]> git.proxmox.com Git - pve-firewall.git/blame - debian/changelog
firewall macros: add new Ceph protocol v2 port while keeping v1 port
[pve-firewall.git] / debian / changelog
CommitLineData
6fc572dc
TL
1pve-firewall (4.0-5) pve; urgency=medium
2
3 * don't use any base path at all for calls to external binaries to make use
4 compativle with bot, /usr merged and unmerged setups
5
6 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Jul 2019 11:47:53 +0200
7
b1379400
TL
8pve-firewall (4.0-4) pve; urgency=medium
9
10 * ebtables: remove PVE chains properly
11
12 * ebtables: treat chain deletion as change
13
14 * use /usr/sbin as base path
15
16 -- Proxmox Support Team <support@proxmox.com> Thu, 11 Jul 2019 19:40:01 +0200
17
9e01d77d
TL
18pve-firewall (4.0-3) pve; urgency=medium
19
20 * Create corosync firewall rules independently of localnet~
21
22 * Display corosync rule info on localnet call
23
24 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
25
9429bd35
TL
26pve-firewall (4.0-2) pve; urgency=medium
27
28 * fix systemd warning about PIDFile directory
29
30 * fix CT rule generation with ipfilter set
31
32 * pve-firewall service: update-alternative iptables and ebtables to working
33 legacy versions
34
35 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
36
6b9da9b0
TL
37pve-firewall (4.0-1) pve; urgency=medium
38
39 * re-build for Debian Buster / PVE 6
40
41 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
42
dd7d737b
TL
43pve-firewall (3.0-21) unstable; urgency=medium
44
45 * fix ipv6 PVEFW-reject
46
47 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
48 ebtables doing the wrong thing here
49
50 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
51
bbf77725
TL
52pve-firewall (3.0-20) unstable; urgency=medium
53
54 * use IPCC to read config and rule files, if the are backed by pmxcfs which
55 has better handling for pmxcfs restarts
56
57 * fix #2178: endless loop on ipv6 extension headers
58
59 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
60
baba607a
TL
61pve-firewall (3.0-19) unstable; urgency=medium
62
63 * ebtables: add arp filtering
64
65 * fix: #2123 Logging of user defined firewall rules
66
67 * fix Razor macro
68
69 * allow to enable/disable and modify cluster wide log ratelimits
70
71 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
72
d8ea08e3
TL
73pve-firewall (3.0-18) unstable; urgency=medium
74
75 * fix #1606: Add nf_conntrack_allow_invalid option
76
77 * log reject : add space after policy REJECT like drop
78
79 * fix #1891: Add zsh command completion for pve-firewall
80
81 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
82
91d88bc5
TL
83pve-firewall (3.0-17) unstable; urgency=medium
84
85 * fix #2005: only allow ascii port digits
86
87 * fix #2004: do not allow backwards ranges
88
89 * add conntrack logging via libnetfilter_conntrack and allow one to enable
90 it through the firewall host configuration
91
92 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
93
81d13a9d
TL
94pve-firewall (3.0-16) unstable; urgency=medium
95
96 * api/rules: fix macro return type
97
98 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
99
bed701bc
TL
100pve-firewall (3.0-15) unstable; urgency=medium
101
102 * fix #1971: display firewall rule properties
103
104 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
105
a24b157b
WB
106pve-firewall (3.0-14) unstable; urgency=medium
107
108 * fix #1841: avoid ebtable reloads when containers have multiple network
109 interfaces
110
111 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
112
cf7dd94b
WB
113pve-firewall (3.0-13) unstable; urgency=medium
114
115 * avoid unnecessary reloads of ebtable ruleset
116
117 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
118
dd03bf6e
WB
119pve-firewall (3.0-12) unstable; urgency=medium
120
121 * fix deleted iptables chains not being properly detected as a change
122
123 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
124
587a0f20 125pve-firewall (3.0-11) unstable; urgency=medium
a3a51dad
TL
126
127 * #1764: rename 'ebtales_enable' option to 'ebtables'
128
587a0f20 129 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
a3a51dad 130
423b86ef
WB
131pve-firewall (3.0-10) unstable; urgency=medium
132
133 * fix #1764: handle existing ebtables rules and allow disabling ebtables
134
135 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
136 ebtables_enable option.
137
138 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
139
567e58ce
WB
140pve-firewall (3.0-9) unstable; urgency=medium
141
142 * fix creation of ebltables FORWARD rule entry
143
144 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
145
ea0d59ed
WB
146pve-firewall (3.0-8) unstable; urgency=medium
147
148 * add ebtables support for better MAC filtering
149
150 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
151
9a19ec81
WB
152pve-firewall (3.0-7) unstable; urgency=medium
153
154 * support distinct source and destination multi-port matching
155
156 * multi-port matching: when specifying the same list of ports for source and
157 destination require them both to match, rather than one of them, as this
158 was rather unexpected behavior
159
160 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
161
8c41d444
DM
162pve-firewall (3.0-6) unstable; urgency=medium
163
164 * fix #1319: don't fail postinst with masked service
165
166 * debian: switch to compat 9, drop init scripts, drop preinst
167
168 * check multiport limit in port ranges
169
170 * build: use git rev-parse for GITVERSION
171
172 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
173
4299c35f
WB
174pve-firewall (3.0-5) unstable; urgency=medium
175
176 * fix issue with disabled flag not being honored within groups
177
178 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
179
a19d4127
WB
180pve-firewall (3.0-4) unstable; urgency=medium
181
182 * fix issues with ipsets reloading unnecessarily or too late
183
184 * fix some typos in the logs
185
186 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
187
c0c71b1b
WB
188pve-firewall (3.0-3) unstable; urgency=medium
189
190 * Fix #1492: logger: use current timestamp if the packet doesn't have one
191
192 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
193
4f7a4bdd
WB
194pve-firewall (3.0-2) unstable; urgency=medium
195
196 * Fix #1446: remove masks in case the package had previously been removed but
197 not purged.
198
199 * improve logging on errors in the firewall configuration
200
201 * forbid trailing commas in lists as iptables-restore doesn't support them
202
203 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
204
29a94c79
FG
205pve-firewall (3.0-1) unstable; urgency=medium
206
207 * rebuild for Debian Stretch
208
209 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
210
df67a3dc
DM
211pve-firewall (2.0-33) unstable; urgency=medium
212
213 * ipset: don't allow zero-prefix entries
214
215 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
216
dc643b4d
DM
217pve-firewall (2.0-32) unstable; urgency=medium
218
219 * improve search for local-network
220
221 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
222
45f206fd
DM
223pve-firewall (2.0-31) unstable; urgency=medium
224
225 * don't try to apply ports to rules which don't support them
226
227 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
228
2ea28d0c
DM
229pve-firewall (2.0-30) unstable; urgency=medium
230
231 * add multicast DNS to the list of Macros
232
233 * add missing parameter descriptions
234
235 * build-depends: add dh-systemd
236
237 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
238
b65d13d9
DM
239pve-firewall (2.0-29) unstable; urgency=medium
240
241 * prevent overwriting ipsets/sec. groups by renaming
242
243 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
244
d0f3bb08
DM
245pve-firewall (2.0-28) unstable; urgency=medium
246
247 * use pve-common's ipv4_mask_hash_localnet
248
5c53cde4
DC
249 * fix allowed group name length
250
251 * make group digest stable
252
d0f3bb08
DM
253 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
254
76a57e1a
DM
255pve-firewall (2.0-27) unstable; urgency=medium
256
257 * fix #972: make PVEFW-FWBR-* rule order stable
258
259 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
260
17642172
DM
261pve-firewall (2.0-26) unstable; urgency=medium
262
263 * fix #988: set rp_filter=2
264
265 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
266
6e29af12
DM
267pve-firewall (2.0-25) unstable; urgency=medium
268
269 * fix #945: add uninitialized check in lxc ipset compilation
270
271 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
272
edb4aff5
DM
273pve-firewall (2.0-24) unstable; urgency=medium
274
275 * Build-Depend on pve-doc-generator
276
277 * generate manpage with pve-doc-generator
278
279 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
280
e1158c15
DM
281pve-firewall (2.0-23) unstable; urgency=medium
282
283 * use only the top bit for our accept marks
284
285 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
286
5399f912
DM
287pve-firewall (2.0-22) unstable; urgency=medium
288
289 * Use cfs_config_path from PVE::QemuConfig
290
291 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
292
b9e73915
DM
293pve-firewall (2.0-21) unstable; urgency=medium
294
295 * added new 'ipfilter' option
296
297 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
298
e2a49003
DM
299pve-firewall (2.0-20) unstable; urgency=medium
300
301 * fix 901: encode unicode characters in sha digest
302
303 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
304
1d10f89a
DM
305pve-firewall (2.0-19) unstable; urgency=medium
306
307 * Add radv option to VM options
308
309 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
310
666093cd
DM
311pve-firewall (2.0-18) unstable; urgency=medium
312
313 * Add ndp option to host and VM firewall options
314
315 * Add router-solicitation to NeighborDiscovery macro
316
317 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
318
eaf25885
DM
319pve-firewall (2.0-17) unstable; urgency=medium
320
321 * Don't leave empty FW config files behind
322
323 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
324
a177fb07
DM
325pve-firewall (2.0-16) unstable; urgency=medium
326
327 * logger: basic ipv6 support
328
329 * add DHCPv6 macro
330
331 * add dhcpv6 support to the dhcp option
332
333 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
334
ab1b8d3c
DM
335pve-firewall (2.0-15) unstable; urgency=medium
336
337 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
338
339 * fix some regular expressions mixups
340
341 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
342
c9c8d7a3
DM
343pve-firewall (2.0-14) unstable; urgency=medium
344
345 * fix systemd service dependencies
346
347 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
348
aa818ae7
DM
349pve-firewall (2.0-13) unstable; urgency=medium
350
351 * allow numeric icmp types
352
353 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
354
8dbebe7d
DM
355pve-firewall (2.0-12) unstable; urgency=medium
356
357 * implement bash completions
358
359 * convert pve-firewall into a PVE::Service class
360
361 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
362
47704f4c
DM
363pve-firewall (2.0-11) unstable; urgency=medium
364
365 * iptables_get_chains: fix veth device name
366
367 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
368
9eb84dc7
DM
369pve-firewall (2.0-10) unstable; urgency=medium
370
371 * new helper: clone_vmfw_conf()
372
373 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
374
a3d34dac
DM
375pve-firewall (2.0-9) unstable; urgency=medium
376
377 * remove firewall config file subroutine added
378
379 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
380
2a42a237
DM
381pve-firewall (2.0-8) unstable; urgency=medium
382
383 * adopt regresion tests for lxc containers
384
385 * removed firewall code for openVZ
386
387 * Subroutine verify_rule fixed to correctly check only for "net\d+"
388 interface device names
389
390 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
391
33448a6e
DM
392pve-firewall (2.0-7) unstable; urgency=medium
393
394 * added firewall code for lxc
395
396 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
397
19f14465
DM
398pve-firewall (2.0-6) unstable; urgency=medium
399
400 * firewall ipversion comparison fix
401
402 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
403
8feec9fa
DM
404pve-firewall (2.0-5) unstable; urgency=medium
405
406 * add ipv6 neighbor discovery and solicitation macros
407
408 * ip6tables accepts both spellings of the word neighbor
409
410 * added Ceph macro
411
412 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
413
e02c77aa
DM
414pve-firewall (2.0-4) unstable; urgency=medium
415
416 * include manual page for pve-firewall
417
418 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
419
eb4a2902
DM
420pve-firewall (2.0-3) unstable; urgency=medium
421
422 * use noawait trigers for pve-api-updates
423
424 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
425
56bb2e69
DM
426pve-firewall (2.0-2) unstable; urgency=medium
427
428 * trigger pve-api-updates event
429
430 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
431
0b18ebe8
DM
432pve-firewall (2.0-1) unstable; urgency=medium
433
434 * recompile for debian jessie
435
436 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
437
609f00c7
DM
438pve-firewall (1.0-18) unstable; urgency=low
439
440 * fix alias lookup
441
442 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
443
de48e659
DM
444pve-firewall (1.0-17) unstable; urgency=low
445
446 * fix restart behavior
447
448 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
449
b92d2ed2
DM
450pve-firewall (1.0-16) unstable; urgency=low
451
452 * use new Daemon class from pve-common
453
454 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
455
22dde8d6
DM
456pve-firewall (1.0-15) unstable; urgency=low
457
458 * bug fix: load cluster conf for host rules
459
460 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
461
e33e2f16
DM
462pve-firewall (1.0-14) unstable; urgency=low
463
464 * do not use ipset list chains
465
466 * remove preinst script (not needed anymore)
467
468 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
469
3bce273b
DM
470pve-firewall (1.0-13) unstable; urgency=low
471
472 * fix ipset remove order
473
474 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
475
7a7c322c
DM
476pve-firewall (1.0-12) unstable; urgency=low
477
478 * add preinst script to clear ipset from older installation (because
479 sets cannot be swapped if there type does not match.
ce41ae23 480
7a7c322c
DM
481 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
482
1b918ee5
DM
483pve-firewall (1.0-11) unstable; urgency=low
484
485 * bug fix: correctly set ipversion for aliases in verify_rule
486
487 * save restore commands into files to make debugging
488 easier (/var/lib/pve-firewall/)
489
490 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
491
df617cea
DM
492pve-firewall (1.0-10) unstable; urgency=low
493
494 * add IPv6 support for VMs (hostfw is IPv4 only)
495
496 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
497
0ac57570
DM
498pve-firewall (1.0-9) unstable; urgency=low
499
500 * fix max ipset name name length
501
502 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
503
05fd3b63
DM
504pve-firewall (1.0-8) unstable; urgency=low
505
506 * implement permission
507
508 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
509
bea9d5ab
DM
510pve-firewall (1.0-7) unstable; urgency=low
511
512 * proxy host rule API calls to correct node
a34cfdd0
DM
513
514 * always generate MAC and IP filter rules if firewall is enabled on NIC
bea9d5ab
DM
515
516 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
517
582275c3
DM
518pve-firewall (1.0-6) unstable; urgency=low
519
520 * ipmlement ipfilter ipsets
521
522 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
523
de0c1e49
DM
524pve-firewall (1.0-5) unstable; urgency=low
525
526 * remove ipsets when firewall disabled
527
528 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
529
64c266f5
DM
530pve-firewall (1.0-4) unstable; urgency=low
531
532 * depend on iptables and ipset
533
534 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
535
16bcfa8b
DM
536pve-firewall (1.0-3) unstable; urgency=low
537
538 * change dh_installinit order (register pvefw-logger before pve-firewall)
539
540 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
541
ba0b3a0a
DM
542pve-firewall (1.0-2) unstable; urgency=low
543
544 * add experimental nflog logging daemon
545
546 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
547
bb272dd3
DM
548pve-firewall (1.0-1) unstable; urgency=low
549
550 * initial package
551
552 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
553