Age | Commit message (Collapse) | Author | |
---|---|---|---|
2022-05-25 | configtest: T4382: system@20 cannot have 'user level' (16-to-17) | John Estabrook | |
The config file isis-small has system@20, but 'user level' which was migrated in system/16-to-17; remove the line in the config, as there is no problem with the migration script in question. | |||
2022-05-25 | configtest: T4382: remove typo | John Estabrook | |
This is a typo in vrf-ospf: 'system nt' on the line before 'system ntp'. | |||
2022-05-25 | configtest: T4382: bgp migration scripts need to follow quagga scripts | John Estabrook | |
The configs bgp_bfd_communities and bgp_big_as_cloud reveal a counterexample to the independence of component migration scripts: quagga migration scripts must precede those of bgp; explicitly reorder from lexical order. | |||
2022-05-25 | configtest: T4382: fix missing delete of 'ipsec-interfaces' node | John Estabrook | |
Migration of bgp-azure-ipsec-gateway and bgp_dmvpn_hub reveals that migration script ipsec/5-to-6 leaves the empty node 'ipsec-interfaces' after moving the interface; fix the migration script, as it is not yet in 1.3. | |||
2022-05-25 | Merge pull request #1319 from goodNETnick/ocserv_sh_otp_key | Viacheslav Hletenko | |
ocserv: T4420: show configured 2FA OTP key | |||
2022-05-25 | Merge pull request #1088 from zdc/T4020-sagitta | Daniil Baturin | |
FRR: T4020: Added CLI options for FRR daemons | |||
2022-05-21 | smoketest: flow-accounting: T4437: adjust smoketest to new generated config ↵ | Christian Poessinger | |
syntax | |||
2022-05-21 | flow-accounting: T4099: "source-address" must exist locally | Christian Poessinger | |
2022-05-21 | xml: flow-accounting: T4437: fix node help | Christian Poessinger | |
2022-05-21 | xml: nhrp: fix CLI description | Christian Poessinger | |
2022-05-21 | nhrp: T4353: use ".service" suffix on systemd name | Christian Poessinger | |
2022-05-21 | op-mode: T4390: add nhrp and flow-accounting logging | Christian Poessinger | |
2022-05-21 | flow-accounting: T4437: also install rule to IPv6 VYOS_CT_PREROUTING_HOOK | Christian Poessinger | |
2022-05-21 | flow-accounting: T4437: bugfix IPv6 flow collector address | Christian Poessinger | |
2022-05-20 | Merge pull request #1317 from sever-sever/T4418 | Christian Poessinger | |
monitoring: T4418: Add output plugin azure-data-explorer | |||
2022-05-20 | monitoring: T4418: Add output plugin azure-data-explorer | Viacheslav Hletenko | |
Add output telegraf Plugin Azure Data Explorer set service monitoring telegraf azure-data-explorer authentication client-id 'x' set service monitoring telegraf azure-data-explorer authentication client-secret 'x' set service monitoring telegraf azure-data-explorer authentication tenant-id 'x' set service monitoring telegraf azure-data-explorer database 'x' set service monitoring telegraf azure-data-explorer group-metrics 'single-table' set service monitoring telegraf azure-data-explorer url 'http://localhost.loc' | |||
2022-05-19 | ipsec: T2816: add completion help for IP addresses to local-address node | Christian Poessinger | |
2022-05-19 | dmvpn: nhrp: T4434: secret length can not exceed 8 characters | Christian Poessinger | |
2022-05-19 | Merge pull request #1329 from dmbaturin/T4432 | John Estabrook | |
T4432: display load averages normalized for the number of CPU cores | |||
2022-05-19 | T4432: display load averages normalized for the number of CPU cores | Daniil Baturin | |
2022-05-16 | Merge pull request #1290 from sever-sever/T4373 | Christian Poessinger | |
ppppoe-server: T4373: Add option multiplier for correct shaping | |||
2022-05-16 | pppoe-server: T4373: Add option multiplier for correct shaping | Viacheslav Hletenko | |
Multiplier option is required by some vendors for correct shaping For RADIUS based rate-limits edit service pppoe-server set authentication radius rate-limit multiplier '0.001' | |||
2022-05-16 | ocserv: T4420: show configured 2FA OTP key | goodNETnick | |
2022-05-13 | smoketest: add sshguard allow-from case | Christian Poessinger | |
2022-05-13 | sshguard: T4408: rename whitelist-address -> allow-from | Christian Poessinger | |
We do not only allow individual host addresses but also prefixes. | |||
2022-05-13 | Debian: T4408: add missing sshguard dependency | Christian Poessinger | |
2022-05-13 | Merge pull request #1320 from sever-sever/T4408 | Christian Poessinger | |
sshguard: T4408: Add service ssh dynamic-protection | |||
2022-05-12 | sshguard: T4408: Add service ssh dynamic-protection | Viacheslav Hletenko | |
Sshguard protects hosts from brute-force attacks Can inspect logs and block "bad" addresses by threshold Auto-generate rules for nftables When service stopped all generated rules are deleted nft "type filter hook input priority filter - 10" set service ssh dynamic-protection set service ssh dynamic-protection block-time 120 set service ssh dynamic-protection detect-time 1800 set service ssh dynamic-protection threshold 30 set service ssh dynamic-protection whitelist-address 192.0.2.1 | |||
2022-05-12 | vrrp: T4417: bugfix service startup priority | Christian Poessinger | |
2022-05-12 | conntrack: T3535: use "reload-or-restart" from systemd | Christian Poessinger | |
2022-05-12 | vrrp: T3944: use "reload-or-restart" over individual code paths | Christian Poessinger | |
systemd has its internal reload or restart logic - we do not need to programm it on our own. | |||
2022-05-12 | container: T2216: use warning over exception when container image does not exist | Christian Poessinger | |
2022-05-12 | Merge pull request #1323 from sever-sever/T4399 | Christian Poessinger | |
Revert "NHRP : T4399: fix issues restart nhrp when add or del tunnel" | |||
2022-05-12 | Merge pull request #1325 from sever-sever/T4424 | Christian Poessinger | |
policy: T4424: Fix incorrect format for IPv6 prefixes | |||
2022-05-12 | policy: T4424: Fix incorrect format for IPv6 prefixes | Viacheslav Hletenko | |
2022-05-12 | Revert "NHRP : T4399: fix issues restart nhrp when add or del tunnel" | Viacheslav Hletenko | |
This reverts commit d1455f936ca721633fcc04d5c84169b4ccf2f447. New spokes can't register on hub with 'reload-or-restart' option And requires option 'restart' for opennhrp.service | |||
2022-05-11 | Merge pull request #1321 from sever-sever/T4405 | Christian Poessinger | |
T4405: Fix administrative distance of DHCP routes | |||
2022-05-10 | T4405: Fix administrative distance of DHCP routes | Dmitri Toubelis | |
- Default dhclient script only uses value of `$IF_MERIC` envvar for default route recived via `router` option. - This variable has no effect on rotes received via `rfc3442-classless-static-routes` option - Considering that Vyos overrrides `ip` command originating from `dhclient` this can be easily fixed in `iptovtysh()` function by using the `$IF_METRIC` envvar directly in the dhclient hook. (cherry picked from commit 0c00e7bf8b6e68814607fde4ff0cd70ce9f4b486) | |||
2022-05-09 | Merge pull request #1279 from nicolas-fort/T990 | Christian Poessinger | |
Firewall: T990: Add snat and dnat connection status on firewall | |||
2022-05-08 | container: T4000: use unique storage for container image | Christian Poessinger | |
Do no longer store container images which are pulled from any registry to /config/containers. Instead save them to a unified location that is the same accross all images on the system: /usr/lib/live/mount/persistence/container/storage Reason for this change is, while living under /config/containers a VyOS image upgrade copied all downloaded container images to the new image - doubling the used space per image on every upgrade. With the new location the images are all the same for every VyOS image running. Container userdata can still be stored under /config and copied to a newer image making rollbacks still efficient. | |||
2022-05-08 | container: op-mode: T3852: use XML inline podman commands | Christian Poessinger | |
Reduce bloat of containers_op.py wrapper script. All commands can be passed directly to podman via the XML script. This also makes the execution faster, as no Python environment needs to be build up. | |||
2022-05-08 | container: T4353: fix conf-mode script name | Christian Poessinger | |
2022-05-08 | smoketest: policy-route: use setUpClass() | Christian Poessinger | |
2022-05-08 | policy: evpn: T3739: support "set evpn gateway-ip" | Christian Poessinger | |
2022-05-07 | vrf: T4419: support to disable IP forwarding within a given VRF | Christian Poessinger | |
2022-05-06 | ocserv: T4231: XML OTP support must not be added globally - only for openconnect | Christian Poessinger | |
2022-05-06 | ipsec: T4353: use "" quotes on road-warrior id | Christian Poessinger | |
2022-05-06 | bgp: T4385: verify() peer-group in interface based neighbors | Christian Poessinger | |
2022-05-06 | Merge pull request #1316 from srividya0208/T4381 | Christian Poessinger | |
openvpn: T4381: Add tunnel ip column for status command | |||
2022-05-06 | openvpn: T4381: Add tunnel ip column for status command | srividya0208 | |
Added the tunnel ip column to see the assigned ip address in server mode |