Age | Commit message (Collapse) | Author | |
---|---|---|---|
2019-01-03 | T1147: Fix SNMP config file generation on newly installed systems | Christian Poessinger | |
2019-01-02 | Initial implementation of declarative config dict retrieval library. | Daniil Baturin | |
2019-01-02 | Merge pull request #64 from daniel-pro/T1119 | Daniil Baturin | |
T1119: 'show vpn ipsec sa' shows tunnel twice in 1.2.0-RC11 | |||
2019-01-01 | T1119: 'show vpn ipsec sa' shows tunnel twice in 1.2.0-RC11 | Daniel | |
Removed duplicates from "connections" list. | |||
2018-12-31 | T1128: restart SNMP on hostname change. | Daniil Baturin | |
2018-12-31 | T1112: migrate BGP redistribute metric and route-map options too. | Daniil Baturin | |
2018-12-31 | T1112: migrate BGP redistribute options (patch by Merijn). | Daniil Baturin | |
2018-12-31 | T1108: warn the user and exit if there are no established IPsec SAs. | Daniil Baturin | |
2018-12-17 | Merge pull request #62 from daniel-pro/T1104 | Daniil Baturin | |
T1104 : "show vpn ipsec sa" crashes | |||
2018-12-16 | Update show_ipsec_sa.py | daniel-pro | |
2018-12-16 | Revert "T1087: Firewall on Wireguard Interface implementation" | Daniil Baturin | |
This reverts commit 51f61991092a163f680e4ec8f122e73f4074ddf9. It's not how it's done, those templates are generated by a script in vyatta-cfg-firewall. If we are planning a firewall overhaul in 1.3.x, there's no reason to transplant the old approach to new code. | |||
2018-12-11 | T1087: Firewall on Wireguard Interface implementation | hagbard | |
2018-12-09 | T1091: extend DNS forwarding/DNSSEC completion help text | Christian Poessinger | |
2018-12-09 | T1091: add DNS forwarding completion helpers for DNSSEC | Christian Poessinger | |
2018-12-07 | T1060: build fix for wrong config-version number | Christian Poessinger | |
Commit 9d35610c173 ("T1060: add missing version file for webproxy") assumed that there is a webproxy config version of 0 but we already have 1. This lead to duplicate files detected by apt. | |||
2018-12-07 | Merge pull request #61 from dsteinkopf/current | Christian Poessinger | |
T1060: Add webproxy migration script (proxy-bypass -> whitelist). | |||
2018-12-03 | T956: display SA traffic counters in human-redable units. | Daniil Baturin | |
2018-12-03 | T956: correct IKE proposal string parsing for SAs with non-zero counters. | Daniil Baturin | |
2018-12-02 | T1060: Add webproxy migration script (proxy-bypass -> whitelist). | Dirk Steinkopf | |
2018-11-30 | Fixes: T1061: Wireguard: Missing option to administrativly shutdown interface | hagbard | |
2018-11-29 | T1001: escape backslashes in the input in the commands pipe as well. | Daniil Baturin | |
2018-11-29 | Merge pull request #60 from arnehaak/current | Daniil Baturin | |
T1001: Bugfix: Handle backslashes in values with "show configuration commands" | |||
2018-11-29 | T1001: Bugfix: Handle backslashes in values with "show configuration commands" | arnehaak | |
This script is usually called with the output of "cli-shell-api showCfg", which does not escape backslashes. "ConfigTree()" expects escaped backslashes when parsing a config string (and also prints them itself). Therefore this script would fail. Manually escape backslashes here to handle backslashes in any configuration strings properly. The alternative would be to modify the output of "cli-shell-api showCfg", but that may be break other things who rely on that specific output. This fixes https://phabricator.vyos.net/T1001 | |||
2018-11-26 | T835: improve help text for PPPoE CLI. | Daniil Baturin | |
2018-11-23 | T835: adding description to ppp-options | hagbard | |
2018-11-23 | New verse for "run show version funny". | Daniil Baturin | |
2018-11-22 | T989: IPoE implementation | hagbard | |
- adding vyos-accel-ppp-ipoe-kmod to dependencies | |||
2018-11-22 | T835: accel-ppp: pppoe implementation | hagbard | |
- verify if an auth mode is set and if its local checking that a user and password for chap-secrets exists. | |||
2018-11-21 | T835: syslog debug message removed (to verbose) | hagbard | |
2018-11-19 | T835: migration script for radius' secret vs. key, rolled back the | hagbard | |
change to 'mode local|radius' | |||
2018-11-19 | T835: add missing call to write_chap_secrets() to generate() | Daniil Baturin | |
2018-11-19 | Move packages that vyos-1x depends on to vyos-1x from vyos-world. | Daniil Baturin | |
2018-11-18 | Merge branch 'current' of https://github.com/vyos/vyos-1x into current | Daniil Baturin | |
2018-11-18 | T956: add a new script for displaying IPsec SAs. | Daniil Baturin | |
2018-11-18 | T835: adding default pado delay and mode autocomplete | hagbard | |
2018-11-17 | T1018: remove obsoleted 'dynamic' option from NTP | Christian Poessinger | |
Increase NTP config version from 0 to 1. For more information see [1]. ntpd: Warning: the "dynamic" keyword has been obsoleted and will be removed in the next release [1]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=553976 | |||
2018-11-17 | Rename show-igmpproxy.py -> show_igmpproxy.py | Christian Poessinger | |
2018-11-17 | T1016: fix IPv4/IPv6 dhcp relay restart command | Christian Poessinger | |
Current implementation referred to a no longer existing Perl script to restart the IPv4 and IPv6 instance of dhcrelay. > restart dhcp relay-agent > restart dhcpv6 relay-agent | |||
2018-11-17 | Lint fixup of opmode XML indention | Christian Poessinger | |
2018-11-14 | Bugfix: T835 - verify radius server settings | hagbard | |
2018-11-14 | Fixes: T940 adding immark to syslog options | hagbard | |
2018-11-14 | T835: accel-ppp pppoe implemetaion | hagbard | |
- ipv6 DNS, ippv6pool, ipv6 PD, ipv6 inf IDs - snmp subagent and master mode - connlimits configurable - more ppp options configurable (mppe, lcp-echo intervals, mtu, mru etc.) - radius extended options (for HA etc.) | |||
2018-11-12 | migration/l2tp: fix file comment | Christian Poessinger | |
2018-11-12 | T987: Unclutter PPTP/IPSec RADIUS configuration nodes | Christian Poessinger | |
In other words, remove top level tag nodes from radius-server and introduce a regular "radius" node, thus we can add additional features, too. A migration script is provided in vyos-1x which takes care of this config migration. Change VyOS CLI from: vyos@vyos# show vpn pptp remote-access { authentication { mode radius radius-server 172.16.100.10 { key barbarbar } radius-server 172.16.100.20 { key foofoofoo } } To: vyos@vyos# show vpn l2tp remote-access { authentication { mode radius radius { server 172.16.100.10 { key barbarbar } server 172.16.100.20 { key foofoofoo } } } | |||
2018-11-11 | T998: "service dns dynamic" does now honor the "use-web" statement | Christian Poessinger | |
This bug was present since the old Vyatta days as the use-web statement was only put into action when also "use-web skip" was defined. The service https://ipinfo.io/ip does not place any crap in front of the IP address so the skip statement was not used and made no sense. | |||
2018-11-11 | T987: Unclutter L2TP/IPSec RADIUS configuration nodes | Christian Poessinger | |
In other words, remove top level tag nodes from radius-server and introduce a regular "radius" node, thus we can add additional features, too. A migration script is provided in vyos-1x which takes care of this config migration. Change VyOS CLI from: vyos@vyos# show vpn l2tp remote-access { authentication { mode radius radius-server 172.16.100.10 { key barbarbar } radius-server 172.16.100.20 { key foofoofoo } radius-source-address 172.16.254.100 } To: vyos@vyos# show vpn l2tp remote-access { authentication { mode radius radius { server 172.16.100.10 { key barbarbar } server 172.16.100.20 { key foofoofoo } source-address 172.16.254.100 } } | |||
2018-11-09 | T835: pppoe-server adding radius server back in | hagbard | |
2018-11-09 | T835: accel-ppp pppoe implementation | hagbard | |
2018-11-09 | Merge pull request #58 from gsadams/current | Christian Poessinger | |
T978: Support PowerDNS Recursor outbound queries over IPv6. | |||
2018-11-08 | T978: Support PowerDNS Recursor outbound queries over IPv6. | Geoff Adams | |
This requires adding a query-local-address6 setting to enable outbound IPv6 queries in general, and also formatting upstream nameserver IPv6 addresses in such a way that Recursor can parse them. |