]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
e2174f5ac0ba51157f856a4dc97c77b9e021c21e
[pve-firewall.git] / debian / changelog
1 pve-firewall (4.0-2) pve; urgency=medium
2
3 * fix systemd warning about PIDFile directory
4
5 * fix CT rule generation with ipfilter set
6
7 * pve-firewall service: update-alternative iptables and ebtables to working
8 legacy versions
9
10 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
11
12 pve-firewall (4.0-1) pve; urgency=medium
13
14 * re-build for Debian Buster / PVE 6
15
16 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
17
18 pve-firewall (3.0-21) unstable; urgency=medium
19
20 * fix ipv6 PVEFW-reject
21
22 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
23 ebtables doing the wrong thing here
24
25 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
26
27 pve-firewall (3.0-20) unstable; urgency=medium
28
29 * use IPCC to read config and rule files, if the are backed by pmxcfs which
30 has better handling for pmxcfs restarts
31
32 * fix #2178: endless loop on ipv6 extension headers
33
34 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
35
36 pve-firewall (3.0-19) unstable; urgency=medium
37
38 * ebtables: add arp filtering
39
40 * fix: #2123 Logging of user defined firewall rules
41
42 * fix Razor macro
43
44 * allow to enable/disable and modify cluster wide log ratelimits
45
46 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
47
48 pve-firewall (3.0-18) unstable; urgency=medium
49
50 * fix #1606: Add nf_conntrack_allow_invalid option
51
52 * log reject : add space after policy REJECT like drop
53
54 * fix #1891: Add zsh command completion for pve-firewall
55
56 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
57
58 pve-firewall (3.0-17) unstable; urgency=medium
59
60 * fix #2005: only allow ascii port digits
61
62 * fix #2004: do not allow backwards ranges
63
64 * add conntrack logging via libnetfilter_conntrack and allow one to enable
65 it through the firewall host configuration
66
67 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
68
69 pve-firewall (3.0-16) unstable; urgency=medium
70
71 * api/rules: fix macro return type
72
73 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
74
75 pve-firewall (3.0-15) unstable; urgency=medium
76
77 * fix #1971: display firewall rule properties
78
79 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
80
81 pve-firewall (3.0-14) unstable; urgency=medium
82
83 * fix #1841: avoid ebtable reloads when containers have multiple network
84 interfaces
85
86 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
87
88 pve-firewall (3.0-13) unstable; urgency=medium
89
90 * avoid unnecessary reloads of ebtable ruleset
91
92 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
93
94 pve-firewall (3.0-12) unstable; urgency=medium
95
96 * fix deleted iptables chains not being properly detected as a change
97
98 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
99
100 pve-firewall (3.0-11) unstable; urgency=medium
101
102 * #1764: rename 'ebtales_enable' option to 'ebtables'
103
104 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
105
106 pve-firewall (3.0-10) unstable; urgency=medium
107
108 * fix #1764: handle existing ebtables rules and allow disabling ebtables
109
110 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
111 ebtables_enable option.
112
113 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
114
115 pve-firewall (3.0-9) unstable; urgency=medium
116
117 * fix creation of ebltables FORWARD rule entry
118
119 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
120
121 pve-firewall (3.0-8) unstable; urgency=medium
122
123 * add ebtables support for better MAC filtering
124
125 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
126
127 pve-firewall (3.0-7) unstable; urgency=medium
128
129 * support distinct source and destination multi-port matching
130
131 * multi-port matching: when specifying the same list of ports for source and
132 destination require them both to match, rather than one of them, as this
133 was rather unexpected behavior
134
135 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
136
137 pve-firewall (3.0-6) unstable; urgency=medium
138
139 * fix #1319: don't fail postinst with masked service
140
141 * debian: switch to compat 9, drop init scripts, drop preinst
142
143 * check multiport limit in port ranges
144
145 * build: use git rev-parse for GITVERSION
146
147 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
148
149 pve-firewall (3.0-5) unstable; urgency=medium
150
151 * fix issue with disabled flag not being honored within groups
152
153 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
154
155 pve-firewall (3.0-4) unstable; urgency=medium
156
157 * fix issues with ipsets reloading unnecessarily or too late
158
159 * fix some typos in the logs
160
161 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
162
163 pve-firewall (3.0-3) unstable; urgency=medium
164
165 * Fix #1492: logger: use current timestamp if the packet doesn't have one
166
167 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
168
169 pve-firewall (3.0-2) unstable; urgency=medium
170
171 * Fix #1446: remove masks in case the package had previously been removed but
172 not purged.
173
174 * improve logging on errors in the firewall configuration
175
176 * forbid trailing commas in lists as iptables-restore doesn't support them
177
178 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
179
180 pve-firewall (3.0-1) unstable; urgency=medium
181
182 * rebuild for Debian Stretch
183
184 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
185
186 pve-firewall (2.0-33) unstable; urgency=medium
187
188 * ipset: don't allow zero-prefix entries
189
190 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
191
192 pve-firewall (2.0-32) unstable; urgency=medium
193
194 * improve search for local-network
195
196 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
197
198 pve-firewall (2.0-31) unstable; urgency=medium
199
200 * don't try to apply ports to rules which don't support them
201
202 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
203
204 pve-firewall (2.0-30) unstable; urgency=medium
205
206 * add multicast DNS to the list of Macros
207
208 * add missing parameter descriptions
209
210 * build-depends: add dh-systemd
211
212 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
213
214 pve-firewall (2.0-29) unstable; urgency=medium
215
216 * prevent overwriting ipsets/sec. groups by renaming
217
218 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
219
220 pve-firewall (2.0-28) unstable; urgency=medium
221
222 * use pve-common's ipv4_mask_hash_localnet
223
224 * fix allowed group name length
225
226 * make group digest stable
227
228 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
229
230 pve-firewall (2.0-27) unstable; urgency=medium
231
232 * fix #972: make PVEFW-FWBR-* rule order stable
233
234 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
235
236 pve-firewall (2.0-26) unstable; urgency=medium
237
238 * fix #988: set rp_filter=2
239
240 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
241
242 pve-firewall (2.0-25) unstable; urgency=medium
243
244 * fix #945: add uninitialized check in lxc ipset compilation
245
246 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
247
248 pve-firewall (2.0-24) unstable; urgency=medium
249
250 * Build-Depend on pve-doc-generator
251
252 * generate manpage with pve-doc-generator
253
254 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
255
256 pve-firewall (2.0-23) unstable; urgency=medium
257
258 * use only the top bit for our accept marks
259
260 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
261
262 pve-firewall (2.0-22) unstable; urgency=medium
263
264 * Use cfs_config_path from PVE::QemuConfig
265
266 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
267
268 pve-firewall (2.0-21) unstable; urgency=medium
269
270 * added new 'ipfilter' option
271
272 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
273
274 pve-firewall (2.0-20) unstable; urgency=medium
275
276 * fix 901: encode unicode characters in sha digest
277
278 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
279
280 pve-firewall (2.0-19) unstable; urgency=medium
281
282 * Add radv option to VM options
283
284 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
285
286 pve-firewall (2.0-18) unstable; urgency=medium
287
288 * Add ndp option to host and VM firewall options
289
290 * Add router-solicitation to NeighborDiscovery macro
291
292 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
293
294 pve-firewall (2.0-17) unstable; urgency=medium
295
296 * Don't leave empty FW config files behind
297
298 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
299
300 pve-firewall (2.0-16) unstable; urgency=medium
301
302 * logger: basic ipv6 support
303
304 * add DHCPv6 macro
305
306 * add dhcpv6 support to the dhcp option
307
308 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
309
310 pve-firewall (2.0-15) unstable; urgency=medium
311
312 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
313
314 * fix some regular expressions mixups
315
316 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
317
318 pve-firewall (2.0-14) unstable; urgency=medium
319
320 * fix systemd service dependencies
321
322 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
323
324 pve-firewall (2.0-13) unstable; urgency=medium
325
326 * allow numeric icmp types
327
328 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
329
330 pve-firewall (2.0-12) unstable; urgency=medium
331
332 * implement bash completions
333
334 * convert pve-firewall into a PVE::Service class
335
336 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
337
338 pve-firewall (2.0-11) unstable; urgency=medium
339
340 * iptables_get_chains: fix veth device name
341
342 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
343
344 pve-firewall (2.0-10) unstable; urgency=medium
345
346 * new helper: clone_vmfw_conf()
347
348 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
349
350 pve-firewall (2.0-9) unstable; urgency=medium
351
352 * remove firewall config file subroutine added
353
354 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
355
356 pve-firewall (2.0-8) unstable; urgency=medium
357
358 * adopt regresion tests for lxc containers
359
360 * removed firewall code for openVZ
361
362 * Subroutine verify_rule fixed to correctly check only for "net\d+"
363 interface device names
364
365 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
366
367 pve-firewall (2.0-7) unstable; urgency=medium
368
369 * added firewall code for lxc
370
371 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
372
373 pve-firewall (2.0-6) unstable; urgency=medium
374
375 * firewall ipversion comparison fix
376
377 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
378
379 pve-firewall (2.0-5) unstable; urgency=medium
380
381 * add ipv6 neighbor discovery and solicitation macros
382
383 * ip6tables accepts both spellings of the word neighbor
384
385 * added Ceph macro
386
387 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
388
389 pve-firewall (2.0-4) unstable; urgency=medium
390
391 * include manual page for pve-firewall
392
393 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
394
395 pve-firewall (2.0-3) unstable; urgency=medium
396
397 * use noawait trigers for pve-api-updates
398
399 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
400
401 pve-firewall (2.0-2) unstable; urgency=medium
402
403 * trigger pve-api-updates event
404
405 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
406
407 pve-firewall (2.0-1) unstable; urgency=medium
408
409 * recompile for debian jessie
410
411 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
412
413 pve-firewall (1.0-18) unstable; urgency=low
414
415 * fix alias lookup
416
417 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
418
419 pve-firewall (1.0-17) unstable; urgency=low
420
421 * fix restart behavior
422
423 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
424
425 pve-firewall (1.0-16) unstable; urgency=low
426
427 * use new Daemon class from pve-common
428
429 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
430
431 pve-firewall (1.0-15) unstable; urgency=low
432
433 * bug fix: load cluster conf for host rules
434
435 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
436
437 pve-firewall (1.0-14) unstable; urgency=low
438
439 * do not use ipset list chains
440
441 * remove preinst script (not needed anymore)
442
443 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
444
445 pve-firewall (1.0-13) unstable; urgency=low
446
447 * fix ipset remove order
448
449 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
450
451 pve-firewall (1.0-12) unstable; urgency=low
452
453 * add preinst script to clear ipset from older installation (because
454 sets cannot be swapped if there type does not match.
455
456 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
457
458 pve-firewall (1.0-11) unstable; urgency=low
459
460 * bug fix: correctly set ipversion for aliases in verify_rule
461
462 * save restore commands into files to make debugging
463 easier (/var/lib/pve-firewall/)
464
465 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
466
467 pve-firewall (1.0-10) unstable; urgency=low
468
469 * add IPv6 support for VMs (hostfw is IPv4 only)
470
471 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
472
473 pve-firewall (1.0-9) unstable; urgency=low
474
475 * fix max ipset name name length
476
477 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
478
479 pve-firewall (1.0-8) unstable; urgency=low
480
481 * implement permission
482
483 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
484
485 pve-firewall (1.0-7) unstable; urgency=low
486
487 * proxy host rule API calls to correct node
488
489 * always generate MAC and IP filter rules if firewall is enabled on NIC
490
491 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
492
493 pve-firewall (1.0-6) unstable; urgency=low
494
495 * ipmlement ipfilter ipsets
496
497 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
498
499 pve-firewall (1.0-5) unstable; urgency=low
500
501 * remove ipsets when firewall disabled
502
503 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
504
505 pve-firewall (1.0-4) unstable; urgency=low
506
507 * depend on iptables and ipset
508
509 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
510
511 pve-firewall (1.0-3) unstable; urgency=low
512
513 * change dh_installinit order (register pvefw-logger before pve-firewall)
514
515 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
516
517 pve-firewall (1.0-2) unstable; urgency=low
518
519 * add experimental nflog logging daemon
520
521 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
522
523 pve-firewall (1.0-1) unstable; urgency=low
524
525 * initial package
526
527 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
528