Page MenuHomeVyOS Platform

panachoi (Adam Feigin)
User

Projects

User does not belong to any projects.

User Details

User Since
Oct 18 2017, 6:35 AM (245 w, 3 d)

Recent Activity

Sun, Jun 12

panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

Thanks for the pointer, but I think it should still be considered a "bug" that you can no longer use an empty group (I'm just going to assume that this would apply to any kind of group, but most are probably using this for host/network groups, as this is where it would be most useful). Judging from the comments in T4147, I'm clearly not the only one who was taking advantage of managing sets outside of the system. Alas, my boot times for 1.4 (what this discussion is about) are not really valid, as my configuration didn't really get migrated from 1.3.1->1.4, or better said, it doesn't actually commit, and I actually ended up with a mostly empty firewall config on boot, which is perhaps why its booting so quickly now.

Sun, Jun 12, 7:09 AM · VyOS 1.3 Equuleus (1.3.0)

Fri, Jun 10

panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

Indeed, I figured that out. I also found that my openvpn config was not migrated properly (T3642?); all of the tls configuration stuff (previously kept under /config/auth somewhere) was gone. After doing run import pki for all of the necessary bits it was able at least to commit properly.

Fri, Jun 10, 1:02 PM · VyOS 1.3 Equuleus (1.3.0)
panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

Sorry its taken me so long to follow up on this

Fri, Jun 10, 8:10 AM · VyOS 1.3 Equuleus (1.3.0)

May 29 2022

panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

This vm started out with 4G of memory and 2CPUs; I doubled quickly everything when I hit the out of memory error the first time, but that didn't help. I can quickly install the latest rolling and test

May 29 2022, 12:18 PM · VyOS 1.3 Equuleus (1.3.0)
panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

I've debugged this further, by breaking up my configuration into various sections (system, interfaces, firewall,nat,service,vpn etc) and running them on a new VM.

May 29 2022, 8:09 AM · VyOS 1.3 Equuleus (1.3.0)
panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

Still not much luck here. But I've let the boot run a bit longer, and notice the following:

May 29 2022, 5:48 AM · VyOS 1.3 Equuleus (1.3.0)

May 28 2022

panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

Okay, thats the only rule where I was using a port-group combined with protocol all; the others that use protocol all dont have a port or port group in the rule, so they are okay?

May 28 2022, 5:50 AM · VyOS 1.3 Equuleus (1.3.0)

May 27 2022

panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

1.4 rolling does not help me, so there must be something "wrong" with my configuration. I've attached the private config, it would be awesome if someone might find what's broken.

May 27 2022, 4:52 AM · VyOS 1.3 Equuleus (1.3.0)

May 26 2022

panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

I'm still having issues moving past anything higher than 1.2.8. Booting 1.2.8 looks thusly:

May 26 2022, 9:47 AM · VyOS 1.3 Equuleus (1.3.0)

Feb 6 2022

panachoi added a comment to T2088: Increased boot time from 1.2.4 -> 1.3 rolling by 100%.

Sorry, but I dont think this is fixed; I just attempted to upgrade my working 1.2.8 configuration to 1.3.

Feb 6 2022, 8:45 AM · VyOS 1.3 Equuleus (1.3.0)

Jan 9 2020

panachoi added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

I'm also affected by this, but even with a relatively "small" configuration (2662 lines, at present, where more than half are firewall rules, 5 interfaces).

Jan 9 2020, 2:03 PM · VyOS 1.3 Equuleus (1.3.0)

Aug 22 2018

panachoi added a comment to T739: flow-accounting stops.

Just updated to build from 20180821, and its still stopping; I'm glad that I'm not the only one seeing this, so it probably is some kind of bug. Again, nothing in the log at all, just the startup:

Aug 22 2018, 5:39 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct

Jul 11 2018

panachoi added a comment to T739: flow-accounting stops.

Sure. The "best" way to visualize flow data is to install nfdump/nfsen:

Jul 11 2018, 6:58 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct

Jul 10 2018

panachoi updated the task description for T739: flow-accounting stops.
Jul 10 2018, 8:05 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct
panachoi created T739: flow-accounting stops.
Jul 10 2018, 8:03 AM · VyOS 1.2 Crux (VyOS 1.2.0-GA), VyOS-1.2.0-GA, pmacct

Oct 18 2017

panachoi triaged T427: Wireguard support as Wishlist priority.
Oct 18 2017, 6:40 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)
panachoi created T427: Wireguard support.
Oct 18 2017, 6:40 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc1)