]> git.proxmox.com Git - pve-firewall.git/blame - debian/changelog
rename ebtables_enable to ebtables
[pve-firewall.git] / debian / changelog
CommitLineData
423b86ef
WB
1pve-firewall (3.0-10) unstable; urgency=medium
2
3 * fix #1764: handle existing ebtables rules and allow disabling ebtables
4
5 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
6 ebtables_enable option.
7
8 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
9
567e58ce
WB
10pve-firewall (3.0-9) unstable; urgency=medium
11
12 * fix creation of ebltables FORWARD rule entry
13
14 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
15
ea0d59ed
WB
16pve-firewall (3.0-8) unstable; urgency=medium
17
18 * add ebtables support for better MAC filtering
19
20 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
21
9a19ec81
WB
22pve-firewall (3.0-7) unstable; urgency=medium
23
24 * support distinct source and destination multi-port matching
25
26 * multi-port matching: when specifying the same list of ports for source and
27 destination require them both to match, rather than one of them, as this
28 was rather unexpected behavior
29
30 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
31
8c41d444
DM
32pve-firewall (3.0-6) unstable; urgency=medium
33
34 * fix #1319: don't fail postinst with masked service
35
36 * debian: switch to compat 9, drop init scripts, drop preinst
37
38 * check multiport limit in port ranges
39
40 * build: use git rev-parse for GITVERSION
41
42 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
43
4299c35f
WB
44pve-firewall (3.0-5) unstable; urgency=medium
45
46 * fix issue with disabled flag not being honored within groups
47
48 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
49
a19d4127
WB
50pve-firewall (3.0-4) unstable; urgency=medium
51
52 * fix issues with ipsets reloading unnecessarily or too late
53
54 * fix some typos in the logs
55
56 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
57
c0c71b1b
WB
58pve-firewall (3.0-3) unstable; urgency=medium
59
60 * Fix #1492: logger: use current timestamp if the packet doesn't have one
61
62 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
63
4f7a4bdd
WB
64pve-firewall (3.0-2) unstable; urgency=medium
65
66 * Fix #1446: remove masks in case the package had previously been removed but
67 not purged.
68
69 * improve logging on errors in the firewall configuration
70
71 * forbid trailing commas in lists as iptables-restore doesn't support them
72
73 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
74
29a94c79
FG
75pve-firewall (3.0-1) unstable; urgency=medium
76
77 * rebuild for Debian Stretch
78
79 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
80
df67a3dc
DM
81pve-firewall (2.0-33) unstable; urgency=medium
82
83 * ipset: don't allow zero-prefix entries
84
85 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
86
dc643b4d
DM
87pve-firewall (2.0-32) unstable; urgency=medium
88
89 * improve search for local-network
90
91 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
92
45f206fd
DM
93pve-firewall (2.0-31) unstable; urgency=medium
94
95 * don't try to apply ports to rules which don't support them
96
97 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
98
2ea28d0c
DM
99pve-firewall (2.0-30) unstable; urgency=medium
100
101 * add multicast DNS to the list of Macros
102
103 * add missing parameter descriptions
104
105 * build-depends: add dh-systemd
106
107 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
108
b65d13d9
DM
109pve-firewall (2.0-29) unstable; urgency=medium
110
111 * prevent overwriting ipsets/sec. groups by renaming
112
113 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
114
d0f3bb08
DM
115pve-firewall (2.0-28) unstable; urgency=medium
116
117 * use pve-common's ipv4_mask_hash_localnet
118
5c53cde4
DC
119 * fix allowed group name length
120
121 * make group digest stable
122
d0f3bb08
DM
123 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
124
76a57e1a
DM
125pve-firewall (2.0-27) unstable; urgency=medium
126
127 * fix #972: make PVEFW-FWBR-* rule order stable
128
129 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
130
17642172
DM
131pve-firewall (2.0-26) unstable; urgency=medium
132
133 * fix #988: set rp_filter=2
134
135 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
136
6e29af12
DM
137pve-firewall (2.0-25) unstable; urgency=medium
138
139 * fix #945: add uninitialized check in lxc ipset compilation
140
141 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
142
edb4aff5
DM
143pve-firewall (2.0-24) unstable; urgency=medium
144
145 * Build-Depend on pve-doc-generator
146
147 * generate manpage with pve-doc-generator
148
149 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
150
e1158c15
DM
151pve-firewall (2.0-23) unstable; urgency=medium
152
153 * use only the top bit for our accept marks
154
155 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
156
5399f912
DM
157pve-firewall (2.0-22) unstable; urgency=medium
158
159 * Use cfs_config_path from PVE::QemuConfig
160
161 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
162
b9e73915
DM
163pve-firewall (2.0-21) unstable; urgency=medium
164
165 * added new 'ipfilter' option
166
167 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
168
e2a49003
DM
169pve-firewall (2.0-20) unstable; urgency=medium
170
171 * fix 901: encode unicode characters in sha digest
172
173 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
174
1d10f89a
DM
175pve-firewall (2.0-19) unstable; urgency=medium
176
177 * Add radv option to VM options
178
179 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
180
666093cd
DM
181pve-firewall (2.0-18) unstable; urgency=medium
182
183 * Add ndp option to host and VM firewall options
184
185 * Add router-solicitation to NeighborDiscovery macro
186
187 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
188
eaf25885
DM
189pve-firewall (2.0-17) unstable; urgency=medium
190
191 * Don't leave empty FW config files behind
192
193 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
194
a177fb07
DM
195pve-firewall (2.0-16) unstable; urgency=medium
196
197 * logger: basic ipv6 support
198
199 * add DHCPv6 macro
200
201 * add dhcpv6 support to the dhcp option
202
203 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
204
ab1b8d3c
DM
205pve-firewall (2.0-15) unstable; urgency=medium
206
207 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
208
209 * fix some regular expressions mixups
210
211 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
212
c9c8d7a3
DM
213pve-firewall (2.0-14) unstable; urgency=medium
214
215 * fix systemd service dependencies
216
217 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
218
aa818ae7
DM
219pve-firewall (2.0-13) unstable; urgency=medium
220
221 * allow numeric icmp types
222
223 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
224
8dbebe7d
DM
225pve-firewall (2.0-12) unstable; urgency=medium
226
227 * implement bash completions
228
229 * convert pve-firewall into a PVE::Service class
230
231 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
232
47704f4c
DM
233pve-firewall (2.0-11) unstable; urgency=medium
234
235 * iptables_get_chains: fix veth device name
236
237 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
238
9eb84dc7
DM
239pve-firewall (2.0-10) unstable; urgency=medium
240
241 * new helper: clone_vmfw_conf()
242
243 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
244
a3d34dac
DM
245pve-firewall (2.0-9) unstable; urgency=medium
246
247 * remove firewall config file subroutine added
248
249 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
250
2a42a237
DM
251pve-firewall (2.0-8) unstable; urgency=medium
252
253 * adopt regresion tests for lxc containers
254
255 * removed firewall code for openVZ
256
257 * Subroutine verify_rule fixed to correctly check only for "net\d+"
258 interface device names
259
260 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
261
33448a6e
DM
262pve-firewall (2.0-7) unstable; urgency=medium
263
264 * added firewall code for lxc
265
266 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
267
19f14465
DM
268pve-firewall (2.0-6) unstable; urgency=medium
269
270 * firewall ipversion comparison fix
271
272 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
273
8feec9fa
DM
274pve-firewall (2.0-5) unstable; urgency=medium
275
276 * add ipv6 neighbor discovery and solicitation macros
277
278 * ip6tables accepts both spellings of the word neighbor
279
280 * added Ceph macro
281
282 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
283
e02c77aa
DM
284pve-firewall (2.0-4) unstable; urgency=medium
285
286 * include manual page for pve-firewall
287
288 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
289
eb4a2902
DM
290pve-firewall (2.0-3) unstable; urgency=medium
291
292 * use noawait trigers for pve-api-updates
293
294 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
295
56bb2e69
DM
296pve-firewall (2.0-2) unstable; urgency=medium
297
298 * trigger pve-api-updates event
299
300 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
301
0b18ebe8
DM
302pve-firewall (2.0-1) unstable; urgency=medium
303
304 * recompile for debian jessie
305
306 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
307
609f00c7
DM
308pve-firewall (1.0-18) unstable; urgency=low
309
310 * fix alias lookup
311
312 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
313
de48e659
DM
314pve-firewall (1.0-17) unstable; urgency=low
315
316 * fix restart behavior
317
318 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
319
b92d2ed2
DM
320pve-firewall (1.0-16) unstable; urgency=low
321
322 * use new Daemon class from pve-common
323
324 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
325
22dde8d6
DM
326pve-firewall (1.0-15) unstable; urgency=low
327
328 * bug fix: load cluster conf for host rules
329
330 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
331
e33e2f16
DM
332pve-firewall (1.0-14) unstable; urgency=low
333
334 * do not use ipset list chains
335
336 * remove preinst script (not needed anymore)
337
338 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
339
3bce273b
DM
340pve-firewall (1.0-13) unstable; urgency=low
341
342 * fix ipset remove order
343
344 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
345
7a7c322c
DM
346pve-firewall (1.0-12) unstable; urgency=low
347
348 * add preinst script to clear ipset from older installation (because
349 sets cannot be swapped if there type does not match.
ce41ae23 350
7a7c322c
DM
351 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
352
1b918ee5
DM
353pve-firewall (1.0-11) unstable; urgency=low
354
355 * bug fix: correctly set ipversion for aliases in verify_rule
356
357 * save restore commands into files to make debugging
358 easier (/var/lib/pve-firewall/)
359
360 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
361
df617cea
DM
362pve-firewall (1.0-10) unstable; urgency=low
363
364 * add IPv6 support for VMs (hostfw is IPv4 only)
365
366 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
367
0ac57570
DM
368pve-firewall (1.0-9) unstable; urgency=low
369
370 * fix max ipset name name length
371
372 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
373
05fd3b63
DM
374pve-firewall (1.0-8) unstable; urgency=low
375
376 * implement permission
377
378 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
379
bea9d5ab
DM
380pve-firewall (1.0-7) unstable; urgency=low
381
382 * proxy host rule API calls to correct node
a34cfdd0
DM
383
384 * always generate MAC and IP filter rules if firewall is enabled on NIC
bea9d5ab
DM
385
386 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
387
582275c3
DM
388pve-firewall (1.0-6) unstable; urgency=low
389
390 * ipmlement ipfilter ipsets
391
392 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
393
de0c1e49
DM
394pve-firewall (1.0-5) unstable; urgency=low
395
396 * remove ipsets when firewall disabled
397
398 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
399
64c266f5
DM
400pve-firewall (1.0-4) unstable; urgency=low
401
402 * depend on iptables and ipset
403
404 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
405
16bcfa8b
DM
406pve-firewall (1.0-3) unstable; urgency=low
407
408 * change dh_installinit order (register pvefw-logger before pve-firewall)
409
410 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
411
ba0b3a0a
DM
412pve-firewall (1.0-2) unstable; urgency=low
413
414 * add experimental nflog logging daemon
415
416 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
417
bb272dd3
DM
418pve-firewall (1.0-1) unstable; urgency=low
419
420 * initial package
421
422 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
423