Proxy - ifcfg-ens33, lab, internal
Proxy Solution · Config document · referenced from Interfaces and firewalld zones
ZONE= line is the first zone-binding method, which needs NetworkManager and whose result came out reversed in the lab (external: ens33). The binding was redone with firewall-cmd --change-interface afterwards. TYPE=ethernet is written in lower case here and Ethernet in the other file; it is how the notes have it.The internal interface of the lab proxy proxy.lab.example.net: the side the client 10.90.114.1 talks to, and the address Squid listens on (http_port 10.90.114.114:3128). The file has no gateway and no default route; everything that is not the local network leaves through ens32.
| Item | Value |
|---|---|
| Path on the host | /etc/sysconfig/network-scripts/ifcfg-ens33 |
| Host | proxy.lab.example.net, RHEL 7.5, a VMware guest |
| Address | 10.90.114.114/24, no gateway |
| firewalld zone | internal |
| Activated with | systemctl restart network, as root |
| Needs | NetworkManager enabled and NM_CONTROLLED=yes, or the ZONE= line has no effect |
The file
TYPE=ethernet NAME=ens33 DEVICE=ens33 ONBOOT=yes BOOTPROTO=none PREFIX=24 IPADDR=10.90.114.114 IPV6INIT=no ZONE=internal NM_CONTROLLED=yes
The lines
| Line | Meaning |
|---|---|
TYPE=ethernet | lower case, unlike ifcfg-ens32; the notes show no error from it. The ifconfig output in the notes precedes the file, so it says nothing about this line |
BOOTPROTO=none, PREFIX=24, IPADDR=10.90.114.114 | static address in the client network 10.90.114.0/24 |
no GATEWAY, no DEFROUTE | the default route belongs to ens32; the notes hold no static route for this side, the lab's only client is in the same network |
IPV6INIT=no | no IPv6 in the lab |
ZONE=internal | the firewalld zone for this interface, read by NetworkManager |
NM_CONTROLLED=yes | NetworkManager manages the interface |
The companion file is ifcfg-ens32, external; the command set that rebound the interfaces, with the reversed listing, is firewalld on the lab host.
Checked against RHEL 10 and firewalld 2.5.2
| As built | Today |
|---|---|
| RHEL 7.5 | RHEL 7 reached the end of its maintenance support on 2024-06-30; Extended Life Cycle Support covers only 7.9, until 2029-05-31 |
/etc/sysconfig/network-scripts/ifcfg-ens33, NM_CONTROLLED=yes | Network scripts deprecated in RHEL 8; no network-scripts package in RHEL 9, where new profiles are keyfiles under /etc/NetworkManager/system-connections/; ifcfg support removed in RHEL 10. nmcli connection migrate converts an ifcfg profile to a keyfile; NetworkManager's ifcfg-rh plugin has been deprecated since 1.44 |
ZONE=internal | nmcli connection modify <profile> connection.zone internal; firewalld.zones(5) still documents ZONE= for ifcfg files, and firewalld.zone(5) says NetworkManager-managed interfaces are bound to zones by NetworkManager itself |
systemctl restart network | gone with network-scripts; nmcli connection reload and nmcli connection up <profile> |
Nothing about the zone binding itself changed in firewalld: internal is still one of the nine predefined zones with the same four default services, and binding an interface to it is still the right shape. Only the file that carries the binding is gone.