]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
bump version to 5.0.0
[pve-firewall.git] / debian / changelog
1 pve-firewall (5.0.0) bookworm; urgency=medium
2
3 * switch to native versioning scheme
4
5 * build for Proxmox VE 8 / Debian 12 Bookworm
6
7 -- Proxmox Support Team <support@proxmox.com> Mon, 22 May 2023 14:43:58 +0200
8
9 pve-firewall (4.3-2) bullseye; urgency=medium
10
11 * fix variables declared in conditional statement
12
13 * fix #4730: add safeguards to prevent ICMP type misuse
14
15 -- Proxmox Support Team <support@proxmox.com> Tue, 16 May 2023 11:17:58 +0200
16
17 pve-firewall (4.3-1) bullseye; urgency=medium
18
19 * allow entering IP address with the host bits (those inside the mask) not
20 being all zero non-zero, like 192.168.1.155/24 for example.
21
22 * api: firewall logger: add optional parameters `since` and `until` for
23 time-range filtering
24
25 * fix #4550: host options: add nf_conntrack_helpers to compensate that
26 kernel 6.1 and newer have removed the auto helpers
27
28 -- Proxmox Support Team <support@proxmox.com> Fri, 17 Mar 2023 15:24:56 +0100
29
30 pve-firewall (4.2-7) bullseye; urgency=medium
31
32 * fix #4018: add firewall macro for SPICE proxy
33
34 * fix #4204: automatically update each usage of a group to the new ID when
35 it is renamed
36
37 * fix #4268: add 'force' parameter to delete IPSet with members
38
39 -- Proxmox Support Team <support@proxmox.com> Thu, 17 Nov 2022 19:53:04 +0100
40
41 pve-firewall (4.2-6) bullseye; urgency=medium
42
43 * config defaults: document that the mac filter defaults to on
44
45 * fix #4175: ignore non-filter ebtables tables
46
47 * fix enabling ebtables if VM firewall config is invalid
48
49 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Aug 2022 09:43:53 +0200
50
51 pve-firewall (4.2-5) bullseye; urgency=medium
52
53 * fix #3677 ipset get chains: handle newer ipset output for actual
54 change detection
55
56 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Nov 2021 16:37:13 +0100
57
58 pve-firewall (4.2-4) bullseye; urgency=medium
59
60 * re-build to avoid issues stemming from semi-broken systemd-debhelper version
61
62 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Oct 2021 10:39:05 +0200
63
64 pve-firewall (4.2-3) bullseye; urgency=medium
65
66 * fix #2721: remove the (nowadays) bogus reject for TCP port 43 from the
67 default drop and reject actions
68
69 -- Proxmox Support Team <support@proxmox.com> Fri, 10 Sep 2021 13:00:07 +0200
70
71 pve-firewall (4.2-2) bullseye; urgency=medium
72
73 * re-set relevant sysctls on every apply round
74
75 -- Proxmox Support Team <support@proxmox.com> Mon, 21 Jun 2021 11:31:42 +0200
76
77 pve-firewall (4.2-1) bullseye; urgency=medium
78
79 * fix #967: source: dest: limit length
80
81 * re-build for Debian 11 Bullseye based releases (Proxmox VE 7)
82
83 * fix #2358: allow --<opt> in firewall rule config files
84
85 -- Proxmox Support Team <support@proxmox.com> Wed, 12 May 2021 20:32:30 +0200
86
87 pve-firewall (4.1-3) pve; urgency=medium
88
89 * fix #2773: ebtables: keep policy of custom chains
90
91 * introduce new icmp-type parameter
92
93 -- Proxmox Support Team <support@proxmox.com> Fri, 18 Sep 2020 16:51:27 +0200
94
95 pve-firewall (4.1-2) pve; urgency=medium
96
97 * revert: rules: verify referenced security group exists
98
99 -- Proxmox Support Team <support@proxmox.com> Wed, 06 May 2020 17:41:36 +0200
100
101 pve-firewall (4.1-1) pve; urgency=medium
102
103 * logging: add missing log message for inbound rules
104
105 * fix #2686: avoid adding 'arp-ip-src' IP filter if guests uses DHCP
106
107 * IPSets: parse the CIDR before checking for duplicates
108
109 * verify that a referenced security group exists
110
111 * ICMP: fix iptables-restore failing if ICMP-type values bigger than '255'
112
113 * ICMP: allow one to specify the 'echo-reply' (0) type also as integer
114
115 * improve handling concurrent (parallel) access and modifications to rules
116
117 -- Proxmox Support Team <support@proxmox.com> Mon, 04 May 2020 15:01:57 +0200
118
119 pve-firewall (4.0-10) pve; urgency=medium
120
121 * macros: add macro for Proxmox Mail Gateway web interface
122
123 * api node: always pass cluster conf to node FW parser to fix false positive
124 error message about non existing aliases, or IP sets, when querying the
125 node FW options GET API call.
126
127 * grammar fix: s/does not exists/does not exist/g
128
129 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jan 2020 19:25:49 +0100
130
131 pve-firewall (4.0-9) pve; urgency=medium
132
133 * ensure port range used for offline storage migration and insecure migration
134 traffic is allowed by default rule set.
135
136 -- Proxmox Support Team <support@proxmox.com> Tue, 03 Dec 2019 08:12:20 +0100
137
138 pve-firewall (4.0-8) pve; urgency=medium
139
140 * increase default nf_conntrack_max to the kernel's default
141
142 * fix some "use of uninitialized value" warnings when updating CIDRs
143
144 * update schema documentation
145
146 * add explicit dependency on libpve-cluster-perl
147
148 * add support for "raw" tables
149
150 * add options for synflood protection for host firewall:
151 - nf_conntrack_tcp_timeout_syn_recv
152 - protection_synflood: boolean
153 - protection_synflood_rate: SYN rate limit (default 200 per second)
154 - protection_synflood_burst: SYN burst limit (default 1000)
155
156 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2019 13:48:20 +0100
157
158 pve-firewall (4.0-7) pve; urgency=medium
159
160 * only add VM chains and rules if VM firewall is enabled
161
162 -- Proxmox Support Team <support@proxmox.com> Wed, 7 Aug 2019 10:55:06 +0200
163
164 pve-firewall (4.0-6) pve; urgency=medium
165
166 * firewall macros: add new Ceph protocol v2 port while keeping v1 port
167
168 -- Proxmox Support Team <support@proxmox.com> Tue, 23 Jul 2019 18:57:48 +0200
169
170 pve-firewall (4.0-5) pve; urgency=medium
171
172 * don't use any base path at all for calls to external binaries to make use
173 compativle with bot, /usr merged and unmerged setups
174
175 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Jul 2019 11:47:53 +0200
176
177 pve-firewall (4.0-4) pve; urgency=medium
178
179 * ebtables: remove PVE chains properly
180
181 * ebtables: treat chain deletion as change
182
183 * use /usr/sbin as base path
184
185 -- Proxmox Support Team <support@proxmox.com> Thu, 11 Jul 2019 19:40:01 +0200
186
187 pve-firewall (4.0-3) pve; urgency=medium
188
189 * Create corosync firewall rules independently of localnet~
190
191 * Display corosync rule info on localnet call
192
193 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
194
195 pve-firewall (4.0-2) pve; urgency=medium
196
197 * fix systemd warning about PIDFile directory
198
199 * fix CT rule generation with ipfilter set
200
201 * pve-firewall service: update-alternative iptables and ebtables to working
202 legacy versions
203
204 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
205
206 pve-firewall (4.0-1) pve; urgency=medium
207
208 * re-build for Debian Buster / PVE 6
209
210 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
211
212 pve-firewall (3.0-21) unstable; urgency=medium
213
214 * fix ipv6 PVEFW-reject
215
216 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
217 ebtables doing the wrong thing here
218
219 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
220
221 pve-firewall (3.0-20) unstable; urgency=medium
222
223 * use IPCC to read config and rule files, if the are backed by pmxcfs which
224 has better handling for pmxcfs restarts
225
226 * fix #2178: endless loop on ipv6 extension headers
227
228 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
229
230 pve-firewall (3.0-19) unstable; urgency=medium
231
232 * ebtables: add arp filtering
233
234 * fix: #2123 Logging of user defined firewall rules
235
236 * fix Razor macro
237
238 * allow to enable/disable and modify cluster wide log ratelimits
239
240 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
241
242 pve-firewall (3.0-18) unstable; urgency=medium
243
244 * fix #1606: Add nf_conntrack_allow_invalid option
245
246 * log reject : add space after policy REJECT like drop
247
248 * fix #1891: Add zsh command completion for pve-firewall
249
250 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
251
252 pve-firewall (3.0-17) unstable; urgency=medium
253
254 * fix #2005: only allow ascii port digits
255
256 * fix #2004: do not allow backwards ranges
257
258 * add conntrack logging via libnetfilter_conntrack and allow one to enable
259 it through the firewall host configuration
260
261 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
262
263 pve-firewall (3.0-16) unstable; urgency=medium
264
265 * api/rules: fix macro return type
266
267 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
268
269 pve-firewall (3.0-15) unstable; urgency=medium
270
271 * fix #1971: display firewall rule properties
272
273 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
274
275 pve-firewall (3.0-14) unstable; urgency=medium
276
277 * fix #1841: avoid ebtable reloads when containers have multiple network
278 interfaces
279
280 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
281
282 pve-firewall (3.0-13) unstable; urgency=medium
283
284 * avoid unnecessary reloads of ebtable ruleset
285
286 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
287
288 pve-firewall (3.0-12) unstable; urgency=medium
289
290 * fix deleted iptables chains not being properly detected as a change
291
292 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
293
294 pve-firewall (3.0-11) unstable; urgency=medium
295
296 * #1764: rename 'ebtales_enable' option to 'ebtables'
297
298 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
299
300 pve-firewall (3.0-10) unstable; urgency=medium
301
302 * fix #1764: handle existing ebtables rules and allow disabling ebtables
303
304 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
305 ebtables_enable option.
306
307 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
308
309 pve-firewall (3.0-9) unstable; urgency=medium
310
311 * fix creation of ebltables FORWARD rule entry
312
313 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
314
315 pve-firewall (3.0-8) unstable; urgency=medium
316
317 * add ebtables support for better MAC filtering
318
319 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
320
321 pve-firewall (3.0-7) unstable; urgency=medium
322
323 * support distinct source and destination multi-port matching
324
325 * multi-port matching: when specifying the same list of ports for source and
326 destination require them both to match, rather than one of them, as this
327 was rather unexpected behavior
328
329 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
330
331 pve-firewall (3.0-6) unstable; urgency=medium
332
333 * fix #1319: don't fail postinst with masked service
334
335 * debian: switch to compat 9, drop init scripts, drop preinst
336
337 * check multiport limit in port ranges
338
339 * build: use git rev-parse for GITVERSION
340
341 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
342
343 pve-firewall (3.0-5) unstable; urgency=medium
344
345 * fix issue with disabled flag not being honored within groups
346
347 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
348
349 pve-firewall (3.0-4) unstable; urgency=medium
350
351 * fix issues with ipsets reloading unnecessarily or too late
352
353 * fix some typos in the logs
354
355 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
356
357 pve-firewall (3.0-3) unstable; urgency=medium
358
359 * Fix #1492: logger: use current timestamp if the packet doesn't have one
360
361 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
362
363 pve-firewall (3.0-2) unstable; urgency=medium
364
365 * Fix #1446: remove masks in case the package had previously been removed but
366 not purged.
367
368 * improve logging on errors in the firewall configuration
369
370 * forbid trailing commas in lists as iptables-restore doesn't support them
371
372 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
373
374 pve-firewall (3.0-1) unstable; urgency=medium
375
376 * rebuild for Debian Stretch
377
378 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
379
380 pve-firewall (2.0-33) unstable; urgency=medium
381
382 * ipset: don't allow zero-prefix entries
383
384 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
385
386 pve-firewall (2.0-32) unstable; urgency=medium
387
388 * improve search for local-network
389
390 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
391
392 pve-firewall (2.0-31) unstable; urgency=medium
393
394 * don't try to apply ports to rules which don't support them
395
396 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
397
398 pve-firewall (2.0-30) unstable; urgency=medium
399
400 * add multicast DNS to the list of Macros
401
402 * add missing parameter descriptions
403
404 * build-depends: add dh-systemd
405
406 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
407
408 pve-firewall (2.0-29) unstable; urgency=medium
409
410 * prevent overwriting ipsets/sec. groups by renaming
411
412 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
413
414 pve-firewall (2.0-28) unstable; urgency=medium
415
416 * use pve-common's ipv4_mask_hash_localnet
417
418 * fix allowed group name length
419
420 * make group digest stable
421
422 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
423
424 pve-firewall (2.0-27) unstable; urgency=medium
425
426 * fix #972: make PVEFW-FWBR-* rule order stable
427
428 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
429
430 pve-firewall (2.0-26) unstable; urgency=medium
431
432 * fix #988: set rp_filter=2
433
434 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
435
436 pve-firewall (2.0-25) unstable; urgency=medium
437
438 * fix #945: add uninitialized check in lxc ipset compilation
439
440 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
441
442 pve-firewall (2.0-24) unstable; urgency=medium
443
444 * Build-Depend on pve-doc-generator
445
446 * generate manpage with pve-doc-generator
447
448 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
449
450 pve-firewall (2.0-23) unstable; urgency=medium
451
452 * use only the top bit for our accept marks
453
454 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
455
456 pve-firewall (2.0-22) unstable; urgency=medium
457
458 * Use cfs_config_path from PVE::QemuConfig
459
460 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
461
462 pve-firewall (2.0-21) unstable; urgency=medium
463
464 * added new 'ipfilter' option
465
466 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
467
468 pve-firewall (2.0-20) unstable; urgency=medium
469
470 * fix 901: encode unicode characters in sha digest
471
472 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
473
474 pve-firewall (2.0-19) unstable; urgency=medium
475
476 * Add radv option to VM options
477
478 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
479
480 pve-firewall (2.0-18) unstable; urgency=medium
481
482 * Add ndp option to host and VM firewall options
483
484 * Add router-solicitation to NeighborDiscovery macro
485
486 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
487
488 pve-firewall (2.0-17) unstable; urgency=medium
489
490 * Don't leave empty FW config files behind
491
492 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
493
494 pve-firewall (2.0-16) unstable; urgency=medium
495
496 * logger: basic ipv6 support
497
498 * add DHCPv6 macro
499
500 * add dhcpv6 support to the dhcp option
501
502 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
503
504 pve-firewall (2.0-15) unstable; urgency=medium
505
506 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
507
508 * fix some regular expressions mixups
509
510 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
511
512 pve-firewall (2.0-14) unstable; urgency=medium
513
514 * fix systemd service dependencies
515
516 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
517
518 pve-firewall (2.0-13) unstable; urgency=medium
519
520 * allow numeric icmp types
521
522 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
523
524 pve-firewall (2.0-12) unstable; urgency=medium
525
526 * implement bash completions
527
528 * convert pve-firewall into a PVE::Service class
529
530 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
531
532 pve-firewall (2.0-11) unstable; urgency=medium
533
534 * iptables_get_chains: fix veth device name
535
536 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
537
538 pve-firewall (2.0-10) unstable; urgency=medium
539
540 * new helper: clone_vmfw_conf()
541
542 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
543
544 pve-firewall (2.0-9) unstable; urgency=medium
545
546 * remove firewall config file subroutine added
547
548 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
549
550 pve-firewall (2.0-8) unstable; urgency=medium
551
552 * adopt regresion tests for lxc containers
553
554 * removed firewall code for openVZ
555
556 * Subroutine verify_rule fixed to correctly check only for "net\d+"
557 interface device names
558
559 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
560
561 pve-firewall (2.0-7) unstable; urgency=medium
562
563 * added firewall code for lxc
564
565 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
566
567 pve-firewall (2.0-6) unstable; urgency=medium
568
569 * firewall ipversion comparison fix
570
571 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
572
573 pve-firewall (2.0-5) unstable; urgency=medium
574
575 * add ipv6 neighbor discovery and solicitation macros
576
577 * ip6tables accepts both spellings of the word neighbor
578
579 * added Ceph macro
580
581 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
582
583 pve-firewall (2.0-4) unstable; urgency=medium
584
585 * include manual page for pve-firewall
586
587 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
588
589 pve-firewall (2.0-3) unstable; urgency=medium
590
591 * use noawait trigers for pve-api-updates
592
593 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
594
595 pve-firewall (2.0-2) unstable; urgency=medium
596
597 * trigger pve-api-updates event
598
599 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
600
601 pve-firewall (2.0-1) unstable; urgency=medium
602
603 * recompile for debian jessie
604
605 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
606
607 pve-firewall (1.0-18) unstable; urgency=low
608
609 * fix alias lookup
610
611 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
612
613 pve-firewall (1.0-17) unstable; urgency=low
614
615 * fix restart behavior
616
617 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
618
619 pve-firewall (1.0-16) unstable; urgency=low
620
621 * use new Daemon class from pve-common
622
623 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
624
625 pve-firewall (1.0-15) unstable; urgency=low
626
627 * bug fix: load cluster conf for host rules
628
629 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
630
631 pve-firewall (1.0-14) unstable; urgency=low
632
633 * do not use ipset list chains
634
635 * remove preinst script (not needed anymore)
636
637 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
638
639 pve-firewall (1.0-13) unstable; urgency=low
640
641 * fix ipset remove order
642
643 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
644
645 pve-firewall (1.0-12) unstable; urgency=low
646
647 * add preinst script to clear ipset from older installation (because
648 sets cannot be swapped if there type does not match.
649
650 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
651
652 pve-firewall (1.0-11) unstable; urgency=low
653
654 * bug fix: correctly set ipversion for aliases in verify_rule
655
656 * save restore commands into files to make debugging
657 easier (/var/lib/pve-firewall/)
658
659 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
660
661 pve-firewall (1.0-10) unstable; urgency=low
662
663 * add IPv6 support for VMs (hostfw is IPv4 only)
664
665 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
666
667 pve-firewall (1.0-9) unstable; urgency=low
668
669 * fix max ipset name name length
670
671 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
672
673 pve-firewall (1.0-8) unstable; urgency=low
674
675 * implement permission
676
677 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
678
679 pve-firewall (1.0-7) unstable; urgency=low
680
681 * proxy host rule API calls to correct node
682
683 * always generate MAC and IP filter rules if firewall is enabled on NIC
684
685 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
686
687 pve-firewall (1.0-6) unstable; urgency=low
688
689 * ipmlement ipfilter ipsets
690
691 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
692
693 pve-firewall (1.0-5) unstable; urgency=low
694
695 * remove ipsets when firewall disabled
696
697 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
698
699 pve-firewall (1.0-4) unstable; urgency=low
700
701 * depend on iptables and ipset
702
703 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
704
705 pve-firewall (1.0-3) unstable; urgency=low
706
707 * change dh_installinit order (register pvefw-logger before pve-firewall)
708
709 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
710
711 pve-firewall (1.0-2) unstable; urgency=low
712
713 * add experimental nflog logging daemon
714
715 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
716
717 pve-firewall (1.0-1) unstable; urgency=low
718
719 * initial package
720
721 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
722