Page MenuHomeVyOS Platform

m.korobeinikov (Mikhail Korobeinikov)
User

Projects

User Details

User Since
Oct 11 2021, 11:52 AM (37 w, 4 d)

Recent Activity

May 16 2022

m.korobeinikov closed T4377: generate tech-support archive includes previous archives as Resolved.

The command works well.

May 16 2022, 1:29 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)
m.korobeinikov added a comment to T4377: generate tech-support archive includes previous archives.
[email protected]:~$ show version
May 16 2022, 1:28 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)

Apr 29 2022

m.korobeinikov added a comment to T4377: generate tech-support archive includes previous archives.

https://github.com/vyos/vyatta-op/pull/55

Apr 29 2022, 3:23 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)

Apr 22 2022

m.korobeinikov added a comment to T4377: generate tech-support archive includes previous archives.

We can solve this problem in three ways.
Now the script (https://github.com/vyos/vyatta-op/blob/29703664633a20385a077083b4393738bdcb7409/scripts/tech-support-archive) creates up to 5 versions of support archives, after which it starts deleting the previous one. The problem is that each new version of the archives contains from 1 to 4 old archives. As a result, the archive can take up a lot of space.

Apr 22 2022, 1:46 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus ( 1.3.1)

Apr 17 2022

m.korobeinikov added a comment to T4348: Site access denied.

Of course. This restriction comes from the communication providers. Through (VPN) - everything works well.

Apr 17 2022, 9:50 PM

Apr 11 2022

m.korobeinikov added a comment to T4301: The "arp-monitor" option in bonding interface settings does not work.

VyOS 1.4-rolling-202204090217 works well.

Apr 11 2022, 1:25 AM · VyOS 1.4 Sagitta
m.korobeinikov added a comment to T4348: Site access denied.


From my ISP access is closed for more than a month.

Apr 11 2022, 12:33 AM

Apr 10 2022

m.korobeinikov changed the status of T4288: IPsec tunnel will break when ESP timeout from In progress to Needs testing.

I've tested the scenario using VyOS 1.4-rolling-202204090217 and (esp lifetime '30'). Attached is the config.
After turning on the right and left routers, IPsec creates two tunnels that are updated every 10 seconds. (Tunnels are updated using strange intervals, the first 1-10 seconds, the second 10-20 seconds).

Apr 10 2022, 10:30 PM · VyOS 1.4 Sagitta
m.korobeinikov changed the status of T4288: IPsec tunnel will break when ESP timeout from Needs testing to In progress.

I tested it with VyOS 1.4-rolling-202204090217 and it works well for a while.

Apr 10 2022, 2:26 AM · VyOS 1.4 Sagitta

Apr 4 2022

m.korobeinikov changed the status of T4246: Failed to delete vrrp transition-script from Open to Needs testing.
Apr 4 2022, 1:37 AM · VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov added a comment to T4246: Failed to delete vrrp transition-script.

@n.fort
I ve added this code in to the scrip and the issue resolved.
if [ "$(id -g -n)" != 'vyattacfg' ] ; then
exec sg vyattacfg -c "/bin/vbash $(readlink -f $0) [email protected]"
fi

Apr 4 2022, 1:35 AM · VyOS 1.3 Equuleus (1.3.0)

Mar 24 2022

m.korobeinikov updated the task description for T4319: The command "set system ipv6 disable" doesn't work as expected..
Mar 24 2022, 9:37 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)
m.korobeinikov created T4319: The command "set system ipv6 disable" doesn't work as expected..
Mar 24 2022, 9:33 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.2)

Mar 10 2022

m.korobeinikov added a comment to T4288: IPsec tunnel will break when ESP timeout.

Could you try to use "ikev2"? Will the same problem be if you use "ikev2"?

Mar 10 2022, 1:32 AM · VyOS 1.4 Sagitta

Mar 9 2022

m.korobeinikov added a comment to T4286: Fix for firewall ipv6 name address validator.

Similar situation in VyOS 1.3-stable-202202191602

Mar 9 2022, 10:47 PM · VyOS 1.4 Sagitta

Feb 27 2022

m.korobeinikov added a comment to T3600: DHCP Interface static route breaks PBR.

I ve tested it:

Feb 27 2022, 1:50 AM · VyOS 1.4 Sagitta

Feb 16 2022

m.korobeinikov triaged T4248: There isn't a way to remove the only rule from the (traffic-policy) class. as Low priority.
Feb 16 2022, 1:10 AM · VyOS 1.4 Sagitta

Feb 15 2022

m.korobeinikov updated subscribers of T4246: Failed to delete vrrp transition-script.
Feb 15 2022, 1:19 AM · VyOS 1.3 Equuleus (1.3.0)

Feb 14 2022

m.korobeinikov triaged T4246: Failed to delete vrrp transition-script as Low priority.
Feb 14 2022, 10:54 PM · VyOS 1.3 Equuleus (1.3.0)

Feb 5 2022

m.korobeinikov added a comment to T4087: IPsec IKE-group proposals limit of 10 pieces .

VyOS 1.4-rolling-202201041316 - works well.

Feb 5 2022, 2:43 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.2 Crux (VyOS 1.2.9)

Feb 2 2022

m.korobeinikov added a comment to T4210: NAT source/destination negated ports throws an error.

I've used for these tests (VyOS 1.4-rolling-202202010836)
The same situation in general when you want to use "!".
Bad exampels.

set nat source rule 10 destination port !1-5
set nat source rule 10 destination port !22
set nat source rule 10 destination port !http
set nat source rule 10 destination port telnet,!http,!123,1001-1005
set nat source rule 10 destination port telnet,http,!123,1001-1005
Feb 2 2022, 2:54 AM · VyOS 1.4 Sagitta

Feb 1 2022

m.korobeinikov added a comment to T4218: firewall: rule name is not allowed to start with a number.

( VyOS 1.4-rolling-202202010836)- Rule name which starts with a number work well.

Feb 1 2022, 9:44 PM · VyOS 1.4 Sagitta

Jan 29 2022

m.korobeinikov added a comment to T4218: firewall: rule name is not allowed to start with a number.

The same situation if you set the number or special symbol.

Jan 29 2022, 11:18 PM · VyOS 1.4 Sagitta
m.korobeinikov added a comment to T4214: [DHCP] static route dhcp-interface issues.

I've checked the same scenario on the cisco router.

Jan 29 2022, 10:04 PM · VyOS 1.3 Equuleus

Jan 28 2022

m.korobeinikov added a comment to T4215: Change the description of the "reboot in" command..

Good question. I missed this moment.
So, if you want to reload in some minutes, VYOS offered you two variants:

  1. To choose between 1 and 99
  2. To set time when you want to reload VYOS if 99 minutes too short for you (for example 10:00, 12:45, 23:59, and so on)

But descriptions of thees command doesn't have enough information about it.

Jan 28 2022, 9:52 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
m.korobeinikov created T4215: Change the description of the "reboot in" command..
Jan 28 2022, 2:18 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
m.korobeinikov closed T4115: reboot in <x> not working as expected as Resolved.

We didn't receive the customer's request.
The timers work without problems.
I'll open a design request to see the range 1-99.

Jan 28 2022, 2:05 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
m.korobeinikov added a comment to T4214: [DHCP] static route dhcp-interface issues.

I have emulated the same scenario in to vyos VyOS 1.4-rolling-202201041316
And it works well.
{

[email protected]:~$ show dhcp client leases
interface  : eth0
ip address : 172.168.32.146     [Active]
subnet mask: 255.255.255.0
domain name: localdomain        [overridden by domain-name set using CLI]
router     : 172.168.32.2
name server: 172.168.32.2
dhcp server: 172.168.32.254
lease time : 1800
last update: Fri Jan 28 01:09:31 UTC 2022
expiry     : Fri Jan 28 01:39:30 UTC 2022
reason     : RENEW
Jan 28 2022, 1:47 AM · VyOS 1.3 Equuleus

Jan 21 2022

m.korobeinikov added a comment to T4154: Error add second gre tunnel with the same source interface.

(VyOS 1.4-rolling-202201200814) - The same.

Jan 21 2022, 2:39 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta
m.korobeinikov added a comment to T4137: Firewall group configuration allows to set incorrect port range and invalid port.

I ve testet it on (Version:VyOS 1.4-rolling-202201200814). It seems well.

Jan 21 2022, 2:21 AM · VyOS 1.4 Sagitta
m.korobeinikov added a comment to T4115: reboot in <x> not working as expected.

I ve tested this scenario on VyOS 1.4-rolling-202201200814, as said Srividya you can choose minutes betwen 1-99.
If this is critical, you can expand the range by opening a "feature request".

Jan 21 2022, 12:52 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus

Jan 17 2022

m.korobeinikov added a comment to T4100: Firewall increase maximum number of rules.

I think we will have a problem with such a large number of rules. Now, if there are 1500 vyos rules, it takes 30 minutes to load. If there are 999999 rules, it will take a very long time to load.

Jan 17 2022, 12:53 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Dec 24 2021

m.korobeinikov added a comment to T4080: Space in "description" commands.

@Viacheslav
If i use this format ('test test test') it works well.
Is it possible using description with space without '' ?

Dec 24 2021, 2:56 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov changed the status of T4080: Space in "description" commands from Open to Needs testing.
Dec 24 2021, 2:40 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)

Dec 21 2021

m.korobeinikov added a comment to T4078: A hybrid of "network-group" and "address-group"..

@adestis thank you. This issue isn't critical. It's more for to improve the design and for convenience of our customers.
You can use /32 to add a host, but we have to have the opportunity to add hosts without masks.
For example, if you need to create a group consisting of 1000 (or more random hosts), it's more convenient to use configuration without masks.

Dec 21 2021, 12:11 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)

Dec 17 2021

m.korobeinikov closed T3176: Ordering of ports on EdgeCore SAF51015I is mixed up? as Resolved.

I ve check this situation on VyOS 1.3(beta-202112120443) and 1.4(rolling-202112160318) (platform SAF51015I) and interfases didont confus.

Dec 17 2021, 1:57 AM · VyOS 1.3 Equuleus (1.3.0)

Dec 16 2021

m.korobeinikov changed the status of T3176: Ordering of ports on EdgeCore SAF51015I is mixed up? from Open to Needs testing.

The bug was fixed. Need to check on SAF51015I platform

Dec 16 2021, 1:02 PM · VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov updated the task description for T4080: Space in "description" commands.
Dec 16 2021, 5:17 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov changed Issue type from unspecified to feature on T4080: Space in "description" commands.
Dec 16 2021, 3:57 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov created T4080: Space in "description" commands.
Dec 16 2021, 3:57 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov created T4079: Source/Destination NAT GROUP.
Dec 16 2021, 2:18 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov updated the task description for T4078: A hybrid of "network-group" and "address-group"..
Dec 16 2021, 2:07 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov created T4078: A hybrid of "network-group" and "address-group"..
Dec 16 2021, 2:05 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)

Dec 13 2021

m.korobeinikov reopened T4059: VRRP sync-group transition script does not persist after reboot as "Needs testing".
Dec 13 2021, 12:47 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov closed T4059: VRRP sync-group transition script does not persist after reboot as Resolved.

@c-po Everything works well, thanks. I've checked on this version (VyOS 1.3-beta-202112120443).
I m going to check it on 1.4

Dec 13 2021, 12:07 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)

Dec 10 2021

m.korobeinikov changed the status of T4059: VRRP sync-group transition script does not persist after reboot from Needs testing to In progress.
Dec 10 2021, 6:24 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov added a comment to T4059: VRRP sync-group transition script does not persist after reboot.

I've checked it and what we have:

Dec 10 2021, 6:23 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov changed the status of T4062: VRRP IPSEC-AH : sequence number xxxxxxx already processed. Packet dropped. Local(xxxxxxx) from Open to Needs testing.
Dec 10 2021, 12:51 AM · VyOS 1.3 Equuleus
m.korobeinikov reopened T4059: VRRP sync-group transition script does not persist after reboot as "Needs testing".
Dec 10 2021, 12:33 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov added a comment to T4059: VRRP sync-group transition script does not persist after reboot.

As I understand it, after the reboot, the following scenarios are running:

Dec 10 2021, 12:29 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)

Dec 9 2021

m.korobeinikov closed T4059: VRRP sync-group transition script does not persist after reboot as Resolved.

"VyOS 1.4-rolling-202112081536" : sync-group scripts work well after rebooting.

Dec 9 2021, 4:29 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov added a comment to T4059: VRRP sync-group transition script does not persist after reboot.

I've checked this bug on "VyOS 1.3-beta-202112080938", everything is well.
After rebooting scripts(sync-groups) work as needed.

Dec 9 2021, 1:09 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)

Dec 7 2021

m.korobeinikov added a comment to T4059: VRRP sync-group transition script does not persist after reboot.

Thank you for sharing your information.

Dec 7 2021, 12:49 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)
m.korobeinikov added a comment to T4059: VRRP sync-group transition script does not persist after reboot.

I confirm the bug. After rebooting script doesn't work on sync-groups. It's necessary to reload vrrp to start running the script (After rebooting).
More detail:
https://phabricator.vyos.net/T4041

Dec 7 2021, 5:26 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0)

Dec 6 2021

m.korobeinikov reopened T4041: "transition-script" doesn't work on "sync-group" as "Open".

I tested this bug on "vyos-1.3-beta-202112060443".


The problem has been partially resolved. If you restart VYOS, scripts on syn-groups don't work. After using the "vrrp restart" command, everything is ok.

Dec 6 2021, 11:46 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
m.korobeinikov added a project to T4033: VRRP - Error security when setting scripts: VyOS 1.4 Sagitta.
Dec 6 2021, 8:05 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
m.korobeinikov added a comment to T4033: VRRP - Error security when setting scripts.

I have the same problem. I created a script, but it doesn't work. VRRP Log write that the skript is unsecure.

Dec 6 2021, 6:13 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Dec 3 2021

m.korobeinikov added a comment to T4041: "transition-script" doesn't work on "sync-group".

I checked it on these versions of VYOS. (VyOS 1.3.0-epa3, VyOS 1.3-beta-202112010443 , VyOS 1.4-rolling-202112021432)

Dec 3 2021, 12:55 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus
m.korobeinikov created T4041: "transition-script" doesn't work on "sync-group".
Dec 3 2021, 12:50 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus

Nov 8 2021

m.korobeinikov added a comment to T3960: FRR Misconfig when using multiple VRF VNI.

If you add configuration to "vtysh" will you see config like this or another:

Nov 8 2021, 5:01 AM · VyOS 1.4 Sagitta