LINUXOR.SK ... open source notes ...

Proxy - ifcfg-ens32, lab, external

category: solutionz/proxy · date: 2019-12-31 · updated: 2026-10-03 · author: LALA

Proxy Solution · Config document · referenced from Interfaces and firewalld zones

noteThe ZONE= line is the first of two methods the lab tried for binding an interface to a firewalld zone. It works only with NetworkManager controlling the interface, and after systemctl restart network the active zones came out reversed (internal: ens32). The binding was redone with firewall-cmd --change-interface afterwards; the file was not changed again in the notes.

The external interface of the lab proxy proxy.lab.example.net: the side that leads to the lab network and holds the default route. The file is the one written during the first zone method, with ZONE=external added to a static IPv4 configuration.

ItemValue
Path on the host/etc/sysconfig/network-scripts/ifcfg-ens32
Hostproxy.lab.example.net, RHEL 7.5, a VMware guest
Address10.90.0.102/24, gateway 10.90.0.1, default route
firewalld zoneexternal
Activated withsystemctl restart network, as root; the note warns that this can cut you off from the system
NeedsNetworkManager enabled and NM_CONTROLLED=yes, or the ZONE= line has no effect

The file

ini
TYPE=Ethernet
NAME=ens32
DEVICE=ens32
ONBOOT=yes
BOOTPROTO=none
PREFIX=24
IPADDR=10.90.0.102
GATEWAY=10.90.0.1
IPV6INIT=no
ZONE=external
NM_CONTROLLED=yes
DEFROUTE=yes

The lines

LineMeaning
BOOTPROTO=nonestatic addressing, no DHCP
PREFIX=24, IPADDR=10.90.0.102the interface's address in the lab network, which ifconfig showed as netmask 255.255.255.0
GATEWAY=10.90.0.1, DEFROUTE=yesthis interface carries the default route; the internal interface has neither line
IPV6INIT=nono IPv6 in the lab; the only IPv6 address in the lab's ifconfig is the link-local one
ZONE=externalthe firewalld zone for this interface, read by NetworkManager
NM_CONTROLLED=yesNetworkManager manages the interface; the note says the ZONE= method works only then

The listing of active zones after the restart showed ens32 in internal, the reverse of this file; see Interfaces and firewalld zones. The companion file is ifcfg-ens33, internal, and the command set that rebound the interfaces is firewalld on the lab host.

Checked against RHEL 10 and firewalld 2.5.2

As builtToday
RHEL 7.5RHEL 7 reached the end of its maintenance support on 2024-06-30; Extended Life Cycle Support covers only the last minor release, 7.9, until 2029-05-31. RHEL 10 was released on 2025-05-20
/etc/sysconfig/network-scripts/ifcfg-ens32, NM_CONTROLLED=yesNetwork scripts were deprecated in RHEL 8 and no longer provided by default; RHEL 9 does not contain the network-scripts package and stores new configurations as keyfiles under /etc/NetworkManager/system-connections/; in RHEL 10 support for the ifcfg format was removed. NetworkManager deprecated its ifcfg-rh plugin in 1.44 and nmcli connection migrate (since 1.38) converts a profile to a keyfile
ZONE=externalfirewalld.zones(5) still documents ZONE= in the ifcfg of a connection, but the keyfile equivalent is nmcli connection modify <profile> connection.zone external, and firewalld.zone(5) says the binding is not needed for NetworkManager-managed interfaces, because NetworkManager binds them to zones itself
systemctl restart networkThe network service came with network-scripts, which RHEL 9 and 10 do not have; nmcli connection reload followed by nmcli connection up <profile> applies a changed profile
Netmask read from ifconfigThe ip utility replaced ifconfig in Red Hat's documentation from RHEL 7 on; net-tools is still packaged in RHEL 9 and 10

The file as a whole is a RHEL 7 artefact: on a current system the same interface is a NetworkManager keyfile, its zone is set with nmcli connection modify <profile> connection.zone external, and the setting travels with the profile rather than with the interface name.

← solutionz/proxy