Release of the NetworkManager 1.56.0 network configurator

A stable release of the interface for simplifying network configuration settings has been published — NetworkManager 1.56.0. Plugins for VPN support (Libreswan, OpenConnect, Openswan, SSTP, etc.) are being developed within their own development cycles.

Key features of NetworkManager 1.56:

  • The nmcli utility has been enhanced with the ability to view and manage peers for VPN WireGuard. nmcli connection modify wg0 wireguard.peers "8W…G1o= preshared-key=16…LQA= allowed-ips=0.0.0.0/0 persistent-keepalive=10" nmcli connection modify wg0 +wireguard.peers "fd2…BCc= allowed-ips=192.168.40.0/24 endpoint=172.25.10.1:8888" $ nmcli -g wireguard.peers connection show wg0 8W…1o= allowed-ips=0.0.0.0/0 persistent-keepalive=10, fd…BCc= allowed-ips=192.168.40.0/24 endpoint=172.25.10.1:8888 $ nmcli connection modify wg0 -wireguard.peers 8W…eG1o= $ nmcli -g wireguard.peers connection show wg0 fd2…BCc= allowed-ips=192.168.40.0/24 endpoint=172.25.10.1:8888
  • A new parameter device-uid has been added to the settings section "[gsm]" to allow connections only to specified devices. [gsm] apn=internet2.voicestream.co device-uid=MODEM1
  • For expanding MPTCP (Multipath TCP), which allows packets to be delivered simultaneously over multiple routes via different network interfaces, a new endpoint type "laminar" has been implemented, which is set by default along with the type "subflow". This new type does not rely on routing rules when selecting a local IP address in situations where the client uses multiple different addresses. server is using multiple different addresses.
  • The logic for applying settings from the "[global-dns]" section has been changed, now overriding the settings in the "search" and "options" lists obtained during the connection setup, rather than merging with them.
  • Support for host names returned via DNS that are larger than 64 bytes has been implemented.
  • Properties "hsr.protocol-version" and "hsr.interlink" have been added to configure the version and port number for the HSR (High-availability Seamless Redundancy) protocol.
  • Support for reapplying properties "sriov.vfs" and "bond-port.vlans" has been added.
  • A new option rd.net.dhcp.client-id has been added in nm-initrd-generator.
  • The ability to apply the option "connection.dnssec" for selective configuration of DNSSEC parameters in systemd-resolved has been implemented.
  • Functions have been added to the libnm library that can be utilized in VPN plugins to check if the user has rights to access keys and certificates.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster