Page MenuHomeVyOS Platform

VyOS 1.2 CruxProject
ActivePublic

Details

Description

Jessie based VyOS - Crux

Recent Activity

Yesterday

s.lorente added a comment to T2700: Redirecting traffic from PPPoE interface to IFB fails.

https://forum.vyos.io/t/limit-download-and-upload-on-wan-for-every-vlan/5608/51

Tue, Sep 22, 4:58 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
SrividyaA renamed T2914: OpenVPN: Fix for IPv4 remote-host hostname in client mode: from OpenVPN: Fix for IPv4 remote-host addresses in client mode: to OpenVPN: Fix for IPv4 remote-host hostname in client mode:.
Tue, Sep 22, 12:12 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
SrividyaA created T2914: OpenVPN: Fix for IPv4 remote-host hostname in client mode:.
Tue, Sep 22, 12:11 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
Viacheslav added a comment to T2895: VPN IPsec "leftsubnet" declared 2 times.

PR for rolling https://github.com/vyos/vyatta-cfg-vpn/pull/38

Tue, Sep 22, 11:48 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
Viacheslav claimed T2895: VPN IPsec "leftsubnet" declared 2 times.

It declared 2 times, because there is 2 checks

Tue, Sep 22, 11:19 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
Viacheslav added a comment to T2883: op-mode reset vpn command shows wrong completion.

PR https://github.com/vyos/vyatta-ravpn/pull/16

Tue, Sep 22, 10:39 AM · VyOS 1.2 Crux
Viacheslav added a comment to T2883: op-mode reset vpn command shows wrong completion.

This is the output of this line

Tue, Sep 22, 7:45 AM · VyOS 1.2 Crux
azdle created T2913: Failure to install fpm while building builder docker image.
Tue, Sep 22, 1:53 AM · VyOS 1.2 Crux

Mon, Sep 21

jack9603301 updated the task description for T2898: Support NDP proxy.
Mon, Sep 21, 6:41 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 updated the task description for T2898: Support NDP proxy.
Mon, Sep 21, 5:58 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 updated the task description for T2898: Support NDP proxy.
Mon, Sep 21, 5:58 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus

Sun, Sep 20

jack9603301 added a comment to T2898: Support NDP proxy.

@c-po If I want to be an interface- ethernet.xml.in Add custom configuration actions (such as proxy NDP) with certain extensibility (its configuration can be extended in other places). What should I do?

Sun, Sep 20, 3:19 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
Cheeze_It added a comment to T2898: Support NDP proxy.

@Cheeze_It

I also take into account the specific situation of the ndp proxy, the configuration of this link prompts, the configuration format of the ndp proxy is like this.

https://manpages.debian.org/buster/ndppd/ndppd.conf.5.en.html

Sun, Sep 20, 12:22 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus

Sat, Sep 19

jack9603301 moved T2898: Support NDP proxy from Need Triage to In Progress on the VyOS 1.3 Equuleus board.
Sat, Sep 19, 6:12 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

I also take into account the specific situation of the ndp proxy, the configuration of this link prompts, the configuration format of the ndp proxy is like this.

Sat, Sep 19, 6:06 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 updated the task description for T2898: Support NDP proxy.
Sat, Sep 19, 5:51 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 updated the task description for T2898: Support NDP proxy.
Sat, Sep 19, 5:51 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

No arp proxy option is found in the configuration path, ndp proxy can manage multiple address rules under one interface

vyos@vyos# set interfaces ethernet eth0 ip 
Possible completions:
   arp-cache-timeout
                ARP cache entry timeout in seconds
   disable-arp-filter
                Disable ARP filter on this interface
   enable-arp-accept
                Enable ARP accept on this interface
   enable-arp-announce
                Enable ARP announce on this interface
   enable-arp-ignore
                Enable ARP ignore on this interface
   enable-proxy-arp
                Enable proxy-arp on this interface
 > ospf         Open Shortest Path First (OSPF) parameters
   proxy-arp-pvlan
                Enable private VLAN proxy ARP on this interface
 > rip          Routing Information Protocol (RIP)
   source-validation
                Policy for source validation by reversed path, as specified in RFC3704
Sat, Sep 19, 5:46 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

Although I intended to think that it is easier to write scripts under the protocol, but from an intuitive point of view, it seems that this path is also a good choice (users can use the same command line as the arp proxy to configure) I have written it A sample, then only need to decide how to modify the cli

Sat, Sep 19, 5:24 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

set interfaces ethernet eth0 ip proxy-arp

The more suitable position may be set protocol ndp-proxy

I...really would like to not put it under "protocols" but to put it under the interface. It's *much* easier and more intuitive to see it under the interface/sub-interface than to see it in its' own stanza under "protocol" node.

Also, I'd argue it would be reasonable to separate ARP proxy and NDP proxy. That way one can pick and choose. Of course ARP proxy can't work without an IP address configured. NDP proxy can't be configured without an IPv6 address configured (those could be used as checks against configuring it on an empty interface).

Sat, Sep 19, 5:21 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

If possible, give your suggested cli path for my reference

Sat, Sep 19, 5:18 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
Cheeze_It added a comment to T2898: Support NDP proxy.

set interfaces ethernet eth0 ip proxy-arp

The more suitable position may be set protocol ndp-proxy

Sat, Sep 19, 5:00 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 updated the task description for T2898: Support NDP proxy.
Sat, Sep 19, 1:34 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 changed the status of T2898: Support NDP proxy from Open to In progress.
Sat, Sep 19, 9:39 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 updated the task description for T2898: Support NDP proxy.
Sat, Sep 19, 7:21 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

I can't find how to enable ipv6 connection tracking. Recompiling and modifying the linux kernel switch does not seem to see the module loaded. I think the current nat66 has completed 90%, and only need to implement ndp proxy to make it work normally.

Sat, Sep 19, 7:20 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

set interfaces ethernet eth0 ip proxy-arp

Sat, Sep 19, 7:17 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a comment to T2898: Support NDP proxy.

I think we do need it, we can’t let users manage all IP manually unless we implement stateful NAT66

Sat, Sep 19, 7:15 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
c-po added a comment to T2898: Support NDP proxy.

set interfaces ethernet eth0 ip proxy-arp

Sat, Sep 19, 6:57 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 triaged T2898: Support NDP proxy as Normal priority.
Sat, Sep 19, 6:41 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 claimed T2898: Support NDP proxy.
Sat, Sep 19, 6:40 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 updated the task description for T2898: Support NDP proxy.
Sat, Sep 19, 6:30 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus
jack9603301 added a project to T2898: Support NDP proxy: VyOS 1.2 Crux.
Sat, Sep 19, 6:29 AM · VyOS 1.2 Crux, VyOS 1.3 Equuleus

Fri, Sep 18

Viacheslav created T2895: VPN IPsec "leftsubnet" declared 2 times.
Fri, Sep 18, 6:09 PM · VyOS 1.2 Crux, VyOS 1.3 Equuleus

Wed, Sep 16

Viacheslav created T2889: Service SNMP doesn't start after adding new addresses.
Wed, Sep 16, 3:13 PM · VyOS 1.2 Crux

Mon, Sep 14

syncer renamed T2883: op-mode reset vpn command shows wrong completion from Reset vpn commands show wrong complation to op-mode reset vpn command shows wrong completion.
Mon, Sep 14, 9:37 PM · VyOS 1.2 Crux
Dmitry created T2883: op-mode reset vpn command shows wrong completion.
Mon, Sep 14, 9:13 PM · VyOS 1.2 Crux

Tue, Sep 8

zsdc added a comment to T2310: vyos-cloud-init use global config to configure pass and ssh login.

This feature now is in the Cloud-init for 1.3 and must be backported after testing.

Tue, Sep 8, 4:40 PM · VyOS 1.2 Crux (VyOS 1.2.7), VyOS 1.3 Equuleus
zsdc added a comment to T2703: VMWare OVA won't deploy an ed25519 key.

@kroy how about testing this in 1.3? It must work now.

Tue, Sep 8, 4:34 PM · VyOS 1.2 Crux

Thu, Sep 3

c-po added a comment to T2852: rename dynamic dns interface breaks ddclient.cache permissions.

Tested with:

set service dns dynamic interface eth0.203 service custom host-name 'test.vyos.net'
set service dns dynamic interface eth0.203 service custom login 'vyos'
set service dns dynamic interface eth0.203 service custom password 'vyos'
set service dns dynamic interface eth0.203 service custom protocol 'dyndns2'
set service dns dynamic interface eth0.203 service custom server 'vyos.io'
Thu, Sep 3, 8:16 PM · VyOS 1.2 Crux (VyOS 1.2.6)
c-po closed T2852: rename dynamic dns interface breaks ddclient.cache permissions as Resolved.
Thu, Sep 3, 8:15 PM · VyOS 1.2 Crux (VyOS 1.2.6)
c-po added a comment to T2852: rename dynamic dns interface breaks ddclient.cache permissions.

This also happens on service deletion

Thu, Sep 3, 6:16 PM · VyOS 1.2 Crux (VyOS 1.2.6)

Wed, Sep 2

Merijn closed T2214: BGP peers dropping randomly as Resolved.
Wed, Sep 2, 7:52 AM · VyOS 1.2 Crux
Merijn closed T2378: BGPD crash in Vyos 1.2.5 as Invalid.
Wed, Sep 2, 7:38 AM · VyOS 1.2 Crux
Merijn added a comment to T2378: BGPD crash in Vyos 1.2.5.

@Viacheslav it happened yesterday again but the stack trace was different. This time it was complaining that BGPD did not respond and the frr watch process tried to restart it, which of course did not help the situation.
I will continue to monitor but i think we can close this issue and wait for more details when it happens again.

Wed, Sep 2, 7:38 AM · VyOS 1.2 Crux

Tue, Sep 1

masterit created T2852: rename dynamic dns interface breaks ddclient.cache permissions.
Tue, Sep 1, 11:55 PM · VyOS 1.2 Crux (VyOS 1.2.6)

Mon, Aug 31

marekm added a comment to T2820: BGP crash in if_destroy_via_zapi.

Even with customers routes redistributed by OSPF instead of iBGP, it has just crashed again:

Mon, Aug 31, 2:28 PM · VyOS 1.2 Crux
marekm added a comment to T2820: BGP crash in if_destroy_via_zapi.

I tried unit-cache earlier but it seems to have issues too - I've seen duplicate routes if the same client (all have static IP assigned by RADIUS based on username) connects to a different PPPoE server and the old route is not removed, as if the cached (not removed) PPPoE interfaces were not seen as removed in FRR. But I haven't investigated this in more detail as it's a production setup, can't experiment too much on live customers.
I'm considering if I could go back to redistributing PPPoE customers /32 routes in OSPF instead of iBGP - it has been that way for a few years (using MikroTik, before moving to VyOS), but I've recently changed it following "BGP Best Current Practices" http://www.bgp4all.com.au/pfs/_media/workshops/05-bgp-bcp.pdf which recommends using OSPF only for infrastructure, not customers - seems logical to me as BGP was designed for much larger routing tables (all of the Internet), but perhaps OSPF is still good enough for just a few hundreds of customers.

Mon, Aug 31, 9:00 AM · VyOS 1.2 Crux
Dmitry added a comment to T2820: BGP crash in if_destroy_via_zapi.

Hello @marekm, I think [ppp]unit-cache=n might help in this case, but the main issue in FRR. Do you want a package for the test with these improvements?

unit-cache=n
By default is disabled: unit-cache=0
Mon, Aug 31, 8:12 AM · VyOS 1.2 Crux

Sun, Aug 30

hagbard triaged T2835: "show system-integrity" reports lots of wrong timestamp packages with v1.2.6-epa1 as Normal priority.
Sun, Aug 30, 3:12 PM · VyOS 1.3 Equuleus, VyOS 1.2 Crux