Page MenuHomeVyOS Platform
Feed All Stories

Nov 22 2020

c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02, a subtask of T3060: OpenVPN virtual interface not coming up after upgrade, from In progress to Needs testing.
Nov 22 2020, 9:41 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02, a subtask of T3081: get_config_dict() does not honor whitespaces in the CLI values field, from In progress to Needs testing.
Nov 22 2020, 9:41 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02 from In progress to Needs testing.
Nov 22 2020, 9:41 AM · VyOS 1.3 Equuleus (1.3.0)
c-po assigned T3081: get_config_dict() does not honor whitespaces in the CLI values field to jestabro.
Nov 22 2020, 9:26 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:25 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a parent task for T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02: T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:23 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a subtask for T3081: get_config_dict() does not honor whitespaces in the CLI values field: T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02.
Nov 22 2020, 9:23 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated subscribers of T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:22 AM · VyOS 1.3 Equuleus (1.3.0)
c-po updated the task description for T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:22 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3081: get_config_dict() does not honor whitespaces in the CLI values field from Open to Confirmed.
Nov 22 2020, 9:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3081: get_config_dict() does not honor whitespaces in the CLI values field.
Nov 22 2020, 9:20 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02, a subtask of T3060: OpenVPN virtual interface not coming up after upgrade, from Open to In progress.
Nov 22 2020, 8:49 AM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02 from Open to In progress.
Nov 22 2020, 8:49 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 21 2020

syncer moved T3035: Allow IPv4 over IPv6 IPsec and vice versa from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Nov 21 2020, 8:54 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer moved T3035: Allow IPv4 over IPv6 IPsec and vice versa from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.7) board.
Nov 21 2020, 8:54 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer changed the status of T3035: Allow IPv4 over IPv6 IPsec and vice versa from Open to Needs testing.
Nov 21 2020, 8:53 PM · VyOS 1.2 Crux (VyOS 1.2.7)
syncer changed the subtype of T3035: Allow IPv4 over IPv6 IPsec and vice versa from "Task" to "Enhancement".
Nov 21 2020, 8:53 PM · VyOS 1.2 Crux (VyOS 1.2.7)
kroy added a parent task for T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02: T3060: OpenVPN virtual interface not coming up after upgrade.
Nov 21 2020, 5:54 PM · VyOS 1.3 Equuleus (1.3.0)
kroy added a subtask for T3060: OpenVPN virtual interface not coming up after upgrade: T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02.
Nov 21 2020, 5:54 PM · VyOS 1.3 Equuleus (1.3.0)
kroy created T3080: OpenVPN failing silently for a number of reasons in rolling post Nov/02.
Nov 21 2020, 5:52 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3060: OpenVPN virtual interface not coming up after upgrade as Resolved.
Nov 21 2020, 4:35 PM · VyOS 1.3 Equuleus (1.3.0)
danielpo added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

Thanks, works now.

Nov 21 2020, 12:58 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

@danielpo thanks foe the config. A new rolling containig a fix for this issue was just published. A smoketest will be added today to ensure this wont happen again.

Nov 21 2020, 12:24 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 moved T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge from In Progress to Finished on the VyOS 1.3 Equuleus board.
Nov 21 2020, 9:28 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 closed T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge as Resolved.
Nov 21 2020, 9:25 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge.

PR: https://github.com/vyos/vyos-1x/pull/615

Nov 21 2020, 7:08 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 changed Is it a breaking change? from none to compatible on T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge.
Nov 21 2020, 7:08 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 moved T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Nov 21 2020, 5:14 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 changed the status of T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge from Open to In progress.
Nov 21 2020, 5:05 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 created T3079: Fix the problem that VLAN 1 will be deleted in VLAN-aware bridge.
Nov 21 2020, 5:05 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 20 2020

danielpo added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.
authentication {
    password xxxx
    username xxxxx
}
device-type tun
encryption {
    cipher aes256
}
firewall {
    in {
        ipv6-name DENYv6_IN
        name DENY_IN
    }
    local {
        ipv6-name DENYv6_IN
        name DENY_IN
    }
}
hash sha256
mode client
openvpn-option "key-direction 1"
openvpn-option route-nopull
persistent-tunnel
protocol tcp-active
remote-host 1.2.3.4
remote-host 1.2.3.5
remote-port 1195
tls {
    ca-cert-file /config/auth/cert.ca
    auth-file  /config/auth/tls-auth
    tls-version-min 1.2
}
Nov 20 2020, 11:47 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3078: CLI cleanup: rename "system options" -> "system option" as Resolved.
Nov 20 2020, 11:39 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3048: Drop static smp-affinity for a more dynamic way using tuned as Resolved.
Nov 20 2020, 11:34 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3078: CLI cleanup: rename "system options" -> "system option" from Open to In progress.
Nov 20 2020, 10:59 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3078: CLI cleanup: rename "system options" -> "system option".
Nov 20 2020, 10:59 PM · VyOS 1.3 Equuleus (1.3.0)
c-po reopened T3060: OpenVPN virtual interface not coming up after upgrade as "Open".
Nov 20 2020, 10:58 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

Please show us your config

Nov 20 2020, 10:58 PM · VyOS 1.3 Equuleus (1.3.0)
danielpo added a comment to T3060: OpenVPN virtual interface not coming up after upgrade.

Now this error appear when trying the latest image:

Nov 20 2020, 5:20 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T160: Support NAT64.

@dmbaturin @artooro Come on, remember not to forget NAT46

Nov 20 2020, 4:32 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
jack9603301 added a comment to T2898: Support NDP proxy.

@c-po I am thinking, although it is not possible to incorporate NAT66, whether we can prioritize how to improve and incorporate NDP Proxy

Nov 20 2020, 4:28 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T439: local PBR support from Open to Needs testing.
Nov 20 2020, 4:19 PM · VyOS 1.4 Sagitta
c-po closed T3077: WireGuard: automatically create link-local IPv6 adresses, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, as Resolved.
Nov 20 2020, 1:42 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3077: WireGuard: automatically create link-local IPv6 adresses as Resolved.
Nov 20 2020, 1:42 PM · VyOS 1.3 Equuleus (1.3.0)
c-po triaged T3077: WireGuard: automatically create link-local IPv6 adresses as Normal priority.
Nov 20 2020, 1:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3077: WireGuard: automatically create link-local IPv6 adresses, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, from Open to In progress.
Nov 20 2020, 1:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po changed the status of T3077: WireGuard: automatically create link-local IPv6 adresses from Open to In progress.
Nov 20 2020, 1:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3077: WireGuard: automatically create link-local IPv6 adresses.
Nov 20 2020, 1:27 PM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T2997: DHCP: disallow/do-not-request certain options when requesting IP address from server as Resolved.
Nov 20 2020, 1:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T2997: DHCP: disallow/do-not-request certain options when requesting IP address from server.

DNS domain name servers are always requested from the server but must be explicitly "allowed" by set systems name-servers-dhcp

Nov 20 2020, 1:16 PM · VyOS 1.3 Equuleus (1.3.0)
Cremator added a comment to T578: Support Linux Container.

Running Docker on 1.3 rolling works, but there is no integration with the docker bridge interfaces and docker iptables rules obviously.
My goal was to run Traefik and Pihole and it works so far.
https://gist.github.com/Cremator/183c1a4d24e7812f94ec4bd41f7718b3

Nov 20 2020, 12:58 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T2550: OpenVPN: IPv4 not working in client mode as Resolved.
Nov 20 2020, 11:58 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T1405: dhclient runs before mac overrides are applied as Resolved.
Nov 20 2020, 11:58 AM
c-po closed T3060: OpenVPN virtual interface not coming up after upgrade as Resolved.
Nov 20 2020, 11:58 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3065: Add "interfaces wirelessmodem" IPv6 support, a subtask of T3063: Add support for Huawei LTE Module ME909s-120, as Resolved.
Nov 20 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3065: Add "interfaces wirelessmodem" IPv6 support as Resolved.
Nov 20 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3072: Migrate tunnel interfaces to new get_config_dict() approach, a subtask of T2653: "set interfaces" Python handler code improvements - next iteration, as Resolved.
Nov 20 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3072: Migrate tunnel interfaces to new get_config_dict() approach as Resolved.
Nov 20 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3068: Automatic generation of IPv6 link local addresses for tunnel interfaces, a subtask of T3072: Migrate tunnel interfaces to new get_config_dict() approach, as Resolved.
Nov 20 2020, 11:57 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T3068: Automatic generation of IPv6 link local addresses for tunnel interfaces as Resolved.
Nov 20 2020, 11:57 AM
jack9603301 moved T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support from Need Triage to Finished on the VyOS 1.3 Equuleus board.
Nov 20 2020, 11:44 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a subtask for T3072: Migrate tunnel interfaces to new get_config_dict() approach: T3068: Automatic generation of IPv6 link local addresses for tunnel interfaces.
Nov 20 2020, 11:28 AM · VyOS 1.3 Equuleus (1.3.0)
c-po added a parent task for T3068: Automatic generation of IPv6 link local addresses for tunnel interfaces: T3072: Migrate tunnel interfaces to new get_config_dict() approach.
Nov 20 2020, 11:28 AM
varac added a comment to T1286: DHCP hostfile-update isn't removing hostfile entries on expiry..

https://marc.info/?l=dhcp-hackers&m=128755776831463 describes the solution.
Setting ClientName, ClientIp, ClientMac, ClientDomain on release and expire fails, and there's no need for that since they are already known.
Simply removing all "set" commands in the release and expire section fixes this bug and restores the desired behaviour that i.e. the leases are removed from /etc/hosts.

Nov 20 2020, 8:30 AM · VyOS 1.3 Equuleus (1.3.0)
tjh added a comment to T2977: Permissions Denied doing "show conntrack-sync status" on backup router.

I just saw the patch above for how to fix this and yes, with that line changed to sudo it now works correctly.
Thanks!

Nov 20 2020, 12:23 AM
tjh created T3076: Router reboot adds unwanted 'conntrack-sync mcast-group '225.0.0.50'' line to configuration.
Nov 20 2020, 12:20 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Nov 19 2020

c-po closed T3075: Update Linux Kernel to v4.19.158 as Resolved.
Nov 19 2020, 9:37 PM · VyOS 1.3 Equuleus (1.3.0)
c-po created T3075: Update Linux Kernel to v4.19.158.
Nov 19 2020, 9:35 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T1405: dhclient runs before mac overrides are applied.

I have adjust the logic which now sets the interface MAC address before any other parameter. Using the OSI model this makes sense as the MAC layer is below IP.

Nov 19 2020, 9:10 PM
c-po changed the status of T1405: dhclient runs before mac overrides are applied from In progress to Needs testing.
Nov 19 2020, 9:09 PM
c-po changed the status of T1405: dhclient runs before mac overrides are applied from Open to In progress.
Nov 19 2020, 9:06 PM
jack9603301 closed T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support as Resolved.
Nov 19 2020, 8:19 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T439: local PBR support.

PR https://github.com/vyos/vyos-1x/pull/614
Add the ability to use policy local-route

Nov 19 2020, 6:11 PM · VyOS 1.4 Sagitta
carazzim0 added a comment to T1405: dhclient runs before mac overrides are applied.

Hi there,

Nov 19 2020, 8:28 AM

Nov 18 2020

jack9603301 added a comment to T3073: sh nat source translations Python error.

Let the responsible person of T2859 take care of it. I have not been able to see the problem from the information you provided for the time being. If you are familiar with python and linux, you can consider troubleshooting by yourself to try to find the problem. If not, just ask Maintenance personnel reproduce the fault

Nov 18 2020, 9:58 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support.

@c-po I have changed the PR to prohibit WLAN ports from joining VLAN-aware bridge ports

Nov 18 2020, 9:08 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 17 2020

c-po added a comment to T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support.

I can now again bridge the WIFI interface to br0, please resolve the outstanding commit message changes and then it feels good to me! Thanks

Nov 17 2020, 7:16 PM · VyOS 1.3 Equuleus (1.3.0)
c-po added a comment to T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support.
# Bridge port handling of wireless interfaces is done by hostapd.
        if 'wlan' in interface:
            return

Why can't wlan be completed in bridge.py?

Nov 17 2020, 7:12 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T439: local PBR support.

Propose to use that format

Nov 17 2020, 3:19 PM · VyOS 1.4 Sagitta
jack9603301 added a comment to T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support.

Contains 2 patch submissions

Nov 17 2020, 3:09 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support.
# Bridge port handling of wireless interfaces is done by hostapd.
        if 'wlan' in interface:
            return
Nov 17 2020, 2:57 PM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support.

This patch changes the settings and does not modify the vlan filter settings when VLAN awareness is not set, but the root cause of different problems is that the following code does not set the wireless port to the bridge normally:

Nov 17 2020, 8:57 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support.

Strange, the problem seems to be that the interface has not been added to the bridge. I may submit a patch about VLAN awareness to refuse to operate the vlan filter setting without enabling VLAN awareness, but I am not sure whether it has any Relationship, manual operation is normal:

Nov 17 2020, 8:47 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support.
Nov 17 2020, 8:22 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3067: Wireless interface can no longer be added to the bridge after bridge VLAN support.

Whether the VLAN aware bridge is activated?

Nov 17 2020, 8:08 AM · VyOS 1.3 Equuleus (1.3.0)

Nov 16 2020

tuxnet added a comment to T3073: sh nat source translations Python error.

@jack9603301 Below the desired information:

Nov 16 2020, 6:10 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T160: Support NAT64.

Jool can handle 2 times as many packets.
https://link.springer.com/article/10.1007/s11235-020-00681-x

Nov 16 2020, 6:03 PM · VyOS 1.4 Sagitta, VyOS 1.5 Circinus
Viacheslav added a comment to T3074: OpenVPN site-to-site creates wrong peer address.
vyos@r4-roll# sudo cat /run/openvpn/vtun30365.conf 
### Autogenerated by interfaces-openvpn.py ###
#
# See https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage
# for individual keyword definition
#
# 
#
Nov 16 2020, 5:06 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav created T3074: OpenVPN site-to-site creates wrong peer address.
Nov 16 2020, 4:54 PM · VyOS 1.3 Equuleus (1.3.0)
jestabro closed T2899: remote syslog server migration error on update as Resolved.
Nov 16 2020, 2:31 PM · Restricted Project
jestabro closed T3003: Extend smoketest framework to allow loading an arbitrary config file as Resolved.
Nov 16 2020, 2:29 PM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T3073: sh nat source translations Python error.

Duplicate T2859

Nov 16 2020, 10:17 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3073: sh nat source translations Python error.

Please execute and analyze the following command to return the result, and carry out fault exploration, if possible, please output the result

Nov 16 2020, 10:07 AM · VyOS 1.3 Equuleus (1.3.0)
tuxnet added a comment to T3073: sh nat source translations Python error.

Sorry, I have forgotten to copy them.
the error does not occur with every query (nor as a supplement)

Nov 16 2020, 9:48 AM · VyOS 1.3 Equuleus (1.3.0)
Viacheslav added a comment to T1316: Support for IS-IS .

PR https://github.com/vyos/vyos-1x/pull/612
Add IS-IS routing.

Nov 16 2020, 9:25 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3073: sh nat source translations Python error.

Is there no NAT policy?

Nov 16 2020, 9:09 AM · VyOS 1.3 Equuleus (1.3.0)
tuxnet created T3073: sh nat source translations Python error.
Nov 16 2020, 8:24 AM · VyOS 1.3 Equuleus (1.3.0)
jack9603301 added a comment to T3030: Support ERSPAN Tunnel Protocol.

I'm curious about how to do ERSPAN?

Nov 16 2020, 2:43 AM · VyOS 1.4 Sagitta

Nov 15 2020

c-po added a comment to T3030: Support ERSPAN Tunnel Protocol.

Why not use ERSPAN?

Nov 15 2020, 9:13 PM · VyOS 1.4 Sagitta
jack9603301 updated the task description for T3071: Display VLAN mode information on the network interface.
Nov 15 2020, 4:44 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
jack9603301 renamed T3071: Display VLAN mode information on the network interface from Change network interface display to Display VLAN mode information on the network interface.
Nov 15 2020, 4:43 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta