summaryrefslogtreecommitdiff
path: root/docs/configuration
AgeCommit message (Collapse)Author
2023-11-07Merge pull request #1127 from JeffWDH/masterRobert Göhler
Update ssh.rst
2023-10-31T5699: vxlan: migrate "external" CLI know to "parameters external"Christian Breunig
2023-10-29Add "monitor log ssh" and "monitor log ssh dynamic-protection"JeffWDH
2023-10-28vxlan: T5668: add CLI knob to enable ARP/ND suppressionChristian Breunig
2023-10-28vxlan: add missing "parameters nolearning" helpChristian Breunig
2023-10-26Merge pull request #1126 from srividya0208/ipsec_vipsRobert Göhler
Added config example of vpn ipsec site-to-site
2023-10-26Added config example of vpn ipsec site-to-sitesrividya0208
2023-10-25Update nat44.rstRobert Göhler
change interface-name and interface-group
2023-10-25Revert "Revert "NAT: add interface-group documentation. ""Robert Göhler
2023-10-19Update ssh.rstJeffWDH
Added: show log ssh show log ssh dynamic-protection show ssh fingerprints show ssh fingerprints ascii show ssh dynamic-protection
2023-10-19Merge pull request #1119 from aslanvyos/patch-8Robert Göhler
Update dmvpn.rst
2023-10-19Merge pull request #1118 from aslanvyos/patch-7Robert Göhler
Update site2site_ipsec.rst
2023-10-18Fix two typos in Wireguard docVeli-Matti Helke
2023-10-18Update dmvpn.rstaslanvyos
When we put this command we got an error like: set interfaces tunnel tun100 local-ip '192.0.2.1' Configuration path: interfaces tunnel tun100 [local-ip] is not valid Set failed
2023-10-18Update site2site_ipsec.rstaslanvyos
To make easily understandable the Site-to-Site VPN ikev2 configuration for users (especially if the user is new to VyOS) made the following changes: - Added dummy interface to both routers for testing purposes - Added static route for both routers for dummy interface - Added this line of command: set vpn ipsec option disable-route-autoinstall Because when we write this line after the commit action we got an error like: WARNING: It's recommended to use ipsec vti with the next command - corrected this line: set vpn ipsec site-to-site peer OFFICE-B local-address '192.168.0.10' to this: set vpn ipsec site-to-site peer OFFICE-B local-address '172.18.201.10'
2023-10-17wireless: extend example with missing country-codeChristian Breunig
2023-10-12Revert "NAT: add interface-group documentation. "Robert Göhler
2023-10-11NAT: add interface-group documentation. Also add firewall rules for allowing ↵Nicolas Fort
destination nat connections.
2023-10-10Merge pull request #1107 from Dibins/patch-1Robert Göhler
Update wireguard.rst
2023-10-08T5630: pppoe: allow to specify MRU in addition to already configurable MTUChristian Breunig
2023-10-05Update wireguard.rstDibins
Adding proper syntax for 1.4 firewall commands
2023-10-02Second update dns.rstDibins
Based on the discussion here: https://forum.vyos.io/t/dynamic-dns-not-wollowing-web-options/12309 it seems necessary to note that setting the web-options on a given interface is not sufficient for determining the IP address when behind NAT. I've added some additional detail, which I think will make that more clear, as well as listed the commands as required to set up DDNS behind NAT. Further I updated the section on RFC2136 to accurately show address instead of interface
2023-10-02Update dns.rstShnoobins
Updated command syntax for dynamic dns - changed set service dns dynamic interface to set service dns dynamic address. Changed the login option from 'login' to 'username' Changed the web options from 'use-web' to 'web-options' Changed because I ran into the command syntax change on a 1.4 install. Updating documents to match.
2023-09-28Merge pull request #1101 from srividya0208/ikev2vpnRobert Göhler
Added details about ipsec remote-access
2023-09-28Added details about ipsec remote-accesssrividya0208
2023-09-26Merge pull request #1095 from aslanvyos/patch-2Robert Göhler
Update login.rst
2023-09-26Merge pull request #1088 from Nephiaust/2023-FirewallUpdatesRobert Göhler
Updates to the firewall pages
2023-09-22Update login.rstaslanvyos
RADIUS and TACACS configuration examples were added. Also mentioned if there is no connection between VyOS and RADIUS/TACACS servers users need to use local accounts for authentication.
2023-09-21Add firewal synproxyViacheslav Hletenko
2023-09-18Added new section about the different firewallsNephiaust
Updated labels for the pages Added new pictures. Signed-off-by: Nephiaust <29741794+Nephiaust@users.noreply.github.com>
2023-09-17Change ref firewall for int groups to be uniqueNephiaust
Signed-off-by: Nephiaust <29741794+Nephiaust@users.noreply.github.com>
2023-09-17Fixed bad formatting for code-blocksNephiaust
Signed-off-by: Nephiaust <29741794+Nephiaust@users.noreply.github.com>
2023-09-13Merge pull request #1063 from NickAnderegg/overview-nftables-translationRobert Göhler
quick-start: update firewall tutorials to reflect nftables-based firewall commands
2023-09-13vrf: add NAT exampleChristian Breunig
2023-09-13Merge pull request #1075 from dmbaturin/T5270-openvpn-peer-fingerprintJohn Estabrook
openvpn: Add peer fingerprint mode
2023-09-13openvpn: Add peer fingerprint modeDaniil Baturin
2023-09-12chore: fix formatting and add linter commentsNick Anderegg
2023-09-12quick-start: add notice about changes to firewall backendNick Anderegg
2023-09-11Merge pull request #1076 from nicolas-fort/Firewall_new_cli_updateRobert Göhler
Firewall refactor: add visible note in firewall docs:
2023-09-10T5518: Document `protocols pim6`Yuxiang Zhu
2023-09-09vxlan: T3700: support VLAN tunnel mapping of VLAN aware bridgesChristian Breunig
2023-09-08Firewall refactor: add visible note in firewall docs: zone, quick-start and ↵Nicolas Fort
config blueprint zone-policy
2023-09-04correction of ipsec compression syntax and added a referencesrividya0208
for changes done for zone based firewall
2023-08-26Merge pull request #1065 from giga1699/T5447Robert Göhler
MACsec: Document static key configuration
2023-08-26MACsec: Document static key configurationGiga Murphy
2023-08-25firewall: correction of default-action for rule-setsrividya0208
2023-08-23l3vpn : add label allocation mode documentationfett0
2023-08-19wifi: fix CLI nodes for country-code definitionChristian Breunig
2023-08-17T5409: add per-client-thread CLI option for wireguard and wireless interfacesChristian Breunig
2023-08-16l3vpn: T5338: fix review commentChristian Breunig