summary refs log tree commit diff
path: root/man/nm-settings-nmcli.5
diff options
context:
space:
mode:
authorMichael Biebl <biebl@debian.org>2022-01-13 22:30:39 +0100
committerMichael Biebl <biebl@debian.org>2022-01-13 22:30:39 +0100
commit88c227d90a6b7b388c5c85d72802a0ca8f05ed5c (patch)
tree71f32df6617802270e8a78574bd8e1637dc532f4 /man/nm-settings-nmcli.5
parente74c568b07b50b97873fb4ee1d776dedefbd54d6 (diff)
New upstream version 1.34.0 upstream/1.34.0
Diffstat (limited to 'man/nm-settings-nmcli.5')
-rw-r--r--man/nm-settings-nmcli.5216
1 files changed, 205 insertions, 11 deletions
diff --git a/man/nm-settings-nmcli.5 b/man/nm-settings-nmcli.5
index f39e8f56..b290f8a5 100644
--- a/man/nm-settings-nmcli.5
+++ b/man/nm-settings-nmcli.5
@@ -2,12 +2,12 @@
 .\"     Title: nm-settings-nmcli
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 09/22/2021
+.\"      Date: 01/13/2022
 .\"    Manual: Configuration
-.\"    Source: NetworkManager 1.32.12
+.\"    Source: NetworkManager 1.34.0
 .\"  Language: English
 .\"
-.TH "NM\-SETTINGS\-NMCLI" "5" "" "NetworkManager 1\&.32\&.12" "Configuration"
+.TH "NM\-SETTINGS\-NMCLI" "5" "" "NetworkManager 1\&.34\&.0" "Configuration"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
@@ -79,14 +79,14 @@ Format: int32
 .RS 4
 Alias: autoconnect
 .sp
-Whether or not the connection should be automatically connected by NetworkManager when the resources for the connection are available\&. TRUE to automatically activate the connection, FALSE to require manual intervention to activate the connection\&. Note that autoconnect is not implemented for VPN profiles\&. See "secondaries" as an alternative to automatically connect VPN profiles\&.
+Whether or not the connection should be automatically connected by NetworkManager when the resources for the connection are available\&. TRUE to automatically activate the connection, FALSE to require manual intervention to activate the connection\&. Autoconnect happens when the circumstances are suitable\&. That means for example that the device is currently managed and not active\&. Autoconnect thus never replaces or competes with an already active profile\&. Note that autoconnect is not implemented for VPN profiles\&. See "secondaries" as an alternative to automatically connect VPN profiles\&.
 .sp
 Format: boolean
 .RE
 .PP
 \fBautoconnect\-priority\fR
 .RS 4
-The autoconnect priority\&. If the connection is set to autoconnect, connections with higher priority will be preferred\&. Defaults to 0\&. The higher number means higher priority\&.
+The autoconnect priority in range \-999 to 999\&. If the connection is set to autoconnect, connections with higher priority will be preferred\&. The higher number means higher priority\&. Defaults to 0\&. Note that this property only matters if there are more than one candidate profile to select for autoconnect\&. In case of equal priority, the profile used most recently is chosen\&.
 .sp
 Format: int32
 .RE
@@ -105,6 +105,13 @@ Whether or not slaves of this connection should be automatically brought up when
 Format: NMSettingConnectionAutoconnectSlaves (int32)
 .RE
 .PP
+\fBdns\-over\-tls\fR
+.RS 4
+Whether DNSOverTls (dns\-over\-tls) is enabled for the connection\&. DNSOverTls is a technology which uses TLS to encrypt dns traffic\&. The permitted values are: "yes" (2) use DNSOverTls and disabled fallback, "opportunistic" (1) use DNSOverTls but allow fallback to unencrypted resolution, "no" (0) don\*(Aqt ever use DNSOverTls\&. If unspecified "default" depends on the plugin used\&. Systemd\-resolved uses global setting\&. This feature requires a plugin which supports DNSOverTls\&. Otherwise, the setting has no effect\&. One such plugin is dns\-systemd\-resolved\&.
+.sp
+Format: int32
+.RE
+.PP
 \fBgateway\-ping\-timeout\fR
 .RS 4
 If greater than zero, delay success of IP addressing until either the timeout is reached, or an IP gateway replies to a ping\&.
@@ -1031,7 +1038,7 @@ Format: NMSettingDcbFlags (uint32)
 .PP
 \fBapp\-fcoe\-mode\fR
 .RS 4
-The FCoE controller mode; either "fabric" (default) or "vn2vn"\&.
+The FCoE controller mode; either "fabric" or "vn2vn"\&. Since 1\&.34, NULL is the default and means "fabric"\&. Before 1\&.34, NULL was rejected as invalid and the default was "fabric"\&.
 .sp
 Format: string
 .RE
@@ -2732,16 +2739,189 @@ Properties:
 .PP
 \fBqdiscs\fR
 .RS 4
-Array of TC queueing disciplines\&. When the "tc" setting is present, qdiscs from this property are applied upon activation\&. If the property is empty, all qdiscs are removed and the device will only have the default qdisc assigned by kernel according to the "net\&.core\&.default_qdisc" sysctl\&. If the "tc" setting is not present, NetworkManager doesn\*(Aqt touch the qdiscs present on the interface\&.
+Array of TC queueing disciplines\&. qdisc is a basic block in the Linux traffic control subsystem
 .sp
-Format: array of vardict
+Each qdisc can be specified by the following attributes:
+.PP
+\fIhandle HANDLE\fR
+.RS 4
+specifies the qdisc handle\&. A qdisc, which potentially can have children, gets assigned a major number, called a \*(Aqhandle\*(Aq, leaving the minor number namespace available for classes\&. The handle is expressed as \*(Aq10:\*(Aq\&. It is customary to explicitly assign a handle to qdiscs expected to have children\&.
+.RE
+.PP
+\fIparent HANDLE\fR
+.RS 4
+specifies the handle of the parent qdisc the current qdisc must be attached to\&.
+.RE
+.PP
+\fIroot\fR
+.RS 4
+specifies that the qdisc is attached to the root of device\&.
+.RE
+.PP
+\fIKIND\fR
+.RS 4
+this is the qdisc kind\&. NetworkManager currently supports the following kinds: fq_codel, sfq, tbf\&. Each qdisc kind has a different set of parameters, described below\&. There are also some kinds like pfifo, pfifo_fast, prio supported by NetworkManager but their parameters are not supported by NetworkManager\&.
+.RE
+.sp
+Parameters for \*(Aqfq_codel\*(Aq:
+.PP
+\fIlimit U32\fR
+.RS 4
+the hard limit on the real queue size\&. When this limit is reached, incoming packets are dropped\&. Default is 10240 packets\&.
+.RE
+.PP
+\fImemory_limit U32\fR
+.RS 4
+sets a limit on the total number of bytes that can be queued in this FQ\-CoDel instance\&. The lower of the packet limit of the limit parameter and the memory limit will be enforced\&. Default is 32 MB\&.
+.RE
+.PP
+\fIflows U32\fR
+.RS 4
+the number of flows into which the incoming packets are classified\&. Due to the stochastic nature of hashing, multiple flows may end up being hashed into the same slot\&. Newer flows have priority over older ones\&. This parameter can be set only at load time since memory has to be allocated for the hash table\&. Default value is 1024\&.
+.RE
+.PP
+\fItarget U32\fR
+.RS 4
+the acceptable minimum standing/persistent queue delay\&. This minimum delay is identified by tracking the local minimum queue delay that packets experience\&. The unit of measurement is microsecond(us)\&. Default value is 5ms\&.
+.RE
+.PP
+\fIinterval U32\fR
+.RS 4
+used to ensure that the measured minimum delay does not become too stale\&. The minimum delay must be experienced in the last epoch of length \&.B interval\&. It should be set on the order of the worst\-case RTT through the bottleneck to give endpoints sufficient time to react\&. Default value is 100ms\&.
+.RE
+.PP
+\fIquantum U32\fR
+.RS 4
+the number of bytes used as \*(Aqdeficit\*(Aq in the fair queuing algorithm\&. Default is set to 1514 bytes which corresponds to the Ethernet MTU plus the hardware header length of 14 bytes\&.
+.RE
+.PP
+\fIecn BOOL\fR
+.RS 4
+can be used to mark packets instead of dropping them\&. ecn is turned on by default\&.
+.RE
+.PP
+\fIce_threshold U32\fR
+.RS 4
+sets a threshold above which all packets are marked with ECN Congestion Experienced\&. This is useful for DCTCP\-style congestion control algorithms that require marking at very shallow queueing thresholds\&.
+.RE
+.sp
+Parameters for \*(Aqsfq\*(Aq:
+.PP
+\fIdivisor U32\fR
+.RS 4
+can be used to set a different hash table size, available from kernel 2\&.6\&.39 onwards\&. The specified divisor must be a power of two and cannot be larger than 65536\&. Default value: 1024\&.
+.RE
+.PP
+\fIlimit U32\fR
+.RS 4
+Upper limit of the SFQ\&. Can be used to reduce the default length of 127 packets\&.
+.RE
+.PP
+\fIdepth U32\fR
+.RS 4
+Limit of packets per flow\&. Default to 127 and can be lowered\&.
+.RE
+.PP
+\fIperturb_period U32\fR
+.RS 4
+Interval in seconds for queue algorithm perturbation\&. Defaults to 0, which means that no perturbation occurs\&. Do not set too low for each perturbation may cause some packet reordering or losses\&. Advised value: 60 This value has no effect when external flow classification is used\&. Its better to increase divisor value to lower risk of hash collisions\&.
+.RE
+.PP
+\fIquantum U32\fR
+.RS 4
+Amount of bytes a flow is allowed to dequeue during a round of the round robin process\&. Defaults to the MTU of the interface which is also the advised value and the minimum value\&.
+.RE
+.PP
+\fIflows U32\fR
+.RS 4
+Default value is 127\&.
+.RE
+.sp
+Parameters for \*(Aqtbf\*(Aq:
+.PP
+\fIrate U64\fR
+.RS 4
+Bandwidth or rate\&. These parameters accept a floating point number, possibly followed by either a unit (both SI and IEC units supported), or a float followed by a percent character to specify the rate as a percentage of the device\*(Aqs speed\&.
+.RE
+.PP
+\fIburst U32\fR
+.RS 4
+Also known as buffer or maxburst\&. Size of the bucket, in bytes\&. This is the maximum amount of bytes that tokens can be available for instantaneously\&. In general, larger shaping rates require a larger buffer\&. For 10mbit/s on Intel, you need at least 10kbyte buffer if you want to reach your configured rate!
+.sp
+If your buffer is too small, packets may be dropped because more tokens arrive per timer tick than fit in your bucket\&. The minimum buffer size can be calculated by dividing the rate by HZ\&.
+.sp
+Token usage calculations are performed using a table which by default has a resolution of 8 packets\&. This resolution can be changed by specifying the cell size with the burst\&. For example, to specify a 6000 byte buffer with a 16 byte cell size, set a burst of 6000/16\&. You will probably never have to set this\&. Must be an integral power of 2\&.
+.RE
+.PP
+\fIlimit U32\fR
+.RS 4
+Limit is the number of bytes that can be queued waiting for tokens to become available\&.
+.RE
+.PP
+\fIlatency U32\fR
+.RS 4
+specifies the maximum amount of time a packet can sit in the TBF\&. The latency calculation takes into account the size of the bucket, the rate and possibly the peakrate (if set)\&. The latency and limit are mutually exclusive\&.
+.RE
+.sp
+Format: GPtrArray(NMTCQdisc)
 .RE
 .PP
 \fBtfilters\fR
 .RS 4
-Array of TC traffic filters\&. When the "tc" setting is present, filters from this property are applied upon activation\&. If the property is empty, NetworkManager removes all the filters\&. If the "tc" setting is not present, NetworkManager doesn\*(Aqt touch the filters present on the interface\&.
+Array of TC traffic filters\&. Traffic control can manage the packet content during classification by using filters\&.
 .sp
-Format: array of vardict
+Each tfilters can be specified by the following attributes:
+.PP
+\fIhandle HANDLE\fR
+.RS 4
+specifies the tfilters handle\&. A filter is used by a classful qdisc to determine in which class a packet will be enqueued\&. It is important to notice that filters reside within qdiscs\&. Therefore, see qdiscs handle for detailed information\&.
+.RE
+.PP
+\fIparent HANDLE\fR
+.RS 4
+specifies the handle of the parent qdisc the current qdisc must be attached to\&.
+.RE
+.PP
+\fIroot\fR
+.RS 4
+specifies that the qdisc is attached to the root of device\&.
+.RE
+.PP
+\fIKIND\fR
+.RS 4
+this is the tfilters kind\&. NetworkManager currently supports following kinds: mirred, simple\&. Each filter kind has a different set of actions, described below\&. There are also some other kinds like matchall, basic, u32 supported by NetworkManager\&.
+.RE
+.sp
+Actions for \*(Aqmirred\*(Aq:
+.PP
+\fIegress bool\fR
+.RS 4
+Define whether the packet should exit from the interface\&.
+.RE
+.PP
+\fIingress bool\fR
+.RS 4
+Define whether the packet should come into the interface\&.
+.RE
+.PP
+\fImirror bool\fR
+.RS 4
+Define whether the packet should be copied to the destination space\&.
+.RE
+.PP
+\fIredirect bool\fR
+.RS 4
+Define whether the packet should be moved to the destination space\&.
+.RE
+.sp
+Action for \*(Aqsimple\*(Aq:
+.PP
+\fIsdata char[32]\fR
+.RS 4
+The actual string to print\&.
+.RE
+.sp
+Format: GPtrArray(NMTCTfilter)
 .RE
 .SS "team setting"
 .PP
@@ -3360,7 +3540,7 @@ Format: string
 .PP
 \fBs390\-options\fR
 .RS 4
-Dictionary of key/value pairs of s390\-specific device options\&. Both keys and values must be strings\&. Allowed keys include "portno", "layer2", "portname", "protocol", among others\&. Key names must contain only alphanumeric characters (ie, [a\-zA\-Z0\-9])\&.
+Dictionary of key/value pairs of s390\-specific device options\&. Both keys and values must be strings\&. Allowed keys include "portno", "layer2", "portname", "protocol", among others\&. Key names must contain only alphanumeric characters (ie, [a\-zA\-Z0\-9])\&. Currently, NetworkManager itself does nothing with this information\&. However, s390utils ships a udev rule which parses this information and applies it to the interface\&.
 .sp
 Format: dict of string to string
 .RE
@@ -3801,6 +3981,20 @@ Short IEEE 802\&.15\&.4 address to be used within a restricted environment\&.
 .sp
 Format: uint32
 .RE
+.SS "bond\-port setting"
+.PP
+Bond Port Settings\&.
+.PP
+Properties:
+.PP
+\fBqueue\-id\fR
+.RS 4
+Alias: queue\-id
+.sp
+The queue ID of this bond port\&. The maximum value of queue ID is the number of TX queues currently active in device\&.
+.sp
+Format: uint32
+.RE
 .SS "hostname setting"
 .PP
 Hostname settings\&.