]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
bump version to 3.0-8
[pve-firewall.git] / debian / changelog
1 pve-firewall (3.0-8) unstable; urgency=medium
2
3 * add ebtables support for better MAC filtering
4
5 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
6
7 pve-firewall (3.0-7) unstable; urgency=medium
8
9 * support distinct source and destination multi-port matching
10
11 * multi-port matching: when specifying the same list of ports for source and
12 destination require them both to match, rather than one of them, as this
13 was rather unexpected behavior
14
15 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
16
17 pve-firewall (3.0-6) unstable; urgency=medium
18
19 * fix #1319: don't fail postinst with masked service
20
21 * debian: switch to compat 9, drop init scripts, drop preinst
22
23 * check multiport limit in port ranges
24
25 * build: use git rev-parse for GITVERSION
26
27 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
28
29 pve-firewall (3.0-5) unstable; urgency=medium
30
31 * fix issue with disabled flag not being honored within groups
32
33 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
34
35 pve-firewall (3.0-4) unstable; urgency=medium
36
37 * fix issues with ipsets reloading unnecessarily or too late
38
39 * fix some typos in the logs
40
41 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
42
43 pve-firewall (3.0-3) unstable; urgency=medium
44
45 * Fix #1492: logger: use current timestamp if the packet doesn't have one
46
47 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
48
49 pve-firewall (3.0-2) unstable; urgency=medium
50
51 * Fix #1446: remove masks in case the package had previously been removed but
52 not purged.
53
54 * improve logging on errors in the firewall configuration
55
56 * forbid trailing commas in lists as iptables-restore doesn't support them
57
58 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
59
60 pve-firewall (3.0-1) unstable; urgency=medium
61
62 * rebuild for Debian Stretch
63
64 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
65
66 pve-firewall (2.0-33) unstable; urgency=medium
67
68 * ipset: don't allow zero-prefix entries
69
70 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
71
72 pve-firewall (2.0-32) unstable; urgency=medium
73
74 * improve search for local-network
75
76 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
77
78 pve-firewall (2.0-31) unstable; urgency=medium
79
80 * don't try to apply ports to rules which don't support them
81
82 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
83
84 pve-firewall (2.0-30) unstable; urgency=medium
85
86 * add multicast DNS to the list of Macros
87
88 * add missing parameter descriptions
89
90 * build-depends: add dh-systemd
91
92 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
93
94 pve-firewall (2.0-29) unstable; urgency=medium
95
96 * prevent overwriting ipsets/sec. groups by renaming
97
98 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
99
100 pve-firewall (2.0-28) unstable; urgency=medium
101
102 * use pve-common's ipv4_mask_hash_localnet
103
104 * fix allowed group name length
105
106 * make group digest stable
107
108 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
109
110 pve-firewall (2.0-27) unstable; urgency=medium
111
112 * fix #972: make PVEFW-FWBR-* rule order stable
113
114 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
115
116 pve-firewall (2.0-26) unstable; urgency=medium
117
118 * fix #988: set rp_filter=2
119
120 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
121
122 pve-firewall (2.0-25) unstable; urgency=medium
123
124 * fix #945: add uninitialized check in lxc ipset compilation
125
126 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
127
128 pve-firewall (2.0-24) unstable; urgency=medium
129
130 * Build-Depend on pve-doc-generator
131
132 * generate manpage with pve-doc-generator
133
134 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
135
136 pve-firewall (2.0-23) unstable; urgency=medium
137
138 * use only the top bit for our accept marks
139
140 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
141
142 pve-firewall (2.0-22) unstable; urgency=medium
143
144 * Use cfs_config_path from PVE::QemuConfig
145
146 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
147
148 pve-firewall (2.0-21) unstable; urgency=medium
149
150 * added new 'ipfilter' option
151
152 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
153
154 pve-firewall (2.0-20) unstable; urgency=medium
155
156 * fix 901: encode unicode characters in sha digest
157
158 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
159
160 pve-firewall (2.0-19) unstable; urgency=medium
161
162 * Add radv option to VM options
163
164 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
165
166 pve-firewall (2.0-18) unstable; urgency=medium
167
168 * Add ndp option to host and VM firewall options
169
170 * Add router-solicitation to NeighborDiscovery macro
171
172 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
173
174 pve-firewall (2.0-17) unstable; urgency=medium
175
176 * Don't leave empty FW config files behind
177
178 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
179
180 pve-firewall (2.0-16) unstable; urgency=medium
181
182 * logger: basic ipv6 support
183
184 * add DHCPv6 macro
185
186 * add dhcpv6 support to the dhcp option
187
188 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
189
190 pve-firewall (2.0-15) unstable; urgency=medium
191
192 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
193
194 * fix some regular expressions mixups
195
196 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
197
198 pve-firewall (2.0-14) unstable; urgency=medium
199
200 * fix systemd service dependencies
201
202 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
203
204 pve-firewall (2.0-13) unstable; urgency=medium
205
206 * allow numeric icmp types
207
208 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
209
210 pve-firewall (2.0-12) unstable; urgency=medium
211
212 * implement bash completions
213
214 * convert pve-firewall into a PVE::Service class
215
216 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
217
218 pve-firewall (2.0-11) unstable; urgency=medium
219
220 * iptables_get_chains: fix veth device name
221
222 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
223
224 pve-firewall (2.0-10) unstable; urgency=medium
225
226 * new helper: clone_vmfw_conf()
227
228 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
229
230 pve-firewall (2.0-9) unstable; urgency=medium
231
232 * remove firewall config file subroutine added
233
234 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
235
236 pve-firewall (2.0-8) unstable; urgency=medium
237
238 * adopt regresion tests for lxc containers
239
240 * removed firewall code for openVZ
241
242 * Subroutine verify_rule fixed to correctly check only for "net\d+"
243 interface device names
244
245 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
246
247 pve-firewall (2.0-7) unstable; urgency=medium
248
249 * added firewall code for lxc
250
251 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
252
253 pve-firewall (2.0-6) unstable; urgency=medium
254
255 * firewall ipversion comparison fix
256
257 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
258
259 pve-firewall (2.0-5) unstable; urgency=medium
260
261 * add ipv6 neighbor discovery and solicitation macros
262
263 * ip6tables accepts both spellings of the word neighbor
264
265 * added Ceph macro
266
267 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
268
269 pve-firewall (2.0-4) unstable; urgency=medium
270
271 * include manual page for pve-firewall
272
273 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
274
275 pve-firewall (2.0-3) unstable; urgency=medium
276
277 * use noawait trigers for pve-api-updates
278
279 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
280
281 pve-firewall (2.0-2) unstable; urgency=medium
282
283 * trigger pve-api-updates event
284
285 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
286
287 pve-firewall (2.0-1) unstable; urgency=medium
288
289 * recompile for debian jessie
290
291 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
292
293 pve-firewall (1.0-18) unstable; urgency=low
294
295 * fix alias lookup
296
297 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
298
299 pve-firewall (1.0-17) unstable; urgency=low
300
301 * fix restart behavior
302
303 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
304
305 pve-firewall (1.0-16) unstable; urgency=low
306
307 * use new Daemon class from pve-common
308
309 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
310
311 pve-firewall (1.0-15) unstable; urgency=low
312
313 * bug fix: load cluster conf for host rules
314
315 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
316
317 pve-firewall (1.0-14) unstable; urgency=low
318
319 * do not use ipset list chains
320
321 * remove preinst script (not needed anymore)
322
323 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
324
325 pve-firewall (1.0-13) unstable; urgency=low
326
327 * fix ipset remove order
328
329 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
330
331 pve-firewall (1.0-12) unstable; urgency=low
332
333 * add preinst script to clear ipset from older installation (because
334 sets cannot be swapped if there type does not match.
335
336 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
337
338 pve-firewall (1.0-11) unstable; urgency=low
339
340 * bug fix: correctly set ipversion for aliases in verify_rule
341
342 * save restore commands into files to make debugging
343 easier (/var/lib/pve-firewall/)
344
345 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
346
347 pve-firewall (1.0-10) unstable; urgency=low
348
349 * add IPv6 support for VMs (hostfw is IPv4 only)
350
351 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
352
353 pve-firewall (1.0-9) unstable; urgency=low
354
355 * fix max ipset name name length
356
357 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
358
359 pve-firewall (1.0-8) unstable; urgency=low
360
361 * implement permission
362
363 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
364
365 pve-firewall (1.0-7) unstable; urgency=low
366
367 * proxy host rule API calls to correct node
368
369 * always generate MAC and IP filter rules if firewall is enabled on NIC
370
371 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
372
373 pve-firewall (1.0-6) unstable; urgency=low
374
375 * ipmlement ipfilter ipsets
376
377 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
378
379 pve-firewall (1.0-5) unstable; urgency=low
380
381 * remove ipsets when firewall disabled
382
383 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
384
385 pve-firewall (1.0-4) unstable; urgency=low
386
387 * depend on iptables and ipset
388
389 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
390
391 pve-firewall (1.0-3) unstable; urgency=low
392
393 * change dh_installinit order (register pvefw-logger before pve-firewall)
394
395 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
396
397 pve-firewall (1.0-2) unstable; urgency=low
398
399 * add experimental nflog logging daemon
400
401 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
402
403 pve-firewall (1.0-1) unstable; urgency=low
404
405 * initial package
406
407 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
408