Page MenuHomeVyOS Platform

rherold (Ruben Herold)
User

Projects

User Details

User Since
Oct 12 2018, 10:21 PM (111 w, 4 d)

Recent Activity

Oct 17 2020

rherold created T2988: ip source validation not working for ipv6 aka move it to netfilter.
Oct 17 2020, 7:10 PM · VyOS 1.2 Crux

Jul 4 2020

rherold created T2683: no dual stack in system static-host-mapping host-name .
Jul 4 2020, 8:49 PM
rherold added a comment to T2678: High RAM usage on SSH logins with lots of IPv6 routes in the routing table..

for me it looks like a name lookup error. I have read the forum entry mentioned above. And they fixed it by disabling name lookup.

Jul 4 2020, 7:09 AM · VyOS 1.3 Equuleus

Jun 8 2020

rherold created T2567: accel-ppp eats al memory with small sstp config.
Jun 8 2020, 12:02 PM · VyOS 1.3 Equuleus
rherold created T2566: sstp not able to run tunnels ipv6 only.
Jun 8 2020, 11:59 AM

May 21 2020

njh awarded T1156: VyOS sticker templates a Like token.
May 21 2020, 8:24 PM · Active contributors
njh awarded T1156: VyOS sticker templates a Love token.
May 21 2020, 8:24 PM · Active contributors

Apr 23 2020

rherold created T2371: custom dyndns configuration lost after upgrade from 1.2.4-epa1 to 1.2.5.
Apr 23 2020, 3:56 PM · VyOS 1.2 Crux

Feb 28 2020

rherold added a comment to T2044: RPKI doesn't boot properly.

looks for my like an frr bug. Has someone contacted upstream?

Feb 28 2020, 4:58 PM · VyOS 1.3 Equuleus

Feb 23 2020

rherold added a comment to T1301: bgp peer-groups don't work when "no-ipv4-unicast" is enabled..

https://github.com/vyos/vyatta-cfg-quagga/pull/43 created

Feb 23 2020, 7:57 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.5)
rherold added a comment to T1301: bgp peer-groups don't work when "no-ipv4-unicast" is enabled..

removing the check makes it work like a charme push request incomming..

Feb 23 2020, 7:50 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.5)
rherold added a comment to T1301: bgp peer-groups don't work when "no-ipv4-unicast" is enabled..

run into the same. If I add parameters default 'no-ipv4-unicast' to my config and commit I get the waring above. All runs fine, cause the sessions where already configured before.
If I do a reboot, bgp config in frr is neartly empty only "router bgp 64512" was there not more. Removing it and do an commit nothing changed. Removing it an reboot helped.

Feb 23 2020, 7:36 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.5)

Feb 21 2020

rherold added a comment to T2058: RCE in pppd and ppp client.

Pull Request: https://github.com/vyos/ppp-upstream/pull/2

Feb 21 2020, 7:32 PM · VyOS-1.2.0-GA
rherold created T2060: source-validation will be configured at different locations and could lead to massiv confusion.
Feb 21 2020, 9:37 AM · VyOS 1.3 Equuleus, VyOS-1.2.0-GA
rherold added a comment to T2058: RCE in pppd and ppp client.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8597

Feb 21 2020, 8:24 AM · VyOS-1.2.0-GA
rherold renamed T2058: RCE in pppd and ppp client from Possible RCE in pppd and ppp client to RCE in pppd and ppp client.
Feb 21 2020, 8:24 AM · VyOS-1.2.0-GA

Feb 20 2020

rherold added a comment to T2059: Set source-validation on bond vif don't work.

I send a pull request to fix it:

Feb 20 2020, 7:49 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus
rherold created T2059: Set source-validation on bond vif don't work.
Feb 20 2020, 7:33 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus
rherold created T2058: RCE in pppd and ppp client.
Feb 20 2020, 6:18 PM · VyOS-1.2.0-GA

Feb 12 2020

rherold added a comment to T31: Add VRF support.

I think we should make somewhere a list of services and which level of vrf support they have.
Openssh for example has build in support for vrf

Feb 12 2020, 12:43 PM · VyOS 1.3 Equuleus
rherold added a comment to T31: Add VRF support.

Could be away. But from my experience most people use vrf to seperate managment from production, and as second prio seperate customers and so on.
But the managment vrf must not be the "default" vrf.

Feb 12 2020, 12:15 PM · VyOS 1.3 Equuleus

Jan 2 2020

rherold added a comment to T1933: Changes in /config/scripts/vyos-postconfig-bootup.script got lost during upgrade to 1.2.4.

I got this on two production systems on the next two I migrated I changed my workflow to:

Jan 2 2020, 11:13 AM · VyOS 1.3 Equuleus
rherold created T1933: Changes in /config/scripts/vyos-postconfig-bootup.script got lost during upgrade to 1.2.4.
Jan 2 2020, 10:27 AM · VyOS 1.3 Equuleus

Nov 12 2019

rherold added a comment to T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP.

In this way we could also add vpp nat64 running complete in vpp independent from all other vyos services:

Nov 12 2019, 11:07 AM · Restricted Project
rherold awarded T1797: Implement DPDK Fast-Path using FRR's Alternate Forwarding Planes and VPP a Like token.
Nov 12 2019, 11:05 AM · Restricted Project

Nov 10 2019

rherold awarded T1788: Intel QAT (QuickAssist Technology ) implementation a Like token.
Nov 10 2019, 10:26 AM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus
rherold awarded T31: Add VRF support a Like token.
Nov 10 2019, 10:23 AM · VyOS 1.3 Equuleus

Oct 9 2019

rherold added a comment to T1183: BFD Support via FRR.

@cpo cumulus behave differently cause they use an other implementation as in pure frr. They use PTMD see https://docs.cumulusnetworks.com/cumulus-linux/Layer-3/Bidirectional-Forwarding-Detection-BFD/ and https://github.com/CumulusNetworks/ptm

Oct 9 2019, 8:06 AM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus

Sep 24 2019

rherold added a comment to T1020: OSPF Stops distributing default route after a while.

Seems that it s merged an in 1.2.3 it looks in the moment good for me:

Sep 24 2019, 3:06 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Sep 18 2019

rherold added a comment to T1020: OSPF Stops distributing default route after a while.

Seems that upstream did not backport the fixes to the stable version's. So it is only included in frr 7.2.
I asked them for backport.

Sep 18 2019, 9:52 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Aug 8 2019

rherold added a comment to T1567: BGP communities Filtering.

You can add a community via route-map to your outgoing routes.

Aug 8 2019, 8:47 AM · Rejected

Aug 2 2019

rherold added a comment to T1020: OSPF Stops distributing default route after a while.

I have setup two vyos router and one is origination default.
All runs fine with this patches since more then 40 minutes so it fixes the problems.

Aug 2 2019, 3:40 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Jul 31 2019

rherold added a comment to T1020: OSPF Stops distributing default route after a while.

Can we make a nightly with the patches from:

Jul 31 2019, 10:46 AM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Jul 30 2019

rherold added a comment to T1550: Add support for Large BGP Community show commands.

https://github.com/vyos/vyatta-op-quagga/pull/3 I hope now it looks better

Jul 30 2019, 12:36 PM · VyOS 1.3 Equuleus
rherold added a comment to T1550: Add support for Large BGP Community show commands.

Did I something wrong with https://phabricator.vyos.net/T1550 and https://github.com/vyos/vyatta-op-quagga/pull/2 that the pull request is not showing in phabricator?

Jul 30 2019, 9:46 AM · VyOS 1.3 Equuleus
rherold created T1550: Add support for Large BGP Community show commands.
Jul 30 2019, 8:49 AM · VyOS 1.3 Equuleus

Jul 29 2019

rherold added a comment to T1020: OSPF Stops distributing default route after a while.

https://github.com/FRRouting/frr/pull/4742 let's give it a try?

Jul 29 2019, 1:16 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Jul 25 2019

rherold added a comment to T1020: OSPF Stops distributing default route after a while.

Some Feedback from the frr people:

Jul 25 2019, 2:24 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Jul 23 2019

rherold added a comment to T1020: OSPF Stops distributing default route after a while.

Run into the same with 1.2.2

Jul 23 2019, 3:02 PM · VyOS 1.2 Crux (VyOS 1.2.5), VyOS 1.3 Equuleus

Jul 15 2019

rherold added a comment to T1529: BGP unnumbered is not working with a vif interface.

I created a pull request to fix it. @guertinf has already test the fix

Jul 15 2019, 9:47 PM · VyOS 1.2 Crux (VyOS 1.2.3), VyOS 1.3 Equuleus

Jul 6 2019

rherold created T1509: Support for BGP replace-as option in the S1 VyOS Public space.
Jul 6 2019, 9:36 PM · VyOS 1.2 Crux (VyOS 1.2.2)

Jul 5 2019

rherold added a comment to T1183: BFD Support via FRR.

For my point of view this is a dependency from the bfd protocol specs.

Jul 5 2019, 8:02 AM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus

Jun 27 2019

rherold created T1493: PPPoE IPv6 prefix delegation in the S1 VyOS Public space.
Jun 27 2019, 12:28 PM · VyOS 1.3 Equuleus

May 30 2019

rherold added a comment to T1309: allow duplicate ip adresses on different interfaces.

I have added the Documentation:

May 30 2019, 9:51 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus
rherold added a comment to T1309: allow duplicate ip adresses on different interfaces.

As far as I can see it is included in 1.2.1 so we can close this or?
If yes I will submit a config example for ospf ip unnumbered that uses it

May 30 2019, 12:08 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus

May 29 2019

rherold added a comment to T1243: BGP local-as accept wrong values.

Try: https://github.com/vyos/vyatta-cfg-quagga/pull/27/commits/8c741da0691cb392a86f249b61c3686a034f908a

May 29 2019, 12:54 PM · VyOS 1.3 Equuleus
rherold added a comment to T1390: Extend bgp config for bestpath as-path multipath-relax.

https://github.com/vyos/vyatta-cfg-quagga/pull/27 < -- seems to look better

May 29 2019, 12:54 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.2)

May 28 2019

rherold added a comment to T1390: Extend bgp config for bestpath as-path multipath-relax.

See my pull request: https://github.com/vyos/vyatta-cfg-quagga/pull/26

May 28 2019, 3:29 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.2)
rherold added a comment to T1243: BGP local-as accept wrong values.

from Slack

May 28 2019, 2:27 PM · VyOS 1.3 Equuleus
rherold added a comment to T1243: BGP local-as accept wrong values.

can it be that the fix for T1243 is broken? I can understand that local-as can't be the same like remote-as if router-as diff from local-as but the patch forbit to set remote-as to the same like router-as that will break ibgp

May 28 2019, 2:26 PM · VyOS 1.3 Equuleus

May 20 2019

rherold added a comment to T1390: Extend bgp config for bestpath as-path multipath-relax.

I want to build a setup like described in:

May 20 2019, 7:23 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.2)
rherold created T1390: Extend bgp config for bestpath as-path multipath-relax in the S1 VyOS Public space.
May 20 2019, 7:08 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux (VyOS 1.2.2)

Mar 26 2019

rherold updated subscribers of T1309: allow duplicate ip adresses on different interfaces.

@dmbaturin can you explain why we schedule it to the next release and not to 1.2.1 for example? Are there any policies?

Mar 26 2019, 8:46 AM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus

Mar 25 2019

rherold created T1316: Support for IS-IS .
Mar 25 2019, 9:54 PM · VyOS 1.3 Equuleus
rherold added a comment to T915: MPLS Support.

I want write an follow up.

Mar 25 2019, 8:55 PM · VyOS 1.3 Equuleus
rherold created T1315: Allow BGP to use address-family l2vpn evpn.
Mar 25 2019, 8:40 PM · VyOS 1.3 Equuleus
rherold created T1314: Allow BGP on unnumbered interfaces.
Mar 25 2019, 8:28 PM · VyOS 1.3 Equuleus

Mar 21 2019

rherold added a comment to T1309: allow duplicate ip adresses on different interfaces.
In T1309#34455, @runar wrote:

As i see it this is a fundamental change and should not be allowed into 1.2 LTS but it migth be added to 1.3 (just a opinion, not a decition)

Mar 21 2019, 5:33 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus
rherold added a comment to T1309: allow duplicate ip adresses on different interfaces.

seems so but:

Mar 21 2019, 4:36 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus
rherold created T1309: allow duplicate ip adresses on different interfaces.
Mar 21 2019, 3:23 PM · VyOS 1.2 Crux (VyOS 1.2.2), VyOS 1.3 Equuleus

Mar 17 2019

rherold added a comment to T1183: BFD Support via FRR.

Here is the current frr documentation:

Mar 17 2019, 11:35 PM · VyOS 1.2 Crux (VyOS 1.2.4), VyOS 1.3 Equuleus
rherold added a comment to T1304: Make frr daemons configurable.

Hi runar,

Mar 17 2019, 4:20 PM · VyOS 1.3 Equuleus
rherold created T1304: Make frr daemons configurable.
Mar 17 2019, 2:30 PM · VyOS 1.3 Equuleus
rherold created T1303: Implement ISIS.
Mar 17 2019, 2:15 PM · VyOS 1.3 Equuleus

Mar 3 2019

rherold closed T1278: Can't configure soft-reconfiguration inbound in bgp as Resolved.

Sorry found it.

Mar 3 2019, 9:46 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
rherold created T1278: Can't configure soft-reconfiguration inbound in bgp in the S1 VyOS Public space.
Mar 3 2019, 9:40 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)

Feb 26 2019

rherold added a comment to T1266: Put management traffic in separate routing table .

Would it be possible to add an option to bind an specific interface to an routing table?
I have tested the scenario above and create only the routing table via protocol static.
After this I manual add:

Feb 26 2019, 2:48 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
rherold changed Version from 1.2 to 1.2.0 on T1266: Put management traffic in separate routing table .
Feb 26 2019, 2:27 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)

Feb 24 2019

rherold added a comment to T1266: Put management traffic in separate routing table .

I added a log rule to:

Feb 24 2019, 12:41 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
rherold added a comment to T1266: Put management traffic in separate routing table .

why do we use fwmark in this case? As far as I can see ip rule give us all needed selectors:

Feb 24 2019, 10:11 AM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
rherold updated the task description for T1266: Put management traffic in separate routing table .
Feb 24 2019, 9:57 AM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
rherold created T1266: Put management traffic in separate routing table in the S1 VyOS Public space.
Feb 24 2019, 9:44 AM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)

Feb 18 2019

rherold added a comment to T160: Support NAT64.

@TriJetScud please see :

Feb 18 2019, 10:59 AM · VyOS 1.3 Equuleus

Jan 24 2019

rherold added a comment to T1196: Not able to set static IPv6 routes .

can reproduce ob EPA3:

Jan 24 2019, 4:16 PM · Invalid

Jan 21 2019

rherold created T1189: [Security Advisory] PowerDNS Recursor 4.1.9 Released.
Jan 21 2019, 2:01 PM · VyOS 1.2 Crux ( VyOS 1.2.0-EPA)
rherold closed T1164: show configuration files Permission denied as Resolved.

Can't reproduce with EPA3

Jan 21 2019, 9:42 AM · Rejected

Jan 18 2019

rherold added a comment to T1155: VyOS don't install on USB Stick .
Jan 18 2019, 11:46 AM · VyOS 1.3 Equuleus

Jan 11 2019

rherold added a comment to T1170: Frr Bgp DOS.

@syncer @dmbaturin Please do not remove use current code!

Jan 11 2019, 6:08 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
rherold added a comment to T1170: Frr Bgp DOS.

@syncer thats not true:

Jan 11 2019, 5:40 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 10 2019

rherold added a comment to T1066: Missing NICs.

Was it not RC6 which got 4.19.0? If I read the kernel changelog right there where some other problems with igb fixed in this area ....
Also I found https://ubuntuforums.org/showthread.php?t=2404431.

Jan 10 2019, 5:02 PM · VyOS 1.3 Equuleus

Jan 8 2019

rherold triaged T1170: Frr Bgp DOS as Unbreak Now! priority.

Please unbreak now. The next test date was announced!!

Jan 8 2019, 8:57 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
rherold created T1170: Frr Bgp DOS in the S1 VyOS Public space.
Jan 8 2019, 7:47 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 6 2019

rherold created T1164: show configuration files Permission denied in the S1 VyOS Public space.
Jan 6 2019, 9:56 PM · Rejected
rherold created T1163: Powerdns Recursor out of date and CVE-2018-10851 in the S1 VyOS Public space.
Jan 6 2019, 9:13 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Jan 5 2019

rherold added a comment to T1035: SNMP BGP 32 bit AS number fail.

@merjin @c-po please have a look to the debian wiki page especially to the mibs-downloader.

Jan 5 2019, 11:29 AM · VyOS 1.3 Equuleus
Line2 awarded T1156: VyOS sticker templates a Like token.
Jan 5 2019, 10:34 AM · Active contributors
c-po awarded T1156: VyOS sticker templates a Like token.
Jan 5 2019, 10:00 AM · Active contributors
MrXermon awarded T1156: VyOS sticker templates a Like token.
Jan 5 2019, 8:38 AM · Active contributors

Jan 4 2019

rherold triaged T1156: VyOS sticker templates as Wishlist priority.
Jan 4 2019, 7:21 PM · Active contributors
rherold created T1155: VyOS don't install on USB Stick in the S1 VyOS Public space.
Jan 4 2019, 6:32 PM · VyOS 1.3 Equuleus
rherold added a comment to T149: IPv6 support in OpenVPN tunnel.

We should have an eye on https://community.openvpn.net/openvpn/ticket/208 cause this will change the config logic again completly.

Jan 4 2019, 11:58 AM · openvpn, VyOS 1.3 Equuleus
rherold added a comment to T1035: SNMP BGP 32 bit AS number fail.

It is not a bug in VyOS self. If you look inside the description of this oid:

Jan 4 2019, 11:26 AM · VyOS 1.3 Equuleus
rherold added a comment to T1152: VyOS inside virtualbox for testing .

Thx for the feedback indeed it runs much better with the virtio-net driver. Bit the e1000 is the default if you choose Debian as OS in Virtualbox.
VyOS is not available in Virtualbox as OS Template. I think we should try to get an own template with nice defaults into Virtualbox. Should I open a case
in Virtualbox for it? Do we have a list of settings that would be optimal for an VyOS vm?

Jan 4 2019, 10:06 AM · Rejected

Jan 3 2019

rherold created T1152: VyOS inside virtualbox for testing .
Jan 3 2019, 4:15 PM · Rejected

Dec 12 2018

rherold added a comment to T1074: Update lldp to version 1.0.2.

Please go direct to version 1.0.3 cause:

Dec 12 2018, 2:57 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)

Oct 20 2018

rherold added a comment to T921: Encrypted DNS.

pdns recursor is from the same people who writes dnsdist.
There are three products wirh diffrent scopes:

Oct 20 2018, 11:31 AM · VyOS 1.3 Equuleus
rherold added a comment to T921: Encrypted DNS.

There is no way to signal DOH (DNS over HTTP/S) via dhcp.
DOH and DOT is supported in latest dnsdist packages see https://dnsdist.org/ and https://mailman.powerdns.com/pipermail/dnsdist/2018-August/000466.html.

Oct 20 2018, 6:51 AM · VyOS 1.3 Equuleus

Oct 19 2018

rherold added a comment to T548: BGP IPv6 multipath support.

As far as I can see it is enabled by default in recent frr:

Oct 19 2018, 10:46 AM · VyOS 1.3 Equuleus

Oct 18 2018

rherold added a comment to T31: Add VRF support.

I will bring this up again. We have now in 1.2 all we need.

Oct 18 2018, 8:34 PM · VyOS 1.3 Equuleus
rherold added a comment to T840: VRRP V3 backup router sending ND RA.

Have you seen this: https://github.com/reubenhwk/radvd/issues/45 ??

Oct 18 2018, 7:42 PM · VyOS 1.3 Equuleus