c-po (Christian Poessinger)
User

Projects

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Wednesday

  • Clear sailing ahead.

User Details

User Since
Aug 3 2017, 1:55 PM (15 w, 4 d)
Availability
Available

Recent Activity

Today

c-po added a comment to T452: WiFi: Enable support for 5GHz AccesPoints with DFS.

@alainlamar Unfortunately I have some problems with APT building my ISO but I added the steps for you here: https://wiki.vyos.net/wiki/Rebuild_VyOS_kernel_Step#VyOS_1.2.x

Mon, Nov 20, 9:45 AM · VyOS 1.2.x

Yesterday

c-po added a comment to T452: WiFi: Enable support for 5GHz AccesPoints with DFS.

@alainlamar would you be willing to test a special image with all your required changes inside (Kernel, hostapd, firmware-atheros)? Only extension of vyatta-wireless is missing, but looks you could do this "on the fly"?

Sun, Nov 19, 1:56 PM · VyOS 1.2.x
c-po added a comment to T452: WiFi: Enable support for 5GHz AccesPoints with DFS.

I can confirm that by using this approach we can have hostapd 2.4 from debian stretch

Sun, Nov 19, 1:43 PM · VyOS 1.2.x

Sat, Nov 18

c-po added a comment to T380: Add system service fail2ban.

Closed b/c I wanted to rewrite it using vyos-1x command package.

Sat, Nov 18, 8:06 AM · VyOS 1.2.x

Wed, Nov 15

c-po added a comment to T461: Central user/key management through JumpCloud.

Thanks for this feature request. I'm not to happy having a cloud provider install some SSH keys onto my system. If you have to manage many VyOS machines, why not use Ansible?

Wed, Nov 15, 9:50 AM · VyOS 1.2.x

Tue, Nov 14

c-po added a comment to T452: WiFi: Enable support for 5GHz AccesPoints with DFS.

Possibly http://debian-live.alioth.debian.org/live-manual/stable/manual/html/live-manual.en.html#apt-pinning will do the trick. I will start a test build...

Tue, Nov 14, 7:11 PM · VyOS 1.2.x

Mon, Nov 13

c-po added a comment to T452: WiFi: Enable support for 5GHz AccesPoints with DFS.

@alainlamar thank you very much for providing such detailed information e.g. what is required inside the kernel configuration. This seems to be not a big deal to enable those.

Mon, Nov 13, 6:05 PM · VyOS 1.2.x

Sun, Nov 12

c-po added a comment to T434: RADIUS as l2tp vpn authentication mode is broken.
Sun, Nov 12, 3:57 PM · VyOS 1.2.x

Wed, Nov 8

c-po added a comment to T281: Add https support to the load command..

@afics @syncer done, will be in the next nightly build

Wed, Nov 8, 10:15 AM · VyOS 1.2.x

Tue, Nov 7

c-po updated subscribers of T426: CVE-2017-13077 - Update wpa_supplicant.

This did the trick. Just build a fresh ISO:

Tue, Nov 7, 8:52 PM · wpa, VyOS 1.2.x, VyOS 1.1.x
c-po updated subscribers of T426: CVE-2017-13077 - Update wpa_supplicant.

@UnicronNL maybe this will fix this issue:

Tue, Nov 7, 7:08 AM · wpa, VyOS 1.2.x, VyOS 1.1.x

Fri, Nov 3

c-po added a comment to T426: CVE-2017-13077 - Update wpa_supplicant.

Our nightly builds ships wpasupplicant 2.3-1+deb8u4, according to https://www.debian.org/security/2017/dsa-3999 it's fixed in 2.3-1+deb8u5.

Fri, Nov 3, 4:52 PM · wpa, VyOS 1.2.x, VyOS 1.1.x
c-po added a comment to T281: Add https support to the load command..

@syncer https://github.com/vyos/vyatta-cfg/pull/9

Fri, Nov 3, 1:59 PM · VyOS 1.2.x
c-po added a comment to T154: monitor feature strange message.

Using a self build ISO: VyOS 999.201710291829 I can confirm this.

Fri, Nov 3, 1:42 PM · VyOS 1.2.x
c-po added a comment to T285: Add flag for DNSmasq to query all dns servers.

implemented 11/2016
https://github.com/vyos/vyatta-cfg-system/commit/4a03838ea877a3a867b283ba85956795e769d563

Fri, Nov 3, 12:45 PM · VyOS 1.2.x
c-po added a comment to T370: lldpctl: invalid option 'L'.

This regression is fixed. @syncer should we resolve it?

Fri, Nov 3, 12:27 PM · vyatta-lldp, lldpd, VyOS 1.2.x
c-po closed T438: System option "Send anonymous system statistic to VyOS maintainers" broken as Wontfix.
Fri, Nov 3, 12:24 PM · VyOS 1.2.x
c-po closed T437: System option "Ctrl-Alt-Delete action" broken as Resolved.
Fri, Nov 3, 12:23 PM · VyOS 1.2.x
c-po closed T436: System option "Reboot system on kernel panic" broken as Invalid.
Fri, Nov 3, 12:23 PM · VyOS 1.2.x
c-po added a comment to T436: System option "Reboot system on kernel panic" broken.

False positive as a previous command was failing.

Fri, Nov 3, 8:03 AM · VyOS 1.2.x
c-po added a comment to T157: Remove "install system" command.

Isn't it the scenario for which all those people in debian have used package manager for decades? Isn't it better to just update one package in installed system?

Fri, Nov 3, 8:01 AM · VyOS 1.2.x
c-po added a comment to T437: System option "Ctrl-Alt-Delete action" broken.

Fixed in https://github.com/vyos/vyatta-cfg-system/pull/65

Fri, Nov 3, 7:57 AM · VyOS 1.2.x
c-po added a comment to T438: System option "Send anonymous system statistic to VyOS maintainers" broken.

Removed in https://github.com/vyos/vyatta-cfg-system/pull/65

Fri, Nov 3, 7:56 AM · VyOS 1.2.x

Thu, Nov 2

c-po updated subscribers of T438: System option "Send anonymous system statistic to VyOS maintainers" broken.

This action installs the following cronjob:

sudo sh -c 'echo "#!/bin/sh" > /etc/cron.weekly/01vyos-popcon'
sudo sh -c 'echo "/opt/vyatta/bin/vyos-popcon.pl 2>&1 >/var/log/popcon.log" >> /etc/cron.weekly/01vyos-popcon'
sudo sh -c 'chmod +x /etc/cron.weekly/01vyos-popcon'
Thu, Nov 2, 3:36 PM · VyOS 1.2.x
c-po updated subscribers of T414: Service telnet doesn't start.

@dmbaturin @UnicronNL what‘s your opinion?

Thu, Nov 2, 9:29 AM · VyOS 1.2.x

Mon, Oct 30

c-po added a comment to T440: VTI/IPSec with dynamic peer.

Do we know why it‘s not possible? Is it due to a missing configuration option in VyOS or is it due to non availability in the underlying Linux Components e.g. Strongswan?

Mon, Oct 30, 3:57 PM · VyOS 1.2.x

Sun, Oct 29

c-po added a comment to T328: review output for show tech-support command.

@syncer @dmbaturin https://github.com/vyos/vyatta-op/pull/12

Sun, Oct 29, 3:56 PM · VyOS 1.2.x
c-po created T438: System option "Send anonymous system statistic to VyOS maintainers" broken.
Sun, Oct 29, 2:17 PM · VyOS 1.2.x
c-po renamed T437: System option "Ctrl-Alt-Delete action" broken from System option "set system options ctrl-alt-del-action" broken to System option "Ctrl-Alt-Delete action" broken.
Sun, Oct 29, 2:16 PM · VyOS 1.2.x
c-po created T437: System option "Ctrl-Alt-Delete action" broken.
Sun, Oct 29, 2:15 PM · VyOS 1.2.x
c-po created T436: System option "Reboot system on kernel panic" broken.
Sun, Oct 29, 2:14 PM · VyOS 1.2.x

Fri, Oct 27

c-po added a comment to T434: RADIUS as l2tp vpn authentication mode is broken.

On VyOS 1.1.7 we have /etc/radiusclient-ng/dictionary.merit which moved to /usr/share/freeradius/dictionary.merit on VyOS 1.2.x.

Fri, Oct 27, 6:19 PM · VyOS 1.2.x
c-po updated the task description for T434: RADIUS as l2tp vpn authentication mode is broken.
Fri, Oct 27, 4:39 PM · VyOS 1.2.x
c-po created T434: RADIUS as l2tp vpn authentication mode is broken.
Fri, Oct 27, 4:37 PM · VyOS 1.2.x

Thu, Oct 26

c-po updated subscribers of T14: Provide VMware OVF and OVA.

@TomekC @syncer just wondering ... should we maybe add those commands to VyOS CLI?

Thu, Oct 26, 5:44 PM · VyOS 1.2.x

Wed, Oct 25

c-po added a comment to T14: Provide VMware OVF and OVA.

Thank you for the effort. I always liked the VMWare template installation. I also tried it for VyOS 1.2.x on ESXi 6.5. I followed the WiKi instructions which worked like a charm!

Wed, Oct 25, 6:34 PM · VyOS 1.2.x

Mon, Oct 23

c-po added a comment to T328: review output for show tech-support command.

Vote for 1.2.x only.

Mon, Oct 23, 5:14 PM · VyOS 1.2.x

Oct 13 2017

c-po added a comment to T337: 'show vpn ipsec sa' output wrong when remote or local prefix not in system subnet.

@syncer this was actually done by @JulesT. Thank you @JulesT.

Oct 13 2017, 7:41 AM · VyOS 1.2.x

Oct 10 2017

c-po added a comment to T414: Service telnet doesn't start.

BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. That means there is just a single BusyBox binary, but that single binary acts like a large number of utilities. This allows BusyBox to be smaller since all the built-in utility programs (we call them applets) can share code for many common operations.

Oct 10 2017, 2:33 AM · VyOS 1.2.x

Oct 9 2017

c-po added a comment to T414: Service telnet doesn't start.

+1 for removal

Oct 9 2017, 2:58 PM · VyOS 1.2.x
c-po added a comment to T414: Service telnet doesn't start.

As VyOS fully re-uses Debian packages it is not possible to enable any given applet inside Busybox. To get this enabled, VyOS has to maintain a forked version of the Debian busybox packages which makes life only harder.

Oct 9 2017, 2:29 AM · VyOS 1.2.x

Sep 20 2017

c-po added a comment to T386: VyOS boot grub timeout in beta image?.
cpo@AC1:~$ cat /boot/grub/grub.cfg | grep timeout
set timeout=5
Sep 20 2017, 7:45 PM · VyOS 1.2.x
c-po updated subscribers of T386: VyOS boot grub timeout in beta image?.

@syncer @dmbaturin @UnicronNL is there any reason to not implement this? I think this should be doable in less then two hours.

Sep 20 2017, 7:38 PM · VyOS 1.2.x
c-po added a comment to T370: lldpctl: invalid option 'L'.

@kingrvbee this is not entirely correct. The problem comes from package vyos-1x which now holds the lldp configuration nodes. @dmbaturin is aware of this and wanted to fix it. Please be patient.

Sep 20 2017, 7:30 AM · vyatta-lldp, lldpd, VyOS 1.2.x

Sep 16 2017

c-po added a comment to T370: lldpctl: invalid option 'L'.

Please also see T393

Sep 16 2017, 10:50 AM · vyatta-lldp, lldpd, VyOS 1.2.x

Sep 15 2017

c-po added a comment to T379: UDP Broadcast Packet Relay.

@mickvav Interesting Idea, I should give it a try ...

Sep 15 2017, 12:58 PM · VyOS 1.2.x
c-po added a comment to T379: UDP Broadcast Packet Relay.

@Asteroza this program forwards UDP packets (Layer 3) on specific ports. Unfortunately WoL is Layer 2 based.

Sep 15 2017, 12:57 PM · VyOS 1.2.x

Sep 12 2017

c-po added a comment to T389: Virtio SCSI is missing in kernel.

I can verify that it now also boots on OVH.net VPS.

Sep 12 2017, 8:53 PM · VyOS 1.1.x (1.1.8), VyOS 1.2.x
c-po added a comment to T366: SNMP Query for BGP Tunnels Returns IPv4 Tunnels Only.

@babak that would be awesome as I do not have any IPv6 BGP connectivity. I created a temporary SSH key for this, could you please create a user cpo:

Sep 12 2017, 5:33 PM · VyOS 1.2.x

Sep 10 2017

c-po added a comment to T386: VyOS boot grub timeout in beta image?.

I guess that you are referring to the installation of VyOS, as a proper installed system will automatically boot up. At least last nights build does.

Sep 10 2017, 8:05 PM · VyOS 1.2.x
c-po added a comment to T389: Virtio SCSI is missing in kernel.

Maybe this is the reason why we also can't boot a VyOS instance on VPSs rentet from OVH.net

Sep 10 2017, 7:53 PM · VyOS 1.1.x (1.1.8), VyOS 1.2.x
c-po added a comment to T379: UDP Broadcast Packet Relay.

Well I think porting this to vyos-1x package would be a good lesson to learn the new system. Let me have a look...

Sep 10 2017, 1:18 PM · VyOS 1.2.x

Sep 8 2017

c-po added a comment to T379: UDP Broadcast Packet Relay.

@dmbaturin You have some good points. Using "service" to start/stop a daemon should be the weapon of choice now. This could/should be changed to have a consitent system, but this inital commit is just a 1:1 EdgeOS copy.

Sep 8 2017, 4:26 PM · VyOS 1.2.x
c-po closed T345: Can't delete vti interface due to incorrect directory name in /proc as Resolved by committing Restricted Diffusion Commit.
Sep 8 2017, 10:32 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)

Sep 7 2017

c-po reassigned T345: Can't delete vti interface due to incorrect directory name in /proc from c-po to syncer.
Sep 7 2017, 12:22 PM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
c-po assigned T380: Add system service fail2ban to syncer.
Sep 7 2017, 12:22 PM · VyOS 1.2.x
c-po assigned T370: lldpctl: invalid option 'L' to syncer.
Sep 7 2017, 12:21 PM · vyatta-lldp, lldpd, VyOS 1.2.x

Sep 4 2017

c-po added a comment to T328: review output for show tech-support command.

@syncer: Thinking about it I have a different proposal:

Sep 4 2017, 7:04 PM · VyOS 1.2.x
c-po added a comment to T366: SNMP Query for BGP Tunnels Returns IPv4 Tunnels Only.

I think as not everybody has access to an IPv6 BGP router, a ro SNMP community for testing would be good. Even better would be a virtual instance to develop a fix for this problem.

Sep 4 2017, 5:35 PM · VyOS 1.2.x

Sep 3 2017

c-po added a comment to T382: IPv6 rapid deployment.

Looks to me that you are mixing up two things. 6rd (Radpid Deployment) is used for ISPs to connect the customers to the IPv6 world (https://en.wikipedia.org/wiki/IPv6_rapid_deployment).

Sep 3 2017, 7:15 PM · VyOS 1.2.x
c-po moved T379: UDP Broadcast Packet Relay from In Progress to Finished on the VyOS 1.2.x board.
Sep 3 2017, 4:26 PM · VyOS 1.2.x
c-po added a comment to T379: UDP Broadcast Packet Relay.

@UnicronNL https://github.com/vyos/vyos-build/pull/11

Sep 3 2017, 4:17 PM · VyOS 1.2.x
c-po reopened T378: mDNS/bonjour forwarding as "In progress".
Sep 3 2017, 2:00 PM · VyOS 1.2.x
c-po closed T378: mDNS/bonjour forwarding as Resolved.
Sep 3 2017, 1:59 PM · VyOS 1.2.x
c-po moved T378: mDNS/bonjour forwarding from In Progress to Finished on the VyOS 1.2.x board.
Sep 3 2017, 1:59 PM · VyOS 1.2.x
c-po updated subscribers of T378: mDNS/bonjour forwarding.

@syncer @dmbaturin Pull requests ready: https://github.com/vyos/vyos-build/pull/10

Sep 3 2017, 10:07 AM · VyOS 1.2.x
c-po reopened T380: Add system service fail2ban as "In progress".
Sep 3 2017, 10:04 AM · VyOS 1.2.x
c-po closed T380: Add system service fail2ban as Resolved.
Sep 3 2017, 10:04 AM · VyOS 1.2.x
c-po updated subscribers of T380: Add system service fail2ban.

@syncer @dmbaturin Please pull https://github.com/vyos/vyatta-cfg-system/pull/60 and https://github.com/vyos/vyos-build/pull/9

Sep 3 2017, 10:03 AM · VyOS 1.2.x
c-po moved T380: Add system service fail2ban from Need Triage to In Progress on the VyOS 1.2.x board.
Sep 3 2017, 9:51 AM · VyOS 1.2.x
c-po added a comment to T176: Kernel: CVE-2016-5195.

Tag VyOS 1.2.x should be removed as CVE is already fixed.

Sep 3 2017, 9:17 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
c-po changed the status of T378: mDNS/bonjour forwarding from Open to In progress.
Sep 3 2017, 8:10 AM · VyOS 1.2.x
c-po added a comment to T378: mDNS/bonjour forwarding.

Verified using iOS 10.3.3 accross VLANs. mDNS services like Airplay working.

Sep 3 2017, 8:09 AM · VyOS 1.2.x
c-po moved T345: Can't delete vti interface due to incorrect directory name in /proc from Need Triage to In Progress on the VyOS 1.2.x board.
Sep 3 2017, 8:00 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
c-po changed the status of T345: Can't delete vti interface due to incorrect directory name in /proc from Open to In progress.
Sep 3 2017, 7:59 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
c-po moved T370: lldpctl: invalid option 'L' from Need Triage to In Progress on the VyOS 1.2.x board.
Sep 3 2017, 7:56 AM · vyatta-lldp, lldpd, VyOS 1.2.x
c-po moved T378: mDNS/bonjour forwarding from Need Triage to In Progress on the VyOS 1.2.x board.
Sep 3 2017, 7:56 AM · VyOS 1.2.x
c-po moved T379: UDP Broadcast Packet Relay from Need Triage to In Progress on the VyOS 1.2.x board.
Sep 3 2017, 7:56 AM · VyOS 1.2.x

Sep 2 2017

c-po updated subscribers of T379: UDP Broadcast Packet Relay.

@UnicronNL could you please mirror https://github.com/c-po/vyos-bcast-relay.git to https://github.com/vyos/vyos-bcast-relay.git and set up a CI job? After this I can submit the appropriate merge requests for vyos-world abd vyos-build.

Sep 2 2017, 10:17 PM · VyOS 1.2.x
c-po updated subscribers of T378: mDNS/bonjour forwarding.

@UnicronNL could you please mirrir https://github.com/c-po/vyos-cfg-avahi to https://github.com/vyos/vyos-cfg-avahi and set up a CI job? After this I can submit the appropriate merge requests for vyos-world abd vyos-build.

Sep 2 2017, 9:44 PM · VyOS 1.2.x
c-po added a comment to T378: mDNS/bonjour forwarding.

Status can be seen here: https://github.com/c-po/vyatta-cfg-avahi

Sep 2 2017, 7:38 PM · VyOS 1.2.x
c-po updated the task description for T380: Add system service fail2ban.
Sep 2 2017, 5:22 PM · VyOS 1.2.x
c-po created T380: Add system service fail2ban.
Sep 2 2017, 5:22 PM · VyOS 1.2.x
c-po added a comment to T110: Ability to store SSH keys out of the config.

Actually I like the fact to have the users SSH pub key inside the config. This makes it super handy to just copy/paste a users config entry arround VyOS instances.

Sep 2 2017, 4:58 PM · VyOS 1.2.x, VyOS 2.0.x
c-po changed Difficulty level from unknown to normal on T379: UDP Broadcast Packet Relay.
Sep 2 2017, 10:26 AM · VyOS 1.2.x
c-po created T379: UDP Broadcast Packet Relay.
Sep 2 2017, 10:26 AM · VyOS 1.2.x
c-po changed Difficulty level from unknown to normal on T378: mDNS/bonjour forwarding.
Sep 2 2017, 10:21 AM · VyOS 1.2.x
c-po created T378: mDNS/bonjour forwarding.
Sep 2 2017, 10:21 AM · VyOS 1.2.x

Sep 1 2017

c-po added a comment to T274: L2TP Server: cant connect from macosx behind nat without some changes to ipsec config.

@syncer This one is fixed/merged and already working in the nightly builds.

Sep 1 2017, 1:03 PM · VyOS 1.2.x
c-po added a comment to T374: Different default IKE DH Group behaviour between v1.1.7 and v999 Nightlies.

Just to give some more information.

Sep 1 2017, 10:16 AM · VyOS 1.2.x

Aug 31 2017

c-po added a comment to T328: review output for show tech-support command.

strip-private is a bash-pipe function (/etc/bash_completion.d/vyatta-op).

Aug 31 2017, 3:43 PM · VyOS 1.2.x
c-po added a comment to T371: Add command alias configuration node.

Good objection. This should be avoided!

Aug 31 2017, 7:55 AM · VyOS 1.2.x

Aug 30 2017

c-po added a comment to T345: Can't delete vti interface due to incorrect directory name in /proc.

VyOS 1.1.7 also has two interfaces (vti0 and ip_vti0)

Aug 30 2017, 2:28 PM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
c-po added a comment to T345: Can't delete vti interface due to incorrect directory name in /proc.

@syncer https://github.com/vyos/vyatta-cfg-quagga/pull/15

Aug 30 2017, 1:55 PM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
c-po added a comment to T345: Can't delete vti interface due to incorrect directory name in /proc.

Using VyOS 999.201708292137 I'm able to reproduce this.

Aug 30 2017, 9:20 AM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
c-po added a comment to T370: lldpctl: invalid option 'L'.

@syncer could this change be approved or is anything else missing?

Aug 30 2017, 7:12 AM · vyatta-lldp, lldpd, VyOS 1.2.x

Aug 29 2017

c-po added a comment to T345: Can't delete vti interface due to incorrect directory name in /proc.

I double checked with VyOS 1.1.7 where I can not reproduce the error. Is version 1.1.7 correct in this BUG report?

Aug 29 2017, 8:29 PM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
c-po added a comment to T345: Can't delete vti interface due to incorrect directory name in /proc.

@ethomas could you please provide a full configuration for my tests? The only thing I see is:

Aug 29 2017, 7:54 PM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
c-po added a comment to T345: Can't delete vti interface due to incorrect directory name in /proc.
Aug 29 2017, 2:47 PM · VyOS 1.2.x, VyOS 1.1.x (1.1.8)
c-po added a comment to T328: review output for show tech-support command.

I'll start an investigatin after T345.

Aug 29 2017, 11:19 AM · VyOS 1.2.x