From 1372848511cb896b80b51ed1a3e9606bd9816631 Mon Sep 17 00:00:00 2001 From: Michael Biebl Date: Fri, 10 Feb 2023 11:50:34 +0100 Subject: New upstream version 1.42.0 --- docs/api/html/nm-settings-ifcfg-rh.html | 3235 ++++++++++++++++--------------- 1 file changed, 1653 insertions(+), 1582 deletions(-) (limited to 'docs/api/html/nm-settings-ifcfg-rh.html') diff --git a/docs/api/html/nm-settings-ifcfg-rh.html b/docs/api/html/nm-settings-ifcfg-rh.html index 8189a493..d05f8335 100644 --- a/docs/api/html/nm-settings-ifcfg-rh.html +++ b/docs/api/html/nm-settings-ifcfg-rh.html @@ -274,8 +274,8 @@ DEVICETYPE=TeamPort
-

Table 12. 802-1x setting

-
+

Table 12. 802-11-wireless setting

+
@@ -290,370 +290,331 @@ DEVICETYPE=TeamPort - - + + - +Example: ESSID="Quick Net" - - + + - +Allowed values: Ad-Hoc, Managed (Auto) [case insensitive] - - + - + - - + + - +Example: CHANNEL=6 - - + - +Example: BSSID=00:1E:BD:64:83:21 - - + + - + - - + + - + - - + + - + - - + + - + - - + - + - - + - + - - + + - + - - + + + + + + + - - + + - - + - +Allowed values: default, ignore, enable, disable - - + - +Allowed values: default, never, always - - + + - + + + + + + +Allowed values: "yes", "no" + +
eapIEEE_8021X_EAP_METHODS(+) -ssidESSID  EAP method for 802.1X authentication. - -Example: IEEE_8021X_EAP_METHODS=PEAP +SSID of Wi-Fi network. -Allowed values: "LEAP", "PWD", "TLS", "PEAP", "TTLS", "FAST"
identityIEEE_8021X_IDENTITY(+) -modeMODE  Identity for EAP authentication methods. +Wi-Fi network mode. -Example: IEEE_8021X_IDENTITY=itsme
anonymous-identityIEEE_8021X_ANON_IDENTITY(+) +bandBAND(+)  Anonymous identity for EAP authentication methods.BAND alone is honored, but CHANNEL overrides BAND since it implies a band. + +Example: BAND=bg + +Allowed values: a, bg
pac-fileIEEE_8021X_PAC_FILE(+) -channelCHANNEL  File with PAC (Protected Access Credential) for EAP-FAST. +Channel used for the Wi-Fi communication. Channels greater than 14 mean "a" band, otherwise the band is "bg". -Example: IEEE_8021X_PAC_FILE=/home/joe/my-fast.pac
ca-certIEEE_8021X_CA_CERT(+) +bssidBSSID(+)  CA certificate for EAP. +Restricts association only to a single AP. -Example: IEEE_8021X_CA_CERT=/home/joe/cacert.crt
ca-pathIEEE_8021X_CA_PATH(+) -rate(none)  The search path for the certificate.This property is not handled by ifcfg-rh plugin.
subject-matchIEEE_8021X_SUBJECT_MATCH(+) -tx-power(none)  Substring to match subject of server certificate against. - -Example: IEEE_8021X_SUBJECT_MATCH="Red Hat"This property is not handled by ifcfg-rh plugin.
altsubject-matchesIEEE_8021X_ALTSUBJECT_MATCHES(+) -mac-addressHWADDR  List of strings to be matched against the altSubjectName. - -Example: IEEE_8021X_ALTSUBJECT_MATCHES="s1.domain.cc"Hardware address of the device in traditional hex-digits-and-colons notation (e.g. 00:22:68:14:5A:05). Note that for initscripts this is the current MAC address of the device as found during ifup. For NetworkManager this is the permanent MAC address. Or in case no permanent MAC address exists, the MAC address initially configured on the device.
domain-suffix-matchIEEE_8021X_DOMAIN_SUFFIX_MATCH(+) -cloned-mac-addressMACADDR  Suffix to match domain of server certificate against.Cloned (spoofed) MAC address in traditional hex-digits-and-colons notation (e.g. 00:22:68:14:5A:99).
domain-matchIEEE_8021X_DOMAIN_MATCH(+) +generate-mac-address-maskGENERATE_MAC_ADDRESS_MASK(+)  Value to match domain of server certificate against.the MAC address mask for generating randomized and stable cloned-mac-address.
client-certIEEE_8021X_CLIENT_CERT(+) +mac-address-blacklistHWADDR_BLACKLIST(+)  Client certificate for EAP. - -Example: IEEE_8021X_CLIENT_CERT=/home/joe/mycert.crtIt denies usage of the connection for any device whose address is listed.
phase1-peapverIEEE_8021X_PEAP_VERSION(+) -seen-bssids(none)  Use to force a specific PEAP version. - -Allowed values: 0, 1This property is not handled by ifcfg-rh plugin.
phase1-peaplabelIEEE_8021X_PEAP_FORCE_NEW_LABEL(+) +mtuMTU MTU of the wireless interface.
hiddenSSID_HIDDEN(+) noUse to force the new PEAP label during key derivation. - -Allowed values: yes, no Whether the network hides the SSID.
phase1-fast-provisioningIEEE_8021X_FAST_PROVISIONING(+) +powersavePOWERSAVE(+)  Enable in-line provisioning of EAP-FAST credentials. +Enables or disables Wi-Fi power saving. -Example: IEEE_8021X_FAST_PROVISIONING="allow-auth allow-unauth" +Example: POWERSAVE=enable -Allowed values: space-separated list of these values [allow-auth, allow-unauth]
phase1-auth-flagsIEEE_8021X_PHASE1_AUTH_FLAGS(+) +mac-address-randomizationMAC_ADDRESS_RANDOMIZATION(+)  Authentication flags for the supplicant +Enables or disables Wi-Fi MAC address randomization. -Example: IEEE_8021X_PHASE1_AUTH_FLAGS="tls-1-0-disable tls-1-1-disable" +Example: MAC_ADDRESS_RANDOMIZATION=always -Allowed values: space-separated list of authentication flags names
phase2-authIEEE_8021X_INNER_AUTH_METHODS(+) -security(none)  Inner non-EAP authentication methods for TTLS or the inner EAP authentication method for PEAP. IEEE_8021X_INNER_AUTH_METHODS can contain values both for 'phase2-auth' and 'phase2-autheap' properties. - -Example: IEEE_8021X_INNER_AUTH_METHODS=PAP +This property is deprecated and not handled by ifcfg-rh-plugin.
ap-isolationAP_ISOLATION(+) +missing variable means global defaultWhether AP isolation is enabled -Allowed values: "PAP", "CHAP", "MSCHAP", "MSCHAPV2", "GTC", "OTP", "MD5" and "TLS"
+
+
+

Table 13. 802-11-wireless-security setting

+
++++++ + + + + + + + - - + - + + + + + + +Allowed values: 1, 2, 3, 4 - - + - + - - + - - + +Allowed values: yes, no - - + - + - - + - + - - + - + - - + - + - - + - + - - + - + - - - - - - - - - - - - - - + - + - - + - + - - + - + - - + + - + - - + - + - - + - + - - + - + - - + - + - - + + - + - - + - - - - - - - - - -
PropertyIfcfg-rh VariableDefaultDescription
phase2-autheapIEEE_8021X_INNER_AUTH_METHODS(+) +key-mgmtKEY_MGMT(+)  Inner EAP-based authentication methods. Note that IEEE_8021X_INNER_AUTH_METHODS is also used for 'phase2-auth' values. +Key management method. -Example: IEEE_8021X_INNER_AUTH_METHODS="MSCHAPV2 EAP-TLS" +Allowed values: none, ieee8021x, owe, wpa-psk, sae, wpa-eap, wpa-eap-suite-b-192
wep-tx-keyidxDEFAULTKEY1Index of active WEP key. Note that in ifcfg format the index starts counting at 1, while NetworkManager API otherwise is zero based. -Allowed values: "EAP-MD5", "EAP-MSCHAPV2", "EAP-GTC", "EAP-OTP" and "EAP-TLS"
phase2-ca-pathIEEE_8021X_PHASE2_CA_PATH(+) +auth-algSECURITYMODE(+)  The search path for the certificate.Authentication algorithm for WEP. + +Allowed values: restricted, open, leap
phase2-subject-matchIEEE_8021X_PHASE2_SUBJECT_MATCH(+) +protoWPA_ALLOW_WPA(+), WPA_ALLOW_WPA2(+)  Substring to match subject of server certificate against. +noAllowed WPA protocols, WPA and WPA2 (RSN). -Example: IEEE_8021X_PHASE2_SUBJECT_MATCH="Red Hat"
phase2-altsubject-matchesIEEE_8021X_PHASE2_ALTSUBJECT_MATCHES(+) +pairwiseCIPHER_PAIRWISE(+)   Restrict pairwise encryption algorithms, specified as a space separated list. + +Allowed values: CCMP, TKIP
phase2-domain-suffix-matchIEEE_8021X_PHASE2_DOMAIN_SUFFIX_MATCH(+) +groupCIPHER_GROUP(+)  Suffix to match domain of server certificate for phase 2 against.Restrict group/broadcast encryption algorithms, specified as a space separated list. + +Allowed values: CCMP, TKIP, WEP40, WEP104
phase2-domain-matchIEEE_8021X_PHASE2_DOMAIN_MATCH(+) +pmfPMF(+)  Value to match domain of server certificate for phase 2 against.Enables or disables PMF (802.11w) + +Example: PMF=required + +Allowed values: default, disable, optional, required
phase2-client-certIEEE_8021X_INNER_CLIENT_CERT(+) +leap-usernameIEEE_8021X_IDENTITY(+)  Client certificate for inner EAP method. - -Example: IEEE_8021X_INNER_CLIENT_CERT=/home/joe/mycert.crtLogin name for LEAP.
passwordIEEE_8021X_PASSWORD(+) +wep-key0KEY1, KEY_PASSPHRASE1(+)  UTF-8 encoded password used for EAP. It can also go to "key-" lookaside file, or it can be owned by a secret agent.The first WEP key (used in most networks). See also DEFAULTKEY for key index.
password-flagsIEEE_8021X_PASSWORD_FLAGS(+) +wep-key1KEY2, KEY_PASSPHRASE2(+)  Password flags for IEEE_8021X_PASSWORD password. (see the section called “Secret flag types:” for _FLAGS values)WEP key with index 1. See also DEFAULTKEY for key index.
password-rawIEEE_8021X_PASSWORD_RAW(+) - password used for EAP, encoded as a hexadecimal string. It can also go to "key-" lookaside file. - -Example: IEEE_8021X_PASSWORD_RAW=041c8320083aa4bf
password-raw-flagsIEEE_8021X_PASSWORD_RAW_FLAGS(+) - The secret flags for password-raw.
private-keyIEEE_8021X_PRIVATE_KEY(+) +wep-key2KEY3, KEY_PASSPHRASE3(+)  Private key for EAP-TLS. - -Example: IEEE_8021X_PRIVATE_KEY=/home/joe/mykey.p12WEP key with index 2. See also DEFAULTKEY for key index.
private-key-passwordIEEE_8021X_PRIVATE_KEY_PASSWORD(+) +wep-key3KEY4, KEY_PASSPHRASE4(+)  Password for IEEE_8021X_PRIVATE_KEY. It can also go to "key-" lookaside file, or it can be owned by a secret agent.WEP key with index 3. See also DEFAULTKEY for key index.
private-key-password-flagsIEEE_8021X_PRIVATE_KEY_PASSWORD_FLAGS(+) +wep-key-flagsWEP_KEY_FLAGS(+)  Password flags for IEEE_8021X_PRIVATE_KEY_PASSWORD password. (see the section called “Secret flag types:” for _FLAGS values)Password flags for KEY<i>, KEY_PASSPHRASE<i> password. (see the section called “Secret flag types:” for _FLAGS values)
phase2-private-keyIEEE_8021X_INNER_PRIVATE_KEY(+) -pskWPA_PSK  Private key for inner authentication method for EAP-TLS.Pre-Shared-Key for WPA networks.
phase2-private-key-passwordIEEE_8021X_INNER_PRIVATE_KEY_PASSWORD(+) +psk-flagsWPA_PSK_FLAGS(+)  Password for IEEE_8021X_INNER_PRIVATE_KEY. It can also go to "key-" lookaside file, or it can be owned by a secret agent.Password flags for WPA_PSK_FLAGS. (see the section called “Secret flag types:” for _FLAGS values) + +Example: WPA_PSK_FLAGS=user
phase2-private-key-password-flagsIEEE_8021X_INNER_PRIVATE_KEY_PASSWORD_FLAGS(+) +leap-passwordIEEE_8021X_PASSWORD(+)  Password flags for IEEE_8021X_INNER_PRIVATE_KEY_PASSWORD password. (see the section called “Secret flag types:” for _FLAGS values)Password for LEAP. It can also go to "key-" lookaside file, or it can be owned by a secret agent.
pinIEEE_8021X_PIN(+) +leap-password-flagsIEEE_8021X_PASSWORD_FLAGS(+)  The pin secret used for EAP authentication methods.Password flags for IEEE_8021X_PASSWORD_FLAGS. (see the section called “Secret flag types:” for _FLAGS values)
pin-flagsIEEE_8021X_PIN_FLAGS(+) +wep-key-typeKEY<i> or KEY_PASSPHRASE<i>(+); KEY_TYPE(+)  The secret flags for the pin property.KEY is used for "key" type (10 or 26 hexadecimal characters, or 5 or 13 character string prefixed with "s:"). KEY_PASSPHRASE is used for WEP passphrases. KEY_TYPE specifies the key type and can be either 'key' or 'passphrase'. KEY_TYPE is redundant and can be omitted. + +Example: KEY1=s:ahoj, KEY1=0a1c45bc02, KEY_PASSPHRASE1=mysupersecretkey
system-ca-certsIEEE_8021X_SYSTEM_CA_CERTS(+) -wps-methodWPS_METHOD  a boolean value.Used to control the WPS methods to be used Valid values are "default", "auto", "disabled", "pin" and "pbc". If omitted, whatver the AP announces is used. + +Example: WPS_METHOD=disabled, WPS_METHOD="pin pbc"
auth-timeoutIEEE_8021X_AUTH_TIMEOUT(+) +filsFILS(+) 0Timeout in seconds for the 802.1X authentication. Zero means the global default or 25.
optionalIEEE_8021X_OPTIONAL(+) default=no  whether the 802.1X authentication is optional
-
-
-

Table 13. bond-port setting

-
------ - - - - - - - - - - - - -
PropertyIfcfg-rh VariableDefaultDescription
queue-idBONDING_OPTS: queue-id=0Queue ID. +Enables or disables FILS (802.11ai) -Allowed values: 0 - 65535
-
-
-

Table 14. bond setting

-
------ - - - - - - - - - - - - +Allowed values: default, disable, optional, required + +
PropertyIfcfg-rh VariableDefaultDescription
optionsBONDING_OPTS Bonding options. +Example: FILS=required -Example: BONDING_OPTS="miimon=100 mode=broadcast"

-

Table 15. bridge-port setting

-
+

Table 14. 802-1x setting

+
@@ -668,527 +629,441 @@ Example: BONDING_OPTS="miimon=100 mode=broadcast" - - - - + + + +Example: IEEE_8021X_EAP_METHODS=PEAP + +Allowed values: "LEAP", "PWD", "TLS", "PEAP", "TTLS", "FAST" - - - - + + + +Example: IEEE_8021X_IDENTITY=itsme - - - - + + + + - - + + - +Example: IEEE_8021X_PAC_FILE=/home/joe/my-fast.pac - -
priorityBRIDGING_OPTS: priority=32STP priority. +eapIEEE_8021X_EAP_METHODS(+) + EAP method for 802.1X authentication. -Allowed values: 0 - 63
path-costBRIDGING_OPTS: path_cost=100STP cost. +identityIEEE_8021X_IDENTITY(+) + Identity for EAP authentication methods. -Allowed values: 1 - 65535
hairpin-modeBRIDGING_OPTS: hairpin_mode=yesHairpin mode of the bridge port.anonymous-identityIEEE_8021X_ANON_IDENTITY(+) + Anonymous identity for EAP authentication methods.
vlansBRIDGE_PORT_VLANSpac-fileIEEE_8021X_PAC_FILE(+) +  List of VLANs on the bridge port +File with PAC (Protected Access Credential) for EAP-FAST. -Example: BRIDGE_PORT_VLANS="1 pvid untagged,20,300-400 untagged"
-
-
-

Table 16. bridge setting

-
------ - - - - - - - - - + - + - - - - + + + + - - - - + + + +Example: IEEE_8021X_SUBJECT_MATCH="Red Hat" - - - - + + + +Example: IEEE_8021X_ALTSUBJECT_MATCHES="s1.domain.cc" - - - - + + + + - - - - + + + + - - - - + + + +Example: IEEE_8021X_CLIENT_CERT=/home/joe/mycert.crt - - - - + + + +Allowed values: 0, 1 - - - - + + + +Allowed values: yes, no - - - - + + + +Example: IEEE_8021X_FAST_PROVISIONING="allow-auth allow-unauth" + +Allowed values: space-separated list of these values [allow-auth, allow-unauth] - - + + - +Example: IEEE_8021X_PHASE1_AUTH_FLAGS="tls-1-0-disable tls-1-1-disable" + +Allowed values: space-separated list of authentication flags names - - + + - +Example: IEEE_8021X_INNER_AUTH_METHODS=PAP + +Allowed values: "PAP", "CHAP", "MSCHAP", "MSCHAPV2", "GTC", "OTP", "MD5" and "TLS" - - + + - +Example: IEEE_8021X_INNER_AUTH_METHODS="MSCHAPV2 EAP-TLS" + +Allowed values: "EAP-MD5", "EAP-MSCHAPV2", "EAP-GTC", "EAP-OTP" and "EAP-TLS" - - - - + + + + - - - - + + + +Example: IEEE_8021X_PHASE2_SUBJECT_MATCH="Red Hat" - - - - + + + + - - - - + + + + - - - - + + + + - - - - + + + +Example: IEEE_8021X_INNER_CLIENT_CERT=/home/joe/mycert.crt - - - - + + + + - - - - + + + + - - - - + + + +Example: IEEE_8021X_PASSWORD_RAW=041c8320083aa4bf - - - - + + + + - - - - + + + +Example: IEEE_8021X_PRIVATE_KEY=/home/joe/mykey.p12 - - - - + + + + - - - - + + + + - -
PropertyIfcfg-rh VariableDefaultDescription
mac-addressBRIDGE_MACADDR(+) +ca-certIEEE_8021X_CA_CERT(+)  MAC address of the bridge. Note that this requires a recent kernel support, originally introduced in 3.15 upstream kernel) BRIDGE_MACADDR for bridges is an NM extension.CA certificate for EAP. + +Example: IEEE_8021X_CA_CERT=/home/joe/cacert.crt
stpSTPnoSpan tree protocol participation.ca-pathIEEE_8021X_CA_PATH(+) + The search path for the certificate.
priorityBRIDGING_OPTS: priority=32768STP priority. +subject-matchIEEE_8021X_SUBJECT_MATCH(+) + Substring to match subject of server certificate against. -Allowed values: 0 - 32768
forward-delayDELAY15STP forwarding delay. +altsubject-matchesIEEE_8021X_ALTSUBJECT_MATCHES(+) + List of strings to be matched against the altSubjectName. -Allowed values: 2 - 30
hello-timeBRIDGING_OPTS: hello_time=2STP hello time. - -Allowed values: 1 - 10domain-suffix-matchIEEE_8021X_DOMAIN_SUFFIX_MATCH(+) + Suffix to match domain of server certificate against.
max-ageBRIDGING_OPTS: max_age=20STP maximum message age. - -Allowed values: 6 - 40domain-matchIEEE_8021X_DOMAIN_MATCH(+) + Value to match domain of server certificate against.
ageing-timeBRIDGING_OPTS: ageing_time=300Ethernet MAC ageing time. +client-certIEEE_8021X_CLIENT_CERT(+) + Client certificate for EAP. -Allowed values: 0 - 1000000
multicast-snoopingBRIDGING_OPTS: multicast_snooping=1IGMP snooping support. +phase1-peapverIEEE_8021X_PEAP_VERSION(+) + Use to force a specific PEAP version. -Allowed values: 0 or 1
vlan-filteringBRIDGING_OPTS: vlan_filtering=0VLAN filtering support. +phase1-peaplabelIEEE_8021X_PEAP_FORCE_NEW_LABEL(+) +noUse to force the new PEAP label during key derivation. -Allowed values: 0 or 1
vlan-default-pvidBRIDGING_OPTS: default_pvid=1default VLAN PVID. +phase1-fast-provisioningIEEE_8021X_FAST_PROVISIONING(+) + Enable in-line provisioning of EAP-FAST credentials. -Allowed values: 0 - 4094
vlansBRIDGE_VLANSphase1-auth-flagsIEEE_8021X_PHASE1_AUTH_FLAGS(+) +  List of VLANs on the bridge +Authentication flags for the supplicant -Example: BRIDGE_VLANS="1 pvid untagged,20,300-400 untagged"
group-addressBRIDGING_OPTS: group_address=phase2-authIEEE_8021X_INNER_AUTH_METHODS(+) +  STP group address. +Inner non-EAP authentication methods for TTLS or the inner EAP authentication method for PEAP. IEEE_8021X_INNER_AUTH_METHODS can contain values both for 'phase2-auth' and 'phase2-autheap' properties. -Example: BRIDGING_OPTS="group_address=01:80:C2:00:00:0A"
vlan-protocolBRIDGING_OPTS: vlan_protocol=phase2-autheapIEEE_8021X_INNER_AUTH_METHODS(+) +  VLAN filtering protocol. +Inner EAP-based authentication methods. Note that IEEE_8021X_INNER_AUTH_METHODS is also used for 'phase2-auth' values. -Example: BRIDGING_OPTS="vlan_protocol=802.1Q"
vlan-stats-enabledBRIDGING_OPTS: vlan_stats_enabled=0 - - -Example: BRIDGING_OPTS="vlan_stats_enabled=1"phase2-ca-pathIEEE_8021X_PHASE2_CA_PATH(+) + The search path for the certificate.
multicast-routerBRIDGING_OPTS: multicast_router=auto - - -Example: BRIDGING_OPTS="multicast_router=enabled" +phase2-subject-matchIEEE_8021X_PHASE2_SUBJECT_MATCH(+) + Substring to match subject of server certificate against. -Allowed values: auto, enabled, disabled
multicast-query-use-ifaddrBRIDGING_OPTS: multicast_query_use_ifaddr=0 - - -Example: BRIDGING_OPTS="multicast_query-use_ifaddr=1"phase2-altsubject-matchesIEEE_8021X_PHASE2_ALTSUBJECT_MATCHES(+) +  
multicast-querierBRIDGING_OPTS: multicast_querier=0 - - -Example: BRIDGING_OPTS="multicast_querier=1"phase2-domain-suffix-matchIEEE_8021X_PHASE2_DOMAIN_SUFFIX_MATCH(+) + Suffix to match domain of server certificate for phase 2 against.
multicast-hash-maxBRIDGING_OPTS: multicast_hash_max=4096 - - -Example: BRIDGING_OPTS="multicast_hash_max=8192"phase2-domain-matchIEEE_8021X_PHASE2_DOMAIN_MATCH(+) + Value to match domain of server certificate for phase 2 against.
multicast-last-member-countBRIDGING_OPTS: multicast_last_member_count=2 - +phase2-client-certIEEE_8021X_INNER_CLIENT_CERT(+) + Client certificate for inner EAP method. -Example: BRIDGING_OPTS="multicast_last_member_count=4"
multicast-last-member-intervalBRIDGING_OPTS: multicast_last_member_interval=100 - - -Example: BRIDGING_OPTS="multicast_last_member_interval=200"passwordIEEE_8021X_PASSWORD(+) + UTF-8 encoded password used for EAP. It can also go to "key-" lookaside file, or it can be owned by a secret agent.
multicast-membership-intervalBRIDGING_OPTS: multicast_membership_interval=26000 - - -Example: BRIDGING_OPTS="multicast_membership_interval=16000"password-flagsIEEE_8021X_PASSWORD_FLAGS(+) + Password flags for IEEE_8021X_PASSWORD password. (see the section called “Secret flag types:” for _FLAGS values)
multicast-querier-intervalBRIDGING_OPTS: multicast_querier_interval=25500 - +password-rawIEEE_8021X_PASSWORD_RAW(+) + password used for EAP, encoded as a hexadecimal string. It can also go to "key-" lookaside file. -Example: BRIDGING_OPTS="multicast_querier_interval=20000"
multicast-query-intervalBRIDGING_OPTS: multicast_query_interval=12500 - - -Example: BRIDGING_OPTS="multicast_query_interval=22500"password-raw-flagsIEEE_8021X_PASSWORD_RAW_FLAGS(+) + The secret flags for password-raw.
multicast-query-response-intervalBRIDGING_OPTS: multicast_query_response_interval=1000 - +private-keyIEEE_8021X_PRIVATE_KEY(+) + Private key for EAP-TLS. -Example: BRIDGING_OPTS="multicast_query_response_interval=2000"
multicast-startup-query-countBRIDGING_OPTS: multicast_startup_query_count=2 - - -Example: BRIDGING_OPTS="multicast_startup_query_count=4"private-key-passwordIEEE_8021X_PRIVATE_KEY_PASSWORD(+) + Password for IEEE_8021X_PRIVATE_KEY. It can also go to "key-" lookaside file, or it can be owned by a secret agent.
multicast-startup-query-intervalBRIDGING_OPTS: multicast_startup_query_interval=3125 - - -Example: BRIDGING_OPTS="multicast_startup_query_interval=4000"private-key-password-flagsIEEE_8021X_PRIVATE_KEY_PASSWORD_FLAGS(+) + Password flags for IEEE_8021X_PRIVATE_KEY_PASSWORD password. (see the section called “Secret flag types:” for _FLAGS values)
-
-
-

Table 17. connection setting

-
------ - - - - - - - - - + - + - - + - + - - + - + - - + + - + - - + + - + - - + - - - - - - - + - - + - + - - + + - + + +
PropertyIfcfg-rh VariableDefaultDescription
idNAME(+) +phase2-private-keyIEEE_8021X_INNER_PRIVATE_KEY(+)  User friendly name for the connection profile.Private key for inner authentication method for EAP-TLS.
uuidUUID(+) +phase2-private-key-passwordIEEE_8021X_INNER_PRIVATE_KEY_PASSWORD(+)  UUID for the connection profile. When missing, NetworkManager creates the UUID itself (by hashing the filename).Password for IEEE_8021X_INNER_PRIVATE_KEY. It can also go to "key-" lookaside file, or it can be owned by a secret agent.
stable-idSTABLE_ID(+) +phase2-private-key-password-flagsIEEE_8021X_INNER_PRIVATE_KEY_PASSWORD_FLAGS(+)  Token to generate stable IDs.Password flags for IEEE_8021X_INNER_PRIVATE_KEY_PASSWORD password. (see the section called “Secret flag types:” for _FLAGS values)
interface-nameDEVICEpinIEEE_8021X_PIN(+) +  Interface name of the device this profile is bound to. The variable can be left out when the profile should apply for more devices. Note that DEVICE can be required for some connection types.The pin secret used for EAP authentication methods.
typeTYPE (DEVICETYPE, DEVICE)pin-flagsIEEE_8021X_PIN_FLAGS(+) +  Base type of the connection. DEVICETYPE is used for teaming connections. - -Example: TYPE=Ethernet; TYPE=Bond; TYPE=Bridge; DEVICETYPE=TeamPort - -Allowed values: Ethernet, Wireless, InfiniBand, Bridge, Bond, Vlan, Team, TeamPortThe secret flags for the pin property.
permissionsUSERS(+) +system-ca-certsIEEE_8021X_SYSTEM_CA_CERTS(+)  Restrict to certain users the access to this connection, and allow the connection to be active only when at least one of the specified users is logged into an active session. - -Example: USERS="joe bob"
autoconnectONBOOTyesWhether the connection should be autoconnected (not only while booting).a boolean value.
autoconnect-priorityAUTOCONNECT_PRIORITY(+) +auth-timeoutIEEE_8021X_AUTH_TIMEOUT(+) 0Connection priority for automatic activation. Connections with higher numbers are preferred when selecting profiles for automatic activation. - -Example: AUTOCONNECT_PRIORITY=20 - -Allowed values: -999 to 999Timeout in seconds for the 802.1X authentication. Zero means the global default or 25.
autoconnect-retriesAUTOCONNECT_RETRIES(+) -optionalIEEE_8021X_OPTIONAL(+) default=no  The number of times a connection should be autoactivated before giving up and switching to the next one. - -Example: AUTOCONNECT_RETRIES=1 - -Allowed values: -1 (use global default), 0 (forever) or a positive valuewhether the 802.1X authentication is optional
+
+
+

Table 15. 802-3-ethernet setting

+
++++++ + + + + + + + - - + + - + - - + + - + - - + + - + - - + + - - - - - - - + - - + + - + - - - - + + + + - - + - + - - + - - + +Example: HWADDR_BLACKLIST="00:22:68:11:69:08 00:11:22:11:44:55" - - - - + + + + - - - - + + + +Example: SUBCHANNELS=0.0.b00a,0.0.b00b,0.0.b00c - - - - + + + +Allowed values: "qeth", "lcs" or "ctc" - - - - + + + + - - - - + + + + - - + + - +Example: ETHTOOL_OPTS="wol gs sopass 00:11:22:33:44:55" - - + + - - - - - - - +
PropertyIfcfg-rh VariableDefaultDescription
multi-connectMULTI_CONNECT(+) -port(none)  whether the profile can be active on multiple devices at a given moment. The values are numbers corresponding to #NMConnectionMultiConnect enum. - -Example: MULTI_CONNECT=3The property is not saved by the plugin.
zoneZONE(+) -speedETHTOOL_OPTS  Trust level of this connection. The string is usually used for a firewall. - -Example: ZONE=WorkFixed speed for the ethernet link. It is added as "speed" parameter in the ETHTOOL_OPTS variable.
masterMASTER, MASTER_UUID, TEAM_MASTER, TEAM_MASTER_UUID, BRIDGE, BRIDGE_UUIDduplexETHTOOL_OPTS  Reference to master connection. The variable used depends on the connection type and the value. In general, if the *_UUID variant is present, the variant without *_UUID is ignored. NetworkManager attempts to write both for compatibility with legacy tooling.Fixed duplex mode for the ethernet link. It is added as "duplex" parameter in the ETHOOL_OPTS variable.
slave-typeMASTER, MASTER_UUID, TEAM_MASTER, TEAM_MASTER_UUID, DEVICETYPE, BRIDGE, BRIDGE_UUIDauto-negotiateETHTOOL_OPTS  Slave type doesn't map directly to a variable, but it is recognized using different variables. MASTER and MASTER_UUID for bonding, TEAM_MASTER, TEAM_MASTER_UUID and DEVICETYPE for teaming, BRIDGE and BRIDGE_UUID for bridging.
autoconnect-slavesAUTOCONNECT_SLAVES(+) -missing variable means global defaultWhether slaves of this connection should be auto-connected when this connection is activated.Whether link speed and duplex autonegotiation is enabled. It is not saved only if disabled and no values are provided for the "speed" and "duplex" parameters (skips link configuration).
secondariesSECONDARY_UUIDS(+) -mac-addressHWADDR  UUID of VPN connections that should be activated together with this connection.Hardware address of the device in traditional hex-digits-and-colons notation (e.g. 00:22:68:14:5A:05). Note that for initscripts this is the current MAC address of the device as found during ifup. For NetworkManager this is the permanent MAC address. Or in case no permanent MAC address exists, the MAC address initially configured on the device.
gateway-ping-timeoutGATEWAY_PING_TIMEOUT(+) -0If greater than zero, the IP connectivity will be checked by pinging the gateway and waiting for the specified timeout (in seconds). - -Example: GATEWAY_PING_TIMEOUT=5cloned-mac-addressMACADDR Cloned (spoofed) MAC address in traditional hex-digits-and-colons notation (e.g. 00:22:68:14:5A:99).
meteredCONNECTION_METERED(+) +generate-mac-address-maskGENERATE_MAC_ADDRESS_MASK(+)  Whether the device is metered - -Example: CONNECTION_METERED=yes - -Allowed values: yes,no,unknownthe MAC address mask for generating randomized and stable cloned-mac-address.
lldpLLDP(+) +mac-address-blacklistHWADDR_BLACKLIST(+) missing variable means global defaultwhether LLDP is enabled for the connection - -Example: LLDP=no + It denies usage of the connection for any device whose address is listed. -Allowed values: boolean value or 'rx'
auth-retriesAUTH_RETRIES(+) -0Number of retries for authentication.mtuMTU MTU of the interface.
mdnsMDNS(+) -missing variable means global defaultWhether or not mDNS is enabled for the connection - -Example: MDNS=yes +s390-subchannelsSUBCHANNELS Subchannels for IBM S390 hosts. -Allowed values: yes,no,resolve
llmnrLLMNR(+) -missing variable means global defaultWhether or not LLMNR is enabled for the connection +s390-nettypeNETTYPE Network type of the S390 host. -Example: LLMNR=yes +Example: NETTYPE=qeth -Allowed values: yes,no,resolve
dns-over-tlsDNS_OVER_TLS(+) -missing variable means global defaultWhether or not DNSOverTls is enabled for the connection - -Allowed values: yes,no,opportunistics390-optionsOPTIONS and PORTNAME, CTCPROTO, S390 device options. All options go to OPTIONS, except for "portname" and "ctcprot" that have their own variables.
mptcp-flagsMPTCP_FLAGS(+) -missing variable means global defaultThe MPTCP flags that indicate whether MPTCP is enabled and which flags to use for the address endpoints. - -Example: MPTCP_FLAGS="signal,subflow"wake-on-lanETHTOOL_OPTS, ETHTOOL_WAKE_ON_LAN Wake on Lan mode for ethernet. The setting "ignore" is expressed with "ETHTOOL_WAKE_ON_LAN=ignore". Otherwise, the "ETHTOOL_OPTS" variable is set with the value "wol" and several of the characters "p|u|m|b|a|g|s|f|d" as explained in the ethtool manual page.
wait-device-timeoutDEVTIMEOUT(+) -wake-on-lan-passwordETHTOOL_OPTS  for initscripts compatibility, this variable must be a whole integer. If necessary, NetworkManager stores also a fractional component for the milliseconds. - -Example: DEVTIMEOUT=5 +Password for secure-on based Wake-on-Lan. It is added as "sopass" parameter in the ETHTOOL_OPTS variable. -Allowed values: timeout in seconds.
mud-urlMUD_URLaccept-all-mac-addressesACCEPT_ALL_MAC_ADDRESSES  MUD_URL to be sent by device (See RFC 8520). - -Example: https://yourdevice.example.com/model.json - -Allowed values: a valid URL that points to recommended policy for this device
wait-activation-delayWAIT_ACTIVATION_DELAY(+) - Time in milliseconds to wait for connection to be considered activated. The wait will start after the pre-up dispatcher event. - -Example: WAIT_ACTIVATION_DELAY=5000 - -Allowed values: delay in milliseconds.Enforce the interface to accept all the packets.

-

Table 18. dcb setting

-
+

Table 16. bond setting

+
@@ -1201,129 +1076,19 @@ Allowed values: delay in milliseconds. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + - - - +Example: BONDING_OPTS="miimon=100 mode=broadcast" +
Default Description
app-fcoe-flagsDCB_APP_FCOE_ENABLE, DCB_APP_FCOE_ADVERTISE, DCB_APP_FCOE_WILLINGnoFCOE flags. - -Example: DCB_APP_FCOE_ENABLE=yes DCB_APP_FCOE_ADVERTISE=yes
app-fcoe-priorityDCB_APP_FCOE_PRIORITY Priority of FCoE frames. - -Allowed values: 0 - 7
app-fcoe-modeDCB_APP_FCOE_MODEfabricFCoE controller mode. - -Allowed values: fabric, vn2vn
app-iscsi-flagsDCB_APP_ISCSI_ENABLE, DCB_APP_ISCSI_ADVERTISE, DCB_APP_ISCSI_WILLINGnoiSCSI flags.
app-iscsi-priorityDCB_APP_ISCSI_PRIORITY Priority of iSCSI frames. - -Allowed values: 0 - 7
app-fip-flagsDCB_APP_FIP_ENABLE, DCB_APP_FIP_ADVERTISE, DCB_APP_FIP_WILLINGnoFIP flags.
app-fip-priorityDCB_APP_FIP_PRIORITY Priority of FIP frames. - -Allowed values: 0 - 7
priority-flow-control-flagsDCB_PFC_ENABLE, DCB_PFC_ADVERTISE, DCB_PFC_WILLINGnoPriority flow control flags.
priority-flow-controlDCB_PFC_UP Priority flow control values. String of 8 "0" and "1", where "0". means "do not transmit priority pause", "1" means "transmit pause". - -Example: DCB_PFC_UP=01101110
priority-group-flagsDCB_PG_ENABLE, DCB_PG_ADVERTISE, DCB_PG_WILLINGnoPriority groups flags.
priority-group-idDCB_PG_ID Priority groups values. String of eight priorities (0 - 7) or "f" (unrestricted). - -Example: DCB_PG_ID=1205f173
priority-group-bandwidthDCB_PG_PCT Priority groups values. Eight bandwidths (in percent), separated with commas. - -Example: DCB_PG_PCT=10,5,10,15,10,10,10,30
priority-bandwidthDCB_PG_UPPCT Priority values. Eight bandwidths (in percent), separated with commas. The sum of the numbers must be 100. - -Example: DCB_PG_UPPCT=7,13,10,10,15,15,10,20
priority-strict-bandwidthDCB_PG_STRICT Priority values. String of eight "0" or "1", where "0" means "may not utilize all bandwidth", "1" means "may utilize all bandwidth". - -Example: DCB_PG_STRICT=01101110
priority-traffic-classDCB_PG_UP2TC
optionsBONDING_OPTS  Priority values. String of eight traffic class values (0 - 7). +Bonding options. -Example: DCB_PG_UP2TC=01623701
-

- All DCB related configuration is a NetworkManager extension. DCB=yes must be - used explicitly to enable DCB so that the rest of the DCB_* variables can apply. -

-
-

Table 19. ethtool setting

-
+
+

Table 17. bond-port setting

+
@@ -1336,12 +1101,19 @@ Example: DCB_PG_UP2TC=01623701 - + + + + + +
Default Description
queue-idBONDING_OPTS: queue-id=0Queue ID. + +Allowed values: 0 - 65535

-

Table 20. hostname setting

-
+

Table 18. bridge setting

+
@@ -1356,288 +1128,231 @@ Example: DCB_PG_UP2TC=01623701 - - + - - + + - - - - + + + + + + + + + +Allowed values: 0 - 32768 - - - - + + + +Allowed values: 2 - 30 - - - - + + + +Allowed values: 1 - 10 - -
priorityHOSTNAME_PRIORITY(+) +mac-addressBRIDGE_MACADDR(+) missing variable means global value or 100hostname priority - -Example: HOSTNAME_PRIORITY=50 MAC address of the bridge. Note that this requires a recent kernel support, originally introduced in 3.15 upstream kernel) BRIDGE_MACADDR for bridges is an NM extension.
from-dhcpHOSTNAME_FROM_DHCP(+) -missing variable means global default or 1whether the system hostname can be determined from DHCP +stpSTPnoSpan tree protocol participation.
priorityBRIDGING_OPTS: priority=32768STP priority. -Example: HOSTNAME_FROM_DHCP=0,1
from-dhcpHOSTNAME_FROM_DNS_LOOKUP(+) -missing variable means global default or 1whether the system hostname can be determined from reverse DNS lookup +forward-delayDELAY15STP forwarding delay. -Example: HOSTNAME_FROM_DNS_LOOKUP=0,1
only-best-deviceHOSTNAME_ONLY_FROM_DEFAULT(+) -missing variable means global default or 1whether the hostname can be determined only from devices with the default route +hello-timeBRIDGING_OPTS: hello_time=2STP hello time. -Example: HOSTNAME_ONLY_FROM_DEFAULT=0,1
-
-
-

Table 21. infiniband setting

-
------ - - - - - - - - - - - + + + +Allowed values: 6 - 40 - - - - + + + + - - - - + + + + - - - - + + + +Allowed values: 0 or 1 - - - - - - -
PropertyIfcfg-rh VariableDefaultDescription
mac-addressHWADDR IBoIP 20-byte hardware address of the device (in traditional hex-digits-and-colons notation). Note that for initscripts this is the current MAC address of the device as found during ifup. For NetworkManager this is the permanent MAC address. Or in case no permanent MAC address exists, the MAC address initially configured on the device. +max-ageBRIDGING_OPTS: max_age=20STP maximum message age. -Example: HWADDR=01:02:03:04:05:06:07:08:09:0A:01:02:03:04:05:06:07:08:09:11
mtuMTU MTU of the interface.ageing-timeBRIDGING_OPTS: ageing_time=300Ethernet MAC ageing time. + +Allowed values: 0 - 1000000
transport-modeCONNECTED_MODECONNECTED_MODE=noCONNECTED_MODE=yes for "connected" mode, CONNECTED_MODE=no for "datagram" modemulticast-snoopingBRIDGING_OPTS: multicast_snooping=1IGMP snooping support. + +Allowed values: 0 or 1
p-keyPKEY_ID (and PKEY=yes)PKEY=noInfiniBand P_Key. The value can be a hex number prefixed with "0x" or a decimal number. When PKEY_ID is specified, PHYSDEV and DEVICE also must be specified. +vlan-filteringBRIDGING_OPTS: vlan_filtering=0VLAN filtering support. -Example: PKEY=yes PKEY_ID=2 PHYSDEV=mlx4_ib0 DEVICE=mlx4_ib0.8002
parentPHYSDEV (PKEY=yes)PKEY=noInfiniBand parent device. - -Example: PHYSDEV=ib0
-
-
-

Table 22. ipv4 setting

-
------ - - - - - - - - - - - - + + + +Allowed values: 0 - 4094 - - + + - - - - - - - +Example: BRIDGE_VLANS="1 pvid untagged,20,300-400 untagged" - - + + - +Example: BRIDGING_OPTS="group_address=01:80:C2:00:00:0A" - - + + - - - - - - - - - - - - - - - - - - - - - - - - - +Example: BRIDGING_OPTS="vlan_protocol=802.1Q" - - - - + + + + - - - - + + + + - - - - + + + + - - - - + + + + - - - - + + + + - - - - + + + +Example: BRIDGING_OPTS="multicast_last_member_count=4" - - - - + + + +Example: BRIDGING_OPTS="multicast_last_member_interval=200" - - - - + + + +Example: BRIDGING_OPTS="multicast_membership_interval=16000" - - - - + + + +Example: BRIDGING_OPTS="multicast_querier_interval=20000" - - - - + + + +Example: BRIDGING_OPTS="multicast_query_interval=22500" - - - - + + + +Example: BRIDGING_OPTS="multicast_query_response_interval=2000" - - - - + + + +Example: BRIDGING_OPTS="multicast_startup_query_count=4" - - - - + + + +Example: BRIDGING_OPTS="multicast_startup_query_interval=4000"
PropertyIfcfg-rh VariableDefaultDescription
methodBOOTPROTOnoneMethod used for IPv4 protocol configuration. +vlan-default-pvidBRIDGING_OPTS: default_pvid=1default VLAN PVID. -Allowed values: none, dhcp (bootp), static, ibft, autoip, shared
dnsDNS1, DNS2, ...vlansBRIDGE_VLANS  List of DNS servers. Even if NetworkManager supports many DNS servers, initscripts and resolver only care about the first three, usually. +List of VLANs on the bridge -Example: DNS1=1.2.3.4 DNS2=10.0.0.254 DNS3=8.8.8.8
dns-searchDOMAIN List of DNS search domains.
addressesIPADDR, PREFIX (NETMASK), IPADDR1, PREFIX1 (NETMASK1), ...group-addressBRIDGING_OPTS: group_address=  List of static IP addresses. +STP group address. -Example: IPADDR=10.5.5.23 PREFIX=24 IPADDR1=1.1.1.2 PREFIX1=16
gatewayGATEWAYvlan-protocolBRIDGING_OPTS: vlan_protocol=  Gateway IP address. +VLAN filtering protocol. -Example: GATEWAY=10.5.5.1
routesADDRESS1, NETMASK1, GATEWAY1, METRIC1, OPTIONS1, ... List of static routes. They are not stored in ifcfg-* file, but in route-* file instead.
ignore-auto-routesPEERROUTES(+) -yesPEERROUTES has the opposite meaning as 'ignore-auto-routes' property.
ignore-auto-dnsPEERDNSyesPEERDNS has the opposite meaning as 'ignore-auto-dns' property.
dhcp-send-hostnameDHCP_SEND_HOSTNAME(+) -yesWhether DHCP_HOSTNAME should be sent to the DHCP server.
dhcp-hostnameDHCP_HOSTNAME Hostname to send to the DHCP server. When both DHCP_HOSTNAME and DHCP_FQDN are specified only the latter is used.vlan-stats-enabledBRIDGING_OPTS: vlan_stats_enabled=0 + + +Example: BRIDGING_OPTS="vlan_stats_enabled=1"
never-defaultDEFROUTE (GATEWAYDEV in /etc/sysconfig/network)yesDEFROUTE=no tells NetworkManager that this connection should not be assigned the default route. DEFROUTE has the opposite meaning as 'never-default' property.multicast-routerBRIDGING_OPTS: multicast_router=auto + + +Example: BRIDGING_OPTS="multicast_router=enabled" + +Allowed values: auto, enabled, disabled
may-failIPV4_FAILURE_FATAL(+) -noIPV4_FAILURE_FATAL has the opposite meaning as 'may-fail' property.multicast-query-use-ifaddrBRIDGING_OPTS: multicast_query_use_ifaddr=0 + + +Example: BRIDGING_OPTS="multicast_query-use_ifaddr=1"
route-metricIPV4_ROUTE_METRIC(+) --1IPV4_ROUTE_METRIC is the default IPv4 metric for routes on this connection. If set to -1, a default metric based on the device type is used.multicast-querierBRIDGING_OPTS: multicast_querier=0 + + +Example: BRIDGING_OPTS="multicast_querier=1"
route-tableIPV4_ROUTE_TABLE(+) -0IPV4_ROUTE_TABLE enables policy-routing and sets the default routing table.multicast-hash-maxBRIDGING_OPTS: multicast_hash_max=4096 + + +Example: BRIDGING_OPTS="multicast_hash_max=8192"
dns-optionsRES_OPTIONS(+) - List of DNS options to be added to /etc/resolv.conf +multicast-last-member-countBRIDGING_OPTS: multicast_last_member_count=2 + -Example: RES_OPTIONS=ndots:2 timeout:3
dns-priorityIPV4_DNS_PRIORITY(+) -0The priority for DNS servers of this connection. Lower values have higher priority. If zero, the default value will be used (50 for VPNs, 100 for other connections). A negative value prevents DNS from other connections with greater values to be used. +multicast-last-member-intervalBRIDGING_OPTS: multicast_last_member_interval=100 + -Example: IPV4_DNS_PRIORITY=20
dhcp-client-idDHCP_CLIENT_ID(+) - A string sent to the DHCP server to identify the local machine. A binary value can be specified using hex notation ('aa:bb:cc'). +multicast-membership-intervalBRIDGING_OPTS: multicast_membership_interval=26000 + -Example: DHCP_CLIENT_ID=ax-srv-1; DHCP_CLIENT_ID=01:44:44:44:44:44:44
dad-timeoutACD_TIMEOUT(+), ARPING_WAITmissing variable means global default (config override or zero)Timeout (in milliseconds for ACD_TIMEOUT or in seconds for ARPING_WAIT) for address conflict detection before configuring IPv4 addresses. 0 turns off the ACD completely, -1 means default value. +multicast-querier-intervalBRIDGING_OPTS: multicast_querier_interval=25500 + -Example: ACD_TIMEOUT=2000 or ARPING_WAIT=2
dhcp-timeoutIPV4_DHCP_TIMEOUT(+) - A timeout after which the DHCP transaction fails in case of no response. +multicast-query-intervalBRIDGING_OPTS: multicast_query_interval=12500 + -Example: IPV4_DHCP_TIMEOUT=10
dhcp-fqdnDHCP_FQDN FQDN to send to the DHCP server. When both DHCP_HOSTNAME and DHCP_FQDN are specified only the latter is used. +multicast-query-response-intervalBRIDGING_OPTS: multicast_query_response_interval=1000 + -Example: DHCP_FQDN=foo.bar.com
dhcp-vendor-class-identifierDHCP_VENDOR_CLASS_IDENTIFIER(+) - The Vendor Class Identifier DHCP option (60). +multicast-startup-query-countBRIDGING_OPTS: multicast_startup_query_count=2 + -Example: DHCP_VENDOR_CLASS_IDENTIFIER=foo
link-localIPV4_LINK_LOCAL(+) - Configure link-local IP address in interaction with method +multicast-startup-query-intervalBRIDGING_OPTS: multicast_startup_query_interval=3125 + -Example: IPV4_LINK_LOCAL=auto

-

Table 23. ipv6 setting

-
+

Table 19. bridge-port setting

+
@@ -1652,181 +1367,288 @@ Example: IPV4_LINK_LOCAL=auto - - - - - - - - - - + + + + - - + + + + + + + + + + + + + + + + + +
methodIPV6INIT, IPV6FORWARDING, IPV6_AUTOCONF, DHCPV6C, IPV6_DISABLEDIPV6INIT=yes; IPV6FORWARDING=no; IPV6_AUTOCONF=!IPV6FORWARDING, DHCPV6=noMethod used for IPv6 protocol configuration. ignore ~ IPV6INIT=no; auto ~ IPV6_AUTOCONF=yes; dhcp ~ IPV6_AUTOCONF=no and DHCPV6C=yes; disabled ~ IPV6_DISABLED=yes
dnsDNS1, DNS2, ... List of DNS servers. NetworkManager uses the variables both for IPv4 and IPv6.priorityBRIDGING_OPTS: priority=32STP priority. + +Allowed values: 0 - 63
dns-searchIPV6_DOMAIN(+) +path-costBRIDGING_OPTS: path_cost=100STP cost. + +Allowed values: 1 - 65535
hairpin-modeBRIDGING_OPTS: hairpin_mode=yesHairpin mode of the bridge port.
vlansBRIDGE_PORT_VLANS List of VLANs on the bridge port + +Example: BRIDGE_PORT_VLANS="1 pvid untagged,20,300-400 untagged"
+
+
+

Table 20. connection setting

+
++++++ + + + + + + + + + + - + - - + + - + - - + + - + - - + + - + - - + + + + + + + + + + + + + - + - - + - - + + - - + + - + - - + - +Example: MULTI_CONNECT=3 - - + + - +Example: ZONE=Work - - - - + + + + - - - - + + + + - - + - - + + - - + - - + + - - + - +Example: GATEWAY_PING_TIMEOUT=5 - - + - +Example: CONNECTION_METERED=yes + +Allowed values: yes,no,unknown - - + - - + +Allowed values: boolean value or 'rx' - - - - + + + + + + + + + +Allowed values: yes,no,resolve - - - - + + + +Example: LLMNR=yes + +Allowed values: yes,no,resolve - - + - - + +Allowed values: yes,no,opportunistic - - + - - + +Example: MPTCP_FLAGS="signal,subflow" + + + + + + + + + + + + + + + + + +
PropertyIfcfg-rh VariableDefaultDescription
idNAME(+)  List of DNS search domains.User friendly name for the connection profile.
addressesIPV6ADDR, IPV6ADDR_SECONDARIESuuidUUID(+) +  List of static IP addresses. - -Example: IPV6ADDR=ab12:9876::1 IPV6ADDR_SECONDARIES="ab12:9876::2 ab12:9876::3"UUID for the connection profile. When missing, NetworkManager creates the UUID itself (by hashing the filename).
gatewayIPV6_DEFAULTGWstable-idSTABLE_ID(+) +  Gateway IP address. - -Example: IPV6_DEFAULTGW=abbe::1Token to generate stable IDs.
routes(none)interface-nameDEVICE  List of static routes. They are not stored in ifcfg-* file, but in route6-* file instead in the form of command line for 'ip route add'.Interface name of the device this profile is bound to. The variable can be left out when the profile should apply for more devices. Note that DEVICE can be required for some connection types.
ignore-auto-routesIPV6_PEERROUTES(+) +typeTYPE (DEVICETYPE, DEVICE) Base type of the connection. DEVICETYPE is used for teaming connections. + +Example: TYPE=Ethernet; TYPE=Bond; TYPE=Bridge; DEVICETYPE=TeamPort + +Allowed values: Ethernet, Wireless, InfiniBand, Bridge, Bond, Vlan, Team, TeamPort
permissionsUSERS(+)  Restrict to certain users the access to this connection, and allow the connection to be active only when at least one of the specified users is logged into an active session. + +Example: USERS="joe bob"
autoconnectONBOOT yesIPV6_PEERROUTES has the opposite meaning as 'ignore-auto-routes' property.Whether the connection should be autoconnected (not only while booting).
ignore-auto-dnsIPV6_PEERDNS(+) +autoconnect-priorityAUTOCONNECT_PRIORITY(+) yesIPV6_PEERDNS has the opposite meaning as 'ignore-auto-dns' property.0Connection priority for automatic activation. Connections with higher numbers are preferred when selecting profiles for automatic activation. + +Example: AUTOCONNECT_PRIORITY=20 + +Allowed values: -999 to 999
dhcp-hostnameDHCPV6_HOSTNAMEautoconnect-retriesAUTOCONNECT_RETRIES(+) +  Hostname to send the DHCP server.The number of times a connection should be autoactivated before giving up and switching to the next one. + +Example: AUTOCONNECT_RETRIES=1 + +Allowed values: -1 (use global default), 0 (forever) or a positive value
dhcp-timeoutIPV6_DHCP_TIMEOUT(+) +multi-connectMULTI_CONNECT(+)  A timeout after which the DHCP transaction fails in case of no response. +whether the profile can be active on multiple devices at a given moment. The values are numbers corresponding to #NMConnectionMultiConnect enum. -Example: IPV6_DHCP_TIMEOUT=10
dhcp-hostname-flagsDHCPV6_HOSTNAME_FLAGSzoneZONE(+) +  flags for the DHCP hostname property +Trust level of this connection. The string is usually used for a firewall. -Example: DHCPV6_HOSTNAME_FLAGS=5
never-defaultIPV6_DEFROUTE(+), (and IPV6_DEFAULTGW, IPV6_DEFAULTDEV in /etc/sysconfig/network)IPV6_DEFROUTE=yes (when no variable specified)IPV6_DEFROUTE=no tells NetworkManager that this connection should not be assigned the default IPv6 route. IPV6_DEFROUTE has the opposite meaning as 'never-default' property.masterMASTER, MASTER_UUID, TEAM_MASTER, TEAM_MASTER_UUID, BRIDGE, BRIDGE_UUID Reference to master connection. The variable used depends on the connection type and the value. In general, if the *_UUID variant is present, the variant without *_UUID is ignored. NetworkManager attempts to write both for compatibility with legacy tooling.
may-failIPV6_FAILURE_FATAL(+) -noIPV6_FAILURE_FATAL has the opposite meaning as 'may-fail' property.slave-typeMASTER, MASTER_UUID, TEAM_MASTER, TEAM_MASTER_UUID, DEVICETYPE, BRIDGE, BRIDGE_UUID Slave type doesn't map directly to a variable, but it is recognized using different variables. MASTER and MASTER_UUID for bonding, TEAM_MASTER, TEAM_MASTER_UUID and DEVICETYPE for teaming, BRIDGE and BRIDGE_UUID for bridging.
route-metricIPV6_ROUTE_METRIC(+) +autoconnect-slavesAUTOCONNECT_SLAVES(+) -1IPV6_ROUTE_METRIC is the default IPv6 metric for routes on this connection. If set to -1, a default metric based on the device type is used.missing variable means global defaultWhether slaves of this connection should be auto-connected when this connection is activated.
route-tableIPV6_ROUTE_TABLE(+) +secondariesSECONDARY_UUIDS(+) 0IPV6_ROUTE_TABLE enables policy-routing and sets the default routing table. UUID of VPN connections that should be activated together with this connection.
dns-priorityIPV6_DNS_PRIORITY(+) +gateway-ping-timeoutGATEWAY_PING_TIMEOUT(+) 0The priority for DNS servers of this connection. Lower values have higher priority. If zero, the default value will be used (50 for VPNs, 100 for other connections). A negative value prevents DNS from other connections with greater values to be used. +If greater than zero, the IP connectivity will be checked by pinging the gateway and waiting for the specified timeout (in seconds). -Example: IPV6_DNS_PRIORITY=20
dns-optionsIPV6_RES_OPTIONS(+) +meteredCONNECTION_METERED(+)  List of DNS options to be added to /etc/resolv.conf +Whether the device is metered -Example: IPV6_RES_OPTIONS=ndots:2 timeout:3
ip6-privacyIPV6_PRIVACY, IPV6_PRIVACY_PREFER_PUBLIC_IP(+) +lldpLLDP(+) noConfigure IPv6 Privacy Extensions for SLAAC (RFC4941). +missing variable means global defaultwhether LLDP is enabled for the connection -Example: IPV6_PRIVACY=rfc3041 IPV6_PRIVACY_PREFER_PUBLIC_IP=yes +Example: LLDP=no -Allowed values: IPV6_PRIVACY: no, yes (rfc3041 or rfc4941); IPV6_PRIVACY_PREFER_PUBLIC_IP: yes, no
addr-gen-modeIPV6_ADDR_GEN_MODE"default-or-eui64"Configure IPv6 Stable Privacy addressing for SLAAC (RFC7217). +auth-retriesAUTH_RETRIES(+) +0Number of retries for authentication.
mdnsMDNS(+) +missing variable means global defaultWhether or not mDNS is enabled for the connection -Example: IPV6_ADDR_GEN_MODE=stable-privacy +Example: MDNS=yes -Allowed values: IPV6_ADDR_GEN_MODE: default, default-or-eui64, eui64, stable-privacy
tokenIPV6_TOKEN The IPv6 tokenized interface identifier token +llmnrLLMNR(+) +missing variable means global defaultWhether or not LLMNR is enabled for the connection -Example: IPV6_TOKEN=::53
dhcp-timeoutIPV6_RA_TIMEOUT(+) +dns-over-tlsDNS_OVER_TLS(+)  A timeout for waiting Router Advertisements in seconds. +missing variable means global defaultWhether or not DNSOverTls is enabled for the connection -Example: IPV6_RA_TIMEOUT=10
dhcp-duidDHCPV6_DUID(+) +mptcp-flagsMPTCP_FLAGS(+)  A string sent to the DHCPv6 server to identify the local machine. Apart from the special values "lease", "stable-llt", "stable-ll", "stable-uuid", "llt" and "ll" a binary value in hex format is expected. An hex string where each octet is separated by a colon is also accepted. +missing variable means global defaultThe MPTCP flags that indicate whether MPTCP is enabled and which flags to use for the address endpoints. -Example: DHCPV6_DUID=LL; DHCPV6_DUID=0301deadbeef0001; DHCPV6_DUID=03:01:de:ad:be:ef:00:01
wait-device-timeoutDEVTIMEOUT(+) + for initscripts compatibility, this variable must be a whole integer. If necessary, NetworkManager stores also a fractional component for the milliseconds. + +Example: DEVTIMEOUT=5 + +Allowed values: timeout in seconds.
mud-urlMUD_URL MUD_URL to be sent by device (See RFC 8520). + +Example: https://yourdevice.example.com/model.json + +Allowed values: a valid URL that points to recommended policy for this device
wait-activation-delayWAIT_ACTIVATION_DELAY(+) + Time in milliseconds to wait for connection to be considered activated. The wait will start after the pre-up dispatcher event. + +Example: WAIT_ACTIVATION_DELAY=5000 + +Allowed values: delay in milliseconds.

-

Table 24. match setting

-
+

Table 21. dcb setting

+
@@ -1839,19 +1661,129 @@ Example: DHCPV6_DUID=LL; DHCPV6_DUID=0301deadbeef0001; DHCPV6_DU - - - + + + + + + + + + + - - +Allowed values: 0 - 7 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Default Description
pathMATCH_PATH
app-fcoe-flagsDCB_APP_FCOE_ENABLE, DCB_APP_FCOE_ADVERTISE, DCB_APP_FCOE_WILLINGnoFCOE flags. + +Example: DCB_APP_FCOE_ENABLE=yes DCB_APP_FCOE_ADVERTISE=yes
app-fcoe-priorityDCB_APP_FCOE_PRIORITY  space-separated list of paths to match against the udev property ID_PATHS of devices +Priority of FCoE frames. -Example: MATCH_PATH="pci-0000:01:00.0 pci-0000:0c:00.0"
app-fcoe-modeDCB_APP_FCOE_MODEfabricFCoE controller mode. + +Allowed values: fabric, vn2vn
app-iscsi-flagsDCB_APP_ISCSI_ENABLE, DCB_APP_ISCSI_ADVERTISE, DCB_APP_ISCSI_WILLINGnoiSCSI flags.
app-iscsi-priorityDCB_APP_ISCSI_PRIORITY Priority of iSCSI frames. + +Allowed values: 0 - 7
app-fip-flagsDCB_APP_FIP_ENABLE, DCB_APP_FIP_ADVERTISE, DCB_APP_FIP_WILLINGnoFIP flags.
app-fip-priorityDCB_APP_FIP_PRIORITY Priority of FIP frames. + +Allowed values: 0 - 7
priority-flow-control-flagsDCB_PFC_ENABLE, DCB_PFC_ADVERTISE, DCB_PFC_WILLINGnoPriority flow control flags.
priority-flow-controlDCB_PFC_UP Priority flow control values. String of 8 "0" and "1", where "0". means "do not transmit priority pause", "1" means "transmit pause". + +Example: DCB_PFC_UP=01101110
priority-group-flagsDCB_PG_ENABLE, DCB_PG_ADVERTISE, DCB_PG_WILLINGnoPriority groups flags.
priority-group-idDCB_PG_ID Priority groups values. String of eight priorities (0 - 7) or "f" (unrestricted). + +Example: DCB_PG_ID=1205f173
priority-group-bandwidthDCB_PG_PCT Priority groups values. Eight bandwidths (in percent), separated with commas. + +Example: DCB_PG_PCT=10,5,10,15,10,10,10,30
priority-bandwidthDCB_PG_UPPCT Priority values. Eight bandwidths (in percent), separated with commas. The sum of the numbers must be 100. + +Example: DCB_PG_UPPCT=7,13,10,10,15,15,10,20
priority-strict-bandwidthDCB_PG_STRICT Priority values. String of eight "0" or "1", where "0" means "may not utilize all bandwidth", "1" means "may utilize all bandwidth". + +Example: DCB_PG_STRICT=01101110
priority-traffic-classDCB_PG_UP2TC Priority values. String of eight traffic class values (0 - 7). + +Example: DCB_PG_UP2TC=01623701
-
-

Table 25. ovs-bridge setting

-
+

+ All DCB related configuration is a NetworkManager extension. DCB=yes must be + used explicitly to enable DCB so that the rest of the DCB_* variables can apply. +

+
+

Table 22. ethtool setting

+
@@ -1868,8 +1800,8 @@ Example: MATCH_PATH="pci-0000:01:00.0 pci-0000:0c:00.0"

-

Table 26. ovs-dpdk setting

-
+

Table 23. hostname setting

+
@@ -1882,12 +1814,49 @@ Example: MATCH_PATH="pci-0000:01:00.0 pci-0000:0c:00.0" - + + + + + + + + + + + + + + + + + + + + + + + + + +
Default Description
priorityHOSTNAME_PRIORITY(+) +missing variable means global value or 100hostname priority + +Example: HOSTNAME_PRIORITY=50
from-dhcpHOSTNAME_FROM_DHCP(+) +missing variable means global default or 1whether the system hostname can be determined from DHCP + +Example: HOSTNAME_FROM_DHCP=0,1
from-dns-lookupHOSTNAME_FROM_DNS_LOOKUP(+) +missing variable means global default or 1whether the system hostname can be determined from reverse DNS lookup + +Example: HOSTNAME_FROM_DNS_LOOKUP=0,1
only-best-deviceHOSTNAME_ONLY_FROM_DEFAULT(+) +missing variable means global default or 1whether the hostname can be determined only from devices with the default route + +Example: HOSTNAME_ONLY_FROM_DEFAULT=0,1

-

Table 27. ovs-external-ids setting

-
+

Table 24. infiniband setting

+
@@ -1900,66 +1869,49 @@ Example: MATCH_PATH="pci-0000:01:00.0 pci-0000:0c:00.0" - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Default Description
mac-addressHWADDR IBoIP 20-byte hardware address of the device (in traditional hex-digits-and-colons notation). Note that for initscripts this is the current MAC address of the device as found during ifup. For NetworkManager this is the permanent MAC address. Or in case no permanent MAC address exists, the MAC address initially configured on the device. + +Example: HWADDR=01:02:03:04:05:06:07:08:09:0A:01:02:03:04:05:06:07:08:09:11
mtuMTU MTU of the interface.
transport-modeCONNECTED_MODECONNECTED_MODE=noCONNECTED_MODE=yes for "connected" mode, CONNECTED_MODE=no for "datagram" mode
p-keyPKEY_ID (and PKEY=yes)PKEY=noInfiniBand P_Key. The value can be a hex number prefixed with "0x" or a decimal number. When PKEY_ID is specified, PHYSDEV and DEVICE also must be specified. + +Example: PKEY=yes PKEY_ID=2 PHYSDEV=mlx4_ib0 DEVICE=mlx4_ib0.8002
parentPHYSDEV (PKEY=yes)PKEY=noInfiniBand parent device. + +Example: PHYSDEV=ib0

-

Table 28. ovs-interface setting

-
------ - - - - - - - -
PropertyIfcfg-rh VariableDefaultDescription
-
-
-

Table 29. ovs-patch setting

-
------ - - - - - - - -
PropertyIfcfg-rh VariableDefaultDescription
-
-
-

Table 30. ovs-port setting

-
------ - - - - - - - -
PropertyIfcfg-rh VariableDefaultDescription
-
-
-

Table 31. proxy setting

-
+

Table 25. ipv4 setting

+
@@ -1975,126 +1927,192 @@ Example: MATCH_PATH="pci-0000:01:00.0 pci-0000:0c:00.0" - + - +Allowed values: none, dhcp (bootp), static, ibft, autoip, shared - - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + - + - - + + + + + + + + + + + + + - +Example: RES_OPTIONS=ndots:2 timeout:3 - - + + + + + + + + + + + + + - +Example: DHCP_CLIENT_ID=ax-srv-1; DHCP_CLIENT_ID=01:44:44:44:44:44:44 - -
methodPROXY_METHOD(+) -BOOTPROTO noneMethod for proxy configuration. For "auto", WPAD is used for proxy configuration, or set the PAC file via PAC_URL or PAC_SCRIPT. +Method used for IPv4 protocol configuration. -Allowed values: none, auto
browser-onlyBROWSER_ONLY(+) +dnsDNS1, DNS2, ... List of DNS servers. Even if NetworkManager supports many DNS servers, initscripts and resolver only care about the first three, usually. + +Example: DNS1=1.2.3.4 DNS2=10.0.0.254 DNS3=8.8.8.8
dns-searchDOMAIN List of DNS search domains.
addressesIPADDR, PREFIX (NETMASK), IPADDR1, PREFIX1 (NETMASK1), ... List of static IP addresses. + +Example: IPADDR=10.5.5.23 PREFIX=24 IPADDR1=1.1.1.2 PREFIX1=16
gatewayGATEWAY Gateway IP address. + +Example: GATEWAY=10.5.5.1
routesADDRESS1, NETMASK1, GATEWAY1, METRIC1, OPTIONS1, ... List of static routes. They are not stored in ifcfg-* file, but in route-* file instead.
ignore-auto-routesPEERROUTES(+) +yesPEERROUTES has the opposite meaning as 'ignore-auto-routes' property.
ignore-auto-dnsPEERDNSyesPEERDNS has the opposite meaning as 'ignore-auto-dns' property.
dhcp-send-hostnameDHCP_SEND_HOSTNAME(+) +yesWhether DHCP_HOSTNAME should be sent to the DHCP server.
dhcp-hostnameDHCP_HOSTNAME Hostname to send to the DHCP server. When both DHCP_HOSTNAME and DHCP_FQDN are specified only the latter is used.
never-defaultDEFROUTE (GATEWAYDEV in /etc/sysconfig/network)yesDEFROUTE=no tells NetworkManager that this connection should not be assigned the default route. DEFROUTE has the opposite meaning as 'never-default' property.
may-failIPV4_FAILURE_FATAL(+) noWhether the proxy configuration is for browser only.IPV4_FAILURE_FATAL has the opposite meaning as 'may-fail' property.
pac-urlPAC_URL(+) +route-metricIPV4_ROUTE_METRIC(+) +-1IPV4_ROUTE_METRIC is the default IPv4 metric for routes on this connection. If set to -1, a default metric based on the device type is used.
route-tableIPV4_ROUTE_TABLE(+) +0IPV4_ROUTE_TABLE enables policy-routing and sets the default routing table.
dns-optionsRES_OPTIONS(+)  URL for PAC file. +List of DNS options to be added to /etc/resolv.conf -Example: PAC_URL=http://wpad.mycompany.com/wpad.dat
pac-scriptPAC_SCRIPT(+) +dns-priorityIPV4_DNS_PRIORITY(+) +0The priority for DNS servers of this connection. Lower values have higher priority. If zero, the default value will be used (50 for VPNs, 100 for other connections). A negative value prevents DNS from other connections with greater values to be used. + +Example: IPV4_DNS_PRIORITY=20
auto-route-ext-gwIPV4_AUTO_ROUTE_EXT_GW(+) +yesVPN connections will default to add the route automatically unless this setting is set to %FALSE. For other connection types, adding such an automatic route is currently not supported and setting this to %TRUE has no effect.
dhcp-client-idDHCP_CLIENT_ID(+)  The PAC script. This is an UTF-8 encoded javascript code that defines a FindProxyForURL() function. +A string sent to the DHCP server to identify the local machine. A binary value can be specified using hex notation ('aa:bb:cc'). -Example: PAC_SCRIPT="function FindProxyForURL (url, host) { return 'PROXY proxy.example.com:8080; DIRECT'; }"
-
-
-

Table 32. sriov setting

-
------ - - - - - - - - - + + + + + + + - +Example: IPV4_DHCP_TIMEOUT=10 - - + + - +Example: DHCP_HOSTNAME_FLAGS=5 - - - - + + + +Example: DHCP_FQDN=foo.bar.com - -
PropertyIfcfg-rh VariableDefaultDescription
total-vfsSRIOV_TOTAL_VFS(+) +dad-timeoutACD_TIMEOUT(+), ARPING_WAITmissing variable means global default (config override or zero)Timeout (in milliseconds for ACD_TIMEOUT or in seconds for ARPING_WAIT) for address conflict detection before configuring IPv4 addresses. 0 turns off the ACD completely, -1 means default value. + +Example: ACD_TIMEOUT=2000 or ARPING_WAIT=2
dhcp-timeoutIPV4_DHCP_TIMEOUT(+)  The total number of virtual functions to create +A timeout after which the DHCP transaction fails in case of no response. -Example: SRIOV_TOTAL_VFS=16
vfsSRIOV_VF1(+), SRIOV_VF2(+), ...dhcp-hostname-flagsDHCP_HOSTNAME_FLAGS  SR-IOV virtual function descriptors +flags for the DHCP hostname and FQDN properties -Example: SRIOV_VF10="mac=00:11:22:33:44:55", ...
autoprobe-driversSRIOV_AUTOPROBE_DRIVERS(+) -missing variable means global defaultWhether to autoprobe virtual functions by a compatible driver +dhcp-fqdnDHCP_FQDN FQDN to send to the DHCP server. When both DHCP_HOSTNAME and DHCP_FQDN are specified only the latter is used. -Example: SRIOV_AUTOPROBE_DRIVERS=0,1
-
-
-

Table 33. tc setting

-
------ - - - - - - - - - + - +Example: DHCP_VENDOR_CLASS_IDENTIFIER=foo - - + - +Example: IPV4_LINK_LOCAL=auto
PropertyIfcfg-rh VariableDefaultDescription
qdiscsQDISC1(+), QDISC2(+), ..., TC_COMMIT(+) +dhcp-vendor-class-identifierDHCP_VENDOR_CLASS_IDENTIFIER(+)  Queueing disciplines to set on the interface. When no QDISC1, QDISC2, ..., FILTER1, FILTER2, ... keys are present, NetworkManager doesn't touch qdiscs and filters present on the interface, unless TC_COMMIT is set to 'yes'. +The Vendor Class Identifier DHCP option (60). -Example: QDISC1=ingress, QDISC2="root handle 1234: fq_codel"
qdiscsFILTER1(+), FILTER2(+), ..., TC_COMMIT(+) +link-localIPV4_LINK_LOCAL(+)  Traffic filters to set on the interface. When no QDISC1, QDISC2, ..., FILTER1, FILTER2, ... keys are present, NetworkManager doesn't touch qdiscs and filters present on the interface, unless TC_COMMIT is set to 'yes'. +Configure link-local IP address in interaction with method -Example: FILTER1="parent ffff: matchall action simple sdata Input", ...

-

Table 34. team-port setting

-
+

Table 26. ipv6 setting

+
@@ -2107,17 +2125,190 @@ Example: FILTER1="parent ffff: matchall action simple sdata Inpu - - - - - - -
Default Description
configTEAM_PORT_CONFIG Team port configuration in JSON. See man teamd.conf for details.
+ + +method +IPV6INIT, IPV6FORWARDING, IPV6_AUTOCONF, DHCPV6C, IPV6_DISABLED +IPV6INIT=yes; IPV6FORWARDING=no; IPV6_AUTOCONF=!IPV6FORWARDING, DHCPV6=no +Method used for IPv6 protocol configuration. ignore ~ IPV6INIT=no; auto ~ IPV6_AUTOCONF=yes; dhcp ~ IPV6_AUTOCONF=no and DHCPV6C=yes; disabled ~ IPV6_DISABLED=yes + + +dns +DNS1, DNS2, ... +  +List of DNS servers. NetworkManager uses the variables both for IPv4 and IPv6. + + +dns-search +IPV6_DOMAIN(+) + +  +List of DNS search domains. + + +addresses +IPV6ADDR, IPV6ADDR_SECONDARIES +  +List of static IP addresses. + +Example: IPV6ADDR=ab12:9876::1 IPV6ADDR_SECONDARIES="ab12:9876::2 ab12:9876::3" + + +gateway +IPV6_DEFAULTGW +  +Gateway IP address. + +Example: IPV6_DEFAULTGW=abbe::1 + + +routes +(none) +  +List of static routes. They are not stored in ifcfg-* file, but in route6-* file instead in the form of command line for 'ip route add'. + + +ignore-auto-routes +IPV6_PEERROUTES(+) + +yes +IPV6_PEERROUTES has the opposite meaning as 'ignore-auto-routes' property. + + +ignore-auto-dns +IPV6_PEERDNS(+) + +yes +IPV6_PEERDNS has the opposite meaning as 'ignore-auto-dns' property. + + +dhcp-hostname +DHCPV6_HOSTNAME +  +Hostname to send the DHCP server. + + +dhcp-timeout +IPV6_DHCP_TIMEOUT(+) + +  +A timeout after which the DHCP transaction fails in case of no response. + +Example: IPV6_DHCP_TIMEOUT=10 + + +dhcp-hostname-flags +DHCPV6_HOSTNAME_FLAGS +  +flags for the DHCP hostname property + +Example: DHCPV6_HOSTNAME_FLAGS=5 + + +never-default +IPV6_DEFROUTE(+), (and IPV6_DEFAULTGW, IPV6_DEFAULTDEV in /etc/sysconfig/network) +IPV6_DEFROUTE=yes (when no variable specified) +IPV6_DEFROUTE=no tells NetworkManager that this connection should not be assigned the default IPv6 route. IPV6_DEFROUTE has the opposite meaning as 'never-default' property. + + +may-fail +IPV6_FAILURE_FATAL(+) + +no +IPV6_FAILURE_FATAL has the opposite meaning as 'may-fail' property. + + +route-metric +IPV6_ROUTE_METRIC(+) + +-1 +IPV6_ROUTE_METRIC is the default IPv6 metric for routes on this connection. If set to -1, a default metric based on the device type is used. + + +route-table +IPV6_ROUTE_TABLE(+) + +0 +IPV6_ROUTE_TABLE enables policy-routing and sets the default routing table. + + +dns-priority +IPV6_DNS_PRIORITY(+) + +0 +The priority for DNS servers of this connection. Lower values have higher priority. If zero, the default value will be used (50 for VPNs, 100 for other connections). A negative value prevents DNS from other connections with greater values to be used. + +Example: IPV6_DNS_PRIORITY=20 + + +dns-options +IPV6_RES_OPTIONS(+) + +  +List of DNS options to be added to /etc/resolv.conf + +Example: IPV6_RES_OPTIONS=ndots:2 timeout:3 + + +auto-route-ext-gw +IPV6_AUTO_ROUTE_EXT_GW(+) + +yes +VPN connections will default to add the route automatically unless this setting is set to %FALSE. For other connection types, adding such an automatic route is currently not supported and setting this to %TRUE has no effect. + + +ip6-privacy +IPV6_PRIVACY, IPV6_PRIVACY_PREFER_PUBLIC_IP(+) + +no +Configure IPv6 Privacy Extensions for SLAAC (RFC4941). + +Example: IPV6_PRIVACY=rfc3041 IPV6_PRIVACY_PREFER_PUBLIC_IP=yes + +Allowed values: IPV6_PRIVACY: no, yes (rfc3041 or rfc4941); IPV6_PRIVACY_PREFER_PUBLIC_IP: yes, no + + +addr-gen-mode +IPV6_ADDR_GEN_MODE +"default-or-eui64" +Configure IPv6 Stable Privacy addressing for SLAAC (RFC7217). + +Example: IPV6_ADDR_GEN_MODE=stable-privacy + +Allowed values: IPV6_ADDR_GEN_MODE: default, default-or-eui64, eui64, stable-privacy + + +token +IPV6_TOKEN +  +The IPv6 tokenized interface identifier token + +Example: IPV6_TOKEN=::53 + + +ra-timeout +IPV6_RA_TIMEOUT(+) + +  +A timeout for waiting Router Advertisements in seconds. + +Example: IPV6_RA_TIMEOUT=10 + + +dhcp-duid +DHCPV6_DUID(+) + +  +A string sent to the DHCPv6 server to identify the local machine. Apart from the special values "lease", "stable-llt", "stable-ll", "stable-uuid", "llt" and "ll" a binary value in hex format is expected. An hex string where each octet is separated by a colon is also accepted. + +Example: DHCPV6_DUID=LL; DHCPV6_DUID=0301deadbeef0001; DHCPV6_DUID=03:01:de:ad:be:ef:00:01 + + +

-

Table 35. team setting

-
+

Table 27. loopback setting

+
@@ -2131,16 +2322,16 @@ Example: FILTER1="parent ffff: matchall action simple sdata Inpu - - + + - +
Description
configTEAM_CONFIGmtuMTU  Team configuration in JSON. See man teamd.conf for details.MTU of the interface.

-

Table 36. user setting

-
+

Table 28. match setting

+
@@ -2154,18 +2345,18 @@ Example: FILTER1="parent ffff: matchall action simple sdata Inpu - - + + - +Example: MATCH_PATH="pci-0000:01:00.0 pci-0000:0c:00.0"
Description
dataNM_USER_*pathMATCH_PATH  each key/value pair is stored as a separate variable with name composed by concatenating NM_USER_ with the encoded key. The key is encoded by substituting lowercase letters with uppercase and prepending uppercase letters with an underscore. A dot is encoded as a double underscore. Remaining characters are encoded as underscore followed by a 3 digit octal representation of the character. +space-separated list of paths to match against the udev property ID_PATHS of devices -Example: NM_USER_FOO__BAR=something

-

Table 37. veth setting

-
+

Table 29. ovs-bridge setting

+
@@ -2182,8 +2373,8 @@ Example: NM_USER_FOO__BAR=something

-

Table 38. vlan setting

-
+

Table 30. ovs-dpdk setting

+
@@ -2196,57 +2387,12 @@ Example: NM_USER_FOO__BAR=something - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +
Default Description
parentDEVICE or PHYSDEV Parent interface of the VLAN.
idVLAN_ID, DEVICE. VLAN identifier. If VLAN_ID is not set, it is attempted to be detected from the suffix of DEVICE=. Note that older versions of NetworkManager had a bug where they would prefer the detected ID from the DEVICE over VLAN_ID.
flagsGVRP, MVRP, VLAN_FLAGS VLAN flags. - -Allowed values: "yes or "no" for GVRP and MVRP; "LOOSE_BINDING" and "NO_REORDER_HDR" for VLAN_FLAGS
ingress-priority-mapVLAN_INGRESS_PRIORITY_MAP Ingress priority mapping. - -Example: VLAN_INGRESS_PRIORITY_MAP=4:2,3:5
egress-priority-mapVLAN_EGRESS_PRIORITY_MAP Egress priority mapping. - -Example: VLAN_EGRESS_PRIORITY_MAP=5:4,4:1,3:7
interface-namePHYSDEV and VLAN_ID, or DEVICE VLAN interface name. If all variables are set, parent device from PHYSDEV takes precedence over DEVICE, but VLAN id from DEVICE takes precedence over VLAN_ID. - -Example: PHYSDEV=eth0, VLAN_ID=12; or DEVICE=eth0.12

-

Table 39. vrf setting

-
+

Table 31. ovs-external-ids setting

+
@@ -2263,8 +2409,8 @@ Example: PHYSDEV=eth0, VLAN_ID=12; or DEVICE=eth0.12

-

Table 40. wifi-p2p setting

-
+

Table 32. ovs-interface setting

+
@@ -2281,8 +2427,8 @@ Example: PHYSDEV=eth0, VLAN_ID=12; or DEVICE=eth0.12

-

Table 41. 802-3-ethernet setting

-
+

Table 33. ovs-other-config setting

+
@@ -2295,115 +2441,12 @@ Example: PHYSDEV=eth0, VLAN_ID=12; or DEVICE=eth0.12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +
Default Description
port(none) The property is not saved by the plugin.
speedETHTOOL_OPTS Fixed speed for the ethernet link. It is added as "speed" parameter in the ETHTOOL_OPTS variable.
duplexETHTOOL_OPTS Fixed duplex mode for the ethernet link. It is added as "duplex" parameter in the ETHOOL_OPTS variable.
auto-negotiateETHTOOL_OPTS Whether link speed and duplex autonegotiation is enabled. It is not saved only if disabled and no values are provided for the "speed" and "duplex" parameters (skips link configuration).
mac-addressHWADDR Hardware address of the device in traditional hex-digits-and-colons notation (e.g. 00:22:68:14:5A:05). Note that for initscripts this is the current MAC address of the device as found during ifup. For NetworkManager this is the permanent MAC address. Or in case no permanent MAC address exists, the MAC address initially configured on the device.
cloned-mac-addressMACADDR Cloned (spoofed) MAC address in traditional hex-digits-and-colons notation (e.g. 00:22:68:14:5A:99).
generate-mac-address-maskGENERATE_MAC_ADDRESS_MASK(+) - the MAC address mask for generating randomized and stable cloned-mac-address.
mac-address-blacklistHWADDR_BLACKLIST(+) - It denies usage of the connection for any device whose address is listed. - -Example: HWADDR_BLACKLIST="00:22:68:11:69:08 00:11:22:11:44:55"
mtuMTU MTU of the interface.
s390-subchannelsSUBCHANNELS Subchannels for IBM S390 hosts. - -Example: SUBCHANNELS=0.0.b00a,0.0.b00b,0.0.b00c
s390-nettypeNETTYPE Network type of the S390 host. - -Example: NETTYPE=qeth - -Allowed values: "qeth", "lcs" or "ctc"
s390-optionsOPTIONS and PORTNAME, CTCPROTO, S390 device options. All options go to OPTIONS, except for "portname" and "ctcprot" that have their own variables.
wake-on-lanETHTOOL_OPTS, ETHTOOL_WAKE_ON_LAN Wake on Lan mode for ethernet. The setting "ignore" is expressed with "ETHTOOL_WAKE_ON_LAN=ignore". Otherwise, the "ETHTOOL_OPTS" variable is set with the value "wol" and several of the characters "p|u|m|b|a|g|s|f|d" as explained in the ethtool manual page.
wake-on-lan-passwordETHTOOL_OPTS Password for secure-on based Wake-on-Lan. It is added as "sopass" parameter in the ETHTOOL_OPTS variable. - -Example: ETHTOOL_OPTS="wol gs sopass 00:11:22:33:44:55"
accept-all-mac-addressesACCEPT_ALL_MAC_ADDRESSES Enforce the interface to accept all the packets.

-

Table 42. wireguard setting

-
+

Table 34. ovs-patch setting

+
@@ -2420,8 +2463,26 @@ Example: ETHTOOL_OPTS="wol gs sopass 00:11:22:33:44:55"

-

Table 43. 802-11-wireless-security setting

-
+

Table 35. ovs-port setting

+
++++++ + + + + + + + +
PropertyIfcfg-rh VariableDefaultDescription
+
+
+

Table 36. proxy setting

+
@@ -2436,174 +2497,216 @@ Example: ETHTOOL_OPTS="wol gs sopass 00:11:22:33:44:55" - - - - - - - - - - - - - - + - - + +Allowed values: none, auto - - + - + - - + - +Example: PAC_URL=http://wpad.mycompany.com/wpad.dat - - + - +Example: PAC_SCRIPT="function FindProxyForURL (url, host) { return 'PROXY proxy.example.com:8080; DIRECT'; }" + +
key-mgmtKEY_MGMT(+) - Key management method. - -Allowed values: none, ieee8021x, owe, wpa-psk, sae, wpa-eap, wpa-eap-suite-b-192
wep-tx-keyidxDEFAULTKEY1Index of active WEP key. Note that in ifcfg format the index starts counting at 1, while NetworkManager API otherwise is zero based. - -Allowed values: 1, 2, 3, 4
auth-algSECURITYMODE(+) +methodPROXY_METHOD(+)  Authentication algorithm for WEP. +noneMethod for proxy configuration. For "auto", WPAD is used for proxy configuration, or set the PAC file via PAC_URL or PAC_SCRIPT. -Allowed values: restricted, open, leap
protoWPA_ALLOW_WPA(+), WPA_ALLOW_WPA2(+) +browser-onlyBROWSER_ONLY(+) noAllowed WPA protocols, WPA and WPA2 (RSN). - -Allowed values: yes, noWhether the proxy configuration is for browser only.
pairwiseCIPHER_PAIRWISE(+) +pac-urlPAC_URL(+)  Restrict pairwise encryption algorithms, specified as a space separated list. +URL for PAC file. -Allowed values: CCMP, TKIP
groupCIPHER_GROUP(+) +pac-scriptPAC_SCRIPT(+)  Restrict group/broadcast encryption algorithms, specified as a space separated list. +The PAC script. This is an UTF-8 encoded javascript code that defines a FindProxyForURL() function. -Allowed values: CCMP, TKIP, WEP40, WEP104
+
+
+

Table 37. sriov setting

+
++++++ + + + + + + + - - + - +Example: SRIOV_TOTAL_VFS=16 - - + + - + - - + - - + + + +
PropertyIfcfg-rh VariableDefaultDescription
pmfPMF(+) +total-vfsSRIOV_TOTAL_VFS(+)  Enables or disables PMF (802.11w) - -Example: PMF=required +The total number of virtual functions to create -Allowed values: default, disable, optional, required
leap-usernameIEEE_8021X_IDENTITY(+) -vfsSRIOV_VF1(+), SRIOV_VF2(+), ...  Login name for LEAP.SR-IOV virtual function descriptors + +Example: SRIOV_VF10="mac=00:11:22:33:44:55", ...
wep-key0KEY1, KEY_PASSPHRASE1(+) +autoprobe-driversSRIOV_AUTOPROBE_DRIVERS(+)  The first WEP key (used in most networks). See also DEFAULTKEY for key index.missing variable means global defaultWhether to autoprobe virtual functions by a compatible driver + +Example: SRIOV_AUTOPROBE_DRIVERS=0,1
+
+
+

Table 38. tc setting

+
++++++ + + + + + + + - - + - + - - + - + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + +
PropertyIfcfg-rh VariableDefaultDescription
wep-key1KEY2, KEY_PASSPHRASE2(+) +qdiscsQDISC1(+), QDISC2(+), ..., TC_COMMIT(+)  WEP key with index 1. See also DEFAULTKEY for key index.Queueing disciplines to set on the interface. When no QDISC1, QDISC2, ..., FILTER1, FILTER2, ... keys are present, NetworkManager doesn't touch qdiscs and filters present on the interface, unless TC_COMMIT is set to 'yes'. + +Example: QDISC1=ingress, QDISC2="root handle 1234: fq_codel"
wep-key2KEY3, KEY_PASSPHRASE3(+) +tfiltersFILTER1(+), FILTER2(+), ..., TC_COMMIT(+)  WEP key with index 2. See also DEFAULTKEY for key index.Traffic filters to set on the interface. When no QDISC1, QDISC2, ..., FILTER1, FILTER2, ... keys are present, NetworkManager doesn't touch qdiscs and filters present on the interface, unless TC_COMMIT is set to 'yes'. + +Example: FILTER1="parent ffff: matchall action simple sdata Input", ...
wep-key3KEY4, KEY_PASSPHRASE4(+) - WEP key with index 3. See also DEFAULTKEY for key index.
wep-key-flagsWEP_KEY_FLAGS(+) - Password flags for KEY<i>, KEY_PASSPHRASE<i> password. (see the section called “Secret flag types:” for _FLAGS values)
pskWPA_PSK Pre-Shared-Key for WPA networks.
psk-flagsWPA_PSK_FLAGS(+) - Password flags for WPA_PSK_FLAGS. (see the section called “Secret flag types:” for _FLAGS values) - -Example: WPA_PSK_FLAGS=user
leap-passwordIEEE_8021X_PASSWORD(+) - Password for LEAP. It can also go to "key-" lookaside file, or it can be owned by a secret agent.
leap-password-flagsIEEE_8021X_PASSWORD_FLAGS(+) - Password flags for IEEE_8021X_PASSWORD_FLAGS. (see the section called “Secret flag types:” for _FLAGS values)
wep-key-typeKEY<i> or KEY_PASSPHRASE<i>(+); KEY_TYPE(+) -
+
+
+

Table 39. team setting

+
++++++ + + + + + + + + + - - - - - + + +
PropertyIfcfg-rh VariableDefaultDescription
configTEAM_CONFIG  KEY is used for "key" type (10 or 26 hexadecimal characters, or 5 or 13 character string prefixed with "s:"). KEY_PASSPHRASE is used for WEP passphrases. KEY_TYPE specifies the key type and can be either 'key' or 'passphrase'. KEY_TYPE is redundant and can be omitted. - -Example: KEY1=s:ahoj, KEY1=0a1c45bc02, KEY_PASSPHRASE1=mysupersecretkey
wps-methodWPS_METHODTeam configuration in JSON. See man teamd.conf for details.
+
+
+

Table 40. team-port setting

+
++++++ + + + + + + + + + - - - - - + + +
PropertyIfcfg-rh VariableDefaultDescription
configTEAM_PORT_CONFIG  Used to control the WPS methods to be used Valid values are "default", "auto", "disabled", "pin" and "pbc". If omitted, whatver the AP announces is used. - -Example: WPS_METHOD=disabled, WPS_METHOD="pin pbc"
filsFILS(+) -Team port configuration in JSON. See man teamd.conf for details.
+
+
+

Table 41. user setting

+
++++++ + + + + + + + + + - - - +Example: NM_USER_FOO__BAR=something +
PropertyIfcfg-rh VariableDefaultDescription
dataNM_USER_*  Enables or disables FILS (802.11ai) - -Example: FILS=required +each key/value pair is stored as a separate variable with name composed by concatenating NM_USER_ with the encoded key. The key is encoded by substituting lowercase letters with uppercase and prepending uppercase letters with an underscore. A dot is encoded as a double underscore. Remaining characters are encoded as underscore followed by a 3 digit octal representation of the character. -Allowed values: default, disable, optional, required

-

Table 44. 802-11-wireless setting

-
+

Table 42. veth setting

+
++++++ + + + + + + + +
PropertyIfcfg-rh VariableDefaultDescription
+
+
+

Table 43. vlan setting

+
@@ -2618,148 +2721,116 @@ Allowed values: default, disable, optional, required - - - - - - - - + + - + - - + + - + - - + + - +Allowed values: "yes or "no" for GVRP and MVRP; "LOOSE_BINDING" and "NO_REORDER_HDR" for VLAN_FLAGS - - + + - - - - - - - - - - - - - +Example: VLAN_PROTOCOL="802.1ad" - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + - +Example: VLAN_INGRESS_PRIORITY_MAP=4:2,3:5 - - + + - +Example: VLAN_EGRESS_PRIORITY_MAP=5:4,4:1,3:7 - - + + - - - - - - - +Example: PHYSDEV=eth0, VLAN_ID=12; or DEVICE=eth0.12
ssidESSID SSID of Wi-Fi network. - -Example: ESSID="Quick Net"
modeMODEparentDEVICE or PHYSDEV  Wi-Fi network mode. - -Allowed values: Ad-Hoc, Managed (Auto) [case insensitive]Parent interface of the VLAN.
bandBAND(+) -idVLAN_ID, DEVICE.  BAND alone is honored, but CHANNEL overrides BAND since it implies a band. - -Example: BAND=bg - -Allowed values: a, bgVLAN identifier. If VLAN_ID is not set, it is attempted to be detected from the suffix of DEVICE=. Note that older versions of NetworkManager had a bug where they would prefer the detected ID from the DEVICE over VLAN_ID.
channelCHANNELflagsGVRP, MVRP, VLAN_FLAGS  Channel used for the Wi-Fi communication. Channels greater than 14 mean "a" band, otherwise the band is "bg". +VLAN flags. -Example: CHANNEL=6
bssidBSSID(+) -protocolVLAN_PROTOCOL  Restricts association only to a single AP. +VLAN protocol. -Example: BSSID=00:1E:BD:64:83:21
rate(none) This property is not handled by ifcfg-rh plugin.
tx-power(none) This property is not handled by ifcfg-rh plugin.
mac-addressHWADDR Hardware address of the device in traditional hex-digits-and-colons notation (e.g. 00:22:68:14:5A:05). Note that for initscripts this is the current MAC address of the device as found during ifup. For NetworkManager this is the permanent MAC address. Or in case no permanent MAC address exists, the MAC address initially configured on the device.
cloned-mac-addressMACADDR Cloned (spoofed) MAC address in traditional hex-digits-and-colons notation (e.g. 00:22:68:14:5A:99).
generate-mac-address-maskGENERATE_MAC_ADDRESS_MASK(+) - the MAC address mask for generating randomized and stable cloned-mac-address.
mac-address-blacklistHWADDR_BLACKLIST(+) - It denies usage of the connection for any device whose address is listed.
seen-bssids(none) This property is not handled by ifcfg-rh plugin.
mtuMTU MTU of the wireless interface.
hiddenSSID_HIDDEN(+) - Whether the network hides the SSID.
powersavePOWERSAVE(+) -ingress-priority-mapVLAN_INGRESS_PRIORITY_MAP  Enables or disables Wi-Fi power saving. - -Example: POWERSAVE=enable +Ingress priority mapping. -Allowed values: default, ignore, enable, disable
mac-address-randomizationMAC_ADDRESS_RANDOMIZATION(+) -egress-priority-mapVLAN_EGRESS_PRIORITY_MAP  Enables or disables Wi-Fi MAC address randomization. - -Example: MAC_ADDRESS_RANDOMIZATION=always +Egress priority mapping. -Allowed values: default, never, always
security(none)interface-namePHYSDEV and VLAN_ID, or DEVICE  This property is deprecated and not handled by ifcfg-rh-plugin.
ap-isolationAP_ISOLATION(+) -missing variable means global defaultWhether AP isolation is enabled +VLAN interface name. If all variables are set, parent device from PHYSDEV takes precedence over DEVICE, but VLAN id from DEVICE takes precedence over VLAN_ID. -Allowed values: "yes", "no"

-

Table 45. wpan setting

+

Table 44. vrf setting

+
++++++ + + + + + + + +
PropertyIfcfg-rh VariableDefaultDescription
+
+
+

Table 45. wifi-p2p setting

+
++++++ + + + + + + + +
PropertyIfcfg-rh VariableDefaultDescription
+
+
+

Table 46. wireguard setting

+
++++++ + + + + + + + +
PropertyIfcfg-rh VariableDefaultDescription
+
+
+

Table 47. wpan setting

-- cgit 1.3.0-6-gf8a5