660 Commits

Author SHA1 Message Date
Christian Breunig
c8f8c2d10c vxlan: T5753: add support for VNI filtering 2023-11-18 19:57:43 +01:00
Christian Breunig
9e9f2755a8
Merge pull request #1151 from vyos/frr-pim-T5733
pim: igmp: T5733: adjust to latest CLI syntax
2023-11-15 18:21:41 +01:00
Christian Breunig
2de650e60c pim: igmp: T5733: adjust to latest CLI syntax 2023-11-13 21:29:52 +01:00
Robert Göhler
092965a217
Update flowtables.rst 2023-11-13 11:16:14 +01:00
Robert Göhler
f59bff9cdd
Merge pull request #1144 from nicolas-fort/fwall-nat-update
Fwall nat update
2023-11-12 21:43:16 +01:00
Robert Göhler
2c14b973a3
Update flowtables.rst 2023-11-12 21:42:49 +01:00
Indrajit Raychaudhuri
510485fd14 mdns: T5227, T5615, T5719: Update mDNS documentation for additional options
Add mdns repeater docs for additional conf-mode and op-mode options.
2023-11-09 22:00:25 -06:00
Daniil Baturin
e4785773bf
Merge pull request #1146 from srividya0208/minor_errors
correction of typos
2023-11-09 13:27:19 +00:00
srividya0208
040472e043 correction of typos 2023-11-09 08:19:04 -05:00
Nicolas Fort
b6c3c7f40a Firewall Update: improve documentation and split file for better experience while reading. Add brief notes regarding Flowtables and Bridge firewall, leaving a note that those documents are still under development. New explanation for Netfilter based firewall, which includes new diagrams. 2023-11-08 13:51:47 -03:00
Robert Göhler
8a1d41b7f1
Merge pull request #1127 from JeffWDH/master
Update ssh.rst
2023-11-07 21:27:00 +01:00
Nicolas Fort
ece28ce809 Update nat and firewall docs. Re-add zone and update several things. 2023-11-01 11:09:42 -03:00
Christian Breunig
8c838d7ca9 T5699: vxlan: migrate "external" CLI know to "parameters external" 2023-10-31 07:37:52 +01:00
JeffWDH
6b2d50c755
Add "monitor log ssh" and "monitor log ssh dynamic-protection" 2023-10-29 10:26:45 -04:00
Christian Breunig
11cb9979e0 vxlan: T5668: add CLI knob to enable ARP/ND suppression 2023-10-28 21:35:55 +02:00
Christian Breunig
8a5804881c vxlan: add missing "parameters nolearning" help 2023-10-28 21:34:25 +02:00
Robert Göhler
7aa0c1ab32
Merge pull request #1126 from srividya0208/ipsec_vips
Added config example of vpn ipsec site-to-site
2023-10-26 13:36:13 +02:00
srividya0208
4d7e44d3e7 Added config example of vpn ipsec site-to-site 2023-10-26 02:00:19 -04:00
Robert Göhler
4db66e6c0c
Update nat44.rst
change interface-name and interface-group
2023-10-25 21:33:07 +02:00
Robert Göhler
535bd97639
Revert "Revert "NAT: add interface-group documentation. "" 2023-10-25 21:30:35 +02:00
JeffWDH
c9a06800f9
Update ssh.rst
Added:
show log ssh
show log ssh dynamic-protection
show ssh fingerprints
show ssh fingerprints ascii
show ssh dynamic-protection
2023-10-19 12:32:06 -04:00
Robert Göhler
858e209ef9
Merge pull request #1119 from aslanvyos/patch-8
Update dmvpn.rst
2023-10-19 13:05:10 +02:00
Robert Göhler
e64913496b
Merge pull request #1118 from aslanvyos/patch-7
Update site2site_ipsec.rst
2023-10-19 10:26:06 +02:00
Veli-Matti Helke
d3afeafb41 Fix two typos in Wireguard doc 2023-10-18 22:08:58 +03:00
aslanvyos
dc2cfd1f61
Update dmvpn.rst
When we put this command we got an error like:

set interfaces tunnel tun100 local-ip '192.0.2.1'

  Configuration path: interfaces tunnel tun100 [local-ip] is not valid
  Set failed
2023-10-18 17:44:00 +04:00
aslanvyos
d3ef41c38f
Update site2site_ipsec.rst
To make easily understandable the Site-to-Site VPN ikev2 configuration for users (especially if the user is new to VyOS) made the following changes:
- Added dummy interface to both routers for testing purposes
- Added static route for both routers for dummy interface
- Added this line of command: 
   set vpn ipsec option disable-route-autoinstall
   Because when we write this line after the commit action we got an error like:
WARNING: It's recommended to use ipsec vti with the next command

- corrected this line:
  set vpn ipsec site-to-site peer OFFICE-B local-address '192.168.0.10'
to this:
set vpn ipsec site-to-site peer OFFICE-B local-address '172.18.201.10'
2023-10-18 15:24:39 +04:00
Christian Breunig
1ddce99cc8 wireless: extend example with missing country-code 2023-10-17 21:19:18 +02:00
Robert Göhler
54525f31ce
Revert "NAT: add interface-group documentation. " 2023-10-12 21:07:02 +02:00
Nicolas Fort
531c5b9c5e NAT: add interface-group documentation. Also add firewall rules for allowing destination nat connections. 2023-10-11 15:41:18 -03:00
Robert Göhler
a7c0717e5d
Merge pull request #1107 from Dibins/patch-1
Update wireguard.rst
2023-10-10 21:36:29 +02:00
Christian Breunig
7090b69845 T5630: pppoe: allow to specify MRU in addition to already configurable MTU 2023-10-08 09:08:35 +02:00
Dibins
7d9792b510
Update wireguard.rst
Adding proper syntax for 1.4 firewall commands
2023-10-05 15:50:06 -05:00
Dibins
fa84bc4b35
Second update dns.rst
Based on the discussion here: https://forum.vyos.io/t/dynamic-dns-not-wollowing-web-options/12309 it seems necessary to note that setting the web-options on a given interface is not sufficient for determining the IP address when behind NAT. 

I've added some additional detail, which I think will make that more clear, as well as listed the commands as required to set up DDNS behind NAT. 

Further I updated the section on RFC2136 to accurately show address instead of interface
2023-10-02 16:53:29 -05:00
Shnoobins
cf1c7eb76d
Update dns.rst
Updated command syntax for dynamic dns - changed set service dns dynamic interface to set service dns dynamic address. 

Changed the login option from 'login' to 'username' 

Changed the web options from 'use-web' to 'web-options' 

Changed because I ran into the command syntax change on a 1.4 install. Updating documents to match.
2023-10-02 12:40:37 -05:00
Robert Göhler
08ac110e10
Merge pull request #1101 from srividya0208/ikev2vpn
Added details about ipsec remote-access
2023-09-28 14:07:40 +02:00
srividya0208
3f7e9a6de9 Added details about ipsec remote-access 2023-09-28 02:41:47 -04:00
Robert Göhler
b15d0560a2
Merge pull request #1095 from aslanvyos/patch-2
Update login.rst
2023-09-26 22:11:13 +02:00
Robert Göhler
f635b6e714
Merge pull request #1088 from Nephiaust/2023-FirewallUpdates
Updates to the firewall pages
2023-09-26 22:08:20 +02:00
aslanvyos
6f8c303510
Update login.rst
RADIUS and TACACS configuration examples were added.
Also mentioned if there is no connection between VyOS and RADIUS/TACACS servers users need to use local accounts for authentication.
2023-09-22 16:33:23 +04:00
Viacheslav Hletenko
f7cd4483aa Add firewal synproxy 2023-09-21 15:22:34 +03:00
Nephiaust
7d07926f37
Added new section about the different firewalls
Updated labels for the pages
Added new pictures.

Signed-off-by: Nephiaust <29741794+Nephiaust@users.noreply.github.com>
2023-09-18 01:08:00 +09:30
Nephiaust
d9a978cf58
Change ref firewall for int groups to be unique
Signed-off-by: Nephiaust <29741794+Nephiaust@users.noreply.github.com>
2023-09-17 23:28:53 +09:30
Nephiaust
b5ce5a2eba
Fixed bad formatting for code-blocks
Signed-off-by: Nephiaust <29741794+Nephiaust@users.noreply.github.com>
2023-09-17 23:27:53 +09:30
Robert Göhler
9688bca70d
Merge pull request #1063 from NickAnderegg/overview-nftables-translation
quick-start: update firewall tutorials to reflect nftables-based firewall commands
2023-09-13 20:46:17 +02:00
Christian Breunig
55b1909b03 vrf: add NAT example 2023-09-13 19:11:17 +02:00
John Estabrook
93c8726ab9
Merge pull request #1075 from dmbaturin/T5270-openvpn-peer-fingerprint
openvpn: Add peer fingerprint mode
2023-09-13 09:54:20 -05:00
Daniil Baturin
14633c945f openvpn: Add peer fingerprint mode 2023-09-13 15:39:58 +01:00
Nick Anderegg
1e8c862c55 chore: fix formatting and add linter comments 2023-09-12 21:36:25 -04:00
Nick Anderegg
63ff118d8a quick-start: add notice about changes to firewall backend 2023-09-12 20:55:59 -04:00
Robert Göhler
0a2c9463b9
Merge pull request #1076 from nicolas-fort/Firewall_new_cli_update
Firewall refactor: add visible note in firewall docs:
2023-09-11 20:37:43 +02:00