]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
bump version to 3.0-13
[pve-firewall.git] / debian / changelog
1 pve-firewall (3.0-13) unstable; urgency=medium
2
3 * avoid unnecessary reloads of ebtable ruleset
4
5 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
6
7 pve-firewall (3.0-12) unstable; urgency=medium
8
9 * fix deleted iptables chains not being properly detected as a change
10
11 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
12
13 pve-firewall (3.0-11) unstable; urgency=medium
14
15 * #1764: rename 'ebtales_enable' option to 'ebtables'
16
17 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
18
19 pve-firewall (3.0-10) unstable; urgency=medium
20
21 * fix #1764: handle existing ebtables rules and allow disabling ebtables
22
23 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
24 ebtables_enable option.
25
26 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
27
28 pve-firewall (3.0-9) unstable; urgency=medium
29
30 * fix creation of ebltables FORWARD rule entry
31
32 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
33
34 pve-firewall (3.0-8) unstable; urgency=medium
35
36 * add ebtables support for better MAC filtering
37
38 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
39
40 pve-firewall (3.0-7) unstable; urgency=medium
41
42 * support distinct source and destination multi-port matching
43
44 * multi-port matching: when specifying the same list of ports for source and
45 destination require them both to match, rather than one of them, as this
46 was rather unexpected behavior
47
48 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
49
50 pve-firewall (3.0-6) unstable; urgency=medium
51
52 * fix #1319: don't fail postinst with masked service
53
54 * debian: switch to compat 9, drop init scripts, drop preinst
55
56 * check multiport limit in port ranges
57
58 * build: use git rev-parse for GITVERSION
59
60 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
61
62 pve-firewall (3.0-5) unstable; urgency=medium
63
64 * fix issue with disabled flag not being honored within groups
65
66 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
67
68 pve-firewall (3.0-4) unstable; urgency=medium
69
70 * fix issues with ipsets reloading unnecessarily or too late
71
72 * fix some typos in the logs
73
74 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
75
76 pve-firewall (3.0-3) unstable; urgency=medium
77
78 * Fix #1492: logger: use current timestamp if the packet doesn't have one
79
80 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
81
82 pve-firewall (3.0-2) unstable; urgency=medium
83
84 * Fix #1446: remove masks in case the package had previously been removed but
85 not purged.
86
87 * improve logging on errors in the firewall configuration
88
89 * forbid trailing commas in lists as iptables-restore doesn't support them
90
91 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
92
93 pve-firewall (3.0-1) unstable; urgency=medium
94
95 * rebuild for Debian Stretch
96
97 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
98
99 pve-firewall (2.0-33) unstable; urgency=medium
100
101 * ipset: don't allow zero-prefix entries
102
103 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
104
105 pve-firewall (2.0-32) unstable; urgency=medium
106
107 * improve search for local-network
108
109 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
110
111 pve-firewall (2.0-31) unstable; urgency=medium
112
113 * don't try to apply ports to rules which don't support them
114
115 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
116
117 pve-firewall (2.0-30) unstable; urgency=medium
118
119 * add multicast DNS to the list of Macros
120
121 * add missing parameter descriptions
122
123 * build-depends: add dh-systemd
124
125 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
126
127 pve-firewall (2.0-29) unstable; urgency=medium
128
129 * prevent overwriting ipsets/sec. groups by renaming
130
131 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
132
133 pve-firewall (2.0-28) unstable; urgency=medium
134
135 * use pve-common's ipv4_mask_hash_localnet
136
137 * fix allowed group name length
138
139 * make group digest stable
140
141 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
142
143 pve-firewall (2.0-27) unstable; urgency=medium
144
145 * fix #972: make PVEFW-FWBR-* rule order stable
146
147 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
148
149 pve-firewall (2.0-26) unstable; urgency=medium
150
151 * fix #988: set rp_filter=2
152
153 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
154
155 pve-firewall (2.0-25) unstable; urgency=medium
156
157 * fix #945: add uninitialized check in lxc ipset compilation
158
159 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
160
161 pve-firewall (2.0-24) unstable; urgency=medium
162
163 * Build-Depend on pve-doc-generator
164
165 * generate manpage with pve-doc-generator
166
167 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
168
169 pve-firewall (2.0-23) unstable; urgency=medium
170
171 * use only the top bit for our accept marks
172
173 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
174
175 pve-firewall (2.0-22) unstable; urgency=medium
176
177 * Use cfs_config_path from PVE::QemuConfig
178
179 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
180
181 pve-firewall (2.0-21) unstable; urgency=medium
182
183 * added new 'ipfilter' option
184
185 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
186
187 pve-firewall (2.0-20) unstable; urgency=medium
188
189 * fix 901: encode unicode characters in sha digest
190
191 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
192
193 pve-firewall (2.0-19) unstable; urgency=medium
194
195 * Add radv option to VM options
196
197 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
198
199 pve-firewall (2.0-18) unstable; urgency=medium
200
201 * Add ndp option to host and VM firewall options
202
203 * Add router-solicitation to NeighborDiscovery macro
204
205 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
206
207 pve-firewall (2.0-17) unstable; urgency=medium
208
209 * Don't leave empty FW config files behind
210
211 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
212
213 pve-firewall (2.0-16) unstable; urgency=medium
214
215 * logger: basic ipv6 support
216
217 * add DHCPv6 macro
218
219 * add dhcpv6 support to the dhcp option
220
221 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
222
223 pve-firewall (2.0-15) unstable; urgency=medium
224
225 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
226
227 * fix some regular expressions mixups
228
229 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
230
231 pve-firewall (2.0-14) unstable; urgency=medium
232
233 * fix systemd service dependencies
234
235 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
236
237 pve-firewall (2.0-13) unstable; urgency=medium
238
239 * allow numeric icmp types
240
241 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
242
243 pve-firewall (2.0-12) unstable; urgency=medium
244
245 * implement bash completions
246
247 * convert pve-firewall into a PVE::Service class
248
249 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
250
251 pve-firewall (2.0-11) unstable; urgency=medium
252
253 * iptables_get_chains: fix veth device name
254
255 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
256
257 pve-firewall (2.0-10) unstable; urgency=medium
258
259 * new helper: clone_vmfw_conf()
260
261 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
262
263 pve-firewall (2.0-9) unstable; urgency=medium
264
265 * remove firewall config file subroutine added
266
267 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
268
269 pve-firewall (2.0-8) unstable; urgency=medium
270
271 * adopt regresion tests for lxc containers
272
273 * removed firewall code for openVZ
274
275 * Subroutine verify_rule fixed to correctly check only for "net\d+"
276 interface device names
277
278 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
279
280 pve-firewall (2.0-7) unstable; urgency=medium
281
282 * added firewall code for lxc
283
284 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
285
286 pve-firewall (2.0-6) unstable; urgency=medium
287
288 * firewall ipversion comparison fix
289
290 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
291
292 pve-firewall (2.0-5) unstable; urgency=medium
293
294 * add ipv6 neighbor discovery and solicitation macros
295
296 * ip6tables accepts both spellings of the word neighbor
297
298 * added Ceph macro
299
300 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
301
302 pve-firewall (2.0-4) unstable; urgency=medium
303
304 * include manual page for pve-firewall
305
306 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
307
308 pve-firewall (2.0-3) unstable; urgency=medium
309
310 * use noawait trigers for pve-api-updates
311
312 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
313
314 pve-firewall (2.0-2) unstable; urgency=medium
315
316 * trigger pve-api-updates event
317
318 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
319
320 pve-firewall (2.0-1) unstable; urgency=medium
321
322 * recompile for debian jessie
323
324 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
325
326 pve-firewall (1.0-18) unstable; urgency=low
327
328 * fix alias lookup
329
330 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
331
332 pve-firewall (1.0-17) unstable; urgency=low
333
334 * fix restart behavior
335
336 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
337
338 pve-firewall (1.0-16) unstable; urgency=low
339
340 * use new Daemon class from pve-common
341
342 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
343
344 pve-firewall (1.0-15) unstable; urgency=low
345
346 * bug fix: load cluster conf for host rules
347
348 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
349
350 pve-firewall (1.0-14) unstable; urgency=low
351
352 * do not use ipset list chains
353
354 * remove preinst script (not needed anymore)
355
356 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
357
358 pve-firewall (1.0-13) unstable; urgency=low
359
360 * fix ipset remove order
361
362 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
363
364 pve-firewall (1.0-12) unstable; urgency=low
365
366 * add preinst script to clear ipset from older installation (because
367 sets cannot be swapped if there type does not match.
368
369 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
370
371 pve-firewall (1.0-11) unstable; urgency=low
372
373 * bug fix: correctly set ipversion for aliases in verify_rule
374
375 * save restore commands into files to make debugging
376 easier (/var/lib/pve-firewall/)
377
378 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
379
380 pve-firewall (1.0-10) unstable; urgency=low
381
382 * add IPv6 support for VMs (hostfw is IPv4 only)
383
384 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
385
386 pve-firewall (1.0-9) unstable; urgency=low
387
388 * fix max ipset name name length
389
390 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
391
392 pve-firewall (1.0-8) unstable; urgency=low
393
394 * implement permission
395
396 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
397
398 pve-firewall (1.0-7) unstable; urgency=low
399
400 * proxy host rule API calls to correct node
401
402 * always generate MAC and IP filter rules if firewall is enabled on NIC
403
404 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
405
406 pve-firewall (1.0-6) unstable; urgency=low
407
408 * ipmlement ipfilter ipsets
409
410 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
411
412 pve-firewall (1.0-5) unstable; urgency=low
413
414 * remove ipsets when firewall disabled
415
416 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
417
418 pve-firewall (1.0-4) unstable; urgency=low
419
420 * depend on iptables and ipset
421
422 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
423
424 pve-firewall (1.0-3) unstable; urgency=low
425
426 * change dh_installinit order (register pvefw-logger before pve-firewall)
427
428 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
429
430 pve-firewall (1.0-2) unstable; urgency=low
431
432 * add experimental nflog logging daemon
433
434 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
435
436 pve-firewall (1.0-1) unstable; urgency=low
437
438 * initial package
439
440 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
441