]> git.proxmox.com Git - pve-firewall.git/blame_incremental - debian/changelog
use /usr/sbin as base path
[pve-firewall.git] / debian / changelog
... / ...
CommitLineData
1pve-firewall (4.0-3) pve; urgency=medium
2
3 * Create corosync firewall rules independently of localnet~
4
5 * Display corosync rule info on localnet call
6
7 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
8
9pve-firewall (4.0-2) pve; urgency=medium
10
11 * fix systemd warning about PIDFile directory
12
13 * fix CT rule generation with ipfilter set
14
15 * pve-firewall service: update-alternative iptables and ebtables to working
16 legacy versions
17
18 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
19
20pve-firewall (4.0-1) pve; urgency=medium
21
22 * re-build for Debian Buster / PVE 6
23
24 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
25
26pve-firewall (3.0-21) unstable; urgency=medium
27
28 * fix ipv6 PVEFW-reject
29
30 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
31 ebtables doing the wrong thing here
32
33 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
34
35pve-firewall (3.0-20) unstable; urgency=medium
36
37 * use IPCC to read config and rule files, if the are backed by pmxcfs which
38 has better handling for pmxcfs restarts
39
40 * fix #2178: endless loop on ipv6 extension headers
41
42 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
43
44pve-firewall (3.0-19) unstable; urgency=medium
45
46 * ebtables: add arp filtering
47
48 * fix: #2123 Logging of user defined firewall rules
49
50 * fix Razor macro
51
52 * allow to enable/disable and modify cluster wide log ratelimits
53
54 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
55
56pve-firewall (3.0-18) unstable; urgency=medium
57
58 * fix #1606: Add nf_conntrack_allow_invalid option
59
60 * log reject : add space after policy REJECT like drop
61
62 * fix #1891: Add zsh command completion for pve-firewall
63
64 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
65
66pve-firewall (3.0-17) unstable; urgency=medium
67
68 * fix #2005: only allow ascii port digits
69
70 * fix #2004: do not allow backwards ranges
71
72 * add conntrack logging via libnetfilter_conntrack and allow one to enable
73 it through the firewall host configuration
74
75 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
76
77pve-firewall (3.0-16) unstable; urgency=medium
78
79 * api/rules: fix macro return type
80
81 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
82
83pve-firewall (3.0-15) unstable; urgency=medium
84
85 * fix #1971: display firewall rule properties
86
87 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
88
89pve-firewall (3.0-14) unstable; urgency=medium
90
91 * fix #1841: avoid ebtable reloads when containers have multiple network
92 interfaces
93
94 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
95
96pve-firewall (3.0-13) unstable; urgency=medium
97
98 * avoid unnecessary reloads of ebtable ruleset
99
100 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
101
102pve-firewall (3.0-12) unstable; urgency=medium
103
104 * fix deleted iptables chains not being properly detected as a change
105
106 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
107
108pve-firewall (3.0-11) unstable; urgency=medium
109
110 * #1764: rename 'ebtales_enable' option to 'ebtables'
111
112 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
113
114pve-firewall (3.0-10) unstable; urgency=medium
115
116 * fix #1764: handle existing ebtables rules and allow disabling ebtables
117
118 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
119 ebtables_enable option.
120
121 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
122
123pve-firewall (3.0-9) unstable; urgency=medium
124
125 * fix creation of ebltables FORWARD rule entry
126
127 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
128
129pve-firewall (3.0-8) unstable; urgency=medium
130
131 * add ebtables support for better MAC filtering
132
133 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
134
135pve-firewall (3.0-7) unstable; urgency=medium
136
137 * support distinct source and destination multi-port matching
138
139 * multi-port matching: when specifying the same list of ports for source and
140 destination require them both to match, rather than one of them, as this
141 was rather unexpected behavior
142
143 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
144
145pve-firewall (3.0-6) unstable; urgency=medium
146
147 * fix #1319: don't fail postinst with masked service
148
149 * debian: switch to compat 9, drop init scripts, drop preinst
150
151 * check multiport limit in port ranges
152
153 * build: use git rev-parse for GITVERSION
154
155 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
156
157pve-firewall (3.0-5) unstable; urgency=medium
158
159 * fix issue with disabled flag not being honored within groups
160
161 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
162
163pve-firewall (3.0-4) unstable; urgency=medium
164
165 * fix issues with ipsets reloading unnecessarily or too late
166
167 * fix some typos in the logs
168
169 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
170
171pve-firewall (3.0-3) unstable; urgency=medium
172
173 * Fix #1492: logger: use current timestamp if the packet doesn't have one
174
175 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
176
177pve-firewall (3.0-2) unstable; urgency=medium
178
179 * Fix #1446: remove masks in case the package had previously been removed but
180 not purged.
181
182 * improve logging on errors in the firewall configuration
183
184 * forbid trailing commas in lists as iptables-restore doesn't support them
185
186 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
187
188pve-firewall (3.0-1) unstable; urgency=medium
189
190 * rebuild for Debian Stretch
191
192 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
193
194pve-firewall (2.0-33) unstable; urgency=medium
195
196 * ipset: don't allow zero-prefix entries
197
198 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
199
200pve-firewall (2.0-32) unstable; urgency=medium
201
202 * improve search for local-network
203
204 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
205
206pve-firewall (2.0-31) unstable; urgency=medium
207
208 * don't try to apply ports to rules which don't support them
209
210 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
211
212pve-firewall (2.0-30) unstable; urgency=medium
213
214 * add multicast DNS to the list of Macros
215
216 * add missing parameter descriptions
217
218 * build-depends: add dh-systemd
219
220 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
221
222pve-firewall (2.0-29) unstable; urgency=medium
223
224 * prevent overwriting ipsets/sec. groups by renaming
225
226 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
227
228pve-firewall (2.0-28) unstable; urgency=medium
229
230 * use pve-common's ipv4_mask_hash_localnet
231
232 * fix allowed group name length
233
234 * make group digest stable
235
236 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
237
238pve-firewall (2.0-27) unstable; urgency=medium
239
240 * fix #972: make PVEFW-FWBR-* rule order stable
241
242 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
243
244pve-firewall (2.0-26) unstable; urgency=medium
245
246 * fix #988: set rp_filter=2
247
248 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
249
250pve-firewall (2.0-25) unstable; urgency=medium
251
252 * fix #945: add uninitialized check in lxc ipset compilation
253
254 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
255
256pve-firewall (2.0-24) unstable; urgency=medium
257
258 * Build-Depend on pve-doc-generator
259
260 * generate manpage with pve-doc-generator
261
262 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
263
264pve-firewall (2.0-23) unstable; urgency=medium
265
266 * use only the top bit for our accept marks
267
268 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
269
270pve-firewall (2.0-22) unstable; urgency=medium
271
272 * Use cfs_config_path from PVE::QemuConfig
273
274 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
275
276pve-firewall (2.0-21) unstable; urgency=medium
277
278 * added new 'ipfilter' option
279
280 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
281
282pve-firewall (2.0-20) unstable; urgency=medium
283
284 * fix 901: encode unicode characters in sha digest
285
286 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
287
288pve-firewall (2.0-19) unstable; urgency=medium
289
290 * Add radv option to VM options
291
292 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
293
294pve-firewall (2.0-18) unstable; urgency=medium
295
296 * Add ndp option to host and VM firewall options
297
298 * Add router-solicitation to NeighborDiscovery macro
299
300 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
301
302pve-firewall (2.0-17) unstable; urgency=medium
303
304 * Don't leave empty FW config files behind
305
306 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
307
308pve-firewall (2.0-16) unstable; urgency=medium
309
310 * logger: basic ipv6 support
311
312 * add DHCPv6 macro
313
314 * add dhcpv6 support to the dhcp option
315
316 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
317
318pve-firewall (2.0-15) unstable; urgency=medium
319
320 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
321
322 * fix some regular expressions mixups
323
324 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
325
326pve-firewall (2.0-14) unstable; urgency=medium
327
328 * fix systemd service dependencies
329
330 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
331
332pve-firewall (2.0-13) unstable; urgency=medium
333
334 * allow numeric icmp types
335
336 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
337
338pve-firewall (2.0-12) unstable; urgency=medium
339
340 * implement bash completions
341
342 * convert pve-firewall into a PVE::Service class
343
344 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
345
346pve-firewall (2.0-11) unstable; urgency=medium
347
348 * iptables_get_chains: fix veth device name
349
350 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
351
352pve-firewall (2.0-10) unstable; urgency=medium
353
354 * new helper: clone_vmfw_conf()
355
356 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
357
358pve-firewall (2.0-9) unstable; urgency=medium
359
360 * remove firewall config file subroutine added
361
362 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
363
364pve-firewall (2.0-8) unstable; urgency=medium
365
366 * adopt regresion tests for lxc containers
367
368 * removed firewall code for openVZ
369
370 * Subroutine verify_rule fixed to correctly check only for "net\d+"
371 interface device names
372
373 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
374
375pve-firewall (2.0-7) unstable; urgency=medium
376
377 * added firewall code for lxc
378
379 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
380
381pve-firewall (2.0-6) unstable; urgency=medium
382
383 * firewall ipversion comparison fix
384
385 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
386
387pve-firewall (2.0-5) unstable; urgency=medium
388
389 * add ipv6 neighbor discovery and solicitation macros
390
391 * ip6tables accepts both spellings of the word neighbor
392
393 * added Ceph macro
394
395 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
396
397pve-firewall (2.0-4) unstable; urgency=medium
398
399 * include manual page for pve-firewall
400
401 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
402
403pve-firewall (2.0-3) unstable; urgency=medium
404
405 * use noawait trigers for pve-api-updates
406
407 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
408
409pve-firewall (2.0-2) unstable; urgency=medium
410
411 * trigger pve-api-updates event
412
413 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
414
415pve-firewall (2.0-1) unstable; urgency=medium
416
417 * recompile for debian jessie
418
419 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
420
421pve-firewall (1.0-18) unstable; urgency=low
422
423 * fix alias lookup
424
425 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
426
427pve-firewall (1.0-17) unstable; urgency=low
428
429 * fix restart behavior
430
431 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
432
433pve-firewall (1.0-16) unstable; urgency=low
434
435 * use new Daemon class from pve-common
436
437 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
438
439pve-firewall (1.0-15) unstable; urgency=low
440
441 * bug fix: load cluster conf for host rules
442
443 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
444
445pve-firewall (1.0-14) unstable; urgency=low
446
447 * do not use ipset list chains
448
449 * remove preinst script (not needed anymore)
450
451 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
452
453pve-firewall (1.0-13) unstable; urgency=low
454
455 * fix ipset remove order
456
457 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
458
459pve-firewall (1.0-12) unstable; urgency=low
460
461 * add preinst script to clear ipset from older installation (because
462 sets cannot be swapped if there type does not match.
463
464 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
465
466pve-firewall (1.0-11) unstable; urgency=low
467
468 * bug fix: correctly set ipversion for aliases in verify_rule
469
470 * save restore commands into files to make debugging
471 easier (/var/lib/pve-firewall/)
472
473 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
474
475pve-firewall (1.0-10) unstable; urgency=low
476
477 * add IPv6 support for VMs (hostfw is IPv4 only)
478
479 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
480
481pve-firewall (1.0-9) unstable; urgency=low
482
483 * fix max ipset name name length
484
485 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
486
487pve-firewall (1.0-8) unstable; urgency=low
488
489 * implement permission
490
491 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
492
493pve-firewall (1.0-7) unstable; urgency=low
494
495 * proxy host rule API calls to correct node
496
497 * always generate MAC and IP filter rules if firewall is enabled on NIC
498
499 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
500
501pve-firewall (1.0-6) unstable; urgency=low
502
503 * ipmlement ipfilter ipsets
504
505 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
506
507pve-firewall (1.0-5) unstable; urgency=low
508
509 * remove ipsets when firewall disabled
510
511 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
512
513pve-firewall (1.0-4) unstable; urgency=low
514
515 * depend on iptables and ipset
516
517 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
518
519pve-firewall (1.0-3) unstable; urgency=low
520
521 * change dh_installinit order (register pvefw-logger before pve-firewall)
522
523 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
524
525pve-firewall (1.0-2) unstable; urgency=low
526
527 * add experimental nflog logging daemon
528
529 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
530
531pve-firewall (1.0-1) unstable; urgency=low
532
533 * initial package
534
535 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
536