Page MenuHomeVyOS Platform

NikolayP (Nikolay P)
User

Projects

User Details

User Since
Sep 3 2021, 9:24 AM (20 w, 3 d)

Recent Activity

Today

NikolayP updated the task description for T4072: Feature Request: Firewall on bridge interfaces.
Mon, Jan 24, 5:29 AM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta
NikolayP added a comment to T4196: DHCP server client-prefix-length parameter results in non-functional leases.

PR for 1.3:
https://github.com/vyos/vyos-1x/pull/1187

Mon, Jan 24, 1:46 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)

Thu, Jan 20

NikolayP added a comment to T4196: DHCP server client-prefix-length parameter results in non-functional leases.

PR:
https://github.com/vyos/vyos-1x/pull/1180/files

Thu, Jan 20, 12:07 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
NikolayP added a comment to T4196: DHCP server client-prefix-length parameter results in non-functional leases.

From ISC-DHCP manual pages:
https://kb.isc.org/docs/isc-dhcp-44-manual-pages-dhcp-options

Thu, Jan 20, 4:38 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
NikolayP updated the task description for T4196: DHCP server client-prefix-length parameter results in non-functional leases.
Thu, Jan 20, 4:22 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
NikolayP created T4196: DHCP server client-prefix-length parameter results in non-functional leases.
Thu, Jan 20, 4:11 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)

Wed, Jan 19

NikolayP created T4194: prefix-list no check for duplicate entries.
Wed, Jan 19, 2:00 AM · VyOS 1.4 Sagitta

Sat, Jan 15

NikolayP closed T4150: VRRP with conntrack-sync does not work as Resolved.

Re-tested in VyOS 1.4-rolling-202201140317
Now it works, thank you!

Sat, Jan 15, 12:45 AM · VyOS 1.4 Sagitta

Fri, Jan 14

NikolayP updated the task description for T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.
Fri, Jan 14, 10:01 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
NikolayP renamed T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses from NTP allow-clients address requires a reboot to NTP allow-clients address doesn't work.
Fri, Jan 14, 9:55 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
NikolayP updated the task description for T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.
Fri, Jan 14, 4:42 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
NikolayP created T4184: NTP allow-clients address doesn't work it allows to use ntp server for all addresses.
Fri, Jan 14, 4:35 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Wed, Jan 12

NikolayP added a comment to T4100: Firewall increase maximum number of rules.

PR:
https://github.com/vyos/vyatta-cfg-firewall/pull/29/commits

Wed, Jan 12, 5:46 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Mon, Jan 10

NikolayP added a comment to T4100: Firewall increase maximum number of rules.

In 1.3 (VyOS 1.3-rolling-202201030317) the rules are handled correctly (except for the numbers in description).

Mon, Jan 10, 12:35 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Sun, Jan 9

NikolayP added a comment to T4100: Firewall increase maximum number of rules.

Tested in VyOS 1.3-rolling-202201030317 & 1.4-rolling-202201070726

Sun, Jan 9, 3:50 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Sat, Jan 8

NikolayP added a comment to T4150: VRRP with conntrack-sync does not work.

The situation has not changed in VyOS 1.4-rolling-202201070726

Sat, Jan 8, 4:36 AM · VyOS 1.4 Sagitta

Fri, Jan 7

NikolayP created T4150: VRRP with conntrack-sync does not work.
Fri, Jan 7, 8:08 AM · VyOS 1.4 Sagitta
NikolayP closed T3924: VRRP stops working with VRF as Resolved.

Tested in VyOS 1.4-rolling-202201060842
Works

Fri, Jan 7, 1:30 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Mon, Jan 3

NikolayP added a comment to T4081: VRRP health-check script stops working when setting up a sync group.

Checked in 1.3-rolling-202201030317, health-check works

Mon, Jan 3, 7:44 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Fri, Dec 31

NikolayP created T4125: Feature Request: bridge STP BPDU translation.
Fri, Dec 31, 3:56 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)

Tue, Dec 28

NikolayP added a comment to T4087: IPsec IKE-group proposals limit of 10 pieces .

PR for 1.2:
https://github.com/vyos/vyatta-cfg-vpn/pull/55

Tue, Dec 28, 6:43 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
NikolayP added a comment to T4087: IPsec IKE-group proposals limit of 10 pieces .

PR for 1.3:
https://github.com/vyos/vyatta-cfg-vpn/pull/54

Tue, Dec 28, 6:35 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus

Mon, Dec 27

NikolayP added a comment to T4100: Firewall increase maximum number of rules.

@Viacheslav thank you so much for your help!

Mon, Dec 27, 8:35 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
NikolayP added a comment to T4100: Firewall increase maximum number of rules.

PR for 1.4:
https://github.com/vyos/vyatta-cfg-firewall/pull/28

Mon, Dec 27, 8:08 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
NikolayP added a comment to T4100: Firewall increase maximum number of rules.

PR for 1.3:
https://github.com/vyos/vyatta-cfg-firewall/pull/27

Mon, Dec 27, 6:58 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
NikolayP updated the task description for T4100: Firewall increase maximum number of rules.
Mon, Dec 27, 6:56 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Dec 25 2021

NikolayP reopened T2764: Increase maximum number of NAT rules as "Confirmed".

In 1.3.0 the limitation remains

Dec 25 2021, 6:07 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
NikolayP created T4100: Firewall increase maximum number of rules.
Dec 25 2021, 6:01 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Dec 23 2021

NikolayP updated subscribers of T4081: VRRP health-check script stops working when setting up a sync group.
Dec 23 2021, 4:34 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Dec 22 2021

NikolayP changed the subtype of T4081: VRRP health-check script stops working when setting up a sync group from "Task" to "Bug".
Dec 22 2021, 10:11 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
NikolayP changed the status of T4081: VRRP health-check script stops working when setting up a sync group from Backport candidate to Confirmed.
Dec 22 2021, 10:05 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
NikolayP changed the status of T4081: VRRP health-check script stops working when setting up a sync group from Confirmed to Backport candidate.

Duplicate PR:
https://github.com/vyos/vyos-1x/pull/1118
Request revoked

Dec 22 2021, 10:00 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Dec 20 2021

NikolayP updated subscribers of T4087: IPsec IKE-group proposals limit of 10 pieces .

@Viacheslav found the source of the restriction:

Dec 20 2021, 6:30 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
NikolayP created T4087: IPsec IKE-group proposals limit of 10 pieces .
Dec 20 2021, 2:51 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus

Dec 17 2021

NikolayP added a comment to T4081: VRRP health-check script stops working when setting up a sync group.

Didn't notice this message, thanks!
Maybe we should add a corresponding sync_group command to the CLI?

Dec 17 2021, 3:30 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Dec 16 2021

NikolayP created T4081: VRRP health-check script stops working when setting up a sync group.
Dec 16 2021, 6:39 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
NikolayP added a comment to T4080: Space in "description" commands.

Have you tried writing the description with spaces in quotes?
Something like this:

Dec 16 2021, 4:12 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)

Dec 14 2021

NikolayP created T4072: Feature Request: Firewall on bridge interfaces.
Dec 14 2021, 6:56 AM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta

Dec 10 2021

NikolayP added a comment to T4059: VRRP sync-group transition script does not persist after reboot.

Looks like the issue is persistent.
Tested on VyOS 1.3-beta-202112080938
Reboot VyOS (first one, wait for it to load. Then the other one)
'transition-script master' script doesn't start

Dec 10 2021, 1:16 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)

Dec 7 2021

NikolayP closed T4041: "transition-script" doesn't work on "sync-group" as Resolved.

There is a task with VRRP scripts problem on reboot:

Dec 7 2021, 12:34 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus

Dec 6 2021

NikolayP added a comment to T4033: VRRP - Error security when setting scripts.

PR:
https://github.com/vyos/vyos-1x/pull/1098

Dec 6 2021, 11:54 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Nov 25 2021

NikolayP closed T4005: Feature Request: IPsec IKEv1 + IKEv2 for one peer as Resolved.
Nov 25 2021, 2:58 AM · VyOS 1.3 Equuleus (1.3.0-epa3)

Nov 20 2021

NikolayP closed T4004: IPsec ike-group parameters are not saved correctly (after reboot) as Resolved.
Nov 20 2021, 9:39 AM · VyOS 1.3 Equuleus (1.3.0-epa3)
NikolayP added a comment to T4004: IPsec ike-group parameters are not saved correctly (after reboot).

A feature request was made with a change in behavior:
https://phabricator.vyos.net/T4005
(Feature Request: IPsec IKEv1 + IKEv2 for one peer)

Nov 20 2021, 9:39 AM · VyOS 1.3 Equuleus (1.3.0-epa3)
NikolayP added a comment to T4005: Feature Request: IPsec IKEv1 + IKEv2 for one peer.

pool request:
https://github.com/vyos/vyatta-cfg-vpn/pull/51
Create an Ike-group without a command "key-exchange" (like in VyOS 1.4):

Nov 20 2021, 9:32 AM · VyOS 1.3 Equuleus (1.3.0-epa3)

Nov 18 2021

NikolayP created T4005: Feature Request: IPsec IKEv1 + IKEv2 for one peer.
Nov 18 2021, 4:30 AM · VyOS 1.3 Equuleus (1.3.0-epa3)
NikolayP created T4004: IPsec ike-group parameters are not saved correctly (after reboot).
Nov 18 2021, 3:53 AM · VyOS 1.3 Equuleus (1.3.0-epa3)

Nov 17 2021

NikolayP created T4002: firewall group network-group long names restriction incorrect behavior.
Nov 17 2021, 12:45 PM · VyOS 1.3 Equuleus (1.3.0-epa3)
NikolayP created T4001: Feature Request: IPsec transport mode. VyOS can not use local-subnet or remote-subnet when using transport mode.
Nov 17 2021, 11:39 AM · VyOS 1.3 Equuleus (1.3.0-epa3)

Nov 13 2021

NikolayP renamed T3988: Feature Request: IPsec Multiple local/remote prefix for the tunnel from Feature Request: IPsec Multiple local prefix for the tunnel to Feature Request: IPsec Multiple local/remote prefix for the tunnel.
Nov 13 2021, 6:33 AM · VyOS 1.3 Equuleus (1.3.0-epa3)
NikolayP created T3988: Feature Request: IPsec Multiple local/remote prefix for the tunnel.
Nov 13 2021, 6:27 AM · VyOS 1.3 Equuleus (1.3.0-epa3)

Nov 6 2021

NikolayP created T3973: Feature Request: Multicast ping. Change TTL in Echo-reply from VyOS.
Nov 6 2021, 3:38 AM · VyOS 1.4 Sagitta

Nov 4 2021

NikolayP created T3967: Feature Request: BGP conditional advertisement.
Nov 4 2021, 5:34 AM

Nov 2 2021

NikolayP added a comment to T3959: MPLS L3VPN IPv6 address-family over IPv4 MPLS backbone.

Mentioned here (FRRouting):
BGP vpnv6 next hop address maybe error?

Nov 2 2021, 8:23 AM · VyOS 1.4 Sagitta
NikolayP created T3959: MPLS L3VPN IPv6 address-family over IPv4 MPLS backbone.
Nov 2 2021, 8:07 AM · VyOS 1.4 Sagitta

Oct 30 2021

NikolayP changed the status of T3952: Add sh bgp ipv4/ipv6 vpn command from In progress to Needs testing.
Oct 30 2021, 9:34 AM · VyOS 1.4 Sagitta

Oct 29 2021

NikolayP changed the status of T3952: Add sh bgp ipv4/ipv6 vpn command from Open to In progress.
Oct 29 2021, 7:01 AM · VyOS 1.4 Sagitta
NikolayP added a comment to T3952: Add sh bgp ipv4/ipv6 vpn command.

PR https://github.com/vyos/vyos-1x/pull/1051

Oct 29 2021, 6:49 AM · VyOS 1.4 Sagitta
NikolayP created T3952: Add sh bgp ipv4/ipv6 vpn command.
Oct 29 2021, 6:31 AM · VyOS 1.4 Sagitta

Oct 26 2021

NikolayP added a comment to T3944: VRRP fails over when adding new group to master.

It seems to be because of the keepalived reloading at "commit".

Oct 26 2021, 1:36 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.4 Sagitta
NikolayP changed the status of T3944: VRRP fails over when adding new group to master from Open to Confirmed.
Oct 26 2021, 1:32 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.4 Sagitta

Oct 25 2021

NikolayP changed the status of T3924: VRRP stops working with VRF from Open to Confirmed.
Oct 25 2021, 10:44 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Oct 21 2021

NikolayP created T3924: VRRP stops working with VRF.
Oct 21 2021, 12:12 PM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Oct 19 2021

NikolayP added a comment to T3910: Hairpin NAT Not Functioning Correctly.

Of course, external services with the same port is not available
This is what you should expect from NAT rules (110)
Works exactly as configured

Oct 19 2021, 12:59 AM · Rejected

Oct 17 2021

NikolayP added a comment to T3910: Hairpin NAT Not Functioning Correctly.

WAN interface is eth2. It set to DHCP
LAN interface is eth3. It set to static address

Oct 17 2021, 12:31 PM · Rejected
NikolayP added a comment to T3910: Hairpin NAT Not Functioning Correctly.

Tested on VyOS 1.3.0-epa1

Oct 17 2021, 6:08 AM · Rejected

Oct 16 2021

NikolayP added a comment to T2787: OSPF auto-cost reference-bandwidth bandwidth command support.

Tested in VyOS 1.2.8, VyOS 1.3.0-epa1, VyOS 1.4-rolling-202109190558

Oct 16 2021, 12:53 PM · VyOS 1.3 Equuleus
NikolayP added a comment to T3851: Missing ospf and rip options for bridge vifs.

Tested in VyOS 1.3.0-epa1 & VyOS 1.4-rolling-202109190558

Oct 16 2021, 9:18 AM · VyOS 1.3 Equuleus
NikolayP added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

Tested on VyOS 1.3.0-epa1.
Confirm IBGP reflection to non-RR-Client
Lab Topology:


RR1 & RR2 -route reflectors
P 3 - RR-Client for RR1 & RR2
P1 - IBGP peering with RR1 only
OSPF-core router - only for core network
Result: P1 gets P 3 routes fron RR1:
vyos@VyOS-P1:~$ sh ip bgp neighbors 10.0.0.1 received-routes
*> 10.0.0.201/32 10.0.0.3 0 100 100 i
*> 10.0.0.202/32 10.0.0.3 0 100 100 i
*> 192.168.3.0/24 10.0.0.3 0 100 100 i

Oct 16 2021, 3:02 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Oct 15 2021

NikolayP added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

@francis Sorry, I don't understand the problem.
Agree that route received from one IBGP peer should not be forwarded to another IBGP peer. Except for the RR client.

Oct 15 2021, 2:58 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
NikolayP added a comment to T3892: BGP Route Reflects to all neighbors when one neighbor has route-reflect-client.

If Cluster ID is not used, full IBGP mesh must be used. Exception is RR client, they should only have peering with RR.
Router 10.0.0.21 has no peering with 10.0.0.3.
This is incorrect IBGP design.

Oct 15 2021, 1:42 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Oct 8 2021

NikolayP added a comment to T3090: Move 'adjust-mss' firewall options to the interface section..

Perhaps the command should be changed a bit
MSS is a property of the TCP protocol, not IP:

Oct 8 2021, 12:23 PM · VyOS 1.4 Sagitta

Oct 4 2021

NikolayP added a comment to T3887: Removal of IPv6 BGP-peer with peer-group may trigger problems.

Acknowledged. Tested on 1.3.0-epa1

Oct 4 2021, 1:02 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux

Sep 19 2021

NikolayP added a comment to T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0.

Tested in vyos-1.4-rolling-202109190558,
works

Sep 19 2021, 12:58 PM · VyOS 1.4 Sagitta

Sep 15 2021

NikolayP updated the task description for T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0.
Sep 15 2021, 9:13 AM · VyOS 1.4 Sagitta
NikolayP updated the task description for T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0.
Sep 15 2021, 9:12 AM · VyOS 1.4 Sagitta
NikolayP created T3831: External traffic stops routing when IPSEC tunnel comes up with interface vti0.
Sep 15 2021, 8:43 AM · VyOS 1.4 Sagitta

Sep 9 2021

NikolayP added a comment to T2326: Migrate NHRP(DMVPN) to FRR.

Cisco Auth is a necessity for those who want to migrate from this vendor's hardware to VyOS. You can easily add a VyOS node to an existing DMVPN.

Sep 9 2021, 8:57 AM · VyOS 1.3 Equuleus (1.3.0)