Page MenuHomeVyOS Platform

n.fort (Nicolas)
User

Projects

User Details

User Since
Jun 9 2021, 3:23 PM (24 w, 3 d)

Recent Activity

Sat, Nov 13

n.fort created T3989: Firewall - Can't delete rule in firewall entry and leave just default-action when firewall entry is in used.
Sat, Nov 13, 11:27 AM · VyOS 1.3 Equuleus

Sun, Oct 31

n.fort added a comment to T3873: Zone based Firewall - Filter traffic in same zone.

This entries:

Sun, Oct 31, 4:25 PM · VyOS 1.4 Sagitta
n.fort added a comment to T3873: Zone based Firewall - Filter traffic in same zone.

Same request: T292

Sun, Oct 31, 3:01 PM · VyOS 1.4 Sagitta
n.fort added a comment to T3933: The firewall does not filter incoming traffic on the interface with vrf..

Definitely miss behavior is generated by the new interface MGT that was created when assigning MGT vrf to eth0.

Sun, Oct 31, 1:45 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
n.fort added a comment to T2251: VRF communication breaks when utilizing zone-based firewalling.

Bug still present in 1.3.0-epa2 version.

Sun, Oct 31, 11:40 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Fri, Oct 29

n.fort added a comment to T1293: Zone-policy implementation does not allow secondary IP on an interface to communicate.

I have done a lab using 1.3.0-epa2 version, and got no troubles.
Have configured 2 IP addresses on interface, and configured zone based firewall. I'm able to ping everywhere, using both IP addresses of that interface.
Also I checked that counters on firewall rules got increased while pinging from any of both IP addresses.

Fri, Oct 29, 7:14 PM · VyOS 1.3 Equuleus

Oct 26 2021

n.fort added a comment to T3944: VRRP fails over when adding new group to master.

Same procedure on 1.2.8, when adding new settings to master, it all remains as master.
Log after commit

Oct 26 2021, 6:17 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.4 Sagitta

Oct 20 2021

n.fort added a comment to T3626: Configuring and disabling DHCP Server.

Well.. Actually when only one dhcp-server shared network is defined, service can be disbable with global disable for dhcp-server

Oct 20 2021, 1:02 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
n.fort added a comment to T3626: Configuring and disabling DHCP Server.

So, in a very very simple config like this, user is not able to enable and disable dhcp-server with just a simple command?

Oct 20 2021, 12:56 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
n.fort added a comment to T3626: Configuring and disabling DHCP Server.

Error still present in 1.3.0-epa2 version:

Oct 20 2021, 12:21 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta

Oct 18 2021

n.fort added a comment to T3610: DHCP-Server creation for not primary IP address fails.

Other test.
In same lab, pool for LAN subnet was modified:

Oct 18 2021, 4:51 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
n.fort added a comment to T3610: DHCP-Server creation for not primary IP address fails.

More tests where done on version 1.3.0-epa1.
First, dhcp_server.py was modified as indicated.

Oct 18 2021, 3:27 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
n.fort closed T3002: VRRP change on IPSec interface causes packet routing issues as Resolved.

Resolved using

Oct 18 2021, 2:21 PM · VyOS 1.4 Sagitta

Oct 17 2021

n.fort added a comment to T3002: VRRP change on IPSec interface causes packet routing issues.

Tests were done using 1.2.8 and 1.3.0-rc6 version.
Same inconvenient present as described.
Problems is that a default route is added in table 220

Oct 17 2021, 6:46 PM · VyOS 1.4 Sagitta

Oct 14 2021

n.fort added a comment to T3907: Firewall - Set log levels.

Maybe, but if the effort is made in order to be able to configure log level, it would be good that it can be set in different levels.
I'm thinking in a mix scenario, where majority of rules may log with info/debug level (for example default accept rules), while other rules may need a warning/error level (some drop rules).

Oct 14 2021, 1:00 PM · VyOS 1.4 Sagitta
n.fort created T3907: Firewall - Set log levels.
Oct 14 2021, 12:31 PM · VyOS 1.4 Sagitta

Oct 2 2021

n.fort created T3883: VRF - Delette vrf config on interface.
Oct 2 2021, 2:59 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.0-epa2)

Sep 29 2021

n.fort created T3873: Zone based Firewall - Filter traffic in same zone.
Sep 29 2021, 6:12 PM · VyOS 1.4 Sagitta

Sep 24 2021

n.fort added a comment to T3435: NAT rules show corruption.

Bug still present.

Sep 24 2021, 12:35 PM · VyOS 1.4 Sagitta

Sep 2 2021

n.fort updated the task description for T3793: Syslog - Improve error handling.
Sep 2 2021, 1:55 PM · VyOS 1.2 Crux (VyOS 1.2.9)
n.fort updated the task description for T3793: Syslog - Improve error handling.
Sep 2 2021, 1:53 PM · VyOS 1.2 Crux (VyOS 1.2.9)
n.fort updated the task description for T3793: Syslog - Improve error handling.
Sep 2 2021, 1:52 PM · VyOS 1.2 Crux (VyOS 1.2.9)
n.fort created T3793: Syslog - Improve error handling.
Sep 2 2021, 1:51 PM · VyOS 1.2 Crux (VyOS 1.2.9)

Jun 15 2021

n.fort added a comment to T3610: DHCP-Server creation for not primary IP address fails.

At least on simple tests, this modification seems to work.
I have tested on version 1.3, first configuring dhcp server for both addresses: for the one that was defined first, and one for the las IP address defined (of course, one instance of dhcp-server running at a time).
If this needs more testes, let me know what I can do for you.

Jun 15 2021, 8:16 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
n.fort created T3626: Configuring and disabling DHCP Server.
Jun 15 2021, 5:56 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta
n.fort created T3625: Configuring and deletting DHCP Server.
Jun 15 2021, 5:49 PM · VyOS 1.2 Crux

Jun 9 2021

n.fort created T3610: DHCP-Server creation for not primary IP address fails.
Jun 9 2021, 3:35 PM · VyOS 1.3 Equuleus (1.3.0-epa3), VyOS 1.2 Crux (VyOS 1.2.9), VyOS 1.4 Sagitta