LINUXOR.SK ... open source notes ...

Proxy - ifcfg-ens33, lab, internal

category: solutionz · date: 2019-12-31 · updated: 2026-10-03 · author: LALA

Proxy Solution · Config document · referenced from Interfaces and firewalld zones

noteAs with its companion, the ZONE= line is the first zone-binding method, which needs NetworkManager and whose result came out reversed in the lab (external: ens33). The binding was redone with firewall-cmd --change-interface afterwards. TYPE=ethernet is written in lower case here and Ethernet in the other file; it is how the notes have it.

The internal interface of the lab proxy proxy.lab.example.net: the side the client 10.90.114.1 talks to, and the address Squid listens on (http_port 10.90.114.114:3128). The file has no gateway and no default route; everything that is not the local network leaves through ens32.

ItemValue
Path on the host/etc/sysconfig/network-scripts/ifcfg-ens33
Hostproxy.lab.example.net, RHEL 7.5, a VMware guest
Address10.90.114.114/24, no gateway
firewalld zoneinternal
Activated withsystemctl restart network, as root
NeedsNetworkManager enabled and NM_CONTROLLED=yes, or the ZONE= line has no effect

The file

ini
TYPE=ethernet
NAME=ens33
DEVICE=ens33
ONBOOT=yes
BOOTPROTO=none
PREFIX=24
IPADDR=10.90.114.114
IPV6INIT=no
ZONE=internal
NM_CONTROLLED=yes

The lines

LineMeaning
TYPE=ethernetlower case, unlike ifcfg-ens32; the notes show no error from it. The ifconfig output in the notes precedes the file, so it says nothing about this line
BOOTPROTO=none, PREFIX=24, IPADDR=10.90.114.114static address in the client network 10.90.114.0/24
no GATEWAY, no DEFROUTEthe default route belongs to ens32; the notes hold no static route for this side, the lab's only client is in the same network
IPV6INIT=nono IPv6 in the lab
ZONE=internalthe firewalld zone for this interface, read by NetworkManager
NM_CONTROLLED=yesNetworkManager manages the interface

The companion file is ifcfg-ens32, external; the command set that rebound the interfaces, with the reversed listing, is firewalld on the lab host.

Checked against RHEL 10 and firewalld 2.5.2

As builtToday
RHEL 7.5RHEL 7 reached the end of its maintenance support on 2024-06-30; Extended Life Cycle Support covers only 7.9, until 2029-05-31
/etc/sysconfig/network-scripts/ifcfg-ens33, NM_CONTROLLED=yesNetwork scripts deprecated in RHEL 8; no network-scripts package in RHEL 9, where new profiles are keyfiles under /etc/NetworkManager/system-connections/; ifcfg support removed in RHEL 10. nmcli connection migrate converts an ifcfg profile to a keyfile; NetworkManager's ifcfg-rh plugin has been deprecated since 1.44
ZONE=internalnmcli connection modify <profile> connection.zone internal; firewalld.zones(5) still documents ZONE= for ifcfg files, and firewalld.zone(5) says NetworkManager-managed interfaces are bound to zones by NetworkManager itself
systemctl restart networkgone with network-scripts; nmcli connection reload and nmcli connection up <profile>

Nothing about the zone binding itself changed in firewalld: internal is still one of the nine predefined zones with the same four default services, and binding an interface to it is still the right shape. Only the file that carries the binding is gone.

← solutionz