about summary refs log tree commit diff
path: root/man
diff options
context:
space:
mode:
authorMichael Biebl <biebl@debian.org>2022-12-18 21:31:39 +0100
committerMichael Biebl <biebl@debian.org>2022-12-18 21:31:39 +0100
commit2965dc70bb3cbfa8de2f279761812b84b87600cb (patch)
tree90d4a861f7cd7a05834e7328af7677e7c8acd17f /man
parent6e9d10e114f94799d54bb3dabc66e35ab4e3e8cd (diff)
New upstream version 1.40.8 upstream/1.40.8
Diffstat (limited to 'man')
-rw-r--r--man/NetworkManager-dispatcher.84
-rw-r--r--man/NetworkManager-wait-online.service.84
-rw-r--r--man/NetworkManager.86
-rw-r--r--man/NetworkManager.conf.56
-rw-r--r--man/nm-cloud-setup.86
-rw-r--r--man/nm-initrd-generator.86
-rw-r--r--man/nm-online.16
-rw-r--r--man/nm-openvswitch.76
-rw-r--r--man/nm-settings-dbus.510
-rw-r--r--man/nm-settings-dbus.xml4
-rw-r--r--man/nm-settings-docs-dbus.xml2
-rw-r--r--man/nm-settings-docs-nmcli.xml2
-rw-r--r--man/nm-settings-ifcfg-rh.56
-rw-r--r--man/nm-settings-ifcfg-rh.xml2
-rw-r--r--man/nm-settings-keyfile.56
-rw-r--r--man/nm-settings-keyfile.xml2
-rw-r--r--man/nm-settings-nmcli.510
-rw-r--r--man/nm-settings-nmcli.xml6
-rw-r--r--man/nmcli-examples.76
-rw-r--r--man/nmcli.16
-rw-r--r--man/nmtui.16
21 files changed, 56 insertions, 56 deletions
diff --git a/man/NetworkManager-dispatcher.8 b/man/NetworkManager-dispatcher.8
index d3f63517..ba14b58a 100644
--- a/man/NetworkManager-dispatcher.8
+++ b/man/NetworkManager-dispatcher.8
@@ -2,9 +2,9 @@
 .\"     Title: NetworkManager-dispatcher
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: Network management daemons
-.\"    Source: NetworkManager-dispatcher 1.40.6
+.\"    Source: NetworkManager-dispatcher 1.40.8
 .\"  Language: English
 .\"
 .TH "NETWORKMANAGER\-DISPATCHER" "8" "" "NetworkManager\-dispatcher 1\&" "Network management daemons"
diff --git a/man/NetworkManager-wait-online.service.8 b/man/NetworkManager-wait-online.service.8
index d9f16857..bfe4c230 100644
--- a/man/NetworkManager-wait-online.service.8
+++ b/man/NetworkManager-wait-online.service.8
@@ -2,9 +2,9 @@
 .\"     Title: NetworkManager-wait-online.service
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: Network management daemons
-.\"    Source: NetworkManager-wait-online.service 1.40.6
+.\"    Source: NetworkManager-wait-online.service 1.40.8
 .\"  Language: English
 .\"
 .TH "NETWORKMANAGER\-WAIT\-ONLINE\&" "8" "" "NetworkManager\-wait\-online\&" "Network management daemons"
diff --git a/man/NetworkManager.8 b/man/NetworkManager.8
index f2ab69e6..b102b9c4 100644
--- a/man/NetworkManager.8
+++ b/man/NetworkManager.8
@@ -2,12 +2,12 @@
 .\"     Title: NetworkManager
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: Network management daemons
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NETWORKMANAGER" "8" "" "NetworkManager 1\&.40\&.6" "Network management daemons"
+.TH "NETWORKMANAGER" "8" "" "NetworkManager 1\&.40\&.8" "Network management daemons"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
diff --git a/man/NetworkManager.conf.5 b/man/NetworkManager.conf.5
index 3373214a..8d092163 100644
--- a/man/NetworkManager.conf.5
+++ b/man/NetworkManager.conf.5
@@ -2,12 +2,12 @@
 .\"     Title: NetworkManager.conf
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: Configuration
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NETWORKMANAGER\&.CONF" "5" "" "NetworkManager 1\&.40\&.6" "Configuration"
+.TH "NETWORKMANAGER\&.CONF" "5" "" "NetworkManager 1\&.40\&.8" "Configuration"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
diff --git a/man/nm-cloud-setup.8 b/man/nm-cloud-setup.8
index a750efaa..6e034264 100644
--- a/man/nm-cloud-setup.8
+++ b/man/nm-cloud-setup.8
@@ -2,12 +2,12 @@
 .\"     Title: nm-cloud-setup
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: Automatic Network Configuration in Cloud with NetworkManager
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NM\-CLOUD\-SETUP" "8" "" "NetworkManager 1\&.40\&.6" "Automatic Network Configuratio"
+.TH "NM\-CLOUD\-SETUP" "8" "" "NetworkManager 1\&.40\&.8" "Automatic Network Configuratio"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
diff --git a/man/nm-initrd-generator.8 b/man/nm-initrd-generator.8
index f3b45def..f62e4732 100644
--- a/man/nm-initrd-generator.8
+++ b/man/nm-initrd-generator.8
@@ -2,12 +2,12 @@
 .\"     Title: nm-initrd-generator
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: System Administration
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NM\-INITRD\-GENERATOR" "8" "" "NetworkManager 1\&.40\&.6" "System Administration"
+.TH "NM\-INITRD\-GENERATOR" "8" "" "NetworkManager 1\&.40\&.8" "System Administration"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
diff --git a/man/nm-online.1 b/man/nm-online.1
index 03bb9cfb..6e554414 100644
--- a/man/nm-online.1
+++ b/man/nm-online.1
@@ -2,12 +2,12 @@
 .\"     Title: nm-online
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: General Commands Manual
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NM\-ONLINE" "1" "" "NetworkManager 1\&.40\&.6" "General Commands Manual"
+.TH "NM\-ONLINE" "1" "" "NetworkManager 1\&.40\&.8" "General Commands Manual"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
diff --git a/man/nm-openvswitch.7 b/man/nm-openvswitch.7
index 73ea2a99..b6f9fba8 100644
--- a/man/nm-openvswitch.7
+++ b/man/nm-openvswitch.7
@@ -2,12 +2,12 @@
 .\"     Title: nm-openvswitch
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: Open vSwitch support overview
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NM\-OPENVSWITCH" "7" "" "NetworkManager 1\&.40\&.6" "Open vSwitch support overview"
+.TH "NM\-OPENVSWITCH" "7" "" "NetworkManager 1\&.40\&.8" "Open vSwitch support overview"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
diff --git a/man/nm-settings-dbus.5 b/man/nm-settings-dbus.5
index 57bcba96..5f38dc88 100644
--- a/man/nm-settings-dbus.5
+++ b/man/nm-settings-dbus.5
@@ -2,12 +2,12 @@
 .\"     Title: nm-settings-dbus
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: Configuration
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NM\-SETTINGS\-DBUS" "5" "" "NetworkManager 1\&.40\&.6" "Configuration"
+.TH "NM\-SETTINGS\-DBUS" "5" "" "NetworkManager 1\&.40\&.8" "Configuration"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
@@ -2990,7 +2990,7 @@ string
 T}:T{
 \ \&
 T}:T{
-The pre\-shared CAK (Connectivity Association Key) for MACsec Key Agreement\&.
+The pre\-shared CAK (Connectivity Association Key) for MACsec Key Agreement\&. Must be a string of 32 hexadecimal characters\&.
 T}
 T{
 mka\-cak\-flags
@@ -3008,7 +3008,7 @@ string
 T}:T{
 \ \&
 T}:T{
-The pre\-shared CKN (Connectivity\-association Key Name) for MACsec Key Agreement\&.
+The pre\-shared CKN (Connectivity\-association Key Name) for MACsec Key Agreement\&. Must be a string of hexadecimal characters with a even length between 2 and 64\&.
 T}
 T{
 mode
diff --git a/man/nm-settings-dbus.xml b/man/nm-settings-dbus.xml
index d02addff..bb56ea04 100644
--- a/man/nm-settings-dbus.xml
+++ b/man/nm-settings-dbus.xml
@@ -1,6 +1,6 @@
 <?xml version="1.0"?>
 <!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.3//EN" "http://www.oasis-open.org/docbook/xml/4.3/docbookx.dtd">
-<refentry id="nm-settings-dbus"><refentryinfo><title>nm-settings-dbus</title><author>NetworkManager developers</author></refentryinfo><refmeta><refentrytitle>nm-settings-dbus</refentrytitle><manvolnum>5</manvolnum><refmiscinfo class="source">NetworkManager</refmiscinfo><refmiscinfo class="manual">Configuration</refmiscinfo><refmiscinfo class="version">1.40.6</refmiscinfo></refmeta><refnamediv><refname>nm-settings-dbus</refname><refpurpose>Description of settings and properties of NetworkManager connection profiles on the D-Bus API</refpurpose></refnamediv><refsect1 id="description"><title>Description</title><para>
+<refentry id="nm-settings-dbus"><refentryinfo><title>nm-settings-dbus</title><author>NetworkManager developers</author></refentryinfo><refmeta><refentrytitle>nm-settings-dbus</refentrytitle><manvolnum>5</manvolnum><refmiscinfo class="source">NetworkManager</refmiscinfo><refmiscinfo class="manual">Configuration</refmiscinfo><refmiscinfo class="version">1.40.8</refmiscinfo></refmeta><refnamediv><refname>nm-settings-dbus</refname><refpurpose>Description of settings and properties of NetworkManager connection profiles on the D-Bus API</refpurpose></refnamediv><refsect1 id="description"><title>Description</title><para>
           NetworkManager is based on a concept of connection profiles, sometimes referred to as
           connections only. These connection profiles contain a network configuration. When
           NetworkManager activates a connection profile on a network device the configuration will
@@ -306,7 +306,7 @@
 
  If the table setting is left at zero, it is eligible to be overwritten via global configuration. If the property is zero even after applying the global configuration value, policy routing is disabled for the address family of this connection.
 
- Policy routing disabled means that NetworkManager will add all routes to the main table (except static routes that explicitly configure a different table). Additionally, NetworkManager will not delete any extraneous routes from tables except the main table. This is to preserve backward compatibility for users who manage routing tables outside of NetworkManager.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ipv6.routes">routes</entry><entry align="left">array of legacy IPv6 route struct (a(ayuayu))</entry><entry align="left"/><entry>Deprecated in favor of the 'route-data' property, but this can be used for backward-compatibility with older daemons. Note that if you send this property the daemon will ignore 'route-data'.  Array of IPv6 route structures.  Each IPv6 route structure is composed of an IPv6 address, a prefix length (0 - 128), an IPv6 next hop address (which may be zeroed out if there is no next hop), and a metric. If the metric is 0, NM will choose an appropriate default metric for the device.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ipv6.token">token</entry><entry align="left">string</entry><entry align="left"/><entry> Configure the token for draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 tokenized interface identifiers. Useful with eui64 addr-gen-mode.</entry></row></tbody></tgroup></informaltable></refsect2><refsect2><title>ip-tunnel setting</title><para> IP Tunneling Settings.</para><informaltable><tgroup cols="4"><thead><row><entry>Key Name</entry><entry>Value Type</entry><entry>Default Value</entry><entry>Value Description</entry></row></thead><tbody><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.encapsulation-limit">encapsulation-limit</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> How many additional levels of encapsulation are permitted to be prepended to packets. This property applies only to IPv6 tunnels.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.flags">flags</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> Tunnel flags. Currently, the following values are supported: NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4), NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8), NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20). They are valid only for IPv6 tunnels.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.flow-label">flow-label</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> The flow label to assign to tunnel packets. This property applies only to IPv6 tunnels.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.input-key">input-key</entry><entry align="left">string</entry><entry align="left"/><entry> The key used for tunnel input packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.local">local</entry><entry align="left">string</entry><entry align="left"/><entry> The local endpoint of the tunnel; the value can be empty, otherwise it must contain an IPv4 or IPv6 address.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.mode">mode</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> The tunneling mode, for example NM_IP_TUNNEL_MODE_IPIP (1) or NM_IP_TUNNEL_MODE_GRE (2).</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.mtu">mtu</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.output-key">output-key</entry><entry align="left">string</entry><entry align="left"/><entry> The key used for tunnel output packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.parent">parent</entry><entry align="left">string</entry><entry align="left"/><entry> If given, specifies the parent interface name or parent connection UUID the new device will be bound to so that tunneled packets will only be routed via that interface.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.path-mtu-discovery">path-mtu-discovery</entry><entry align="left">boolean</entry><entry align="left">TRUE</entry><entry> Whether to enable Path MTU Discovery on this tunnel.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.remote">remote</entry><entry align="left">string</entry><entry align="left"/><entry> The remote endpoint of the tunnel; the value must contain an IPv4 or IPv6 address.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.tos">tos</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> The type of service (IPv4) or traffic class (IPv6) field to be set on tunneled packets.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.ttl">ttl</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> The TTL to assign to tunneled packets. 0 is a special value meaning that packets inherit the TTL value.</entry></row></tbody></tgroup></informaltable></refsect2><refsect2><title>macsec setting</title><para> MACSec Settings.</para><informaltable><tgroup cols="4"><thead><row><entry>Key Name</entry><entry>Value Type</entry><entry>Default Value</entry><entry>Value Description</entry></row></thead><tbody><row><entry align="left" id="nm-settings-dbus.property.macsec.encrypt">encrypt</entry><entry align="left">boolean</entry><entry align="left">TRUE</entry><entry> Whether the transmitted traffic must be encrypted.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.mka-cak">mka-cak</entry><entry align="left">string</entry><entry align="left"/><entry> The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.mka-cak-flags">mka-cak-flags</entry><entry align="left">NMSettingSecretFlags (uint32)</entry><entry align="left"/><entry> Flags indicating how to handle the "mka-cak" property.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.mka-ckn">mka-ckn</entry><entry align="left">string</entry><entry align="left"/><entry> The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.mode">mode</entry><entry align="left">int32</entry><entry align="left">0</entry><entry> Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.parent">parent</entry><entry align="left">string</entry><entry align="left"/><entry> If given, specifies the parent interface name or parent connection UUID from which this MACSEC interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.port">port</entry><entry align="left">int32</entry><entry align="left">1</entry><entry> The port component of the SCI (Secure Channel Identifier), between 1 and 65534.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.send-sci">send-sci</entry><entry align="left">boolean</entry><entry align="left">TRUE</entry><entry> Specifies whether the SCI (Secure Channel Identifier) is included in every packet.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.validation">validation</entry><entry align="left">int32</entry><entry align="left">2</entry><entry> Specifies the validation mode for incoming frames.</entry></row></tbody></tgroup></informaltable></refsect2><refsect2><title>macvlan setting</title><para> MAC VLAN Settings.</para><informaltable><tgroup cols="4"><thead><row><entry>Key Name</entry><entry>Value Type</entry><entry>Default Value</entry><entry>Value Description</entry></row></thead><tbody><row><entry align="left" id="nm-settings-dbus.property.macvlan.mode">mode</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> The macvlan mode, which specifies the communication mechanism between multiple macvlans on the same lower device.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macvlan.parent">parent</entry><entry align="left">string</entry><entry align="left"/><entry> If given, specifies the parent interface name or parent connection UUID from which this MAC-VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macvlan.promiscuous">promiscuous</entry><entry align="left">boolean</entry><entry align="left">TRUE</entry><entry> Whether the interface should be put in promiscuous mode.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macvlan.tap">tap</entry><entry align="left">boolean</entry><entry align="left">FALSE</entry><entry> Whether the interface should be a MACVTAP.</entry></row></tbody></tgroup></informaltable></refsect2><refsect2><title>match setting</title><para> Match settings.</para><informaltable><tgroup cols="4"><thead><row><entry>Key Name</entry><entry>Value Type</entry><entry>Default Value</entry><entry>Value Description</entry></row></thead><tbody><row><entry align="left" id="nm-settings-dbus.property.match.driver">driver</entry><entry align="left">array of string</entry><entry align="left"/><entry> A list of driver names to match. Each element is a shell wildcard pattern.
+ Policy routing disabled means that NetworkManager will add all routes to the main table (except static routes that explicitly configure a different table). Additionally, NetworkManager will not delete any extraneous routes from tables except the main table. This is to preserve backward compatibility for users who manage routing tables outside of NetworkManager.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ipv6.routes">routes</entry><entry align="left">array of legacy IPv6 route struct (a(ayuayu))</entry><entry align="left"/><entry>Deprecated in favor of the 'route-data' property, but this can be used for backward-compatibility with older daemons. Note that if you send this property the daemon will ignore 'route-data'.  Array of IPv6 route structures.  Each IPv6 route structure is composed of an IPv6 address, a prefix length (0 - 128), an IPv6 next hop address (which may be zeroed out if there is no next hop), and a metric. If the metric is 0, NM will choose an appropriate default metric for the device.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ipv6.token">token</entry><entry align="left">string</entry><entry align="left"/><entry> Configure the token for draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 tokenized interface identifiers. Useful with eui64 addr-gen-mode.</entry></row></tbody></tgroup></informaltable></refsect2><refsect2><title>ip-tunnel setting</title><para> IP Tunneling Settings.</para><informaltable><tgroup cols="4"><thead><row><entry>Key Name</entry><entry>Value Type</entry><entry>Default Value</entry><entry>Value Description</entry></row></thead><tbody><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.encapsulation-limit">encapsulation-limit</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> How many additional levels of encapsulation are permitted to be prepended to packets. This property applies only to IPv6 tunnels.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.flags">flags</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> Tunnel flags. Currently, the following values are supported: NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4), NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8), NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20). They are valid only for IPv6 tunnels.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.flow-label">flow-label</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> The flow label to assign to tunnel packets. This property applies only to IPv6 tunnels.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.input-key">input-key</entry><entry align="left">string</entry><entry align="left"/><entry> The key used for tunnel input packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.local">local</entry><entry align="left">string</entry><entry align="left"/><entry> The local endpoint of the tunnel; the value can be empty, otherwise it must contain an IPv4 or IPv6 address.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.mode">mode</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> The tunneling mode, for example NM_IP_TUNNEL_MODE_IPIP (1) or NM_IP_TUNNEL_MODE_GRE (2).</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.mtu">mtu</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.output-key">output-key</entry><entry align="left">string</entry><entry align="left"/><entry> The key used for tunnel output packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.parent">parent</entry><entry align="left">string</entry><entry align="left"/><entry> If given, specifies the parent interface name or parent connection UUID the new device will be bound to so that tunneled packets will only be routed via that interface.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.path-mtu-discovery">path-mtu-discovery</entry><entry align="left">boolean</entry><entry align="left">TRUE</entry><entry> Whether to enable Path MTU Discovery on this tunnel.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.remote">remote</entry><entry align="left">string</entry><entry align="left"/><entry> The remote endpoint of the tunnel; the value must contain an IPv4 or IPv6 address.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.tos">tos</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> The type of service (IPv4) or traffic class (IPv6) field to be set on tunneled packets.</entry></row><row><entry align="left" id="nm-settings-dbus.property.ip-tunnel.ttl">ttl</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> The TTL to assign to tunneled packets. 0 is a special value meaning that packets inherit the TTL value.</entry></row></tbody></tgroup></informaltable></refsect2><refsect2><title>macsec setting</title><para> MACSec Settings.</para><informaltable><tgroup cols="4"><thead><row><entry>Key Name</entry><entry>Value Type</entry><entry>Default Value</entry><entry>Value Description</entry></row></thead><tbody><row><entry align="left" id="nm-settings-dbus.property.macsec.encrypt">encrypt</entry><entry align="left">boolean</entry><entry align="left">TRUE</entry><entry> Whether the transmitted traffic must be encrypted.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.mka-cak">mka-cak</entry><entry align="left">string</entry><entry align="left"/><entry> The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement. Must be a string of 32 hexadecimal characters.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.mka-cak-flags">mka-cak-flags</entry><entry align="left">NMSettingSecretFlags (uint32)</entry><entry align="left"/><entry> Flags indicating how to handle the "mka-cak" property.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.mka-ckn">mka-ckn</entry><entry align="left">string</entry><entry align="left"/><entry> The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement. Must be a string of hexadecimal characters with a even length between 2 and 64.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.mode">mode</entry><entry align="left">int32</entry><entry align="left">0</entry><entry> Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.parent">parent</entry><entry align="left">string</entry><entry align="left"/><entry> If given, specifies the parent interface name or parent connection UUID from which this MACSEC interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.port">port</entry><entry align="left">int32</entry><entry align="left">1</entry><entry> The port component of the SCI (Secure Channel Identifier), between 1 and 65534.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.send-sci">send-sci</entry><entry align="left">boolean</entry><entry align="left">TRUE</entry><entry> Specifies whether the SCI (Secure Channel Identifier) is included in every packet.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macsec.validation">validation</entry><entry align="left">int32</entry><entry align="left">2</entry><entry> Specifies the validation mode for incoming frames.</entry></row></tbody></tgroup></informaltable></refsect2><refsect2><title>macvlan setting</title><para> MAC VLAN Settings.</para><informaltable><tgroup cols="4"><thead><row><entry>Key Name</entry><entry>Value Type</entry><entry>Default Value</entry><entry>Value Description</entry></row></thead><tbody><row><entry align="left" id="nm-settings-dbus.property.macvlan.mode">mode</entry><entry align="left">uint32</entry><entry align="left">0</entry><entry> The macvlan mode, which specifies the communication mechanism between multiple macvlans on the same lower device.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macvlan.parent">parent</entry><entry align="left">string</entry><entry align="left"/><entry> If given, specifies the parent interface name or parent connection UUID from which this MAC-VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macvlan.promiscuous">promiscuous</entry><entry align="left">boolean</entry><entry align="left">TRUE</entry><entry> Whether the interface should be put in promiscuous mode.</entry></row><row><entry align="left" id="nm-settings-dbus.property.macvlan.tap">tap</entry><entry align="left">boolean</entry><entry align="left">FALSE</entry><entry> Whether the interface should be a MACVTAP.</entry></row></tbody></tgroup></informaltable></refsect2><refsect2><title>match setting</title><para> Match settings.</para><informaltable><tgroup cols="4"><thead><row><entry>Key Name</entry><entry>Value Type</entry><entry>Default Value</entry><entry>Value Description</entry></row></thead><tbody><row><entry align="left" id="nm-settings-dbus.property.match.driver">driver</entry><entry align="left">array of string</entry><entry align="left"/><entry> A list of driver names to match. Each element is a shell wildcard pattern.
 
  See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\\' are used for optional and mandatory matches and inverting the pattern.</entry></row><row><entry align="left" id="nm-settings-dbus.property.match.interface-name">interface-name</entry><entry align="left">array of string</entry><entry align="left"/><entry> A list of interface names to match. Each element is a shell wildcard pattern.
 
diff --git a/man/nm-settings-docs-dbus.xml b/man/nm-settings-docs-dbus.xml
index 7158e86a..9b2273ee 100644
--- a/man/nm-settings-docs-dbus.xml
+++ b/man/nm-settings-docs-dbus.xml
@@ -272,7 +272,7 @@
 
  If the table setting is left at zero, it is eligible to be overwritten via global configuration. If the property is zero even after applying the global configuration value, policy routing is disabled for the address family of this connection.
 
- Policy routing disabled means that NetworkManager will add all routes to the main table (except static routes that explicitly configure a different table). Additionally, NetworkManager will not delete any extraneous routes from tables except the main table. This is to preserve backward compatibility for users who manage routing tables outside of NetworkManager.</description></property><property name="routes" name_upper="ROUTES" type="array of legacy IPv6 route struct (a(ayuayu))"><description-docbook><para> Array of IP routes.</para></description-docbook><description>Deprecated in favor of the 'route-data' property, but this can be used for backward-compatibility with older daemons. Note that if you send this property the daemon will ignore 'route-data'.  Array of IPv6 route structures.  Each IPv6 route structure is composed of an IPv6 address, a prefix length (0 - 128), an IPv6 next hop address (which may be zeroed out if there is no next hop), and a metric. If the metric is 0, NM will choose an appropriate default metric for the device.</description></property><property name="token" name_upper="TOKEN" type="string"><description-docbook><para> Configure the token for draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 tokenized interface identifiers. Useful with eui64 addr-gen-mode.</para></description-docbook><description> Configure the token for draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 tokenized interface identifiers. Useful with eui64 addr-gen-mode.</description></property></setting><setting name="ip-tunnel" description=" IP Tunneling Settings" name_upper="IP_TUNNEL"><property name="encapsulation-limit" name_upper="ENCAPSULATION_LIMIT" type="uint32" default="0"><description-docbook><para> How many additional levels of encapsulation are permitted to be prepended to packets. This property applies only to IPv6 tunnels.</para></description-docbook><description> How many additional levels of encapsulation are permitted to be prepended to packets. This property applies only to IPv6 tunnels.</description></property><property name="flags" name_upper="FLAGS" type="uint32" default="0"><description-docbook><para> Tunnel flags. Currently, the following values are supported: NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4), NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8), NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20). They are valid only for IPv6 tunnels.</para></description-docbook><description> Tunnel flags. Currently, the following values are supported: NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4), NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8), NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20). They are valid only for IPv6 tunnels.</description></property><property name="flow-label" name_upper="FLOW_LABEL" type="uint32" default="0"><description-docbook><para> The flow label to assign to tunnel packets. This property applies only to IPv6 tunnels.</para></description-docbook><description> The flow label to assign to tunnel packets. This property applies only to IPv6 tunnels.</description></property><property name="input-key" name_upper="INPUT_KEY" type="string"><description-docbook><para> The key used for tunnel input packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</para></description-docbook><description> The key used for tunnel input packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</description></property><property name="local" name_upper="LOCAL" type="string"><description-docbook><para> The local endpoint of the tunnel; the value can be empty, otherwise it must contain an IPv4 or IPv6 address.</para></description-docbook><description> The local endpoint of the tunnel; the value can be empty, otherwise it must contain an IPv4 or IPv6 address.</description></property><property name="mode" name_upper="MODE" type="uint32" default="0"><description-docbook><para> The tunneling mode, for example NM_IP_TUNNEL_MODE_IPIP (1) or NM_IP_TUNNEL_MODE_GRE (2).</para></description-docbook><description> The tunneling mode, for example NM_IP_TUNNEL_MODE_IPIP (1) or NM_IP_TUNNEL_MODE_GRE (2).</description></property><property name="mtu" name_upper="MTU" type="uint32" default="0"><description-docbook><para> If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments.</para></description-docbook><description> If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments.</description></property><property name="output-key" name_upper="OUTPUT_KEY" type="string"><description-docbook><para> The key used for tunnel output packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</para></description-docbook><description> The key used for tunnel output packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</description></property><property name="parent" name_upper="PARENT" type="string"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID the new device will be bound to so that tunneled packets will only be routed via that interface.</para></description-docbook><description> If given, specifies the parent interface name or parent connection UUID the new device will be bound to so that tunneled packets will only be routed via that interface.</description></property><property name="path-mtu-discovery" name_upper="PATH_MTU_DISCOVERY" type="boolean" default="TRUE"><description-docbook><para> Whether to enable Path MTU Discovery on this tunnel.</para></description-docbook><description> Whether to enable Path MTU Discovery on this tunnel.</description></property><property name="remote" name_upper="REMOTE" type="string"><description-docbook><para> The remote endpoint of the tunnel; the value must contain an IPv4 or IPv6 address.</para></description-docbook><description> The remote endpoint of the tunnel; the value must contain an IPv4 or IPv6 address.</description></property><property name="tos" name_upper="TOS" type="uint32" default="0"><description-docbook><para> The type of service (IPv4) or traffic class (IPv6) field to be set on tunneled packets.</para></description-docbook><description> The type of service (IPv4) or traffic class (IPv6) field to be set on tunneled packets.</description></property><property name="ttl" name_upper="TTL" type="uint32" default="0"><description-docbook><para> The TTL to assign to tunneled packets. 0 is a special value meaning that packets inherit the TTL value.</para></description-docbook><description> The TTL to assign to tunneled packets. 0 is a special value meaning that packets inherit the TTL value.</description></property></setting><setting name="macsec" description=" MACSec Settings" name_upper="MACSEC"><property name="encrypt" name_upper="ENCRYPT" type="boolean" default="TRUE"><description-docbook><para> Whether the transmitted traffic must be encrypted.</para></description-docbook><description> Whether the transmitted traffic must be encrypted.</description></property><property name="mka-cak" name_upper="MKA_CAK" type="string"><description-docbook><para> The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement.</para></description-docbook><description> The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement.</description></property><property name="mka-cak-flags" name_upper="MKA_CAK_FLAGS" type="NMSettingSecretFlags (uint32)"><description-docbook><para> Flags indicating how to handle the "mka-cak" property.</para></description-docbook><description> Flags indicating how to handle the "mka-cak" property.</description></property><property name="mka-ckn" name_upper="MKA_CKN" type="string"><description-docbook><para> The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement.</para></description-docbook><description> The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement.</description></property><property name="mode" name_upper="MODE" type="int32" default="0"><description-docbook><para> Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained.</para></description-docbook><description> Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained.</description></property><property name="parent" name_upper="PARENT" type="string"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID from which this MACSEC interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</para></description-docbook><description> If given, specifies the parent interface name or parent connection UUID from which this MACSEC interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</description></property><property name="port" name_upper="PORT" type="int32" default="1"><description-docbook><para> The port component of the SCI (Secure Channel Identifier), between 1 and 65534.</para></description-docbook><description> The port component of the SCI (Secure Channel Identifier), between 1 and 65534.</description></property><property name="send-sci" name_upper="SEND_SCI" type="boolean" default="TRUE"><description-docbook><para> Specifies whether the SCI (Secure Channel Identifier) is included in every packet.</para></description-docbook><description> Specifies whether the SCI (Secure Channel Identifier) is included in every packet.</description></property><property name="validation" name_upper="VALIDATION" type="int32" default="2"><description-docbook><para> Specifies the validation mode for incoming frames.</para></description-docbook><description> Specifies the validation mode for incoming frames.</description></property></setting><setting name="macvlan" description=" MAC VLAN Settings" name_upper="MACVLAN"><property name="mode" name_upper="MODE" type="uint32" default="0"><description-docbook><para> The macvlan mode, which specifies the communication mechanism between multiple macvlans on the same lower device.</para></description-docbook><description> The macvlan mode, which specifies the communication mechanism between multiple macvlans on the same lower device.</description></property><property name="parent" name_upper="PARENT" type="string"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID from which this MAC-VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</para></description-docbook><description> If given, specifies the parent interface name or parent connection UUID from which this MAC-VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</description></property><property name="promiscuous" name_upper="PROMISCUOUS" type="boolean" default="TRUE"><description-docbook><para> Whether the interface should be put in promiscuous mode.</para></description-docbook><description> Whether the interface should be put in promiscuous mode.</description></property><property name="tap" name_upper="TAP" type="boolean" default="FALSE"><description-docbook><para> Whether the interface should be a MACVTAP.</para></description-docbook><description> Whether the interface should be a MACVTAP.</description></property></setting><setting name="match" description=" Match settings" name_upper="MATCH"><property name="driver" name_upper="DRIVER" type="array of string"><description-docbook><para> A list of driver names to match. Each element is a shell wildcard pattern.</para><para> See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\\' are used for optional and mandatory matches and inverting the pattern.</para></description-docbook><description> A list of driver names to match. Each element is a shell wildcard pattern.
+ Policy routing disabled means that NetworkManager will add all routes to the main table (except static routes that explicitly configure a different table). Additionally, NetworkManager will not delete any extraneous routes from tables except the main table. This is to preserve backward compatibility for users who manage routing tables outside of NetworkManager.</description></property><property name="routes" name_upper="ROUTES" type="array of legacy IPv6 route struct (a(ayuayu))"><description-docbook><para> Array of IP routes.</para></description-docbook><description>Deprecated in favor of the 'route-data' property, but this can be used for backward-compatibility with older daemons. Note that if you send this property the daemon will ignore 'route-data'.  Array of IPv6 route structures.  Each IPv6 route structure is composed of an IPv6 address, a prefix length (0 - 128), an IPv6 next hop address (which may be zeroed out if there is no next hop), and a metric. If the metric is 0, NM will choose an appropriate default metric for the device.</description></property><property name="token" name_upper="TOKEN" type="string"><description-docbook><para> Configure the token for draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 tokenized interface identifiers. Useful with eui64 addr-gen-mode.</para></description-docbook><description> Configure the token for draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 tokenized interface identifiers. Useful with eui64 addr-gen-mode.</description></property></setting><setting name="ip-tunnel" description=" IP Tunneling Settings" name_upper="IP_TUNNEL"><property name="encapsulation-limit" name_upper="ENCAPSULATION_LIMIT" type="uint32" default="0"><description-docbook><para> How many additional levels of encapsulation are permitted to be prepended to packets. This property applies only to IPv6 tunnels.</para></description-docbook><description> How many additional levels of encapsulation are permitted to be prepended to packets. This property applies only to IPv6 tunnels.</description></property><property name="flags" name_upper="FLAGS" type="uint32" default="0"><description-docbook><para> Tunnel flags. Currently, the following values are supported: NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4), NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8), NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20). They are valid only for IPv6 tunnels.</para></description-docbook><description> Tunnel flags. Currently, the following values are supported: NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4), NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8), NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20). They are valid only for IPv6 tunnels.</description></property><property name="flow-label" name_upper="FLOW_LABEL" type="uint32" default="0"><description-docbook><para> The flow label to assign to tunnel packets. This property applies only to IPv6 tunnels.</para></description-docbook><description> The flow label to assign to tunnel packets. This property applies only to IPv6 tunnels.</description></property><property name="input-key" name_upper="INPUT_KEY" type="string"><description-docbook><para> The key used for tunnel input packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</para></description-docbook><description> The key used for tunnel input packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</description></property><property name="local" name_upper="LOCAL" type="string"><description-docbook><para> The local endpoint of the tunnel; the value can be empty, otherwise it must contain an IPv4 or IPv6 address.</para></description-docbook><description> The local endpoint of the tunnel; the value can be empty, otherwise it must contain an IPv4 or IPv6 address.</description></property><property name="mode" name_upper="MODE" type="uint32" default="0"><description-docbook><para> The tunneling mode, for example NM_IP_TUNNEL_MODE_IPIP (1) or NM_IP_TUNNEL_MODE_GRE (2).</para></description-docbook><description> The tunneling mode, for example NM_IP_TUNNEL_MODE_IPIP (1) or NM_IP_TUNNEL_MODE_GRE (2).</description></property><property name="mtu" name_upper="MTU" type="uint32" default="0"><description-docbook><para> If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments.</para></description-docbook><description> If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments.</description></property><property name="output-key" name_upper="OUTPUT_KEY" type="string"><description-docbook><para> The key used for tunnel output packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</para></description-docbook><description> The key used for tunnel output packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</description></property><property name="parent" name_upper="PARENT" type="string"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID the new device will be bound to so that tunneled packets will only be routed via that interface.</para></description-docbook><description> If given, specifies the parent interface name or parent connection UUID the new device will be bound to so that tunneled packets will only be routed via that interface.</description></property><property name="path-mtu-discovery" name_upper="PATH_MTU_DISCOVERY" type="boolean" default="TRUE"><description-docbook><para> Whether to enable Path MTU Discovery on this tunnel.</para></description-docbook><description> Whether to enable Path MTU Discovery on this tunnel.</description></property><property name="remote" name_upper="REMOTE" type="string"><description-docbook><para> The remote endpoint of the tunnel; the value must contain an IPv4 or IPv6 address.</para></description-docbook><description> The remote endpoint of the tunnel; the value must contain an IPv4 or IPv6 address.</description></property><property name="tos" name_upper="TOS" type="uint32" default="0"><description-docbook><para> The type of service (IPv4) or traffic class (IPv6) field to be set on tunneled packets.</para></description-docbook><description> The type of service (IPv4) or traffic class (IPv6) field to be set on tunneled packets.</description></property><property name="ttl" name_upper="TTL" type="uint32" default="0"><description-docbook><para> The TTL to assign to tunneled packets. 0 is a special value meaning that packets inherit the TTL value.</para></description-docbook><description> The TTL to assign to tunneled packets. 0 is a special value meaning that packets inherit the TTL value.</description></property></setting><setting name="macsec" description=" MACSec Settings" name_upper="MACSEC"><property name="encrypt" name_upper="ENCRYPT" type="boolean" default="TRUE"><description-docbook><para> Whether the transmitted traffic must be encrypted.</para></description-docbook><description> Whether the transmitted traffic must be encrypted.</description></property><property name="mka-cak" name_upper="MKA_CAK" type="string"><description-docbook><para> The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement. Must be a string of 32 hexadecimal characters.</para></description-docbook><description> The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement. Must be a string of 32 hexadecimal characters.</description></property><property name="mka-cak-flags" name_upper="MKA_CAK_FLAGS" type="NMSettingSecretFlags (uint32)"><description-docbook><para> Flags indicating how to handle the "mka-cak" property.</para></description-docbook><description> Flags indicating how to handle the "mka-cak" property.</description></property><property name="mka-ckn" name_upper="MKA_CKN" type="string"><description-docbook><para> The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement. Must be a string of hexadecimal characters with a even length between 2 and 64.</para></description-docbook><description> The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement. Must be a string of hexadecimal characters with a even length between 2 and 64.</description></property><property name="mode" name_upper="MODE" type="int32" default="0"><description-docbook><para> Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained.</para></description-docbook><description> Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained.</description></property><property name="parent" name_upper="PARENT" type="string"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID from which this MACSEC interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</para></description-docbook><description> If given, specifies the parent interface name or parent connection UUID from which this MACSEC interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</description></property><property name="port" name_upper="PORT" type="int32" default="1"><description-docbook><para> The port component of the SCI (Secure Channel Identifier), between 1 and 65534.</para></description-docbook><description> The port component of the SCI (Secure Channel Identifier), between 1 and 65534.</description></property><property name="send-sci" name_upper="SEND_SCI" type="boolean" default="TRUE"><description-docbook><para> Specifies whether the SCI (Secure Channel Identifier) is included in every packet.</para></description-docbook><description> Specifies whether the SCI (Secure Channel Identifier) is included in every packet.</description></property><property name="validation" name_upper="VALIDATION" type="int32" default="2"><description-docbook><para> Specifies the validation mode for incoming frames.</para></description-docbook><description> Specifies the validation mode for incoming frames.</description></property></setting><setting name="macvlan" description=" MAC VLAN Settings" name_upper="MACVLAN"><property name="mode" name_upper="MODE" type="uint32" default="0"><description-docbook><para> The macvlan mode, which specifies the communication mechanism between multiple macvlans on the same lower device.</para></description-docbook><description> The macvlan mode, which specifies the communication mechanism between multiple macvlans on the same lower device.</description></property><property name="parent" name_upper="PARENT" type="string"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID from which this MAC-VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</para></description-docbook><description> If given, specifies the parent interface name or parent connection UUID from which this MAC-VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</description></property><property name="promiscuous" name_upper="PROMISCUOUS" type="boolean" default="TRUE"><description-docbook><para> Whether the interface should be put in promiscuous mode.</para></description-docbook><description> Whether the interface should be put in promiscuous mode.</description></property><property name="tap" name_upper="TAP" type="boolean" default="FALSE"><description-docbook><para> Whether the interface should be a MACVTAP.</para></description-docbook><description> Whether the interface should be a MACVTAP.</description></property></setting><setting name="match" description=" Match settings" name_upper="MATCH"><property name="driver" name_upper="DRIVER" type="array of string"><description-docbook><para> A list of driver names to match. Each element is a shell wildcard pattern.</para><para> See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\\' are used for optional and mandatory matches and inverting the pattern.</para></description-docbook><description> A list of driver names to match. Each element is a shell wildcard pattern.
 
  See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\\' are used for optional and mandatory matches and inverting the pattern.</description></property><property name="interface-name" name_upper="INTERFACE_NAME" type="array of string"><description-docbook><para> A list of interface names to match. Each element is a shell wildcard pattern.</para><para> An element can be prefixed with a pipe symbol (|) or an ampersand (&amp;). The former means that the element is optional and the latter means that it is mandatory. If there are any optional elements, than the match evaluates to true if at least one of the optional element matches (logical OR). If there are any mandatory elements, then they all must match (logical AND). By default, an element is optional. This means that an element "foo" behaves the same as "|foo". An element can also be inverted with exclamation mark (!) between the pipe symbol (or the ampersand) and before the pattern. Note that "!foo" is a shortcut for the mandatory match "&amp;!foo". Finally, a backslash can be used at the beginning of the element (after the optional special characters) to escape the start of the pattern. For example, "&amp;\\!a" is an mandatory match for literally "!a".</para></description-docbook><description> A list of interface names to match. Each element is a shell wildcard pattern.
 
diff --git a/man/nm-settings-docs-nmcli.xml b/man/nm-settings-docs-nmcli.xml
index d2b7781c..7323d72b 100644
--- a/man/nm-settings-docs-nmcli.xml
+++ b/man/nm-settings-docs-nmcli.xml
@@ -166,7 +166,7 @@ fixed priority.
 </para>
 <para>
 Example: <literal>priority 5 from 1:2:3::5/128 table 45</literal>
-</para></description-docbook><description>A comma separated list of routing rules for policy routing.</description></property><property name="token" name_upper="TOKEN" type="string"><description-docbook><para> Configure the token for draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 tokenized interface identifiers. Useful with eui64 addr-gen-mode.</para></description-docbook><description>Configure the token for draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 tokenized interface identifiers. Useful with eui64 addr-gen-mode.</description></property></setting><setting name="ip-tunnel" description=" IP Tunneling Settings" name_upper="IP_TUNNEL"><property name="encapsulation-limit" name_upper="ENCAPSULATION_LIMIT" type="uint32" default="0"><description-docbook><para> How many additional levels of encapsulation are permitted to be prepended to packets. This property applies only to IPv6 tunnels.</para></description-docbook><description>How many additional levels of encapsulation are permitted to be prepended to packets. This property applies only to IPv6 tunnels.</description></property><property name="flags" name_upper="FLAGS" type="uint32" default="0"><description-docbook><para> Tunnel flags. Currently, the following values are supported: NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4), NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8), NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20). They are valid only for IPv6 tunnels.</para></description-docbook><description>Tunnel flags. Currently, the following values are supported: NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4), NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8), NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20). They are valid only for IPv6 tunnels.</description></property><property name="flow-label" name_upper="FLOW_LABEL" type="uint32" default="0"><description-docbook><para> The flow label to assign to tunnel packets. This property applies only to IPv6 tunnels.</para></description-docbook><description>The flow label to assign to tunnel packets. This property applies only to IPv6 tunnels.</description></property><property name="input-key" name_upper="INPUT_KEY" type="string"><description-docbook><para> The key used for tunnel input packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</para></description-docbook><description>The key used for tunnel input packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</description></property><property name="local" name_upper="LOCAL" type="string" alias="local"><description-docbook><para> The local endpoint of the tunnel; the value can be empty, otherwise it must contain an IPv4 or IPv6 address.</para></description-docbook><description>The local endpoint of the tunnel; the value can be empty, otherwise it must contain an IPv4 or IPv6 address.</description></property><property name="mode" name_upper="MODE" type="uint32" default="0" alias="mode"><description-docbook><para> The tunneling mode, for example NM_IP_TUNNEL_MODE_IPIP (1) or NM_IP_TUNNEL_MODE_GRE (2).</para></description-docbook><description>The tunneling mode, for example NM_IP_TUNNEL_MODE_IPIP (1) or NM_IP_TUNNEL_MODE_GRE (2).</description></property><property name="mtu" name_upper="MTU" type="uint32" default="0"><description-docbook><para> If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments.</para></description-docbook><description>If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments.</description></property><property name="output-key" name_upper="OUTPUT_KEY" type="string"><description-docbook><para> The key used for tunnel output packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</para></description-docbook><description>The key used for tunnel output packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</description></property><property name="parent" name_upper="PARENT" type="string" alias="dev"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID the new device will be bound to so that tunneled packets will only be routed via that interface.</para></description-docbook><description>If given, specifies the parent interface name or parent connection UUID the new device will be bound to so that tunneled packets will only be routed via that interface.</description></property><property name="path-mtu-discovery" name_upper="PATH_MTU_DISCOVERY" type="boolean" default="TRUE"><description-docbook><para> Whether to enable Path MTU Discovery on this tunnel.</para></description-docbook><description>Whether to enable Path MTU Discovery on this tunnel.</description></property><property name="remote" name_upper="REMOTE" type="string" alias="remote"><description-docbook><para> The remote endpoint of the tunnel; the value must contain an IPv4 or IPv6 address.</para></description-docbook><description>The remote endpoint of the tunnel; the value must contain an IPv4 or IPv6 address.</description></property><property name="tos" name_upper="TOS" type="uint32" default="0"><description-docbook><para> The type of service (IPv4) or traffic class (IPv6) field to be set on tunneled packets.</para></description-docbook><description>The type of service (IPv4) or traffic class (IPv6) field to be set on tunneled packets.</description></property><property name="ttl" name_upper="TTL" type="uint32" default="0"><description-docbook><para> The TTL to assign to tunneled packets. 0 is a special value meaning that packets inherit the TTL value.</para></description-docbook><description>The TTL to assign to tunneled packets. 0 is a special value meaning that packets inherit the TTL value.</description></property></setting><setting name="macsec" description=" MACSec Settings" name_upper="MACSEC"><property name="encrypt" name_upper="ENCRYPT" type="boolean" default="TRUE" alias="encrypt"><description-docbook><para> Whether the transmitted traffic must be encrypted.</para></description-docbook><description>Whether the transmitted traffic must be encrypted.</description></property><property name="mka-cak" name_upper="MKA_CAK" type="string" alias="cak"><description-docbook><para> The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement.</para></description-docbook><description>The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement.</description></property><property name="mka-cak-flags" name_upper="MKA_CAK_FLAGS" type="NMSettingSecretFlags (uint32)"><description-docbook><para> Flags indicating how to handle the "mka-cak" property.</para></description-docbook><description>Flags indicating how to handle the "mka-cak" property.</description></property><property name="mka-ckn" name_upper="MKA_CKN" type="string" alias="ckn"><description-docbook><para> The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement.</para></description-docbook><description>The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement.</description></property><property name="mode" name_upper="MODE" type="int32" default="0" alias="mode"><description-docbook><para> Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained.</para></description-docbook><description>Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained.</description></property><property name="parent" name_upper="PARENT" type="string" alias="dev"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID from which this MACSEC interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</para></description-docbook><description>If given, specifies the parent interface name or parent connection UUID from which this MACSEC interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</description></property><property name="port" name_upper="PORT" type="int32" default="1" alias="port"><description-docbook><para> The port component of the SCI (Secure Channel Identifier), between 1 and 65534.</para></description-docbook><description>The port component of the SCI (Secure Channel Identifier), between 1 and 65534.</description></property><property name="send-sci" name_upper="SEND_SCI" type="boolean" default="TRUE"><description-docbook><para> Specifies whether the SCI (Secure Channel Identifier) is included in every packet.</para></description-docbook><description>Specifies whether the SCI (Secure Channel Identifier) is included in every packet.</description></property><property name="validation" name_upper="VALIDATION" type="int32" default="2"><description-docbook><para> Specifies the validation mode for incoming frames.</para></description-docbook><description>Specifies the validation mode for incoming frames.</description></property></setting><setting name="macvlan" description=" MAC VLAN Settings" name_upper="MACVLAN"><property name="mode" name_upper="MODE" type="uint32" default="0" alias="mode"><description-docbook><para> The macvlan mode, which specifies the communication mechanism between multiple macvlans on the same lower device.</para></description-docbook><description>The macvlan mode, which specifies the communication mechanism between multiple macvlans on the same lower device.</description></property><property name="parent" name_upper="PARENT" type="string" alias="dev"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID from which this MAC-VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</para></description-docbook><description>If given, specifies the parent interface name or parent connection UUID from which this MAC-VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</description></property><property name="promiscuous" name_upper="PROMISCUOUS" type="boolean" default="TRUE"><description-docbook><para> Whether the interface should be put in promiscuous mode.</para></description-docbook><description>Whether the interface should be put in promiscuous mode.</description></property><property name="tap" name_upper="TAP" type="boolean" default="FALSE" alias="tap"><description-docbook><para> Whether the interface should be a MACVTAP.</para></description-docbook><description>Whether the interface should be a MACVTAP.</description></property></setting><setting name="match" description=" Match settings" name_upper="MATCH"><property name="driver" name_upper="DRIVER" type="array of string"><description-docbook><para> A list of driver names to match. Each element is a shell wildcard pattern.</para><para> See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\\' are used for optional and mandatory matches and inverting the pattern.</para></description-docbook><description>A list of driver names to match. Each element is a shell wildcard pattern. See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\' are used for optional and mandatory matches and inverting the pattern.</description></property><property name="interface-name" name_upper="INTERFACE_NAME" type="array of string"><description-docbook><para> A list of interface names to match. Each element is a shell wildcard pattern.</para><para> An element can be prefixed with a pipe symbol (|) or an ampersand (&amp;). The former means that the element is optional and the latter means that it is mandatory. If there are any optional elements, than the match evaluates to true if at least one of the optional element matches (logical OR). If there are any mandatory elements, then they all must match (logical AND). By default, an element is optional. This means that an element "foo" behaves the same as "|foo". An element can also be inverted with exclamation mark (!) between the pipe symbol (or the ampersand) and before the pattern. Note that "!foo" is a shortcut for the mandatory match "&amp;!foo". Finally, a backslash can be used at the beginning of the element (after the optional special characters) to escape the start of the pattern. For example, "&amp;\\!a" is an mandatory match for literally "!a".</para></description-docbook><description>A list of interface names to match. Each element is a shell wildcard pattern. An element can be prefixed with a pipe symbol (|) or an ampersand (&amp;). The former means that the element is optional and the latter means that it is mandatory. If there are any optional elements, than the match evaluates to true if at least one of the optional element matches (logical OR). If there are any mandatory elements, then they all must match (logical AND). By default, an element is optional. This means that an element "foo" behaves the same as "|foo". An element can also be inverted with exclamation mark (!) between the pipe symbol (or the ampersand) and before the pattern. Note that "!foo" is a shortcut for the mandatory match "&amp;!foo". Finally, a backslash can be used at the beginning of the element (after the optional special characters) to escape the start of the pattern. For example, "&amp;\!a" is an mandatory match for literally "!a".</description></property><property name="kernel-command-line" name_upper="KERNEL_COMMAND_LINE" type="array of string"><description-docbook><para> A list of kernel command line arguments to match. This may be used to check whether a specific kernel command line option is set (or unset, if prefixed with the exclamation mark). The argument must either be a single word, or an assignment (i.e. two words, joined by "="). In the former case the kernel command line is searched for the word appearing as is, or as left hand side of an assignment. In the latter case, the exact assignment is looked for with right and left hand side matching. Wildcard patterns are not supported.</para><para> See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\\' are used for optional and mandatory matches and inverting the match.</para></description-docbook><description>A list of kernel command line arguments to match. This may be used to check whether a specific kernel command line option is set (or unset, if prefixed with the exclamation mark). The argument must either be a single word, or an assignment (i.e. two words, joined by "="). In the former case the kernel command line is searched for the word appearing as is, or as left hand side of an assignment. In the latter case, the exact assignment is looked for with right and left hand side matching. Wildcard patterns are not supported. See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\' are used for optional and mandatory matches and inverting the match.</description></property><property name="path" name_upper="PATH" type="array of string"><description-docbook><para> A list of paths to match against the ID_PATH udev property of devices. ID_PATH represents the topological persistent path of a device. It typically contains a subsystem string (pci, usb, platform, etc.) and a subsystem-specific identifier.</para><para> For PCI devices the path has the form "pci-$domain:$bus:$device.$function", where each variable is an hexadecimal value; for example "pci-0000:0a:00.0".</para><para> The path of a device can be obtained with "udevadm info /sys/class/net/$dev | grep ID_PATH=" or by looking at the "path" property exported by NetworkManager ("nmcli -f general.path device show $dev").</para><para> Each element of the list is a shell wildcard pattern.</para><para> See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\\' are used for optional and mandatory matches and inverting the pattern.</para></description-docbook><description>A list of paths to match against the ID_PATH udev property of devices. ID_PATH represents the topological persistent path of a device. It typically contains a subsystem string (pci, usb, platform, etc.) and a subsystem-specific identifier. For PCI devices the path has the form "pci-$domain:$bus:$device.$function", where each variable is an hexadecimal value; for example "pci-0000:0a:00.0". The path of a device can be obtained with "udevadm info /sys/class/net/$dev | grep ID_PATH=" or by looking at the "path" property exported by NetworkManager ("nmcli -f general.path device show $dev"). Each element of the list is a shell wildcard pattern. See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\' are used for optional and mandatory matches and inverting the pattern.</description></property></setting><setting name="802-11-olpc-mesh" description=" OLPC Wireless Mesh Settings" name_upper="OLPC_MESH" alias="olpc-mesh"><property name="channel" name_upper="CHANNEL" type="uint32" default="0" alias="channel"><description-docbook><para> Channel on which the mesh network to join is located.</para></description-docbook><description>Channel on which the mesh network to join is located.</description></property><property name="dhcp-anycast-address" name_upper="DHCP_ANYCAST_ADDRESS" type="byte array" alias="dhcp-anycast"><description-docbook><para> Anycast DHCP MAC address used when requesting an IP address via DHCP. The specific anycast address used determines which DHCP server class answers the request.</para><para> This is currently only implemented by dhclient DHCP plugin.</para></description-docbook><description>Anycast DHCP MAC address used when requesting an IP address via DHCP. The specific anycast address used determines which DHCP server class answers the request. This is currently only implemented by dhclient DHCP plugin.</description></property><property name="ssid" name_upper="SSID" type="byte array" alias="ssid"><description-docbook><para> SSID of the mesh network to join.</para></description-docbook><description>SSID of the mesh network to join.</description></property></setting><setting name="ovs-bridge" description=" OvsBridge Link Settings" name_upper="OVS_BRIDGE"><property name="datapath-type" name_upper="DATAPATH_TYPE" type="string"><description-docbook><para> The data path type. One of "system", "netdev" or empty.</para></description-docbook><description>The data path type. One of "system", "netdev" or empty.</description></property><property name="fail-mode" name_upper="FAIL_MODE" type="string"><description-docbook><para> The bridge failure mode. One of "secure", "standalone" or empty.</para></description-docbook><description>The bridge failure mode. One of "secure", "standalone" or empty.</description></property><property name="mcast-snooping-enable" name_upper="MCAST_SNOOPING_ENABLE" type="boolean" default="FALSE"><description-docbook><para> Enable or disable multicast snooping.</para></description-docbook><description>Enable or disable multicast snooping.</description></property><property name="rstp-enable" name_upper="RSTP_ENABLE" type="boolean" default="FALSE"><description-docbook><para> Enable or disable RSTP.</para></description-docbook><description>Enable or disable RSTP.</description></property><property name="stp-enable" name_upper="STP_ENABLE" type="boolean" default="FALSE"><description-docbook><para> Enable or disable STP.</para></description-docbook><description>Enable or disable STP.</description></property></setting><setting name="ovs-dpdk" description=" OvsDpdk Link Settings" name_upper="OVS_DPDK"><property name="devargs" name_upper="DEVARGS" type="string"><description-docbook><para> Open vSwitch DPDK device arguments.</para></description-docbook><description>Open vSwitch DPDK device arguments.</description></property><property name="n-rxq" name_upper="N_RXQ" type="uint32" default="0"><description-docbook><para> Open vSwitch DPDK number of rx queues. Defaults to zero which means to leave the parameter in OVS unspecified and effectively configures one queue.</para></description-docbook><description>Open vSwitch DPDK number of rx queues. Defaults to zero which means to leave the parameter in OVS unspecified and effectively configures one queue.</description></property></setting><setting name="ovs-interface" description=" Open vSwitch Interface Settings" name_upper="OVS_INTERFACE"><property name="type" name_upper="TYPE" type="string"><description-docbook><para> The interface type. Either "internal", "system", "patch", "dpdk", or empty.</para></description-docbook><description>The interface type. Either "internal", "system", "patch", "dpdk", or empty.</description></property></setting><setting name="ovs-patch" description=" OvsPatch Link Settings" name_upper="OVS_PATCH"><property name="peer" name_upper="PEER" type="string"><description-docbook><para> Specifies the name of the interface for the other side of the patch. The patch on the other side must also set this interface as peer.</para></description-docbook><description>Specifies the name of the interface for the other side of the patch. The patch on the other side must also set this interface as peer.</description></property></setting><setting name="ovs-port" description=" OvsPort Link Settings" name_upper="OVS_PORT"><property name="bond-downdelay" name_upper="BOND_DOWNDELAY" type="uint32" default="0"><description-docbook><para> The time port must be inactive in order to be considered down.</para></description-docbook><description>The time port must be inactive in order to be considered down.</description></property><property name="bond-mode" name_upper="BOND_MODE" type="string"><description-docbook><para> Bonding mode. One of "active-backup", "balance-slb", or "balance-tcp".</para></description-docbook><description>Bonding mode. One of "active-backup", "balance-slb", or "balance-tcp".</description></property><property name="bond-updelay" name_upper="BOND_UPDELAY" type="uint32" default="0"><description-docbook><para> The time port must be active before it starts forwarding traffic.</para></description-docbook><description>The time port must be active before it starts forwarding traffic.</description></property><property name="lacp" name_upper="LACP" type="string"><description-docbook><para> LACP mode. One of "active", "off", or "passive".</para></description-docbook><description>LACP mode. One of "active", "off", or "passive".</description></property><property name="tag" name_upper="TAG" type="uint32" default="0"><description-docbook><para> The VLAN tag in the range 0-4095.</para></description-docbook><description>The VLAN tag in the range 0-4095.</description></property><property name="vlan-mode" name_upper="VLAN_MODE" type="string"><description-docbook><para> The VLAN mode. One of "access", "native-tagged", "native-untagged", "trunk" or unset.</para></description-docbook><description>The VLAN mode. One of "access", "native-tagged", "native-untagged", "trunk" or unset.</description></property></setting><setting name="ppp" description=" Point-to-Point Protocol Settings" name_upper="PPP"><property name="baud" name_upper="BAUD" type="uint32" default="0"><description-docbook><para> If non-zero, instruct pppd to set the serial port to the specified baudrate.  This value should normally be left as 0 to automatically choose the speed.</para></description-docbook><description>If non-zero, instruct pppd to set the serial port to the specified baudrate.  This value should normally be left as 0 to automatically choose the speed.</description></property><property name="crtscts" name_upper="CRTSCTS" type="boolean" default="FALSE"><description-docbook><para> If TRUE, specify that pppd should set the serial port to use hardware flow control with RTS and CTS signals.  This value should normally be set to FALSE.</para></description-docbook><description>If TRUE, specify that pppd should set the serial port to use hardware flow control with RTS and CTS signals.  This value should normally be set to FALSE.</description></property><property name="lcp-echo-failure" name_upper="LCP_ECHO_FAILURE" type="uint32" default="0"><description-docbook><para> If non-zero, instruct pppd to presume the connection to the peer has failed if the specified number of LCP echo-requests go unanswered by the peer.  The "lcp-echo-interval" property must also be set to a non-zero value if this property is used.</para></description-docbook><description>If non-zero, instruct pppd to presume the connection to the peer has failed if the specified number of LCP echo-requests go unanswered by the peer.  The "lcp-echo-interval" property must also be set to a non-zero value if this property is used.</description></property><property name="lcp-echo-interval" name_upper="LCP_ECHO_INTERVAL" type="uint32" default="0"><description-docbook><para> If non-zero, instruct pppd to send an LCP echo-request frame to the peer every n seconds (where n is the specified value).  Note that some PPP peers will respond to echo requests and some will not, and it is not possible to autodetect this.</para></description-docbook><description>If non-zero, instruct pppd to send an LCP echo-request frame to the peer every n seconds (where n is the specified value).  Note that some PPP peers will respond to echo requests and some will not, and it is not possible to autodetect this.</description></property><property name="mppe-stateful" name_upper="MPPE_STATEFUL" type="boolean" default="FALSE"><description-docbook><para> If TRUE, stateful MPPE is used.  See pppd documentation for more information on stateful MPPE.</para></description-docbook><description>If TRUE, stateful MPPE is used.  See pppd documentation for more information on stateful MPPE.</description></property><property name="mru" name_upper="MRU" type="uint32" default="0"><description-docbook><para> If non-zero, instruct pppd to request that the peer send packets no larger than the specified size.  If non-zero, the MRU should be between 128 and 16384.</para></description-docbook><description>If non-zero, instruct pppd to request that the peer send packets no larger than the specified size.  If non-zero, the MRU should be between 128 and 16384.</description></property><property name="mtu" name_upper="MTU" type="uint32" default="0"><description-docbook><para> If non-zero, instruct pppd to send packets no larger than the specified size.</para></description-docbook><description>If non-zero, instruct pppd to send packets no larger than the specified size.</description></property><property name="no-vj-comp" name_upper="NO_VJ_COMP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, Van Jacobsen TCP header compression will not be requested.</para></description-docbook><description>If TRUE, Van Jacobsen TCP header compression will not be requested.</description></property><property name="noauth" name_upper="NOAUTH" type="boolean" default="TRUE"><description-docbook><para> If TRUE, do not require the other side (usually the PPP server) to authenticate itself to the client.  If FALSE, require authentication from the remote side.  In almost all cases, this should be TRUE.</para></description-docbook><description>If TRUE, do not require the other side (usually the PPP server) to authenticate itself to the client.  If FALSE, require authentication from the remote side.  In almost all cases, this should be TRUE.</description></property><property name="nobsdcomp" name_upper="NOBSDCOMP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, BSD compression will not be requested.</para></description-docbook><description>If TRUE, BSD compression will not be requested.</description></property><property name="nodeflate" name_upper="NODEFLATE" type="boolean" default="FALSE"><description-docbook><para> If TRUE, "deflate" compression will not be requested.</para></description-docbook><description>If TRUE, "deflate" compression will not be requested.</description></property><property name="refuse-chap" name_upper="REFUSE_CHAP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, the CHAP authentication method will not be used.</para></description-docbook><description>If TRUE, the CHAP authentication method will not be used.</description></property><property name="refuse-eap" name_upper="REFUSE_EAP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, the EAP authentication method will not be used.</para></description-docbook><description>If TRUE, the EAP authentication method will not be used.</description></property><property name="refuse-mschap" name_upper="REFUSE_MSCHAP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, the MSCHAP authentication method will not be used.</para></description-docbook><description>If TRUE, the MSCHAP authentication method will not be used.</description></property><property name="refuse-mschapv2" name_upper="REFUSE_MSCHAPV2" type="boolean" default="FALSE"><description-docbook><para> If TRUE, the MSCHAPv2 authentication method will not be used.</para></description-docbook><description>If TRUE, the MSCHAPv2 authentication method will not be used.</description></property><property name="refuse-pap" name_upper="REFUSE_PAP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, the PAP authentication method will not be used.</para></description-docbook><description>If TRUE, the PAP authentication method will not be used.</description></property><property name="require-mppe" name_upper="REQUIRE_MPPE" type="boolean" default="FALSE"><description-docbook><para> If TRUE, MPPE (Microsoft Point-to-Point Encryption) will be required for the PPP session.  If either 64-bit or 128-bit MPPE is not available the session will fail.  Note that MPPE is not used on mobile broadband connections.</para></description-docbook><description>If TRUE, MPPE (Microsoft Point-to-Point Encryption) will be required for the PPP session.  If either 64-bit or 128-bit MPPE is not available the session will fail.  Note that MPPE is not used on mobile broadband connections.</description></property><property name="require-mppe-128" name_upper="REQUIRE_MPPE_128" type="boolean" default="FALSE"><description-docbook><para> If TRUE, 128-bit MPPE (Microsoft Point-to-Point Encryption) will be required for the PPP session, and the "require-mppe" property must also be set to TRUE.  If 128-bit MPPE is not available the session will fail.</para></description-docbook><description>If TRUE, 128-bit MPPE (Microsoft Point-to-Point Encryption) will be required for the PPP session, and the "require-mppe" property must also be set to TRUE.  If 128-bit MPPE is not available the session will fail.</description></property></setting><setting name="pppoe" description=" PPP-over-Ethernet Settings" name_upper="PPPOE"><property name="parent" name_upper="PARENT" type="string" alias="parent"><description-docbook><para> If given, specifies the parent interface name on which this PPPoE connection should be created.  If this property is not specified, the connection is activated on the interface specified in "interface-name" of NMSettingConnection.</para></description-docbook><description>If given, specifies the parent interface name on which this PPPoE connection should be created.  If this property is not specified, the connection is activated on the interface specified in "interface-name" of NMSettingConnection.</description></property><property name="password" name_upper="PASSWORD" type="string" alias="password"><description-docbook><para> Password used to authenticate with the PPPoE service.</para></description-docbook><description>Password used to authenticate with the PPPoE service.</description></property><property name="password-flags" name_upper="PASSWORD_FLAGS" type="NMSettingSecretFlags (uint32)"><description-docbook><para> Flags indicating how to handle the "password" property.</para></description-docbook><description>Flags indicating how to handle the "password" property.</description></property><property name="service" name_upper="SERVICE" type="string" alias="service"><description-docbook><para> If specified, instruct PPPoE to only initiate sessions with access concentrators that provide the specified service.  For most providers, this should be left blank.  It is only required if there are multiple access concentrators or a specific service is known to be required.</para></description-docbook><description>If specified, instruct PPPoE to only initiate sessions with access concentrators that provide the specified service.  For most providers, this should be left blank.  It is only required if there are multiple access concentrators or a specific service is known to be required.</description></property><property name="username" name_upper="USERNAME" type="string" alias="username"><description-docbook><para> Username used to authenticate with the PPPoE service.</para></description-docbook><description>Username used to authenticate with the PPPoE service.</description></property></setting><setting name="proxy" description=" WWW Proxy Settings" name_upper="PROXY"><property name="browser-only" name_upper="BROWSER_ONLY" type="boolean" default="FALSE" alias="browser-only"><description-docbook><para> Whether the proxy configuration is for browser only.</para></description-docbook><description>Whether the proxy configuration is for browser only.</description></property><property name="method" name_upper="METHOD" type="int32" default="0" alias="method"><description-docbook><para> Method for proxy configuration, Default is NM_SETTING_PROXY_METHOD_NONE (0)</para></description-docbook><description>Method for proxy configuration, Default is NM_SETTING_PROXY_METHOD_NONE (0)</description></property><property name="pac-script" name_upper="PAC_SCRIPT" type="string" alias="pac-script"><description-docbook><para> PAC script for the connection. This is an UTF-8 encoded javascript code that defines a FindProxyForURL() function.</para></description-docbook><description>The PAC script. In the profile this must be an UTF-8 encoded javascript code that defines a FindProxyForURL() function. When setting the property in nmcli, a filename is accepted too. In that case, nmcli will read the content of the file and set the script. The prefixes "file://" and "js://" are supported to explicitly differentiate between the two.</description></property><property name="pac-url" name_upper="PAC_URL" type="string" alias="pac-url"><description-docbook><para> PAC URL for obtaining PAC file.</para></description-docbook><description>PAC URL for obtaining PAC file.</description></property></setting><setting name="serial" description=" Serial Link Settings" name_upper="SERIAL"><property name="baud" name_upper="BAUD" type="uint32" default="57600"><description-docbook><para> Speed to use for communication over the serial port.  Note that this value usually has no effect for mobile broadband modems as they generally ignore speed settings and use the highest available speed.</para></description-docbook><description>Speed to use for communication over the serial port.  Note that this value usually has no effect for mobile broadband modems as they generally ignore speed settings and use the highest available speed.</description></property><property name="bits" name_upper="BITS" type="uint32" default="8"><description-docbook><para> Byte-width of the serial communication. The 8 in "8n1" for example.</para></description-docbook><description>Byte-width of the serial communication. The 8 in "8n1" for example.</description></property><property name="parity" name_upper="PARITY" type="NMSettingSerialParity (byte)"><description-docbook><para> Parity setting of the serial port.</para></description-docbook><description>Parity setting of the serial port.</description></property><property name="send-delay" name_upper="SEND_DELAY" type="uint64" default="0"><description-docbook><para> Time to delay between each byte sent to the modem, in microseconds.</para></description-docbook><description>Time to delay between each byte sent to the modem, in microseconds.</description></property><property name="stopbits" name_upper="STOPBITS" type="uint32" default="1"><description-docbook><para> Number of stop bits for communication on the serial port.  Either 1 or 2. The 1 in "8n1" for example.</para></description-docbook><description>Number of stop bits for communication on the serial port.  Either 1 or 2. The 1 in "8n1" for example.</description></property></setting><setting name="sriov" description=" SR-IOV settings" name_upper="SRIOV"><property name="autoprobe-drivers" name_upper="AUTOPROBE_DRIVERS" type="NMTernary (int32)"><description-docbook><para> Whether to autoprobe virtual functions by a compatible driver.</para><para> If set to NM_TERNARY_TRUE (1), the kernel will try to bind VFs to a compatible driver and if this succeeds a new network interface will be instantiated for each VF.</para><para> If set to NM_TERNARY_FALSE (0), VFs will not be claimed and no network interfaces will be created for them.</para><para> When set to NM_TERNARY_DEFAULT (-1), the global default is used; in case the global default is unspecified it is assumed to be NM_TERNARY_TRUE (1).</para></description-docbook><description>Whether to autoprobe virtual functions by a compatible driver. If set to NM_TERNARY_TRUE (1), the kernel will try to bind VFs to a compatible driver and if this succeeds a new network interface will be instantiated for each VF. If set to NM_TERNARY_FALSE (0), VFs will not be claimed and no network interfaces will be created for them. When set to NM_TERNARY_DEFAULT (-1), the global default is used; in case the global default is unspecified it is assumed to be NM_TERNARY_TRUE (1).</description></property><property name="total-vfs" name_upper="TOTAL_VFS" type="uint32" default="0"><description-docbook><para> The total number of virtual functions to create.</para><para> Note that when the sriov setting is present NetworkManager enforces the number of virtual functions on the interface (also when it is zero) during activation and resets it upon deactivation. To prevent any changes to SR-IOV parameters don't add a sriov setting to the connection.</para></description-docbook><description>The total number of virtual functions to create. Note that when the sriov setting is present NetworkManager enforces the number of virtual functions on the interface (also when it is zero) during activation and resets it upon deactivation. To prevent any changes to SR-IOV parameters don't add a sriov setting to the connection.</description></property><property name="vfs" name_upper="VFS" type="array of vardict"><description-docbook><para> Array of virtual function descriptors.</para><para> Each VF descriptor is a dictionary mapping attribute names to GVariant values. The 'index' entry is mandatory for each VF.</para><para> When represented as string a VF is in the form:</para><para> "INDEX [ATTR=VALUE[ ATTR=VALUE]...]".</para><para> for example:</para><para> "2 mac=00:11:22:33:44:55 spoof-check=true".</para><para> Multiple VFs can be specified using a comma as separator. Currently, the following attributes are supported: mac, spoof-check, trust, min-tx-rate, max-tx-rate, vlans.</para><para> The "vlans" attribute is represented as a semicolon-separated list of VLAN descriptors, where each descriptor has the form</para><para> "ID[.PRIORITY[.PROTO]]".</para><para> PROTO can be either 'q' for 802.1Q (the default) or 'ad' for 802.1ad.</para></description-docbook><description>Array of virtual function descriptors. Each VF descriptor is a dictionary mapping attribute names to GVariant values. The 'index' entry is mandatory for each VF. When represented as string a VF is in the form: "INDEX [ATTR=VALUE[ ATTR=VALUE]...]". for example: "2 mac=00:11:22:33:44:55 spoof-check=true". Multiple VFs can be specified using a comma as separator. Currently, the following attributes are supported: mac, spoof-check, trust, min-tx-rate, max-tx-rate, vlans. The "vlans" attribute is represented as a semicolon-separated list of VLAN descriptors, where each descriptor has the form "ID[.PRIORITY[.PROTO]]". PROTO can be either 'q' for 802.1Q (the default) or 'ad' for 802.1ad.</description></property></setting><setting name="tc" description=" Linux Traffic Control Settings" name_upper="TC_CONFIG"><property name="qdiscs" name_upper="QDISCS" type="GPtrArray(NMTCQdisc)"><description-docbook>
+</para></description-docbook><description>A comma separated list of routing rules for policy routing.</description></property><property name="token" name_upper="TOKEN" type="string"><description-docbook><para> Configure the token for draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 tokenized interface identifiers. Useful with eui64 addr-gen-mode.</para></description-docbook><description>Configure the token for draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 tokenized interface identifiers. Useful with eui64 addr-gen-mode.</description></property></setting><setting name="ip-tunnel" description=" IP Tunneling Settings" name_upper="IP_TUNNEL"><property name="encapsulation-limit" name_upper="ENCAPSULATION_LIMIT" type="uint32" default="0"><description-docbook><para> How many additional levels of encapsulation are permitted to be prepended to packets. This property applies only to IPv6 tunnels.</para></description-docbook><description>How many additional levels of encapsulation are permitted to be prepended to packets. This property applies only to IPv6 tunnels.</description></property><property name="flags" name_upper="FLAGS" type="uint32" default="0"><description-docbook><para> Tunnel flags. Currently, the following values are supported: NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4), NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8), NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20). They are valid only for IPv6 tunnels.</para></description-docbook><description>Tunnel flags. Currently, the following values are supported: NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4), NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8), NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20). They are valid only for IPv6 tunnels.</description></property><property name="flow-label" name_upper="FLOW_LABEL" type="uint32" default="0"><description-docbook><para> The flow label to assign to tunnel packets. This property applies only to IPv6 tunnels.</para></description-docbook><description>The flow label to assign to tunnel packets. This property applies only to IPv6 tunnels.</description></property><property name="input-key" name_upper="INPUT_KEY" type="string"><description-docbook><para> The key used for tunnel input packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</para></description-docbook><description>The key used for tunnel input packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</description></property><property name="local" name_upper="LOCAL" type="string" alias="local"><description-docbook><para> The local endpoint of the tunnel; the value can be empty, otherwise it must contain an IPv4 or IPv6 address.</para></description-docbook><description>The local endpoint of the tunnel; the value can be empty, otherwise it must contain an IPv4 or IPv6 address.</description></property><property name="mode" name_upper="MODE" type="uint32" default="0" alias="mode"><description-docbook><para> The tunneling mode, for example NM_IP_TUNNEL_MODE_IPIP (1) or NM_IP_TUNNEL_MODE_GRE (2).</para></description-docbook><description>The tunneling mode, for example NM_IP_TUNNEL_MODE_IPIP (1) or NM_IP_TUNNEL_MODE_GRE (2).</description></property><property name="mtu" name_upper="MTU" type="uint32" default="0"><description-docbook><para> If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments.</para></description-docbook><description>If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments.</description></property><property name="output-key" name_upper="OUTPUT_KEY" type="string"><description-docbook><para> The key used for tunnel output packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</para></description-docbook><description>The key used for tunnel output packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used.</description></property><property name="parent" name_upper="PARENT" type="string" alias="dev"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID the new device will be bound to so that tunneled packets will only be routed via that interface.</para></description-docbook><description>If given, specifies the parent interface name or parent connection UUID the new device will be bound to so that tunneled packets will only be routed via that interface.</description></property><property name="path-mtu-discovery" name_upper="PATH_MTU_DISCOVERY" type="boolean" default="TRUE"><description-docbook><para> Whether to enable Path MTU Discovery on this tunnel.</para></description-docbook><description>Whether to enable Path MTU Discovery on this tunnel.</description></property><property name="remote" name_upper="REMOTE" type="string" alias="remote"><description-docbook><para> The remote endpoint of the tunnel; the value must contain an IPv4 or IPv6 address.</para></description-docbook><description>The remote endpoint of the tunnel; the value must contain an IPv4 or IPv6 address.</description></property><property name="tos" name_upper="TOS" type="uint32" default="0"><description-docbook><para> The type of service (IPv4) or traffic class (IPv6) field to be set on tunneled packets.</para></description-docbook><description>The type of service (IPv4) or traffic class (IPv6) field to be set on tunneled packets.</description></property><property name="ttl" name_upper="TTL" type="uint32" default="0"><description-docbook><para> The TTL to assign to tunneled packets. 0 is a special value meaning that packets inherit the TTL value.</para></description-docbook><description>The TTL to assign to tunneled packets. 0 is a special value meaning that packets inherit the TTL value.</description></property></setting><setting name="macsec" description=" MACSec Settings" name_upper="MACSEC"><property name="encrypt" name_upper="ENCRYPT" type="boolean" default="TRUE" alias="encrypt"><description-docbook><para> Whether the transmitted traffic must be encrypted.</para></description-docbook><description>Whether the transmitted traffic must be encrypted.</description></property><property name="mka-cak" name_upper="MKA_CAK" type="string" alias="cak"><description-docbook><para> The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement. Must be a string of 32 hexadecimal characters.</para></description-docbook><description>The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement. Must be a string of 32 hexadecimal characters.</description></property><property name="mka-cak-flags" name_upper="MKA_CAK_FLAGS" type="NMSettingSecretFlags (uint32)"><description-docbook><para> Flags indicating how to handle the "mka-cak" property.</para></description-docbook><description>Flags indicating how to handle the "mka-cak" property.</description></property><property name="mka-ckn" name_upper="MKA_CKN" type="string" alias="ckn"><description-docbook><para> The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement. Must be a string of hexadecimal characters with a even length between 2 and 64.</para></description-docbook><description>The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement. Must be a string of hexadecimal characters with a even length between 2 and 64.</description></property><property name="mode" name_upper="MODE" type="int32" default="0" alias="mode"><description-docbook><para> Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained.</para></description-docbook><description>Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained.</description></property><property name="parent" name_upper="PARENT" type="string" alias="dev"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID from which this MACSEC interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</para></description-docbook><description>If given, specifies the parent interface name or parent connection UUID from which this MACSEC interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</description></property><property name="port" name_upper="PORT" type="int32" default="1" alias="port"><description-docbook><para> The port component of the SCI (Secure Channel Identifier), between 1 and 65534.</para></description-docbook><description>The port component of the SCI (Secure Channel Identifier), between 1 and 65534.</description></property><property name="send-sci" name_upper="SEND_SCI" type="boolean" default="TRUE"><description-docbook><para> Specifies whether the SCI (Secure Channel Identifier) is included in every packet.</para></description-docbook><description>Specifies whether the SCI (Secure Channel Identifier) is included in every packet.</description></property><property name="validation" name_upper="VALIDATION" type="int32" default="2"><description-docbook><para> Specifies the validation mode for incoming frames.</para></description-docbook><description>Specifies the validation mode for incoming frames.</description></property></setting><setting name="macvlan" description=" MAC VLAN Settings" name_upper="MACVLAN"><property name="mode" name_upper="MODE" type="uint32" default="0" alias="mode"><description-docbook><para> The macvlan mode, which specifies the communication mechanism between multiple macvlans on the same lower device.</para></description-docbook><description>The macvlan mode, which specifies the communication mechanism between multiple macvlans on the same lower device.</description></property><property name="parent" name_upper="PARENT" type="string" alias="dev"><description-docbook><para> If given, specifies the parent interface name or parent connection UUID from which this MAC-VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</para></description-docbook><description>If given, specifies the parent interface name or parent connection UUID from which this MAC-VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property.</description></property><property name="promiscuous" name_upper="PROMISCUOUS" type="boolean" default="TRUE"><description-docbook><para> Whether the interface should be put in promiscuous mode.</para></description-docbook><description>Whether the interface should be put in promiscuous mode.</description></property><property name="tap" name_upper="TAP" type="boolean" default="FALSE" alias="tap"><description-docbook><para> Whether the interface should be a MACVTAP.</para></description-docbook><description>Whether the interface should be a MACVTAP.</description></property></setting><setting name="match" description=" Match settings" name_upper="MATCH"><property name="driver" name_upper="DRIVER" type="array of string"><description-docbook><para> A list of driver names to match. Each element is a shell wildcard pattern.</para><para> See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\\' are used for optional and mandatory matches and inverting the pattern.</para></description-docbook><description>A list of driver names to match. Each element is a shell wildcard pattern. See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\' are used for optional and mandatory matches and inverting the pattern.</description></property><property name="interface-name" name_upper="INTERFACE_NAME" type="array of string"><description-docbook><para> A list of interface names to match. Each element is a shell wildcard pattern.</para><para> An element can be prefixed with a pipe symbol (|) or an ampersand (&amp;). The former means that the element is optional and the latter means that it is mandatory. If there are any optional elements, than the match evaluates to true if at least one of the optional element matches (logical OR). If there are any mandatory elements, then they all must match (logical AND). By default, an element is optional. This means that an element "foo" behaves the same as "|foo". An element can also be inverted with exclamation mark (!) between the pipe symbol (or the ampersand) and before the pattern. Note that "!foo" is a shortcut for the mandatory match "&amp;!foo". Finally, a backslash can be used at the beginning of the element (after the optional special characters) to escape the start of the pattern. For example, "&amp;\\!a" is an mandatory match for literally "!a".</para></description-docbook><description>A list of interface names to match. Each element is a shell wildcard pattern. An element can be prefixed with a pipe symbol (|) or an ampersand (&amp;). The former means that the element is optional and the latter means that it is mandatory. If there are any optional elements, than the match evaluates to true if at least one of the optional element matches (logical OR). If there are any mandatory elements, then they all must match (logical AND). By default, an element is optional. This means that an element "foo" behaves the same as "|foo". An element can also be inverted with exclamation mark (!) between the pipe symbol (or the ampersand) and before the pattern. Note that "!foo" is a shortcut for the mandatory match "&amp;!foo". Finally, a backslash can be used at the beginning of the element (after the optional special characters) to escape the start of the pattern. For example, "&amp;\!a" is an mandatory match for literally "!a".</description></property><property name="kernel-command-line" name_upper="KERNEL_COMMAND_LINE" type="array of string"><description-docbook><para> A list of kernel command line arguments to match. This may be used to check whether a specific kernel command line option is set (or unset, if prefixed with the exclamation mark). The argument must either be a single word, or an assignment (i.e. two words, joined by "="). In the former case the kernel command line is searched for the word appearing as is, or as left hand side of an assignment. In the latter case, the exact assignment is looked for with right and left hand side matching. Wildcard patterns are not supported.</para><para> See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\\' are used for optional and mandatory matches and inverting the match.</para></description-docbook><description>A list of kernel command line arguments to match. This may be used to check whether a specific kernel command line option is set (or unset, if prefixed with the exclamation mark). The argument must either be a single word, or an assignment (i.e. two words, joined by "="). In the former case the kernel command line is searched for the word appearing as is, or as left hand side of an assignment. In the latter case, the exact assignment is looked for with right and left hand side matching. Wildcard patterns are not supported. See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\' are used for optional and mandatory matches and inverting the match.</description></property><property name="path" name_upper="PATH" type="array of string"><description-docbook><para> A list of paths to match against the ID_PATH udev property of devices. ID_PATH represents the topological persistent path of a device. It typically contains a subsystem string (pci, usb, platform, etc.) and a subsystem-specific identifier.</para><para> For PCI devices the path has the form "pci-$domain:$bus:$device.$function", where each variable is an hexadecimal value; for example "pci-0000:0a:00.0".</para><para> The path of a device can be obtained with "udevadm info /sys/class/net/$dev | grep ID_PATH=" or by looking at the "path" property exported by NetworkManager ("nmcli -f general.path device show $dev").</para><para> Each element of the list is a shell wildcard pattern.</para><para> See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\\' are used for optional and mandatory matches and inverting the pattern.</para></description-docbook><description>A list of paths to match against the ID_PATH udev property of devices. ID_PATH represents the topological persistent path of a device. It typically contains a subsystem string (pci, usb, platform, etc.) and a subsystem-specific identifier. For PCI devices the path has the form "pci-$domain:$bus:$device.$function", where each variable is an hexadecimal value; for example "pci-0000:0a:00.0". The path of a device can be obtained with "udevadm info /sys/class/net/$dev | grep ID_PATH=" or by looking at the "path" property exported by NetworkManager ("nmcli -f general.path device show $dev"). Each element of the list is a shell wildcard pattern. See NMSettingMatch:interface-name for how special characters '|', '&amp;', '!' and '\' are used for optional and mandatory matches and inverting the pattern.</description></property></setting><setting name="802-11-olpc-mesh" description=" OLPC Wireless Mesh Settings" name_upper="OLPC_MESH" alias="olpc-mesh"><property name="channel" name_upper="CHANNEL" type="uint32" default="0" alias="channel"><description-docbook><para> Channel on which the mesh network to join is located.</para></description-docbook><description>Channel on which the mesh network to join is located.</description></property><property name="dhcp-anycast-address" name_upper="DHCP_ANYCAST_ADDRESS" type="byte array" alias="dhcp-anycast"><description-docbook><para> Anycast DHCP MAC address used when requesting an IP address via DHCP. The specific anycast address used determines which DHCP server class answers the request.</para><para> This is currently only implemented by dhclient DHCP plugin.</para></description-docbook><description>Anycast DHCP MAC address used when requesting an IP address via DHCP. The specific anycast address used determines which DHCP server class answers the request. This is currently only implemented by dhclient DHCP plugin.</description></property><property name="ssid" name_upper="SSID" type="byte array" alias="ssid"><description-docbook><para> SSID of the mesh network to join.</para></description-docbook><description>SSID of the mesh network to join.</description></property></setting><setting name="ovs-bridge" description=" OvsBridge Link Settings" name_upper="OVS_BRIDGE"><property name="datapath-type" name_upper="DATAPATH_TYPE" type="string"><description-docbook><para> The data path type. One of "system", "netdev" or empty.</para></description-docbook><description>The data path type. One of "system", "netdev" or empty.</description></property><property name="fail-mode" name_upper="FAIL_MODE" type="string"><description-docbook><para> The bridge failure mode. One of "secure", "standalone" or empty.</para></description-docbook><description>The bridge failure mode. One of "secure", "standalone" or empty.</description></property><property name="mcast-snooping-enable" name_upper="MCAST_SNOOPING_ENABLE" type="boolean" default="FALSE"><description-docbook><para> Enable or disable multicast snooping.</para></description-docbook><description>Enable or disable multicast snooping.</description></property><property name="rstp-enable" name_upper="RSTP_ENABLE" type="boolean" default="FALSE"><description-docbook><para> Enable or disable RSTP.</para></description-docbook><description>Enable or disable RSTP.</description></property><property name="stp-enable" name_upper="STP_ENABLE" type="boolean" default="FALSE"><description-docbook><para> Enable or disable STP.</para></description-docbook><description>Enable or disable STP.</description></property></setting><setting name="ovs-dpdk" description=" OvsDpdk Link Settings" name_upper="OVS_DPDK"><property name="devargs" name_upper="DEVARGS" type="string"><description-docbook><para> Open vSwitch DPDK device arguments.</para></description-docbook><description>Open vSwitch DPDK device arguments.</description></property><property name="n-rxq" name_upper="N_RXQ" type="uint32" default="0"><description-docbook><para> Open vSwitch DPDK number of rx queues. Defaults to zero which means to leave the parameter in OVS unspecified and effectively configures one queue.</para></description-docbook><description>Open vSwitch DPDK number of rx queues. Defaults to zero which means to leave the parameter in OVS unspecified and effectively configures one queue.</description></property></setting><setting name="ovs-interface" description=" Open vSwitch Interface Settings" name_upper="OVS_INTERFACE"><property name="type" name_upper="TYPE" type="string"><description-docbook><para> The interface type. Either "internal", "system", "patch", "dpdk", or empty.</para></description-docbook><description>The interface type. Either "internal", "system", "patch", "dpdk", or empty.</description></property></setting><setting name="ovs-patch" description=" OvsPatch Link Settings" name_upper="OVS_PATCH"><property name="peer" name_upper="PEER" type="string"><description-docbook><para> Specifies the name of the interface for the other side of the patch. The patch on the other side must also set this interface as peer.</para></description-docbook><description>Specifies the name of the interface for the other side of the patch. The patch on the other side must also set this interface as peer.</description></property></setting><setting name="ovs-port" description=" OvsPort Link Settings" name_upper="OVS_PORT"><property name="bond-downdelay" name_upper="BOND_DOWNDELAY" type="uint32" default="0"><description-docbook><para> The time port must be inactive in order to be considered down.</para></description-docbook><description>The time port must be inactive in order to be considered down.</description></property><property name="bond-mode" name_upper="BOND_MODE" type="string"><description-docbook><para> Bonding mode. One of "active-backup", "balance-slb", or "balance-tcp".</para></description-docbook><description>Bonding mode. One of "active-backup", "balance-slb", or "balance-tcp".</description></property><property name="bond-updelay" name_upper="BOND_UPDELAY" type="uint32" default="0"><description-docbook><para> The time port must be active before it starts forwarding traffic.</para></description-docbook><description>The time port must be active before it starts forwarding traffic.</description></property><property name="lacp" name_upper="LACP" type="string"><description-docbook><para> LACP mode. One of "active", "off", or "passive".</para></description-docbook><description>LACP mode. One of "active", "off", or "passive".</description></property><property name="tag" name_upper="TAG" type="uint32" default="0"><description-docbook><para> The VLAN tag in the range 0-4095.</para></description-docbook><description>The VLAN tag in the range 0-4095.</description></property><property name="vlan-mode" name_upper="VLAN_MODE" type="string"><description-docbook><para> The VLAN mode. One of "access", "native-tagged", "native-untagged", "trunk" or unset.</para></description-docbook><description>The VLAN mode. One of "access", "native-tagged", "native-untagged", "trunk" or unset.</description></property></setting><setting name="ppp" description=" Point-to-Point Protocol Settings" name_upper="PPP"><property name="baud" name_upper="BAUD" type="uint32" default="0"><description-docbook><para> If non-zero, instruct pppd to set the serial port to the specified baudrate.  This value should normally be left as 0 to automatically choose the speed.</para></description-docbook><description>If non-zero, instruct pppd to set the serial port to the specified baudrate.  This value should normally be left as 0 to automatically choose the speed.</description></property><property name="crtscts" name_upper="CRTSCTS" type="boolean" default="FALSE"><description-docbook><para> If TRUE, specify that pppd should set the serial port to use hardware flow control with RTS and CTS signals.  This value should normally be set to FALSE.</para></description-docbook><description>If TRUE, specify that pppd should set the serial port to use hardware flow control with RTS and CTS signals.  This value should normally be set to FALSE.</description></property><property name="lcp-echo-failure" name_upper="LCP_ECHO_FAILURE" type="uint32" default="0"><description-docbook><para> If non-zero, instruct pppd to presume the connection to the peer has failed if the specified number of LCP echo-requests go unanswered by the peer.  The "lcp-echo-interval" property must also be set to a non-zero value if this property is used.</para></description-docbook><description>If non-zero, instruct pppd to presume the connection to the peer has failed if the specified number of LCP echo-requests go unanswered by the peer.  The "lcp-echo-interval" property must also be set to a non-zero value if this property is used.</description></property><property name="lcp-echo-interval" name_upper="LCP_ECHO_INTERVAL" type="uint32" default="0"><description-docbook><para> If non-zero, instruct pppd to send an LCP echo-request frame to the peer every n seconds (where n is the specified value).  Note that some PPP peers will respond to echo requests and some will not, and it is not possible to autodetect this.</para></description-docbook><description>If non-zero, instruct pppd to send an LCP echo-request frame to the peer every n seconds (where n is the specified value).  Note that some PPP peers will respond to echo requests and some will not, and it is not possible to autodetect this.</description></property><property name="mppe-stateful" name_upper="MPPE_STATEFUL" type="boolean" default="FALSE"><description-docbook><para> If TRUE, stateful MPPE is used.  See pppd documentation for more information on stateful MPPE.</para></description-docbook><description>If TRUE, stateful MPPE is used.  See pppd documentation for more information on stateful MPPE.</description></property><property name="mru" name_upper="MRU" type="uint32" default="0"><description-docbook><para> If non-zero, instruct pppd to request that the peer send packets no larger than the specified size.  If non-zero, the MRU should be between 128 and 16384.</para></description-docbook><description>If non-zero, instruct pppd to request that the peer send packets no larger than the specified size.  If non-zero, the MRU should be between 128 and 16384.</description></property><property name="mtu" name_upper="MTU" type="uint32" default="0"><description-docbook><para> If non-zero, instruct pppd to send packets no larger than the specified size.</para></description-docbook><description>If non-zero, instruct pppd to send packets no larger than the specified size.</description></property><property name="no-vj-comp" name_upper="NO_VJ_COMP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, Van Jacobsen TCP header compression will not be requested.</para></description-docbook><description>If TRUE, Van Jacobsen TCP header compression will not be requested.</description></property><property name="noauth" name_upper="NOAUTH" type="boolean" default="TRUE"><description-docbook><para> If TRUE, do not require the other side (usually the PPP server) to authenticate itself to the client.  If FALSE, require authentication from the remote side.  In almost all cases, this should be TRUE.</para></description-docbook><description>If TRUE, do not require the other side (usually the PPP server) to authenticate itself to the client.  If FALSE, require authentication from the remote side.  In almost all cases, this should be TRUE.</description></property><property name="nobsdcomp" name_upper="NOBSDCOMP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, BSD compression will not be requested.</para></description-docbook><description>If TRUE, BSD compression will not be requested.</description></property><property name="nodeflate" name_upper="NODEFLATE" type="boolean" default="FALSE"><description-docbook><para> If TRUE, "deflate" compression will not be requested.</para></description-docbook><description>If TRUE, "deflate" compression will not be requested.</description></property><property name="refuse-chap" name_upper="REFUSE_CHAP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, the CHAP authentication method will not be used.</para></description-docbook><description>If TRUE, the CHAP authentication method will not be used.</description></property><property name="refuse-eap" name_upper="REFUSE_EAP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, the EAP authentication method will not be used.</para></description-docbook><description>If TRUE, the EAP authentication method will not be used.</description></property><property name="refuse-mschap" name_upper="REFUSE_MSCHAP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, the MSCHAP authentication method will not be used.</para></description-docbook><description>If TRUE, the MSCHAP authentication method will not be used.</description></property><property name="refuse-mschapv2" name_upper="REFUSE_MSCHAPV2" type="boolean" default="FALSE"><description-docbook><para> If TRUE, the MSCHAPv2 authentication method will not be used.</para></description-docbook><description>If TRUE, the MSCHAPv2 authentication method will not be used.</description></property><property name="refuse-pap" name_upper="REFUSE_PAP" type="boolean" default="FALSE"><description-docbook><para> If TRUE, the PAP authentication method will not be used.</para></description-docbook><description>If TRUE, the PAP authentication method will not be used.</description></property><property name="require-mppe" name_upper="REQUIRE_MPPE" type="boolean" default="FALSE"><description-docbook><para> If TRUE, MPPE (Microsoft Point-to-Point Encryption) will be required for the PPP session.  If either 64-bit or 128-bit MPPE is not available the session will fail.  Note that MPPE is not used on mobile broadband connections.</para></description-docbook><description>If TRUE, MPPE (Microsoft Point-to-Point Encryption) will be required for the PPP session.  If either 64-bit or 128-bit MPPE is not available the session will fail.  Note that MPPE is not used on mobile broadband connections.</description></property><property name="require-mppe-128" name_upper="REQUIRE_MPPE_128" type="boolean" default="FALSE"><description-docbook><para> If TRUE, 128-bit MPPE (Microsoft Point-to-Point Encryption) will be required for the PPP session, and the "require-mppe" property must also be set to TRUE.  If 128-bit MPPE is not available the session will fail.</para></description-docbook><description>If TRUE, 128-bit MPPE (Microsoft Point-to-Point Encryption) will be required for the PPP session, and the "require-mppe" property must also be set to TRUE.  If 128-bit MPPE is not available the session will fail.</description></property></setting><setting name="pppoe" description=" PPP-over-Ethernet Settings" name_upper="PPPOE"><property name="parent" name_upper="PARENT" type="string" alias="parent"><description-docbook><para> If given, specifies the parent interface name on which this PPPoE connection should be created.  If this property is not specified, the connection is activated on the interface specified in "interface-name" of NMSettingConnection.</para></description-docbook><description>If given, specifies the parent interface name on which this PPPoE connection should be created.  If this property is not specified, the connection is activated on the interface specified in "interface-name" of NMSettingConnection.</description></property><property name="password" name_upper="PASSWORD" type="string" alias="password"><description-docbook><para> Password used to authenticate with the PPPoE service.</para></description-docbook><description>Password used to authenticate with the PPPoE service.</description></property><property name="password-flags" name_upper="PASSWORD_FLAGS" type="NMSettingSecretFlags (uint32)"><description-docbook><para> Flags indicating how to handle the "password" property.</para></description-docbook><description>Flags indicating how to handle the "password" property.</description></property><property name="service" name_upper="SERVICE" type="string" alias="service"><description-docbook><para> If specified, instruct PPPoE to only initiate sessions with access concentrators that provide the specified service.  For most providers, this should be left blank.  It is only required if there are multiple access concentrators or a specific service is known to be required.</para></description-docbook><description>If specified, instruct PPPoE to only initiate sessions with access concentrators that provide the specified service.  For most providers, this should be left blank.  It is only required if there are multiple access concentrators or a specific service is known to be required.</description></property><property name="username" name_upper="USERNAME" type="string" alias="username"><description-docbook><para> Username used to authenticate with the PPPoE service.</para></description-docbook><description>Username used to authenticate with the PPPoE service.</description></property></setting><setting name="proxy" description=" WWW Proxy Settings" name_upper="PROXY"><property name="browser-only" name_upper="BROWSER_ONLY" type="boolean" default="FALSE" alias="browser-only"><description-docbook><para> Whether the proxy configuration is for browser only.</para></description-docbook><description>Whether the proxy configuration is for browser only.</description></property><property name="method" name_upper="METHOD" type="int32" default="0" alias="method"><description-docbook><para> Method for proxy configuration, Default is NM_SETTING_PROXY_METHOD_NONE (0)</para></description-docbook><description>Method for proxy configuration, Default is NM_SETTING_PROXY_METHOD_NONE (0)</description></property><property name="pac-script" name_upper="PAC_SCRIPT" type="string" alias="pac-script"><description-docbook><para> PAC script for the connection. This is an UTF-8 encoded javascript code that defines a FindProxyForURL() function.</para></description-docbook><description>The PAC script. In the profile this must be an UTF-8 encoded javascript code that defines a FindProxyForURL() function. When setting the property in nmcli, a filename is accepted too. In that case, nmcli will read the content of the file and set the script. The prefixes "file://" and "js://" are supported to explicitly differentiate between the two.</description></property><property name="pac-url" name_upper="PAC_URL" type="string" alias="pac-url"><description-docbook><para> PAC URL for obtaining PAC file.</para></description-docbook><description>PAC URL for obtaining PAC file.</description></property></setting><setting name="serial" description=" Serial Link Settings" name_upper="SERIAL"><property name="baud" name_upper="BAUD" type="uint32" default="57600"><description-docbook><para> Speed to use for communication over the serial port.  Note that this value usually has no effect for mobile broadband modems as they generally ignore speed settings and use the highest available speed.</para></description-docbook><description>Speed to use for communication over the serial port.  Note that this value usually has no effect for mobile broadband modems as they generally ignore speed settings and use the highest available speed.</description></property><property name="bits" name_upper="BITS" type="uint32" default="8"><description-docbook><para> Byte-width of the serial communication. The 8 in "8n1" for example.</para></description-docbook><description>Byte-width of the serial communication. The 8 in "8n1" for example.</description></property><property name="parity" name_upper="PARITY" type="NMSettingSerialParity (byte)"><description-docbook><para> Parity setting of the serial port.</para></description-docbook><description>Parity setting of the serial port.</description></property><property name="send-delay" name_upper="SEND_DELAY" type="uint64" default="0"><description-docbook><para> Time to delay between each byte sent to the modem, in microseconds.</para></description-docbook><description>Time to delay between each byte sent to the modem, in microseconds.</description></property><property name="stopbits" name_upper="STOPBITS" type="uint32" default="1"><description-docbook><para> Number of stop bits for communication on the serial port.  Either 1 or 2. The 1 in "8n1" for example.</para></description-docbook><description>Number of stop bits for communication on the serial port.  Either 1 or 2. The 1 in "8n1" for example.</description></property></setting><setting name="sriov" description=" SR-IOV settings" name_upper="SRIOV"><property name="autoprobe-drivers" name_upper="AUTOPROBE_DRIVERS" type="NMTernary (int32)"><description-docbook><para> Whether to autoprobe virtual functions by a compatible driver.</para><para> If set to NM_TERNARY_TRUE (1), the kernel will try to bind VFs to a compatible driver and if this succeeds a new network interface will be instantiated for each VF.</para><para> If set to NM_TERNARY_FALSE (0), VFs will not be claimed and no network interfaces will be created for them.</para><para> When set to NM_TERNARY_DEFAULT (-1), the global default is used; in case the global default is unspecified it is assumed to be NM_TERNARY_TRUE (1).</para></description-docbook><description>Whether to autoprobe virtual functions by a compatible driver. If set to NM_TERNARY_TRUE (1), the kernel will try to bind VFs to a compatible driver and if this succeeds a new network interface will be instantiated for each VF. If set to NM_TERNARY_FALSE (0), VFs will not be claimed and no network interfaces will be created for them. When set to NM_TERNARY_DEFAULT (-1), the global default is used; in case the global default is unspecified it is assumed to be NM_TERNARY_TRUE (1).</description></property><property name="total-vfs" name_upper="TOTAL_VFS" type="uint32" default="0"><description-docbook><para> The total number of virtual functions to create.</para><para> Note that when the sriov setting is present NetworkManager enforces the number of virtual functions on the interface (also when it is zero) during activation and resets it upon deactivation. To prevent any changes to SR-IOV parameters don't add a sriov setting to the connection.</para></description-docbook><description>The total number of virtual functions to create. Note that when the sriov setting is present NetworkManager enforces the number of virtual functions on the interface (also when it is zero) during activation and resets it upon deactivation. To prevent any changes to SR-IOV parameters don't add a sriov setting to the connection.</description></property><property name="vfs" name_upper="VFS" type="array of vardict"><description-docbook><para> Array of virtual function descriptors.</para><para> Each VF descriptor is a dictionary mapping attribute names to GVariant values. The 'index' entry is mandatory for each VF.</para><para> When represented as string a VF is in the form:</para><para> "INDEX [ATTR=VALUE[ ATTR=VALUE]...]".</para><para> for example:</para><para> "2 mac=00:11:22:33:44:55 spoof-check=true".</para><para> Multiple VFs can be specified using a comma as separator. Currently, the following attributes are supported: mac, spoof-check, trust, min-tx-rate, max-tx-rate, vlans.</para><para> The "vlans" attribute is represented as a semicolon-separated list of VLAN descriptors, where each descriptor has the form</para><para> "ID[.PRIORITY[.PROTO]]".</para><para> PROTO can be either 'q' for 802.1Q (the default) or 'ad' for 802.1ad.</para></description-docbook><description>Array of virtual function descriptors. Each VF descriptor is a dictionary mapping attribute names to GVariant values. The 'index' entry is mandatory for each VF. When represented as string a VF is in the form: "INDEX [ATTR=VALUE[ ATTR=VALUE]...]". for example: "2 mac=00:11:22:33:44:55 spoof-check=true". Multiple VFs can be specified using a comma as separator. Currently, the following attributes are supported: mac, spoof-check, trust, min-tx-rate, max-tx-rate, vlans. The "vlans" attribute is represented as a semicolon-separated list of VLAN descriptors, where each descriptor has the form "ID[.PRIORITY[.PROTO]]". PROTO can be either 'q' for 802.1Q (the default) or 'ad' for 802.1ad.</description></property></setting><setting name="tc" description=" Linux Traffic Control Settings" name_upper="TC_CONFIG"><property name="qdiscs" name_upper="QDISCS" type="GPtrArray(NMTCQdisc)"><description-docbook>
 <para>
 Array of TC queueing disciplines. qdisc is a basic block in the
 Linux traffic control subsystem
diff --git a/man/nm-settings-ifcfg-rh.5 b/man/nm-settings-ifcfg-rh.5
index 90fa6662..cd438540 100644
--- a/man/nm-settings-ifcfg-rh.5
+++ b/man/nm-settings-ifcfg-rh.5
@@ -2,12 +2,12 @@
 .\"     Title: nm-settings-ifcfg-rh
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: Configuration
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NM\-SETTINGS\-IFCFG\-RH" "5" "" "NetworkManager 1\&.40\&.6" "Configuration"
+.TH "NM\-SETTINGS\-IFCFG\-RH" "5" "" "NetworkManager 1\&.40\&.8" "Configuration"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
diff --git a/man/nm-settings-ifcfg-rh.xml b/man/nm-settings-ifcfg-rh.xml
index 8106d703..3834ec51 100644
--- a/man/nm-settings-ifcfg-rh.xml
+++ b/man/nm-settings-ifcfg-rh.xml
@@ -1,6 +1,6 @@
 <?xml version="1.0"?>
 <!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.3//EN" "http://www.oasis-open.org/docbook/xml/4.3/docbookx.dtd">
-<refentry id="nm-settings-ifcfg-rh"><refentryinfo><title>nm-settings-ifcfg-rh</title><author>NetworkManager developers</author></refentryinfo><refmeta><refentrytitle>nm-settings-ifcfg-rh</refentrytitle><manvolnum>5</manvolnum><refmiscinfo class="source">NetworkManager</refmiscinfo><refmiscinfo class="manual">Configuration</refmiscinfo><refmiscinfo class="version">1.40.6</refmiscinfo></refmeta><refnamediv><refname>nm-settings-ifcfg-rh</refname><refpurpose>Description of <emphasis>ifcfg-rh</emphasis> settings plugin</refpurpose></refnamediv><refsect1 id="description"><title>Description</title><para>
+<refentry id="nm-settings-ifcfg-rh"><refentryinfo><title>nm-settings-ifcfg-rh</title><author>NetworkManager developers</author></refentryinfo><refmeta><refentrytitle>nm-settings-ifcfg-rh</refentrytitle><manvolnum>5</manvolnum><refmiscinfo class="source">NetworkManager</refmiscinfo><refmiscinfo class="manual">Configuration</refmiscinfo><refmiscinfo class="version">1.40.8</refmiscinfo></refmeta><refnamediv><refname>nm-settings-ifcfg-rh</refname><refpurpose>Description of <emphasis>ifcfg-rh</emphasis> settings plugin</refpurpose></refnamediv><refsect1 id="description"><title>Description</title><para>
           NetworkManager is based on the concept of connection profiles that contain
           network configuration (see <citerefentry><refentrytitle>nm-settings</refentrytitle><manvolnum>5</manvolnum></citerefentry> for details). The profiles can be
           stored in various formats. NetworkManager uses plugins for reading and writing
diff --git a/man/nm-settings-keyfile.5 b/man/nm-settings-keyfile.5
index 90ee1456..c08e2c8f 100644
--- a/man/nm-settings-keyfile.5
+++ b/man/nm-settings-keyfile.5
@@ -2,12 +2,12 @@
 .\"     Title: nm-settings-keyfile
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: Configuration
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NM\-SETTINGS\-KEYFILE" "5" "" "NetworkManager 1\&.40\&.6" "Configuration"
+.TH "NM\-SETTINGS\-KEYFILE" "5" "" "NetworkManager 1\&.40\&.8" "Configuration"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
diff --git a/man/nm-settings-keyfile.xml b/man/nm-settings-keyfile.xml
index 45e78cab..b3487914 100644
--- a/man/nm-settings-keyfile.xml
+++ b/man/nm-settings-keyfile.xml
@@ -1,6 +1,6 @@
 <?xml version="1.0"?>
 <!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.3//EN" "http://www.oasis-open.org/docbook/xml/4.3/docbookx.dtd">
-<refentry id="nm-settings-keyfile"><refentryinfo><title>nm-settings-keyfile</title><author>NetworkManager developers</author></refentryinfo><refmeta><refentrytitle>nm-settings-keyfile</refentrytitle><manvolnum>5</manvolnum><refmiscinfo class="source">NetworkManager</refmiscinfo><refmiscinfo class="manual">Configuration</refmiscinfo><refmiscinfo class="version">1.40.6</refmiscinfo></refmeta><refnamediv><refname>nm-settings-keyfile</refname><refpurpose>Description of <emphasis>keyfile</emphasis> settings plugin</refpurpose></refnamediv><refsect1 id="description"><title>Description</title><para>
+<refentry id="nm-settings-keyfile"><refentryinfo><title>nm-settings-keyfile</title><author>NetworkManager developers</author></refentryinfo><refmeta><refentrytitle>nm-settings-keyfile</refentrytitle><manvolnum>5</manvolnum><refmiscinfo class="source">NetworkManager</refmiscinfo><refmiscinfo class="manual">Configuration</refmiscinfo><refmiscinfo class="version">1.40.8</refmiscinfo></refmeta><refnamediv><refname>nm-settings-keyfile</refname><refpurpose>Description of <emphasis>keyfile</emphasis> settings plugin</refpurpose></refnamediv><refsect1 id="description"><title>Description</title><para>
           NetworkManager is based on the concept of connection profiles that contain
           network configuration (see <citerefentry><refentrytitle>nm-settings</refentrytitle><manvolnum>5</manvolnum></citerefentry> for details). The profiles can be
           stored in various formats. NetworkManager uses plugins for reading and writing
diff --git a/man/nm-settings-nmcli.5 b/man/nm-settings-nmcli.5
index 20b571b6..d9c1bd4f 100644
--- a/man/nm-settings-nmcli.5
+++ b/man/nm-settings-nmcli.5
@@ -2,12 +2,12 @@
 .\"     Title: nm-settings-nmcli
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: Configuration
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NM\-SETTINGS\-NMCLI" "5" "" "NetworkManager 1\&.40\&.6" "Configuration"
+.TH "NM\-SETTINGS\-NMCLI" "5" "" "NetworkManager 1\&.40\&.8" "Configuration"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
@@ -2924,7 +2924,7 @@ Format: boolean
 .RS 4
 Alias: cak
 .sp
-The pre\-shared CAK (Connectivity Association Key) for MACsec Key Agreement\&.
+The pre\-shared CAK (Connectivity Association Key) for MACsec Key Agreement\&. Must be a string of 32 hexadecimal characters\&.
 .sp
 Format: string
 .RE
@@ -2940,7 +2940,7 @@ Format: NMSettingSecretFlags (uint32)
 .RS 4
 Alias: ckn
 .sp
-The pre\-shared CKN (Connectivity\-association Key Name) for MACsec Key Agreement\&.
+The pre\-shared CKN (Connectivity\-association Key Name) for MACsec Key Agreement\&. Must be a string of hexadecimal characters with a even length between 2 and 64\&.
 .sp
 Format: string
 .RE
diff --git a/man/nm-settings-nmcli.xml b/man/nm-settings-nmcli.xml
index a0bfd8d9..2a77ffa8 100644
--- a/man/nm-settings-nmcli.xml
+++ b/man/nm-settings-nmcli.xml
@@ -1,6 +1,6 @@
 <?xml version="1.0"?>
 <!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.3//EN" "http://www.oasis-open.org/docbook/xml/4.3/docbookx.dtd">
-<refentry id="nm-settings-nmcli"><refentryinfo><title>nm-settings-nmcli</title><author>NetworkManager developers</author></refentryinfo><refmeta><refentrytitle>nm-settings-nmcli</refentrytitle><manvolnum>5</manvolnum><refmiscinfo class="source">NetworkManager</refmiscinfo><refmiscinfo class="manual">Configuration</refmiscinfo><refmiscinfo class="version">1.40.6</refmiscinfo></refmeta><refnamediv><refname>nm-settings-nmcli</refname><refpurpose>Description of settings and properties of NetworkManager connection profiles for nmcli</refpurpose></refnamediv><refsect1 id="description"><title>Description</title><para>
+<refentry id="nm-settings-nmcli"><refentryinfo><title>nm-settings-nmcli</title><author>NetworkManager developers</author></refentryinfo><refmeta><refentrytitle>nm-settings-nmcli</refentrytitle><manvolnum>5</manvolnum><refmiscinfo class="source">NetworkManager</refmiscinfo><refmiscinfo class="manual">Configuration</refmiscinfo><refmiscinfo class="version">1.40.8</refmiscinfo></refmeta><refnamediv><refname>nm-settings-nmcli</refname><refpurpose>Description of settings and properties of NetworkManager connection profiles for nmcli</refpurpose></refnamediv><refsect1 id="description"><title>Description</title><para>
           NetworkManager is based on a concept of connection profiles, sometimes referred to as
           connections only. These connection profiles contain a network configuration. When
           NetworkManager activates a connection profile on a network device the configuration will
@@ -492,10 +492,10 @@ Example: <literal>priority 5 from 1:2:3::5/128 table 45</literal>
         <variablelist><varlistentry><term><option id="nm-settings-nmcli.property.macsec.encrypt">encrypt</option></term><listitem><para>
             Alias: encrypt</para><para> Whether the transmitted traffic must be encrypted.</para><para>
             Format: boolean</para></listitem></varlistentry><varlistentry><term><option id="nm-settings-nmcli.property.macsec.mka-cak">mka-cak</option></term><listitem><para>
-            Alias: cak</para><para> The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement.</para><para>
+            Alias: cak</para><para> The pre-shared CAK (Connectivity Association Key) for MACsec Key Agreement. Must be a string of 32 hexadecimal characters.</para><para>
             Format: string</para></listitem></varlistentry><varlistentry><term><option id="nm-settings-nmcli.property.macsec.mka-cak-flags">mka-cak-flags</option></term><listitem><para> Flags indicating how to handle the "mka-cak" property.</para><para>
             Format: NMSettingSecretFlags (uint32)</para></listitem></varlistentry><varlistentry><term><option id="nm-settings-nmcli.property.macsec.mka-ckn">mka-ckn</option></term><listitem><para>
-            Alias: ckn</para><para> The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement.</para><para>
+            Alias: ckn</para><para> The pre-shared CKN (Connectivity-association Key Name) for MACsec Key Agreement. Must be a string of hexadecimal characters with a even length between 2 and 64.</para><para>
             Format: string</para></listitem></varlistentry><varlistentry><term><option id="nm-settings-nmcli.property.macsec.mode">mode</option></term><listitem><para>
             Alias: mode</para><para> Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained.</para><para>
             Format: int32</para></listitem></varlistentry><varlistentry><term><option id="nm-settings-nmcli.property.macsec.parent">parent</option></term><listitem><para>
diff --git a/man/nmcli-examples.7 b/man/nmcli-examples.7
index 65bcd698..d7c97a67 100644
--- a/man/nmcli-examples.7
+++ b/man/nmcli-examples.7
@@ -2,12 +2,12 @@
 .\"     Title: nmcli-examples
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: Examples
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NMCLI\-EXAMPLES" "7" "" "NetworkManager 1\&.40\&.6" "Examples"
+.TH "NMCLI\-EXAMPLES" "7" "" "NetworkManager 1\&.40\&.8" "Examples"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
diff --git a/man/nmcli.1 b/man/nmcli.1
index f11bc34f..409a59ad 100644
--- a/man/nmcli.1
+++ b/man/nmcli.1
@@ -2,12 +2,12 @@
 .\"     Title: nmcli
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: General Commands Manual
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NMCLI" "1" "" "NetworkManager 1\&.40\&.6" "General Commands Manual"
+.TH "NMCLI" "1" "" "NetworkManager 1\&.40\&.8" "General Commands Manual"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------
diff --git a/man/nmtui.1 b/man/nmtui.1
index f126a124..5d74d326 100644
--- a/man/nmtui.1
+++ b/man/nmtui.1
@@ -2,12 +2,12 @@
 .\"     Title: nmtui
 .\"    Author: 
 .\" Generator: DocBook XSL Stylesheets vsnapshot <http://docbook.sf.net/>
-.\"      Date: 11/30/2022
+.\"      Date: 12/16/2022
 .\"    Manual: General Commands Manual
-.\"    Source: NetworkManager 1.40.6
+.\"    Source: NetworkManager 1.40.8
 .\"  Language: English
 .\"
-.TH "NMTUI" "1" "" "NetworkManager 1\&.40\&.6" "General Commands Manual"
+.TH "NMTUI" "1" "" "NetworkManager 1\&.40\&.8" "General Commands Manual"
 .\" -----------------------------------------------------------------
 .\" * Define some portability stuff
 .\" -----------------------------------------------------------------