nstall openwrt as host - system:
\
simple backup config \
http://217.160.255.254:8000/openwrt/backup-demogitjava.ddns.net-2025-11-06.tar.gz \
v2 with switch config \
http://217.160.255.254:8000/openwrt/backup-demogitjava.ddns.net-2026-06-22.tar.gz \
http://217.160.255.254:8000/openwrt/wg-config \


default pw jj78mvpr5k21

add to openwrt local startup to run ipfire forwarded \
ifconfig eth0 up \
docker exec -it ipfire /bin/bash sh /root/configiptables.v2 \





edit /etc/resolv.conf \
nameserver 95.85.95.85 \
nameserver 2.56.220.2 \

\


http://217.160.255.254:8000/openwrt/openwrt_installwithgparted \

if openwrt is installed the you can install the container over a simple GUI-ServerPanel \
the containers over console via tty are only available over vpn wireguard \
http://192.168.10.56:8081 \
admin \
jj78mvpr52k1 \ 
by default \

for setting config \



/etc/rc.d/init.d/networking/red start \
RED_DEV=eth0 is set to -- RED_MACADDR=02:01:18:4f:53:80 \
GREEN_DEV=vxlanwireguard --- GREEN_MACADDR=e2:3e:c8:2d:3e:1c \
ORANGE_DEV=vlan20 --- as DMZ with ip 10.255.255.1 -- ORANGE_MACADDR=0e:98:7f:b7:2d:ec \
\

http://217.160.255.254:8000/webhtml/Guiserverpanel-0.0.1-SNAPSHOT.jar \

the ipfire firewall works over DMZ in my case the gateway ip is set to 10.255.255.1 \

http3 rule for iptables \
iptables -A INPUT -p udp -s 217.160.255.254 --dport 80 -j ACCEPT \
iptables -A OUTPUT -p udp -s 217.160.255.254 --dport 80 -j ACCEPT \

ipfire cloud:
--> disable Network / Use DNS servers assigned by the ISP \
    

simple docker compose.yml run file with \
docker-compose up -d --build \

compose setup on red0 with pppoe with tap drivers\
then start the second docker container with classic setup over static ip 
the it runs as dmz
```
services:
    ipfire:
        stdin_open: true
        tty: true
        platform: linux/amd64
        container_name: ipfire
        restart: unless-stopped
        network_mode: host
        cap_add:
            - NET_ADMIN
            - SYS_ADMIN
        privileged: true
        tmpfs: /opt/docker
        image: jgsoftwares/ipfire:cloud
        command: /bin/bash
```
```
#netmask /24 

#sudo ifconfig lo add 127.0.0.1 netmask 0xffffff00  

docker run -it -p 0.0.0.0:444:444 --security-opt seccomp=unconfined --security-opt apparmor=docker-default --platform=linux/amd64 --name ipfire --restart unless-stopped --kernel-memory=6M --detach --net=host --net=none --cap-add=NET_ADMIN --cap-add SYS_ADMIN --privileged --security-opt seccomp=unconfined --tmpfs /opt/docker jgsoftwares/ipfire:cloudredorangenative /bin/bash sh configiptables.v2
-
openwrt
edit board.json eth0 from lan to wan 
/etc/board.json
{
        "model": {
                "id": "qemu-standard-pc-i440fx-piix-1996",
                "name": "QEMU Standard PC (i440FX + PIIX, 1996)"
        },
        "network": {
                "wan": {
                        "device": "eth0",
                        "protocol": "static"
                }
        }
}
simple switch config for
/etc/config/network 
http://217.160.255.254:8000/openwrt/switcheth0
resart network with 
service network restart 

\
reconfig lo interface 
host console from your provider
\
ip addr del 127.0.0.1/8 dev lo
ip addr del ::1/128 dev lo
ip addr del 127.0.0.1/24 dev lo
ip addr add 127.0.0.1/24 dev lo scope link
ip address add 10.255.255.1/32 dev eth0 scope host
ip address add 217.160.255.254/32 dev eth0 scope host
\
enable Spanning Tree Protocol (STP) on bridges 
config device                          
        option type 'bridge'                       
   -->  option stp '1'                    
                                       
config device                             
        option name 'br-bf443d7e15e7'           
   -->  option stp '1'


for wireguard optional add to peer

config wireguard_wireguard                                                 
        option description 'FritzBox'   
   -->  option scope 'host'                 

edit wireguard vpn relay server over the openwrt panel
/network/dhcp/dnsmasq/Relay
192.168.10.56 wirguard  ----    8.8.4.4 
to
192.168.10.56 wirguard  ----    95.85.95.85
192.168.10.56 wirguard  ----    2.56.220.2



\
[root@ipfire /]# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/24 scope link lo
       valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    link/ether 02:01:18:4f:53:80 brd ff:ff:ff:ff:ff:ff
    inet 10.255.255.1/32 scope host eth0
       valid_lft forever preferred_lft forever
    inet 217.160.255.254/32 scope host eth0
       valid_lft forever preferred_lft forever
[root@ipfire /]# route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         10.255.255.1    0.0.0.0         UG    0      0        0 eth0
192.168.10.0    192.168.10.56   255.255.255.0   UG    0      0        0 wireguard
[root@ipfire /]# 


optional disable uhttpd service in the host console from your provider
/etc/init.d/uhttpd stop 
```



```
connect to cloud dhcp 

start web login 
/etc/init.d/apache start

web access over http wiht:
https://192.168.10.56:444

iptables list rules
iptables -L --line-numbers
# delete rules by
iptables -D INPUT 3

http://demogitjava.ddns.net:8000/backup-demogitjava.ddns.net-2025-11-06.tar.gz
edit iptables config if u using openwrt backup



restart docker container every hour
/System/Scheduled Tasks
0 * * * * docker container restart ipfire 

login with default password
jj78mvpr52k1


the docker deamon is started with
# start docker daemon
if manuly started with 
--insecure-registry=192.168.10.56/24,size=254 --default-address-pool base=10.255.255.1/32,size=7
\
dockerd --debug -H=unix:///var/run/docker.sock -H=0.0.0.0:2375 --iptables=true --bridge=none  --default-cgroupns-mode=host --ip-masq=false --ipv6=false --default-runtime io.containerd.runc.v2 --data-root=/opt/docker --dns=95.85.95.85 --dns=2.56.220.2 --selinux-enabled=true --mtu=1500 --tls=false --seccomp-profile=unconfined 

/etc/hosts   --> delete 127.0.0.1 localhost

start the red interface manually
/etc/rc.d/init.d/networking/red start


vi /var/ipfire/main/routing 
on,0.0.0.0/0,10.255.255.1,orange0                                                                                     
on,192.168.10.0/24,192.168.10.56,wireguard                                                                                        
 

----------------------------
 setup interface 
 red      --> 217.160.255.254 255.255.255.0 10.255.255.1
 orange   --> 10.255.255.1 255.255.255.255
 green    --> 192.168.10.56 255.255.255.0 
----------------------------

# start wireguard server as second
# port 51820
/etc/init.d/wireguard start

# if red get ip over dhcp 
#
#brctl addbr ipfirehub
#ifconfig ipfirehub up
#brctl addbr ipfirehubred
#ifconfig ipfirehubred up
#brctl addif ipfirehub vxlanwireguard
#brctl addif ipfirehubred vlan20
#brctl setfd ipfirehubred 0

# commands run on openwrt 25.12.2 version
# with iptables 
# web port on tcp alternative with http3 edit to upd
# running with fiber driver ixgbe
docker exec -it ipfire /bin/bash
#run ipfire config 
reboot 
iptables -F
iptables -N raw
/etc/rc.d/init.d/networking/red start
ip route del 10.255.255.1/32 
/etc/init.d/localnet start
/etc/init.d/dhcrelay start
/etc/init.d/leds start 
/etc/init.d/sysctl start
/etc/init.d/wlanclient stop
/var/ipfire/ethernet/vlans restart
# openports
iptables -A INPUT -i vlan20 -p tcp --dport 80 -j OWNACCEPT
iptables -A OUTPUT -i vlan20 -p tcp --dport 80 -j OWNACCEPT
iptables -A INPUT -i vlan20 -p tcp --dport 8000 -j OWNACCEPT
iptables -A OUTPUT -i vlan20 -p tcp --dport 8000 -j OWNACCEPT
iptables -A INPUT -i eth0 -p upd --dport 51820 -j OWNACCEPT
iptables -A OUTPUT -i eth0 -p upd --dport 51820 -j OWNACCEPT
iptables -t nat -I PREROUTING -p tcp -i orange0 --dport 22 -j DNAT --to 192.168.10.56:22
iptables -A FORWARD -i orange0 -o green0 -p tcp --dport 22 -j ACCEPT
iptables -t nat -I PREROUTING -p tcp -i orange0 --dport 6010 -j DNAT --to 127.0.0.1:6010
iptables -A FORWARD -i orange0 -o green0 -p tcp --dport 6010 -j ACCEPT
iptables -A INPUT -p tcp --dport 80 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 80 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A INPUT -p tcp --dport 8000 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 8000 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A INPUT -p tcp --dport 1527 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 1527 -i vlan20 -s 10.255.255.1 -j ACCEPT
iptables -A INPUT -p tcp --dport 8443 -i vxlanwireguard -s 192.168.10.56 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 8443 -i vxlanwireguard -s 192.168.10.56 -j ACCEPT
iptables -A INPUT -p tcp --dport 8081 -i vxlanwireguard -s 192.168.10.56 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 8081 -i vxlanwireguard -s 192.168.10.56 -j ACCEPT
iptables -A INPUT -i eth0 -p udp --dport 51820 -j ACCEPT
iptables -A OUTPUT -i eth0 -p udp --dport 51820 -s 10.255.255.1 -j ACCEPT
iptables -A INPUT -p tcp -i vlan20 --dport 853 -d 95.85.95.85,2.56.220.2 -j ACCEPT
iptables -A INPUT -p tcp -i vlan20 --sport 853 -s 95.85.95.85,2.56.220.2 -j ACCEPT
iptables -A INPUT -p tcp -i vlan20 --dport 853 -d 8.8.8.8,8.8.4.4 -j ACCEPT
iptables -A INPUT -p tcp -i vlan20 --sport 853 -s 8.8.8.8,8.8.4.4 -j ACCEPT
ip6tables -P INPUT DROP
ip6tables -P FORWARD DROP
iptables -D FORWARD 1 # docker-user
iptables -D FORWARD 1 # DOCKER-ISOLATION-STAGE-1
iptables -D DOCKER-ISOLATION-STAGE-1 1 # DOCKER-ISOLATION-STAGE-1           
iptables -D DOCKER-ISOLATION-STAGE-1 1 # return 
iptables -D DOCKER-ISOLATION-STAGE-2 1 # DOCKER-ISOLATION-STAGE-1
iptables -D DOCKER-ISOLATION-STAGE-2 1 # return
iptables -D DOCKER-USER 1 # return
iptables -t nat -A POSTROUTING -j MASQUERADE
iptables -vt nat -A CUSTOMPREROUTING ! -o orange0 -p udp --destination-port 853 -j REDIRECT --to-ports 853
iptables -vt nat -A CUSTOMPREROUTING ! -o orange0 -p tcp --destination-port 853 -j REDIRECT --to-ports 853
iptables -A OUTPUT -m conntrack --ctstate ESTABLISHED -j ACCEPT
/etc/sysconfig/firewall.local start
/etc/init.d/wlanclient stop
/etc/init.d/cloud-init start
/etc/rc.d/init.d/static-routes reload
ip addr del 127.0.0.1/8 dev lo
ip addr del ::1/128 dev lo
sysctl net.ipv4.ip_forward=1
sysctl net.ipv4.conf.all.src_valid_mark=1
sysctl net.ipv6.conf.all.disable_ipv6=1
sysctl net.ipv6.conf.default.disable_ipv6 = 1
sysctl net.ipv6.conf.lo.disable_ipv6 = 1
ip route del 10.255.255.1/32 
route del -net 192.168.10.0 gw 0.0.0.0 netmask 255.255.255.0 dev wireguard
route add -net 192.168.10.0 gw 192.168.10.56 netmask 255.255.255.0 dev wireguard
/etc/rc.d/init.d/smt restart
ip route add 217.160.255.254 via 10.255.255.1 dev orange0
chmod 777 /var/ipfire/ethernet/vlans 
/var/ipfire/ethernet/vlans restart
ethtool -s eth0 speed 10000 duplex half autoneg off
iptables-save
exit
# second connect to container 
# to start the container in cloud mode
docker exec -it ipfire /bin/bash
/etc/init.d/cloud-init start
exit

----------------------------

[root@demogitjava /]# brctl show
bridge name     bridge id               STP enabled     interfaces
ipfirehub               8000.0201184f5380       no              vxlanwireguard
                                                                vlan20
[root@demogitjava /]# 

----------------------------

restart firewall on openwrt
service firewall restart

----------------------------

delte red0.info file
rm -rf /var/ipfire/dhcpc/red0.lease

edit dhcp config file
/var/ipfire/dhcpc/dhcpcd-red0.info
 
broadcast_address=217.160.255.254                                                                                                               
dhcp_lease_time=600                                                                                                                             
dhcp_message_type=5                                                                                                                             
dhcp_server_identifier=169.254.254.1                                                                                                            
domain_name_servers='95.85.95.85 2.56.220.2'    <-----                                                                                                
host_name=demogitjava.ddns.net                                                                                                                  
ip_address=217.160.255.254                                                                                                                      
network_number=217.160.255.254                                                                                                                  
routers=10.255.255.1                                                                                                                            
subnet_cidr=32                                                                                                                                  
subnet_mask=255.255.255.255                                                                                                                     
   
restart the network with 
/etc/init.d/network restart 

add ip addr to red0
ip addr 217.160.255.254/32 dev red0

delete static ip with
ip route del 10.255.255.1/32 
----------------------------------




                         
```


```
openwrt as cloud system - over gparted
http://demogitjava.ddns.net:8000/openwrt/openwrt_installwithgparted
-> disable dns server over the wireguard interface if u use a ipfire dmz container for internet


openwrt backup 
http://demogitjava.ddns.net:8000/backup-demogitjava.ddns.net-2025-10-11.tar.gz
default password 
jj78mvpr52k1

change password with 
passwd

IpFire config for Layer2 
--> dmz setup

-----> openwrt                             | container ipfire -> red interface only
         -----  vpn wireguard  ----->      | red -> wan ip
                                             2: red0: <BROADCAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
                                                link/ether 02:01:18:4f:53:80 brd ff:ff:ff:ff:ff:ff
                                                inet 217.160.255.254/32 scope global red0
                                                valid_lft forever preferred_lft forever

                                           
                                | INTERNET | openvpn started on port 1194
                                           | add a routed peer over firewall
                                           |
                                             TCP	OpenVPN 1194
ssh connect
console login over port 444
https://192.168.10.56:444/cgi-bin/index.cgi

Firewall rules -> vi /var/ipfire/firewall/config 

5,REJECT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,RED,ON,UDP,,9092,ON,,,TGT_PORT,9092,dropbittorent,,,,,,,,,,00:00,00:00,,AUTO,,dnat,,,,,second
6,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,,TCP,,80,ON,,,cust_srv,HTTP,HTTP,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
1,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,ON,TCP,,1527,ON,,,TGT_PORT,1527,DerbyDB,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
4,ACCEPT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,ORANGE,,TCP,,51820,ON,,,cust_srv,SSH,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second
3,ACCEPT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,ORANGE,,TCP,,51820,ON,,,cust_srv,SSH,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second
2,ACCEPT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,ORANGE,,TCP,,51820,ON,,,cust_srv,SSH,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second

Firewall rules -> vi /var/ipfire/firewall/input
8,ACCEPT,INPUTFW,ON,std_net_src,ALL,ipfire,ORANGE,,TCP,,51820,ON,,,cust_srv,SSH,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second,
4,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,RED1,ON,TCP,,1527,ON,,,TGT_PORT,1527,DerbyDB,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
5,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,RED1,ON,TCP,,8443,ON,,,TGT_PORT,8443,Lanserver,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
6,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,RED1,ON,TCP,,8000,ON,,,TGT_PORT,8000,HttpFileserver,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
3,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,RED1,,TCP,,80,ON,,,cust_srv,HTTP,HTTP,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
7,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,GREEN,ON,UDP,,51820,ON,,,TGT_PORT,51820,Wireguard,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second
1,ACCEPT,INPUTFW,ON,src_addr,192.168.10.56/32,ipfire,ORANGE,ON,TCP,,22,ON,,,TGT_PORT,22,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second
2,ACCEPT,INPUTFW,ON,src_addr,217.160.255.254/32,ipfire,RED1,,TCP,,80,ON,,,cust_srv,HTTP,HTTP,,,,,,,,,,00:00,00:00,ON,Default IP,80,dnat,,,,,second

Firewall rules -> vi /var/ipfire/firewall/outgoing
1,REJECT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,RED,ON,UDP,,9092,ON,,,TGT_PORT,9092,dropbittorent,,,,,,,,,,00:00,00:00,,AUTO,,dnat,,,,,second                             
4,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,ON,TCP,,8443,ON,,,TGT_PORT,8443,Lanserver,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second                     
2,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,,TCP,,80,ON,,,cust_srv,HTTP,HTTP,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second                              
3,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,ON,TCP,,1527,ON,,,TGT_PORT,1527,DerbyDB,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second                       
7,ACCEPT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,OpenVPN-Dyn,,TCP,,51820,ON,,,cust_srv,SSH,ssh,,,,,,,,,,00:00,00:00,ON,ORANGE,,snat,,,,,second                              
5,ACCEPT,FORWARDFW,ON,src_addr,217.160.255.254/32,std_net_tgt,RED,ON,TCP,,8000,ON,,,TGT_PORT,8000,HttpFileserver,,,,,,,,,,00:00,00:00,ON,RED,,snat,,,,,second                
6,ACCEPT,FORWARDFW,ON,std_net_src,ALL,std_net_tgt,OpenVPN-Dyn,ON,UDP,,51820,ON,,,TGT_PORT,51820,Wireguard,,,,,,,,,,00:00,00:00,,AUTO,,dnat,,,,,second,ON 



                                | INTERNET | orange 
                                             used interface
                                             5: orange0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1370 qdisc noqueue state UNKNOWN group default qlen 1000
                                                link/ether e2:3e:c8:2d:3e:1c brd ff:ff:ff:ff:ff:ff

           #aternative with 2 containers DMZ
           # without dns server  
           # removed dns gcore from wireguard 
           # removed dns gcore on ipfire containers
           # brctl addbr orange0
          [root@demogitjava /]# route -n
          Kernel IP routing table
          Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
          0.0.0.0         10.255.255.1    0.0.0.0         UG    0      0        0 red0
          192.168.10.0    192.168.10.56   255.255.255.0   UG    0      0        0 wireguard
          192.168.10.0    0.0.0.0         255.255.255.0   U     0      0        0 green0
          192.168.10.0    0.0.0.0         255.255.255.0   U     0      0        0 orange0
          [root@demogitjava /]# 

   
          # alternative create file 
          vi /etc/unbound/local.d/insecure.conf
          #########################
          server:
               domain-insecure: demogitjava.ddns.net
          #########################
          :w
          :q
          restart unbound
          /etc/init.d/unbound restart
                                           
                                           | container landingpage
                                            web
                                            ---> landingpage           | 80
                                           | container derbydb
                                            ---> derbydb               | 1527  
                                           | container lanserver           
                                            ---> lanserver             | 8443
                                           
                                   openwrt
  <---------------------------------------->  client 1
                                            

                                              ssh Graphical Support with Cipher chacha20-poly1305@openssh.com 
                                              over vpn with web support


                                          


```

```
docker run -it -p 0.0.0.0:444:444 --security-opt seccomp=unconfined --security-opt apparmor=docker-default --platform=linux/amd64 --name ipfiredmz --restart unless-stopped --kernel-memory=6M --detach --net=host --net=none --cap-add=NET_ADMIN --cap-add SYS_ADMIN --privileged --tmpfs /opt/docker jgsoftwares/ipfire:dmz /bin/bash
```

```
vi /var/ipfire/ethernet/vlans
/var/ipfire/ethernet/vlans restart
vlan config

GREEN_PARENT_DEV=eth0                                                                                                                                                               
GREEN_VLAN_ID=10                                                                                                                                                                               
GREEN_MAC_ADDRESS=02:01.18:4f:53:80                                                                                                                                                     
RED_PARENT_DEV=eth0                                                                                                                                                                           
RED_VLAN_ID=0                                                                                                                                                                                 
RED_MAC_ADDRESS=02:01.18:4f:53:80                                                                                                                                                        
ORANGE_PARENT_DEV=eth0                                                                                                                                                            
ORANGE_VLAN_ID=20                                                                                                                                                                              
ORANGE_MAC_ADDRESS=02:01.18:4f:53:80                                                                                                                                                           
```                                                                                                                                                                                                                                
```
vi /etc/ntp/ntpInclude.conf

server 2.rhel.pool.ntp.org prefer

restart ntp 
/etc/init.d/ntp start 
```


```
vi /var/ipfire/ethernet/settings

check mac address 
by vxlanwireguard an ethernet interface eth0 

type command in container for soft reboot
# tap 
# e1000e 
# ethtool -s eth0 speed 1000 duplex half
# ixgbe - 10GbE
# ethtool -s eth0 speed 10000 duplex half
#
# wan ip - 217.160.255.254
# ORANGE_NETADDRESS=217.160.255.254
#
# alternative runs with 
# RED_TYPE=DHCP

vi /var/ipfire/ethernet/settings
CONFIG_TYPE=2
GREEN_DEV=eth0
GREEN_MACADDR=02:01.18:4f:53:80
GREEN_DESCRIPTION='"tap: device on green0"'
GREEN_MODE=bridge
GREEN_ADDRESS=192.168.10.56
GREEN_NETMASK=255.255.255.0
GREEN_NETADDRESS=192.168.10.0
GREEN_DRIVER=ixgbe
RED_DEV=eth0
RED_MACADDR=02:01:18:4f:53:80
RED_DESCRIPTION='"tap: device on red0"'
RED_DRIVER=ixgbe
RED_MODE=NATIVE
RED_DHCP_HOSTNAME=demogitjava.ddns.net
RED_DHCP_FORCE_MTU=1500
RED_DHCP_RAPID_COMMIT=off
RED_ADDRESS=217.160.255.254
RED_NETMASK=255.255.255.255
DEFAULT_GATEWAY=10.255.255.1
RED_NETADDRESS=217.160.255.254
ORANGE_DEV=eth0
ORANGE_MACADDR=02:01:18:4f:53:80
ORANGE_DESCRIPTION='"???: Unknown Network Interface (vxlanwan)"'
ORANGE_MODE=NATIVE
ORANGE_DESCRIPTION='"tap: device on orange0"'
ORANGE_DRIVER=ixgbe
ORANGE_ADDRESS=10.255.255.1
ORANGE_NETMASK=255.255.255.255
ORANGE_NETADDRESS=217.160.255.254
RED_TYPE=STATIC
BLUE_DRIVER=
BLUE_DEV=
BLUE_MACADDR=
BLUE_DESCRIPTION=


```
```
/etc/sysconfig/rc.local
chmod +x /etc/sysconfig/rc.local

iwconfig red0 txpower 2
iwconfig orange0 txpower 2
iwconfig green0 txpower 2
```                                                                                                                     


```
this image is converted the qcow2 image over an debian system \
apt-get install virt-tar-out \
apt-get install libguestfs-tools \
simple convert form qrow2 to tar.gz on debian \
\
sudo virt-tar-out -a ipfire.qcow2 / - | gzip --best > ipfire.tar.gz \
cat ipfire.tar.gz | sudo docker import - jgsoftwares/ipfire:latest \
```


