User Tools

Site Tools


networking:networkmanager-nmcli

This is an old revision of the document!


nmcli - NetworkManager


nmcli manages NetworkManager in Linux. Work with two core concepts: Device (physical hardware like eth0 or wlan0) and Connection (a saved configuration profile).

Overview & Diagnostics

* View overall network status:

$ nmcli general status

* List physical network interfaces and their status:

$ nmcli device status
---------------------
DEVICE  TYPE      STATE                   CONNECTION         
enp2s0  ethernet  connected               Wired connection 1 
lo      loopback  connected (externally)  lo                 
virbr0  bridge    connected (externally)  virbr0          

* Show detailed interface info (IP, MAC, DNS, Gateway):

$ nmcli device show enp2s0
--------------------------
GENERAL.DEVICE:                         enp2s0
GENERAL.TYPE:                           ethernet
GENERAL.HWADDR:                         50:E5:49:ED:A9:BF
GENERAL.MTU:                            1500
GENERAL.STATE:                          100 (connected)
GENERAL.CONNECTION:                     Wired connection 1
GENERAL.CON-PATH:                       /org/freedesktop/NetworkManager/ActiveConnection/2
WIRED-PROPERTIES.CARRIER:               on
IP4.ADDRESS[1]:                         192.168.178.18/24
IP4.GATEWAY:                            192.168.178.1
IP4.ROUTE[1]:                           dst = 192.168.178.0/24, nh = 0.0.0.0, mt = 100
IP4.ROUTE[2]:                           dst = 0.0.0.0/0, nh = 192.168.178.1, mt = 100
IP4.DNS[1]:                             192.168.178.1
IP4.DOMAIN[1]:                          lan
IP6.ADDRESS[1]:                         2001:1c00:2e07:fa0a:c363:14e8:16bd:6436/64
IP6.ADDRESS[2]:                         fdaa:66:67:a:4b23:15d3:3424:d1ab/64
IP6.ADDRESS[3]:                         fdaa:66:67:a::e78/128
IP6.ADDRESS[4]:                         2001:1c00:2e07:fa0a::e78/128
IP6.ADDRESS[5]:                         2001:1c00:2e07:fa0a:52e5:49ff:feed:a9bf/64
IP6.ADDRESS[6]:                         fdaa:66:67:a:52e5:49ff:feed:a9bf/64
IP6.ADDRESS[7]:                         fe80::52e5:49ff:feed:a9bf/64
IP6.GATEWAY:                            fe80::ee08:6bff:fe84:2043
IP6.ROUTE[1]:                           dst = fe80::/64, nh = ::, mt = 1024
IP6.ROUTE[2]:                           dst = fdaa:66:67:a::/64, nh = ::, mt = 100
IP6.ROUTE[3]:                           dst = 2001:1c00:2e07:fa0a::/64, nh = ::, mt = 100
IP6.ROUTE[4]:                           dst = ::/0, nh = fe80::ee08:6bff:fe84:2043, mt = 100
IP6.ROUTE[5]:                           dst = fdaa:66:67:a::e78/128, nh = ::, mt = 100
IP6.ROUTE[6]:                           dst = 2001:1c00:2e07:fa0a::e78/128, nh = ::, mt = 100
IP6.DNS[1]:                             fdaa:66:67:a::1

* List all saved connection profiles:

$ nmcli connection show

* Show only active connections:

$ nmcli connection show --active
--------------------------------
NAME                UUID                                  TYPE      DEVICE 
Wired connection 1  483fb914-06e5-4b66-b00f-e2b31025eaff  ethernet  enp2s0 
lo                  ce29234b-7809-4b88-b743-79bf79ac55bf  loopback  lo     
virbr0              4778a23b-a938-412c-8c64-e78ecb98571c  bridge    virbr0 

Wi-Fi Management

* Scan for nearby Wi-Fi networks:

$ nmcli device wifi list

* Connect to a Wi-Fi network:

# nmcli device wifi connect "SSID_NAME" password "WIFI_PASSWORD"

* Prompt securely for Wi-Fi password (prevents saving password in shell history):

# nmcli --ask device wifi connect "SSID_NAME"

* Toggle Wi-Fi on or off:

$ nmcli radio wifi off
$ nmcli radio wifi on

Connection Controls (Up / Down / Delete)

* Activate a connection profile:

# nmcli connection up "MyConnection"

* Deactivate a connection profile:

# nmcli connection down "MyConnection"

* Disconnect a hardware device directly:

# nmcli device disconnect eth0

* Delete a saved connection profile:

sudo nmcli connection delete "MyConnection"

Network Configuration (IP, Gateway, DNS)

* Set a static IPv4 address and gateway:

# nmcli connection modify "Wired connection 1" ipv4.addresses 192.168.1.50/24 ipv4.gateway 192.168.1.1 ipv4.method manual
# nmcli connection up "Wired connection 1"

* Switch back to dynamic IP (DHCP):

# nmcli connection modify "Wired connection 1" ipv4.method auto
# nmcli connection up "Wired connection 1"

* Set custom DNS servers:

# nmcli connection modify "Wired connection 1" ipv4.dns "1.1.1.1 8.8.8.8"
# nmcli connection up "Wired connection 1"

Adding New Profiles

* Add a standard Ethernet connection profile (DHCP):

# nmcli connection add type ethernet con-name "Office-Eth" ifname eth0

* Add a static Ethernet connection profile directly:

# nmcli connection add type ethernet con-name "Static-Eth" ifname eth0 ip4 10.0.0.10/24 gw4 10.0.0.1

NetworkManager Configuration

Locations

NetworkManager configuration files and connection profiles are stored across a few specific directories on your system.

LocationDescription
/etc/NetworkManager/system-connections/Saved Connection Profile.Contains all individual network profiles (Wi-Fi access points, static IP settings, VPNs, Ethernet configurations). Each file is stored in Keyfile format and contains sensitive credentials like Wi-Fi passwords.
/etc/NetworkManager/NetworkManager.conf
/etc/NetworkManager/conf.d/
Global Configuration & Custom Drops. NetworkManager.conf is the primary system configuration file. Any custom overrides or plugin configurations belong in /etc/NetworkManager/conf.d/.
/run/NetworkManager/
/var/lib/NetworkManager/
DNS& Runtime Network State (Auto-generated).Contains internal DHCP leases, runtime connection states, and auto-generated DNS configurations. These do not need to be backed up.

Backing Up and Restoring NetworkManager Configuration

When testing network changes such as bridges, VLANs, or bonds with nmcli, back up the NetworkManager connection profiles first. Also capture the current runtime state as a readable reference.

Back up NetworkManager

Because /etc/NetworkManager/system-connections/ stores Wi-Fi passwords, you must use sudo to read and archive the files. Create a compressed tarball archive of all configurations.

# tar -czvf /tmp/nm-config-backup-$(date +%F).tar.gz /etc/NetworkManager/ 

After restoring reload NetworkManager to apply changes:

# nmcli connection reload
# systemctl restart NetworkManager

Save a readable snapshot of the current state

These files are not used for automatic restoration, but they are useful for comparing the working setup with the changed configuration:

mkdir -p "$HOME/network-state-before-change"

nmcli connection show \
  > "$HOME/network-state-before-change/nm-connections.txt"

nmcli device show \
  > "$HOME/network-state-before-change/nm-devices.txt"

ip address show \
  > "$HOME/network-state-before-change/ip-address.txt"

ip route show table all \
  > "$HOME/network-state-before-change/ip-routes.txt"

ip rule show \
  > "$HOME/network-state-before-change/ip-rules.txt"

For more detail, export every NetworkManager profile in a human-readable form:

while IFS= read -r uuid; do
  nmcli --show-secrets connection show uuid "$uuid"
  printf '\n%s\n\n' '----------------------------------------'
done < <(nmcli -g UUID connection show) \
  > "$HOME/network-state-before-change/nm-connections-full.txt"

chmod 600 "$HOME/network-state-before-change/nm-connections-full.txt"

Because --show-secrets may reveal credentials, protect this file carefully. Omit --show-secrets if the secrets are not needed in the reference copy.

6. Additional protection for a virtual machine

If the Debian host is a virtual machine, take a hypervisor snapshot before changing the network configuration. This provides a complete rollback point, not only a backup of NetworkManager profiles.

Important limitations

- The profile backup covers persistent NetworkManager connection profiles. - It does not necessarily capture temporary runtime-only changes made directly with commands such as ip address add or ip route add. - It does not back up unrelated network configuration, firewall rules, DNS server configuration outside NetworkManager, or custom dispatcher scripts. - For a broader system backup, also consider /etc/NetworkManager/NetworkManager.conf, /etc/NetworkManager/conf.d/, /etc/NetworkManager/dispatcher.d/, and any locally maintained firewall configuration.

networking/networkmanager-nmcli.1789399990.txt.gz · Last modified: by oscar