Page MenuHomeVyOS Platform

Dmitry (Dmitry)
UserAdministrator

Projects

User Details

User Since
Mar 4 2019, 8:50 PM (69 w, 2 d)
Roles
Administrator

Recent Activity

Mon, Jun 29

Dmitry updated the task description for T2661: SSTP wrong certificates check.
Mon, Jun 29, 1:12 PM · VyOS 1.3 Equuleus
Dmitry created T2661: SSTP wrong certificates check.
Mon, Jun 29, 1:06 PM · VyOS 1.3 Equuleus

Sat, Jun 27

Dmitry added a comment to T2659: Add fastnetmon (DDoS detection) support.

Yes, it is possible not only to detect DoS/DDoS and also to make some reactions and run alert script.
Alert script receives next params:

#  $1 client_ip_as_string
#  $2 data_direction
#  $3 pps_as_string
#  $4 action (ban or unban)
Sat, Jun 27, 3:32 PM · VyOS 1.3 Equuleus
Dmitry added a comment to T2659: Add fastnetmon (DDoS detection) support.

@jack9603301 can you explain snort perspectives and describe the difference between? Do you have experience with both IDS?

Sat, Jun 27, 3:11 PM · VyOS 1.3 Equuleus
Dmitry updated the task description for T2659: Add fastnetmon (DDoS detection) support.
Sat, Jun 27, 1:56 PM · VyOS 1.3 Equuleus
Dmitry created T2659: Add fastnetmon (DDoS detection) support.
Sat, Jun 27, 1:49 PM · VyOS 1.3 Equuleus

Wed, Jun 24

Dmitry claimed T2641: Rewrite vpn ipsec OP commands in new style XML syntax.
Wed, Jun 24, 4:48 PM · VyOS 1.3 Equuleus
Dmitry created T2641: Rewrite vpn ipsec OP commands in new style XML syntax.
Wed, Jun 24, 4:48 PM · VyOS 1.3 Equuleus

Mon, Jun 22

Dmitry created T2628: Make logs more user friendly..
Mon, Jun 22, 2:54 PM · VyOS 1.3 Equuleus
Dmitry changed the status of T1773: Make it possible to export config to JSON from Open to In progress.
Mon, Jun 22, 10:28 AM · VyOS 1.2 Crux (VyOS 1.2.6), VyOS 1.3 Equuleus

Sun, Jun 21

Dmitry updated the task description for T2622: An issue with config migration (interface pseudo ethernet).
Sun, Jun 21, 7:09 AM · VyOS 1.3 Equuleus
Dmitry created T2622: An issue with config migration (interface pseudo ethernet).
Sun, Jun 21, 7:05 AM · VyOS 1.3 Equuleus
Dmitry closed T2299: login radius-server priority as Resolved.

Works as expected, tested on 1.3-rolling-202006201113

Sun, Jun 21, 6:18 AM · VyOS 1.3 Equuleus

Sat, Jun 20

Dmitry updated the task description for T2299: login radius-server priority.
Sat, Jun 20, 12:15 PM · VyOS 1.3 Equuleus
Dmitry updated the task description for T2299: login radius-server priority.
Sat, Jun 20, 12:14 PM · VyOS 1.3 Equuleus
Dmitry created T2620: Add ipsec peer-name to log to simplifies grepping and troubleshooting.
Sat, Jun 20, 7:07 AM · VyOS 1.3 Equuleus

Thu, Jun 18

Dmitry added a comment to T2614: Add an option to mangle dict keys to vyos.config.get_config_dict().

Can I propose this do as default but keep the possibility redefine replace option?

Thu, Jun 18, 7:17 PM · VyOS 1.3 Equuleus

Wed, Jun 17

Dmitry added a comment to T2299: login radius-server priority.

@c-po Yes, sorry. This is my fault, I forgot that you told me already this.
Done, PR https://github.com/vyos/vyos-1x/pull/464

Wed, Jun 17, 7:15 PM · VyOS 1.3 Equuleus
Dmitry changed the status of T2299: login radius-server priority from Open to Needs testing.

Add PR for rolling https://github.com/vyos/vyos-1x/pull/462

Wed, Jun 17, 1:26 PM · VyOS 1.3 Equuleus

Tue, Jun 16

Dmitry added a comment to T2584: pppoe-server NAS-Filter-Rule attribute.

Implementation steps:

  1. Add $INCLUDE dictionary.rfc4849 to /usr/share/accel-ppp/radius/dictionary file
  2. Add required modules for use ip-pre-up/ip-up/ip-down scripts
[modules]
sigchld
pppd_compat

And pppd_compat params

[pppd-compat]
verbose=1
ip-pre-up=/path/to/ip-pre-up 
radattr-prefix=/var/run/radattr
  1. Create ip-pre-up/ip-down script which will get configured firewall names and rules from CLI or supported script

Note: When ip-pre-up return 1 then the session will not start like described in https://tools.ietf.org/html/rfc4849

Tue, Jun 16, 7:45 PM · VyOS 1.3 Equuleus
Dmitry added a comment to T2602: pptp/sstp/l2tp add possibility enable or disable CCP.

Fixed https://github.com/vyos/vyos-1x/pull/460.

Tue, Jun 16, 10:21 AM · VyOS 1.3 Equuleus
Dmitry added a comment to T2602: pptp/sstp/l2tp add possibility enable or disable CCP.

Does not possible to disable ccp in l2tp

vyos@RTR1# set vpn l2tp remote-access ccp-disable 
[edit]
vyos@RTR1# commit
[ vpn l2tp ]
VyOS had an issue completing a command.
Tue, Jun 16, 10:04 AM · VyOS 1.3 Equuleus
Dmitry created T2603: pppoe-server: reduce min MTU.
Tue, Jun 16, 8:49 AM · VyOS 1.3 Equuleus
Dmitry claimed T2602: pptp/sstp/l2tp add possibility enable or disable CCP.
Tue, Jun 16, 8:36 AM · VyOS 1.3 Equuleus
Dmitry created T2602: pptp/sstp/l2tp add possibility enable or disable CCP.
Tue, Jun 16, 8:36 AM · VyOS 1.3 Equuleus
Dmitry changed the status of T2601: pppoe-server: does not possible to disable ccp from Open to Needs testing.

PR https://github.com/vyos/vyos-1x/pull/459

Tue, Jun 16, 8:29 AM · VyOS 1.3 Equuleus
Dmitry claimed T2601: pppoe-server: does not possible to disable ccp.
Tue, Jun 16, 7:36 AM · VyOS 1.3 Equuleus
Dmitry created T2601: pppoe-server: does not possible to disable ccp.
Tue, Jun 16, 7:36 AM · VyOS 1.3 Equuleus

Mon, Jun 15

Dmitry added a comment to T2599: "show interfaces" does not list VIF interfaces in ascending order.

I think this is a related task https://phabricator.vyos.net/T2591

Mon, Jun 15, 3:30 PM · VyOS 1.3 Equuleus

Sun, Jun 14

Dmitry added a project to T1729: PIM (Protocol Independent Multicast) implementation: VyOS 1.2 Crux (VyOS 1.2.6).
Sun, Jun 14, 8:08 PM · VyOS 1.2 Crux (VyOS 1.2.6), VyOS 1.3 Equuleus
Dmitry added a comment to T1729: PIM (Protocol Independent Multicast) implementation.

Add PR for CRUX.
https://github.com/vyos/vyos-build/pull/107
https://github.com/vyos/vyos-1x/pull/455

Sun, Jun 14, 8:07 PM · VyOS 1.2 Crux (VyOS 1.2.6), VyOS 1.3 Equuleus

Sat, Jun 13

Dmitry created T2591: show command has wrong interfaces ordering.
Sat, Jun 13, 12:39 PM · VyOS 1.3 Equuleus

Fri, Jun 12

Dmitry changed the status of T2091: The swanctl.conf file does not generate properly from Needs testing to Backport candidate.

Successfully tested on 1.3-rolling-202006120643

Fri, Jun 12, 10:00 AM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus
Dmitry changed the status of T2000: strongSwan does not install routes to table 220 in certain cases from Needs testing to Backport candidate.

Successfully tested on rolling 1.3-rolling-202006120643

Fri, Jun 12, 9:50 AM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus

Thu, Jun 11

Dmitry created T2584: pppoe-server NAS-Filter-Rule attribute.
Thu, Jun 11, 11:07 AM · VyOS 1.3 Equuleus

Wed, Jun 10

Dmitry added a comment to T2580: be able to setup ip pools for ippoe.

ipoe daemon allows us to use this possibility. We need to add CLI commands.
Proposed commands:

set service ipoe-server client-ip-pool name POOL1 subnet 100.64.0.0/24

Radius attribute Framed-Pool.

Wed, Jun 10, 8:19 PM · VyOS 1.3 Equuleus
Dmitry closed T2565: Does not possible connect to l2tp server with radius auth as Resolved.
Wed, Jun 10, 8:06 PM · VyOS 1.3 Equuleus
Dmitry closed T2575: pppoe-server: does not possibly assign IP address as Resolved.

Tested on VyOS 1.3-rolling-202006101523
SSTP, L2TP and PPPoE work as expected.
As for pptp, needs to create an additional bug report

Wed, Jun 10, 8:05 PM · VyOS 1.3 Equuleus

Tue, Jun 9

Dmitry changed the status of T2575: pppoe-server: does not possibly assign IP address from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/448

Tue, Jun 9, 8:16 PM · VyOS 1.3 Equuleus
Dmitry claimed T2575: pppoe-server: does not possibly assign IP address.
Tue, Jun 9, 2:25 PM · VyOS 1.3 Equuleus
Dmitry created T2575: pppoe-server: does not possibly assign IP address.
Tue, Jun 9, 2:25 PM · VyOS 1.3 Equuleus
Dmitry added a comment to T2567: accel-ppp eats al memory with small sstp config.

In this case, SSTP daemon trying to allocate RAM for ipv6 pool and router does not have enough RAM. Dynamic memory allocation is not implemented for ip-pools.
Maybe, in this case, we need to calculate before commit, and show commit fail message with reason?
Calculating:
2^64 bit = 18446744073709551616 bit or 2305843009213693952 byte
2305843009213693952 * 64 (structure size byte) = 147573952589676412928 byte or 137438953472 GB
Correct me if my calculation wrong.

Tue, Jun 9, 10:34 AM · VyOS 1.3 Equuleus

Mon, Jun 8

Dmitry changed the status of T2565: Does not possible connect to l2tp server with radius auth from Open to In progress.

PR https://github.com/vyos/vyos-1x/pull/446
Note: gw-ip-address necessary define for [radius] or [chap-secrets] sections.

Mon, Jun 8, 9:11 AM · VyOS 1.3 Equuleus
Dmitry claimed T2565: Does not possible connect to l2tp server with radius auth.
Mon, Jun 8, 8:36 AM · VyOS 1.3 Equuleus
Dmitry created T2565: Does not possible connect to l2tp server with radius auth.
Mon, Jun 8, 8:36 AM · VyOS 1.3 Equuleus
Dmitry added a comment to T2563: Wrong interface binding for Dell VEP 1445.

I think the old interface sequence number can confuse on this device

Mon, Jun 8, 6:23 AM · VyOS 1.2 Crux (VyOS 1.2.6)
Dmitry added a comment to T2563: Wrong interface binding for Dell VEP 1445.

@c-po these changes will take effect only for the newly installed system, HW-ID in config has more priority.

Mon, Jun 8, 6:17 AM · VyOS 1.2 Crux (VyOS 1.2.6)

Sun, Jun 7

Dmitry changed the status of T2563: Wrong interface binding for Dell VEP 1445 from Open to Needs testing.

PR https://github.com/vyos/vyos-build/pull/106

Sun, Jun 7, 8:32 PM · VyOS 1.2 Crux (VyOS 1.2.6)
Dmitry claimed T2563: Wrong interface binding for Dell VEP 1445.
Sun, Jun 7, 8:26 PM · VyOS 1.2 Crux (VyOS 1.2.6)
Dmitry created T2563: Wrong interface binding for Dell VEP 1445.
Sun, Jun 7, 8:26 PM · VyOS 1.2 Crux (VyOS 1.2.6)

May 29 2020

Dmitry changed the status of T2000: strongSwan does not install routes to table 220 in certain cases from In progress to Needs testing.
May 29 2020, 6:21 PM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus

May 28 2020

Dmitry added a comment to T945: Unable to change configuration after changing it from script (vbash + script-template).

@zsdc can you try to reproduce this issue on 1.3 rollings or on 1.2.5? I can't reach this behavior.

May 28 2020, 12:10 PM · VyOS 1.3 Equuleus
Dmitry changed the status of T2000: strongSwan does not install routes to table 220 in certain cases from Confirmed to In progress.
May 28 2020, 11:57 AM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus
Dmitry added a comment to T2000: strongSwan does not install routes to table 220 in certain cases.

PR added https://github.com/vyos/vyatta-cfg-vpn/pull/33.

vyos@vyos# commit
[ vpn ]
Warning: local prefix 192.168.34.0/24 specified for peer "192.168.50.2"
is not configured on any interfaces
May 28 2020, 11:56 AM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus
Dmitry edited projects for T2517: vyos-container: link_filter: No such file or directory, added: VyOS 1.2 Crux (VyOS 1.2.6); removed VyOS 1.2 Crux.
May 28 2020, 11:25 AM · VyOS 1.2 Crux (VyOS 1.2.6)
Dmitry changed the status of T2517: vyos-container: link_filter: No such file or directory from Open to In progress.

PR https://github.com/vyos/vyatta-cfg-quagga/pull/48
Also added the second commit which fixes the path to zebra daemon

May 28 2020, 11:25 AM · VyOS 1.2 Crux (VyOS 1.2.6)

May 26 2020

Dmitry changed the status of T2478: login radius: use NAS-IP-Address if defined source address from In progress to Backport candidate.

Successfully tested on 1.3-rolling-202005261512, propose to backport it to CRUX.

May 26 2020, 5:47 PM · VyOS 1.2 Crux (VyOS 1.2.6), VyOS 1.3 Equuleus
Dmitry closed T1933: Changes in /config/scripts/vyos-postconfig-bootup.script got lost during upgrade to 1.2.4 as Invalid.
May 26 2020, 3:59 PM · VyOS 1.3 Equuleus
Dmitry placed T2519: Broadcast address does not add automatically up for grabs.
May 26 2020, 2:00 PM · VyOS 1.3 Equuleus
Dmitry changed the status of T2519: Broadcast address does not add automatically from Open to In progress.
May 26 2020, 1:37 PM · VyOS 1.3 Equuleus
Dmitry created T2519: Broadcast address does not add automatically.
May 26 2020, 1:36 PM · VyOS 1.3 Equuleus
Dmitry created T2517: vyos-container: link_filter: No such file or directory.
May 26 2020, 10:06 AM · VyOS 1.2 Crux (VyOS 1.2.6)
Dmitry created T2516: vyos-container: does not possible to configure ethernet interface.
May 26 2020, 9:41 AM · VyOS 1.3 Equuleus

May 25 2020

Dmitry changed the status of T2478: login radius: use NAS-IP-Address if defined source address from Open to In progress.
May 25 2020, 8:08 PM · VyOS 1.2 Crux (VyOS 1.2.6), VyOS 1.3 Equuleus
Dmitry added a comment to T2513: BGP peer-group commit error and reboot conifg not found . .

Hello @lawrencepan , can you explain, why you need different AS for route-reflector-client?
Can you add your route-maps ROUTE-V4 and 'ROUTER-V6?

May 25 2020, 5:36 PM · VyOS 1.2 Crux
Dmitry claimed T2478: login radius: use NAS-IP-Address if defined source address.
May 25 2020, 5:27 PM · VyOS 1.2 Crux (VyOS 1.2.6), VyOS 1.3 Equuleus
Dmitry added a comment to T2478: login radius: use NAS-IP-Address if defined source address.

PR for this task https://github.com/vyos/libpam-radius-auth/pull/3
I propose to use always source-address as NAS-IP-Address if it defined

May 25 2020, 3:45 PM · VyOS 1.2 Crux (VyOS 1.2.6), VyOS 1.3 Equuleus
Dmitry closed T2269: SSTP specify tunnels names as Resolved.

Tested successfully on 1.3-rolling-202005250117

vyos@RTR1:~$ show sstp-server sessions 
 ifname | username |     ip     | ip6 | ip6-dp | calling-sid | rate-limit | state  |  uptime  | rx-bytes | tx-bytes 
--------+----------+------------+-----+--------+-------------+------------+--------+----------+----------+----------
 sstp0  | test     | 100.64.2.0 |     |        |   x.x.x.x.  |            | active | 00:01:16 | 27.9 KiB | 80.3 KiB
May 25 2020, 10:23 AM · VyOS 1.3 Equuleus
Dmitry closed T2391: pppoe-server session-control does not work as Resolved.

Tested on 1.3-rolling-202005250117, works as expected.

May 25 2020, 9:55 AM · VyOS 1.3 Equuleus

May 22 2020

Dmitry added a comment to T2490: Add serial (rs232) to ssh bridge service.

Maybe set service serial-bridge?

May 22 2020, 7:03 PM · VyOS 1.3 Equuleus

May 21 2020

Dmitry closed T1876: IPSec VTI tunnels are deleted after rekey and dangling around as A/D as Resolved.
May 21 2020, 9:29 AM · VyOS 1.3 Equuleus
Dmitry closed T2364: Add CLI command for mroute , a subtask of T1729: PIM (Protocol Independent Multicast) implementation, as Resolved.
May 21 2020, 9:06 AM · VyOS 1.2 Crux (VyOS 1.2.6), VyOS 1.3 Equuleus
Dmitry closed T2364: Add CLI command for mroute as Resolved.
May 21 2020, 9:06 AM · VyOS 1.3 Equuleus
Dmitry closed T1820: VRRP transition scripts for sync-groups are not supported in VyOS (anymore) as Resolved.

Tested on 1.3-rolling-202005210117, works properly

May 21 2020, 9:04 AM · VyOS 1.3 Equuleus
Dmitry created T2487: VRRP does not display info when group disabled.
May 21 2020, 8:06 AM · VyOS 1.3 Equuleus
Dmitry closed T2342: Bridge l2tpv3 + ethX errors as Resolved.
May 21 2020, 6:59 AM · VyOS 1.2 Crux (VyOS 1.2.6)

May 20 2020

Dmitry added a comment to T1999: support for ip groups in nat.

Note: When we migrate NAT to nftables, we need to use nftables sets instead of ipset

May 20 2020, 10:55 AM · VyOS 1.3 Equuleus

May 19 2020

Dmitry created T2478: login radius: use NAS-IP-Address if defined source address.
May 19 2020, 12:12 PM · VyOS 1.2 Crux (VyOS 1.2.6), VyOS 1.3 Equuleus

May 14 2020

Dmitry closed T2456: netflow source-ip cannot be configured as Resolved.
May 14 2020, 8:51 AM · VyOS 1.3 Equuleus

May 13 2020

Dmitry changed the status of T2457: IPv6 ping by address not working from Open to Confirmed.

Issue with socket.gethostbyname()

May 13 2020, 9:24 PM
Dmitry reopened T2443: NHRP: Add debugging information to syslog as "Backport pending".
May 13 2020, 7:20 PM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus
Dmitry added a project to T2443: NHRP: Add debugging information to syslog: Ready for Crux (1.2.x).
May 13 2020, 7:11 PM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus
Dmitry changed the status of T2456: netflow source-ip cannot be configured from In progress to Needs testing.
May 13 2020, 6:49 PM · VyOS 1.3 Equuleus
Dmitry changed the status of T2456: netflow source-ip cannot be configured from Confirmed to In progress.

PR https://github.com/vyos/vyos-1x/pull/409

May 13 2020, 6:39 PM · VyOS 1.3 Equuleus
Dmitry closed T2294: ipoe-server broken (jinja2 template issue) as Resolved.
May 13 2020, 12:23 PM · VyOS 1.3 Equuleus
Dmitry closed T2443: NHRP: Add debugging information to syslog as Resolved.

Successfully tested on the VyOS 1.3-rolling-202005130117.
Full opennhrp logs might be enabled by the following command

May 13 2020, 10:59 AM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus
Dmitry changed the status of T2448: monitor command does not work for protocol BGP from Open to Backport candidate.

Fixed in T832

May 13 2020, 10:36 AM · VyOS 1.2 Crux (VyOS 1.2.6)
Dmitry changed the status of T832: show monitoring protocols bgp not works with frr, a subtask of T306: Migration from vyatta-quagga to FRR, from Open to Backport pending.
May 13 2020, 10:34 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1), vyos-frr
Dmitry changed the status of T832: show monitoring protocols bgp not works with frr from Open to Backport pending.
May 13 2020, 10:34 AM · VyOS 1.2 Crux (VyOS 1.2.6), VyOS 1.3 Equuleus, vyos-frr

May 11 2020

Dmitry changed the status of T2443: NHRP: Add debugging information to syslog from In progress to Needs testing.
May 11 2020, 12:54 PM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus
Dmitry added a comment to T2443: NHRP: Add debugging information to syslog.

https://github.com/vyos/vyos-opennhrp/pull/2
https://github.com/vyos/vyos-nhrp/pull/4

May 11 2020, 8:31 AM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus
Dmitry updated the task description for T2448: monitor command does not work for protocol BGP.
May 11 2020, 7:21 AM · VyOS 1.2 Crux (VyOS 1.2.6)
Dmitry created T2448: monitor command does not work for protocol BGP.
May 11 2020, 7:11 AM · VyOS 1.2 Crux (VyOS 1.2.6)

May 9 2020

Dmitry changed the status of T2443: NHRP: Add debugging information to syslog from Open to In progress.
May 9 2020, 1:18 PM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus
Dmitry created T2443: NHRP: Add debugging information to syslog.
May 9 2020, 1:17 PM · Ready for Crux (1.2.x), VyOS 1.3 Equuleus

May 6 2020

Dmitry closed T1982: Increase rotation for atop.acct as Resolved.
May 6 2020, 1:58 PM · VyOS 1.2 Crux (VyOS 1.2.6)

May 4 2020

Dmitry added a comment to T2294: ipoe-server broken (jinja2 template issue).

Fix path to mac-address node. PR https://github.com/vyos/vyos-1x/pull/392

May 4 2020, 12:34 PM · VyOS 1.3 Equuleus
Dmitry closed T2412: ping flood does not work as Resolved.

All works on the rolling 1.3-rolling-202005030117

vyos@vyos:~$ ping 100.64.0.1 flood count 300
PING 100.64.0.1 (100.64.0.1) 56(84) bytes of data.
May 4 2020, 7:50 AM · VyOS 1.3 Equuleus
Dmitry added a comment to T1982: Increase rotation for atop.acct.

PR https://github.com/vyos/vyos-build/pull/104

May 4 2020, 7:36 AM · VyOS 1.2 Crux (VyOS 1.2.6)

May 2 2020

Dmitry assigned T2404: change mtu to thomas-mangin.
May 2 2020, 2:28 PM · VyOS 1.3 Equuleus