LINUXOR.SK ... open source notes ...

Email - route6-eth0, relay servers

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Relay servers

noteThe route to the AD segment has no gateway, and two comments name the jump servers of the wrong site. The file is shown as archived.

The static IPv6 routes of a relay server: one route per management segment the server has to reach, all through the gateway of the internal VLAN on eth0.

ItemValue
Path on the server/etc/sysconfig/network-scripts/route6-eth0
Shown hereDC2-A-VCMSR001
Also onDC2-B-VCMSR001, identical except for an empty line at the end
Gateway2001:db8:a2:b6f::1, the gateway of the internal VLAN 1168
Activated withthe network service, when eth0 comes up

The file

ini
# Route to ANSIBLE segment
2001:db8:a2:b89::/64 via 2001:db8:a2:b6f::1

# Route to AD segment
2001:db8:a2:b99::/64

# Route to InfoBLOX segment
2001:db8:a2:c0b::/64 via 2001:db8:a2:b6f::1

# Route to InfoBlox segment - section A
2001:db8:b1:c0a::/64 via 2001:db8:a2:b6f::1

# Route to InfoBlox segment - section B
2001:db8:b1:c0a::/64 via 2001:db8:a2:b6f::1

# Route to SENSU segment
2001:db8:a2:bb1::/64 via 2001:db8:a2:b6f::1

# Route to COBBLER segment
2001:db8:a2:ba5::/64 via 2001:db8:a2:b6f::1

# Route to PROXY segment
2001:db8:a2:b96::/64 via 2001:db8:a2:b6f::1

# Route to Jump server segment (DC1-A-VCJMP001)
2001:db8:a2:ba3::/64 via 2001:db8:a2:b6f::1

#Route to Jump server segment (DC2-A-VCJMP001)
2001:db8:a1:ba3::/64 via 2001:db8:a2:b6f::1

# Route to RabbitMQ segment
2001:db8:a2:baf::/64 via 2001:db8:a2:b6f::1

# Route to Graphite segment
2001:db8:a2:b85::/64 via 2001:db8:a2:b6f::1

Reading it

LineWhat I see today
Route to AD segmentThe line has a prefix and no via. The design says the Active Directory servers are integrated over IPv4 only, so nothing depended on it
Section A and section B of the DNS appliancesBoth entries carry the same prefix, 2001:db8:b1:c0a::/64
Jump server segmentsThe comment with DC1-A-VCJMP001 stands above a prefix of site 2 (2001:db8:a2:) and the one with DC2-A-VCJMP001 above a prefix of site 1 (2001:db8:a1:); the two comments are swapped

Unlike IPv4, where three summary routes cover every private range, IPv6 got one route per segment, so each new management segment meant a new line on every dual-homed server. The name of the organisation was removed from two comments.

Checked against RHEL 10.2

As builtToday
ifcfg-* files read by the network service, NM_CONTROLLED="no"The legacy network scripts were deprecated in RHEL 8; RHEL 9 does not contain the network-scripts package; in RHEL 10 support for the ifcfg format was removed
One file per interface under /etc/sysconfig/network-scriptsNetworkManager keyfiles under /etc/NetworkManager/system-connections/; on RHEL 9 nmcli connection migrate converts ifcfg profiles to keyfiles
route6-eth0 with <prefix> via <gateway> linesStatic routes are properties of the connection and live in the [ipv6] section of its keyfile

Red Hat's advice today is not to write these profiles by hand at all, but to use nmcli, the network system role or the nmstate API. RHEL 7 itself left maintenance on 2024-06-30.

← solutionz