Page MenuHomeVyOS Platform
Feed All Stories

Jun 29 2022

c-po added a comment to T4477: router-advert: support RDNSS lifetime option.

Implemented as: set service router-advert interface eth0 name-server-lifetime <value> which will be option A

Jun 29 2022, 6:05 PM · VyOS 1.4 Sagitta
c-po closed T4477: router-advert: support RDNSS lifetime option as Resolved.
Jun 29 2022, 6:02 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4494: Cannot reset BGP peer within VRF.

PR https://github.com/vyos/vyos-1x/pull/1379 (without completion help)

Jun 29 2022, 3:48 PM · VyOS 1.4 Sagitta
diekos added a comment to T4299: Firewall - GeoIP filtering.

Because with a rule like that I accept everything coming from nl from wan to lan, or I would need to add the source nl to every rule. That's why I did it with a deny not coming from nl on top, and then specific rules for the traffic that I want to accept.

Jun 29 2022, 3:28 PM · VyOS 1.4 Sagitta
jestabro changed the status of T4491: Use empty string for internal name of root node of config_tree, a subtask of T4235: Add config tree diff algorithm, from In progress to Backport candidate.
Jun 29 2022, 2:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro changed the status of T4491: Use empty string for internal name of root node of config_tree from In progress to Backport candidate.
Jun 29 2022, 2:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
SrividyaA claimed T4493: Incorrect help for "show bgp neighbors".
Jun 29 2022, 10:31 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T4492: Incorrect list of neighbors in help for "show bgp vrf VRF neighbors": VyOS 1.4 Sagitta.
Jun 29 2022, 10:31 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4493: Incorrect help for "show bgp neighbors" from "Task" to "Bug".
Jun 29 2022, 10:30 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4494: Cannot reset BGP peer within VRF from "Task" to "Bug".
Jun 29 2022, 10:28 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T4495: Combine BGP reset op commands: VyOS 1.4 Sagitta.
Jun 29 2022, 10:28 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T4496: ping vrf help does not list VRFs: VyOS 1.4 Sagitta.
Jun 29 2022, 10:27 AM · VyOS 1.4 Sagitta
Viacheslav added a project to T4497: ping cannot force ipv4 or ipv6: VyOS 1.4 Sagitta.
Jun 29 2022, 10:27 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4496: ping vrf help does not list VRFs from "Task" to "Feature Request".
Jun 29 2022, 10:27 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4498: bridge: Add option to enable/disable IGMP/MLD snooping.

If the default option is enabled or 1
Maybe it makes sense to create disable option like:

set interfaces bridge br0 ip disable-multicast-snooping
Jun 29 2022, 10:23 AM · VyOS 1.4 Sagitta
vfreex added a comment to T4498: bridge: Add option to enable/disable IGMP/MLD snooping.

PR to add the option: https://github.com/vyos/vyos-1x/pull/1378

Jun 29 2022, 9:54 AM · VyOS 1.4 Sagitta
vfreex created T4498: bridge: Add option to enable/disable IGMP/MLD snooping.
Jun 29 2022, 9:53 AM · VyOS 1.4 Sagitta
aderouineau triaged T4497: ping cannot force ipv4 or ipv6 as Normal priority.
Jun 29 2022, 12:55 AM · VyOS 1.4 Sagitta
aderouineau triaged T4496: ping vrf help does not list VRFs as Low priority.
Jun 29 2022, 12:50 AM · VyOS 1.4 Sagitta
aderouineau triaged T4495: Combine BGP reset op commands as Wishlist priority.
Jun 29 2022, 12:41 AM · VyOS 1.4 Sagitta
aderouineau triaged T4494: Cannot reset BGP peer within VRF as Normal priority.
Jun 29 2022, 12:34 AM · VyOS 1.4 Sagitta
aderouineau triaged T4493: Incorrect help for "show bgp neighbors" as Low priority.
Jun 29 2022, 12:27 AM · VyOS 1.4 Sagitta
aderouineau triaged T4492: Incorrect list of neighbors in help for "show bgp vrf VRF neighbors" as Normal priority.
Jun 29 2022, 12:25 AM · VyOS 1.4 Sagitta

Jun 28 2022

jestabro added a comment to T4491: Use empty string for internal name of root node of config_tree.

PR:
https://github.com/vyos/vyos1x-config/pull/9

Jun 28 2022, 8:18 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro renamed T4491: Use empty string for internal name of root node of config_tree from Use empty string for internal name of root of config_tree to Use empty string for internal name of root node of config_tree.
Jun 28 2022, 8:17 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro added a subtask for T4235: Add config tree diff algorithm: T4491: Use empty string for internal name of root node of config_tree.
Jun 28 2022, 8:17 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro added a parent task for T4491: Use empty string for internal name of root node of config_tree: T4235: Add config tree diff algorithm.
Jun 28 2022, 8:17 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro changed the status of T4295: Use config_tree instead of legacy loadFile in vyos-load-config.py, a subtask of T4235: Add config tree diff algorithm, from Open to On hold.
Jun 28 2022, 7:57 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
jestabro changed the status of T4295: Use config_tree instead of legacy loadFile in vyos-load-config.py, a subtask of T4316: Update save-config/load-config, from Open to On hold.
Jun 28 2022, 7:57 PM · VyOS 1.4 Sagitta
jestabro changed the status of T4295: Use config_tree instead of legacy loadFile in vyos-load-config.py from Open to On hold.
Jun 28 2022, 7:57 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T4316: Update save-config/load-config.
Jun 28 2022, 7:56 PM · VyOS 1.4 Sagitta
jestabro updated the task description for T4295: Use config_tree instead of legacy loadFile in vyos-load-config.py.
Jun 28 2022, 7:55 PM · VyOS 1.4 Sagitta
jestabro changed the status of T4491: Use empty string for internal name of root node of config_tree from Open to In progress.
Jun 28 2022, 7:05 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
Viacheslav lowered the priority of T4232: VyOS 1.2 traffic-policy shaper match interface not working from High to Normal.
Jun 28 2022, 4:57 PM · VyOS 1.2 Crux
Viacheslav closed T4348: Site access denied as Invalid.

It is not related to a router bug/feature
Close it

Jun 28 2022, 4:54 PM
Viacheslav closed T4473: Use container network without network declaration error as Resolved.
Jun 28 2022, 4:30 PM · VyOS 1.4 Sagitta
Viacheslav closed T4486: Container can't be deleted as Resolved.
Jun 28 2022, 4:29 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4471: Explicit declare root domain in static-host-mapping.

Did you try dns forwarding domain?

set service dns forwarding domain abc.local server 192.0.2.5
Jun 28 2022, 3:23 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4475: route-map does not support ipv6 peer from In progress to Needs testing.
Jun 28 2022, 3:20 PM · VyOS 1.3 Equuleus (1.3.4)
Viacheslav added a comment to T4486: Container can't be deleted.

PR https://github.com/vyos/vyos-1x/pull/1377

Jun 28 2022, 1:46 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4486: Container can't be deleted from Open to In progress.
Jun 28 2022, 12:59 PM · VyOS 1.4 Sagitta
n.fort closed T4458: Firewall - add support for matching ip ttl in firewall rules as Resolved.
Jun 28 2022, 12:49 PM · VyOS 1.4 Sagitta
n.fort closed T3907: Firewall - Set log levels as Resolved.
Jun 28 2022, 12:48 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4443: Wan Load Balancing Multiple Regressions.

Task for rewriting wan-loadbalancing to XML/Python T4470

Jun 28 2022, 12:18 PM · VyOS 1.3 Equuleus (1.3.7)
fernando added a comment to T4490: BGP- warning message that AFI/SAFI is needed to establish the neighborship.

@Viacheslav thanks

Jun 28 2022, 12:15 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T4473: Use container network without network declaration error from Open to In progress.
Jun 28 2022, 12:13 PM · VyOS 1.4 Sagitta
Viacheslav claimed T4473: Use container network without network declaration error.
Jun 28 2022, 12:13 PM · VyOS 1.4 Sagitta
fernando changed the status of T4490: BGP- warning message that AFI/SAFI is needed to establish the neighborship from Open to In progress.
Jun 28 2022, 12:13 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4473: Use container network without network declaration error.

PR https://github.com/vyos/vyos-1x/pull/1376

Jun 28 2022, 12:12 PM · VyOS 1.4 Sagitta
Viacheslav added a project to T4489: MPLS sysctl not persistent for tunnel interfaces: VyOS 1.3 Equuleus (1.3.2).

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1375

Jun 28 2022, 10:42 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav moved T4429: Ability to detect external IP address from op-mode from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Jun 28 2022, 10:27 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a project to T4429: Ability to detect external IP address from op-mode: VyOS 1.3 Equuleus (1.3.2).

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1374

Jun 28 2022, 10:21 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4489: MPLS sysctl not persistent for tunnel interfaces.

Will be fixed in the next rolling release

Jun 28 2022, 9:58 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T1375: Add clear dhcp server lease function.

PR for 1.3 https://github.com/vyos/vyos-1x/pull/1372

Jun 28 2022, 9:34 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav moved T1375: Add clear dhcp server lease function from Need Triage to Finished on the VyOS 1.4 Sagitta board.
Jun 28 2022, 9:05 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4490: BGP- warning message that AFI/SAFI is needed to establish the neighborship.

PR https://github.com/vyos/vyos-1x/pull/1371

Jun 28 2022, 9:04 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T4299: Firewall - GeoIP filtering.

Why don't use action accept for nl and drop all others?

Jun 28 2022, 8:40 AM · VyOS 1.4 Sagitta
Viacheslav closed T4457: L2TP/IPSec Remote Access VPN does not work as expected in 1.3.1-S1 as Invalid.
Jun 28 2022, 8:38 AM · VyOS 1.3 Equuleus ( 1.3.1)
e.khudiyev added a comment to T4457: L2TP/IPSec Remote Access VPN does not work as expected in 1.3.1-S1.
In T4457#124584, @NikolayP wrote:

The problem seems to be in these lines:

set vpn l2tp remote-access authentication local-users username test static-ip '172.25.255.1'
set vpn l2tp remote-access client-ip-pool start '172.25.255.1'
set vpn l2tp remote-access client-ip-pool stop '172.25.255.14'

Replacing "static IP" with 172.25.255.2 makes it work in VyOS 1.3.1

set vpn l2tp remote-access authentication local-users username test static-ip '172.25.255.2'

Full corrected config for 1.3.1 from the first post:

set interfaces dummy dum4 address '4.4.4.4/32'
set interfaces ethernet eth0 address 'dhcp'
set interfaces ethernet eth1 address '192.168.6.31/24'
set service ssh
set vpn ipsec ipsec-interfaces interface 'eth1'
set vpn ipsec nat-networks allowed-network 0.0.0.0/0
set vpn ipsec nat-traversal 'enable'
set vpn l2tp remote-access authentication local-users username test password 'test'
set vpn l2tp remote-access authentication local-users username test static-ip '172.25.255.2'
set vpn l2tp remote-access authentication mode 'local'
set vpn l2tp remote-access authentication require 'mschap-v2'
set vpn l2tp remote-access client-ip-pool start '172.25.255.1'
set vpn l2tp remote-access client-ip-pool stop '172.25.255.14'
set vpn l2tp remote-access idle '1800'
set vpn l2tp remote-access ipsec-settings authentication mode 'pre-shared-secret'
set vpn l2tp remote-access ipsec-settings authentication pre-shared-secret 'test'
set vpn l2tp remote-access ipsec-settings ike-lifetime '3600'
set vpn l2tp remote-access ipsec-settings lifetime '3600'
set vpn l2tp remote-access outside-address '192.168.6.31'
Jun 28 2022, 8:29 AM · VyOS 1.3 Equuleus ( 1.3.1)
Viacheslav added a comment to T4489: MPLS sysctl not persistent for tunnel interfaces.

PR https://github.com/vyos/vyos-1x/pull/1370

Jun 28 2022, 8:18 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav changed the status of T4489: MPLS sysctl not persistent for tunnel interfaces from Confirmed to In progress.
Jun 28 2022, 8:03 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
Viacheslav added a comment to T4489: MPLS sysctl not persistent for tunnel interfaces.

It seems a wrong priority
Mpls configuration applied before creation tunnel
As a result sysctl parameter for the tunnel interface doesn't exist yet
To reproduce it in one commit:

set interfaces dummy dum1 address '10.5.4.8/24'
set interfaces tunnel tun0 address '10.255.0.2/30'
set interfaces tunnel tun0 encapsulation 'gre'
set interfaces tunnel tun0 remote '192.0.2.254'
set interfaces tunnel tun0 source-address '192.0.2.1'
set protocols mpls interface 'dum1'
set protocols mpls interface 'tun0'
set protocols mpls ldp discovery transport-ipv4-address '192.0.2.1'
set protocols mpls ldp interface 'dum1'
set protocols mpls ldp interface 'tun0'
set protocols mpls ldp router-id '192.0.2.1'
Jun 28 2022, 7:53 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

Jun 27 2022

fernando created T4490: BGP- warning message that AFI/SAFI is needed to establish the neighborship.
Jun 27 2022, 9:11 PM · VyOS 1.4 Sagitta
sarthurdev closed T4484: Firewall op-mode summary doesn't correctly handle address group containing ranges as Resolved.
Jun 27 2022, 8:16 PM · VyOS 1.4 Sagitta
ssasso added a comment to T4489: MPLS sysctl not persistent for tunnel interfaces.

Hi,
I think this is a BUG, not a feature.
If I enable mpls on an interface, then the proper sysctl flags must be applied and be persistent.

Jun 27 2022, 2:33 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
fernando changed the status of T4489: MPLS sysctl not persistent for tunnel interfaces from Open to Confirmed.
Jun 27 2022, 2:05 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
fernando added a comment to T4489: MPLS sysctl not persistent for tunnel interfaces.

it's a common behavior when you want to set sysctl variable and bash-cli is used ( vyos-cli by default when restart the vm set this value in 0 ) . however , it's possible to configure it with this command :

Jun 27 2022, 2:03 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
ssasso updated the task description for T4489: MPLS sysctl not persistent for tunnel interfaces.
Jun 27 2022, 12:15 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
ssasso created T4489: MPLS sysctl not persistent for tunnel interfaces.
Jun 27 2022, 12:10 PM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta
c-po claimed T4477: router-advert: support RDNSS lifetime option.
Jun 27 2022, 6:36 AM · VyOS 1.4 Sagitta

Jun 26 2022

diekos added a comment to T4299: Firewall - GeoIP filtering.

I just tested it on VyOS 1.4-rolling-202206260217, everything seems to work so far!
It would be nice to also have the negate option, something like:

Jun 26 2022, 9:34 PM · VyOS 1.4 Sagitta
aderouineau added a comment to T1733: Route filters syntax redesign.

@MrXermon Let's say someone is setting up BGP peering and wants to control import or export of prefixes using prefixlist. With your suggestion, how would you deny certain prefixes and accept all others? Can JunOS solve this directly with prefixlist without using route-map?

Jun 26 2022, 9:06 PM · VyOS 2.0.x
Nova_Logic added a comment to T4480: add an ability to configure squid acl safe ports and acl ssl safe ports.

Thank you!

Jun 26 2022, 4:16 PM · VyOS 1.4 Sagitta
n.fort changed the status of T4480: add an ability to configure squid acl safe ports and acl ssl safe ports from Open to In progress.
Jun 26 2022, 3:49 PM · VyOS 1.4 Sagitta
n.fort added a project to T4480: add an ability to configure squid acl safe ports and acl ssl safe ports: VyOS 1.4 Sagitta.
Jun 26 2022, 3:49 PM · VyOS 1.4 Sagitta
n.fort added a comment to T4480: add an ability to configure squid acl safe ports and acl ssl safe ports.

PR: https://github.com/vyos/vyos-1x/pull/1369

Jun 26 2022, 3:48 PM · VyOS 1.4 Sagitta
Nova_Logic updated the task description for T4488: allow manual configuration changes of interfaces created by high-availability with rfc3768-compatibility option .
Jun 26 2022, 3:11 PM · VyOS 1.5 Circinus
Nova_Logic created T4488: allow manual configuration changes of interfaces created by high-availability with rfc3768-compatibility option .
Jun 26 2022, 3:06 PM · VyOS 1.5 Circinus
n.fort claimed T4480: add an ability to configure squid acl safe ports and acl ssl safe ports.
Jun 26 2022, 12:25 PM · VyOS 1.4 Sagitta
Viacheslav changed Version from - to VyOS 1.4-rolling-202206260217 on T4487: Create container without downloaded image wrong behavior.
Jun 26 2022, 8:37 AM · VyOS 1.4 Sagitta
Viacheslav changed the subtype of T4487: Create container without downloaded image wrong behavior from "Feature Request" to "Bug".
Jun 26 2022, 8:29 AM · VyOS 1.4 Sagitta
Viacheslav created T4487: Create container without downloaded image wrong behavior.
Jun 26 2022, 8:28 AM · VyOS 1.4 Sagitta
Viacheslav closed T4404: Container is not deleted as Resolved N/A.
Jun 26 2022, 8:14 AM · VyOS 1.4 Sagitta
Viacheslav created T4486: Container can't be deleted.
Jun 26 2022, 8:11 AM · VyOS 1.4 Sagitta

Jun 25 2022

sarthurdev changed the status of T4485: OpenVPN: Allow multiple CAs certificates from Open to In progress.
Jun 25 2022, 9:58 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4484: Firewall op-mode summary doesn't correctly handle address group containing ranges from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1368

Jun 25 2022, 9:48 PM · VyOS 1.4 Sagitta
sarthurdev changed the status of T4484: Firewall op-mode summary doesn't correctly handle address group containing ranges from Open to In progress.
Jun 25 2022, 9:46 PM · VyOS 1.4 Sagitta
c-po closed T4483: Upgrade fastnetmon to v1.2.2 community edition, a subtask of T2659: Add fastnetmon (DDoS detection) support, as Resolved.
Jun 25 2022, 9:11 AM · VyOS 1.3 Equuleus (1.3.0)
c-po closed T4483: Upgrade fastnetmon to v1.2.2 community edition as Resolved.
Jun 25 2022, 9:11 AM · VyOS 1.4 Sagitta
c-po created T4483: Upgrade fastnetmon to v1.2.2 community edition.
Jun 25 2022, 9:11 AM · VyOS 1.4 Sagitta
c-po moved T1748: vbash: beautify tab completion output/line breaks from In Progress to Finished on the VyOS 1.4 Sagitta board.
Jun 25 2022, 9:03 AM · VyOS 1.4 Sagitta
c-po moved T4482: dhcp: toggle of "dhcp-options no-default-route" has no effect from In Progress to Finished on the VyOS 1.4 Sagitta board.
Jun 25 2022, 9:03 AM · VyOS 1.4 Sagitta
c-po closed T4482: dhcp: toggle of "dhcp-options no-default-route" has no effect as Resolved.
Jun 25 2022, 9:03 AM · VyOS 1.4 Sagitta
c-po updated the task description for T4482: dhcp: toggle of "dhcp-options no-default-route" has no effect.
Jun 25 2022, 7:47 AM · VyOS 1.4 Sagitta
c-po moved T4482: dhcp: toggle of "dhcp-options no-default-route" has no effect from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Jun 25 2022, 7:47 AM · VyOS 1.4 Sagitta
c-po claimed T4482: dhcp: toggle of "dhcp-options no-default-route" has no effect.
Jun 25 2022, 7:46 AM · VyOS 1.4 Sagitta
c-po created T4482: dhcp: toggle of "dhcp-options no-default-route" has no effect.
Jun 25 2022, 7:46 AM · VyOS 1.4 Sagitta

Jun 24 2022

Nova_Logic created T4481: containers are not starting.
Jun 24 2022, 10:16 PM · VyOS 1.4 Sagitta
Nova_Logic created T4480: add an ability to configure squid acl safe ports and acl ssl safe ports.
Jun 24 2022, 10:13 PM · VyOS 1.4 Sagitta
sandwichdoge added a comment to T3933: The firewall does not filter incoming traffic on the interface with vrf..

@Viacheslav As for your other concern, you can filter the actual inbound interface (eth4 in this my case) in mangle-PREROUTING. Maybe you could try packet marking in mangle-PREROUTING, then filter them later in VYOS_FW_FORWARD/VYOS_FW_LOCAL in the filter table?
Something like this:

Jun 24 2022, 4:06 AM · VyOS 1.4 Sagitta (1.4.0-epa1), Restricted Project, VyOS 1.3 Equuleus (1.3.7)