diff --git a/changelogs/fragments/cliconf.yml b/changelogs/fragments/cliconf.yml new file mode 100644 index 00000000..53c26ada --- /dev/null +++ b/changelogs/fragments/cliconf.yml @@ -0,0 +1,4 @@ +--- + +minor_changes: + - added `network_os_major_version` to facts diff --git a/changelogs/fragments/firewall_global_14.yml b/changelogs/fragments/firewall_global_14.yml new file mode 100644 index 00000000..269c3e5a --- /dev/null +++ b/changelogs/fragments/firewall_global_14.yml @@ -0,0 +1,7 @@ +--- +minor_changes: + - with 1.4+, use the the global keyword to define global firewall rules + - Fixed ipv6 route-redirects and tests + - Added support for input, output, and forward chains (1.4+) + - Fixed state-policy deletion (partial and full) + - Added support for log-level in state-policy (1.4+) diff --git a/changelogs/fragments/firewall_rules.yml b/changelogs/fragments/firewall_rules.yml new file mode 100644 index 00000000..7cd02a24 --- /dev/null +++ b/changelogs/fragments/firewall_rules.yml @@ -0,0 +1,8 @@ +--- +breaking_changes: + - firewall_rules - tcp.flags is now a list with an inversion flag to support 1.4+ firewall rules, but still supports 1.3- + +minor_changes: + - firewall_rules - Added support for 1.4+ firewall rules + - fix tests for 1.4+ firewall rules (ICMP V6 code and type) + - added support for 1.5+ firewall `match-ipsec-in`, `match-ipsec-out`, `match-none-in`, `match-none-out` diff --git a/changelogs/fragments/interfaces_update.yml b/changelogs/fragments/interfaces_update.yml new file mode 100644 index 00000000..e9a6d21b --- /dev/null +++ b/changelogs/fragments/interfaces_update.yml @@ -0,0 +1,9 @@ +--- +minor_changes: + - fixed bug where 'replace' would delete an active disable and not reinstate it + - make l3_interfaces pick up loopback interfaces + - added tests for verifying both of these + - fixed over-zealous handling of disable, which could catch other interface + items that are disabled. + - enable support for 1.4 firewall + - support for 1.4 ospf diff --git a/changelogs/fragments/tests.yml b/changelogs/fragments/tests.yml new file mode 100644 index 00000000..78e3d597 --- /dev/null +++ b/changelogs/fragments/tests.yml @@ -0,0 +1,3 @@ +--- +trivial: + - ignore 2.19 sanity tests for now diff --git a/docs/vyos.vyos.vyos_firewall_global_module.rst b/docs/vyos.vyos.vyos_firewall_global_module.rst index 34293b1b..a77ce80f 100644 --- a/docs/vyos.vyos.vyos_firewall_global_module.rst +++ b/docs/vyos.vyos.vyos_firewall_global_module.rst @@ -1,1794 +1,1796 @@ .. _vyos.vyos.vyos_firewall_global_module: ****************************** vyos.vyos.vyos_firewall_global ****************************** **FIREWALL global resource module** Version added: 1.0.0 .. contents:: :local: :depth: 1 Synopsis -------- - This module manage global policies or configurations for firewall on VyOS devices. Parameters ---------- .. raw:: html