]> git.proxmox.com Git - pve-firewall.git/blame - debian/changelog
pve-firewall.service: update-alternative ip-/eb- tables to legacy versions
[pve-firewall.git] / debian / changelog
CommitLineData
6b9da9b0
TL
1pve-firewall (4.0-1) pve; urgency=medium
2
3 * re-build for Debian Buster / PVE 6
4
5 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
6
dd7d737b
TL
7pve-firewall (3.0-21) unstable; urgency=medium
8
9 * fix ipv6 PVEFW-reject
10
11 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
12 ebtables doing the wrong thing here
13
14 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
15
bbf77725
TL
16pve-firewall (3.0-20) unstable; urgency=medium
17
18 * use IPCC to read config and rule files, if the are backed by pmxcfs which
19 has better handling for pmxcfs restarts
20
21 * fix #2178: endless loop on ipv6 extension headers
22
23 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
24
baba607a
TL
25pve-firewall (3.0-19) unstable; urgency=medium
26
27 * ebtables: add arp filtering
28
29 * fix: #2123 Logging of user defined firewall rules
30
31 * fix Razor macro
32
33 * allow to enable/disable and modify cluster wide log ratelimits
34
35 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
36
d8ea08e3
TL
37pve-firewall (3.0-18) unstable; urgency=medium
38
39 * fix #1606: Add nf_conntrack_allow_invalid option
40
41 * log reject : add space after policy REJECT like drop
42
43 * fix #1891: Add zsh command completion for pve-firewall
44
45 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
46
91d88bc5
TL
47pve-firewall (3.0-17) unstable; urgency=medium
48
49 * fix #2005: only allow ascii port digits
50
51 * fix #2004: do not allow backwards ranges
52
53 * add conntrack logging via libnetfilter_conntrack and allow one to enable
54 it through the firewall host configuration
55
56 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
57
81d13a9d
TL
58pve-firewall (3.0-16) unstable; urgency=medium
59
60 * api/rules: fix macro return type
61
62 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
63
bed701bc
TL
64pve-firewall (3.0-15) unstable; urgency=medium
65
66 * fix #1971: display firewall rule properties
67
68 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
69
a24b157b
WB
70pve-firewall (3.0-14) unstable; urgency=medium
71
72 * fix #1841: avoid ebtable reloads when containers have multiple network
73 interfaces
74
75 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
76
cf7dd94b
WB
77pve-firewall (3.0-13) unstable; urgency=medium
78
79 * avoid unnecessary reloads of ebtable ruleset
80
81 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
82
dd03bf6e
WB
83pve-firewall (3.0-12) unstable; urgency=medium
84
85 * fix deleted iptables chains not being properly detected as a change
86
87 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
88
587a0f20 89pve-firewall (3.0-11) unstable; urgency=medium
a3a51dad
TL
90
91 * #1764: rename 'ebtales_enable' option to 'ebtables'
92
587a0f20 93 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
a3a51dad 94
423b86ef
WB
95pve-firewall (3.0-10) unstable; urgency=medium
96
97 * fix #1764: handle existing ebtables rules and allow disabling ebtables
98
99 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
100 ebtables_enable option.
101
102 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
103
567e58ce
WB
104pve-firewall (3.0-9) unstable; urgency=medium
105
106 * fix creation of ebltables FORWARD rule entry
107
108 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
109
ea0d59ed
WB
110pve-firewall (3.0-8) unstable; urgency=medium
111
112 * add ebtables support for better MAC filtering
113
114 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
115
9a19ec81
WB
116pve-firewall (3.0-7) unstable; urgency=medium
117
118 * support distinct source and destination multi-port matching
119
120 * multi-port matching: when specifying the same list of ports for source and
121 destination require them both to match, rather than one of them, as this
122 was rather unexpected behavior
123
124 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
125
8c41d444
DM
126pve-firewall (3.0-6) unstable; urgency=medium
127
128 * fix #1319: don't fail postinst with masked service
129
130 * debian: switch to compat 9, drop init scripts, drop preinst
131
132 * check multiport limit in port ranges
133
134 * build: use git rev-parse for GITVERSION
135
136 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
137
4299c35f
WB
138pve-firewall (3.0-5) unstable; urgency=medium
139
140 * fix issue with disabled flag not being honored within groups
141
142 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
143
a19d4127
WB
144pve-firewall (3.0-4) unstable; urgency=medium
145
146 * fix issues with ipsets reloading unnecessarily or too late
147
148 * fix some typos in the logs
149
150 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
151
c0c71b1b
WB
152pve-firewall (3.0-3) unstable; urgency=medium
153
154 * Fix #1492: logger: use current timestamp if the packet doesn't have one
155
156 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
157
4f7a4bdd
WB
158pve-firewall (3.0-2) unstable; urgency=medium
159
160 * Fix #1446: remove masks in case the package had previously been removed but
161 not purged.
162
163 * improve logging on errors in the firewall configuration
164
165 * forbid trailing commas in lists as iptables-restore doesn't support them
166
167 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
168
29a94c79
FG
169pve-firewall (3.0-1) unstable; urgency=medium
170
171 * rebuild for Debian Stretch
172
173 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
174
df67a3dc
DM
175pve-firewall (2.0-33) unstable; urgency=medium
176
177 * ipset: don't allow zero-prefix entries
178
179 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
180
dc643b4d
DM
181pve-firewall (2.0-32) unstable; urgency=medium
182
183 * improve search for local-network
184
185 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
186
45f206fd
DM
187pve-firewall (2.0-31) unstable; urgency=medium
188
189 * don't try to apply ports to rules which don't support them
190
191 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
192
2ea28d0c
DM
193pve-firewall (2.0-30) unstable; urgency=medium
194
195 * add multicast DNS to the list of Macros
196
197 * add missing parameter descriptions
198
199 * build-depends: add dh-systemd
200
201 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
202
b65d13d9
DM
203pve-firewall (2.0-29) unstable; urgency=medium
204
205 * prevent overwriting ipsets/sec. groups by renaming
206
207 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
208
d0f3bb08
DM
209pve-firewall (2.0-28) unstable; urgency=medium
210
211 * use pve-common's ipv4_mask_hash_localnet
212
5c53cde4
DC
213 * fix allowed group name length
214
215 * make group digest stable
216
d0f3bb08
DM
217 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
218
76a57e1a
DM
219pve-firewall (2.0-27) unstable; urgency=medium
220
221 * fix #972: make PVEFW-FWBR-* rule order stable
222
223 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
224
17642172
DM
225pve-firewall (2.0-26) unstable; urgency=medium
226
227 * fix #988: set rp_filter=2
228
229 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
230
6e29af12
DM
231pve-firewall (2.0-25) unstable; urgency=medium
232
233 * fix #945: add uninitialized check in lxc ipset compilation
234
235 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
236
edb4aff5
DM
237pve-firewall (2.0-24) unstable; urgency=medium
238
239 * Build-Depend on pve-doc-generator
240
241 * generate manpage with pve-doc-generator
242
243 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
244
e1158c15
DM
245pve-firewall (2.0-23) unstable; urgency=medium
246
247 * use only the top bit for our accept marks
248
249 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
250
5399f912
DM
251pve-firewall (2.0-22) unstable; urgency=medium
252
253 * Use cfs_config_path from PVE::QemuConfig
254
255 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
256
b9e73915
DM
257pve-firewall (2.0-21) unstable; urgency=medium
258
259 * added new 'ipfilter' option
260
261 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
262
e2a49003
DM
263pve-firewall (2.0-20) unstable; urgency=medium
264
265 * fix 901: encode unicode characters in sha digest
266
267 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
268
1d10f89a
DM
269pve-firewall (2.0-19) unstable; urgency=medium
270
271 * Add radv option to VM options
272
273 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
274
666093cd
DM
275pve-firewall (2.0-18) unstable; urgency=medium
276
277 * Add ndp option to host and VM firewall options
278
279 * Add router-solicitation to NeighborDiscovery macro
280
281 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
282
eaf25885
DM
283pve-firewall (2.0-17) unstable; urgency=medium
284
285 * Don't leave empty FW config files behind
286
287 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
288
a177fb07
DM
289pve-firewall (2.0-16) unstable; urgency=medium
290
291 * logger: basic ipv6 support
292
293 * add DHCPv6 macro
294
295 * add dhcpv6 support to the dhcp option
296
297 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
298
ab1b8d3c
DM
299pve-firewall (2.0-15) unstable; urgency=medium
300
301 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
302
303 * fix some regular expressions mixups
304
305 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
306
c9c8d7a3
DM
307pve-firewall (2.0-14) unstable; urgency=medium
308
309 * fix systemd service dependencies
310
311 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
312
aa818ae7
DM
313pve-firewall (2.0-13) unstable; urgency=medium
314
315 * allow numeric icmp types
316
317 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
318
8dbebe7d
DM
319pve-firewall (2.0-12) unstable; urgency=medium
320
321 * implement bash completions
322
323 * convert pve-firewall into a PVE::Service class
324
325 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
326
47704f4c
DM
327pve-firewall (2.0-11) unstable; urgency=medium
328
329 * iptables_get_chains: fix veth device name
330
331 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
332
9eb84dc7
DM
333pve-firewall (2.0-10) unstable; urgency=medium
334
335 * new helper: clone_vmfw_conf()
336
337 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
338
a3d34dac
DM
339pve-firewall (2.0-9) unstable; urgency=medium
340
341 * remove firewall config file subroutine added
342
343 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
344
2a42a237
DM
345pve-firewall (2.0-8) unstable; urgency=medium
346
347 * adopt regresion tests for lxc containers
348
349 * removed firewall code for openVZ
350
351 * Subroutine verify_rule fixed to correctly check only for "net\d+"
352 interface device names
353
354 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
355
33448a6e
DM
356pve-firewall (2.0-7) unstable; urgency=medium
357
358 * added firewall code for lxc
359
360 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
361
19f14465
DM
362pve-firewall (2.0-6) unstable; urgency=medium
363
364 * firewall ipversion comparison fix
365
366 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
367
8feec9fa
DM
368pve-firewall (2.0-5) unstable; urgency=medium
369
370 * add ipv6 neighbor discovery and solicitation macros
371
372 * ip6tables accepts both spellings of the word neighbor
373
374 * added Ceph macro
375
376 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
377
e02c77aa
DM
378pve-firewall (2.0-4) unstable; urgency=medium
379
380 * include manual page for pve-firewall
381
382 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
383
eb4a2902
DM
384pve-firewall (2.0-3) unstable; urgency=medium
385
386 * use noawait trigers for pve-api-updates
387
388 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
389
56bb2e69
DM
390pve-firewall (2.0-2) unstable; urgency=medium
391
392 * trigger pve-api-updates event
393
394 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
395
0b18ebe8
DM
396pve-firewall (2.0-1) unstable; urgency=medium
397
398 * recompile for debian jessie
399
400 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
401
609f00c7
DM
402pve-firewall (1.0-18) unstable; urgency=low
403
404 * fix alias lookup
405
406 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
407
de48e659
DM
408pve-firewall (1.0-17) unstable; urgency=low
409
410 * fix restart behavior
411
412 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
413
b92d2ed2
DM
414pve-firewall (1.0-16) unstable; urgency=low
415
416 * use new Daemon class from pve-common
417
418 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
419
22dde8d6
DM
420pve-firewall (1.0-15) unstable; urgency=low
421
422 * bug fix: load cluster conf for host rules
423
424 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
425
e33e2f16
DM
426pve-firewall (1.0-14) unstable; urgency=low
427
428 * do not use ipset list chains
429
430 * remove preinst script (not needed anymore)
431
432 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
433
3bce273b
DM
434pve-firewall (1.0-13) unstable; urgency=low
435
436 * fix ipset remove order
437
438 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
439
7a7c322c
DM
440pve-firewall (1.0-12) unstable; urgency=low
441
442 * add preinst script to clear ipset from older installation (because
443 sets cannot be swapped if there type does not match.
ce41ae23 444
7a7c322c
DM
445 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
446
1b918ee5
DM
447pve-firewall (1.0-11) unstable; urgency=low
448
449 * bug fix: correctly set ipversion for aliases in verify_rule
450
451 * save restore commands into files to make debugging
452 easier (/var/lib/pve-firewall/)
453
454 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
455
df617cea
DM
456pve-firewall (1.0-10) unstable; urgency=low
457
458 * add IPv6 support for VMs (hostfw is IPv4 only)
459
460 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
461
0ac57570
DM
462pve-firewall (1.0-9) unstable; urgency=low
463
464 * fix max ipset name name length
465
466 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
467
05fd3b63
DM
468pve-firewall (1.0-8) unstable; urgency=low
469
470 * implement permission
471
472 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
473
bea9d5ab
DM
474pve-firewall (1.0-7) unstable; urgency=low
475
476 * proxy host rule API calls to correct node
a34cfdd0
DM
477
478 * always generate MAC and IP filter rules if firewall is enabled on NIC
bea9d5ab
DM
479
480 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
481
582275c3
DM
482pve-firewall (1.0-6) unstable; urgency=low
483
484 * ipmlement ipfilter ipsets
485
486 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
487
de0c1e49
DM
488pve-firewall (1.0-5) unstable; urgency=low
489
490 * remove ipsets when firewall disabled
491
492 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
493
64c266f5
DM
494pve-firewall (1.0-4) unstable; urgency=low
495
496 * depend on iptables and ipset
497
498 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
499
16bcfa8b
DM
500pve-firewall (1.0-3) unstable; urgency=low
501
502 * change dh_installinit order (register pvefw-logger before pve-firewall)
503
504 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
505
ba0b3a0a
DM
506pve-firewall (1.0-2) unstable; urgency=low
507
508 * add experimental nflog logging daemon
509
510 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
511
bb272dd3
DM
512pve-firewall (1.0-1) unstable; urgency=low
513
514 * initial package
515
516 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
517