LINUXOR.SK ... open source notes ...

Email - ifcfg-eth1, relay servers

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Relay servers

noteThe file of the second relay carries an IPv6 address that belongs to the first relay's other interface. See the table below before copying anything.

The second network interface of a relay server: its address in the relay VLAN 1172, with the default gateway. This is the address the firewall translates to a public one.

ItemValue
Path on the server/etc/sysconfig/network-scripts/ifcfg-eth1
Shown hereDC2-A-VCMSR001; the address has its own DNS name, dc2-a-vcmsn001.adm.example.net
Also onDC2-B-VCMSR001, with the differences below
Placeholder<ETH1_HWADDR> stands for the hardware address; the UUID line is empty in the archive
Activated withthe network service; the first line says the file came from Ansible

The file

bash
## Ansible managed
# Interface
DEVICE="eth1"
NAME="eth1"
TYPE="Ethernet"
BOOTPROTO="none"
ONBOOT="yes"
UUID=""
HWADDR="<ETH1_HWADDR>"
NM_CONTROLLED="no"

# IPv4
IPADDR="10.12.19.65"
NETMASK="255.255.255.240"
GATEWAY="10.12.19.78"
DEFROUTE="yes"
IPV4_FAILURE_FATAL="no"

# IPv6
IPV6ADDR="2001:db8:a2:b6b::f:1/64"
IPV6_DEFAULTGW="2001:db8:a2:b6b::1"
IPV6INIT="yes"
IPV6_AUTOCONF="no"
IPV6_DEFROUTE="yes"
IPV6_FAILURE_FATAL="no"
IPV6_ADDR_GEN_MODE="stable-privacy"
IPV6_PRIVACY="no"

Differences on the second relay

The result of diff between the two archived files.

HostLineValue
DC2-A-VCMSR001first line## Ansible managed
DC2-B-VCMSR001first linenot present
DC2-A-VCMSR001HWADDRpresent
DC2-B-VCMSR001HWADDRnot present
DC2-A-VCMSR001IPADDR10.12.19.65
DC2-B-VCMSR001IPADDR10.12.19.66
DC2-A-VCMSR001IPV6ADDR2001:db8:a2:b6b::f:1/64
DC2-B-VCMSR001IPV6ADDR2001:db8:a2:b6f::f:2/64
DC2-A-VCMSR001IPV6_DEFROUTEyes
DC2-B-VCMSR001IPV6_DEFROUTEno
DC2-B-VCMSR001ZONEpublic, only on this host

GATEWAY is 10.12.19.78 on both, at a different place in the file. The IPv6 address on the second relay is wrong twice: it is from the prefix of the internal VLAN (b6f) on an interface in the relay VLAN (b6b), and it is the very address of eth0 of the first relay. The design gives this interface 2001:db8:a2:b6b::f:2. Both interface files of the second relay have IPV6_DEFROUTE="no", and both set an IPV6_DEFAULTGW: 2001:db8:a2:b6f::1 on eth0 and 2001:db8:a2:b6b::1 on eth1. Which IPv6 default route that produced under the classic network scripts is not recorded in the Source material. The design states that the solution is based on IPv4, which is probably why nobody noticed.

Checked against RHEL 10.2

As builtToday
ifcfg-* files read by the network service, NM_CONTROLLED="no"The legacy network scripts were deprecated in RHEL 8; RHEL 9 does not contain the network-scripts package; in RHEL 10 support for the ifcfg format was removed
One file per interface under /etc/sysconfig/network-scriptsNetworkManager keyfiles under /etc/NetworkManager/system-connections/; on RHEL 9 nmcli connection migrate converts ifcfg profiles to keyfiles
route-eth0 with <prefix> via <gateway> linesStatic routes are properties of the connection, set for IPv4 with nmcli connection modify <connection> +ipv4.routes "<prefix> <gateway>"

Red Hat's advice today is not to write these profiles by hand at all, but to use nmcli, the network system role or the nmstate API. RHEL 7 itself left maintenance on 2024-06-30.

← solutionz