Page MenuHomeVyOS Platform

sdev (Simon)
User

Projects

User Details

User Since
May 6 2021, 3:27 PM (82 w, 4 d)

Recent Activity

Sat, Dec 3

sdev added a comment to T478: Firewall address group (multi and nesting).

PR to fix recursion check: https://github.com/vyos/vyos-1x/pull/1691

Sat, Dec 3, 11:43 AM · VyOS 1.4 Sagitta

Tue, Nov 22

sdev changed the status of T4834: Limit container network name to 15 characters from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1674

Tue, Nov 22, 11:58 AM · VyOS 1.4 Sagitta
sdev changed the status of T4834: Limit container network name to 15 characters from Open to In progress.
Tue, Nov 22, 11:55 AM · VyOS 1.4 Sagitta
sdev created T4834: Limit container network name to 15 characters.
Tue, Nov 22, 11:55 AM · VyOS 1.4 Sagitta

Fri, Nov 11

sdev added a comment to T4605: Firewall change default table names.

PR for policy route refactor updates to vyos_mangle: https://github.com/vyos/vyos-1x/pull/1654

Fri, Nov 11, 4:49 PM · VyOS 1.4 Sagitta

Nov 3 2022

sdev triaged T4797: External address/network lists for firewall (Local and remote) as Wishlist priority.
Nov 3 2022, 7:44 PM · VyOS 1.4 Sagitta
sdev changed the status of T1097: Make firewall groups work everywhere that's appropropriate from Open to In progress.

PR adds groups to NAT: https://github.com/vyos/vyos-1x/pull/1633

Nov 3 2022, 7:41 PM · VyOS 1.4 Sagitta
sdev changed the status of T1097: Make firewall groups work everywhere that's appropropriate, a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to In progress.
Nov 3 2022, 7:41 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

Nov 1 2022

sdev changed the status of T1877: Feature Request: Allow NAT to use network and address groups from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1633

Nov 1 2022, 12:48 PM · VyOS 1.4 Sagitta
sdev added a comment to T970: Hostname Support in NAT and Firewall Rules.

Adds firewall node rule N source/destination fqdn domain.com for single domains per rule and refactors resolver daemon.

Nov 1 2022, 12:47 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
sdev moved T4759: domain-group on policy route not working from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Nov 1 2022, 9:19 AM · VyOS 1.4 Sagitta
sdev changed the status of T4759: domain-group on policy route not working from Open to In progress.
Nov 1 2022, 9:19 AM · VyOS 1.4 Sagitta
sdev closed T4764: NAT tables vyos_nat and vyos_static_nat not deleting after deleting nat as Resolved.
Nov 1 2022, 9:19 AM · VyOS 1.4 Sagitta
sdev changed the status of T4774: Disallow duplicate pubkey on peers of a wireguard interface from In progress to Backport candidate.
Nov 1 2022, 9:18 AM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus

Oct 31 2022

sdev changed the status of T1877: Feature Request: Allow NAT to use network and address groups from Open to In progress.
Oct 31 2022, 8:15 PM · VyOS 1.4 Sagitta

Oct 29 2022

sdev moved T4764: NAT tables vyos_nat and vyos_static_nat not deleting after deleting nat from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Oct 29 2022, 5:54 PM · VyOS 1.4 Sagitta
sdev changed the status of T4782: Allow multiple CA certificates (on e.g. EAPoL) from Open to Confirmed.

Good point, I'll try and look into this and see if it can be handled everywhere the new PKI nodes are used.

Oct 29 2022, 5:53 PM · VyOS 1.4 Sagitta
sdev changed the status of T3903: Containers: after command "reboot" the host system will reboot after 1.5 minutes from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1628

Oct 29 2022, 5:48 PM · VyOS 1.4 Sagitta

Oct 28 2022

sdev added a comment to T3903: Containers: after command "reboot" the host system will reboot after 1.5 minutes.

Best suggestion seems to be introducing a script to call podman stop -t N on shutdown/reboot to reduce the timeout before SIGKILL is sent.

Oct 28 2022, 1:27 PM · VyOS 1.4 Sagitta

Oct 27 2022

sdev changed the status of T4774: Disallow duplicate pubkey on peers of a wireguard interface from Open to In progress.

1.4 PR: https://github.com/vyos/vyos-1x/pull/1621

Oct 27 2022, 10:54 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus

Oct 25 2022

sdev changed the status of T4764: NAT tables vyos_nat and vyos_static_nat not deleting after deleting nat from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1618

Oct 25 2022, 10:02 PM · VyOS 1.4 Sagitta
sdev changed the status of T4764: NAT tables vyos_nat and vyos_static_nat not deleting after deleting nat from Open to In progress.
Oct 25 2022, 10:29 AM · VyOS 1.4 Sagitta

Oct 11 2022

sdev closed T4741: set firewall zone Local local-zone failed as Resolved.
Oct 11 2022, 1:29 PM · VyOS 1.4 Sagitta
sdev closed T4742: Autocomplete in policy route rule x set table / does not show the tables created in the static protocols as Resolved.
Oct 11 2022, 1:29 PM · VyOS 1.4 Sagitta

Oct 10 2022

sdev changed the status of T4742: Autocomplete in policy route rule x set table / does not show the tables created in the static protocols from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1577

Oct 10 2022, 2:27 PM · VyOS 1.4 Sagitta
sdev changed the status of T4741: set firewall zone Local local-zone failed from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1577

Oct 10 2022, 2:27 PM · VyOS 1.4 Sagitta

Sep 28 2022

sdev changed the status of T4713: [email protected]:~$ show nat destination rules | doesn't work from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1564

Sep 28 2022, 11:13 AM · VyOS 1.4 Sagitta
sdev changed the status of T4713: [email protected]:~$ show nat destination rules | doesn't work from Open to Confirmed.
Sep 28 2022, 9:57 AM · VyOS 1.4 Sagitta

Sep 27 2022

sdev added a comment to T4713: [email protected]:~$ show nat destination rules | doesn't work.

Can we see example destination NAT config with the issue?

Sep 27 2022, 8:56 PM · VyOS 1.4 Sagitta

Sep 21 2022

sdev added a comment to T4706: NAT and NAT66 issues.

Included a fix for this in NAT refactor: https://github.com/vyos/vyos-1x/pull/1552

Sep 21 2022, 4:12 PM · VyOS 1.4 Sagitta
sdev added a comment to T4605: Firewall change default table names.

PR for NAT included with refactor: https://github.com/vyos/vyos-1x/pull/1552

Sep 21 2022, 4:12 PM · VyOS 1.4 Sagitta

Sep 12 2022

sdev added a comment to T2199: Rewrite firewall in new XML/Python style.

Refactor PR: https://github.com/vyos/vyos-1x/pull/1534

Sep 12 2022, 7:16 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
sdev added a comment to T4605: Firewall change default table names.

PR for filter tables: https://github.com/vyos/vyos-1x/pull/1534

Sep 12 2022, 7:15 PM · VyOS 1.4 Sagitta

Sep 10 2022

sdev added a comment to T1185: Firewall rulesets are ignored in RFC-compliant VRRP setups.

Just a suggestion, would it be a weird idea to move the firewall config from the interface section to the firewall section? A bit like the zone config. So something like:

set firewall local interface eth0 name <firewall-filter>
set firewall in interface eth0 name <firewall-filter>
set firewall out interface eth0 name <firewall-filter>
set firewall local interface bond0.10v22v6 ipv6-name <firewall-filter>

The problem is that using zone-policy firewall is a bit overkill for a pure router or even a router with async routing. In which scenario I guess only the local variant would be useful.

Sep 10 2022, 6:23 PM · VyOS 1.3 Equuleus (1.3.3)

Aug 17 2022

sdev added a comment to T4612: Support arbitrary netmasks in firewall rules.

Not supported at the moment, but we can look into adding it for both ipv4/v6 in 1.4

Aug 17 2022, 8:05 PM · VyOS 1.4 Sagitta
sdev added a comment to T4605: Firewall change default table names.

While I'm for changing to prefixed tables, I think the issue of tailscale and custom apps should fall under the accepted risk of running custom scripts outside of the config.

Aug 17 2022, 8:02 PM · VyOS 1.4 Sagitta
sdev added a comment to T4610: Firewall with 20K entries cannot load after reboot.

Any config available to test against?

Aug 17 2022, 7:53 PM · VyOS 1.4 Sagitta

Jul 7 2022

sdev triaged T4515: Reduce telegraf binary size as Wishlist priority.
Jul 7 2022, 11:01 AM · VyOS 1.3 Equuleus (1.3.2), VyOS 1.4 Sagitta

Jul 6 2022

sdev added a comment to T4250: Organize logrotate settings to avoid duplicates.

I think there's still a problem possible with /var/log/messages handling:

Jul 6 2022, 3:50 PM · VyOS 1.4 Sagitta
sdev changed the status of T4500: Missing firewall logs from Confirmed to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1398

Jul 6 2022, 3:46 PM · VyOS 1.4 Sagitta
sdev changed the status of T4500: Missing firewall logs from Open to Confirmed.

Confirmed issue, seems to be a problem in rsyslog/logrotate. Possibly related to T4250

Jul 6 2022, 2:50 PM · VyOS 1.4 Sagitta

Jul 5 2022

sdev closed T478: Firewall address group (multi and nesting), a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Jul 5 2022, 11:41 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
sdev closed T478: Firewall address group (multi and nesting) as Resolved.
Jul 5 2022, 11:41 PM · VyOS 1.4 Sagitta
sdev changed the status of T4512: enable-default-log on zone-policy from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1394

Jul 5 2022, 6:08 PM · VyOS 1.4 Sagitta
sdev changed the status of T4512: enable-default-log on zone-policy from Open to In progress.
Jul 5 2022, 5:27 PM · VyOS 1.4 Sagitta

Jul 2 2022

sdev added a comment to T4299: Firewall - GeoIP filtering.

Inverse match PR: https://github.com/vyos/vyos-1x/pull/1386

Jul 2 2022, 12:52 AM · VyOS 1.4 Sagitta

Jul 1 2022

sdev added a comment to T4500: Missing firewall logs.

If the counters are visible and incrementing when checking with nft list table ip filter then I don't think this is an implementation issue. Wondering if its a problem with the syslog daemon.

Jul 1 2022, 9:49 PM · VyOS 1.4 Sagitta

Jun 29 2022

sdev added a comment to T4485: OpenVPN: Allow multiple CAs certificates.

PR: https://github.com/vyos/vyos-1x/pull/1380

Jun 29 2022, 10:11 PM · VyOS 1.4 Sagitta

Jun 27 2022

sdev closed T4484: Firewall op-mode summary doesn't correctly handle address group containing ranges as Resolved.
Jun 27 2022, 8:16 PM · VyOS 1.4 Sagitta

Jun 25 2022

sdev changed the status of T4485: OpenVPN: Allow multiple CAs certificates from Open to In progress.
Jun 25 2022, 9:58 PM · VyOS 1.4 Sagitta
sdev changed the status of T4484: Firewall op-mode summary doesn't correctly handle address group containing ranges from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1368

Jun 25 2022, 9:48 PM · VyOS 1.4 Sagitta
sdev changed the status of T4484: Firewall op-mode summary doesn't correctly handle address group containing ranges from Open to In progress.
Jun 25 2022, 9:46 PM · VyOS 1.4 Sagitta

Jun 15 2022

sdev changed the status of T4435: Policy route and firewall - error when using undefined group from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1362

Jun 15 2022, 9:15 PM · VyOS 1.4 Sagitta
sdev changed the status of T4147: New Firewall Implementation - proposed changes on group implementation from In progress to Needs testing.
Jun 15 2022, 1:33 PM · VyOS 1.4 Sagitta
sdev added a comment to T4147: New Firewall Implementation - proposed changes on group implementation.

PR: https://github.com/vyos/vyos-1x/pull/1361

Jun 15 2022, 1:32 PM · VyOS 1.4 Sagitta

Jun 13 2022

sdev changed the status of T4147: New Firewall Implementation - proposed changes on group implementation from Open to In progress.

Working on moving groups to named set as part of a refactor in some firewall code.

Jun 13 2022, 12:11 PM · VyOS 1.4 Sagitta

Jun 10 2022

sdev changed the status of T4299: Firewall - GeoIP filtering from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1357

Jun 10 2022, 11:02 PM · VyOS 1.4 Sagitta
sdev changed the status of T478: Firewall address group (multi and nesting), a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Jun 10 2022, 7:23 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
sdev changed the status of T478: Firewall address group (multi and nesting) from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1356

Jun 10 2022, 7:23 PM · VyOS 1.4 Sagitta

May 31 2022

sdev closed T3659: Configuration won't accept IPv6 addresses for site-to-site VPN tunnel prefixes/traffic selectors as Resolved.
May 31 2022, 6:13 PM · VyOS 1.4 Sagitta
sdev closed T4148: Firewall - Error messages not that clear as it were in old firewall as Resolved.
May 31 2022, 6:11 PM · VyOS 1.4 Sagitta
sdev closed T4199: Commit failed when setting icmpv6 type any as Resolved.
May 31 2022, 6:09 PM · VyOS 1.4 Sagitta
sdev closed T4212: PermissionError when generating/installing server Certificate (generate pki certificate sign ...) as Resolved.
May 31 2022, 6:05 PM · VyOS 1.4 Sagitta

May 30 2022

sdev added a comment to T3642: PKI configuration.

PR for op-mode importing existing PKI files into config: https://github.com/vyos/vyos-1x/pull/1343

May 30 2022, 10:59 PM · VyOS 1.4 Sagitta

May 27 2022

sdev added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

1.4 rolling does not help me, so there must be something "wrong" with my configuration. I've attached the private config, it would be awesome if someone might find what's broken.

May 27 2022, 6:20 PM · VyOS 1.3 Equuleus (1.3.3)

May 26 2022

sdev added a comment to T1230: Improving Boot Time for Large Firewall Configurations.

@panachoi If you can share the anonymized config that works in 1.2.8 that would be useful. I'd expect migrating to 1.4 to see a decent improvement in firewall load times.

May 26 2022, 10:07 AM · VyOS 1.3 Equuleus (1.3.3)

Apr 20 2022

sdev closed T4345: New firewall code does not accept "rate/time interval" syntax used in old config as Resolved.
Apr 20 2022, 11:58 AM · VyOS 1.4 Sagitta

Apr 14 2022

sdev added a comment to T4358: Image sizes have grown significantly in 1.4.

30 largest packages in 1.4 dev build:

telegraf 144 MB
linux-image-5.10.109-amd64-vyos 107 MB
libwireshark14 100 MB
vyos-linux-firmware 68.8 MB
containernetworking-plugins 51.2 MB
vyos-http-api-tools 40.4 MB
podman 37.3 MB
python3-pycryptodome 36.0 MB
libicu67 33.9 MB
vim-runtime 32.9 MB
vyos-1x 29.2 MB
libperl5.32 28.5 MB
salt-common 27.9 MB
nmap-common 21.2 MB
frr 20.2 MB
libruby2.7 17.9 MB
coreutils 17.9 MB
perl-modules-5.32 17.9 MB
grub-common 17.8 MB
systemd 16.4 MB
locales 16.4 MB
libc6 13.1 MB
pmacct 13.0 MB
ieee-data 12.3 MB
vyos-intel-qat 11.7 MB
aptitude-common 10.3 MB
gdb 10.0 MB
udev 9,184 kB
grub-efi-amd64-bin 8,831 kB
squid 8,582 kB
Apr 14 2022, 3:01 PM · VyOS 1.4 Sagitta

Apr 6 2022

sdev changed the status of T4345: New firewall code does not accept "rate/time interval" syntax used in old config from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1275

Apr 6 2022, 2:11 PM · VyOS 1.4 Sagitta
sdev moved T4345: New firewall code does not accept "rate/time interval" syntax used in old config from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Apr 6 2022, 12:01 PM · VyOS 1.4 Sagitta
sdev changed the status of T4345: New firewall code does not accept "rate/time interval" syntax used in old config from Open to In progress.
Apr 6 2022, 12:01 PM · VyOS 1.4 Sagitta

Mar 29 2022

sdev closed T3635: Add ability to use mDNS repeater with VRRP as Resolved.
Mar 29 2022, 9:30 PM · VyOS 1.4 Sagitta

Mar 18 2022

sdev added a comment to T4299: Firewall - GeoIP filtering.

Perhaps only in-use sets can be determined and loaded?

Mar 18 2022, 5:36 PM · VyOS 1.4 Sagitta
sdev added a comment to T4307: Policy routing anymore, Commit generating errors.

Error implies that firewall failed to configure on boot as mangle table is missing. Any logs/config trace from boot?

Mar 18 2022, 1:42 PM · VyOS 1.4 Sagitta

Feb 24 2022

sdev changed the status of T4262: install image doesn't respect chosen root partition size from Confirmed to Needs testing.

1.3 PR: https://github.com/vyos/vyatta-cfg-system/pull/176
1.4 PR: https://github.com/vyos/vyatta-cfg-system/pull/177

Feb 24 2022, 12:49 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
sdev changed the status of T4262: install image doesn't respect chosen root partition size from Open to Confirmed.

@n.fort I have been able to reproduce this, it only occurs when installing for UEFI.

Feb 24 2022, 11:51 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta

Feb 20 2022

sdev added a comment to T4262: install image doesn't respect chosen root partition size.

sgdisk man says -n should have a partition number followed by start/end values. Looking at the code this bug is present in all versions 1.2 and above.

Feb 20 2022, 7:51 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
sdev closed Restricted Maniphest Task, a subtask of T2816: Rewrite IPsec scripts with the new XML/Python approach, as Resolved.
Feb 20 2022, 7:21 PM · VyOS 1.4 Sagitta

Feb 15 2022

sdev updated subscribers of T4145: Conntrack table not showing after firewall rewriting.

I think @c-po has started migrating it in T3579 but op-mode not yet complete.

Feb 15 2022, 7:10 PM · VyOS 1.4 Sagitta

Feb 6 2022

sdev closed T3970: Add support for op-mode PKI direct install into an active config session, a subtask of T3642: PKI configuration, as Resolved.
Feb 6 2022, 12:51 PM · VyOS 1.4 Sagitta
sdev closed T3970: Add support for op-mode PKI direct install into an active config session as Resolved.
Feb 6 2022, 12:51 PM · VyOS 1.4 Sagitta
sdev closed T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta as Resolved.
Feb 6 2022, 12:48 PM · VyOS 1.4 Sagitta
sdev closed T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf` as Resolved.
Feb 6 2022, 12:47 PM · VyOS 1.4 Sagitta
sdev closed T4178: policy based routing tcp flags issue as Resolved.
Feb 6 2022, 12:47 PM · VyOS 1.4 Sagitta
sdev closed T4216: Firewall: can't use negated groups in firewall rules as Resolved.
Feb 6 2022, 12:46 PM · VyOS 1.4 Sagitta
sdev closed T4223: policy route cannot have several entries with the same table as Resolved.
Feb 6 2022, 12:45 PM · VyOS 1.4 Sagitta

Feb 4 2022

sdev changed the status of T4209: Firewall incorrect handler for recent count and time from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1206

Feb 4 2022, 12:51 AM · VyOS 1.4 Sagitta

Feb 2 2022

sdev changed the status of T4178: policy based routing tcp flags issue from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1201

Feb 2 2022, 11:36 PM · VyOS 1.4 Sagitta
sdev changed the status of T4178: policy based routing tcp flags issue from Needs testing to In progress.

Adding this issue to this task: https://forum.vyos.io/t/firewall-configuration-issue-after-upgrade/8414

Feb 2 2022, 11:07 PM · VyOS 1.4 Sagitta

Jan 31 2022

sdev changed the status of T4216: Firewall: can't use negated groups in firewall rules from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1199

Jan 31 2022, 5:06 PM · VyOS 1.4 Sagitta
sdev changed the status of T4218: firewall: rule name is not allowed to start with a number from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1199

Jan 31 2022, 5:06 PM · VyOS 1.4 Sagitta
sdev changed the status of T4223: policy route cannot have several entries with the same table from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1199

Jan 31 2022, 5:05 PM · VyOS 1.4 Sagitta
sdev changed the status of T4223: policy route cannot have several entries with the same table from Open to In progress.

I already have a fix for this from your comment on T4213. Will have it included in a PR shortly.

Jan 31 2022, 4:47 PM · VyOS 1.4 Sagitta

Jan 29 2022

sdev changed the status of T4218: firewall: rule name is not allowed to start with a number from Open to In progress.
Jan 29 2022, 10:34 PM · VyOS 1.4 Sagitta
sdev changed the status of T4216: Firewall: can't use negated groups in firewall rules from Confirmed to In progress.
Jan 29 2022, 10:34 PM · VyOS 1.4 Sagitta

Jan 28 2022

sdev added a comment to T4209: Firewall incorrect handler for recent count and time.

I've actually found a way to define this properly, resulting rule now looks like below:

tcp dport { 22 } add @FOO_30 { ip saddr limit rate over 4/minute burst 4 packets } counter packets 3 bytes 156 reject comment "FOO-30"
ct state { new } tcp dport { 22 } counter packets 5 bytes 260 return comment "FOO-40"
Jan 28 2022, 6:00 PM · VyOS 1.4 Sagitta
sdev changed the status of T4216: Firewall: can't use negated groups in firewall rules from Open to Confirmed.
Jan 28 2022, 5:02 PM · VyOS 1.4 Sagitta

Jan 27 2022

sdev closed T4213: ipv6 policy routing not working anymore as Resolved.

Good to hear, going to mark this as resolved.

Jan 27 2022, 10:08 PM · VyOS 1.4 Sagitta
sdev changed the status of T4213: ipv6 policy routing not working anymore from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1194

Jan 27 2022, 9:23 PM · VyOS 1.4 Sagitta
sdev added a comment to T4209: Firewall incorrect handler for recent count and time.
In T4209#117429, @sdev wrote:

Would changing the guide to use limit rate 4/minute achieve the same target functionality?

What is the practical difference between limit rate and recent? Is it just two different ways of accomplishing the same?

Jan 27 2022, 8:38 PM · VyOS 1.4 Sagitta