1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
|
vyatta-conntrack (0.45) unstable; urgency=low
* check protocol timers are configured on commit: bug 8216
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Wed, 25 Jul 2012 17:10:40 -0700
vyatta-conntrack (0.44) unstable; urgency=low
* fix bug 8165
* 0.42
* 0.43
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Wed, 20 Jun 2012 19:37:47 -0700
vyatta-conntrack (0.43) unstable; urgency=low
* fix bug 8165
* 0.42
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Wed, 20 Jun 2012 16:18:58 -0700
vyatta-conntrack (0.42) unstable; urgency=low
* fix bug 8165
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Wed, 20 Jun 2012 16:18:28 -0700
vyatta-conntrack (0.41) unstable; urgency=low
* fix 8112
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Mon, 18 Jun 2012 15:25:39 -0700
vyatta-conntrack (0.40) unstable; urgency=low
* 0.39
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Thu, 14 Jun 2012 11:22:28 -0700
vyatta-conntrack (0.39) unstable; urgency=low
* remove unwanted functions
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Thu, 14 Jun 2012 11:19:41 -0700
vyatta-conntrack (0.38) unstable; urgency=low
* re-factored deletion code, disabling module scripts fixed
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Thu, 07 Jun 2012 23:20:41 -0700
vyatta-conntrack (0.37) unstable; urgency=low
[ Gaurav ]
* initial CLI for NFS and SQLnet modules
[ Gaurav Sinha ]
* CLI to add nfs/SQLnet module helpers
* ensure single reload of conntrackd daemon
* fix help strings
* remove SQLnet
* change default behavior, added vyatta-cthelper.pl
* add vyatta-cthelper.pl, disable nodes, add/remove functions for
chain
* delete enable config node
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Wed, 06 Jun 2012 21:03:37 -0700
vyatta-conntrack (0.36) unstable; urgency=low
* Fix nfct path as per new packaging due to cthelper
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Tue, 05 Jun 2012 22:05:11 -0700
vyatta-conntrack (0.35) unstable; urgency=low
* fixing 7998
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Mon, 16 Apr 2012 11:11:07 -0700
vyatta-conntrack (0.34) unstable; urgency=low
* fixing bug 7861, resolve protocol name from /etc/protocols.
-- Gaurav <gaurav.sinha@vyatta.com> Mon, 09 Apr 2012 18:07:47 -0700
vyatta-conntrack (0.33) unstable; urgency=low
* introducing CT_TIMEOUT chain with related fixes.
* 0.28+oxnard4
-- Gaurav <gaurav.sinha@vyatta.com> Fri, 23 Mar 2012 18:04:51 -0700
vyatta-conntrack (0.32) unstable; urgency=low
[ Gaurav Sinha ]
* 0.31
[ Gaurav ]
-- Gaurav <gaurav.sinha@vyatta.com> Tue, 20 Mar 2012 20:41:08 -0700
vyatta-conntrack (0.31) unstable; urgency=low
[ Gaurav Sinha ]
* Initial commit for per-flow timeout CLI
* Removed unwanted address-group/network group etc. from CLI
* adding an initial version of conntrack-timeouts script
* timeouts script, and new nodes
[ Gaurav ]
* timeout script, similar to firewall one, with a few differences.
* Adding rule and address setup/parsing libraries
* Removing newly added file AddressFilterCT.pm.
* removing AddressFilterCT.pm
* modified to use AddressFilter from IpTables
* adding various timers in custom rule template
* changing structure of hashes kept for timeouts
* Add function to create nfct-timeout policy
* Fixing templates to avoid defaults since these rules override the
global defaults
* Fixing nfct-command string:only modified timer is included in the
command
* Removed default timeouts for override udp/icmp/other, fixed minor
bugs
* Error checks for ports with other/icmp, as not allowed
* Adding deletion, error handling etc.
* adding apply/remove policy function, still dummy
* add run_cmd function with error checking
* re-factored
* handle modification, disabled error handling for now as iptables
does not support timeout target yet
* do_protocol_check function, mandates one protocol subtree per rule
max
* Updated help strings to avoid confusion with global timeouts
* check presence of protocol config subtree
* Using connection instead of flow to refer to 5 tuple in help strings
* changing nfct-timeout to nfct timeout
* use right path of the nfct executable
[ Gaurav Sinha ]
* use add instead of create, use inet, pre-pend protocol to iptables
rule
* fixed generic timeout, udp stream->replied and other->unreplied,
fixed bug with protocol string comparision
* delete nfct fixed, use only policy name, modified deletion function
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Sat, 17 Mar 2012 13:08:57 -0700
vyatta-conntrack (0.30) unstable; urgency=low
* fixing 7866
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Fri, 16 Mar 2012 15:42:47 -0700
vyatta-conntrack (0.28+oxnard1) unstable; urgency=low
* new branch
-- Deepti Kulkarni <deepti@vyatta.com> Sat, 03 Mar 2012 02:23:06 -0800
vyatta-conntrack (0.28) unstable; urgency=low
* reset epoch
* Make sure all node.def files have newline at end of file
-- Stephen Hemminger <shemminger@vyatta.com> Thu, 16 Feb 2012 08:40:17 -0800
vyatta-conntrack (0.27) unstable; urgency=low
* Force release
-- Daniil Baturin <daniil.baturin@vyatta.com> Wed, 04 Jan 2012 01:56:07 +0700
vyatta-conntrack (0.26) unstable; urgency=low
[ Stephen Hemminger ]
* Fix compiler warnings
[ Daniil Baturin ]
* Something looking like a real fix for SIP port update problem.
-- Daniil Baturin <daniil.baturin@vyatta.com> Thu, 29 Dec 2011 01:27:44 +0700
vyatta-conntrack (0.25) unstable; urgency=low
* Corrected incorrect malloc.
-- Deepti Kulkarni <deepti@vyatta.com> Wed, 21 Dec 2011 10:16:27 -0800
vyatta-conntrack (0.24) unstable; urgency=low
* Improved validation of command syntax.
-- Deepti Kulkarni <deepti@vyatta.com> Mon, 19 Dec 2011 15:04:30 -0800
vyatta-conntrack (0.23) unstable; urgency=low
* Updating references to ConntrackUtil perl module
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Fri, 16 Dec 2011 13:15:44 -0800
vyatta-conntrack (0.22) unstable; urgency=low
* Resolved merge errors from Makefile.
-- Deepti Kulkarni <deepti@vyatta.com> Fri, 16 Dec 2011 04:22:07 -0800
vyatta-conntrack (0.21) unstable; urgency=low
* Fixing broken build as a result of merge
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Thu, 15 Dec 2011 17:46:10 -0800
vyatta-conntrack (0.20) unstable; urgency=low
[ Daniil Baturin ]
* Add default value for SIP port.
* Dirty hack for SIP port option.
[ Gaurav Sinha ]
* Bug 7676: including unstaged changes for 7677
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Thu, 15 Dec 2011 17:26:32 -0800
vyatta-conntrack (0.19) unstable; urgency=low
* Fix version check on boot, doesn't depend on version string
-- Daniil Baturin <daniil.baturin@vyatta.com> Thu, 15 Dec 2011 04:16:07 +0700
vyatta-conntrack (0.18) unstable; urgency=low
* Add messages to syslog on daemon start, stop or crash.
-- Deepti Kulkarni <deepti@vyatta.com> Tue, 13 Dec 2011 14:28:35 -0800
vyatta-conntrack (0.17) unstable; urgency=low
* Bug fix 7397 - Conntrack log creation and deletion.
-- Deepti Kulkarni <deepti@vyatta.com> Tue, 13 Dec 2011 02:50:50 -0800
vyatta-conntrack (0.16) unstable; urgency=low
* Bug 7680: Fixed sentence displayed in deletion
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Mon, 12 Dec 2011 15:34:37 -0800
vyatta-conntrack (0.15) unstable; urgency=low
[ Daniil Baturin ]
* Fix year in package copyright file.
* Handle the case of missing config version on reboot properly.
[ Gaurav Sinha ]
* Bug 7677:Allow quiet mode for delete conntrack command to
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Mon, 12 Dec 2011 15:09:59 -0800
vyatta-conntrack (0.14) unstable; urgency=low
* Bug 7675:Allow any and combination of any with port in conntrack
entry show / deletion commands
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Fri, 09 Dec 2011 14:06:07 -0800
vyatta-conntrack (0.13) unstable; urgency=low
* Fix a mistype in conntrack top-level node.def (1638 instead of
16384)
* Add a case for pre-oxnard config boot to check-params-on-reboot
-- Daniil Baturin <daniil.baturin@vyatta.com> Fri, 02 Dec 2011 08:00:42 +0700
vyatta-conntrack (0.12) unstable; urgency=low
* Move check-params-on-reboot script from firewall, change paths
acordingly.
* Update automake rules to include check-params-on-reboot script.
* Get conntrack default values to sync with kernel defaults.
-- Daniil Baturin <daniil.baturin@vyatta.com> Wed, 23 Nov 2011 21:43:40 +0700
vyatta-conntrack (0.11) unstable; urgency=low
* bug 7411: IPv6 check added to show / delete
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Mon, 21 Nov 2011 15:04:09 -0800
vyatta-conntrack (0.10) unstable; urgency=low
* bug 7411: IPv6 conntrack delete code, updated formatting
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Thu, 17 Nov 2011 17:08:03 -0800
vyatta-conntrack (0.9) unstable; urgency=low
* bug ID 7411: added output format for IPv6 show command
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Thu, 17 Nov 2011 14:07:18 -0800
vyatta-conntrack (0.8) unstable; urgency=low
* bug 7411:IPv6 show command: validation added
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Wed, 16 Nov 2011 17:00:43 -0800
vyatta-conntrack (0.7) unstable; urgency=low
* bug 7411:IPv6 show command without port
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Wed, 16 Nov 2011 13:54:01 -0800
vyatta-conntrack (0.6) unstable; urgency=low
* bug 7411:Added initial code for IPv6, templates and script
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Wed, 16 Nov 2011 11:50:11 -0800
vyatta-conntrack (0.5) unstable; urgency=low
* Bug 7411: improving validations for IPv4 address / port combinations
for conntrack
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Tue, 15 Nov 2011 11:40:19 -0800
vyatta-conntrack (0.4) unstable; urgency=low
* Bug 7411: Initial commit for conntrack entry deletion / show op mode
commands
-- Gaurav Sinha <gaurav.sinha@vyatta.com> Mon, 14 Nov 2011 16:33:04 -0800
vyatta-conntrack (0.3) unstable; urgency=low
* Remove files mistakanly inherited from vyatta-cfg-system.
* Move templates t templates-cfg to let op mode templates also exist.
* Fix dependencies.
* Fix mistake in dependencies.
* Fix debian control not to break update of vyatta-cfg-firewall
* Fix automake rules to match new name of cfg templates directory.
* Move conntrack modprobe config from firewall.
-- Daniil Baturin <daniil.baturin@vyatta.com> Sat, 05 Nov 2011 06:11:05 +0700
vyatta-conntrack (0.2) unstable; urgency=low
* Force build
-- Daniil Baturin <daniil.baturin@vyatta.com> Fri, 04 Nov 2011 05:42:18 +0700
vyatta-conntrack (0.1) unstable; urgency=low
* Initial Release.
-- Daniil Baturin <daniil.baturin@vyatta.com> Thu, 3 Nov 2011 12:31:53 -0700
|