Andrew Mercer
on this page

Creating and inspecting connections

nmcli connection add con-name eno1 type ethernet ifname eno1
nmcli connection show
ip addr show eno1

Static IPv4

nmcli connection modify eno1 ipv4.addresses 192.168.1.50/24 ipv4.gateway 192.168.1.1 ipv4.dns 192.168.1.1
nmcli connection modify eno1 ipv4.method manual
nmcli connection reload
nmcli connection up eno1

Static IPv6

nmcli connection modify eno1 ipv6.addresses 'fd00:1234:5678::1/64 fd00:1234:5678::fe'
nmcli connection modify eno1 ipv6.method manual
nmcli connection down eno1
nmcli connection up eno1
ip addr show eno1
ping6 fd00:1234:5678::1
ip -6 route

Creating a dummy interface

Useful for testing routing/policy without real hardware:

sudo nmcli connection add type dummy connection.interface-name dummy0

Assigning an interface to a firewalld zone

nmcli connection modify "External eth0" connection.zone external
nmcli connection modify "Internal eth1" connection.zone internal

See the iptables guide for the firewalld side of zone configuration.

Editing DNS interactively

sudo nmcli connection edit br0

nmcli> set ipv4.dns 192.168.1.1
nmcli> set ipv4.dns-search example.local
nmcli> save

nmcli> print ipv4.dns
nmcli> print ipv4.dns-search

Known gotcha: on some systems the setting appears to save but /etc/resolv.conf doesn't actually update to match — if DNS resolution doesn't reflect the change after nmcli connection up, check /etc/resolv.conf directly and update it manually as a workaround while you track down whether systemd-resolved or a stale symlink is the cause.

Troubleshooting: default gateway not being set

nmcli connection edit "External eth0"
nmcli> set ipv4.never-default off
nmcli> set ipv4.gateway 192.168.1.1
nmcli> save

Bridged networking

The Linux bridge (see the dedicated bridge guide for the underlying concept) managed through NetworkManager:

Single NIC bridge

nmcli connection add type bridge autoconnect yes con-name br0 ifname br0
nmcli connection modify br0 ipv4.addresses 192.168.1.50/24 ipv4.method manual
nmcli connection modify br0 ipv4.gateway 192.168.1.1
nmcli connection modify br0 ipv4.dns 192.168.1.1
nmcli connection add type bridge-slave autoconnect yes con-name eth0 ifname eth0 master br0

sudo shutdown -r now

Bridge across two NICs

nmcli connection add type bridge-slave con-name br0-eth0 ifname eth0 master br0
nmcli connection add type bridge-slave con-name br0-eth1 ifname eth1 master br0

nmcli connection up br0-eth0
nmcli connection up br0-eth1
nmcli connection up br0

Cheat sheet

nmcli connection show                                          # list connections
nmcli connection modify <conn> ipv4.method manual \
  ipv4.addresses <ip>/<prefix> ipv4.gateway <gw>                 # static IPv4
nmcli connection modify <conn> connection.zone <zone>            # firewalld zone
nmcli connection add type bridge con-name br0 ifname br0         # create bridge