c-po (Christian Poessinger)
User

Projects

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Saturday

  • Clear sailing ahead.

User Details

User Since
Aug 3 2017, 1:55 PM (24 w, 2 m)
Availability
Available

Recent Activity

Sun, Jan 7

c-po added a comment to T518: Move VyOS configuration syntax from Bash and node.def to XML.

@alainlamar nice work digging!

Sun, Jan 7, 8:14 PM · VyOS 1.2.x, VyOS 1.3.x
c-po moved T341: WOL Tools in base image from Backlog to In Progress on the VyOS 1.2.x board.
Sun, Jan 7, 8:26 AM · VyOS 1.2.x
c-po updated subscribers of T341: WOL Tools in base image.

@syncer tools added to base image. This would be perfect for a vyos-1x op mode command. Unfortunately I was not able to build a working template with the relax-ng templates (lack of xml/relax-ng) knowledge. @dmbaturin maybe you can help?

Sun, Jan 7, 8:26 AM · VyOS 1.2.x

Sat, Jan 6

c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

@squeeby which sflow collector do you use? Is there one you can recommend?

Sat, Jan 6, 11:02 PM · VyOS 1.2.x
c-po updated the task description for T512: New package versions not synced to http://dev.packages.vyos.net.
Sat, Jan 6, 9:56 PM · VyOS 1.2.x
c-po moved T379: UDP Broadcast Packet Relay from In Progress to Finished on the VyOS 1.2.x board.
Sat, Jan 6, 9:52 PM · VyOS 1.2.x
c-po added a comment to T379: UDP Broadcast Packet Relay.

Rewrote the scripts using vyos-1x and Python. This is now functioning on my routers.

Sat, Jan 6, 9:52 PM · VyOS 1.2.x
c-po created T512: New package versions not synced to http://dev.packages.vyos.net.
Sat, Jan 6, 11:52 AM · VyOS 1.2.x
c-po closed T509: vyos-build: VyOS Images have stopped building as Resolved.
Sat, Jan 6, 8:13 AM · VyOS 1.2.x
c-po added a comment to T509: vyos-build: VyOS Images have stopped building.

Working again

Sat, Jan 6, 8:12 AM · VyOS 1.2.x

Fri, Jan 5

c-po moved T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown from In Progress to Finished on the VyOS 1.2.x board.
Fri, Jan 5, 8:12 PM · VyOS 1.2.x
c-po moved T510: vyos-1x generated crontab nodes missleading from In Progress to Finished on the VyOS 1.2.x board.
Fri, Jan 5, 8:12 PM · VyOS 1.2.x
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

Merged into vyatta-netflow package and will be included in tonights build.

Fri, Jan 5, 8:07 PM · VyOS 1.2.x
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

Ok, next try: https://www.mybll.net/vyatta-netflow_ver02_all.deb

Fri, Jan 5, 3:15 PM · VyOS 1.2.x
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

Could you alter the file manually to get a working state and pass it to me by e.g. pasting it here or a https://pastebin.com/ link? Then I could regenerate a package for testing. This would help me a lot as I do not have any flow collector.

Fri, Jan 5, 2:43 PM · VyOS 1.2.x
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

You can revert by switching back to the official VyOS package.

Fri, Jan 5, 2:13 PM · VyOS 1.2.x
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

Strange. I only changed /opt/vyatta/sbin/vyatta-netflow.pl to your recommendation.

Fri, Jan 5, 9:32 AM · VyOS 1.2.x
c-po moved T510: vyos-1x generated crontab nodes missleading from Need Triage to In Progress on the VyOS 1.2.x board.
Fri, Jan 5, 6:51 AM · VyOS 1.2.x
c-po added a comment to T296: Enabling NetFlow fails, iptables chain VYATTA_CT_PREROUTING_HOOK unknown.

@squeeby do you mind verifying the following package containing your fix:

Fri, Jan 5, 6:50 AM · VyOS 1.2.x

Thu, Jan 4

c-po triaged T510: vyos-1x generated crontab nodes missleading as Normal priority.
Thu, Jan 4, 11:34 AM · VyOS 1.2.x
c-po created T510: vyos-1x generated crontab nodes missleading.
Thu, Jan 4, 11:33 AM · VyOS 1.2.x

Tue, Jan 2

c-po added a comment to T122: Control over which users have ssh access.

@alainlamar your effort and support is tremendous and very much appreciated. I'm also super new to VyOS "development".

Tue, Jan 2, 7:14 PM · VyOS 1.2.x
c-po updated subscribers of T509: vyos-build: VyOS Images have stopped building.
Tue, Jan 2, 6:48 PM · VyOS 1.2.x
c-po added a comment to T509: vyos-build: VyOS Images have stopped building.

Problem is that two new packages (mdns-repeater and udp-bcast-relay) are build on the CI server, but somehow do not show up in the package repository at http://dev.packages.vyos.net/vyos/pool/main/ which is used during build.

Tue, Jan 2, 6:48 PM · VyOS 1.2.x

Mon, Jan 1

c-po updated subscribers of T122: Control over which users have ssh access.

@alainlamar thanks for sharing your thoughts. Regarding your MR, you add a node sshd_option where someone could add ANY option to sshd. I'm not a big fan of those "you can do everything nodes".

Mon, Jan 1, 6:39 PM · VyOS 1.2.x
c-po added a comment to T122: Control over which users have ssh access.

I think T141 also wants to achieve something similar but with proper AAA. Unfortunately my network has not reached the critical mass to go for a TAC server. But we should keep this in mind!

Mon, Jan 1, 1:38 PM · VyOS 1.2.x

Sun, Dec 31

c-po moved T507: vyatta-cfg-system -> SSH: Failure to correctly alter Ciphers and MACs from Need Triage to Finished on the VyOS 1.2.x board.
Sun, Dec 31, 3:23 PM · VyOS 1.2.x
c-po added a comment to T507: vyatta-cfg-system -> SSH: Failure to correctly alter Ciphers and MACs.

Dissecting your patch .. I come up with those commits: https://github.com/c-po/vyatta-cfg-system/commits/t507-sshd

Sun, Dec 31, 2:37 PM · VyOS 1.2.x
c-po added a comment to T507: vyatta-cfg-system -> SSH: Failure to correctly alter Ciphers and MACs.

@alainlamar thanks for the contribution.

Sun, Dec 31, 2:29 PM · VyOS 1.2.x

Sat, Dec 30

c-po added a comment to T123: Set module/kernel options from CLI.

T419 also needs this capability.

Sat, Dec 30, 8:40 PM · VyOS 1.2.x
c-po added a comment to T419: Support setting dstport for VXLAN interfaces.

Okay, the proof of concept worked on the console

Sat, Dec 30, 4:34 PM · VyOS 1.2.x
c-po added a comment to T169: Image install should put correct serial console device in created grub menuentry.

IMHO the whole serial part should be re-written.

Sat, Dec 30, 4:27 PM · VyOS 1.2.x

Fri, Dec 29

c-po moved T355: Outstanding CVEs - OpenVPN from In Progress to Finished on the VyOS 1.2.x board.
Fri, Dec 29, 5:33 PM · VyOS 1.2.x, openvpn
c-po created T506: Support CIDR notation in firewall address-group.
Fri, Dec 29, 12:18 PM · VyOS 1.2.x
c-po added a comment to T452: WiFi: Enable support for 5GHz AccesPoints with DFS.

@alainlamar Kernel Updated and Rebuild triggered on CI server.

Fri, Dec 29, 11:49 AM · VyOS 1.2.x, VyOS 1.3.x

Thu, Dec 28

c-po moved T355: Outstanding CVEs - OpenVPN from Need Triage to In Progress on the VyOS 1.2.x board.
Thu, Dec 28, 11:54 AM · VyOS 1.2.x, openvpn
c-po added a comment to T355: Outstanding CVEs - OpenVPN.

@UnicronNL lithium branch @ https://github.com/vyos/openvpn

Thu, Dec 28, 11:54 AM · VyOS 1.2.x, openvpn
c-po added a comment to T51: Add support for an included dns recursor.

Please correct me if I‘m wrong but is the integrated dnsmasq insufficient for your needs?

Thu, Dec 28, 11:05 AM · VyOS 1.2.x

Wed, Dec 27

c-po added Q118: IPv6 system name-server (Answer 171).
Wed, Dec 27, 11:49 PM
c-po moved T297: DNS Forwarding server does not allow IPv6 address in name-server from In Progress to Finished on the VyOS 1.2.x board.
Wed, Dec 27, 11:44 PM · VyOS 1.2.x
c-po updated subscribers of T297: DNS Forwarding server does not allow IPv6 address in name-server.

Implemented in https://github.com/vyos/vyatta-cfg-system/commit/c5e11462769bea9769335944f0f8a8f5411d027e

Wed, Dec 27, 11:44 PM · VyOS 1.2.x
c-po changed the status of T297: DNS Forwarding server does not allow IPv6 address in name-server from Open to In progress.
Wed, Dec 27, 11:41 PM · VyOS 1.2.x
c-po moved T297: DNS Forwarding server does not allow IPv6 address in name-server from Need Triage to In Progress on the VyOS 1.2.x board.
Wed, Dec 27, 11:09 PM · VyOS 1.2.x
c-po added a comment to T297: DNS Forwarding server does not allow IPv6 address in name-server.

Anyone know to which software portion the DNS forwarder is linked? Or even better, has an idea how to fix it on the shell? This would make it much easier to adopt the scripts.

Wed, Dec 27, 11:03 PM · VyOS 1.2.x
c-po added a comment to T496: RAID1 install with 60 MB diagnositcs partition.

Triggered Jenkins build https://ci.vyos.net/job/vyatta-cfg-system/281/changes, will be in the next nightly build

Wed, Dec 27, 10:42 PM · VyOS 1.2.x, VyOS 1.1.x
c-po added a comment to T316: Latest Nightly build (vyos-999.201705242137-amd64) is not booting.

@syncer I'm doing almost daily installs for testing in an ESXi environment. No problems. I think this one can be closed ..

Wed, Dec 27, 10:38 PM · VyOS 1.2.x (VyOS 1.2.0 LTS Lithium)
c-po added a comment to T279: VyOS Beta, automatic partitioning does not leave enough space for Grub after MBR..

@syncer I'm doing almost daily installs for testing in an ESXi environment. No problems. I think this one can be closed ..

Wed, Dec 27, 10:38 PM · VyOS 1.2.x
c-po moved T496: RAID1 install with 60 MB diagnositcs partition from In Progress to Finished on the VyOS 1.2.x board.
Wed, Dec 27, 10:36 PM · VyOS 1.2.x, VyOS 1.1.x
c-po added a comment to T419: Support setting dstport for VXLAN interfaces.

Found inside the Linux Kernels source code:
./drivers/net/vxlan.c: * The IANA assigned port is 4789, but the Linux default is 8472

Wed, Dec 27, 10:08 PM · VyOS 1.2.x
c-po moved T419: Support setting dstport for VXLAN interfaces from Need Triage to In Progress on the VyOS 1.2.x board.
Wed, Dec 27, 9:41 PM · VyOS 1.2.x
c-po moved T475: IPSec set log-mode broken from Backlog to In Progress on the VyOS 1.2.x board.
Wed, Dec 27, 12:02 PM · VyOS 1.2.x
c-po moved T379: UDP Broadcast Packet Relay from Finished to In Progress on the VyOS 1.2.x board.
Wed, Dec 27, 12:02 PM · VyOS 1.2.x
c-po moved T481: traffic-policy limiter is broken from In Progress to Finished on the VyOS 1.2.x board.
Wed, Dec 27, 12:01 PM · VyOS 1.2.x
c-po moved T504: Commit archive via IPv6 not works from Backlog to Finished on the VyOS 1.2.x board.
Wed, Dec 27, 12:01 PM · VyOS 1.1.x (1.1.9), VyOS 1.2.x
c-po changed the status of T481: traffic-policy limiter is broken from Open to In progress.
Wed, Dec 27, 12:00 PM · VyOS 1.2.x
c-po moved T481: traffic-policy limiter is broken from Need Triage to In Progress on the VyOS 1.2.x board.
Wed, Dec 27, 11:59 AM · VyOS 1.2.x
c-po added a comment to T481: traffic-policy limiter is broken.

@carl.byington Thanks! Pushed to https://github.com/vyos/vyatta-cfg-qos

Wed, Dec 27, 11:59 AM · VyOS 1.2.x
c-po moved T496: RAID1 install with 60 MB diagnositcs partition from Backlog to In Progress on the VyOS 1.2.x board.
Wed, Dec 27, 11:57 AM · VyOS 1.2.x, VyOS 1.1.x
c-po moved T496: RAID1 install with 60 MB diagnositcs partition from Need Triage to Backlog on the VyOS 1.2.x board.
Wed, Dec 27, 11:56 AM · VyOS 1.2.x, VyOS 1.1.x
c-po changed the status of T496: RAID1 install with 60 MB diagnositcs partition from Open to In progress.
Wed, Dec 27, 11:49 AM · VyOS 1.2.x, VyOS 1.1.x
c-po added a comment to T496: RAID1 install with 60 MB diagnositcs partition.

A FAT16 partition is created that is not formated? As It's also broken in 1.1.8 and nobody knows what it does I opt for removal of this "feature"

Wed, Dec 27, 11:09 AM · VyOS 1.2.x, VyOS 1.1.x
c-po updated subscribers of T452: WiFi: Enable support for 5GHz AccesPoints with DFS.

Pushed here for review: https://github.com/c-po/vyos-kernel/commit/0456e0acdcc5b9545723f57ebf489f2a1801a864

Wed, Dec 27, 10:04 AM · VyOS 1.2.x, VyOS 1.3.x

Tue, Dec 26

c-po closed T453: Qos/Match.pm shaper max-length as Resolved.
Tue, Dec 26, 9:41 PM · VyOS 1.2.x
c-po added a comment to T453: Qos/Match.pm shaper max-length.

@carl.byington Thanks! Pushed to https://github.com/vyos/vyatta-cfg-qos

Tue, Dec 26, 9:41 PM · VyOS 1.2.x
c-po closed T498: Enable UDF support in kernel, a subtask of T164: Create image for MicroSoft Azure, as Resolved.
Tue, Dec 26, 9:30 PM · VyOS 1.2.x, Hyper-V/Azure Support
c-po closed T498: Enable UDF support in kernel as Resolved.
Tue, Dec 26, 9:30 PM · VyOS 1.2.x, Hyper-V/Azure Support
c-po added a comment to T498: Enable UDF support in kernel.

Jenkins up and running again: https://ci.vyos.net/job/vyos-kernel/115/changes

Tue, Dec 26, 9:30 PM · VyOS 1.2.x, Hyper-V/Azure Support
c-po added a comment to T80: Upgrade OpenVPN to latest version.

@syncer will be "automatically" fixed by 1.3 as it uses Debian Stretch. So we don't have to do anything :)

Tue, Dec 26, 9:27 PM · VyOS 1.2.x
c-po updated subscribers of T193: Kick ISC DHCP-server to a more recent version.

@syncer looks like finished, but can't edit

Tue, Dec 26, 9:26 PM · VyOS 1.2.x
c-po added a comment to T193: Kick ISC DHCP-server to a more recent version.

VyOS 1.2.x ships ISC DHCP server version 4.3.1-6+deb8u integrated in Debian Jessie.

Tue, Dec 26, 9:26 PM · VyOS 1.2.x
c-po updated subscribers of T126: charon listening on ALL interfaces.

@syncer can be set to finished?

Tue, Dec 26, 9:24 PM · VyOS 1.2.x
c-po added a comment to T80: Upgrade OpenVPN to latest version.

@syncer looks like "Wontfix"

Tue, Dec 26, 9:17 PM · VyOS 1.2.x
c-po added a comment to T80: Upgrade OpenVPN to latest version.

Current VyOS 1.2.x uses OpenVPN 2.3.4 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [PKCS11] [MH] [IPv6] built on Jun 26 2017.
We now install latest Debian Jessie security Updates inside every ISO. Going for 2.4.x will cause a lot of headache in VyOS 1.2.x...

Tue, Dec 26, 9:16 PM · VyOS 1.2.x
c-po added a comment to T415: Beta ISO VTI Tunnel.

Also see T71

Tue, Dec 26, 9:12 PM · VyOS 1.2.x
c-po added a comment to T452: WiFi: Enable support for 5GHz AccesPoints with DFS.

@alainlamar thanks for your effort! Could you please regenerate your patch against arch/x86/configs/x86_64_vyos_defconfig which is used for the CI builds?

Tue, Dec 26, 9:02 PM · VyOS 1.2.x, VyOS 1.3.x
c-po asked Q121: Two Kernel configurations, drop one?.
Tue, Dec 26, 8:59 PM · VyOS 1.2.x
c-po added a comment to T419: Support setting dstport for VXLAN interfaces.

@syncer: To recap, are you OK with the following changes:

Tue, Dec 26, 5:23 PM · VyOS 1.2.x
c-po added a comment to T488: GRUB can't boot from software RAID.

Adjusted generated GRUB configuration to the one from Debian Jessie.

Tue, Dec 26, 3:56 PM · VyOS 1.2.x
c-po closed T488: GRUB can't boot from software RAID as Resolved.
Tue, Dec 26, 3:55 PM · VyOS 1.2.x

Sat, Dec 23

c-po closed T285: Add flag for DNSmasq to query all dns servers as Resolved.
Sat, Dec 23, 1:40 PM · VyOS 1.2.x
c-po changed the status of T285: Add flag for DNSmasq to query all dns servers from Open to In progress.
Sat, Dec 23, 1:40 PM · VyOS 1.2.x
c-po added a comment to T419: Support setting dstport for VXLAN interfaces.

The VXLAN RFC states:

Sat, Dec 23, 1:38 PM · VyOS 1.2.x
c-po added a comment to T419: Support setting dstport for VXLAN interfaces.
cpo@CR1# set interfaces vxlan vxlan1 remote
Possible completions:
   <x.x.x.x>    Remote address of this VXLAN tunnel
Sat, Dec 23, 8:04 AM · VyOS 1.2.x

Fri, Dec 22

c-po added a comment to T359: command "monitor interface" is unable to filter traffic.

What would be a filter that is not working?

Fri, Dec 22, 6:20 PM · VyOS 1.2.x
c-po added a comment to T504: Commit archive via IPv6 not works.

Please wait for todays build and test again. Thanks for your support!

Fri, Dec 22, 5:09 PM · VyOS 1.1.x (1.1.9), VyOS 1.2.x
c-po added a comment to T504: Commit archive via IPv6 not works.

IPv6 address in scp://<user>:<passwd>@[IPv6-address]/<dir> looks like not properly escaped. Should be \[IPv6-address\].

Fri, Dec 22, 5:04 PM · VyOS 1.1.x (1.1.9), VyOS 1.2.x

Dec 11 2017

c-po added Q116: Howto perform IGMP memebership management? (Answer 167).
Dec 11 2017, 1:31 PM

Dec 10 2017

c-po closed T497: Make ISO installer more convenient as Invalid.
Dec 10 2017, 4:49 PM · VyOS 1.2.x
c-po added a comment to T497: Make ISO installer more convenient.

Unfortunately this does not properly work as debian live-build can not distinguish between ISO and IMAGE because both are actually the same.

Dec 10 2017, 4:49 PM · VyOS 1.2.x
c-po updated the task description for T497: Make ISO installer more convenient.
Dec 10 2017, 1:06 PM · VyOS 1.2.x
c-po created T497: Make ISO installer more convenient.
Dec 10 2017, 1:05 PM · VyOS 1.2.x
c-po created T496: RAID1 install with 60 MB diagnositcs partition.
Dec 10 2017, 11:26 AM · VyOS 1.2.x, VyOS 1.1.x

Dec 9 2017

c-po updated the task description for T495: IPSec / Charon deprecated keywods.
Dec 9 2017, 3:07 PM · VyOS 1.2.x
c-po created T495: IPSec / Charon deprecated keywods.
Dec 9 2017, 3:07 PM · VyOS 1.2.x
c-po added a comment to T378: mDNS/bonjour forwarding.

Worked, thanks
https://wiki.vyos.net/wiki/User_Guide#mDNS_Repeater

Dec 9 2017, 3:02 PM · VyOS 1.2.x
c-po closed T281: Add https support to the load command. as Resolved.
Dec 9 2017, 2:58 PM · VyOS 1.2.x
c-po closed T378: mDNS/bonjour forwarding as Resolved.
Dec 9 2017, 2:57 PM · VyOS 1.2.x
c-po claimed T379: UDP Broadcast Packet Relay.
Dec 9 2017, 2:57 PM · VyOS 1.2.x
c-po claimed T434: RADIUS as l2tp vpn authentication mode is broken.
Dec 9 2017, 2:57 PM · VyOS 1.2.x
c-po closed T434: RADIUS as l2tp vpn authentication mode is broken as Resolved.
Dec 9 2017, 2:56 PM · VyOS 1.2.x