diff --git a/man/systemd.network.xml b/man/systemd.network.xml index 5c1c6e118ee..15ba1dfb06d 100644 --- a/man/systemd.network.xml +++ b/man/systemd.network.xml @@ -1616,79 +1616,9 @@ IPv6Token=prefixstable:2002:da8:1:: DHCP= setting described above: - - UseDNS= - - When true (the default), the DNS servers received from the DHCP server will be used. - This corresponds to the - option in resolv.conf5. - - - - RoutesToDNS= - - When true, the routes to the DNS servers received from the DHCP server will be - configured. When UseDNS= is disabled, this setting is ignored. - Defaults to true. - - - - UseNTP= - - When true (the default), the NTP servers received from the DHCP server will be used by - systemd-timesyncd.service. - - - - RoutesToNTP= - - When true, the routes to the NTP servers received from the DHCP server will be - configured. When UseNTP= is disabled, this setting is ignored. - Defaults to true. - - - - UseSIP= - - When true (the default), the SIP servers received from the DHCP server will be collected - and made available to client programs. - - + - - UseMTU= - - When true, the interface maximum transmission unit - from the DHCP server will be used on the current link. - If MTUBytes= is set, then this setting is ignored. - Defaults to false. - - - - Anonymize= - - Takes a boolean. When true, the options sent to the DHCP server will follow the - RFC 7844 (Anonymity Profiles for - DHCP Clients) to minimize disclosure of identifying information. Defaults to false. - - This option should only be set to true when MACAddressPolicy= is - set to random (see - systemd.link5). - - - When true, SendHostname=, ClientIdentifier=, - VendorClassIdentifier=, UserClass=, - RequestOptions=, SendOption=, - SendVendorOption=, and MUDURL= are ignored. - - With this option enabled DHCP requests will mimic those generated by Microsoft - Windows, in order to reduce the ability to fingerprint and recognize installations. This - means DHCP request sizes will grow and lease data will be more comprehensive than normally, - though most of the requested data is not actually used. - - SendHostname= @@ -1699,6 +1629,15 @@ IPv6Token=prefixstable:2002:da8:1:: + + Hostname= + + Use this value for the hostname which is sent to the DHCP server, instead of machine's hostname. + Note that the specified hostname must consist only of 7-bit ASCII lower-case characters and + no spaces or dots, and be formatted as a valid DNS domain name. + + + MUDURL= @@ -1715,74 +1654,15 @@ IPv6Token=prefixstable:2002:da8:1:: - - UseHostname= - - When true (the default), the hostname received from - the DHCP server will be set as the transient hostname of the system. - - - - - Hostname= - - Use this value for the hostname which is sent to the DHCP server, instead of machine's hostname. - Note that the specified hostname must consist only of 7-bit ASCII lower-case characters and - no spaces or dots, and be formatted as a valid DNS domain name. - - - - UseDomains= - - Takes a boolean, or the special value route. When true, the domain name - received from the DHCP server will be used as DNS search domain over this link, similar to the effect of - the setting. If set to route, the domain name received from - the DHCP server will be used for routing DNS queries only, but not for searching, similar to the effect of - the setting when the argument is prefixed with ~. Defaults to - false. - - It is recommended to enable this option only on trusted networks, as setting this affects resolution - of all hostnames, in particular of single-label names. It is generally safer to use the supplied domain - only as routing domain, rather than as search domain, in order to not have it affect local resolution of - single-label names. - - When set to true, this setting corresponds to the option in resolv.conf5. - - - - UseRoutes= - - When true (the default), the static routes will be requested from the DHCP server and added to the - routing table with a metric of 1024, and a scope of "global", "link" or "host", depending on the route's - destination and gateway. If the destination is on the local host, e.g., 127.x.x.x, or the same as the - link's own address, the scope will be set to "host". Otherwise if the gateway is null (a direct route), a - "link" scope will be used. For anything else, scope defaults to "global". - - - - UseGateway= - - When true, the gateway will be requested from the DHCP server and added to the routing table with a - metric of 1024, and a scope of "link". When unset, the value specified with - is used. - - - - UseTimezone= - When true, the timezone received from the - DHCP server will be set as timezone of the local - system. Defaults to no. - - ClientIdentifier= - The DHCPv4 client identifier to use. Takes one of mac, duid or duid-only. - If set to mac, the MAC address of the link is used. - If set to duid, an RFC4361-compliant Client ID, which is the combination of IAID and DUID (see below), is used. - If set to duid-only, only DUID is used, this may not be RFC compliant, but some setups may require to use this. - Defaults to duid. + The DHCPv4 client identifier to use. Takes one of , + or . If set to , the + MAC address of the link is used. If set to , an RFC4361-compliant Client + ID, which is the combination of IAID and DUID (see below), is used. If set to + , only DUID is used, this may not be RFC compliant, but some setups + may require to use this. Defaults to . @@ -1797,28 +1677,18 @@ IPv6Token=prefixstable:2002:da8:1:: UserClass= - A DHCPv4 client can use UserClass option to identify the type or category of user or applications - it represents. The information contained in this option is a string that represents the user class of which - the client is a member. Each class sets an identifying string of information to be used by the DHCP - service to classify clients. Takes a whitespace-separated list of strings. - - - - - MaxAttempts= - - Specifies how many times the DHCPv4 client configuration should be attempted. Takes a - number or infinity. Defaults to infinity. Note that the - time between retries is increased exponentially, up to approximately one per minute, so the - network will not be overloaded even if this number is high. The default is suitable in most - circumstances. + A DHCPv4 client can use UserClass option to identify the type or category of user or + applications it represents. The information contained in this option is a string that represents + the user class of which the client is a member. Each class sets an identifying string of + information to be used by the DHCP service to classify clients. Takes a whitespace-separated list + of strings. DUIDType= - Override the global DUIDType setting for this network. See + Override the global DUIDType= setting for this network. See networkd.conf5 for a description of possible values. @@ -1827,7 +1697,7 @@ IPv6Token=prefixstable:2002:da8:1:: DUIDRawData= - Override the global DUIDRawData setting for this network. See + Override the global DUIDRawData= setting for this network. See networkd.conf5 for a description of possible values. @@ -1836,100 +1706,35 @@ IPv6Token=prefixstable:2002:da8:1:: IAID= - The DHCP Identity Association Identifier (IAID) for the interface, a 32-bit unsigned integer. + The DHCP Identity Association Identifier (IAID) for the interface, a 32-bit unsigned + integer. - RequestBroadcast= + Anonymize= - Request the server to use broadcast messages before - the IP address has been configured. This is necessary for - devices that cannot receive RAW packets, or that cannot - receive packets at all before an IP address has been - configured. On the other hand, this must not be enabled on - networks where broadcasts are filtered out. - - + Takes a boolean. When true, the options sent to the DHCP server will follow the + RFC 7844 (Anonymity Profiles for + DHCP Clients) to minimize disclosure of identifying information. Defaults to false. - - RouteMetric= - - Set the routing metric for routes specified by the DHCP server. Takes an unsigned - integer in the range 0…4294967295. Defaults to 1024. - - - - - RouteTable=num - - The table identifier for DHCP routes (a number between 1 and 4294967295, or 0 to unset). - The table can be retrieved using ip route show table num. - - When used in combination with VRF=, the - VRF's routing table is used when this parameter is not specified. + This option should only be set to true when MACAddressPolicy= is + set to (see + systemd.link5). + + When true, SendHostname=, ClientIdentifier=, + VendorClassIdentifier=, UserClass=, + RequestOptions=, SendOption=, + SendVendorOption=, and MUDURL= are ignored. + + With this option enabled DHCP requests will mimic those generated by Microsoft + Windows, in order to reduce the ability to fingerprint and recognize installations. This + means DHCP request sizes will grow and lease data will be more comprehensive than normally, + though most of the requested data is not actually used. - - RouteMTUBytes= - - Specifies the MTU for the DHCP routes. Please see the [Route] section for further details. - - - - - ListenPort= - - Allow setting custom port for the DHCP client to listen on. - - - - - FallbackLeaseLifetimeSec= - - Allows to set DHCPv4 lease lifetime when DHCPv4 server does not send the lease lifetime. - Takes one of forever or infinity means that the address - never expires. Defaults to unset. - - - - - SendRelease= - - When true, the DHCPv4 client sends a DHCP release packet when it stops. - Defaults to true. - - - - - SendDecline= - - A boolean. When true, the DHCPv4 client receives the IP address from the - DHCP server. After a new IP is received, the DHCPv4 client performs IPv4 Duplicate Address - Detection. If duplicate use is detected, the DHCPv4 client rejects the IP by sending a - DHCPDECLINE packet and tries to obtain an IP address again. See RFC 5224. Defaults to - unset. - - - - - DenyList= - - A whitespace-separated list of IPv4 addresses. DHCP offers from servers in the list are rejected. Note that - if AllowList= is configured then DenyList= is ignored. - - - - - AllowList= - - A whitespace-separated list of IPv4 addresses. DHCP offers from servers in the list are accepted. - - - RequestOptions= @@ -1969,7 +1774,224 @@ IPv6Token=prefixstable:2002:da8:1:: then all options specified earlier are cleared. Defaults to unset. - + + + + + UseDNS= + + When true (the default), the DNS servers received from the DHCP server will be used. + + This corresponds to the + option in resolv.conf5. + + + + + RoutesToDNS= + + When true, the routes to the DNS servers received from the DHCP server will be + configured. When UseDNS= is disabled, this setting is ignored. + Defaults to true. + + + + + UseNTP= + + When true (the default), the NTP servers received from the DHCP server will be used by + systemd-timesyncd.service. + + + + + RoutesToNTP= + + When true, the routes to the NTP servers received from the DHCP server will be + configured. When UseNTP= is disabled, this setting is ignored. + Defaults to true. + + + + + UseSIP= + + When true (the default), the SIP servers received from the DHCP server will be collected + and made available to client programs. + + + + + UseMTU= + + When true, the interface maximum transmission unit from the DHCP server will be used on the + current link. If MTUBytes= is set, then this setting is ignored. Defaults to + false. + + + + + UseHostname= + + When true (the default), the hostname received from the DHCP server will be set as the + transient hostname of the system. + + + + + UseDomains= + + Takes a boolean, or the special value . When true, the domain name + received from the DHCP server will be used as DNS search domain over this link, similar to the + effect of the setting. If set to , the domain + name received from the DHCP server will be used for routing DNS queries only, but not for + searching, similar to the effect of the setting when the argument is + prefixed with ~. Defaults to false. + + It is recommended to enable this option only on trusted networks, as setting this affects + resolution of all hostnames, in particular of single-label names. It is generally safer to use + the supplied domain only as routing domain, rather than as search domain, in order to not have it + affect local resolution of single-label names. + + When set to true, this setting corresponds to the option in + resolv.conf5. + + + + + + UseRoutes= + + When true (the default), the static routes will be requested from the DHCP server and added + to the routing table with a metric of 1024, and a scope of , + or , depending on the route's destination and + gateway. If the destination is on the local host, e.g., 127.x.x.x, or the same as the link's own + address, the scope will be set to . Otherwise if the gateway is null (a + direct route), a scope will be used. For anything else, scope defaults to + . + + + + + RouteMetric= + + Set the routing metric for routes specified by the DHCP server. Takes an unsigned + integer in the range 0…4294967295. Defaults to 1024. + + + + + RouteTable=num + + The table identifier for DHCP routes (a number between 1 and 4294967295, or 0 to unset). + The table can be retrieved using ip route show table num. + + When used in combination with VRF=, the + VRF's routing table is used when this parameter is not specified. + + + + + + RouteMTUBytes= + + Specifies the MTU for the DHCP routes. Please see the [Route] section for further details. + + + + + UseGateway= + + When true, the gateway will be requested from the DHCP server and added to the routing + table with a metric of 1024, and a scope of . When unset, the value specified + with UseRoutes= is used. + + + + + UseTimezone= + When true, the timezone received from the DHCP server will be set as timezone of + the local system. Defaults to false. + + + + FallbackLeaseLifetimeSec= + + Allows to set DHCPv4 lease lifetime when DHCPv4 server does not send the lease lifetime. + Takes one of forever or infinity means that the address + never expires. Defaults to unset. + + + + + + + RequestBroadcast= + + Request the server to use broadcast messages before the IP address has been configured. + This is necessary for devices that cannot receive RAW packets, or that cannot receive packets at + all before an IP address has been configured. On the other hand, this must not be enabled on + networks where broadcasts are filtered out. + + + + + MaxAttempts= + + Specifies how many times the DHCPv4 client configuration should be attempted. Takes a + number or infinity. Defaults to infinity. Note that the + time between retries is increased exponentially, up to approximately one per minute, so the + network will not be overloaded even if this number is high. The default is suitable in most + circumstances. + + + + + ListenPort= + + Allow setting custom port for the DHCP client to listen on. + + + + + DenyList= + + A whitespace-separated list of IPv4 addresses. DHCP offers from servers in the list are + rejected. Note that if AllowList= is configured then + DenyList= is ignored. + + + + + AllowList= + + A whitespace-separated list of IPv4 addresses. DHCP offers from servers in the list are + accepted. + + + + + SendRelease= + + When true, the DHCPv4 client sends a DHCP release packet when it stops. Defaults to + true. + + + + + SendDecline= + + A boolean. When true, the DHCPv4 client receives the IP address from the + DHCP server. After a new IP is received, the DHCPv4 client performs IPv4 Duplicate Address + Detection. If duplicate use is detected, the DHCPv4 client rejects the IP by sending a + DHCPDECLINE packet and tries to obtain an IP address again. See RFC 5224. Defaults to + unset. + + + + @@ -1978,55 +2000,25 @@ IPv6Token=prefixstable:2002:da8:1:: DHCP= setting described above, or invoked by the IPv6 Router Advertisement: - - UseAddress= - - When true (the default), the IP addresses provided by the DHCPv6 server will be - assigned. - - + + - UseDNS= - UseNTP= - UseHostname= - UseDomains= + MUDURL= IAID= DUIDType= DUIDRawData= + RequestOptions= As in the [DHCPv4] section. - RapidCommit= + SendOption= - Takes a boolean. The DHCPv6 client can obtain configuration parameters from a DHCPv6 server through - a rapid two-message exchange (solicit and reply). When the rapid commit option is enabled by both - the DHCPv6 client and the DHCPv6 server, the two-message exchange is used, rather than the default - four-message exchange (solicit, advertise, request, and reply). The two-message exchange provides - faster client configuration and is beneficial in environments in which networks are under a heavy load. - See RFC 3315 for details. - Defaults to true. - - - - - MUDURL= - - When configured, the specified Manufacturer Usage Description (MUD) URL will be sent to - the DHCPv6 server. The syntax and semantics are the same as for MUDURL= in the - [DHCPv4] section described above. - - - - - RequestOptions= - - When configured, allows to set arbitrary request options in the DHCPv6 request options list - that will be sent to the DHCPv6 server. A whitespace-separated list of integers in the range - 1…254. Defaults to unset. + As in the [DHCPv4] section, however because DHCPv6 uses 16-bit fields to store option + numbers, the option number is an integer in the range 1…65536. @@ -2035,12 +2027,12 @@ IPv6Token=prefixstable:2002:da8:1:: Send an arbitrary vendor option in the DHCPv6 request. Takes an enterprise identifier, DHCP option number, data type, and data separated with a colon (enterprise - identifier:option:type: - value). Enterprise identifier is an unsigned integer in the - range 1–4294967294. The option number must be an integer in the range 1–254. Data type takes one - of uint8, uint16, uint32, - ipv4address, ipv6address, or - string. Special characters in the data string may be escaped using :option:type:value). + Enterprise identifier is an unsigned integer in the range 1…4294967294. The option number must be + an integer in the range 1…254. Data type takes one of uint8, + uint16, uint32, ipv4address, + ipv6address, or string. Special characters in the data + string may be escaped using C-style escapes. This setting can be specified multiple times. If an empty string is specified, then all options specified earlier are cleared. Defaults to unset. @@ -2048,18 +2040,27 @@ IPv6Token=prefixstable:2002:da8:1:: - ForceDHCPv6PDOtherInformation= + UserClass= - Takes a boolean that enforces DHCPv6 stateful mode when the 'Other information' bit is set in - Router Advertisement messages. By default setting only the 'O' bit in Router Advertisements - makes DHCPv6 request network information in a stateless manner using a two-message Information - Request and Information Reply message exchange. - RFC 7084, requirement WPD-4, updates - this behavior for a Customer Edge router so that stateful DHCPv6 Prefix Delegation is also - requested when only the 'O' bit is set in Router Advertisements. This option enables such a CE - behavior as it is impossible to automatically distinguish the intention of the 'O' bit otherwise. - By default this option is set to 'false', enable it if no prefixes are delegated when the device - should be acting as a CE router. + A DHCPv6 client can use User Class option to identify the type or category of user or + applications it represents. The information contained in this option is a string that represents + the user class of which the client is a member. Each class sets an identifying string of + information to be used by the DHCP service to classify clients. Special characters in the data + string may be escaped using C-style + escapes. This setting can be specified multiple times. If an empty string is specified, + then all options specified earlier are cleared. Takes a whitespace-separated list of + strings. Note that currently NUL bytes are not allowed. + + + + + VendorClass= + + A DHCPv6 client can use VendorClass option to identify the vendor that manufactured the + hardware on which the client is running. The information contained in the data area of this + option is contained in one or more opaque fields that identify details of the hardware + configuration. Takes a whitespace-separated list of strings. @@ -2073,6 +2074,44 @@ IPv6Token=prefixstable:2002:da8:1:: + + + + UseAddress= + + When true (the default), the IP addresses provided by the DHCPv6 server will be + assigned. + + + + + UseDNS= + UseNTP= + UseHostname= + UseDomains= + + As in the [DHCPv4] section. + + + + + + + ForceDHCPv6PDOtherInformation= + + Takes a boolean that enforces DHCPv6 stateful mode when the 'Other information' bit is set in + Router Advertisement messages. By default setting only the 'O' bit in Router Advertisements + makes DHCPv6 request network information in a stateless manner using a two-message Information + Request and Information Reply message exchange. + RFC 7084, requirement WPD-4, updates + this behavior for a Customer Edge router so that stateful DHCPv6 Prefix Delegation is also + requested when only the 'O' bit is set in Router Advertisements. This option enables such a CE + behavior as it is impossible to automatically distinguish the intention of the 'O' bit otherwise. + By default this option is set to false, enable it if no prefixes are delegated when the device + should be acting as a CE router. + + + WithoutRA= @@ -2083,35 +2122,15 @@ IPv6Token=prefixstable:2002:da8:1:: - SendOption= + RapidCommit= - As in the [DHCPv4] section, however because DHCPv6 uses 16-bit fields to store - option numbers, the option number is an integer in the range 1…65536. - - - - - UserClass= - - A DHCPv6 client can use User Class option to identify the type or category of user or applications - it represents. The information contained in this option is a string that represents the user class of which - the client is a member. Each class sets an identifying string of information to be used by the DHCP - service to classify clients. Special characters in the data string may be escaped using - C-style - escapes. This setting can be specified multiple times. If an empty string is specified, - then all options specified earlier are cleared. Takes a whitespace-separated list of strings. Note that - currently NUL bytes are not allowed. - - - - - VendorClass= - - A DHCPv6 client can use VendorClass option to identify the vendor that - manufactured the hardware on which the client is running. The information - contained in the data area of this option is contained in one or more opaque - fields that identify details of the hardware configuration. Takes a - whitespace-separated list of strings. + Takes a boolean. The DHCPv6 client can obtain configuration parameters from a DHCPv6 server through + a rapid two-message exchange (solicit and reply). When the rapid commit option is enabled by both + the DHCPv6 client and the DHCPv6 server, the two-message exchange is used, rather than the default + four-message exchange (solicit, advertise, request, and reply). The two-message exchange provides + faster client configuration and is beneficial in environments in which networks are under a heavy load. + See RFC 3315 for details. + Defaults to true.