Page MenuHomeVyOS Platform

EwaldvanGeffen (Ewald van Geffen)
User

Projects

User does not belong to any projects.

User Details

User Since
Feb 15 2016, 11:55 AM (422 w, 20 h)

Recent Activity

Oct 12 2020

EwaldvanGeffen added a comment to T563: webproxy: migrate 'service webproxy' to get_config_dict().

ATS looks nice.

Oct 12 2020, 1:37 AM · VyOS 1.3 Equuleus (1.3.0-epa1)

Feb 7 2019

EwaldvanGeffen added a comment to T1171: 1.2.0 epa2 - IPsec VPN initiation.

@ekim rephrased: remove the DHCP-interface option and only use and configure the local-address to 0.0.0.0.

Feb 7 2019, 5:17 PM · VyOS 1.3 Equuleus (1.3.0-epa1)

Feb 5 2019

EwaldvanGeffen added a comment to T1171: 1.2.0 epa2 - IPsec VPN initiation.

Can you try without dhcp-interface and set 0.0.0.0 as local-address?

Feb 5 2019, 8:56 PM · VyOS 1.3 Equuleus (1.3.0-epa1)

Feb 4 2019

EwaldvanGeffen added a comment to T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.

Configured protocols does not match Proposed protocols. Try without pfs configuration on the VyOS side.

Feb 4 2019, 9:14 PM · VyOS 1.3 Equuleus (1.3.0-epa1)

Oct 18 2018

EwaldvanGeffen added a comment to T865: Add initial RPKI support.
In T865#20843, @rherold wrote:

It would be nice to have it in 1.2 .x cause in the moment most poviders start enforcing it.

Oct 18 2018, 5:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Oct 16 2018

EwaldvanGeffen added a comment to T816: ipaddrcheck / libcidr but on IPv6 network validation.

I've redone the patch, it uses a simpler regex because we do not need mixed-mode. The main issue was it didn't validate lowercase. I had to split the host/mask parsing to do the cidr variant properly. I've added tests and it ran succesfully. PR#2

Oct 16 2018, 7:02 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Oct 15 2018

EwaldvanGeffen added a comment to T895: Some logs are not forwarded to syslog.

Maybe it merits the larger question on howto migrate this away from rsyslog (if at all) and create sub-tasks.

Oct 15 2018, 12:15 AM · VyOS 1.2 Crux (VyOS 1.2.0-rc4), VyOS-1.2.0-GA

Oct 14 2018

EwaldvanGeffen moved T816: ipaddrcheck / libcidr but on IPv6 network validation from Needs Triage to In Progress on the VyOS 1.2 Crux (VyOS 1.2.0-rc3) board.
Oct 14 2018, 11:46 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
EwaldvanGeffen moved T885: Bug in add system image signature check confirmation from Needs Triage to In Progress on the VyOS 1.2 Crux (VyOS 1.2.0-rc3) board.
Oct 14 2018, 11:45 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)
EwaldvanGeffen added a comment to T885: Bug in add system image signature check confirmation.

docu
PR

Oct 14 2018, 11:44 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)
EwaldvanGeffen added a comment to T816: ipaddrcheck / libcidr but on IPv6 network validation.

regex or for the lazy

Oct 14 2018, 11:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
EwaldvanGeffen added a comment to T901: Vyatta firewall service (vyatta-router.service) times out with zone-based policies.

Do you experience this now? How many rules / what hardware may I ask?
edit: Not trying to undermine your request for this change, just to get an idea at which point it becomes a problem with the current setting to estimate whether we need to address the root-cause urgently.

Oct 14 2018, 6:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc4)
EwaldvanGeffen added a comment to T895: Some logs are not forwarded to syslog.

[Journal]
ForwardToSyslog=yes
MaxLevelStore=debug
MaxLevelSyslog=debug

Oct 14 2018, 12:48 PM · VyOS 1.2 Crux (VyOS 1.2.0-rc4), VyOS-1.2.0-GA
EwaldvanGeffen added a comment to T895: Some logs are not forwarded to syslog.

so far found this:

Oct 14 2018, 12:26 PM · VyOS 1.2 Crux (VyOS 1.2.0-rc4), VyOS-1.2.0-GA

Oct 13 2018

EwaldvanGeffen added a comment to T889: ZeroDivisionError in show_dhcp.py if number of leases is 0.

this bug is cute as fuck.
https://github.com/vyos/vyos-1x/pull/54
cfr. inb4 T823

Oct 13 2018, 4:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc3)
EwaldvanGeffen added a comment to T375: WAN failover, not to balance the load.

@syncer if there is an actual issue we need more input from the user to continue. ONHOLD for me (or ARCHIVE).

Oct 13 2018, 4:30 PM · VyOS 1.4 Sagitta
EwaldvanGeffen added a comment to T350: Initial mockups.

how about NETCONF, YANG ...

Oct 13 2018, 4:29 PM · vyConductor
EwaldvanGeffen added a comment to T292: [ZBF] Allow filtering intra zone traffic.

Design-wise this is the right choice. Other platforms have adopted this mantra. The only thing we need to think about is the default policy for intra-zone traffic (allow, drop, reject). My personal preference would be to set the default-intra-zone policy to allow-all within the upgrade scripts, otherwise drop for new configs.

Oct 13 2018, 4:16 PM · VyOS 1.4 Sagitta

Sep 24 2018

EwaldvanGeffen added a comment to T852: Router responding to arp requests for all addresses, breaks Windows networking!.

Does your box have a mellanox card? Is there any virtualization involved? Can you check the driver revision in non-/working state in the kernel? Use ethtool to find out the driver servicing your interface and then modinfo the kernel driver name to get its version.

Sep 24 2018, 10:53 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
EwaldvanGeffen added a comment to T840: VRRP V3 backup router sending ND RA.

I think the radvd should be made vrrp3 aware. In Juniper this looks like protocols router-advertisement interface <val> virtual-router-only: Send advertisemnets only for vrrp-inet6-group.

Sep 24 2018, 10:41 PM · VyOS 1.3 Equuleus (1.3.7), test

May 23 2018

EwaldvanGeffen added a comment to Q137: When DR is down, VyOS doesn't update routes. (Answer 190).

Can you share configs?
What do you mean with "when BDR comes up" ? Was BDR also down together with DR ?
Can you describe more precisely the steps you undertake and what you observe (on which box)? (c/p output into our pastebin )

May 23 2018, 6:35 PM
EwaldvanGeffen added a comment to Q135: man command missing (Answer 182).

+1 close/wontfix

May 23 2018, 4:50 PM
EwaldvanGeffen added a comment to T658: DNS Forwarder does not reload hosts file when modified..

Thinking ahead: what happens when you have a very active DHCP server? Shouldn't we rate-limit reload-zones to max once/n sec ?

May 23 2018, 4:48 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

May 22 2018

EwaldvanGeffen added a comment to T201: Beep When Fully Booted.
In T201#14503, @c-po wrote:

any updates on this?

May 22 2018, 8:01 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Oct 25 2017

EwaldvanGeffen added a comment to T429: Pi-Hole or similar feature.

How exactly do you see the two products interact on a single system?
Do you have this request on their ticketing system? Can you link the two?
Does it have to run on a rpi?

Oct 25 2017, 9:12 PM · Rejected

Oct 12 2017

EwaldvanGeffen added a comment to T375: WAN failover, not to balance the load.

Run tcpdump on your WAN with filter ICMP to confirm probing goes haywire; should be pretty easy to spot as you employed four different targets.

Oct 12 2017, 10:07 PM · VyOS 1.4 Sagitta
EwaldvanGeffen added a comment to T417: Allow bonding non-ethernet interfaces.

I've tried to attain this holy grail of combining VPNs to gain a faster more reliable link. Although my environment where multiple consumer WAN links with different specs. Yours seem to be more uniform to account for so you might get away with easier.

Oct 12 2017, 9:48 PM · VyOS 1.5 Circinus

Aug 30 2017

EwaldvanGeffen added a comment to T371: Add command alias configuration node.

note: careful when overruling vtysh commands (tt == save?)

Aug 30 2017, 7:32 PM · Invalid

Aug 25 2017

EwaldvanGeffen added a comment to T329: add phabricator.vyos.net paste app as valid destination for show tech-support save-uncompressed.

@syncer not in the config dump, in the bash-history that's included.

Aug 25 2017, 9:59 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
EwaldvanGeffen added a comment to T329: add phabricator.vyos.net paste app as valid destination for show tech-support save-uncompressed.

I just noticed your pastes. We need to filter out the set password commands as they will contain plaintext passwords. This could be solved by making the command interactive (it asks for the password to be typed in) similarly to other platforms. There might be other stuff that requires filtering-out history or refactoring.

Aug 25 2017, 6:43 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Aug 12 2017

EwaldvanGeffen changed the status of T103: DHCP server prepends shared network name to hostnames from Open to In progress.

Please vote in https://phabricator.vyos.net/V4

Aug 12 2017, 5:16 PM · VyOS 1.2 Crux (VyOS 1.2.6)

Aug 5 2017

EwaldvanGeffen added a comment to Q107: Suggestion for adding functionality global group.

@syncer I think the problem is that many fields (eg. within the NAT, WLB, PBR facilities) don't allow to use groups you can use in the firewall stanzas. I think there's no need to poll on this, seems to me like a no-brainer, everyone wants this. Many modern products also add auto variables such as eth0_ipaddresses or eth0_networks. Juniper has an implementation that also allows for hierarchical grouping.

Aug 5 2017, 1:11 PM · VyOS 1.2 Crux

Aug 4 2017

EwaldvanGeffen added a comment to T103: DHCP server prepends shared network name to hostnames.

This required a little voting or some input by a core member on syntax. Once that's established implementation proceeds.

Aug 4 2017, 10:21 PM · VyOS 1.2 Crux (VyOS 1.2.6)

Aug 3 2017

EwaldvanGeffen added a comment to V2: Should VyOS-specific shell be the login shell in VyOS 2.0?.

Merijn is right in my experience. I think root should get unix and the rest the vyos-cli. If you make it a configurable setting within the vyos-cli it would be bestest for everyone.

Aug 3 2017, 6:10 PM · VyOS 2.0.x

Jul 22 2017

EwaldvanGeffen added a comment to T329: add phabricator.vyos.net paste app as valid destination for show tech-support save-uncompressed.

https://secure.phabricator.com/conduit/method/paste.edit/
title
language
text
projects.add
subscribers.add

Jul 22 2017, 1:13 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jul 17 2017

EwaldvanGeffen closed T335: SNMP monitoring integration w/ Quagga as Resolved.

is already implemented. great!

Jul 17 2017, 7:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
EwaldvanGeffen updated the task description for T335: SNMP monitoring integration w/ Quagga.
Jul 17 2017, 7:22 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
EwaldvanGeffen created T335: SNMP monitoring integration w/ Quagga.
Jul 17 2017, 7:22 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jul 4 2017

EwaldvanGeffen added a comment to T329: add phabricator.vyos.net paste app as valid destination for show tech-support save-uncompressed.

could you create a phabricator test paste with the correct permission settings as example. Next step is to programmaticly create the same and then integrate w/ vyos.

Jul 4 2017, 6:20 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jul 3 2017

EwaldvanGeffen added a comment to T329: add phabricator.vyos.net paste app as valid destination for show tech-support save-uncompressed.

This requires that VyOS has either some kind of token that allows him to post-as user or the user credentials for pastebin. PHabricator Bots could be perhaps leveraged.

Jul 3 2017, 6:12 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

May 29 2017

EwaldvanGeffen added a comment to T305: loadbalancing does not work with one pppoe connection and another connection of either dhcp or static .

I added a force-gateway option some time ago. Regardless it's somewhat expected on 1.2, it needs testing and review. I meant 1.1.7 in my previous post (yes, confusion).

May 29 2017, 9:24 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, test

May 22 2017

EwaldvanGeffen added a comment to T186: DHCP with VRRP.

save https://github.com/vyos/vyatta-op-dhcp-server/commit/64817db98e485eee75b53caf4b308197d094784c in /opt/vyatta/share/perl5/Vyatta/DHCPServerOpMode.pm

May 22 2017, 7:11 PM · VyOS 1.1.x (1.1.8)

May 21 2017

EwaldvanGeffen added a comment to T186: DHCP with VRRP.

@tsumaru720 Could you provide feedback?

May 21 2017, 5:31 PM · VyOS 1.1.x (1.1.8)
EwaldvanGeffen added a comment to T208: Ability to ignore default-route from dhcpcd per interface.

I'm sorry for the belated response. This is great. Thanks for your contribution @fatihusta! Once testing checks out I'll add this to my CLI integration todo.

May 21 2017, 5:28 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
EwaldvanGeffen lowered the priority of T305: loadbalancing does not work with one pppoe connection and another connection of either dhcp or static from Unbreak Now! to Requires assessment.
May 21 2017, 5:22 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, test
EwaldvanGeffen added a comment to T305: loadbalancing does not work with one pppoe connection and another connection of either dhcp or static .

What version have you been using?

May 21 2017, 5:18 PM · VyOS 1.3 Equuleus (1.3.5), VyOS 1.4 Sagitta, test

Apr 29 2017

EwaldvanGeffen closed T167: "set service ssh allow-root" is not enough to root system-access via ssh as Resolved.

https://github.com/vyos/vyatta-cfg-system/pull/56

Apr 29 2017, 9:10 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
EwaldvanGeffen closed T217: Cron error as Resolved.

Resolved in https://github.com/vyos/vyatta-cfg-vpn/commit/0ff779958f9c8951bb7e3e866ca52bc70b470fa9

Apr 29 2017, 9:08 PM · VyOS 1.1.x (1.1.8)

Apr 18 2017

EwaldvanGeffen added a comment to T167: "set service ssh allow-root" is not enough to root system-access via ssh.

@mdsmds you sure that is not it's intended purpose; scare away people from enabling root on their boxes ;p I'm hoping to have some time soon to do some small stuff like this.

Apr 18 2017, 8:10 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
EwaldvanGeffen added a comment to T167: "set service ssh allow-root" is not enough to root system-access via ssh.

Okay, so maybe we should expand the configuration in that case a little. Let's make it replace whatever value is found and allow all three options in the CLI?

Apr 18 2017, 7:50 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Mar 5 2017

EwaldvanGeffen closed T271: Is there a solution to deploy this vyos in raspberry Pi 3 as Invalid.

There's no point in having VyOS on a rpi, it's too slow to be useful.

Mar 5 2017, 7:07 PM · Invalid
EwaldvanGeffen added a comment to T284: SSH and load balancing failover not playing nice together.

This is more likely a configuration problem. Did you enable the local-traffic-loadbalancing option and is your SSH traffic handled by any WLB rule (or left untouched?). Also post your routing table when all wan interfaces are up. What is the status of the enable-sticky-connections option? From where do you test your SSH connectivity from (a connected subnet of vyos? a routed-subnet ?)

Mar 5 2017, 2:18 PM

Jan 7 2017

EwaldvanGeffen added a comment to T217: Cron error.

Can you provide the output of /etc/logrotate.conf via a pastebin

Jan 7 2017, 1:03 PM · VyOS 1.1.x (1.1.8)

Dec 21 2016

EwaldvanGeffen marked Q52: Integrate Vyos with standalone web filtering device? (Answer 97) as hidden.
Dec 21 2016, 6:31 PM
EwaldvanGeffen added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@elico if you apply a 'source my-lan-clients, destination port-80, proto tcp' rule with gateway your proxy server + the custom testing-target script. If the proxy is up it will be routed towards it. If the target goes down, without any other policies the packet will fall onto PBR and then routing. Isn't that the behaviour you were looking for?

Dec 21 2016, 6:13 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

Dec 20 2016

EwaldvanGeffen added a comment to Q52: Integrate Vyos with standalone web filtering device?.

Wan-load-balance. Example is here: https://github.com/vyos/vyatta-wanloadbalance/blob/current/scripts/http_test.pl and implementation https://github.com/vyos/vyatta-wanloadbalance/blob/current/templates/load-balancing/wan/interface-health/node.tag/test/node.tag/type/node.def

Dec 20 2016, 11:33 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
EwaldvanGeffen added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@elico it's pretty simple since WLB supports custom tests for gateway/targets. You can simply script it up to that.

Dec 20 2016, 10:26 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
EwaldvanGeffen added a comment to T161: VyOS 1.2 (jessie) testing spreadsheet.

In for a quick meeting. I think one of the major points would be 118; what goes in and what not; this shouldn't take more than 10 minutes, I think.

Dec 20 2016, 8:10 PM · Invalid

Dec 16 2016

EwaldvanGeffen added a comment to T201: Beep When Fully Booted.

I'll start with 1.2 and backport from there if necessary.

Dec 16 2016, 8:19 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
EwaldvanGeffen added a comment to T211: show DHCP issue.

Should be fixed in that same commit if I'm not mistaken as T186 here

Dec 16 2016, 8:16 PM · VyOS 1.1.x
EwaldvanGeffen added a comment to T211: show DHCP issue.

Should be fixed in that same commit if I'm not mistaken as T186 here

Dec 16 2016, 8:16 PM · VyOS 1.1.x
EwaldvanGeffen added a comment to T127: Double quotes in openvpn-option.

@oliveriandrea what happens when you use double-quotes for vyos-config and single-quotes for the statement within? Can you also test out the other possible combinations; eg. "--with-escaping-the \"inner quotes\""; this is just for reference (I agree with @syncer recommendations for now). I would be especially interested in if they are treated differently by the tab-completion feature as IIRC it generates somewhat broken suggestions (vyos@vyos #delete openvpn-opt<tab> .. ).

Dec 16 2016, 8:09 PM · Invalid
EwaldvanGeffen added a comment to T213: Cant set protocols static routes with newer versions of vyos.

Duplicate T194?

Dec 16 2016, 8:00 PM

Dec 11 2016

EwaldvanGeffen added a comment to T201: Beep When Fully Booted.

set system options beep-on-startup

Dec 11 2016, 11:45 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
EwaldvanGeffen created T208: Ability to ignore default-route from dhcpcd per interface.
Dec 11 2016, 10:32 PM · VyOS 1.3 Equuleus (1.3.0-epa1)
EwaldvanGeffen added a comment to T167: "set service ssh allow-root" is not enough to root system-access via ssh.

That's strange because it's exactly what the code does: https://github.com/vyos/vyatta-cfg-system/blob/current/templates/service/ssh/allow-root/node.def

Dec 11 2016, 10:27 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
EwaldvanGeffen closed T207: bridge-utils location as Resolved.

Closed in https://github.com/vyos/vyatta-op/pull/7

Dec 11 2016, 10:20 PM · VyOS 1.1.x (1.1.8)
EwaldvanGeffen created T207: bridge-utils location.
Dec 11 2016, 9:13 PM · VyOS 1.1.x (1.1.8)
EwaldvanGeffen added a comment to T161: VyOS 1.2 (jessie) testing spreadsheet.

Maybe it's interesting to attach the configs to the tested-build data-entry.

Dec 11 2016, 12:39 AM · Invalid

Nov 19 2016

EwaldvanGeffen updated the task description for T193: Kick ISC DHCP-server to a more recent version.
Nov 19 2016, 12:58 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
EwaldvanGeffen created T193: Kick ISC DHCP-server to a more recent version.
Nov 19 2016, 12:58 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
EwaldvanGeffen added a comment to Q56: nDPI integration, what is required?.

I think the next step for this proof-of-concept is to be tried and validated (setup log rules, tcpdump and send in traffic, manually compare counters to dump) then merged into the regular build-process and finally come up with a CLI syntax.

Nov 19 2016, 12:13 AM · VyOS 1.1.x (1.1.8)
EwaldvanGeffen added a comment to T186: DHCP with VRRP.

Could this patch be your solution. I remember there was the duplicate print effect when using DHCP-FO on the entries in the lease file in a specific condition that I've made it to ignore.

Nov 19 2016, 12:09 AM · VyOS 1.1.x (1.1.8)

Nov 9 2016

EwaldvanGeffen added a comment to T186: DHCP with VRRP.

When doing DHCP-FO it's intentional both machines send out a lease. The duplicate 'lease' issue in the show statements should've been resolved in latest versions IIRC. Which version are you running?

Nov 9 2016, 7:09 PM · VyOS 1.1.x (1.1.8)

Sep 26 2016

EwaldvanGeffen added a comment to Q56: nDPI integration, what is required?.

I have used nDPI on CentOS 5 in the past with 'fair' results. The problem is that the makers of nDPI went commercial and their old/OSS package is afair not maintained anymore.

Sep 26 2016, 10:20 PM · VyOS 1.1.x (1.1.8)

Sep 20 2016

EwaldvanGeffen added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@rps I think he needs a more modern version of squid with sslbump support. I wouldn't put any effort in WCCP, it seems fairly legacy to me.

Sep 20 2016, 6:01 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

Sep 17 2016

EwaldvanGeffen created T158: Implement HA-Proxy.
Sep 17 2016, 4:39 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
EwaldvanGeffen added a comment to Q52: Integrate Vyos with standalone web filtering device?.

or do a fallback to another device.

Sep 17 2016, 4:05 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
EwaldvanGeffen added a comment to T103: DHCP server prepends shared network name to hostnames.

I prefer opt-in options over 'enable by proxy'.
use-host-decl-name [no-prefix]
and future get-lease-hostnames?

Sep 17 2016, 4:00 PM · VyOS 1.2 Crux (VyOS 1.2.6)

Sep 15 2016

EwaldvanGeffen added a comment to T103: DHCP server prepends shared network name to hostnames.

Could you provide the contents of "sudo vi /opt/vyatta/etc/dhcpd.conf"? It could be related to previously fixed http://bugzilla.vyos.net/show_bug.cgi?id=334 / Reading into it.

Sep 15 2016, 5:32 PM · VyOS 1.2 Crux (VyOS 1.2.6)
EwaldvanGeffen added a comment to Q52: Integrate Vyos with standalone web filtering device?.

Short answer: not really.

Sep 15 2016, 4:40 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

Sep 11 2016

EwaldvanGeffen added a comment to Q52: Integrate Vyos with standalone web filtering device?.

You would have to forward traffic to your device. Preferably it handles all types of traffic. Otherwise you can forward dport 443 towards a specific IP.

Sep 11 2016, 6:27 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

Sep 1 2016

EwaldvanGeffen added a comment to T103: DHCP server prepends shared network name to hostnames.

From the looks of the script it seems this hostname is coming from the DHCP-server upstream. I wonder if this behaviour is controlable.

Sep 1 2016, 11:40 PM · VyOS 1.2 Crux (VyOS 1.2.6)
EwaldvanGeffen added a comment to T139: Commit archive backends.

FTP/SCP also.

Sep 1 2016, 7:03 PM · VyOS 1.4 Sagitta

Aug 25 2016

EwaldvanGeffen added a comment to T135: Any need to respond to the encryption weakness described in sweet32.io?.

The page you've linked mentioned the fix: don't use legacy ciphers.

Aug 25 2016, 9:12 PM · Rejected

Aug 8 2016

EwaldvanGeffen added a comment to T122: Control over which users have ssh access.

Would this be a setting in the SSH service or rather system login. Because the former allows you to employ wildcards: VYOS-* while the latter feels more correct otherwise. Or you could have both, default the SSHd setting to no-one, and whitelist per user || employ the wildcard solution.

Aug 8 2016, 5:22 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)

Jul 13 2016

EwaldvanGeffen created T104: Hierarchy plugin for mediawiki.
Jul 13 2016, 7:59 PM · Rejected

Jul 4 2016

EwaldvanGeffen closed T58: "monitor firewall name <name>" does not monitor any firewall-log-entry as Resolved.

Merged, closing.

Jul 4 2016, 5:12 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)
EwaldvanGeffen closed T45: VRRP "uninitialized value in printf" on show vrrp interface as Resolved.

Commited into current, separate patch available for 117 users if needed be.

Jul 4 2016, 5:10 PM · VyOS 1.1.x (1.1.8)

Jun 27 2016

EwaldvanGeffen awarded Q7: simple or advanced OVA/OVF distribution? a Like token.
Jun 27 2016, 5:34 PM · VyOS 2.0.x, VyOS 1.1.x

Jun 21 2016

EwaldvanGeffen added a comment to T58: "monitor firewall name <name>" does not monitor any firewall-log-entry.

@mdsmds looks good. I can work with this :) patch

Jun 21 2016, 4:16 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Jun 18 2016

EwaldvanGeffen added a comment to T58: "monitor firewall name <name>" does not monitor any firewall-log-entry.

On which version was this experienced? Cannot reproduce on 1.1.6, 1.1.7 and 1.2. Could you provide the output of sudo iptables-save? Or sudo iptables -t filter -L -nv (includes packet counters and should show you why your traffic is not hitting your log-rule).

Jun 18 2016, 3:40 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc2)

Jun 14 2016

EwaldvanGeffen added a member for VyOS 1.1.x: EwaldvanGeffen.
Jun 14 2016, 9:30 PM
EwaldvanGeffen added a watcher for VyOS 1.1.x: EwaldvanGeffen.
Jun 14 2016, 9:25 PM

Jun 11 2016

EwaldvanGeffen closed T83: Remove autogenerated files from git as Resolved.
Jun 11 2016, 4:08 PM · Python Management Library

Jun 6 2016

EwaldvanGeffen added a comment to T81: Incomplete autocompletion (ends after "delete protocols").

I'm telling you I cannot reproduce on 115,116 and 117.

pasted_file (962×661 px, 61 KB)

Jun 6 2016, 6:17 PM · Rejected

Jun 5 2016

EwaldvanGeffen added a comment to T81: Incomplete autocompletion (ends after "delete protocols").

Can it be you have two protocol children entries and didn't tab twice? [cannot-confirm]

Jun 5 2016, 5:24 PM · Rejected

Jun 2 2016

EwaldvanGeffen created T78: A development VM.
Jun 2 2016, 9:57 PM · Invalid

Jun 1 2016

EwaldvanGeffen added a comment to T75: NetFlow have impact on performance.

I think we can choose how to implement it. We can apply it as a default entry in one of the vyos chains or let the user-decide. The advantage with the latter is that both implementations can co-exist for a while. With the former solution I would remove the old implementation to not confuse the user.

Jun 1 2016, 5:18 PM · VyOS 1.3 Equuleus (1.3.7)

May 25 2016

EwaldvanGeffen added a comment to T71: Add virtual IP and route installation policy options for IPsec.

abferm, could you work out which other settings would be typically employed w/ a syntax proposal. This way we would implement all at once (saving time).

May 25 2016, 7:08 PM · Restricted Project, VyOS 1.4 Sagitta