mirror of
https://gitlab.freedesktop.org/NetworkManager/NetworkManager.git
synced 2025-12-26 19:20:12 +01:00
Add support for configuring per-interface IPv4 sysctl forwarding setting in NetworkManager. The feature allows users to configure the net.ipv4.conf.<interface>.forward setting directly through NetworkManager, enabling targeted forwarding configurations for interfaces. This is particularly useful for cases such as enabling forwarding for MetalLB load balancing without requiring a global ip_forward=1 setting. While forwarding setting can be managed via /etc/sysctl.conf, configuring sysctl options for dynamically created or software-configured interfaces (e.g., bridges) poses challenges. With this feature, NetworkManager can configure these settings when interfaces are created or updated, users no longer need to rely on nm-dispatcher scripts for per-interface sysctl configuration, which can be error-prone and complex. This feature ensures a more seamless and integrated way to manage per-interface forwarding configurations, reducing user overhead and improving usability in complex network setups. We do not support configuring per-device IPv6 sysctl forwarding because in order to make per-device IPv6 sysctl forwarding work, we also need to enable the IPv6 global sysctl forwarding setting, but this has potential security concerns because it changes the behavior of the system to function as a router, which expose the system to new risks and unintended traffic flows, especially when enabling forwarding on the interface the user previously explicitly disabled. Also enabling per-device IPv6 sysctl setting will change the behavior of router advertisement (accept_ra), which is not expected. Therefore, we only support configuring per-device IPv4 sysctl forwarding option in NetworkManager. Resolves: https://issues.redhat.com/browse/RHEL-60237 https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2071 https://gitlab.freedesktop.org/NetworkManager/NetworkManager-ci/-/merge_requests/1833 |
||
|---|---|---|
| .. | ||
| c-list | ||
| c-rbtree | ||
| c-siphash | ||
| c-stdaux | ||
| contrib | ||
| core | ||
| libnm-base | ||
| libnm-client-aux-extern | ||
| libnm-client-impl | ||
| libnm-client-public | ||
| libnm-client-test | ||
| libnm-core-aux-extern | ||
| libnm-core-aux-intern | ||
| libnm-core-impl | ||
| libnm-core-intern | ||
| libnm-core-public | ||
| libnm-crypto | ||
| libnm-glib-aux | ||
| libnm-lldp | ||
| libnm-log-core | ||
| libnm-log-null | ||
| libnm-platform | ||
| libnm-std-aux | ||
| libnm-systemd-core | ||
| libnm-systemd-shared | ||
| libnm-udev-aux | ||
| libnmc-base | ||
| libnmc-setting | ||
| libnmt-newt | ||
| linux-headers | ||
| n-acd | ||
| n-dhcp4 | ||
| nm-cloud-setup | ||
| nm-compat-headers | ||
| nm-daemon-helper | ||
| nm-dispatcher | ||
| nm-initrd-generator | ||
| nm-online | ||
| nm-priv-helper | ||
| nmcli | ||
| nmtui | ||
| tests | ||
| meson.build | ||
| README.md | ||
src/
Most of the subdirectories are static helper libraries, which get linked into one of the final build artifacts (like libnm, nmcli or NetworkManager). Static libraries are internal API.
The only public API is libnm, which is a shared library provided client implementations.
Our own clients (like nmcli and nmtui) also use libnm, the shared library. But they also use additional static helper libraries.
The daemon statically links against a part of libnm, the part that provides connection profiles. That is libnm-core. libnm-core is thus statically linked with libnm and the daemon. It does not get linked by clients that already link with libnm (like nmtui).
Read the individual README.md files in the subdirectories for details:
| Directory | Description |
|---|---|
| core/ | the NetworkManager daemon |
| nmcli/ | nmcli application, a command line client for NetworkManager |
| nmtui/ | nmtui application, a text UI client for NetworkManager |
| nm-cloud-setup/ | service to automatically configure NetworkManager in cloud environment |
| nm-initrd-generator/ | generates NetworkManager configuration by parsing kernel command line options for dracut/initrd |
| nm-dispatcher/ | NetworkManager-dispatcher service to run user scripts |
| nm-online/ | application which checks whether NetworkManager is done, for implementing NetworkManager-wait-online.service |
| nm-priv-helper/ | internal service for privileged operations |
| nm-daemon-helper/ | internal helper binary spawned by NetworkManager |
| libnm-std-aux/ | internal helper library for standard C |
| libnm-glib-aux/ | internal helper library for glib |
| libnm-log-null/ | internal helper library with dummy (null) logging backend |
| libnm-log-core/ | internal helper library with logging backend (syslog) used by daemon |
| libnm-base/ | internal helper library with base definitions |
| libnm-platform/ | internal helper library for netlink and other platform/kernel API |
| libnm-udev-aux/ | internal helper library for libudev |
| libnm-core-public/ | public API of libnm (libnm-core part) |
| libnm-core-intern/ | internal API of libnm-core, used by libnm and daemon |
| libnm-core-impl/ | implementation of libnm-core |
| libnm-core-aux-intern/ | internal helper library on top of libnm-core (used by libnm-core itself) |
| libnm-core-aux-extern/ | internal helper library on top of libnm-core (not used by libnm-core) |
| libnm-client-public/ | public API of libnm (NMClient part) |
| libnm-client-impl/ | implementation of libnm (NMClient) |
| libnm-client-aux-extern/ | internal helper library on top of libnm (not used by libnm itself) |
| libnmc-base/ | internal helper library for libnm clients |
| libnmc-setting/ | internal helper library for setting connection profiles (used by nmcli) |
| libnmt-newt/ | internal helper library for libnewt for nmtui |
| linux-headers/ | extra Linux kernel UAPI headers |
| contrib/ | sources that are not used by NetworkManager itself |
| tests/ | unit tests that are not specific to one of the other directories |
| libnm-client-test/ | internal helper library with test utils for libnm |
| c-list/ | fork of c-util helper library for intrusive, doubly linked list |
| c-rbtree/ | fork of c-util helper library for intrusive Red-Black Tree |
| c-siphash/ | fork of c-util helper library for SIPHash24 |
| c-stdaux/ | fork of c-util general purpose helpers for standard C |
| n-acd/ | fork of nettools IPv4 ACD library |
| n-dhcp4/ | fork of nettools DHCPv4 library |
| libnm-systemd-core/ | fork of systemd code as network library |
| libnm-systemd-shared/ | fork of systemd code as general purpose library |