Component: firewall
248 changelog entries across 110 version(s)
Releases by channel (stacked)
- fixed bridge priority target;
- fixed DSCP priority target for IPv6 Mangle;
- fixed netmap range maximum address calculation for IPv6 NAT;
- fixed bridge priority target;
- fixed DSCP priority target for IPv6 Mangle;
- fixed netmap range maximum address calculation for IPv6 NAT;
- added "set-priority" option for IPv6 mangle firewall;
- made "dynamic" parameter settable for IPv4 address lists;
- added "set-priority" option for IPv6 mangle firewall;
- made "dynamic" parameter settable for IPv4 address lists;
- added "src/dst-address-type" parameter under "IPv6/Firewall/Mangle" menu;
- disable IRC NAT helper on upgrade;
- fixed IPv6 filtering with "in/out-interface" matcher that is in VRF;
- fixed IRC NAT helper (CVE-2022-2663);
- fixed usage of "netmap" action for IPv6 source NAT;
- fixed usage of "netmap" action for IPv6 source NAT (CLI only);
- added "src/dst-address-type" parameter under "IPv6/Firewall/Mangle" menu;
- disable IRC NAT helper on upgrade;
- fixed IPv6 filtering with "in/out-interface" matcher that is in VRF;
- fixed IRC NAT helper (CVE-2022-2663);
- added support for RTSP helper;
- added support for RTSP helper;
- fixed "in-interface-list" matcher when VRF is used;
- added support for RTSP helper;
- added "srcnat" and "dstnat" flags to IPv6/Firewall/Connection table;
- added support for IPv6/Firewall/NAT action=src-nat rules;
- fixed IPv6 NAT functionality when processing GRE traffic on TILE devices;
- fixed IPv6/Firewall/RAW functionality;
- include "connection-mark", "connection-state", and "packet-mark" when packet logging is enabled;
- properly handle interface matcher when VRF interface is specified;
- improved available port lookup for source NAT when free port range is exhausted;
- improved available port lookup for source NAT when free port range is exhausted;
- improved system stability when using address lists (introduced in v7.2rc1);
- fixed "ingress-priority" matcher;
- fixed GRE protocol packets considered invalid when PPTP helper is disabled;
- fixed "ingress-priority" matcher;
- fixed GRE protocol packets considered invalid when PPTP helper is disabled;
- fixed fragmented packet processing when only RAW firewall is configured;
- process packets by firewall when accepted by RAW with disabled connection tracking;
- fixed fragmented packet processing when only RAW firewall is configured;
- process packets by firewall when accepted by RAW with disabled connection tracking;
- process packets by firewall when accepted by RAW with disabled connection tracking;
- fixed fragmented packet processing when only RAW firewall is configured;
- fixed "tls-host" firewall feature (introduced in v6.41);
- limited maximum "address-list-timeout" value to ā35w3d13h13m56sā;
- fixed "tls-host" firewall feature (introduced v6.41);