Component: firewall
248 changelog entries across 110 version(s)
Releases by channel (stacked)
- improved system stability;
- improved system stability;
- improved system stability (additional fixes);
- improved system stability;
- improved stability for SIP helper;
- added "h" flag indicating that firewall service helper is applied for particular connection;
- added support for TOS/mask matching for raw rules;
- clear relevant masqueraded connection tracking entries on IP address change;
- fixed "tls-host" not matching expected hosts;
- fixed hotspot value loss on rule enable/disable;
- fixed strip-ipv4-options always passthrough;
- hide hw-offload setting from devices that do not support it;
- improved system stability and memory allocation when using firewall services;
- make hw-offload=yes default setting in /ip/firewall/filter menu;
- use the highest TTL as timeout value for domain address list entries if multiple domain names resolve to same IP;
- clear relevant masqueraded connection tracking entries on IP address change;
- clear relevant masqueraded connection tracking entries on IP address change;
- clear relevant masqueraded connection tracking entries on WAN address change;
- added support for TOS/mask matching for raw rules (additional fixes);
- fixed "tls-host" not matching expected hosts;
- reduce maximum connection tracking entry count;
- reduce maximum connection tracking entry count;
- use the highest TTL as timeout value for domain address list entries if multiple domain names resolve to same IP (additional fixes);
- added "h" flag indicating that firewall service helper is applied for particular connection;
- added support for TOS/mask matching for raw rules;
- fixed hotspot value loss on rule enable/disable;
- fixed strip-ipv4-options always passthrough;
- hide hw-offload setting from devices that do not support it;
- improved system stability and memory allocation when using firewall services;
- make hw-offload=yes default setting in /ip/firewall/filter menu;
- use the highest TTL as timeout value for domain address list entries if multiple domain names resolve to same IP;
- added "liberal-tcp-tracking" connection tracking setting;
- added connection tracking "total-ip4-entries" and "total-ip6-entries" counters;
- allow "dst-limit" matcher to work properly above value 10000;
- fixed IPv6 firewall interface matchers not matching VRF interfaces;
- improved IPv6 connection tracking lookup responsiveness;
- improved system stability when processing connections on multicore systems;
- reorganized firewall connection tracking table values and make them persistent between IPv4 and IPv6;
- reorganized firewall connection tracking table values and make them persistent between IPv4 and IPv6 (additional fixes);
- fixed IPv6 firewall interface matchers not matching VRF interfaces;
- added "liberal-tcp-tracking" connection tracking setting;
- added connection tracking "total-ip4-entries" and "total-ip6-entries" counters;
- allow "dst-limit" matcher to work properly above value 10000;
- improved IPv6 connection tracking lookup responsiveness;
- improved system stability when processing connections on multicore systems;
- reorganized firewall connection tracking table values and make them persistent between IPv4 and IPv6;
- always show "passthrough" when exporting mangle table;
- detect VRF addresses as local;
- fixed IP/Settings "ipv4-fasttrack-active" status showing as inactive when it is active;
- fixed IP/Settings "ipv4-fasttrack-active" status showing as inactive when it is active;
- always show "passthrough" when exporting mangle table;
- detect VRF addresses as local;
- allow in-interface/in-bridge-port/in-bridge matching in postrouting chains;
- fixed incorrectly inverted hotspot value configuration;
- increased maximum connection tracking entry count based on device total RAM size;
- allow in-interface/in-bridge-port/in-bridge matching in postrouting chains;
- fixed incorrectly inverted hotspot value configuration;
- increased maximum connection tracking entry count based on device total RAM size;