← RHCSA: RHEL 10 production administration
06 / 8 · 25 MIN

Network profiles and durable rules

Control persistent configuration, applied state, and access recovery.

Concept and mechanism

NetworkManager maintains connection profiles. Modifying a profile does not mean every property is immediately applied to the active connection. Determine the supported application procedure and its impact on the remote session; a console or independent recovery path reduces lockout risk. When the address comes from DHCP but DNS must be locally specified, consider static servers and automatic-DNS control for the relevant address family. Configuring only IPv4 can leave IPv6 information participating in resolution. Confirm effective data, not merely the profile’s text.

Guided application

firewalld distinguishes runtime and permanent configuration, organized through zones and other mechanisms. A runtime-only rule can disappear when permanent configuration is loaded again. Before persisting, compare differences and identify what belongs to the approved change. Saving all runtime can retain temporary diagnostic exceptions. During validation, confirm the interface or source zone, the listener, a new allowed connection, and behavior for traffic that should remain restricted. An already established session may not exercise the rule being assessed.

IN PRACTICE

On a remote server, prepare recovery access before reactivating a profile. For the firewall, test a new connection after applying reviewed permanent configuration.

Common pitfalls

Editing a profile and assuming application; forgetting IPv6 DNS; persisting exceptions in bulk; testing only the existing session.

Related topics: Identities, sessions, and delegation · Shared permissions and SELinux

Take this idea with you

Accept the change after proving applied state and persistence within intended scope.

Create account

Reference: RHEL10 Ethernet connections · EX200 based on Red Hat Enterprise Linux 10