]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
6f10814b02caaf3bbfbcc4a26da2e89d25cbab35
[pve-firewall.git] / debian / changelog
1 pve-firewall (4.0-5) pve; urgency=medium
2
3 * don't use any base path at all for calls to external binaries to make use
4 compativle with bot, /usr merged and unmerged setups
5
6 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Jul 2019 11:47:53 +0200
7
8 pve-firewall (4.0-4) pve; urgency=medium
9
10 * ebtables: remove PVE chains properly
11
12 * ebtables: treat chain deletion as change
13
14 * use /usr/sbin as base path
15
16 -- Proxmox Support Team <support@proxmox.com> Thu, 11 Jul 2019 19:40:01 +0200
17
18 pve-firewall (4.0-3) pve; urgency=medium
19
20 * Create corosync firewall rules independently of localnet~
21
22 * Display corosync rule info on localnet call
23
24 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
25
26 pve-firewall (4.0-2) pve; urgency=medium
27
28 * fix systemd warning about PIDFile directory
29
30 * fix CT rule generation with ipfilter set
31
32 * pve-firewall service: update-alternative iptables and ebtables to working
33 legacy versions
34
35 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
36
37 pve-firewall (4.0-1) pve; urgency=medium
38
39 * re-build for Debian Buster / PVE 6
40
41 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
42
43 pve-firewall (3.0-21) unstable; urgency=medium
44
45 * fix ipv6 PVEFW-reject
46
47 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
48 ebtables doing the wrong thing here
49
50 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
51
52 pve-firewall (3.0-20) unstable; urgency=medium
53
54 * use IPCC to read config and rule files, if the are backed by pmxcfs which
55 has better handling for pmxcfs restarts
56
57 * fix #2178: endless loop on ipv6 extension headers
58
59 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
60
61 pve-firewall (3.0-19) unstable; urgency=medium
62
63 * ebtables: add arp filtering
64
65 * fix: #2123 Logging of user defined firewall rules
66
67 * fix Razor macro
68
69 * allow to enable/disable and modify cluster wide log ratelimits
70
71 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
72
73 pve-firewall (3.0-18) unstable; urgency=medium
74
75 * fix #1606: Add nf_conntrack_allow_invalid option
76
77 * log reject : add space after policy REJECT like drop
78
79 * fix #1891: Add zsh command completion for pve-firewall
80
81 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
82
83 pve-firewall (3.0-17) unstable; urgency=medium
84
85 * fix #2005: only allow ascii port digits
86
87 * fix #2004: do not allow backwards ranges
88
89 * add conntrack logging via libnetfilter_conntrack and allow one to enable
90 it through the firewall host configuration
91
92 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
93
94 pve-firewall (3.0-16) unstable; urgency=medium
95
96 * api/rules: fix macro return type
97
98 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
99
100 pve-firewall (3.0-15) unstable; urgency=medium
101
102 * fix #1971: display firewall rule properties
103
104 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
105
106 pve-firewall (3.0-14) unstable; urgency=medium
107
108 * fix #1841: avoid ebtable reloads when containers have multiple network
109 interfaces
110
111 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
112
113 pve-firewall (3.0-13) unstable; urgency=medium
114
115 * avoid unnecessary reloads of ebtable ruleset
116
117 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
118
119 pve-firewall (3.0-12) unstable; urgency=medium
120
121 * fix deleted iptables chains not being properly detected as a change
122
123 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
124
125 pve-firewall (3.0-11) unstable; urgency=medium
126
127 * #1764: rename 'ebtales_enable' option to 'ebtables'
128
129 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
130
131 pve-firewall (3.0-10) unstable; urgency=medium
132
133 * fix #1764: handle existing ebtables rules and allow disabling ebtables
134
135 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
136 ebtables_enable option.
137
138 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
139
140 pve-firewall (3.0-9) unstable; urgency=medium
141
142 * fix creation of ebltables FORWARD rule entry
143
144 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
145
146 pve-firewall (3.0-8) unstable; urgency=medium
147
148 * add ebtables support for better MAC filtering
149
150 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
151
152 pve-firewall (3.0-7) unstable; urgency=medium
153
154 * support distinct source and destination multi-port matching
155
156 * multi-port matching: when specifying the same list of ports for source and
157 destination require them both to match, rather than one of them, as this
158 was rather unexpected behavior
159
160 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
161
162 pve-firewall (3.0-6) unstable; urgency=medium
163
164 * fix #1319: don't fail postinst with masked service
165
166 * debian: switch to compat 9, drop init scripts, drop preinst
167
168 * check multiport limit in port ranges
169
170 * build: use git rev-parse for GITVERSION
171
172 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
173
174 pve-firewall (3.0-5) unstable; urgency=medium
175
176 * fix issue with disabled flag not being honored within groups
177
178 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
179
180 pve-firewall (3.0-4) unstable; urgency=medium
181
182 * fix issues with ipsets reloading unnecessarily or too late
183
184 * fix some typos in the logs
185
186 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
187
188 pve-firewall (3.0-3) unstable; urgency=medium
189
190 * Fix #1492: logger: use current timestamp if the packet doesn't have one
191
192 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
193
194 pve-firewall (3.0-2) unstable; urgency=medium
195
196 * Fix #1446: remove masks in case the package had previously been removed but
197 not purged.
198
199 * improve logging on errors in the firewall configuration
200
201 * forbid trailing commas in lists as iptables-restore doesn't support them
202
203 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
204
205 pve-firewall (3.0-1) unstable; urgency=medium
206
207 * rebuild for Debian Stretch
208
209 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
210
211 pve-firewall (2.0-33) unstable; urgency=medium
212
213 * ipset: don't allow zero-prefix entries
214
215 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
216
217 pve-firewall (2.0-32) unstable; urgency=medium
218
219 * improve search for local-network
220
221 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
222
223 pve-firewall (2.0-31) unstable; urgency=medium
224
225 * don't try to apply ports to rules which don't support them
226
227 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
228
229 pve-firewall (2.0-30) unstable; urgency=medium
230
231 * add multicast DNS to the list of Macros
232
233 * add missing parameter descriptions
234
235 * build-depends: add dh-systemd
236
237 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
238
239 pve-firewall (2.0-29) unstable; urgency=medium
240
241 * prevent overwriting ipsets/sec. groups by renaming
242
243 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
244
245 pve-firewall (2.0-28) unstable; urgency=medium
246
247 * use pve-common's ipv4_mask_hash_localnet
248
249 * fix allowed group name length
250
251 * make group digest stable
252
253 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
254
255 pve-firewall (2.0-27) unstable; urgency=medium
256
257 * fix #972: make PVEFW-FWBR-* rule order stable
258
259 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
260
261 pve-firewall (2.0-26) unstable; urgency=medium
262
263 * fix #988: set rp_filter=2
264
265 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
266
267 pve-firewall (2.0-25) unstable; urgency=medium
268
269 * fix #945: add uninitialized check in lxc ipset compilation
270
271 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
272
273 pve-firewall (2.0-24) unstable; urgency=medium
274
275 * Build-Depend on pve-doc-generator
276
277 * generate manpage with pve-doc-generator
278
279 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
280
281 pve-firewall (2.0-23) unstable; urgency=medium
282
283 * use only the top bit for our accept marks
284
285 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
286
287 pve-firewall (2.0-22) unstable; urgency=medium
288
289 * Use cfs_config_path from PVE::QemuConfig
290
291 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
292
293 pve-firewall (2.0-21) unstable; urgency=medium
294
295 * added new 'ipfilter' option
296
297 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
298
299 pve-firewall (2.0-20) unstable; urgency=medium
300
301 * fix 901: encode unicode characters in sha digest
302
303 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
304
305 pve-firewall (2.0-19) unstable; urgency=medium
306
307 * Add radv option to VM options
308
309 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
310
311 pve-firewall (2.0-18) unstable; urgency=medium
312
313 * Add ndp option to host and VM firewall options
314
315 * Add router-solicitation to NeighborDiscovery macro
316
317 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
318
319 pve-firewall (2.0-17) unstable; urgency=medium
320
321 * Don't leave empty FW config files behind
322
323 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
324
325 pve-firewall (2.0-16) unstable; urgency=medium
326
327 * logger: basic ipv6 support
328
329 * add DHCPv6 macro
330
331 * add dhcpv6 support to the dhcp option
332
333 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
334
335 pve-firewall (2.0-15) unstable; urgency=medium
336
337 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
338
339 * fix some regular expressions mixups
340
341 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
342
343 pve-firewall (2.0-14) unstable; urgency=medium
344
345 * fix systemd service dependencies
346
347 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
348
349 pve-firewall (2.0-13) unstable; urgency=medium
350
351 * allow numeric icmp types
352
353 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
354
355 pve-firewall (2.0-12) unstable; urgency=medium
356
357 * implement bash completions
358
359 * convert pve-firewall into a PVE::Service class
360
361 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
362
363 pve-firewall (2.0-11) unstable; urgency=medium
364
365 * iptables_get_chains: fix veth device name
366
367 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
368
369 pve-firewall (2.0-10) unstable; urgency=medium
370
371 * new helper: clone_vmfw_conf()
372
373 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
374
375 pve-firewall (2.0-9) unstable; urgency=medium
376
377 * remove firewall config file subroutine added
378
379 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
380
381 pve-firewall (2.0-8) unstable; urgency=medium
382
383 * adopt regresion tests for lxc containers
384
385 * removed firewall code for openVZ
386
387 * Subroutine verify_rule fixed to correctly check only for "net\d+"
388 interface device names
389
390 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
391
392 pve-firewall (2.0-7) unstable; urgency=medium
393
394 * added firewall code for lxc
395
396 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
397
398 pve-firewall (2.0-6) unstable; urgency=medium
399
400 * firewall ipversion comparison fix
401
402 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
403
404 pve-firewall (2.0-5) unstable; urgency=medium
405
406 * add ipv6 neighbor discovery and solicitation macros
407
408 * ip6tables accepts both spellings of the word neighbor
409
410 * added Ceph macro
411
412 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
413
414 pve-firewall (2.0-4) unstable; urgency=medium
415
416 * include manual page for pve-firewall
417
418 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
419
420 pve-firewall (2.0-3) unstable; urgency=medium
421
422 * use noawait trigers for pve-api-updates
423
424 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
425
426 pve-firewall (2.0-2) unstable; urgency=medium
427
428 * trigger pve-api-updates event
429
430 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
431
432 pve-firewall (2.0-1) unstable; urgency=medium
433
434 * recompile for debian jessie
435
436 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
437
438 pve-firewall (1.0-18) unstable; urgency=low
439
440 * fix alias lookup
441
442 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
443
444 pve-firewall (1.0-17) unstable; urgency=low
445
446 * fix restart behavior
447
448 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
449
450 pve-firewall (1.0-16) unstable; urgency=low
451
452 * use new Daemon class from pve-common
453
454 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
455
456 pve-firewall (1.0-15) unstable; urgency=low
457
458 * bug fix: load cluster conf for host rules
459
460 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
461
462 pve-firewall (1.0-14) unstable; urgency=low
463
464 * do not use ipset list chains
465
466 * remove preinst script (not needed anymore)
467
468 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
469
470 pve-firewall (1.0-13) unstable; urgency=low
471
472 * fix ipset remove order
473
474 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
475
476 pve-firewall (1.0-12) unstable; urgency=low
477
478 * add preinst script to clear ipset from older installation (because
479 sets cannot be swapped if there type does not match.
480
481 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
482
483 pve-firewall (1.0-11) unstable; urgency=low
484
485 * bug fix: correctly set ipversion for aliases in verify_rule
486
487 * save restore commands into files to make debugging
488 easier (/var/lib/pve-firewall/)
489
490 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
491
492 pve-firewall (1.0-10) unstable; urgency=low
493
494 * add IPv6 support for VMs (hostfw is IPv4 only)
495
496 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
497
498 pve-firewall (1.0-9) unstable; urgency=low
499
500 * fix max ipset name name length
501
502 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
503
504 pve-firewall (1.0-8) unstable; urgency=low
505
506 * implement permission
507
508 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
509
510 pve-firewall (1.0-7) unstable; urgency=low
511
512 * proxy host rule API calls to correct node
513
514 * always generate MAC and IP filter rules if firewall is enabled on NIC
515
516 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
517
518 pve-firewall (1.0-6) unstable; urgency=low
519
520 * ipmlement ipfilter ipsets
521
522 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
523
524 pve-firewall (1.0-5) unstable; urgency=low
525
526 * remove ipsets when firewall disabled
527
528 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
529
530 pve-firewall (1.0-4) unstable; urgency=low
531
532 * depend on iptables and ipset
533
534 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
535
536 pve-firewall (1.0-3) unstable; urgency=low
537
538 * change dh_installinit order (register pvefw-logger before pve-firewall)
539
540 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
541
542 pve-firewall (1.0-2) unstable; urgency=low
543
544 * add experimental nflog logging daemon
545
546 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
547
548 pve-firewall (1.0-1) unstable; urgency=low
549
550 * initial package
551
552 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
553