]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
bump version to 3.0-22
[pve-firewall.git] / debian / changelog
1 pve-firewall (3.0-22) unstable; urgency=medium
2
3 * fix IP Filter rule generation for Container
4
5 * fix redundant logging of packets passing the tap chain
6
7 -- Proxmox Support Team <support@proxmox.com> Tue, 28 May 2019 08:22:23 +0200
8
9 pve-firewall (3.0-21) unstable; urgency=medium
10
11 * fix ipv6 PVEFW-reject
12
13 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
14 ebtables doing the wrong thing here
15
16 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
17
18 pve-firewall (3.0-20) unstable; urgency=medium
19
20 * use IPCC to read config and rule files, if the are backed by pmxcfs which
21 has better handling for pmxcfs restarts
22
23 * fix #2178: endless loop on ipv6 extension headers
24
25 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
26
27 pve-firewall (3.0-19) unstable; urgency=medium
28
29 * ebtables: add arp filtering
30
31 * fix: #2123 Logging of user defined firewall rules
32
33 * fix Razor macro
34
35 * allow to enable/disable and modify cluster wide log ratelimits
36
37 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
38
39 pve-firewall (3.0-18) unstable; urgency=medium
40
41 * fix #1606: Add nf_conntrack_allow_invalid option
42
43 * log reject : add space after policy REJECT like drop
44
45 * fix #1891: Add zsh command completion for pve-firewall
46
47 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
48
49 pve-firewall (3.0-17) unstable; urgency=medium
50
51 * fix #2005: only allow ascii port digits
52
53 * fix #2004: do not allow backwards ranges
54
55 * add conntrack logging via libnetfilter_conntrack and allow one to enable
56 it through the firewall host configuration
57
58 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
59
60 pve-firewall (3.0-16) unstable; urgency=medium
61
62 * api/rules: fix macro return type
63
64 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
65
66 pve-firewall (3.0-15) unstable; urgency=medium
67
68 * fix #1971: display firewall rule properties
69
70 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
71
72 pve-firewall (3.0-14) unstable; urgency=medium
73
74 * fix #1841: avoid ebtable reloads when containers have multiple network
75 interfaces
76
77 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
78
79 pve-firewall (3.0-13) unstable; urgency=medium
80
81 * avoid unnecessary reloads of ebtable ruleset
82
83 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
84
85 pve-firewall (3.0-12) unstable; urgency=medium
86
87 * fix deleted iptables chains not being properly detected as a change
88
89 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
90
91 pve-firewall (3.0-11) unstable; urgency=medium
92
93 * #1764: rename 'ebtales_enable' option to 'ebtables'
94
95 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
96
97 pve-firewall (3.0-10) unstable; urgency=medium
98
99 * fix #1764: handle existing ebtables rules and allow disabling ebtables
100
101 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
102 ebtables_enable option.
103
104 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
105
106 pve-firewall (3.0-9) unstable; urgency=medium
107
108 * fix creation of ebltables FORWARD rule entry
109
110 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
111
112 pve-firewall (3.0-8) unstable; urgency=medium
113
114 * add ebtables support for better MAC filtering
115
116 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
117
118 pve-firewall (3.0-7) unstable; urgency=medium
119
120 * support distinct source and destination multi-port matching
121
122 * multi-port matching: when specifying the same list of ports for source and
123 destination require them both to match, rather than one of them, as this
124 was rather unexpected behavior
125
126 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
127
128 pve-firewall (3.0-6) unstable; urgency=medium
129
130 * fix #1319: don't fail postinst with masked service
131
132 * debian: switch to compat 9, drop init scripts, drop preinst
133
134 * check multiport limit in port ranges
135
136 * build: use git rev-parse for GITVERSION
137
138 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
139
140 pve-firewall (3.0-5) unstable; urgency=medium
141
142 * fix issue with disabled flag not being honored within groups
143
144 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
145
146 pve-firewall (3.0-4) unstable; urgency=medium
147
148 * fix issues with ipsets reloading unnecessarily or too late
149
150 * fix some typos in the logs
151
152 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
153
154 pve-firewall (3.0-3) unstable; urgency=medium
155
156 * Fix #1492: logger: use current timestamp if the packet doesn't have one
157
158 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
159
160 pve-firewall (3.0-2) unstable; urgency=medium
161
162 * Fix #1446: remove masks in case the package had previously been removed but
163 not purged.
164
165 * improve logging on errors in the firewall configuration
166
167 * forbid trailing commas in lists as iptables-restore doesn't support them
168
169 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
170
171 pve-firewall (3.0-1) unstable; urgency=medium
172
173 * rebuild for Debian Stretch
174
175 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
176
177 pve-firewall (2.0-33) unstable; urgency=medium
178
179 * ipset: don't allow zero-prefix entries
180
181 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
182
183 pve-firewall (2.0-32) unstable; urgency=medium
184
185 * improve search for local-network
186
187 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
188
189 pve-firewall (2.0-31) unstable; urgency=medium
190
191 * don't try to apply ports to rules which don't support them
192
193 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
194
195 pve-firewall (2.0-30) unstable; urgency=medium
196
197 * add multicast DNS to the list of Macros
198
199 * add missing parameter descriptions
200
201 * build-depends: add dh-systemd
202
203 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
204
205 pve-firewall (2.0-29) unstable; urgency=medium
206
207 * prevent overwriting ipsets/sec. groups by renaming
208
209 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
210
211 pve-firewall (2.0-28) unstable; urgency=medium
212
213 * use pve-common's ipv4_mask_hash_localnet
214
215 * fix allowed group name length
216
217 * make group digest stable
218
219 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
220
221 pve-firewall (2.0-27) unstable; urgency=medium
222
223 * fix #972: make PVEFW-FWBR-* rule order stable
224
225 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
226
227 pve-firewall (2.0-26) unstable; urgency=medium
228
229 * fix #988: set rp_filter=2
230
231 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
232
233 pve-firewall (2.0-25) unstable; urgency=medium
234
235 * fix #945: add uninitialized check in lxc ipset compilation
236
237 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
238
239 pve-firewall (2.0-24) unstable; urgency=medium
240
241 * Build-Depend on pve-doc-generator
242
243 * generate manpage with pve-doc-generator
244
245 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
246
247 pve-firewall (2.0-23) unstable; urgency=medium
248
249 * use only the top bit for our accept marks
250
251 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
252
253 pve-firewall (2.0-22) unstable; urgency=medium
254
255 * Use cfs_config_path from PVE::QemuConfig
256
257 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
258
259 pve-firewall (2.0-21) unstable; urgency=medium
260
261 * added new 'ipfilter' option
262
263 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
264
265 pve-firewall (2.0-20) unstable; urgency=medium
266
267 * fix 901: encode unicode characters in sha digest
268
269 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
270
271 pve-firewall (2.0-19) unstable; urgency=medium
272
273 * Add radv option to VM options
274
275 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
276
277 pve-firewall (2.0-18) unstable; urgency=medium
278
279 * Add ndp option to host and VM firewall options
280
281 * Add router-solicitation to NeighborDiscovery macro
282
283 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
284
285 pve-firewall (2.0-17) unstable; urgency=medium
286
287 * Don't leave empty FW config files behind
288
289 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
290
291 pve-firewall (2.0-16) unstable; urgency=medium
292
293 * logger: basic ipv6 support
294
295 * add DHCPv6 macro
296
297 * add dhcpv6 support to the dhcp option
298
299 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
300
301 pve-firewall (2.0-15) unstable; urgency=medium
302
303 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
304
305 * fix some regular expressions mixups
306
307 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
308
309 pve-firewall (2.0-14) unstable; urgency=medium
310
311 * fix systemd service dependencies
312
313 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
314
315 pve-firewall (2.0-13) unstable; urgency=medium
316
317 * allow numeric icmp types
318
319 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
320
321 pve-firewall (2.0-12) unstable; urgency=medium
322
323 * implement bash completions
324
325 * convert pve-firewall into a PVE::Service class
326
327 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
328
329 pve-firewall (2.0-11) unstable; urgency=medium
330
331 * iptables_get_chains: fix veth device name
332
333 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
334
335 pve-firewall (2.0-10) unstable; urgency=medium
336
337 * new helper: clone_vmfw_conf()
338
339 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
340
341 pve-firewall (2.0-9) unstable; urgency=medium
342
343 * remove firewall config file subroutine added
344
345 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
346
347 pve-firewall (2.0-8) unstable; urgency=medium
348
349 * adopt regresion tests for lxc containers
350
351 * removed firewall code for openVZ
352
353 * Subroutine verify_rule fixed to correctly check only for "net\d+"
354 interface device names
355
356 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
357
358 pve-firewall (2.0-7) unstable; urgency=medium
359
360 * added firewall code for lxc
361
362 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
363
364 pve-firewall (2.0-6) unstable; urgency=medium
365
366 * firewall ipversion comparison fix
367
368 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
369
370 pve-firewall (2.0-5) unstable; urgency=medium
371
372 * add ipv6 neighbor discovery and solicitation macros
373
374 * ip6tables accepts both spellings of the word neighbor
375
376 * added Ceph macro
377
378 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
379
380 pve-firewall (2.0-4) unstable; urgency=medium
381
382 * include manual page for pve-firewall
383
384 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
385
386 pve-firewall (2.0-3) unstable; urgency=medium
387
388 * use noawait trigers for pve-api-updates
389
390 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
391
392 pve-firewall (2.0-2) unstable; urgency=medium
393
394 * trigger pve-api-updates event
395
396 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
397
398 pve-firewall (2.0-1) unstable; urgency=medium
399
400 * recompile for debian jessie
401
402 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
403
404 pve-firewall (1.0-18) unstable; urgency=low
405
406 * fix alias lookup
407
408 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
409
410 pve-firewall (1.0-17) unstable; urgency=low
411
412 * fix restart behavior
413
414 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
415
416 pve-firewall (1.0-16) unstable; urgency=low
417
418 * use new Daemon class from pve-common
419
420 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
421
422 pve-firewall (1.0-15) unstable; urgency=low
423
424 * bug fix: load cluster conf for host rules
425
426 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
427
428 pve-firewall (1.0-14) unstable; urgency=low
429
430 * do not use ipset list chains
431
432 * remove preinst script (not needed anymore)
433
434 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
435
436 pve-firewall (1.0-13) unstable; urgency=low
437
438 * fix ipset remove order
439
440 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
441
442 pve-firewall (1.0-12) unstable; urgency=low
443
444 * add preinst script to clear ipset from older installation (because
445 sets cannot be swapped if there type does not match.
446
447 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
448
449 pve-firewall (1.0-11) unstable; urgency=low
450
451 * bug fix: correctly set ipversion for aliases in verify_rule
452
453 * save restore commands into files to make debugging
454 easier (/var/lib/pve-firewall/)
455
456 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
457
458 pve-firewall (1.0-10) unstable; urgency=low
459
460 * add IPv6 support for VMs (hostfw is IPv4 only)
461
462 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
463
464 pve-firewall (1.0-9) unstable; urgency=low
465
466 * fix max ipset name name length
467
468 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
469
470 pve-firewall (1.0-8) unstable; urgency=low
471
472 * implement permission
473
474 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
475
476 pve-firewall (1.0-7) unstable; urgency=low
477
478 * proxy host rule API calls to correct node
479
480 * always generate MAC and IP filter rules if firewall is enabled on NIC
481
482 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
483
484 pve-firewall (1.0-6) unstable; urgency=low
485
486 * ipmlement ipfilter ipsets
487
488 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
489
490 pve-firewall (1.0-5) unstable; urgency=low
491
492 * remove ipsets when firewall disabled
493
494 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
495
496 pve-firewall (1.0-4) unstable; urgency=low
497
498 * depend on iptables and ipset
499
500 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
501
502 pve-firewall (1.0-3) unstable; urgency=low
503
504 * change dh_installinit order (register pvefw-logger before pve-firewall)
505
506 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
507
508 pve-firewall (1.0-2) unstable; urgency=low
509
510 * add experimental nflog logging daemon
511
512 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
513
514 pve-firewall (1.0-1) unstable; urgency=low
515
516 * initial package
517
518 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
519