stable release of the interface for simplifying network parameter configuration — . to support VPN, OpenConnect, PPTP, OpenVPN, and OpenSWAN, developed within their own development cycles.
NetworkManager 1.26:
- A new build option 'firewalld-zone' has been added. When enabled, NetworkManager will configure the firewalld dynamic firewall zone for shared connections, and when new connections are activated, it will place network interfaces in this zone. To open ports for DNS and DHCP, as well as for address translation, NetworkManager still invokes iptables. The new firewalld-zone option may be useful for systems using firewalld with an nftables backend, where iptables usage is insufficient.
- The syntax of the match properties has been extended, now allowing the use of operations '|', '&', '!' and '\'.
- For connection profiles, the MUD URL property has been added (, Manufacturer Usage Description) and its configuration has been ensured for DHCP and DHCPv6 requests.
- In the ifcfg-rh plugin, the handling of the properties 802-1x.pin and '802-1x.{,phase2-}ca-path' has been added.
- The vulnerability in nmcli has been addressed , to ignoring the parameters 802-1x.ca-path and 802-1x.phase2-ca-path when creating a new connection profile. When attempting to connect to a network under this profile, authentication was not performed, resulting in an insecure connection. The vulnerability manifests only in builds using the ifcfg-rh plugin for configuration.
- For Ethernet, original settings for auto-negotiation, speed and duplex are reset when the device is deactivated.
- Support for the 'coalesce' and 'ring' options of the ethtool utility has been added.
- The ability to operate team connections without D-Bus (e.g., in initrd) has been provided.
- For Wi-Fi, auto-connection attempts are allowed to continue after failures of previous activation attempts (the initial connection setup failure no longer blocks auto-connection, but auto-connection attempts may resume for existing blocked profiles).
- Support for 'local' route types, in addition to 'unicast', has been added.
- The man pages nm-settings-dbus and nm-settings-nmcli have been included.
- Support for marking externally managed devices and profiles via D-Bus is provided. Such devices, which are managed through an external handler, are now specifically marked in nmcli.
- Support for setting options for network bridges has been added.
- Match-matching for the device path, driver, and kernel parameters has been added to connection profiles.
- Support for traffic shaping disciplines bf and sfq has been added.
- A provider for Google Cloud Platform has been implemented in nm-cloud-setup, which automatically detects and configures traffic retrieval from internal load balancers.
Source: opennet.ru
