]> git.proxmox.com Git - pve-firewall.git/blame - debian/changelog
use /usr/sbin as base path
[pve-firewall.git] / debian / changelog
CommitLineData
9e01d77d
TL
1pve-firewall (4.0-3) pve; urgency=medium
2
3 * Create corosync firewall rules independently of localnet~
4
5 * Display corosync rule info on localnet call
6
7 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
8
9429bd35
TL
9pve-firewall (4.0-2) pve; urgency=medium
10
11 * fix systemd warning about PIDFile directory
12
13 * fix CT rule generation with ipfilter set
14
15 * pve-firewall service: update-alternative iptables and ebtables to working
16 legacy versions
17
18 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
19
6b9da9b0
TL
20pve-firewall (4.0-1) pve; urgency=medium
21
22 * re-build for Debian Buster / PVE 6
23
24 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
25
dd7d737b
TL
26pve-firewall (3.0-21) unstable; urgency=medium
27
28 * fix ipv6 PVEFW-reject
29
30 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
31 ebtables doing the wrong thing here
32
33 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
34
bbf77725
TL
35pve-firewall (3.0-20) unstable; urgency=medium
36
37 * use IPCC to read config and rule files, if the are backed by pmxcfs which
38 has better handling for pmxcfs restarts
39
40 * fix #2178: endless loop on ipv6 extension headers
41
42 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
43
baba607a
TL
44pve-firewall (3.0-19) unstable; urgency=medium
45
46 * ebtables: add arp filtering
47
48 * fix: #2123 Logging of user defined firewall rules
49
50 * fix Razor macro
51
52 * allow to enable/disable and modify cluster wide log ratelimits
53
54 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
55
d8ea08e3
TL
56pve-firewall (3.0-18) unstable; urgency=medium
57
58 * fix #1606: Add nf_conntrack_allow_invalid option
59
60 * log reject : add space after policy REJECT like drop
61
62 * fix #1891: Add zsh command completion for pve-firewall
63
64 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
65
91d88bc5
TL
66pve-firewall (3.0-17) unstable; urgency=medium
67
68 * fix #2005: only allow ascii port digits
69
70 * fix #2004: do not allow backwards ranges
71
72 * add conntrack logging via libnetfilter_conntrack and allow one to enable
73 it through the firewall host configuration
74
75 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
76
81d13a9d
TL
77pve-firewall (3.0-16) unstable; urgency=medium
78
79 * api/rules: fix macro return type
80
81 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
82
bed701bc
TL
83pve-firewall (3.0-15) unstable; urgency=medium
84
85 * fix #1971: display firewall rule properties
86
87 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
88
a24b157b
WB
89pve-firewall (3.0-14) unstable; urgency=medium
90
91 * fix #1841: avoid ebtable reloads when containers have multiple network
92 interfaces
93
94 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
95
cf7dd94b
WB
96pve-firewall (3.0-13) unstable; urgency=medium
97
98 * avoid unnecessary reloads of ebtable ruleset
99
100 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
101
dd03bf6e
WB
102pve-firewall (3.0-12) unstable; urgency=medium
103
104 * fix deleted iptables chains not being properly detected as a change
105
106 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
107
587a0f20 108pve-firewall (3.0-11) unstable; urgency=medium
a3a51dad
TL
109
110 * #1764: rename 'ebtales_enable' option to 'ebtables'
111
587a0f20 112 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
a3a51dad 113
423b86ef
WB
114pve-firewall (3.0-10) unstable; urgency=medium
115
116 * fix #1764: handle existing ebtables rules and allow disabling ebtables
117
118 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
119 ebtables_enable option.
120
121 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
122
567e58ce
WB
123pve-firewall (3.0-9) unstable; urgency=medium
124
125 * fix creation of ebltables FORWARD rule entry
126
127 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
128
ea0d59ed
WB
129pve-firewall (3.0-8) unstable; urgency=medium
130
131 * add ebtables support for better MAC filtering
132
133 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
134
9a19ec81
WB
135pve-firewall (3.0-7) unstable; urgency=medium
136
137 * support distinct source and destination multi-port matching
138
139 * multi-port matching: when specifying the same list of ports for source and
140 destination require them both to match, rather than one of them, as this
141 was rather unexpected behavior
142
143 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
144
8c41d444
DM
145pve-firewall (3.0-6) unstable; urgency=medium
146
147 * fix #1319: don't fail postinst with masked service
148
149 * debian: switch to compat 9, drop init scripts, drop preinst
150
151 * check multiport limit in port ranges
152
153 * build: use git rev-parse for GITVERSION
154
155 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
156
4299c35f
WB
157pve-firewall (3.0-5) unstable; urgency=medium
158
159 * fix issue with disabled flag not being honored within groups
160
161 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
162
a19d4127
WB
163pve-firewall (3.0-4) unstable; urgency=medium
164
165 * fix issues with ipsets reloading unnecessarily or too late
166
167 * fix some typos in the logs
168
169 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
170
c0c71b1b
WB
171pve-firewall (3.0-3) unstable; urgency=medium
172
173 * Fix #1492: logger: use current timestamp if the packet doesn't have one
174
175 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
176
4f7a4bdd
WB
177pve-firewall (3.0-2) unstable; urgency=medium
178
179 * Fix #1446: remove masks in case the package had previously been removed but
180 not purged.
181
182 * improve logging on errors in the firewall configuration
183
184 * forbid trailing commas in lists as iptables-restore doesn't support them
185
186 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
187
29a94c79
FG
188pve-firewall (3.0-1) unstable; urgency=medium
189
190 * rebuild for Debian Stretch
191
192 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
193
df67a3dc
DM
194pve-firewall (2.0-33) unstable; urgency=medium
195
196 * ipset: don't allow zero-prefix entries
197
198 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
199
dc643b4d
DM
200pve-firewall (2.0-32) unstable; urgency=medium
201
202 * improve search for local-network
203
204 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
205
45f206fd
DM
206pve-firewall (2.0-31) unstable; urgency=medium
207
208 * don't try to apply ports to rules which don't support them
209
210 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
211
2ea28d0c
DM
212pve-firewall (2.0-30) unstable; urgency=medium
213
214 * add multicast DNS to the list of Macros
215
216 * add missing parameter descriptions
217
218 * build-depends: add dh-systemd
219
220 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
221
b65d13d9
DM
222pve-firewall (2.0-29) unstable; urgency=medium
223
224 * prevent overwriting ipsets/sec. groups by renaming
225
226 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
227
d0f3bb08
DM
228pve-firewall (2.0-28) unstable; urgency=medium
229
230 * use pve-common's ipv4_mask_hash_localnet
231
5c53cde4
DC
232 * fix allowed group name length
233
234 * make group digest stable
235
d0f3bb08
DM
236 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
237
76a57e1a
DM
238pve-firewall (2.0-27) unstable; urgency=medium
239
240 * fix #972: make PVEFW-FWBR-* rule order stable
241
242 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
243
17642172
DM
244pve-firewall (2.0-26) unstable; urgency=medium
245
246 * fix #988: set rp_filter=2
247
248 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
249
6e29af12
DM
250pve-firewall (2.0-25) unstable; urgency=medium
251
252 * fix #945: add uninitialized check in lxc ipset compilation
253
254 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
255
edb4aff5
DM
256pve-firewall (2.0-24) unstable; urgency=medium
257
258 * Build-Depend on pve-doc-generator
259
260 * generate manpage with pve-doc-generator
261
262 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
263
e1158c15
DM
264pve-firewall (2.0-23) unstable; urgency=medium
265
266 * use only the top bit for our accept marks
267
268 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
269
5399f912
DM
270pve-firewall (2.0-22) unstable; urgency=medium
271
272 * Use cfs_config_path from PVE::QemuConfig
273
274 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
275
b9e73915
DM
276pve-firewall (2.0-21) unstable; urgency=medium
277
278 * added new 'ipfilter' option
279
280 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
281
e2a49003
DM
282pve-firewall (2.0-20) unstable; urgency=medium
283
284 * fix 901: encode unicode characters in sha digest
285
286 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
287
1d10f89a
DM
288pve-firewall (2.0-19) unstable; urgency=medium
289
290 * Add radv option to VM options
291
292 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
293
666093cd
DM
294pve-firewall (2.0-18) unstable; urgency=medium
295
296 * Add ndp option to host and VM firewall options
297
298 * Add router-solicitation to NeighborDiscovery macro
299
300 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
301
eaf25885
DM
302pve-firewall (2.0-17) unstable; urgency=medium
303
304 * Don't leave empty FW config files behind
305
306 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
307
a177fb07
DM
308pve-firewall (2.0-16) unstable; urgency=medium
309
310 * logger: basic ipv6 support
311
312 * add DHCPv6 macro
313
314 * add dhcpv6 support to the dhcp option
315
316 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
317
ab1b8d3c
DM
318pve-firewall (2.0-15) unstable; urgency=medium
319
320 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
321
322 * fix some regular expressions mixups
323
324 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
325
c9c8d7a3
DM
326pve-firewall (2.0-14) unstable; urgency=medium
327
328 * fix systemd service dependencies
329
330 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
331
aa818ae7
DM
332pve-firewall (2.0-13) unstable; urgency=medium
333
334 * allow numeric icmp types
335
336 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
337
8dbebe7d
DM
338pve-firewall (2.0-12) unstable; urgency=medium
339
340 * implement bash completions
341
342 * convert pve-firewall into a PVE::Service class
343
344 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
345
47704f4c
DM
346pve-firewall (2.0-11) unstable; urgency=medium
347
348 * iptables_get_chains: fix veth device name
349
350 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
351
9eb84dc7
DM
352pve-firewall (2.0-10) unstable; urgency=medium
353
354 * new helper: clone_vmfw_conf()
355
356 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
357
a3d34dac
DM
358pve-firewall (2.0-9) unstable; urgency=medium
359
360 * remove firewall config file subroutine added
361
362 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
363
2a42a237
DM
364pve-firewall (2.0-8) unstable; urgency=medium
365
366 * adopt regresion tests for lxc containers
367
368 * removed firewall code for openVZ
369
370 * Subroutine verify_rule fixed to correctly check only for "net\d+"
371 interface device names
372
373 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
374
33448a6e
DM
375pve-firewall (2.0-7) unstable; urgency=medium
376
377 * added firewall code for lxc
378
379 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
380
19f14465
DM
381pve-firewall (2.0-6) unstable; urgency=medium
382
383 * firewall ipversion comparison fix
384
385 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
386
8feec9fa
DM
387pve-firewall (2.0-5) unstable; urgency=medium
388
389 * add ipv6 neighbor discovery and solicitation macros
390
391 * ip6tables accepts both spellings of the word neighbor
392
393 * added Ceph macro
394
395 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
396
e02c77aa
DM
397pve-firewall (2.0-4) unstable; urgency=medium
398
399 * include manual page for pve-firewall
400
401 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
402
eb4a2902
DM
403pve-firewall (2.0-3) unstable; urgency=medium
404
405 * use noawait trigers for pve-api-updates
406
407 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
408
56bb2e69
DM
409pve-firewall (2.0-2) unstable; urgency=medium
410
411 * trigger pve-api-updates event
412
413 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
414
0b18ebe8
DM
415pve-firewall (2.0-1) unstable; urgency=medium
416
417 * recompile for debian jessie
418
419 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
420
609f00c7
DM
421pve-firewall (1.0-18) unstable; urgency=low
422
423 * fix alias lookup
424
425 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
426
de48e659
DM
427pve-firewall (1.0-17) unstable; urgency=low
428
429 * fix restart behavior
430
431 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
432
b92d2ed2
DM
433pve-firewall (1.0-16) unstable; urgency=low
434
435 * use new Daemon class from pve-common
436
437 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
438
22dde8d6
DM
439pve-firewall (1.0-15) unstable; urgency=low
440
441 * bug fix: load cluster conf for host rules
442
443 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
444
e33e2f16
DM
445pve-firewall (1.0-14) unstable; urgency=low
446
447 * do not use ipset list chains
448
449 * remove preinst script (not needed anymore)
450
451 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
452
3bce273b
DM
453pve-firewall (1.0-13) unstable; urgency=low
454
455 * fix ipset remove order
456
457 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
458
7a7c322c
DM
459pve-firewall (1.0-12) unstable; urgency=low
460
461 * add preinst script to clear ipset from older installation (because
462 sets cannot be swapped if there type does not match.
ce41ae23 463
7a7c322c
DM
464 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
465
1b918ee5
DM
466pve-firewall (1.0-11) unstable; urgency=low
467
468 * bug fix: correctly set ipversion for aliases in verify_rule
469
470 * save restore commands into files to make debugging
471 easier (/var/lib/pve-firewall/)
472
473 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
474
df617cea
DM
475pve-firewall (1.0-10) unstable; urgency=low
476
477 * add IPv6 support for VMs (hostfw is IPv4 only)
478
479 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
480
0ac57570
DM
481pve-firewall (1.0-9) unstable; urgency=low
482
483 * fix max ipset name name length
484
485 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
486
05fd3b63
DM
487pve-firewall (1.0-8) unstable; urgency=low
488
489 * implement permission
490
491 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
492
bea9d5ab
DM
493pve-firewall (1.0-7) unstable; urgency=low
494
495 * proxy host rule API calls to correct node
a34cfdd0
DM
496
497 * always generate MAC and IP filter rules if firewall is enabled on NIC
bea9d5ab
DM
498
499 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
500
582275c3
DM
501pve-firewall (1.0-6) unstable; urgency=low
502
503 * ipmlement ipfilter ipsets
504
505 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
506
de0c1e49
DM
507pve-firewall (1.0-5) unstable; urgency=low
508
509 * remove ipsets when firewall disabled
510
511 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
512
64c266f5
DM
513pve-firewall (1.0-4) unstable; urgency=low
514
515 * depend on iptables and ipset
516
517 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
518
16bcfa8b
DM
519pve-firewall (1.0-3) unstable; urgency=low
520
521 * change dh_installinit order (register pvefw-logger before pve-firewall)
522
523 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
524
ba0b3a0a
DM
525pve-firewall (1.0-2) unstable; urgency=low
526
527 * add experimental nflog logging daemon
528
529 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
530
bb272dd3
DM
531pve-firewall (1.0-1) unstable; urgency=low
532
533 * initial package
534
535 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
536