]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
79d32f772f145effd50a90c5a15f743610fdf03d
[pve-firewall.git] / debian / changelog
1 pve-firewall (4.2-1) bullseye; urgency=medium
2
3 * fix #967: source: dest: limit length
4
5 * re-build for Debian 11 Bullseye based releases (Proxmox VE 7)
6
7 * fix #2358: allow --<opt> in firewall rule config files
8
9 -- Proxmox Support Team <support@proxmox.com> Wed, 12 May 2021 20:32:30 +0200
10
11 pve-firewall (4.1-3) pve; urgency=medium
12
13 * fix #2773: ebtables: keep policy of custom chains
14
15 * introduce new icmp-type parameter
16
17 -- Proxmox Support Team <support@proxmox.com> Fri, 18 Sep 2020 16:51:27 +0200
18
19 pve-firewall (4.1-2) pve; urgency=medium
20
21 * revert: rules: verify referenced security group exists
22
23 -- Proxmox Support Team <support@proxmox.com> Wed, 06 May 2020 17:41:36 +0200
24
25 pve-firewall (4.1-1) pve; urgency=medium
26
27 * logging: add missing log message for inbound rules
28
29 * fix #2686: avoid adding 'arp-ip-src' IP filter if guests uses DHCP
30
31 * IPSets: parse the CIDR before checking for duplicates
32
33 * verify that a referenced security group exists
34
35 * ICMP: fix iptables-restore failing if ICMP-type values bigger than '255'
36
37 * ICMP: allow one to specify the 'echo-reply' (0) type also as integer
38
39 * improve handling concurrent (parallel) access and modifications to rules
40
41 -- Proxmox Support Team <support@proxmox.com> Mon, 04 May 2020 15:01:57 +0200
42
43 pve-firewall (4.0-10) pve; urgency=medium
44
45 * macros: add macro for Proxmox Mail Gateway web interface
46
47 * api node: always pass cluster conf to node FW parser to fix false positive
48 error message about non existing aliases, or IP sets, when querying the
49 node FW options GET API call.
50
51 * grammar fix: s/does not exists/does not exist/g
52
53 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jan 2020 19:25:49 +0100
54
55 pve-firewall (4.0-9) pve; urgency=medium
56
57 * ensure port range used for offline storage migration and insecure migration
58 traffic is allowed by default rule set.
59
60 -- Proxmox Support Team <support@proxmox.com> Tue, 03 Dec 2019 08:12:20 +0100
61
62 pve-firewall (4.0-8) pve; urgency=medium
63
64 * increase default nf_conntrack_max to the kernel's default
65
66 * fix some "use of uninitialized value" warnings when updating CIDRs
67
68 * update schema documentation
69
70 * add explicit dependency on libpve-cluster-perl
71
72 * add support for "raw" tables
73
74 * add options for synflood protection for host firewall:
75 - nf_conntrack_tcp_timeout_syn_recv
76 - protection_synflood: boolean
77 - protection_synflood_rate: SYN rate limit (default 200 per second)
78 - protection_synflood_burst: SYN burst limit (default 1000)
79
80 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2019 13:48:20 +0100
81
82 pve-firewall (4.0-7) pve; urgency=medium
83
84 * only add VM chains and rules if VM firewall is enabled
85
86 -- Proxmox Support Team <support@proxmox.com> Wed, 7 Aug 2019 10:55:06 +0200
87
88 pve-firewall (4.0-6) pve; urgency=medium
89
90 * firewall macros: add new Ceph protocol v2 port while keeping v1 port
91
92 -- Proxmox Support Team <support@proxmox.com> Tue, 23 Jul 2019 18:57:48 +0200
93
94 pve-firewall (4.0-5) pve; urgency=medium
95
96 * don't use any base path at all for calls to external binaries to make use
97 compativle with bot, /usr merged and unmerged setups
98
99 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Jul 2019 11:47:53 +0200
100
101 pve-firewall (4.0-4) pve; urgency=medium
102
103 * ebtables: remove PVE chains properly
104
105 * ebtables: treat chain deletion as change
106
107 * use /usr/sbin as base path
108
109 -- Proxmox Support Team <support@proxmox.com> Thu, 11 Jul 2019 19:40:01 +0200
110
111 pve-firewall (4.0-3) pve; urgency=medium
112
113 * Create corosync firewall rules independently of localnet~
114
115 * Display corosync rule info on localnet call
116
117 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
118
119 pve-firewall (4.0-2) pve; urgency=medium
120
121 * fix systemd warning about PIDFile directory
122
123 * fix CT rule generation with ipfilter set
124
125 * pve-firewall service: update-alternative iptables and ebtables to working
126 legacy versions
127
128 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
129
130 pve-firewall (4.0-1) pve; urgency=medium
131
132 * re-build for Debian Buster / PVE 6
133
134 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
135
136 pve-firewall (3.0-21) unstable; urgency=medium
137
138 * fix ipv6 PVEFW-reject
139
140 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
141 ebtables doing the wrong thing here
142
143 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
144
145 pve-firewall (3.0-20) unstable; urgency=medium
146
147 * use IPCC to read config and rule files, if the are backed by pmxcfs which
148 has better handling for pmxcfs restarts
149
150 * fix #2178: endless loop on ipv6 extension headers
151
152 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
153
154 pve-firewall (3.0-19) unstable; urgency=medium
155
156 * ebtables: add arp filtering
157
158 * fix: #2123 Logging of user defined firewall rules
159
160 * fix Razor macro
161
162 * allow to enable/disable and modify cluster wide log ratelimits
163
164 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
165
166 pve-firewall (3.0-18) unstable; urgency=medium
167
168 * fix #1606: Add nf_conntrack_allow_invalid option
169
170 * log reject : add space after policy REJECT like drop
171
172 * fix #1891: Add zsh command completion for pve-firewall
173
174 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
175
176 pve-firewall (3.0-17) unstable; urgency=medium
177
178 * fix #2005: only allow ascii port digits
179
180 * fix #2004: do not allow backwards ranges
181
182 * add conntrack logging via libnetfilter_conntrack and allow one to enable
183 it through the firewall host configuration
184
185 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
186
187 pve-firewall (3.0-16) unstable; urgency=medium
188
189 * api/rules: fix macro return type
190
191 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
192
193 pve-firewall (3.0-15) unstable; urgency=medium
194
195 * fix #1971: display firewall rule properties
196
197 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
198
199 pve-firewall (3.0-14) unstable; urgency=medium
200
201 * fix #1841: avoid ebtable reloads when containers have multiple network
202 interfaces
203
204 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
205
206 pve-firewall (3.0-13) unstable; urgency=medium
207
208 * avoid unnecessary reloads of ebtable ruleset
209
210 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
211
212 pve-firewall (3.0-12) unstable; urgency=medium
213
214 * fix deleted iptables chains not being properly detected as a change
215
216 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
217
218 pve-firewall (3.0-11) unstable; urgency=medium
219
220 * #1764: rename 'ebtales_enable' option to 'ebtables'
221
222 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
223
224 pve-firewall (3.0-10) unstable; urgency=medium
225
226 * fix #1764: handle existing ebtables rules and allow disabling ebtables
227
228 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
229 ebtables_enable option.
230
231 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
232
233 pve-firewall (3.0-9) unstable; urgency=medium
234
235 * fix creation of ebltables FORWARD rule entry
236
237 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
238
239 pve-firewall (3.0-8) unstable; urgency=medium
240
241 * add ebtables support for better MAC filtering
242
243 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
244
245 pve-firewall (3.0-7) unstable; urgency=medium
246
247 * support distinct source and destination multi-port matching
248
249 * multi-port matching: when specifying the same list of ports for source and
250 destination require them both to match, rather than one of them, as this
251 was rather unexpected behavior
252
253 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
254
255 pve-firewall (3.0-6) unstable; urgency=medium
256
257 * fix #1319: don't fail postinst with masked service
258
259 * debian: switch to compat 9, drop init scripts, drop preinst
260
261 * check multiport limit in port ranges
262
263 * build: use git rev-parse for GITVERSION
264
265 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
266
267 pve-firewall (3.0-5) unstable; urgency=medium
268
269 * fix issue with disabled flag not being honored within groups
270
271 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
272
273 pve-firewall (3.0-4) unstable; urgency=medium
274
275 * fix issues with ipsets reloading unnecessarily or too late
276
277 * fix some typos in the logs
278
279 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
280
281 pve-firewall (3.0-3) unstable; urgency=medium
282
283 * Fix #1492: logger: use current timestamp if the packet doesn't have one
284
285 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
286
287 pve-firewall (3.0-2) unstable; urgency=medium
288
289 * Fix #1446: remove masks in case the package had previously been removed but
290 not purged.
291
292 * improve logging on errors in the firewall configuration
293
294 * forbid trailing commas in lists as iptables-restore doesn't support them
295
296 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
297
298 pve-firewall (3.0-1) unstable; urgency=medium
299
300 * rebuild for Debian Stretch
301
302 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
303
304 pve-firewall (2.0-33) unstable; urgency=medium
305
306 * ipset: don't allow zero-prefix entries
307
308 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
309
310 pve-firewall (2.0-32) unstable; urgency=medium
311
312 * improve search for local-network
313
314 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
315
316 pve-firewall (2.0-31) unstable; urgency=medium
317
318 * don't try to apply ports to rules which don't support them
319
320 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
321
322 pve-firewall (2.0-30) unstable; urgency=medium
323
324 * add multicast DNS to the list of Macros
325
326 * add missing parameter descriptions
327
328 * build-depends: add dh-systemd
329
330 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
331
332 pve-firewall (2.0-29) unstable; urgency=medium
333
334 * prevent overwriting ipsets/sec. groups by renaming
335
336 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
337
338 pve-firewall (2.0-28) unstable; urgency=medium
339
340 * use pve-common's ipv4_mask_hash_localnet
341
342 * fix allowed group name length
343
344 * make group digest stable
345
346 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
347
348 pve-firewall (2.0-27) unstable; urgency=medium
349
350 * fix #972: make PVEFW-FWBR-* rule order stable
351
352 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
353
354 pve-firewall (2.0-26) unstable; urgency=medium
355
356 * fix #988: set rp_filter=2
357
358 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
359
360 pve-firewall (2.0-25) unstable; urgency=medium
361
362 * fix #945: add uninitialized check in lxc ipset compilation
363
364 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
365
366 pve-firewall (2.0-24) unstable; urgency=medium
367
368 * Build-Depend on pve-doc-generator
369
370 * generate manpage with pve-doc-generator
371
372 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
373
374 pve-firewall (2.0-23) unstable; urgency=medium
375
376 * use only the top bit for our accept marks
377
378 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
379
380 pve-firewall (2.0-22) unstable; urgency=medium
381
382 * Use cfs_config_path from PVE::QemuConfig
383
384 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
385
386 pve-firewall (2.0-21) unstable; urgency=medium
387
388 * added new 'ipfilter' option
389
390 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
391
392 pve-firewall (2.0-20) unstable; urgency=medium
393
394 * fix 901: encode unicode characters in sha digest
395
396 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
397
398 pve-firewall (2.0-19) unstable; urgency=medium
399
400 * Add radv option to VM options
401
402 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
403
404 pve-firewall (2.0-18) unstable; urgency=medium
405
406 * Add ndp option to host and VM firewall options
407
408 * Add router-solicitation to NeighborDiscovery macro
409
410 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
411
412 pve-firewall (2.0-17) unstable; urgency=medium
413
414 * Don't leave empty FW config files behind
415
416 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
417
418 pve-firewall (2.0-16) unstable; urgency=medium
419
420 * logger: basic ipv6 support
421
422 * add DHCPv6 macro
423
424 * add dhcpv6 support to the dhcp option
425
426 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
427
428 pve-firewall (2.0-15) unstable; urgency=medium
429
430 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
431
432 * fix some regular expressions mixups
433
434 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
435
436 pve-firewall (2.0-14) unstable; urgency=medium
437
438 * fix systemd service dependencies
439
440 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
441
442 pve-firewall (2.0-13) unstable; urgency=medium
443
444 * allow numeric icmp types
445
446 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
447
448 pve-firewall (2.0-12) unstable; urgency=medium
449
450 * implement bash completions
451
452 * convert pve-firewall into a PVE::Service class
453
454 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
455
456 pve-firewall (2.0-11) unstable; urgency=medium
457
458 * iptables_get_chains: fix veth device name
459
460 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
461
462 pve-firewall (2.0-10) unstable; urgency=medium
463
464 * new helper: clone_vmfw_conf()
465
466 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
467
468 pve-firewall (2.0-9) unstable; urgency=medium
469
470 * remove firewall config file subroutine added
471
472 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
473
474 pve-firewall (2.0-8) unstable; urgency=medium
475
476 * adopt regresion tests for lxc containers
477
478 * removed firewall code for openVZ
479
480 * Subroutine verify_rule fixed to correctly check only for "net\d+"
481 interface device names
482
483 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
484
485 pve-firewall (2.0-7) unstable; urgency=medium
486
487 * added firewall code for lxc
488
489 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
490
491 pve-firewall (2.0-6) unstable; urgency=medium
492
493 * firewall ipversion comparison fix
494
495 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
496
497 pve-firewall (2.0-5) unstable; urgency=medium
498
499 * add ipv6 neighbor discovery and solicitation macros
500
501 * ip6tables accepts both spellings of the word neighbor
502
503 * added Ceph macro
504
505 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
506
507 pve-firewall (2.0-4) unstable; urgency=medium
508
509 * include manual page for pve-firewall
510
511 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
512
513 pve-firewall (2.0-3) unstable; urgency=medium
514
515 * use noawait trigers for pve-api-updates
516
517 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
518
519 pve-firewall (2.0-2) unstable; urgency=medium
520
521 * trigger pve-api-updates event
522
523 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
524
525 pve-firewall (2.0-1) unstable; urgency=medium
526
527 * recompile for debian jessie
528
529 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
530
531 pve-firewall (1.0-18) unstable; urgency=low
532
533 * fix alias lookup
534
535 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
536
537 pve-firewall (1.0-17) unstable; urgency=low
538
539 * fix restart behavior
540
541 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
542
543 pve-firewall (1.0-16) unstable; urgency=low
544
545 * use new Daemon class from pve-common
546
547 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
548
549 pve-firewall (1.0-15) unstable; urgency=low
550
551 * bug fix: load cluster conf for host rules
552
553 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
554
555 pve-firewall (1.0-14) unstable; urgency=low
556
557 * do not use ipset list chains
558
559 * remove preinst script (not needed anymore)
560
561 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
562
563 pve-firewall (1.0-13) unstable; urgency=low
564
565 * fix ipset remove order
566
567 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
568
569 pve-firewall (1.0-12) unstable; urgency=low
570
571 * add preinst script to clear ipset from older installation (because
572 sets cannot be swapped if there type does not match.
573
574 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
575
576 pve-firewall (1.0-11) unstable; urgency=low
577
578 * bug fix: correctly set ipversion for aliases in verify_rule
579
580 * save restore commands into files to make debugging
581 easier (/var/lib/pve-firewall/)
582
583 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
584
585 pve-firewall (1.0-10) unstable; urgency=low
586
587 * add IPv6 support for VMs (hostfw is IPv4 only)
588
589 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
590
591 pve-firewall (1.0-9) unstable; urgency=low
592
593 * fix max ipset name name length
594
595 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
596
597 pve-firewall (1.0-8) unstable; urgency=low
598
599 * implement permission
600
601 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
602
603 pve-firewall (1.0-7) unstable; urgency=low
604
605 * proxy host rule API calls to correct node
606
607 * always generate MAC and IP filter rules if firewall is enabled on NIC
608
609 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
610
611 pve-firewall (1.0-6) unstable; urgency=low
612
613 * ipmlement ipfilter ipsets
614
615 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
616
617 pve-firewall (1.0-5) unstable; urgency=low
618
619 * remove ipsets when firewall disabled
620
621 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
622
623 pve-firewall (1.0-4) unstable; urgency=low
624
625 * depend on iptables and ipset
626
627 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
628
629 pve-firewall (1.0-3) unstable; urgency=low
630
631 * change dh_installinit order (register pvefw-logger before pve-firewall)
632
633 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
634
635 pve-firewall (1.0-2) unstable; urgency=low
636
637 * add experimental nflog logging daemon
638
639 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
640
641 pve-firewall (1.0-1) unstable; urgency=low
642
643 * initial package
644
645 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
646