???<!-- GIF89;a -->
123123123123
.....................................................................................................................................???<!-- GIF89;a -->
123123123123
.....................................................................................................................................    J     lB             1        3     P     c     l     |  $     !     5   б  %        ,     F  	   [  	   e     o     r     z  
                   ʲ  '              0  !   Q     s  7        Ƴ               &     :  >   N                 	     !          &        "     >  &   ^       *     (   ͵  -     %   $  3   J  /   ~  (        ׶            -     $   G  )   l                ȷ  '             *     C      c        !         Ǹ  0              :     Z     s            '   ǹ             !   ,  "   N  "   q               ź  ,          "   ,  3   O  *     %         Ի                 2  G   S       <          )     @   .  4   o  /     '   Խ  #     )      #   J     n       0     .   Ծ  4        8  R   L       '     %   ܿ  (         +  .   L  *   {       $     #     ,        9  *   X                  D     %     -   <  /   j            =     L   	     V  #   i  &     	               	              2       +     4     A     J     ]     n     v      &        :     Y  /   r  0                    -     	   &    0  F   F  @     A     U     K   f  4     Y     8   A  E   z  G     %     9   .     h  #   Z  Z   ~  T      .     E    *    ;           !         r  m  *     5     4   A  C   v                         (  	     2     7  ?   G  '                         <     9     :   G                                     0     .   &  7   U  *          &                    	   %  
   /     :     U     t  $          %                         ,  a         ;  5   ?    u 4      M %   Z          - F     
          +       &    ;    Q 	   p    z                                	              \  2 	                        F       -    E 6   L                 	    C    &       9     I    j "   o                                 5   2    h    z             q      E    	    
        )    +   	 ,   5 )   b +    (    A    "   #    F    c 0   ~ ,    ?    :    2   W %    +                        H"   #   & 2  )   -   0   2 8   7 n  8    9 I   V: 6   :    : ,   : /   ; ,   ;; /   h; 3   ; 4   ; /   < w   1< 1   < '   < 2   = *   6= .   a= *   =    = )   C> 5   m> 1   > (   > !   > &    ?     G? 9   h? 4   ? #   ? #   ? #   @    C@ $   a@    @ (   @    @    @    A    A !   9A     [A     |A    A    A    A '   A '   %B &   MB    tB     B     B    B    B    B    C    C    C    C    C    C 0   D 1   BD    tD <
  D    N    N    N 1   N 8   O    QO 
   ZO    eO    lO X   xO    O    O .   O '   P "   EP    hP 1   ~P    P %   P    P    P a   Q    uQ    Q    R    R '   R -   R "   S    3S (   IS    rS    S    S    S    S /   S *   S &   T    DT 1   HT    zT    T    T    T    T &   T    T    T    U    U #   U    U    U    V 0   &V '   WV #   V *   V %   V f   V #   [W   W    [ u  [ ;   ]    N]    b]    u] J   ^ A  `^ b   _    `   ` Z  b b   c k   Nd 6  d   e ]   ~i    i 9  j I  k    +m    Cm    n    n    o    p   q b   "s '   s    s "   s    s 
   t '   t    Ct 0   bt 
   t    t    t     t !   t    t *   u 4   Bu >   wu #   u )   u 2   v 2   7v B   jv    v <   v    w    !w    ?w    Xw    sw #   w    w     w    w +   x .   0x    _x #   rx &   x 0   x .   x 5   y A   Sy '   y 9   y %   y '   z .   Ez &   tz ,   z ,   z ,   z 1   "{ )   T{    ~{    { 7   { [   { #   O| 3   s| (   | (   | 0   | +   *} /   V} &   } *   }    } %   }    ~ -   ;~    i~    ~    ~ '   ~    ~ 1    >   > 6   } >    5    0   ) B   Z ;    !   ـ     #    +   >    j     @        <   
 6   G /   ~ ,    !   ۂ 3    #   1 *   U     (       ă *    !    (   0 !   Y %   { %    .   Ǆ (        *   ; '   f $    !        Յ #    0    )   K    u #    #    #   ۆ /    !   /    Q    n ;    6   ɇ >     %   ? 5   e             ۈ (    ,    )   K    u )    %    )   ݉ +    (   3 #   \ !        $        E    (   K )   t )       ȋ         -   %    S "   g     )    7   Ҍ    
    #    < !   T (   v $       č     +    !   + J   M                Ȏ ?   َ %       ? #   Z    ~    6 %   U )   {      $   Ɛ     "   	 &   , *   S <   ~ =    +    #   % #   I    m 5    ,    )    )    &   ;    b '   | +    ;   Г 0    ,   = ;   j 0    ,   ה !       & -   F "   t           +   ٕ +       1   B ?   1 C   q <    6    7   ) ;   a F    J    J   / 2   z :    C    2   , a   _ ,              _    " b      ~                 !   У                7    >    F    _    p                    Ǥ 
   Ԥ    ߤ H    #   -    Q    Z    p             5   ( 5   ^ v    q    
   } 	    L    +  ߧ 	           *    B    U    \    c    h    n    w                ̫    ߫            ! #   ( -   L %   z       < U   E Q    d    5   R     /   ]     C   n :            r     ^    9   
 8   D ;   } =    8       0   Ǻ         |           y    p    e H    E   W }    s               ?    4     M        ~    x   &    u      )   E   a w  u E     3        ^                        s    3         u  |            b     ,    $   +    P        r     ,   &   
    A       7    M 1   f 	            	    E           $    0 `   N                   (   % !   N 0   p !            B    #   A    e                 0        7    4   1 7   f ,    ,        c    <   l             &   
       	                 }    P    Y    n 5        
            (            '    A    [ '   m                                     4    0   : 9   k 0    /    4       ;    B    [    a    i K   n ,        #           '    <    Z -   u         !        #           :    X (   t *    !    #    =       L )   a         0    b       (    D    c    v "                       +    B        6    Q    g 
    /    (    (        &        G    ]    f                            
     "     3     8     O  e   j       	               l    !   p    X   k  l         #    $       A    X    j '        %               ' 
   :    E    M 
   m     x     <    8       	    "	 $   &	 &   K	 !   r	    	    	    	 2   	    	 (   
    5
    9
 
   K
    V
    o
    
    
    
    
    
    
    
    
    
     "   )    L    U    e -   |     4    5    
    N   	 	   X    b <   g             5      2    9    N +   V %                        Z       D     I    j    | #        	            +    +       :    F    N 3   d             (    -    !       *    :     0    6    5   = 2   s '        1    4   	 	   >    H    ^    n    v     {        x   # F        f    <   ^        "    # g    /   # z   S         
         )    G   :                 ,           n   `                   M     ! 3   ! V   " L   r" Z  " S  $ F   n& Y   & p   ' Y   '    ' <   a(    ( 2   i) )   ) C   ) C   
* 3   N* R   *    * }   W+ "   +    + &   ,    ,    , o  - >  .    /     / "   / 5   
0 :   @0 K   {0 B   0 >   
1 E   I1 >   1 E   1 @   2 N   U2 E   2 F   2 /   13 H   a3 D   3 C   3    34 	   84    B4    Q4    V4    u4    4    4 	   4 +   4 $   4 F   4 ,   F5 0   s5   5 '   k7 H   7    7   8   9 7   : 7   ; 6  C;   z= M  \@ f   A    B >   C 8   CC A   |C J   C >   	D g   HD    D C   GE U   E !   E %   F    )F .   IF $   xF <   F D   F ,  G %   LH $   rH 6  H +   I @   I 5   ;J     qJ 1   J ;   J (    K q   )K `   K    K .   L -   KL )   yL (   L *   L .   L *   &M )   QM +   {M *   M ,   M *   M /   *N 2   ZN -   N )   N (   N 0   O )   ?O *   iO 7   O /   O 0   O /   -P     ]P    ~P 7   P g   P   9Q 1   FS    xS H   S B   S G   T >   cT &   T    T    uU *   U ,   U    U     V    V )   9V "   cV W   V _   V C   >W    W    @X    X    Y K   ~Z 5   Z     [    [    	\ o   \ l   \ b   \ b   Z] q   ] 6   /^    f^ S   ^ Z  ^   2a =  Ab    c    &d    d    e    Tf    f    g    `h    i O   i   j R   l    m '   "m    Jm A   jm >   m Y  m H  Eo C  p X   q W   +r    r ^   ~s    s 6   t H   t \   u G   tu    u X   u C   4v   xv   w   ^y    {    {    '{ 
   +{ l  6{ E   | *   | 3   }    H}    U}    l}    } 4   }    } 6  `~ =       Հ     %       <    Z +   u &    .   ȁ +       #    +    K    b    p             +   Ƃ     %    %   3 $   Y    ~    _           ɉ M    2     : V  N     o             Q    X     k   M           
       Ƥ    {    e              ?   M    n   b   i    ̺ p   l    ݻ >    <   ݼ }    ~    }        k           r $                        4    5   /    e 3   | /                           5 %   =    c    z    ~     )    $                &   $    K    a    r                                 1           )    B    G    W    j !    	                                2    8    N 9   b 1    '    A    N   8 1    &    2    &       :    H    X    f    v 7    J    ;    <   G <    '        >    K   5 H    7    7       : &    J   6 F    <    c    0   i @              u r   =        `  {          +       >   6   -  
    8 *    8    4   %   Z 2  v 2    d     A 4   %    Z    `    p 	   }             k       -    @    P    d    |         	                                   0   D H  F         L    *    (   % 0   N :                A    C   J D    D    >    #   W    {         	    
                    "    '    '       %    *    / !   ; &   ]         @    G       6 +   <    h 5    ,    7    %    G   B 4    3    0       $ %   @ &   f 3        @    &       F +   a O    ;    %     %   ?     e  E   ~  	                    
    %       C    \ %   t          +    
        &        C $   d         !        G       8    E    Q    ^    x 1           A /    1       E    N    [ (   i                                -    D #   T    x 	            "    :            ?    Z    r "             &           "    0    I 
   N $   Y :   ~         *   	 &   	 (   
 0   D
 4   u
    
    
    
    
    
 .   
    ,    I 0   _ D    *             '   ;    c '   { )    ,    +       &    @    [ $   w I         W       _    p             $            .       ?    V    q                                 1    G -   Z             "    ,    %   , 7   R                     +       &    3    D    Y    j    ~ 2    +    *            @    Z    j .   ~ $        (        '   2    Z    o 2        3    "         #    D $   c                                0    E    _    s         ,    ,    +   
    6 "   D    g    ~          "                       . &   I %   p     #    /         9    #   V &   z                     #        D "   U    x '                         +   
 >   6    u *                        8   + 6   d     (    -        +       ;     P    q     3    ;        #   /    S :   c     +        "    .    !   . &   P    w +   |            V  V! B   " 1   "    "#    :#    P#    l#    o# #   |#    # #   # :   #    $    5$    :$    J$ 5   `$ :   $    $    $     %    %    %    +% ,   K%    x%    |% 3   %    %    % !   % !   & P   -& 0   ~&    & )   &    &    ' D   $'    i' (   '    '    '    '    (    (    7(    P(    _(    d( 	   k(    u(    ( 2   ) "   ) (   * 5   >* %   t*    *    *    *    *    *    +    $+ 0   >+ !   o+    + 6   + @   + #   $, .   H,    w,    , 	   - 
  - /  (. >   X0    0    0    0    0   \1    |3 '   3    3    3    3    3    4    +4 U   4 -   5     35 -   T5 '   5    5 ,   5 5   5 9   6 .   Y6 ,   6    6    6    6 >   6 "   7    57    87    D7 ,   Y7    7 .   7    7    7 +   8    48    E8 8   c8 +   8 !   8 -   8 -   9    F9 0   d9 3   9    9    9 )   9 ,   (: "   U: -   x:    :    : D   : 9   (; )   b; (   ; ,   ;    ; T   < 1   V< @   <    < 5   < =   = F   I=     =    =    =    =    =    =    > $   '>    L>    h>    {>    >    >    > 	   >    >     > '   ?    D?    `?    u?    ? !   ?    ? ?   ? :   -@ Q   h@    @ "   @ &   @     A    ;A    [A    iA    xA    A -   A    A    A    A :  B 	   KC 3   UC !   C 	   C %   C (   C    D    D   D (   E    E    F    +F    :F    IF !   XF    zF /   F "   F    F    G    G     G    ,G 
   /G     :G 	   [G    eG    sG     G    G    G    G    G    H 2   3H    fH    H    H    H    H /   H    I    :I    AI 	   II %   SI    yI #   I    I    I &   I    J #   /J %   SJ )   yJ    J 0   J 2   J %   %K    KK    cK    zK     K    K )   K    K    L !   +L &   ML    tL    L     L !   L     L !   M     4M ,   UM     M    M    M !   M    M    N 0   1N    bN #   N #   N     N     N #   	O    -O    HO /   cO     O     O )   O #   O    #P    @P    `P    P    P ;   P    P K   Q    OQ    lQ 9   Q ,   Q 1   Q #   %R %   IR ,   oR    R    R    R /   R /   S 8   DS    }S G   S    S #   S &   T &   6T     ]T &   ~T #   T    T     T    U #   &U    JU #   dU    U    U    U A   U    V #   8V *   \V    V    V 7   V A   V    -W "   IW #   lW    W 	   W    W    W !   W   W   Z 
   \    \ 
   \    \    \    \    ] P  ]    a^    ~^    ^ "   ^ *   ^    _    _    _ (   "_ 	   K_    U_ ,   K` 5   x` 9   ` \   ` M   Ea 0   a O   a -   b :   Bb ?   }b    b .   b    c    c R   c 1  Rd   e    f    xg   fh `  hk    m   n    q H  Br     s 0   s !   s 5   s   5t /  y    ~ m       R   I    
     <    %   X    ~     
    	    ,    )   ȃ -            '    4    F    M    `    g *   u (    5   Ʉ !       ! $   @    e 	   l    v                    ݅            )    G    ܆        U            '   9    a $       #       1 c  D c        *        ڗ     !     !   " '   D    l    s                    ј    ߘ                      ?       `    g    z             W            :       X    e    u         :       ћ                    3    :    Q    o                 *   Ŝ                 7    J   ]    `    	            $        ң $    $    &   = '   d 5    &   ¤         +    %   > ;   d 3    *   ԥ &    4   & 	   [    e   ~   3    l  T    N  g    ~  B    5  | -    a      B 9   ٿ 0       D %   K (   q %    (    ,    -    (   D `   m *         +    #   F '   j #        "   8 .   [ *    !        !        6   * 0   a     *                !   , #   N    r                              4    T    l &    &    %            
     +    L    S    k     
    "       9    N    c %   ~ )         	               *     ,   K 	   x             X            '       4    P    l 0        '            M    n   _        g    n %    +             6       G    ]    d    q    ~ *                 (    	   -    7    J    W 	   d '   n         r       :    M    m         (            !       ? T   ^        T    '  $ 5   L             H   < -   e           F  s e    c     $   Y   _       c 1   -  O    }        `    E         _   n   O      "    "    "   %    H /   U     .                       #    B /   ` 2    D    ,    '   5 2   ] .    C        B   "    e                              7    T (   o +             %    +   # 1   O 2    @    $    0       K     k )    !    +    -    ,   2 5   _ +    #    $    B   
 v   M      ,         &   3 *   Z &    ,    ,    '    %   . 8   T "    1                -   9    g 5    8    /    8   "  .   [  -     @     4        . %   L '   r '            F    #   B ?   f .    )    -    "   - 2   P !    $        +         (   5 #   ^ 0    _    (    #   < /   ` )         '    '    '   + #   S     w      ;    ,       " $   A &   f &    1    %            + B   L C    I    &   	 8   D	 $   }	 &   	    	 #   	 5   
 %   <
    b
 *   {
 !   
 -   
 -   
 *   $ $   O !   t !    *    !    E    )   K +   u +         !    "    *   3    ^ $   r      0    6            <    T    o )    (             $       D M   c 	                6       $    D    ^    {        * "   E -   h                     0    -   L    z -                 0    ,   L .   y )             #    .   6 $   e     .    *           "    ;    N    j $    $    $    $          . 8   	 <   B 5    /    0    4    ?   K C    C    +    3   ? <   s +    Y      6    =            m  A  P!    "    "    " )   " )   " '   " !   ## 
   E#    P#    g#    p#    w#    #    #    #    # 	   #    #    #    #    # H   $ 3   L$ 	   $    $    $    $ `   $    '% 4   5% 5   j% c   % `   & 
   e& 	   p& 6   z&   & 	   )    )    )    )    )    )    )    ) 	   )    )    )    *    +*    7*    C*    c*    u*    * -   * *   * !   * H  +    L, V   S, W   , \   - 4   _-    - .   8.    g. >   / +  Z/ O  0    1 t  2    5 e   5 5   5 4   '6 7   \6 9   6 4   6    7   7 o   N9    9 e   w:    :    ;    <    b= G   = F   => d   > ~   >    h?    2@    @    A    'B H   B q   AC l   C c    D    D c   pE   E   G    H   I   GL [  N    XP    P    xQ    ER m   R    PS    S    zT    U    U {   V +  V    +X    X    cY    Y     Y    Z    ,Z    Z    8[    [   >\ 
  W^ 
   b` /   m`    `    ` ,   `    `    `    a     a -   -a 	   [a 	   ea    oa f   a    a    
b    (b    Cb 0   ab (   b )   b    b     c    %c ;   Cc +   c    c    c    c    c    d 6   d    ?d %   Dd %   jd *   d     d "   d    d _   e E   pe    e    e    e ,  e    h b   #h    h    h    hi    !j 	   j    j    j ;   j    ,k 	   Kk    Uk    ]k "   lk    k    k    k    k !   k    k    l    l    l    l    &l    *l    Jl    Sl >   rl ?   l M   l K   ?m ?   m :   m    n    n    n    $n    1n B   6n .   yn 	   n (   n    n    n    o    o 2   1o    do    qo    o    o *   o    o $   o    p !   -p     Op    pp    p 1   p    p 0   p 	   q    q !   &q S   Hq    q    q !   q !   q    	r    (r    Ar    Zr    rr    r    r    Us    ks    s    s    s +   s (   s '   t    4t    At    Zt    mt    }t    t    t    t    t    t    t    t    u    $u    (u    Cu ]   Su    u 	   u    u    u k   u    Mv ]  cv L  w   y    !{    .{ !   B{    d{    {    {    { "   {    {    |    "|    <|    S|    i|    v| %   ~| 
   | "   | 
   | 1   | ,   }    <}    @} $   D} $   i} *   }     }    }    }     }    ~ !   ~    A~ 
   E~ 
   P~    [~    u~ 
   ~    ~    ~    ~    ~    ~    ~    ~    ~            :    A    N *   k     $   ] %    	    2            '       !    1 #   O F  s            ׂ $   ނ $    	   (    2    ?    O    ` B   g            ʃ    ؃ !       
 	           " '   7 '   _             =                %    &   " #   I    m e    	        +    )   ; 0   e     	    $    '    	   	        .    ;    B    O    _     u    H       ʈ q    6   R i            o   p %    y                        6   ݌        3    :    W $   d         8   W   ŏ                q    4 /    ?   ) J   i V   4   ;   @ E   | V    E    c   _ 6   Ù     !        Ś 9    9     !   Z I   | b   ƛ b   )          %   V    |     ,   
  ɞ    ԟ    ۟     '    .   < :   k 0    -   נ 3    -   9 0   g *    2   á -    0   $ -   U =    7    0       *    1 
   >    I    P    i    v         %       ƣ *   ߣ    
 2   & {  Y    ե O       ;         )   ɨ )    P     n   m Y   y    ӯ 3    3   Ͱ 9    B   ; 6   ~ S    y   	 -    \    $       3    P    g     &    .   ų                    ?   9 0   y         ,   ܶ     	 i   * Z            "       A    `    ~ ,       ˸ (        )   3 !   ] '    #    #   ˹ #    (       < 0   Z         +   ɺ "    $    #   =    a    s ;    ]   »        ۽     -    ,   / 1   \ '           վ    ]    p                Կ         Q    N   l *               B     J    $                ]    ]   z _    b   8 ]    !        Q   4       U %      D        t     x               D r    L   ?    E   f             0    -   (   V &  X 	   Q    V    .  2 Q   a     3   \ E    Y    F   0    w B    E           0               
    X  $ G   } .    0    
   %    0    J    ` >   d       ( "  D    g                     $       -    L    h    o                         (       0    L    k #                  8    N      c    } F  l     >      M      " Z      j      "                 m  I        	    8
          B       Z   Y   U        Z     9    8    }            &     k   9          !    !    !    !    ! 	   !    ! '   " (   ."    W" =   j" )   "    "    "    "    "    #    #    +#    K#    ^#    b#    p# &   ~#    #    # 
   #    # *   #    #$    4$    B$    T$ 
   X$    c$    g$    l$    r$    {$    $ '   $    $    $    $    $    %    % 2   )% 
   \%    g%    u%    w%    y%    {%     %    %    %    % 1   % *   & "   B& 8   e& ?   & "   &    '    '    >'    ['    g'    s' 
   '    ' *   ' 3   ' @   ' 1   ?( A   q( ,   (    ( 6   ( h   $) E   ) 5   ) 5   	* d   ?* !   * G   * C   + =   R+ q   + +   , 8   .,    g,    =-   - Q   l/   /    1 y  )2   3   V6   8    9 S  :   b<   D>   
@ f   &A    A '   A '   A    A    B    C 5  C   F ,   G    "H    (H 	   /H 	   9H    CH    TH    aH u   qH    H    H    I    I    'I    -I    >I 	   KI    UI    jI    I    I    I    I    I    I    I )  J    O    O A   O !   8P    ZP 0   yP F   P    P    Q    Q 2   *Q 2   ]Q 2   Q 8   Q 6   Q    3R    LR    _R    rR 	   US 	   _S    iS 
   2T    =T 	   QT    [T    {T    T    T    T    T    T $   T    U    'U -   4U <   bU    U    U    U $   U    V <   V $   [V K   V ;   V 8   W 4   AW    vW &   W 1   W 3   W     X 9   =X    wX    X $   X A   X ;   Y     ?Y     `Y    Y =   Y 	   Y    Y    Y    Z 	   &Z (   0Z    YZ    uZ %   Z    Z    Z '   Z    [    [    [    8[    N[    j[    w[    }[    [ @   [    [ 	   [ 	   [    \    \ )   %\    O\    \ $   ] '   ] 	   ] 	   ] 	   ^    ^    /^    K^    j^    ^    ^    ^    ^    ^    ^ !   ^ 	   _ 
   _    $_    B_ "   ^_ ;   _    _    _    _    ` !   #`    E` &   X` &   `    `    `    `    `    ` &   ` 0   a    Ga    Ta *   :b $   eb (   b -   b -   b    c    c    &c    -c    Lc /   kc    c    c :   c =   d $   Dd    id    d *   d    d $   d (   e    /e    Ke    ke    {e    e "   e 6   e    e V   f    hf    {f    f    f    f %   f    g    g ,   ,g    Yg    rg    g #   g    g    g    	h    h    /h    Fh    ah    vh (   h    h    h    h "   h .   i *   Ni <   yi !   i    i    i    j    j %   /j    Uj    dj    tj    j    j    j 6   j .   k >   ;k $   zk    k    k    k ,   k 2   l    ?l 2   ]l    l )   l    l    l 6   m    =m -   Pm    ~m    m    m "   m    m    n    .n %   Hn    nn    n /   n    n    n    n    o *   *o    Uo )   fo $   o (   o 	   o    o    p    p !   4p    Vp +   rp 
   p 
   p 	   p    p    p '   p ,   q    Aq #   ]q 5   q    q F   q #   r 5   Br    xr    r    r    r    r 3   r    )s #   Fs    js     ws    s    s    s    s 	   s '   s I   s    Ht    \t    |t    t    t    t    t 6   t 3   u    <u )   Lu 0   vu    u -   u    u     u -   v    Gv .   Wv 3   v    v     v    v 3   v 	   3w .   =w    lw %   pw    w    w *   w    w $   x    )x    0x x  =x 5  y ]   z -   J{    x{    {    {    {    { $   {    { *   | 8   ,|    e|    y|    }|    | 3   | ;   |    '}    E}    U}    c}    q}    } *   }    }    } +   }     ~    "~ !   :~ !   \~ H   ~~ %   ~    ~        *    C 3   V      +        #           5    J    e             	    o        1             0   " #   S    w                ɂ    ւ     #           3 )   H )   r      '    {       a 	   n    x   _ :   5    p     	    u           %       A    _ '   s         ~    P   A $        '   ֋         $   * *   O .   z &    '   Ќ 	    	        2    "   Q    t    {     '    (   ɍ 7        *    K !   ^         ;    %    "       /    K    g -   } #       Ϗ     #    5       Q 6   o        Ð 6    2    #   M    q         H   ɑ &    D   9 	   ~ =    C   ƒ N   
 #   Y    }                    ғ (           .    @    `    m     	        "    '       
    & 3   8    l 8        =   ٕ 8    S   P             Ӗ #            4 	   @ 	   J    T 2   m     	       ×   ӗ     &       & 
   E    P 0   p            j      +          K                            l   !      O    7  {  _          -  {       !                                S        D            y       Y  f  .      ?              5        $             l  4          z                <  h    7  \          )                      u                                      2        [                    C    F    G                             &      ^      C  O            U                    o             }  j         .  Q     |  5                 D  q           )          )      %      0   /              P                      ;               7         7        i            u  (      R               z        l      
  '         I      L                  n           A                     p                         8                              2  }     M    }                  B        J                r        v      i        V          z        S       a    j    E    U       =        #  G                                .                                        k  g  d        a      x  -          D                          <                  9                               M   *  z                  f    e               @  F                        S                    ~  P   	  i  o  "      r      i    W               Z             .         q  m     (        
  <       ,  w        B            h    k       r               M                     L  `                     u    p                  &                ?  _          m       T                +           	            (        %   #              -                           [  v  *    <      f            >      V          I              (        W  ]                  F      <          '                
          ^      O  
                                                                    S      /                J        `     f                    H          -  9      k      `    B  U    [    P  T            %  e        6      Q    ^    >  T  8      G     U    ]  
        a  w        i  Z  }    $    L                                 z           	     $              )                             &          b       9        9  n             ;  f     F      }         M                            t  o                                w        [        i      1      %        A  .  -                                                      "  k            *               S          l      G      s  0                  /          D  ]                 2                  y                  K     Y              q  \      1  *   t    m   l              6                  F  g            /              ]      L  U              =           %         >    m  Q  u                            P    K        P        _           
   t   N     [    ?  c                 p       |         6          +  .                       g                o  ?            `                C            t  2  `                                         L           R  +        >          \       W    E                  |         h  4        k             V                   u     H          (         1            K        c      e          R      \      -      Y    T        3      A     1  f  j  e  g  U      J  R              5    n                 _                !              V        "    /         H                       \  s              C  0  >  y             4    3  1  =        y                j          3             3                  	     c      &          I      r    "      n    N    b  6      L  Z                 *                                               ,                                Q  n        C  0  7            M  ~    O    B          p                {      ;      b    n  e                                I          V                              8                 :  5  b  ,                 @           Z                   Q                                        9                              	  <        H    w  4      d    I         o  :  *                        !          #    Y        r             G  #            '              b        N    5  8       ;             H  w       X                {                   a       X                  g  '              R        1  W  p     {           &  
  D  *  <          ]       N      E  6   )        d   '    e  Y  F               I  "      H            :        N          X    1  =          m                            s           3    m  M        J  0  t  L      "  a      ~   2      s      Y    ~                  (                        )                            e                i                  r         /            Q  ~         C           2   G           q    Z            ,      D     :            A    6            d    A        c        y      b               (  H   8  8                S  S            [             ?        :        G  #       0      F          )            ~                                     |    h  {      3    b           R       "  9                  v        O    F                                    G                 %          P    "      X  ,        /          ?     +            C       R  o       `  x  N  (  9                   7  #  +        ^        W     W  z  
    A                       Z                       }        6               r       ^    i      !                `                X           p  V              {          E             J    d  u       D    6        4              %                    &  d          +     T  |      \  L  P              O  K      k  U                        >        _      B          y  @              }           M                     @      W                q   j                                 w    !        s  *        u  @  1          ,      X      g    x  ?                         w  #    q                    }                       Z               c  v          j          E      9         T     o  p    -                                          "       .      b      H          ^    h         v               y      4    s  E        =  o  %  x  t        ~              2              K  3    -  :        |              ~            N  I  	  j                        3  ;            G                    5        :                   3                    &  \           	                     f      :  |           0      '     z               ^  >            Q  h                       B  8  t            X                    ;          `            x  y            $    C        @                                      !  S    t      B     ?        8  k  e                             M              &     R          l          2  a       q  $            .    a  c   @  >  <        E                                    =                                          )                O     7     ;    ]   .                     D      7          4                C                  %               ;          '  J        ,       @        X    ?    *      +  Q   x  
          #      U          r                                  Y                       &      v  0             =  4        K        J               u      K  c  !         (  m      A              '  ;          $  |  	                I  T                      c  a           p  <  :    v  h      J             1  D  T                      )  s                  ,                   =              0  m        @                  7           Z              P  l           V                    [                       x   8  W               -                            l                  x    F        	      g                ^  H                            n      5    O                f              z      d    _          B      _                 s        J            h              '                    =      $  +                            ]                  /  I   5                $  n  9      g                               N          [                               E   ,      w  A            !   {          q      4     Y       >   \                        /     6  ]          d            5  _     A  V       $        #      v      E                          2  k        B         "uid-range-start" is greater than "uid-range-end" # Created by NetworkManager
 # Merged from %s

 %d (key) %d (passphrase) %d (unknown) %d is greater than local port max %d %d. DNS server address is invalid %d. IP address has 'label' property with invalid type %d. IP address has invalid label '%s' %d. IP address is invalid %d. route is invalid %lld (%s) %lld - %s %s %s (%s) %s (%s) cloned as %s (%s).
 %s Network %s VPN connection %s argument is missing %s is already running (pid %ld)
 %s is incompatible with static WEP keys %s is not a valid route type %s is only allowed for runner %s %s is only allowed for runners %s %s is out of range [0, %d] %s.  Please use --help to see a list of valid options.
 %s: connection profile changed
 %s: connection profile created
 %s: connection profile removed
 %s: device created
 %s: device removed
 %s: don't retry loading plugin which already failed previously %s: using connection '%s'
 %u MHz %u Mb/s %u Mbit/s %u. rule has wrong address-family %u. rule is invalid: %s '%%' is not allowed in interface names '%d' is not a valid channel '%d' is not a valid tunnel mode '%d' is out of valid range <128-16384> '%ld' is not a valid channel '%s' and '%s' cannot have different values '%s' can only be used with '%s=%s' (WEP) '%s' connection requires '%s' or '%s' setting '%s' connection requires '%s' setting '%s' connections must be enslaved to '%s', not '%s' '%s' contains invalid char(s) (use [A-Za-z._-]) '%s' does not contain a valid PAC Script '%s' has to be alone '%s' is ambiguous (%s) '%s' is ambiguous: %s '%s' is neither an UUID nor an interface name '%s' is not a VPN connection profile '%s' is not a name of any exiting profile '%s' is not a number '%s' is not a valid DCB flag '%s' is not a valid Ethernet MAC '%s' is not a valid Ethernet port value '%s' is not a valid FQDN '%s' is not a valid IAID '%s' is not a valid IBoIP P_Key '%s' is not a valid IP or subnet '%s' is not a valid IP%s address '%s' is not a valid IPv%c address '%s' is not a valid IPv4 address '%s' is not a valid IPv4 address for '%s' option '%s' is not a valid IPv6 address '%s' is not a valid MAC address '%s' is not a valid UUID '%s' is not a valid Wi-Fi mode '%s' is not a valid band '%s' is not a valid channel '%s' is not a valid channel; use <1-13> '%s' is not a valid duplex value '%s' is not a valid handle. '%s' is not a valid hex character '%s' is not a valid interface name '%s' is not a valid interface type '%s' is not a valid key '%s' is not a valid kind '%s' is not a valid number '%s' is not a valid number (or out of range) '%s' is not a valid tunnel key '%s' is not a valid value for '%s' '%s' is not a valid value for '%s' mode connections '%s' is not a valid value for the property '%s' is not allowed as interface name '%s' is not allowed in bond_mode '%s' is not allowed in fail_mode '%s' is not allowed in lacp '%s' is not allowed in vlan_mode '%s' is not compatible with '%s' type, please change or delete the key. '%s' is not valid '%s' is not valid WEP key (it should be 5 or 13 ASCII chars) '%s' is not valid WPA PSK '%s' is not valid for the '%s' option: %s '%s' is not valid: properties should be specified as 'key=value' '%s' is not valid; 2 or 3 strings should be provided '%s' is not valid; use 'on', 'off', or 'ignore' '%s' is not valid; use <option>=<value> '%s' is not valid; use [%s] or [%s] '%s' is not valid; use [%s], [%s] or [%s] '%s' is now the primary connection
 '%s' is out of range [% '%s' is out of range [0, %u] '%s' length is invalid (should be 5 or 6 digits) '%s' not a number between 0 and %u (inclusive) '%s' not a number between 0 and %u (inclusive) or %u '%s' not among [%s] '%s' not compatible with %s '%s', please change the key or set the right %s first. '%s' option is empty '%s' option is not valid with mode '%s' '%s' option is only valid for '%s=%s' '%s' option is only valid with mode '%s' '%s' option must be a power of 2 '%s' option requires '%s' option to be enabled '%s' option requires '%s' option to be set '%s' option should be string '%s' requires '%s' and '%s' property '%s' requires setting '%s' property '%s' security requires '%s' setting presence '%s' security requires '%s=%s' '%s' unexpected: parent already specified. '%s' value doesn't match '%s=%s' '%s': invalid group ID '%s': invalid user ID '%s::%s' is not a valid property name; '%s' is not a GObject subtype '%s=%s' is incompatible with '%s > 0' '%s=%s' is not a valid configuration for '%s' '%u' flags are not valid; use combination of %s '%u': invalid mode '--order' argument is missing 'fqdn-clear-flags' flag is incompatible with other FQDN flags 'fqdn-no-update' and 'fqdn-serv-update' flags cannot be set at the same time (No custom routes) (No support for dynamic-wep yet...) (No support for wpa-enterprise yet...) (default) (none) (unknown error) (unknown) , neither a valid setting name ---[ Main menu ]---
goto     [<setting> | <prop>]        :: go to a setting or property
remove   <setting>[.<prop>] | <prop> :: remove setting or reset property value
set      [<setting>.<prop> <value>]  :: set property value
describe [<setting>.<prop>]          :: describe property
print    [all | <setting>[.<prop>]]  :: print the connection
verify   [all | fix]                 :: verify the connection
save     [persistent|temporary]      :: save the connection
activate [<ifname>] [/<ap>|<nsp>]    :: activate the connection
back                                 :: go one level up (back)
help/?   [<command>]                 :: print this help
nmcli    <conf-option> <value>       :: nmcli configuration
quit                                 :: exit nmcli
 ---[ Property menu ]---
set      [<value>]               :: set new value
add      [<value>]               :: add new option to the property
change                           :: change current value
remove   [<index> | <option>]    :: delete the value
describe                         :: describe property
print    [setting | connection]  :: print property (setting/connection) value(s)
back                             :: go to upper level
help/?   [<command>]             :: print this help or command description
quit                             :: exit nmcli
 0 (NONE) 0 (disabled) 0 (none) 6LOWPAN connection 6LOWPAN settings 6LoWPAN 802-1x settings 802.11 frequency band of the network.  One of "a" for 5GHz 802.11a or "bg" for 2.4GHz 802.11.  This will lock associations to the Wi-Fi network to the specific band, i.e. if "a" is specified, the device will not associate with the same network in the 2.4GHz band even if the network's settings are compatible.  This setting depends on specific driver capability and may not work with all drivers. 802.1X supplicant configuration failed 802.1X supplicant disconnected 802.1X supplicant failed 802.1X supplicant took too long to authenticate 802.1x setting requires 'wpa-eap' key management 802.3ad <invisible> <invisible> | %s ===| nmcli interactive connection editor |=== A (5 GHz) A MCC/MNC string like "310260" or "21601" identifying the specific mobile network operator which this connection applies to.  If given, the connection will apply to any device also allowed by "device-id" and "sim-id" which contains a SIM card provisioned by the given operator. A connection can not have both '%s' and '%s' settings at the same time A connection of type '%s' cannot have an ovs-interface.type "%s" A connection of type '%s' cannot have ovs-interface.type "system" A connection with '%s' setting must be of connection.type "ovs-interface" but is "%s" A connection with '%s' setting needs to be of '%s' interface type, not '%s' A connection with a '%s' setting must have a master. A connection with a '%s' setting must have the slave-type set to '%s'. Instead it is '%s' A connection with a '%s' setting must not have a master. A connection with a '%s' setting needs connection.type explicitly set A connection with ovs-interface.type '%s' setting a 'ovs-patch' setting A dependency of the connection failed A dictionary of key/value pairs with exernal-ids for OVS. A dictionary of key/value pairs with user data. This data is ignored by NetworkManager and can be used at the users discretion. The keys only support a strict ascii format, but the values can be arbitrary UTF8 strings up to a certain length. A duplicate IP address was detected A human readable unique identifier for the connection, like "Work Wi-Fi" or "T-Mobile 3G". A list of BSSIDs (each BSSID formatted as a MAC address like "00:11:22:33:44:55") that have been detected as part of the Wi-Fi network.  NetworkManager internally tracks previously seen BSSIDs. The property is only meant for reading and reflects the BSSID list of NetworkManager. The changes you make to this property will not be preserved. A list of IPv4 destination addresses, prefix length, optional IPv4 next hop addresses, optional route metric, optional attribute. The valid syntax is: "ip[/prefix] [next-hop] [metric] [attribute=val]...[,ip[/prefix]...]". For example "192.0.2.0/24 10.1.1.1 77, 198.51.100.0/24". A list of driver names to match. Each element is a shell wildcard pattern. See NMSettingMatch:interface-name for how special characters '|', '&', '!' and '\' are used for optional and mandatory matches and inverting the pattern. A list of group/broadcast encryption algorithms which prevents connections to Wi-Fi networks that do not utilize one of the algorithms in the list.  For maximum compatibility leave this property empty.  Each list element may be one of "wep40", "wep104", "tkip", or "ccmp". A list of interface names to match. Each element is a shell wildcard pattern. An element can be prefixed with a pipe symbol (|) or an ampersand (&). The former means that the element is optional and the latter means that it is mandatory. If there are any optional elements, than the match evaluates to true if at least one of the optional element matches (logical OR). If there are any mandatory elements, then they all must match (logical AND). By default, an element is optional. This means that an element "foo" behaves the same as "|foo". An element can also be inverted with exclamation mark (!) between the pipe symbol (or the ampersand) and before the pattern. Note that "!foo" is a shortcut for the mandatory match "&!foo". Finally, a backslash can be used at the beginning of the element (after the optional special characters) to escape the start of the pattern. For example, "&\!a" is an mandatory match for literally "!a". A list of kernel command line arguments to match. This may be used to check whether a specific kernel command line option is set (or unset, if prefixed with the exclamation mark). The argument must either be a single word, or an assignment (i.e. two words, joined by "="). In the former case the kernel command line is searched for the word appearing as is, or as left hand side of an assignment. In the latter case, the exact assignment is looked for with right and left hand side matching. Wildcard patterns are not supported. See NMSettingMatch:interface-name for how special characters '|', '&', '!' and '\' are used for optional and mandatory matches and inverting the match. A list of pairwise encryption algorithms which prevents connections to Wi-Fi networks that do not utilize one of the algorithms in the list. For maximum compatibility leave this property empty.  Each list element may be one of "tkip" or "ccmp". A list of paths to match against the ID_PATH udev property of devices. ID_PATH represents the topological persistent path of a device. It typically contains a subsystem string (pci, usb, platform, etc.) and a subsystem-specific identifier. For PCI devices the path has the form "pci-$domain:$bus:$device.$function", where each variable is an hexadecimal value; for example "pci-0000:0a:00.0". The path of a device can be obtained with "udevadm info /sys/class/net/$dev | grep ID_PATH=" or by looking at the "path" property exported by NetworkManager ("nmcli -f general.path device show $dev"). Each element of the list is a shell wildcard pattern. See NMSettingMatch:interface-name for how special characters '|', '&', '!' and '\' are used for optional and mandatory matches and inverting the pattern. A list of permanent MAC addresses of Wi-Fi devices to which this connection should never apply.  Each MAC address should be given in the standard hex-digits-and-colons notation (eg "00:11:22:33:44:55"). A mask of group addresses to forward. Usually, group addresses in the range from 01:80:C2:00:00:00 to 01:80:C2:00:00:0F are not forwarded according to standards. This property is a mask of 16 bits, each corresponding to a group address in that range that must be forwarded. The mask can't have bits 0, 1 or 2 set because they are used for STP, MAC pause frames and LACP. A password is required to connect to '%s'. A problem with the RFC 2684 Ethernet over ADSL bridge A secondary connection of the base connection failed A slave connection with '%s' set to '%s' cannot have a '%s' setting A string containing the DHCPv6 Unique Identifier (DUID) used by the dhcp client to identify itself to DHCPv6 servers (RFC 3315). The DUID is carried in the Client Identifier option. If the property is a hex string ('aa:bb:cc') it is interpreted as a binary DUID and filled as an opaque value in the Client Identifier option. The special value "lease" will retrieve the DUID previously used from the lease file belonging to the connection. If no DUID is found and "dhclient" is the configured dhcp client, the DUID is searched in the system-wide dhclient lease file. If still no DUID is found, or another dhcp client is used, a global and permanent DUID-UUID (RFC 6355) will be generated based on the machine-id. The special values "llt" and "ll" will generate a DUID of type LLT or LL (see RFC 3315) based on the current MAC address of the device. In order to try providing a stable DUID-LLT, the time field will contain a constant timestamp that is used globally (for all profiles) and persisted to disk. The special values "stable-llt", "stable-ll" and "stable-uuid" will generate a DUID of the corresponding type, derived from the connection's stable-id and a per-host unique key. You may want to include the "${DEVICE}" or "${MAC}" specifier in the stable-id, in case this profile gets activated on multiple devices. So, the link-layer address of "stable-ll" and "stable-llt" will be a generated address derived from the stable id. The DUID-LLT time value in the "stable-llt" option will be picked among a static timespan of three years (the upper bound of the interval is the same constant timestamp used in "llt"). When the property is unset, the global value provided for "ipv6.dhcp-duid" is used. If no global value is provided, the default "lease" value is assumed. A string sent to the DHCP server to identify the local machine which the DHCP server may use to customize the DHCP lease and options. When the property is a hex string ('aa:bb:cc') it is interpreted as a binary client ID, in which case the first byte is assumed to be the 'type' field as per RFC 2132 section 9.14 and the remaining bytes may be an hardware address (e.g. '01:xx:xx:xx:xx:xx:xx' where 1 is the Ethernet ARP type and the rest is a MAC address). If the property is not a hex string it is considered as a non-hardware-address client ID and the 'type' field is set to 0. The special values "mac" and "perm-mac" are supported, which use the current or permanent MAC address of the device to generate a client identifier with type ethernet (01). Currently, these options only work for ethernet type of links. The special value "ipv6-duid" uses the DUID from "ipv6.dhcp-duid" property as an RFC4361-compliant client identifier. As IAID it uses "ipv4.dhcp-iaid" and falls back to "ipv6.dhcp-iaid" if unset. The special value "duid" generates a RFC4361-compliant client identifier based on "ipv4.dhcp-iaid" and uses a DUID generated by hashing /etc/machine-id. The special value "stable" is supported to generate a type 0 client identifier based on the stable-id (see connection.stable-id) and a per-host key. If you set the stable-id, you may want to include the "${DEVICE}" or "${MAC}" specifier to get a per-device key. If unset, a globally configured default is used. If still unset, the default depends on the DHCP plugin. A timeout for a DHCP transaction in seconds. If zero (the default), a globally configured default is used. If still unspecified, a device specific timeout is used (usually 45 seconds). Set to 2147483647 (MAXINT32) for infinity. A timeout for the authentication. Zero means the global default; if the global default is not set, the authentication timeout is 25 seconds. A timeout for waiting Router Advertisements in seconds. If zero (the default), a globally configured default is used. If still unspecified, the timeout depends on the sysctl settings of the device. Set to 2147483647 (MAXINT32) for infinity. A universally unique identifier for the connection, for example generated with libuuid.  It should be assigned when the connection is created, and never changed as long as the connection still applies to the same network.  For example, it should not be changed when the "id" property or NMSettingIP4Config changes, but might need to be re-created when the Wi-Fi SSID, mobile broadband network provider, or "type" property changes. The UUID must be in the format "2815492f-7e56-435e-b2e9-246bd7cdc664" (ie, contains only hexadecimal characters and "-"). ADSL ADSL connection ADSL connection protocol.  Can be "pppoa", "pppoe" or "ipoatm". AP isolation can be set only in AP mode APN ARP ARP targets Access Point Access point does not support 802.1x but setting requires it Access point does not support PSK but setting requires it Access point is unencrypted but setting specifies security Activate Activate a connection Activation failed: %s Active Backup Active connection details Ad-Hoc Ad-Hoc Network Ad-Hoc mode is incompatible with 802.1x security Ad-Hoc mode is incompatible with LEAP security Ad-Hoc mode requires 'none' or 'wpa-psk' key management Ad-Hoc mode requires 'open' authentication Adaptive Load Balancing (alb) Adaptive Transmit Load Balancing (tlb) Add Add... Adding a new '%s' connection Addresses Aging time Allow BSD data compression Allow Deflate data compression Allow control of Wi-Fi scans Allow control of network connections Allowed authentication methods: Allowed values for '%s' property: %s
 An array of 8 boolean values, where the array index corresponds to the User Priority (0 - 7) and the value indicates whether or not the corresponding priority should transmit priority pause. An array of 8 boolean values, where the array index corresponds to the User Priority (0 - 7) and the value indicates whether or not the priority may use all of the bandwidth allocated to its assigned group. An array of 8 uint values, where the array index corresponds to the Priority Group ID (0 - 7) and the value indicates the percentage of link bandwidth allocated to that group.  Allowed values are 0 - 100, and the sum of all values must total 100 percents. An array of 8 uint values, where the array index corresponds to the User Priority (0 - 7) and the value indicates the Priority Group ID.  Allowed Priority Group ID values are 0 - 7 or 15 for the unrestricted group. An array of 8 uint values, where the array index corresponds to the User Priority (0 - 7) and the value indicates the percentage of bandwidth of the priority's assigned group that the priority may use.  The sum of all percentages for priorities which belong to the same group must total 100 percents. An array of 8 uint values, where the array index corresponds to the User Priority (0 - 7) and the value indicates the traffic class (0 - 7) to which the priority is mapped. An array of strings defining what access a given user has to this connection.  If this is NULL or empty, all users are allowed to access this connection; otherwise users are allowed if and only if they are in this list.  When this is not empty, the connection can be active only when one of the specified users is logged into an active session.  Each entry is of the form "[type]:[id]:[reserved]"; for example, "user:dcbw:blah". At this time only the "user" [type] is allowed.  Any other values are ignored and reserved for future use.  [id] is the username that this permission refers to, which may not contain the ":" character. Any [reserved] information present must be ignored and is reserved for future use.  All of [type], [id], and [reserved] must be valid UTF-8. An http(s) address for checking internet connectivity Anonymous identity string for EAP authentication methods.  Used as the unencrypted identity with EAP types that support different tunneled identity like EAP-TTLS. Are you sure you want to delete the connection '%s'? Array of DNS options as described in man 5 resolv.conf. NULL means that the options are unset and left at the default. In this case NetworkManager will use default options. This is distinct from an empty list of properties. The currently supported options are "attempts", "debug", "edns0", "inet6", "ip6-bytestring", "ip6-dotint", "ndots", "no-check-names", "no-ip6-dotint", "no-reload", "no-tld-query", "rotate", "single-request", "single-request-reopen", "timeout", "trust-ad", "use-vc". The "trust-ad" setting is only honored if the profile contributes name servers to resolv.conf, and if all contributing profiles have "trust-ad" enabled. When using a caching DNS plugin (dnsmasq or systemd-resolved in NetworkManager.conf) then "edns0" and "trust-ad" are automatically added. Array of IP addresses of DNS servers. Array of IP routes. Array of bridge VLAN objects. In addition to the VLANs specified here, the bridge will also have the default-pvid VLAN configured  by the bridge.vlan-default-pvid property. In nmcli the VLAN list can be specified with the following syntax: $vid [pvid] [untagged] [, $vid [pvid] [untagged]]... where $vid is either a single id between 1 and 4094 or a range, represented as a couple of ids separated by a dash. Array of bridge VLAN objects. In addition to the VLANs specified here, the port will also have the default-pvid VLAN configured on the bridge by the bridge.vlan-default-pvid property. In nmcli the VLAN list can be specified with the following syntax: $vid [pvid] [untagged] [, $vid [pvid] [untagged]]... where $vid is either a single id between 1 and 4094 or a range, represented as a couple of ids separated by a dash. Array of servers from which DHCP offers must be rejected. This property is useful to avoid getting a lease from misconfigured or rogue servers. For DHCPv4, each element must be an IPv4 address, optionally followed by a slash and a prefix length (e.g. "192.168.122.0/24"). This property is currently not implemented for DHCPv6. Array of virtual function descriptors. Each VF descriptor is a dictionary mapping attribute names to GVariant values. The 'index' entry is mandatory for each VF. When represented as string a VF is in the form: "INDEX [ATTR=VALUE[ ATTR=VALUE]...]". for example: "2 mac=00:11:22:33:44:55 spoof-check=true". Multiple VFs can be specified using a comma as separator. Currently, the following attributes are supported: mac, spoof-check, trust, min-tx-rate, max-tx-rate, vlans. The "vlans" attribute is represented as a semicolon-separated list of VLAN descriptors, where each descriptor has the form "ID[.PRIORITY[.PROTO]]". PROTO can be either 'q' for 802.1Q (the default) or 'ad' for 802.1ad. Ask for this password every time Authentication Authentication required by wireless network AutoIP service error AutoIP service failed AutoIP service failed to start Automatic Automatic (DHCP-only) Automatically connect Available properties: %s
 Available settings: %s
 Available to all users B/G (2.4 GHz) BOND BRIDGE BRIDGE PORT BSSID Back Bad '%s' option:  Base type of the connection. For hardware-dependent connections, should contain the setting name of the hardware-type specific setting (ie, "802-3-ethernet" or "802-11-wireless" or "bluetooth", etc), and for non-hardware dependent connections like VPN or otherwise, should contain the setting name of that setting type (ie, "vpn" or "bridge", etc). Bluetooth Bluetooth device address Bond Bond connection Bond connection %d Bond device Bonding mode. One of "active-backup", "balance-slb", or "balance-tcp". Bonding monitoring mode Bridge Bridge VLANs %d and %d are not sorted by ascending vid Bridge connection Bridge connection %d Bridge device Bridge port Broadcast Byte-width of the serial communication. The 8 in "8n1" for example. CA certificate must be in X.509 format CDMA connection CDMA mobile broadband connection CHAP Can not change the connection type Cancel Cannot create '%s': %s Cannot set '%s' without '%s' Carrier/link changed Certificate file is empty Certificate password Channel Channel (<default|0-26>) Channel on which the mesh network to join is located. Cloned MAC [none] Cloned MAC address Closing %s failed: %s
 Config directory location Config file location Configure IPv6 Privacy Extensions for SLAAC, described in RFC4941.  If enabled, it makes the kernel generate a temporary IPv6 address in addition to the public one generated from MAC address via modified EUI-64.  This enhances privacy, but could cause problems in some applications, on the other hand.  The permitted values are: -1: unknown, 0: disabled, 1: enabled (prefer public address), 2: enabled (prefer temporary addresses). Having a per-connection setting set to "-1" (unknown) means fallback to global configuration "ipv6.ip6-privacy". If also global configuration is unspecified or set to "-1", fallback to read "/proc/sys/net/ipv6/conf/default/use_tempaddr". Note that this setting is distinct from the Stable Privacy addresses that can be enabled with the "addr-gen-mode" property's "stable-privacy" setting as another way of avoiding host tracking with IPv6 addresses. Configure the token for draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 tokenized interface identifiers. Useful with eui64 addr-gen-mode. Configures AP isolation, which prevents communication between wireless devices connected to this AP. This property can be set to a value different from NM_TERNARY_DEFAULT (-1) only when the interface is configured in AP mode. If set to NM_TERNARY_TRUE (1), devices are not able to communicate with each other. This increases security because it protects devices against attacks from other clients in the network. At the same time, it prevents devices to access resources on the same wireless networks as file shares, printers, etc. If set to NM_TERNARY_FALSE (0), devices can talk to each other. When set to NM_TERNARY_DEFAULT (-1), the global default is used; in case the global default is unspecified it is assumed to be NM_TERNARY_FALSE (0). Connected Connecting Connecting... Connection '%s' (%s) successfully added.
 Connection '%s' (%s) successfully deleted.
 Connection '%s' (%s) successfully modified.
 Connection '%s' (%s) successfully saved.
 Connection '%s' (%s) successfully updated.
 Connection '%s' deactivation failed: %s
 Connection '%s' successfully deactivated (D-Bus active path: %s)
 Connection (name, UUID, or path):  Connection is already active Connection profile details Connection sharing via a protected Wi-Fi network Connection sharing via an open Wi-Fi network Connection successfully activated (%s) (D-Bus active path: %s)
 Connection successfully activated (D-Bus active path: %s)
 Connection successfully reapplied to device '%s'.
 Connection(s) (name, UUID, or path):  Connection(s) (name, UUID, path or apath):  Connectivity Connectivity is now '%s'
 Constraint for server domain name. If set, this FQDN is used as a suffix match requirement for dNSName element(s) of the certificate presented by the authentication server during the inner "phase 2" authentication.  If a matching dNSName is found, this constraint is met.  If no dNSName values are present, this constraint is matched against SubjectName CN using same suffix match comparison. Since version 1.24, multiple valid FQDNs can be passed as a ";" delimited list. Constraint for server domain name. If set, this FQDN is used as a suffix match requirement for dNSName element(s) of the certificate presented by the authentication server.  If a matching dNSName is found, this constraint is met.  If no dNSName values are present, this constraint is matched against SubjectName CN using same suffix match comparison. Since version 1.24, multiple valid FQDNs can be passed as a ";" delimited list. Constraint for server domain name. If set, this list of FQDNs is used as a match requirement for dNSName element(s) of the certificate presented by the authentication server during the inner "phase 2" authentication. If a matching dNSName is found, this constraint is met.  If no dNSName values are present, this constraint is matched against SubjectName CN using the same comparison. Multiple valid FQDNs can be passed as a ";" delimited list. Constraint for server domain name. If set, this list of FQDNs is used as a match requirement for dNSName element(s) of the certificate presented by the authentication server.  If a matching dNSName is found, this constraint is met.  If no dNSName values are present, this constraint is matched against SubjectName CN using the same comparison. Multiple valid FQDNs can be passed as a ";" delimited list. Contains the "phase 2" CA certificate if used by the EAP method specified in the "phase2-auth" or "phase2-autheap" properties. Certificate data is specified using a "scheme"; three are currently supported: blob, path and pkcs#11 URL. When using the blob scheme this property should be set to the certificate's DER encoded data. When using the path scheme, this property should be set to the full UTF-8 encoded path of the certificate, prefixed with the string "file://" and ending with a terminating NUL byte. This property can be unset even if the EAP method supports CA certificates, but this allows man-in-the-middle attacks and is NOT recommended. Note that enabling NMSetting8021x:system-ca-certs will override this setting to use the built-in path, if the built-in path is not a directory. Contains the "phase 2" client certificate if used by the EAP method specified in the "phase2-auth" or "phase2-autheap" properties. Certificate data is specified using a "scheme"; two are currently supported: blob and path. When using the blob scheme (which is backwards compatible with NM 0.7.x) this property should be set to the certificate's DER encoded data. When using the path scheme, this property should be set to the full UTF-8 encoded path of the certificate, prefixed with the string "file://" and ending with a terminating NUL byte. This property can be unset even if the EAP method supports CA certificates, but this allows man-in-the-middle attacks and is NOT recommended. Contains the "phase 2" inner private key when the "phase2-auth" or "phase2-autheap" property is set to "tls". Key data is specified using a "scheme"; two are currently supported: blob and path. When using the blob scheme and private keys, this property should be set to the key's encrypted PEM encoded data. When using private keys with the path scheme, this property should be set to the full UTF-8 encoded path of the key, prefixed with the string "file://" and ending with a terminating NUL byte. When using PKCS#12 format private keys and the blob scheme, this property should be set to the PKCS#12 data and the "phase2-private-key-password" property must be set to password used to decrypt the PKCS#12 certificate and key. When using PKCS#12 files and the path scheme, this property should be set to the full UTF-8 encoded path of the key, prefixed with the string "file://" and ending with a terminating NUL byte, and as with the blob scheme the "phase2-private-key-password" property must be set to the password used to decode the PKCS#12 private key and certificate. Contains the CA certificate if used by the EAP method specified in the "eap" property. Certificate data is specified using a "scheme"; three are currently supported: blob, path and pkcs#11 URL. When using the blob scheme this property should be set to the certificate's DER encoded data. When using the path scheme, this property should be set to the full UTF-8 encoded path of the certificate, prefixed with the string "file://" and ending with a terminating NUL byte. This property can be unset even if the EAP method supports CA certificates, but this allows man-in-the-middle attacks and is NOT recommended. Note that enabling NMSetting8021x:system-ca-certs will override this setting to use the built-in path, if the built-in path is not a directory. Contains the client certificate if used by the EAP method specified in the "eap" property. Certificate data is specified using a "scheme"; two are currently supported: blob and path. When using the blob scheme (which is backwards compatible with NM 0.7.x) this property should be set to the certificate's DER encoded data. When using the path scheme, this property should be set to the full UTF-8 encoded path of the certificate, prefixed with the string "file://" and ending with a terminating NUL byte. Contains the private key when the "eap" property is set to "tls". Key data is specified using a "scheme"; two are currently supported: blob and path. When using the blob scheme and private keys, this property should be set to the key's encrypted PEM encoded data. When using private keys with the path scheme, this property should be set to the full UTF-8 encoded path of the key, prefixed with the string "file://" and ending with a terminating NUL byte. When using PKCS#12 format private keys and the blob scheme, this property should be set to the PKCS#12 data and the "private-key-password" property must be set to password used to decrypt the PKCS#12 certificate and key. When using PKCS#12 files and the path scheme, this property should be set to the full UTF-8 encoded path of the key, prefixed with the string "file://" and ending with a terminating NUL byte, and as with the blob scheme the "private-key-password" property must be set to the password used to decode the PKCS#12 private key and certificate. WARNING: "private-key" is not a "secret" property, and thus unencrypted private key data using the BLOB scheme may be readable by unprivileged users.  Private keys should always be encrypted with a private key password to prevent unauthorized access to unencrypted private key data. Control whether VLAN filtering is enabled on the bridge. Controls the interpretation of WEP keys.  Allowed values are NM_WEP_KEY_TYPE_KEY (1), in which case the key is either a 10- or 26-character hexadecimal string, or a 5- or 13-character ASCII password; or NM_WEP_KEY_TYPE_PASSPHRASE (2), in which case the passphrase is provided as a string and will be hashed using the de-facto MD5 method to derive the actual WEP key. Controls whether IGMP snooping is enabled for this bridge. Note that if snooping was automatically disabled due to hash collisions, the system may refuse to enable the feature until the collisions are resolved. Controls whether Spanning Tree Protocol (STP) is enabled for this bridge. Controls whether per-VLAN stats accounting is enabled. Cookie Corresponds to the teamd mcast_rejoin.count. Corresponds to the teamd mcast_rejoin.interval. Corresponds to the teamd notify_peers.count. Corresponds to the teamd notify_peers.interval. Corresponds to the teamd ports.PORTIFNAME.lacp_key. Corresponds to the teamd ports.PORTIFNAME.lacp_prio. Corresponds to the teamd ports.PORTIFNAME.prio. Corresponds to the teamd ports.PORTIFNAME.queue_id. When set to -1 means the parameter is skipped from the json config. Corresponds to the teamd ports.PORTIFNAME.sticky. Corresponds to the teamd runner.active. Corresponds to the teamd runner.agg_select_policy. Corresponds to the teamd runner.fast_rate. Corresponds to the teamd runner.hwaddr_policy. Corresponds to the teamd runner.min_ports. Corresponds to the teamd runner.name. Permitted values are: "roundrobin", "broadcast", "activebackup", "loadbalance", "lacp", "random". Corresponds to the teamd runner.sys_prio. Corresponds to the teamd runner.tx_balancer.interval. Corresponds to the teamd runner.tx_balancer.name. Corresponds to the teamd runner.tx_hash. Could not activate connection: %s Could not contact NetworkManager: %s.
 Could not create a software link Could not create editor for connection '%s' of type '%s'. Could not create editor for invalid connection '%s'. Could not create temporary file: %s Could not daemonize: %s [error %u]
 Could not deactivate connection: %s Could not decode private key. Could not delete connection '%s': %s Could not find "%s" binary Could not find any session id for uid %d Could not generate random data. Could not load file '%s'
 Could not parse arguments Could not re-read file: %s Could not retrieve session id: %s Couldn't decode PKCS#12 file: %d Couldn't decode PKCS#12 file: %s Couldn't decode PKCS#8 file: %s Couldn't decode certificate: %d Couldn't decode certificate: %s Couldn't initialize PKCS#12 decoder: %d Couldn't initialize PKCS#12 decoder: %s Couldn't initialize PKCS#8 decoder: %s Couldn't initialize slot Couldn't verify PKCS#12 file: %d Couldn't verify PKCS#12 file: %s Create Current nmcli configuration:
 D-Bus service name of the VPN plugin that this setting uses to connect to its network.  i.e. org.freedesktop.NetworkManager.vpnc for the vpnc plugin. DCB or FCoE setup failed DCB settings DHCP anycast MAC address [none] DHCP client error DHCP client failed DHCP client failed to start DHCP option cannot be longer than 255 characters DHCPv6 does not support the E (encoded) FQDN flag DNS servers DNS servers priority. The relative priority for DNS servers specified by this setting.  A lower numerical value is better (higher priority). Negative values have the special effect of excluding other configurations with a greater numerical priority value; so in presence of at least one negative priority, only DNS servers from connections with the lowest priority value will be used. To avoid all DNS leaks, set the priority of the profile that should be used to the most negative value of all active connections profiles. Zero selects a globally configured default value. If the latter is missing or zero too, it defaults to 50 for VPNs (including WireGuard) and 100 for other connections. Note that the priority is to order DNS settings for multiple active connections.  It does not disambiguate multiple DNS servers within the same connection profile. When multiple devices have configurations with the same priority, VPNs will be considered first, then devices with the best (lowest metric) default route and then all other devices. When using dns=default, servers with higher priority will be on top of resolv.conf. To prioritize a given server over another one within the same connection, just specify them in the desired order. Note that commonly the resolver tries name servers in /etc/resolv.conf in the order listed, proceeding with the next server in the list on failure. See for example the "rotate" option of the dns-options setting. If there are any negative DNS priorities, then only name servers from the devices with that lowest priority will be considered. When using a DNS resolver that supports Conditional Forwarding or Split DNS (with dns=dnsmasq or dns=systemd-resolved settings), each connection is used to query domains in its search list. The search domains determine which name servers to ask, and the DNS priority is used to prioritize name servers based on the domain.  Queries for domains not present in any search list are routed through connections having the '~.' special wildcard domain, which is added automatically to connections with the default route (or can be added manually).  When multiple connections specify the same domain, the one with the best priority (lowest numerical value) wins.  If a sub domain is configured on another interface it will be accepted regardless the priority, unless parent domain on the other interface has a negative priority, which causes the sub domain to be shadowed. With Split DNS one can avoid undesired DNS leaks by properly configuring DNS priorities and the search domains, so that only name servers of the desired interface are configured. DSL DSL authentication DSL connection %d DUN connection must include a GSM or CDMA setting DUN requested, but Bluetooth device does not support DUN Datagram Deactivate Delete Destination Detect a slave connection with '%s' set and a port type '%s'. '%s' should be set to '%s' Device Device '%s' not found Device '%s' successfully activated with '%s'.
 Device '%s' successfully disconnected.
 Device '%s' successfully removed.
 Device LLDP neighbors Device MAC (%s) is blacklisted by the connection. Device details Device disconnected by user or client Device is now managed Device is now unmanaged Dictionary of key/value pairs of VPN plugin specific data.  Both keys and values must be strings. Dictionary of key/value pairs of VPN plugin specific secrets like passwords or private keys.  Both keys and values must be strings. Dictionary of key/value pairs of bonding options.  Both keys and values must be strings. Option names must contain only alphanumeric characters (ie, [a-zA-Z0-9]). Disabled Disconnected by user Do you also want to clear '%s'? [yes]:  Do you also want to set '%s' to '%s'? [yes]:  Do you want to remove them? [yes]  Don't become a daemon Don't become a daemon, and log to stderr Don't print anything Dummy Dummy connection Dummy settings Dynamic WEP (802.1x) Dynamic WEP requires 'ieee8021x' key management Dynamic WEP requires 'open' authentication Dynamic WEP requires an 802.1x setting EAP EAP key management requires '%s' setting presence ETHERNET Edit '%s' value:  Edit Connection Edit a connection Edit... Editing existing '%s' connection: '%s' Editor failed: %s Egress priority maps [none] Either "dun" for Dial-Up Networking connections or "panu" for Personal Area Networking connections to devices supporting the NAP profile. Enable IGMP snooping Enable STP (Spanning Tree Protocol) Enable or disable RSTP. Enable or disable STP. Enable or disable Wi-Fi devices Enable or disable WiMAX mobile broadband devices Enable or disable connectivity checking Enable or disable device statistics Enable or disable mobile broadband devices Enable or disable multicast snooping. Enable or disable sending of multicast queries by the bridge. If not specified the option is disabled. Enable or disable system networking Enable policy routing (source routing) and set the routing table used when adding routes. This affects all routes, including device-routes, IPv4LL, DHCP, SLAAC, default-routes and static routes. But note that static routes can individually overwrite the setting by explicitly specifying a non-zero routing table. If the table setting is left at zero, it is eligible to be overwritten via global configuration. If the property is zero even after applying the global configuration value, policy routing is disabled for the address family of this connection. Policy routing disabled means that NetworkManager will add all routes to the main table (except static routes that explicitly configure a different table). Additionally, NetworkManager will not delete any extraneous routes from tables except the main table. This is to preserve backward compatibility for users who manage routing tables outside of NetworkManager. Enables or disables "hairpin mode" for the port, which allows frames to be sent back out through the port the frame was received on. Enables or disables in-line provisioning of EAP-FAST credentials when FAST is specified as the EAP method in the "eap" property. Recognized values are "0" (disabled), "1" (allow unauthenticated provisioning), "2" (allow authenticated provisioning), and "3" (allow both authenticated and unauthenticated provisioning).  See the wpa_supplicant documentation for more details. Encapsulation of ADSL connection.  Can be "vcmux" or "llc". Enhanced Open (OWE) Enter '%s' value:  Enter a list of IPv4 addresses formatted as:
  ip[/prefix], ip[/prefix],...
Missing prefix is regarded as prefix of 32.

Example: 192.168.1.5/24, 10.0.0.11/24
 Enter a list of IPv4 addresses of DNS servers.

Example: 8.8.8.8, 8.8.4.4
 Enter a list of IPv4 routes formatted as:
  ip[/prefix] [next-hop] [metric],...

Missing prefix is regarded as a prefix of 32.
Missing next-hop is regarded as 0.0.0.0.
Missing metric means default (NM/kernel will set a default value).

Examples: 192.168.2.0/24 192.168.2.1 3, 10.1.0.0/16 10.0.0.254
          10.1.2.0/24
 Enter a list of IPv4 routing rules formatted as:
  priority [prio] [from [src]] [to [dst]], ,...

 Enter a list of IPv6 addresses formatted as:
  ip[/prefix], ip[/prefix],...
Missing prefix is regarded as prefix of 128.

Example: 2607:f0d0:1002:51::4/64, 1050:0:0:0:5:600:300c:326b
 Enter a list of IPv6 addresses of DNS servers.  If the IPv6 configuration method is 'auto' these DNS servers are appended to those (if any) returned by automatic configuration.  DNS servers cannot be used with the 'shared' or 'link-local' IPv6 configuration methods, as there is no upstream network. In all other IPv6 configuration methods, these DNS servers are used as the only DNS servers for this connection.

Example: 2607:f0d0:1002:51::4, 2607:f0d0:1002:51::1
 Enter a list of IPv6 routes formatted as:
  ip[/prefix] [next-hop] [metric],...

Missing prefix is regarded as a prefix of 128.
Missing next-hop is regarded as "::".
Missing metric means default (NM/kernel will set a default value).

Examples: 2001:db8:beef:2::/64 2001:db8:beef::2, 2001:db8:beef:3::/64 2001:db8:beef::3 2
          abbe::/64 55
 Enter a list of IPv6 routing rules formatted as:
  priority [prio] [from [src]] [to [dst]], ,...

 Enter a list of S/390 options formatted as:
  option = <value>, option = <value>,...
Valid options are: %s
 Enter a list of bonding options formatted as:
  option = <value>, option = <value>,... 
Valid options are: %s
'mode' can be provided as a name or a number:
balance-rr    = 0
active-backup = 1
balance-xor   = 2
broadcast     = 3
802.3ad       = 4
balance-tlb   = 5
balance-alb   = 6

Example: mode=2,miimon=120
 Enter a list of link watchers formatted as dictionaries where the keys are teamd properties. Dictionary pairs are in the form: key=value and pairs are separated by ' '. Dictionaries are separated with ','.
The keys allowed/required in the dictionary change on the basis of the link watcher type, while the only property common to all the link watchers is  'name'*, which defines the link watcher to be specified.

Properties available for the 'ethtool' link watcher:
  'delay-up', 'delay-down'

Properties available for the 'nsna_ping' link watcher:
  'init-wait', 'interval', 'missed-max', 'target-host'*

Properties available for the 'arp_ping' include all the ones for 'nsna_ping' and:
  'source-host'*, 'validate-active', 'validate-inactive', 'send-always'.

Properties flagged with a '*' are mandatory.

Example:
   name=arp_ping source-host=172.16.1.1 target-host=172.16.1.254, name=ethtool delay-up=3
 Enter a list of subchannels (comma or space separated).

Example: 0.0.0e20 0.0.0e21 0.0.0e22
 Enter a list of user permissions. This is a list of user names formatted as:
  [user:]<user name 1>, [user:]<user name 2>,...
The items can be separated by commas or spaces.

Example: alice bob charlie
 Enter a value which indicates whether the connection is subject to a data
quota, usage costs or other limitations. Accepted options are:
'true','yes','on' to set the connection as metered
'false','no','off' to set the connection as not metered
'unknown' to let NetworkManager choose a value using some heuristics
 Enter bytes as a list of hexadecimal values.
Two formats are accepted:
(a) a string of hexadecimal digits, where each two digits represent one byte
(b) space-separated list of bytes written as hexadecimal digits (with optional 0x/0X prefix, and optional leading 0).

Examples: ab0455a6ea3a74C2
          ab 4 55 0xa6 ea 3a 74 C2
 Enter connection type:  Enter file path to CA certificate (optionally prefixed with file://).
  [file://]<file path>
Note that nmcli does not support specifying certificates as raw blob data.
Example: /home/cimrman/cacert.crt
 Enter file path to CA certificate for inner authentication (optionally prefixed
with file://).
  [file://]<file path>
Note that nmcli does not support specifying certificates as raw blob data.
Example: /home/cimrman/ca-zweite-phase.crt
 Enter file path to client certificate (optionally prefixed with file://).
  [file://]<file path>
Note that nmcli does not support specifying certificates as raw blob data.
Example: /home/cimrman/jara.crt
 Enter file path to client certificate for inner authentication (optionally prefixed
with file://).
  [file://]<file path>
Note that nmcli does not support specifying certificates as raw blob data.
Example: /home/cimrman/jara-zweite-phase.crt
 Enter path to a private key and the key password (if not set yet):
  [file://]<file path> [<password>]
Note that nmcli does not support specifying private key as raw blob data.
Example: /home/cimrman/jara-priv-key Dardanely
 Enter secondary connections that should be activated when this connection is
activated. Connections can be specified either by UUID or ID (name). nmcli
transparently translates names to UUIDs. Note that NetworkManager only supports
VPNs as secondary connections at the moment.
The items can be separated by commas or spaces.

Example: private-openvpn, fe6ba5d8-c2fc-4aae-b2e3-97efddd8d9a7
 Enter the type of WEP keys. The accepted values are: 0 or unknown, 1 or key, and 2 or passphrase.
 Error initializing certificate data: %s Error reading nmcli output: %s
 Error updating secrets for %s: %s
 Error writing nmcli output: %s
 Error: %s
 Error: %s - no such connection profile. Error: %s argument is missing. Error: %s properties, nor it is a setting name.
 Error: %s. Error: %s.
 Error: %s: %s. Error: '%s' argument is missing. Error: '%s' argument is required. Error: '%s' cannot repeat. Error: '%s' is ambiguous (%s.%s or %s.%s). Error: '%s' is not a valid argument for '%s' option. Error: '%s' is not a valid monitoring mode; use '%s' or '%s'.
 Error: '%s' is not a valid timeout. Error: '%s' is not an active connection.
 Error: '%s' is not valid argument for '%s' option. Error: '%s' setting not present in the connection
 Error: '--fields' value '%s' is not valid here (allowed field: %s) Error: 'autoconnect': %s. Error: 'bt-type': '%s' not valid; use [%s, %s, %s (%s), %s]. Error: 'connection show': %s Error: 'device lldp list': %s Error: 'device show': %s Error: 'device status': %s Error: 'device wifi': %s Error: 'file' argument is required. Error: 'general logging': %s Error: 'general permissions': %s Error: 'managed': %s. Error: 'monitor' command '%s' is not valid. Error: 'networking' command '%s' is not valid. Error: 'save': %s. Error: 'type' argument is required. Error: <new name> argument is missing. Error: <setting>.<property> argument is missing. Error: Access point with bssid '%s' not found. Error: Argument '%s' was expected, but '%s' provided. Error: BSSID to connect to (%s) differs from bssid argument (%s). Error: Cannot activate connection: %s.
 Error: Connection '%s' exists but properties don't match. Error: Connection activation failed.
 Error: Connection activation failed: %s Error: Connection activation failed: (%d) %s.
 Error: Connection deletion failed: %s
 Error: Could not create NMClient object: %s
 Error: Could not create NMClient object: %s. Error: Device '%s' (%s) deletion failed: %s
 Error: Device '%s' (%s) disconnecting failed: %s
 Error: Device '%s' is not a Wi-Fi device. Error: Device '%s' not found. Error: Device '%s' not found.
 Error: Device '%s' supports neither AP nor Ad-Hoc mode. Error: Device '%s' was not recognized as a Wi-Fi device, check NetworkManager Wi-Fi plugin. Error: Device activation failed: %s Error: Failed to activate '%s' (%s) connection: %s
 Error: Failed to activate connection: %s Error: Failed to add '%s' connection: %s Error: Failed to add/activate new connection: %s Error: Failed to modify connection '%s': %s Error: Failed to save '%s' (%s) connection: %s
 Error: Failed to scan hidden SSID: %s. Error: Failed to setup a Wi-Fi hotspot: %s Error: Invalid 'password': %s. Error: NetworkManager is not running. Error: No Wi-Fi device found. Error: No access point with BSSID '%s' found. Error: No arguments provided. Error: No connection specified. Error: No interface specified. Error: No network with SSID '%s' found. Error: No property specified. Error: Option '%s' is unknown, try 'nmcli -help'. Error: Option '--pretty' is mutually exclusive with '--terse'. Error: Option '--pretty' is specified the second time. Error: Option '--terse' is mutually exclusive with '--pretty'. Error: Option '--terse' is specified the second time. Error: Parameter '%s' is neither SSID nor BSSID. Error: Reading applied connection from device '%s' (%s) failed: %s Error: Reapplying connection to device '%s' (%s) failed: %s Error: SSID or BSSID are missing. Error: Timeout %d sec expired. Error: Timeout expired (%d seconds) Error: Timeout saving '%s' (%s) connection
 Error: Unexpected argument '%s' Error: Unknown connection '%s'. Error: argument '%s' not understood. Try passing --help instead. Error: bad connection type: %s Error: band argument value '%s' is invalid; use 'a' or 'bg'. Error: bssid argument value '%s' is not a valid BSSID. Error: cannot delete unknown connection(s): %s. Error: channel '%s' not valid for band '%s'. Error: channel requires band too. Error: connection is not saved. Type 'save' first.
 Error: connection is not valid: %s
 Error: connection verification failed: %s
 Error: extra argument '%s' Error: extra argument not allowed: '%s'. Error: failed to %s %s.%s: %s. Error: failed to create temporary file %s. Error: failed to export '%s': %s. Error: failed to find VPN plugin for %s. Error: failed to import '%s': %s. Error: failed to load VPN plugin: %s. Error: failed to load connection: %s. Error: failed to read temporary file '%s': %s. Error: failed to reload connections: %s. Error: failed to reload: %s Error: failed to remove value of '%s': %s
 Error: failed to set '%s' property: %s
 Error: failed to set Wi-Fi radio: %s Error: failed to set hostname: %s Error: failed to set logging: %s Error: failed to set networking: %s Error: invalid '%s' argument: '%s' (use on/off). Error: invalid <setting>.<property> '%s'. Error: invalid argument '%s'
 Error: invalid connection type; %s
 Error: invalid connection type; %s. Error: invalid extra argument '%s'. Error: invalid or not allowed setting '%s': %s. Error: invalid property '%s': %s. Error: invalid property: %s
 Error: invalid property: %s%s
 Error: invalid property: %s, neither a valid setting name.
 Error: invalid reload flag '%s'. Allowed flags are: %s Error: invalid rescan argument: '%s' not among [auto, no, yes] Error: invalid setting argument '%s'. Error: invalid setting argument '%s'; valid are [%s]
 Error: invalid setting name; %s
 Error: invalid slave type; %s. Error: master is required Error: missing argument for '%s' option. Error: missing argument. Try passing --help. Error: missing setting for '%s' property
 Error: missing setting. Error: nmcli terminated by signal %s (%d) Error: no active connection provided. Error: no argument given; valid are [%s]
 Error: no setting selected; valid are [%s]
 Error: not all active connections found. Error: not all connections deleted. Error: not all connections found. Error: not all devices deleted. Error: not all devices disconnected. Error: not all devices found. Error: only one of 'id', 'filename', uuid, or 'path' can be provided. Error: only these fields are allowed: %s Error: openconnect failed with signal %d
 Error: openconnect failed with status %d
 Error: openconnect failed: %s Error: openconnect failed: %s
 Error: polkit agent failed: %s
 Error: polkit agent initialization failed: %s Error: property %s
 Error: property '%s' is not known. Error: save-confirmation: %s
 Error: secret agent initialization failed Error: setting '%s' is mandatory and cannot be removed. Error: show-secrets: %s
 Error: ssid is too long. Error: status-line: %s
 Error: the connection is not VPN. Error: timeout creating NMClient object
 Error: unknown extra argument: '%s'. Error: unknown setting '%s'
 Error: unknown setting: '%s'
 Error: value for '%s' argument is required. Error: value for '%s' is missing. Error: wep-key-type argument value '%s' is invalid, use 'key' or 'phrase'. Ethernet Ethernet connection %d Ethernet device Ethtool settings Exit immediately if NetworkManager is not running or connecting Expected a line break following '%s'
 Expected a value for '%s'
 Expected whitespace following '%s'
 FALSE if the connection can be modified using the provided settings service's D-Bus interface with the right privileges, or TRUE if the connection is read-only and cannot be modified. FQDN flags requires a FQDN set Failed to configure SR-IOV parameters Failed to create WireGuard connection: %s Failed to create pager pipe: %s
 Failed to decode PKCS#8 private key. Failed to decode certificate. Failed to decrypt the private key. Failed to decrypt the private key: %d. Failed to decrypt the private key: %s (%s) Failed to decrypt the private key: decrypted data too large. Failed to decrypt the private key: unexpected padding length. Failed to determine AP security information Failed to duplicate pager pipe: %s
 Failed to encrypt the data: %s (%s) Failed to encrypt: %d. Failed to finalize decryption of the private key: %d. Failed to find expected PKCS#8 end tag '%s'. Failed to find expected PKCS#8 start tag. Failed to find expected TSS end tag '%s'. Failed to find expected TSS start tag. Failed to fork pager: %s
 Failed to initialize the crypto engine. Failed to initialize the crypto engine: %d. Failed to initialize the decryption cipher context: %s (%s) Failed to initialize the decryption cipher slot. Failed to initialize the decryption context. Failed to initialize the encryption cipher context: %s (%s) Failed to initialize the encryption cipher slot. Failed to initialize the encryption context. Failed to read configuration: %s
 Failed to recognize certificate Failed to register with the requested network Failed to select the specified APN Failed to set IV for decryption. Failed to set IV for encryption. Failed to set symmetric key for decryption. Failed to set symmetric key for encryption. File to import:  Flags for the DHCP hostname and FQDN. Currently, this property only includes flags to control the FQDN flags set in the DHCP FQDN option. Supported FQDN flags are NM_DHCP_HOSTNAME_FLAG_FQDN_SERV_UPDATE (0x1), NM_DHCP_HOSTNAME_FLAG_FQDN_ENCODED (0x2) and NM_DHCP_HOSTNAME_FLAG_FQDN_NO_UPDATE (0x4).  When no FQDN flag is set and NM_DHCP_HOSTNAME_FLAG_FQDN_CLEAR_FLAGS (0x8) is set, the DHCP FQDN option will contain no flag. Otherwise, if no FQDN flag is set and NM_DHCP_HOSTNAME_FLAG_FQDN_CLEAR_FLAGS (0x8) is not set, the standard FQDN flags are set in the request: NM_DHCP_HOSTNAME_FLAG_FQDN_SERV_UPDATE (0x1), NM_DHCP_HOSTNAME_FLAG_FQDN_ENCODED (0x2) for IPv4 and NM_DHCP_HOSTNAME_FLAG_FQDN_SERV_UPDATE (0x1) for IPv6. When this property is set to the default value NM_DHCP_HOSTNAME_FLAG_NONE (0x0), a global default is looked up in NetworkManager configuration. If that value is unset or also NM_DHCP_HOSTNAME_FLAG_NONE (0x0), then the standard FQDN flags described above are sent in the DHCP requests. Flags indicating how to handle the "ca-cert-password" property. Flags indicating how to handle the "client-cert-password" property. Flags indicating how to handle the "leap-password" property. Flags indicating how to handle the "mka-cak" property. Flags indicating how to handle the "password" property. Flags indicating how to handle the "password-raw" property. Flags indicating how to handle the "phase2-ca-cert-password" property. Flags indicating how to handle the "phase2-client-cert-password" property. Flags indicating how to handle the "phase2-private-key-password" property. Flags indicating how to handle the "pin" property. Flags indicating how to handle the "private-key" property. Flags indicating how to handle the "private-key-password" property. Flags indicating how to handle the "psk" property. Flags indicating how to handle the "wep-key0", "wep-key1", "wep-key2", and "wep-key3" properties. Flags indicating which mode of WPS is to be used if any. There's little point in changing the default setting as NetworkManager will automatically determine whether it's feasible to start WPS enrollment from the Access Point capabilities. WPS can be disabled by setting this property to a value of 1. Flags indicating which mode of WPS is to be used. There's little point in changing the default setting as NetworkManager will automatically determine the best method to use. For incoming packets, a list of mappings from 802.1p priorities to Linux SKB priorities.  The mapping is given in the format "from:to" where both "from" and "to" are unsigned integers, ie "7:3". For outgoing packets, a list of mappings from Linux SKB priorities to 802.1p priorities.  The mapping is given in the format "from:to" where both "from" and "to" are unsigned integers, ie "7:3". Forces use of the new PEAP label during key derivation.  Some RADIUS servers may require forcing the new PEAP label to interoperate with PEAPv1.  Set to "1" to force use of the new PEAP label.  See the wpa_supplicant documentation for more details. Forces which PEAP version is used when PEAP is set as the EAP method in the "eap" property.  When unset, the version reported by the server will be used.  Sometimes when using older RADIUS servers, it is necessary to force the client to use a particular PEAP version.  To do so, this property may be set to "0" or "1" to force that specific PEAP version. Forward delay GRE GROUP GSM Modem's SIM PIN required GSM Modem's SIM PUK required GSM Modem's SIM card not inserted GSM Modem's SIM wrong GSM connection GSM mobile broadband connection GVRP,  Gateway Gateway certificate hash General settings Generic settings Group ID [none] Group forward mask Group password HTTP proxy password Hairpin mode Hello time Hide Hint: "nmcli dev wifi show-password" shows the Wi-Fi name and password.
 Hint: use '%s' to get more details. Hostname Hostname set to '%s'
 Hostname settings Hotspot password: %s
 How many additional levels of encapsulation are permitted to be prepended to packets. This property applies only to IPv6 tunnels. IEEE 802.15.4 IEEE 802.15.4 (WPAN) parent device or connection UUID IEEE 802.15.4 Personal Area Network (PAN) identifier. IEEE 802.15.4 channel page. A positive integer or -1, meaning "do not set, use whatever the device is already set to". IEEE 802.15.4 channel. A positive integer or -1, meaning "do not set, use whatever the device is already set to". INFINIBAND IP Tunnel IP configuration could not be reserved (no available address, timeout, etc.) IP configuration method. NMSettingIP4Config and NMSettingIP6Config both support "disabled", "auto", "manual", and "link-local". See the subclass-specific documentation for other values. In general, for the "auto" method, properties such as "dns" and "routes" specify information that is added on to the information returned from automatic configuration.  The "ignore-auto-routes" and "ignore-auto-dns" properties modify this behavior. For methods that imply no upstream network, such as "shared" or "link-local", these properties must be empty. For IPv4 method "shared", the IP subnet can be configured by adding one manual IPv4 address or otherwise 10.42.x.0/24 is chosen. Note that the shared method must be configured on the interface which shares the internet to a subnet, not on the uplink which is shared. IP tunnel IP tunnel connection IP tunnel connection %d IP-tunnel settings IP6GRE IP6IP6 IPIP IPIP6 IPTunnel IPv4 CONFIGURATION IPv4 address (IP[/plen]) [none] IPv4 gateway [none] IPv4 protocol IPv6 CONFIGURATION IPv6 address (IP[/plen]) [none] IPv6 gateway [none] IPv6 protocol ISATAP IV contains non-hexadecimal digits. IV must be an even number of bytes in length. IV must contain at least 8 characters Identifies specific subchannels that this network device uses for communication with z/VM or s390 host.  Like the "mac-address" property for non-z/VM devices, this property can be used to ensure this connection only applies to the network device that uses these subchannels.  The list should contain exactly 3 strings, and each string may only be composed of hexadecimal characters and the period (.) character. Identity Identity string for EAP authentication methods.  Often the user's user or login name. If TRUE the IFF_VNET_HDR the tunnel packets will include a virtio network header. If TRUE the interface will prepend a 4 byte header describing the physical interface to the packets. If TRUE, "deflate" compression will not be requested. If TRUE, 128-bit MPPE (Microsoft Point-to-Point Encryption) will be required for the PPP session, and the "require-mppe" property must also be set to TRUE.  If 128-bit MPPE is not available the session will fail. If TRUE, BSD compression will not be requested. If TRUE, MPPE (Microsoft Point-to-Point Encryption) will be required for the PPP session.  If either 64-bit or 128-bit MPPE is not available the session will fail.  Note that MPPE is not used on mobile broadband connections. If TRUE, Van Jacobsen TCP header compression will not be requested. If TRUE, a hostname is sent to the DHCP server when acquiring a lease. Some DHCP servers use this hostname to update DNS databases, essentially providing a static hostname for the computer.  If the "dhcp-hostname" property is NULL and this property is TRUE, the current persistent hostname of the computer is sent. If TRUE, allow overall network configuration to proceed even if the configuration specified by this property times out.  Note that at least one IP configuration must succeed or overall network configuration will still fail.  For example, in IPv6-only networks, setting this property to TRUE on the NMSettingIP4Config allows the overall network configuration to succeed if IPv4 configuration fails but IPv6 configuration completes successfully. If TRUE, do not require the other side (usually the PPP server) to authenticate itself to the client.  If FALSE, require authentication from the remote side.  In almost all cases, this should be TRUE. If TRUE, indicates that the network is a non-broadcasting network that hides its SSID. This works both in infrastructure and AP mode. In infrastructure mode, various workarounds are used for a more reliable discovery of hidden networks, such as probe-scanning the SSID.  However, these workarounds expose inherent insecurities with hidden SSID networks, and thus hidden SSID networks should be used with caution. In AP mode, the created network does not broadcast its SSID. Note that marking the network as hidden may be a privacy issue for you (in infrastructure mode) or client stations (in AP mode), as the explicit probe-scans are distinctly recognizable on the air. If TRUE, specify that pppd should set the serial port to use hardware flow control with RTS and CTS signals.  This value should normally be set to FALSE. If TRUE, stateful MPPE is used.  See pppd documentation for more information on stateful MPPE. If TRUE, the CHAP authentication method will not be used. If TRUE, the EAP authentication method will not be used. If TRUE, the MSCHAP authentication method will not be used. If TRUE, the MSCHAPv2 authentication method will not be used. If TRUE, the PAP authentication method will not be used. If TRUE, this connection will never be the default connection for this IP type, meaning it will never be assigned the default route by NetworkManager. If configured, set to a Manufacturer Usage Description (MUD) URL that points to manufacturer-recommended network policies for IoT devices. It is transmitted as a DHCPv4 or DHCPv6 option. The value must be a valid URL starting with "https://". The special value "none" is allowed to indicate that no MUD URL is used. If the per-profile value is unspecified (the default), a global connection default gets consulted. If still unspecified, the ultimate default is "none". If enabled the bridge's own IP address is used as the source address for IGMP queries otherwise the default of 0.0.0.0 is used. If given, specifies the parent interface name on which this PPPoE connection should be created.  If this property is not specified, the connection is activated on the interface specified in "interface-name" of NMSettingConnection. If given, specifies the parent interface name or parent connection UUID from which this 6LowPAN interface should be created. If given, specifies the parent interface name or parent connection UUID from which this MAC-VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property. If given, specifies the parent interface name or parent connection UUID from which this MACSEC interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property. If given, specifies the parent interface name or parent connection UUID from which this VLAN interface should be created.  If this property is not specified, the connection must contain an "802-3-ethernet" setting with a "mac-address" property. If given, specifies the parent interface name or parent connection UUID the new device will be bound to so that tunneled packets will only be routed via that interface. If given, specifies the parent interface name or parent connection UUID. If given, specifies the source IP address to use in outgoing packets. If greater than zero, delay success of IP addressing until either the timeout is reached, or an IP gateway replies to a ping. If no queries are seen after this delay (in deciseconds) has passed, the bridge will start to send its own queries. If non-zero, directs the device to only use the specified bitrate for communication with the access point.  Units are in Kb/s, ie 5500 = 5.5 Mbit/s.  This property is highly driver dependent and not all devices support setting a static bitrate. If non-zero, directs the device to use the specified transmit power. Units are dBm.  This property is highly driver dependent and not all devices support setting a static transmit power. If non-zero, instruct pppd to presume the connection to the peer has failed if the specified number of LCP echo-requests go unanswered by the peer.  The "lcp-echo-interval" property must also be set to a non-zero value if this property is used. If non-zero, instruct pppd to request that the peer send packets no larger than the specified size.  If non-zero, the MRU should be between 128 and 16384. If non-zero, instruct pppd to send an LCP echo-request frame to the peer every n seconds (where n is the specified value).  Note that some PPP peers will respond to echo requests and some will not, and it is not possible to autodetect this. If non-zero, instruct pppd to send packets no larger than the specified size. If non-zero, instruct pppd to set the serial port to the specified baudrate.  This value should normally be left as 0 to automatically choose the speed. If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple Ethernet frames. If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments. If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple fragments. If zero a default MTU is used. Note that contrary to wg-quick's MTU setting, this does not take into account the current routes at the time of activation. If non-zero, only transmit packets of the specified size or smaller, breaking larger packets up into multiple frames. If set to NM_TERNARY_TRUE (1), NetworkManager attempts to get the hostname via DHCPv4/DHCPv6 or reverse DNS lookup on this device only when the device has the default route for the given address family (IPv4/IPv6). If set to NM_TERNARY_FALSE (0), the hostname can be set from this device even if it doesn't have the default route. When set to NM_TERNARY_DEFAULT (-1), the value from global configuration is used. If the property doesn't have a value in the global configuration, NetworkManager assumes the value to be NM_TERNARY_FALSE (0). If specified, The MAC address of the multicast group this bridge uses for STP. The address must be a link-local address in standard Ethernet MAC address format, ie an address of the form 01:80:C2:00:00:0X, with X in [0, 4..F]. If not specified the default value is 01:80:C2:00:00:00. If specified, instruct PPPoE to only initiate sessions with access concentrators that provide the specified service.  For most providers, this should be left blank.  It is only required if there are multiple access concentrators or a specific service is known to be required. If specified, request that the device use this MAC address instead. This is known as MAC cloning or spoofing. Beside explicitly specifying a MAC address, the special values "preserve", "permanent", "random" and "stable" are supported. "preserve" means not to touch the MAC address on activation. "permanent" means to use the permanent hardware address if the device has one (otherwise this is treated as "preserve"). "random" creates a random MAC address on each connect. "stable" creates a hashed MAC address based on connection.stable-id and a machine dependent key. If unspecified, the value can be overwritten via global defaults, see manual of NetworkManager.conf. If still unspecified, it defaults to "preserve" (older versions of NetworkManager may use a different default value). On D-Bus, this field is expressed as "assigned-mac-address" or the deprecated "cloned-mac-address". If specified, request that the device use this MAC address instead. This is known as MAC cloning or spoofing. Beside explicitly specifying a MAC address, the special values "preserve", "permanent", "random" and "stable" are supported. "preserve" means not to touch the MAC address on activation. "permanent" means to use the permanent hardware address of the device. "random" creates a random MAC address on each connect. "stable" creates a hashed MAC address based on connection.stable-id and a machine dependent key. If unspecified, the value can be overwritten via global defaults, see manual of NetworkManager.conf. If still unspecified, it defaults to "preserve" (older versions of NetworkManager may use a different default value). On D-Bus, this field is expressed as "assigned-mac-address" or the deprecated "cloned-mac-address". If specified, the MAC address of bridge. When creating a new bridge, this MAC address will be set. If this field is left unspecified, the "ethernet.cloned-mac-address" is referred instead to generate the initial MAC address. Note that setting "ethernet.cloned-mac-address" anyway overwrites the MAC address of the bridge later while activating the bridge. Hence, this property is deprecated. Deprecated: 1 If specified, the password used with magic-packet-based Wake-on-LAN, represented as an Ethernet MAC address.  If NULL, no password will be required. If specified, the protocol used for VLAN filtering. Supported values are: '802.1Q', '802.1ad'. If not specified the default value is '802.1Q'. If specified, this connection will never apply to the Ethernet device whose permanent MAC address matches an address in the list.  Each MAC address is in the standard hex-digits-and-colons notation (00:11:22:33:44:55). If specified, this connection will only apply to the Ethernet device whose permanent MAC address matches. This property does not change the MAC address of the device (i.e. MAC spoofing). If specified, this connection will only apply to the IEEE 802.15.4 (WPAN) MAC layer device whose permanent MAC address matches. If specified, this connection will only apply to the IPoIB device whose permanent MAC address matches. This property does not change the MAC address of the device (i.e. MAC spoofing). If specified, this connection will only apply to the Wi-Fi device whose permanent MAC address matches. This property does not change the MAC address of the device (i.e. MAC spoofing). If specified, this connection will only apply to the WiMAX device whose MAC address matches. This property does not change the MAC address of the device (known as MAC spoofing). Deprecated: 1 If the "dhcp-send-hostname" property is TRUE, then the specified FQDN will be sent to the DHCP server when acquiring a lease. This property and "dhcp-hostname" are mutually exclusive and cannot be set at the same time. If the "dhcp-send-hostname" property is TRUE, then the specified name will be sent to the DHCP server when acquiring a lease. This property and "dhcp-fqdn" are mutually exclusive and cannot be set at the same time. If the SIM is locked with a PIN it must be unlocked before any other operations are requested.  Specify the PIN here to allow operation of the device. If the VPN connection requires a user name for authentication, that name should be provided here.  If the connection is available to more than one user, and the VPN requires each user to supply a different name, then leave this property empty.  If this property is empty, NetworkManager will automatically supply the username of the user which requested the VPN connection. If the VPN service supports persistence, and this property is TRUE, the VPN will attempt to stay connected across link changes and outages, until explicitly disconnected. If the property is set to TRUE, the interface will support multiple file descriptors (queues) to parallelize packet sending or receiving. Otherwise, the interface will only support a single queue. If you are creating a VPN, and the VPN connection you wish to create does not appear in the list, you may not have the correct VPN plugin installed. Ignore Ignore automatically obtained DNS parameters Ignore automatically obtained routes Index 0 WEP key.  This is the WEP key used in most networks.  See the "wep-key-type" property for a description of how this key is interpreted. Index 1 WEP key.  This WEP index is not used by most networks.  See the "wep-key-type" property for a description of how this key is interpreted. Index 2 WEP key.  This WEP index is not used by most networks.  See the "wep-key-type" property for a description of how this key is interpreted. Index 3 WEP key.  This WEP index is not used by most networks.  See the "wep-key-type" property for a description of how this key is interpreted. Indicates whether Fast Initial Link Setup (802.11ai) must be enabled for the connection.  One of NM_SETTING_WIRELESS_SECURITY_FILS_DEFAULT (0) (use global default value), NM_SETTING_WIRELESS_SECURITY_FILS_DISABLE (1) (disable FILS), NM_SETTING_WIRELESS_SECURITY_FILS_OPTIONAL (2) (enable FILS if the supplicant and the access point support it) or NM_SETTING_WIRELESS_SECURITY_FILS_REQUIRED (3) (enable FILS and fail if not supported).  When set to NM_SETTING_WIRELESS_SECURITY_FILS_DEFAULT (0) and no global default is set, FILS will be optionally enabled. Indicates whether Protected Management Frames (802.11w) must be enabled for the connection.  One of NM_SETTING_WIRELESS_SECURITY_PMF_DEFAULT (0) (use global default value), NM_SETTING_WIRELESS_SECURITY_PMF_DISABLE (1) (disable PMF), NM_SETTING_WIRELESS_SECURITY_PMF_OPTIONAL (2) (enable PMF if the supplicant and the access point support it) or NM_SETTING_WIRELESS_SECURITY_PMF_REQUIRED (3) (enable PMF and fail if not supported).  When set to NM_SETTING_WIRELESS_SECURITY_PMF_DEFAULT (0) and no global default is set, PMF will be optionally enabled. InfiniBand InfiniBand P_Key connection did not specify parent interface name InfiniBand connection InfiniBand connection %d InfiniBand device does not support connected mode Info: %s
 Infra Ingress priority maps [none] Input key Interface name of the master device or UUID of the master connection. Interface(s):  Interface:  Internal config file location Interval (in deciseconds) between queries sent by the bridge after the end of the startup phase. Invalid IPv4 address '%s' Invalid IPv4 address prefix '%u' Invalid IPv6 address '%s' Invalid IPv6 address prefix '%u' Invalid IV length (must be at least %u). Invalid MAC in the blacklist: %s. Invalid configuration option '%s'; allowed [%s]
 Invalid device Bluetooth address. Invalid device MAC address %s. Invalid device MAC address. Invalid option.  Please use --help to see a list of valid options. Invalid peer starting at %s:%zu: %s Invalid routing metric '%s' Invalid secrets Invalid verify option: %s
 JSON configuration Key LACP mode. One of "active", "off", or "passive". LEAP LEAP authentication is incompatible with 802.1x setting LEAP authentication is incompatible with Ad-Hoc mode LEAP authentication requires IEEE 802.1x key management LEAP authentication requires a LEAP username LEAP username requires 'leap' authentication LOOSE_BINDING,  Legacy setting that used to help establishing PPP data sessions for GSM-based modems. Deprecated: 1 Like ip4-auto-default-route, but for the IPv6 default route. Link down delay Link monitoring Link up delay Link watchers configuration for the connection: each link watcher is defined by a dictionary, whose keys depend upon the selected link watcher. Available link watchers are 'ethtool', 'nsna_ping' and 'arp_ping' and it is specified in the dictionary with the key 'name'. Available keys are:   ethtool: 'delay-up', 'delay-down', 'init-wait'; nsna_ping: 'init-wait', 'interval', 'missed-max', 'target-host'; arp_ping: all the ones in nsna_ping and 'source-host', 'validate-active', 'validate-inactive', 'send-always'. See teamd.conf man for more details. Link-Local List of connection UUIDs that should be activated when the base connection itself is activated. Currently, only VPN connections are supported. List of plugins separated by ',' List of strings specifying the allowed WPA protocol versions to use. Each element may be one "wpa" (allow WPA) or "rsn" (allow WPA2/RSN).  If not specified, both WPA and RSN connections are allowed. List of strings to be matched against the altSubjectName of the certificate presented by the authentication server during the inner "phase 2" authentication. If the list is empty, no verification of the server certificate's altSubjectName is performed. List of strings to be matched against the altSubjectName of the certificate presented by the authentication server. If the list is empty, no verification of the server certificate's altSubjectName is performed. Local IP Local address [none] Local endpoint [none] Log domains separated by ',': any combination of [%s] Log level: one of [%s] MAC [none] MACVLAN MACVLAN connection MACVLAN parent device or connection UUID MACsec MACsec EAP authentication MACsec PSK authentication MACsec connection MACsec parent device or connection UUID MII (recommended) MKA CAK MKA_CKN MSCHAP MSCHAPv2 MTU MUD URL is not a valid URL MVRP,  Make all warnings fatal Malformed PEM file: DEK-Info was not the second tag. Malformed PEM file: Proc-Type was not first tag. Malformed PEM file: invalid format of IV in DEK-Info tag. Malformed PEM file: no IV found in DEK-Info tag. Malformed PEM file: unknown Proc-Type tag '%s'. Malformed PEM file: unknown private key cipher '%s'. Manual Master connection failed Match Max age Mesh Method for proxy configuration, Default is NM_SETTING_PROXY_METHOD_NONE (0) Method returned type '%s', but expected '%s' Metric Missing %s in arp_ping link watcher Missing IPv4 address Missing IPv6 address Missing ovs interface setting Missing ovs interface type Missing target-host in nsna_ping link watcher Mobile Broadband Mobile broadband connection %d Mobile broadband network password Mode Modem failed or no longer available Modem initialization failed Modem now ready and available ModemManager is unavailable Modify network connections for all users Modify persistent global DNS configuration Modify persistent system hostname Modify personal network connections Monitoring connection activation (press any key to continue)
 Monitoring frequency Must specify a P_Key if specifying parent N/A NAME Necessary firmware for the device may be missing Network Service Provider (NSP) name of the WiMAX network this connection should use. Deprecated: 1 Network registration denied Network registration timed out NetworkManager TUI NetworkManager active profiles NetworkManager connection profiles NetworkManager has started NetworkManager has stopped NetworkManager is not running NetworkManager is not running. NetworkManager logging NetworkManager monitors all network connections and automatically
chooses the best connection to use.  It also allows the user to
specify wireless access points which wireless cards in the computer
should associate with. NetworkManager options NetworkManager permissions NetworkManager status NetworkManager went to sleep Networking Networkmanager is not running (waiting for it)
 Networkmanager is now in the '%s' state
 Never use this network for default route New Connection New connection activation was enqueued New connection name:  Next Hop No carrier could be established No connection specified No custom routes are defined. No dial tone No interface specified No reason given No service name specified No such connection '%s' No valid secrets None Not a valid PAC Script Not searching for networks Number of stop bits for communication on the serial port.  Either 1 or 2. The 1 in "8n1" for example. OK OLPC Mesh OLPC Mesh connection OVS External IDs OVS external IDs can only be added to a profile of type OVS bridge/port/interface or to OVS system interface One custom route %d custom routes One of NM_SETTING_MAC_RANDOMIZATION_DEFAULT (0) (never randomize unless the user has set a global default to randomize and the supplicant supports randomization),  NM_SETTING_MAC_RANDOMIZATION_NEVER (1) (never randomize the MAC address), or NM_SETTING_MAC_RANDOMIZATION_ALWAYS (2) (always randomize the MAC address). This property is deprecated for 'cloned-mac-address'. Deprecated: 1 One of NM_SETTING_WIRELESS_POWERSAVE_DISABLE (2) (disable Wi-Fi power saving), NM_SETTING_WIRELESS_POWERSAVE_ENABLE (3) (enable Wi-Fi power saving), NM_SETTING_WIRELESS_POWERSAVE_IGNORE (1) (don't touch currently configure setting) or NM_SETTING_WIRELESS_POWERSAVE_DEFAULT (0) (use the globally configured value). All other values are reserved. One or more flags which control the behavior and features of the VLAN interface.  Flags include NM_VLAN_FLAG_REORDER_HEADERS (0x1) (reordering of output packet headers), NM_VLAN_FLAG_GVRP (0x2) (use of the GVRP protocol), and NM_VLAN_FLAG_LOOSE_BINDING (0x4) (loose binding of the interface to its master device's operating state). NM_VLAN_FLAG_MVRP (0x8) (use of the MVRP protocol). The default value of this property is NM_VLAN_FLAG_REORDER_HEADERS, but it used to be 0. To preserve backward compatibility, the default-value in the D-Bus API continues to be 0 and a missing property on D-Bus is still considered as 0. Open System Open vSwitch Bridge Open vSwitch DPDK device arguments. Open vSwitch DPDK interface settings Open vSwitch Interface Open vSwitch Port Open vSwitch bridge settings Open vSwitch database connection failed Open vSwitch interface settings Open vSwitch patch interface settings Open vSwitch port settings Opening %s failed: %s
 Output file name:  Output key PAC URL PAC URL for obtaining PAC file. PAC script PAN Identifier (<0x0000-0xffff>) PAN connection PAN connections cannot specify GSM, CDMA, or serial settings PAN requested, but Bluetooth device does not support NAP PAP PCI PEM certificate had no end tag '%s'. PEM certificate had no start tag '%s'. PEM key file had no end tag '%s'. PEM key file had no start tag PIN PIN check failed PIN code is needed for the mobile broadband device PIN code required PIN used for EAP authentication methods. PPP PPP CONFIGURATION PPP failed PPP service disconnected PPP service failed to start PPP settings PPPoE PPPoE connection PPPoE parent device PPPoE username P_KEY [none] Page (<default|0-31>) Parent Parent device [none] Parent interface [none] Parity setting of the serial port. Password Password [none] Password must be UTF-8 Password provided, but key was not encrypted. Password used for EAP authentication methods, given as a byte array to allow passwords in other encodings than UTF-8 to be used. If both the "password" property and the "password-raw" property are specified, "password" is preferred. Password used to authenticate with the ADSL service. Password used to authenticate with the PPPoE service. Password:  Passwords or encryption keys are required to access the wireless network '%s'. Path cost Peer Perform a checkpoint or rollback of interfaces configuration Please select an option Plugin file does not exist (%s) Plugin is not a valid file (%s) Pre-Shared-Key for WPA networks. For WPA-PSK, it's either an ASCII passphrase of 8 to 63 characters that is (as specified in the 802.11i standard) hashed to derive the actual key, or the key in form of 64 hexadecimal character. The WPA3-Personal networks use a passphrase of any length for SAE authentication. Prefix Preshared-key for %s Primary Print NetworkManager configuration and exit Print NetworkManager version and exit Priority Private key password Profile name Property name?  Proxy Put NetworkManager to sleep or wake it up (should only be used by system power management) Quit Quit after initial configuration REORDER_HEADERS,  Radio switches Reload NetworkManager configuration Remote Remote IP Remove Require 128-bit encryption Require IPv4 addressing for this connection Require IPv6 addressing for this connection Round-robin Routing SIM PIN was incorrect SIM operator ID must be a 5 or 6 number MCCMNC code SIT SR-IOV settings SSID SSID length is out of range <1-32> bytes SSID of the Wi-Fi network. Must be specified. SSID of the mesh network to join. SSID or BSSID:  Saving the connection with 'autoconnect=yes'. That might result in an immediate activation of the connection.
Do you still want to save? %s Search domains Secrets are required for the DSL connection '%s' Secrets are required to access the MACsec network '%s' Secrets are required to access the wired network '%s' Secrets are required to connect WireGuard VPN '%s' Secrets were required, but not provided Security Select the type of connection you wish to create. Select the type of slave connection you wish to add. Select... Send PPP echo packets Serial settings Service Service [none] Set Hostname Set delay (in deciseconds) after which the bridge will leave a group, if no membership reports for this group are received. Set hostname to '%s' Set interval (in deciseconds) between queries to find remaining members of a group, after a "leave" message is received. Set maximum size of multicast hash table (value must be a power of 2). Set system hostname Set the Max Response Time/Max Response Delay (in deciseconds) for IGMP/MLD queries sent by the bridge. Set the number of IGMP queries to send during startup phase. Set the number of queries the bridge will send before stopping forwarding a multicast group after a "leave" message has been received. Sets bridge's multicast router. Multicast-snooping must be enabled for this option to work. Supported values are: 'auto', 'disabled', 'enabled' to which kernel assigns the numbers 1, 0, and 2, respectively. If not specified the default value is 'auto' (1). Sets the Spanning Tree Protocol (STP) priority for this bridge.  Lower values are "better"; the lowest priority bridge will be elected the root bridge. Sets the time (in deciseconds) between queries sent out at startup to determine membership information. Setting '%s' is not present in the connection.
 Setting name of the device type of this slave's master connection (eg, "bond"), or NULL if this connection is not a slave. Setting name?  Shared Shared Key Shared connection service failed Shared connection service failed to start Short IEEE 802.15.4 address to be used within a restricted environment. Short address (<0x0000-0xffff>) Show Show NetworkManager options Show password Slave connections need a valid '%s' property Slaves Specific port type to use if the device supports multiple attachment methods.  One of "tp" (Twisted Pair), "aui" (Attachment Unit Interface), "bnc" (Thin Ethernet) or "mii" (Media Independent Interface). If the device supports only one port type, this setting is ignored. Specifies authentication flags to use in "phase 1" outer authentication using NMSetting8021xAuthFlags options. The individual TLS versions can be explicitly disabled. If a certain TLS disable flag is not set, it is up to the supplicant to allow or forbid it. The TLS options map to tls_disable_tlsv1_x settings. See the wpa_supplicant documentation for more details. Specifies how the CAK (Connectivity Association Key) for MKA (MACsec Key Agreement) is obtained. Specifies the NMSettingDcbFlags for DCB Priority Flow Control (PFC). Flags may be any combination of NM_SETTING_DCB_FLAG_ENABLE (0x1), NM_SETTING_DCB_FLAG_ADVERTISE (0x2), and NM_SETTING_DCB_FLAG_WILLING (0x4). Specifies the NMSettingDcbFlags for DCB Priority Groups.  Flags may be any combination of NM_SETTING_DCB_FLAG_ENABLE (0x1), NM_SETTING_DCB_FLAG_ADVERTISE (0x2), and NM_SETTING_DCB_FLAG_WILLING (0x4). Specifies the NMSettingDcbFlags for the DCB FCoE application.  Flags may be any combination of NM_SETTING_DCB_FLAG_ENABLE (0x1), NM_SETTING_DCB_FLAG_ADVERTISE (0x2), and NM_SETTING_DCB_FLAG_WILLING (0x4). Specifies the NMSettingDcbFlags for the DCB FIP application.  Flags may be any combination of NM_SETTING_DCB_FLAG_ENABLE (0x1), NM_SETTING_DCB_FLAG_ADVERTISE (0x2), and NM_SETTING_DCB_FLAG_WILLING (0x4). Specifies the NMSettingDcbFlags for the DCB iSCSI application.  Flags may be any combination of NM_SETTING_DCB_FLAG_ENABLE (0x1), NM_SETTING_DCB_FLAG_ADVERTISE (0x2), and NM_SETTING_DCB_FLAG_WILLING (0x4). Specifies the TOS value to use in outgoing packets. Specifies the UDP destination port to communicate to the remote VXLAN tunnel endpoint. Specifies the VXLAN Network Identifier (or VXLAN Segment Identifier) to use. Specifies the allowed "phase 2" inner EAP-based authentication method when TTLS is specified in the "eap" property.  Recognized EAP-based "phase 2" methods are "md5", "mschapv2", "otp", "gtc", and "tls". Each "phase 2" inner method requires specific parameters for successful authentication; see the wpa_supplicant documentation for more details. Specifies the allowed "phase 2" inner authentication method when an EAP method that uses an inner TLS tunnel is specified in the "eap" property.  For TTLS this property selects one of the supported non-EAP inner methods: "pap", "chap", "mschap", "mschapv2" while "phase2-autheap" selects an EAP inner method.  For PEAP this selects an inner EAP method, one of: "gtc", "otp", "md5" and "tls". Each "phase 2" inner method requires specific parameters for successful authentication; see the wpa_supplicant documentation for more details. Both "phase2-auth" and "phase2-autheap" cannot be specified. Specifies the lifetime in seconds of FDB entries learnt by the kernel. Specifies the maximum UDP source port to communicate to the remote VXLAN tunnel endpoint. Specifies the maximum number of FDB entries. A value of zero means that the kernel will store unlimited entries. Specifies the minimum UDP source port to communicate to the remote VXLAN tunnel endpoint. Specifies the name of the interface for the other side of the patch. The patch on the other side must also set this interface as peer. Specifies the time-to-live value to use in outgoing packets. Specifies the unicast destination IP address to use in outgoing packets when the destination link layer address is not known in the VXLAN device forwarding database, or the multicast IP address to join. Specifies the validation mode for incoming frames. Specifies whether ARP proxy is turned on. Specifies whether netlink IP ADDR miss notifications are generated. Specifies whether netlink LL ADDR miss notifications are generated. Specifies whether route short circuit is turned on. Specifies whether the SCI (Secure Channel Identifier) is included in every packet. Specifies whether the profile can be active multiple times at a particular moment. The value is of type NMConnectionMultiConnect. Specifies whether unknown source link layer addresses and IP addresses are entered into the VXLAN device forwarding database. Specify the location of a PID file Speed to use for communication over the serial port.  Note that this value usually has no effect for mobile broadband modems as they generally ignore speed settings and use the highest available speed. State file for no-auto-default devices State file location Status of devices Substring to be matched against the subject of the certificate presented by the authentication server during the inner "phase 2" authentication. When unset, no verification of the authentication server certificate's subject is performed.  This property provides little security, if any, and its use is deprecated in favor of NMSetting8021x:phase2-domain-suffix-match. Substring to be matched against the subject of the certificate presented by the authentication server. When unset, no verification of the authentication server certificate's subject is performed.  This property provides little security, if any, and its use is deprecated in favor of NMSetting8021x:domain-suffix-match. Success System config directory location System policy prevents Wi-Fi scans System policy prevents control of network connections System policy prevents enabling or disabling Wi-Fi devices System policy prevents enabling or disabling WiMAX mobile broadband devices System policy prevents enabling or disabling connectivity checking System policy prevents enabling or disabling device statistics System policy prevents enabling or disabling mobile broadband devices System policy prevents enabling or disabling system networking System policy prevents modification of network settings for all users System policy prevents modification of personal network settings System policy prevents modification of the persistent global DNS configuration System policy prevents modification of the persistent system hostname System policy prevents putting NetworkManager to sleep or waking it up System policy prevents reloading NetworkManager System policy prevents sharing connections via a protected Wi-Fi network System policy prevents sharing connections via an open Wi-Fi network System policy prevents the creation of a checkpoint or its rollback TEAM TEAM PORT TUN connection Team Team JSON configuration [none] Team connection Team connection %d Team device Team port The 256 bit private-key in base64 encoding. The Bluetooth address of the device. The Bluetooth addresses of the device and the connection didn't match. The Bluetooth connection failed or timed out The Ethernet MAC address aging time, in seconds. The GPRS Access Point Name specifying the APN used when establishing a data session with the GSM-based network.  The APN often determines how the user will be billed for their network usage and whether the user has access to the Internet or just a provider-specific walled-garden, so it is important to use the correct APN for the user's mobile broadband plan. The APN may only be composed of the characters a-z, 0-9, ., and - per GSM 03.60 Section 14.9. The IP configuration is no longer valid The IP-over-InfiniBand transport mode. Either "datagram" or "connected". The InfiniBand P_Key to use for this device. A value of -1 means to use the default P_Key (aka "the P_Key at index 0"). Otherwise, it is a 16-bit unsigned integer, whose high bit is set if it is a "full membership" P_Key. The JSON configuration for the team network interface.  The property should contain raw JSON configuration data suitable for teamd, because the value is passed directly to teamd. If not specified, the default configuration is used.  See man teamd.conf for the format details. The JSON configuration for the team port. The property should contain raw JSON configuration data suitable for teamd, because the value is passed directly to teamd. If not specified, the default configuration is used. See man teamd.conf for the format details. The MACs of the device and the connection didn't match. The MACs of the device and the connection do not match. The NMSettingWiredWakeOnLan options to enable. Not all devices support all options. May be any combination of NM_SETTING_WIRED_WAKE_ON_LAN_PHY (0x2), NM_SETTING_WIRED_WAKE_ON_LAN_UNICAST (0x4), NM_SETTING_WIRED_WAKE_ON_LAN_MULTICAST (0x8), NM_SETTING_WIRED_WAKE_ON_LAN_BROADCAST (0x10), NM_SETTING_WIRED_WAKE_ON_LAN_ARP (0x20), NM_SETTING_WIRED_WAKE_ON_LAN_MAGIC (0x40) or the special values NM_SETTING_WIRED_WAKE_ON_LAN_DEFAULT (0x1) (to use global settings) and NM_SETTING_WIRED_WAKE_ON_LAN_IGNORE (0x8000) (to disable management of Wake-on-LAN in NetworkManager). The NMSettingWirelessWakeOnWLan options to enable. Not all devices support all options. May be any combination of NM_SETTING_WIRELESS_WAKE_ON_WLAN_ANY (0x2), NM_SETTING_WIRELESS_WAKE_ON_WLAN_DISCONNECT (0x4), NM_SETTING_WIRELESS_WAKE_ON_WLAN_MAGIC (0x8), NM_SETTING_WIRELESS_WAKE_ON_WLAN_GTK_REKEY_FAILURE (0x10), NM_SETTING_WIRELESS_WAKE_ON_WLAN_EAP_IDENTITY_REQUEST (0x20), NM_SETTING_WIRELESS_WAKE_ON_WLAN_4WAY_HANDSHAKE (0x40), NM_SETTING_WIRELESS_WAKE_ON_WLAN_RFKILL_RELEASE (0x80), NM_SETTING_WIRELESS_WAKE_ON_WLAN_TCP (0x100) or the special values NM_SETTING_WIRELESS_WAKE_ON_WLAN_DEFAULT (0x1) (to use global settings) and NM_SETTING_WIRELESS_WAKE_ON_WLAN_IGNORE (0x8000) (to disable management of Wake-on-LAN in NetworkManager). The Network ID (GSM LAI format, ie MCC-MNC) to force specific network registration.  If the Network ID is specified, NetworkManager will attempt to force the device to register only on the specified network. This can be used to ensure that the device does not roam when direct roaming control of the device is not otherwise possible. The P2P device that should be connected to. Currently, this is the only way to create or join a group. The SIM card unique identifier (as given by the WWAN management service) which this connection applies to.  If given, the connection will apply to any device also allowed by "device-id" which contains a SIM card matching the given identifier. The Spanning Tree Protocol (STP) forwarding delay, in seconds. The Spanning Tree Protocol (STP) hello time, in seconds. The Spanning Tree Protocol (STP) maximum message age, in seconds. The Spanning Tree Protocol (STP) port cost for destinations via this port. The Spanning Tree Protocol (STP) priority of this bridge port. The TTL to assign to tunneled packets. 0 is a special value meaning that packets inherit the TTL value. The VLAN identifier that the interface created by this connection should be assigned. The valid range is from 0 to 4094, without the reserved id 4095. The VLAN identifiers of the device and the connection didn't match. The VLAN mode. One of "access", "native-tagged", "native-untagged", "trunk" or unset. The VLAN tag in the range 0-4095. The VPN service did not start in time The VPN service failed to start The VPN service returned invalid configuration The VPN service stopped unexpectedly The VRF table of the device and the connection didn't match. The VXLAN identifiers of the device and the connection didn't match. The Wi-Fi Display (WFD) Information Elements (IEs) to set. Wi-Fi Display requires a protocol specific information element to be set in certain Wi-Fi frames. These can be specified here for the purpose of establishing a connection. This setting is only useful when implementing a Wi-Fi Display client. The Wi-Fi P2P peer could not be found The Wi-Fi network could not be found The allowed EAP method to be used when authenticating to the network with 802.1x.  Valid methods are: "leap", "md5", "tls", "peap", "ttls", "pwd", and "fast".  Each method requires different configuration using the properties of this setting; refer to wpa_supplicant documentation for the allowed combinations. The base network connection was interrupted The bridge failure mode. One of "secure", "standalone" or empty. The connection and device differ in S390 subchannels. The connection attempt timed out The connection did not specify an interface name. The connection is not saved. Do you really want to quit? %s The connection is of Bluetooth NAP type. The connection profile has been removed from another client. You may type 'save' in the main menu to restore it.
 The connection profile has been removed from another client. You may type 'save' to restore it.
 The connection was disconnected The connection was not a Bluetooth connection. The connection was not a MAC-VLAN connection. The connection was not a VLAN connection. The connection was not a VRF connection. The connection was not a VXLAN connection. The connection was not a Wi-Fi P2P connection. The connection was not a Wi-Fi connection. The connection was not a bond connection. The connection was not a bridge connection. The connection was not a dummy connection. The connection was not a generic connection. The connection was not a modem connection. The connection was not a ovs_bridge connection. The connection was not a ovs_interface connection. The connection was not a ovs_port connection. The connection was not a team connection. The connection was not a tun connection. The connection was not a valid modem connection. The connection was not a wpan connection. The connection was not an ADSL connection. The connection was not an Ethernet or PPPoE connection. The connection was not an IP tunnel connection. The connection was not an InfiniBand connection. The connection was not an OLPC Mesh connection. The connection was not valid: %s The connection was removed The data path type. One of "system", "netdev" or empty. The default PVID for the ports of the bridge, that is the VLAN id assigned to incoming untagged frames. The default metric for routes that don't explicitly specify a metric. The default value -1 means that the metric is chosen automatically based on the device type. The metric applies to dynamic routes, manual (static) routes that don't have an explicit metric setting, address prefix routes, and the default route. Note that for IPv6, the kernel accepts zero (0) but coerces it to 1024 (user default). Hence, setting this property to zero effectively mean setting it to 1024. For IPv4, zero is a regular value for the metric. The device could not be readied for configuration The device disappeared The device is lacking Bluetooth capabilities required by the connection. The device is lacking WPA capabilities required by the connection. The device is lacking WPA2/RSN capabilities required by the connection. The device is lacking capabilities required by the connection. The device parent's management changed The device unique identifier (as given by the WWAN management service) which this connection applies to.  If given, the connection will only apply to the specified device. The device was removed The device's active connection disappeared The device's existing connection was assumed The device's parent changed The dialing attempt failed The dialing request timed out The error cannot be fixed automatically.
 The expected start of the response The flow label to assign to tunnel packets. This property applies only to IPv6 tunnels. The group ID which will own the device. If set to NULL everyone will be able to use the device. The hardware address of the device and the connection didn't match. The highest User Priority (0 - 7) which FCoE frames should use, or -1 for default priority.  Only used when the "app-fcoe-flags" property includes the NM_SETTING_DCB_FLAG_ENABLE (0x1) flag. The highest User Priority (0 - 7) which FIP frames should use, or -1 for default priority.  Only used when the "app-fip-flags" property includes the NM_SETTING_DCB_FLAG_ENABLE (0x1) flag. The highest User Priority (0 - 7) which iSCSI frames should use, or -1 for default priority. Only used when the "app-iscsi-flags" property includes the NM_SETTING_DCB_FLAG_ENABLE (0x1) flag. The interface name of the parent device of this device. Normally NULL, but if the "p_key" property is set, then you must specify the base device by setting either this property or "mac-address". The interface type. Either "internal", "system", "patch", "dpdk", or empty. The interval between connectivity checks (in seconds) The key used for tunnel input packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used. The key used for tunnel output packets; the property is valid only for certain tunnel modes (GRE, IP6GRE). If empty, no key is used. The line is busy The listen-port. If listen-port is not specified, the port will be chosen randomly when the interface comes up. The local endpoint of the tunnel; the value can be empty, otherwise it must contain an IPv4 or IPv6 address. The login password for legacy LEAP connections (ie, key-mgmt = "ieee8021x" and auth-alg = "leap"). The login username for legacy LEAP connections (ie, key-mgmt = "ieee8021x" and auth-alg = "leap"). The macvlan mode, which specifies the communication mechanism between multiple macvlans on the same lower device. The mode of the device and the connection didn't match The modem could not be found The name of the WireGuard config must be a valid interface name followed by ".conf" The name of the network interface this connection is bound to. If not set, then the connection can be attached to any interface of the appropriate type (subject to restrictions imposed by other settings). For software devices this specifies the name of the created device. For connection types where interface names cannot easily be made persistent (e.g. mobile broadband or USB Ethernet), this property should not be used. Setting this property restricts the interfaces a connection can be used with, and if interface names change or are reordered the connection may be applied to the wrong interface. The number of retries for the authentication. Zero means to try indefinitely; -1 means to use a global default. If the global default is not set, the authentication retries for 3 times before failing the connection. Currently, this only applies to 802-1x authentication. The number of times a connection should be tried when autoactivating before giving up. Zero means forever, -1 means the global default (4 times if not overridden). Setting this to 1 means to try activation only once before blocking autoconnect. Note that after a timeout, NetworkManager will try to autoconnect again. The number to dial to establish the connection to the CDMA-based mobile broadband network, if any.  If not specified, the default number (#777) is used when required. The operating mode of the virtual device. Allowed values are NM_SETTING_TUN_MODE_TUN (1) to create a layer 3 device and NM_SETTING_TUN_MODE_TAP (2) to create an Ethernet-like layer 2 one. The password used to access the "phase2" CA certificate stored in "phase2-ca-cert" property. Only makes sense if the certificate is stored on a PKCS#11 token that requires a login. The password used to access the "phase2" client certificate stored in "phase2-client-cert" property. Only makes sense if the certificate is stored on a PKCS#11 token that requires a login. The password used to access the CA certificate stored in "ca-cert" property. Only makes sense if the certificate is stored on a PKCS#11 token that requires a login. The password used to access the client certificate stored in "client-cert" property. Only makes sense if the certificate is stored on a PKCS#11 token that requires a login. The password used to authenticate with the network, if required.  Many providers do not require a password, or accept any password.  But if a password is required, it is specified here. The password used to decrypt the "phase 2" private key specified in the "phase2-private-key" property when the private key either uses the path scheme, or is a PKCS#12 format key. The password used to decrypt the private key specified in the "private-key" property when the private key either uses the path scheme, or if the private key is a PKCS#12 format key. The port component of the SCI (Secure Channel Identifier), between 1 and 65534. The relative priority of this connection to determine the system hostname. A lower numerical value is better (higher priority).  A connection with higher priority is considered before connections with lower priority. If the value is zero, it can be overridden by a global value from NetworkManager configuration. If the property doesn't have a value in the global configuration, the value is assumed to be 100. Negative values have the special effect of excluding other connections with a greater numerical priority value; so in presence of at least one negative priority, only connections with the lowest priority value will be used to determine the hostname. The remote endpoint of the tunnel; the value must contain an IPv4 or IPv6 address. The routing table for this VRF. The selected IP method is not supported The supplicant is now available The time port must be active before it starts forwarding traffic. The time port must be inactive in order to be considered down. The time, in seconds since the Unix Epoch, that the connection was last _successfully_ fully activated. NetworkManager updates the connection timestamp periodically when the connection is active to ensure that an active connection has the latest timestamp. The property is only meant for reading (changes to this property will not be preserved). The total number of virtual functions to create. Note that when the sriov setting is present NetworkManager enforces the number of virtual functions on the interface (also when it is zero) during activation and resets it upon deactivation. To prevent any changes to SR-IOV parameters don't add a sriov setting to the connection. The trust level of a the connection.  Free form case-insensitive string (for example "Home", "Work", "Public").  NULL or unspecified zone means the connection will be placed in the default zone as defined by the firewall. When updating this property on a currently activated connection, the change takes effect immediately. The tunneling mode, for example NM_IP_TUNNEL_MODE_IPIP (1) or NM_IP_TUNNEL_MODE_GRE (2). The type of service (IPv4) or traffic class (IPv6) field to be set on tunneled packets. The use of fwmark is optional and is by default off. Setting it to 0 disables it. Otherwise, it is a 32-bit fwmark for outgoing packets. Note that "ip4-auto-default-route" or "ip6-auto-default-route" enabled, implies to automatically choose a fwmark. The user ID which will own the device. If set to NULL everyone will be able to use the device. The username used to authenticate with the network, if required.  Many providers do not require a username, or accept any username.  But if a username is required, it is specified here. The valid syntax is: '<vid>[-<vid>] [pvid] [untagged]' The valid syntax is: '[root | parent <handle>] [handle <handle>] <kind>' The valid syntax is: 'ip[/prefix] [next-hop] [metric] [attribute=val]... [,ip[/prefix] ...]' The valid syntax is: vf [attribute=value]... [,vf [attribute=value]...] There's no primary connection
 This property specifies the peer interface name of the veth. This property is mandatory. Time to delay between each byte sent to the modem, in microseconds. Timeout for the VPN service to establish the connection. Some services may take quite a long time to connect. Value of 0 means a default timeout, which is 60 seconds (unless overridden by vpn.timeout in configuration file). Values greater than zero mean timeout in seconds. Timeout in milliseconds to wait for device at startup. During boot, devices may take a while to be detected by the driver. This property will cause to delay NetworkManager-wait-online.service and nm-online to give the device a chance to appear. This works by waiting for the given timeout until a compatible device for the profile is available and managed. The value 0 means no wait time. The default value is -1, which currently has the same meaning as no wait time. Timeout in milliseconds used to check for the presence of duplicate IP addresses on the network.  If an address conflict is detected, the activation will fail.  A zero value means that no duplicate address detection is performed, -1 means the default value (either configuration ipvx.dad-timeout override or zero).  A value greater than zero is a timeout in milliseconds. The property is currently implemented only for IPv4. Traffic controls Transport mode Tun Tun device Tunnel flags. Currently, the following values are supported: NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4), NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8), NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10), NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20). They are valid only for IPv6 tunnels. Type 'describe [<setting>.<prop>]' for detailed property description. Type 'help' or '?' for available commands. Type 'print' to show all the connection properties. URI is empty URI is not valid UTF-8 URI not NUL terminated USB UTF-8 encoded file path containing PAC for EAP-FAST. UTF-8 encoded password used for EAP authentication methods. If both the "password" property and the "password-raw" property are specified, "password" is preferred. UTF-8 encoded path to a directory containing PEM or DER formatted certificates to be added to the verification chain in addition to the certificate specified in the "ca-cert" property. If NMSetting8021x:system-ca-certs is enabled and the built-in CA path is an existing directory, then this setting is ignored. UTF-8 encoded path to a directory containing PEM or DER formatted certificates to be added to the verification chain in addition to the certificate specified in the "phase2-ca-cert" property. If NMSetting8021x:system-ca-certs is enabled and the built-in CA path is an existing directory, then this setting is ignored. Unable to add new connection: %s Unable to delete connection: %s Unable to determine private key type. Unable to save connection: %s Unable to set hostname: %s Unexpected amount of data after encrypting. Unexpected end of file following '%s'
 Unexpected failure to normalize the connection Unexpected failure to verify the connection Unknown Unknown command argument: '%s'
 Unknown command: '%s'
 Unknown error Unknown log domain '%s' Unknown log level '%s' Unknown reason Unknown slave type '%s' Unknown/unhandled Bluetooth connection type Unsupported extra-argument Unsupported key cipher for decryption Unsupported key cipher for encryption Unsupported to-string-flags argument Usage Usage: nmcli [OPTIONS] OBJECT { COMMAND | help }

OPTIONS
  -a, --ask                                ask for missing parameters
  -c, --colors auto|yes|no                 whether to use colors in output
  -e, --escape yes|no                      escape columns separators in values
  -f, --fields <field,...>|all|common      specify fields to output
  -g, --get-values <field,...>|all|common  shortcut for -m tabular -t -f
  -h, --help                               print this help
  -m, --mode tabular|multiline             output mode
  -o, --overview                           overview mode
  -p, --pretty                             pretty output
  -s, --show-secrets                       allow displaying passwords
  -t, --terse                              terse output
  -v, --version                            show program version
  -w, --wait <seconds>                     set timeout waiting for finishing operations

OBJECT
  g[eneral]       NetworkManager's general status and operations
  n[etworking]    overall networking control
  r[adio]         NetworkManager radio switches
  c[onnection]    NetworkManager's connections
  d[evice]        devices managed by NetworkManager
  a[gent]         NetworkManager secret agent or polkit agent
  m[onitor]       monitor NetworkManager changes

 Usage: nmcli agent all { help }

Runs nmcli as both NetworkManager secret and a polkit agent.

 Usage: nmcli agent polkit { help }

Registers nmcli as a polkit action for the user session.
When a polkit daemon requires an authorization, nmcli asks the user and gives
the response back to polkit.

 Usage: nmcli agent secret { help }

Runs nmcli as NetworkManager secret agent. When NetworkManager requires
a password it asks registered agents for it. This command keeps nmcli running
and if a password is required asks the user for it.

 Usage: nmcli agent { COMMAND | help }

COMMAND := { secret | polkit | all }

 Usage: nmcli connection clone { ARGUMENTS | help }

ARGUMENTS := [--temporary] [id | uuid | path] <ID> <new name>

Clone an existing connection profile. The newly created connection will be
the exact copy of the <ID>, except the uuid property (will be generated) and
id (provided as <new name> argument).

 Usage: nmcli connection down { ARGUMENTS | help }

ARGUMENTS := [id | uuid | path | apath] <ID> ...

Deactivate a connection from a device (without preventing the device from
further auto-activation). The profile to deactivate is identified by its name,
UUID or D-Bus path.

 Usage: nmcli connection edit { ARGUMENTS | help }

ARGUMENTS := [id | uuid | path] <ID>

Edit an existing connection profile in an interactive editor.
The profile is identified by its name, UUID or D-Bus path

ARGUMENTS := [type <new connection type>] [con-name <new connection name>]

Add a new connection profile in an interactive editor.

 Usage: nmcli connection export { ARGUMENTS | help }

ARGUMENTS := [id | uuid | path] <ID> [<output file>]

Export a connection. Only VPN connections are supported at the moment.
The data are directed to standard output or to a file if a name is given.

 Usage: nmcli connection import { ARGUMENTS | help }

ARGUMENTS := [--temporary] type <type> file <file to import>

Import an external/foreign configuration as a NetworkManager connection profile.
The type of the input file is specified by type option.
Only VPN configurations are supported at the moment. The configuration
is imported by NetworkManager VPN plugins.

 Usage: nmcli connection load { ARGUMENTS | help }

ARGUMENTS := <filename> [<filename>...]

Load/reload one or more connection files from disk. Use this after manually
editing a connection file to ensure that NetworkManager is aware of its latest
state.

 Usage: nmcli connection modify { ARGUMENTS | help }

ARGUMENTS := [id | uuid | path] <ID> ([+|-]<setting>.<property> <value>)+

Modify one or more properties of the connection profile.
The profile is identified by its name, UUID or D-Bus path. For multi-valued
properties you can use optional '+' or '-' prefix to the property name.
The '+' sign allows appending items instead of overwriting the whole value.
The '-' sign allows removing selected items instead of the whole value.

ARGUMENTS := remove <setting>

Remove a setting from the connection profile.

Examples:
nmcli con mod home-wifi wifi.ssid rakosnicek
nmcli con mod em1-1 ipv4.method manual ipv4.addr "192.168.1.2/24, 10.10.1.5/8"
nmcli con mod em1-1 +ipv4.dns 8.8.4.4
nmcli con mod em1-1 -ipv4.dns 1
nmcli con mod em1-1 -ipv6.addr "abbe::cafe/56"
nmcli con mod bond0 +bond.options mii=500
nmcli con mod bond0 -bond.options downdelay
nmcli con mod em1-1 remove sriov

 Usage: nmcli connection monitor { ARGUMENTS | help }

ARGUMENTS := [id | uuid | path] <ID> ...

Monitor connection profile activity.
This command prints a line whenever the specified connection changes.
Monitors all connection profiles in case none is specified.

 Usage: nmcli connection reload { help }

Reload all connection files from disk.

 Usage: nmcli connection show { ARGUMENTS | help }

ARGUMENTS := [--active] [--order <order spec>]

List in-memory and on-disk connection profiles, some of which may also be
active if a device is using that connection profile. Without a parameter, all
profiles are listed. When --active option is specified, only the active
profiles are shown. --order allows custom connection ordering (see manual page).

ARGUMENTS := [--active] [id | uuid | path | apath] <ID> ...

Show details for specified connections. By default, both static configuration
and active connection data are displayed. It is possible to filter the output
using global '--fields' option. Refer to the manual page for more information.
When --active option is specified, only the active profiles are taken into
account. Use global --show-secrets option to reveal associated secrets as well.
 Usage: nmcli connection up { ARGUMENTS | help }

ARGUMENTS := [id | uuid | path] <ID> [ifname <ifname>] [ap <BSSID>] [nsp <name>] [passwd-file <file with passwords>]

Activate a connection on a device. The profile to activate is identified by its
name, UUID or D-Bus path.

ARGUMENTS := ifname <ifname> [ap <BSSID>] [nsp <name>] [passwd-file <file with passwords>]

Activate a device with a connection. The connection profile is selected
automatically by NetworkManager.

ifname      - specifies the device to active the connection on
ap          - specifies AP to connect to (only valid for Wi-Fi)
nsp         - specifies NSP to connect to (only valid for WiMAX)
passwd-file - file with password(s) required to activate the connection

 Usage: nmcli connection { COMMAND | help }

COMMAND := { show | up | down | add | modify | clone | edit | delete | monitor | reload | load | import | export }

  show [--active] [--order <order spec>]
  show [--active] [id | uuid | path | apath] <ID> ...

  up [[id | uuid | path] <ID>] [ifname <ifname>] [ap <BSSID>] [passwd-file <file with passwords>]

  down [id | uuid | path | apath] <ID> ...

  add COMMON_OPTIONS TYPE_SPECIFIC_OPTIONS SLAVE_OPTIONS IP_OPTIONS [-- ([+|-]<setting>.<property> <value>)+]

  modify [--temporary] [id | uuid | path] <ID> ([+|-]<setting>.<property> <value>)+

  clone [--temporary] [id | uuid | path ] <ID> <new name>

  edit [id | uuid | path] <ID>
  edit [type <new_con_type>] [con-name <new_con_name>]

  delete [id | uuid | path] <ID>

  monitor [id | uuid | path] <ID> ...

  reload

  load <filename> [ <filename>... ]

  import [--temporary] type <type> file <file to import>

  export [id | uuid | path] <ID> [<output file>]

 Usage: nmcli device connect { ARGUMENTS | help }

ARGUMENTS := <ifname>

Connect the device.
NetworkManager will try to find a suitable connection that will be activated.
It will also consider connections that are not set to auto-connect.

 Usage: nmcli device delete { ARGUMENTS | help }

ARGUMENTS := <ifname> ...

Delete the software devices.
The command removes the interfaces. It only works for software devices
(like bonds, bridges, etc.). Hardware devices cannot be deleted by the
command.

 Usage: nmcli device disconnect { ARGUMENTS | help }

ARGUMENTS := <ifname> ...

Disconnect devices.
The command disconnects the device and prevents it from auto-activating
further connections without user/manual intervention.

 Usage: nmcli device lldp { ARGUMENTS | help }

ARGUMENTS := [list [ifname <ifname>]]

List neighboring devices discovered through LLDP. The 'ifname' option can be
used to list neighbors for a particular interface.

 Usage: nmcli device modify { ARGUMENTS | help }

ARGUMENTS := <ifname> ([+|-]<setting>.<property> <value>)+

Modify one or more properties that are currently active on the device without modifying
the connection profile. The changes have immediate effect. For multi-valued
properties you can use optional '+' or '-' prefix to the property name.
The '+' sign allows appending items instead of overwriting the whole value.
The '-' sign allows removing selected items instead of the whole value.

Examples:
nmcli dev mod em1 ipv4.method manual ipv4.addr "192.168.1.2/24, 10.10.1.5/8"
nmcli dev mod em1 +ipv4.dns 8.8.4.4
nmcli dev mod em1 -ipv4.dns 1
nmcli dev mod em1 -ipv6.addr "abbe::cafe/56"
 Usage: nmcli device monitor { ARGUMENTS | help }

ARGUMENTS := [<ifname>] ...

Monitor device activity.
This command prints a line whenever the specified devices change state.
Monitors all devices in case no interface is specified.

 Usage: nmcli device reapply { ARGUMENTS | help }

ARGUMENTS := <ifname>

Attempts to update device with changes to the currently active connection
made since it was last applied.

 Usage: nmcli device set { ARGUMENTS | help }

ARGUMENTS := DEVICE { PROPERTY [ PROPERTY ... ] }
DEVICE    := [ifname] <ifname> 
PROPERTY  := { autoconnect { yes | no } |
             { managed { yes | no }

Modify device properties.

 Usage: nmcli device show { ARGUMENTS | help }

ARGUMENTS := [<ifname>]

Show details of device(s).
The command lists details for all devices, or for a given device.

 Usage: nmcli device status { help }

Show status for all devices.
By default, the following columns are shown:
 DEVICE     - interface name
 TYPE       - device type
 STATE      - device state
 CONNECTION - connection activated on device (if any)
Displayed columns can be changed using '--fields' global option. 'status' is
the default command, which means 'nmcli device' calls 'nmcli device status'.

 Usage: nmcli device wifi { ARGUMENTS | help }

Perform operation on Wi-Fi devices.

ARGUMENTS := [list [ifname <ifname>] [bssid <BSSID>] [--rescan yes|no|auto]]

List available Wi-Fi access points. The 'ifname' and 'bssid' options can be
used to list APs for a particular interface, or with a specific BSSID. The
--rescan flag tells whether a new Wi-Fi scan should be triggered.

ARGUMENTS := connect <(B)SSID> [password <password>] [wep-key-type key|phrase] [ifname <ifname>]
                     [bssid <BSSID>] [name <name>] [private yes|no] [hidden yes|no]

Connect to a Wi-Fi network specified by SSID or BSSID. The command finds a
matching connection or creates one and then activates it on a device. This
is a command-line counterpart of clicking an SSID in a GUI client. If a
connection for the network already exists, it is possible to bring up the
existing profile as follows: nmcli con up id <name>. Note that only open,
WEP and WPA-PSK networks are supported if no previous connection exists.
It is also assumed that IP configuration is obtained via DHCP.

ARGUMENTS := hotspot [ifname <ifname>] [con-name <name>] [ssid <SSID>]
                     [band a|bg] [channel <channel>] [password <password>]

Create a Wi-Fi hotspot. Use 'connection down' or 'device disconnect'
to stop the hotspot.
Parameters of the hotspot can be influenced by the optional parameters:
ifname - Wi-Fi device to use
con-name - name of the created hotspot connection profile
ssid - SSID of the hotspot
band - Wi-Fi band to use
channel - Wi-Fi channel to use
password - password to use for the hotspot

ARGUMENTS := rescan [ifname <ifname>] [[ssid <SSID to scan>] ...]

Request that NetworkManager immediately re-scan for available access points.
NetworkManager scans Wi-Fi networks periodically, but in some cases it might
be useful to start scanning manually. 'ssid' allows scanning for a specific
SSID, which is useful for APs with hidden SSIDs. More 'ssid' parameters can be
given. Note that this command does not show the APs,
use 'nmcli device wifi list' for that.

 Usage: nmcli device { COMMAND | help }

COMMAND := { status | show | set | connect | reapply | modify | disconnect | delete | monitor | wifi | lldp }

  status

  show [<ifname>]

  set [ifname] <ifname> [autoconnect yes|no] [managed yes|no]

  connect <ifname>

  reapply <ifname>

  modify <ifname> ([+|-]<setting>.<property> <value>)+

  disconnect <ifname> ...

  delete <ifname> ...

  monitor <ifname> ...

  wifi [list [ifname <ifname>] [bssid <BSSID>] [--rescan yes|no|auto]]

  wifi connect <(B)SSID> [password <password>] [wep-key-type key|phrase] [ifname <ifname>]
                         [bssid <BSSID>] [name <name>] [private yes|no] [hidden yes|no]

  wifi hotspot [ifname <ifname>] [con-name <name>] [ssid <SSID>] [band a|bg] [channel <channel>] [password <password>]

  wifi rescan [ifname <ifname>] [[ssid <SSID to scan>] ...]

  wifi show-password [ifname <ifname>]

  lldp [list [ifname <ifname>]]

 Usage: nmcli general hostname { ARGUMENTS | help }

ARGUMENTS := [<hostname>]

Get or change persistent system hostname.
With no arguments, this prints currently configured hostname. When you pass
a hostname, NetworkManager will set it as the new persistent system hostname.

 Usage: nmcli general logging { ARGUMENTS | help }

ARGUMENTS := [level <log level>] [domains <log domains>]

Get or change NetworkManager logging level and domains.
Without any argument current logging level and domains are shown. In order to
change logging state, provide level and/or domain. Please refer to the man page
for the list of possible logging domains.

 Usage: nmcli general permissions { help }

Show caller permissions for authenticated operations.

 Usage: nmcli general status { help }

Show overall status of NetworkManager.
'status' is the default action, which means 'nmcli gen' calls 'nmcli gen status'

 Usage: nmcli monitor

Monitor NetworkManager changes.
Prints a line whenever a change occurs in NetworkManager

 Usage: nmcli networking connectivity { ARGUMENTS | help }

ARGUMENTS := [check]

Get network connectivity state.
The optional 'check' argument makes NetworkManager re-check the connectivity.

 Usage: nmcli networking off { help }

Switch networking off.

 Usage: nmcli networking on { help }

Switch networking on.

 Usage: nmcli networking { COMMAND | help }

COMMAND := { [ on | off | connectivity ] }

  on

  off

  connectivity [check]

 Usage: nmcli radio all { ARGUMENTS | help }

ARGUMENTS := [on | off]

Get status of all radio switches, or turn them on/off.

 Usage: nmcli radio wifi { ARGUMENTS | help }

ARGUMENTS := [on | off]

Get status of Wi-Fi radio switch, or turn it on/off.

 Usage: nmcli radio wwan { ARGUMENTS | help }

ARGUMENTS := [on | off]

Get status of mobile broadband radio switch, or turn it on/off.

 Usage: nmcli radio { COMMAND | help }

COMMAND := { all | wifi | wwan }

  all | wifi | wwan [ on | off ]

 Use "nmcli device show" to get complete information about known devices and
"nmcli connection show" to get an overview on active connection profiles.

Consult nmcli(1) and nmcli-examples(7) manual pages for complete usage details.
 Use TCP header compression Use point-to-point encryption (MPPE) Use stateful MPPE User ID [none] User settings Username Username [none] Username used to authenticate with the ADSL service. Username used to authenticate with the PPPoE service. VCI of ADSL connection VF with index %u, but the total number of VFs is %u VFs %d and %d are not sorted by ascending index VLAN VLAN ID (<0-4094>) VLAN connection VLAN connection %d VLAN flags (<0-7>) [none] VLAN id VLAN parent device or connection UUID VPI of ADSL connection VPN VPN connected VPN connecting VPN connecting (getting IP configuration) VPN connecting (need authentication) VPN connecting (prepare) VPN connection VPN connection %d VPN connection (name, UUID, or path):  VPN connection failed VPN disconnected VPN password required VRF VRF connection VTI VTI6 VXLAN VXLAN ID VXLAN connection Valid connection types: %s
 Value cannot be interpreted as a list of numbers. Verify connection: %s
 Verify setting '%s': %s
 Veth Veth connection Veth connection %d WEP 128-bit Passphrase WEP 40/128-bit Key (Hex or ASCII) WEP index WEP key index1 (Default) WEP key index2 WEP key index3 WEP key index4 WEP key index set to '%d' WEP key is guessed to be of '%s' WI-FI WPA & WPA2 Enterprise WPA & WPA2 Personal WPA Ad-Hoc authentication requires 'ccmp' pairwise cipher WPA Ad-Hoc authentication requires 'rsn' protocol WPA Ad-Hoc requires 'ccmp' group cipher WPA authentication is incompatible with Shared Key authentication WPA authentication is incompatible with non-EAP (original) LEAP or Dynamic WEP WPA-EAP authentication requires an 802.1x setting WPA-EAP requires 'open' authentication WPA-PSK authentication is incompatible with 802.1x WPA-PSK requires 'open' authentication WPA3 Personal WPAN connection WPAN settings WPS is required WWAN radio switch Wait for NetworkManager startup instead of a connection Waits for NetworkManager to finish activating startup network connections. Wake-on-LAN mode 'default' and 'ignore' are exclusive flags Wake-on-LAN password can only be used with magic packet mode Wake-on-WLAN mode 'default' and 'ignore' are exclusive flags Wake-on-WLAN trying to set unknown flag Warning: %s
 Warning: %s is not an UUID of any existing connection profile
 Warning: %s.%s set to '%s', but it might be ignored in infrastructure mode
 Warning: '%s' should be SSID for hidden APs; but it looks like a BSSID.
 Warning: 'file' already specified, ignoring extra one.
 Warning: 'type' already specified, ignoring extra one.
 Warning: There is another connection with the name '%1$s'. Reference the connection by its uuid '%2$s'
 Warning: There are %3$u other connections with the name '%1$s'. Reference the connection by its uuid '%2$s'
 Warning: argument '%s' is duplicated.
 Warning: editing existing connection '%s'; 'con-name' argument is ignored
 Warning: editing existing connection '%s'; 'type' argument is ignored
 Warning: master='%s' doesn't refer to any existing profile.
 Warning: password for '%s' not given in 'passwd-file' and nmcli cannot ask without '--ask' option.
 Warning: polkit agent initialization failed: %s
 Warning: setting %s.%s requires removing ipv4 and ipv6 settings
 When "method" is set to "auto" and this property to TRUE, automatically configured name servers and search domains are ignored and only name servers and search domains specified in the "dns" and "dns-search" properties, if any, are used. When "method" is set to "auto" and this property to TRUE, automatically configured routes are ignored and only routes specified in the "routes" property, if any, are used. When TRUE, enforce auto-negotiation of speed and duplex mode. If "speed" and "duplex" properties are both specified, only that single mode will be advertised and accepted during the link auto-negotiation process: this works only for BASE-T 802.3 specifications and is useful for enforcing gigabits modes, as in these cases link negotiation is mandatory. When FALSE, "speed" and "duplex" properties should be both set or link configuration will be skipped. When TRUE, only connections to the home network will be allowed. Connections to roaming networks will not be made. When TRUE, overrides the "ca-path" and "phase2-ca-path" properties using the system CA directory specified at configure time with the --system-ca-path switch.  The certificates in this directory are added to the verification chain in addition to any certificates specified by the "ca-cert" and "phase2-ca-cert" properties. If the path provided with --system-ca-path is rather a file name (bundle of trusted CA certificates), it overrides "ca-cert" and "phase2-ca-cert" properties instead (sets ca_cert/ca_cert2 options for wpa_supplicant). When TRUE, the settings such as APN, username, or password will default to values that match the network the modem will register to in the Mobile Broadband Provider database. When WEP is used (ie, key-mgmt = "none" or "ieee8021x") indicate the 802.11 authentication algorithm required by the AP here.  One of "open" for Open System, "shared" for Shared Key, or "leap" for Cisco LEAP.  When using Cisco LEAP (ie, key-mgmt = "ieee8021x" and auth-alg = "leap") the "leap-username" and "leap-password" properties must be specified. When a value greater than 0 is set, configures the device to use the specified speed. If "auto-negotiate" is "yes" the specified speed will be the only one advertised during link negotiation: this works only for BASE-T 802.3 specifications and is useful for enforcing gigabit speeds, as in this case link negotiation is mandatory. If the value is unset (0, the default), the link configuration will be either skipped (if "auto-negotiate" is "no", the default) or will be auto-negotiated (if "auto-negotiate" is "yes") and the local device will advertise all the supported speeds. In Mbit/s, ie 100 == 100Mbit/s. Must be set together with the "duplex" property when non-zero. Before specifying a speed value be sure your device supports it. When a value is set, either "half" or "full", configures the device to use the specified duplex mode. If "auto-negotiate" is "yes" the specified duplex mode will be the only one advertised during link negotiation: this works only for BASE-T 802.3 specifications and is useful for enforcing gigabits modes, as in these cases link negotiation is mandatory. If the value is unset (the default), the link configuration will be either skipped (if "auto-negotiate" is "no", the default) or will be auto-negotiated (if "auto-negotiate" is "yes") and the local device will advertise all the supported duplex modes. Must be set together with the "speed" property if specified. Before specifying a duplex mode be sure your device supports it. When static WEP is used (ie, key-mgmt = "none") and a non-default WEP key index is used by the AP, put that WEP key index here.  Valid values are 0 (default key) through 3.  Note that some consumer access points (like the Linksys WRT54G) number the keys 1 - 4. Whether LLDP is enabled for the connection. Whether Link-Local Multicast Name Resolution (LLMNR) is enabled for the connection. LLMNR is a protocol based on the Domain Name System (DNS) packet format that allows both IPv4 and IPv6 hosts to perform name resolution for hosts on the same local link. The permitted values are: "yes" (2) register hostname and resolving for the connection, "no" (0) disable LLMNR for the interface, "resolve" (1) do not register hostname but allow resolving of LLMNR host names If unspecified, "default" ultimately depends on the DNS plugin (which for systemd-resolved currently means "yes"). This feature requires a plugin which supports LLMNR. Otherwise, the setting has no effect. One such plugin is dns-systemd-resolved. Whether mDNS is enabled for the connection. The permitted values are: "yes" (2) register hostname and resolving for the connection, "no" (0) disable mDNS for the interface, "resolve" (1) do not register hostname but allow resolving of mDNS host names and "default" (-1) to allow lookup of a global default in NetworkManager.conf. If unspecified, "default" ultimately depends on the DNS plugin (which for systemd-resolved currently means "no"). This feature requires a plugin which supports mDNS. Otherwise, the setting has no effect. One such plugin is dns-systemd-resolved. Whether or not slaves of this connection should be automatically brought up when NetworkManager activates this connection. This only has a real effect for master connections. The properties "autoconnect", "autoconnect-priority" and "autoconnect-retries" are unrelated to this setting. The permitted values are: 0: leave slave connections untouched, 1: activate all the slave connections with this connection, -1: default. If -1 (default) is set, global connection.autoconnect-slaves is read to determine the real value. If it is default as well, this fallbacks to 0. Whether the 802.1X authentication is optional. If TRUE, the activation will continue even after a timeout or an authentication failure. Setting the property to TRUE is currently allowed only for Ethernet connections. If set to FALSE, the activation can continue only after a successful authentication. Whether the connection is metered. When updating this property on a currently activated connection, the change takes effect immediately. Whether the interface should be a MACVTAP. Whether the interface should be put in promiscuous mode. Whether the proxy configuration is for browser only. Whether the system hostname can be determined from DHCP on this connection. When set to NM_TERNARY_DEFAULT (-1), the value from global configuration is used. If the property doesn't have a value in the global configuration, NetworkManager assumes the value to be NM_TERNARY_TRUE (1). Whether the system hostname can be determined from reverse DNS lookup of addresses on this device. When set to NM_TERNARY_DEFAULT (-1), the value from global configuration is used. If the property doesn't have a value in the global configuration, NetworkManager assumes the value to be NM_TERNARY_TRUE (1). Whether the transmitted traffic must be encrypted. Whether to automatically add routes for the AllowedIPs ranges of the peers. If TRUE (the default), NetworkManager will automatically add routes in the routing tables according to ipv4.route-table and ipv6.route-table. Usually you want this automatism enabled. If FALSE, no such routes are added automatically. In this case, the user may want to configure static routes in ipv4.routes and ipv6.routes, respectively. Note that if the peer's AllowedIPs is "0.0.0.0/0" or "::/0" and the profile's ipv4.never-default or ipv6.never-default setting is enabled, the peer route for this peer won't be added automatically. Whether to autoprobe virtual functions by a compatible driver. If set to NM_TERNARY_TRUE (1), the kernel will try to bind VFs to a compatible driver and if this succeeds a new network interface will be instantiated for each VF. If set to NM_TERNARY_FALSE (0), VFs will not be claimed and no network interfaces will be created for them. When set to NM_TERNARY_DEFAULT (-1), the global default is used; in case the global default is unspecified it is assumed to be NM_TERNARY_TRUE (1). Whether to enable Path MTU Discovery on this tunnel. Wi-Fi Wi-FiAutomatic Wi-FiClient Wi-Fi P2P Wi-Fi P2P connection Wi-Fi connection Wi-Fi connection %d Wi-Fi network mode; one of "infrastructure", "mesh", "adhoc" or "ap".  If blank, infrastructure is assumed. Wi-Fi radio switch Wi-Fi scan list Wi-Fi securityNone Wi-Fi security settings WiMAX WiMAX NSP name WiMAX connection WireGuard WireGuard VPN secret WireGuard VPN settings WireGuard private-key Wired Wired 802.1X authentication Wired Ethernet Wired connection Wired connection %d Wireless channel to use for the Wi-Fi connection.  The device will only join (or create for Ad-Hoc networks) a Wi-Fi network on the specified channel.  Because channel numbers overlap between bands, this property also requires the "band" property to be set. With "cloned-mac-address" setting "random" or "stable", by default all bits of the MAC address are scrambled and a locally-administered, unicast MAC address is created. This property allows to specify that certain bits are fixed. Note that the least significant bit of the first MAC address will always be unset to create a unicast MAC address. If the property is NULL, it is eligible to be overwritten by a default connection setting. If the value is still NULL or an empty string, the default is to create a locally-administered, unicast MAC address. If the value contains one MAC address, this address is used as mask. The set bits of the mask are to be filled with the current MAC address of the device, while the unset bits are subject to randomization. Setting "FE:FF:FF:00:00:00" means to preserve the OUI of the current MAC address and only randomize the lower 3 bytes using the "random" or "stable" algorithm. If the value contains one additional MAC address after the mask, this address is used instead of the current MAC address to fill the bits that shall not be randomized. For example, a value of "FE:FF:FF:00:00:00 68:F7:28:00:00:00" will set the OUI of the MAC address to 68:F7:28, while the lower bits are randomized. A value of "02:00:00:00:00:00 00:00:00:00:00:00" will create a fully scrambled globally-administered, burned-in MAC address. If the value contains more than one additional MAC addresses, one of them is chosen randomly. For example, "02:00:00:00:00:00 00:00:00:00:00:00 02:00:00:00:00:00" will create a fully scrambled MAC address, randomly locally or globally administered. Writing to %s failed: %s
 XOR You can specify this option more than once. Press <Enter> when you're done.
 You may edit the following properties: %s
 You may edit the following settings: %s
 You may try running 'verify fix' to fix errors.
 [ Type: %s | Name: %s | UUID: %s | Dirty: %s | Temp: %s ]
 ['%s' setting values]
 [NM property description] [nmcli specific description] a connection using '%s' authentication cannot specify WPA ciphers a connection using '%s' authentication cannot specify WPA protocols a connection using '%s' authentication cannot specify a WPA password a connection using '%s' authentication cannot use WPA key management a fixed TTL is allowed only when path MTU discovery is enabled a gateway is incompatible with '%s' access denied action name missing. activate [<ifname>] [/<ap>|<nsp>]  :: activate the connection

Activates the connection.

Available options:
<ifname>    - device the connection will be activated on
/<ap>|<nsp> - AP (Wi-Fi) or NSP (WiMAX) (prepend with / when <ifname> is not specified)
 activated activating add [<value>]  :: append new value to the property

This command adds provided <value> to this property, if the property is of a container type. For single-valued properties the property value is replaced (same as 'set').
 advertise,  agent-owned,  asleep attribute '%s' is invalid for "%s" attribute is not valid for a IPv4 route attribute is not valid for a IPv6 route auth auto autoconnect back  :: go to upper menu level

 bandwidth percentages must total 100%% binary data missing bluetooth connection both speed and duplex are required for static link configuration both speed and duplex should have a valid value or both should be unset bytes can be enabled only on Ethernet connections can not set property: %s can't be enabled when manual configuration is present can't be simultaneously disabled and enabled can't set property of type '%s' from value of type '%s' cannot detect address family for rule cannot load VPN plugin "%s" due to missing "%s". Missing client plugin? cannot load VPN plugin in '%s': invalid service name cannot load VPN plugin in '%s': missing plugin name cannot load legacy-only VPN plugin "%s" for "%s" cannot load plugin "%s": %s cannot read pac-script from file '%s' cannot read team config from file '%s' cannot set connection.multi-connect for VPN setting cannot set empty "%s" option cannot set parameters for lacp and activebackup runners together certificate detected as invalid scheme certificate is invalid: %s certificate or key file '%s' does not exist change  :: change current value

Displays current value and allows editing it.
 changes will have no effect until '%s' includes 1 (enabled) channel must not be between %d and %d coalesce option must be either 0 or 1 conflicting secret flags conflicting value of mac-address-randomization and cloned-mac-address connected connected (externally) connected (local only) connected (site only) connecting connecting (checking IP connectivity) connecting (configuring) connecting (externally) connecting (getting IP configuration) connecting (need authentication) connecting (prepare) connecting (starting secondary connections) connection connection available connection does not match access point connection does not match device connection does not match mesh point connection failed connection id fallback%s %u connection type '%s' is not valid connections available construct property "%s" for object '%s' can't be set after construction data missing deactivated deactivating deactivating (externally) default deprecated semicolon at the end of value %s: '%s' describe  :: describe property

Shows property description. You can consult nm-settings(5) manual page to see all NM settings and properties.
 describe [<setting>.<prop>]  :: describe property

Shows property description. You can consult nm-settings(5) manual page to see all NM settings and properties.
 device '%s' not compatible with connection '%s' device '%s' not compatible with connection '%s':  disabled disconnected disconnecting don't know how to get the property value duplicate D-Bus property "%s" duplicate VF index %u duplicate bridge VLAN vid %u duplicate key "%s" duplicate key %s duplicate key '%s' duplicate property duplicate setting name element invalid empty text does not describe a rule enabled enabled,  error loading setting value: %s failed stat file %s: %s failed to load VPN plugin "%s": %s failed to load nm_vpn_editor_plugin_factory() from %s (%s) failed to set bond option "%s" failed to set property: %s failure to select field field '%s' has to be alone file '%s' contains non-valid utf-8 file permissions for %s filename has invalid format (%s) filename must be an absolute path (%s) flags are invalid flags invalid flags invalid - disabled full fw missing garbage at the end of value %s: '%s' gateway cannot be set if there are no addresses configured gateway is invalid goto <setting>[.<prop>] | <prop>  :: enter setting/property for editing

This command enters into a setting or property for editing it.

Examples: nmcli> goto connection
          nmcli connection> goto secondaries
          nmcli> goto ipv4.addresses
 has from/src but the prefix-length is zero has to match '%s' property for PKCS#12 has to/dst but the prefix-length is zero help/? [<command>]  :: help for nmcli commands

 help/? [<command>]  :: help for the nmcli commands

 hw hw disabled iface ignoring invalid %s address: %s ignoring invalid %s route: %s ignoring invalid DNS server IPv%c address '%s' ignoring invalid MAC address ignoring invalid SSID ignoring invalid bond option %s%s%s = %s%s%s: %s ignoring invalid byte element '%u' (not between 0 and 255 inclusive) ignoring invalid gateway '%s' for %s route ignoring invalid number '%s' ignoring invalid raw password ignoring invalid team configuration: %s ignoring missing number incorrect item '%s' in '--order' option incorrect string '%s' of '--order' option interface name contains an invalid character interface name is longer than 15 characters interface name is missing interface name is reserved interface name is too short interface name must be UTF-8 encoded interface name must be alphanumerical with no forward or backward slashes interface name must not be empty interface name of software infiniband device must be '%s' or unset (instead it is '%s') invalid "family" invalid "from" part invalid "to" part invalid 'name' "%s" invalid D-Bus property "%s" invalid D-Bus property "%s" for "%s" invalid D-Bus type "%s" invalid DUID invalid IP address "%s" for allowed-ip of peer invalid IP address: %s invalid IPv%c address '%s' invalid IPv4 or subnet "%s" invalid JSON at position %d (%s) invalid PKCS#11 URI "%s" invalid VF %u: %s invalid action type invalid action:  invalid address family invalid attribute type '%s' invalid attribute: %s invalid auth flags invalid boolean value '%s' for attribute '%s' invalid certificate format invalid destination port range invalid endpoint for peer invalid field '%s%s%s%s%s'; %s%s%s invalid field '%s%s%s'; allowed fields: [%s] invalid field '%s%s%s'; no such field invalid field '%s'; allowed fields: %s and %s, or %s,%s invalid file owner %d for %s invalid from/src invalid gateway address '%s' invalid handle: '%s' invalid iifname invalid int32 value '%s' for attribute '%s' invalid json invalid key "%s" invalid key "%s": %s invalid key '%s' invalid key '%s.%s' invalid key/cert value invalid key/cert value data:;base64, is not base64 invalid key/cert value data:;base64,file:// invalid key/cert value is not a valid blob invalid key/cert value path "%s" invalid link-watchers: %s invalid oifname invalid option '%s' invalid option '%s', use a combination of [%s] invalid option '%s', use one of [%s] invalid parity value '%s' invalid passwd-file '%s' at line %zd: %s invalid passwd-file '%s': %s invalid peer public key in section '%s' invalid peer secrets invalid permission "%s" invalid permissions not in format "user:$UNAME[:]" invalid prefix %s invalid prefix length for %s '%s', defaulting to %d invalid prefix length for from/src invalid prefix length for to/dst invalid preshared-key for peer invalid preshared-key-flags for peer invalid priority map '%s' invalid proxy method invalid public-key for peer invalid qdisc: %s invalid route: %s. %s invalid runner-tx-hash invalid secret '%s' at %s:%zu invalid setting name invalid setting name '%s' invalid setting: %s invalid source port range invalid tfilter: %s invalid to/dst invalid uint32 value '%s' for attribute '%s' invalid uint64 value '%s' for attribute '%s' invalid uint8 value '%s' for attribute '%s' invalid value invalid value '%s' for option '%s' invalid value for "%s" invalid value for "%s": %s invalid value for '%s' at %s:%zu invalid value for key '%s' invalid variant type '%s' for "%s" ip4 default ip6 default is empty is not a JSON object is not a valid MAC address is not a valid VLAN filtering protocol is not a valid link local MAC address is not a valid option key '%s.%s' has invalid allowed-ips key '%s.%s' is not a integer in range 0 to 2^32 key '%s.%s' is not a uint32 key '%s.%s' is not a valid 256 bit key in base64 encoding key '%s.%s' is not a valid endpoint key '%s.%s' is not a valid secret flag key '%s.%s' is not boolean key cannot contain ".." key cannot start with "NM." key contains invalid characters key is too long key must be 32 bytes base64 encoded key must be UTF8 key requires a '.' for a namespace kind is missing libtool archives are not supported (%s) limited long device name%s %s macvlan connection mandatory option '%s' is missing master maximum number of user data entries reached maximum number of user data entries reached (%u instead of %u) metered value %d is not valid method "%s" is not supported for WireGuard millisecondsms missing "family" missing "plugin" setting missing 'name' attribute missing argument for "%s" missing colon for "<setting>.<property>:<secret>" format missing dot for "<setting>.<property>:<secret>" format missing filename missing filename to load VPN plugin info missing from/src for a non zero prefix-length missing key missing key-value separator '%c' after '%s' missing link watcher missing name for VPN plugin info missing name, try one of [%s] missing option name missing prefix length for %s '%s', defaulting to %d missing property for "<setting>.<property>:<secret>" format missing public-key for peer missing service for VPN plugin info missing setting missing setting for "<setting>.<property>:<secret>" format missing table missing to/dst for a non zero prefix-length mtu mtu can be at most %u but it is %u multiple addresses are not allowed for '%s=%s' must be either psk (0) or eap (1) must contain 8 comma-separated numbers name neither a valid connection nor device given never new hostname nmcli [<conf-option> <value>]  :: nmcli configuration

Configures nmcli. The following options are available:
status-line yes | no          [default: no]
save-confirmation yes | no    [default: yes]
show-secrets yes | no         [default: no]
prompt-color <color> | <0-8>  [default: 0]
%s
Examples: nmcli> nmcli status-line yes
          nmcli> nmcli save-confirmation no
          nmcli> nmcli prompt-color 3
 nmcli can accepts both direct JSON configuration data and a file name containing the configuration. In the latter case the file is read and the contents is put into this property.

Examples: set team.config { "device": "team0", "runner": {"name": "roundrobin"}, "ports": {"eth1": {}, "eth2": {}} }
          set team.config /etc/my-team.conf
 nmcli successfully registered as a NetworkManager's secret agent.
 nmcli successfully registered as a polkit agent.
 nmcli tool, version %s
 nmcli-overview%s: %s nmcli-overview%s: %s to %s no no (guessed) no active connection on device '%s' no active connection or device no device found for connection '%s' non promiscuous operation is allowed only in passthru mode non-existing peer '%s' none not a file (%s) not a secret property not a valid ethernet MAC address #%u at position %lld not a valid ethernet MAC address for mask at position %lld not a valid hex-string not a valid private key not required,  not saved,  not valid utf-8 number for '%s' is out of range object class '%s' has no property named '%s' off on only makes sense with EUI64 address generation mode only one VLAN can be the PVID only valid for psk mode openconnect failed with signal %d openconnect failed with status %d openconnect will be run to authenticate.
It will return to nmtui when completed. operation succeeded but object %s does not exist page must be between %d and %d page must be defined along with a channel parent handle missing parent not specified. password is not supported when certificate is not on a PKCS#11 token path is not absolute (%s) peer #%u has invalid allowed-ips setting peer #%u has invalid endpoint peer #%u has invalid public-key peer #%u has no public-key peer #%u is invalid: %s peer #%u lacks public-key peer '%s' is invalid: %s plugin missing port portal preparing print [all]  :: print setting or connection values

Shows current property or the whole connection.

Example: nmcli ipv4> print all
 print [property|setting|connection]  :: print property (setting, connection) value(s)

Shows property value. Providing an argument you can also display values for the whole setting or connection.
 property '%s' of object class '%s' is not writable property cannot be an empty string property cannot be longer than 255 bytes property cannot be set when dhcp-hostname is also set property cannot contain any nul bytes property invalid property invalid (not enabled) property is empty property is empty or wrong size property is invalid property is missing property is not specified property is not specified and neither is '%s:%s' property must contain only digits property name is not UTF-8 property should be TRUE when method is set to disabled property should be TRUE when method is set to ignore or disabled property type should be set to '%s' property value '%s' is empty or too long (>64) quit  :: exit nmcli

This command exits nmcli. When the connection being edited is not saved, the user is asked to confirm the action.
 registration failed reject %s remove <setting>[.<prop>]  :: remove setting or reset property value

This command removes an entire setting from the connection, or if a property
is given, resets that property to the default value.

Examples: nmcli> remove wifi-sec
          nmcli> remove eth.mtu
 remove [<value>|<index>|<option name>]  :: delete the value

Removes the property value. For single-valued properties, this sets the
property back to its default value. For container-type properties, this removes
all the values of that property or you can specify an argument to remove just
a single item or option. The argument is either a value or index of the item to
remove, or an option name (for properties with named options).

Examples: nmcli ipv4.dns> remove 8.8.8.8
          nmcli ipv4.dns> remove 2
          nmcli bond.options> remove downdelay

 request succeeded with %s but object is in an unsuitable state rule #%u is invalid: %s rule is invalid: %s running s390 network device type; one of "qeth", "lcs", or "ctc", representing the different types of virtual network devices available on s390 systems. save [persistent|temporary]  :: save the connection

Sends the connection profile to NetworkManager that either will save it
persistently, or will only keep it in memory. 'save' without an argument
means 'save persistent'.
Note that once you save the profile persistently those settings are saved
across reboot or restart. Subsequent changes can also be temporary or
persistent, but any temporary changes will not persist across reboot or
restart. If you want to fully remove the persistent connection, the connection
profile must be deleted.
 seconds secret flags must not be "not-required" secret flags property not found secret is not UTF-8 secret is not of correct type secret name cannot be empty secret not found set [<setting>.<prop> <value>]  :: set property value

This command sets property value.

Example: nmcli> set con.id My connection
 set [<value>]  :: set new value

This command sets provided <value> to this property
 setting contained a secret with an empty name setting has invalid variant type setting is required for non-slave connections setting not allowed in slave connection setting not found setting required for connection of type '%s' setting this property requires non-zero '%s' property slave-type '%s' requires a '%s' setting in the connection some flags are invalid for the select mode: %s source-host '%s' contains invalid characters started starting sum not 100% suppress_prefixlength is only allowed with the to-table action suppress_prefixlength out of range sw sw disabled table cannot be zero target-host '%s' contains invalid characters team config exceeds size limit team config file '%s' contains non-valid utf-8 team config is not valid UTF-8 teamd control failed the key contains non-hexadecimal characters the key is empty the key must be %d characters the mask can't contain bits 0 (STP), 1 (MAC) or 2 (LACP) the metric ('%s') must be before attributes the next hop ('%s') must be first the plugin does not support export capability the plugin does not support import capability the property can't be changed the property cannot be set when '%s' is disabled the property is currently supported only for DHCPv4 the script is not valid utf8 the script is too large the script lacks FindProxyForURL function the tag id must be in range 0-4094 but is %u the value '%s' is not a valid UUID the vlan id must be in range 0-4094 but is %u there are duplicate TC filters there are duplicate TC qdiscs there exists a conflicting plugin (%s) that has the same %s.%s value there exists a conflicting plugin with the same name (%s) this property cannot be empty for '%s=%s' this property is not allowed for '%s=%s' this property is not allowed for method none token is not in canonical form too many arguments. Please only specify a private key file and optionally a password tunnel keys can only be specified for GRE tunnels unable to set property '%s' of type '%s' from value of type '%s' unavailable unexpected character '%c' for %s: '%s' (position %td) unexpected character '%c' for address %s: '%s' (position %td) unexpected character '%c' in prefix length for %s: '%s' (position %td) unexpected uuid %s instead of %s unknown unknown VPN plugin "%s" unknown attribute unknown attribute '%s' unknown connection '%s' unknown device '%s'. unknown error initializing plugin %s unknown ethtool option '%s' unknown flags 0x%x unknown link-watcher name "%s" unknown property unknown secret flags unknown setting name unmanaged unrecognized line at %s:%zu unsupported action option: '%s'. unsupported attribute '%s' of type '%s' unsupported ethtool setting unsupported key "%s" unsupported qdisc option: '%s'. unsupported secret flags unsupported tfilter option: '%s'. unterminated escape sequence use 'goto <setting>' first, or 'describe <setting>.<property>'
 use 'goto <setting>' first, or 'set <setting>.<property>'
 value "%s" of type '%s' is invalid or out of range for property '%s' of type '%s' value %d is not valid value '%d' is out of range <%d-%d> value cannot be interpreted as integer value for '%s' must be a boolean value for '%s' must be a number value is NULL value is empty value is missing value is not a valid token value is not an integer in range [%lld, %lld] value is not valid UTF8 value is too large value out or range verify [all | fix]  :: verify setting or connection validity

Verifies whether the setting or connection is valid and can be saved later.
It indicates invalid values on error. Some errors may be fixed automatically
by 'fix' option.

Examples: nmcli> verify
          nmcli> verify fix
          nmcli bond> verify
 veth peer vlan setting should have a ethernet setting as well vlanid is out of range [-1, 4094] willing,  wired setting not allowed for mode %s wrong type; should be a list of strings. yes yes (guessed) Project-Id-Version: NetworkManager
Report-Msgid-Bugs-To: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/issues
PO-Revision-Date: 2021-11-09 20:06+0800
Last-Translator: Dingzhong Chen <wsxy162@gmail.com>
Language-Team: Chinese - China <i18n-zh@googlegroups.com>
Language: zh_CN
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Plural-Forms: nplurals=1; plural=0
X-Generator: Gtranslator 40.0
 "uid-range-start" 大于 "uid-range-end" # 由 NetworkManger 创建
 # 合并自 %s

 %d（密钥） %d（密码） %d（未知） %d 大于本地端口最大值 %d %d。DNS 服务器地址无效 %d。IP 地址有无效类型的 "label" 属性 %d。IP 地址有无效标签 "%s" %d。IP 地址无效 %d。路由无效 %lld（%s） %lld — %s %s %s（%s） %s (%s) 已克隆为 %s (%s)。
 %s 网络 %s VPN 连接 缺少 %s 参数 %s 已在运行中（pid %ld）
 %s 不兼容静态 WEP 密钥 %s 不是有效的路由类型 %s 只被 runner %s 允许 %s 只被 runner %s 允许 %s 超出了范围 [0, %d] %s。请使用 --help 查看有效选项列表。
 %s：连接配置集已改动
 %s：连接配置集已创建
 %s：连接配置集已移除
 %s：设备已创建
 %s：设备已移除
 %s：不要重试加载之前已失败的插件 %s：正使用连接 "%s"
 %u MHz %u Mb/s %u Mbit/s %u. 规则带有错误的地址家族 %u. 规则无效：%s 接口名称中不允许使用 "%%" "%d" 不是有效的信道 "%d" 是无效的隧道模式 "%d" 超出了有效范围 <128-16384> "%ld" 不是有效的信道 "%s" 和 "%s" 不能有不同的值 "%s" 只能与 "%s=%s"（WEP）共用 "%s" 连接需要 "%s" 或者 "%s" 设置 "%s" 连接需要 "%s" 设置 "%s" 连接必须从属于 "%s"，而不是 "%s" "%s" 包含无效字符（请使用 [A-Za-z._-]） "%s" 没有包含有效的 PAC 脚本 "%s" 必须是单独的 "%s" 不明确（%s） "%s" 不明确：%s "%s" 不是 UUID 或接口名称 "%s" 不是 VPN 连接配置集 "%s" 不是任何现有配置集的名称 "%s" 不是数字 "%s" 不是有效的 DCB 标记 "%s" 不是有效的以太网 MAC "%s" 不是有效的以太网端口值 "%s" 不是有效的 FQDN "%s" 不是一个有效的 IAID "%s" 不是有效的 IBoIP P_Key "%s" 不是有效的 IP 或子网 "%s" 不是有效的 IP%s 地址 "%s" 不是有效的 IPv%c 地址 "%s" 不是有效的 IPv4 地址 "%s" 不是 "%s" 选项的有效 IPv4 地址 "%s" 不是有效的 IPv6 地址 "%s" 不是有效的 MAC 地址 "%s"不是有效的 UUID "%s" 不是有效的 Wi-Fi 模式 "%s" 不是有效频段 "%s" 不是有效的信道 "%s" 不是一个有效的信道；使用 <1-13> "%s"不是有效的双工值 "%s" 不是有效的处理模块。 "%s" 不是有效十六进制字符 "%s" 不是有效的接口名称 "%s" 不是有效的接口类型 "%s" 不是一个有效的关键字 "%s" 不是有效的种类 "%s" 不是有效的数字 "%s" 不是有效的数字（或超出范围） "%s" 不是有效的隧道密钥 "%s" 不是 "%s" 的有效取值 "%s" 不是 "%s" 模式连接的有效值 "%s" 不是该属性的有效取值 ""%s不允许作为接口名 "%s" 在 bond_mode 里不允许 "%s" 在 fail_mode 里不允许 "%s" 在 lacp 里不允许 "%s" 在 vlan_mode 里不允许 "%s" 和 "%s" 类型不兼容，请修改或删除密钥。 "%s" 无效 "%s" 不是有效的 WEP 密钥（它应该是 5 或 13 个 ASCII 字符） "%s" 不是有效的 WPA PSK "%s" 对 "%s" 选项无效：%s "%s" 无效：属性需要以 "key=value" 的形式指定 "%s" 无效；应提供两至三个字符串 "%s" 无效；请使用 "on"、"off" 或 "ignore" "%s" 无效；使用 <选项>=<值> "%s" 无效，请使用 [%s] 或 [%s] "%s" 无效，请使用 [%s]、[%s] 或 [%s] "%s" 现在是主连接
 "%s" 超出范围 [% "%s" 超出范围 [0, %u] "%s" 长度无效（应为 5 位或 6 位数） "%s" 不是 0 和 %u（包括）之间的数字 "%s" 不是 0 和 %u（包括）之间的数字或是 %u "%s" 不在 [%s] 中 "%s" 和 %s "%s" 不兼容，请先修改密钥或设置正确的 %s。 "%s"选项为空 "%s" 选项在 "%s" 模式里无效 "%s" 选项只能在 "%s=%s" 中使用 "%s" 选项只在 "%s" 模式里有效 "%s" 选项需要是 2 个指数 "%s" 选项需要 "%s" 选项来启用 "%s" 选项需要设置 "%s" 选项 "%s" 选项应该为字符串 "%s" 需要 "%s" 和 "%s" 属性 "%s" 需要设置 "%s" 属性 "%s" 安全需要 "%s" 设置存在 "%s" 安全需要 "%s=%s" 意外的 "%s"：已指定上级。 "%s" 值与 "%s=%s" 不匹配 "%s"：无效的组 ID "%s"：无效的用户 ID "%s::%s" 不是有效的属性名；"%s" 不是 GObject 子类型 "%s=%s" 与 "%s > 0" 不兼容 "%s=%s" 不是 "%s" 的有效配置 "%u" 标记无效；请使用 %s 的组合 "%u"：无效模式 缺少 "--order" 参数 "fqdn-clear-flags" 标志与其他 FQDN 标志不兼容 不能同时设置 "fqdn-no-update" 和 "fqdn-serv-update" 标志 （没有自定义路由） （还未支持动态 WEP……） （还未支持 WPA 企业……） （默认） （无） （未知错误） （未知） ，也不是有效的设置名称 ---[ 主菜单 ]---
goto     [<设置> | <属性>]        :: 转到设置或属性
remove   <设置>[.<属性>] | <属性> :: 移除设置或重置属性值
set      [<设置>.<属性> <值>]     :: 设置属性值
describe [<设置>.<属性>]          :: 描述属性
print    [all | <设置>[.<属性>]]  :: 输出连接
verify   [all | fix]              :: 验证连接
save     [persistent|temporary]   :: 保存连接
activate [<接口名>] [/<ap>|<nsp>] :: 激活连接
back                              :: 转到上层（返回）
help/?   [<命令>]                 :: 输出此帮助
nmcli    <配置选项> <值>          :: nmcli configuration
quit                              :: 退出 nmcli
 ---[ 属性菜单 ]---
set      [<值>]                  :: 设置新值
add      [<值>]                  :: 添加新选项到属性
change                           :: 更改当前值
remove   [<索引> | <选项>]       :: 删除该值
describe                         :: 描述属性
print    [setting | connection]  :: 输出（设置/连接）值
back                             :: 转到上一级
help/?   [<命令>]                :: 输出该帮助或命令描述
quit                             :: 退出 nmcli
 0（无） 0（禁用） 0（无） 6LOWPAN 连接 6LOWPAN 设置 6LoWPAN 802-1x 设置 网络的 802.11 频段。一个 "a" 代表 5GHz 802.11a 或 "bg" 代表 2.4GHz 802.11。这将锁定关联的 Wi-Fi 网络到特定的频段，比如指定了 "a"，设备就不会关联在 2.4GHz 内的相同网络，不管网络设置是否兼容。此设置取决于具体驱动的功能，且可能不是全部的驱动都有效。 802.1X 请求方配置失败 802.1X 请求方已断开连接 802.1X 请求方失败 802.1X 请求方验证时间过长 802.1x 设置要求 "wpa-eap" 密钥管理 802.3ad <隐藏> <隐藏> | %s ===| nmcli 交互式连接编辑器 |=== A (5 GHz) 一个如 "310260" 或 "21601" 的 MCC/MNC 字符串，用来鉴定此连接应用到的指定移动网络运营商。如果给定了，连接将应用到包含给定运营商提供 SIM 卡的 "device-id" 和 "sim-id" 所允许的任何设备。 一个连接不能同时设置 "%s" 和 "%s" "%s" 类型的连接不能有 ovs-interface.type "%s" "%s" 类型的连接不能有 ovs-interface.type "system" 有 "%s" 设置的连接必须是 connection.type "ovs-interface" 类型，但现在是 "%s" 一个带有 "%s" 设置的连接需要是 "%s" 接口类型，而不是 "%s" 有 "%s" 设置的连接必须有个主连接。 具有 "%s" 设置的连接必须将 slave-type 设置为 "%s"。而它是 "%s" 有 "%s" 设置的连接不能有主连接。 有 "%s" 设置的连接需要明确设定 connection.type ovs-interface.type "%s" 类型的连接缺少设置 "ovs-patch" 连接的依赖关系失败 带有 OVS 外部 ID 的键/值对的字典。 包含用户数据的键/值对字典。此数据被网络管理器（NetworkManager）忽略且可被用户随意使用。键只支持严格的 ASCII 格式，但是值可以为长度有限的任意 UTF8 字符串。 检测到重复的 IP 地址 用户可读的连接的唯一标识符，如 "工作 Wi-Fi" 或 "运营商 4G"。 检测为 Wi-Fi 网络一部分的 BSSID 列表（每个 BSSID 格式化为如 "00:11:22:33:44:55" 的 MAC 地址）。网络管理器（NetworkManager）会内部追踪先前见过的 BSSID。此属性仅用于读取和显示网络管理器的 BSSID 列表。您对此属性所作的更改不会保留。 包含 IPv4 目标地址、前缀长度、可选的 IPv4 下一跃点地址、可选的路由跃点数和可选属性的列表。有效的语法为："ip[/prefix] [next-hop] [metric] [attribute=val]...[,ip[/prefix]...]"。示例 "192.0.2.0/24 10.1.1.1 77, 198.51.100.0/24"。 要匹配的驱动程序名称列表。每个元素都是一个 shell 通配符模式。请参阅 NMSettingMatch:interface-name，了解特殊字符"|"、"&"、"!"和"\"如何用于可选和强制匹配以及反转模式。 组/广播加密算法列表，用来阻止连接到那些不使用列表中算法的 Wi-Fi 网络。为了最好的兼容性，可以让此属性留空。每个列表元素可以为 "wep40"、"wep104"、"tkip" 或 "ccmp" 中的一个。 要匹配的接口名称列表。每个元素都是一个 shell 通配符模式。一个元素可以用一个 | 或 & 作为前缀。前者表示该元素是可选的，后者表示它是必须的。如果有任何可选元素，如果至少有一个可选元素匹配，则匹配值为 true（逻辑 OR）。如果有任何强制性元素，那么它们必须全部匹配（逻辑 AND）。默认情况下，一个元素是可选的。这意味着 "foo" 和 "|foo" 的效果是一样的。在 ！（或 &）和特征直接使用 ! 可以进行反转。请注意，"!foo" 和 "&!foo" 的的一个快捷模式。最后，可以在元素的开头（在可选的特殊字符之后）使用反斜杠来转义特殊字符。例如，"&\!a"代表按字面意思匹配 "!a"。 需要匹配的内核命令行参数列表。它可以用来检查一个特定的内核命令行选项是否被设置（或者未被设置，如果前缀为感叹号）。参数必须是单个单词，或者是赋值（即两个单词，用  "=" 分开）。在前一种情况下，内核命令行会搜索单词的原样，或者作为一个赋值的左面部分。在后一种情况下，是寻找左面部分和右面部分匹配的赋值。不支持通配符模式。请参阅 NMSettingMatch:interface-name 了解特殊字符 "|"、"&"、"!" 和 "\" 如何用于可选和强制匹配以及反转模式。 成对加密算法列表，用来阻止连接到那些不使用列表中算法的 Wi-Fi 网络。为了最好的兼容性，可以让此属性留空。每个列表元素可以为 "tkip" 或 "ccmp" 中的一个。 要与设备的 ID_PATH udev 属性匹配的路径列表。ID_PATH 表示设备的拓扑持久路径。它通常包含一个子系统字符串（pci、usb、platform 等）和一个子系统特定的标识符。对于PCI设备，路径的形式是 "pci-$domain:$bus:$device.$function"，其中每个变量是一个十六进制值，例如 "pci-0000:0a:00.0"。设备的路径可以通过 "udevadm info /sys/class/net/$dev | grep ID_PATH=" 或查看 NetworkManager导出的 "path" 属性来获得（"nmcli -f general.path device show"）。列表中的每个元素都是一个 shell 通配符模式。请参阅NMSettingMatch:interface-name，了解特殊字符 "|"、"&"、"!" 和 "\ "如何用于可选和强制匹配以及反转模式。 Wi-Fi 设备的永久 MAC 地址列表，其地址此连接应该从不应用。每个 MAC 地址应给定为标准的十六进制数字和冒号的表示法（比如 "00:11:22:33:44:55"）。 要转发的组地址掩码。通常，范围在 01:80:C2:00:00:00 到 01:80:C2:00:00:0F 内的组地址根据标准不转发。此属性是个 16 位的掩码，每个对应于一个组地址，组地址范围内的地址必须被转发。掩码不能设定了位 0、1 或 2，因为它们用于 STP、MAC 暂停帧和 LACP。 需要密码来连接到 "%s"。 ADSL 网桥上的 RFC 2684 以太网出现问题 基础连接的次级连接失败 "%s" 设为 "%s" 的从连接不能有个 "%s" 设置 包含 DHCPv6 唯一标识符（DUID）的字符串，用于 dhcp 客户端鉴定它自己到 DHCPv6 服务器（RFC 3315）。DUID 携带在客户端标识符选项中。如果属性为十六进制的字符串（"aa:bb:cc"），它被解读为二进制 DUID 并在客户端标识符选项中以不透明值填充。特殊值 "lease" 将重试连接所属租约文件上次使用的 DUID。如果为找到且 "dhclient" 为配置的 dhcp 客户端，DUID 将在系统范围的 dhclient 租约文件中搜索。如果仍为找到 DUID 或使用了其他 dhcp 客户端，将基于 machine-id 生成全局和永久的 DUID-UUID（RFC 6355）。特殊值 "llt" 和 "ll" 将基于设备的当前 MAC 地址生成 LLT 或 LL 类型的 DUID（参阅 RFC 3315）。为了试着提供稳定的 DUID-LLT，时间字段将包含固定时间戳，用于全局（的所有配置集）且保留到磁盘上。特殊值 "stable-llt"、"stable-ll" 和 "stable-uuid" 将生成相应类型的 DUID，衍生自连接的 stable-id 和每个主机的唯一密钥。因此，"stable-ll" 和 "stable-llt" 的链路层地址将是衍生自稳定 id 的生成地址。"stable-llt" 选项中的 DUID-LLT 时间值将在静态的三年时间跨度中选择（区间的上限与用在 "llt" 中的固定时间戳相同）。当属性未设定时，使用 "ipv6.dhcp-duid" 提供的全局值。如果未提供全局值，认定为默认的 "lease" 值。 发送到 DHCP 服务器的字符串，用以确定 DHCP 服务器可能用于自定义 DHCP 租约和选项的本地机器。当属性值为十六进制字符串时，将其解读为二进制的客户端 ID，这种情况下根据 RFC 2132 章节 9.14 首字节被认为是 "type" 字段而剩下的字节可为一个硬件地址（例如 "01:xx:xx:xx:xx:xx:xx" 中 1 是以太网 ARP 类型而其余的是个 MAC 地址）。如果属性不是十六进制字符串，它被视作非硬件地址客户端 ID 且 "type" 字段被设为 0。支持特殊值 "mac" 和 "perm-mac"，其使用设备的当前或永久 MAC 地址来生成类型为以太网类型 (01) 的客户端标识符。当前这些选项仅适用于以太网类型的链路。特殊值 "ipv6-duid" 使用来自 "ipv6.dhcp-duid" 属性的 DUID，作为符合 RFC4361 的客户端标识符。作为 IAID 它使用 "ipv4.dhcp-iaid" 并且在未设定时回落到 "ipv6.dhcp-iaid"。特殊值 "duid" 根据 "ipv4.dhcp-iaid" 生成符合 RFC4361 的客户端标识符，并且使用生成自 /etc/machine-id 散列值的 DUID。支持特殊值 "stable" 基于 stable-id 和每个主机的密钥生成一个类型 0 的客户端标识符（参见 connection.stable-id）。如果未设，使用全局默认值。如果仍未设定，默认值取决于 DHCP 插件。 DHCP 的超时时间，以秒为单位。如果为 0（默认值），则使用全局配置的默认值。如果还没有指定，则使用特定于设备的超时（通常为 45 秒）。设为 2147483647 (MAXINT32) 代表无限大。 身份验证的超时时间。零代表全局默认；如果全局默认未设定，验证超时为 25 秒。 等待 Router Advertisements 的超时时间，单位为秒。如果为 0（默认值），则使用全局配置的默认值。如果仍未指定，则超时时间取决于设备的 sysctl 设置。设置为2147483647（MAXINT32）为无穷大。 用于连接的全局唯一标识符，例如以 libuuid 生成。它应该在连接创建时分配，并且只要连接仍应用到同个网络就不改变。例如，当 "id" 属性或 NMSettingIP4Config 更改时它不应改变；但当 Wi-Fi SSID、移动宽带网络运营商或 "type" 属性改变时它可能需要重新创建。UUIS 必须为如 "2815492f-7e56-435e-b2e9-246bd7cdc664" 的格式（示例，只包含十六进制和 "-"）。 ADSL ADSL 连接 ADSL 连接协议。可为 "pppoa"、"pppoe" 或 "ipoatm"。 AP 隔离只能在 AP 模式下设定 APN ARP ARP 目标 接入点 接入点不支持 802.1x 但设置要求它 接入点不支持 PSK 但设置要求它 接入点未加密但设置指定了安全性 激活 启用连接 激活失败：%s 热备 激活连接详情 Ad-Hoc Ad-Hoc 网络 Ad-Hoc 模式和 802.1x 安全性不兼容 Ad-Hoc 模式和 LEAP 安全性不兼容 Ad-Hoc 模式需要 "none" 或 "wpa-psk" 密钥管理 Ad-Hoc 模式要求 "open" 验证 自适应负载均衡（alb） 自适应传输负载均衡（tlb） 添加 添加... 正在添加新的 "%s" 连接 地址 老化时间 允许 BSD 数据压缩 允许 Deflate 数据压缩 允许控制 Wi-Fi 扫描 允许控制网络连接 允许的验证方法： "%s" 属性允许的值：%s
 8 个布尔值组成的数组，其数组索引对应于用户优先级（0～7）而其值指示对应优先级是否应该传输优先级暂停。 8 个布尔值组成的数组，其数组索引对应于用户优先级（0～7）而其值指示优先级是否可以使用分配到它指定组的全部带宽。 8 个无符号整数值组成的数组，其数组索引对应于用户优先级（0～7）而其值指示分配到该组的链路带宽百分比。允许的值为 0～100，且所有值的总和必须为 100%。 8 个无符号整数值组成的数组，其数组索引对应于用户优先级（0～7）而其值指示优先级组 ID。允许的优先级组 ID 值为 0～7，或 15 表示无限制组。 8 个无符号整数值组成的数组，其数组索引对应于用户优先级（0～7）而其值指示优先级可使用的优先级指定组的带宽百分比。属于同个组的所有优先级百分比总和必须为 100%。 8 个无符号整数值组成的数组，其数组索引对应于用户优先级（0～7）而其值指示该优先级映射的流量等级（0～7）。 字符串数组，用于定义给定用户对此连接的访问权。如果此属性为 NULL 或空，允许所有用户访问此连接；否则只允许在此列表中的用户。当此属性非空时，只有当指定用户之一登录到活动会话时，连接被激活。每个条目的形式为 "[类型]:[ID]:[已保留]"；例如 "user:dcbw:blah"。此时，只允许用户 "user" [类型]。其他任何值被忽略并保留为将来使用。[ID] 是此权限引用的用户名，不能包含冒号 ":" 字符。存在的任何 [已保留] 信息都必须被忽略并保留为将来使用。所有的 [类型]、[ID] 和 [已保留] 都必须为有效的 UTF-8。 检查网络连通用的 http(s) 地址 用于 EAP 验证方法的匿名标识字符串。用作支持不同隧道标识如 EAP-TTLS 的 EAP 类型的未加密标识。 您确定要删除连接 "%s" 吗？ DNS 选项数组的信息包括在 resolv.conf 的 man 5 中。NULL表示未设置选项，保持默认值。在这种情况下，NetworkManager 将使用默认选项。这与空的属性列表不同。目前支持的选项是 "attempts"、"debug"、"edns0"、"inet6"、"ip6-bytestring"、"ip6-dotint"、"ndots"、"no-check-names"、"no-ip6-dotint"、"no-reload"、"no-tld-query"、"rotate"、"single-request"、"single-request-reopen"、"timeout"、"trust-ad"、"use-vc"。只有当配置文件向 resolv.conf 提供名称服务器，并且所有提供名称服务器的配置文件都启用了 "trust-ad" 时，"trust-ad" 设置才会生效。使用缓存 DNS 插件（dnsmasq 或者 systemd-resolved 于 NetworkManager.conf），会自动添加 "edns0" 和 "trust-ad"。 DNS 服务器的 IP 地址数组。 IP 路由数组。 网桥 VLAN 对象阵列。除了这里指定的 VLAN，网桥还可以带有由 bridge.vlan-default-pvid 属性配置的 default-pvid VLAN。在 nmcli 中，VLAN 列表可以使用以下语法指定：$vid [pvid] [untagged] [, $vid [pvid] [untagged]]... 其中 $vid 是一个 1 到 4094 的 id，或是一个由短横线分隔的 id 所代表的范围。 网桥 VLAN 对象阵列。除了这里指定的 VLAN，网桥还可以带有由 bridge.vlan-default-pvid 属性配置的 default-pvid VLAN。在 nmcli 中，VLAN 列表可以使用以下语法指定：$vid [pvid] [untagged] [, $vid [pvid] [untagged]]... 其中 $vid 是一个 1 到 4094 的 id，或是一个由短横线分隔的 id 所代表的范围。 必须拒绝 DHCP 提供的服务器数组。此属性可用于避免从错误配置或非授权的服务器获取租期。对于 DHCPv4，每个元素都必须为 IPv4 地址，可跟随一个斜线和前缀长度（例如 "192.168.122.0/24"）。此属性当前未实现于 DHCPv6。 虚拟功能描述符数组。每个虚拟功能描述符都是映射属性名到 GVariant 值的字典。"index" 条目为每个虚拟功能的必填项。当表示为字符串时，虚拟功能的格式为："INDEX [ATTR=VALUE[ ATTR=VALUE]...]"。例如："2 mac=00:11:22:33:44:55 spoof-check=true"。多个虚拟功能之间使用半角逗号作为分隔符。当前支持以下属性：mac、spoof-check、trust、min-tx-rate、max-tx-rate、vlans。"vlans" 属性表示为半角分号分隔的 VLAN 描述符列表，其中每个描述符的格式为 "ID[.PRIORITY[.PROTO]]"。PROTO 可以是用于 802.1Q（默认）的 "q" 或用于 802.1ad 的 "ad"。 每次都询问这个密码 验证 无线网络要求身份验证 自动 IP（AutoIP）服务出错 自动 IP（AutoIP）服务失败 自动 IP（AutoIP）服务无法启动 自动 自动（仅 DHCP） 自动连接 有效属性：%s
 有效设置：%s
 对所有用户有效 B/G (2.4 GHz) 绑定 网桥 网桥端口 BSSID 返回 错误的 "%s" 选项： 连接的基础类型。对于硬件相关的连接，应包含硬件类型特定设置的设置名称（例如 "802-3-ethernet" 或 "802-11-wireless" 或 "bluetooth"，等等），而对于非硬件相关的连接如 VPN 或其他的，应包含该设置类型的设置名称（例如 "vpn" 或 "bridge"，等等）。 蓝牙 蓝牙设备地址 绑定 绑定连接 绑定连接 %d 绑定设备 绑定（Bonding）模式。"active-backup"、"balance-slb" 或 "balance-tcp" 之一。 绑定监控模式 网桥 网桥 VLANs %d 和 %d 没有根据生序 vid 进行排序 网桥连接 网桥连接 %d 网桥设备 网桥端口 广播 串口通信的字节宽度。以 "8n1" 中的 8 为例。 CA 证书必须是 X.509 格式 CDMA 连接 CDMA 移动宽带连接 CHAP 无法更改连接类型 取消 无法创建 "%s"：%s 没有 "%s" 无法设置 "%s" 载波/链路已更改 整数文件为空 证书密码 信道 信道 (<default|0-26>) 已位于要加入的 Mesh 网络信道。 克隆的 MAC 地址 [无] 克隆的 MAC 地址 关闭 %s 失败：%s
 配置目录位置 配置文件位置 配置 SLAAC 的 IPv6 隐私扩展，描述于 RFC4941。如果启用，它让内核通过修改 EUI-64 生成临时的 IPv6 地址附加到从 MAC 地址生成的公共地址上。此可以增强隐私性，但另一方面也可能在有些应用程序上引起问题。允许的值有：-1，未知；0：禁用；1：启用（首选公共地址）；2：启用（首选临时地址）。把单个连接的设置设为 "-1" 表示其回落到全局配置 "ipv6.ip6-privacy"。如果全局配置也为配置或设为 "-1"，回落到读取 "/proc/sys/net/ipv6/conf/default/use_tempaddr" 的值。注意此设置与固定隐私地址不同，后者可通过 "addr-gen-mode" 属性的 "stable-privacy" 设置启用，可作为避免 IPv6 地址追踪的另一种方法。 配置用于 draft-chown-6man-tokenised-ipv6-identifiers-02 IPv6 令牌化接口标识符的令牌。对 eui64 addr-gen-mode 有用。 配置 AP 隔离，可以阻止连接到此 AP 的无线设备之间的通信。此属性只能在接口配置为 AP 模式时，设定为一个不同于 NM_TERNARY_DEFAULT (-1) 的值。如果设为 NM_TERNARY_TRUE (1)，设备就不能互相通信。这样可以增加设备的安全性，因为它可以保护设备不受该网络下其他客户端的攻击。与此同时，它也阻止了设备访问同一无线网络下的资源，如文件共享、打印机等等。如果设为 NM_TERNARY_FALSE (0)，设备可以相互通信。设为 NM_TERNARY_DEFAULT (-1) 时，使用全局默认值；全局默认值未指定的情况下则假定为 NM_TERNARY_FALSE (0)。 已连接 正在连接 正在连接... 连接 "%s" (%s) 已成功添加。
 成功删除连接 "%s" (%s)。
 连接 "%s" (%s) 已成功修改。
 连接 "%s" (%s) 已成功保存。
 成功地更新了连接 "%s" (%s)。
 错误：停用连接 "%s" 失败：%s
 成功停用连接 "%s"（D-Bus 活动路径：%s）
 连接（名称、UUID 或路径）： 连接已经激活 连接配置集详情 通过受保护的 Wi-Fi 网络共享连接 通过开放 Wi-Fi 网络共享连接 连接已成功激活（%s）（D-Bus 活动路径：%s）
 连接已成功激活（D-Bus 活动路径：%s）
 成功重新应用连接到设备 "%s"。
 连接（名称、UUID 或路径）： 连接（名称、UUID、路径或活动路径）： 连接性 连接性现在是 "%s"
 服务器域名的约束。如果设定，在内部 "阶段 2" 验证过程中，在这个列表中的 FQDN 作为后缀来匹配由验证服务器提供的证书的 dNSName 元素需求。如果找到了匹配的 dNSName，此约束被满足。如果没有 dNSName 值，此约束使用同样的后缀比较来匹配 SubjectName CN。从版本 1.24 开始，可以使用 ";" 作为分隔符来提供包括多个有效 FQDN 的列表。 服务器域名的约束。如果设定，在这个列表中的 FQDN 作为后缀来匹配由验证服务器提供的证书的 dNSName 元素需求。如果找到了匹配的 dNSName，此约束被满足。如果没有 dNSName 值，此约束使用同样的后缀比较来匹配 SubjectName CN。从版本 1.24 开始，可以使用 ";" 作为分隔符来提供包括多个有效 FQDN 的列表。 服务器域名的约束。如果设定，在内部 "阶段2" 验证过程中，在这个列表中的 FQDN 用来匹配由验证服务器提供的证书的 dNSName 元素需求。如果找到了匹配的 dNSName，此约束被满足。如果没有 dNSName 值，此约束使用同样的比较方法来匹配 SubjectName CN。可以使用 ";" 作为分隔符来提供包括多个有效 FQDN 的列表。 服务器域名的约束。如果设定，在这个列表中的 FQDN 用来匹配由验证服务器提供的证书的 dNSName 元素需求。如果找到了匹配的 dNSName，此约束被满足。如果没有 dNSName 值，此约束使用同样的比较方法来匹配 SubjectName CN。可以使用 ";" 作为分隔符来提供包括多个有效 FQDN 的列表。 包含 "phase2-auth" 或 "phase2-autheap" 属性指定的 EAP 方法所使用的 "阶段2" CA 证书，证书数据由 "scheme" 指定；当前支持三种方案：blob、path 和 pkcs#11 URL。当使用 blob 时，此属性应设定为证书的 DER 编码数据。当使用 path 时，此属性应设定为证书的完整 UTF-8 编码路径，以字符串 "file://" 为前缀并以终止 NUL 字节结束。此属性可以被取消设定，即使 EAP 方法支持 CA 证书，但这将可能会受到中间人攻击，因此不推荐。请注意，启用 NMSetting8021x:system-ca-certs 将会覆盖这个设置来使用内建的路径，如果内建路径不是一个目录。 包含 "phase2-auth" 或 "phase2-autheap" 属性指定的 EAP 方法所使用的 "phase 2" 客户端证书，如果其使用了。证书数据用 "scheme" 指定；当前支持两种方案：比特块（blob）和路径。当使用比特块方案（与 NM 0.7.x 后向兼容）时，此属性应设定为证书的 DER 编码数据。当使用路径方案时，此属性应设定为证书的完整 UTF-8 编码路径，以字符串 "file://" 为前缀并以终止 NUL 字节结束。此属性可不设定，即使 EAP 方法支持 CA 证书，但这将允许中间人攻击因此不推荐。 包含如果 "phase2-auth" 或 "phase2-autheap" 属性设为 "tls" 时的 "阶段 2" 内部私钥。密钥数据用 "scheme" 指定；当前支持两种方案：比特块（blob）和路径。当使用比特块方案时，此属性应设定为私钥加密过的 PEM 编码数据。当使用路径方案时，此属性应设定为私钥的完整 UTF-8 编码路径，以字符串 "file://" 为前缀并以终止 NUL 字节结束。当使用 PKCS#12 格式私钥和比特块方案时，此属性应设为 PKCS#12 数据且 "phase2-private-key-password" 属性必须设为用于解密 PKCS#12 证书和私钥的密码。当使用 PKCS#12 文件和路径方案时，此属性应设为私钥的完整 UTF-8 编码路径，以字符串 "file://" 为前缀并以终止 NUL 字节结束；而与 blob 方案同用时，"phase2-private-key-password" 属性必须设为用于解码 PKCS#12 私钥和证书的密码。 包含 "eap" 属性指定的 EAP 方法所使用的 CA 证书，证书数据由 "scheme" 指定；当前支持三种方案：blob、path 和 pkcs#11 URL。当使用 blob 时，此属性应设定为证书的 DER 编码数据。当使用 path 时，此属性应设定为证书的完整 UTF-8 编码路径，以字符串 "file://" 为前缀并以终止 NUL 字节结束。此属性可以被取消设定，即使 EAP 方法支持 CA 证书，但这将可能会受到中间人攻击，因此不推荐。请注意，启用 NMSetting8021x:system-ca-certs 将会覆盖这个设置来使用内建的路径，如果内建路径不是一个目录。 包含 "eap" 属性指定的 EAP 方法所使用的客户端证书，如果其使用了。证书数据用 "scheme" 指定；当前支持两种方案：比特块（blob）和路径。当使用比特块方案（与 NM 0.7.x 后向兼容）时，此属性应设定为证书的 DER 编码数据。当使用路径方案时，此属性应设定为证书的完整 UTF-8 编码路径，以字符串 "file://" 为前缀并以终止 NUL 字节结束。 包含如果 "eap" 属性设为 "tls" 时的私钥。私钥数据用 "scheme" 指定；当前支持两种方案：比特块（blob）和路径。当使用比特块方案时，此属性应设为私钥加密过的 PEM 编码数据。当使用路径方案时，此属性应设定为私钥的完整 UTF-8 编码路径，以字符串 "file://" 为前缀并以终止 NUL 字节结束。当使用 PKCS#12 格式私钥和比特块方案时，此属性应设为 PKCS#12 数据且 "private-key-password" 属性必须设为用于解密 PKCS#12 证书和私钥的密码。当使用 PKCS#12 文件和路径方案时，此属性应设为私钥的完整 UTF-8 编码路径，以字符串 "file://" 为前缀并以终止 NUL 字节结束；而与比特块方案同用时，"private-key-password" 属性必须设为用于解码 PKCS#12 私钥和证书的密码。警告："private-key" 不是 "secret" 属性，因此使用比特块方案时未加密的私钥数据可能会被非特权用户读取。私钥总是应该用私钥密码加密以阻止对未加密私钥数据的未授权访问。 控制在网桥中是否启用 VLAN 过滤。 控制 WEP 密钥的转义。允许的值有 NM_WEP_KEY_TYPE_KEY (1)，此情况下密钥要么是 10 或 26 个字符长度的十六进制字符串，要么是 5 或 13 个字符长度的 ASCII 密码；还有 NM_WEP_KEY_TYPE_PASSPHRASE (2)，此情况下密码以字符串提供，并使用事实上的 MD5 方法散列以衍生实际的 WEP 密钥。 控制是否为此网桥启用 IGMP 监听。注意如果散列冲突监听会被自动禁用，系统可能拒绝启用该功能直到冲突解决。 控制是否为此网桥启用生成树协议（STP）。 控制是否启用每个 VLAN 的统计核算。 Cookie 对应于 teamd mcast_rejoin.count。 对应于 teamd mcast_rejoin.interval。 对应于 teamd notify_peers.count。 对应于 teamd notify_peers.interval。 对应于 teamd ports.PORTIFNAME.lacp_key。 对应于 teamd ports.PORTIFNAME.lacp_prio。 对应于 teamd ports.PORTIFNAME.prio。 对应于 teamd ports.PORTIFNAME.queue_id。设定为 -1 时表示参数从 json 配置忽略。 对应于 teamd ports.PORTIFNAME.sticky。 对应于 teamd runner.active。 对应于 teamd runner.agg_select_policy。 对应于 teamd runner.fast_rate。 对应于 teamd runner.hwaddr_policy。 对应于 teamd runner.min_ports。 对应于 teamd runner.name。允许的值为 "roundrobin"、"broadcast"、"activebackup"、 "loadbalance"、"lacp"、"random"。 对应于 teamd runner.sys_prio。 对应于 teamd runner.tx_balancer.interval。 对应于 teamd runner.tx_balancer.name。 对应于 teamd runner.tx_hash。 无法激活连接：%s 无法联系网络管理器：%s
 无法创建软件链路 无法为类型 "%s" 的连接 "%s" 创建编辑器。 无法为无效的连接 "%s" 创建编辑器。 无法创建临时文件：%s 无法设为守护进程：%s [错误 %u]
 无法取消激活连接：%s 无法解码私钥。 无法删除连接 "%s"：%s 无法找到 "%s" 二进制文件 找不到 uid 的任何会话 ID %d 无法生成随机数据。 无法加载文件 "%s"
 无法解析参数 无法重新读取文件：%s 无法检索会话ID：%s 无法解码 PKCS#12 文件：%d 无法解码 PKCS#12 文件：%s 无法解码 PKCS#8 文件：%s 无法解码证书：%d 无法解码证书：%s 无法初始化 PKCS#12 解码器：%d 无法初始化 PKCS#12 解码器：%s 无法初始化 PKCS#8 解码器：%s 无法初始 slot 无法校验 PKCS#12 文件：%d 无法校验 PKCS#12 文件：%s 创建 当前 nmcli 配置：
 此连接用于连接到它网络的 VPN 插件的 D-Bus 服务名。例如 org.freedesktop.NetworkManager.vpnc 用于 vpnc 插件。 DCB 或 FCoE 设置失败 DCB 设置 DHCP 任意广播 MAC 地址 [无] DHCP 客户端错误 DHCP 客户端失败 DHCP 客户端启动失败 DHCP 选项不能多于 255 个字符 DHCPv6 不支持 E（编码）FQDN 标志 DNS 服务器 DNS 服务器优先级。此设置指定 DNS 服务器的相关优先级。数值越低优先级越高。负值具有排除其他具有高优先级数值的配置的特殊效果；所以存在至少一个负值优先级的情况下，连接中只有具有最低优先级数值的的 DNS 服务器会被使用。为了避免所有的 DNS 泄漏，设定应要使用的配置集的优先级为所有活动连接配置集里最小的负值。零则选择全局配置的默认值。如果后者也缺失或同为零，则 VPN（包括 WireGuard）默认为 50 ，其他连接默认为 100。注意此优先级用于为多个活动连接排序 DNS 设置。它不会对同个连接配置集中的多个 DNS 服务器进行明确选择。当多个设备配置了同样的优先级，VPN 会被首先考虑，然后是带有最高优先级（最低的跃点数）默认路由的设备，然后是所有其他设备。当使用 dns=default 时，更高优先级的服务器将在 resolv.conf 里的更顶部。要让给定服务器优先于同连接内的另一服务器，只要以期望的顺序指定它们就行。注意通常解析器按照 /etc/resolv.conf 里列出的顺序尝试解析其中的名称服务器，并在失败时继续处理列表中的下一个服务器。参见 dns-options 设置的 "rotate" 选项示例。如果存在任一负数的 DNS 优先级，那么设备中只有具有最低优先级数值的名称服务器会被考虑。当使用支持条件转发或分割的 DNS（以 dns=dnsmasq 或 dns=systemd-resolved 设置）时，每个连接用于查询它搜索列表中的域。搜索域决定了要询问的名称服务器以及 DNS 优先级，后者用于根据域对名称服务器进行优先级排序。未在任何搜索列表中的域查询会由具有 "~." 特殊通配符的域进行路由，并自动添加到默认路由的连接上（也可以手动添加）。当多个连接指定了同个域时，拥有最高优先级（最低的数值）的那个连接将获选。如果另一接口配置了一个子域，则无论优先级如何它都会被接受，除非其他接口的父域名具有负的优先级，这样子域就会被盖过。使用分割 DNS，通过适当配置 DNS 优先级和搜索域可以避免意外的 DNS 泄漏，这样就只有所需接口的名称服务器会被配置。 DSL DSL 身份验证 DSL 连接 %d DUN 连接必须包含 GSM 或 CDMA 设置 DUN 已请求，但蓝牙设备不支持 DUN 数据报 停用 删除 目标 检测到设置了 "%s" 和端口类型为 "%s" 的从连接。"%s" 应该设置为 "%s" 设备 未找到设备 "%s" 成功用 "%s%s" 激活了设备 ""。
 成功断开设备 "%s"。
 成功移除设备 "%s"。
 设备 LLDP 邻居 设备 MAC（%s）被连接列入了黑名单。 设备详情 用户或客户端断开了设备连接 设备现在已托管 设备现在未托管 VPN 插件特定数据的键/值对字典。键和值都必须为字符串。 VPN 插件指定如密码或密钥的密钥（secret）的键/值对字典。键和值都必须为字符串。 绑定（bonding）选项的键/值对字典。键和值都必须为字符串。选项名必须只能包含字母数字字符（示例 [a-zA-Z0-9]）。 禁用 已被用户断开连接 您是否也要清除 "%s"？[yes]： 您是否也将 "%s" 设为 "%s"？[yes]： 您要移除它们吗？[yes]： 不成为守护进程 不成为守护进程，并向标准错误打印日志 不输出任何结果 虚拟 虚拟连接 虚拟设置 动态 WEP（802.1x） 动态 WEP 要求 "ieee8021x" 密钥管理 动态 WEP 要求 "open" 验证 动态 WEP 要求 802.1x 设置 EAP EAP 密钥管理需要 "%s" 设置存在 以太网 编辑 "%s" 值： 编辑连接 编辑连接 编辑... 正在编辑已有的连接 "%s"："%s" 编辑器失败：%s 出口优先级映射 [无] 拨号网络连接时使用 "dun"，或者支持 NAP 配置集设备的个人区域网络连接时使用 "panu"。 启用 IGMP 监听 启用 STP（生成树协议） 启用或禁用 RSTP。 启用或禁用 STP。 启用或禁用 Wi-Fi 设备 启用或禁用 WiMAX 移动宽带设备 启用或禁用连接性检查 启用或禁用设备统计 启用或禁用移动宽带设备 启用或禁用多播监听。 启用或禁用网桥发送多播查询。如果没有指定，则禁用该选项。 启用或禁用系统联网 启用策略路由（源路由）并在添加路由时设定路由表。此属性影响所有的路由，包括设备路由、IPv4LL、DHCP、SLAAC、默认路由和静态路由。但请注意静态路由可以通过明确地指定非零的路由表来自己覆盖掉设置。如果表设置保留为零，它有权被全局配置覆盖。如果在应用全局配置值后属性仍为零，对此连接的地址族禁用策略路由。禁用策略路由意味着网络管理器（NetworkManager）将添加所有路由到主表（除了明确配置了不同路由表的静态路由）。另外，网络管理器将不会从表中删除任何外部路由，除了主路由。这是为了给用网络管理器之外工具管理路由表的用户保持后向兼容性。 启用或禁用端口的 "hairpin mode"，其允许从接收帧的端口发回帧。 当 "eap" 属性里的 EAP 方法指定为 FAST 时，启用或禁用 EAP-FAST 凭据的行内设置。可识别的值有 "0"（禁用）、"1"（允许未验证的设置）、"2"（允许验证的设置）和 "3"（验证和未验证的设置都允许）。详情请见 wpa_supplicant 文档。 ADSL 连接的封装。可以是 "vcmux" 或 "llc"。 增强型开放（OWE） 输入 "%s" 值： 输入 IPv4 地址列表，格式为：
  ip[/prefix], ip[/prefix],...
缺少前缀则默认为 32。

示例：192.168.1.5/24, 10.0.0.11/24
 输入 DNS 服务器的 IPv4 地址列表。

示例：8.8.8.8, 8.8.4.4
 输入 IPv4 路由列表，格式为：
  ip[/prefix] [next-hop] [metric],...
缺少前缀则默认为 32。
缺少 next-hop 则默认为 0.0.0.0。
缺少跃点数则使用默认值（NM/kernel 将设置默认值）。

示例：192.168.2.0/24 192.168.2.1 3, 10.1.0.0/16 10.0.0.254
      10.1.2.0/24
 使用以下格式输入一组 IPv4 路由规则：
  priority [prio] [from [src]] [to [dst]], ,...

 输入 IPv6 地址列表，格式为：
  ip[/prefix], ip[/prefix],...
缺少前缀则默认为 128。

示例：2607:f0d0:1002:51::4/64, 1050:0:0:0:5:600:300c:326b
 输入 DNS 服务器的 IPv6 地址列表。如果 IPv6 配置方法为 "auto"，这些 DNS 服务器将附加到哪些自动配置返回的地址中（如果有）。DNS 服务器不能使用 "shared" 或者 "link-local" IPv6 配置方法，因为它们不是上游网络。在所有其他 IPv6 配置方法中，这些 DNS 服务器可作为这个连接的唯一 DNS 服务器。

示例：2607:f0d0:1002:51::4, 2607:f0d0:1002:51::1
 输入 IPv6 路由列表，格式为：
  ip[/prefix] [next-hop] [metric],...
缺少前缀则默认为 128。
缺少 next-hop 则默认为 "::"。
缺少跃点数则使用默认值（NM/kernel 将设置默认值）。

示例：2001:db8:beef:2::/64 2001:db8:beef::2, 2001:db8:beef:3::/64 2001:db8:beef::3 2
      abbe::/64 55
 使用以下格式输入一组 IPv6 路由规则：
  priority [prio] [from [src]] [to [dst]], ,...

 输入 S/390 选项列表，格式为：
  option = <值>, option = <值>,...
有效选项为：%s
 输入绑定选项列表，格式为：
  option = <值>, option = <值>,... 
有效选项为：%s
"mode" 可以是一个名称或数字:
balance-rr    = 0
active-backup = 1
balance-xor   = 2
broadcast     = 3
802.3ad       = 4
balance-tlb   = 5
balance-alb   = 6

例如：mode=2,miimon=120
 输入链路监视器列表，其格式为键值是 teamd 属性的字典。字典对的形式为：键=值，且字典对以空格 " " 分隔。字典间以 "," 分隔。
在字典里允许或需要的键根据链路监视器的类型改变，而所有链路监视器的唯一共同属性是 "name"*，其定义了指定的链路监视器。

适用于 "ethtool" 链路监视器的属性有：
  "delay-up"、"delay-down"

适用于 "nsna_ping" 链路监视器的属性有：
  "init-wait"、"interval"、"missed-max"、"target-host"*

适用于 "arp_ping" 链路监视器的属性除了包含 "nsna_ping" 下的所有属性还有：
  "source-host"*、"validate-active"、"validate-inactive"、"send-always"。

带有 "*" 标记的属性为必填的。

示例：
   name=arp_ping source-host=172.16.1.1 target-host=172.16.1.254, name=ethtool delay-up=3
 输入子通道列表（用逗号或者空格分开）。

示例：0.0.0e20 0.0.0e21 0.0.0e22
 输入用户权限列表。这个列表的用户名格式为：
  [user:]<用户名 1>, [user:]<用户名 2>,... 
使用逗号或者空格将名称分开。

例如：alice bob charlie
 输入的值表示连接是否有数据配额、使用成本或其他限制。
可接受的选项是：
"true"、"yes"、"on"，设置连接为计算流量的
"false"、"no"、"off"，设置连接为不计流量的
"unknown"，让网络管理器（NetworkManager）使用一些启发式算法来选择值
 输入十六进制值列表。
可使用两种格式：
(a) 十六进制数字字符串，每两个数字代表一个字节。
(b) 用空格分开的采用十六进制数字写入的字节（选项有0x/0X 前缀以及自选的 0 开头）。

例如：ab0455a6ea3a74C2
      ab 4 55 0xa6 ea 3a 74 C2
 输入连接类型： 输入 CA 证书的文件路径（前缀可选择 file://）。
  [file://]<文件路径>
请注意，nmcli 不支持将证书指定为原始比特块（blob）数据。
示例：/home/cimrman/cacert.crt
 输入内部验证的 CA 证书的文件路径（前缀可选择 file://）。
  [file://]<文件路径>
请注意，nmcli 不支持将证书指定为原始比特块（blob）数据。
示例：/home/cimrman/ca-zweite-phase.crt
 输入客户证书的文件路径（前缀可选择 file://）。
  [file://]<文件路径>
请注意，nmcli 不支持将证书指定为原始比特块（blob）数据。
示例：/home/cimrman/jara.crt
 输入内部验证的客户证书的文件路径（前缀可选择 file://）。
  [file://]<文件路径>
请注意，nmcli 不支持将证书指定为原始比特块（blob）数据。
示例：/home/cimrman/jara-zweite-phase.crt
 输入私有密钥和密钥密码的路径（如果还没有设置）：
  [file://]<文件路径> [<密码>]
请注意，nmcli 不支持将私有密钥指定为原始比特块（blob）数据。
示例：/home/cimrman/jara-priv-key Dardanely
 输入当这个连接激活时应该被激活的次级连接。连接可用 UUID 或 ID（名称）指定。nmcli
自动将名称地转换为 UUID。请注意，目前网络管理器（NetworkManager）只支持将 VPN 作为次级连接。
这些输入项可用逗号或空格隔开。

示例：private-openvpn, fe6ba5d8-c2fc-4aae-b2e3-97efddd8d9a7
 输入 WEP 密钥类型。可接受的值为：0 或者 unknown、1 或者 key, 以及 2 或者 passphrase。
 初始化证书数据出错：%s 读取 nmcli 输出时出错：%s
 更新 %s 的密钥时出错：%s
 写入 nmcli 输出时出错：%s
 错误：%s
 错误：%s - 没有这样的连接配置集。 错误：缺少 %s 参数。 错误：%s 属性，也不是设置名称。
 错误：%s。 错误：%s。
 错误：%s：%s。 错误：缺少 "%s" 参数。 错误：需要 "%s" 参数。 错误："%s" 不能重复。 错误："%s" 不明确（%s.%s 或 %s.%s）。 错误："%s" 不是 "%s" 选项的有效参数。 错误："%s" 不是有效的监视模式；使用 "%s" 或 "%s"。
 错误："%s" 不是有效的超时时间。 错误："%s" 不是活动的连接。
 错误："%s" 不是 "%s" 选项的有效参数。 错误：设置 "%s" 在连接里未提供。
 错误："--fields" 值 "%s" 在此无效（允许的字段：%s） 错误："autoconnect"：%s。 错误："bt-type"："%s" 无效；使用 [%s, %s, %s (%s), %s]。 错误："connection show"：%s 错误："device lldp list"：%s 错误："device show"：%s 错误："dev status"：%s 错误："device wifi"：%s 错误：需要 "file" 参数。 错误："常规日志"：%s 错误："常规权限"：%s 错误："managed"：%s。 错误："monitor" 命令 "%s" 无效。 错误："networking" 命令 "%s" 无效。 错误："save"：%s。 错误：需要 "type" 参数。 错误：缺少 <新名称> 参数。 错误：缺少 <设置>.<属性> 参数。 错误：未找到 bssid 为 "%s" 的接入点。 错误：需要参数 "%s" 但提供的是 "%s"。 错误：要连接的 BSSID (%s) 与 bssid 参数 (%s) 不同。 错误：无法激活连接：%s。
 错误：连接 "%s" 存在但属性不匹配。 错误：连接激活失败。
 错误：连接激活失败：%s 错误：连接激活失败：(%d) %s。
 错误：连接删除失败：%s
 错误：无法创建 NMClient 对象：%s
 错误：无法创建 NMClient 对象：%s。 错误：删除设备 "%s" (%s) 失败：%s
 错误：断开设备 "%s" (%s) 的连接失败：%s
 错误：设备 "%s" 不是 Wi-Fi 设备。 错误：没有找到设备 "%s"。 错误：没有找到设备 "%s"。
 错误：设备 "%s" 既不支持 AP 也不支持 Ad-Hoc 模式。 错误：设备 "%s" 没有被识别为 Wi-Fi 设备，请检查网络管理器（NetworkManager）的 Wi-Fi 插件。 错误：激活设备失败：%s 错误：激活 "%s" (%s) 连接失败：%s
 错误：激活连接失败：%s 错误：添加 "%s" 连接失败：%s 错误：添加/激活新连接失败：%s 错误：修改连接 "%s" 失败：%s 错误：保存 "%s" (%s) 连接失败：%s
 错误：扫描隐藏的 SSID 失败：%s。 错误：建立 Wi-Fi 热点失败：%s 错误：无效的 "password"：%s。 错误：网络管理器（NetworkManager）未运行。 错误：未发现 Wi-Fi 设备。 错误：未找到 BSSID 为 "%s" 的接入点。 错误：未提供参数。 错误：未指定连接。 错误：没有指定接口。 错误：未发现 SSID 为 "%s" 的网络。 错误：未指定属性。 错误：选项 "%s" 未知，尝试 "nmcli -help"。 错误：选项 "--pretty" 与 "--terse" 相互排斥。 错误：第二次指定了选项 "--pretty"。 错误：选项 "--terse" 与 "--pretty" 相互排斥。 错误：第二次指定了选项 "--terse"。 错误：参数 "%s" 不是 SSID 或 BSSID。 错误：从设备 "%s" (%s) 读取已应用的连接失败：%s 错误：重新应用连接到 "%s" (%s) 失败：%s 错误：缺少 SSID/BSSID。 错误：超时时间 %d 秒已到。 错误：超时时间已到（%d 秒） 错误：保存 "%s" (%s) 连接超时
 错误：意外参数 "%s" 错误：未知连接 "%s"。 错误：不能理解参数 "%s"。试下换成传递 --help 参数。 错误：错误的连接类型：%s 错误：band 参数值 "%s" 无效，请使用 "a" 或 "bg"。 错误：bssid 参数值"%s"为无效 BSSID。 错误：无法删除未知连接：%s。 错误：band "%s" 的 channel "%s" 无效。 错误：channal 也需要 band。 错误：连接还未保存。先输入 "save"。
 错误：连接是无效的：%s
 错误：连接验证失败：%s。
 错误：额外参数 "%s"。 错误：不允许的额外参数："%s"。 错误：%s %s.%s 失败：%s。 错误：创建临时文件 %s 失败。 错误：导出 "%s" 失败：%s。 错误：查找用于 %s 的 VPN 插件失败。 错误：导入 "%s" 失败失败失败失败失败失败失败失败失败失败失败：%s。 错误：加载 VPN 插件失败：%s。 错误：加载连接失败：%s。 错误：读取临时文件 "%s" 失败：%s。 错误：重新加载连接失败：%s。 错误：重新加载失败：%s 错误：移除 "%s" 的值失败：%s
 错误：设置 "%s" 属性失败：%s
 错误：设置 Wi-Fi radio 失败：%s 错误：设置主机名失败：%s 错误：设置日志失败：%s 错误：设置联网失败：%s 错误：无效的 "%s" 参数："%s"（使用 on/off）。 错误：无效的 <设置>.<属性> "%s"。 错误：无效的参数 "%s"
 错误：无效的连接类型；%s
 错误：无效的连接类型；%s。 错误：无效的额外参数 "%s"。 错误：无效或不允许的设置 "%s"：%s。 错误：无效的属性 "%s"：%s。 错误：无效的属性：%s
 错误：无效的属性：%s%s
 错误：无效的属性：%s，也不是有效的设置名称。
 错误：无效的重新加载标志" %s"。允许的标志是：%s 错误：无效的重新扫描参数："%s" 未在 [auto, no, yes] 之中 错误：无效的设置参数 "%s"。 错误：无效的设置参数 "%s"；有效的为 [%s]
 错误：无效的设置名称；%s
 错误：无效的从属类型；%s。 错误：需要主连接 错误："%s" 选项缺少参数。 错误：缺少参数。试下传递 --help 参数。 错误：缺少 "%s" 属性的设置
 错误：缺少设置。 错误：nmcli 被信号 %s (%d) 终止了 错误：未提供活动连接。 错误：未给定参数：有效的为 [%s]
 错误：未选择设置；有效的为 [%s]
 错误：未找到所有的活动连接。 错误：未删除所有的连接。 错误：未找到所有连接。 错误：未删除所有设备。 错误：未断开所有设备的连接。 错误：未找到所有设备。 错误：只能提供 "id"、"filename"、"uuid" 或 "path" 之一。 错误：只允许使用这些字段：%s 错误：openconnect 失败，信号为 %d
 错误：openconnect 失败，状态为 %d
 错误：openconnect 失败：%s 错误：openconnect 失败：%s
 错误：polkit 代理失败：%s
 错误：polkit 代理初始化失败：%s 错误：属性 %s
 错误：属性 "%s" 是未知的。 错误：save-confirmation：%s
 错误：密钥（secret）代理初始化失败 错误：设置 "%s" 是必填的而且无法移除。 错误：show-secrets：%s
 错误：SSID 太长。 错误：status-line：%s
 错误：连接不是 VPN。 错误：创建 NMClient 对象时超时
 错误：未知的额外参数："%s"。 错误：未知的设置 "%s"
 错误：未知的设置："%s"
 错误：需要 "%s" 参数的值。 错误：缺少 "%s" 的值。 错误：wep-key-type 参数值 "%s" 无效，请使用 "key" 或 "phrase"。 以太网 以太网连接 %d 以太网设备 Ethtool 设置 如果网络管理器未运行或连接则立即退出 期望 "%s" 后更随换行符
 期望一个 "%s" 的值
 期望 "%s" 后更随空白
 如果连接可以用提供设置服务的 D-Bus 接口以正确的权限来修改，为 FALSE；如果连接为只读且无法修改，为 TRUE。 FQDN 标志需要 FQDN 集 配置 SR-IOV 参数失败 创建 WireGuard 连接失败：%s 创建与子进程通讯的管道失败：%s
 无法解码 PKCS#8 私钥。 无法解码证书。 解密私钥失败。 解密私钥失败：%d。 解密私钥失败：%s（%s） 解密私钥失败：解密后的数据太大。 解密私钥失败：意外的填充长度。 确定 AP 安全信息失败 复制与子进程通讯的管道失败：%s
 加密数据失败：%s（%s） 加密失败：%d。 结束解密私钥失败：%d。 无法找到预期的 PKCS#8 结束标记"%s"。 无法找到预期的 PKCS#8 起始标记。 无法找到预期的 TSS 结束标记 "%s"。 无法找到预期的 TSS 起始标记。 fork 通讯子进程失败：%s
 初始化加密引擎失败。 初始化加密引擎失败：%d。 初始化解密计算内容失败：%s（%s） 初始化解密计算插槽失败。 初始化解密环境失败。 初始化加密计算内容失败：%s（%s） 初始化加密计算插槽空间失败。 初始化加密内容失败。 读取配置失败：%s
 识别证书失败 注册请求的网络失败 无法选择指定的 APN 为解密设置初始向量失败。 为加密设置初始向量失败。 为解密设置对称密钥失败。 为加密设置对称密钥失败。 要导入的文件： DHCP 主机名和 FQDN 的标志。当前，此属性仅包含用于控制在 DHCP FQDN 选项中设置的 FQDN 标志的标志。支持的 FQDN 标志是有 NM_DHCP_HOSTNAME_FLAG_FQDN_SERV_UPDATE (0x1)、NM_DHCP_HOSTNAME_FLAG_FQDN_ENCODED (0x2) 和 NM_DHCP_HOSTNAME_FLAG_FQDN_NO_UPDATE (0x4)。如果未设置 FQDN 标志并且设置了NM_DHCP_HOSTNAME_FLAG_FQDN_CLEAR_FLAGS (0x8)，则 DHCP FQDN 选项将不包含标志。否则，如果 FQDN 标志和 NM_DHCP_HOSTNAME_FLAG_FQDN_CLEAR_FLAGS (0x8) 都未设置，则将在以下请求中设置标准 FQDN 标志：NM_DHCP_HOSTNAME_FLAG_FQDN_SERV_UPDATE (0x1)、NM_DHCP_HOSTNAME_FLAG_FQDN_ENCODED (0x2) 用于 IPv4 和 NM_DHCP_HOSTNAME_FLAG_FQDN_SERV_UPDATE (0x1) 用于 IPv6。当此属性设置为默认值NM_DHCP_HOSTNAME_FLAG_NONE (0x0) 时，将在 NetworkManager 配置中查找全局默认值。如果未设置该值，或者也未设置 NM_DHCP_HOSTNAME_FLAG_NONE (0x0)，则在 DHCP 请求中发送上述标准 FQDN 标志。 指示如何处理 "ca-cert-password" 属性的标志。 指示如何处理 "client-cert-password" 属性的标志。 指示如何处理 "leap-password" 属性的标志。 指示如何处理 "mka-cak" 属性的标志。 指示如何处理 "password" 属性的标志。 指示如何处理 "password-raw" 属性的标志。 指示如何处理 "phase2-ca-cert-password" 属性的标志。 指示如何处理 "phase2-client-cert-password" 属性的标志。 指示如何处理 "phase2-private-key-password" 属性的标志。 指示如何处理 "pin" 属性的标志。 指示如何处理 "private-key" 属性的标志。 指示如何处理 "private-key-password" 属性的标志。 指示如何处理 "psk" 属性的标志。 指示如何处理 "wep-key0"、"wep-key1"、"wep-key2" 和 "wep-key3" 属性的标志。 指示使用哪种 WPS 模式（如果可用）的标志。由于网络管理器（NetworkManager）会自动从接入点功能确定启动 WPS 注册是否可行，因此改变默认设置几乎没有意义。可以通过设置此属性值为 1 来禁用 WPS。 指示使用哪种 WPS 模式（如果可用）的标志。由于网络管理器（NetworkManager）会自动决定要使用的最佳方法，因此改变默认设置几乎没有意义。 用于传入的数据包，从 802.1p 优先级到 Linux SKB 优先级的映射列表。映射以 "从:到" 的格式给定，其中 "从" 和 "到" 都是无符号整数，如 "7:3"。 用于传出的数据包，从 Linux SKB 优先级到 802.1p 优先级的映射列表。映射以 "从:到" 的格式给定，其中 "从" 和 "到" 都是无符号整数，如 "7:3"。 强制在衍生密钥时使用新的 PEAP 标签。有些 RADIUS 服务器可能需要强制使用新的 PEAP 标签以与 PEAPv1 互操作。设为 "1" 以强制使用新的 PEAP 标签。详情请见 wpa_supplicant 文档。 当 "eap" 属性里的 EAP 方法指定为 PEAP 时，强制所使用的 PEAP 版本。未设定时，将使用服务器报告的版本。有时使用旧的 RADIUS 服务器时，强制客户端使用特定的 PEAP 版本时必须的。要这么做，此属性可以设为 "0" 或 "1" 以强制所指定的 PEAP 版本。 转发延时 GRE 组 GSM 调制解调器的 SIM 需要 PIN 码 GSM 调制解调器的 SIM 需要 PUK 码 GSM 调制解调器的 SIM 卡未插入 GSM 调制解调器的 SIM 错误 GSM 连接 GSM 移动宽带连接 GVRP、  网关 网关证书散列 常规设置 通用设置 分组 ID [无] 组前向掩码 组密码 HTTP 代理密码 Hairpin 模式 问候时间 隐藏 提示："nmcli dev wifi show-password" 显示 Wi-Fi 名称和密码。
 提示：使用 "%s" 来获得更详细的信息。 主机名 主机名已设为 "%s"
 主机名设置 热点密码：%s
 允许多少个附加的封装等级预置到数据包。此属性值只应用到 IPv6 隧道。 IEEE 802.15.4 IEEE 802.15.4（WPAN）上级设备或连接的 UUID IEEE 802.15.4 个人区域网络（PAN）标识符。 IEEE 802.15.4 信道页。一个正整数，或 -1 意味着 "不设置，使用设备的设置"。 IEEE 802.15.4 信道。一个正整数，或 -1 意味着 "不设置，使用设置的设置"。 INFINIBAND IP 隧道 IP 配置无法保留（无可用地址、超时等） IP 配置方法。 NMSettingIP4Config 和 NMSettingIP6Config 都支持 "auto"、"manual" 和 "link-local"。对于其它值，请参阅相关子类的文档。通常情况下，对于 "auto" 方法，"dns" 和 "routes" 等属性指定是在从自动配置返回的信息添加的信息。"ignore-auto-routes" 和 "ignore-auto-dns"属性会改变这个行为。对于意味着没有上游网络的方法，如 "shared" 或 "link-local"，这些性能必须为空。对于 IPv4 的方法 "sharded"，IP 子网可以通过加入一个手工 IPv4 地址或选择 10.42.x.0/24 来配置。注意，共享方法必须在这个子网中的用来共享互联网的接口中进行配置，而不是在共享的上部连接中进行配置。 IP 隧道 IP 隧道连接 IP 隧道连接 %d IP 隧道设置 IP6GRE IP6IP6 IPIP IPIP6 IP 隧道 IPv4 配置 IPv4 地址（IP[/plen]）[无] IPv4 网关 [无] IPv4 协议 IPv6 配置 IPv6 地址（IP[/plen]）[无] IPv6 网关 [无] IPv6 协议 ISATAP 初始向量中包含非十六进制数字。 初始向量长度必须是偶数字节。 IV 需要最少包括 8 个字符 指定此网络设备与 z/VM 或 s390 主机通信使用的子通道的标识符。如 "mac-address" 用于非 z/VM 设备，此属性可用来确保此连接只应用到使用这些子通道的网络设备。列表应该包含 3 个字符串，且每个字符串只能由十六进制字符和半角句号（.）字符组成。 身份 用于 EAP 验证方法的标识字符串。通常是用户的用户名或登录名。 如果为 TRUE，隧道数据包的 IFF_VNET_HDR 将包含一个 virtio 网络首部。 如果为 TRUE，接口将前置一个描述到数据包的物理接口的 4 字节首部。 如果为 TURE，将不会请求 "deflate" 压缩。 如果为 TRUE，PPP 会话将需要 MPPE（微软点对点加密）且 "require-mppe" 也必须设为 TRUE。如果 128 位的 MPPE 不可用，会话将失败。 如果为 TURE，将不会请求 BSD 压缩。 如果为 TRUE，PPP 会话将需要 MPPE（微软点对点加密）。如果 64 位或 128 位的 MPPE 都不可用，会话将失败。注意 MPPE 不用在移动宽带连接。 如果为 TRUE，将不请求压缩 Van Jacobsen TCP 首部。 如果为 TRUE，当获取租约时发送主机名到 DHCP 服务器。有些 DHCP 服务器使用这个主机名来更新 DNS 数据库，实质上为计算机提供了个静态的主机名。如果 "dhcp-hostname" 属性为 NULL 且此属性为 TRUE，以计算机的当前永久主机名发送。 如果为 TURE，允许进行整体网络配置不管此属性指定的配置是否超时。注意至少要有一个 IP 配置成功不然整体网络配置仍将失败。示例，在纯 IPv6 网络，在 NMSettingIP4Config 设置此属性为 TRUE 时允许整体网络配置在 IPv4 配置失败但 IPv6 配置成功完成时成功。 如果为 TRUE，不需要其他方（通常是 PPP 服务器）验证自己到客户端。如果为 FALSE，需要来自远端的验证。在大多数情况下，此属性应为 TRUE。 如果为 TRUE，代表网络是一个隐藏了其 SSID 的非广播网络。这适用于基础结构（infrastructure）模式和 AP 模式。对于基础结构模式，可以使用不同的方法来更可靠地发现隐藏网络，例如探针扫描 SSID。然而，这些方法会暴露出隐藏了 SSID 的网络的不安全性，因此在使用隐藏了 SSID 的网络时应谨慎。对于 AP 模式，创建的网络不会广播其 SSID。请注意，把网络标记为隐藏对于您（基础结构模式）或客户端工作站（AP 模式）可能只是一个隐私问题，因为显式探针扫描可以识别它们。 如果为 TRUE，指定 pppd 应设定串口以使用通过 RTS 和 CTS 信号的硬件流量控制。此值通常应设为 FALSE。 如果为 TRUE，使用有状态 MPPE。关于有状态 MPPPE 的更多信息请查看 pppd 文档。 如果为 TRUE，将不会使用 CHAP 验证方法。 如果为 TRUE，将不会使用 EAP 验证方法。 如果为 TRUE，将不会使用 MSCHAP 验证方法。 如果为 TRUE，将不会使用 MSCHAPv2 验证方法。 如果为 TRUE，将不会使用 PAP 验证方法。 如果为 TRUE，此连接将永不成为此 IP 类型的默认连接，这表示网络管理器（NetworkManager）永远不会为其分配默认路由。 如果配置，设置为制造商使用说明（MUD）URL，该 URL 指向制造商推荐的 IoT 设备网络策略。它作为DHCPv4 或 DHCPv6 选项传输。该值必须是以 "https://" 开头的有效 URL。允许使用特殊值 "none" 来表示没有使用 MUD URL。如果每个配置文件的值是未指定的（默认），全局连接的默认值会被参考。如果仍然没有指定，最终的默认值是 "none"。 如果启用，网桥自己的 IP 地址将作为 IGMP 查询的源地址，否则将使用默认的 0.0.0.0。 如果给定了，指定此 PPPoE 连接应被创建在的上级接口名。如果此属性未指定，连接将激活到 NMSettingConnection 的 "interface-name" 所指定的接口。 如果给定了，其指定 6LowPAN 接口应被创建在上级接口名称或上级连接的 UUID。 如果给定了，其指定从此 MAC-VLAN 接口应该创建自的上级接口名称或上级连接的 UUID。如果此属性未指定，该连接必须包含具有 "mac-address" 属性的 "802-3-ethernet" 设置。 如果给定了，其指定从此 MACSEC 接口应该创建自的上级接口名称或上级连接的 UUID。如果此属性未指定，该连接必须包含具有 "mac-address" 属性的 "802-3-ethernet" 设置。 如果给定了，其指定从此 VLAN 接口应该创建自的上级接口名称或上级连接的 UUID。如果此属性未指定，该连接必须包含具有 "mac-address" 属性的 "802-3-ethernet" 设置。 如果给定了，指定新设备将绑定到的上级接口名或上级连接 UUID，以让隧道的数据包只能通过该接口进行路由。 如果给定了，其指定上级接口名称或上级连接的 UUID。 如果给定，指定要在传出数据包使用的来源 IP 地址。 如果大于零，推迟 IP 寻址的成功，直到到达超时时间或 IP 网关应答了 ping。 如果过了这个延迟时间（以十分之一秒为单位），没有看到查询，网桥将开始发送自己的查询。 如果非零，指示设备仅使用指定的比特率与接入点进行通信。单位为 Kb/s，示例 5500=5.5 Mbit/s。此属性依赖于驱动，并非所有设备都支持设置静态比特率。 如果非零，指示设备使用指定的传输功率。单位为 dBm。此属性依赖于驱动，并非所有设备都支持设置静态的传输功率。 如果非零，指示如果指定的 LCP 回响请求号码未被节点回应时 pppd 就认定到节点的连接失败了。如果要使用此属性，"lcp-echo-interval" 属性也必须设为非零值。 如果非零，指示 pppd 请求节点发送的数据包不要超过指定的大小。如果非零，MRU 应在 128 和 16384 之间。 如果非零，指示 pppd 每几秒发送一个 LCP 回响请求帧到节点（几秒为该属性指定）。注意有些 PPP 节点将响应回响请求而有些不会，并且无法自动检测此行为。 如果非零，指示 pppd 不要发送超过指定大小的数据包。 如果非零，指示 pppd 设定串口到指定的波特率。要自动选择速度时此值通常保留为 0。 如果非零，只传输指定大小或更小的数据包，将较大的数据包分成多个以太网帧。 如果非零，只传输指定大小或更小的数据包，将较大的数据包分成多个帧。 如果非零，只传输指定大小或更小的数据包，大的数据包会被分成多个以太网帧。如果为 0， 则使用默认的 MTU。请注意，与 wg-quick 的 MTU 不同，它不会考虑在激活时当前的路由。 如果非零，只传输指定大小或更小的数据包，将较大的数据包分成多个帧。 如果设为 NM_TERNARY_TRUE (1)，仅当设备拥有给定地址族（IPv4/IPv6）的默认路由时，NetworkManager 尝试通过此设备上的 DHCPv4/DHCPv6 或反向 DNS 查找获取主机名。如果设为 NM_TERNARY_FALSE (0)，主机名可以从此设备设定，即使它没有默认路由。当设为 NM_TERNARY_DEFAULT (-1)，使用全局配置的值。如果全局配置也没有设定值，NetworkManager 则假定值为 NM_TERNARY_FALSE (0)。 如果指定，此网桥用于 STP 的多播组的 MAC 地址。该地址必须是标准以太网 MAC 地址格式的 link-local 地址，例如 01:80:C2:00:00:0X，其中的 X 为 [0, 4..F] 范围中的一个值。如果没有指定，则使用默认值 01:80:C2:00:00:00。 如果指定了，指示 PPPoE 只启动与提供了指定服务的集线器的会话。对于大多数运营商，此属性应留空。如果有多个集线器存在或者特定服务需要时，此属性才需要设定。 如指定了，则请求该设备使用此 MAC 地址来代替。这个可被称为 MAC 克隆或欺骗。除了明确地指定 MAC 地址，也支持 "preserve"、"permanent"、"random" 和 "stable" 等特殊值。"preserve" 表示激活时不动 MAC 地址。"permanent" 使用设备的永久硬件地址。"random" 则在每个连接上创建随机的 MAC 地址。"stable" 则根据 connection.stable-id 和机器相关密钥创建散列的 MAC 地址。如未指定，该值可被全局默认值覆盖，参见 NetworkManager.conf 的手册。如还未指定，它就默认为 "permanent"。在 D-Bus 上, 此字段表示为 "assigned-mac-address" 或已弃用的 "cloned-mac-address"。 如指定了，则请求该设备使用此 MAC 地址来代替。这个可被称为 MAC 克隆或欺骗。除了明确地指定 MAC 地址，也支持 "preserve"、"permanent"、"random" 和 "stable" 等特殊值。"preserve" 表示激活时不动 MAC 地址。"permanent" 使用设备的永久硬件地址。"random" 则在每个连接上创建随机的 MAC 地址。"stable" 则根据 connection.stable-id 和机器相关密钥创建散列的 MAC 地址。如未指定，该值可被全局默认值覆盖，参见 NetworkManager.conf 的手册。如还未指定，它就默认为 "permanent"。在 D-Bus 上, 此字段表示为 "assigned-mac-address" 或已弃用的 "cloned-mac-address"。 如果指定了，其为网桥的 MAC 地址。当创建新网桥时，将设定此 MAC 地址。如果不指定此字段，换成引用 "ethernet.cloned-mac-address" 来生成初始 MAC 地址。注意设置 "ethernet.cloned-mac-address" 怎样都会在之后激活网桥时覆盖网桥的 MAC 地址。因此，此属性被弃用。已弃用：1 如果指定了，其为基于幻数据包的 LAN 唤醒所使用的密码，表示为以太网 MAC 地址。如果为 NULL，将不需要密码。 如果指定，则表示用于 VLAN 过滤的协议。支持的值有："802.1Q"、"802.1ad"。如果没有指定，默认值是"802.1Q"。 如果指定了，此连接将从不应用到其永久 MAC 地址与列表里的地址匹配的以太网设备。每个 MAC 地址采用标准的十六进制数字和冒号标记（00:11:22:33:44:55）。 如果指定了，此连接将只应用到其永久 MAC 地址匹配的以太网设备。此属性不会改变设备的 MAC 地址（例如 MAC 欺骗）。 如果指定了，此连接将只应用到其永久 MAC 地址匹配的 IEEE 802.15.4 (WPAN) MAC 层设备。 如指定了，此连接将只应用到符合永久 MAC 地址的 IPoIB 设备。此属性不会改变设备的 MAC 地址（例如 MAC 欺骗）。 如指定了，此连接将只应用到符合永久 MAC 地址的 Wi-Fi 设备。此属性不会改变设备的 MAC 地址（例如 MAC 欺骗）。 如指定了，此连接将只应用到其 MAC 地址符合的 WiMAX 设备。此属性不会改变设备的 MAC 地址（又名 MAC 欺骗）。已弃用：1 如果 "dhcp-send-hostname" 属性为 TRUE，当获取租约时指定的 FQDN 将被发送到 DHCP 服务器。此属性与 "dhcp-hostname" 相互排斥而且无法被同时设定。 如果 "dhcp-send-hostname" 属性为 TRUE，当获取租约时指定的名称将被发送到 DHCP 服务器。此属性与 "dhcp-fqdn" 相互排斥而且无法被同时设定。 如果 SIM 被 PIN 锁住了，在请求任何其他操作前必须解锁。在这里指定 PIN 以允许设备的操作。 如果 VPN 连接需要用户名用于验证，应在这里提供。如果连接可用于多个用户，且 VPN 需要每个用户提供个不同的名称，那么让此属性留空。如果此属性留空，网络管理器（NetworkManager）将自动提供 VPN 连接所需要用户的用户名。 如果 VPN 服务支持持久连接，并且此属性为 TRUE，VPN 将尝试在链路更改和中断的整个期间都保持连接，直到手动断开连接。 如果属性设为 TRUE，接口将支持多个文件描述符（队列）以并行化数据包的发送和接收，接口将只支持单个队列。 如果您想创建一个 VPN 但列表中没有您想要创建的 VPN 类型，这很可能是您没有安装正确的 VPN 插件。 忽略 忽略自动获取的 DNS 参数 忽略自动获取的路由 索引 0 WEP 密钥。这个是在大多数网络下使用的 WEP 密钥。参见 "wep-key-type" 属性获取解释该密钥的描述。 索引 1 WEP 密钥。此 WEP 索引不在大多数网络下使用。参见 "wep-key-type" 属性获取解释该密钥的描述。 索引 2 WEP 密钥。此 WEP 索引不在大多数网络下使用。参见 "wep-key-type" 属性获取解释该密钥的描述。 索引 3 WEP 密钥。此 WEP 索引不在大多数网络下使用。参见 "wep-key-type" 属性获取解释该密钥的描述。 指示链路是否为连接启用快速初始链路设置（FILS/802.11ai）。NM_SETTING_WIRELESS_SECURITY_FILS_DEFAULT (0)（使用全局默认值）、 NM_SETTING_WIRELESS_SECURITY_FILS_DISABLE (1)（禁用 FILS）、 NM_SETTING_WIRELESS_SECURITY_FILS_OPTIONAL (2)（如果请求方和接入点支持 FILS 就启用）或 NM_SETTING_WIRELESS_SECURITY_FILS_REQUIRED (3)（启用 FILS，不支持就失败）之一。当设定为 NM_SETTING_WIRELESS_SECURITY_FILS_DEFAULT (0) 时且未设定全局默认值，FILS 将被选择启用。 指示是否必须为连接启用受保护的管理帧（PMF/802.11w）。NM_SETTING_WIRELESS_SECURITY_PMF_DEFAULT (0)（使用全局默认值）、 NM_SETTING_WIRELESS_SECURITY_PMF_DISABLE (1)（禁用 PMF）、 NM_SETTING_WIRELESS_SECURITY_PMF_OPTIONAL (2)（如果请求方和接入点支持 PMF 就启用）或 NM_SETTING_WIRELESS_SECURITY_PMF_REQUIRED (3)（启用 PMF，不支持就失败）之一。当设定为 NM_SETTING_WIRELESS_SECURITY_PMF_DEFAULT (0) 时且未设定全局默认值，PMF 将被选择启用。 InfiniBand InfiniBand P_Key 连接未指定上级接口名 InfiniBand 连接 InfiniBand 连接 %d InfiniBand 设备不支持已连接的模式 信息：%s
 Infra 入口优先级映射 [无] 输入密钥 主设备的接口名或 UUID 或主连接。 接口： 接口： 内部配置文件位置 启动阶段结束后，网桥发送的查询之间的时间间隔（以十分之一秒为单位）。 无效的 IPv4 地址 "%s" 无效 IPv4 地址前缀 "%u" 无效的 IPv6 地址 "%s" 无效 IPv6 地址前缀 "%u" 无效的初始向量长度（至少为 %u）。 黑名单里无效的 MAC 地址：%s。 无效的配置选项 "%s"；允许 [%s]
 无效的设备蓝牙地址。 无效的设备 MAC 地址 %s。 无效的设备 MAC 地址。 无效选项。请使用 --help 查看有效选项列表。 在 %s:%zu 正启动无效的对等端：%s 无效的路由跃点数 "%s" 无效的密钥 无效的验证选项：%s
 JSON 配置 密钥 LACP 模式。"active"、"off" 或 "passive" 之一。 LEAP LEAP 验证和 802.1x 设置不兼容 LEAP 验证和 Ad-Hoc 模式不兼容 LEAP 验证要求 IEEE 802.1x 密钥管理 LEAP 验证要求 LEAP 用户名 LEAP 用户名要求 "leap" 验证 松散绑定、  用来帮助基于 GSM 的调制解调器创建 PPP 数据会话的老的设置。已过期：1 与 ip4-auto-default-route 相同，但针对于 IPv6 默认路由。 链路关闭延时 链路监测 链路开启延时 连接的链路监视器配置：每个链路监视器都由一个字典定义，其密钥取决于所选的链路监视器。可用的链路监视器有 "ethtool"、"nsna_ping" 和 "arp_ping"，并且在字典中以密钥 "name" 指定。可用的密钥有：ethtool："delay-up"、"delay-down"、"init-wait"；nsna_ping："init-wait"、"interval"、"missed-max"、"target-host"；arp_ping：包括 nsna_ping 中的所有以及 "source-host"、"validate-active"、"validate-incative"、"send-always"。请参阅 teamd.conf 的 man 页了解详细信息。 本地链路 当基础连接本身激活时应一块激活的连接 UUID 列表。当前只支持 VPN 连接。 插件列表，以 "," 隔开 字符串列表，指定允许使用的 WPA 协议版本。每个元素可以为 "wpa"（允许 WPA）或 "rsn"（允许 WPA2/RSN）中的一个。如果未指定，WPA 和 RSN 连接都允许。 字符串列表，在 "phase 2" 验证期间将与验证服务器所提供证书里的 altSubjectName 匹配。如果列表为空，不执行服务器证书的 altSubjectName 验证。 字符串列表，将与验证服务器所提供证书里的 altSubjectName 匹配。如果列表为空，不执行服务器证书的 altSubjectName 验证。 本地 IP 本地地址 [无] 本地端点 [无] 以 "," 分开的日志域：可以是 [%s] 的任意组合 日志级别：取 [%s] 之一 MAC [无] MACVLAN MACVLAN 连接 MACVLAN 上级设备或连接 UUID MACsec MACsec EAP 身份验证 MACsec PSK 身份验证 MACsec 连接 MACsec 上级设备或连接 UUID MII（推荐） MKA CAK MKA_CKN MSCHAP MSCHAPv2 MTU MUD URL不是一个有效的URL MVRP、  视所有警告为致命错误 错误的 PEM 文件格式：DEK-Info 不是第二个标记。 错误的 PEM 文件格式：Proc-Type 不是第一个标记。 错误的 PEM 文件格式：DEK-Info 标签中的初始向量格式无效。 错误的 PEM 文件格式：没有在 DEK-Info 标记找到初始向量。 错误的 PEM 文件格式：未知的 Proc-Type 标记 "%s"。 错误的 PEM 文件格式：未知的私钥密码 "%s"。 手动 主连接失败 匹配 最大寿命 Mesh 代理配置的方法，默认为 NM_SETTING_PROXY_METHOD_NONE (0) 方法返回类型 "%s"，但期望的是 "%s" 跃点数 在 arp_ping 链路监视器里缺少 %s 缺失 IPv4 地址 缺失 IPv6 地址 缺少 ovs 接口设置 缺少 ovs 接口类型 在 nsna_ping 链路监视器里缺少目标主机 移动宽带 移动宽带连接 %d 移动宽带网络密码 模式 调制解调器出现故障或不再可用 调制解调器初始化失败 调制解调器现已就绪且可用 ModemManager 不可用 修改所有用户的网络连接 修改持久性全局 DNS 配置 修改系统固有主机名 更改个人网络连接 正在监视连接激活（按任意键继续）
 监视频率 如果指定上级接口，则必须指定 P_Key 不可用 名称 该设备所需固件可能缺失 此连接应使用的 WiMAX 网络服务提供商（NSP）的名称。已弃用：1 网络注册遭拒绝 网络注册超时 网络管理器文本用户界面 网络管理器活动的配置集 网络管理器连接配置集 网络管理器已启动 网络管理器已停止 NetworkManaer 未运行 NetworkManaer 未运行。 网络管理器日志 网络管理器（NetworkManager）监视所有网络连接，并自动选择要使用的最佳连接。
它还允许用户指定计算机无线网卡连接的无线访问点。 NetworkManager 选项 网络管理器权限 网络管理器状态 网络管理器已挂起 联网 网络管理器未运行（等待中）。
 网络管理器现在处于 "%s" 状态
 始终不使用此网络于默认路由 新建连接 新连接激活已排队 新连接名称： 下一个跃点 无法建立载波 未指定连接 未定义自定义陆游。 无拨号音 没有指定接口 未给出原因 未指定服务 无此连接 "%s" 没有有效的密钥 无 不是有效的 PAC 脚本 不搜索网络 用在串口通信的停止位数量。要么是 1 要么是 2。以 "8n1" 中的 1 为例。 确定 OLPC Mesh OLPC Mesh 连接 OVS 外部 ID OVS 外部 ID 只能添加到 OVS 桥接/端口/接口类型的配置集，或者添加到 OVS 系统接口 %d 条自定义路由 NM_SETTING_MAC_RANDOMIZATION_DEFAULT (0)（从不随机化，除非用户设定了全局默认随机且请求方支持随机化）、NM_SETTING_MAC_RANDOMIZATION_NEVER (1)（从不随机化 MAC 地址）或 NM_SETTING_MAC_RANDOMIZATION_ALWAYS (2)（总是随机化 MAC 地址）之一。此属性已为 "cloned-mac-address" 所弃用。已弃用：1 NM_SETTING_WIRELESS_POWERSAVE_DISABLE (2)（禁用 Wi-Fi 的节能模式）、 NM_SETTING_WIRELESS_POWERSAVE_ENABLE (3)（启用 Wi-Fi 的节能模式）、 NM_SETTING_WIRELESS_POWERSAVE_IGNORE (1)（不改变当前配置）或 NM_SETTING_WIRELESS_POWERSAVE_DEFAULT (0)（使用全局配置值）之一。所有其他值都保留。 控制 VLAN 接口的行为和功能的一个或多个标志。标识包含 NM_VLAN_FLAG_REORDER_HEADERS (0x1)（重新排序输出数据包首部）、NM_VLAN_FLAG_GVRP (0x2)（使用 GVRP 协议）、NM_VLAN_FLAG_LOOSE_BINDING (0x4)（接口到它主设备运行状态的松散绑定）和 NM_VLAN_FLAG_MVRP (0x8)（使用 MVRP 协议）。此属性的默认值为 NM_VLAN_FLAG_REORDER_HEADERS，但它以前是 0。为了保持后向兼容性，D-Bus API 里的默认值继续为 0 而且 D-Bus 上缺少属性时仍视为 0。 开放系统 Open vSwitch 网桥 Open vSwitch DPDK 设备参数。 Open vSwitch DPDK 接口设置 Open vSwitch 接口 Open vSwitch 端口 Open vSwitch 网桥设置 Open vSwitch 数据库连接失败 Open vSwitch 接口设置 Open vSwitch 插线接口设置 Open vSwitch 端口设置 打开 %s 失败：%s
 输出文件名称： 输出密钥 PAC URL 用户获取 PAC 文件的 PAC URL。 PAC 脚本 PAN 标识符（<0x0000-0xffff>） PAN 连接 PAN 连接无法指定 GSM、CDMA 或串行设置 PAN 已请求，但蓝牙设备不支持 NAP PAP PCI PEM 证书没有结束标记 "%s"。 PEM 证书没有起始标记 "%s"。 PEM 密钥文件没有结束标记 "%s"。 PEM 密钥文件没有 start tag PIN PIN 检查失败 移动宽带设备需要 PIN 码 需要 PIN 码 用于 EAP 验证方法的 PIN。 PPP PPP 配置 PPP 失败 PPP 服务已断开连接 PPP 服务无法启动 PPP 设置 PPPoE PPPoE 连接 PPPoE 上级设备 PPPoE 用户名 P_KEY [无] 页 (<default|0-31>) 上级 上级设备 [无] 上级接口 [无] 串口的奇偶校验设置。 密码 密码 [无] 密码必须是 UTF-8 格式 已提供密码，但密钥没有加密。 用于 EAP 验证方法的密码，以字节数组给定以允许其他不是 UTF-8 编码的密码能够使用。如果 "password" 属性和 "password-raw" 属性都指定了，首选 "password"。 用于 ADSL 服务验证的密码。 用于 PPPoE 服务验证的密码。 密码： 需要密码或密钥来访问无线网络 "%s"。 路径开销 同等 执行接口配置的检查点或回滚 请选择选项 插件文件不存在（%s） 插件不是有效的文件（%s） WPA 网络的预共享密钥（Pre-Shared-Key）。对于 WPA-PSK，它是一个 8 到 63 个字符的 ASCII 密码口令（由 802.11i 标准指定）通过哈希以获得实际的密钥，或为一个 64 位  hexadecimal 字符的密钥。WPA3-Personal 网络使用可以为任何长度的密码口令以进行 SAE 验证。 前缀 %s 的预共享密钥 主机 输出网络管理器配置并退出 输出网络管理器版本并退出 优先级 私钥密码 配置集名称 属性名称？  代理 挂起或唤醒网络管理器（应仅用于系统电源管理） 退出 初始化配置后退出 记录头、  无线电开关 重新加载网络管理器配置 远程 远程 IP 移除 需要 128 位加密 需要 IPv4 地址来完成这个连接 需要 IPv6 地址来完成这个连接 轮询 路由 SIM PIN 不正确 SIM 运营商 ID 必须为 5 或 6 个数字的 MCCMNC 代码 SIT SR-IOV 设置 SSID SSID 长度超出 <1-32> 字节范围 Wi-Fi 网络的 SSID。必须指定。 要加入的 mesh 网络的 SSID。 SSID 或 BSSID： 使用 "autoconnect=yes" 保存该连接。这样会立即激活该连接。
您仍要保存吗？ %s 搜索域 DSL 连接 "%s" 需要密钥。 需要密钥来访问 MACsec 网络 "%s"。 需要密钥来访问有线网络 "%s"。 连接到 WireGuard VPN "%s" 所需要的 secret 需要密钥，但未提供 安全性 选择您要创建的连接类型。 选择您要添加的从连接类型。 选择... 发送 PPP 回响数据包 串行设置 服务 服务 [无] 设置主机名 设置延迟时间（以十分之一秒为单位），如果没有收到该组的成员报告，则桥接将在这个延迟时间后离开该组。 主机名已设为 "%s" 设置在收到 "leave" 消息后，查询寻找组内剩余成员的时间间隔（以十分之一秒为单位）。 设置多播哈希表的最大大小（数值必须是 2 的指数）。 设置系统主机名 设置网桥发送的 IGMP/MLD 查询的最大响应时间/最大响应延迟（以十分之一秒为单位）。 设置在启动阶段要发送的 IGMP 查询次数。 设置网桥在收到 "leave" 消息后，停止转发一个多播组之前，将发送的查询次数。 设置网桥的多播路由。只有在启用了multicast-snooping 时此选项才起作用。支持的值有："auto"、"disabled"、"enabled"，内核分别为它们分配数字 1、0 和 2。如果没有指定，默认值是 "auto" (1)。 设定此网桥的生成树协议（STP）优先级。值越小优先级越高；最高优先级（值最低）的网桥将选为根桥。 设置启动时为确定成员信息而发出的查询之间的间隔时间（以十分之一秒为单位）。 设置 "%s" 在连接里未提供。
 此从连接的主连接设备类型的设置名称（例如 "bond"），或者为 NULL 如果此连接不是从连接。 设置名称？  共享 共享密钥 共享连接服务失败 共享连接服务启动失败 在受限环境中使用的短 IEEE 802.15.4 地址。 短地址（<0x0000-0xffff>） 显示 显示 NetworkManager 选项 显示密码 从连接需要有效的 "%s" 属性 从机 如果设备支持多个连接方法，指定其使用的端口类型。"tp"（双绞线）、"aui"（连接单元接口）、"bnc"（细以太网）或 "mii"（介质无关接口）之一。如果设备只支持一个端口类型，忽略此设置。 指定 NMSetting8021xAuthFlags 选项使用的 "phase 1" 外部验证所要用的验证标识。可以明确地禁用个别 TLS 版本。如果未设定确切的 TLS 禁用标识，将由请求方决定允许还是禁止它。TLS 选项映射到 tls_disable_tlsv1_x 设置。详情请见 wpa_supplicant 文档。 指定如何获取用于 MKA（MACsec 密钥协商）的 CAK（连接关联密钥）。 指定 DCB 优先级流量控制（PFC）的 NMSettingDcbFlags。标志可以是 NM_SETTING_DCB_FLAG_ENABLE (0x1)、NM_SETTING_DCB_FLAG_ADVERTISE (0x2) 和 NM_SETTING_DCB_FLAG_WILLING (0x4) 的任意组合。 指定 DCB 优先级组的 NMSettingDcbFlags。标志可以是 NM_SETTING_DCB_FLAG_ENABLE (0x1)、NM_SETTING_DCB_FLAG_ADVERTISE (0x2) 和 NM_SETTING_DCB_FLAG_WILLING (0x4) 的任意组合。 指定 DCB FCoE 应用程序的 NMSettingDcbFlags。标志可以是 NM_SETTING_DCB_FLAG_ENABLE (0x1)、NM_SETTING_DCB_FLAG_ADVERTISE (0x2) 和 NM_SETTING_DCB_FLAG_WILLING (0x4) 的任意组合。 指定 DCB FIP 应用程序的 NMSettingDcbFlags。标志可以是 NM_SETTING_DCB_FLAG_ENABLE (0x1)、NM_SETTING_DCB_FLAG_ADVERTISE (0x2) 和 NM_SETTING_DCB_FLAG_WILLING (0x4) 的任意组合。 指定 DCB iSCSI 应用程序的 NMSettingDcbFlags。标志可以是 NM_SETTING_DCB_FLAG_ENABLE (0x1)、NM_SETTING_DCB_FLAG_ADVERTISE (0x2) 和 NM_SETTING_DCB_FLAG_WILLING (0x4) 的任意组合。 指定要在传出数据包使用的 TOS 值。 指定连接到远程 VXLAN 隧道端点的 UDP 目标端口。 指定要使用的 VXLAN 网络标识符（或 VXLAN 分段标识符）。 当在 "eap" 属性中指定了 TTLS 时，指定允许的 "阶段2" 内部基于 EAP 的身份验证方法。可用的基于 EAP 的 "阶段2" 方法是 "md5"、"mschapv2"、"otp"、"gtc" 和 "tls"。每个 "阶段2" 内部方法都需要特定的参数才能成功进行身份验证。更多详细信息，请参阅 wpa_supplicant 文档。 当在 "eap" 属性中指定了使用内部 TLS 隧道的 EAP 方法时，指定允许的 "阶段2" 内部身份验证方法。对于 TTLS，此属性可选择的非 EAP 内部方法有："pap"、"chap"、"mschap"、"mschapv2"，而 EAP 内部方法可选 "phase2-autheap"。对于 PEAP，此属性可选择的内部 EAP 方法有："gtc"、"otp"、"md5" 和 "tls"。每个 "阶段2" 内部方法都需要特定的参数才能成功进行身份验证。更多详细信息，请参阅 wpa_supplicant 文档。"phase2-auth" 和 "phase2-autheap" 都不能被指定。 指定内核已获知 FDB 条目的生存期，以秒计。 指定连接到远程 VXLAN 隧道端点的最大 UDP 来源端口。 指定 FDB 条目的最大数量。零值表示允许内核存储不限量的条目。 指定连接到远程 VXLAN 隧道端点的最小 UDP 来源端口。 指定补丁另一侧的接口名称。另一边的补丁也必须将此接口设置为对等体。 指定要在传出数据包使用的存活时间值。 指定当目标链路层地址在 VXLAN 设备转发数据库中未知时要在传出数据包中使用的单播目标 IP 地址，或者要加入的多播 IP 地址。 指定传入帧的验证模式。 指定是否打开 ARP 代理。 指定是否生成网络链路 IP ADDR 未命中通知。 指定是否生成网络链路 LL ADDR 未命中通知。 指定是否打开路由短路。 指定 SCI（安全信道标识符）是否包括在每个数据包中。 指定配置集是否能在指定时刻激活多次。该值为 NMConnectionMultiConnect 类型。 指定是否让未知来源的链路层地址和 IP 地址输入进 VXLAN 设备转发数据库。 指定一个 PID 文件的位置 通过串口通信使用的速度。注意该值一般对移动宽带调制解调器没有效果，因为它们通常忽略速度设置并使用最高的可用速度。 no-auto-default 设备的状态文件 状态文件位置 设备状态 主题字符串，在 "阶段 2" 验证期间将与验证服务器所提供证书的主题匹配。如果未设，不执行服务器证书的主题验证。就算设定了此属性也提供不了多少安全性，而且它的使用已废弃，取代的是 NMSetting8021x:phase2-domain-suffix-match。 主题字符串，将与验证服务器所提供证书的主题匹配。如果未设，不执行服务器证书的主题验证。就算设定了此属性也提供不了多少安全性，而且它的使用已废弃，取代的是 NMSetting8021x:domain-suffix-match。 成功 系统配置目录位置 系统策略阻止 Wi-Fi 扫描 系统策略阻止网络连接的控制 系统策略阻止启用或禁用 Wi-Fi 设备 系统策略阻止启用或禁用 WiMAX 移动宽带设备 系统策略阻止启用或禁用连接性检查 系统策略阻止启用或禁用设备统计 系统策略阻止启用或禁用移动宽带设备 系统策略阻止启用或禁用系统联网 系统策略阻止所有用户修改网络设置 系统策略阻止更改个人网络设置 系统策略阻止修改持久性全局 DNS 配置 系统策略阻止修改系统固有主机名 系统策略阻止挂起或唤醒网络管理器 系统策略阻止重新加载网络管理器 系统策略阻止使用受保护的 Wi-Fi 网络共享连接 系统策略阻止使用开放 Wi-Fi 网络共享连接 系统策略阻止检查点的创建或其回滚 组合 组合端口 TUN 连接 组合 组合 JSON 配置 [无] 组合连接 组合连接 %d 组合设备 组合端口 以 base64 编码的 256 为私钥。 设备的蓝牙地址。 设备和连接的蓝牙地址不匹配。 蓝牙连接失败或超时 以太网 MAC 地址的老化时间，以秒计。 当与基于 GSM 网络建立数据会话时指定使用的 APN 的 GPRS 接入点名称。APN 通常确定了用户如何为他们的网络使用付费，和用户能否访问互联网或只是运营商特定的封闭平台，因此为用户的移动带宽套餐使用正确的 APN 很重要。根据 GSM 03.60 章节 14.9，APN 只能由字符 a～z、0～9、. 和 - 组成。 IP 配置不再有效 IP-over-InfiniBand 传输模式。要么为 "datagram" 要么为 "connected"。 用于此设备的 InfiniBand P_Key。值 -1 代表使用默认的 P_Key（又名 "索引 0 的 P_Key"）。否则它是个 16 位无符号整数，如果它是个 "完全成员" P_Key 则设定它的高位。 组合（team）网络接口的 JSON 配置。此属性应包含适用于 teamd 的原始 JSON 配置，因为该值直接传递给 teamd。如果未指定则使用默认的配置。格式详情请参阅 teamd.conf 手册。 组合（team）接口的 JSON 配置。此属性应包含适用于 teamd 的原始 JSON 配置，因为该值直接传递给 teamd。如果未指定则使用默认的配置。格式详情请参阅 teamd.conf 手册。 设备和连接的 MAC 地址不匹配。 设备和连接的 MAC 地址不匹配。 启用 NMSettingWiredWakeOnLan 的选项。并非全部设备都支持所有选项。可以是以下选项的任意组合：NM_SETTING_WIRED_WAKE_ON_LAN_PHY (0x2)、NM_SETTING_WIRED_WAKE_ON_LAN_UNICAST (0x4)、NM_SETTING_WIRED_WAKE_ON_LAN_MULTICAST (0x8)、NM_SETTING_WIRED_WAKE_ON_LAN_BROADCAST (0x10)、NM_SETTING_WIRED_WAKE_ON_LAN_ARP (0x20)、NM_SETTING_WIRED_WAKE_ON_LAN_MAGIC (0x40) 或特殊值 NM_SETTING_WIRED_WAKE_ON_LAN_DEFAULT (0x1)（使用全局设置）和 NM_SETTING_WIRED_WAKE_ON_LAN_IGNORE (0x8000)（在网络管理器（NetworkManager）里禁用 LAN 唤醒的管理）。 启用 NMSettingWiredWakeOnWLan 的选项。并非全部设备都支持所有选项。可以是以下选项的任意组合：NM_SETTING_WIRELESS_WAKE_ON_WLAN_ANY (0x2)、NM_SETTING_WIRELESS_WAKE_ON_WLAN_DISCONNECT (0x4)、NM_SETTING_WIRELESS_WAKE_ON_WLAN_MAGIC (0x8)、NM_SETTING_WIRELESS_WAKE_ON_WLAN_GTK_REKEY_FAILURE (0x10)、NM_SETTING_WIRELESS_WAKE_ON_WLAN_EAP_IDENTITY_REQUEST (0x20)、NM_SETTING_WIRELESS_WAKE_ON_WLAN_4WAY_HANDSHAKE (0x40)、NM_SETTING_WIRELESS_WAKE_ON_WLAN_RFKILL_RELEASE (0x80)、NM_SETTING_WIRELESS_WAKE_ON_WLAN_TCP (0x100) 或特殊值 NM_SETTING_WIRELESS_WAKE_ON_WLAN_DEFAULT (0x1)（使用全局默认值）和 NM_SETTING_WIRELESS_WAKE_ON_WLAN_IGNORE (0x8000)（在网络管理器（NetworkManager）中禁用 WLAN 唤醒的管理）。 要强制指定网络注册的网络 ID（GSM LAI 格式，如 MCC-MNC）。如果指定了网络 ID，网络管理器（NetworkManager）将尝试强制设备只在指定的网络注册。当设备不能直接控制漫游时，这可以用于确保设备不漫游。 应该连接到的 P2P 设备。目前，这是唯一创建或加入一个组的方法。 此连接应用的 SIM 卡的唯一标识符（由 WWAN 管理服务给定）。如果给定了，此连接将应用到包含匹配给定标识符 SIM 卡的 "device-id" 所允许的任何设备。 生成树协议（STP）转发延迟，以秒计。 生成树协议（STP）呼叫时间，以秒计。 生成树协议（STP）最大消息寿命，以秒计。 通过此端口的目标的生成树协议（STP）端口开销。 此网桥端口的生成树协议（STP）优先级。 分配到隧道数据包的 TTL。0 为特殊值，表示数据包继承 TTL 值。 由此连接创建的接口应该分配的 VLAN 标识符。有效范围为从 0 到 4094，不包括保留的 ID 4095。 设备和连接的 VLAN 标识符不匹配。 VLAN 模式。"access"、"native-tagged"、"native-untagged"、"trunk" 之一或不设定。 VLAN 标记在 0～4095 范围内。 VPN 连接没有及时启动 VPN 服务启动失败 VPN 服务返回了无效配置 VPN 服务意外停止 设备的 VRF 表和连接不匹配。 设备和连接的 VXLAN 标识符不匹配。 要设置的 WFD（Wi-Fi Display）IE（Information Elements）。WFD 需要在特定 Wi-Fi 数据帧中设置一个特定于协议的 IE。它们可以在这里设置来建立连接。这个设置只在实现一个 WFD 客户端时有用。 无法找到 Wi-Fi P2P peer 未找到 Wi-Fi 网络 当验证到 802.1x 网络时，所允许使用的 EAP 方法。有效方法有："leap"、"md5"、"tls"、"peap"、"ttls"、"pwd" 和 "fast"。每种方法需要使用此设置属性的不同配置；请参考 wpa_supplicant 文档以获取允许的组合。 基础网络连接已中断 网桥失败模式。"secure"、"standalone" 之一或留空。 此连接和设备在 S390 子信道不相同。 连接尝试超时 此连接未指定接口名。 连接未保存。您真的要退出吗？%s 此连接为蓝牙 NAP 类型。 此连接配置集已被其他客户端移除了。您可以在主菜单中输入 "save" 来还原它。
 此连接配置集已被其他客户端移除了。您可以输入 "save" 来还原它。
 连接已断开 此连接不是蓝牙连接。 此连接不是 MAC-VLAN 连接。 此连接不是 VLAN 连接。 此连接不是 VRF 连接。 此连接不是 VXLAN 连接。 这个连接不是一个 Wi-Fi P2P 连接。 此连接不是 Wi-Fi 连接。 此连接不是绑定（bond）连接。 此连接不是网桥连接。 此连接不是虚拟（dummy）连接。 此连接不是通用的连接。 此连接不是调制解调器连接。 此连接不是 ovs 网桥连接。 此连接不是 ovs 接口连接。 此连接不是 ovs 端口连接。 此连接不是组合（team）连接。 此连接不是 tun 连接。 此连接不是有效的调制解调器连接。 此连接不是 wpan 连接。 此连接不是 ADSL 连接。 此连接不是以太网或 PPPoE 连接。 此连接不是 IP 隧道连接。 此连接不是 InfiniBand 连接。 此连接不是 OLPC Mesh 连接。 连接无效：%s 连接已被移除 数据路径类型。"system"、"netdev" 之一或留空。 网桥端口的默认 PVID，它是分配给入站的未经过 tag 的数据包的 VLAN id。 用于没有明确指定跃点数的路由的默认跃点数。默认值 -1 表示根据设备类型自动选择跃点数。该跃点数应用到自动路由、没有明确跃点数设置的手动（静态）路由、地址前缀路由和默认路由。注意对于 IPv6，内核接受零值（0）但会将其转为 1024（用户默认）。因此，设置此属性为零等于设置它为 1024。对于 IPv4，零是跃点数的常规值。 设备配置未就绪 设备已消失 设备缺少连接所要求的蓝牙功能。 设备缺少连接所要求的 WPA 功能。 设备缺少连接所要求的 WPA2/RSN 功能。 设备缺少连接所要求的功能。 设备的上级管理已更改 此连接要应用的设备唯一标识符（由 WWAN 管理服务给定）。如果给定了，连接将只应用到指定的设备。 设备已被移除 设备的活动连接已消失 假定设备已有连接 设备的上级已更改 拨号尝试失败 拨号请求超时 错误无法自动修复。
 预期的响应开头 要分配到隧道数据包的流量标签。此属性只应用到 IPv6 隧道。 将拥有设备的组 ID。如果设为 NULL 则每个人都能使用设备。 设备和连接的硬件地址不匹配。 FCoE 帧应使用的最高用户优先级（0～7），或 -1 代表默认优先级。只当 "app-fcoe-flags" 属性包含 NM_SETTING_DCB_FLAG_ENABLE (0x1) 标志时使用。 FIP 帧应使用的最高用户优先级（0～7），或 -1 代表默认优先级。只当 "app-fip-flags" 属性包含 NM_SETTING_DCB_FLAG_ENABLE (0x1) 标志时使用。 iSCSI 帧应使用的最高用户优先级（0～7），或 -1 代表默认优先级。只当 "app-iscsi-flags" 属性包含 NM_SETTING_DCB_FLAG_ENABLE (0x1) 标志时使用。 此设备的上级设备的接口名称。一般是 NULL，但如果 "p_key" 已设定，您必须通过设置此属性或 "mac-address" 来指定基础设备。 接口类型。"internal"、"system"、"patch"、"dpdk" 之一或留空。 连接性检查间隔（以秒计） 用于隧道输入数据包的密钥。该属性值对某些隧道模式有效（GRE、IP6GRE）。如果留空则不使用密钥。 用于隧道输出数据包的密钥。该属性值对某些隧道模式有效（GRE、IP6GRE）。如果留空则不使用密钥。 线路正忙 listen-port。如果 listen-port 没有被指定，则会在接口使用随机选择端口。 隧道的本地端点。值可以为空，否则它必须包含一个 IPv4 或 IPv6 地址。 传统 LEAP 连接的登录密码（示例，key-mgmt = "ieee8021x" 和 auth-alg = "leap"）。 传统 LEAP 连接的登录用户名（示例，key-mgmt = "ieee8021x" 和 auth-alg = "leap"）。 macvlan 模式，它指定了同一低层设备上的多个 macvlans 之间的通信机制。 设备和连接的模式不匹配 未找到调制解调器 WireGuard 配置文件的名称需要是一个有效的接口名再加上 ".conf" 此连接绑定的网络接口名称。如果未设定，此连接可以连接到任何合适类型的接口（受其他设置的限制）。对于软件设备，此值指定创建设备的名称。对于其接口名无法很容易固定的连接类型（例如 移动宽带或 USB 以太网），不应使用此属性。设置此属性会限制连接可以使用的接口，而且当接口名改变或重新排序了，连接可能会应用到错误的接口。 验证的重试次数。零代表无限次数；-1 代表使用全局默认值。如果全局默认值未设定，允许连接失败前验证重试 3 次。当前此属性只应用于 802-1x 验证。 自动激活放弃前连接应该尝试的次数。零表示从不，-1 表示全局默认值（未被覆盖时为 4 次）。设定此属性为 1 表示阻止自动连接前只尝试一次激活。注意一段超时时间后，网络管理器（NetworkManager）将重新尝试自动连接。 建立基于 CDMA 移动宽带网络连接的拨号号码，如果有的话。如未指定，需要时默认使用号码（#777）。 虚拟设备的操作模式。允许值有 NM_SETTING_TUN_MODE_TUN (1) 以创建第三层设备和 NM_SETTING_TUN_MODE_TAP (2) 以创建类以太网的第二层设备。 用于访问 "phase2-ca-cert" 属性里存储的 "阶段2" CA 证书的密码。只在 PKCS#11 令牌里存储的证书需要登录时有意义。 用于访问 "phase2-client-cert" 属性里存储的 "phase2" 客户端证书的密码。只在 PKCS#11 令牌里存储的证书需要登录时有意义。 用于访问 "ca-cert" 存储的 CA 证书的密码。只在 PKCS#11 令牌里存储的证书需要登录时有意义。 用于访问 "client-cert" 属性里存储的客户端证书的密码。只在 PKCS#11 令牌里存储的证书需要登录时有意义。 用于与网络验证的密码，如果需要。很多运营商不需要密码，或是接受任何密码。但是如果需要密码，可在这里指定。 当私钥使用路径方案或为 PKCS#12 格式时，解密 "phase2-private-key" 属性指定的 "phase 2" 私钥所使用的密码。 当私钥使用路径方案或为 PKCS#12 格式时，解密 "private-key" 属性指定私钥所使用的密码。 SCI（安全信道标识符）的端口组件，介于 1 和 65534 之间。 此连接确定系统主机名的相对优先级。数值越低优先级越高。高优先级的连接比低优先级的先被考虑。如果值为零，它可以被 NetworkManager 配置的全局值覆盖。如果全局配置里该属性没有值，则假定值为 100。负值具有排除其他具有高优先级数值的连接的特殊效果；所以存在至少一个负值优先级的情况下，只有具有最低优先级数值的连接会被用于确定主机名。 隧道的远程端点；值必须包含一个 IPv4 或 IPv6 地址。 该 VRF 的路由表。 选中的 IP 方法未支持 客户端目前可用 端口开始流量转发所需激活的时间。 端口被视为关闭所需停用的时间。 连接上次完全激活的时间，以秒计算和 Unix 时间表示。当连接激活时网络管理器（NetworkManager）会定期更新连接的时间戳以确保活动连接有最新的时间戳。该用来读取（此属性的更改不被保留）。 要创建的虚拟功能的总数。请注意，在激活或取消激活时重置它时，如果存在 sriov 设置（即使为 0），NetworkManager 都会强制实现在接口上的虚拟功能的数量。为了防止对 SR-IOV 参数的任何改变，则不要向连接添加 sriov 设置。 连接的信任级别。格式自由、不区分大小写的字符串（例如 "Home"、"工作"、"公共"）。NULL 或为指定区域表示连接将放置到防火墙定义的默认区域。当在当前激活的连接上更新此属性时，更改立即生效。 隧道模式，例如 NM_IP_TUNNEL_MODE_IPIP (1) 或 NM_IP_TUNNEL_MODE_GRE (2)。 设定在隧道数据包上的服务类型（IPv4）或流量等级（IPv6）字段。 使用 fwmark 是可选的，它在默认情况下被禁用。如果把它设为 0，则代表被禁用，其他情况下，它是一个用于出站数据包的 32 位 fwmark。请注意，如果 "ip4-auto-default-route" 或 "ip6-auto-default-route" 已启用，则意味着自动选择一个 fwmark。 将拥有设备的用户 ID。如果设为 NULL 则每个人都能使用设备。 用于与网络验证的用户名，如果需要。很多运营商不需要用户名，或是接受任何用户名。但是如果需要用户名，可在这里指定。 正确语法为："<vid>[-<vid>] [pvid] [untagged]" 正确语法为："[root | parent <handle>] [handle <handle>] <kind>" 有效语法为："ip[/prefix] [next-hop] [metric] [attribute=val]... [,ip[/prefix] ...]" 有效语法为："vf [attribute=value]... [,vf [attribute=value]...]" 没有主连接
 此属性指定了 veth 对等端的接口名称。必须填写。 每次发送字节到调制解调器的延迟时间，以微秒计。 VPN 服务建立连接的超时时间。有些服务可能需要很多时间才能连接。值 0 表示默认的超时，即 60 秒（除非被配置文件中的 vpn.timeout 覆盖）。大于零的值表示以秒计算的超时时间。 等待设备启动的超时时间（以毫秒为单位）。在引导期间，设备可能需要一段时间才能被驱动程序检测到。使用此属性将可以延迟 NetworkManager-wait-online.service 和 nm-online 以使设备有时间可以被驱动程序检测到。通过等待给定的超时时间，直到配置集兼容的设备可用并受管。如果为 0，则表示没有等待时间。 默认值为 -1，当前也是代表无等待时间。 用于检查网络中是否存在重复 IP 地址的超时时间。如果检测到了冲突，激活将失败。零值表示不执行重复 IP 检查，-1 表示默认值（配置 ipvx.dad-timeout 覆盖或 3 秒）。大于零的值为以毫秒计算的超时时间。该属性当前只实现于 IPv4。 流量控制 传输模式 Tun Tun 设备 隧道标志。当前支持下列值：NM_IP_TUNNEL_FLAG_IP6_IGN_ENCAP_LIMIT (0x1)、NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_TCLASS (0x2)、NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FLOWLABEL (0x4)、NM_IP_TUNNEL_FLAG_IP6_MIP6_DEV (0x8)、NM_IP_TUNNEL_FLAG_IP6_RCV_DSCP_COPY (0x10)、NM_IP_TUNNEL_FLAG_IP6_USE_ORIG_FWMARK (0x20)。它们只对 IPv6 隧道有效。 输入 "describe [<设置>.<属性>]" 来获得详细的属性描述。 输入 "help" 或 "?" 查看可用的命令。 输入 "print" 来显示所有的连接属性。 URI 为空 URI 不是有效的 UTF-8 URI 非 NUL 终止符 USB UTF-8 编码的文件路径，包含用于 EAP-FAST 的 PAC。 用于 EAP 验证方法的 UTF-8 编码密码。如果 "password" 属性和 "password-raw" 属性都指定了，首选 "password"。 一个到包含 PEM 或 DER 格式证书的目录的 UTF-8 编码路径，它被添加到包括 "ca-cert" 属性中指定的证书的验证链中。如果 NMSetting8021x:system-ca-certs 被启用，并且内置的 CA 路径是一个现有的目录，那么这个设置将被忽略。 一个到包含 PEM 或 DER 格式证书的目录的 UTF-8 编码路径，它被添加到包括 "phase2-ca-cert" 属性中指定的证书的验证链中。如果 NMSetting8021x:system-ca-certs 被启用，并且内置的 CA 路径是一个现有的目录，那么这个设置将被忽略。 无法添加新连接：%s 无法删除连接：%s 无法确定私钥类型。 无法保存连接：%s 无法设置主机名：%s 加密后意外的数据量。 "%s" 后更随着意外的文件尾
 正常化连接意外地失败 检验连接意外地失败 未知 未知的命令参数："%s"
 未知命令："%s"
 未知错误 未知的日志域 "%s" 未知的日志等级 "%s" 未知原因 未知的从类型 "%s" 未知的/未处理的蓝牙连接类型 不支持的 extra-argument 解密不支持的密钥密码 加密不支持的密钥密码 不支持的 to-string-flags 参数 用法 用法：nmcli [选项] 对象 { 命令 | help }

选项
  -a, --ask                                询问缺少的参数
  -c, --colors auto|yes|no                 是否在输出中使用颜色
  -e, --escape yes|no                      转义值中的列分隔符
  -f, --fields <字段,...>|all|common       指定要输出的字段
  -g, --get-values <字段,...>|all|common   -m tabular -t -f 的快捷方式
  -h, --help                               打印此帮助
  -m, --mode tabular|multiline             输出模式
  -o, --overview                           概览模式
  -p, --pretty                             美化输出
  -s, --show-secrets                       允许显示密码
  -t, --terse                              简介输出
  -v, --version                            显示程序版本
  -w, --wait <秒数>                        设定操作完成的等待超时

对象
  g[eneral]       NetworkManager 的常规状态和操作
  n[etworking]    整体网络控制
  r[adio]         NetworkManager 无线电开关
  c[onnection]    NetworkManager 的连接
  d[evice]        NetworkManager 管理的设备
  a[gent]         NetworkManager 机密（secret）或 polkit 代理
  m[onitor]       监视 NetworkManager 更改

 用法：nmcli agent all { help }

将 nmcli 同时作为网络管理器（NetworkManager）的密钥（secret）代理及 polkit 代理运行。

 用法：nmcli agent polkit { help }

将 nmcli 注册为用于用户会话的 polkit 操作。
当 polkit 守护进程要求授权时，nmcli 询问用户后将其响应返回 polkit。

 用法：nmcli agent secret { help }

将 nmcli 作为网络管理器（NetworkManager）的密钥（secret）代理运行。当 NetworkManager 要求密码时，它将请求
注册的代理提供。这个命令将使 nmcli 保持运行，如果要求密码则会请求用户提供。

 用法：nmcli agent { COMMAND | help }

命令 := { secret | polkit | all }

 用法：nmcli connection clone { 参数 | help }

参数 := [--temporary] [id | uuid | path] <ID> <新名称>

克隆现有的连接配置集。新创建的连接将是 <ID> 的完全复制，除了 UUID 属性（将被生
成）和 ID（由 <新名称> 参数提供）不同。

 用法：nmcli connection down { 参数 | help }

参数 := [id | uuid | path | apath] <ID> ...

从设备停用连接（无需阻止设备再次自动激活）。要停用的配置集由它的名称、UUID 或 
D-Bus 路径来确定。

 用法：nmcli connection edit { 参数 | help }

参数 := [id | uuid | path] <ID>

在交互式编辑器中编辑已有的连接配置集。
配置集由其名称、UUID 或 D-Bus 路径来确定。

参数 := [type <新连接类型>] [con-name <新连接名称>]

在交互式编辑器中添加新的连接配置文件。

 用法：nmcli connection export { 参数 | help }

参数 := [id | uuid | path] <ID> [<输出文件>]

导出连接。目前只支持 VPN 连接。数据会导出到标准输出或文件（如果给定了）。

 用法：nmcli connection import { 参数 | help }

参数 := [--temporary] type <类型> file <要导入的文件>

将外部配置作为网络管理器（NetworkManager）连接配置导入。输入文件的类型由 type 选项指定。
目前只支持 VPN 配置。配置通过 NetworkManager VPN 插件导入。

 用法：nmcli connection load { 参数 | help }

参数 := <文件名> [<文件名>...]

从磁盘加载/重载一个或多个连接文件。在手动编辑连接文件后使用此方法以确保
网络管理器（NetworkManager）能注意到它的最新状态。

 用法：nmcli connection modify { 参数 | help }

参数 := [id | uuid | path] <ID> ([+|-]<设置>.<属性> <值>)+

修改连接配置集的一个或多个属性。
配置集由它的名称、UUID 或 D-Bus 路径代表。对于有多个值
的属性，可以使用 "+" 或 "-" 为属性名加前缀。
"+" 代表附加项而不是覆盖整个值。
"-"代表删除选项的项而不是整个值。

参数 := remove <设置>

从连接配置集中删除一个设置。

示例：
nmcli con mod home-wifi wifi.ssid rakosnicek
nmcli con mod em1-1 ipv4.method manual ipv4.addr "192.168.1.2/24, 10.10.1.5/8"
nmcli con mod em1-1 +ipv4.dns 8.8.4.4
nmcli con mod em1-1 -ipv4.dns 1
nmcli con mod em1-1 -ipv6.addr "abbe::cafe/56"
nmcli con mod bond0 +bond.options mii=500
nmcli con mod bond0 -bond.options downdelay
nmcli con mod em1-1 remove sriov

 用法：nmcli connection monitor { 参数 | help }

参数 := [id | uuid | path] <ID> ...

监视连接配置集活动。
每当指定的连接修改时，这个命令将其打印出来。如果没有指定则监视所有的连接。

 用法：nmcli connection reload { help }

从磁盘重新载入所有的连接文件。

 用法：nmcli connection show { 参数 | help }

参数 := [--active] [--order <排序规则>]

列出内存中以及磁盘上的连接配置集，其中也有些是活动的，如果它正被设备使用的话。
未使用参数时，所有的配置集都将列出。当指定 --active 选项时，只显示活动的配置
集。--order 允许自定义连接的顺序（请参考手册页）。

参数 := [--active] [id | uuid | path | apath] <ID> ...

显示指定连接的细节。在默认情况下，静态配置和活动连接数据都会被显示。您可以用全
局的 "--fields" 选项过滤输出。更多信息请参考手册页。当指定 --active 选项时，只
会考虑活动的配置集。请使用全局的 --show-secrets 选项以同时显示关联的密钥（secret）。
 用法：nmcli connection up { 参数 | help }

参数 := [id | uuid | path] <ID> [ifname <接口名>] [ap <BSSID>] [nsp <名称>] [passwd-file <密码文件>]

激活设备上的连接。要激活的配置集由它的名称、UUID 或 D-Bus 路径来确定。

参数 := ifname <接口名称> [ap <BSSID>] [nsp <名称>] [passwd-file <密码文件>]

用连接激活设备。网络管理器（NetworkManager）会自动选择连接配置集。

ifname      - 指定激活连接所用的设备
ap          - 指定要连接的 AP（只对 Wi-Fi 有效）
nsp         - 指定要连接的 NSP（只对 WiMAX 有效）
passwd-file - 激活连接所需的密码文件
 用法：nmcli connection { 命令 | help }

命令 := { show | up | down | add | modify | clone | edit | delete | monitor | reload | load | import | export }

  show [--active] [--order <排序规则>]
  show [--active] [id | uuid | path | apath] <ID> ...

  up [[id | uuid | path] <ID>] [ifname <接口名称>] [ap <BSSID>] [passwd-file <密码文件>]

  down [id | uuid | path | apath] <ID> ...

  add 常用选项 类型特定选项 从选项 IP_选项 [-- ([+|-]<设置>.<属性> <值>)+]

  modify [--temporary] [id | uuid | path] <ID> ([+|-]<设置>.<属性> <值>)+

  clone [--temporary] [id | uuid | path ] <ID> <新名称>

  edit [id | uuid | path] <ID>
  edit [type <新连接类型>] [con-name <新连接名称>]

  delete [id | uuid | path] <ID>

  monitor [id | uuid | path] <ID> ...

  reload

  load <文件名> [ <文件名>... ]

  import [--temporary] type <类型> file <要导入的文件>

  export [id | uuid | path] <ID> [<输出文件>]

 用法：nmcli device connect { 参数 | help }

参数 := <接口名称>

连接该设备。
网络管理器（NetworkManager）将尝试查找将激活的合适连接，包括那些没有设定为自动连接的连接。

 用法：nmcli device delete { 参数 | help }

参数 := <接口名> ...

删除软件设备。
此命令用于移除接口。它仅适用于软件设备（如绑定、网桥等）。硬件设备不能用这个命
令来删除。

 用法：nmcli device disconnect { 参数 | help }

参数 := <接口名称>

断开设备的连接。
该命令断开设备的连接并阻止其在没有用户/手动干预的情况下继续自动激活连接。

 用法：nmcli device lldp { 参数 | help }

参数 := [list [ifname <接口名>]]

列出通过 LLDP 发现的邻居设备。可使用 "ifname" 选项列出具体接口的邻居设备。

 用法：nmcli device modify { 参数 | --help }

参数 := <接口名称> ([+|-]<设置>.<属性> <值>)+

修改设备上当前活动连接的一个或多个属性，但不用更改该连接的配置集。更改会即时生
效。对于多值属性，您可以在属性名前插可选的 "+" 或 "-" 符号。"+" 符号允许附加项
而不是是替换掉整个值。"-" 符号允许移除选中项而不是整个值。
例如：
nmcli dev mod em1 ipv4.method manual ipv4.addr "192.168.1.2/24, 10.10.1.5/8"
nmcli dev mod em1 +ipv4.dns 8.8.4.4
nmcli dev mod em1 -ipv4.dns 1
nmcli dev mod em1 -ipv6.addr "abbe::cafe/56"
 用法：nmcli device monitor { 参数 | help }

参数 := [<接口名>] ...

监视设备活动。
每当指定的连接修改时，这个命令会将其打印出来。如果没有指定则监视所有的连接。

 用法：nmcli device reapply { 参数 | help }

参数 := <接口名称>

尝试将自上次应用以后对当前活动连接所做出的改变应用到设备中。

 用法：nmcli device set { 参数 | help }

参数 := 设备 { 属性 [ 属性 ... ] }
设备 := [ifname] <接口名> 
属性 := { autoconnect { yes | no } |
        { managed { yes | no }

修改设备属性。

 用法：nmcli device show { 参数 | help }

参数 := [<接口名称>]

显示设备详情。
该命令列出所有设备或者给定设备的详情。

 用法：nmcli device status { help }

显示所有设备的状态。
默认情况下，显示下列栏目：
 DEVICE     - 接口名称
 TYPE       - 设备类型
 STATE      - 设备状态
 CONNECTION - 设备上激活的连接（如果有的话）
显示哪些栏目可以通过 "--fields" 全局选项改变。"status" 是默认命令，也就是说 
"nmcli device" 会调用 "nmcli device status"。

 用法：nmcli device wifi { 参数 | help }

在 Wi-Fi 设备上执行操作。

参数 := [list [ifname <接口名称>] [bssid <BSSID>] [--rescan yes|no|auto]]

列出可用的 Wi-Fi 接入点。"ifname" 和 "bssid" 选项可用于列出指定接口或 BSSID 
的接入点。--rescan 标志告知是否要触发新的 Wi-Fi 扫描。

参数 := connect <(B)SSID> [password <密码>] [wep-key-type key|phrase] [ifname <接口名称>]
                     [bssid <BSSID>] [name <名称>] [private yes|no] [hidden yes|no]

连接到 SSID 或 BSSID 指定的 Wi-Fi 网络。该命令查找匹配的连接或者在设备上创建
一个然后激活它。此命令行项对应于在 GUI 客户端上点击一个 SSID。如果网络的连接
已经存在，可以由以下命令调出现有配置集：nmcli con up id <名称>。注意如果之前
不存在连接，那么只有开放、WAP 和 WPA-PSK 网络受支持。同时假设 IP 配置是由 
DHCP 获取的。

参数 := hotspot [ifname <接口名称>] [con-name <名称>] [ssid <SSID>]
                     [band a|bg] [channel <信道>] [password <密码>]

创建一 Wi-Fi 热点。使用 "connection down" 或 "device disconnect" 来停止该热点。
热点的参数会受到可选参数的影响：
ifname——要使用的 Wi-Fi 设备
con-name——创建的热点连接配置集名称
ssid——热点的 SSID
band——要使用的 Wi-Fi 频段
channel——要使用的 Wi-Fi 信道
password——用于热点的密码

参数 := rescan [ifname <接口名称>] [[ssid <要扫描的 SSID>] ...]

请求网络管理器（NetworkManager）立即重新扫描可用的接入点。网络管理器会定期地扫描
 Wi-Fi 网络，但在某些情况下手动开始可能会很有用。"ssid" 允许扫描指定的 SSID，这
 可以用于扫描拥有隐藏 SSID 的接入点。可以给定多个 "ssid" 参数。注意此命令不会
 显示接入点，要显示接入点请使用 "nmcli device wifi list"。
 用法：nmcli device { 命令 | help }

命令 := { status | show | set | connect | reapply | modify | disconnect | delete | monitor | wifi | lldp }

  status

  show [<接口名称>]

  set [ifname] <接口名称> [autoconnect yes|no] [managed yes|no]

  connect <接口名称>

  reapply <接口名称>

  modify <接口名称> ([+|-]<设置>.<属性> <值>)+

  disconnect <接口名称> ...

  delete <接口名称> ...

  monitor <接口名称> ...

  wifi [list [ifname <接口名称>] [bssid <BSSID>] [--rescan yes|no|auto]]

  wifi connect <(B)SSID> [password <密码>] [wep-key-type key|phrase] [ifname <接口名称>]
                         [bssid <BSSID>] [name <名称>] [private yes|no] [hidden yes|no]

  wifi hotspot [ifname <接口名称>] [con-name <名称>] [ssid <SSID>] [band a|bg] [channel <信道>] [password <密码>]

  wifi rescan [ifname <接口名称>] [[ssid <要扫描的 SSID>] ...]

  wifi show-password [ifname <接口名称>]

  lldp [list [ifname <接口名称>]]

 用法：nmcli general hostname { 参数 | help }

参数 := [<主机名>]

获取或更改永久的系统主机名。
如果没有参数，则会输出当前配置的主机名。给定主机名后，网络管理器（NetworkManager）会将其设为
新的永久系统主机名。

 用法：nmcli general logging { 参数 | help }

参数 := [level <日志级别>] [domains <日志域>]

获取或更改网络管理器（NetworkManager）的日志级别和域。
如果没有任何参数则显示当前日志级别和域。要更改日志状态，请提供级别和（或）域。
可能的日志域列表请参阅手册页。

 用法：nmcli general permissions { help }

显示验证操作的调用程序权限。

 用法：nmcli general status { help }

显示网络管理器（NetworkManager）的整体状态。
"status" 是默认操作，即 "nmcli gen" 调用 "nmcli gen status"

 用法：nmcli monitor

监视网络管理器（NetworkManager）的更改。
每当 NetworkManager 出现更改时打印一行信息。

 用法：nmcli networking connectivity { 参数 | help }

参数 := [check]

获取网络连接性状态。
可选的 "check" 参数可让网络管理器（NetworkManager）重新检查连接性。

 用法：nmcli networking off { help }

关闭联网。

 用法：nmcli networking on { help }

打开联网。

 用法：nmcli networking { 命令 | help }

命令 := { [ on | off | connectivity ] }

  on

  off

  connectivity [check]

 用法：nmcli radio all { 参数 | help }

参数 := [on | off]

获取所有无线电开关的状态，或者打开/关闭它们。

 用法：nmcli radio wifi { 参数 | help }

参数 := [on | off]

获取 Wi-Fi 无线电开关的状态，或者打开/关闭它。

 用法：nmcli radio wwan { 参数 | help }

参数 := [on | off]

获取移动宽带无线电开关的状态，或者打开/关闭它。

 用法：nmcli radio { 命令 | help }

命令 := { all | wifi | wwan }

  all | wifi | wwan [ on | off ]

 使用 "nmcli device show" 获取关于已知设备的完整信息，以及 
"nmcli connection show" 获取活动连接配置集的概述。

完整的用法细节，可参考 nmcli(1) 和 nmcli-examples(7) 手册页。
 使用 TCP 首部压缩 使用点到点加密（MPPE） 使用有状态 MPPE 用户 ID [无] 用户设置 用户名 用户名 [无] 用于 ADSL 服务验证的用户名。 用于 PPPoE 服务验证的用户名。 ADSL 连接的 VCI 有索引为 %u 的虚拟功能，但虚拟功能总数为 %u 虚拟功能 %d 和 %d 未按升序排列 VLAN VLAN ID <0-4095> VLAN 连接 VLAN 连接 %d VLAN 标记（<0-7>）[无] VLAN 标识 VLAN 上级设备或连接 UUID ADSL 连接的 VPI VPN VPN 已连接 VPN 连接中 VPN 连接中（获取 IP 配置中） VPN 连接中（需要验证） VPN 连接中（准备） VPN 连接 VPN 连接 %d VPN 连接（名称、UUID 或路径）： VPN 连接失败 VPN 已断开 需要 VPN 密码 VRF VRF 连接 VTI VTI6 VXLAN VXLAN ID VXLAN 连接 有效的连接类型：%s
 值不能解释为一个数字列表。 验证连接：%s
 验证设置 "%s"：%s
 Veth Veth 连接 Veth 连接 %d WEP 128位 密码 WEP 40/128 位密钥（十六进制或者 ASCII） WEP 索引 1（默认） 2 3 4 WEP 密钥索引已设为 "%d" 猜测 WEP 密钥为 "%s" 类型 WI-FI WPA & WPA2 企业 WPA & WPA2 个人 WPA Ad-Hoc 身份验证需要 "ccmp" 成对密码 WPA Ad-Hoc 身份验证需要 "rsn" 协议 WPA Ad-Hoc 需要 "ccmp" 组密码 WPA 验证和共享密钥（Shared Key）验证不兼容 WPA 验证和非 EAP（原始的）LEAP 或动态 WEP 不兼容 WPA-EAP 验证要求 802.1x 设置 WPA-EAP 要求 "open" 验证 WPA-PSK 验证和 802.1x 兼容 WPA-PSK 要求 "open" 验证 WPA3 个人 WPAN 连接 WPAN 设置 需要 WPS WWAN 无线电开关 等待网络管理器启动而不是连接 等待网络管理完成激活启动网络连接。 LAN 唤醒模式 "default" 和 "ignore" 是相互排斥的标记 LAN 唤醒密码只能在幻数据包模式使用 WLAN 唤醒模式 "default" 和 "ignore" 是相互排斥的标记 WLAN 唤醒正在尝试设定未知的标记 警告：%s
 警告：%s 不是任何现有连接配置集的 UUID
 警告：%s.%s 已设为 "%s"，但在基础结构（infrastructure）模式下它可能会被忽略。
 警告："%s" 应该是隐藏 AP 的 SSID，但看起来像 BSSID。
 警告：已指定 "file"，忽略额外的参数。
 警告：已指定 "type"，忽略额外的参数。
 警告：存在其他 %3$u 条带有名称 "%1$s" 的连接。通过其 uuid "%2$s" 引用连接。
 警告：重复的参数 "%s"。
 警告：正在编辑已有的连接 "%s"；"con-name" 参数已忽略
 警告：正在编辑已有的连接 "%s"；"type" 参数已忽略
 警告：master="%s" 没有引用任何现有的配置集。
 警告："passwd-file" 里没有给定 "%s" 的密码而且 nmcli 没有 "--ask" 选项就无法进行
询问。
 警告：polkit 代理初始化失败：%s
 警告：设置 %s.%s 需要删除 ipv4 和 ipv6 设置
 当 "method" 设为 "auto" 且此属性为 TRUE 时，自动配置的名称服务器和搜索域被忽略且只有 "dns" 和 "dns-search" 属性中指定的名称服务器和搜索域被使用，如果有的话。 当 "method" 设为 "auto" 且此属性为 TRUE 时，自动配置的路由被忽略且只有 "routes" 属性中指定的路由被使用，如果有的话。 为 TRUE 时，强制速度和双工模式的自动协商。如果 "speed" 和 "duplex" 属性都指定了，只有那一个模式会在链路自动协商过程中被通告和接受：这只对 BASE-T 802.3 规范有效并用于强制吉比特模式，因为在这些情况下链路协商时强制性的。为 FALSE 时，"speed" 和 "duplex" 属性应该都设置，否则链路配置将被忽略。 为 TRUE 时，将只允许连接到本地网络，不会连接到漫游网络。 设为 TRUE 时，覆盖掉 "ca-path" 和 "phase2-ca-path" 属性，换成使用配置时 --system-ca-path 指定的系统 CA 目录。该目录中的证书同 "ca-cert" 和 "phase2-ca-cert" 属性指定的任何证书一起加入到验证链。如果以 --system-ca-path 提供的路径不是文件名（捆绑或受信任 CA 证书），它会变成覆盖 "ca-cert" 和 "phase2-ca-cert" 属性（为 wpa_supplicant 设定 ca_cert/ca_cert2 选项）。 如果为TRUE，则设置（例如 APN，用户名或密码）将默认为与调制解调器将在移动宽带提供商数据库中注册的网络相匹配的值。 当时使用 WEP 时（示例，key-mgmt = "none" 或 "ieee8021x"）表示接入点这里需要 802.11 验证算法。其中的 "open" 用于开放系统（Open System），"shared" 用于共享密钥，而 "leap" 用于思科 LEAP。当使用思科 LEAP（示例，key-mgmt = "ieee8021x" 和 auth-alg = "leap"）时，必须指定 "leap-username" 和 "leap-password" 属性。 当设定为大于 0 的值时，配置此设备使用指定的速度。如果 "auto-negotiate" 为 "yes"，只有指定的速度会在链路自动协商过程中被通告：这只对 BASE-T 802.3 规范有效并用于强制吉比特模式，因为在这些情况下链路协商时强制性的。如果值未设定（0，默认值），链路配置要么将被忽略（如果 "auto-negotiate" 为 "no"，默认值）要么将被自动协商（如果 "auto-negotiate" 为 "yes"），并且本地设备将通告所有支持的双工模式。单位为 Mbit/s，例如 100 == 100Mbit/s。如果非零，必须与 "duplex" 属性一块设定。在指定速度值前请确保您的设备支持。 设定值时，"half" 和 "full" 二选一，配置设备要使用的指定双工模式。如果 "auto-negotiate" 为 "yes"，只有指定的模式会在链路自动协商过程中被通告：这只对 BASE-T 802.3 规范有效并用于强制吉比特模式，因为在这些情况下链路协商时强制性的。如果值未设定（默认值），链路配置要么将被忽略（如果 "auto-negotiate" 为 "no"，默认值）要么将被自动协商（如果 "auto-negotiate" 为 "yes"），并且本地设备将通告所有支持的双工模式。如果指定，必须与 "speed" 属性一块设定。在指定双工模式前请确保您的设备支持。 当使用静态 WEP 时（例如 key-mgmt = "none"）并且接入点使用非默认的 WEP 密钥索引，在这里设置该 WEP 密钥索引。有效值从 0（默认密钥）到 3。注意有些用户接入点（如 Linksys WRT54G）编号密钥为 1～4。 是否为连接启用 LLDP。 连接是否启用本地链路多播名称解析（LLMNR）。LLMNR 是一个基于域名系统（DNS）数据包格式的协议，它允许 IPv4 和 IPv6 主机对位于同一本地链路中的主机进行名称解析。允许的值有："yes" (2) 注册主机名并为连接进行解析，"no" (0) 在接口中禁用 LLMNR，"resolve" (1) 不注册主机名，但允许解析 LLMNR 主机名。如果未指定，"default" 将取决于 DNS 插件 (systemd-resolved 当前代表 "yes")。这个功能需要支持 LLMNR 的插件，否则设置无效。比如 dns-systemd-resolved 这个插件。 是否为连接启用 mDNS。允许的值为："yes" (2) 为连接注册主机名和解析，"no" (0) 禁用接口的mDNS，"resolve" (1) 不注册主机名，但允许解析 mDNS 主机名，"default" (-1) 允许在 NetworkManager.conf 中查找全局默认值。如果没有指定，"default" 最终取决于 DNS 插件（对于systemd-resolved 目前代表"no"）。这个功能需要一个支持 mDNS 的插件，否则设置无效。比如 dns-systemd-resolved 这个插件。 NetworkManger 激活此连接时，是否自动启动此连接的从连接。这只对主连接有实际效果。属性 "autoconnect"、"autoconnect-priority" 和 "autoconnect-retries" 跟此设置无关。允许的值有：0：保持从连接不变；1：激活此连接的所有从连接；-1：默认。如果设为 -1（默认）时，读取全局 connection.autoconnect-slaves 以确定实际值。如果它也是默认的，此设置回落到 0。 802.1X 身份验证是否是可选设置。如果为TRUE，即使在超时或身份验证失败后，激活操作仍将继续。当前仅允许为以太网连接把这个属性设置为 TRUE。如果设置为 FALSE，则只有在成功通过身份验证后才能继续激活操作。 连接是否按流量计费。当在当前激活的连接上更新此属性时，更改立即生效。 接口是否应为 MACVTAP。 是否应将接口置于混杂模式。 代理配置是否只用于浏览器。 此连接上的系统主机名是否能由 DHCP 决定。当设为 NM_TERNARY_DEFAULT (-1)，使用全局配置的值。如果全局配置也没有设定值，NetworkManager 则假定值为 NM_TERNARY_TRUE (1)。 此连接上的系统主机名是否能由反向 DNS 查找的地址决定。当设为 NM_TERNARY_DEFAULT (-1)，使用全局配置的值。如果全局配置也没有设定值，NetworkManager 则假定值为 NM_TERNARY_TRUE (1)。 是否加密传输的流量。 是否为 peer 的 AllowedIPs 范围自动添加路由。如果为 TRUE (默认设置)，NetworkManager 会根据 ipv4.route-table 和 ipv6.route-table 在路由表中自动添加路由。通常情况下这个自动性应该被启用。如果为 FALSE，不会自动添加路由。在这种情况下，用户需要分别在 ipv4.routes 和  ipv6.routes 中添加静态路由。注意，如果 peer 的AllowedIPs 为 "0.0.0.0/0" 或 "::/0"，并且启用了配置文件的 ipv4.never-default 或 ipv6.never-default 设置，则不会自动添加该 peer 的路由。 是否通过兼容的驱动程序自动探测虚拟功能（virtual function）。如果设为 NM_TERNARY_TRUE (1)，内核将尝试绑定虚拟功能到兼容的驱动，而且如果成功，每个虚拟功能都将实例化一个新的网络接口。如果设为 NM_TERNARY_FALSE (0)，虚拟功能将不被声明且不会为它们创建网络接口。当设为 NM_TERNARY_DEFAULT (-1) 时，使用全局默认值；全局默认未指定的情况下则假定为 NM_TERNARY_TRUE (1)。 是否在此隧道启用路径 MTU 发现。 Wi-Fi 自动 客户端 Wi-Fi P2P Wi-Fi P2P 连接 Wi-Fi 连接 Wi-Fi 连接 %d Wi-Fi 网络模式；"infrastructure"、"mesh"、"adhoc" 或 "ap" 之一。如果留空，假定为 infrastructure。 Wi-Fi 无线电开关 Wi-Fi 扫描列表 无 Wi-Fi 安全设置 WiMAX WiMAX NSP 名称 WiMAX 连接 WireGuard WireGuard VPN secret WireGuard VPN 设置 WireGuard 私钥 有线 有线 802.1X 身份验证 有线以太网 有线连接 有线连接 %d 用于 Wi-Fi 连接的无线信道。设备将只在指定的信道上加入（或创建 Ad-Hoc 网络）Wi-Fi 网络。因为信道号码在不同频段间重复，此属性也需要设定 "band" 属性。 "cloned-mac-address" 设置为 "random" 或 "stable" 时，按默认 MAC 地址的所有位都被扰乱，并创建一个本地管理的单播 MAC 地址。 此属性允许指定某些位为固定的。请注意，第一个 MAC 地址的最低有效位始终未被设置以创建单播MAC地址。如果属性为 NULL，它可以被默认的连接设置覆盖。如果该值还是 NULL 或为空字符串，默认值就为创建一个本地管理的单播 MAC 地址。如果该值包含一个 MAC 地址，此地址用作掩码。掩码的设置位将以设备的当前 MAC 地址填充，而未设置位将随机化。设为 "FE:FF:FF:00:00:00" 表示保留当前 MAC 地址的 OUI 且使用 "random" 或 "stable" 算法只随机最低三位。如果该值在掩码后包含一个附加的 MAC 地址，使用此地址来代替当前的 MAC 地址去填充那些不应该随机的位。示例，值 "FE:FF:FF:00:00:00 68:F7:28:00:00:00" 将设定 MAC 地址的 OUI 为  68:F7:28，而更低位随机化。值 "02:00:00:00:00:00 00:00:00:00:00:00" 将创建完全扰乱的全局管理烧录的 MAC 地址。如果值包含多个附加 MAC 地址，就随机选择其中一个。示例，"02:00:00:00:00:00 00:00:00:00:00:00 02:00:00:00:00:00" 将创建完全扰乱的 MAC 地址，随机地选择本地或全局管理。 写入 %s 失败：%s
 异或 您可以多次指定此选项。按下 <回车键> 以完成。
 您可以编辑下列属性：%s
 您可编辑下列设置：%s
 您可以运行 "verify fix" 来修复错误。
 [ 类型：%s | 名称：%s | UUID：%s | 变动：%s | 临时：%s ]
 ["%s" 设置值]
 [NM 属性描述] [nmcli 特定描述] 使用 "%s" 验证的连接无法指定 WPA 密文 使用 "%s" 验证的连接无法指定 WPA 协议 使用 "%s" 验证的连接无法指定 WPA 密码 使用 "%s" 验证的连接无法使用 WPA 密钥管理 只有启用路径 MTU 发现时才允许固定的 TTL 网关与 "%s" 不兼容 访问遭到拒绝 操作名缺失。 activate [<接口名>] [/<ap>|<nsp>]  :: 激活连接

激活连接。

可用选项：
<接口名>    - 将激活连接的设备。
/<ap>|<nsp> - AP (Wi-Fi) 或者 NSP (WiMAX)（未指定 <接口名> 时前置 / 符号。）
 已激活 激活中 add [<值>]  :: 附加新值到这个属性

如果该属性为容器类型，则这个命令在这个属性中添加提供的 <值>。对于单值属性，它会替换该值（和 "set" 一样）。
 通告、  为代理拥有、  睡眠中 属性 "%s"  对于 "%s" 无效 属性对 IPv4 路由无效 属性对 IPv6 路由无效 验证 自动 自动连接 back  :: 转到上层菜单

 带宽百分比总和必须为 100%% 二进制数据缺失 蓝牙连接 静态链路配置需要设置速度和双工 速度和双工都应设定有效值或者都保持未设定 字节 只能为以太网连接启用 无法设定属性：%s 如果手工配置，则不能启用 不能同时启用和禁用 无法从类型为 "%s%s" 的值设置类型为 "" 的属性 无法为规则检测到地址家族 由于缺少 "%s%s"，无法加载 VPN 插件 ""。缺少客户端插件？ 无法在 "%s" 里加载 VPN 插件：无效的服务名称 无法在 "%s" 里加载 VPN 插件：缺少插件名称 无法为 "%s%s" 加载旧版限定的 VPN 插件 "" 无法加载插件 "%s"：%s 无法从文件 "%s" 读取 PAC 脚本 无法从文件 "%s" 读取组合（team）配置 无法为 VPN 设置设定 connection.multi-connect 无法设定空的 %s 选项 无法为 lacp 和 activebackup runner 一起设置参数 证书无效 证书是无效的：%s 证书或密钥文件 "%s" 不存在 change  :: 更改当前值

显示当前值并允许编辑它。
 除非 "%s" 包含 1（启用），否则更改无法生效 信道不能在 %d 和 %d 之间 coalesce 选项必须是 0 或 1 冲突的 secret 标记 mac-address-randomization 和 cloned-mac-address 的值冲突 已连接 连接（外部） 已连接（仅本地） 已连接（仅站点） 连接中 连接中（正在检查 IP 连接性） 连接中（正在配置） 连接（外部） 连接中（正在获取 IP 配置） 连接中（需要验证） 连接中（准备） 连接中（正在启动次级连接） 连接 连接可用 连接和接入点不匹配 连接不匹配设备 连接与 mesh 点不匹配 连接失败 %s %u 连接类型 "%s" 无效 连接可用 对象 "%2$s" 的构造属性 "%1$s" 在构造后不能被设定 数据缺失 已停用 停用中 取消激活（外部） 默认 值 %s 的末尾有舍弃的分号："%s" describe  :: 描述属性

显示属性描述。您可以参阅 nm-settings(5) 手册页来查看所有的网络管理器（NetworkManager）设置和属性。
 describe [<设置>.<属性>]  :: 描述属性

显示属性描述。您可以参阅 nm-settings(5) 手册页来查看全部的网络管理器（NetworkManager）设置和属性。
 设备 "%s" 与连接 "%s" 不兼容 设备 "%s" 与连接 "%s" 不兼容： 已禁用 已断开 断开中 不知道如何获取属性值 重复的 D-Bus 属性 "%s" 重复的虚拟功能索引 %u 重复的网桥 VLAN vid %u 重复的 "%s" 重复的 %s 重复的关键字 "%s" 重复的属性 重复的设置名称 元素无效 空文本没有描述一个规则 已启用 启用、  加载设置值时出错：%s 统计文件 %s 失败：%s 加载 VPN 插件 "%s" 失败：%s 从 %s 加载 nm_vpn_editor_plugin_factory() 失败（%s） 设定绑定属性失败 %s 设定属性失败：%s 选择字段失败 字段 "%s" 必须是单独的 文件 "%s" 包含无效的 utf-8 %s 的文件权限 文件名具有无效的格式（%s） 文件名必须为绝对路径（%s） 标记无效 标志无效 标志无效 — 已禁用 完全 缺失固件 值 %s 的末尾有无用信息："%s" 如果没有配置地址，网关会无法设置 网关无效 goto <设置>[.<属性>] | <属性>  :: 进入设置/属性进行编辑

该命令进入设置或属性来进行编辑。

示例：nmcli> goto connection
      nmcli connection> goto secondaries
      nmcli> goto ipv4.addresses
 带有 from/src 但是 prefix-length 为 0 必须匹配 PKCS#12 的 "%s" 属性 带有 to/dst 但是 prefix-length 为 0 help/? [<命令>]  :: nmcli 命令的帮助

 help/? [<命令>]  :: nmcli 命令的帮助

 硬件 已硬件禁用 接口 忽略无效的 %s 地址：%s 忽略无效的 %s 路由：%s 忽略无效的 DNS 服务器 IPv%c 地址 "%s" 忽略无效的 MAC 地址 忽略无效的 SSID 忽略无效的绑定（bond）选项 %s%s%s = %s%s%s：%s 忽略无效的字节元素 "%u"（不在 0 和 255 之间） 忽略 %s%s 路由的无效网关 "" 忽略无效的数字 "%s" 忽略无效的原始密码 忽略无效的组合（team）配置：%s 忽略缺失的数字 "--order" 选项里有错误项 "%s" "--order" 选项的字符串 "%s" 错误 接口名包含无效字符 接口名长度超过 15 字符 缺少接口名 接口名被保留 接口名太短 接口名称必须是 UTF-8 编码 接口名称必须是字母数字，没有正反斜杠 接口名称不能为空 软件 infiniband 设备的接口名必须为 "%s" 或未设置（但现在是 "%s"） 无效的 "family" 无效的 "from" 部分 无效的 "to" 部分 无效的 "name" "%s" 无效的 D-Bus 属性 "%s" 无效的 D-Bus 属性 "%s"（"%s"） 无效的 D-Bus 类型 "%s" 无效的 DUID peer 的 allowed-ip 无效的 IP 地址 "%s" 无效的 IP 地址：%s 无效的 IPv%c 地址 "%s" 无效的 IPv4 或子网 "%s" 位置 %d 有无效的 JSON（%s） 无效的 PKCS#11 URI "%s" 无效的虚拟功能 %u：%s 无效的操作类型 无效操作： 无效的 地址家族 无效的属性类型 "%s" 无效的属性：%s 无效的验证标记 布尔值 "%1$s" 对属性 "%2$s" 无效 无效的证书格式 无效的目标端口范围 peer 无效的端点 无效字段 "%s%s%s%s%s"；%s%s%s 无效字段 "%s%s%s"；允许的字段：[%s] 无效字段 "%s%s%s"；没有此类字段 无效字段 "%s"；允许的字段为 %s 和 %s，或 %s,%s 对 %d%s 无效的文件所有者 无效的 from/src 无效的网关地址 "%s" 无效的句柄："%s" 无效的 iifname uint32 值 "%s" 对属性 "%s" 无效 无效的 json 无效的  "%s" 无效的密钥 "%s"：%s 无效的密钥 "%s" 无效的密钥 "%s.%s" 无效的密钥/证书值 无效的密钥/证书值 data:;base64，不是 base64 无效的密钥/证书值 data:;base64,file:// 无效的密钥/证书值，不是有效的比特块（blob） 无效的密钥/证书值路径 "%s" 无效的 link-watcher：%s 无效的 oifname 无效选项 "%s" 无效选项 "%s"，请使用 [%s] 的组合 无效选项 "%s"，请使用 [%s] 中的一个。 无效的奇偶校验值 "%s" 行 %2$zd: %3$s 存在无效的 passwd-file "%1$s" 无效的 passwd-file "%s"：%s "%s" 项中存在无效的对等端公钥 无效的 peer secrets 无效的权限 "%s" 无效的权限，没有以 "user:$UNAME[:]" 为格式 无效的前缀 %s %s 的前缀长度 "%s" 无效，默认为 %d from/src 无效的前缀长度 to/dst 无效的前缀长度 peer 无效的 preshared-key peer 无效的 preshared-key-flags 无效的优先级映射 "%s" 无效的代理方法 peer 无效的 public-key 无效的排队规则（qdisc）：%s 无效路由：%s。%s 无效的 runner-tx-hash %2$s:%3$zu 有无效的机密（secret）"%1$s" 无效的设置名称 无效的设置名称 "%s" 无效设置：%s 无效的源端口范围 无效的流量过滤器（tfilter）：%s 无效的 to/dst uint32 值 "%1$s" 对属性 "%2$s" 无效 uint8 值 "%s" 对属性 "%s" 无效 uint8 值 "%1$s" 对属性 "%2$s" 无效 无效值 值 "%s" 对选项 "%s" 无效 "%s" 无效的值 对 "%s" 无效的值：%s %2$s:%3$zu 有无效的值 "%1$s" 值对于密钥 "%s" 无效 无效的变体类型 "%s"（对于 "%s"） ip4 默认 ip6 默认 是空的 不是 JSON 对象 不是有效的 MAC 地址 不是一个有效的 VLAN 过滤协议 不是一个有效的链路本地 MAC 地址 不是一个有效的选项 "%s.%s" 包括无效的 allowed-ips "%s.%s" 不是在 0 到 2^32 范围内的一个整数 key "%s.%s" 不是一个 uint32 密钥 "%s.%s" 不是一个以 base64 编码的有效的 256 位密钥 "%s.%s" 不是一个有效的端点 "%s.%s" 不是一个有效的机密（secret）标记 密钥 "%s.%s" 不是布尔值 密钥不能包含 ".." 密钥不能以 "NM." 开头 密钥包含无效的字符 密钥太长 密钥需要是基于 base64 编码的 32 个字节 密码必须是 UTF-8 格式 密钥需要 "." 用于命名空间 缺少种类 不支持 libtool 归档（%s） 受限 %s %s macvlan 连接 缺少必填选项 "%s" 主连接 已达到最大的用户数据输入项 已达到最大的用户数据输入项（现为 %u，最大只有 %u ） 计量值 %d 无效 方法 "%s" 不支持 WireGuard 毫秒 缺少 "family" 缺少 "plugin" 设置 缺少 "name" 属性 "%s" 缺少参数 缺少 "<设置>.<属性>:<机密>" 格式中的冒号 缺少 "<设置>.<属性>:<机密>" 格式中的点 缺少文件名 缺少文件名来加载 VPN 插件信息 一个非 0 的 prefix-length 但没有 from/src 缺少密钥 在 "%2$s" 后缺少键值对分隔符 "%1$c" 缺少链路监视器 缺少 VPN 插件信息的名称 缺少名称，请尝试使用 [%s] 之一。 缺少选项名 缺少 %s 的前缀长度  "%s"，默认为 %d 缺少 "<设置>.<属性>:<机密>" 格式的属性 peer 缺少 public-key 缺少 VPN 插件信息的服务 缺少设置 缺少 "<设置>.<属性>:<机密>" 格式的设置 缺少表 一个非 0 的 prefix-length 但没有 to/dst mtu mtu 最大为 %u，但它的值是 %u "%s=%s" 不允许多个地址 必须为 psk (0) 或 eap (1) 必须包含 8 个用逗号分隔的数字 名称 没有给定有效的连接或设备 从不 新主机名 nmcli [<配置选项> <值>]  :: nmcli 配置

配置 nmcli。可用以下选项：
status-line yes | no          [默认：no]
save-confirmation yes | no    [默认：yes]
show-secrets yes | no         [默认：no]
prompt-color <颜色> | <0-8>  [默认：0]
%s
示例：nmcli> nmcli status-line yes
      nmcli> nmcli save-confirmation no
      nmcli> nmcli prompt-color 3
 nmcli 可接受直接 JSON 配置数据和包含该配置的文件名。在后一种情况下会读取该文件并将内容放到这个属性中。

例如：set team.config { "device": "team0", "runner": {"name": "roundrobin"}, "ports": {"eth1": {}, "eth2": {}} }
          set team.config /etc/my-team.conf
 nmcli 已成功地注册为网络管理器（NetworkManager）的密钥（secret）代理。
 nmcli 已成功地注册为 polkit 代理。
 nmcli 工具，版本 %s
 %s：%s %s：%s 到 %s 否 否（猜测） 设备 "%s" 上没有活动的连接 没有活动的连接或设备 没有找到可用于连接 "%s" 的设备 只有通过（passthru）模式才允许无混杂操作 不存在 peer "%s" 无 不是一个文件（%s） 不是密钥（secret）属性 在位置 %u%lld，该以太网 MAC 地址 # 无效 对于 %lld 位置的掩码，该以太网 MAC 地址无效 不是有效的 hex 字符串 无效的私钥 不必需、  未保存、  不是有效的 utf-8 "%s" 的值超出了范围 对象类 "%s" 没有名为 "%s" 的属性 关 开 只有 EUI64 地址生成模式才有意义 只有一个 VLAN 可以是 PVID 只对 psk 模式有效 openconnect 失败，信号为 %d openconnect 失败，状态为 %d openconnect 将运行以进行验证，完成后它将返回至 nmtui。 操作成功，但对象 %s 不存在 页需要在 %d 和 %d 之间 页需要和一个信道定义 缺少上级处理模块 未指定上级。 当证书不在 PKCS#11 令牌上时不支持密码 路径不是绝对路径（%s） peer #%u 带有无效的 allowed-ips 设置 peer #%u 带有无效的端点 peer #%u 带有无效的 public-key peer #%u 没有 public-key peer #%u 无效：%s peer #%u 缺少 public-key 对等端 "%s" 无效：%s 缺失插件 端口 入口 准备中 print [all]  :: 输出设置或连接值

显示当前属性或整个连接。

示例：nmcli ipv4> print all
 print [property|setting|connection]  :: 输出属性（设置、连接）值

显示属性。提供参数您也可以显示整个设置或连接的值。
 对象类 "%2$s" 的 "%1$s" 属性是不可写的 属性不能为空的字符串 属性不能多于 255 个字符 当设置了 dhcp-hostname 则不能设置属性 属性不能包含任何 nul 字节 属性无效 属性无效（未启用） 属性为空 属性为空或大小错误 属性无效 缺少属性 未指定属性 属性未指定，也不是 "%s:%s" 属性必须只包含数字 属性名不是UTF-8 方法设为禁用时属性应该是 TRUE 方法设为禁用时属性应该是 TRUE 属性类型应该设置为 "%s" 属性值 "%s" 为空或过长（>64） quit  :: 退出 nmcli

此命令用于退出 nmcli。当被编辑的连接没有保存时，会询问用户确定操作。
 注册失败 拒绝 %s remove <设置>[.<属性>]  :: 移除设置或重置属性值

该命令移除来自连接的输入项设置，或者如果给定属性，重置该属性为默认值。

示例：nmcli> remove wifi-sec
      nmcli> remove eth.mtu
 remove [<值>|<索引>|<选项名称>]  :: 删除属性值

移除属性值。对于单值属性，将属性设置回其默认值。对于容器类属性，这将删除该属性
的所有值，或者您可以指定参数只删除单项或选项。参数可以是要删除项的值或索引，又
或者是选项名称（具有命名选项的属性）。

示例: nmcli ipv4.dns> remove 8.8.8.8
      nmcli ipv4.dns> remove 2
      nmcli bond.options> remove downdelay

 使用 %s 请求成功，但对象处于不合适的状态 规则 #%u 无效：%s 规则无效：%s 运行中 s390 网络设备类型；"qeth"、"lcs" 或 "ctc" 之一，代表 s390 系统上可用的不同虚拟网络设备。 save [persistent|temporary]  :: 保存连接

发送连接配置集到网络管理器（NetworkManager），可以选择永久保存或者是只保存在内存里。不带参数
的 "save" 表示 "save persistent"。
请注意，一旦您永久地保存了配置集，这些设置在重启机器/NM 后都会存在。随后的修改
可以是临时的，也可以是永久的，但任何临时的修改在重启后都会复原。如果您想完全删
除永久性连接，连接配置集就必须被删除。
 秒 secret 标记不能为 "not-required" 未找到 secret 标记属性 secret 不是 UTF-8 密钥（secret）不是正确的类型 secret 名不能为空 未找到密钥 set [<设置>.<属性> <值>]  :: 设置属性值

该命令用于设置属性值。

示例：nmcli> set con.id 我的连接
 set [<值>]  :: 设置新值

此命令用于设置提供的 <值> 到该属性
 设置包含具有空名称的密钥 设置有无效的变量类型 对于非从连接，设置是必需的 从连接中不允许设置 未找到设置 类型为 "%s" 的连接需要设置 设置此属性要求 "%s" 属性不为零 slave-type "%s" 要求连接中有 "%s" 设置 有些标记对所选模式无效：%s 来源主机 "%s" 包含无效的字符 已启动 启动中 总和不是 100% 只有 to-table 操作允许 suppress_prefixlength suppress_prefixlength 超出范围 软件 已软件禁用 表大小不能为零 目标主机 "%s" 包含无效的字符 组合（team）配置超过大小限制 组合（team）配置文件 "%s" 包含无效的 utf-8 team 配置不是有效的 UTF-8 teamd 控制失败 密钥包含非十六进制字符 密钥为空 密钥必须是 %d 个字符 掩码不能包含位 0（STP）、1（MAC）或2（LACP） 跃点数（"%s"）必需在属性前 下一跳（"%s"）必须在首位 插件不支持导出功能 插件不支持导入功能 无法更改该属性 当 "%s" 被禁用时不能设置这个属性 该属性当前只被 DHCPv4 支持 脚本不是有效的 utf8 脚本太大 脚本缺少 FindProxyForURL 功能 标记 ID 必须在 0～4094 范围内，但其是 %u 值 "%s" 不是有效的 UUID vlan id 的必须在范围 0～4094 内，但却是 %u 存在重复的 TC 过滤器 存在重复的 TC 排队规则 已存在具有相同 %s.%s 值的冲突插件（%s） 已存在具有相同名称（%s）的冲突插件 "%s=%s" 不允许这个属性为空 此属性不允许用于"%s=%s" 无方法时不允许此属性 令牌不是规范形式 参数太多。只能指定一个私钥或再指定一个可选的密码 只能为 GRE 隧道指定隧道密钥 无法从类型 "%3$s" 的值设定类型为 "%2$s" 的属性 "%1$s" 不可用 对于 %2$s 的意外字符 "%1$c"："%3$s"（位置 %4$td） 对于地址 %2$s 的意外字符 "%1$c"："%3$s"（位置 %4$td） 对于 %2$s，前缀长度中有意外字符 "%1$c"："%3$s"（位置 %4$td） 非预期的 uuid %s，而不是 %s 未知 未知的 VPN 插件 "%s" 未知属性 未知属性 "%s" 未知的连接 "%s" 未知设备 "%s"。 初始化插件 %s 时出现未知错误 未知的 ethtool 选项 "%s" 未知标志 0x%x 未知的 link-watcher 名 "%s" 未知属性 未知的 secret 标记 未知的设置名称 未托管 无法识别的行 %s:%zu 不支持的操作选项："%s"。 不支持类型 "%2$s" 的属性 "%1$s" 不支持的 ethtool 设置 不支持的 "%s" 不支持的排队规则（qdisc）选项："%s"。 不支持的 secret 标记 不支持的流量过滤器（tfilter）选项："%s"。 未结束的转义序列 先使用 "goto <设置>"，或 "describe <设置>.<属性>"
 先使用 "goto <设置>"，或 "set <设置>.<属性>"
 类型 "%2$s" 的值 "%1$s" 无效或超出类型为 "%4$s" 的属性 "%3$s" 范围 值 %d 无效 值 "%d" 超出了范围 <%d-%d> 值无法被解析为整数 "%s" 的值需要是一个布尔值 "%s" 的值需要是一个数字 值为 NULL 值为空 缺少值 值不是有效的令牌 值不是在 [%lld, %lld] 范围内的一个整数 值不是有效的 UTF-8 值太大 值超出范围 verify [all | fix]  :: 验证设置或连接的有效性

验证设置或连接是否有效和可以稍后保存。发生错误时它会指出无效的值。有些错误可以
通过 "fix" 选项自动修复。

示例：nmcli> verify
      nmcli> verify fix
      nmcli bond> verify
 veth 对等端 vlan 设置也应该有以太网设置 vlanid 超出范围 [-1, 4094] 愿意、  模式 %s 不允许有线设置 错误的类型；应为一个字符串列表。 是 是（猜测） 