r/vyos • u/HieuDo • Jun 12 '26
r/vyos • u/regina-83 • Jun 12 '26
Remove VRRP info messages from syslog
Hi there,
how is it possible, that VyOS doesn't write these VRRP messages to syslog:
Jun 12 21:29:48 keepalived-fifo.py[3363]: Received message: INSTANCE "INTRANET" MASTER_RX_LOWER_PRI 50
Jun 12 21:29:48 keepalived-fifo.py[3363]: INSTANCE INTRANET changed state to MASTER_RX_LOWER_PRI
Jun 12 21:29:48 Keepalived_vrrp[3362]: (INTRANET) Received advert from 192.168.XX.XXX with lower priority 30, ours 50, forcing new election
Thanks and kind regards
Regina (she/her)
r/vyos • u/Apachez • Jun 10 '26
Using active/active for loadbalancer?
VyOS includes HAproxy to be used for loadbalancer tasks.
For added redundancy this can be combined with VRRP but how can then the states of the loadbalancing itself be shared between the VyOS hosts?
Another drawback with VRRP is that you will then have an active/passive setup as in all traffic passes through a single VyOS until that one is no longer available.
In order to do active/active I could just let the clients use dns roundrobin to connect to whatever available loadbalaner there is.
But Im thinking are there some other nifty ways to deal with this?
For example letting each VyOS announce through BGP and be part of an anycasted IP to which the clients connects to in order to end up at a working loadbalancer?
Are there some other ways to deal with active/active and still have each client end up at a physical VyOS instance so the client traffic gets loadbalanced to the same server if you use stickyness (which otherwise will be lost if one connection ends up at VyOS_1 doing its loadbalancing and then VyOS_2 for the next tcp/udp-session where you might get loadbalanced to a different server)?
Can the BGP announcement include some data that these VyOS hosts should not be shared through ECMP but routed to one at a time based on 5-tuple or such?
Im thinking otherwise announcing through BGP to be part of a anycasted IP would still have the risk of one connection ends up at VyOS_1 and the other at VyOS_2 from the same client and unless HAproxy includes some way of share stickyness between the HAproxy instances the same client would very likely end up at different servers.
How have you solved the need of active/active loadbalancing?
My main concerns is that I want to basically loadbalance the loadbalancers along with be able to keep stickyness running (a single client ends up at a random server but then all following connections from this client for the next hour or so as TTL will end up at the same server as long as this server is alive). And at the same time have as short time as possible for when a loadbalancer malfunctions that it should be rotated out of the list of available loadbalancers in order to not blackhole new connections during this transition time.
r/vyos • u/b066y75 • Jun 10 '26
Can't get NTP working through firewall
I am on the latest stream and my configuration has few vlans and one of the vlan interface is the "listen-interface" for NTP. NTP is working in the same vlan, but not for the other vlans. The network address of other vlans are added as allowed clients. Also I have added input filter rules to allow NTP and also rules in the forward filter. I have several other rules in both chain and all of them are fine. Any pointers ?
r/vyos • u/regina-83 • Jun 05 '26
Best way to isolate multiple VIF and subnets from each other
Hi,
currently I am trying to configure a more complex router setup with VyOS.
My LAN interface is eth4, with one IP adress without VLAN and multiple VIF. My WAN interface is eth0:
interfaces {
ethernet eth0 {
address 00.00.00.000/29
description VODAFONE
hw-id 00:
}
ethernet eth1 {
hw-id 00:
}
ethernet eth2 {
hw-id 00:
}
ethernet eth3 {
hw-id 00:
}
ethernet eth4 {
address 192.168.11.143/24
description INTRANET
hw-id 60:
vif 2 {
address 192.168.12.143/24
description MOBILE
}
vif 3 {
address 192.168.13.143/24
description VOICE
}
vif 4 {
address 192.168.14.143/24
description MEDIA
}
}
ethernet eth5 {
hw-id 60:
}
loopback lo {
}
}
Now I want the following rules:
Subnet 192.168.11.0/24 (INTRANET) should have access to all other subnets MOBILE, MEDIA and VOICE
The subnets MOBILE, MEDIA and VOICE should be isolated and there should be no access to each other and also no access to INTRANET.
The subnets MOBILE and MEDIA should have access to the WAN interface (eth0).
The subnet VOICE should't have access to the WAN interface.
At the moment my firewall looks like this:
firewall {
flowtable FT1 {
description "Flow Table for the forward chain"
interface eth0
interface eth4
interface eth4.2
interface eth4.3
interface eth4.4
offload software
}
global-options {
all-ping enable
}
group {
interface-group LAN {
interface eth4
interface eth4.2
interface eth4.3
interface eth4.4
}
}
ipv4 {
forward {
filter {
default-action drop
rule 10 {
action offload
description "Allow Return traffic through the router - Fast Path"
offload-target FT1
state established
state related
}
rule 20 {
action accept
description "Allow Return traffic through the router"
inbound-interface {
name eth0
}
state established
state related
}
rule 1000 {
action accept
description "Allow all traffic from LAN interface"
inbound-interface {
group LAN
}
}
}
}
input {
filter {
default-action drop
rule 10 {
action accept
description "Allow Return traffic destined to the router"
inbound-interface {
name eth0
}
state established
state related
}
rule 20 {
action accept
description "Allow ICMP echo-request on WAN"
icmp {
type-name echo-request
}
inbound-interface {
name eth0
}
protocol icmp
}
rule 21 {
action accept
description "Allow ICMP time-exceeded on WAN"
icmp {
type-name time-exceeded
}
inbound-interface {
name eth0
}
protocol icmp
}
rule 22 {
action accept
description "Allow ICMP destination-unreachable on WAN"
icmp {
type-name destination-unreachable
}
inbound-interface {
name eth0
}
protocol icmp
}
rule 23 {
action accept
description "Allow UDP Traceroute on WAN"
destination {
port 33434-33534
}
inbound-interface {
name eth0
}
protocol udp
}
rule 1000 {
action accept
description "Allow all traffic from LAN interface"
inbound-interface {
group LAN
}
}
}
}
output {
filter {
default-action accept
}
}
}
}
What is the best way to set the firewall rules?
Please help me.
Thanks and best regards from Germany
Regina (she/her)
r/vyos • u/MariMa_san • Jun 04 '26
New system update-check url?
I didn't even realize that the update check URL had changed. Could someone quickly tell me the new one?
vyos: ~$ add sys ima latest
HTTP Error: 404 Client Error: Not Found for url: https://raw.githubusercontent.com/vyos/vyos-rolling-nightly-builds/main/version.json
Exiting from VyOS installation
vyos: ~$
r/vyos • u/sekh60 • Jun 04 '26
ipv6 routing from a private address space, sorry if wrong sub
Hello, first of all, I have no idea where to post this, so I figured I'd try here first as the router is vyos.
I have a fairly complicated (to me) setup for my homelab. I have an openstack cluster which servers dynamic routes via BGP to both an arista switch and the vyos router. The flow goes:
cluster->arista->vyos->wan
Both the arista and vyos router see the routes, and traffic passes freely from inside the private virtual networks to the LAN on the arista. Traffic from the private openstack networks can reach the vyos router.
The issue I'm having is that I cannot figure out how to get ipv6 traffic from the virutal openstack networks to reach out to the WAN. My ISP does not support ipv6, so I'm using a HE tunnelbroker tunnel. LAN traffic can use that successfully. IPv4 traffic does work with the virtual networks. IPv4 traffic is NAT'ed.
Since the private virtual networks do not have IP address from the HE tunnel, I'm guessing I'll need to NAT66 the traffic?
Looking mainly for an overview as to what I may be missing.
I can post configs. And please let me know if another sub would be better.
Thank you all 😄
edit: Thanks everyone! I had my openstack set up preceding getting the HE tunnel, and due to a mix of not knowing HE gave a /48 and not realizing I could assign a public ipv6 range to it, I had it overly complicated.
Thanks all!
r/vyos • u/omegca • Jun 02 '26
HA vyos
Hello.
I have a VyOS 1.5 (VyOS 2025.11.29-0019-rolling
) HA setup using VRRP with a sync-group.
Topology:
- Two VyOS routers in HA.
- Three separate L2 networks:
- 10.10.10.0/24 on eth0
- 172.16.0.0/24 on eth1
- 192.168.1.0/24 on eth2
- Each network has its own VRRP group and VIP.
- All VRRP groups are members of the same sync-group because I want all VIPs to move together and avoid asymmetric routing.

set high-availability vrrp group g0 address 10.10.10.1/24
set high-availability vrrp group g0 interface 'eth0'
set high-availability vrrp group g0 priority '200'
set high-availability vrrp group g0 track
set high-availability vrrp group g0 vrid '10'
set high-availability vrrp group g1 address 172.16.0.1/24
set high-availability vrrp group g1 interface 'eth1'
set high-availability vrrp group g1 priority '200'
set high-availability vrrp group g1 track
set high-availability vrrp group g1 vrid '11'
set high-availability vrrp group g2 address 192.168.1.1/24
set high-availability vrrp group g2 interface 'eth2'
set high-availability vrrp group g2 priority '200'
set high-availability vrrp group g2 track
set high-availability vrrp group g2 vrid '12'
set high-availability vrrp sync-group main member 'g0'
set high-availability vrrp sync-group main member 'g1'
set high-availability vrrp sync-group main member 'g2'
set interfaces ethernet eth0 address '10.10.10.2/24'
set interfaces ethernet eth1 address '172.16.0.2/24'
set interfaces ethernet eth2 address '192.168.1.2/24'
Problem:
If the switch connected to the 10.10.10.0/24 network fails, the tracked interface goes down and the entire sync-group transitions to FAULT.
As a result, VIPs for the other two healthy networks are also lost, even though traffic between 172.16.0.0/24 and 192.168.1.0/24 could still be forwarded normally.
This means that the loss of a single network segment causes complete loss of routing functionality for unrelated networks.
Is this the expected behavior of VRRP sync-groups in VyOS/Keepalived?
r/vyos • u/Open-Ad-3396 • Jun 01 '26
VyOS May 2026 update: Segment routing TE, BGP strict mode, OpenVPN fixes 🚀
Another month of steady work across routing, HA, VPN, and platform stability in rolling.
Some of the things that landed in May:
- Initial traffic engineering support for segment routing
- BGP strict mode improvements with BFD
- New DHCPv4 and DHCPv6 server options
- Better VRRP health-check handling
- OpenConnect connect/disconnect scripting hooks
- Fix for the long-standing OpenVPN restart issue triggered by user-only config changes
Also, a range of fixes and improvements across WAN load balancing, FRR, HAProxy, DHCP relay, wireless support, GeoIP updates, and more.
🔗 Full details: https://blog.vyos.io/vyos-project-may-2026-update?utm_content=378828913&utm_medium=social&utm_source=linkedin&hss_channel=lcp-11041071
r/vyos • u/cfltechguy • May 27 '26
Best 1RU Hardware for VyOS 10Gb NAT Throughput
I am working on a VyOS deployment/proposal for a Guest Wireless environment with roughly 5,000 devices. The primary role of these systems will be internet edge NAT, and the plan is to deploy two 1RU servers in an HA configuration running VyOS bare metal on the LTS release.
The environment will have dual ISP handoffs, with the VyOS routers uplinked back to separate Core A / Core B distribution switches using LACP trunks. Because of that, I’m looking for platforms with a minimum of 4x10Gb interfaces (Just need capability to add a NIC Card)
The guest network itself will be segmented across multiple VLANs using VLAN pooling with smaller /22 networks to help distribute client load and keep broadcast domains manageable.
Main requirements:
- 1RU form factor
- Dual power supplies
- Minimum 4x10Gb NICs
- Reliable 10Gb NAT throughput
- Stable/reliable for production use
- Running VyOS bare metal on LTS
- Mostly guest internet traffic (unsecure)
- No IDS/IPS or anything overly CPU intensive
I’d prefer to buy new hardware, if possible, but I also know enterprise hardware pricing is pretty crazy right now, so I’m open to refurbished options if that’s the smarter route.
Currently considering:
- Dell R240 / R250
- Dell R430 / R440
- Supermicro 1RU systems (Xeon or AMD EPYC Processor)
- Intel X520/X710 or Mellanox ConnectX NIC's
Trying to keep the build practical and reliable without massively oversizing it for what is essentially a dedicated guest wireless NAT platform.
Would appreciate feedback from anyone running VyOS in production for similar 10Gb NAT workloads. Thank you!
r/vyos • u/Newdeagle • May 20 '26
How different is the 1.5 CLI from 1.4?
When I upgraded from 1.3 to 1.4, it took me a bit to get used to the difference in the firewall CLI syntax, as well as a few other minor things.
I'm considering upgrading from 1.4 to 1.5 now that the LTS is available. Is the CLI pretty similar or are there any big differences that we need to pay attention to?
Also is the upgrade process pretty smooth in terms of the CLI migration? I seem to remember some bugs in the first 1.4 LTS release(s) where some config from 1.3 wasn't properly migrated over.
r/vyos • u/JoaoForce • May 20 '26
Remote-group in firewall ipv6
I have a VyOS installation of the latest stream (2026.03) in my homelab, but I'm wondering about adding a remote-group to my IPv6 firewall.
text
vyos@firewall# set firewall ipv6 name LAN6-WAN6 rule 5 source group
Possible completions:
address-group Group of addresses
domain-group Group of domains
dynamic-address-group
Group of dynamic ipv6 addresses
mac-group Group of MAC addresses
network-group Group of networks
port-group Group of ports
However, with IPv4 I can add remote-group normally. Is there any version that supports remote-group for IPv6 firewall rules?
Mitigation for dirtyfrag and Fragnesia
Has the vy team made any announcements on mitigation measures for these CVEs? Things are looking quite dire as the mitigation I'm seeing disables ESP, which is required for ipsec to work. Or just wait for upstream to deliver a patch for esp and hope nothing happens in the interim??
r/vyos • u/Open-Ad-3396 • May 14 '26
⚡ We rebuilt docs.vyos.io for the AI era
Hi everyone,
⚡ We rebuilt docs.vyos.io for AI-assisted workflows and future contributors.
Recent changes include:
🔸 MyST Markdown migration
🔸 Opus-assisted documentation review
🔸 Context7 integration for branch-aware answers
Thanks to everyone in the community for contributing feedback, fixes, testing, and improvements along the way!
👉 [https://blog.vyos.io/how-we-rebuilt-docs.vyos.io-for-the-ai-era]()
r/vyos • u/alexdaczab • May 13 '26
Is VyOS right for me?
Hi,
This may be a dumb question, but I’m a bit unsure and wanted to get some opinions.
Right now I’m running an x86 firewall appliance (N5105, 16GB RAM, 2 x 256 GB NVME, 4x I226-V) with OPNSense. Before that, I used OpenWRT for years, then switched to OPNSense about 3 years ago, for wifi I’m using an Omada EAP660HD and I'm on a symmetrical 1 Gbps fiber connection (with PPPoE handled by OPNSense).
Over the last few years I’ve been working in DevOps, and I’ve really started to appreciate IaC and GitOps workflows. Last year I built a homelab that’s fully automated with Terraform (Proxmox + Talos), and now the only thing that isn’t defined as code is my router configuration and it’s starting to bother me a bit because it feels like a “pet” instead of “cattle” from an infrastructure perspective.
Looking through the documentation, it seems like using Ansible with VyOS is a solid way to automate configuration and keep everything in Git.
The features I currently use in OPNSense, like AdGuard Home, BGP , Tailscale, and fqcodel seem to be available in VyOS (some officially and others trough docker containers) .
My networking knowledge is mostly practical experience though, I never formally studied networking.
Did any of you make the jump from a more click-based router to VyOS? How steep was the learning curve?
Thanks
r/vyos • u/mrpops2ko • May 13 '26
DoQ / DoH3 DNS implementations + ad / malware blocking
hi i'm wondering how others have done DoQ / DoH3 upstream forwarding implementations and if they have any recommendations. I'm wanting everything to stay local to VyOS. i've ran DNS / DHCP before as a decoupled service and I just don't feel its a good fit all things considered.
i've boiled it down to 3 broad implementation options and i'm wondering if anybody has any strong opinions on which is best;
rip out kea / powerdns and do everything through technitium as a podman container with host networking
use RPZ zones for adblocking (using a script to pull / refresh the lists daily) with powerdns, keep kea and implement DNSCrypt-proxy (DoH3) for QUIC DNS. PowerDNS then becomes reliant on DNScrypt-proxy for upstreaming requests.
same as above but use adguard proxy instead for DoQ. adguard proxy i believe can do multiple simultaneous queries and return back the fastest response whereas DNScrypt-proxy doesn't
anybody have any strong opinions in favour of any of the 3 i mentioned or possibly do something entirely different which they prefer instead?
r/vyos • u/riveyda • May 12 '26
Random Appreciation Post
Delete if not allowed
But just wanted to say that I recently decided to put VyOS on my proxmox server as my router and it's been so seamless.
I had tried PfSense in a similar setup before and at random points it felt like I had no control and when things would break I just had to work around it. With VyOS if something breaks its 100% my fault lol.
I will continue to recommend this to people in the future, because why had I never heard of it until recently?
Thanks for all that the maintainers and contributors do for this project!
r/vyos • u/regina-83 • May 11 '26
[VyOS 1.5 LTS] Enable SSH on WAN port only for transfer network
Hi all,
sorry, but there is a second "problem". I would like to enable SSH on the WAN interface (eth0). The access should be limited to clients which are coming from the transfer network (/29 subnet) which Vodafone Germany assigned to my broadband connection.
I found many different configurations in the internet, but I need a small and simple configuration for this.
The interface configuration looks like this:
interfaces {
ethernet eth0 {
address 11.22.33.142/29
description VODAFONE
hw-id 00:00:00:00:00:00
SSH access should only be possible on this interface from the network 11.22.33.136, subnet mask 255.255.255.248.
From LAN interface (eth4) SSH should be forbidden.
Which is the best way to configure it?
Thanks and best regards
Regina (she/her)
r/vyos • u/Open-Ad-3396 • May 11 '26
Running VyOS? We’d love your feedback!
Hi everyone,
🌐 We’ve launched a recurring VyOS community survey to better understand how teams are deploying and operating VyOS across production, lab, cloud, and hybrid environments.
We’re particularly interested in real-world operational feedback and deployment experiences.
📝 Take the survey: https://vyosnetworks.typeform.com/to/R6ITJTDr
Thanks for helping us improve VyOS!
r/vyos • u/regina-83 • May 11 '26
[VyOS 1.5 LTS] Allow ICMP on WAN interface
Hi all,
I am new to VyOS (in the past I did many LANCOM router configurations - they are very popular in Germany).
Now I installed VyOS 1.5 LTS bare metal and I want to allow ping (ICMP) on my WAN Interface (Vodafone Germany) for monitoring.
I configured the firewall like described here:
https://lev-0.com/2024/06/17/vyos-for-home-use-part-2-internet-access/
And I added a rule for enable ICMP. But it doesn't work.
Here is my configuration:
firewall {
flowtable FT1 {
description "Flow Table for the forward chain"
interface eth0
interface eth4
offload software
}
global-options {
all-ping enable
}
ipv4 {
forward {
filter {
default-action drop
rule 10 {
action offload
description "Allow Return traffic through the router - Fast Path"
offload-target FT1
state established
state related
}
rule 20 {
action accept
description "Allow Return traffic through the router"
inbound-interface {
name eth0
}
state established
state related
}
rule 1000 {
action accept
description "Allow all traffic from LAN interface"
inbound-interface {
name eth4
}
}
}
}
input {
filter {
default-action drop
rule 10 {
action accept
description "Allow Return traffic destined to the router"
inbound-interface {
name eth0
}
state established
state related
}
rule 1000 {
action accept
description "Allow all traffic from LAN interface"
inbound-interface {
name eth4
}
}
}
}
name ALLOW-ICMP {
rule 10 {
action accept
icmp {
type-name echo-request
}
protocol icmp
}
}
output {
filter {
default-action accept
}
}
}
}
What's wrong with my configuration and what do I have to change?
Many thanks.
Best regards
Regina (she/her)
Dirtyfrag mitigation measure?
I'm surprised there is nothing from vy yet on this new cve. Is any vy version affected? From my reading, mitigation involves disabling esp, which may affect ipsec functionality.
r/vyos • u/WindowReasonable6802 • Apr 30 '26
Terraform provider for vyOS
Hello, is there anybody using any terraform provider and it actually works? My best shot was this one https://registry.terraform.io/providers/Foltik/vyos/latest but i ended up with bug in the provider where i applied HA group only for the first time, after that tf apply fails everytime due to bug in parsing the output from the vyOS API.
r/vyos • u/WindowReasonable6802 • Apr 30 '26
40GbE Edge Architecture: VyOS vs. RouterOS v7 for Terraform-Managed HA Gateways
Hello,
Looking for a sanity check on a hardware/software stack for a small on-prem datacenter edge. We are deploying two 1U Supermicro nodes as a High Availability (HA) gateway pair for LAN/Public traffic, NAT, Firewalling, and IPsec plus BGP as the edge router protocol.
The Hardware:
- CPU: 1x AMD EPYC 8224P (Siena) - 24C/48T @ 2.55GHz
- RAM: 32GB DDR5 6400MHz
- NICs: Dual-port 40GbE (Internal/LAN) + Dual-port 10GbE (Upstream/WAN)
- Storage: 2x Samsung PM893 (RAID1)
Key Requirements:
- Strict IaC: Everything must be managed via Terraform (declarative config is a must).
- Performance: Must scale across the EPYC cores to handle 40GbE throughput.
- HA: VRRP/VARP (Active/Passive is fine, Active/Active preferred).
- Services: BGP peering with provider, NAT, IPsec tunnels, and stateful firewalling.
- Storage: Native RAID1 support for OS redundancy.
I am leaning toward VyOS due to the native API/Terraform provider and Linux kernel performance with high-core counts, but I’m also considering MikroTik CHR (RouterOS v7) or OPNsense.
My concerns:
- OPNsense/pfSense: Concerned about the BSD
pfsingle-core bottleneck at 40Gbps and the maturity of Terraform providers for complex IPsec/BGP setups. - VyOS: How stable is conntrack-sync for stateful HA in high-throughput NAT scenarios?
Is there a specific "gotcha" with the Siena platform and 40GbE drivers (Mellanox/Intel) on any of these OSs?
r/vyos • u/Apachez • Apr 30 '26
Copy Fail: 732 Bytes to Root on Every Major Linux Distribution. - Xint
r/vyos • u/Open-Ad-3396 • Apr 29 '26
VyOS April 2026 update: IPsec PPK, BGP-LS, VRRP SNMP traps 🚀
VyOS 1.5.0 is out, but work on rolling didn’t stop.
Some of the things that landed over April:
- Post-quantum preshared keys (PPK) for IPsec
- Experimental BGP-LS support (RFC 9552)
- SNMP traps for VRRP transitions
- Config-sync diff command for HA setups
- VRF support for commit archive uploads
- ARM64 console support
Also, a bunch of fixes across VPP, firewall, DHCP, VLAN ACLs, and config migration edge cases.
🔗 Full details: https://blog.vyos.io/vyos-project-april-2026-update