]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
bump version to 5.0.2
[pve-firewall.git] / debian / changelog
1 pve-firewall (5.0.2) bookworm; urgency=medium
2
3 * fix #4556: api: return scoped IPSets and aliases
4
5 -- Proxmox Support Team <support@proxmox.com> Wed, 21 Jun 2023 19:17:19 +0200
6
7 pve-firewall (5.0.1) bookworm; urgency=medium
8
9 * fix #4556: support 'dc/' and 'guest/' prefix for aliases and ipsets
10
11 -- Proxmox Support Team <support@proxmox.com> Wed, 07 Jun 2023 16:06:10 +0200
12
13 pve-firewall (5.0.0) bookworm; urgency=medium
14
15 * switch to native versioning scheme
16
17 * build for Proxmox VE 8 / Debian 12 Bookworm
18
19 -- Proxmox Support Team <support@proxmox.com> Mon, 22 May 2023 14:43:58 +0200
20
21 pve-firewall (4.3-2) bullseye; urgency=medium
22
23 * fix variables declared in conditional statement
24
25 * fix #4730: add safeguards to prevent ICMP type misuse
26
27 -- Proxmox Support Team <support@proxmox.com> Tue, 16 May 2023 11:17:58 +0200
28
29 pve-firewall (4.3-1) bullseye; urgency=medium
30
31 * allow entering IP address with the host bits (those inside the mask) not
32 being all zero non-zero, like 192.168.1.155/24 for example.
33
34 * api: firewall logger: add optional parameters `since` and `until` for
35 time-range filtering
36
37 * fix #4550: host options: add nf_conntrack_helpers to compensate that
38 kernel 6.1 and newer have removed the auto helpers
39
40 -- Proxmox Support Team <support@proxmox.com> Fri, 17 Mar 2023 15:24:56 +0100
41
42 pve-firewall (4.2-7) bullseye; urgency=medium
43
44 * fix #4018: add firewall macro for SPICE proxy
45
46 * fix #4204: automatically update each usage of a group to the new ID when
47 it is renamed
48
49 * fix #4268: add 'force' parameter to delete IPSet with members
50
51 -- Proxmox Support Team <support@proxmox.com> Thu, 17 Nov 2022 19:53:04 +0100
52
53 pve-firewall (4.2-6) bullseye; urgency=medium
54
55 * config defaults: document that the mac filter defaults to on
56
57 * fix #4175: ignore non-filter ebtables tables
58
59 * fix enabling ebtables if VM firewall config is invalid
60
61 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Aug 2022 09:43:53 +0200
62
63 pve-firewall (4.2-5) bullseye; urgency=medium
64
65 * fix #3677 ipset get chains: handle newer ipset output for actual
66 change detection
67
68 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Nov 2021 16:37:13 +0100
69
70 pve-firewall (4.2-4) bullseye; urgency=medium
71
72 * re-build to avoid issues stemming from semi-broken systemd-debhelper version
73
74 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Oct 2021 10:39:05 +0200
75
76 pve-firewall (4.2-3) bullseye; urgency=medium
77
78 * fix #2721: remove the (nowadays) bogus reject for TCP port 43 from the
79 default drop and reject actions
80
81 -- Proxmox Support Team <support@proxmox.com> Fri, 10 Sep 2021 13:00:07 +0200
82
83 pve-firewall (4.2-2) bullseye; urgency=medium
84
85 * re-set relevant sysctls on every apply round
86
87 -- Proxmox Support Team <support@proxmox.com> Mon, 21 Jun 2021 11:31:42 +0200
88
89 pve-firewall (4.2-1) bullseye; urgency=medium
90
91 * fix #967: source: dest: limit length
92
93 * re-build for Debian 11 Bullseye based releases (Proxmox VE 7)
94
95 * fix #2358: allow --<opt> in firewall rule config files
96
97 -- Proxmox Support Team <support@proxmox.com> Wed, 12 May 2021 20:32:30 +0200
98
99 pve-firewall (4.1-3) pve; urgency=medium
100
101 * fix #2773: ebtables: keep policy of custom chains
102
103 * introduce new icmp-type parameter
104
105 -- Proxmox Support Team <support@proxmox.com> Fri, 18 Sep 2020 16:51:27 +0200
106
107 pve-firewall (4.1-2) pve; urgency=medium
108
109 * revert: rules: verify referenced security group exists
110
111 -- Proxmox Support Team <support@proxmox.com> Wed, 06 May 2020 17:41:36 +0200
112
113 pve-firewall (4.1-1) pve; urgency=medium
114
115 * logging: add missing log message for inbound rules
116
117 * fix #2686: avoid adding 'arp-ip-src' IP filter if guests uses DHCP
118
119 * IPSets: parse the CIDR before checking for duplicates
120
121 * verify that a referenced security group exists
122
123 * ICMP: fix iptables-restore failing if ICMP-type values bigger than '255'
124
125 * ICMP: allow one to specify the 'echo-reply' (0) type also as integer
126
127 * improve handling concurrent (parallel) access and modifications to rules
128
129 -- Proxmox Support Team <support@proxmox.com> Mon, 04 May 2020 15:01:57 +0200
130
131 pve-firewall (4.0-10) pve; urgency=medium
132
133 * macros: add macro for Proxmox Mail Gateway web interface
134
135 * api node: always pass cluster conf to node FW parser to fix false positive
136 error message about non existing aliases, or IP sets, when querying the
137 node FW options GET API call.
138
139 * grammar fix: s/does not exists/does not exist/g
140
141 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jan 2020 19:25:49 +0100
142
143 pve-firewall (4.0-9) pve; urgency=medium
144
145 * ensure port range used for offline storage migration and insecure migration
146 traffic is allowed by default rule set.
147
148 -- Proxmox Support Team <support@proxmox.com> Tue, 03 Dec 2019 08:12:20 +0100
149
150 pve-firewall (4.0-8) pve; urgency=medium
151
152 * increase default nf_conntrack_max to the kernel's default
153
154 * fix some "use of uninitialized value" warnings when updating CIDRs
155
156 * update schema documentation
157
158 * add explicit dependency on libpve-cluster-perl
159
160 * add support for "raw" tables
161
162 * add options for synflood protection for host firewall:
163 - nf_conntrack_tcp_timeout_syn_recv
164 - protection_synflood: boolean
165 - protection_synflood_rate: SYN rate limit (default 200 per second)
166 - protection_synflood_burst: SYN burst limit (default 1000)
167
168 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2019 13:48:20 +0100
169
170 pve-firewall (4.0-7) pve; urgency=medium
171
172 * only add VM chains and rules if VM firewall is enabled
173
174 -- Proxmox Support Team <support@proxmox.com> Wed, 7 Aug 2019 10:55:06 +0200
175
176 pve-firewall (4.0-6) pve; urgency=medium
177
178 * firewall macros: add new Ceph protocol v2 port while keeping v1 port
179
180 -- Proxmox Support Team <support@proxmox.com> Tue, 23 Jul 2019 18:57:48 +0200
181
182 pve-firewall (4.0-5) pve; urgency=medium
183
184 * don't use any base path at all for calls to external binaries to make use
185 compativle with bot, /usr merged and unmerged setups
186
187 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Jul 2019 11:47:53 +0200
188
189 pve-firewall (4.0-4) pve; urgency=medium
190
191 * ebtables: remove PVE chains properly
192
193 * ebtables: treat chain deletion as change
194
195 * use /usr/sbin as base path
196
197 -- Proxmox Support Team <support@proxmox.com> Thu, 11 Jul 2019 19:40:01 +0200
198
199 pve-firewall (4.0-3) pve; urgency=medium
200
201 * Create corosync firewall rules independently of localnet~
202
203 * Display corosync rule info on localnet call
204
205 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
206
207 pve-firewall (4.0-2) pve; urgency=medium
208
209 * fix systemd warning about PIDFile directory
210
211 * fix CT rule generation with ipfilter set
212
213 * pve-firewall service: update-alternative iptables and ebtables to working
214 legacy versions
215
216 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
217
218 pve-firewall (4.0-1) pve; urgency=medium
219
220 * re-build for Debian Buster / PVE 6
221
222 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
223
224 pve-firewall (3.0-21) unstable; urgency=medium
225
226 * fix ipv6 PVEFW-reject
227
228 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
229 ebtables doing the wrong thing here
230
231 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
232
233 pve-firewall (3.0-20) unstable; urgency=medium
234
235 * use IPCC to read config and rule files, if the are backed by pmxcfs which
236 has better handling for pmxcfs restarts
237
238 * fix #2178: endless loop on ipv6 extension headers
239
240 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
241
242 pve-firewall (3.0-19) unstable; urgency=medium
243
244 * ebtables: add arp filtering
245
246 * fix: #2123 Logging of user defined firewall rules
247
248 * fix Razor macro
249
250 * allow to enable/disable and modify cluster wide log ratelimits
251
252 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
253
254 pve-firewall (3.0-18) unstable; urgency=medium
255
256 * fix #1606: Add nf_conntrack_allow_invalid option
257
258 * log reject : add space after policy REJECT like drop
259
260 * fix #1891: Add zsh command completion for pve-firewall
261
262 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
263
264 pve-firewall (3.0-17) unstable; urgency=medium
265
266 * fix #2005: only allow ascii port digits
267
268 * fix #2004: do not allow backwards ranges
269
270 * add conntrack logging via libnetfilter_conntrack and allow one to enable
271 it through the firewall host configuration
272
273 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
274
275 pve-firewall (3.0-16) unstable; urgency=medium
276
277 * api/rules: fix macro return type
278
279 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
280
281 pve-firewall (3.0-15) unstable; urgency=medium
282
283 * fix #1971: display firewall rule properties
284
285 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
286
287 pve-firewall (3.0-14) unstable; urgency=medium
288
289 * fix #1841: avoid ebtable reloads when containers have multiple network
290 interfaces
291
292 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
293
294 pve-firewall (3.0-13) unstable; urgency=medium
295
296 * avoid unnecessary reloads of ebtable ruleset
297
298 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
299
300 pve-firewall (3.0-12) unstable; urgency=medium
301
302 * fix deleted iptables chains not being properly detected as a change
303
304 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
305
306 pve-firewall (3.0-11) unstable; urgency=medium
307
308 * #1764: rename 'ebtales_enable' option to 'ebtables'
309
310 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
311
312 pve-firewall (3.0-10) unstable; urgency=medium
313
314 * fix #1764: handle existing ebtables rules and allow disabling ebtables
315
316 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
317 ebtables_enable option.
318
319 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
320
321 pve-firewall (3.0-9) unstable; urgency=medium
322
323 * fix creation of ebltables FORWARD rule entry
324
325 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
326
327 pve-firewall (3.0-8) unstable; urgency=medium
328
329 * add ebtables support for better MAC filtering
330
331 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
332
333 pve-firewall (3.0-7) unstable; urgency=medium
334
335 * support distinct source and destination multi-port matching
336
337 * multi-port matching: when specifying the same list of ports for source and
338 destination require them both to match, rather than one of them, as this
339 was rather unexpected behavior
340
341 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
342
343 pve-firewall (3.0-6) unstable; urgency=medium
344
345 * fix #1319: don't fail postinst with masked service
346
347 * debian: switch to compat 9, drop init scripts, drop preinst
348
349 * check multiport limit in port ranges
350
351 * build: use git rev-parse for GITVERSION
352
353 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
354
355 pve-firewall (3.0-5) unstable; urgency=medium
356
357 * fix issue with disabled flag not being honored within groups
358
359 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
360
361 pve-firewall (3.0-4) unstable; urgency=medium
362
363 * fix issues with ipsets reloading unnecessarily or too late
364
365 * fix some typos in the logs
366
367 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
368
369 pve-firewall (3.0-3) unstable; urgency=medium
370
371 * Fix #1492: logger: use current timestamp if the packet doesn't have one
372
373 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
374
375 pve-firewall (3.0-2) unstable; urgency=medium
376
377 * Fix #1446: remove masks in case the package had previously been removed but
378 not purged.
379
380 * improve logging on errors in the firewall configuration
381
382 * forbid trailing commas in lists as iptables-restore doesn't support them
383
384 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
385
386 pve-firewall (3.0-1) unstable; urgency=medium
387
388 * rebuild for Debian Stretch
389
390 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
391
392 pve-firewall (2.0-33) unstable; urgency=medium
393
394 * ipset: don't allow zero-prefix entries
395
396 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
397
398 pve-firewall (2.0-32) unstable; urgency=medium
399
400 * improve search for local-network
401
402 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
403
404 pve-firewall (2.0-31) unstable; urgency=medium
405
406 * don't try to apply ports to rules which don't support them
407
408 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
409
410 pve-firewall (2.0-30) unstable; urgency=medium
411
412 * add multicast DNS to the list of Macros
413
414 * add missing parameter descriptions
415
416 * build-depends: add dh-systemd
417
418 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
419
420 pve-firewall (2.0-29) unstable; urgency=medium
421
422 * prevent overwriting ipsets/sec. groups by renaming
423
424 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
425
426 pve-firewall (2.0-28) unstable; urgency=medium
427
428 * use pve-common's ipv4_mask_hash_localnet
429
430 * fix allowed group name length
431
432 * make group digest stable
433
434 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
435
436 pve-firewall (2.0-27) unstable; urgency=medium
437
438 * fix #972: make PVEFW-FWBR-* rule order stable
439
440 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
441
442 pve-firewall (2.0-26) unstable; urgency=medium
443
444 * fix #988: set rp_filter=2
445
446 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
447
448 pve-firewall (2.0-25) unstable; urgency=medium
449
450 * fix #945: add uninitialized check in lxc ipset compilation
451
452 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
453
454 pve-firewall (2.0-24) unstable; urgency=medium
455
456 * Build-Depend on pve-doc-generator
457
458 * generate manpage with pve-doc-generator
459
460 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
461
462 pve-firewall (2.0-23) unstable; urgency=medium
463
464 * use only the top bit for our accept marks
465
466 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
467
468 pve-firewall (2.0-22) unstable; urgency=medium
469
470 * Use cfs_config_path from PVE::QemuConfig
471
472 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
473
474 pve-firewall (2.0-21) unstable; urgency=medium
475
476 * added new 'ipfilter' option
477
478 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
479
480 pve-firewall (2.0-20) unstable; urgency=medium
481
482 * fix 901: encode unicode characters in sha digest
483
484 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
485
486 pve-firewall (2.0-19) unstable; urgency=medium
487
488 * Add radv option to VM options
489
490 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
491
492 pve-firewall (2.0-18) unstable; urgency=medium
493
494 * Add ndp option to host and VM firewall options
495
496 * Add router-solicitation to NeighborDiscovery macro
497
498 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
499
500 pve-firewall (2.0-17) unstable; urgency=medium
501
502 * Don't leave empty FW config files behind
503
504 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
505
506 pve-firewall (2.0-16) unstable; urgency=medium
507
508 * logger: basic ipv6 support
509
510 * add DHCPv6 macro
511
512 * add dhcpv6 support to the dhcp option
513
514 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
515
516 pve-firewall (2.0-15) unstable; urgency=medium
517
518 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
519
520 * fix some regular expressions mixups
521
522 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
523
524 pve-firewall (2.0-14) unstable; urgency=medium
525
526 * fix systemd service dependencies
527
528 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
529
530 pve-firewall (2.0-13) unstable; urgency=medium
531
532 * allow numeric icmp types
533
534 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
535
536 pve-firewall (2.0-12) unstable; urgency=medium
537
538 * implement bash completions
539
540 * convert pve-firewall into a PVE::Service class
541
542 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
543
544 pve-firewall (2.0-11) unstable; urgency=medium
545
546 * iptables_get_chains: fix veth device name
547
548 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
549
550 pve-firewall (2.0-10) unstable; urgency=medium
551
552 * new helper: clone_vmfw_conf()
553
554 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
555
556 pve-firewall (2.0-9) unstable; urgency=medium
557
558 * remove firewall config file subroutine added
559
560 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
561
562 pve-firewall (2.0-8) unstable; urgency=medium
563
564 * adopt regresion tests for lxc containers
565
566 * removed firewall code for openVZ
567
568 * Subroutine verify_rule fixed to correctly check only for "net\d+"
569 interface device names
570
571 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
572
573 pve-firewall (2.0-7) unstable; urgency=medium
574
575 * added firewall code for lxc
576
577 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
578
579 pve-firewall (2.0-6) unstable; urgency=medium
580
581 * firewall ipversion comparison fix
582
583 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
584
585 pve-firewall (2.0-5) unstable; urgency=medium
586
587 * add ipv6 neighbor discovery and solicitation macros
588
589 * ip6tables accepts both spellings of the word neighbor
590
591 * added Ceph macro
592
593 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
594
595 pve-firewall (2.0-4) unstable; urgency=medium
596
597 * include manual page for pve-firewall
598
599 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
600
601 pve-firewall (2.0-3) unstable; urgency=medium
602
603 * use noawait trigers for pve-api-updates
604
605 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
606
607 pve-firewall (2.0-2) unstable; urgency=medium
608
609 * trigger pve-api-updates event
610
611 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
612
613 pve-firewall (2.0-1) unstable; urgency=medium
614
615 * recompile for debian jessie
616
617 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
618
619 pve-firewall (1.0-18) unstable; urgency=low
620
621 * fix alias lookup
622
623 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
624
625 pve-firewall (1.0-17) unstable; urgency=low
626
627 * fix restart behavior
628
629 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
630
631 pve-firewall (1.0-16) unstable; urgency=low
632
633 * use new Daemon class from pve-common
634
635 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
636
637 pve-firewall (1.0-15) unstable; urgency=low
638
639 * bug fix: load cluster conf for host rules
640
641 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
642
643 pve-firewall (1.0-14) unstable; urgency=low
644
645 * do not use ipset list chains
646
647 * remove preinst script (not needed anymore)
648
649 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
650
651 pve-firewall (1.0-13) unstable; urgency=low
652
653 * fix ipset remove order
654
655 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
656
657 pve-firewall (1.0-12) unstable; urgency=low
658
659 * add preinst script to clear ipset from older installation (because
660 sets cannot be swapped if there type does not match.
661
662 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
663
664 pve-firewall (1.0-11) unstable; urgency=low
665
666 * bug fix: correctly set ipversion for aliases in verify_rule
667
668 * save restore commands into files to make debugging
669 easier (/var/lib/pve-firewall/)
670
671 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
672
673 pve-firewall (1.0-10) unstable; urgency=low
674
675 * add IPv6 support for VMs (hostfw is IPv4 only)
676
677 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
678
679 pve-firewall (1.0-9) unstable; urgency=low
680
681 * fix max ipset name name length
682
683 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
684
685 pve-firewall (1.0-8) unstable; urgency=low
686
687 * implement permission
688
689 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
690
691 pve-firewall (1.0-7) unstable; urgency=low
692
693 * proxy host rule API calls to correct node
694
695 * always generate MAC and IP filter rules if firewall is enabled on NIC
696
697 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
698
699 pve-firewall (1.0-6) unstable; urgency=low
700
701 * ipmlement ipfilter ipsets
702
703 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
704
705 pve-firewall (1.0-5) unstable; urgency=low
706
707 * remove ipsets when firewall disabled
708
709 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
710
711 pve-firewall (1.0-4) unstable; urgency=low
712
713 * depend on iptables and ipset
714
715 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
716
717 pve-firewall (1.0-3) unstable; urgency=low
718
719 * change dh_installinit order (register pvefw-logger before pve-firewall)
720
721 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
722
723 pve-firewall (1.0-2) unstable; urgency=low
724
725 * add experimental nflog logging daemon
726
727 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
728
729 pve-firewall (1.0-1) unstable; urgency=low
730
731 * initial package
732
733 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
734