2020, 2:51 PM · VyOS 1.3 Equuleus
Dmitry created T2744: igmp-proxy issue: Address already in use.
Jul 30 2020, 1:31 PM · VyOS 1.3 Equuleus
Viacheslav added a comment to T2378: BGPD crash in Vyos 1.2.5.

@Merijn Have such problems been repeated?

Jul 30 2020, 10:05 AM · VyOS 1.2 Crux
thamosliam updated thamosliam.
Jul 30 2020, 8:32 AM

Jul 29 2020

c-po closed T2743: WireGuard: move key migration from config script to migration script as Resolved.
Jul 29 2020, 7:57 PM · VyOS 1.3 Equuleus
c-po changed the status of T2243: Bridge interface fails if member is VXLAN interface with VTI underlay, a subtask of T2353: Interface [conf_mode] errors, from Open to On hold.
Jul 29 2020, 6:53 PM · VyOS 1.3 Equuleus
c-po changed the status of T2243: Bridge interface fails if member is VXLAN interface with VTI underlay from Open to On hold.
Jul 29 2020, 6:53 PM · VyOS 1.3 Equuleus
c-po added a comment to T2243: Bridge interface fails if member is VXLAN interface with VTI underlay.

The problem is that vti interfaces are only created when VPN is configured this is done very late with priority 900. VXLAN, bridge etc (also in 1.2) use a lower priority. The only solution will be that the vti interface is added imediately and then later bound to the VPN.

Jul 29 2020, 6:05 PM · VyOS 1.3 Equuleus
SrividyaA closed T2598: Error when commiting firewall groups as Invalid.

The issue did not reproduce neither in 1.2.5 nor in 1.3 version.
Try in the new release and re-open the ticket if any new information appeared.

Jul 29 2020, 5:37 PM · VyOS 1.2 Crux
jack9603301 updated the task description for T2724: Support for IPv6 Toolset.
Jul 29 2020, 5:19 PM · VyOS 1.3 Equuleus
Viacheslav added a comment to T2598: Error when commiting firewall groups.

@olofl I can't confirm this bug int the 1.2.5 LTS version.

Jul 29 2020, 5:16 PM · VyOS 1.2 Crux
Viacheslav added a comment to T2606: ikev2 mobike commit failed .

I can't confirm this bug.

vyos@vyos# set vpn ipsec ike-group IKEv2_DEFAULT mobike disable 
[edit]
vyos@vyos# commit
[edit]
vyos@vyos# run show version 
Version:          VyOS 1.2.5
Built by:         Sentrium S.L.
Built on:         Sun 12 Apr 2020 15:18 UTC
Build UUID:       1695c660-d785-4b16-a54b-66d6a02ea24f
Build Commit ID:  48cc9fc46569e6
Jul 29 2020, 5:06 PM · VyOS 1.2 Crux
c-po added a comment to T2243: Bridge interface fails if member is VXLAN interface with VTI underlay.

That configuration does not work in 1.2.5 either - we probably should exclude vti from VXLAN source interface?

Jul 29 2020, 4:56 PM · VyOS 1.3 Equuleus
c-po added a comment to T2243: Bridge interface fails if member is VXLAN interface with VTI underlay.

In latest rolling releases this will break b/c of:

Jul 29 2020, 4:43 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

@c-po In my vyos, the following commands run successfully, and the rule settings are normal, but the rules are not tested to be effective and correct. For reference only, if I have time, I will open the eve ng simulation environment.

Jul 29 2020, 4:38 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2724: Support for IPv6 Toolset.

@c-po Since I can't find a suitable place to use ndptool send, in this task list, cancel the implementation of this function. If necessary, the user can run it directly from the command, and now submit the correction. If possible, please re audit pr

Jul 29 2020, 4:31 PM · VyOS 1.3 Equuleus
jack9603301 updated the task description for T2724: Support for IPv6 Toolset.
Jul 29 2020, 4:29 PM · VyOS 1.3 Equuleus
jestabro changed the status of T2582: Script daemon to offload processing during commit from In progress to Needs testing.

What is here:

Jul 29 2020, 4:27 PM · VyOS 1.3 Equuleus
jack9603301 added a comment to T2518: Support NAT for ipv6(NPT).

Although this document may not be a direct help, it may help us understand how to set up IPv6 NAT for nftables?

Jul 29 2020, 4:19 PM · VyOS 1.3 Equuleus
c-po changed the status of T2743: WireGuard: move key migration from config script to migration script from Open to In progress.
Jul 29 2020, 4:14 PM · VyOS 1.3 Equuleus