LINUXOR.SK ... open source notes ...

Proxy - ifcfg-ens33, lab, internal

category: solutionz/proxy · date: 2019-12-31 · updated: 2026-10-03 · author: LALA

Proxy Solution · Config document · referenced from Interfaces and firewalld zones

noteAs with its companion, the ZONE= line is the first zone-binding method, which needs NetworkManager and whose result came out reversed in the lab (external: ens33). The binding was redone with firewall-cmd --change-interface afterwards. TYPE=ethernet is written in lower case here and Ethernet in the other file; it is how the notes have it.

The internal interface of the lab proxy proxy.lab.example.net: the side the client 10.90.114.1 talks to, and the address Squid listens on (http_port 10.90.114.114:3128). The file has no gateway and no default route; everything that is not the local network leaves through ens32.

ItemValue
Path on the host/etc/sysconfig/network-scripts/ifcfg-ens33
Hostproxy.lab.example.net, RHEL 7.5, a VMware guest
Address10.90.114.114/24, no gateway
firewalld zoneinternal
Activated withsystemctl restart network, as root
NeedsNetworkManager enabled and NM_CONTROLLED=yes, or the ZONE= line has no effect

The file

ini
TYPE=ethernet
NAME=ens33
DEVICE=ens33
ONBOOT=yes
BOOTPROTO=none
PREFIX=24
IPADDR=10.90.114.114
IPV6INIT=no
ZONE=internal
NM_CONTROLLED=yes

The lines

LineMeaning
TYPE=ethernetlower case, unlike ifcfg-ens32; the notes show no error from it. The ifconfig output in the notes precedes the file, so it says nothing about this line
BOOTPROTO=none, PREFIX=24, IPADDR=10.90.114.114static address in the client network 10.90.114.0/24
no GATEWAY, no DEFROUTEthe default route belongs to ens32; the notes hold no static route for this side, the lab's only client is in the same network
IPV6INIT=nono IPv6 in the lab
ZONE=internalthe firewalld zone for this interface, read by NetworkManager
NM_CONTROLLED=yesNetworkManager manages the interface

The companion file is ifcfg-ens32, external; the command set that rebound the interfaces, with the reversed listing, is firewalld on the lab host.

Checked against RHEL 10 and firewalld 2.5.2

As builtToday
RHEL 7.5RHEL 7 reached the end of its maintenance support on 2024-06-30; Extended Life Cycle Support covers only 7.9, until 2029-05-31
/etc/sysconfig/network-scripts/ifcfg-ens33, NM_CONTROLLED=yesNetwork scripts deprecated in RHEL 8; no network-scripts package in RHEL 9, where new profiles are keyfiles under /etc/NetworkManager/system-connections/; ifcfg support removed in RHEL 10. nmcli connection migrate converts an ifcfg profile to a keyfile; NetworkManager's ifcfg-rh plugin has been deprecated since 1.44
ZONE=internalnmcli connection modify <profile> connection.zone internal; firewalld.zones(5) still documents ZONE= for ifcfg files, and firewalld.zone(5) says NetworkManager-managed interfaces are bound to zones by NetworkManager itself
systemctl restart networkgone with network-scripts; nmcli connection reload and nmcli connection up <profile>

Nothing about the zone binding itself changed in firewalld: internal is still one of the nine predefined zones with the same four default services. The file that carries the binding is gone.

← solutionz/proxy