Page MenuHomePhabricator

kroy (Kroy)
User

Projects

User does not belong to any projects.

User Details

User Since
Sep 15 2018, 11:31 PM (65 w, 21 h)

Recent Activity

Wed, Dec 11

kroy updated subscribers of T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config..

T1846 fixes this

Wed, Dec 11, 5:30 AM · VyOS 1.2 Crux

Tue, Dec 10

kroy added a comment to T1845: syslog host no longer accepts a port.

@hagbard Confirmed fix. Migration worked perfectly.

Tue, Dec 10, 7:09 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Mon, Dec 9

kroy added a comment to T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config..

Related to T1844, which should correct the original problem in this ticket

Mon, Dec 9, 7:17 PM · VyOS 1.2 Crux
kroy added a comment to T1853: wireguard - disable peer doesn't work .
Mon, Dec 9, 6:57 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux

Fri, Dec 6

kroy added a comment to T1845: syslog host no longer accepts a port.

Trying to apply the fix manually:

Fri, Dec 6, 11:12 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus
kroy added a comment to T1845: syslog host no longer accepts a port.

Built a fresh rolling. It failed with:

Fri, Dec 6, 11:10 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus
kroy added a comment to T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config..

Okay, so this problem just got a LOT more bizarre.

Fri, Dec 6, 1:31 AM · VyOS 1.2 Crux

Thu, Dec 5

kroy added a comment to T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config..

When the config was gone, the processes still seemed to be running

Thu, Dec 5, 4:42 PM · VyOS 1.2 Crux
kroy created T1851: wireguard - changing the pubkey on an existing peer seems to destroy the running config..
Thu, Dec 5, 4:39 PM · VyOS 1.2 Crux

Wed, Dec 4

kroy added a comment to T1845: syslog host no longer accepts a port.

It actually does work, if only by accident

Wed, Dec 4, 5:59 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus
kroy closed T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred as Resolved.

This should be all of the relevant configs from the ASA side

Wed, Dec 4, 4:58 PM · VyOS 1.3 Equuleus
kroy created T1845: syslog host no longer accepts a port.
Wed, Dec 4, 5:06 AM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Thu, Nov 21

kroy added a comment to T1816: provide perf package for running kernel.

I guess I'd ask the question of whether we have any complaints of performance type issues that perf could pinpoint? I don't know if I've ever seen any of those kind of complaints in the circles I hang out in.

Thu, Nov 21, 4:35 PM · VyOS 1.3 Equuleus

Mon, Nov 18

kroy changed the status of T1812: DHCP: hostnames of clients not resolving after update v1.2.3 -> 1.2-rolling from Open to Needs testing.
Mon, Nov 18, 11:26 PM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus
kroy added a comment to T1812: DHCP: hostnames of clients not resolving after update v1.2.3 -> 1.2-rolling .

PR166 should fix this.

Mon, Nov 18, 11:19 PM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus

Oct 31 2019

kroy closed T1779: Tunnel interfaces aren't suggested as being available for bridging as Resolved.

Complete

Oct 31 2019, 3:57 PM · VyOS 1.2 Crux

Oct 30 2019

kroy added a comment to T1779: Tunnel interfaces aren't suggested as being available for bridging.

PR: https://github.com/vyos/vyos-1x/pull/156

Oct 30 2019, 10:13 PM · VyOS 1.2 Crux
kroy updated the task description for T1779: Tunnel interfaces aren't suggested as being available for bridging.
Oct 30 2019, 10:11 PM · VyOS 1.2 Crux
kroy changed Difficulty level from normal to easy on T1779: Tunnel interfaces aren't suggested as being available for bridging.
Oct 30 2019, 10:11 PM · VyOS 1.2 Crux
kroy created T1779: Tunnel interfaces aren't suggested as being available for bridging.
Oct 30 2019, 10:11 PM · VyOS 1.2 Crux

Oct 27 2019

kroy added a comment to T1759: Replacing Vyatta::Interface perl.

This eliminates the redundant interfaces.py and merges the op_mode displaying code into ifconfig.py

Oct 27 2019, 3:44 PM · VyOS 1.3 Equuleus

Oct 25 2019

kroy created T1771: Recover from failed boots/upgrades automatically.
Oct 25 2019, 3:43 PM · VyOS 1.3 Equuleus
kroy renamed T1770: webproxy breaks commit and http access on routed client from webproxy breaks commit and routing to webproxy breaks commit and http access on routed client.
Oct 25 2019, 12:03 AM · VyOS 1.3 Equuleus

Oct 24 2019

kroy created T1770: webproxy breaks commit and http access on routed client.
Oct 24 2019, 11:48 PM · VyOS 1.3 Equuleus
kroy added a comment to T1759: Replacing Vyatta::Interface perl.

This pull request rewrites all the functionality of ioctl.pm and lays the framework for the rest of Interface.pm

Oct 24 2019, 5:23 PM · VyOS 1.3 Equuleus
kroy added a comment to T1762: VLAN interface configuration fails after internal representation of edit level was switched from a string to a list.

Attached

Oct 24 2019, 4:16 AM · VyOS 1.3 Equuleus
kroy added a comment to T1762: VLAN interface configuration fails after internal representation of edit level was switched from a string to a list.

VyOS 1.2-rolling-201910210211 boots perfectly.

Oct 24 2019, 1:30 AM · VyOS 1.3 Equuleus
kroy created T1762: VLAN interface configuration fails after internal representation of edit level was switched from a string to a list.
Oct 24 2019, 1:25 AM · VyOS 1.3 Equuleus

Oct 22 2019

kroy added a comment to T1759: Replacing Vyatta::Interface perl.

Example output. Note this is all programmatically generated in Python now instead of parsing the output of wg

Oct 22 2019, 7:24 PM · VyOS 1.3 Equuleus
kroy closed T1756: Modify output to be more useful - Wireguard as Resolved.

Superseded by T1759

Oct 22 2019, 7:23 PM · VyOS 1.3 Equuleus
kroy added a comment to T1759: Replacing Vyatta::Interface perl.

PR: https://github.com/vyos/vyos-1x/pull/150

Oct 22 2019, 7:22 PM · VyOS 1.3 Equuleus
kroy created T1759: Replacing Vyatta::Interface perl.
Oct 22 2019, 7:21 PM · VyOS 1.3 Equuleus

Oct 21 2019

kroy edited projects for T1756: Modify output to be more useful - Wireguard, added: VyOS 1.3 Equuleus; removed VyOS 1.2 Crux.
Oct 21 2019, 7:23 PM · VyOS 1.3 Equuleus
kroy added a comment to T1756: Modify output to be more useful - Wireguard.

PR: https://github.com/vyos/vyos-1x/pull/149

Oct 21 2019, 6:51 PM · VyOS 1.3 Equuleus
kroy created T1756: Modify output to be more useful - Wireguard.
Oct 21 2019, 6:42 PM · VyOS 1.3 Equuleus

Oct 15 2019

kroy added a comment to T1730: Adding the remote syslog feature to webproxy.

Okay, after working with this for a while, I believe the whole 'vyatta-webproxy` should be a candidate for deletion in equuleus (see T1732).

Oct 15 2019, 4:36 AM · VyOS 1.3 Equuleus
kroy created T1732: Removing vyatta-webproxy module.
Oct 15 2019, 4:25 AM · VyOS 1.3 Equuleus

Oct 14 2019

kroy added a comment to T1730: Adding the remote syslog feature to webproxy.

To be fair, that’s what prompted this. The logs go to a different file already.

Oct 14 2019, 9:17 PM · VyOS 1.3 Equuleus
kroy added a comment to T1730: Adding the remote syslog feature to webproxy.

This PR should address those concerns

Oct 14 2019, 8:26 PM · VyOS 1.3 Equuleus
kroy added a comment to T1730: Adding the remote syslog feature to webproxy.
Oct 14 2019, 7:20 PM · VyOS 1.3 Equuleus
kroy created T1730: Adding the remote syslog feature to webproxy.
Oct 14 2019, 7:16 PM · VyOS 1.3 Equuleus

Oct 1 2019

kroy added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

This is going to become more and more of a problem as wireguard adoption continues. Most major Wireguard VPN services provide a FQDN as their endpoint, not IP:

Oct 1 2019, 1:58 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
kroy added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

This should be reverted, as the change is breaking. After more testing, I found some problems due to things like static routing being applied before wireguard now. So the wireguard tunnel works, but in some cases any routing that shouldbe going over the tunnel does not work.

Oct 1 2019, 1:20 AM · VyOS 1.3 Equuleus, VyOS 1.2 Crux

Sep 30 2019

kroy added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

Yep. Changing the priority fixes the issue completely

Sep 30 2019, 9:55 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
kroy added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

@runar This isn't a routing issue though.

Sep 30 2019, 8:31 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
kroy added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

Changing when the tunnel comes up isn’t an option? For whatever reason the tunnel comes up before DNS resolution works. Using a hostname when the system is running works perfectly

Sep 30 2019, 4:22 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux

Sep 29 2019

kroy added a comment to T1700: Wireguard FQDN endpoint doesn't work after reboot.

Guess? Wireguard coming up before vyos-hostsd?

Sep 29 2019, 8:12 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
kroy created T1700: Wireguard FQDN endpoint doesn't work after reboot.
Sep 29 2019, 8:03 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux
kroy added a comment to T1697: Configurable FQDN at vbash prompt.
Sep 29 2019, 7:55 PM · VyOS 1.3 Equuleus

Sep 24 2019

kroy added a comment to T1020: OSPF Stops distributing default route after a while.

Can confirm. All my routing tables now have 0.0.0.0/0, no matter what the device is. This is just in 1.2.3.

Sep 24 2019, 3:17 PM · VyOS 1.3 Equuleus

Sep 23 2019

kroy added a comment to T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.

At this point I've moved all my ASAs to VyOS, and all my tunnels to Wireguard. Unfortunately I cannot test this setup anymore.

Sep 23 2019, 4:49 PM · VyOS 1.3 Equuleus

Sep 20 2019

kroy closed T1638: vyos-hostsd not setting system domain name as Resolved.
Sep 20 2019, 12:44 AM · VyOS 1.2 Crux (VyOS 1.2.4)
kroy closed T1638: vyos-hostsd not setting system domain name , a subtask of T1598: New implementation of the resolv.conf and hosts update mechanism, as Resolved.
Sep 20 2019, 12:44 AM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
kroy claimed T1638: vyos-hostsd not setting system domain name .
Sep 20 2019, 12:44 AM · VyOS 1.2 Crux (VyOS 1.2.4)
kroy added a comment to T1638: vyos-hostsd not setting system domain name .

PR132 fixes this problem

Sep 20 2019, 12:34 AM · VyOS 1.2 Crux (VyOS 1.2.4)

Sep 19 2019

kroy edited projects for T1638: vyos-hostsd not setting system domain name , added: VyOS 1.2 Crux (VyOS 1.2.3); removed VyOS 1.2 Crux.
Sep 19 2019, 10:24 PM · VyOS 1.2 Crux (VyOS 1.2.4)

Sep 18 2019

kroy created T1669: Stacking routers, for centralized management.
Sep 18 2019, 11:33 PM · VyOS 1.3 Equuleus
kroy created T1668: Integration between VyOS installs and a centralized repository..
Sep 18 2019, 11:20 PM · VyOS Manager

Sep 16 2019

kroy added a comment to T1490: BGP configuration (is lost|not applied) when updating 1.1.8 -> 1.2.1.

There are a number of strange things going on here, and I suspect there are multiple bugs:

Sep 16 2019, 1:13 AM · VyOS 1.3 Equuleus

Sep 9 2019

kroy updated the task description for T1643: Deleting all firewall zones failed and locked out box.
Sep 9 2019, 6:34 PM · VyOS 1.3 Equuleus
kroy created T1643: Deleting all firewall zones failed and locked out box.
Sep 9 2019, 6:33 PM · VyOS 1.3 Equuleus

Sep 6 2019

kroy added a subtask for T1598: New implementation of the resolv.conf and hosts update mechanism: T1638: vyos-hostsd not setting system domain name .
Sep 6 2019, 2:17 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus
kroy added a parent task for T1638: vyos-hostsd not setting system domain name : T1598: New implementation of the resolv.conf and hosts update mechanism.
Sep 6 2019, 2:17 PM · VyOS 1.2 Crux (VyOS 1.2.4)
kroy updated the task description for T1638: vyos-hostsd not setting system domain name .
Sep 6 2019, 2:13 PM · VyOS 1.2 Crux (VyOS 1.2.4)
kroy created T1638: vyos-hostsd not setting system domain name .
Sep 6 2019, 2:12 PM · VyOS 1.2 Crux (VyOS 1.2.4)

Sep 3 2019

kroy added a comment to T1629: IP addresses configured on vif-s interfaces are not added to the system.

I took a look, but was unable to figure out how to finagle VyOS to fix it.

Sep 3 2019, 7:19 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Jul 25 2019

kroy added a comment to T1020: OSPF Stops distributing default route after a while.

Attached are the pcap and debug logs from a simple setup as outlined above, two hosts. "Master" distributing the route.

Jul 25 2019, 4:17 PM · VyOS 1.3 Equuleus

Mar 17 2019

kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

Yep. Can confirm issue is fixed with the latest hot fix.

Mar 17 2019, 12:27 AM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.1)

Feb 13 2019

kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

Strange. I’ve seen that error a lot. Every time it’s been when I’ve forgotten to checkout current after cloning the repo.

Feb 13 2019, 1:27 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.1)
kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

@Merijn make sure you git checkout currenton everything.

Feb 13 2019, 12:38 AM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.1)

Feb 6 2019

kroy added a comment to T1153: VyOS 1.2.0RC10, RAID-1, fresh install, unable to save config.

Can you describe the system and disks involved?

Feb 6 2019, 9:08 PM · VyOS 1.3 Equuleus
kroy added a comment to T1153: VyOS 1.2.0RC10, RAID-1, fresh install, unable to save config.

@jmlccdmd See the fix in T1120. Does changing the rootdelay to something longer fix it for you? Or turning off acpi as suggested?

Feb 6 2019, 6:57 PM · VyOS 1.3 Equuleus
kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

Yeah, it wasn't really a workable solution for me either and I too had to roll back. But it would be good to confirm that is the problem.

Feb 6 2019, 4:57 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.1)
kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

@lbv2rus There might actually be a few problems here. We might have hacked out that it's the interface-route with the custom routing table that's causing the problem.

Feb 6 2019, 4:39 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.1)
kroy added a comment to T1233: ipsec vpn sa showing down.

I’ll add that I think this is happening because of the .252 and .254 addresses. The 254 address connects, but the 252 address is marked in a constant state of connecting.

Feb 6 2019, 12:16 AM · VyOS 1.3 Equuleus

Feb 1 2019

kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

There might actually be a bit of a deeper problem here, somewhat conditional on some static interface routing. On an broken system, it does say something about staticd starting

Feb 1 2019, 9:59 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.1)

Jan 31 2019

kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

And more info:

Jan 31 2019, 1:11 AM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.1)
kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

I tracked down what is causing this.

Jan 31 2019, 1:01 AM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.1)

Jan 30 2019

kroy added a comment to T1218: Static routes not being applied in 1.2 Release.

Too add, routes are present in FRR

Jan 30 2019, 10:58 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.1)
kroy created T1218: Static routes not being applied in 1.2 Release.
Jan 30 2019, 10:44 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.1)

Jan 29 2019

kroy renamed T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred from IPSec Tunnel to Cisco ASA drops after exactly 4.2GB transferred to IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.
Jan 29 2019, 5:21 AM · VyOS 1.3 Equuleus
kroy updated the task description for T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.
Jan 29 2019, 5:20 AM · VyOS 1.3 Equuleus
kroy updated the task description for T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.
Jan 29 2019, 5:19 AM · VyOS 1.3 Equuleus
kroy created T1212: IPSec Tunnel to Cisco ASA drops reliably after 4.2GB transferred.
Jan 29 2019, 5:18 AM · VyOS 1.3 Equuleus

Jan 27 2019

olivier.hault awarded T1097: Make firewall groups work everywhere that's appropropriate a Like token.
Jan 27 2019, 4:32 PM · VyOS 1.3 Equuleus

Jan 26 2019

kroy added a comment to T1169: LLDP potentially broken.

THis shows up in the logs:

Jan 26 2019, 7:09 PM · VyOS 1.3 Equuleus
kroy added a comment to T1169: LLDP potentially broken.

Unfortunately that seems to have made the problem worse. Before, at least each host was seeing one other host. Now most of them see no hosts.

Jan 26 2019, 7:07 PM · VyOS 1.3 Equuleus
kroy added a comment to T1169: LLDP potentially broken.

Sure. I'll set a reminder to check it out tomorrow when I have a free minute. Thanks

Jan 26 2019, 2:25 AM · VyOS 1.3 Equuleus

Jan 25 2019

kroy added a comment to T1178: Scheduled script breaks ability to modify configuration.

Sorry. Spent the week restoring almost half a petabyte of data from backups due to a ZFS crash.

Jan 25 2019, 8:21 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 22 2019

kroy added a comment to T1178: Scheduled script breaks ability to modify configuration.

Yeah. I remove the initial vyos user and add an admin and an ansible user. The admin is just for consistency across different devices.

Jan 22 2019, 6:28 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy added a comment to T1178: Scheduled script breaks ability to modify configuration.

@hagbard I remove/change the vyos user too. So it's definitely a breaking change.

Jan 22 2019, 4:41 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 21 2019

kroy added a comment to T1178: Scheduled script breaks ability to modify configuration.

The latest rolling did seem to correct the base problem. That being cron scripts running breaking the ability to edit config afterwards.

Jan 21 2019, 6:45 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy added a comment to T1178: Scheduled script breaks ability to modify configuration.

@hagbard Note that a reboot does fix the ability to edit configuration again until the next time the cron script runs.

Jan 21 2019, 5:26 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 20 2019

kroy added a comment to T1020: OSPF Stops distributing default route after a while.

Okay, spent the whole day messing with this and I've tracked it down so it's reproducible.

Jan 20 2019, 7:58 PM · VyOS 1.3 Equuleus

Jan 14 2019

kroy closed T1177: Unable to modify or delete task-scheduler tasks as Resolved.

Superseded by T1178

Jan 14 2019, 7:04 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy created T1178: Scheduled script breaks ability to modify configuration.
Jan 14 2019, 7:03 PM · VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy added a comment to T1177: Unable to modify or delete task-scheduler tasks.

Seems to be a problem with just that build. I'll install a newer rolling when I get a chance and see if that corrects it.

Jan 14 2019, 5:41 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy added a comment to T1177: Unable to modify or delete task-scheduler tasks.

Edit... actually I can't update anything:

Jan 14 2019, 5:30 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)
kroy created T1177: Unable to modify or delete task-scheduler tasks.
Jan 14 2019, 5:19 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-GA)

Jan 13 2019

kroy added a comment to T1020: OSPF Stops distributing default route after a while.

I was mistaken. Seems to have lost the route again.

Jan 13 2019, 5:00 PM · VyOS 1.3 Equuleus