]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
bump version to 4.0-3
[pve-firewall.git] / debian / changelog
1 pve-firewall (4.0-3) pve; urgency=medium
2
3 * Create corosync firewall rules independently of localnet~
4
5 * Display corosync rule info on localnet call
6
7 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
8
9 pve-firewall (4.0-2) pve; urgency=medium
10
11 * fix systemd warning about PIDFile directory
12
13 * fix CT rule generation with ipfilter set
14
15 * pve-firewall service: update-alternative iptables and ebtables to working
16 legacy versions
17
18 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
19
20 pve-firewall (4.0-1) pve; urgency=medium
21
22 * re-build for Debian Buster / PVE 6
23
24 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
25
26 pve-firewall (3.0-21) unstable; urgency=medium
27
28 * fix ipv6 PVEFW-reject
29
30 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
31 ebtables doing the wrong thing here
32
33 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
34
35 pve-firewall (3.0-20) unstable; urgency=medium
36
37 * use IPCC to read config and rule files, if the are backed by pmxcfs which
38 has better handling for pmxcfs restarts
39
40 * fix #2178: endless loop on ipv6 extension headers
41
42 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
43
44 pve-firewall (3.0-19) unstable; urgency=medium
45
46 * ebtables: add arp filtering
47
48 * fix: #2123 Logging of user defined firewall rules
49
50 * fix Razor macro
51
52 * allow to enable/disable and modify cluster wide log ratelimits
53
54 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
55
56 pve-firewall (3.0-18) unstable; urgency=medium
57
58 * fix #1606: Add nf_conntrack_allow_invalid option
59
60 * log reject : add space after policy REJECT like drop
61
62 * fix #1891: Add zsh command completion for pve-firewall
63
64 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
65
66 pve-firewall (3.0-17) unstable; urgency=medium
67
68 * fix #2005: only allow ascii port digits
69
70 * fix #2004: do not allow backwards ranges
71
72 * add conntrack logging via libnetfilter_conntrack and allow one to enable
73 it through the firewall host configuration
74
75 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
76
77 pve-firewall (3.0-16) unstable; urgency=medium
78
79 * api/rules: fix macro return type
80
81 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
82
83 pve-firewall (3.0-15) unstable; urgency=medium
84
85 * fix #1971: display firewall rule properties
86
87 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
88
89 pve-firewall (3.0-14) unstable; urgency=medium
90
91 * fix #1841: avoid ebtable reloads when containers have multiple network
92 interfaces
93
94 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
95
96 pve-firewall (3.0-13) unstable; urgency=medium
97
98 * avoid unnecessary reloads of ebtable ruleset
99
100 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
101
102 pve-firewall (3.0-12) unstable; urgency=medium
103
104 * fix deleted iptables chains not being properly detected as a change
105
106 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
107
108 pve-firewall (3.0-11) unstable; urgency=medium
109
110 * #1764: rename 'ebtales_enable' option to 'ebtables'
111
112 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
113
114 pve-firewall (3.0-10) unstable; urgency=medium
115
116 * fix #1764: handle existing ebtables rules and allow disabling ebtables
117
118 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
119 ebtables_enable option.
120
121 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
122
123 pve-firewall (3.0-9) unstable; urgency=medium
124
125 * fix creation of ebltables FORWARD rule entry
126
127 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
128
129 pve-firewall (3.0-8) unstable; urgency=medium
130
131 * add ebtables support for better MAC filtering
132
133 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
134
135 pve-firewall (3.0-7) unstable; urgency=medium
136
137 * support distinct source and destination multi-port matching
138
139 * multi-port matching: when specifying the same list of ports for source and
140 destination require them both to match, rather than one of them, as this
141 was rather unexpected behavior
142
143 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
144
145 pve-firewall (3.0-6) unstable; urgency=medium
146
147 * fix #1319: don't fail postinst with masked service
148
149 * debian: switch to compat 9, drop init scripts, drop preinst
150
151 * check multiport limit in port ranges
152
153 * build: use git rev-parse for GITVERSION
154
155 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
156
157 pve-firewall (3.0-5) unstable; urgency=medium
158
159 * fix issue with disabled flag not being honored within groups
160
161 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
162
163 pve-firewall (3.0-4) unstable; urgency=medium
164
165 * fix issues with ipsets reloading unnecessarily or too late
166
167 * fix some typos in the logs
168
169 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
170
171 pve-firewall (3.0-3) unstable; urgency=medium
172
173 * Fix #1492: logger: use current timestamp if the packet doesn't have one
174
175 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
176
177 pve-firewall (3.0-2) unstable; urgency=medium
178
179 * Fix #1446: remove masks in case the package had previously been removed but
180 not purged.
181
182 * improve logging on errors in the firewall configuration
183
184 * forbid trailing commas in lists as iptables-restore doesn't support them
185
186 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
187
188 pve-firewall (3.0-1) unstable; urgency=medium
189
190 * rebuild for Debian Stretch
191
192 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
193
194 pve-firewall (2.0-33) unstable; urgency=medium
195
196 * ipset: don't allow zero-prefix entries
197
198 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
199
200 pve-firewall (2.0-32) unstable; urgency=medium
201
202 * improve search for local-network
203
204 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
205
206 pve-firewall (2.0-31) unstable; urgency=medium
207
208 * don't try to apply ports to rules which don't support them
209
210 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
211
212 pve-firewall (2.0-30) unstable; urgency=medium
213
214 * add multicast DNS to the list of Macros
215
216 * add missing parameter descriptions
217
218 * build-depends: add dh-systemd
219
220 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
221
222 pve-firewall (2.0-29) unstable; urgency=medium
223
224 * prevent overwriting ipsets/sec. groups by renaming
225
226 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
227
228 pve-firewall (2.0-28) unstable; urgency=medium
229
230 * use pve-common's ipv4_mask_hash_localnet
231
232 * fix allowed group name length
233
234 * make group digest stable
235
236 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
237
238 pve-firewall (2.0-27) unstable; urgency=medium
239
240 * fix #972: make PVEFW-FWBR-* rule order stable
241
242 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
243
244 pve-firewall (2.0-26) unstable; urgency=medium
245
246 * fix #988: set rp_filter=2
247
248 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
249
250 pve-firewall (2.0-25) unstable; urgency=medium
251
252 * fix #945: add uninitialized check in lxc ipset compilation
253
254 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
255
256 pve-firewall (2.0-24) unstable; urgency=medium
257
258 * Build-Depend on pve-doc-generator
259
260 * generate manpage with pve-doc-generator
261
262 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
263
264 pve-firewall (2.0-23) unstable; urgency=medium
265
266 * use only the top bit for our accept marks
267
268 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
269
270 pve-firewall (2.0-22) unstable; urgency=medium
271
272 * Use cfs_config_path from PVE::QemuConfig
273
274 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
275
276 pve-firewall (2.0-21) unstable; urgency=medium
277
278 * added new 'ipfilter' option
279
280 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
281
282 pve-firewall (2.0-20) unstable; urgency=medium
283
284 * fix 901: encode unicode characters in sha digest
285
286 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
287
288 pve-firewall (2.0-19) unstable; urgency=medium
289
290 * Add radv option to VM options
291
292 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
293
294 pve-firewall (2.0-18) unstable; urgency=medium
295
296 * Add ndp option to host and VM firewall options
297
298 * Add router-solicitation to NeighborDiscovery macro
299
300 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
301
302 pve-firewall (2.0-17) unstable; urgency=medium
303
304 * Don't leave empty FW config files behind
305
306 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
307
308 pve-firewall (2.0-16) unstable; urgency=medium
309
310 * logger: basic ipv6 support
311
312 * add DHCPv6 macro
313
314 * add dhcpv6 support to the dhcp option
315
316 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
317
318 pve-firewall (2.0-15) unstable; urgency=medium
319
320 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
321
322 * fix some regular expressions mixups
323
324 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
325
326 pve-firewall (2.0-14) unstable; urgency=medium
327
328 * fix systemd service dependencies
329
330 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
331
332 pve-firewall (2.0-13) unstable; urgency=medium
333
334 * allow numeric icmp types
335
336 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
337
338 pve-firewall (2.0-12) unstable; urgency=medium
339
340 * implement bash completions
341
342 * convert pve-firewall into a PVE::Service class
343
344 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
345
346 pve-firewall (2.0-11) unstable; urgency=medium
347
348 * iptables_get_chains: fix veth device name
349
350 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
351
352 pve-firewall (2.0-10) unstable; urgency=medium
353
354 * new helper: clone_vmfw_conf()
355
356 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
357
358 pve-firewall (2.0-9) unstable; urgency=medium
359
360 * remove firewall config file subroutine added
361
362 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
363
364 pve-firewall (2.0-8) unstable; urgency=medium
365
366 * adopt regresion tests for lxc containers
367
368 * removed firewall code for openVZ
369
370 * Subroutine verify_rule fixed to correctly check only for "net\d+"
371 interface device names
372
373 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
374
375 pve-firewall (2.0-7) unstable; urgency=medium
376
377 * added firewall code for lxc
378
379 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
380
381 pve-firewall (2.0-6) unstable; urgency=medium
382
383 * firewall ipversion comparison fix
384
385 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
386
387 pve-firewall (2.0-5) unstable; urgency=medium
388
389 * add ipv6 neighbor discovery and solicitation macros
390
391 * ip6tables accepts both spellings of the word neighbor
392
393 * added Ceph macro
394
395 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
396
397 pve-firewall (2.0-4) unstable; urgency=medium
398
399 * include manual page for pve-firewall
400
401 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
402
403 pve-firewall (2.0-3) unstable; urgency=medium
404
405 * use noawait trigers for pve-api-updates
406
407 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
408
409 pve-firewall (2.0-2) unstable; urgency=medium
410
411 * trigger pve-api-updates event
412
413 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
414
415 pve-firewall (2.0-1) unstable; urgency=medium
416
417 * recompile for debian jessie
418
419 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
420
421 pve-firewall (1.0-18) unstable; urgency=low
422
423 * fix alias lookup
424
425 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
426
427 pve-firewall (1.0-17) unstable; urgency=low
428
429 * fix restart behavior
430
431 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
432
433 pve-firewall (1.0-16) unstable; urgency=low
434
435 * use new Daemon class from pve-common
436
437 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
438
439 pve-firewall (1.0-15) unstable; urgency=low
440
441 * bug fix: load cluster conf for host rules
442
443 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
444
445 pve-firewall (1.0-14) unstable; urgency=low
446
447 * do not use ipset list chains
448
449 * remove preinst script (not needed anymore)
450
451 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
452
453 pve-firewall (1.0-13) unstable; urgency=low
454
455 * fix ipset remove order
456
457 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
458
459 pve-firewall (1.0-12) unstable; urgency=low
460
461 * add preinst script to clear ipset from older installation (because
462 sets cannot be swapped if there type does not match.
463
464 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
465
466 pve-firewall (1.0-11) unstable; urgency=low
467
468 * bug fix: correctly set ipversion for aliases in verify_rule
469
470 * save restore commands into files to make debugging
471 easier (/var/lib/pve-firewall/)
472
473 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
474
475 pve-firewall (1.0-10) unstable; urgency=low
476
477 * add IPv6 support for VMs (hostfw is IPv4 only)
478
479 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
480
481 pve-firewall (1.0-9) unstable; urgency=low
482
483 * fix max ipset name name length
484
485 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
486
487 pve-firewall (1.0-8) unstable; urgency=low
488
489 * implement permission
490
491 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
492
493 pve-firewall (1.0-7) unstable; urgency=low
494
495 * proxy host rule API calls to correct node
496
497 * always generate MAC and IP filter rules if firewall is enabled on NIC
498
499 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
500
501 pve-firewall (1.0-6) unstable; urgency=low
502
503 * ipmlement ipfilter ipsets
504
505 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
506
507 pve-firewall (1.0-5) unstable; urgency=low
508
509 * remove ipsets when firewall disabled
510
511 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
512
513 pve-firewall (1.0-4) unstable; urgency=low
514
515 * depend on iptables and ipset
516
517 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
518
519 pve-firewall (1.0-3) unstable; urgency=low
520
521 * change dh_installinit order (register pvefw-logger before pve-firewall)
522
523 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
524
525 pve-firewall (1.0-2) unstable; urgency=low
526
527 * add experimental nflog logging daemon
528
529 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
530
531 pve-firewall (1.0-1) unstable; urgency=low
532
533 * initial package
534
535 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
536