]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
bump version to 5.0.1
[pve-firewall.git] / debian / changelog
1 pve-firewall (5.0.1) bookworm; urgency=medium
2
3 * fix #4556: support 'dc/' and 'guest/' prefix for aliases and ipsets
4
5 -- Proxmox Support Team <support@proxmox.com> Wed, 07 Jun 2023 16:06:10 +0200
6
7 pve-firewall (5.0.0) bookworm; urgency=medium
8
9 * switch to native versioning scheme
10
11 * build for Proxmox VE 8 / Debian 12 Bookworm
12
13 -- Proxmox Support Team <support@proxmox.com> Mon, 22 May 2023 14:43:58 +0200
14
15 pve-firewall (4.3-2) bullseye; urgency=medium
16
17 * fix variables declared in conditional statement
18
19 * fix #4730: add safeguards to prevent ICMP type misuse
20
21 -- Proxmox Support Team <support@proxmox.com> Tue, 16 May 2023 11:17:58 +0200
22
23 pve-firewall (4.3-1) bullseye; urgency=medium
24
25 * allow entering IP address with the host bits (those inside the mask) not
26 being all zero non-zero, like 192.168.1.155/24 for example.
27
28 * api: firewall logger: add optional parameters `since` and `until` for
29 time-range filtering
30
31 * fix #4550: host options: add nf_conntrack_helpers to compensate that
32 kernel 6.1 and newer have removed the auto helpers
33
34 -- Proxmox Support Team <support@proxmox.com> Fri, 17 Mar 2023 15:24:56 +0100
35
36 pve-firewall (4.2-7) bullseye; urgency=medium
37
38 * fix #4018: add firewall macro for SPICE proxy
39
40 * fix #4204: automatically update each usage of a group to the new ID when
41 it is renamed
42
43 * fix #4268: add 'force' parameter to delete IPSet with members
44
45 -- Proxmox Support Team <support@proxmox.com> Thu, 17 Nov 2022 19:53:04 +0100
46
47 pve-firewall (4.2-6) bullseye; urgency=medium
48
49 * config defaults: document that the mac filter defaults to on
50
51 * fix #4175: ignore non-filter ebtables tables
52
53 * fix enabling ebtables if VM firewall config is invalid
54
55 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Aug 2022 09:43:53 +0200
56
57 pve-firewall (4.2-5) bullseye; urgency=medium
58
59 * fix #3677 ipset get chains: handle newer ipset output for actual
60 change detection
61
62 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Nov 2021 16:37:13 +0100
63
64 pve-firewall (4.2-4) bullseye; urgency=medium
65
66 * re-build to avoid issues stemming from semi-broken systemd-debhelper version
67
68 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Oct 2021 10:39:05 +0200
69
70 pve-firewall (4.2-3) bullseye; urgency=medium
71
72 * fix #2721: remove the (nowadays) bogus reject for TCP port 43 from the
73 default drop and reject actions
74
75 -- Proxmox Support Team <support@proxmox.com> Fri, 10 Sep 2021 13:00:07 +0200
76
77 pve-firewall (4.2-2) bullseye; urgency=medium
78
79 * re-set relevant sysctls on every apply round
80
81 -- Proxmox Support Team <support@proxmox.com> Mon, 21 Jun 2021 11:31:42 +0200
82
83 pve-firewall (4.2-1) bullseye; urgency=medium
84
85 * fix #967: source: dest: limit length
86
87 * re-build for Debian 11 Bullseye based releases (Proxmox VE 7)
88
89 * fix #2358: allow --<opt> in firewall rule config files
90
91 -- Proxmox Support Team <support@proxmox.com> Wed, 12 May 2021 20:32:30 +0200
92
93 pve-firewall (4.1-3) pve; urgency=medium
94
95 * fix #2773: ebtables: keep policy of custom chains
96
97 * introduce new icmp-type parameter
98
99 -- Proxmox Support Team <support@proxmox.com> Fri, 18 Sep 2020 16:51:27 +0200
100
101 pve-firewall (4.1-2) pve; urgency=medium
102
103 * revert: rules: verify referenced security group exists
104
105 -- Proxmox Support Team <support@proxmox.com> Wed, 06 May 2020 17:41:36 +0200
106
107 pve-firewall (4.1-1) pve; urgency=medium
108
109 * logging: add missing log message for inbound rules
110
111 * fix #2686: avoid adding 'arp-ip-src' IP filter if guests uses DHCP
112
113 * IPSets: parse the CIDR before checking for duplicates
114
115 * verify that a referenced security group exists
116
117 * ICMP: fix iptables-restore failing if ICMP-type values bigger than '255'
118
119 * ICMP: allow one to specify the 'echo-reply' (0) type also as integer
120
121 * improve handling concurrent (parallel) access and modifications to rules
122
123 -- Proxmox Support Team <support@proxmox.com> Mon, 04 May 2020 15:01:57 +0200
124
125 pve-firewall (4.0-10) pve; urgency=medium
126
127 * macros: add macro for Proxmox Mail Gateway web interface
128
129 * api node: always pass cluster conf to node FW parser to fix false positive
130 error message about non existing aliases, or IP sets, when querying the
131 node FW options GET API call.
132
133 * grammar fix: s/does not exists/does not exist/g
134
135 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jan 2020 19:25:49 +0100
136
137 pve-firewall (4.0-9) pve; urgency=medium
138
139 * ensure port range used for offline storage migration and insecure migration
140 traffic is allowed by default rule set.
141
142 -- Proxmox Support Team <support@proxmox.com> Tue, 03 Dec 2019 08:12:20 +0100
143
144 pve-firewall (4.0-8) pve; urgency=medium
145
146 * increase default nf_conntrack_max to the kernel's default
147
148 * fix some "use of uninitialized value" warnings when updating CIDRs
149
150 * update schema documentation
151
152 * add explicit dependency on libpve-cluster-perl
153
154 * add support for "raw" tables
155
156 * add options for synflood protection for host firewall:
157 - nf_conntrack_tcp_timeout_syn_recv
158 - protection_synflood: boolean
159 - protection_synflood_rate: SYN rate limit (default 200 per second)
160 - protection_synflood_burst: SYN burst limit (default 1000)
161
162 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2019 13:48:20 +0100
163
164 pve-firewall (4.0-7) pve; urgency=medium
165
166 * only add VM chains and rules if VM firewall is enabled
167
168 -- Proxmox Support Team <support@proxmox.com> Wed, 7 Aug 2019 10:55:06 +0200
169
170 pve-firewall (4.0-6) pve; urgency=medium
171
172 * firewall macros: add new Ceph protocol v2 port while keeping v1 port
173
174 -- Proxmox Support Team <support@proxmox.com> Tue, 23 Jul 2019 18:57:48 +0200
175
176 pve-firewall (4.0-5) pve; urgency=medium
177
178 * don't use any base path at all for calls to external binaries to make use
179 compativle with bot, /usr merged and unmerged setups
180
181 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Jul 2019 11:47:53 +0200
182
183 pve-firewall (4.0-4) pve; urgency=medium
184
185 * ebtables: remove PVE chains properly
186
187 * ebtables: treat chain deletion as change
188
189 * use /usr/sbin as base path
190
191 -- Proxmox Support Team <support@proxmox.com> Thu, 11 Jul 2019 19:40:01 +0200
192
193 pve-firewall (4.0-3) pve; urgency=medium
194
195 * Create corosync firewall rules independently of localnet~
196
197 * Display corosync rule info on localnet call
198
199 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
200
201 pve-firewall (4.0-2) pve; urgency=medium
202
203 * fix systemd warning about PIDFile directory
204
205 * fix CT rule generation with ipfilter set
206
207 * pve-firewall service: update-alternative iptables and ebtables to working
208 legacy versions
209
210 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
211
212 pve-firewall (4.0-1) pve; urgency=medium
213
214 * re-build for Debian Buster / PVE 6
215
216 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
217
218 pve-firewall (3.0-21) unstable; urgency=medium
219
220 * fix ipv6 PVEFW-reject
221
222 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
223 ebtables doing the wrong thing here
224
225 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
226
227 pve-firewall (3.0-20) unstable; urgency=medium
228
229 * use IPCC to read config and rule files, if the are backed by pmxcfs which
230 has better handling for pmxcfs restarts
231
232 * fix #2178: endless loop on ipv6 extension headers
233
234 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
235
236 pve-firewall (3.0-19) unstable; urgency=medium
237
238 * ebtables: add arp filtering
239
240 * fix: #2123 Logging of user defined firewall rules
241
242 * fix Razor macro
243
244 * allow to enable/disable and modify cluster wide log ratelimits
245
246 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
247
248 pve-firewall (3.0-18) unstable; urgency=medium
249
250 * fix #1606: Add nf_conntrack_allow_invalid option
251
252 * log reject : add space after policy REJECT like drop
253
254 * fix #1891: Add zsh command completion for pve-firewall
255
256 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
257
258 pve-firewall (3.0-17) unstable; urgency=medium
259
260 * fix #2005: only allow ascii port digits
261
262 * fix #2004: do not allow backwards ranges
263
264 * add conntrack logging via libnetfilter_conntrack and allow one to enable
265 it through the firewall host configuration
266
267 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
268
269 pve-firewall (3.0-16) unstable; urgency=medium
270
271 * api/rules: fix macro return type
272
273 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
274
275 pve-firewall (3.0-15) unstable; urgency=medium
276
277 * fix #1971: display firewall rule properties
278
279 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
280
281 pve-firewall (3.0-14) unstable; urgency=medium
282
283 * fix #1841: avoid ebtable reloads when containers have multiple network
284 interfaces
285
286 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
287
288 pve-firewall (3.0-13) unstable; urgency=medium
289
290 * avoid unnecessary reloads of ebtable ruleset
291
292 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
293
294 pve-firewall (3.0-12) unstable; urgency=medium
295
296 * fix deleted iptables chains not being properly detected as a change
297
298 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
299
300 pve-firewall (3.0-11) unstable; urgency=medium
301
302 * #1764: rename 'ebtales_enable' option to 'ebtables'
303
304 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
305
306 pve-firewall (3.0-10) unstable; urgency=medium
307
308 * fix #1764: handle existing ebtables rules and allow disabling ebtables
309
310 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
311 ebtables_enable option.
312
313 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
314
315 pve-firewall (3.0-9) unstable; urgency=medium
316
317 * fix creation of ebltables FORWARD rule entry
318
319 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
320
321 pve-firewall (3.0-8) unstable; urgency=medium
322
323 * add ebtables support for better MAC filtering
324
325 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
326
327 pve-firewall (3.0-7) unstable; urgency=medium
328
329 * support distinct source and destination multi-port matching
330
331 * multi-port matching: when specifying the same list of ports for source and
332 destination require them both to match, rather than one of them, as this
333 was rather unexpected behavior
334
335 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
336
337 pve-firewall (3.0-6) unstable; urgency=medium
338
339 * fix #1319: don't fail postinst with masked service
340
341 * debian: switch to compat 9, drop init scripts, drop preinst
342
343 * check multiport limit in port ranges
344
345 * build: use git rev-parse for GITVERSION
346
347 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
348
349 pve-firewall (3.0-5) unstable; urgency=medium
350
351 * fix issue with disabled flag not being honored within groups
352
353 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
354
355 pve-firewall (3.0-4) unstable; urgency=medium
356
357 * fix issues with ipsets reloading unnecessarily or too late
358
359 * fix some typos in the logs
360
361 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
362
363 pve-firewall (3.0-3) unstable; urgency=medium
364
365 * Fix #1492: logger: use current timestamp if the packet doesn't have one
366
367 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
368
369 pve-firewall (3.0-2) unstable; urgency=medium
370
371 * Fix #1446: remove masks in case the package had previously been removed but
372 not purged.
373
374 * improve logging on errors in the firewall configuration
375
376 * forbid trailing commas in lists as iptables-restore doesn't support them
377
378 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
379
380 pve-firewall (3.0-1) unstable; urgency=medium
381
382 * rebuild for Debian Stretch
383
384 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
385
386 pve-firewall (2.0-33) unstable; urgency=medium
387
388 * ipset: don't allow zero-prefix entries
389
390 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
391
392 pve-firewall (2.0-32) unstable; urgency=medium
393
394 * improve search for local-network
395
396 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
397
398 pve-firewall (2.0-31) unstable; urgency=medium
399
400 * don't try to apply ports to rules which don't support them
401
402 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
403
404 pve-firewall (2.0-30) unstable; urgency=medium
405
406 * add multicast DNS to the list of Macros
407
408 * add missing parameter descriptions
409
410 * build-depends: add dh-systemd
411
412 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
413
414 pve-firewall (2.0-29) unstable; urgency=medium
415
416 * prevent overwriting ipsets/sec. groups by renaming
417
418 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
419
420 pve-firewall (2.0-28) unstable; urgency=medium
421
422 * use pve-common's ipv4_mask_hash_localnet
423
424 * fix allowed group name length
425
426 * make group digest stable
427
428 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
429
430 pve-firewall (2.0-27) unstable; urgency=medium
431
432 * fix #972: make PVEFW-FWBR-* rule order stable
433
434 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
435
436 pve-firewall (2.0-26) unstable; urgency=medium
437
438 * fix #988: set rp_filter=2
439
440 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
441
442 pve-firewall (2.0-25) unstable; urgency=medium
443
444 * fix #945: add uninitialized check in lxc ipset compilation
445
446 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
447
448 pve-firewall (2.0-24) unstable; urgency=medium
449
450 * Build-Depend on pve-doc-generator
451
452 * generate manpage with pve-doc-generator
453
454 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
455
456 pve-firewall (2.0-23) unstable; urgency=medium
457
458 * use only the top bit for our accept marks
459
460 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
461
462 pve-firewall (2.0-22) unstable; urgency=medium
463
464 * Use cfs_config_path from PVE::QemuConfig
465
466 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
467
468 pve-firewall (2.0-21) unstable; urgency=medium
469
470 * added new 'ipfilter' option
471
472 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
473
474 pve-firewall (2.0-20) unstable; urgency=medium
475
476 * fix 901: encode unicode characters in sha digest
477
478 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
479
480 pve-firewall (2.0-19) unstable; urgency=medium
481
482 * Add radv option to VM options
483
484 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
485
486 pve-firewall (2.0-18) unstable; urgency=medium
487
488 * Add ndp option to host and VM firewall options
489
490 * Add router-solicitation to NeighborDiscovery macro
491
492 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
493
494 pve-firewall (2.0-17) unstable; urgency=medium
495
496 * Don't leave empty FW config files behind
497
498 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
499
500 pve-firewall (2.0-16) unstable; urgency=medium
501
502 * logger: basic ipv6 support
503
504 * add DHCPv6 macro
505
506 * add dhcpv6 support to the dhcp option
507
508 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
509
510 pve-firewall (2.0-15) unstable; urgency=medium
511
512 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
513
514 * fix some regular expressions mixups
515
516 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
517
518 pve-firewall (2.0-14) unstable; urgency=medium
519
520 * fix systemd service dependencies
521
522 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
523
524 pve-firewall (2.0-13) unstable; urgency=medium
525
526 * allow numeric icmp types
527
528 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
529
530 pve-firewall (2.0-12) unstable; urgency=medium
531
532 * implement bash completions
533
534 * convert pve-firewall into a PVE::Service class
535
536 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
537
538 pve-firewall (2.0-11) unstable; urgency=medium
539
540 * iptables_get_chains: fix veth device name
541
542 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
543
544 pve-firewall (2.0-10) unstable; urgency=medium
545
546 * new helper: clone_vmfw_conf()
547
548 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
549
550 pve-firewall (2.0-9) unstable; urgency=medium
551
552 * remove firewall config file subroutine added
553
554 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
555
556 pve-firewall (2.0-8) unstable; urgency=medium
557
558 * adopt regresion tests for lxc containers
559
560 * removed firewall code for openVZ
561
562 * Subroutine verify_rule fixed to correctly check only for "net\d+"
563 interface device names
564
565 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
566
567 pve-firewall (2.0-7) unstable; urgency=medium
568
569 * added firewall code for lxc
570
571 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
572
573 pve-firewall (2.0-6) unstable; urgency=medium
574
575 * firewall ipversion comparison fix
576
577 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
578
579 pve-firewall (2.0-5) unstable; urgency=medium
580
581 * add ipv6 neighbor discovery and solicitation macros
582
583 * ip6tables accepts both spellings of the word neighbor
584
585 * added Ceph macro
586
587 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
588
589 pve-firewall (2.0-4) unstable; urgency=medium
590
591 * include manual page for pve-firewall
592
593 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
594
595 pve-firewall (2.0-3) unstable; urgency=medium
596
597 * use noawait trigers for pve-api-updates
598
599 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
600
601 pve-firewall (2.0-2) unstable; urgency=medium
602
603 * trigger pve-api-updates event
604
605 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
606
607 pve-firewall (2.0-1) unstable; urgency=medium
608
609 * recompile for debian jessie
610
611 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
612
613 pve-firewall (1.0-18) unstable; urgency=low
614
615 * fix alias lookup
616
617 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
618
619 pve-firewall (1.0-17) unstable; urgency=low
620
621 * fix restart behavior
622
623 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
624
625 pve-firewall (1.0-16) unstable; urgency=low
626
627 * use new Daemon class from pve-common
628
629 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
630
631 pve-firewall (1.0-15) unstable; urgency=low
632
633 * bug fix: load cluster conf for host rules
634
635 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
636
637 pve-firewall (1.0-14) unstable; urgency=low
638
639 * do not use ipset list chains
640
641 * remove preinst script (not needed anymore)
642
643 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
644
645 pve-firewall (1.0-13) unstable; urgency=low
646
647 * fix ipset remove order
648
649 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
650
651 pve-firewall (1.0-12) unstable; urgency=low
652
653 * add preinst script to clear ipset from older installation (because
654 sets cannot be swapped if there type does not match.
655
656 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
657
658 pve-firewall (1.0-11) unstable; urgency=low
659
660 * bug fix: correctly set ipversion for aliases in verify_rule
661
662 * save restore commands into files to make debugging
663 easier (/var/lib/pve-firewall/)
664
665 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
666
667 pve-firewall (1.0-10) unstable; urgency=low
668
669 * add IPv6 support for VMs (hostfw is IPv4 only)
670
671 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
672
673 pve-firewall (1.0-9) unstable; urgency=low
674
675 * fix max ipset name name length
676
677 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
678
679 pve-firewall (1.0-8) unstable; urgency=low
680
681 * implement permission
682
683 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
684
685 pve-firewall (1.0-7) unstable; urgency=low
686
687 * proxy host rule API calls to correct node
688
689 * always generate MAC and IP filter rules if firewall is enabled on NIC
690
691 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
692
693 pve-firewall (1.0-6) unstable; urgency=low
694
695 * ipmlement ipfilter ipsets
696
697 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
698
699 pve-firewall (1.0-5) unstable; urgency=low
700
701 * remove ipsets when firewall disabled
702
703 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
704
705 pve-firewall (1.0-4) unstable; urgency=low
706
707 * depend on iptables and ipset
708
709 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
710
711 pve-firewall (1.0-3) unstable; urgency=low
712
713 * change dh_installinit order (register pvefw-logger before pve-firewall)
714
715 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
716
717 pve-firewall (1.0-2) unstable; urgency=low
718
719 * add experimental nflog logging daemon
720
721 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
722
723 pve-firewall (1.0-1) unstable; urgency=low
724
725 * initial package
726
727 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
728