Age | Commit message (Collapse) | Author | |
---|---|---|---|
2024-08-23 | sysctl: T3204: restore sysctl setttings overwritten by tunedmergify/bp/circinus/pr-3945 | Christian Breunig | |
(cherry picked from commit 8500e8658ff10f52739143fd7814cf60c9195f16) | |||
2024-08-16 | T6649: Accel-ppp separate vlan-mon from listen interfacesmergify/bp/circinus/pr-3987 | Nataliia Solomko | |
(cherry picked from commit 663e468de2b431f771534b4e3a2d00a5924b98fe) | |||
2024-08-05 | OPENVPN: T6555: fix name to bridge | fett0 | |
(cherry picked from commit d5ae708581d453e2205ad4cf8576503f42e262b6) | |||
2024-08-05 | OPENVPN: T6555: add server-bridge options in mode server | fett0 | |
(cherry picked from commit 4acad3eb8d9be173b76fecafc32b0c70eae9b192) | |||
2024-08-02 | T6619: Remove the remaining uses of per-protocol FRR configs (#3916)mergify/bp/circinus/pr-3916 | Roman Khramshin | |
(cherry picked from commit f2256ad338fc3fbaa9a5de2c0615603cd23e0f94) | |||
2024-08-01 | T6617: T6618: vpn ipsec remote-access: fix profile generatorsmergify/bp/circinus/pr-3903 | Lucas Christian | |
(cherry picked from commit e97d86e619e134f4dfda06efb7df4a3296d17b95) | |||
2024-07-25 | system_option: T5552: Apply IPv4 and IPv6 options after reapplying sysctls ↵ | mergify[bot] | |
by TuneD (#3863) (cherry picked from commit 7b82e4005724683c6311fab22358746f2cca4c1b) Co-authored-by: Nataliia Solomko <natalirs1985@gmail.com> | |||
2024-07-23 | SSTP-server: add missed pppd_compat modulemergify/bp/circinus/pr-3832 | Viacheslav Hletenko | |
(cherry picked from commit 8c8054ad5410e8aedf6ab7a0702b317872d4fd41) | |||
2024-07-23 | PPTP-server: add missed pppd_compat module | Viacheslav Hletenko | |
(cherry picked from commit 440a3e6b89748bfd861f580fc8c4f41b58c6cec2) | |||
2024-07-23 | L2TP-server: add missed pppd_compat module | Viacheslav Hletenko | |
(cherry picked from commit ef50cd9954a2d6eb2a041c26a0bb8ea0758b1f17) | |||
2024-07-23 | IPoE-server: add missed pppd_compat module | Viacheslav Hletenko | |
(cherry picked from commit b92bc209cc1d6ed54a5fa052e0c27c54488ae955) | |||
2024-07-22 | wireless: T6320: add 802.11ax at 6GHz | Alain Lamar | |
Authored-By: Alain Lamar <alain_lamar@yahoo.de> (cherry picked from commit d5e988ba2d0fa0189feff22374c9b46eb49e2e79) | |||
2024-07-22 | wireless: T6425: Fix broken VHT beamforming | Alain Lamar | |
(cherry picked from commit f75f0f9c94472f46e056808c3ac6aba809c090f0) | |||
2024-07-22 | T6599: ipsec: support disabling rekey of CHILD_SA. | Lucas Christian | |
Also adds support for life_bytes, life_packets, and DPD for remote-access connections. Changes behavior of remote-access esp-group lifetime setting to have parity with site-to-site connections. (cherry picked from commit fd5d7ff0b4fd69b248ecb29c6ec1f3cf844c41cf) | |||
2024-07-03 | Merge pull request #3758 from vyos/mergify/bp/circinus/pr-3721 | Christian Breunig | |
ssh: T5878: Allow changing the PubkeyAcceptedAlgorithms option (backport #3721) | |||
2024-07-03 | syslog: T5366: remove reference to deprecated sysvinit rsyslog script | John Estabrook | |
(cherry picked from commit 977d2fbf7a62a97d98b38cf28e62f08fc9e8d3a2) | |||
2024-07-03 | ssh: T5878: Allow changing the PubkeyAcceptedAlgorithms option | khramshinr | |
(cherry picked from commit 06e6e011cdf12e8d10cf1f6d4d848fd5db51720d) | |||
2024-07-02 | T6523: Telegraf use nft scripts only if the firewall configured | Viacheslav Hletenko | |
If a firewall is not configured there is no reason to get and execute telegraf firewall custom scripts as there are no nft chain in the firewall nftables configuration (cherry picked from commit ebff0c481907ac0c2c0be9981c3c3d87caf3003b) | |||
2024-06-28 | T6477: Add telegraf loki output plugin | Viacheslav Hletenko | |
Add Loki plugin to telegraf set service monitoring telegraf loki url xxx (cherry picked from commit 3365eb7ab99fa9a259fe440eb51e82fc0a0a4dc6) | |||
2024-06-26 | Merge pull request #3723 from sever-sever/T751 | Daniil Baturin | |
T751: Remove ids suricata | |||
2024-06-25 | Merge pull request #3716 from vyos/mergify/bp/circinus/pr-3694 | Daniil Baturin | |
snmp: T6489: use new Python wrapper to interact with config filesystem (backport #3694) | |||
2024-06-24 | login: T6489: add smarter way to interact with the working config instead of ↵ | Christian Breunig | |
my_set/my_delete (cherry picked from commit da29c9b3ab7b0cc23d64c8b033fc5a79c1b09174) | |||
2024-06-24 | snmp: T6489: use new Python wrapper to interact with config filesystem | Christian Breunig | |
Do no longer use my_set and my_delete as this prevents scripts beeing run under supervision of vyos-configd. (cherry picked from commit 7e0e8101998a6c8de6cb93c42bfbf1278c13f226) | |||
2024-06-22 | T5949: Add option to disable USB autosuspend | khramshinr | |
(cherry picked from commit c0b2693cebc3429e1974a9cec5946fa88ffc0205) | |||
2024-06-12 | op_mode: T6227: Rewrite show conntrack-sync cache internal to use tabulate ↵ | Nataliia Solomko | |
output | |||
2024-06-10 | T751: Remove ids suricata | Viacheslav Hletenko | |
2024-06-10 | Merge pull request #3610 from c-po/ipsec-profile-T6424 | Christian Breunig | |
op-mode: T6424: ipsec: honor certificate CN and CA chain during profile generation | |||
2024-06-10 | Merge pull request #3612 from c-po/haproxy-pki-T6463 | Christian Breunig | |
pki: T6463: reverse-proxy service not reloaded when updating SSL certificate(s) | |||
2024-06-09 | op-mode: T6424: ipsec: honor certificate CN and CA chain during profile ↵ | Christian Breunig | |
generation In e6fe6e50a5c ("op-mode: ipsec: T6407: fix profile generation") we fixed support for multiple CAs when dealing with the generation of Apple IOS profiles. This commit extends support to properly include the common name of the server certificate issuer and all it's paren't CAs. A list of parent CAs is automatically generated from the "PKI" subsystem content and embedded into the resulting profile. | |||
2024-06-09 | pki: T6464: sstpc interface not reloaded when updating SSL certificate(s) | Christian Breunig | |
The SSTPC client was not reloaded/restarted with the new SSL certificate(s) after a change in the PKI subsystem. This was due to missing dependencies. | |||
2024-06-09 | pki: T6463: reverse-proxy service not reloaded when updating SSL certificate(s) | Christian Breunig | |
The haproxy reverse proxy was not reloaded/restarted with the new SSL certificate(s) after a change in the PKI subsystem. This was due to missing dependencies. | |||
2024-06-07 | reverse-proxy: T6454: Set default value of http for haproxy mode | Alex W | |
2024-06-06 | Merge pull request #3578 from nicolas-fort/raw-hook | Daniil Baturin | |
T3900: Add support for raw tables in firewall | |||
2024-06-05 | migration: T6006: update config.boot.default and move to vyos-1x | John Estabrook | |
2024-06-05 | Merge pull request #3584 from dmbaturin/T6446-display-support-url | Daniil Baturin | |
show version: T6446: display the support URL for LTS builds | |||
2024-06-05 | Merge pull request #3571 from fett0/T6429 | Daniil Baturin | |
isis: T6429: fix isis metric-style configuration missing | |||
2024-06-05 | show version: T6446: display the support URL for LTS builds | Daniil Baturin | |
2024-06-04 | T3900: T6394: extend functionalities in firewall; move netfilter sysctl ↵ | Nicolas Fort | |
timeout parameters defined in conntrack to firewall global-opton section. | |||
2024-06-03 | reverse-proxy: T6434: Support additional healthcheck options (#3574) | Alex W | |
2024-05-31 | isis: T6429: fix isis metric-style configuration missing | fett0 | |
2024-05-30 | Merge pull request #3510 from HollyGurza/T4576 | Daniil Baturin | |
T4576: Accel-ppp logging level configuration | |||
2024-05-30 | Merge pull request #3552 from c-po/ipsec-profile | Christian Breunig | |
op-mode: ipsec: T6407: fix profile generation | |||
2024-05-30 | Merge pull request #3546 from c-po/haproxy | Christian Breunig | |
reverse-proxy: T6419: build full CA chain when verifying backend server | |||
2024-05-30 | op-mode: ipsec: T6407: fix profile generation | Christian Breunig | |
Commit 952b1656f51 ("ipsec: T5606: T5871: Use multi node for CA certificates") added support for multiple CA certificates which broke the OP mode command to generate the IPSec profiles as it did not expect a list and was rather working on a string. Now multiple CAs can be rendered into the Apple IOS profile. | |||
2024-05-29 | reverse-proxy: T5231: better mark v4v6 listen any address | Christian Breunig | |
haproxy supports both ":::80 v4v6" and "[::]:80 v4v6" as listen statement, where the later one is more humand readable. Both act in the same way. | |||
2024-05-29 | ISIS: T6332: Fix isis not working only ipv6 | fett0 | |
2024-05-27 | T4576: Accel-ppp logging level configuration | khramshinr | |
add ability to change logging level config for: * VPN L2TP * VPN PPTP * VPN SSTP * IPoE Server * PPPoE Serve | |||
2024-05-23 | Merge pull request #3399 from 0xThiebaut/suricata | Christian Breunig | |
suricata: T751: Initial support for suricata | |||
2024-05-23 | suricata: T751: use key_mangling in get_config_dict() | Christian Breunig | |
2024-05-21 | reverse-proxy: T6370: Set custom HTTP headers in reverse-proxy responses | Alex W | |