social.tchncs.de is one of the many independent Mastodon servers you can use to participate in the fediverse.
A friendly server from Germany – which tends to attract techy people, but welcomes everybody. This is one of the oldest Mastodon instances.

Administered by:

Server stats:

3.7K
active users

#vyos

0 posts0 participants0 posts today
LibreQoS<p>Great to see this nice farewell to our beloved <span class="h-card" translate="no"><a href="https://bird.makeup/users/mtaht" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>mtaht</span></a></span> at <span class="h-card" translate="no"><a href="https://vyos.social/users/news" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>news</span></a></span> forum:</p><p><a href="https://forum.vyos.io/t/farewell-dave-taht/16379" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">forum.vyos.io/t/farewell-dave-</span><span class="invisible">taht/16379</span></a></p><p><a href="https://fosstodon.org/tags/DaveTaht" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DaveTaht</span></a> <a href="https://fosstodon.org/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> <a href="https://fosstodon.org/tags/RFC8290" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RFC8290</span></a> <a href="https://fosstodon.org/tags/BandwidthIsALIE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BandwidthIsALIE</span></a> <a href="https://fosstodon.org/tags/FQ_CoDel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FQ_CoDel</span></a> <a href="https://fosstodon.org/tags/sch_CAKE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sch_CAKE</span></a> <a href="https://fosstodon.org/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> <a href="https://fosstodon.org/tags/OpenSource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSource</span></a> <a href="https://fosstodon.org/tags/FLOSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FLOSS</span></a> <a href="https://fosstodon.org/tags/bufferbloat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bufferbloat</span></a> <a href="https://fosstodon.org/tags/latency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>latency</span></a> <a href="https://fosstodon.org/tags/jitter" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>jitter</span></a> <a href="https://fosstodon.org/tags/LibreQoS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LibreQoS</span></a> <a href="https://fosstodon.org/tags/schCAKE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>schCAKE</span></a> <a href="https://fosstodon.org/tags/FQCoDel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FQCoDel</span></a> <a href="https://fosstodon.org/tags/WiFi" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WiFi</span></a> <a href="https://fosstodon.org/tags/router" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>router</span></a></p>
Salearlyman<p>Hey fellow sysadmin cosplay nerds, does anyone here use VyOS? I use VyOS as the main router for my home network and I just found out that a job for uploading backups to an off-site location is strangling my upstream bandwidth.</p><p>I want to create a QOS / traffic shaping policy to treat this as bulk traffic - take up as much bandwidth as available but give priority to all other traffic.</p><p>Is there a simple way to do this? I don't want to allocate a fixed bandwidth for it.</p><p><a href="https://cloudisland.nz/tags/HomeLab" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HomeLab</span></a> <a href="https://cloudisland.nz/tags/vyos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vyos</span></a> <a href="https://cloudisland.nz/tags/sysadmin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sysadmin</span></a></p>
Junicast<p>I think I might actually migrate my <a href="https://chaos.social/tags/firewall" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>firewall</span></a> to <a href="https://chaos.social/tags/vyos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vyos</span></a>. Just the fact that I can easily deploy <a href="https://chaos.social/tags/podman" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>podman</span></a> <a href="https://chaos.social/tags/container" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>container</span></a> onto my firewall this is also possible with <a href="https://chaos.social/tags/OpenWrt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenWrt</span></a> but sadly it's a bit hacky as their partitioning is ephemeral in it's nature.<br>I'm still struggling a bit with managing core functionalities like firewalling but I will manage. Why isn't there already a GUI? Isn't their API supposed to be ready to use idk?<br>Solutions like <a href="https://chaos.social/tags/pfSense" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pfSense</span></a> or <a href="https://chaos.social/tags/OPNsense" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OPNsense</span></a> are just a bit too inflexible for me.</p>
Junicast<p>After a couple of years of abstence I have to try <a href="https://chaos.social/tags/vyos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vyos</span></a> once again. I have been also trying to go back to <a href="https://chaos.social/tags/opnsense" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opnsense</span></a> lately but it seems I like <a href="https://chaos.social/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a> based firewalls better, even though somehow <a href="https://chaos.social/tags/BSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BSD</span></a>'s <a href="https://chaos.social/tags/pf" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pf</span></a> is really good.</p>
Daniil Baturin<p>I'm pretty sure there will be stink about an evil multi-billion corporation sending DMCA takedowns now, but for the record, <a href="https://github.com/umlumpa/vyos-1x" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com/umlumpa/vyos-1x</span><span class="invisible"></span></a> was taken down because the owner of that account proceeded to _remove GPL license headers_ from all files and went as far as to replace my name in "this package was debianized by Daniil Baturin in 20xx" with his own name but the original date.</p><p>If that's how you honor FOSS licenses, that's how we respond — no hard feelings, folks.</p><p><a href="https://functional.cafe/tags/vyos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vyos</span></a></p>
Scott Laird<p>Feeling okay about progress on my <a href="https://hachyderm.io/tags/golang" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>golang</span></a> <a href="https://hachyderm.io/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> config handling code. It can read and write all 3 forms of config (`show`, `set`, and the on-disk boot format), and I have a demo WASM app with a text area that I can paste `show` configs into and get them auto-converted to `set` configs.</p><p>The next step is to bundle up a couple sample configs and add a template interface where you can specify which interfaces have LAN, WAN, etc, and what your IP address ranges look like. Then it'll auto-create a config for you.</p><p>Yeah, this is doable without a full parser or WASM, but it's not a bad exercise. Plus this is inherently flexible in ways that strict text templating systems aren't.</p>
Scott Laird<p>Today's "fun" side project: working on a <a href="https://hachyderm.io/tags/golang" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>golang</span></a> library for parsing <a href="https://hachyderm.io/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> router configs. </p><p>VyOS"s config is Juniper-like, rather than IOS-like, which I like. However, like Junos, that means that it has (at least) 2 different formats: the block-structured `show configuration` output and the `set` format (`show | display set` in Junos, `show | commands` in VyOS) that can actually be pasted into a device.</p><p>Right now, I can parse VyOS's block-structured configs into an AST and then dump the AST as `set` commands. The goal is to be able to parse and write all 3 of VyOS's config formats (its boot config format is *just* different enough to need its own code), to allow conversion between formats. The end goal is to be able to throw together a web app generating templatized starter configs that can convert between formats trivially.</p><p>The other goal is to get some practice with Go generics and probably WASM.</p>
Scott Laird<p>You know, <a href="https://hachyderm.io/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> really doesn't seem happy when you try to add 65,536 static routes to its config. Sorta slow.</p>
Alex<p>Also, while my previous choice <a href="https://swiss.social/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> was "okay", their update lifecycle and buggy config migrations leave no second guesses of moving away.<br><a href="https://swiss.social/tags/pfSense" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pfSense</span></a> and <a href="https://swiss.social/tags/OPNsense" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OPNsense</span></a> are fine for basic functionality but in my experience are too buggy as well.<br>And I cannot just fix those, my playbook I can. 😁<br><a href="https://swiss.social/tags/homelab" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>homelab</span></a> <a href="https://swiss.social/tags/network" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>network</span></a></p>
Marek<p>VyOS is unfortunately becoming more and more isolated. They now even have an EULA - doesn't that contradict the GNU GPL?<br>I can understand the commercial interests behind it, but I think it's a shame.</p><p><a href="https://forum.vyos.io/t/doesnt-the-eula-contradict-the-gnu-gpl-is-vyos-stream-publicly-available/15756" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">forum.vyos.io/t/doesnt-the-eul</span><span class="invisible">a-contradict-the-gnu-gpl-is-vyos-stream-publicly-available/15756</span></a></p><p><a href="https://blog.vyos.io/vyos-1.4.1-release" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.vyos.io/vyos-1.4.1-releas</span><span class="invisible">e</span></a></p><p><a href="https://layer8.space/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> <a href="https://layer8.space/tags/BGP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BGP</span></a> <a href="https://layer8.space/tags/FLOSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FLOSS</span></a> <a href="https://layer8.space/tags/OpenSource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSource</span></a> <a href="https://layer8.space/tags/FreeSoftware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FreeSoftware</span></a></p>
AliveDevil<p><a href="https://tauri.earth/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> PSA: If you have Accept_ANY rules in Zone-based firewall, don't</p><p># set firewall global-options state-policy invalid action drop</p><p>This will just shortcut drop all new packets, sometimes.</p><p><a href="https://tauri.earth/tags/Router" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Router</span></a> <a href="https://tauri.earth/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a></p>
AliveDevil<p>This configuration looks neat.<br>Missing are just the migration from the second IKEv2 TCP reverse proxy VPN to this router as well.</p><p><a href="https://tauri.earth/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> <a href="https://tauri.earth/tags/Firewall" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Firewall</span></a> <a href="https://tauri.earth/tags/VPN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VPN</span></a> <a href="https://tauri.earth/tags/Wireguard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Wireguard</span></a></p>
AliveDevil<p>So … <a href="https://tauri.earth/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> people. What's your solution for monitoring link stability?<br>E.g. latency, ICMP drops, etc.</p><p><a href="https://tauri.earth/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> <a href="https://tauri.earth/tags/Router" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Router</span></a> <a href="https://tauri.earth/tags/HomeLab" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HomeLab</span></a> <a href="https://tauri.earth/tags/SelfHosting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SelfHosting</span></a></p>
AliveDevil<p>That urge to build a client app to configure <a href="https://tauri.earth/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a>.</p><p><a href="https://tauri.earth/tags/Avalonia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Avalonia</span></a> <a href="https://tauri.earth/tags/Desktop" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Desktop</span></a> <a href="https://tauri.earth/tags/CSharp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CSharp</span></a></p>
AliveDevil<p>Someone here who wants to translate <a href="https://tauri.earth/tags/OpenWRT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenWRT</span></a> firewall rules to <a href="https://tauri.earth/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> firewall rules?</p>
AliveDevil<p>Building <a href="https://tauri.earth/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> 1.4 for arm64, because Cloudflare.</p>
ItzTrain<p>I got tired of fussing with <a href="https://hachyderm.io/tags/FRR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FRR</span></a> and trying to use it to do VRF's and routing as it really is geared towards Dynamic Routing! Back to <a href="https://hachyderm.io/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> for the <a href="https://hachyderm.io/tags/homelab" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>homelab</span></a>. I am still using VRRP with 3 FFA routers on my <a href="https://hachyderm.io/tags/incus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>incus</span></a> hosts. So as long as my upstream router is up. I can reboot hosts all day long and no internet go down.</p><p><a href="https://hachyderm.io/tags/selfhosted" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>selfhosted</span></a> <a href="https://hachyderm.io/tags/selfhosting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>selfhosting</span></a></p>
Paul<p>The <a href="https://social.pfzetto.de/tags/Vyos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vyos</span></a> firewall currently doesn't support SIIT-DC (Stateless IP/ICMP Translation for IPv6 Data Center Environments). Luckily there is a workaround to configure it anyway: <a href="https://pfzetto.de/blog/siit-dc-for-vyos" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">pfzetto.de/blog/siit-dc-for-vy</span><span class="invisible">os</span></a><br><a href="https://social.pfzetto.de/tags/networking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>networking</span></a> <a href="https://social.pfzetto.de/tags/ipv6" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ipv6</span></a></p>
Marek<p>VyOS 1.5 is somehow broken for me: Babel does not work at all (not even with the example from the documentation) and with BGP you cannot set a source address for installed routes (possible with route-map set src, but has no effect).</p><p>The rolling release seems to be enormously rolling.</p><p><a href="https://layer8.space/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> <a href="https://layer8.space/tags/Babel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Babel</span></a> <a href="https://layer8.space/tags/FRR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FRR</span></a> <a href="https://layer8.space/tags/BGP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BGP</span></a> <a href="https://layer8.space/tags/Networking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Networking</span></a></p>
ItzTrain<p>I'm trying to get <a href="https://hachyderm.io/tags/VyOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VyOS</span></a> dhcp across it's VRF's.. It doesn't seem to like it unless it's the default vrf, in which I do have services there.. I am running my own Kea dhcp server and that is pretty ehh.. getting dhcp lease information is cumbersome. So naturally i'm running 2.. for the vrf's that I can't use :) ..</p><p><a href="https://hachyderm.io/tags/homelab" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>homelab</span></a> <br> <br><a href="https://hachyderm.io/tags/selfhosted" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>selfhosted</span></a> <br> <br><a href="https://hachyderm.io/tags/selfhosting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>selfhosting</span></a></p>