]> git.proxmox.com Git - pve-firewall.git/blame - debian/changelog
fix PVEFW-FORWARD chain not being used
[pve-firewall.git] / debian / changelog
CommitLineData
ea0d59ed
WB
1pve-firewall (3.0-8) unstable; urgency=medium
2
3 * add ebtables support for better MAC filtering
4
5 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
6
9a19ec81
WB
7pve-firewall (3.0-7) unstable; urgency=medium
8
9 * support distinct source and destination multi-port matching
10
11 * multi-port matching: when specifying the same list of ports for source and
12 destination require them both to match, rather than one of them, as this
13 was rather unexpected behavior
14
15 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
16
8c41d444
DM
17pve-firewall (3.0-6) unstable; urgency=medium
18
19 * fix #1319: don't fail postinst with masked service
20
21 * debian: switch to compat 9, drop init scripts, drop preinst
22
23 * check multiport limit in port ranges
24
25 * build: use git rev-parse for GITVERSION
26
27 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
28
4299c35f
WB
29pve-firewall (3.0-5) unstable; urgency=medium
30
31 * fix issue with disabled flag not being honored within groups
32
33 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
34
a19d4127
WB
35pve-firewall (3.0-4) unstable; urgency=medium
36
37 * fix issues with ipsets reloading unnecessarily or too late
38
39 * fix some typos in the logs
40
41 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
42
c0c71b1b
WB
43pve-firewall (3.0-3) unstable; urgency=medium
44
45 * Fix #1492: logger: use current timestamp if the packet doesn't have one
46
47 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
48
4f7a4bdd
WB
49pve-firewall (3.0-2) unstable; urgency=medium
50
51 * Fix #1446: remove masks in case the package had previously been removed but
52 not purged.
53
54 * improve logging on errors in the firewall configuration
55
56 * forbid trailing commas in lists as iptables-restore doesn't support them
57
58 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
59
29a94c79
FG
60pve-firewall (3.0-1) unstable; urgency=medium
61
62 * rebuild for Debian Stretch
63
64 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
65
df67a3dc
DM
66pve-firewall (2.0-33) unstable; urgency=medium
67
68 * ipset: don't allow zero-prefix entries
69
70 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
71
dc643b4d
DM
72pve-firewall (2.0-32) unstable; urgency=medium
73
74 * improve search for local-network
75
76 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
77
45f206fd
DM
78pve-firewall (2.0-31) unstable; urgency=medium
79
80 * don't try to apply ports to rules which don't support them
81
82 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
83
2ea28d0c
DM
84pve-firewall (2.0-30) unstable; urgency=medium
85
86 * add multicast DNS to the list of Macros
87
88 * add missing parameter descriptions
89
90 * build-depends: add dh-systemd
91
92 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
93
b65d13d9
DM
94pve-firewall (2.0-29) unstable; urgency=medium
95
96 * prevent overwriting ipsets/sec. groups by renaming
97
98 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
99
d0f3bb08
DM
100pve-firewall (2.0-28) unstable; urgency=medium
101
102 * use pve-common's ipv4_mask_hash_localnet
103
5c53cde4
DC
104 * fix allowed group name length
105
106 * make group digest stable
107
d0f3bb08
DM
108 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
109
76a57e1a
DM
110pve-firewall (2.0-27) unstable; urgency=medium
111
112 * fix #972: make PVEFW-FWBR-* rule order stable
113
114 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
115
17642172
DM
116pve-firewall (2.0-26) unstable; urgency=medium
117
118 * fix #988: set rp_filter=2
119
120 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
121
6e29af12
DM
122pve-firewall (2.0-25) unstable; urgency=medium
123
124 * fix #945: add uninitialized check in lxc ipset compilation
125
126 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
127
edb4aff5
DM
128pve-firewall (2.0-24) unstable; urgency=medium
129
130 * Build-Depend on pve-doc-generator
131
132 * generate manpage with pve-doc-generator
133
134 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
135
e1158c15
DM
136pve-firewall (2.0-23) unstable; urgency=medium
137
138 * use only the top bit for our accept marks
139
140 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
141
5399f912
DM
142pve-firewall (2.0-22) unstable; urgency=medium
143
144 * Use cfs_config_path from PVE::QemuConfig
145
146 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
147
b9e73915
DM
148pve-firewall (2.0-21) unstable; urgency=medium
149
150 * added new 'ipfilter' option
151
152 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
153
e2a49003
DM
154pve-firewall (2.0-20) unstable; urgency=medium
155
156 * fix 901: encode unicode characters in sha digest
157
158 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
159
1d10f89a
DM
160pve-firewall (2.0-19) unstable; urgency=medium
161
162 * Add radv option to VM options
163
164 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
165
666093cd
DM
166pve-firewall (2.0-18) unstable; urgency=medium
167
168 * Add ndp option to host and VM firewall options
169
170 * Add router-solicitation to NeighborDiscovery macro
171
172 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
173
eaf25885
DM
174pve-firewall (2.0-17) unstable; urgency=medium
175
176 * Don't leave empty FW config files behind
177
178 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
179
a177fb07
DM
180pve-firewall (2.0-16) unstable; urgency=medium
181
182 * logger: basic ipv6 support
183
184 * add DHCPv6 macro
185
186 * add dhcpv6 support to the dhcp option
187
188 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
189
ab1b8d3c
DM
190pve-firewall (2.0-15) unstable; urgency=medium
191
192 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
193
194 * fix some regular expressions mixups
195
196 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
197
c9c8d7a3
DM
198pve-firewall (2.0-14) unstable; urgency=medium
199
200 * fix systemd service dependencies
201
202 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
203
aa818ae7
DM
204pve-firewall (2.0-13) unstable; urgency=medium
205
206 * allow numeric icmp types
207
208 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
209
8dbebe7d
DM
210pve-firewall (2.0-12) unstable; urgency=medium
211
212 * implement bash completions
213
214 * convert pve-firewall into a PVE::Service class
215
216 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
217
47704f4c
DM
218pve-firewall (2.0-11) unstable; urgency=medium
219
220 * iptables_get_chains: fix veth device name
221
222 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
223
9eb84dc7
DM
224pve-firewall (2.0-10) unstable; urgency=medium
225
226 * new helper: clone_vmfw_conf()
227
228 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
229
a3d34dac
DM
230pve-firewall (2.0-9) unstable; urgency=medium
231
232 * remove firewall config file subroutine added
233
234 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
235
2a42a237
DM
236pve-firewall (2.0-8) unstable; urgency=medium
237
238 * adopt regresion tests for lxc containers
239
240 * removed firewall code for openVZ
241
242 * Subroutine verify_rule fixed to correctly check only for "net\d+"
243 interface device names
244
245 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
246
33448a6e
DM
247pve-firewall (2.0-7) unstable; urgency=medium
248
249 * added firewall code for lxc
250
251 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
252
19f14465
DM
253pve-firewall (2.0-6) unstable; urgency=medium
254
255 * firewall ipversion comparison fix
256
257 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
258
8feec9fa
DM
259pve-firewall (2.0-5) unstable; urgency=medium
260
261 * add ipv6 neighbor discovery and solicitation macros
262
263 * ip6tables accepts both spellings of the word neighbor
264
265 * added Ceph macro
266
267 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
268
e02c77aa
DM
269pve-firewall (2.0-4) unstable; urgency=medium
270
271 * include manual page for pve-firewall
272
273 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
274
eb4a2902
DM
275pve-firewall (2.0-3) unstable; urgency=medium
276
277 * use noawait trigers for pve-api-updates
278
279 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
280
56bb2e69
DM
281pve-firewall (2.0-2) unstable; urgency=medium
282
283 * trigger pve-api-updates event
284
285 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
286
0b18ebe8
DM
287pve-firewall (2.0-1) unstable; urgency=medium
288
289 * recompile for debian jessie
290
291 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
292
609f00c7
DM
293pve-firewall (1.0-18) unstable; urgency=low
294
295 * fix alias lookup
296
297 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
298
de48e659
DM
299pve-firewall (1.0-17) unstable; urgency=low
300
301 * fix restart behavior
302
303 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
304
b92d2ed2
DM
305pve-firewall (1.0-16) unstable; urgency=low
306
307 * use new Daemon class from pve-common
308
309 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
310
22dde8d6
DM
311pve-firewall (1.0-15) unstable; urgency=low
312
313 * bug fix: load cluster conf for host rules
314
315 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
316
e33e2f16
DM
317pve-firewall (1.0-14) unstable; urgency=low
318
319 * do not use ipset list chains
320
321 * remove preinst script (not needed anymore)
322
323 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
324
3bce273b
DM
325pve-firewall (1.0-13) unstable; urgency=low
326
327 * fix ipset remove order
328
329 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
330
7a7c322c
DM
331pve-firewall (1.0-12) unstable; urgency=low
332
333 * add preinst script to clear ipset from older installation (because
334 sets cannot be swapped if there type does not match.
ce41ae23 335
7a7c322c
DM
336 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
337
1b918ee5
DM
338pve-firewall (1.0-11) unstable; urgency=low
339
340 * bug fix: correctly set ipversion for aliases in verify_rule
341
342 * save restore commands into files to make debugging
343 easier (/var/lib/pve-firewall/)
344
345 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
346
df617cea
DM
347pve-firewall (1.0-10) unstable; urgency=low
348
349 * add IPv6 support for VMs (hostfw is IPv4 only)
350
351 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
352
0ac57570
DM
353pve-firewall (1.0-9) unstable; urgency=low
354
355 * fix max ipset name name length
356
357 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
358
05fd3b63
DM
359pve-firewall (1.0-8) unstable; urgency=low
360
361 * implement permission
362
363 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
364
bea9d5ab
DM
365pve-firewall (1.0-7) unstable; urgency=low
366
367 * proxy host rule API calls to correct node
a34cfdd0
DM
368
369 * always generate MAC and IP filter rules if firewall is enabled on NIC
bea9d5ab
DM
370
371 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
372
582275c3
DM
373pve-firewall (1.0-6) unstable; urgency=low
374
375 * ipmlement ipfilter ipsets
376
377 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
378
de0c1e49
DM
379pve-firewall (1.0-5) unstable; urgency=low
380
381 * remove ipsets when firewall disabled
382
383 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
384
64c266f5
DM
385pve-firewall (1.0-4) unstable; urgency=low
386
387 * depend on iptables and ipset
388
389 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
390
16bcfa8b
DM
391pve-firewall (1.0-3) unstable; urgency=low
392
393 * change dh_installinit order (register pvefw-logger before pve-firewall)
394
395 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
396
ba0b3a0a
DM
397pve-firewall (1.0-2) unstable; urgency=low
398
399 * add experimental nflog logging daemon
400
401 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
402
bb272dd3
DM
403pve-firewall (1.0-1) unstable; urgency=low
404
405 * initial package
406
407 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
408