Page MenuHomeVyOS Platform

krox2 (Damian)
User

Projects

User does not belong to any projects.

User Details

User Since
Jan 7 2021, 9:24 AM (168 w, 23 h)

Recent Activity

Feb 21 2023

krox2 closed T5021: IPsec SA is closed before negotiating a new one or it is negotiated on every second if big life-time is set in swanctl.conf as Resolved.

it's fixed already in vyos/vyos-build#293 (although in a different way), just downloaded the newest image and tested it. I'm closing this ticket, apologies for the noise.

Feb 21 2023, 9:48 AM · VyOS 1.4 Sagitta

Feb 20 2023

krox2 added a comment to T5021: IPsec SA is closed before negotiating a new one or it is negotiated on every second if big life-time is set in swanctl.conf.

https://github.com/vyos/vyos-1x/pull/1836

Feb 20 2023, 11:22 PM · VyOS 1.4 Sagitta
krox2 created T5021: IPsec SA is closed before negotiating a new one or it is negotiated on every second if big life-time is set in swanctl.conf.
Feb 20 2023, 10:57 PM · VyOS 1.4 Sagitta

Aug 22 2022

krox2 added a comment to T4526: keepalived-fifo.py unable to load config.

This is what I did (forgot to write it here) with the difference that my sleep timer is 60s as my config has many lines.
Would be good to have this fixed properly.

Aug 22 2022, 2:55 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta

Jul 11 2022

krox2 created T4526: keepalived-fifo.py unable to load config.
Jul 11 2022, 3:07 PM · vyos-keepalived, vyatta-vrrp, VyOS 1.4 Sagitta

Aug 26 2021

krox2 added a comment to T3780: VTI not being brought down when tunnel is down.

https://github.com/vyos/vyos-1x/pull/979

Aug 26 2021, 12:46 PM · VyOS 1.4 Sagitta
krox2 created T3780: VTI not being brought down when tunnel is down.
Aug 26 2021, 11:03 AM · VyOS 1.4 Sagitta

Aug 17 2021

krox2 created T3760: LLDP causes interface RX drops.
Aug 17 2021, 4:17 PM · lldpd, VyOS 1.4 Sagitta

Jun 11 2021

krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

It's a bit confusing, I can create a tunnel with 0.0.0.0/0 if I need it. That how it is also done on PaloAlto FW and Fortigate. Anyway, it is just my opinion. Thanks for picking up this request so quickly.

Jun 11 2021, 5:15 PM · VyOS 1.4 Sagitta
krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@sdev That makes sense, you can also get rid of "esp-group" under vti as it will be specified per tunnel.
I like that we can specify multiple prefixes under one tunnel but also can configure multiple tunnels for more complex scenarios.

Jun 11 2021, 4:43 PM · VyOS 1.4 Sagitta
krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@sdev Yes, this can be done identically as the tunnel definition.

Jun 11 2021, 12:19 PM · VyOS 1.4 Sagitta

Jun 10 2021

krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@sdev Will it not create a full mesh, for example:
10.10.10.0/24 <--> 192.168.10.0/24
10.10.20.0/24 <--> 192.168.20.0/24
It will also set IPsec for 10.10.10.0/24 <--> 192.168.20.0/24 and 10.10.20.0/24 <--> 192.168.10.0/24 that may not be desired.

Jun 10 2021, 11:09 PM · VyOS 1.4 Sagitta
krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@Viacheslav Can be similar to policy-based ipsec

# set vpn ipsec site-to-site peer 1.1.1.1 tunnel 1 
Possible completions:
   allow-nat-networks
                Option to allow NAT networks
   allow-public-networks
                Option to allow public networks
   disable      Option to disable vpn tunnel
   esp-group    ESP group name
 > local        Local parameters for interesting traffic
   protocol     Protocol to encrypt
 > remote       Remote parameters for interesting traffic
Jun 10 2021, 9:07 PM · VyOS 1.4 Sagitta
Viacheslav awarded T3613: Selectors for route-based IPsec tunnel (vti) a Like token.
Jun 10 2021, 8:37 PM · VyOS 1.4 Sagitta
krox2 updated the task description for T3613: Selectors for route-based IPsec tunnel (vti).
Jun 10 2021, 8:19 PM · VyOS 1.4 Sagitta
krox2 updated the task description for T3613: Selectors for route-based IPsec tunnel (vti).
Jun 10 2021, 8:18 PM · VyOS 1.4 Sagitta
krox2 created T3613: Selectors for route-based IPsec tunnel (vti).
Jun 10 2021, 8:17 PM · VyOS 1.4 Sagitta

May 26 2021

krox2 closed T3540: Keepalived memory utilisation issue when constantly getting its state in JSON format as Resolved.

@Viacheslav We have been running the new rolling realse in the lab since 24th May with no issues. Thanks for help.

May 26 2021, 8:54 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

May 12 2021

krox2 created T3540: Keepalived memory utilisation issue when constantly getting its state in JSON format.
May 12 2021, 12:26 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta