| Age | Commit message (Collapse) | Author |
|
|
|
* Move core logic to separate vyos.geoip module
* Use a sqlite database for storing and querying address ranges by country
* Remove downloaded geoip ranges once loaded into sqlite db
* No longer rebuild geoip sets on each commit unless necessary
* Allows for extensibility using other geoip data vendors
|
|
|
|
ssh: T7483: Add fido2 PubkeyAuthOptions
|
|
T8187: fix watchdog timeout validation if kernel min/max timeout are zero
|
|
T8156: T8157: T8164: update commit hash for completion and other fixes
|
|
|
|
|
|
|
|
T7101: Add hardware watchdog support via systemd
|
|
openvpn: T7633: Add support for `data-ciphers-fallback` in site-to-site tunnels
|
|
|
|
|
|
T8171: Make vyos-smoketest more user-friendly
|
|
vrf: T8169: prevent deletion if instance referenced in policy based routing
|
|
T7876: VPP increase dpdk-options num-rx-desc to 16384
|
|
T8170: VPP fix IPFIX op-mode commands if VPP is not configured
|
|
In FRR 10.5 ip protocols
* connected
* kernel
* local
* table
* table-direct
are removed. First three in fb8e399e4f66d09780f176fbecb99168089e64eb,
table* in 7fd030504be060387694e8a2af7f19ddd7dee39d.
In `ip protocols`, `ipv6 protocols` and `vrf` VyOS supports
* connected
* kernel
* table
Remove these from CLI, add migration scripts, update tests.
|
|
* Output progress before each test
* On finish, output list of failed tests if there were any.
* Otuput "TIMEOUT" as result of test if it hanged
|
|
Some NICs as `AWS ENA VF` allow to use 16384 descriptors
|
|
Fix the VPP op-mode commands traceback errror for the IPFIX feature
if VPP is not configured
|
|
- Introduced new CLI option 'data-ciphers-fallback' for OpenVPN interfaces
(used as fallback cipher in site-to-site mode)
- Adjust migration 1‑to‑2 to skip migrating 'cipher' for site‑to‑site interfaces
|
|
isis: T8158: fix lsp-timers
|
|
Check if the VRF which is about to be removed is referenced in any PBR rule,
where any is one or more of route, route6, local-route or local-route6.
|
|
T8144: fix and correct TPM and VPP test result reporting in smoke test workflow
|
|
T8046: traffic-engineering: support link-params
|
|
There are three configuration values in VyOS isis XML:
* lsp-gen-interval
* lsp-refresh-interval
* max-lsp-lifetime
In FRR they have the following restrictions in yang model:
* refresh-interval, default 900
* maximum-lifetime >= refresh-interval + 300 (350-65535), default 1200
* generation-interval < refresh-interval (1..120), default 30
When setting these values in separate steps we can get error e.g.:
libyang: Must condition ". >= ../refresh-interval + 300" not satisfied.
even when all restrictions are satisfied.
To fix the issue:
1. Write default values in our XML.
2. Check these restrictions in protocol_isis.py
3. Use FRR command `lsp-timers` that sets all these values in one go
|
|
Add 'traffic-engineering' commands under 'protocols'.
set protocols traffic-engineering admin-group ADMINGROUP bit-position 1
set protocols traffic-engineering interface INTERFACE admin-group ADMINGROUP
set protocols traffic-engineering interface INTERFACE max-bandwidth 1280
set protocols traffic-engineering interface INTERFACE max-reservable-bandwidth 1280
Also add
set protocols isis traffic-engineering export
|
|
|
|
ipsec: T8022: Fix invalid automatic `dynamic` prefix assignment for transport mode tunnels
|
|
T7098: Fix VPP MTU misconfiguration
|
|
|
|
T8146: Confirm the key when config encryption is configured without TPM
|
|
T8153: PPPoE IPv6 autoconf: no Router Solicitation sent and default IPv6 route not installed after successful dial-up
|
|
Co-authored-by: Christian Breunig <christian@breunig.cc>
|
|
ethernet: T8142: do not raise ValueError for non-existing interfaces
|
|
|
|
T7635: OpenConnect Certificate Authentication
|
|
T8145: LUKS Encryption Passphrase Observable
|
|
router-advert: T8140: add captive portal support (RFC 8910)
|
|
nat66: T8139: add support for NAT66 source groups
|
|
transport mode tunnels
When ESP was configured in transport mode for GRE-based site-to-site tunnels,
the default value `dynamic` was automatically injected into the configuration,
even though prefixes must not be set in transport mode. This led to error
"Local/remote prefix cannot be used with ESP transport mode" and commit failures.
This fix updates configuration logic to skip default prefix assignment
for site-to-site peers using ESP transport mode tunnels.
|
|
Call verify_interface_exists() with state_required=True to ensure the interface
exists physically and is recognized by the kernel, rather than relying on its
presence in the CLI configuration. Unlike bridge or bond interfaces, Ethernet
interfaces are not virtual and must be physically present.
Ethtool() instance can only be created when the physical interface exists,
otherwise a ValueError is raised.
|
|
|
|
|
|
T8138: add nat66 as dependent of firewall groups
|
|
T8144: Updated trigger-rebuild-repo-package workflow for pull_request_target policy change
|
|
policy change
|
|
Add support for captive portal identification in IPv6 router adverts as
defined in RFC 8910. The value is a quoted URL pointing to an RFC
8908-compliant API endpoint.
|
|
Copy the support for NAT66 destination groups (commit f96733dd and
commit 43554efc) over to NAT66 source groups as well.
Change the existing smoketest for NAT66 groups to also cover a source
group use-case example.
|