Page MenuHomeVyOS Platform
Feed All Stories

Jun 8 2022

Viacheslav changed the status of T3083: Add feature event-handler from Open to Needs testing.
Jun 8 2022, 10:54 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T4350: DMVPN opennhrp spokes dont work behind NAT as Resolved.
Jun 8 2022, 6:50 AM · VyOS 1.3 Equuleus (1.3.2)
c-po closed T4447: DHCPv6 prefix delegation `sla-id` limited to 128 as Resolved.
Jun 8 2022, 6:50 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po moved T4350: DMVPN opennhrp spokes dont work behind NAT from In Progress to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Jun 8 2022, 6:50 AM · VyOS 1.3 Equuleus (1.3.2)
c-po moved T4447: DHCPv6 prefix delegation `sla-id` limited to 128 from In Progress to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
Jun 8 2022, 6:50 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po moved T4350: DMVPN opennhrp spokes dont work behind NAT from Need Triage to In Progress on the VyOS 1.3 Equuleus (1.3.2) board.
Jun 8 2022, 5:55 AM · VyOS 1.3 Equuleus (1.3.2)

Jun 7 2022

e.khudiyev created T4460: nhrp not starting due to missing cisco-authentication value.
Jun 7 2022, 12:32 PM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project

Jun 6 2022

Viacheslav added a comment to T4457: L2TP/IPSec Remote Access VPN does not work as expected in 1.3.1-S1.

Don't have any issues with Ubuntu

set interfaces dummy dum0 address '192.0.2.1/32'
set interfaces dummy dum4 address '203.0.113.1/24'
set interfaces ethernet eth0 address '192.168.122.11/24'
set interfaces ethernet eth0 description 'WAN'
set vpn ipsec ipsec-interfaces interface 'eth0'
set vpn l2tp remote-access authentication local-users username test password 'test'
set vpn l2tp remote-access authentication mode 'local'
set vpn l2tp remote-access client-ip-pool start '192.168.255.2'
set vpn l2tp remote-access client-ip-pool stop '192.168.255.254'
set vpn l2tp remote-access ipsec-settings authentication mode 'pre-shared-secret'
set vpn l2tp remote-access ipsec-settings authentication pre-shared-secret 'secret'
set vpn l2tp remote-access outside-address '192.0.2.1'
Jun 6 2022, 10:03 AM · VyOS 1.3 Equuleus ( 1.3.1)

Jun 5 2022

n.fort added a comment to T4387: Create additional smoketests for multiwan PBR & load-balanced configurations .

Added more options. PR https://github.com/vyos/vyos-1x/pull/1350

Jun 5 2022, 8:12 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4457: L2TP/IPSec Remote Access VPN does not work as expected in 1.3.1-S1.

@NikolayP , Looks like MTU and MPPE issue. Stoping daemon does not related to this I think.

Jun 5 2022, 6:56 PM · VyOS 1.3 Equuleus ( 1.3.1)
c-po added a comment to T2472: Ability to configure EIGRP protocol.

I already merged your XML definition ;)

Jun 5 2022, 2:02 PM · VyOS 1.5 Circinus
Viacheslav renamed T1237: Static Route Path Monitoring, failover from Static Route Path Monitoring to Static Route Path Monitoring, failover.
Jun 5 2022, 12:04 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T1237: Static Route Path Monitoring, failover: VyOS 1.4 Sagitta.
Jun 5 2022, 12:04 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T2472: Ability to configure EIGRP protocol.

I once made XML, it might come in handy

Jun 5 2022, 10:36 AM · VyOS 1.5 Circinus
kajiuray created T4459: API service with VRF doesn't work in 1.3.1.
Jun 5 2022, 9:39 AM · VyOS 1.3 Equuleus (1.3.4)

Jun 4 2022

n.fort added a comment to T3976: Missing prefix-list and access-list option from ipv6 route-map.

PR: https://github.com/vyos/vyos-1x/pull/1348

Jun 4 2022, 4:19 PM
n.fort claimed T4458: Firewall - add support for matching ip ttl in firewall rules.
Jun 4 2022, 3:03 PM · VyOS 1.4 Sagitta
n.fort changed Version from - to 1.4 on T4458: Firewall - add support for matching ip ttl in firewall rules.
Jun 4 2022, 3:03 PM · VyOS 1.4 Sagitta
n.fort created T4458: Firewall - add support for matching ip ttl in firewall rules.
Jun 4 2022, 3:02 PM · VyOS 1.4 Sagitta
showipintbri renamed T4445: [EDIT] Service Restored: Outage: Interface stops forwarding, IPv4 martian seen in the logs from Outage: Interface stops forwarding, IPv4 martian seen in the logs to [EDIT] Service Restored: Outage: Interface stops forwarding, IPv4 martian seen in the logs.
Jun 4 2022, 3:39 AM
showipintbri added a comment to T4445: [EDIT] Service Restored: Outage: Interface stops forwarding, IPv4 martian seen in the logs.

Ultimately I moved my physical connection from port eth0 to eth4, and configured eth4 with the same config as was on eth0. Once I did that everything was stable and has been stable for days (nearly a week now). I'm not sure what could be causing an interface to work for an amount of time, then as if on-cue stop forwarding packets.

Jun 4 2022, 3:38 AM

Jun 3 2022

Viacheslav added a project to T4445: [EDIT] Service Restored: Outage: Interface stops forwarding, IPv4 martian seen in the logs: VyOS 1.4 Sagitta.
Jun 3 2022, 8:59 PM
n.fort changed the status of T4450: Route-map - Extend options for ip|ipv6 address match from Open to Needs testing.
Jun 3 2022, 3:49 PM · VyOS 1.4 Sagitta
Unknown Object (User) added a comment to T4457: L2TP/IPSec Remote Access VPN does not work as expected in 1.3.1-S1.

Not sure if this is relevant to the task.
But once when shutting down a VM with VyOS 1.3.1-S1, it took a long time to shut down:

image.png (117×1 px, 10 KB)

Jun 3 2022, 2:42 PM · VyOS 1.3 Equuleus ( 1.3.1)
Unknown Object (User) triaged T4457: L2TP/IPSec Remote Access VPN does not work as expected in 1.3.1-S1 as High priority.
Jun 3 2022, 2:31 PM · VyOS 1.3 Equuleus ( 1.3.1)
jack9603301 added a comment to T3420: Support UPNP protocol.

Should I make improvements to the remaining revisions in the PR?

Jun 3 2022, 1:06 PM · VyOS 1.5 Circinus
jack9603301 updated subscribers of T3420: Support UPNP protocol.

Sorry I just saw it now, I'll test it. But because of limited conditions, I may test in the future, please forgive me

Jun 3 2022, 12:21 PM · VyOS 1.5 Circinus
jack9603301 added a comment to T3435: NAT rules show corruption.

Error still present on VyOS 1.4-rolling-202201020317

vyos@vyos:~$ show nat source rules 
Traceback (most recent call last):
  File "/usr/libexec/vyos/op_mode/show_nat_rules.py", line 114, in <module>
    print(format_nat_rule.format(rule, srcdests[0], tran_addr, interface))
IndexError: list index out of range
Rule       Source                                             Translation                                        Outbound Interface
----       ------                                             -----------                                        ------------------
vyos@vyos:~$ show ver

Version:          VyOS 1.4-rolling-202201020317
Release train:    sagitta

Nat config in this example:

vyos@vyos:~$ show config comm | grep nat
set nat source rule 10 description 'Masquerade to NAT'
set nat source rule 10 outbound-interface 'eth0'
set nat source rule 10 translation address 'masquerade'
Jun 3 2022, 12:19 PM · VyOS 1.4 Sagitta

Jun 2 2022

zsdc added a comment to T4288: IPsec tunnel will break when ESP timeout.

@m.korobeinikov I believe that I already posted this some time ago, but just in case...
Not all combinations of DPD and close-action are safe. Actually, most of them sooner or later will lead to issues with IPSec. So, I created the next scheme. It is from 2020, so I will not say that nothing was changed from that time, however, it shows well how careful you should be while configuring IPSec. On the scheme, you can see the only safe configuration of the close-action option, depending on how the peer is configured, but the same logic can be applied to DPD.

IPSec site-to-site IKE configuration.png (780×1 px, 27 KB)

Jun 2 2022, 6:42 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4222: Support for TWAMP as round-trip metric.

PR https://github.com/vyos/vyos-build/pull/240
disable owamp|twamp.service by default

Jun 2 2022, 5:01 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
marekm created T4456: NTP client in VRF tries to bind to interfaces outside VRF, logs many messages.
Jun 2 2022, 3:30 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav created T4455: smp-affinity required by some platforms but doesn't exists in the CLI.
Jun 2 2022, 3:21 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
erkin triaged T4454: `install-image` should check free storage as Low priority.
Jun 2 2022, 2:14 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4222: Support for TWAMP as round-trip metric from Open to Needs testing.

@SrividyaA will be present in the next rolling release

Jun 2 2022, 10:39 AM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
Viacheslav added a comment to T4387: Create additional smoketests for multiwan PBR & load-balanced configurations .

PR for the current https://github.com/vyos/vyos-1x/pull/1346

Jun 2 2022, 10:09 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T973: Create Prometheus Exporter for VyOS .
In T973#124168, @superq wrote:

I wouldn't call telegraf a very good option. It does a very bad job of producing Prometheus metrics.

Jun 2 2022, 10:04 AM · VyOS 1.5 Circinus
Viacheslav added a comment to T141: TACACS+ Support.

For Debian11 requires pkg "libpam-tacplus" that is not available https://github.com/kravietz/pam_tacplus/issues/180

Jun 2 2022, 9:58 AM · VyOS 1.4 Sagitta
superq added a comment to T973: Create Prometheus Exporter for VyOS .

I wouldn't call telegraf a very good option. It does a very bad job of producing Prometheus metrics.

Jun 2 2022, 9:07 AM · VyOS 1.5 Circinus
Viacheslav added a comment to T973: Create Prometheus Exporter for VyOS .

Prometheus-client already in 1.4
https://docs.vyos.io/en/latest/configuration/service/monitoring.html#prometheus-client

Jun 2 2022, 8:59 AM · VyOS 1.5 Circinus

Jun 1 2022

Viacheslav added a comment to T4222: Support for TWAMP as round-trip metric.

PR https://github.com/vyos/vyos-1x/pull/1345

Jun 1 2022, 4:57 PM · VyOS 1.3 Equuleus (1.3.6), VyOS 1.4 Sagitta
marekm updated the task description for T4453: dhclient fails to renew DHCP lease with VRF.
Jun 1 2022, 3:39 PM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta
marekm created T4453: dhclient fails to renew DHCP lease with VRF.
Jun 1 2022, 8:38 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta

May 31 2022

egoistdream added a comment to T3976: Missing prefix-list and access-list option from ipv6 route-map.

Yes on this version it is available the requested options for ipv6:

May 31 2022, 11:27 PM
fernando added a comment to T3976: Missing prefix-list and access-list option from ipv6 route-map.

yes, it was added on this version vyos-1.4-rolling-202205311706, please check again

May 31 2022, 11:13 PM
sarthurdev closed T3659: Configuration won't accept IPv6 addresses for site-to-site VPN tunnel prefixes/traffic selectors as Resolved.
May 31 2022, 6:13 PM · VyOS 1.4 Sagitta
sarthurdev closed T4148: Firewall - Error messages not that clear as it were in old firewall as Resolved.
May 31 2022, 6:11 PM · VyOS 1.4 Sagitta
sarthurdev closed T4199: Commit failed when setting icmpv6 type any as Resolved.
May 31 2022, 6:09 PM · VyOS 1.4 Sagitta
sarthurdev closed T4212: PermissionError when generating/installing server Certificate (generate pki certificate sign ...) as Resolved.
May 31 2022, 6:05 PM · VyOS 1.4 Sagitta
egoistdream added a comment to T3976: Missing prefix-list and access-list option from ipv6 route-map.

I just check and on version: vyos-1.4-rolling-202205310217 is still missing :(

May 31 2022, 2:17 PM
fernando added a comment to T3976: Missing prefix-list and access-list option from ipv6 route-map.

We've added this feature in our latest nightly building release, could you check it ?

May 31 2022, 1:50 PM
fernando changed the status of T3976: Missing prefix-list and access-list option from ipv6 route-map from Open to Needs testing.
May 31 2022, 1:40 PM
zsdc created T4452: WAN load-balancing exclude rules break PBR.
May 31 2022, 11:01 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.4 Sagitta
gabrieltackitt added a comment to T2044: RPKI doesn't boot properly.

Has any progress on this been made? I am still having this issue on 1.4-rolling-202205250217.

May 31 2022, 1:45 AM · VyOS 1.3 Equuleus (1.3.7), VyOS 1.5 Circinus, VyOS 1.4 Sagitta

May 30 2022

sarthurdev added a comment to T3642: PKI configuration.

PR for op-mode importing existing PKI files into config: https://github.com/vyos/vyos-1x/pull/1343

May 30 2022, 10:59 PM · VyOS 1.4 Sagitta
RyVolodya created T4451: The DHCPv6 server leases function the display of the hostname.
May 30 2022, 8:13 PM · VyOS 1.5 Circinus
Viacheslav closed T4315: Telegraf - Output to prometheus as Resolved.
May 30 2022, 1:30 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

May 29 2022

n.fort added a comment to T4450: Route-map - Extend options for ip|ipv6 address match.

PR: https://github.com/vyos/vyos-1x/pull/1342

May 29 2022, 4:51 PM · VyOS 1.4 Sagitta
n.fort claimed T4450: Route-map - Extend options for ip|ipv6 address match.
May 29 2022, 3:05 PM · VyOS 1.4 Sagitta
n.fort created T4450: Route-map - Extend options for ip|ipv6 address match.
May 29 2022, 3:05 PM · VyOS 1.4 Sagitta
panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

This vm started out with 4G of memory and 2CPUs; I doubled quickly everything when I hit the out of memory error the first time, but that didn't help. I can quickly install the latest rolling and test

May 29 2022, 12:18 PM · VyOS 1.3 Equuleus (1.3.6)
n.fort changed the status of T4449: Route-map - Extend options for ip next-hop match from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1339

May 29 2022, 11:04 AM · VyOS 1.4 Sagitta
n.fort added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

Yes, you error with "root" user is a known issue: T4281.

May 29 2022, 10:52 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a comment to T2597: Add more options to API.

Reset added in T4442

May 29 2022, 10:00 AM
c-po added a comment to T2472: Ability to configure EIGRP protocol.

Currently dealing with some minor FRR issues:

May 29 2022, 9:45 AM · VyOS 1.5 Circinus
c-po updated the task description for T2472: Ability to configure EIGRP protocol.
May 29 2022, 9:45 AM · VyOS 1.5 Circinus
c-po changed the status of T2773: EIGRP support for VRF from Open to In progress.
May 29 2022, 9:45 AM · VyOS 1.4 Sagitta
c-po edited projects for T2472: Ability to configure EIGRP protocol, added: VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.0).
May 29 2022, 9:44 AM · VyOS 1.5 Circinus
c-po changed the status of T2472: Ability to configure EIGRP protocol from Open to In progress.
May 29 2022, 8:13 AM · VyOS 1.5 Circinus
panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

I've debugged this further, by breaking up my configuration into various sections (system, interfaces, firewall,nat,service,vpn etc) and running them on a new VM.

May 29 2022, 8:09 AM · VyOS 1.3 Equuleus (1.3.6)
c-po claimed T2773: EIGRP support for VRF.
May 29 2022, 8:01 AM · VyOS 1.4 Sagitta
c-po closed T2473: Xml for EIGRP [conf_mode], a subtask of T2472: Ability to configure EIGRP protocol, as Resolved.
May 29 2022, 8:01 AM · VyOS 1.5 Circinus
c-po closed T2473: Xml for EIGRP [conf_mode] as Resolved.
May 29 2022, 8:01 AM · VyOS 1.4 Sagitta
panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

Still not much luck here. But I've let the boot run a bit longer, and notice the following:

May 29 2022, 5:48 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav moved T2580: Support for ip pools for ippoe from Backport Candidates to Finished on the VyOS 1.4 Sagitta board.
May 29 2022, 12:19 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav edited projects for T2580: Support for ip pools for ippoe, added: VyOS 1.3 Equuleus (1.3.2); removed VyOS 1.3 Equuleus (1.3.0).
May 29 2022, 12:18 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

May 28 2022

Viacheslav added a comment to T4352: wan-load balance - priority traffic rule doesn't work .

@fernando Could you try to set sysctl mark?

sysctl -w net.ipv4.conf.eth0.src_valid_mark=1
sysctl -w net.ipv4.conf.eth1.src_valid_mark=1
May 28 2022, 7:40 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T3083: Add feature event-handler.

PR https://github.com/vyos/vyos-1x/pull/1340

set service event-handler event first filter pattern '.*ssh2.*'
set service event-handler event first script arguments '192.0.2.5'
set service event-handler event first script environment interface value 'eth0'
set service event-handler event first script path '/config/scripts/hello.sh'
May 28 2022, 6:49 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a comment to T2218: Add support for the peeringdb module in salt (upgrade salt-minion to 2019.2).

The current salt-minion version 3003.4+ds-1
@maznu Do we need anything else for it?

May 28 2022, 1:51 PM · VyOS 1.5 Circinus, VyOS 1.4 Sagitta
n.fort claimed T4449: Route-map - Extend options for ip next-hop match.
May 28 2022, 11:15 AM · VyOS 1.4 Sagitta
n.fort created T4449: Route-map - Extend options for ip next-hop match.
May 28 2022, 11:15 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4387: Create additional smoketests for multiwan PBR & load-balanced configurations .

PR https://github.com/vyos/vyos-1x/pull/1338

May 28 2022, 11:05 AM · VyOS 1.4 Sagitta
c-po closed T4448: rip: add support for explicit version selection as Resolved.
May 28 2022, 6:18 AM · VyOS 1.4 Sagitta
c-po changed the status of T4448: rip: add support for explicit version selection from Open to In progress.
May 28 2022, 6:07 AM · VyOS 1.4 Sagitta
c-po created T4448: rip: add support for explicit version selection.
May 28 2022, 6:07 AM · VyOS 1.4 Sagitta
panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

Okay, thats the only rule where I was using a port-group combined with protocol all; the others that use protocol all dont have a port or port group in the rule, so they are okay?

May 28 2022, 5:50 AM · VyOS 1.3 Equuleus (1.3.6)
Viacheslav added a project to T4387: Create additional smoketests for multiwan PBR & load-balanced configurations : VyOS 1.3 Equuleus (1.3.0).
May 28 2022, 5:14 AM · VyOS 1.4 Sagitta

May 27 2022

fernando added a comment to T3976: Missing prefix-list and access-list option from ipv6 route-map.

PR for 1.4 Sagitta branch https://github.com/vyos/vyos-1x/pull/1337

May 27 2022, 9:27 PM
c-po added a comment to T4350: DMVPN opennhrp spokes dont work behind NAT.

Works on my setup

May 27 2022, 8:04 PM · VyOS 1.3 Equuleus (1.3.2)
sarthurdev added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

1.4 rolling does not help me, so there must be something "wrong" with my configuration. I've attached the private config, it would be awesome if someone might find what's broken.

May 27 2022, 6:20 PM · VyOS 1.3 Equuleus (1.3.6)
fernando claimed T3976: Missing prefix-list and access-list option from ipv6 route-map.
May 27 2022, 5:59 PM
n.fort added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

For a better analysis, can you share your firewall and nat config without hidden data? You can send it to my email: [email protected]

May 27 2022, 4:36 PM · VyOS 1.3 Equuleus (1.3.6)
c-po closed T4441: wwan: connection not possible after a change added after 1.3.1-S1 release as Resolved.
May 27 2022, 6:44 AM · VyOS 1.3 Equuleus (1.3.2)
c-po moved T4447: DHCPv6 prefix delegation `sla-id` limited to 128 from Need Triage to In Progress on the VyOS 1.3 Equuleus (1.3.2) board.
May 27 2022, 6:43 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po moved T4447: DHCPv6 prefix delegation `sla-id` limited to 128 from Need Triage to Finished on the VyOS 1.4 Sagitta board.
May 27 2022, 6:43 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po added a comment to T4447: DHCPv6 prefix delegation `sla-id` limited to 128 .

PR for 1.3 equuleus branch https://github.com/vyos/vyos-1x/pull/1336

May 27 2022, 6:38 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po changed the status of T4447: DHCPv6 prefix delegation `sla-id` limited to 128 from Open to In progress.
May 27 2022, 6:34 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
c-po created T4447: DHCPv6 prefix delegation `sla-id` limited to 128 .
May 27 2022, 6:34 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

1.4 rolling does not help me, so there must be something "wrong" with my configuration. I've attached the private config, it would be awesome if someone might find what's broken.

May 27 2022, 4:52 AM · VyOS 1.3 Equuleus (1.3.6)

May 26 2022

Viacheslav moved T4442: HTTP API add action "reset" from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.2) board.
May 26 2022, 2:53 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav closed T4442: HTTP API add action "reset" as Resolved.
May 26 2022, 2:53 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta