]> git.proxmox.com Git - pve-firewall.git/blame - debian/changelog
localnet: skip local node for corosync information
[pve-firewall.git] / debian / changelog
CommitLineData
9429bd35
TL
1pve-firewall (4.0-2) pve; urgency=medium
2
3 * fix systemd warning about PIDFile directory
4
5 * fix CT rule generation with ipfilter set
6
7 * pve-firewall service: update-alternative iptables and ebtables to working
8 legacy versions
9
10 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
11
6b9da9b0
TL
12pve-firewall (4.0-1) pve; urgency=medium
13
14 * re-build for Debian Buster / PVE 6
15
16 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
17
dd7d737b
TL
18pve-firewall (3.0-21) unstable; urgency=medium
19
20 * fix ipv6 PVEFW-reject
21
22 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
23 ebtables doing the wrong thing here
24
25 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
26
bbf77725
TL
27pve-firewall (3.0-20) unstable; urgency=medium
28
29 * use IPCC to read config and rule files, if the are backed by pmxcfs which
30 has better handling for pmxcfs restarts
31
32 * fix #2178: endless loop on ipv6 extension headers
33
34 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
35
baba607a
TL
36pve-firewall (3.0-19) unstable; urgency=medium
37
38 * ebtables: add arp filtering
39
40 * fix: #2123 Logging of user defined firewall rules
41
42 * fix Razor macro
43
44 * allow to enable/disable and modify cluster wide log ratelimits
45
46 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
47
d8ea08e3
TL
48pve-firewall (3.0-18) unstable; urgency=medium
49
50 * fix #1606: Add nf_conntrack_allow_invalid option
51
52 * log reject : add space after policy REJECT like drop
53
54 * fix #1891: Add zsh command completion for pve-firewall
55
56 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
57
91d88bc5
TL
58pve-firewall (3.0-17) unstable; urgency=medium
59
60 * fix #2005: only allow ascii port digits
61
62 * fix #2004: do not allow backwards ranges
63
64 * add conntrack logging via libnetfilter_conntrack and allow one to enable
65 it through the firewall host configuration
66
67 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
68
81d13a9d
TL
69pve-firewall (3.0-16) unstable; urgency=medium
70
71 * api/rules: fix macro return type
72
73 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
74
bed701bc
TL
75pve-firewall (3.0-15) unstable; urgency=medium
76
77 * fix #1971: display firewall rule properties
78
79 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
80
a24b157b
WB
81pve-firewall (3.0-14) unstable; urgency=medium
82
83 * fix #1841: avoid ebtable reloads when containers have multiple network
84 interfaces
85
86 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
87
cf7dd94b
WB
88pve-firewall (3.0-13) unstable; urgency=medium
89
90 * avoid unnecessary reloads of ebtable ruleset
91
92 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
93
dd03bf6e
WB
94pve-firewall (3.0-12) unstable; urgency=medium
95
96 * fix deleted iptables chains not being properly detected as a change
97
98 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
99
587a0f20 100pve-firewall (3.0-11) unstable; urgency=medium
a3a51dad
TL
101
102 * #1764: rename 'ebtales_enable' option to 'ebtables'
103
587a0f20 104 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
a3a51dad 105
423b86ef
WB
106pve-firewall (3.0-10) unstable; urgency=medium
107
108 * fix #1764: handle existing ebtables rules and allow disabling ebtables
109
110 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
111 ebtables_enable option.
112
113 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
114
567e58ce
WB
115pve-firewall (3.0-9) unstable; urgency=medium
116
117 * fix creation of ebltables FORWARD rule entry
118
119 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
120
ea0d59ed
WB
121pve-firewall (3.0-8) unstable; urgency=medium
122
123 * add ebtables support for better MAC filtering
124
125 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
126
9a19ec81
WB
127pve-firewall (3.0-7) unstable; urgency=medium
128
129 * support distinct source and destination multi-port matching
130
131 * multi-port matching: when specifying the same list of ports for source and
132 destination require them both to match, rather than one of them, as this
133 was rather unexpected behavior
134
135 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
136
8c41d444
DM
137pve-firewall (3.0-6) unstable; urgency=medium
138
139 * fix #1319: don't fail postinst with masked service
140
141 * debian: switch to compat 9, drop init scripts, drop preinst
142
143 * check multiport limit in port ranges
144
145 * build: use git rev-parse for GITVERSION
146
147 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
148
4299c35f
WB
149pve-firewall (3.0-5) unstable; urgency=medium
150
151 * fix issue with disabled flag not being honored within groups
152
153 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
154
a19d4127
WB
155pve-firewall (3.0-4) unstable; urgency=medium
156
157 * fix issues with ipsets reloading unnecessarily or too late
158
159 * fix some typos in the logs
160
161 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
162
c0c71b1b
WB
163pve-firewall (3.0-3) unstable; urgency=medium
164
165 * Fix #1492: logger: use current timestamp if the packet doesn't have one
166
167 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
168
4f7a4bdd
WB
169pve-firewall (3.0-2) unstable; urgency=medium
170
171 * Fix #1446: remove masks in case the package had previously been removed but
172 not purged.
173
174 * improve logging on errors in the firewall configuration
175
176 * forbid trailing commas in lists as iptables-restore doesn't support them
177
178 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
179
29a94c79
FG
180pve-firewall (3.0-1) unstable; urgency=medium
181
182 * rebuild for Debian Stretch
183
184 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
185
df67a3dc
DM
186pve-firewall (2.0-33) unstable; urgency=medium
187
188 * ipset: don't allow zero-prefix entries
189
190 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
191
dc643b4d
DM
192pve-firewall (2.0-32) unstable; urgency=medium
193
194 * improve search for local-network
195
196 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
197
45f206fd
DM
198pve-firewall (2.0-31) unstable; urgency=medium
199
200 * don't try to apply ports to rules which don't support them
201
202 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
203
2ea28d0c
DM
204pve-firewall (2.0-30) unstable; urgency=medium
205
206 * add multicast DNS to the list of Macros
207
208 * add missing parameter descriptions
209
210 * build-depends: add dh-systemd
211
212 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
213
b65d13d9
DM
214pve-firewall (2.0-29) unstable; urgency=medium
215
216 * prevent overwriting ipsets/sec. groups by renaming
217
218 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
219
d0f3bb08
DM
220pve-firewall (2.0-28) unstable; urgency=medium
221
222 * use pve-common's ipv4_mask_hash_localnet
223
5c53cde4
DC
224 * fix allowed group name length
225
226 * make group digest stable
227
d0f3bb08
DM
228 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
229
76a57e1a
DM
230pve-firewall (2.0-27) unstable; urgency=medium
231
232 * fix #972: make PVEFW-FWBR-* rule order stable
233
234 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
235
17642172
DM
236pve-firewall (2.0-26) unstable; urgency=medium
237
238 * fix #988: set rp_filter=2
239
240 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
241
6e29af12
DM
242pve-firewall (2.0-25) unstable; urgency=medium
243
244 * fix #945: add uninitialized check in lxc ipset compilation
245
246 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
247
edb4aff5
DM
248pve-firewall (2.0-24) unstable; urgency=medium
249
250 * Build-Depend on pve-doc-generator
251
252 * generate manpage with pve-doc-generator
253
254 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
255
e1158c15
DM
256pve-firewall (2.0-23) unstable; urgency=medium
257
258 * use only the top bit for our accept marks
259
260 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
261
5399f912
DM
262pve-firewall (2.0-22) unstable; urgency=medium
263
264 * Use cfs_config_path from PVE::QemuConfig
265
266 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
267
b9e73915
DM
268pve-firewall (2.0-21) unstable; urgency=medium
269
270 * added new 'ipfilter' option
271
272 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
273
e2a49003
DM
274pve-firewall (2.0-20) unstable; urgency=medium
275
276 * fix 901: encode unicode characters in sha digest
277
278 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
279
1d10f89a
DM
280pve-firewall (2.0-19) unstable; urgency=medium
281
282 * Add radv option to VM options
283
284 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
285
666093cd
DM
286pve-firewall (2.0-18) unstable; urgency=medium
287
288 * Add ndp option to host and VM firewall options
289
290 * Add router-solicitation to NeighborDiscovery macro
291
292 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
293
eaf25885
DM
294pve-firewall (2.0-17) unstable; urgency=medium
295
296 * Don't leave empty FW config files behind
297
298 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
299
a177fb07
DM
300pve-firewall (2.0-16) unstable; urgency=medium
301
302 * logger: basic ipv6 support
303
304 * add DHCPv6 macro
305
306 * add dhcpv6 support to the dhcp option
307
308 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
309
ab1b8d3c
DM
310pve-firewall (2.0-15) unstable; urgency=medium
311
312 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
313
314 * fix some regular expressions mixups
315
316 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
317
c9c8d7a3
DM
318pve-firewall (2.0-14) unstable; urgency=medium
319
320 * fix systemd service dependencies
321
322 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
323
aa818ae7
DM
324pve-firewall (2.0-13) unstable; urgency=medium
325
326 * allow numeric icmp types
327
328 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
329
8dbebe7d
DM
330pve-firewall (2.0-12) unstable; urgency=medium
331
332 * implement bash completions
333
334 * convert pve-firewall into a PVE::Service class
335
336 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
337
47704f4c
DM
338pve-firewall (2.0-11) unstable; urgency=medium
339
340 * iptables_get_chains: fix veth device name
341
342 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
343
9eb84dc7
DM
344pve-firewall (2.0-10) unstable; urgency=medium
345
346 * new helper: clone_vmfw_conf()
347
348 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
349
a3d34dac
DM
350pve-firewall (2.0-9) unstable; urgency=medium
351
352 * remove firewall config file subroutine added
353
354 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
355
2a42a237
DM
356pve-firewall (2.0-8) unstable; urgency=medium
357
358 * adopt regresion tests for lxc containers
359
360 * removed firewall code for openVZ
361
362 * Subroutine verify_rule fixed to correctly check only for "net\d+"
363 interface device names
364
365 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
366
33448a6e
DM
367pve-firewall (2.0-7) unstable; urgency=medium
368
369 * added firewall code for lxc
370
371 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
372
19f14465
DM
373pve-firewall (2.0-6) unstable; urgency=medium
374
375 * firewall ipversion comparison fix
376
377 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
378
8feec9fa
DM
379pve-firewall (2.0-5) unstable; urgency=medium
380
381 * add ipv6 neighbor discovery and solicitation macros
382
383 * ip6tables accepts both spellings of the word neighbor
384
385 * added Ceph macro
386
387 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
388
e02c77aa
DM
389pve-firewall (2.0-4) unstable; urgency=medium
390
391 * include manual page for pve-firewall
392
393 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
394
eb4a2902
DM
395pve-firewall (2.0-3) unstable; urgency=medium
396
397 * use noawait trigers for pve-api-updates
398
399 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
400
56bb2e69
DM
401pve-firewall (2.0-2) unstable; urgency=medium
402
403 * trigger pve-api-updates event
404
405 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
406
0b18ebe8
DM
407pve-firewall (2.0-1) unstable; urgency=medium
408
409 * recompile for debian jessie
410
411 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
412
609f00c7
DM
413pve-firewall (1.0-18) unstable; urgency=low
414
415 * fix alias lookup
416
417 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
418
de48e659
DM
419pve-firewall (1.0-17) unstable; urgency=low
420
421 * fix restart behavior
422
423 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
424
b92d2ed2
DM
425pve-firewall (1.0-16) unstable; urgency=low
426
427 * use new Daemon class from pve-common
428
429 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
430
22dde8d6
DM
431pve-firewall (1.0-15) unstable; urgency=low
432
433 * bug fix: load cluster conf for host rules
434
435 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
436
e33e2f16
DM
437pve-firewall (1.0-14) unstable; urgency=low
438
439 * do not use ipset list chains
440
441 * remove preinst script (not needed anymore)
442
443 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
444
3bce273b
DM
445pve-firewall (1.0-13) unstable; urgency=low
446
447 * fix ipset remove order
448
449 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
450
7a7c322c
DM
451pve-firewall (1.0-12) unstable; urgency=low
452
453 * add preinst script to clear ipset from older installation (because
454 sets cannot be swapped if there type does not match.
ce41ae23 455
7a7c322c
DM
456 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
457
1b918ee5
DM
458pve-firewall (1.0-11) unstable; urgency=low
459
460 * bug fix: correctly set ipversion for aliases in verify_rule
461
462 * save restore commands into files to make debugging
463 easier (/var/lib/pve-firewall/)
464
465 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
466
df617cea
DM
467pve-firewall (1.0-10) unstable; urgency=low
468
469 * add IPv6 support for VMs (hostfw is IPv4 only)
470
471 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
472
0ac57570
DM
473pve-firewall (1.0-9) unstable; urgency=low
474
475 * fix max ipset name name length
476
477 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
478
05fd3b63
DM
479pve-firewall (1.0-8) unstable; urgency=low
480
481 * implement permission
482
483 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
484
bea9d5ab
DM
485pve-firewall (1.0-7) unstable; urgency=low
486
487 * proxy host rule API calls to correct node
a34cfdd0
DM
488
489 * always generate MAC and IP filter rules if firewall is enabled on NIC
bea9d5ab
DM
490
491 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
492
582275c3
DM
493pve-firewall (1.0-6) unstable; urgency=low
494
495 * ipmlement ipfilter ipsets
496
497 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
498
de0c1e49
DM
499pve-firewall (1.0-5) unstable; urgency=low
500
501 * remove ipsets when firewall disabled
502
503 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
504
64c266f5
DM
505pve-firewall (1.0-4) unstable; urgency=low
506
507 * depend on iptables and ipset
508
509 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
510
16bcfa8b
DM
511pve-firewall (1.0-3) unstable; urgency=low
512
513 * change dh_installinit order (register pvefw-logger before pve-firewall)
514
515 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
516
ba0b3a0a
DM
517pve-firewall (1.0-2) unstable; urgency=low
518
519 * add experimental nflog logging daemon
520
521 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
522
bb272dd3
DM
523pve-firewall (1.0-1) unstable; urgency=low
524
525 * initial package
526
527 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
528