+pve-firewall (3.0-21) unstable; urgency=medium
+
+ * fix ipv6 PVEFW-reject
+
+ * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
+ ebtables doing the wrong thing here
+
+ -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
+
+pve-firewall (3.0-20) unstable; urgency=medium
+
+ * use IPCC to read config and rule files, if the are backed by pmxcfs which
+ has better handling for pmxcfs restarts
+
+ * fix #2178: endless loop on ipv6 extension headers
+
+ -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
+
+pve-firewall (3.0-19) unstable; urgency=medium
+
+ * ebtables: add arp filtering
+
+ * fix: #2123 Logging of user defined firewall rules
+
+ * fix Razor macro
+
+ * allow to enable/disable and modify cluster wide log ratelimits
+
+ -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
+
+pve-firewall (3.0-18) unstable; urgency=medium
+
+ * fix #1606: Add nf_conntrack_allow_invalid option
+
+ * log reject : add space after policy REJECT like drop
+
+ * fix #1891: Add zsh command completion for pve-firewall
+
+ -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
+
+pve-firewall (3.0-17) unstable; urgency=medium
+
+ * fix #2005: only allow ascii port digits
+
+ * fix #2004: do not allow backwards ranges
+
+ * add conntrack logging via libnetfilter_conntrack and allow one to enable
+ it through the firewall host configuration
+
+ -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
+
+pve-firewall (3.0-16) unstable; urgency=medium
+
+ * api/rules: fix macro return type
+
+ -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
+
+pve-firewall (3.0-15) unstable; urgency=medium
+
+ * fix #1971: display firewall rule properties
+
+ -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
+
+pve-firewall (3.0-14) unstable; urgency=medium
+
+ * fix #1841: avoid ebtable reloads when containers have multiple network
+ interfaces
+
+ -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
+
+pve-firewall (3.0-13) unstable; urgency=medium
+
+ * avoid unnecessary reloads of ebtable ruleset
+
+ -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
+
+pve-firewall (3.0-12) unstable; urgency=medium
+
+ * fix deleted iptables chains not being properly detected as a change
+
+ -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
+
+pve-firewall (3.0-11) unstable; urgency=medium
+
+ * #1764: rename 'ebtales_enable' option to 'ebtables'
+
+ -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
+
+pve-firewall (3.0-10) unstable; urgency=medium
+
+ * fix #1764: handle existing ebtables rules and allow disabling ebtables
+
+ * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
+ ebtables_enable option.
+
+ -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
+
+pve-firewall (3.0-9) unstable; urgency=medium
+
+ * fix creation of ebltables FORWARD rule entry
+
+ -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
+
+pve-firewall (3.0-8) unstable; urgency=medium
+
+ * add ebtables support for better MAC filtering
+
+ -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
+
+pve-firewall (3.0-7) unstable; urgency=medium
+
+ * support distinct source and destination multi-port matching
+
+ * multi-port matching: when specifying the same list of ports for source and
+ destination require them both to match, rather than one of them, as this
+ was rather unexpected behavior
+
+ -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
+