]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
4f8df311285d726119bcc3e1296c75e3a6d71176
[pve-firewall.git] / debian / changelog
1 pve-firewall (3.0-20) unstable; urgency=medium
2
3 * use IPCC to read config and rule files, if the are backed by pmxcfs which
4 has better handling for pmxcfs restarts
5
6 * fix #2178: endless loop on ipv6 extension headers
7
8 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
9
10 pve-firewall (3.0-19) unstable; urgency=medium
11
12 * ebtables: add arp filtering
13
14 * fix: #2123 Logging of user defined firewall rules
15
16 * fix Razor macro
17
18 * allow to enable/disable and modify cluster wide log ratelimits
19
20 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
21
22 pve-firewall (3.0-18) unstable; urgency=medium
23
24 * fix #1606: Add nf_conntrack_allow_invalid option
25
26 * log reject : add space after policy REJECT like drop
27
28 * fix #1891: Add zsh command completion for pve-firewall
29
30 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
31
32 pve-firewall (3.0-17) unstable; urgency=medium
33
34 * fix #2005: only allow ascii port digits
35
36 * fix #2004: do not allow backwards ranges
37
38 * add conntrack logging via libnetfilter_conntrack and allow one to enable
39 it through the firewall host configuration
40
41 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
42
43 pve-firewall (3.0-16) unstable; urgency=medium
44
45 * api/rules: fix macro return type
46
47 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
48
49 pve-firewall (3.0-15) unstable; urgency=medium
50
51 * fix #1971: display firewall rule properties
52
53 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
54
55 pve-firewall (3.0-14) unstable; urgency=medium
56
57 * fix #1841: avoid ebtable reloads when containers have multiple network
58 interfaces
59
60 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
61
62 pve-firewall (3.0-13) unstable; urgency=medium
63
64 * avoid unnecessary reloads of ebtable ruleset
65
66 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
67
68 pve-firewall (3.0-12) unstable; urgency=medium
69
70 * fix deleted iptables chains not being properly detected as a change
71
72 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
73
74 pve-firewall (3.0-11) unstable; urgency=medium
75
76 * #1764: rename 'ebtales_enable' option to 'ebtables'
77
78 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
79
80 pve-firewall (3.0-10) unstable; urgency=medium
81
82 * fix #1764: handle existing ebtables rules and allow disabling ebtables
83
84 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
85 ebtables_enable option.
86
87 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
88
89 pve-firewall (3.0-9) unstable; urgency=medium
90
91 * fix creation of ebltables FORWARD rule entry
92
93 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
94
95 pve-firewall (3.0-8) unstable; urgency=medium
96
97 * add ebtables support for better MAC filtering
98
99 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
100
101 pve-firewall (3.0-7) unstable; urgency=medium
102
103 * support distinct source and destination multi-port matching
104
105 * multi-port matching: when specifying the same list of ports for source and
106 destination require them both to match, rather than one of them, as this
107 was rather unexpected behavior
108
109 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
110
111 pve-firewall (3.0-6) unstable; urgency=medium
112
113 * fix #1319: don't fail postinst with masked service
114
115 * debian: switch to compat 9, drop init scripts, drop preinst
116
117 * check multiport limit in port ranges
118
119 * build: use git rev-parse for GITVERSION
120
121 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
122
123 pve-firewall (3.0-5) unstable; urgency=medium
124
125 * fix issue with disabled flag not being honored within groups
126
127 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
128
129 pve-firewall (3.0-4) unstable; urgency=medium
130
131 * fix issues with ipsets reloading unnecessarily or too late
132
133 * fix some typos in the logs
134
135 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
136
137 pve-firewall (3.0-3) unstable; urgency=medium
138
139 * Fix #1492: logger: use current timestamp if the packet doesn't have one
140
141 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
142
143 pve-firewall (3.0-2) unstable; urgency=medium
144
145 * Fix #1446: remove masks in case the package had previously been removed but
146 not purged.
147
148 * improve logging on errors in the firewall configuration
149
150 * forbid trailing commas in lists as iptables-restore doesn't support them
151
152 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
153
154 pve-firewall (3.0-1) unstable; urgency=medium
155
156 * rebuild for Debian Stretch
157
158 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
159
160 pve-firewall (2.0-33) unstable; urgency=medium
161
162 * ipset: don't allow zero-prefix entries
163
164 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
165
166 pve-firewall (2.0-32) unstable; urgency=medium
167
168 * improve search for local-network
169
170 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
171
172 pve-firewall (2.0-31) unstable; urgency=medium
173
174 * don't try to apply ports to rules which don't support them
175
176 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
177
178 pve-firewall (2.0-30) unstable; urgency=medium
179
180 * add multicast DNS to the list of Macros
181
182 * add missing parameter descriptions
183
184 * build-depends: add dh-systemd
185
186 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
187
188 pve-firewall (2.0-29) unstable; urgency=medium
189
190 * prevent overwriting ipsets/sec. groups by renaming
191
192 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
193
194 pve-firewall (2.0-28) unstable; urgency=medium
195
196 * use pve-common's ipv4_mask_hash_localnet
197
198 * fix allowed group name length
199
200 * make group digest stable
201
202 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
203
204 pve-firewall (2.0-27) unstable; urgency=medium
205
206 * fix #972: make PVEFW-FWBR-* rule order stable
207
208 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
209
210 pve-firewall (2.0-26) unstable; urgency=medium
211
212 * fix #988: set rp_filter=2
213
214 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
215
216 pve-firewall (2.0-25) unstable; urgency=medium
217
218 * fix #945: add uninitialized check in lxc ipset compilation
219
220 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
221
222 pve-firewall (2.0-24) unstable; urgency=medium
223
224 * Build-Depend on pve-doc-generator
225
226 * generate manpage with pve-doc-generator
227
228 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
229
230 pve-firewall (2.0-23) unstable; urgency=medium
231
232 * use only the top bit for our accept marks
233
234 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
235
236 pve-firewall (2.0-22) unstable; urgency=medium
237
238 * Use cfs_config_path from PVE::QemuConfig
239
240 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
241
242 pve-firewall (2.0-21) unstable; urgency=medium
243
244 * added new 'ipfilter' option
245
246 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
247
248 pve-firewall (2.0-20) unstable; urgency=medium
249
250 * fix 901: encode unicode characters in sha digest
251
252 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
253
254 pve-firewall (2.0-19) unstable; urgency=medium
255
256 * Add radv option to VM options
257
258 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
259
260 pve-firewall (2.0-18) unstable; urgency=medium
261
262 * Add ndp option to host and VM firewall options
263
264 * Add router-solicitation to NeighborDiscovery macro
265
266 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
267
268 pve-firewall (2.0-17) unstable; urgency=medium
269
270 * Don't leave empty FW config files behind
271
272 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
273
274 pve-firewall (2.0-16) unstable; urgency=medium
275
276 * logger: basic ipv6 support
277
278 * add DHCPv6 macro
279
280 * add dhcpv6 support to the dhcp option
281
282 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
283
284 pve-firewall (2.0-15) unstable; urgency=medium
285
286 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
287
288 * fix some regular expressions mixups
289
290 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
291
292 pve-firewall (2.0-14) unstable; urgency=medium
293
294 * fix systemd service dependencies
295
296 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
297
298 pve-firewall (2.0-13) unstable; urgency=medium
299
300 * allow numeric icmp types
301
302 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
303
304 pve-firewall (2.0-12) unstable; urgency=medium
305
306 * implement bash completions
307
308 * convert pve-firewall into a PVE::Service class
309
310 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
311
312 pve-firewall (2.0-11) unstable; urgency=medium
313
314 * iptables_get_chains: fix veth device name
315
316 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
317
318 pve-firewall (2.0-10) unstable; urgency=medium
319
320 * new helper: clone_vmfw_conf()
321
322 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
323
324 pve-firewall (2.0-9) unstable; urgency=medium
325
326 * remove firewall config file subroutine added
327
328 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
329
330 pve-firewall (2.0-8) unstable; urgency=medium
331
332 * adopt regresion tests for lxc containers
333
334 * removed firewall code for openVZ
335
336 * Subroutine verify_rule fixed to correctly check only for "net\d+"
337 interface device names
338
339 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
340
341 pve-firewall (2.0-7) unstable; urgency=medium
342
343 * added firewall code for lxc
344
345 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
346
347 pve-firewall (2.0-6) unstable; urgency=medium
348
349 * firewall ipversion comparison fix
350
351 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
352
353 pve-firewall (2.0-5) unstable; urgency=medium
354
355 * add ipv6 neighbor discovery and solicitation macros
356
357 * ip6tables accepts both spellings of the word neighbor
358
359 * added Ceph macro
360
361 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
362
363 pve-firewall (2.0-4) unstable; urgency=medium
364
365 * include manual page for pve-firewall
366
367 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
368
369 pve-firewall (2.0-3) unstable; urgency=medium
370
371 * use noawait trigers for pve-api-updates
372
373 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
374
375 pve-firewall (2.0-2) unstable; urgency=medium
376
377 * trigger pve-api-updates event
378
379 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
380
381 pve-firewall (2.0-1) unstable; urgency=medium
382
383 * recompile for debian jessie
384
385 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
386
387 pve-firewall (1.0-18) unstable; urgency=low
388
389 * fix alias lookup
390
391 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
392
393 pve-firewall (1.0-17) unstable; urgency=low
394
395 * fix restart behavior
396
397 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
398
399 pve-firewall (1.0-16) unstable; urgency=low
400
401 * use new Daemon class from pve-common
402
403 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
404
405 pve-firewall (1.0-15) unstable; urgency=low
406
407 * bug fix: load cluster conf for host rules
408
409 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
410
411 pve-firewall (1.0-14) unstable; urgency=low
412
413 * do not use ipset list chains
414
415 * remove preinst script (not needed anymore)
416
417 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
418
419 pve-firewall (1.0-13) unstable; urgency=low
420
421 * fix ipset remove order
422
423 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
424
425 pve-firewall (1.0-12) unstable; urgency=low
426
427 * add preinst script to clear ipset from older installation (because
428 sets cannot be swapped if there type does not match.
429
430 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
431
432 pve-firewall (1.0-11) unstable; urgency=low
433
434 * bug fix: correctly set ipversion for aliases in verify_rule
435
436 * save restore commands into files to make debugging
437 easier (/var/lib/pve-firewall/)
438
439 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
440
441 pve-firewall (1.0-10) unstable; urgency=low
442
443 * add IPv6 support for VMs (hostfw is IPv4 only)
444
445 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
446
447 pve-firewall (1.0-9) unstable; urgency=low
448
449 * fix max ipset name name length
450
451 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
452
453 pve-firewall (1.0-8) unstable; urgency=low
454
455 * implement permission
456
457 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
458
459 pve-firewall (1.0-7) unstable; urgency=low
460
461 * proxy host rule API calls to correct node
462
463 * always generate MAC and IP filter rules if firewall is enabled on NIC
464
465 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
466
467 pve-firewall (1.0-6) unstable; urgency=low
468
469 * ipmlement ipfilter ipsets
470
471 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
472
473 pve-firewall (1.0-5) unstable; urgency=low
474
475 * remove ipsets when firewall disabled
476
477 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
478
479 pve-firewall (1.0-4) unstable; urgency=low
480
481 * depend on iptables and ipset
482
483 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
484
485 pve-firewall (1.0-3) unstable; urgency=low
486
487 * change dh_installinit order (register pvefw-logger before pve-firewall)
488
489 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
490
491 pve-firewall (1.0-2) unstable; urgency=low
492
493 * add experimental nflog logging daemon
494
495 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
496
497 pve-firewall (1.0-1) unstable; urgency=low
498
499 * initial package
500
501 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
502