Page MenuHomeVyOS Platform

maznu (Marek Isalski)
User

Projects

User does not belong to any projects.

User Details

User Since
Apr 24 2019, 5:50 AM (63 w, 1 d)

Recent Activity

May 6 2020

maznu added a comment to T1698: prefix-list and/or route-map not configured before referencing BGP neighbor is configured (BGP session established before filters applied).

The good news is that this can be fixed with:

May 6 2020, 12:44 PM

May 4 2020

maznu added a comment to T2425: Rewrite policy prefix-list to XML/Python style.

Would love to see this resolved — a large (but reasonable) configuration doing IRR-based filtering from BGP peers took 9 hours to boot up.

May 4 2020, 4:43 PM · VyOS 1.3 Equuleus
maznu added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

We don't do any firewalling — we have lots of prefix-lists for filtering eBGP sessions. Right now we're looking at a router that's taken more than 1h20minutes to boot up — and it is still not finished — on modern Xeon CPUs. That's doubled in length since adding a prefix-list of around 5000 entries (roughly double the total number of prefix-list entries as before).

May 4 2020, 8:46 AM · VyOS 1.3 Equuleus

Apr 28 2020

maznu added a comment to T2214: BGP peers dropping randomly.

We've got full IPv4 and IPv6 routing tables on our VyOS boxes, and we *definitely* needed to increase net.ipv6.route.max_size (we picked 256k to give us some headroom).

Apr 28 2020, 6:11 PM · VyOS 1.2 Crux

Apr 18 2020

maznu added a comment to T2044: RPKI doesn't boot properly.

While testing T1874 the procedure we followed was:

Apr 18 2020, 7:48 AM · VyOS 1.3 Equuleus
maznu added a comment to T1874: FRR crashing triggered by RPKI.

This is looking like it might be fixed in FRR version 7.2.1 onwards:

Apr 18 2020, 7:13 AM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus
maznu added a comment to T1874: FRR crashing triggered by RPKI.

We managed to reproduce this on a test instance running VyOS 1.2.4 talking RTRR to Routinator3000 0.6.4:

Apr 18 2020, 7:10 AM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Apr 17 2020

maznu added a comment to T2044: RPKI doesn't boot properly.

We saw something similar to this, but it seems like FRR eventually connected to RTRR. I think it has a timeout parameter — is that how often (slowly) it tries to re-establish?

Apr 17 2020, 8:20 PM · VyOS 1.3 Equuleus
maznu added a comment to T1874: FRR crashing triggered by RPKI.

We had this bug earlier today on 1.2.4.

Apr 17 2020, 8:18 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Apr 4 2020

maznu added a comment to T2218: Add support for the peeringdb module in salt (upgrade salt-minion to 2019.2).

Can highly recommend: http://repo.saltstack.com/2019.2.html#debian (includes Jessie)

Apr 4 2020, 9:56 AM · VyOS 1.3 Equuleus
maznu updated the task description for T2218: Add support for the peeringdb module in salt (upgrade salt-minion to 2019.2).
Apr 4 2020, 9:55 AM · VyOS 1.3 Equuleus
maznu created T2218: Add support for the peeringdb module in salt (upgrade salt-minion to 2019.2).
Apr 4 2020, 9:54 AM · VyOS 1.3 Equuleus

Mar 25 2020

maznu added a comment to T1894: FRR config not loaded after daemons segfault or restart.

I'm not expecting a persisted-across-reboots FRR config — hence suggesting tmpfs — so when the system boots there is nothing there. Obviously something would need to create the (empty) FRR config files in tmpfs before running FRR, otherwise I expect all the FRR daemons will fail to start.

Mar 25 2020, 3:34 PM · VyOS 1.3 Equuleus
maznu added a comment to T1894: FRR config not loaded after daemons segfault or restart.

We've seen this recently on bleeding-edge (yesterday's version) of 1.3. I'm currently investigating what tripped ospf6d, but I suspect it's going to be some Ubiquiti routers spewing their nasty OSPFv3 implementation.

Mar 25 2020, 9:25 AM · VyOS 1.3 Equuleus

Sep 29 2019

maznu added a comment to T1699: net.ipv6.route.max_size = 32768.

Agreed, I'm going to workaround with set system sysctl custom, but also submit a PR: https://github.com/vyos/vyatta-cfg-system/pull/107

Sep 29 2019, 8:50 PM · VyOS 1.2 Crux (VyOS 1.2.6)
maznu created T1699: net.ipv6.route.max_size = 32768.
Sep 29 2019, 12:18 PM · VyOS 1.2 Crux (VyOS 1.2.6)
maznu updated the task description for T1698: prefix-list and/or route-map not configured before referencing BGP neighbor is configured (BGP session established before filters applied).
Sep 29 2019, 9:23 AM
maznu created T1698: prefix-list and/or route-map not configured before referencing BGP neighbor is configured (BGP session established before filters applied).
Sep 29 2019, 9:23 AM
maznu added a comment to T1514: Add ability to restart frr processes.

…or, indeed, it'd be great to be able to restart FRR and have it get a new config when this happened just now:

Sep 29 2019, 3:40 AM · VyOS 1.3 Equuleus

Sep 23 2019

maznu added a comment to T1679: during bootup: invalid literal for int() with base 10.

That's fixed the problem we had, but we've encountered some other strangeness.

Sep 23 2019, 10:27 PM · VyOS 1.3 Equuleus
maznu added a comment to T1679: during bootup: invalid literal for int() with base 10.

Thank you, @c-po, I'll go deploy it now, then! :-)

Sep 23 2019, 4:18 PM · VyOS 1.3 Equuleus
maznu added a comment to T1679: during bootup: invalid literal for int() with base 10.

Has this been merged into 1.2, or just 1.3? Because all of the 1.2-rolling images currently available from downloads.vyos.io right now have this bug in them :-(

Sep 23 2019, 3:42 PM · VyOS 1.3 Equuleus
maznu added a comment to T1237: Static Route Path Monitoring.

MikroTik RouterOS supports something like this:

Sep 23 2019, 3:34 PM · VyOS 1.3 Equuleus
maznu added a comment to T732: Netflow: generate ASNs from the uacctd BGP thread..

Why does this BGP neighbor need to be configred in the VyOS CLI? Wouldn't it be added automatically as a side-effect of wanting netflow data to have ASNs? Maybe add a flag to netflow, for those of us who are carrying full tables.

Sep 23 2019, 3:31 PM · VyOS 1.3 Equuleus
maznu added a comment to T1514: Add ability to restart frr processes.

Having had bgpd peg a core to 100% (for no discernible reason), I'd welcome the ability to give quag^WFRR a kick, rather than rebooting the entire VyOS box.

Sep 23 2019, 3:14 PM · VyOS 1.3 Equuleus
maznu added a comment to T1520: Advanced network monitoring: nTop or similar.

We run ntop on a separate device, and export netflow data to the ntop/nprobe box from our routers (VyOS included). Would that work in your scenario too?

Sep 23 2019, 3:12 PM · VyOS 1.3 Equuleus
maznu added a comment to T1679: during bootup: invalid literal for int() with base 10.

Symptoms which cause no configuration of the device after booting into 1.2:

Sep 23 2019, 3:01 PM · VyOS 1.3 Equuleus
maznu added a comment to T1679: during bootup: invalid literal for int() with base 10.

PR to fix this: https://github.com/vyos/vyos-1x/pull/136

Sep 23 2019, 3:00 PM · VyOS 1.3 Equuleus
maznu created T1679: during bootup: invalid literal for int() with base 10.
Sep 23 2019, 2:56 PM · VyOS 1.3 Equuleus