Page MenuHomeVyOS Platform

krox2 (Damian)
User

Projects

User does not belong to any projects.

User Details

User Since
Jan 7 2021, 9:24 AM (22 w, 4 d)

Recent Activity

Fri, Jun 11

krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

It's a bit confusing, I can create a tunnel with 0.0.0.0/0 if I need it. That how it is also done on PaloAlto FW and Fortigate. Anyway, it is just my opinion. Thanks for picking up this request so quickly.

Fri, Jun 11, 5:15 PM · VyOS 1.4 Sagitta
krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@sdev That makes sense, you can also get rid of "esp-group" under vti as it will be specified per tunnel.
I like that we can specify multiple prefixes under one tunnel but also can configure multiple tunnels for more complex scenarios.

Fri, Jun 11, 4:43 PM · VyOS 1.4 Sagitta
krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@sdev Yes, this can be done identically as the tunnel definition.

Fri, Jun 11, 12:19 PM · VyOS 1.4 Sagitta

Thu, Jun 10

krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@sdev Will it not create a full mesh, for example:
10.10.10.0/24 <--> 192.168.10.0/24
10.10.20.0/24 <--> 192.168.20.0/24
It will also set IPsec for 10.10.10.0/24 <--> 192.168.20.0/24 and 10.10.20.0/24 <--> 192.168.10.0/24 that may not be desired.

Thu, Jun 10, 11:09 PM · VyOS 1.4 Sagitta
krox2 added a comment to T3613: Selectors for route-based IPsec tunnel (vti).

@Viacheslav Can be similar to policy-based ipsec

# set vpn ipsec site-to-site peer 1.1.1.1 tunnel 1 
Possible completions:
   allow-nat-networks
                Option to allow NAT networks
   allow-public-networks
                Option to allow public networks
   disable      Option to disable vpn tunnel
   esp-group    ESP group name
 > local        Local parameters for interesting traffic
   protocol     Protocol to encrypt
 > remote       Remote parameters for interesting traffic
Thu, Jun 10, 9:07 PM · VyOS 1.4 Sagitta
Viacheslav awarded T3613: Selectors for route-based IPsec tunnel (vti) a Like token.
Thu, Jun 10, 8:37 PM · VyOS 1.4 Sagitta
krox2 updated the task description for T3613: Selectors for route-based IPsec tunnel (vti).
Thu, Jun 10, 8:19 PM · VyOS 1.4 Sagitta
krox2 updated the task description for T3613: Selectors for route-based IPsec tunnel (vti).
Thu, Jun 10, 8:18 PM · VyOS 1.4 Sagitta
krox2 created T3613: Selectors for route-based IPsec tunnel (vti).
Thu, Jun 10, 8:17 PM · VyOS 1.4 Sagitta

Wed, May 26

krox2 closed T3540: Keepalived memory utilisation issue when constantly getting its state in JSON format as Resolved.

@Viacheslav We have been running the new rolling realse in the lab since 24th May with no issues. Thanks for help.

Wed, May 26, 8:54 AM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta

May 12 2021

krox2 created T3540: Keepalived memory utilisation issue when constantly getting its state in JSON format.
May 12 2021, 12:26 PM · VyOS 1.3 Equuleus, VyOS 1.4 Sagitta