5 ms·
The question 'what is this thing' is probably best answered by the Github project page: https://github.com/vyos https://github.com/vyos It's a decent-ish optio
by PreInternet01 3y ago
The question 'what is this thing' is probably best answered by the Github project page: https://github.com/vyos https://github.com/vyos
It's a decent-ish option if you need advanced routing functionality; one thing to keep in mind, though, is that unless you're OK with running unstable 'nightly' code, you'll be spending USD 8K+ on an annual basis.
- awesomeMilou 3y agohttps://support.vyos.io/en/support/solutions/103000152091 https://support.vyos.io/en/support/solutions/103000152091 They have an LTS release, no? They seem to follow the RedHat strategy though, only subscribers can download prebuilt images, but you can build the LTS ones yourself: https://blog.vyos.io/vyos-1.3.2-lts-release https://blog.vyos.io/vyos-1.3.2-lts-release
- blinkingled 3y ago> If you are an individual, you can get the generic ISO by donating on Open Collective. And if you are contributing to VyOS, whether you are writing code, improving the docs, or promoting VyOS publicly, we are happy to share pre-built images with you through contributor subscriptions. Finally, you can always build your own images — just follow these instructions. Sounds fair to me. Truth is there's no good alternative other than pfSense but if you want Linux (hw support etc) I don't know if you can do better than vyos for routers.
- laurowyn 3y agoIf you want a web GUI, then pfSense or OPNSense are the general go tos. However, if you're comfortable with CLI and modifying configs in /etc/ then just running a bare metal Alpine Linux box is perfectly doable on a tiny box. iptables/nftables for firewall/NAT, dnsmasq/bind9 for dns, dnsmasq/isc-dhcp for DHCP. I've got a handful of these boxes all interlinked via wireguard, sharing routes via BGP using bird. Sure, you miss the config verification that VyOS provides, but does mean you learn the underlying tools themselves and that knowledge is portable to any other box running those systems. Personally, I don't quite understand why VyOS is a standalone distro when it could just be a config generator/checker package. Could even support multiple different underlying tools so if you want to use dnsmasq over bind9, or vice versa, it can provide a unified config interface for them.
- LeBit 3y agoHow do you do zone based firewalls with alpine?
- laurowyn 3y agodefine zone based? If wanting internal and external subnets as "zones", iptables/nftables lets you match against incoming and outgoing interfaces. It would be trivial to make match against an incoming interface and jump to a zone specific chain. This is how I manage private subnets. fw-mark is also useful for setting routing rules. Can change which routing table is used by matching rules in iptables. If wanting to do more stateful things, I'm not aware of any default package, but setting a rule to send packets to an NFQUEUE and implementing some custom logic on that nfqueue would be rather trivial too. I'm sure eBPFs are useable in there somewhere too, but I've very little experience with them. Obviously iptables/nftables has its own issues, as seen in recent (and not so recent) posts about it being bypassable with raw sockets, but that tends to be host only and not when used as a gateway.
- LeBit 3y ago> define zone based? https://support.vyos.io/en/support/solutions/articles/103000096269-zone-based-firewall-guide https://support.vyos.io/en/support/solutions/articles/103000... You create a _zone_. You name it and assign some interfaces to it. For my needs, I only assign 1 interface per zone. Then, you specify with which other zone that zone can receive traffic from. That also comes with the identification of a firewall rulesets to apply to that pair. So, `'Zone WAN (iface eth0) <- Zone LAN (iface eth1)' => apply fw LAN-TO-WAN` When you do that, the firewall rules become much simpler to write and maintain. But, a best practice is to assign every zone to every other zone. This soon becomes a combinatorial nightmare. When you want to add a zone, you have to create 2xN new zone configurations and 2xN new firewall rulesets.
- laurowyn 3y agoSo the equivalent of: iptables -N eth0toeth1; iptables -P eth0toeth1 DROP; iptables -A FORWARD -i eth0 -o eth1 -j eth0toeth1; iptables -A eth0toeth1 -m tcp -p 80 -j ACCEPT; # add any more rules Or, as you say to avoid exponential combinations, just make a chain for each zone (interface) and explicitly allow specific protocols/ports to target interfaces. Zones with multiple interfaces are just multiple rules to jump to the same zone chain.
- the_third_wave 3y ago> Truth is there's no good alternative other than pfSense but if you want Linux (hw support etc) I don't know if you can do better than vyos for routers. OpenWRT comes to mind, I've been using it for decades on first dedicated hardware, the last 6 years running in a container on a ProxMox box (DL380 G7). It has no problems whatsoever routing at (gigabit) line speed using a few megabytes of RAM and a few cores. Configuration is mostly declarative using UCI although it also offers the freedom (which comes with responsibility) to use scripts. I use the latter to deal with edge cases which lie outside of the purview of normal routing operations, e.g. triggered actions related to the use of Timelimit [1] on my daughter's phone, IoShit things with special needs, etc. [1] https://codeberg.org/timelimit/timelimit-server https://codeberg.org/timelimit/timelimit-server
- synergy20 3y agoopenwry,ipfire,ipcop,all do the job well
- sp0ck 3y agoDefinitely they are not. I couldn't find any other open source routing software that has support for following very popular features on enterprise level: - MPLS - VXLAN - IS-IS This is must have to be considered by any ISP/enterprise where networking is their core business. vOS has all three. More or less buggy but they are here.
- synergy20 3y agoEnterprise level I assume some will buy commercial equipment with support etc. The above mentioned I feel are good enough for home and SOHO(small businesses).
- zrail 3y agoYeah, the cost of buying equipment and licenses supported by a team with a phone number is immaterial for most enterprise-level organizations.
- circularfoyers 3y agoHow about OpenWRT? It appears it has support for MPLS[1], IS-IS[2], and VXLAN[3]. Where VXLAN appears to even have a LuCI component[4]. [1] https://openwrt.org/packages/pkgdata/kmod-mpls https://openwrt.org/packages/pkgdata/kmod-mpls [2] https://openwrt.org/packages/pkgdata/frr https://openwrt.org/packages/pkgdata/frr [3] https://openwrt.org/packages/pkgdata/vxlan https://openwrt.org/packages/pkgdata/vxlan [4] https://openwrt.org/packages/pkgdata/luci-proto-vxlan https://openwrt.org/packages/pkgdata/luci-proto-vxlan
- sp0ck 3y agoYou have very narrow definition of what software router/service router is. Firewall and two interfaces and VPN server is not the best scenario :) All those systems (pfSense etc) are for private/soho use. Big networks need stuff that is not avaiable on mentioned platforms like i.e BFD (Bidirectional Forwarding Detecion), MPLS (MultiProtocol Label Switching), VXLAN (Virtual Extensible LAN), IS-IS routing protocol or Segment Routing. If anyone knows other Opensource routing software that support all of this - let me know. To my knowledge vOS is the only one.
- ihattendorf 3y agoDANOS [0] supports all of those I believe. It's essentially AT&Ts continued development of Vyatta (a subset of it at least) with a DPDK dataplane + multiple other enhancements. [0]: https://www.danosproject.org/ https://www.danosproject.org/
- LeBit 3y agoI have created some automation to build the LTS ISO every time a new commit is made on the 1.3 LTS branch.