elico (Eliezer Croitoru)
User

Projects

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Monday

  • Clear sailing ahead.

User Details

User Since
Jun 14 2016, 12:46 AM (66 w, 3 d)
Availability
Available

Recent Activity

Aug 21 2017

elico added a comment to T322: GRE Header flags drop packet.

@NceAirport Are you connecting two vyos using a gre or vyos to other vendor?
Do these devices have a public ip address on their interfaces or an internal ip with direct routed link(no nat in the middle)?
How can we try to reproduce the issue?

Aug 21 2017, 4:19 AM · VyOS 1.2.x

Jul 24 2017

elico updated the task description for T344: Software basesd FastPath.
Jul 24 2017, 2:11 PM · VyOS 2.0.x, VyOS 1.2.x
elico created T344: Software basesd FastPath.
Jul 24 2017, 2:10 PM · VyOS 2.0.x, VyOS 1.2.x

Jul 20 2017

elico asked Q106: I have seen FastPath in couple places and I was wondering if it's going to make it into VyOS?.
Jul 20 2017, 5:42 PM · VyOS 1.2.x
elico added a comment to T336: OSPF Neighbor Flapping.

@ekim Technically the dhcp lease should not affect on the network traffic at all, the renew should be transparent if the IP stays the same.
I believe that since the issue appears after a minute and the lease is 1 hour then it should be fine and probably not the cause for the issue.

Jul 20 2017, 5:25 PM · VyOS 1.1.x
elico added Q105: Next Developer Meeting (Answer 140).
Jul 20 2017, 5:19 PM

Jul 19 2017

elico added a comment to T336: OSPF Neighbor Flapping.

Can you verify using tcpdump or other means how long the dhcp lease is?

Jul 19 2017, 10:27 PM · VyOS 1.1.x

Jul 18 2017

elico added a comment to T335: SNMP monitoring integration w/ Quagga.

@EwaldvanGeffen it's not clear to me if and what is implemented.
Can you please describe what is implemented and in what version?

Jul 18 2017, 4:35 PM · VyOS 1.2.x

Apr 23 2017

elico added a comment to Q50: Any hope for DPDK?.

Has anyone tried to do something with the howtoforge: https://www.howtoforge.com/tutorial/opendataplane-with-open-fast-path-on-ubuntu/

Apr 23 2017, 8:04 PM · VyOS 1.2.x, VyOS 2.0.x
elico marked Q50: Any hope for DPDK? (Answer 119) as hidden.
Apr 23 2017, 8:03 PM
elico added Q50: Any hope for DPDK? (Answer 119).
Apr 23 2017, 8:03 PM

Dec 21 2016

elico added a comment to Q52: Integrate Vyos with standalone web filtering device?.

Mentioning: http://pastebin.com/yZLVRfnA
Which is an example of how would WLB work with a custom script.

Dec 21 2016, 10:47 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
elico added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@EwaldvanGeffen apply this rule on what? a WLB?
the WLB from what I understood required an interface per gateway while PBR allows me to route the traffic towards any of the gateways which can be the next-hop ie 10.0.0.100/24 or 10.0.0.101/24.
This is what I remember from vyatta and I haven't digged into the subject since I have a huge gap ahead as far as I can see.

Dec 21 2016, 6:18 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
elico updated the answer details for Q52: Integrate Vyos with standalone web filtering device? (Answer 97).
Dec 21 2016, 6:18 PM
elico added Q52: Integrate Vyos with standalone web filtering device? (Answer 97).
Dec 21 2016, 6:17 PM
elico added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@EwaldvanGeffen WLB has a difference from PBR and what is required a PBR.
The code is not something I was looking for but an example of implementation in the configuration.
Then I will be able to look at the code and understand what might be applied to PBR compared to WLB.

Dec 21 2016, 6:40 AM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

Dec 20 2016

elico added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@EwaldvanGeffen Can you help with giving an example of implementing this?
Like with a tiny ping that returns a status code?
(I do not know what WLB is...)

Dec 20 2016, 11:31 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)
elico added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@EwaldvanGeffen technically we can simplify it into a form of a script that monitors the service using http or another tcp\udp based and would flag the avaliability of the service.
The marking and forwarding rule can be automativally bypassed if the service is flagged as down.
Anyone interested working with me on this?
It's basically a simple conditional PBR.. and since WCCP is "OK" for tiny routers for beafy machines such VYOS have I believe that it would be a piece of cake to cook this up.

Dec 20 2016, 9:48 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

Dec 4 2016

elico added a comment to Q56: nDPI integration, what is required?.

Tried to compile on sqeeze and got errors so it will only meet .1.2.0.

Dec 4 2016, 2:54 AM · VyOS 1.1.x (1.1.8)
elico closed T197: Rebuild kernel instructions do not work as Resolved.

There was a missing package "bc".
so "apt-get install -y bc" resolved the issue.

Dec 4 2016, 2:52 AM

Dec 2 2016

elico created T197: Rebuild kernel instructions do not work.
Dec 2 2016, 10:58 AM

Nov 19 2016

elico added a comment to Q56: nDPI integration, what is required?.

@mickvav The userspace software is not something that we need in the build.
I have just built it since it's in the packages\repo.
The important thing is the module and the libraries to build them.
I will try to disable the userspace software build and move on from there.

Nov 19 2016, 5:59 PM · VyOS 1.1.x (1.1.8)

Nov 18 2016

elico added a comment to Q56: nDPI integration, what is required?.

It took faster then expected with a help from a friend so:
https://github.com/elico/debian8-dev-ndpi-vel

Nov 18 2016, 1:31 PM · VyOS 1.1.x (1.1.8)
elico added a comment to Q56: nDPI integration, what is required?.

In order to speed up the build process I want us to work on the VYOS development docker container.
Once we will have this I and others can do things much faster.
I will try to share my build node for debian in two days and then we can move forward from this one step forward towards simple kernel compilation for VYOS in a docker container.
After we will have this we can simply buidl the NDPI modules(which are being used in zeroshell....).

Nov 18 2016, 11:31 AM · VyOS 1.1.x (1.1.8)

Nov 16 2016

elico added a comment to Q56: nDPI integration, what is required?.

OK I have just seen that Mikrotik routers have p2p block and it's an iptables level concept.
I have compiled the module for debian but needs some help from others.
Waiting for others to help.

Nov 16 2016, 9:04 PM · VyOS 1.1.x (1.1.8)

Oct 19 2016

elico added a comment to Q52: Integrate Vyos with standalone web filtering device?.

@hmkias I think that some kind of a daemon would be required to "coordinate" between the squid machine to the VYOS.
I had an idea about it in the past but never had the chance to actually implement it with vyatta.
However I have seen that in ZEROSHELL there is a very nice feature which test for proxy IP level availability.
How complex would it be to make a condition to the policy based on a lock file?

Oct 19 2016, 6:44 PM · VyOS 2.0.x, VyOS 1.1.x (1.1.8)

Sep 26 2016

elico added a comment to Q56: nDPI integration, what is required?.

@EwaldvanGeffen The main point is that the basic and working extra modules should be usable to the public since it gives anyone that want's to enhance the existing code.
The main example is blocking windows updates, if you have the sources you can see it's being blocked based couple simple things:
domain name in plain HTTP
domain name in SNI of SSL

Sep 26 2016, 10:33 PM · VyOS 1.1.x (1.1.8)
elico added a comment to Q56: nDPI integration, what is required?.

@mickvav I do not need it personally since it works for me fine on other systems but I would like to put my efforts in order to have others have some benefit from my work.
I will take a look at the ipt-netflow-code work and with time I will probably practice it.

Sep 26 2016, 1:28 PM · VyOS 1.1.x (1.1.8)
elico added a comment to Q56: nDPI integration, what is required?.

@mickvav I learned the debian packaging and produced more then one or these for Squid-Cache but everytime I am sitting on the build it's from 0.
To deploy most of my compiled softwares I am using a tar.xz which can be deployed ontop of the existing system as a 'module' and I found it much simpler for me to work with simple bash scripts then the debian packaging.
Without someone helping me to repackage over and over couple times of packages then it's not being pulled into the box but merely passing from one side to the other...
@dmbaturin gave me couple tips and cleared things for me.
I will try to finish couple things here before we\I can dive into the subject.

Sep 26 2016, 12:11 PM · VyOS 1.1.x (1.1.8)

Sep 23 2016

elico added a comment to Q56: nDPI integration, what is required?.

It can be disabled as will.
It works or not like any other external module which doesn't require kernel changes.( the specific ve21loring version)

Sep 23 2016, 7:02 AM · VyOS 1.1.x (1.1.8)

Sep 22 2016

elico updated Q56: nDPI integration, what is required? from to nDPI integration, what is required?.
Sep 22 2016, 10:39 PM · VyOS 1.1.x (1.1.8)