Page MenuHomeVyOS Platform
Feed All Stories

Oct 18 2020

c-po added a comment to T2969: OpenVPN: command_set on interface is not applied, if interface doesn't come up in commit.

The root cause of this problem is that OpenVPN when the deamon is started and in tries to connect to the server, yet did not create the vtun11 interface on the system. Thus all calls to the ifconfig python library will fail big time.

Oct 18 2020, 10:16 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2907: OpenVPN: Option to disable encryption as Resolved.
Oct 18 2020, 10:03 AM · VyOS 1.3 Equuleus (1.3.0), openvpn
jack9603301 added a comment to T766: Implement support for the Tinc VPN daemon.

I updated pr. so far, tinc VPN cli will automatically generate the local node key file, such as the following code:

Oct 18 2020, 9:53 AM
jack9603301 added a comment to T160: Support NAT64.

Isn't anyone implementing this feature right now?

Oct 18 2020, 4:35 AM · VyOS 1.4 Sagitta (1.4.0-epa1)

Oct 17 2020

c-po changed the status of T2985: Add glue code to create bridge interface on demand, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, from In progress to Needs testing.
Oct 17 2020, 8:55 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2985: Add glue code to create bridge interface on demand from In progress to Needs testing.
Oct 17 2020, 8:55 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2980: FRR bfdd crash due to invalid length as Resolved.
Oct 17 2020, 8:42 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2990: Update Linux Kernel to v4.19.152 as Resolved.
Oct 17 2020, 8:38 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2990: Update Linux Kernel to v4.19.152 from Open to In progress.
Oct 17 2020, 8:35 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2991: Update WireGuard to 1.0.20200908, a subtask of T2990: Update Linux Kernel to v4.19.152, as Resolved.
Oct 17 2020, 8:34 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2991: Update WireGuard to 1.0.20200908 as Resolved.
Oct 17 2020, 8:34 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2991: Update WireGuard to 1.0.20200908.
Oct 17 2020, 8:34 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2990: Update Linux Kernel to v4.19.152.
Oct 17 2020, 8:34 PM · VyOS 1.3 Equuleus (1.3.0)
Cheeze_It changed the status of T2989: MPLS documentation expansion from Open to In progress.
Oct 17 2020, 7:28 PM · VyOS 1.3 Equuleus (1.3.0)
rherold created T2988: ip source validation not working for ipv6 aka move it to netfilter.
Oct 17 2020, 7:10 PM · VyOS 1.2 Crux
tom.siewert added a comment to T2987: VxLAN not working properly after upgrading to latest October build and with a new installation.

My last comment was wrong, here are the outputs for bridge fdb show dev vxlan122:

Oct 17 2020, 6:08 PM · VyOS 1.3 Equuleus (1.3.0)
tom.siewert added a comment to T2987: VxLAN not working properly after upgrading to latest October build and with a new installation.
Oct 17 2020, 5:58 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2987: VxLAN not working properly after upgrading to latest October build and with a new installation.

I can't reproduce it with VyOS 1.3-rolling-202010170146 and other october releases

Oct 17 2020, 4:27 PM · VyOS 1.3 Equuleus (1.3.0)
tom.siewert added a comment to T2987: VxLAN not working properly after upgrading to latest October build and with a new installation.

source-interface cannot be used as the routers are not in the same multicast group, neither can communicate via multicast

Oct 17 2020, 4:23 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2987: VxLAN not working properly after upgrading to latest October build and with a new installation.
Oct 17 2020, 4:20 PM · VyOS 1.3 Equuleus (1.3.0)
tom.siewert added a comment to T2987: VxLAN not working properly after upgrading to latest October build and with a new installation.

@tom.siewert
What will be if you delete the source-address on "October" node?

Oct 17 2020, 4:19 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2987: VxLAN not working properly after upgrading to latest October build and with a new installation.

@tom.siewert
What will be if you delete the source-address on "October" node?

Oct 17 2020, 4:08 PM · VyOS 1.3 Equuleus (1.3.0)
tom.siewert created T2987: VxLAN not working properly after upgrading to latest October build and with a new installation.
Oct 17 2020, 3:20 PM · VyOS 1.3 Equuleus (1.3.0)
UnicronNL changed the status of T2834: Config rollback function is broken due lack access to the config.boot from Confirmed to Needs testing.
Oct 17 2020, 1:27 PM · Restricted Project
superq added a comment to T973: Create Prometheus Exporter for VyOS .

We should avoid having a constellation of exporters, but favour having a single one. I feel like starting and stopping those would be pretty icky.

Oct 17 2020, 1:22 PM · VyOS 1.5 Circinus
UnicronNL claimed T2834: Config rollback function is broken due lack access to the config.boot.
Oct 17 2020, 12:57 PM · Restricted Project
Viacheslav added a comment to T752: Add an option to disable IPv4 forwarding on specific interface only.

PR https://github.com/vyos/vyos-1x/pull/576

Oct 17 2020, 12:54 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
jack9603301 added a comment to T2986: Unable to build qemu image due to misconfigured Packer.

Must this command be executed from docker now?

Oct 17 2020, 11:55 AM · VyOS 1.3 Equuleus (1.3.0)
c-po edited projects for T2792: Failed to run `sudo make qemu` with vyos-build container due to the change of packer, added: VyOS 1.3 Equuleus; removed vyos-build.
Oct 17 2020, 11:45 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2792: Failed to run `sudo make qemu` with vyos-build container due to the change of packer as Resolved.
Oct 17 2020, 11:44 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2986: Unable to build qemu image due to misconfigured Packer as Invalid.
Oct 17 2020, 11:37 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2986: Unable to build qemu image due to misconfigured Packer.

This will break builds in out Docker environment where we ship a packer version. See T2792 and https://github.com/vyos/vyos-build/commit/e2dd9db8a2539b6d13c98d89e18872336cf8f974

Oct 17 2020, 11:37 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 updated the task description for T2986: Unable to build qemu image due to misconfigured Packer.
Oct 17 2020, 10:52 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 created T2986: Unable to build qemu image due to misconfigured Packer.
Oct 17 2020, 10:51 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed Version from - to 1.3-rolling-202010081758 on T2985: Add glue code to create bridge interface on demand.
Oct 17 2020, 10:01 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2985: Add glue code to create bridge interface on demand from Open to In progress.
Oct 17 2020, 10:00 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T2985: Add glue code to create bridge interface on demand, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, from Open to In progress.
Oct 17 2020, 10:00 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2985: Add glue code to create bridge interface on demand.
Oct 17 2020, 9:59 AM · VyOS 1.3 Equuleus (1.3.0)
jmcg added a comment to T1229: Add support for unencrypted L2TPv2 client connections.

Also very interested in this. Ready and willing to test.

Oct 17 2020, 9:39 AM · VyOS 1.5 Circinus
Viacheslav closed T2981: MPLS LDP neighbor session clear capability as Resolved.

@Cheeze_It thanks, works fine.

Oct 17 2020, 8:32 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) changed the status of T2984: (igb, ixgbe) HW queues applied only for the first 2 interfaces from In progress to Needs testing.

PR https://github.com/vyos/vyos-build/pull/128

Oct 17 2020, 7:16 AM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) changed the status of T2984: (igb, ixgbe) HW queues applied only for the first 2 interfaces from Open to In progress.
Oct 17 2020, 7:09 AM · VyOS 1.2 Crux (VyOS 1.2.7)
Unknown Object (User) created T2984: (igb, ixgbe) HW queues applied only for the first 2 interfaces .
Oct 17 2020, 7:09 AM · VyOS 1.2 Crux (VyOS 1.2.7)

Oct 16 2020

Unknown Object (User) changed the status of T2978: IPoE service does not work on shared mode from Confirmed to Needs testing.

PR https://github.com/vyos/vyos-1x/pull/575

Oct 16 2020, 11:29 PM · VyOS 1.3 Equuleus (1.3.0)
Cheeze_It changed the status of T2981: MPLS LDP neighbor session clear capability from Open to Needs testing.
Oct 16 2020, 11:24 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T752: Add an option to disable IPv4 forwarding on specific interface only.

That would be a workaround only - see IPv6 syntax above. Using the refactored interface handling (T2653) makes this a low-hanging fruit.

Oct 16 2020, 8:43 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Cheeze_It added a comment to T915: MPLS Support.

I'll be giving those a test once T2981 is done. I'll report back here with results :)

Oct 16 2020, 8:26 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Cheeze_It added a comment to T2981: MPLS LDP neighbor session clear capability.

PR is added here...

Oct 16 2020, 7:07 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) created T2983: Add support to DHCP server include an extended config.
Oct 16 2020, 6:47 PM · VyOS 1.3 Equuleus (1.3.4)
jack9603301 added a comment to T973: Create Prometheus Exporter for VyOS .

Quite interesting, support, in fact some information can not be captured from SNMP very well

Oct 16 2020, 6:36 PM · VyOS 1.5 Circinus
syncer reassigned T973: Create Prometheus Exporter for VyOS from kroy to superq.
Oct 16 2020, 6:27 PM · VyOS 1.5 Circinus
owensresearch awarded T2257: BGP does not work with VRF a Heartbreak token.
Oct 16 2020, 6:22 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T752: Add an option to disable IPv4 forwarding on specific interface only.

How about this?

Oct 16 2020, 5:28 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T2938: Adding remote Syslog RFC5424 compatibility.

@D0peX That's correct? I updated pr

Oct 16 2020, 2:29 PM · VyOS 1.3 Equuleus (1.3.0)
D0peX added a comment to T2938: Adding remote Syslog RFC5424 compatibility.

Thank you Viacheslav

Oct 16 2020, 2:06 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav changed the status of T2907: OpenVPN: Option to disable encryption from Open to Needs testing.
Oct 16 2020, 1:46 PM · VyOS 1.3 Equuleus (1.3.0), openvpn
Viacheslav claimed T2938: Adding remote Syslog RFC5424 compatibility.
Oct 16 2020, 1:14 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav updated subscribers of T2982: show protocols bfd command parse failure.

@c-po @dmbaturin It can be safely cherry-picked to the "crux".
I tested this on 1.2.6-s1, it works.

Oct 16 2020, 1:11 PM · Ready for Crux (1.2.x), VyOS 1.2 Crux
Viacheslav added a comment to T2938: Adding remote Syslog RFC5424 compatibility.

PR https://github.com/vyos/vyos-1x/pull/573

Oct 16 2020, 12:56 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2965: Brief BFD Peer Info.

@trae32566 Will be added in the next rolling release.
Check, please.

Oct 16 2020, 12:09 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2958: DHCP server doesn't work from a live CD.

The possible reason, that it can't get the lease file, because that directory not present in the LiveCD

lease_file = "/config/dhcpd.leases"
Oct 16 2020, 8:19 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav claimed T2965: Brief BFD Peer Info.
Oct 16 2020, 7:46 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2965: Brief BFD Peer Info.

PR https://github.com/vyos/vyos-1x/pull/572

Oct 16 2020, 7:46 AM · VyOS 1.3 Equuleus (1.3.0)
trae32566 added a comment to T2965: Brief BFD Peer Info.

That sounds great to me! I actually like that more.

Oct 16 2020, 7:23 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2965: Brief BFD Peer Info.

Proposed cli
One of them

Oct 16 2020, 7:22 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav assigned T2981: MPLS LDP neighbor session clear capability to Cheeze_It.
Oct 16 2020, 7:11 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2982: show protocols bfd command parse failure.

It was fixed in the rolling T2573
https://phabricator.vyos.net/rVYOSONEXf812c5d1ce01efa8323bfb797c57f68f474665bb

Oct 16 2020, 6:16 AM · Ready for Crux (1.2.x), VyOS 1.2 Crux
qxmips published a new version of 1.2.6.
Oct 16 2020, 3:12 AM
qxmips edited the content of 1.2.6.
Oct 16 2020, 3:09 AM

Oct 15 2020

c-po renamed T2980: FRR bfdd crash due to invalid length from FRR bfdd crash due to invlid length to FRR bfdd crash due to invalid length.
Oct 15 2020, 8:16 PM · VyOS 1.3 Equuleus (1.3.0)
dirtycache created T2982: show protocols bfd command parse failure.
Oct 15 2020, 8:00 PM · Ready for Crux (1.2.x), VyOS 1.2 Crux
Viacheslav added a comment to T2979: BGP route leak at system boot.

@Robot82
It will be by default in the new BGP implementation.
https://github.com/vyos/vyos-1x/blob/current/data/templates/frr/bgp.frr.tmpl#L5

Oct 15 2020, 6:47 PM · VyOS 1.2 Crux
Viacheslav added a comment to T2981: MPLS LDP neighbor session clear capability.

Proposed CLI

reset mpls ldp neighbor x.x.x.x
Oct 15 2020, 6:44 PM · VyOS 1.3 Equuleus (1.3.0)
Cheeze_It changed Is it a breaking change? from none to compatible on T2981: MPLS LDP neighbor session clear capability.
Oct 15 2020, 6:21 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T915: MPLS Support.

PR https://github.com/vyos/vyos-1x/pull/571

Oct 15 2020, 6:06 PM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
Cheeze_It created T2981: MPLS LDP neighbor session clear capability.
Oct 15 2020, 6:05 PM · VyOS 1.3 Equuleus (1.3.0)
trae32566 added a comment to T2980: FRR bfdd crash due to invalid length.

awesome, thanks!

Oct 15 2020, 4:52 PM · VyOS 1.3 Equuleus (1.3.0)
trae32566 awarded T2980: FRR bfdd crash due to invalid length a Like token.
Oct 15 2020, 4:51 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) added a comment to T2971: Provide a CLI solution for Ingress Shaping when there is SNAT.

https://forum.vyos.io/t/limit-bandwith-for-indivindual-ips-on-1-2-5/5947/30?u=s.lorente

Oct 15 2020, 4:19 PM · VyOS 1.5 Circinus
c-po added a comment to T2980: FRR bfdd crash due to invalid length.

Also submitted PR for FRR 7.3 series https://github.com/FRRouting/frr/pull/7318

Oct 15 2020, 3:23 PM · VyOS 1.3 Equuleus (1.3.0)
Robot82 added a comment to T2979: BGP route leak at system boot.

OK, thank you. I will test this. This should probably be made as default.

Oct 15 2020, 3:09 PM · VyOS 1.2 Crux
jack9603301 added a comment to T766: Implement support for the Tinc VPN daemon.

@runar The preliminary integration of tinc is basically completed, please see

Oct 15 2020, 12:52 PM
Unknown Object (User) added a comment to T2978: IPoE service does not work on shared mode.

Yes, both clients configured as DHCP clients.
Client 1 - eth0 - 50:00:00:06:00:00
Client 2 - eth0 - 50:00:00:07:00:00

Oct 15 2020, 12:18 PM · VyOS 1.3 Equuleus (1.3.0)
danhusan added a comment to T2979: BGP route leak at system boot.

This has come up multiple times before, see https://phabricator.vyos.net/T1698 for the solution.

Oct 15 2020, 12:14 PM · VyOS 1.2 Crux
Viacheslav added a comment to T2713: VyOS must not change permissions on files in /config/auth.

I can confirm.
It happens after update procedure.

Oct 15 2020, 12:03 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T2834: Config rollback function is broken due lack access to the config.boot.

If I do a clean install of 1.2.6-s1 from iso, the rollback works fine.
If deploy from a qcow2 image, I see a similar error.

Oct 15 2020, 6:15 AM · Restricted Project

Oct 14 2020

soxrok2212 added a comment to T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing.

I should add that building the package on arm64 hardware (pi3/4) works fine. Building in the docker container fails.

Oct 14 2020, 11:41 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
c-po changed the status of T2980: FRR bfdd crash due to invalid length from Open to Needs testing.
Oct 14 2020, 7:41 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T2980: FRR bfdd crash due to invalid length.
Oct 14 2020, 7:40 PM · VyOS 1.3 Equuleus (1.3.0)
marekm added a comment to T2060: source-validation will be configured at different locations and could lead to massive confusion.

Just my thoughts - there are situations where rp_filter is not sufficient, and it was not clear to me how to do this cleanly with the zone firewall, so I ended up hacking a few iptables commands in rc.local instead.

Oct 14 2020, 6:59 PM · VyOS 1.3 Equuleus (1.3.6), VyOS-1.2.0-GA
Robot82 created T2979: BGP route leak at system boot.
Oct 14 2020, 6:30 PM · VyOS 1.2 Crux
runar added a comment to T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing.

the issue is verified by soxrok2122 by using a stock ubuntu 20 host with the stock vyos/vyos-build:current-arm64 docker image

Oct 14 2020, 5:39 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
runar reopened T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing, a subtask of T476: Update the base system to Debian 10 (Buster), as Open.
Oct 14 2020, 5:36 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
runar reopened T1663: T1656 equuleus: buster: arm64/aarch64: ipaddrcheck does not complete testing as "Open".

I'm reopening this issue as this seams to still be an issue. reported by user soxrok2212 on slack (#vyos-on-arm64)

Oct 14 2020, 5:36 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
Viacheslav added a comment to T2978: IPoE service does not work on shared mode.

It seems Client1 and Client2 only DHCP-clients.

Oct 14 2020, 3:10 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2978: IPoE service does not work on shared mode.

Could you share also Client1 and Client2 configuration? Would be nice adding this lab setup to the docs

Oct 14 2020, 2:31 PM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) changed the status of T2978: IPoE service does not work on shared mode from Open to Confirmed.
Oct 14 2020, 8:14 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) created T2978: IPoE service does not work on shared mode.
Oct 14 2020, 8:14 AM · VyOS 1.3 Equuleus (1.3.0)
Unknown Object (User) closed T2972: PPPoE server rate limiter allows max 65535 kbps to be set as Resolved.
Oct 14 2020, 7:59 AM · VyOS 1.2 Crux (VyOS 1.2.7)
Magnum added a comment to T2969: OpenVPN: command_set on interface is not applied, if interface doesn't come up in commit.
interfaces {
    ethernet eth2 {
        address 10.201.1.2/30
        description WAN
        hw-id 0c:6b:af:b0:4f:02
    }
    openvpn vtun11 {
        description "CPE MGMT"
        device-type tun
        encryption {
            cipher aes256
        }
        hash sha1
        mode client
        persistent-tunnel
        protocol udp
        remote-host 10.200.200.11
        remote-port 1194
        tls {
            auth-file /config/auth/shared.key
            ca-cert-file /config/auth/ca.crt
            cert-file /config/auth/cpe1-1.crt
            key-file /config/auth/cpe1-1.key
        }
        vrf CPE-MGMT
    }
}
protocols {
    static {
        route 0.0.0.0/0 {
            next-hop 10.201.1.1 {
            }
        }
    }
}
vrf {
    name CPE-MGMT {
        description "CPE MGMT"
        table 112
    }
}
Oct 14 2020, 7:01 AM · VyOS 1.3 Equuleus (1.3.0)