Page MenuHomeVyOS Platform

vyatta-natProject
ActivePublic

Members

  • This project does not have any members.
  • View All

Watchers

  • This project does not have any watchers.
  • View All

Details

Description

This package has Vyatta configuration and operational templates and scripts for NAT.

Recent Activity

Aug 23 2023

n.fort closed T4889: Add nftables NAT REDIRECT [to localhost] to CLI as Resolved.
Aug 23 2023, 11:17 AM · vyatta-nat, VyOS 1.4 Sagitta

Jul 24 2023

n.fort changed the status of T4889: Add nftables NAT REDIRECT [to localhost] to CLI from In progress to Needs testing.
Jul 24 2023, 10:11 AM · vyatta-nat, VyOS 1.4 Sagitta

Jul 19 2023

n.fort changed the status of T4889: Add nftables NAT REDIRECT [to localhost] to CLI from Open to In progress.
Jul 19 2023, 2:36 PM · vyatta-nat, VyOS 1.4 Sagitta
n.fort added a comment to T4889: Add nftables NAT REDIRECT [to localhost] to CLI.

PR: https://github.com/vyos/vyos-1x/pull/2100

Jul 19 2023, 2:36 PM · vyatta-nat, VyOS 1.4 Sagitta

Jul 14 2023

n.fort claimed T4889: Add nftables NAT REDIRECT [to localhost] to CLI.
Jul 14 2023, 6:53 PM · vyatta-nat, VyOS 1.4 Sagitta

Dec 21 2022

marvin added projects to T4889: Add nftables NAT REDIRECT [to localhost] to CLI: VyOS 1.4 Sagitta, vyatta-nat.
Dec 21 2022, 7:27 PM · vyatta-nat, VyOS 1.4 Sagitta

Dec 27 2021

Viacheslav closed T3287: Ability to set DNAT translation address incorrectly as Invalid.

There is a task for "loadbalancing" T4109

Dec 27 2021, 6:42 PM · vyatta-nat, VyOS 1.4 Sagitta

Feb 28 2021

Viacheslav added a comment to T3287: Ability to set DNAT translation address incorrectly.

You can use <x.x.x.x>-<x.x.x.x>
Or you need "multi" addresses not in "range"? Something like

set nat destination rule 5 translation member 203.0.113.1
set nat destination rule 5 translation member 203.0.113.14
set nat destination rule 5 translation member 203.0.113.240
Feb 28 2021, 1:56 PM · vyatta-nat, VyOS 1.4 Sagitta

Feb 22 2021

Viacheslav triaged T3287: Ability to set DNAT translation address incorrectly as Normal priority.
Feb 22 2021, 10:57 AM · vyatta-nat, VyOS 1.4 Sagitta

Feb 4 2021

Dickins created T3287: Ability to set DNAT translation address incorrectly.
Feb 4 2021, 5:16 PM · vyatta-nat, VyOS 1.4 Sagitta

Sep 4 2020

disirk74 created T2859: show nat source translation - Errors out.
Sep 4 2020, 2:20 PM · VyOS 1.3 Equuleus (1.3.0)

Jan 21 2020

xrobau closed T1979: 'set nat destination' incorrectly requires inbound-interface as Invalid.

Turns out that 'destination-interface any' works, and I just hadn't read the help.

Jan 21 2020, 10:39 PM · vyatta-nat
xrobau created T1979: 'set nat destination' incorrectly requires inbound-interface.
Jan 21 2020, 10:29 PM · vyatta-nat

Jan 24 2019

hexes closed T1195: Passive FTP + NAT + Privileged Port as Resolved.
Jan 24 2019, 4:09 PM · vyos-kernel, vyatta-cfg-firewall, vyatta-nat, VyOS-1.2.0-GA
hexes added a comment to T1195: Passive FTP + NAT + Privileged Port.

I'm not sure. Only hypothesis...

Jan 24 2019, 4:09 PM · vyos-kernel, vyatta-cfg-firewall, vyatta-nat, VyOS-1.2.0-GA
Line2 added a comment to T1195: Passive FTP + NAT + Privileged Port.

are you sure, or could it be related to conntrack helper topic in T1141?

Jan 24 2019, 2:58 PM · vyos-kernel, vyatta-cfg-firewall, vyatta-nat, VyOS-1.2.0-GA
hexes created T1195: Passive FTP + NAT + Privileged Port in the S1 VyOS Public space.
Jan 24 2019, 1:26 AM · vyos-kernel, vyatta-cfg-firewall, vyatta-nat, VyOS-1.2.0-GA

May 27 2018

syncer closed T576: DNS forwarding service or nat forwarding bug as Wontfix.

We moved to pdns in 1.2 and will not be fixing it in 1.1.x
if you can reproduce on 1.2 mention this task or create new

May 27 2018, 10:08 AM · Rejected

Apr 7 2018

syncer added a comment to T576: DNS forwarding service or nat forwarding bug.

can you repeat same on 1.2 ?

Apr 7 2018, 11:10 AM · Rejected

Mar 12 2018

Smiley added a comment to T576: DNS forwarding service or nat forwarding bug.

Well, as I previously said, I finally know why it doesn't worked as expected for me, since lines like "listen-on vti0 and listen-on vti1" were missing, for requests incoming from tunneled networks.
However, it seems to be strange that requests are sometimes still forwarded, as we can expect that none are forwarded, or all are forwarded, but why sometimes only some request are forwarded ? This seems to be a bug, however this ticket can be closed since for my needs it's ok...

Mar 12 2018, 9:19 AM · Rejected

Mar 9 2018

rps added a comment to T576: DNS forwarding service or nat forwarding bug.

P.S. This is really starting to get more into the territory of support than bug reporting, have you considered purchasing support?

Mar 9 2018, 2:30 PM · Rejected
rps added a comment to T576: DNS forwarding service or nat forwarding bug.

At first glance it looks like the name servers you are using are not reliable, and the lack of response is because the forwarder is also not getting a response.

Mar 9 2018, 2:26 PM · Rejected
Smiley added a comment to T576: DNS forwarding service or nat forwarding bug.

(By the way, it would be interesting to be able to add more than only one inbound-interface to a NAT rule...)

Mar 9 2018, 1:14 PM · Rejected
Smiley added a comment to T576: DNS forwarding service or nat forwarding bug.

(And I guess that it's the same reason for NAT rule : the inbound-interface should not only be eth0...)

Mar 9 2018, 12:42 PM · Rejected
Smiley added a comment to T576: DNS forwarding service or nat forwarding bug.
  1. There are no firewall rules set, and no firewall rulset set to the interface on the affected VyOS instances
  2. The problems seems to occur whatever the name resolution request is
  3. Yes, see below
Mar 9 2018, 11:37 AM · Rejected

Mar 8 2018

rps added a comment to T576: DNS forwarding service or nat forwarding bug.

We'll need some more information.

Mar 8 2018, 4:09 PM · Rejected
Smiley added a comment to T576: DNS forwarding service or nat forwarding bug.

Yes, I thought about that too, but with or without setting the dns
cache-size to 0, I have the same result !

Mar 8 2018, 8:11 AM · Rejected

Mar 7 2018

rps added a comment to T576: DNS forwarding service or nat forwarding bug.

By default the DNS forwarder will cache recent responses. Have you disabled DNS caching on the forwarding service with the following configuration?

Mar 7 2018, 10:20 PM · Rejected
Smiley created T576: DNS forwarding service or nat forwarding bug.
Mar 7 2018, 5:10 PM · Rejected
rps added a comment to T575: SNAT with static port not working.

It was likely the first scenario that I mentioned where there was traffic already established before the NAT rule was created. Also note that a reset conntrack is essentially a flush of the conntrack table and can be disruptive for established connections. Alternatively you could have cleared conntrack entries for the specific host address only as a more safe way of doing it in the future.

Mar 7 2018, 4:32 AM · VyOS 1.1.x (1.1.8), vyatta-nat
vasglebov closed T575: SNAT with static port not working as Resolved.

Thank you for your attention, cause it's router in production at night executed

reset conntrack

I don't know what it was but now all works fine, sorry for the trouble.

Mar 7 2018, 2:21 AM · VyOS 1.1.x (1.1.8), vyatta-nat

Mar 6 2018

rps added a comment to T575: SNAT with static port not working.

I have verified that this is working on 1.1.8 so there might be a configuration or operation issue that is making you see this behavior (I actually have this working in production at scale using over 14,500 rules across 28 chains).

Mar 6 2018, 9:37 PM · VyOS 1.1.x (1.1.8), vyatta-nat
vasglebov updated the task description for T575: SNAT with static port not working.
Mar 6 2018, 7:51 AM · VyOS 1.1.x (1.1.8), vyatta-nat
vasglebov created T575: SNAT with static port not working.
Mar 6 2018, 7:50 AM · VyOS 1.1.x (1.1.8), vyatta-nat

Jul 24 2017

syncer created vyatta-nat.
Jul 24 2017, 8:27 PM