Sign inSign up

jgsoftwares/ipfire

By jgsoftwares

•Updated 4 months ago

ip fire - 2.29

Image
Security
0

7.9K

jgsoftwares/ipfire repository overview

install openwrt as host - system:
simple backup config
http://217.160.255.254:8000/openwrt/backup-demogitjava.ddns.net-2025-11-06.tar.gz⁠
v2 with switch config
http://217.160.255.254:8000/openwrt/backup-demogitjava.ddns.net-2026-06-22.tar.gz⁠
http://217.160.255.254:8000/webhtml/Guiserverpanel-0.0.1-SNAPSHOT.jar⁠
default pw jj78mvpr5k21 \

/etc/sysconfig/cpupower -> GOVERNOR="powersave" \

root@demogitjava:~# route -n 
Kernel IP routing table 
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface 
0.0.0.0         10.255.255.1    0.0.0.0         UG    0      0        0 eth0 
192.168.10.0    192.168.10.56   255.255.255.0   UG    0      0        0 wg0 
- openwrt hostpanel config - 
run interface wg0 on 2 mbit - works only over host panel not in container 
install trafic controll
apk add tc
tc qdisc add dev wg0 root tbf rate 2mbit burst 32kbit latency 400ms
ip link set dev wg0 txqueuelen 512
ip link add link eth0 name vlan0 type vlan id 0
ifconfig vlan0 up
ip addr add 10.255.255.1/32 dev vlan0 scope host
/etc/init.d/odhcpd disable
/etc/init.d/odhcpd stop
/etc/init.d/firewall restart

edit wireguard interface to wg0 
vi /etc/config/dockerd
    from - wireguard to -->  option _luci_lan 'wg0'



tc qdisc show dev wg0
qdisc tbf 8007: root refcnt 2 rate 2Mbit burst 4Kb lat 400ms 


http://217.160.255.254:8000/openwrt/openwrt_installwithgparted⁠
\

http://217.160.255.254:8000/webhtml/Guiserverpanel-0.0.1-SNAPSHOT.jar⁠ \

the ipfire firewall works over DMZ in my case the gateway ip is set to 10.255.255.1 \

http3 rule for iptables
iptables -A INPUT -p udp -s 217.160.255.254 --dport 80 -j ACCEPT
iptables -A OUTPUT -p udp -s 217.160.255.254 --dport 80 -j ACCEPT \

ipfire cloud: --> disable Network / Use DNS servers assigned by the ISP \

/var/ipfire/dns

/var/ipfire/dns/settings

QNAME_MIN=strict
USE_IS_NAMESERVERS=off
ENABLE_SAFE_SEARCH_YOUTUBE=off
ENABLE_SAFE_SEARCH=OFF
PROTO=TLS

/var/ipfire/dns/servers

10,8.8.4.4,,enabled,google
11,81.3.27.54,recursor01.dns.lightningwirelabs.com,enable,ipfire
9,8.8.8.8,,enabled,google
3,95.85.95.85,,enabled,gcore
4,2.56.220.2,,enabled,gcore


#netmask /24 

#sudo ifconfig lo add 127.0.0.1 netmask 0xffffff00  

docker run -it -p 0.0.0.0:444:444 --security-opt seccomp=unconfined --security-opt apparmor=docker-default --platform=linux/amd64 --name ipfire --restart unless-stopped --kernel-memory=6M --detach --net=host --net=none --cap-add=NET_ADMIN --cap-add SYS_ADMIN --privileged --security-opt seccomp=unconfined --tmpfs /opt/docker jgsoftwares/ipfire:cloud /bin/bash
-
openwrt
edit board.json eth0 from lan to wan 
/etc/board.json
{
        "model": {
                "id": "qemu-standard-pc-i440fx-piix-1996",
                "name": "QEMU Standard PC (i440FX + PIIX, 1996)"
        },
        "network": {
                "wan": {
                        "device": "eth0",
                        "protocol": "static"
                }
        }
}

\
reconfig lo interface 
host console from your provider
\
ip addr del 127.0.0.1/8 dev lo
ip addr del ::1/128 dev lo
ip addr del 127.0.0.1/24 dev lo
ip addr add 127.0.0.1/24 dev lo scope link
ip address add 10.255.255.1/32 dev eth0 scope host
ip address add 217.160.255.254/32 dev eth0 scope host
\
enable Spanning Tree Protocol (STP) on bridges 
config device                          
        option type 'bridge'                       
   -->  option stp '1'                    
                                       
config device                             
        option name 'br-bf443d7e15e7'           
   -->  option stp '1'


for wireguard optional add to peer

config wireguard_wireguard                                                 
        option description 'FritzBox'   
   -->  option scope 'host'                 

edit wireguard vpn relay server over the openwrt panel
/network/dhcp/dnsmasq/Relay
192.168.10.56 wirguard  ----    8.8.4.4 
to
192.168.10.56 wirguard  ----    95.85.95.85
192.168.10.56 wirguard  ----    2.56.220.2



\
[root@ipfire /]# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/24 scope link lo
       valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    link/ether 02:01:18:4f:53:80 brd ff:ff:ff:ff:ff:ff
    inet 10.255.255.1/32 scope host eth0
       valid_lft forever preferred_lft forever
    inet 217.160.255.254/32 scope host eth0
       valid_lft forever preferred_lft forever
[root@ipfire /]# route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         10.255.255.1    0.0.0.0         UG    0      0        0 eth0
192.168.10.0    192.168.10.56   255.255.255.0   UG    0      0        0 wireguard
[root@ipfire /]# 


optional disable uhttpd service in the host console from your provider
/etc/init.d/uhttpd stop 
connect to cloud dhcp 

start web login 
/etc/init.d/apache start

web access over http wiht:
https://192.168.10.56:444

iptables list rules
iptables -L --line-numbers
# delete rules by
iptables -D INPUT 3

http://demogitjava.ddns.net:8000/backup-demogitjava.ddns.net-2025-11-06.tar.gz
edit iptables config if u using openwrt backup



restart docker container every hour
/System/Scheduled Tasks
0 * * * * docker container restart ipfire 

login with default password
jj78mvpr52k1


the docker deamon is started with
# start docker daemon
if manuly started with 
--insecure-registry=192.168.10.56/24,size=254 --default-address-pool base=10.255.255.1/32,size=7
\
dockerd --debug -H=unix:///var/run/docker.sock -H=0.0.0.0:2375 --iptables=true --bridge=none  --default-cgroupns-mode=host --ip-masq=false --ipv6=false --default-runtime io.containerd.runc.v2 --data-root=/opt/docker --dns=95.85.95.85 --dns=2.56.220.2 --selinux-enabled=true --mtu=1500 --tls=false --seccomp-profile=unconfined 
on docker engine 29
--firewall-backend=nftables

/etc/hosts   --> delete 127.0.0.1 localhost

start the red interface manually
/etc/rc.d/init.d/networking/red start


vi /var/ipfire/main/routing 
on,217.160.255.254/32,10.255.255.1,eth0                                                                     
 

----------------------------
 setup interface 
 red      --> 217.160.255.254 255.255.255.0 10.255.255.1
 orange   --> 10.255.255.1 255.255.255.255
 green    --> 192.168.10.56 255.255.255.0 
----------------------------

# start wireguard server as second
# port 51820
/etc/init.d/wireguard start

# if red get ip over dhcp 
#
#brctl addbr ipfirehub
#ifconfig ipfirehub up
#brctl addbr ipfirehubred
#ifconfig ipfirehubred up
#brctl addif ipfirehub vxlanwireguard
#brctl addif ipfirehubred vlan20
#brctl setfd ipfirehubred 0

# commands run on openwrt 25.12.2 version
# with iptables 
# web port on tcp alternative with http3 edit to upd
# running with fiber driver ixgbe
#
# /etc/init.d/unbound restart

# ip route add 217.160.255.254 via 10.255.255.1 dev eth0
#
docker exec -it ipfire /bin/bash
#run ipfire config 
reboot 
iptables -F
iptables -N raw
/etc/init.d/localnet start
/etc/init.d/unbound start
/etc/rc.d/init.d/networking/green stop
/etc/rc.d/init.d/networking/orange start
/etc/rc.d/init.d/networking/red start
ip route del 10.255.255.1/32 
/etc/init.d/dhcrelay start
/etc/init.d/leds start 
/etc/init.d/sysctl start
/etc/init.d/wlanclient stop
/var/ipfire/ethernet/vlans restart
# openports
iptables -A INPUT -i vlan20 -p tcp --dport 80 -j OWNACCEPT
iptables -A OUTPUT -i vlan20 -p tcp --dport 80 -j OWNACCEPT
iptables -A INPUT -i vlan20 -p tcp --dport 8000 -j OWNACCEPT
iptables -A OUTPUT -i vlan20 -p tcp --dport 8000 -j OWNACCEPT
iptables -A INPUT -i eth0 -p upd --dport 51820 -j OWNACCEPT
iptables -A OUTPUT -i eth0 -p upd --dport 51820 -j OWNACCEPT
iptables -t nat -I PREROUTING -p tcp -i orange0 --dport 22 -j DNAT --to 192.168.10.56:22
iptables -A FORWARD -i orange0 -o green0 -p tcp --dport 22 -j ACCEPT
#ssh
#iptables -t nat -I PREROUTING -p tcp -i orange0 --dport 6010 -j DNAT --to 127.0.0.1:6010
#iptables -A FORWARD -i orange0 -o green0 -p tcp --dport 6010 -j ACCEPT
iptables -A INPUT -p tcp --dport 80 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 80 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A INPUT -p tcp --dport 8000 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 8000 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A INPUT -p tcp --dport 1527 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 1527 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A INPUT -p tcp --dport 8443 -i vxlanwireguard -s 192.168.10.56 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 8443 -i vxlanwireguard -s 192.168.10.56 -j ACCEPT
iptables -A INPUT -p tcp --dport 8081 -i vxlanwireguard -s 192.168.10.56 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 8081 -i vxlanwireguard -s 192.168.10.56 -j ACCEPT
iptables -A INPUT -i eth0 -p udp --dport 51820 -j ACCEPT
iptables -A OUTPUT -i eth0 -p udp --dport 51820 -s 10.255.255.1 -j ACCEPT
iptables -A INPUT -p tcp -i vlan20 --dport 853 -d 95.85.95.85,2.56.220.2 -j ACCEPT
iptables -A INPUT -p tcp -i vlan20 --sport 853 -s 95.85.95.85,2.56.220.2 -j ACCEPT
iptables -A INPUT -p tcp -i vlan20 --dport 853 -d 8.8.8.8,8.8.4.4 -j ACCEPT
iptables -A INPUT -p tcp -i vlan20 --sport 853 -s 8.8.8.8,8.8.4.4 -j ACCEPT
ip6tables -P INPUT DROP
ip6tables -P FORWARD DROP
iptables -D FORWARD 1 # docker-user
iptables -D FORWARD 1 # DOCKER-ISOLATION-STAGE-1
iptables -D DOCKER-ISOLATION-STAGE-1 1 # DOCKER-ISOLATION-STAGE-1           
iptables -D DOCKER-ISOLATION-STAGE-1 1 # return 
iptables -D DOCKER-ISOLATION-STAGE-2 1 # DOCKER-ISOLATION-STAGE-1
iptables -D DOCKER-ISOLATION-STAGE-2 1 # return
iptables -D DOCKER-USER 1 # return
iptables -t nat -A POSTROUTING -j MASQUERADE
iptables -vt nat -A CUSTOMPREROUTING ! -o orange0 -p udp --destination-port 853 -j REDIRECT --to-ports 853
iptables -vt nat -A CUSTOMPREROUTING ! -o orange0 -p tcp --destination-port 853 -j REDIRECT --to-ports 853
iptables -A OUTPUT -m conntrack --ctstate ESTABLISHED -j ACCEPT
/etc/sysconfig/firewall.local start
/etc/init.d/wlanclient stop
/etc/init.d/cloud-init start
/etc/rc.d/init.d/static-routes reload
ip addr del 127.0.0.1/8 dev lo
ip addr del ::1/128 dev lo
sysctl net.ipv4.ip_forward=1
sysctl net.ipv4.conf.all.src_valid_mark=1
sysctl net.ipv6.conf.all.disable_ipv6=1
sysctl net.ipv6.conf.default.disable_ipv6 = 1
sysctl net.ipv6.conf.lo.disable_ipv6 = 1
ip route del 10.255.255.1/32 
route del -net 192.168.10.0 gw 0.0.0.0 netmask 255.255.255.0 dev wireguard
route add -net 192.168.10.0 gw 192.168.10.56 netmask 255.255.255.0 dev wireguard
/etc/rc.d/init.d/smt restart
chmod 777 /var/ipfire/ethernet/vlans 
/var/ipfire/ethernet/vlans restart
ethtool -s eth0 speed 10000 duplex half autoneg off
iptables-save
ip link set eth0 txqueuelen 512
ip link set wg0 txqueuelen 0
#iptables -t nat -A PREROUTING -i lo -p tcp --dport 80 -j DNAT --to-destination 217.160.255.254:80
#iptables -t nat -A PREROUTING -i lo -p tcp --dport 8000 -j DNAT --to-destination 217.160.255.254:8000
iptables -t nat -A PREROUTING -i lo -p tcp -j DNAT --to-destination 10.255.255.1
exit
# second connect to container 
# to start the container in cloud mode
docker exec -it ipfire /bin/bash
/etc/init.d/cloud-init start
exit


restart firewall on openwrt
service firewall restart

----------------------------

delte red0.info file
rm -rf /var/ipfire/dhcpc/red0.lease

edit dhcp config file
/var/ipfire/dhcpc/dhcpcd-red0.info
 
broadcast_address=217.160.255.254                                                                                                               
dhcp_lease_time=600                                                                                                                             
dhcp_message_type=5                                                                                                                                                                                                                                  
domain_name_servers='81.3.27.54'    <-----                                                                                                
host_name=demogitjava.ddns.net                                                                                                                  
ip_address=217.160.255.254                                                                                                                      
network_number=217.160.255.254                                                                                                                  
routers=10.255.255.1                                                                                                                            
subnet_cidr=32                                                                                                                                  
subnet_mask=255.255.255.255                                                                                                                     
   
restart the network with 
/etc/init.d/network restart 

add ip addr to red0
ip addr 217.160.255.254/32 dev red0

delete static ip with
ip route del 10.255.255.1/32 
----------------------------------




                         
openwrt as cloud system - over gparted
http://demogitjava.ddns.net:8000/openwrt/openwrt_installwithgparted
-> disable dns server over the wireguard interface if u use a ipfire dmz container for internet


openwrt backup 
http://demogitjava.ddns.net:8000/backup-demogitjava.ddns.net-2025-10-11.tar.gz
default password 
jj78mvpr52k1

change password with 
passwd

IpFire config for Layer2 
--> dmz setup

-----> openwrt                             | container ipfire -> red interface only
         -----  vpn wireguard  ----->      | red -> wan ip
                                             2: red0: <BROADCAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
                                                link/ether 02:01:18:4f:53:80 brd ff:ff:ff:ff:ff:ff
                                                inet 217.160.255.254/32 scope global red0
                                                valid_lft forever preferred_lft forever

                                           
                                | INTERNET | openvpn started on port 1194
                                           | add a routed peer over firewall
                                           |
                                             TCP	OpenVPN 1194
ssh connect
console login over port 444
https://192.168.10.56:444/cgi-bin/index.cgi

Firewall rules -> vi /var/ipfire/firewall/config 

5,REJECT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,RED,ON,UDP,,9092,ON,,,TGT_PORT,9092,dropbittorent,,,,,,,,,,00:00,00:00,,AUTO,,dnat,,,,,second
6,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,,TCP,,80,ON,,,cust_srv,HTTP,HTTP,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
1,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,ON,TCP,,1527,ON,,,TGT_PORT,1527,DerbyDB,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
4,ACCEPT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,ORANGE,,TCP,,51820,ON,,,cust_srv,SSH,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second
3,ACCEPT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,ORANGE,,TCP,,51820,ON,,,cust_srv,SSH,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second
2,ACCEPT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,ORANGE,,TCP,,51820,ON,,,cust_srv,SSH,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second

Firewall rules -> vi /var/ipfire/firewall/input
8,ACCEPT,INPUTFW,ON,std_net_src,ALL,ipfire,ORANGE,,TCP,,51820,ON,,,cust_srv,SSH,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second,
4,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,RED1,ON,TCP,,1527,ON,,,TGT_PORT,1527,DerbyDB,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
5,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,RED1,ON,TCP,,8443,ON,,,TGT_PORT,8443,Lanserver,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
6,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,RED1,ON,TCP,,8000,ON,,,TGT_PORT,8000,HttpFileserver,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
3,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,RED1,,TCP,,80,ON,,,cust_srv,HTTP,HTTP,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
7,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,GREEN,ON,UDP,,51820,ON,,,TGT_PORT,51820,Wireguard,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
1,ACCEPT,INPUTFW,ON,src_addr,192.168.10.56/32,ipfire,ORANGE,ON,TCP,,22,ON,,,TGT_PORT,22,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second
2,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,RED1,,TCP,,80,ON,,,cust_srv,HTTP,HTTP,,,,,,,,,,00:00,00:00,ON,Default IP,80,dnat,,,,,second

Firewall rules -> vi /var/ipfire/firewall/outgoing
1,REJECT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,RED,ON,UDP,,9092,ON,,,TGT_PORT,9092,dropbittorent,,,,,,,,,,00:00,00:00,,AUTO,,dnat,,,,,second                             
4,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,ON,TCP,,8443,ON,,,TGT_PORT,8443,Lanserver,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second                     
2,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,,TCP,,80,ON,,,cust_srv,HTTP,HTTP,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second                              
3,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,ON,TCP,,1527,ON,,,TGT_PORT,1527,DerbyDB,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second                       
7,ACCEPT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,OpenVPN-Dyn,,TCP,,51820,ON,,,cust_srv,SSH,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second                              
5,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,ON,TCP,,8000,ON,,,TGT_PORT,8000,HttpFileserver,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second                
6,ACCEPT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,OpenVPN-Dyn,ON,UDP,,51820,ON,,,TGT_PORT,51820,Wireguard,,,,,,,,,,00:00,00:00,,AUTO,,dnat,,,,,second,ON 



                                | INTERNET | orange 
                                             used interface
                                             5: orange0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1370 qdisc noqueue state UNKNOWN group default qlen 1000
                                                link/ether e2:3e:c8:2d:3e:1c brd ff:ff:ff:ff:ff:ff

           #aternative with 2 containers DMZ
           # without dns server  
           # removed dns gcore from wireguard 
           # removed dns gcore on ipfire containers
           # brctl addbr orange0
          [root@demogitjava /]# route -n
          Kernel IP routing table
          Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
          0.0.0.0         10.255.255.1    0.0.0.0         UG    0      0        0 red0
          192.168.10.0    192.168.10.56   255.255.255.0   UG    0      0        0 wireguard
          192.168.10.0    0.0.0.0         255.255.255.0   U     0      0        0 green0
          192.168.10.0    0.0.0.0         255.255.255.0   U     0      0        0 orange0
          [root@demogitjava /]# 

   
          # alternative create file 
          vi /etc/unbound/local.d/insecure.conf
          #########################
          server:
               domain-insecure: demogitjava.ddns.net
          #########################
          :w
          :q
          restart unbound
          /etc/init.d/unbound restart
                                           
                                           | container landingpage
                                            web
                                            ---> landingpage           | 80
                                           | container derbydb
                                            ---> derbydb               | 1527  
                                           | container lanserver           
                                            ---> lanserver             | 8443
                                           
                                   openwrt
  <---------------------------------------->  client 1
                                            

                                              ssh Graphical Support with Cipher [email protected] 
                                              over vpn with web support


                                          


docker run -it -p 0.0.0.0:444:444 --security-opt seccomp=unconfined --security-opt apparmor=docker-default --platform=linux/amd64 --name ipfiredmz --restart unless-stopped --kernel-memory=6M --detach --net=host --net=none --cap-add=NET_ADMIN --cap-add SYS_ADMIN --privileged --tmpfs /opt/docker jgsoftwares/ipfire:dmz /bin/bash
vi /var/ipfire/ethernet/vlans
/var/ipfire/ethernet/vlans restart
vlan config

GREEN_PARENT_DEV=eth0                                                                                                                                                               
GREEN_VLAN_ID=10                                                                                                                                                                               
GREEN_MAC_ADDRESS=02:01.18:4f:53:80                                                                                                                                                     
RED_PARENT_DEV=eth0                                                                                                                                                                           
RED_VLAN_ID=30                                                                                                                                                                                 
RED_MAC_ADDRESS=02:01.18:4f:53:80                                                                                                                                                        
ORANGE_PARENT_DEV=eth0                                                                                                                                                            
ORANGE_VLAN_ID=20                                                                                                                                                                              
ORANGE_MAC_ADDRESS=02:01.18:4f:53:80                                                                                                                                                           
vi /etc/ntp/ntpInclude.conf

server 2.rhel.pool.ntp.org prefer

restart ntp 
/etc/init.d/ntp start 
vi /var/ipfire/ethernet/settings

check mac address 
by vxlanwireguard an ethernet interface eth0 

type command in container for soft reboot
# tap 
# e1000e 
# ethtool -s eth0 speed 1000 duplex half
# ixgbe - 10GbE
# ethtool -s eth0 speed 10000 duplex half
#
# wan ip - 217.160.255.254
# ORANGE_NETADDRESS=217.160.255.254
#
# alternative runs with 
# RED_TYPE=DHCP

# GREEN_MODE=bridge
vi /var/ipfire/ethernet/settings
CONFIG_TYPE=2
GREEN_DEV=eth0
GREEN_MACADDR=02:01.18:4f:53:80
GREEN_DESCRIPTION='"tap: device on green0"'
GREEN_MODE=STATIC
GREEN_ADDRESS=192.168.10.56
GREEN_NETMASK=255.255.255.0
GREEN_NETADDRESS=192.168.10.0
GREEN_DRIVER=ixgbe
RED_DEV=eth0
RED_MACADDR=02:01:18:4f:53:80
RED_DESCRIPTION='"tap: device on red0"'
RED_DRIVER=ixgbe
RED_MODE=NATIVE
RED_DHCP_HOSTNAME=demogitjava.ddns.net
RED_DHCP_FORCE_MTU=1500
RED_DHCP_RAPID_COMMIT=off
RED_ADDRESS=217.160.255.254
RED_NETMASK=255.255.255.255
DEFAULT_GATEWAY=10.255.255.1
RED_NETADDRESS=217.160.255.254
ORANGE_DEV=eth0
ORANGE_MACADDR=02:01:18:4f:53:80
ORANGE_DESCRIPTION='"???: Unknown Network Interface (vxlanwan)"'
ORANGE_MODE=NATIVE
ORANGE_DESCRIPTION='"tap: device on orange0"'
ORANGE_DRIVER=ixgbe
ORANGE_ADDRESS=10.255.255.1
ORANGE_NETMASK=255.255.255.255
ORANGE_NETADDRESS=217.160.255.254
RED_TYPE=STATIC
BLUE_DRIVER=
BLUE_DEV=
BLUE_MACADDR=
BLUE_DESCRIPTION=


/etc/sysconfig/rc.local
chmod +x /etc/sysconfig/rc.local

iwconfig red0 txpower 2
iwconfig orange0 txpower 2
iwconfig green0 txpower 2
iwconfig wg0 txpower 2
this image is converted the qcow2 image over an debian system \
apt-get install virt-tar-out \
apt-get install libguestfs-tools \
simple convert form qrow2 to tar.gz on debian \
\
sudo virt-tar-out -a ipfire.qcow2 / - | gzip --best > ipfire.tar.gz \
cat ipfire.tar.gz | sudo docker import - jgsoftwares/ipfire:latest \

Tag summary

Content type

Image

Digest

sha256:a78890f5d…

Size

845.4 MB

Last updated

about 1 year ago

docker pull jgsoftwares/ipfire