]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
bump version to 3.0-9
[pve-firewall.git] / debian / changelog
1 pve-firewall (3.0-9) unstable; urgency=medium
2
3 * fix creation of ebltables FORWARD rule entry
4
5 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
6
7 pve-firewall (3.0-8) unstable; urgency=medium
8
9 * add ebtables support for better MAC filtering
10
11 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
12
13 pve-firewall (3.0-7) unstable; urgency=medium
14
15 * support distinct source and destination multi-port matching
16
17 * multi-port matching: when specifying the same list of ports for source and
18 destination require them both to match, rather than one of them, as this
19 was rather unexpected behavior
20
21 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
22
23 pve-firewall (3.0-6) unstable; urgency=medium
24
25 * fix #1319: don't fail postinst with masked service
26
27 * debian: switch to compat 9, drop init scripts, drop preinst
28
29 * check multiport limit in port ranges
30
31 * build: use git rev-parse for GITVERSION
32
33 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
34
35 pve-firewall (3.0-5) unstable; urgency=medium
36
37 * fix issue with disabled flag not being honored within groups
38
39 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
40
41 pve-firewall (3.0-4) unstable; urgency=medium
42
43 * fix issues with ipsets reloading unnecessarily or too late
44
45 * fix some typos in the logs
46
47 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
48
49 pve-firewall (3.0-3) unstable; urgency=medium
50
51 * Fix #1492: logger: use current timestamp if the packet doesn't have one
52
53 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
54
55 pve-firewall (3.0-2) unstable; urgency=medium
56
57 * Fix #1446: remove masks in case the package had previously been removed but
58 not purged.
59
60 * improve logging on errors in the firewall configuration
61
62 * forbid trailing commas in lists as iptables-restore doesn't support them
63
64 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
65
66 pve-firewall (3.0-1) unstable; urgency=medium
67
68 * rebuild for Debian Stretch
69
70 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
71
72 pve-firewall (2.0-33) unstable; urgency=medium
73
74 * ipset: don't allow zero-prefix entries
75
76 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
77
78 pve-firewall (2.0-32) unstable; urgency=medium
79
80 * improve search for local-network
81
82 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
83
84 pve-firewall (2.0-31) unstable; urgency=medium
85
86 * don't try to apply ports to rules which don't support them
87
88 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
89
90 pve-firewall (2.0-30) unstable; urgency=medium
91
92 * add multicast DNS to the list of Macros
93
94 * add missing parameter descriptions
95
96 * build-depends: add dh-systemd
97
98 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
99
100 pve-firewall (2.0-29) unstable; urgency=medium
101
102 * prevent overwriting ipsets/sec. groups by renaming
103
104 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
105
106 pve-firewall (2.0-28) unstable; urgency=medium
107
108 * use pve-common's ipv4_mask_hash_localnet
109
110 * fix allowed group name length
111
112 * make group digest stable
113
114 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
115
116 pve-firewall (2.0-27) unstable; urgency=medium
117
118 * fix #972: make PVEFW-FWBR-* rule order stable
119
120 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
121
122 pve-firewall (2.0-26) unstable; urgency=medium
123
124 * fix #988: set rp_filter=2
125
126 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
127
128 pve-firewall (2.0-25) unstable; urgency=medium
129
130 * fix #945: add uninitialized check in lxc ipset compilation
131
132 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
133
134 pve-firewall (2.0-24) unstable; urgency=medium
135
136 * Build-Depend on pve-doc-generator
137
138 * generate manpage with pve-doc-generator
139
140 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
141
142 pve-firewall (2.0-23) unstable; urgency=medium
143
144 * use only the top bit for our accept marks
145
146 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
147
148 pve-firewall (2.0-22) unstable; urgency=medium
149
150 * Use cfs_config_path from PVE::QemuConfig
151
152 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
153
154 pve-firewall (2.0-21) unstable; urgency=medium
155
156 * added new 'ipfilter' option
157
158 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
159
160 pve-firewall (2.0-20) unstable; urgency=medium
161
162 * fix 901: encode unicode characters in sha digest
163
164 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
165
166 pve-firewall (2.0-19) unstable; urgency=medium
167
168 * Add radv option to VM options
169
170 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
171
172 pve-firewall (2.0-18) unstable; urgency=medium
173
174 * Add ndp option to host and VM firewall options
175
176 * Add router-solicitation to NeighborDiscovery macro
177
178 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
179
180 pve-firewall (2.0-17) unstable; urgency=medium
181
182 * Don't leave empty FW config files behind
183
184 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
185
186 pve-firewall (2.0-16) unstable; urgency=medium
187
188 * logger: basic ipv6 support
189
190 * add DHCPv6 macro
191
192 * add dhcpv6 support to the dhcp option
193
194 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
195
196 pve-firewall (2.0-15) unstable; urgency=medium
197
198 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
199
200 * fix some regular expressions mixups
201
202 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
203
204 pve-firewall (2.0-14) unstable; urgency=medium
205
206 * fix systemd service dependencies
207
208 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
209
210 pve-firewall (2.0-13) unstable; urgency=medium
211
212 * allow numeric icmp types
213
214 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
215
216 pve-firewall (2.0-12) unstable; urgency=medium
217
218 * implement bash completions
219
220 * convert pve-firewall into a PVE::Service class
221
222 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
223
224 pve-firewall (2.0-11) unstable; urgency=medium
225
226 * iptables_get_chains: fix veth device name
227
228 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
229
230 pve-firewall (2.0-10) unstable; urgency=medium
231
232 * new helper: clone_vmfw_conf()
233
234 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
235
236 pve-firewall (2.0-9) unstable; urgency=medium
237
238 * remove firewall config file subroutine added
239
240 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
241
242 pve-firewall (2.0-8) unstable; urgency=medium
243
244 * adopt regresion tests for lxc containers
245
246 * removed firewall code for openVZ
247
248 * Subroutine verify_rule fixed to correctly check only for "net\d+"
249 interface device names
250
251 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
252
253 pve-firewall (2.0-7) unstable; urgency=medium
254
255 * added firewall code for lxc
256
257 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
258
259 pve-firewall (2.0-6) unstable; urgency=medium
260
261 * firewall ipversion comparison fix
262
263 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
264
265 pve-firewall (2.0-5) unstable; urgency=medium
266
267 * add ipv6 neighbor discovery and solicitation macros
268
269 * ip6tables accepts both spellings of the word neighbor
270
271 * added Ceph macro
272
273 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
274
275 pve-firewall (2.0-4) unstable; urgency=medium
276
277 * include manual page for pve-firewall
278
279 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
280
281 pve-firewall (2.0-3) unstable; urgency=medium
282
283 * use noawait trigers for pve-api-updates
284
285 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
286
287 pve-firewall (2.0-2) unstable; urgency=medium
288
289 * trigger pve-api-updates event
290
291 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
292
293 pve-firewall (2.0-1) unstable; urgency=medium
294
295 * recompile for debian jessie
296
297 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
298
299 pve-firewall (1.0-18) unstable; urgency=low
300
301 * fix alias lookup
302
303 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
304
305 pve-firewall (1.0-17) unstable; urgency=low
306
307 * fix restart behavior
308
309 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
310
311 pve-firewall (1.0-16) unstable; urgency=low
312
313 * use new Daemon class from pve-common
314
315 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
316
317 pve-firewall (1.0-15) unstable; urgency=low
318
319 * bug fix: load cluster conf for host rules
320
321 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
322
323 pve-firewall (1.0-14) unstable; urgency=low
324
325 * do not use ipset list chains
326
327 * remove preinst script (not needed anymore)
328
329 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
330
331 pve-firewall (1.0-13) unstable; urgency=low
332
333 * fix ipset remove order
334
335 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
336
337 pve-firewall (1.0-12) unstable; urgency=low
338
339 * add preinst script to clear ipset from older installation (because
340 sets cannot be swapped if there type does not match.
341
342 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
343
344 pve-firewall (1.0-11) unstable; urgency=low
345
346 * bug fix: correctly set ipversion for aliases in verify_rule
347
348 * save restore commands into files to make debugging
349 easier (/var/lib/pve-firewall/)
350
351 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
352
353 pve-firewall (1.0-10) unstable; urgency=low
354
355 * add IPv6 support for VMs (hostfw is IPv4 only)
356
357 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
358
359 pve-firewall (1.0-9) unstable; urgency=low
360
361 * fix max ipset name name length
362
363 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
364
365 pve-firewall (1.0-8) unstable; urgency=low
366
367 * implement permission
368
369 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
370
371 pve-firewall (1.0-7) unstable; urgency=low
372
373 * proxy host rule API calls to correct node
374
375 * always generate MAC and IP filter rules if firewall is enabled on NIC
376
377 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
378
379 pve-firewall (1.0-6) unstable; urgency=low
380
381 * ipmlement ipfilter ipsets
382
383 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
384
385 pve-firewall (1.0-5) unstable; urgency=low
386
387 * remove ipsets when firewall disabled
388
389 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
390
391 pve-firewall (1.0-4) unstable; urgency=low
392
393 * depend on iptables and ipset
394
395 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
396
397 pve-firewall (1.0-3) unstable; urgency=low
398
399 * change dh_installinit order (register pvefw-logger before pve-firewall)
400
401 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
402
403 pve-firewall (1.0-2) unstable; urgency=low
404
405 * add experimental nflog logging daemon
406
407 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
408
409 pve-firewall (1.0-1) unstable; urgency=low
410
411 * initial package
412
413 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
414