Proxy - ifcfg-ens32, lab, external
Proxy Solution · Config document · referenced from Interfaces and firewalld zones
ZONE= line is the first of two methods the lab tried for binding an interface to a firewalld zone. It works only with NetworkManager controlling the interface, and after systemctl restart network the active zones came out reversed (internal: ens32). The binding was redone with firewall-cmd --change-interface afterwards; the file was not changed again in the notes.The external interface of the lab proxy proxy.lab.example.net: the side that leads to the lab network and holds the default route. The file is the one written during the first zone method, with ZONE=external added to a static IPv4 configuration.
| Item | Value |
|---|---|
| Path on the host | /etc/sysconfig/network-scripts/ifcfg-ens32 |
| Host | proxy.lab.example.net, RHEL 7.5, a VMware guest |
| Address | 10.90.0.102/24, gateway 10.90.0.1, default route |
| firewalld zone | external |
| Activated with | systemctl restart network, as root; the note warns that this can cut you off from the system |
| Needs | NetworkManager enabled and NM_CONTROLLED=yes, or the ZONE= line has no effect |
The file
TYPE=Ethernet NAME=ens32 DEVICE=ens32 ONBOOT=yes BOOTPROTO=none PREFIX=24 IPADDR=10.90.0.102 GATEWAY=10.90.0.1 IPV6INIT=no ZONE=external NM_CONTROLLED=yes DEFROUTE=yes
The lines
| Line | Meaning |
|---|---|
BOOTPROTO=none | static addressing, no DHCP |
PREFIX=24, IPADDR=10.90.0.102 | the interface's address in the lab network, which ifconfig showed as netmask 255.255.255.0 |
GATEWAY=10.90.0.1, DEFROUTE=yes | this interface carries the default route; the internal interface has neither line |
IPV6INIT=no | no IPv6 in the lab; the only IPv6 address in the lab's ifconfig is the link-local one |
ZONE=external | the firewalld zone for this interface, read by NetworkManager |
NM_CONTROLLED=yes | NetworkManager manages the interface; the note says the ZONE= method works only then |
The listing of active zones after the restart showed ens32 in internal, the reverse of this file; see Interfaces and firewalld zones. The companion file is ifcfg-ens33, internal, and the command set that rebound the interfaces is firewalld on the lab host.
Checked against RHEL 10 and firewalld 2.5.2
| As built | Today |
|---|---|
| RHEL 7.5 | RHEL 7 reached the end of its maintenance support on 2024-06-30; Extended Life Cycle Support covers only the last minor release, 7.9, until 2029-05-31. RHEL 10 was released on 2025-05-20 |
/etc/sysconfig/network-scripts/ifcfg-ens32, NM_CONTROLLED=yes | Network scripts were deprecated in RHEL 8 and no longer provided by default; RHEL 9 does not contain the network-scripts package and stores new configurations as keyfiles under /etc/NetworkManager/system-connections/; in RHEL 10 support for the ifcfg format was removed. NetworkManager deprecated its ifcfg-rh plugin in 1.44 and nmcli connection migrate (since 1.38) converts a profile to a keyfile |
ZONE=external | firewalld.zones(5) still documents ZONE= in the ifcfg of a connection, but the keyfile equivalent is nmcli connection modify <profile> connection.zone external, and firewalld.zone(5) says the binding is not needed for NetworkManager-managed interfaces, because NetworkManager binds them to zones itself |
systemctl restart network | The network service came with network-scripts, which RHEL 9 and 10 do not have; nmcli connection reload followed by nmcli connection up <profile> applies a changed profile |
Netmask read from ifconfig | The ip utility replaced ifconfig in Red Hat's documentation from RHEL 7 on; net-tools is still packaged in RHEL 9 and 10 |
The file as a whole is a RHEL 7 artefact: on a current system the same interface is a NetworkManager keyfile, its zone is set with nmcli connection modify <profile> connection.zone external, and the setting travels with the profile rather than with the interface name.