Age | Commit message (Collapse) | Author | |
---|---|---|---|
2020-03-10 | pppoe: T1318: minor code cleanup | Christian Poessinger | |
2020-03-09 | openvpn: T2065: pass daemon parameter to start-stop-daemon in op-mode | Christian Poessinger | |
Commit cd2147cfa2 ("openvpn: T2065: move daemon parameter to start-stop-daemon commandline") only added the cfg-mode part but missed out op-mode. | |||
2020-03-09 | T1967: add a migration script for the enforce-first-as option. | Daniil Baturin | |
2020-03-08 | vrf: T31: add missing import netifaces.interfaces | Christian Poessinger | |
2020-03-08 | wireless: T1627: configure own_ip_addr to be compliant with the RADIUS protocol | Christian Poessinger | |
2020-03-08 | wireless: radius: T2110: aupport server disable option | Christian Poessinger | |
2020-03-08 | vrf: T31: fix invalid variable reference | Christian Poessinger | |
With commit d61cab4 ("vrf: T31: enable vrf support for wireless interface") an unknown variable has been referenced. | |||
2020-03-08 | vrf: T31: add member interfaces to 'show ver' output | Christian Poessinger | |
VRF name state mac address flags interfaces -------- ----- ----------- ----- ---------- blue up de:c4:83:d8:74:24 noarp,master,up,lower_up dum200,eth0.302 red up be:36:ce:02:df:aa noarp,master,up,lower_up dum100,eth0.300,bond0.100,peth0 | |||
2020-03-08 | vrf: T31: enable vrf support for wireless interface | Christian Poessinger | |
2020-03-08 | vrf: T31: enable vrf support for pseudo-ethernet/macvlan interface | Christian Poessinger | |
2020-03-08 | macvlan: T1635: add missing VLAN/VIF creation logic | Christian Poessinger | |
2020-03-08 | vrf: T31: support VRF usage on VLAN/VIF interfaces | Christian Poessinger | |
2020-03-07 | wireless: T2107: fix connecting to networks without passphrase | Christian Poessinger | |
2020-03-07 | pppoe: T1318: move to Python3 f-strings where possible | Christian Poessinger | |
2020-03-07 | vrf: T31: enable vrf support for pppoe interface | Christian Poessinger | |
2020-03-07 | pppoe: T1493: rename variables on ipv6-up script | Christian Poessinger | |
2020-03-07 | pppoe: T1318: add ip-pre-up script | Christian Poessinger | |
ppp already supports ip-pre-up script but none was being supplied. Need ip-pre-up to handle renames and firewall properly. Script imported from old VyOS PPP fork repository at https://github.com/vyos/ppp-debian | |||
2020-03-07 | vrf: T31: move to Python3 f-strings where possible | Christian Poessinger | |
2020-03-07 | vrf: T31: ensure VRF can not be deleted with an attached routing protocol | Christian Poessinger | |
2020-03-07 | vrf: T31: rephrase error messages | Christian Poessinger | |
2020-03-07 | vrf: T31: reuse Config in interfaces_with_vrf() | Christian Poessinger | |
2020-03-07 | vrf: T31: properly set configuration level when parsing | Christian Poessinger | |
2020-03-06 | vrf: T31: enable vrf support for bridge interface | Christian Poessinger | |
2020-03-06 | vrf: T31: enable vrf support for bonding interface | Christian Poessinger | |
2020-03-06 | vrf: T31: enable vrf support for ethernet interface | Christian Poessinger | |
2020-03-06 | Merge pull request #242 from thomas-mangin/split | Christian Poessinger | |
ifconfig: T2104: splt ifconfig.py into multiple files | |||
2020-03-06 | ifconfig: T2104: splt ifconfig.py into multiple files | Thomas Mangin | |
2020-03-06 | wireless: T2105: Add check interface state | DmitriyEshenko | |
2020-03-05 | vrf: T31: improve kernel rule lookup table code | Christian Poessinger | |
2020-03-05 | vrf: T31: modify kernel rule lookup table only once | Christian Poessinger | |
2020-03-05 | vrf: T31: add more documentation links | Christian Poessinger | |
2020-03-05 | vrf: T31: use subprocess check_output over check_call | Christian Poessinger | |
2020-03-05 | pppoe: T1493: fix for fix of invalid reference of ipv6-up script file | Christian Poessinger | |
Commit d161cbb ("pppoe: T1493: fix invalid reference of ipv6-up script file") actually introduced another bug instead of fixing it. It was catched by vyos-smoketest ... luckily! Sorry! | |||
2020-03-05 | vrf: T31: routing table IDs must be unique | Christian Poessinger | |
2020-03-05 | vrf: T31: use vyos.ifconfig to set ifalias | Christian Poessinger | |
2020-03-05 | vrf: T31: table id is mandatory | Christian Poessinger | |
2020-03-05 | pppoe: T1493: fix invalid reference of ipv6-up script file | Christian Poessinger | |
2020-03-05 | login: T2050: extend verify() on public-keys | Christian Poessinger | |
* A type must be present for any one public-key element * A key must be present for any one public-key element | |||
2020-03-05 | pppoe: T1493: support IPv6 address negotiation which is required for DHCPv6-PD | Christian Poessinger | |
2020-03-05 | macvlan: T1635: ensure 'link' interface really exists | Christian Poessinger | |
2020-03-05 | vxlan: T1636: ensure 'link' interface really exists | Christian Poessinger | |
2020-03-04 | pppoe: T1318: IPv6 support | Christian Poessinger | |
2020-03-04 | vrf: T31: remove pass in exception handler | Christian Poessinger | |
2020-03-04 | banner: T2099: accept empty pre-/post-login banner | Christian Poessinger | |
2020-03-04 | vrf: T31: enable vrf support for dummy interface | Christian Poessinger | |
2020-03-04 | vrf: T31: reorder routing table lookups | Christian Poessinger | |
Linux routing uses rules to find tables - routing targets are then looked up in those tables. If the lookup got a matching route, the process ends. TL;DR; first table with a matching entry wins! You can see your routing table lookup rules using "ip rule", sadly the local lookup is hit before any VRF lookup. Pinging an addresses from the VRF will usually find a hit in the local table, and never reach the VRF routing table - this is usually not what you want. Thus we will re-arrange the tables and move the local lookup furhter down once VRFs are enabled. | |||
2020-03-04 | vrf: T31: adding unreachable routes to the routing tables | Christian Poessinger | |
2020-03-04 | vrf: T31: prior to the v4.8 kernel iif and oif rules are needed | Christian Poessinger | |
.. we run on 4.19 thus this is no longer needed. | |||
2020-03-04 | vrf: T31: create iproute2 table to name mapping reference | Christian Poessinger | |
2020-03-04 | vrf: T31: rename 'vrf disable-bind-to-all ipv4' to 'vrf bind-to-all' | Christian Poessinger | |
By default the scope of the port bindings for unbound sockets is limited to the default VRF. That is, it will not be matched by packets arriving on interfaces enslaved to an l3mdev and processes may bind to the same port if they bind to an l3mdev. TCP & UDP services running in the default VRF context (ie., not bound to any VRF device) can work across all VRF domains by enabling the 'vrf bind-to-all' option. |