]> git.proxmox.com Git - pve-firewall.git/blame - debian/changelog
change vm/ prefix to guest/ prefix
[pve-firewall.git] / debian / changelog
CommitLineData
97f2bc6c
TL
1pve-firewall (5.0.0) bookworm; urgency=medium
2
3 * switch to native versioning scheme
4
5 * build for Proxmox VE 8 / Debian 12 Bookworm
6
7 -- Proxmox Support Team <support@proxmox.com> Mon, 22 May 2023 14:43:58 +0200
8
d3bf672b
TL
9pve-firewall (4.3-2) bullseye; urgency=medium
10
11 * fix variables declared in conditional statement
12
13 * fix #4730: add safeguards to prevent ICMP type misuse
14
15 -- Proxmox Support Team <support@proxmox.com> Tue, 16 May 2023 11:17:58 +0200
16
4fffdd36 17pve-firewall (4.3-1) bullseye; urgency=medium
23b3e816 18
e3d08ca1 19 * allow entering IP address with the host bits (those inside the mask) not
23b3e816
TL
20 being all zero non-zero, like 192.168.1.155/24 for example.
21
22 * api: firewall logger: add optional parameters `since` and `until` for
23 time-range filtering
24
25 * fix #4550: host options: add nf_conntrack_helpers to compensate that
26 kernel 6.1 and newer have removed the auto helpers
27
28 -- Proxmox Support Team <support@proxmox.com> Fri, 17 Mar 2023 15:24:56 +0100
29
b4577a25
TL
30pve-firewall (4.2-7) bullseye; urgency=medium
31
32 * fix #4018: add firewall macro for SPICE proxy
33
34 * fix #4204: automatically update each usage of a group to the new ID when
35 it is renamed
36
37 * fix #4268: add 'force' parameter to delete IPSet with members
38
39 -- Proxmox Support Team <support@proxmox.com> Thu, 17 Nov 2022 19:53:04 +0100
40
dd559e8a
TL
41pve-firewall (4.2-6) bullseye; urgency=medium
42
43 * config defaults: document that the mac filter defaults to on
44
45 * fix #4175: ignore non-filter ebtables tables
46
47 * fix enabling ebtables if VM firewall config is invalid
48
49 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Aug 2022 09:43:53 +0200
50
fba392f2
TL
51pve-firewall (4.2-5) bullseye; urgency=medium
52
53 * fix #3677 ipset get chains: handle newer ipset output for actual
54 change detection
55
56 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Nov 2021 16:37:13 +0100
57
bd63a439
TL
58pve-firewall (4.2-4) bullseye; urgency=medium
59
60 * re-build to avoid issues stemming from semi-broken systemd-debhelper version
61
62 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Oct 2021 10:39:05 +0200
63
2a2b81b4
TL
64pve-firewall (4.2-3) bullseye; urgency=medium
65
66 * fix #2721: remove the (nowadays) bogus reject for TCP port 43 from the
67 default drop and reject actions
68
69 -- Proxmox Support Team <support@proxmox.com> Fri, 10 Sep 2021 13:00:07 +0200
70
dcdbb559
TL
71pve-firewall (4.2-2) bullseye; urgency=medium
72
73 * re-set relevant sysctls on every apply round
74
75 -- Proxmox Support Team <support@proxmox.com> Mon, 21 Jun 2021 11:31:42 +0200
76
ce9cfab8
TL
77pve-firewall (4.2-1) bullseye; urgency=medium
78
79 * fix #967: source: dest: limit length
80
81 * re-build for Debian 11 Bullseye based releases (Proxmox VE 7)
82
83 * fix #2358: allow --<opt> in firewall rule config files
84
85 -- Proxmox Support Team <support@proxmox.com> Wed, 12 May 2021 20:32:30 +0200
86
8a4e5b69
TL
87pve-firewall (4.1-3) pve; urgency=medium
88
89 * fix #2773: ebtables: keep policy of custom chains
90
91 * introduce new icmp-type parameter
92
93 -- Proxmox Support Team <support@proxmox.com> Fri, 18 Sep 2020 16:51:27 +0200
94
70718917
TL
95pve-firewall (4.1-2) pve; urgency=medium
96
97 * revert: rules: verify referenced security group exists
98
99 -- Proxmox Support Team <support@proxmox.com> Wed, 06 May 2020 17:41:36 +0200
100
c5530455
TL
101pve-firewall (4.1-1) pve; urgency=medium
102
103 * logging: add missing log message for inbound rules
104
105 * fix #2686: avoid adding 'arp-ip-src' IP filter if guests uses DHCP
106
107 * IPSets: parse the CIDR before checking for duplicates
108
109 * verify that a referenced security group exists
110
111 * ICMP: fix iptables-restore failing if ICMP-type values bigger than '255'
112
113 * ICMP: allow one to specify the 'echo-reply' (0) type also as integer
114
115 * improve handling concurrent (parallel) access and modifications to rules
116
117 -- Proxmox Support Team <support@proxmox.com> Mon, 04 May 2020 15:01:57 +0200
118
56a47140
TL
119pve-firewall (4.0-10) pve; urgency=medium
120
121 * macros: add macro for Proxmox Mail Gateway web interface
122
123 * api node: always pass cluster conf to node FW parser to fix false positive
124 error message about non existing aliases, or IP sets, when querying the
125 node FW options GET API call.
126
127 * grammar fix: s/does not exists/does not exist/g
128
129 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jan 2020 19:25:49 +0100
130
5162c268
TL
131pve-firewall (4.0-9) pve; urgency=medium
132
133 * ensure port range used for offline storage migration and insecure migration
134 traffic is allowed by default rule set.
135
136 -- Proxmox Support Team <support@proxmox.com> Tue, 03 Dec 2019 08:12:20 +0100
137
5ac03b1c
WB
138pve-firewall (4.0-8) pve; urgency=medium
139
140 * increase default nf_conntrack_max to the kernel's default
141
142 * fix some "use of uninitialized value" warnings when updating CIDRs
143
144 * update schema documentation
145
146 * add explicit dependency on libpve-cluster-perl
147
148 * add support for "raw" tables
149
150 * add options for synflood protection for host firewall:
151 - nf_conntrack_tcp_timeout_syn_recv
152 - protection_synflood: boolean
153 - protection_synflood_rate: SYN rate limit (default 200 per second)
154 - protection_synflood_burst: SYN burst limit (default 1000)
155
156 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2019 13:48:20 +0100
157
bd368955
FG
158pve-firewall (4.0-7) pve; urgency=medium
159
160 * only add VM chains and rules if VM firewall is enabled
161
162 -- Proxmox Support Team <support@proxmox.com> Wed, 7 Aug 2019 10:55:06 +0200
163
c8f3e1ee
TL
164pve-firewall (4.0-6) pve; urgency=medium
165
166 * firewall macros: add new Ceph protocol v2 port while keeping v1 port
167
168 -- Proxmox Support Team <support@proxmox.com> Tue, 23 Jul 2019 18:57:48 +0200
169
6fc572dc
TL
170pve-firewall (4.0-5) pve; urgency=medium
171
172 * don't use any base path at all for calls to external binaries to make use
173 compativle with bot, /usr merged and unmerged setups
174
175 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Jul 2019 11:47:53 +0200
176
b1379400
TL
177pve-firewall (4.0-4) pve; urgency=medium
178
179 * ebtables: remove PVE chains properly
180
181 * ebtables: treat chain deletion as change
182
183 * use /usr/sbin as base path
184
185 -- Proxmox Support Team <support@proxmox.com> Thu, 11 Jul 2019 19:40:01 +0200
186
9e01d77d
TL
187pve-firewall (4.0-3) pve; urgency=medium
188
189 * Create corosync firewall rules independently of localnet~
190
191 * Display corosync rule info on localnet call
192
193 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
194
9429bd35
TL
195pve-firewall (4.0-2) pve; urgency=medium
196
197 * fix systemd warning about PIDFile directory
198
199 * fix CT rule generation with ipfilter set
200
201 * pve-firewall service: update-alternative iptables and ebtables to working
202 legacy versions
203
204 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
205
6b9da9b0
TL
206pve-firewall (4.0-1) pve; urgency=medium
207
208 * re-build for Debian Buster / PVE 6
209
210 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
211
dd7d737b
TL
212pve-firewall (3.0-21) unstable; urgency=medium
213
214 * fix ipv6 PVEFW-reject
215
216 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
217 ebtables doing the wrong thing here
218
219 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
220
bbf77725
TL
221pve-firewall (3.0-20) unstable; urgency=medium
222
223 * use IPCC to read config and rule files, if the are backed by pmxcfs which
224 has better handling for pmxcfs restarts
225
226 * fix #2178: endless loop on ipv6 extension headers
227
228 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
229
baba607a
TL
230pve-firewall (3.0-19) unstable; urgency=medium
231
232 * ebtables: add arp filtering
233
234 * fix: #2123 Logging of user defined firewall rules
235
236 * fix Razor macro
237
238 * allow to enable/disable and modify cluster wide log ratelimits
239
240 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
241
d8ea08e3
TL
242pve-firewall (3.0-18) unstable; urgency=medium
243
244 * fix #1606: Add nf_conntrack_allow_invalid option
245
246 * log reject : add space after policy REJECT like drop
247
248 * fix #1891: Add zsh command completion for pve-firewall
249
250 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
251
91d88bc5
TL
252pve-firewall (3.0-17) unstable; urgency=medium
253
254 * fix #2005: only allow ascii port digits
255
256 * fix #2004: do not allow backwards ranges
257
258 * add conntrack logging via libnetfilter_conntrack and allow one to enable
259 it through the firewall host configuration
260
261 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
262
81d13a9d
TL
263pve-firewall (3.0-16) unstable; urgency=medium
264
265 * api/rules: fix macro return type
266
267 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
268
bed701bc
TL
269pve-firewall (3.0-15) unstable; urgency=medium
270
271 * fix #1971: display firewall rule properties
272
273 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
274
a24b157b
WB
275pve-firewall (3.0-14) unstable; urgency=medium
276
277 * fix #1841: avoid ebtable reloads when containers have multiple network
278 interfaces
279
280 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
281
cf7dd94b
WB
282pve-firewall (3.0-13) unstable; urgency=medium
283
284 * avoid unnecessary reloads of ebtable ruleset
285
286 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
287
dd03bf6e
WB
288pve-firewall (3.0-12) unstable; urgency=medium
289
290 * fix deleted iptables chains not being properly detected as a change
291
292 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
293
587a0f20 294pve-firewall (3.0-11) unstable; urgency=medium
a3a51dad
TL
295
296 * #1764: rename 'ebtales_enable' option to 'ebtables'
297
587a0f20 298 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
a3a51dad 299
423b86ef
WB
300pve-firewall (3.0-10) unstable; urgency=medium
301
302 * fix #1764: handle existing ebtables rules and allow disabling ebtables
303
304 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
305 ebtables_enable option.
306
307 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
308
567e58ce
WB
309pve-firewall (3.0-9) unstable; urgency=medium
310
311 * fix creation of ebltables FORWARD rule entry
312
313 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
314
ea0d59ed
WB
315pve-firewall (3.0-8) unstable; urgency=medium
316
317 * add ebtables support for better MAC filtering
318
319 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
320
9a19ec81
WB
321pve-firewall (3.0-7) unstable; urgency=medium
322
323 * support distinct source and destination multi-port matching
324
325 * multi-port matching: when specifying the same list of ports for source and
326 destination require them both to match, rather than one of them, as this
327 was rather unexpected behavior
328
329 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
330
8c41d444
DM
331pve-firewall (3.0-6) unstable; urgency=medium
332
333 * fix #1319: don't fail postinst with masked service
334
335 * debian: switch to compat 9, drop init scripts, drop preinst
336
337 * check multiport limit in port ranges
338
339 * build: use git rev-parse for GITVERSION
340
341 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
342
4299c35f
WB
343pve-firewall (3.0-5) unstable; urgency=medium
344
345 * fix issue with disabled flag not being honored within groups
346
347 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
348
a19d4127
WB
349pve-firewall (3.0-4) unstable; urgency=medium
350
351 * fix issues with ipsets reloading unnecessarily or too late
352
353 * fix some typos in the logs
354
355 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
356
c0c71b1b
WB
357pve-firewall (3.0-3) unstable; urgency=medium
358
359 * Fix #1492: logger: use current timestamp if the packet doesn't have one
360
361 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
362
4f7a4bdd
WB
363pve-firewall (3.0-2) unstable; urgency=medium
364
365 * Fix #1446: remove masks in case the package had previously been removed but
366 not purged.
367
368 * improve logging on errors in the firewall configuration
369
370 * forbid trailing commas in lists as iptables-restore doesn't support them
371
372 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
373
29a94c79
FG
374pve-firewall (3.0-1) unstable; urgency=medium
375
376 * rebuild for Debian Stretch
377
378 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
379
df67a3dc
DM
380pve-firewall (2.0-33) unstable; urgency=medium
381
382 * ipset: don't allow zero-prefix entries
383
384 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
385
dc643b4d
DM
386pve-firewall (2.0-32) unstable; urgency=medium
387
388 * improve search for local-network
389
390 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
391
45f206fd
DM
392pve-firewall (2.0-31) unstable; urgency=medium
393
394 * don't try to apply ports to rules which don't support them
395
396 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
397
2ea28d0c
DM
398pve-firewall (2.0-30) unstable; urgency=medium
399
400 * add multicast DNS to the list of Macros
401
402 * add missing parameter descriptions
403
404 * build-depends: add dh-systemd
405
406 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
407
b65d13d9
DM
408pve-firewall (2.0-29) unstable; urgency=medium
409
410 * prevent overwriting ipsets/sec. groups by renaming
411
412 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
413
d0f3bb08
DM
414pve-firewall (2.0-28) unstable; urgency=medium
415
416 * use pve-common's ipv4_mask_hash_localnet
417
5c53cde4
DC
418 * fix allowed group name length
419
420 * make group digest stable
421
d0f3bb08
DM
422 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
423
76a57e1a
DM
424pve-firewall (2.0-27) unstable; urgency=medium
425
426 * fix #972: make PVEFW-FWBR-* rule order stable
427
428 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
429
17642172
DM
430pve-firewall (2.0-26) unstable; urgency=medium
431
432 * fix #988: set rp_filter=2
433
434 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
435
6e29af12
DM
436pve-firewall (2.0-25) unstable; urgency=medium
437
438 * fix #945: add uninitialized check in lxc ipset compilation
439
440 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
441
edb4aff5
DM
442pve-firewall (2.0-24) unstable; urgency=medium
443
444 * Build-Depend on pve-doc-generator
445
446 * generate manpage with pve-doc-generator
447
448 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
449
e1158c15
DM
450pve-firewall (2.0-23) unstable; urgency=medium
451
452 * use only the top bit for our accept marks
453
454 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
455
5399f912
DM
456pve-firewall (2.0-22) unstable; urgency=medium
457
458 * Use cfs_config_path from PVE::QemuConfig
459
460 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
461
b9e73915
DM
462pve-firewall (2.0-21) unstable; urgency=medium
463
464 * added new 'ipfilter' option
465
466 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
467
e2a49003
DM
468pve-firewall (2.0-20) unstable; urgency=medium
469
470 * fix 901: encode unicode characters in sha digest
471
472 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
473
1d10f89a
DM
474pve-firewall (2.0-19) unstable; urgency=medium
475
476 * Add radv option to VM options
477
478 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
479
666093cd
DM
480pve-firewall (2.0-18) unstable; urgency=medium
481
482 * Add ndp option to host and VM firewall options
483
484 * Add router-solicitation to NeighborDiscovery macro
485
486 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
487
eaf25885
DM
488pve-firewall (2.0-17) unstable; urgency=medium
489
490 * Don't leave empty FW config files behind
491
492 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
493
a177fb07
DM
494pve-firewall (2.0-16) unstable; urgency=medium
495
496 * logger: basic ipv6 support
497
498 * add DHCPv6 macro
499
500 * add dhcpv6 support to the dhcp option
501
502 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
503
ab1b8d3c
DM
504pve-firewall (2.0-15) unstable; urgency=medium
505
506 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
507
508 * fix some regular expressions mixups
509
510 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
511
c9c8d7a3
DM
512pve-firewall (2.0-14) unstable; urgency=medium
513
514 * fix systemd service dependencies
515
516 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
517
aa818ae7
DM
518pve-firewall (2.0-13) unstable; urgency=medium
519
520 * allow numeric icmp types
521
522 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
523
8dbebe7d
DM
524pve-firewall (2.0-12) unstable; urgency=medium
525
526 * implement bash completions
527
528 * convert pve-firewall into a PVE::Service class
529
530 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
531
47704f4c
DM
532pve-firewall (2.0-11) unstable; urgency=medium
533
534 * iptables_get_chains: fix veth device name
535
536 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
537
9eb84dc7
DM
538pve-firewall (2.0-10) unstable; urgency=medium
539
540 * new helper: clone_vmfw_conf()
541
542 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
543
a3d34dac
DM
544pve-firewall (2.0-9) unstable; urgency=medium
545
546 * remove firewall config file subroutine added
547
548 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
549
2a42a237
DM
550pve-firewall (2.0-8) unstable; urgency=medium
551
552 * adopt regresion tests for lxc containers
553
554 * removed firewall code for openVZ
555
556 * Subroutine verify_rule fixed to correctly check only for "net\d+"
557 interface device names
558
559 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
560
33448a6e
DM
561pve-firewall (2.0-7) unstable; urgency=medium
562
563 * added firewall code for lxc
564
565 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
566
19f14465
DM
567pve-firewall (2.0-6) unstable; urgency=medium
568
569 * firewall ipversion comparison fix
570
571 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
572
8feec9fa
DM
573pve-firewall (2.0-5) unstable; urgency=medium
574
575 * add ipv6 neighbor discovery and solicitation macros
576
577 * ip6tables accepts both spellings of the word neighbor
578
579 * added Ceph macro
580
581 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
582
e02c77aa
DM
583pve-firewall (2.0-4) unstable; urgency=medium
584
585 * include manual page for pve-firewall
586
587 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
588
eb4a2902
DM
589pve-firewall (2.0-3) unstable; urgency=medium
590
591 * use noawait trigers for pve-api-updates
592
593 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
594
56bb2e69
DM
595pve-firewall (2.0-2) unstable; urgency=medium
596
597 * trigger pve-api-updates event
598
599 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
600
0b18ebe8
DM
601pve-firewall (2.0-1) unstable; urgency=medium
602
603 * recompile for debian jessie
604
605 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
606
609f00c7
DM
607pve-firewall (1.0-18) unstable; urgency=low
608
609 * fix alias lookup
610
611 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
612
de48e659
DM
613pve-firewall (1.0-17) unstable; urgency=low
614
615 * fix restart behavior
616
617 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
618
b92d2ed2
DM
619pve-firewall (1.0-16) unstable; urgency=low
620
621 * use new Daemon class from pve-common
622
623 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
624
22dde8d6
DM
625pve-firewall (1.0-15) unstable; urgency=low
626
627 * bug fix: load cluster conf for host rules
628
629 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
630
e33e2f16
DM
631pve-firewall (1.0-14) unstable; urgency=low
632
633 * do not use ipset list chains
634
635 * remove preinst script (not needed anymore)
636
637 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
638
3bce273b
DM
639pve-firewall (1.0-13) unstable; urgency=low
640
641 * fix ipset remove order
642
643 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
644
7a7c322c
DM
645pve-firewall (1.0-12) unstable; urgency=low
646
647 * add preinst script to clear ipset from older installation (because
648 sets cannot be swapped if there type does not match.
ce41ae23 649
7a7c322c
DM
650 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
651
1b918ee5
DM
652pve-firewall (1.0-11) unstable; urgency=low
653
654 * bug fix: correctly set ipversion for aliases in verify_rule
655
656 * save restore commands into files to make debugging
657 easier (/var/lib/pve-firewall/)
658
659 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
660
df617cea
DM
661pve-firewall (1.0-10) unstable; urgency=low
662
663 * add IPv6 support for VMs (hostfw is IPv4 only)
664
665 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
666
0ac57570
DM
667pve-firewall (1.0-9) unstable; urgency=low
668
669 * fix max ipset name name length
670
671 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
672
05fd3b63
DM
673pve-firewall (1.0-8) unstable; urgency=low
674
675 * implement permission
676
677 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
678
bea9d5ab
DM
679pve-firewall (1.0-7) unstable; urgency=low
680
681 * proxy host rule API calls to correct node
a34cfdd0
DM
682
683 * always generate MAC and IP filter rules if firewall is enabled on NIC
bea9d5ab
DM
684
685 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
686
582275c3
DM
687pve-firewall (1.0-6) unstable; urgency=low
688
689 * ipmlement ipfilter ipsets
690
691 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
692
de0c1e49
DM
693pve-firewall (1.0-5) unstable; urgency=low
694
695 * remove ipsets when firewall disabled
696
697 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
698
64c266f5
DM
699pve-firewall (1.0-4) unstable; urgency=low
700
701 * depend on iptables and ipset
702
703 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
704
16bcfa8b
DM
705pve-firewall (1.0-3) unstable; urgency=low
706
707 * change dh_installinit order (register pvefw-logger before pve-firewall)
708
709 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
710
ba0b3a0a
DM
711pve-firewall (1.0-2) unstable; urgency=low
712
713 * add experimental nflog logging daemon
714
715 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
716
bb272dd3
DM
717pve-firewall (1.0-1) unstable; urgency=low
718
719 * initial package
720
721 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
722