]> git.proxmox.com Git - pve-firewall.git/blame - debian/changelog
Fix #1841: ebtables: sort interfaces per guest
[pve-firewall.git] / debian / changelog
CommitLineData
cf7dd94b
WB
1pve-firewall (3.0-13) unstable; urgency=medium
2
3 * avoid unnecessary reloads of ebtable ruleset
4
5 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
6
dd03bf6e
WB
7pve-firewall (3.0-12) unstable; urgency=medium
8
9 * fix deleted iptables chains not being properly detected as a change
10
11 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
12
587a0f20 13pve-firewall (3.0-11) unstable; urgency=medium
a3a51dad
TL
14
15 * #1764: rename 'ebtales_enable' option to 'ebtables'
16
587a0f20 17 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
a3a51dad 18
423b86ef
WB
19pve-firewall (3.0-10) unstable; urgency=medium
20
21 * fix #1764: handle existing ebtables rules and allow disabling ebtables
22
23 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
24 ebtables_enable option.
25
26 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
27
567e58ce
WB
28pve-firewall (3.0-9) unstable; urgency=medium
29
30 * fix creation of ebltables FORWARD rule entry
31
32 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
33
ea0d59ed
WB
34pve-firewall (3.0-8) unstable; urgency=medium
35
36 * add ebtables support for better MAC filtering
37
38 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
39
9a19ec81
WB
40pve-firewall (3.0-7) unstable; urgency=medium
41
42 * support distinct source and destination multi-port matching
43
44 * multi-port matching: when specifying the same list of ports for source and
45 destination require them both to match, rather than one of them, as this
46 was rather unexpected behavior
47
48 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
49
8c41d444
DM
50pve-firewall (3.0-6) unstable; urgency=medium
51
52 * fix #1319: don't fail postinst with masked service
53
54 * debian: switch to compat 9, drop init scripts, drop preinst
55
56 * check multiport limit in port ranges
57
58 * build: use git rev-parse for GITVERSION
59
60 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
61
4299c35f
WB
62pve-firewall (3.0-5) unstable; urgency=medium
63
64 * fix issue with disabled flag not being honored within groups
65
66 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
67
a19d4127
WB
68pve-firewall (3.0-4) unstable; urgency=medium
69
70 * fix issues with ipsets reloading unnecessarily or too late
71
72 * fix some typos in the logs
73
74 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
75
c0c71b1b
WB
76pve-firewall (3.0-3) unstable; urgency=medium
77
78 * Fix #1492: logger: use current timestamp if the packet doesn't have one
79
80 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
81
4f7a4bdd
WB
82pve-firewall (3.0-2) unstable; urgency=medium
83
84 * Fix #1446: remove masks in case the package had previously been removed but
85 not purged.
86
87 * improve logging on errors in the firewall configuration
88
89 * forbid trailing commas in lists as iptables-restore doesn't support them
90
91 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
92
29a94c79
FG
93pve-firewall (3.0-1) unstable; urgency=medium
94
95 * rebuild for Debian Stretch
96
97 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
98
df67a3dc
DM
99pve-firewall (2.0-33) unstable; urgency=medium
100
101 * ipset: don't allow zero-prefix entries
102
103 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
104
dc643b4d
DM
105pve-firewall (2.0-32) unstable; urgency=medium
106
107 * improve search for local-network
108
109 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
110
45f206fd
DM
111pve-firewall (2.0-31) unstable; urgency=medium
112
113 * don't try to apply ports to rules which don't support them
114
115 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
116
2ea28d0c
DM
117pve-firewall (2.0-30) unstable; urgency=medium
118
119 * add multicast DNS to the list of Macros
120
121 * add missing parameter descriptions
122
123 * build-depends: add dh-systemd
124
125 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
126
b65d13d9
DM
127pve-firewall (2.0-29) unstable; urgency=medium
128
129 * prevent overwriting ipsets/sec. groups by renaming
130
131 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
132
d0f3bb08
DM
133pve-firewall (2.0-28) unstable; urgency=medium
134
135 * use pve-common's ipv4_mask_hash_localnet
136
5c53cde4
DC
137 * fix allowed group name length
138
139 * make group digest stable
140
d0f3bb08
DM
141 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
142
76a57e1a
DM
143pve-firewall (2.0-27) unstable; urgency=medium
144
145 * fix #972: make PVEFW-FWBR-* rule order stable
146
147 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
148
17642172
DM
149pve-firewall (2.0-26) unstable; urgency=medium
150
151 * fix #988: set rp_filter=2
152
153 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
154
6e29af12
DM
155pve-firewall (2.0-25) unstable; urgency=medium
156
157 * fix #945: add uninitialized check in lxc ipset compilation
158
159 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
160
edb4aff5
DM
161pve-firewall (2.0-24) unstable; urgency=medium
162
163 * Build-Depend on pve-doc-generator
164
165 * generate manpage with pve-doc-generator
166
167 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
168
e1158c15
DM
169pve-firewall (2.0-23) unstable; urgency=medium
170
171 * use only the top bit for our accept marks
172
173 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
174
5399f912
DM
175pve-firewall (2.0-22) unstable; urgency=medium
176
177 * Use cfs_config_path from PVE::QemuConfig
178
179 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
180
b9e73915
DM
181pve-firewall (2.0-21) unstable; urgency=medium
182
183 * added new 'ipfilter' option
184
185 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
186
e2a49003
DM
187pve-firewall (2.0-20) unstable; urgency=medium
188
189 * fix 901: encode unicode characters in sha digest
190
191 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
192
1d10f89a
DM
193pve-firewall (2.0-19) unstable; urgency=medium
194
195 * Add radv option to VM options
196
197 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
198
666093cd
DM
199pve-firewall (2.0-18) unstable; urgency=medium
200
201 * Add ndp option to host and VM firewall options
202
203 * Add router-solicitation to NeighborDiscovery macro
204
205 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
206
eaf25885
DM
207pve-firewall (2.0-17) unstable; urgency=medium
208
209 * Don't leave empty FW config files behind
210
211 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
212
a177fb07
DM
213pve-firewall (2.0-16) unstable; urgency=medium
214
215 * logger: basic ipv6 support
216
217 * add DHCPv6 macro
218
219 * add dhcpv6 support to the dhcp option
220
221 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
222
ab1b8d3c
DM
223pve-firewall (2.0-15) unstable; urgency=medium
224
225 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
226
227 * fix some regular expressions mixups
228
229 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
230
c9c8d7a3
DM
231pve-firewall (2.0-14) unstable; urgency=medium
232
233 * fix systemd service dependencies
234
235 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
236
aa818ae7
DM
237pve-firewall (2.0-13) unstable; urgency=medium
238
239 * allow numeric icmp types
240
241 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
242
8dbebe7d
DM
243pve-firewall (2.0-12) unstable; urgency=medium
244
245 * implement bash completions
246
247 * convert pve-firewall into a PVE::Service class
248
249 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
250
47704f4c
DM
251pve-firewall (2.0-11) unstable; urgency=medium
252
253 * iptables_get_chains: fix veth device name
254
255 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
256
9eb84dc7
DM
257pve-firewall (2.0-10) unstable; urgency=medium
258
259 * new helper: clone_vmfw_conf()
260
261 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
262
a3d34dac
DM
263pve-firewall (2.0-9) unstable; urgency=medium
264
265 * remove firewall config file subroutine added
266
267 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
268
2a42a237
DM
269pve-firewall (2.0-8) unstable; urgency=medium
270
271 * adopt regresion tests for lxc containers
272
273 * removed firewall code for openVZ
274
275 * Subroutine verify_rule fixed to correctly check only for "net\d+"
276 interface device names
277
278 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
279
33448a6e
DM
280pve-firewall (2.0-7) unstable; urgency=medium
281
282 * added firewall code for lxc
283
284 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
285
19f14465
DM
286pve-firewall (2.0-6) unstable; urgency=medium
287
288 * firewall ipversion comparison fix
289
290 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
291
8feec9fa
DM
292pve-firewall (2.0-5) unstable; urgency=medium
293
294 * add ipv6 neighbor discovery and solicitation macros
295
296 * ip6tables accepts both spellings of the word neighbor
297
298 * added Ceph macro
299
300 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
301
e02c77aa
DM
302pve-firewall (2.0-4) unstable; urgency=medium
303
304 * include manual page for pve-firewall
305
306 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
307
eb4a2902
DM
308pve-firewall (2.0-3) unstable; urgency=medium
309
310 * use noawait trigers for pve-api-updates
311
312 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
313
56bb2e69
DM
314pve-firewall (2.0-2) unstable; urgency=medium
315
316 * trigger pve-api-updates event
317
318 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
319
0b18ebe8
DM
320pve-firewall (2.0-1) unstable; urgency=medium
321
322 * recompile for debian jessie
323
324 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
325
609f00c7
DM
326pve-firewall (1.0-18) unstable; urgency=low
327
328 * fix alias lookup
329
330 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
331
de48e659
DM
332pve-firewall (1.0-17) unstable; urgency=low
333
334 * fix restart behavior
335
336 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
337
b92d2ed2
DM
338pve-firewall (1.0-16) unstable; urgency=low
339
340 * use new Daemon class from pve-common
341
342 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
343
22dde8d6
DM
344pve-firewall (1.0-15) unstable; urgency=low
345
346 * bug fix: load cluster conf for host rules
347
348 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
349
e33e2f16
DM
350pve-firewall (1.0-14) unstable; urgency=low
351
352 * do not use ipset list chains
353
354 * remove preinst script (not needed anymore)
355
356 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
357
3bce273b
DM
358pve-firewall (1.0-13) unstable; urgency=low
359
360 * fix ipset remove order
361
362 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
363
7a7c322c
DM
364pve-firewall (1.0-12) unstable; urgency=low
365
366 * add preinst script to clear ipset from older installation (because
367 sets cannot be swapped if there type does not match.
ce41ae23 368
7a7c322c
DM
369 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
370
1b918ee5
DM
371pve-firewall (1.0-11) unstable; urgency=low
372
373 * bug fix: correctly set ipversion for aliases in verify_rule
374
375 * save restore commands into files to make debugging
376 easier (/var/lib/pve-firewall/)
377
378 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
379
df617cea
DM
380pve-firewall (1.0-10) unstable; urgency=low
381
382 * add IPv6 support for VMs (hostfw is IPv4 only)
383
384 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
385
0ac57570
DM
386pve-firewall (1.0-9) unstable; urgency=low
387
388 * fix max ipset name name length
389
390 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
391
05fd3b63
DM
392pve-firewall (1.0-8) unstable; urgency=low
393
394 * implement permission
395
396 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
397
bea9d5ab
DM
398pve-firewall (1.0-7) unstable; urgency=low
399
400 * proxy host rule API calls to correct node
a34cfdd0
DM
401
402 * always generate MAC and IP filter rules if firewall is enabled on NIC
bea9d5ab
DM
403
404 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
405
582275c3
DM
406pve-firewall (1.0-6) unstable; urgency=low
407
408 * ipmlement ipfilter ipsets
409
410 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
411
de0c1e49
DM
412pve-firewall (1.0-5) unstable; urgency=low
413
414 * remove ipsets when firewall disabled
415
416 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
417
64c266f5
DM
418pve-firewall (1.0-4) unstable; urgency=low
419
420 * depend on iptables and ipset
421
422 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
423
16bcfa8b
DM
424pve-firewall (1.0-3) unstable; urgency=low
425
426 * change dh_installinit order (register pvefw-logger before pve-firewall)
427
428 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
429
ba0b3a0a
DM
430pve-firewall (1.0-2) unstable; urgency=low
431
432 * add experimental nflog logging daemon
433
434 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
435
bb272dd3
DM
436pve-firewall (1.0-1) unstable; urgency=low
437
438 * initial package
439
440 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
441