Age | Commit message (Collapse) | Author | |
---|---|---|---|
2022-05-28 | firewall: T970: Add firewall group domain-group | Viacheslav Hletenko | |
Domain group allows to filter addresses by domain main Resolved addresses as elements are stored to named "nft set" that used in the nftables rules Also added a dynamic "resolver" systemd daemon vyos-domain-group-resolve.service which starts python script for the domain-group addresses resolving by timeout 300 sec set firewall group domain-group DOMAINS address 'example.com' set firewall group domain-group DOMAINS address 'example.org' set firewall name FOO rule 10 action 'drop' set firewall name FOO rule 10 source group domain-group 'DOMAINS' set interfaces ethernet eth0 firewall local name 'FOO' nft list table ip filter table ip filter { set DOMAINS { type ipv4_addr flags interval elements = { 192.0.2.1, 192.0.2.85, 203.0.113.55, 203.0.113.58 } } chain NAME_FOO { ip saddr @DOMAINS counter packets 0 bytes 0 drop comment "FOO-10" counter packets 0 bytes 0 return comment "FOO default-action accept" } } | |||
2022-05-16 | Merge pull request #1290 from sever-sever/T4373 | Christian Poessinger | |
ppppoe-server: T4373: Add option multiplier for correct shaping | |||
2022-05-16 | pppoe-server: T4373: Add option multiplier for correct shaping | Viacheslav Hletenko | |
Multiplier option is required by some vendors for correct shaping For RADIUS based rate-limits edit service pppoe-server set authentication radius rate-limit multiplier '0.001' | |||
2022-05-13 | sshguard: T4408: rename whitelist-address -> allow-from | Christian Poessinger | |
We do not only allow individual host addresses but also prefixes. | |||
2022-05-12 | sshguard: T4408: Add service ssh dynamic-protection | Viacheslav Hletenko | |
Sshguard protects hosts from brute-force attacks Can inspect logs and block "bad" addresses by threshold Auto-generate rules for nftables When service stopped all generated rules are deleted nft "type filter hook input priority filter - 10" set service ssh dynamic-protection set service ssh dynamic-protection block-time 120 set service ssh dynamic-protection detect-time 1800 set service ssh dynamic-protection threshold 30 set service ssh dynamic-protection whitelist-address 192.0.2.1 | |||
2022-05-08 | container: T4000: use unique storage for container image | Christian Poessinger | |
Do no longer store container images which are pulled from any registry to /config/containers. Instead save them to a unified location that is the same accross all images on the system: /usr/lib/live/mount/persistence/container/storage Reason for this change is, while living under /config/containers a VyOS image upgrade copied all downloaded container images to the new image - doubling the used space per image on every upgrade. With the new location the images are all the same for every VyOS image running. Container userdata can still be stored under /config and copied to a newer image making rollbacks still efficient. | |||
2022-05-08 | container: T4353: fix conf-mode script name | Christian Poessinger | |
2022-05-08 | policy: evpn: T3739: support "set evpn gateway-ip" | Christian Poessinger | |
2022-05-06 | ipsec: T4353: use "" quotes on road-warrior id | Christian Poessinger | |
2022-05-05 | Merge pull request #1312 from sever-sever/T4410 | Christian Poessinger | |
monitoring: T4410: Add telegraf output Plugin http for Splunk | |||
2022-05-05 | policy: T4414: add support for route-map "as-path prepend last-as x" | Christian Poessinger | |
2022-05-05 | monitoring: T4410: Add telegraf output Plugin http for Splunk | Viacheslav Hletenko | |
Ability to send HTTP output to Splunk via telegraf set service monitoring telegraf splunk authentication insecure set service monitoring telegraf splunk authentication token 'xxx' set service monitoring telegraf splunk url 'https://x.x.x.x' | |||
2022-05-03 | monitoring: T4315: Add telegraf output plugin prometheus-client | Viacheslav Hletenko | |
Add output Plugin "prometheus-client" for telegraf: set service monitoring telegraf prometheus-client | |||
2022-05-02 | ipsec: T4353: bugfix template extension | Christian Poessinger | |
2022-05-02 | T2216: file is called container.py | Christian Poessinger | |
2022-05-01 | accel-ppp: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | http: api: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | system-logs: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | openconnect: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | syslog: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | igmp-proxy: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | pppoe: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | nhrp: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | firewall: zone: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | lcd: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | vrrp: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | firewall: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | system-options: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | ids: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | router-advert: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | mdns-repeater: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | ipsec: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | vrf: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | login: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | telegraf: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | serial-console: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | webproxy: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | flow-accounting: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | snmp: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | lldp: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | tftp-server: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | container: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | conserver: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | conntrackd: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | conntrack: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-05-01 | bcast-relay: T4353: fix Jinja2 linting errors | Christian Poessinger | |
2022-04-30 | vyos-configd: enable firewall support | Christian Poessinger | |
2022-04-29 | T2216: containers need to be added via "add container image" in advance ↵ | Christian Poessinger | |
before using them | |||
2022-04-28 | configd: eanble other missed out services | Christian Poessinger | |
2022-04-28 | system-proxy: T1741: migrate to get_config_dict() | Christian Poessinger | |