Page MenuHomeVyOS Platform

sdev (Simon)
User

Projects

User Details

User Since
May 6 2021, 3:27 PM (37 w, 3 d)

Recent Activity

Fri, Jan 21

sdev added a comment to T4186: Firewall icmp type - Offered options not supported.

PR + migration: https://github.com/vyos/vyos-1x/pull/1184

Fri, Jan 21, 10:08 PM · VyOS 1.4 Sagitta
sdev changed the status of T4199: Commit failed when setting icmpv6 type any from Open to In progress.
Fri, Jan 21, 12:22 PM · VyOS 1.4 Sagitta
sdev added a comment to T4200: Assigning ipv6-name to interface is not generating nftables rules.

I can't reproduce this issue on latest rolling

Fri, Jan 21, 12:03 PM · VyOS 1.4 Sagitta

Tue, Jan 18

sdev changed the status of T4188: Firewall does not correctly handle conntracking from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1178

Tue, Jan 18, 6:02 PM · VyOS 1.4 Sagitta
johannrichard awarded T3560: Ability to create groups of MAC addresses a Like token.
Tue, Jan 18, 5:46 PM · VyOS 1.4 Sagitta
sdev changed the status of T3560: Ability to create groups of MAC addresses, a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Tue, Jan 18, 5:35 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sdev changed the status of T3560: Ability to create groups of MAC addresses from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1177

Tue, Jan 18, 5:35 PM · VyOS 1.4 Sagitta
sdev renamed T4188: Firewall does not correctly handle conntracking from Firewall does not match ICMPv6 packets to Firewall does not correctly handle conntracking.
Tue, Jan 18, 5:30 PM · VyOS 1.4 Sagitta
sdev changed the status of T4188: Firewall does not correctly handle conntracking from Open to In progress.

Okay, thanks for the update. I have found a conntrack issue in the code. Will have a fix in shortly.

Tue, Jan 18, 5:29 PM · VyOS 1.4 Sagitta
sdev closed T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails, a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Tue, Jan 18, 1:50 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sdev closed T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails as Resolved.
Tue, Jan 18, 1:50 PM · VyOS 1.4 Sagitta
sdev closed T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases , a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Tue, Jan 18, 1:50 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sdev closed T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases as Resolved.
Tue, Jan 18, 1:50 PM · VyOS 1.4 Sagitta
sdev closed T3286: Switch the firewall from iptables to nftables, a subtask of T2199: Rewrite firewall in new XML/Python style, as Resolved.
Tue, Jan 18, 1:47 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sdev closed T3286: Switch the firewall from iptables to nftables as Resolved.
Tue, Jan 18, 1:47 PM · VyOS 1.4 Sagitta
sdev changed the status of T1292: Issues while deleting all rules from a firewall, a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Tue, Jan 18, 1:45 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sdev changed the status of T1292: Issues while deleting all rules from a firewall from Open to Needs testing.

Fixed in 1.4 PR: https://github.com/vyos/vyos-1x/pull/1176

Tue, Jan 18, 1:45 PM · VyOS 1.4 Sagitta

Mon, Jan 17

sdev closed T4188: Firewall does not correctly handle conntracking as Invalid.

You need to remove the state new match on the rule and it'll work.

Mon, Jan 17, 7:54 PM · VyOS 1.4 Sagitta
sdev added a comment to T4178: policy based routing tcp flags issue.

Included those flags in PR: https://github.com/vyos/vyos-1x/pull/1174

Mon, Jan 17, 11:29 AM · VyOS 1.4 Sagitta
sdev added a comment to T3873: Zone based Firewall - Filter traffic in same zone.

Included in PR: https://github.com/vyos/vyos-1x/pull/1174

Mon, Jan 17, 11:08 AM · VyOS 1.4 Sagitta

Sun, Jan 16

sdev changed the status of T3873: Zone based Firewall - Filter traffic in same zone from Open to In progress.

Thanks, will include a fix in a PR shortly

Sun, Jan 16, 9:43 PM · VyOS 1.4 Sagitta

Thu, Jan 13

sdev changed the status of T4178: policy based routing tcp flags issue from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1167

Thu, Jan 13, 8:29 PM · VyOS 1.4 Sagitta
sdev changed the status of T4178: policy based routing tcp flags issue from Open to In progress.

Thanks for the report, working on the fix now.

Thu, Jan 13, 11:55 AM · VyOS 1.4 Sagitta

Wed, Jan 12

sdev changed the status of T2199: Rewrite firewall in new XML/Python style from Open to Needs testing.
Wed, Jan 12, 5:11 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sdev changed the status of T4160: Firewall - Error in rules that matches everything except something from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1161

Wed, Jan 12, 12:32 PM · VyOS 1.4 Sagitta
sdev moved T4131: Show firewall group incorrect format members from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Wed, Jan 12, 10:14 AM · VyOS 1.4 Sagitta
sdev moved T4137: Firewall group configuration allows to set incorrect port range and invalid port from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Wed, Jan 12, 10:14 AM · VyOS 1.4 Sagitta
sdev moved T4144: Firewall address-group - Improve error messages from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Wed, Jan 12, 10:13 AM · VyOS 1.4 Sagitta
sdev moved T4148: Firewall - Error messages not that clear as it were in old firewall from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Wed, Jan 12, 10:13 AM · VyOS 1.4 Sagitta
sdev moved T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Wed, Jan 12, 10:13 AM · VyOS 1.4 Sagitta
sdev moved T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Wed, Jan 12, 10:13 AM · VyOS 1.4 Sagitta
sdev moved T4160: Firewall - Error in rules that matches everything except something from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Wed, Jan 12, 10:13 AM · VyOS 1.4 Sagitta
sdev moved T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf` from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Wed, Jan 12, 10:13 AM · VyOS 1.4 Sagitta

Tue, Jan 11

sdev changed the status of T4160: Firewall - Error in rules that matches everything except something from Open to In progress.
Tue, Jan 11, 11:25 PM · VyOS 1.4 Sagitta
sdev added a comment to T4173: Wan Load Balancing - Error on firewall NAT rules.

Forgot that my PR for WLB was still a draft. That the jump does seem to be created properly with this PR in place.

Tue, Jan 11, 11:07 PM · VyOS 1.4 Sagitta
sdev added a comment to T4144: Firewall address-group - Improve error messages.

That build at 08:11 UTC was a couple of hours before the commit was merged: https://github.com/vyos/vyos-1x/commit/f97144259335102c3d96b232cbb0af4970120d62

Tue, Jan 11, 10:02 PM · VyOS 1.4 Sagitta
sdev added a comment to T4144: Firewall address-group - Improve error messages.

Seems to be working on my latest build?

Tue, Jan 11, 8:21 PM · VyOS 1.4 Sagitta
sdev changed the status of T4164: PBR: network groups (as well as address and port groups) don't resolve in `nftables_policy.conf` from Open to Needs testing.

Thanks, I really like the include idea and have implemented it in the attached PR. Also added a check in firewall.py to reload policy-route script to keep any group changes updated.

Tue, Jan 11, 2:51 PM · VyOS 1.4 Sagitta
sdev changed the status of T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails, a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Tue, Jan 11, 2:48 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sdev changed the status of T4159: Empty firewall group (address, network & port) generates invalid nftables config, commit fails from Open to Needs testing.

PR removes the empty line when there are no group members, also adds a warning message when empty groups are used in rules.

Tue, Jan 11, 2:48 PM · VyOS 1.4 Sagitta
sdev changed the status of T4131: Show firewall group incorrect format members from Open to Needs testing.

@Viacheslav Not using exact ipset format, however addresses are sorted and output one per line.

Tue, Jan 11, 2:46 PM · VyOS 1.4 Sagitta
sdev changed the status of T4144: Firewall address-group - Improve error messages from In progress to Needs testing.

Should resolve the rest of the error messages.

Tue, Jan 11, 2:45 PM · VyOS 1.4 Sagitta

Mon, Jan 10

sdev changed the status of T4144: Firewall address-group - Improve error messages from Open to In progress.

IPv4 address range error messages are included in PR: https://github.com/vyos/vyos-1x/pull/1152

Mon, Jan 10, 9:09 PM · VyOS 1.4 Sagitta
sdev changed the status of T4148: Firewall - Error messages not that clear as it were in old firewall from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1152

Mon, Jan 10, 9:04 PM · VyOS 1.4 Sagitta
sdev changed the status of T4137: Firewall group configuration allows to set incorrect port range and invalid port from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1152

Mon, Jan 10, 9:02 PM · VyOS 1.4 Sagitta
sdev changed the status of T4149: [Firewall-IPV6] Error delete Fw rules on VIF/INT from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1151

Mon, Jan 10, 6:40 PM · VyOS 1.4 Sagitta
sdev changed the status of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases , a subtask of T2199: Rewrite firewall in new XML/Python style, from Open to Needs testing.
Mon, Jan 10, 6:40 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta
sdev changed the status of T4155: PBR: `set table main` fails in `firewall.py` with newer rolling releases from Open to Needs testing.

Thanks for catching that!

Mon, Jan 10, 6:40 PM · VyOS 1.4 Sagitta
sdev changed the status of T4149: [Firewall-IPV6] Error delete Fw rules on VIF/INT from Open to In progress.
Mon, Jan 10, 5:53 PM · VyOS 1.4 Sagitta

Thu, Jan 6

sdev moved T4133: Firewall network group error with zone-based firewall rules from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Thu, Jan 6, 5:27 PM · VyOS 1.4 Sagitta, VyConf
sdev moved T4145: Conntrack table not showing after firewall rewriting from Need Triage to In Progress on the VyOS 1.4 Sagitta board.
Thu, Jan 6, 5:26 PM · VyOS 1.4 Sagitta
sdev added a comment to T4145: Conntrack table not showing after firewall rewriting.

Updates the vyatta-conntrack package to work without legacy firewall and fixes the op-mode commands. Should also fix some conntrack functionality (untested).

Thu, Jan 6, 3:23 PM · VyOS 1.4 Sagitta

Wed, Jan 5

sdev changed the status of T4133: Firewall network group error with zone-based firewall rules from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1139

Wed, Jan 5, 5:10 PM · VyOS 1.4 Sagitta, VyConf
sdev changed the status of T4133: Firewall network group error with zone-based firewall rules from Open to In progress.
Wed, Jan 5, 2:07 PM · VyOS 1.4 Sagitta, VyConf
sdev changed the status of T3635: Add ability to use mDNS repeater with VRRP from In progress to Needs testing.
Wed, Jan 5, 1:55 PM · VyOS 1.4 Sagitta
sdev changed the status of T4135: Declare zone policy firewall without local zone errors from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1136

Wed, Jan 5, 12:40 AM · VyOS 1.4 Sagitta
sdev changed the status of T4135: Declare zone policy firewall without local zone errors from Open to In progress.
Wed, Jan 5, 12:33 AM · VyOS 1.4 Sagitta

Tue, Jan 4

sdev added a comment to T4136: Firewall State Policy entries fail to load..

Duplicate of T4130

Tue, Jan 4, 12:45 AM · VyOS 1.4 Sagitta
sdev changed the status of T4130: Firewall state policy errors chain from In progress to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/1130

Tue, Jan 4, 12:14 AM · VyOS 1.4 Sagitta

Mon, Jan 3

sdev changed the status of T4130: Firewall state policy errors chain from Open to In progress.
Mon, Jan 3, 9:58 PM · VyOS 1.4 Sagitta

Nov 4 2021

sdev changed the status of T3970: Add support for op-mode PKI direct install into an active config session, a subtask of T3642: PKI configuration, from Open to In progress.
Nov 4 2021, 7:27 PM · VyOS 1.4 Sagitta
sdev changed the status of T3970: Add support for op-mode PKI direct install into an active config session from Open to In progress.

PR: https://github.com/vyos/vyos-1x/pull/1066

Nov 4 2021, 7:27 PM · VyOS 1.4 Sagitta
sdev created T3970: Add support for op-mode PKI direct install into an active config session.
Nov 4 2021, 7:21 PM · VyOS 1.4 Sagitta

Nov 3 2021

sdev added a comment to T3931: SSTP doesn't work after rewriting to PKI.

PR: https://github.com/vyos/vyos-1x/pull/1062

Nov 3 2021, 1:31 PM · VyOS 1.4 Sagitta

Oct 31 2021

sdev added a comment to T3873: Zone based Firewall - Filter traffic in same zone.

Included this feature in the firewall/zone-policy rewrite: https://github.com/vyos/vyos-1x/pull/1033

Oct 31 2021, 10:05 PM · VyOS 1.4 Sagitta

Oct 20 2021

sdev added a comment to T2199: Rewrite firewall in new XML/Python style.

Draft PR: https://github.com/vyos/vyos-1x/pull/1033

Oct 20 2021, 3:21 PM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Oct 19 2021

sdev added a comment to T3917: Use Avahi as mDNS repeater for IPv6 support.

PR: https://github.com/vyos/vyos-1x/pull/1030

Oct 19 2021, 8:54 PM · VyOS 1.4 Sagitta
sdev changed the status of T3917: Use Avahi as mDNS repeater for IPv6 support from Open to In progress.
Oct 19 2021, 8:40 PM · VyOS 1.4 Sagitta

Sep 24 2021

sdev created T3854: Missing op-mode commands for conntrack-sync.
Sep 24 2021, 10:31 AM · VyOS 1.3 Equuleus ( 1.3.1), VyOS 1.4 Sagitta

Sep 14 2021

sdev added a comment to T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta.

Good shout, fixed in following PR: https://github.com/vyos/vyos-1x/pull/1005

Sep 14 2021, 9:05 AM · VyOS 1.4 Sagitta

Sep 13 2021

sdev added a comment to T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta.

PR: https://github.com/vyos/vyos-1x/pull/1004

Sep 13 2021, 12:52 PM · VyOS 1.4 Sagitta

Aug 13 2021

sdev changed the status of T3752: generate pki certificate file xxx doesn't touch file from Open to Needs testing.

PR: https://github.com/vyos/vyos-1x/pull/969

Aug 13 2021, 4:42 PM · VyOS 1.4 Sagitta

Aug 10 2021

sdev added a comment to T3727: VPN IPsec ESP proposal and ESP presented in config missmatch.

PR: https://github.com/vyos/vyos-1x/pull/961

Aug 10 2021, 11:57 AM · VyOS 1.4 Sagitta

Jul 22 2021

sdev changed the status of T3642: PKI configuration, a subtask of T2799: VyOS Certificates Manager, from In progress to Needs testing.
Jul 22 2021, 3:49 PM · VyOS 1.3 Equuleus (1.3.0)
sdev changed the status of T3642: PKI configuration from In progress to Needs testing.
Jul 22 2021, 3:49 PM · VyOS 1.4 Sagitta
sdev updated the task description for T3642: PKI configuration.
Jul 22 2021, 3:49 PM · VyOS 1.4 Sagitta

Jul 21 2021

sdev updated the task description for T3642: PKI configuration.
Jul 21 2021, 10:01 PM · VyOS 1.4 Sagitta
sdev updated the task description for T3642: PKI configuration.
Jul 21 2021, 10:00 PM · VyOS 1.4 Sagitta

Jul 20 2021

sdev updated the task description for T3642: PKI configuration.
Jul 20 2021, 1:46 PM · VyOS 1.4 Sagitta

Jul 19 2021

sdev updated the task description for T3642: PKI configuration.
Jul 19 2021, 5:17 PM · VyOS 1.4 Sagitta
sdev added a comment to T3642: PKI configuration.

PKI Wireguard PR: https://github.com/vyos/vyos-1x/pull/929

Jul 19 2021, 5:17 PM · VyOS 1.4 Sagitta

Jul 16 2021

sdev updated the task description for T3642: PKI configuration.
Jul 16 2021, 5:39 PM · VyOS 1.4 Sagitta

Jul 13 2021

sdev added a comment to T3678: VyOS 1.4: Invalid error message while deleting ipsec vpn configuration.

This error occurs because the ipsec module blindly updates the l2tp module after a commit change to ensure any l2tp via ipsec config is then refreshed also.

Jul 13 2021, 4:01 PM · VyOS 1.4 Sagitta

Jul 7 2021

sdev updated the task description for T3642: PKI configuration.
Jul 7 2021, 11:59 AM · VyOS 1.4 Sagitta
sdev added a comment to T3642: PKI configuration.

vpn rsa-keys migrated: https://github.com/vyos/vyos-1x/pull/912

Jul 7 2021, 11:57 AM · VyOS 1.4 Sagitta

Jul 2 2021

sdev changed the status of T3659: Configuration won't accept IPv6 addresses for site-to-site VPN tunnel prefixes/traffic selectors from In progress to Needs testing.
Jul 2 2021, 10:38 AM · VyOS 1.4 Sagitta
sdev added a comment to T3656: IPSec 1.4 : "show vpn ike sa" does not show the correct default ike version.

Should be resolved in PR: https://github.com/vyos/vyos-1x/pull/903

Jul 2 2021, 10:38 AM · VyOS 1.4 Sagitta
sdev added a comment to T3659: Configuration won't accept IPv6 addresses for site-to-site VPN tunnel prefixes/traffic selectors.

Fixed in PR: https://github.com/vyos/vyos-1x/pull/903

Jul 2 2021, 10:37 AM · VyOS 1.4 Sagitta
sdev changed the status of T3659: Configuration won't accept IPv6 addresses for site-to-site VPN tunnel prefixes/traffic selectors from Open to In progress.
Jul 2 2021, 9:00 AM · VyOS 1.4 Sagitta

Jun 29 2021

sdev added a comment to T3642: PKI configuration.

PR is in: https://github.com/vyos/vyos-1x/pull/901

Jun 29 2021, 4:39 PM · VyOS 1.4 Sagitta
sdev changed the status of T3642: PKI configuration, a subtask of T2799: VyOS Certificates Manager, from Open to In progress.
Jun 29 2021, 12:37 PM · VyOS 1.3 Equuleus (1.3.0)
sdev changed the status of T3642: PKI configuration from Open to In progress.

I should soon have a PR ready for this, including an update to IPSec config to show how to port existing configs to use PKI.

Jun 29 2021, 12:37 PM · VyOS 1.4 Sagitta

Jun 26 2021

sdev added a comment to T3642: PKI configuration.

When using show pki ... commands you would be able to see the relation between certificates and CAs.

Jun 26 2021, 5:27 PM · VyOS 1.4 Sagitta

Jun 22 2021

sdev added a comment to T2816: Rewrite IPsec scripts with the new XML/Python approach.

@SrividyaA Fixed in PR https://github.com/vyos/vyos-1x/pull/894

Jun 22 2021, 7:45 AM · VyOS 1.4 Sagitta
sdev added a comment to T3643: show vpn ipsec sa doesn't show tunnels in "down" state.

PR: https://github.com/vyos/vyos-1x/pull/894

Jun 22 2021, 7:44 AM · VyOS 1.3 Equuleus (1.3.0), VyOS 1.4 Sagitta

Jun 21 2021

sdev updated the task description for T3642: PKI configuration.
Jun 21 2021, 5:18 PM · VyOS 1.4 Sagitta
sdev updated the task description for T3642: PKI configuration.
Jun 21 2021, 5:18 PM · VyOS 1.4 Sagitta
sdev created T3642: PKI configuration.
Jun 21 2021, 5:14 PM · VyOS 1.4 Sagitta

Jun 19 2021

sdev added a comment to T3635: Add ability to use mDNS repeater with VRRP.

PR: https://github.com/vyos/vyos-1x/pull/887

Jun 19 2021, 11:55 AM · VyOS 1.4 Sagitta
sdev changed the status of T3635: Add ability to use mDNS repeater with VRRP from Open to In progress.
Jun 19 2021, 11:48 AM · VyOS 1.4 Sagitta