]> git.proxmox.com Git - pve-firewall.git/blame - debian/changelog
d/control: add missing Build-Depends
[pve-firewall.git] / debian / changelog
CommitLineData
a24b157b
WB
1pve-firewall (3.0-14) unstable; urgency=medium
2
3 * fix #1841: avoid ebtable reloads when containers have multiple network
4 interfaces
5
6 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
7
cf7dd94b
WB
8pve-firewall (3.0-13) unstable; urgency=medium
9
10 * avoid unnecessary reloads of ebtable ruleset
11
12 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
13
dd03bf6e
WB
14pve-firewall (3.0-12) unstable; urgency=medium
15
16 * fix deleted iptables chains not being properly detected as a change
17
18 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
19
587a0f20 20pve-firewall (3.0-11) unstable; urgency=medium
a3a51dad
TL
21
22 * #1764: rename 'ebtales_enable' option to 'ebtables'
23
587a0f20 24 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
a3a51dad 25
423b86ef
WB
26pve-firewall (3.0-10) unstable; urgency=medium
27
28 * fix #1764: handle existing ebtables rules and allow disabling ebtables
29
30 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
31 ebtables_enable option.
32
33 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
34
567e58ce
WB
35pve-firewall (3.0-9) unstable; urgency=medium
36
37 * fix creation of ebltables FORWARD rule entry
38
39 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
40
ea0d59ed
WB
41pve-firewall (3.0-8) unstable; urgency=medium
42
43 * add ebtables support for better MAC filtering
44
45 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
46
9a19ec81
WB
47pve-firewall (3.0-7) unstable; urgency=medium
48
49 * support distinct source and destination multi-port matching
50
51 * multi-port matching: when specifying the same list of ports for source and
52 destination require them both to match, rather than one of them, as this
53 was rather unexpected behavior
54
55 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
56
8c41d444
DM
57pve-firewall (3.0-6) unstable; urgency=medium
58
59 * fix #1319: don't fail postinst with masked service
60
61 * debian: switch to compat 9, drop init scripts, drop preinst
62
63 * check multiport limit in port ranges
64
65 * build: use git rev-parse for GITVERSION
66
67 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
68
4299c35f
WB
69pve-firewall (3.0-5) unstable; urgency=medium
70
71 * fix issue with disabled flag not being honored within groups
72
73 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
74
a19d4127
WB
75pve-firewall (3.0-4) unstable; urgency=medium
76
77 * fix issues with ipsets reloading unnecessarily or too late
78
79 * fix some typos in the logs
80
81 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
82
c0c71b1b
WB
83pve-firewall (3.0-3) unstable; urgency=medium
84
85 * Fix #1492: logger: use current timestamp if the packet doesn't have one
86
87 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
88
4f7a4bdd
WB
89pve-firewall (3.0-2) unstable; urgency=medium
90
91 * Fix #1446: remove masks in case the package had previously been removed but
92 not purged.
93
94 * improve logging on errors in the firewall configuration
95
96 * forbid trailing commas in lists as iptables-restore doesn't support them
97
98 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
99
29a94c79
FG
100pve-firewall (3.0-1) unstable; urgency=medium
101
102 * rebuild for Debian Stretch
103
104 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
105
df67a3dc
DM
106pve-firewall (2.0-33) unstable; urgency=medium
107
108 * ipset: don't allow zero-prefix entries
109
110 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
111
dc643b4d
DM
112pve-firewall (2.0-32) unstable; urgency=medium
113
114 * improve search for local-network
115
116 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
117
45f206fd
DM
118pve-firewall (2.0-31) unstable; urgency=medium
119
120 * don't try to apply ports to rules which don't support them
121
122 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
123
2ea28d0c
DM
124pve-firewall (2.0-30) unstable; urgency=medium
125
126 * add multicast DNS to the list of Macros
127
128 * add missing parameter descriptions
129
130 * build-depends: add dh-systemd
131
132 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
133
b65d13d9
DM
134pve-firewall (2.0-29) unstable; urgency=medium
135
136 * prevent overwriting ipsets/sec. groups by renaming
137
138 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
139
d0f3bb08
DM
140pve-firewall (2.0-28) unstable; urgency=medium
141
142 * use pve-common's ipv4_mask_hash_localnet
143
5c53cde4
DC
144 * fix allowed group name length
145
146 * make group digest stable
147
d0f3bb08
DM
148 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
149
76a57e1a
DM
150pve-firewall (2.0-27) unstable; urgency=medium
151
152 * fix #972: make PVEFW-FWBR-* rule order stable
153
154 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
155
17642172
DM
156pve-firewall (2.0-26) unstable; urgency=medium
157
158 * fix #988: set rp_filter=2
159
160 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
161
6e29af12
DM
162pve-firewall (2.0-25) unstable; urgency=medium
163
164 * fix #945: add uninitialized check in lxc ipset compilation
165
166 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
167
edb4aff5
DM
168pve-firewall (2.0-24) unstable; urgency=medium
169
170 * Build-Depend on pve-doc-generator
171
172 * generate manpage with pve-doc-generator
173
174 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
175
e1158c15
DM
176pve-firewall (2.0-23) unstable; urgency=medium
177
178 * use only the top bit for our accept marks
179
180 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
181
5399f912
DM
182pve-firewall (2.0-22) unstable; urgency=medium
183
184 * Use cfs_config_path from PVE::QemuConfig
185
186 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
187
b9e73915
DM
188pve-firewall (2.0-21) unstable; urgency=medium
189
190 * added new 'ipfilter' option
191
192 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
193
e2a49003
DM
194pve-firewall (2.0-20) unstable; urgency=medium
195
196 * fix 901: encode unicode characters in sha digest
197
198 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
199
1d10f89a
DM
200pve-firewall (2.0-19) unstable; urgency=medium
201
202 * Add radv option to VM options
203
204 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
205
666093cd
DM
206pve-firewall (2.0-18) unstable; urgency=medium
207
208 * Add ndp option to host and VM firewall options
209
210 * Add router-solicitation to NeighborDiscovery macro
211
212 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
213
eaf25885
DM
214pve-firewall (2.0-17) unstable; urgency=medium
215
216 * Don't leave empty FW config files behind
217
218 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
219
a177fb07
DM
220pve-firewall (2.0-16) unstable; urgency=medium
221
222 * logger: basic ipv6 support
223
224 * add DHCPv6 macro
225
226 * add dhcpv6 support to the dhcp option
227
228 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
229
ab1b8d3c
DM
230pve-firewall (2.0-15) unstable; urgency=medium
231
232 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
233
234 * fix some regular expressions mixups
235
236 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
237
c9c8d7a3
DM
238pve-firewall (2.0-14) unstable; urgency=medium
239
240 * fix systemd service dependencies
241
242 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
243
aa818ae7
DM
244pve-firewall (2.0-13) unstable; urgency=medium
245
246 * allow numeric icmp types
247
248 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
249
8dbebe7d
DM
250pve-firewall (2.0-12) unstable; urgency=medium
251
252 * implement bash completions
253
254 * convert pve-firewall into a PVE::Service class
255
256 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
257
47704f4c
DM
258pve-firewall (2.0-11) unstable; urgency=medium
259
260 * iptables_get_chains: fix veth device name
261
262 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
263
9eb84dc7
DM
264pve-firewall (2.0-10) unstable; urgency=medium
265
266 * new helper: clone_vmfw_conf()
267
268 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
269
a3d34dac
DM
270pve-firewall (2.0-9) unstable; urgency=medium
271
272 * remove firewall config file subroutine added
273
274 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
275
2a42a237
DM
276pve-firewall (2.0-8) unstable; urgency=medium
277
278 * adopt regresion tests for lxc containers
279
280 * removed firewall code for openVZ
281
282 * Subroutine verify_rule fixed to correctly check only for "net\d+"
283 interface device names
284
285 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
286
33448a6e
DM
287pve-firewall (2.0-7) unstable; urgency=medium
288
289 * added firewall code for lxc
290
291 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
292
19f14465
DM
293pve-firewall (2.0-6) unstable; urgency=medium
294
295 * firewall ipversion comparison fix
296
297 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
298
8feec9fa
DM
299pve-firewall (2.0-5) unstable; urgency=medium
300
301 * add ipv6 neighbor discovery and solicitation macros
302
303 * ip6tables accepts both spellings of the word neighbor
304
305 * added Ceph macro
306
307 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
308
e02c77aa
DM
309pve-firewall (2.0-4) unstable; urgency=medium
310
311 * include manual page for pve-firewall
312
313 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
314
eb4a2902
DM
315pve-firewall (2.0-3) unstable; urgency=medium
316
317 * use noawait trigers for pve-api-updates
318
319 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
320
56bb2e69
DM
321pve-firewall (2.0-2) unstable; urgency=medium
322
323 * trigger pve-api-updates event
324
325 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
326
0b18ebe8
DM
327pve-firewall (2.0-1) unstable; urgency=medium
328
329 * recompile for debian jessie
330
331 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
332
609f00c7
DM
333pve-firewall (1.0-18) unstable; urgency=low
334
335 * fix alias lookup
336
337 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
338
de48e659
DM
339pve-firewall (1.0-17) unstable; urgency=low
340
341 * fix restart behavior
342
343 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
344
b92d2ed2
DM
345pve-firewall (1.0-16) unstable; urgency=low
346
347 * use new Daemon class from pve-common
348
349 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
350
22dde8d6
DM
351pve-firewall (1.0-15) unstable; urgency=low
352
353 * bug fix: load cluster conf for host rules
354
355 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
356
e33e2f16
DM
357pve-firewall (1.0-14) unstable; urgency=low
358
359 * do not use ipset list chains
360
361 * remove preinst script (not needed anymore)
362
363 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
364
3bce273b
DM
365pve-firewall (1.0-13) unstable; urgency=low
366
367 * fix ipset remove order
368
369 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
370
7a7c322c
DM
371pve-firewall (1.0-12) unstable; urgency=low
372
373 * add preinst script to clear ipset from older installation (because
374 sets cannot be swapped if there type does not match.
ce41ae23 375
7a7c322c
DM
376 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
377
1b918ee5
DM
378pve-firewall (1.0-11) unstable; urgency=low
379
380 * bug fix: correctly set ipversion for aliases in verify_rule
381
382 * save restore commands into files to make debugging
383 easier (/var/lib/pve-firewall/)
384
385 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
386
df617cea
DM
387pve-firewall (1.0-10) unstable; urgency=low
388
389 * add IPv6 support for VMs (hostfw is IPv4 only)
390
391 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
392
0ac57570
DM
393pve-firewall (1.0-9) unstable; urgency=low
394
395 * fix max ipset name name length
396
397 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
398
05fd3b63
DM
399pve-firewall (1.0-8) unstable; urgency=low
400
401 * implement permission
402
403 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
404
bea9d5ab
DM
405pve-firewall (1.0-7) unstable; urgency=low
406
407 * proxy host rule API calls to correct node
a34cfdd0
DM
408
409 * always generate MAC and IP filter rules if firewall is enabled on NIC
bea9d5ab
DM
410
411 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
412
582275c3
DM
413pve-firewall (1.0-6) unstable; urgency=low
414
415 * ipmlement ipfilter ipsets
416
417 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
418
de0c1e49
DM
419pve-firewall (1.0-5) unstable; urgency=low
420
421 * remove ipsets when firewall disabled
422
423 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
424
64c266f5
DM
425pve-firewall (1.0-4) unstable; urgency=low
426
427 * depend on iptables and ipset
428
429 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
430
16bcfa8b
DM
431pve-firewall (1.0-3) unstable; urgency=low
432
433 * change dh_installinit order (register pvefw-logger before pve-firewall)
434
435 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
436
ba0b3a0a
DM
437pve-firewall (1.0-2) unstable; urgency=low
438
439 * add experimental nflog logging daemon
440
441 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
442
bb272dd3
DM
443pve-firewall (1.0-1) unstable; urgency=low
444
445 * initial package
446
447 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
448