]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
a9dab658053f66fadfd42d54a8bd95cef09e407b
[pve-firewall.git] / debian / changelog
1 pve-firewall (4.0-10) pve; urgency=medium
2
3 * macros: add macro for Proxmox Mail Gateway web interface
4
5 * api node: always pass cluster conf to node FW parser to fix false positive
6 error message about non existing aliases, or IP sets, when querying the
7 node FW options GET API call.
8
9 * grammar fix: s/does not exists/does not exist/g
10
11 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jan 2020 19:25:49 +0100
12
13 pve-firewall (4.0-9) pve; urgency=medium
14
15 * ensure port range used for offline storage migration and insecure migration
16 traffic is allowed by default rule set.
17
18 -- Proxmox Support Team <support@proxmox.com> Tue, 03 Dec 2019 08:12:20 +0100
19
20 pve-firewall (4.0-8) pve; urgency=medium
21
22 * increase default nf_conntrack_max to the kernel's default
23
24 * fix some "use of uninitialized value" warnings when updating CIDRs
25
26 * update schema documentation
27
28 * add explicit dependency on libpve-cluster-perl
29
30 * add support for "raw" tables
31
32 * add options for synflood protection for host firewall:
33 - nf_conntrack_tcp_timeout_syn_recv
34 - protection_synflood: boolean
35 - protection_synflood_rate: SYN rate limit (default 200 per second)
36 - protection_synflood_burst: SYN burst limit (default 1000)
37
38 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2019 13:48:20 +0100
39
40 pve-firewall (4.0-7) pve; urgency=medium
41
42 * only add VM chains and rules if VM firewall is enabled
43
44 -- Proxmox Support Team <support@proxmox.com> Wed, 7 Aug 2019 10:55:06 +0200
45
46 pve-firewall (4.0-6) pve; urgency=medium
47
48 * firewall macros: add new Ceph protocol v2 port while keeping v1 port
49
50 -- Proxmox Support Team <support@proxmox.com> Tue, 23 Jul 2019 18:57:48 +0200
51
52 pve-firewall (4.0-5) pve; urgency=medium
53
54 * don't use any base path at all for calls to external binaries to make use
55 compativle with bot, /usr merged and unmerged setups
56
57 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Jul 2019 11:47:53 +0200
58
59 pve-firewall (4.0-4) pve; urgency=medium
60
61 * ebtables: remove PVE chains properly
62
63 * ebtables: treat chain deletion as change
64
65 * use /usr/sbin as base path
66
67 -- Proxmox Support Team <support@proxmox.com> Thu, 11 Jul 2019 19:40:01 +0200
68
69 pve-firewall (4.0-3) pve; urgency=medium
70
71 * Create corosync firewall rules independently of localnet~
72
73 * Display corosync rule info on localnet call
74
75 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
76
77 pve-firewall (4.0-2) pve; urgency=medium
78
79 * fix systemd warning about PIDFile directory
80
81 * fix CT rule generation with ipfilter set
82
83 * pve-firewall service: update-alternative iptables and ebtables to working
84 legacy versions
85
86 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
87
88 pve-firewall (4.0-1) pve; urgency=medium
89
90 * re-build for Debian Buster / PVE 6
91
92 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
93
94 pve-firewall (3.0-21) unstable; urgency=medium
95
96 * fix ipv6 PVEFW-reject
97
98 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
99 ebtables doing the wrong thing here
100
101 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
102
103 pve-firewall (3.0-20) unstable; urgency=medium
104
105 * use IPCC to read config and rule files, if the are backed by pmxcfs which
106 has better handling for pmxcfs restarts
107
108 * fix #2178: endless loop on ipv6 extension headers
109
110 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
111
112 pve-firewall (3.0-19) unstable; urgency=medium
113
114 * ebtables: add arp filtering
115
116 * fix: #2123 Logging of user defined firewall rules
117
118 * fix Razor macro
119
120 * allow to enable/disable and modify cluster wide log ratelimits
121
122 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
123
124 pve-firewall (3.0-18) unstable; urgency=medium
125
126 * fix #1606: Add nf_conntrack_allow_invalid option
127
128 * log reject : add space after policy REJECT like drop
129
130 * fix #1891: Add zsh command completion for pve-firewall
131
132 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
133
134 pve-firewall (3.0-17) unstable; urgency=medium
135
136 * fix #2005: only allow ascii port digits
137
138 * fix #2004: do not allow backwards ranges
139
140 * add conntrack logging via libnetfilter_conntrack and allow one to enable
141 it through the firewall host configuration
142
143 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
144
145 pve-firewall (3.0-16) unstable; urgency=medium
146
147 * api/rules: fix macro return type
148
149 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
150
151 pve-firewall (3.0-15) unstable; urgency=medium
152
153 * fix #1971: display firewall rule properties
154
155 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
156
157 pve-firewall (3.0-14) unstable; urgency=medium
158
159 * fix #1841: avoid ebtable reloads when containers have multiple network
160 interfaces
161
162 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
163
164 pve-firewall (3.0-13) unstable; urgency=medium
165
166 * avoid unnecessary reloads of ebtable ruleset
167
168 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
169
170 pve-firewall (3.0-12) unstable; urgency=medium
171
172 * fix deleted iptables chains not being properly detected as a change
173
174 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
175
176 pve-firewall (3.0-11) unstable; urgency=medium
177
178 * #1764: rename 'ebtales_enable' option to 'ebtables'
179
180 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
181
182 pve-firewall (3.0-10) unstable; urgency=medium
183
184 * fix #1764: handle existing ebtables rules and allow disabling ebtables
185
186 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
187 ebtables_enable option.
188
189 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
190
191 pve-firewall (3.0-9) unstable; urgency=medium
192
193 * fix creation of ebltables FORWARD rule entry
194
195 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
196
197 pve-firewall (3.0-8) unstable; urgency=medium
198
199 * add ebtables support for better MAC filtering
200
201 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
202
203 pve-firewall (3.0-7) unstable; urgency=medium
204
205 * support distinct source and destination multi-port matching
206
207 * multi-port matching: when specifying the same list of ports for source and
208 destination require them both to match, rather than one of them, as this
209 was rather unexpected behavior
210
211 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
212
213 pve-firewall (3.0-6) unstable; urgency=medium
214
215 * fix #1319: don't fail postinst with masked service
216
217 * debian: switch to compat 9, drop init scripts, drop preinst
218
219 * check multiport limit in port ranges
220
221 * build: use git rev-parse for GITVERSION
222
223 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
224
225 pve-firewall (3.0-5) unstable; urgency=medium
226
227 * fix issue with disabled flag not being honored within groups
228
229 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
230
231 pve-firewall (3.0-4) unstable; urgency=medium
232
233 * fix issues with ipsets reloading unnecessarily or too late
234
235 * fix some typos in the logs
236
237 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
238
239 pve-firewall (3.0-3) unstable; urgency=medium
240
241 * Fix #1492: logger: use current timestamp if the packet doesn't have one
242
243 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
244
245 pve-firewall (3.0-2) unstable; urgency=medium
246
247 * Fix #1446: remove masks in case the package had previously been removed but
248 not purged.
249
250 * improve logging on errors in the firewall configuration
251
252 * forbid trailing commas in lists as iptables-restore doesn't support them
253
254 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
255
256 pve-firewall (3.0-1) unstable; urgency=medium
257
258 * rebuild for Debian Stretch
259
260 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
261
262 pve-firewall (2.0-33) unstable; urgency=medium
263
264 * ipset: don't allow zero-prefix entries
265
266 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
267
268 pve-firewall (2.0-32) unstable; urgency=medium
269
270 * improve search for local-network
271
272 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
273
274 pve-firewall (2.0-31) unstable; urgency=medium
275
276 * don't try to apply ports to rules which don't support them
277
278 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
279
280 pve-firewall (2.0-30) unstable; urgency=medium
281
282 * add multicast DNS to the list of Macros
283
284 * add missing parameter descriptions
285
286 * build-depends: add dh-systemd
287
288 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
289
290 pve-firewall (2.0-29) unstable; urgency=medium
291
292 * prevent overwriting ipsets/sec. groups by renaming
293
294 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
295
296 pve-firewall (2.0-28) unstable; urgency=medium
297
298 * use pve-common's ipv4_mask_hash_localnet
299
300 * fix allowed group name length
301
302 * make group digest stable
303
304 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
305
306 pve-firewall (2.0-27) unstable; urgency=medium
307
308 * fix #972: make PVEFW-FWBR-* rule order stable
309
310 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
311
312 pve-firewall (2.0-26) unstable; urgency=medium
313
314 * fix #988: set rp_filter=2
315
316 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
317
318 pve-firewall (2.0-25) unstable; urgency=medium
319
320 * fix #945: add uninitialized check in lxc ipset compilation
321
322 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
323
324 pve-firewall (2.0-24) unstable; urgency=medium
325
326 * Build-Depend on pve-doc-generator
327
328 * generate manpage with pve-doc-generator
329
330 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
331
332 pve-firewall (2.0-23) unstable; urgency=medium
333
334 * use only the top bit for our accept marks
335
336 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
337
338 pve-firewall (2.0-22) unstable; urgency=medium
339
340 * Use cfs_config_path from PVE::QemuConfig
341
342 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
343
344 pve-firewall (2.0-21) unstable; urgency=medium
345
346 * added new 'ipfilter' option
347
348 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
349
350 pve-firewall (2.0-20) unstable; urgency=medium
351
352 * fix 901: encode unicode characters in sha digest
353
354 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
355
356 pve-firewall (2.0-19) unstable; urgency=medium
357
358 * Add radv option to VM options
359
360 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
361
362 pve-firewall (2.0-18) unstable; urgency=medium
363
364 * Add ndp option to host and VM firewall options
365
366 * Add router-solicitation to NeighborDiscovery macro
367
368 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
369
370 pve-firewall (2.0-17) unstable; urgency=medium
371
372 * Don't leave empty FW config files behind
373
374 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
375
376 pve-firewall (2.0-16) unstable; urgency=medium
377
378 * logger: basic ipv6 support
379
380 * add DHCPv6 macro
381
382 * add dhcpv6 support to the dhcp option
383
384 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
385
386 pve-firewall (2.0-15) unstable; urgency=medium
387
388 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
389
390 * fix some regular expressions mixups
391
392 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
393
394 pve-firewall (2.0-14) unstable; urgency=medium
395
396 * fix systemd service dependencies
397
398 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
399
400 pve-firewall (2.0-13) unstable; urgency=medium
401
402 * allow numeric icmp types
403
404 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
405
406 pve-firewall (2.0-12) unstable; urgency=medium
407
408 * implement bash completions
409
410 * convert pve-firewall into a PVE::Service class
411
412 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
413
414 pve-firewall (2.0-11) unstable; urgency=medium
415
416 * iptables_get_chains: fix veth device name
417
418 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
419
420 pve-firewall (2.0-10) unstable; urgency=medium
421
422 * new helper: clone_vmfw_conf()
423
424 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
425
426 pve-firewall (2.0-9) unstable; urgency=medium
427
428 * remove firewall config file subroutine added
429
430 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
431
432 pve-firewall (2.0-8) unstable; urgency=medium
433
434 * adopt regresion tests for lxc containers
435
436 * removed firewall code for openVZ
437
438 * Subroutine verify_rule fixed to correctly check only for "net\d+"
439 interface device names
440
441 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
442
443 pve-firewall (2.0-7) unstable; urgency=medium
444
445 * added firewall code for lxc
446
447 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
448
449 pve-firewall (2.0-6) unstable; urgency=medium
450
451 * firewall ipversion comparison fix
452
453 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
454
455 pve-firewall (2.0-5) unstable; urgency=medium
456
457 * add ipv6 neighbor discovery and solicitation macros
458
459 * ip6tables accepts both spellings of the word neighbor
460
461 * added Ceph macro
462
463 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
464
465 pve-firewall (2.0-4) unstable; urgency=medium
466
467 * include manual page for pve-firewall
468
469 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
470
471 pve-firewall (2.0-3) unstable; urgency=medium
472
473 * use noawait trigers for pve-api-updates
474
475 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
476
477 pve-firewall (2.0-2) unstable; urgency=medium
478
479 * trigger pve-api-updates event
480
481 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
482
483 pve-firewall (2.0-1) unstable; urgency=medium
484
485 * recompile for debian jessie
486
487 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
488
489 pve-firewall (1.0-18) unstable; urgency=low
490
491 * fix alias lookup
492
493 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
494
495 pve-firewall (1.0-17) unstable; urgency=low
496
497 * fix restart behavior
498
499 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
500
501 pve-firewall (1.0-16) unstable; urgency=low
502
503 * use new Daemon class from pve-common
504
505 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
506
507 pve-firewall (1.0-15) unstable; urgency=low
508
509 * bug fix: load cluster conf for host rules
510
511 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
512
513 pve-firewall (1.0-14) unstable; urgency=low
514
515 * do not use ipset list chains
516
517 * remove preinst script (not needed anymore)
518
519 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
520
521 pve-firewall (1.0-13) unstable; urgency=low
522
523 * fix ipset remove order
524
525 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
526
527 pve-firewall (1.0-12) unstable; urgency=low
528
529 * add preinst script to clear ipset from older installation (because
530 sets cannot be swapped if there type does not match.
531
532 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
533
534 pve-firewall (1.0-11) unstable; urgency=low
535
536 * bug fix: correctly set ipversion for aliases in verify_rule
537
538 * save restore commands into files to make debugging
539 easier (/var/lib/pve-firewall/)
540
541 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
542
543 pve-firewall (1.0-10) unstable; urgency=low
544
545 * add IPv6 support for VMs (hostfw is IPv4 only)
546
547 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
548
549 pve-firewall (1.0-9) unstable; urgency=low
550
551 * fix max ipset name name length
552
553 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
554
555 pve-firewall (1.0-8) unstable; urgency=low
556
557 * implement permission
558
559 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
560
561 pve-firewall (1.0-7) unstable; urgency=low
562
563 * proxy host rule API calls to correct node
564
565 * always generate MAC and IP filter rules if firewall is enabled on NIC
566
567 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
568
569 pve-firewall (1.0-6) unstable; urgency=low
570
571 * ipmlement ipfilter ipsets
572
573 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
574
575 pve-firewall (1.0-5) unstable; urgency=low
576
577 * remove ipsets when firewall disabled
578
579 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
580
581 pve-firewall (1.0-4) unstable; urgency=low
582
583 * depend on iptables and ipset
584
585 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
586
587 pve-firewall (1.0-3) unstable; urgency=low
588
589 * change dh_installinit order (register pvefw-logger before pve-firewall)
590
591 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
592
593 pve-firewall (1.0-2) unstable; urgency=low
594
595 * add experimental nflog logging daemon
596
597 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
598
599 pve-firewall (1.0-1) unstable; urgency=low
600
601 * initial package
602
603 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
604