Email - ifcfg-eth1, relay servers
Email Solution · Config document · referenced from Relay servers
The second network interface of a relay server: its address in the relay VLAN 1172, with the default gateway. This is the address the firewall translates to a public one.
| Item | Value |
|---|---|
| Path on the server | /etc/sysconfig/network-scripts/ifcfg-eth1 |
| Shown here | DC2-A-VCMSR001; the address has its own DNS name, dc2-a-vcmsn001.adm.example.net |
| Also on | DC2-B-VCMSR001, with the differences below |
| Placeholder | <ETH1_HWADDR> stands for the hardware address; the UUID line is empty in the archive |
| Activated with | the network service; the first line says the file came from Ansible |
The file
## Ansible managed # Interface DEVICE="eth1" NAME="eth1" TYPE="Ethernet" BOOTPROTO="none" ONBOOT="yes" UUID="" HWADDR="<ETH1_HWADDR>" NM_CONTROLLED="no" # IPv4 IPADDR="10.12.19.65" NETMASK="255.255.255.240" GATEWAY="10.12.19.78" DEFROUTE="yes" IPV4_FAILURE_FATAL="no" # IPv6 IPV6ADDR="2001:db8:a2:b6b::f:1/64" IPV6_DEFAULTGW="2001:db8:a2:b6b::1" IPV6INIT="yes" IPV6_AUTOCONF="no" IPV6_DEFROUTE="yes" IPV6_FAILURE_FATAL="no" IPV6_ADDR_GEN_MODE="stable-privacy" IPV6_PRIVACY="no"
Differences on the second relay
The result of diff between the two archived files.
| Host | Line | Value |
|---|---|---|
DC2-A-VCMSR001 | first line | ## Ansible managed |
DC2-B-VCMSR001 | first line | not present |
DC2-A-VCMSR001 | HWADDR | present |
DC2-B-VCMSR001 | HWADDR | not present |
DC2-A-VCMSR001 | IPADDR | 10.12.19.65 |
DC2-B-VCMSR001 | IPADDR | 10.12.19.66 |
DC2-A-VCMSR001 | IPV6ADDR | 2001:db8:a2:b6b::f:1/64 |
DC2-B-VCMSR001 | IPV6ADDR | 2001:db8:a2:b6f::f:2/64 |
DC2-A-VCMSR001 | IPV6_DEFROUTE | yes |
DC2-B-VCMSR001 | IPV6_DEFROUTE | no |
DC2-B-VCMSR001 | ZONE | public, only on this host |
GATEWAY is 10.12.19.78 on both, at a different place in the file. The IPv6 address on the second relay is wrong twice: it is from the prefix of the internal VLAN (b6f) on an interface in the relay VLAN (b6b), and it is the very address of eth0 of the first relay. The design gives this interface 2001:db8:a2:b6b::f:2. Both interface files of the second relay have IPV6_DEFROUTE="no", and both set an IPV6_DEFAULTGW: 2001:db8:a2:b6f::1 on eth0 and 2001:db8:a2:b6b::1 on eth1. Which IPv6 default route that produced under the classic network scripts is not recorded in the Source material. The design states that the solution is based on IPv4, which is probably why nobody noticed.
Checked against RHEL 10.2
| As built | Today |
|---|---|
ifcfg-* files read by the network service, NM_CONTROLLED="no" | The legacy network scripts were deprecated in RHEL 8; RHEL 9 does not contain the network-scripts package; in RHEL 10 support for the ifcfg format was removed |
One file per interface under /etc/sysconfig/network-scripts | NetworkManager keyfiles under /etc/NetworkManager/system-connections/; on RHEL 9 nmcli connection migrate converts ifcfg profiles to keyfiles |
route-eth0 with <prefix> via <gateway> lines | Static routes are properties of the connection, set for IPv4 with nmcli connection modify <connection> +ipv4.routes "<prefix> <gateway>" |
Red Hat's advice today is not to write these profiles by hand at all, but to use nmcli, the network system role or the nmstate API. RHEL 7 itself left maintenance on 2024-06-30.