]> git.proxmox.com Git - pve-firewall.git/blame - debian/changelog
bump version to 3.0-22
[pve-firewall.git] / debian / changelog
CommitLineData
489f9bf6
TL
1pve-firewall (3.0-22) unstable; urgency=medium
2
3 * fix IP Filter rule generation for Container
4
5 * fix redundant logging of packets passing the tap chain
6
7 -- Proxmox Support Team <support@proxmox.com> Tue, 28 May 2019 08:22:23 +0200
8
dd7d737b
TL
9pve-firewall (3.0-21) unstable; urgency=medium
10
11 * fix ipv6 PVEFW-reject
12
13 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
14 ebtables doing the wrong thing here
15
16 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
17
bbf77725
TL
18pve-firewall (3.0-20) unstable; urgency=medium
19
20 * use IPCC to read config and rule files, if the are backed by pmxcfs which
21 has better handling for pmxcfs restarts
22
23 * fix #2178: endless loop on ipv6 extension headers
24
25 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
26
baba607a
TL
27pve-firewall (3.0-19) unstable; urgency=medium
28
29 * ebtables: add arp filtering
30
31 * fix: #2123 Logging of user defined firewall rules
32
33 * fix Razor macro
34
35 * allow to enable/disable and modify cluster wide log ratelimits
36
37 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
38
d8ea08e3
TL
39pve-firewall (3.0-18) unstable; urgency=medium
40
41 * fix #1606: Add nf_conntrack_allow_invalid option
42
43 * log reject : add space after policy REJECT like drop
44
45 * fix #1891: Add zsh command completion for pve-firewall
46
47 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
48
91d88bc5
TL
49pve-firewall (3.0-17) unstable; urgency=medium
50
51 * fix #2005: only allow ascii port digits
52
53 * fix #2004: do not allow backwards ranges
54
55 * add conntrack logging via libnetfilter_conntrack and allow one to enable
56 it through the firewall host configuration
57
58 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
59
81d13a9d
TL
60pve-firewall (3.0-16) unstable; urgency=medium
61
62 * api/rules: fix macro return type
63
64 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
65
bed701bc
TL
66pve-firewall (3.0-15) unstable; urgency=medium
67
68 * fix #1971: display firewall rule properties
69
70 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
71
a24b157b
WB
72pve-firewall (3.0-14) unstable; urgency=medium
73
74 * fix #1841: avoid ebtable reloads when containers have multiple network
75 interfaces
76
77 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
78
cf7dd94b
WB
79pve-firewall (3.0-13) unstable; urgency=medium
80
81 * avoid unnecessary reloads of ebtable ruleset
82
83 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
84
dd03bf6e
WB
85pve-firewall (3.0-12) unstable; urgency=medium
86
87 * fix deleted iptables chains not being properly detected as a change
88
89 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
90
587a0f20 91pve-firewall (3.0-11) unstable; urgency=medium
a3a51dad
TL
92
93 * #1764: rename 'ebtales_enable' option to 'ebtables'
94
587a0f20 95 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
a3a51dad 96
423b86ef
WB
97pve-firewall (3.0-10) unstable; urgency=medium
98
99 * fix #1764: handle existing ebtables rules and allow disabling ebtables
100
101 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
102 ebtables_enable option.
103
104 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
105
567e58ce
WB
106pve-firewall (3.0-9) unstable; urgency=medium
107
108 * fix creation of ebltables FORWARD rule entry
109
110 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
111
ea0d59ed
WB
112pve-firewall (3.0-8) unstable; urgency=medium
113
114 * add ebtables support for better MAC filtering
115
116 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
117
9a19ec81
WB
118pve-firewall (3.0-7) unstable; urgency=medium
119
120 * support distinct source and destination multi-port matching
121
122 * multi-port matching: when specifying the same list of ports for source and
123 destination require them both to match, rather than one of them, as this
124 was rather unexpected behavior
125
126 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
127
8c41d444
DM
128pve-firewall (3.0-6) unstable; urgency=medium
129
130 * fix #1319: don't fail postinst with masked service
131
132 * debian: switch to compat 9, drop init scripts, drop preinst
133
134 * check multiport limit in port ranges
135
136 * build: use git rev-parse for GITVERSION
137
138 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
139
4299c35f
WB
140pve-firewall (3.0-5) unstable; urgency=medium
141
142 * fix issue with disabled flag not being honored within groups
143
144 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
145
a19d4127
WB
146pve-firewall (3.0-4) unstable; urgency=medium
147
148 * fix issues with ipsets reloading unnecessarily or too late
149
150 * fix some typos in the logs
151
152 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
153
c0c71b1b
WB
154pve-firewall (3.0-3) unstable; urgency=medium
155
156 * Fix #1492: logger: use current timestamp if the packet doesn't have one
157
158 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
159
4f7a4bdd
WB
160pve-firewall (3.0-2) unstable; urgency=medium
161
162 * Fix #1446: remove masks in case the package had previously been removed but
163 not purged.
164
165 * improve logging on errors in the firewall configuration
166
167 * forbid trailing commas in lists as iptables-restore doesn't support them
168
169 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
170
29a94c79
FG
171pve-firewall (3.0-1) unstable; urgency=medium
172
173 * rebuild for Debian Stretch
174
175 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
176
df67a3dc
DM
177pve-firewall (2.0-33) unstable; urgency=medium
178
179 * ipset: don't allow zero-prefix entries
180
181 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
182
dc643b4d
DM
183pve-firewall (2.0-32) unstable; urgency=medium
184
185 * improve search for local-network
186
187 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
188
45f206fd
DM
189pve-firewall (2.0-31) unstable; urgency=medium
190
191 * don't try to apply ports to rules which don't support them
192
193 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
194
2ea28d0c
DM
195pve-firewall (2.0-30) unstable; urgency=medium
196
197 * add multicast DNS to the list of Macros
198
199 * add missing parameter descriptions
200
201 * build-depends: add dh-systemd
202
203 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
204
b65d13d9
DM
205pve-firewall (2.0-29) unstable; urgency=medium
206
207 * prevent overwriting ipsets/sec. groups by renaming
208
209 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
210
d0f3bb08
DM
211pve-firewall (2.0-28) unstable; urgency=medium
212
213 * use pve-common's ipv4_mask_hash_localnet
214
5c53cde4
DC
215 * fix allowed group name length
216
217 * make group digest stable
218
d0f3bb08
DM
219 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
220
76a57e1a
DM
221pve-firewall (2.0-27) unstable; urgency=medium
222
223 * fix #972: make PVEFW-FWBR-* rule order stable
224
225 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
226
17642172
DM
227pve-firewall (2.0-26) unstable; urgency=medium
228
229 * fix #988: set rp_filter=2
230
231 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
232
6e29af12
DM
233pve-firewall (2.0-25) unstable; urgency=medium
234
235 * fix #945: add uninitialized check in lxc ipset compilation
236
237 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
238
edb4aff5
DM
239pve-firewall (2.0-24) unstable; urgency=medium
240
241 * Build-Depend on pve-doc-generator
242
243 * generate manpage with pve-doc-generator
244
245 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
246
e1158c15
DM
247pve-firewall (2.0-23) unstable; urgency=medium
248
249 * use only the top bit for our accept marks
250
251 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
252
5399f912
DM
253pve-firewall (2.0-22) unstable; urgency=medium
254
255 * Use cfs_config_path from PVE::QemuConfig
256
257 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
258
b9e73915
DM
259pve-firewall (2.0-21) unstable; urgency=medium
260
261 * added new 'ipfilter' option
262
263 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
264
e2a49003
DM
265pve-firewall (2.0-20) unstable; urgency=medium
266
267 * fix 901: encode unicode characters in sha digest
268
269 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
270
1d10f89a
DM
271pve-firewall (2.0-19) unstable; urgency=medium
272
273 * Add radv option to VM options
274
275 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
276
666093cd
DM
277pve-firewall (2.0-18) unstable; urgency=medium
278
279 * Add ndp option to host and VM firewall options
280
281 * Add router-solicitation to NeighborDiscovery macro
282
283 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
284
eaf25885
DM
285pve-firewall (2.0-17) unstable; urgency=medium
286
287 * Don't leave empty FW config files behind
288
289 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
290
a177fb07
DM
291pve-firewall (2.0-16) unstable; urgency=medium
292
293 * logger: basic ipv6 support
294
295 * add DHCPv6 macro
296
297 * add dhcpv6 support to the dhcp option
298
299 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
300
ab1b8d3c
DM
301pve-firewall (2.0-15) unstable; urgency=medium
302
303 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
304
305 * fix some regular expressions mixups
306
307 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
308
c9c8d7a3
DM
309pve-firewall (2.0-14) unstable; urgency=medium
310
311 * fix systemd service dependencies
312
313 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
314
aa818ae7
DM
315pve-firewall (2.0-13) unstable; urgency=medium
316
317 * allow numeric icmp types
318
319 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
320
8dbebe7d
DM
321pve-firewall (2.0-12) unstable; urgency=medium
322
323 * implement bash completions
324
325 * convert pve-firewall into a PVE::Service class
326
327 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
328
47704f4c
DM
329pve-firewall (2.0-11) unstable; urgency=medium
330
331 * iptables_get_chains: fix veth device name
332
333 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
334
9eb84dc7
DM
335pve-firewall (2.0-10) unstable; urgency=medium
336
337 * new helper: clone_vmfw_conf()
338
339 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
340
a3d34dac
DM
341pve-firewall (2.0-9) unstable; urgency=medium
342
343 * remove firewall config file subroutine added
344
345 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
346
2a42a237
DM
347pve-firewall (2.0-8) unstable; urgency=medium
348
349 * adopt regresion tests for lxc containers
350
351 * removed firewall code for openVZ
352
353 * Subroutine verify_rule fixed to correctly check only for "net\d+"
354 interface device names
355
356 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
357
33448a6e
DM
358pve-firewall (2.0-7) unstable; urgency=medium
359
360 * added firewall code for lxc
361
362 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
363
19f14465
DM
364pve-firewall (2.0-6) unstable; urgency=medium
365
366 * firewall ipversion comparison fix
367
368 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
369
8feec9fa
DM
370pve-firewall (2.0-5) unstable; urgency=medium
371
372 * add ipv6 neighbor discovery and solicitation macros
373
374 * ip6tables accepts both spellings of the word neighbor
375
376 * added Ceph macro
377
378 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
379
e02c77aa
DM
380pve-firewall (2.0-4) unstable; urgency=medium
381
382 * include manual page for pve-firewall
383
384 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
385
eb4a2902
DM
386pve-firewall (2.0-3) unstable; urgency=medium
387
388 * use noawait trigers for pve-api-updates
389
390 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
391
56bb2e69
DM
392pve-firewall (2.0-2) unstable; urgency=medium
393
394 * trigger pve-api-updates event
395
396 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
397
0b18ebe8
DM
398pve-firewall (2.0-1) unstable; urgency=medium
399
400 * recompile for debian jessie
401
402 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
403
609f00c7
DM
404pve-firewall (1.0-18) unstable; urgency=low
405
406 * fix alias lookup
407
408 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
409
de48e659
DM
410pve-firewall (1.0-17) unstable; urgency=low
411
412 * fix restart behavior
413
414 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
415
b92d2ed2
DM
416pve-firewall (1.0-16) unstable; urgency=low
417
418 * use new Daemon class from pve-common
419
420 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
421
22dde8d6
DM
422pve-firewall (1.0-15) unstable; urgency=low
423
424 * bug fix: load cluster conf for host rules
425
426 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
427
e33e2f16
DM
428pve-firewall (1.0-14) unstable; urgency=low
429
430 * do not use ipset list chains
431
432 * remove preinst script (not needed anymore)
433
434 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
435
3bce273b
DM
436pve-firewall (1.0-13) unstable; urgency=low
437
438 * fix ipset remove order
439
440 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
441
7a7c322c
DM
442pve-firewall (1.0-12) unstable; urgency=low
443
444 * add preinst script to clear ipset from older installation (because
445 sets cannot be swapped if there type does not match.
ce41ae23 446
7a7c322c
DM
447 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
448
1b918ee5
DM
449pve-firewall (1.0-11) unstable; urgency=low
450
451 * bug fix: correctly set ipversion for aliases in verify_rule
452
453 * save restore commands into files to make debugging
454 easier (/var/lib/pve-firewall/)
455
456 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
457
df617cea
DM
458pve-firewall (1.0-10) unstable; urgency=low
459
460 * add IPv6 support for VMs (hostfw is IPv4 only)
461
462 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
463
0ac57570
DM
464pve-firewall (1.0-9) unstable; urgency=low
465
466 * fix max ipset name name length
467
468 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
469
05fd3b63
DM
470pve-firewall (1.0-8) unstable; urgency=low
471
472 * implement permission
473
474 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
475
bea9d5ab
DM
476pve-firewall (1.0-7) unstable; urgency=low
477
478 * proxy host rule API calls to correct node
a34cfdd0
DM
479
480 * always generate MAC and IP filter rules if firewall is enabled on NIC
bea9d5ab
DM
481
482 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
483
582275c3
DM
484pve-firewall (1.0-6) unstable; urgency=low
485
486 * ipmlement ipfilter ipsets
487
488 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
489
de0c1e49
DM
490pve-firewall (1.0-5) unstable; urgency=low
491
492 * remove ipsets when firewall disabled
493
494 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
495
64c266f5
DM
496pve-firewall (1.0-4) unstable; urgency=low
497
498 * depend on iptables and ipset
499
500 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
501
16bcfa8b
DM
502pve-firewall (1.0-3) unstable; urgency=low
503
504 * change dh_installinit order (register pvefw-logger before pve-firewall)
505
506 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
507
ba0b3a0a
DM
508pve-firewall (1.0-2) unstable; urgency=low
509
510 * add experimental nflog logging daemon
511
512 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
513
bb272dd3
DM
514pve-firewall (1.0-1) unstable; urgency=low
515
516 * initial package
517
518 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
519