networking:networkmanager-nmcli
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| networking:networkmanager-nmcli [2026/09/14 14:58] – [Overview & Diagnostics] oscar | networking:networkmanager-nmcli [2026/09/14 16:50] (current) – [nmcli - NetworkManager] oscar | ||
|---|---|---|---|
| Line 2: | Line 2: | ||
| ---- | ---- | ||
| `nmcli` manages NetworkManager in Linux. Work with two core concepts: **Device** (physical hardware like `eth0` or `wlan0`) and **Connection** (a saved configuration profile). | `nmcli` manages NetworkManager in Linux. Work with two core concepts: **Device** (physical hardware like `eth0` or `wlan0`) and **Connection** (a saved configuration profile). | ||
| + | |||
| + | Alternatively you could use `nmtui` application with simple console UI (NetworkManager Textual User Interface). | ||
| ### Overview & Diagnostics | ### Overview & Diagnostics | ||
| Line 22: | Line 24: | ||
| ``` | ``` | ||
| $ nmcli device show enp2s0 | $ nmcli device show enp2s0 | ||
| + | -------------------------- | ||
| + | GENERAL.DEVICE: | ||
| + | GENERAL.TYPE: | ||
| + | GENERAL.HWADDR: | ||
| + | GENERAL.MTU: | ||
| + | GENERAL.STATE: | ||
| + | GENERAL.CONNECTION: | ||
| + | GENERAL.CON-PATH: | ||
| + | WIRED-PROPERTIES.CARRIER: | ||
| + | IP4.ADDRESS[1]: | ||
| + | IP4.GATEWAY: | ||
| + | IP4.ROUTE[1]: | ||
| + | IP4.ROUTE[2]: | ||
| + | IP4.DNS[1]: | ||
| + | IP4.DOMAIN[1]: | ||
| + | IP6.ADDRESS[1]: | ||
| + | IP6.ADDRESS[2]: | ||
| + | IP6.ADDRESS[3]: | ||
| + | IP6.ADDRESS[4]: | ||
| + | IP6.ADDRESS[5]: | ||
| + | IP6.ADDRESS[6]: | ||
| + | IP6.ADDRESS[7]: | ||
| + | IP6.GATEWAY: | ||
| + | IP6.ROUTE[1]: | ||
| + | IP6.ROUTE[2]: | ||
| + | IP6.ROUTE[3]: | ||
| + | IP6.ROUTE[4]: | ||
| + | IP6.ROUTE[5]: | ||
| + | IP6.ROUTE[6]: | ||
| + | IP6.DNS[1]: | ||
| ``` | ``` | ||
| * **List all saved connection profiles:** | * **List all saved connection profiles:** | ||
| Line 32: | Line 63: | ||
| ``` | ``` | ||
| $ nmcli connection show --active | $ nmcli connection show --active | ||
| + | -------------------------------- | ||
| + | NAME UUID TYPE DEVICE | ||
| + | Wired connection 1 483fb914-06e5-4b66-b00f-e2b31025eaff | ||
| + | lo ce29234b-7809-4b88-b743-79bf79ac55bf | ||
| + | virbr0 | ||
| ``` | ``` | ||
| --- | --- | ||
| Line 119: | Line 154: | ||
| --- | --- | ||
| - | ### Useful Shortcuts & Scripting Flags | + | # NetworkManager Configuration |
| - | + | ## Locations | |
| - | * **Shortened syntax:** Object names can be abbreviated | + | NetworkManager configuration files and connection profiles are stored across a few specific directories on your system. |
| - | ``` | + | |Location|Description| |
| - | $ nmcli d status | + | |--|--| |
| - | $ nmcli c show | + | |/ |
| - | + | |/ | |
| - | ``` | + | |/ |
| - | * **Terse output (cleaner for scripts/grep):** | + | |
| - | ``` | + | |
| - | $ nmcli -t -f NAME,DEVICE | + | |
| - | + | ||
| - | ``` | + | |
| - | * **Get a single specific field value:** | + | |
| - | ``` | + | |
| - | $ nmcli -g IP4.ADDRESS device show eth0 | + | |
| - | + | ||
| - | ``` | + | |
| - | + | ||
| - | + | ||
| - | + | ||
| - | # Backing Up and Restoring NetworkManager Configuration | + | |
| + | ## Backup/ | ||
| When testing network changes such as bridges, VLANs, or bonds with `nmcli`, back up the NetworkManager connection profiles first. Also capture the current runtime state as a readable reference. | When testing network changes such as bridges, VLANs, or bonds with `nmcli`, back up the NetworkManager connection profiles first. Also capture the current runtime state as a readable reference. | ||
| - | ## 1. Back up NetworkManager | + | ### Back up NetworkManager |
| - | + | Because | |
| - | On Debian Bookworm, persistent NetworkManager connection profiles are normally stored in: | + | |
| - | + | ||
| - | ```text | + | |
| - | / | + | |
| ``` | ``` | ||
| - | + | # tar -czvf /tmp/nm-config-backup-$(date +%F).tar.gz / | |
| - | Create a compressed backup: | + | |
| - | + | ||
| - | ```bash | + | |
| - | sudo tar --create --gzip --preserve-permissions \ | + | |
| - | --file=" | + | |
| - | | + | |
| ``` | ``` | ||
| - | + | After restoring reload | |
| - | Alternatively, | + | |
| - | + | ||
| - | ```bash | + | |
| - | sudo mkdir -p / | + | |
| - | sudo cp -a /etc/NetworkManager/ | + | |
| - | / | + | |
| ``` | ``` | ||
| + | # nmcli connection reload | ||
| + | # systemctl restart NetworkManager | ||
| - | The `-a` option preserves ownership, permissions, | ||
| - | |||
| - | > **Security note:** NetworkManager profiles can contain Wi-Fi credentials or other secrets. Keep the backup readable only by root, especially if it is stored outside `/root`. | ||
| - | |||
| - | For a tar archive stored in your home directory, tighten its permissions: | ||
| - | |||
| - | ```bash | ||
| - | chmod 600 " | ||
| ``` | ``` | ||
| - | + | ## Save a readable snapshot of the current state | |
| - | ## 2. Save a readable snapshot of the current state | + | |
| These files are not used for automatic restoration, | These files are not used for automatic restoration, | ||
| - | + | ``` | |
| - | ```bash | + | |
| mkdir -p " | mkdir -p " | ||
| Line 200: | Line 197: | ||
| > " | > " | ||
| ``` | ``` | ||
| - | |||
| For more detail, export every NetworkManager profile in a human-readable form: | For more detail, export every NetworkManager profile in a human-readable form: | ||
| - | ```bash | + | ``` |
| while IFS= read -r uuid; do | while IFS= read -r uuid; do | ||
| nmcli --show-secrets connection show uuid " | nmcli --show-secrets connection show uuid " | ||
| Line 212: | Line 208: | ||
| chmod 600 " | chmod 600 " | ||
| ``` | ``` | ||
| - | |||
| Because `--show-secrets` may reveal credentials, | Because `--show-secrets` may reveal credentials, | ||
| - | ## 3. Restore the saved profiles | ||
| - | |||
| - | A local console, hypervisor console, IPMI/ | ||
| - | |||
| - | ### Restore from the directory copy | ||
| - | |||
| - | ```bash | ||
| - | sudo systemctl stop NetworkManager | ||
| - | |||
| - | sudo mkdir -p / | ||
| - | sudo rm -f / | ||
| - | |||
| - | sudo cp -a / | ||
| - | / | ||
| - | |||
| - | sudo chown -R root:root / | ||
| - | sudo find / | ||
| - | -type f -exec chmod 600 {} + | ||
| - | |||
| - | sudo systemctl start NetworkManager | ||
| - | sudo nmcli connection reload | ||
| - | ``` | ||
| - | |||
| - | ### Restore from the tar archive | ||
| - | |||
| - | Replace the archive name with the actual backup file: | ||
| - | |||
| - | ```bash | ||
| - | sudo systemctl stop NetworkManager | ||
| - | sudo rm -rf / | ||
| - | sudo tar --extract --gzip --preserve-permissions \ | ||
| - | --file=" | ||
| - | --directory=/ | ||
| - | sudo chown -R root:root / | ||
| - | sudo systemctl start NetworkManager | ||
| - | sudo nmcli connection reload | ||
| - | ``` | ||
| - | |||
| - | After restoring, verify the profiles and device state: | ||
| - | |||
| - | ```bash | ||
| - | nmcli connection show | ||
| - | nmcli device status | ||
| - | ip address show | ||
| - | ip route show | ||
| - | ``` | ||
| - | |||
| - | If the expected connection does not activate automatically, | ||
| - | |||
| - | ```bash | ||
| - | sudo nmcli connection up " | ||
| - | ``` | ||
| - | |||
| - | ## 4. Safer testing over SSH | ||
| - | |||
| - | Network changes involving a bridge can disconnect the interface carrying the SSH session. Prefer a local or out-of-band console. | ||
| - | |||
| - | If the `at` command is installed and its service is running, schedule a rollback **before** applying the test configuration. | ||
| - | |||
| - | First create a rollback script: | ||
| - | |||
| - | ```bash | ||
| - | sudo tee / | ||
| - | #!/bin/sh | ||
| - | set -eu | ||
| - | systemctl stop NetworkManager | ||
| - | rm -f / | ||
| - | cp -a / | ||
| - | chown -R root:root / | ||
| - | find / | ||
| - | systemctl start NetworkManager | ||
| - | nmcli connection reload | ||
| - | EOF | ||
| - | |||
| - | sudo chmod 700 / | ||
| - | ``` | ||
| - | |||
| - | Schedule it, for example, ten minutes from now: | ||
| - | |||
| - | ```bash | ||
| - | echo / | ||
| - | ``` | ||
| - | |||
| - | List the scheduled job: | ||
| - | |||
| - | ```bash | ||
| - | sudo atq | ||
| - | ``` | ||
| - | |||
| - | After confirming that the new configuration works, cancel the rollback job: | ||
| - | |||
| - | ```bash | ||
| - | sudo atrm JOB_ID | ||
| - | ``` | ||
| - | |||
| - | > A simple scheduled `systemctl restart NetworkManager` is not a full rollback. It only restarts NetworkManager with whatever configuration is currently present. The rollback job must restore the saved profile files first. | ||
| - | |||
| - | ## 5. Recommended quick workflow | ||
| - | |||
| - | Before the experiment: | ||
| - | |||
| - | ```bash | ||
| - | sudo rm -rf / | ||
| - | sudo mkdir -p / | ||
| - | sudo cp -a / | ||
| - | / | ||
| - | |||
| - | nmcli connection show | ||
| - | nmcli device status | ||
| - | ``` | ||
| - | |||
| - | Make the changes using `nmcli`. If they work, keep them and remove the temporary rollback job. If they fail, restore the profile directory from a local or out-of-band console. | ||
| - | |||
| - | ## 6. Additional protection for a virtual machine | ||
| - | |||
| - | If the Debian host is a virtual machine, take a hypervisor snapshot before changing the network configuration. This provides a complete rollback point, not only a backup of NetworkManager profiles. | ||
| - | |||
| - | ## Important limitations | ||
| - | |||
| - | - The profile backup covers persistent NetworkManager connection profiles. | ||
| - | - It does not necessarily capture temporary runtime-only changes made directly with commands such as `ip address add` or `ip route add`. | ||
| - | - It does not back up unrelated network configuration, | ||
| - | - For a broader system backup, also consider `/ | ||
networking/networkmanager-nmcli.1789397922.txt.gz · Last modified: by oscar
