User Tools

Site Tools


networking:networkmanager-nmcli

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
networking:networkmanager-nmcli [2026/09/14 15:20] – oscarnetworking:networkmanager-nmcli [2026/09/14 16:50] (current) – [nmcli - NetworkManager] oscar
Line 2: Line 2:
 ---- ----
 `nmcli` manages NetworkManager in Linux. Work with two core concepts: **Device** (physical hardware like `eth0` or `wlan0`) and **Connection** (a saved configuration profile). `nmcli` manages NetworkManager in Linux. Work with two core concepts: **Device** (physical hardware like `eth0` or `wlan0`) and **Connection** (a saved configuration profile).
 +
 +Alternatively you could use `nmtui` application with simple console UI (NetworkManager Textual User Interface).
  
 ### Overview & Diagnostics ### Overview & Diagnostics
Line 153: Line 155:
  
 # NetworkManager Configuration # NetworkManager Configuration
 +## Locations
 +NetworkManager configuration files and connection profiles are stored across a few specific directories on your system.
 |Location|Description| |Location|Description|
 |--|--| |--|--|
Line 159: Line 163:
 |/run/NetworkManager/ \\ /var/lib/NetworkManager/|DNS & Runtime Network State (Auto-generated).Contains internal DHCP leases, runtime connection states, and auto-generated DNS configurations. These do not need to be backed up.| |/run/NetworkManager/ \\ /var/lib/NetworkManager/|DNS & Runtime Network State (Auto-generated).Contains internal DHCP leases, runtime connection states, and auto-generated DNS configurations. These do not need to be backed up.|
  
- +## Backup/Restore Configuration
-# Backing Up and Restoring NetworkManager Configuration +
 When testing network changes such as bridges, VLANs, or bonds with `nmcli`, back up the NetworkManager connection profiles first. Also capture the current runtime state as a readable reference. When testing network changes such as bridges, VLANs, or bonds with `nmcli`, back up the NetworkManager connection profiles first. Also capture the current runtime state as a readable reference.
  
-## 1. Back up NetworkManager connection profiles +### Back up NetworkManager 
- +Because `/etc/NetworkManager/system-connections/` stores Wi-Fi passwords, you must use `sudo` to read and archive the files. Create a compressed tarball archive of all configurations.
-On Debian Bookworm, persistent NetworkManager connection profiles are normally stored in: +
- +
-```text +
-/etc/NetworkManager/system-connections/+
 ``` ```
- +# tar -czvf /tmp/nm-config-backup-$(date +%F).tar.gz /etc/NetworkManager/ 
-Create a compressed backup: +
- +
-```bash +
-sudo tar --create --gzip --preserve-permissions \ +
-  --file="$HOME/networkmanager-backup-$(date +%F-%H%M%S).tar.gz" \ +
-  /etc/NetworkManager/system-connections+
 ``` ```
- +After restoring reload NetworkManager to apply changes:
-Alternatively, create a directory copy under `/root`: +
- +
-```bash +
-sudo mkdir -p /root/networkmanager-backup +
-sudo cp -a /etc/NetworkManager/system-connections/. \ +
-  /root/networkmanager-backup/+
 ``` ```
 +# nmcli connection reload
 +# systemctl restart NetworkManager
  
-The `-a` option preserves ownership, permissions, timestamps, and symbolic links. 
- 
-> **Security note:** NetworkManager profiles can contain Wi-Fi credentials or other secrets. Keep the backup readable only by root, especially if it is stored outside `/root`. 
- 
-For a tar archive stored in your home directory, tighten its permissions: 
- 
-```bash 
-chmod 600 "$HOME"/networkmanager-backup-*.tar.gz 
 ``` ```
- +## Save a readable snapshot of the current state
-## 2. Save a readable snapshot of the current state +
 These files are not used for automatic restoration, but they are useful for comparing the working setup with the changed configuration: These files are not used for automatic restoration, but they are useful for comparing the working setup with the changed configuration:
- +```
-```bash+
 mkdir -p "$HOME/network-state-before-change" mkdir -p "$HOME/network-state-before-change"
  
Line 220: Line 197:
   > "$HOME/network-state-before-change/ip-rules.txt"   > "$HOME/network-state-before-change/ip-rules.txt"
 ``` ```
- 
 For more detail, export every NetworkManager profile in a human-readable form: For more detail, export every NetworkManager profile in a human-readable form:
  
-```bash+```
 while IFS= read -r uuid; do while IFS= read -r uuid; do
   nmcli --show-secrets connection show uuid "$uuid"   nmcli --show-secrets connection show uuid "$uuid"
Line 232: Line 208:
 chmod 600 "$HOME/network-state-before-change/nm-connections-full.txt" chmod 600 "$HOME/network-state-before-change/nm-connections-full.txt"
 ``` ```
- 
 Because `--show-secrets` may reveal credentials, protect this file carefully. Omit `--show-secrets` if the secrets are not needed in the reference copy. Because `--show-secrets` may reveal credentials, protect this file carefully. Omit `--show-secrets` if the secrets are not needed in the reference copy.
  
-## 3. Restore the saved profiles 
- 
-A local console, hypervisor console, IPMI/iDRAC/iLO session, or other out-of-band access is strongly recommended before restarting NetworkManager. 
- 
-### Restore from the directory copy 
- 
-```bash 
-sudo systemctl stop NetworkManager 
- 
-sudo mkdir -p /etc/NetworkManager/system-connectionsnftables 
-sudo rm -f /etc/NetworkManager/system-connections/* 
- 
-sudo cp -a /root/networkmanager-backup/. \ 
-  /etc/NetworkManager/system-connections/ 
- 
-sudo chown -R root:root /etc/NetworkManager/system-connections 
-sudo find /etc/NetworkManager/system-connections \ 
-  -type f -exec chmod 600 {} + 
- 
-sudo systemctl start NetworkManager 
-sudo nmcli connection reload 
-``` 
- 
-### Restore from the tar archive 
- 
-Replace the archive name with the actual backup file: 
- 
-```bash 
-sudo systemctl stop NetworkManager 
-sudo rm -rf /etc/NetworkManager/system-connections 
-sudo tar --extract --gzip --preserve-permissions \ 
-  --file="$HOME/networkmanager-backup-YYYY-MM-DD-HHMMSS.tar.gz" \ 
-  --directory=/ 
-sudo chown -R root:root /etc/NetworkManager/system-connections 
-sudo systemctl start NetworkManager 
-sudo nmcli connection reload 
-``` 
- 
-After restoring, verify the profiles and device state: 
- 
-```bash 
-nmcli connection show 
-nmcli device status 
-ip address show 
-ip route show 
-``` 
- 
-If the expected connection does not activate automatically, bring it up explicitly: 
- 
-```bash 
-sudo nmcli connection up "CONNECTION_NAME" 
-``` 
- 
-## 4. Safer testing over SSH 
- 
-Network changes involving a bridge can disconnect the interface carrying the SSH session. Prefer a local or out-of-band console. 
- 
-If the `at` command is installed and its service is running, schedule a rollback **before** applying the test configuration. 
- 
-First create a rollback script: 
- 
-```bash 
-sudo tee /root/restore-networkmanager.sh >/dev/null <<'EOF' 
-#!/bin/sh 
-set -eu 
-systemctl stop NetworkManager 
-rm -f /etc/NetworkManager/system-connections/* 
-cp -a /root/networkmanager-backup/. /etc/NetworkManager/system-connections/ 
-chown -R root:root /etc/NetworkManager/system-connections 
-find /etc/NetworkManager/system-connections -type f -exec chmod 600 {} + 
-systemctl start NetworkManager 
-nmcli connection reload 
-EOF 
- 
-sudo chmod 700 /root/restore-networkmanager.sh 
-``` 
- 
-Schedule it, for example, ten minutes from now: 
- 
-```bash 
-echo /root/restore-networkmanager.sh | sudo at now + 10 minutes 
-``` 
- 
-List the scheduled job: 
- 
-```bash 
-sudo atq 
-``` 
- 
-After confirming that the new configuration works, cancel the rollback job: 
- 
-```bash 
-sudo atrm JOB_ID 
-``` 
- 
-> A simple scheduled `systemctl restart NetworkManager` is not a full rollback. It only restarts NetworkManager with whatever configuration is currently present. The rollback job must restore the saved profile files first. 
- 
-## 5. Recommended quick workflow 
- 
-Before the experiment: 
- 
-```bash 
-sudo rm -rf /root/networkmanager-backup 
-sudo mkdir -p /root/networkmanager-backup 
-sudo cp -a /etc/NetworkManager/system-connections/. \ 
-  /root/networkmanager-backup/ 
- 
-nmcli connection show 
-nmcli device status 
-``` 
- 
-Make the changes using `nmcli`. If they work, keep them and remove the temporary rollback job. If they fail, restore the profile directory from a local or out-of-band console. 
- 
-## 6. Additional protection for a virtual machine 
- 
-If the Debian host is a virtual machine, take a hypervisor snapshot before changing the network configuration. This provides a complete rollback point, not only a backup of NetworkManager profiles. 
- 
-## Important limitations 
- 
-- The profile backup covers persistent NetworkManager connection profiles. 
-- It does not necessarily capture temporary runtime-only changes made directly with commands such as `ip address add` or `ip route add`. 
-- It does not back up unrelated network configuration, firewall rules, DNS server configuration outside NetworkManager, or custom dispatcher scripts. 
-- For a broader system backup, also consider `/etc/NetworkManager/NetworkManager.conf`, `/etc/NetworkManager/conf.d/`, `/etc/NetworkManager/dispatcher.d/`, and any locally maintained firewall configuration. 
  
networking/networkmanager-nmcli.1789399217.txt.gz · Last modified: by oscar