Page MenuHomePhabricator

VyOS 1.2 Crux (VyOS 1.2.0-rc10)Milestone
ArchivedPublic

Members

  • This project does not have any members.

Watchers

  • This project does not have any watchers.

Recent Activity

Feb 20 2019

windflag triaged T1256: Execute "show ipsec vpn ipsec sa" returns incorrect results as Normal priority.
Feb 20 2019, 4:16 PM · VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Feb 11 2019

yun added a comment to T1001: show config commands - breaks when using backslashes in values.

Just to add extra info to this ticket, I had a openvpn-option that i wanted to add but it contained a single quote. I was not able to do this (in version 1.8.x this worked).

Feb 11 2019, 12:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Jan 16 2019

jakub.mieszko added a comment to T956: Incorrect output of "run show vpn ipsec sa".

Hello,
how to test new versions of vyos
I can not download version 1.2 epa2
Thank you in advance for the information

Jan 16 2019, 7:33 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Jan 6 2019

c-po added a parent task for T419: Support setting dstport for VXLAN interfaces: T1067: VXLAN support improvements.
Jan 6 2019, 10:27 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Jan 3 2019

syncer archived VyOS 1.2 Crux (VyOS 1.2.0-rc10).
Jan 3 2019, 1:52 PM
syncer moved T1081: GitHub Phabricator connection is broken from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Jan 3 2019, 1:52 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Dec 17 2018

syncer moved T958: Problems with wireguard description from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 17 2018, 7:00 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer edited projects for T958: Problems with wireguard description, added: VyOS 1.2 Crux (VyOS 1.2.0-rc10), VyOS-1.2.0-GA; removed VyOS 1.2 Crux.
Dec 17 2018, 7:00 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Dec 7 2018

dongjunbo edited projects for T1088: Can't change pasword of vyos, added: VyOS 1.2 Crux (VyOS 1.2.0-rc10); removed VyOS 1.2 Crux ( VyOS 1.2.0-rc11).
Dec 7 2018, 7:29 AM · Rejected
dongjunbo created T1088: Can't change pasword of vyos.
Dec 7 2018, 7:18 AM · Rejected

Dec 6 2018

Line2 added a comment to T956: Incorrect output of "run show vpn ipsec sa".

all these commands show the same output:
show vpn ipsec sa
show vpn ipsec sa verbose
show vpn debug
sudo ipsec statusall

Dec 6 2018, 3:54 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
jakub.mieszko added a comment to T956: Incorrect output of "run show vpn ipsec sa".

oj
~$ show vpn ipsec sa
Traceback (most recent call last):

File "/usr/libexec/vyos/op_mode/show_ipsec_sa.py", line 51, in <module>
  raise e
File "/usr/libexec/vyos/op_mode/show_ipsec_sa.py", line 45, in <module>

Status of IKE charon daemon (strongSwan 5.6.2, Linux 4.19.4-amd64-vyos, x86_64):

uptime: 7 minutes, since Dec 06 15:06:21 2018
malloc: sbrk 2965504, mmap 0, used 1546144, free 1419360
worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 48
loaded plugins: charon test-vectors ldap pkcs11 tpm aesni aes rc2 sha2 sha1 md5 mgf1 random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs8 pkcs12 pgp dnskey sshkey pem openssl gcrypt af-alg fips-prf gmp curve25519 agent xcbc cmac hmac ctr ccm gcm curl attr kernel-netlink resolve socket-default connmark stroke vici updown eap-identity eap-aka eap-md5 eap-gtc eap-mschapv2 eap-radius eap-tls eap-ttls eap-tnc xauth-generic xauth-eap xauth-pam xauth-noauth tnc-tnccs dhcp lookip error-notify certexpire led addrblock counters

Listening IP addresses:

Dec 6 2018, 2:15 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
c-po merged task T419: Support setting dstport for VXLAN interfaces into T1067: VXLAN support improvements.
Dec 6 2018, 7:05 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer closed T1081: GitHub Phabricator connection is broken as Resolved.

it seems that vyos-kernel was disabled

Dec 6 2018, 12:14 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T902: VyOS 1.2.0-rc2 fails to load configuration when conntrack modules are disabled in config from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T956: Incorrect output of "run show vpn ipsec sa" from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T969: Console device speed has no effect on GRUB configuration from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T1006: Eliminate unnecessary IP address validation utilities from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T1001: show config commands - breaks when using backslashes in values from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T1019: Enable Google BBR support at kernel compile time from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T1031: Upgraded vyos1.2rc7 to vyos1.2rc8, interface is down and pppoe is not working. from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T1046: Maximum CPU limit should be increased to 256 to accomodate high end servers from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T1053: Error when re-configuring an interface from DHCP to static IP from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T1045: static route dhcp-interface failes on bootup from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T419: Support setting dstport for VXLAN interfaces from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T337: 'show vpn ipsec sa' output wrong when remote or local prefix not in system subnet from Backlog to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
syncer moved T816: ipaddrcheck / libcidr but on IPv6 network validation from In Progress to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 6 2018, 12:00 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Dec 5 2018

syncer moved T984: BGP received routes not installed to FIB from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.0-rc10) board.
Dec 5 2018, 9:32 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
bswinnerton closed T984: BGP received routes not installed to FIB as Resolved.
Dec 5 2018, 6:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
bswinnerton added a comment to T984: BGP received routes not installed to FIB.

👍 cool. Since we've confirmed that as a solution, I think it's safe to close.

Dec 5 2018, 6:35 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
sebastianm added a comment to T984: BGP received routes not installed to FIB.

adding a static route towards the vultr gateway fixes this, as @bswinnerton pointed out.

Dec 5 2018, 6:30 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
bswinnerton added a comment to T984: BGP received routes not installed to FIB.

I ended up moving away from VyOS but the more that I think this problem, I wonder if it's due to mutihop being on and not having a route to the next hop.

Dec 5 2018, 1:58 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
frolswe added a comment to T1056: Console is slugish.
  • Does anyone actually need a graphical frame buffer for Vyos? I would expect it to run mostly headless.
  • Is the frame buffer tied to or necessary to solve the EFI issues @c-po raised?
Dec 5 2018, 9:09 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
Line2 added a comment to T956: Incorrect output of "run show vpn ipsec sa".

I just tested "show vpn ipsec sa" on latest rolling (vyos-1.2.0-rolling+201812050337) and get exactly the output of "sudo ipsec statusall"

Dec 5 2018, 8:50 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
frolswe added a comment to T1047: Configuration saved on a livecd cannot be carried over to the installed image.

This works fine for me on rc10. Thanks.

Dec 5 2018, 7:55 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
frolswe added a comment to T1056: Console is slugish.

And in rc10 it is back to being sluggish with CONFIG_FB_VGA16=y :(

Dec 5 2018, 7:49 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
oliko added a comment to T1014: Mellanox cards, problem with interrupts.

@dmbaturin Hello, sorry for delay. We tested rc10 today, it not crashed but still writing a lot of errors to logs (in the attach).

Dec 5 2018, 6:10 AM · VyOS 1.3 Equuleus
mbailey added a comment to T922: OSPF - Process Crash after peer reboot.

@kroy - I tried doing an upgrade to match all routers to the same version and it ended quite badly.. all four had their OSPF instance die.

Dec 5 2018, 12:18 AM · VyOS 1.3 Equuleus

Dec 4 2018

Merijn added a comment to T904: BGP process does not start a boot.

Upgrade to 1.2.0-rc10 and BGP is still working fine. It starts at boot and loads all BGP peers and several full tables.

Dec 4 2018, 10:36 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-EPA3)
kroy added a comment to T922: OSPF - Process Crash after peer reboot.

I'll add here that I've got a reasonably complex OSPF setup with around 10 hosts. I converted it over to VyOS when the first RC came out and I haven't seen this issue at all, and I'm constantly rebooting hosts. Currently upgraded the whole setup to RC10 and not a single host crashed. It's worth adding that I've had a bunch of Mikrotiks in the mix at a time and no problem there either.

Dec 4 2018, 4:16 PM · VyOS 1.3 Equuleus
dmbaturin renamed T1047: Configuration saved on a livecd cannot be carried over to the installed image from Configuration does not propagate to install image. to Configuration saved on a livecd cannot be carried over to the installed image.
Dec 4 2018, 3:27 PM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
zsdc added a comment to T1000: Broken 6rd tunnel implementation.

Tested with 1.2.0-rolling+201812010337. Still many bugs, very hard to diagnostic it properly.
Minimal list TODO, for we can continue testing:

Dec 4 2018, 3:24 PM · VyOS 1.3 Equuleus
dmbaturin closed T1019: Enable Google BBR support at kernel compile time as Resolved.
Dec 4 2018, 12:48 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)

Dec 3 2018

hagbard added a comment to T1028: Suspending and resuming VyOS in VMware will result in loss of static ip addresses.

The vmware tools scripts work as expected, they are stopping and starting the network config as they are supposed to do, but are using debian defaults. So they are not executing the config. I'm going to check of we can extend it a little somewhere to execute the config again when 'resume' happens. In general that won't be an easy fix.

Dec 3 2018, 5:00 PM · VyOS 1.3 Equuleus
c-po added a comment to T419: Support setting dstport for VXLAN interfaces.

Setting destination port per VXLAN interface sound much more reasonable

Dec 3 2018, 6:39 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
c-po merged task T419: Support setting dstport for VXLAN interfaces into T1067: VXLAN support improvements.
Dec 3 2018, 6:39 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
dmbaturin closed T902: VyOS 1.2.0-rc2 fails to load configuration when conntrack modules are disabled in config as Resolved.

I've tested this configuration again and it works for me, so I suppose it's fixed. If it reapprears, feel free to reopen.

Dec 3 2018, 3:02 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
dmbaturin closed T337: 'show vpn ipsec sa' output wrong when remote or local prefix not in system subnet as Resolved.

@hagbard "show vpn ipsec sa verbose" is now a thin wrapper for "ipsec statusall" so it's not applicable there either. :)

Dec 3 2018, 2:56 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc10)
dmbaturin added a comment to T1047: Configuration saved on a livecd cannot be carried over to the installed image.

...to be fair, I also think there should be a warning when trying to save a config on a livecd. We hear from people once in a while that they forgot they are running from a livecd and lose their config after reboot.

Dec 3 2018, 1:52 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux ( VyOS 1.2.0-rc11)
dmbaturin closed T769: StrongSWAN starts when "vpn ipsec" is not present in the config as Resolved.

Clearly undesirable behaviour was caused by a combination of two issues: StrongSWAN starting even when IPsec is not present in the VyOS config, and /etc/ipsec.conf staying in place if config was commited but not saved.

Dec 3 2018, 1:36 AM · VyOS-1.2.0-GA, VyOS 1.2 Crux (VyOS 1.2.0-rc9)