Skip to content

Configure a Static IP, DNS, and Gateway with nmcli

On RHEL-compatible Linux systems that use NetworkManager, you can use nmcli to configure the IPv4 address, DNS servers, and default gateway of a connection profile together.

Changes to network configuration can interrupt administrative connections such as SSH. This article therefore prioritizes safety by targeting a connected Ethernet NIC that is not being used by the current IPv4 default route. The existing connection profile is duplicated, and the static IP configuration is tested on the copy. Because the original profile is not modified, it can be reactivated at the end if necessary to roll back the changes.

The IP addresses used in the examples are reserved for documentation purposes. In a real environment, replace them with values assigned by your network administrator.

Variable nameExample settingDescription
<<TEST_INTERFACE>>ens6Name of the Ethernet NIC used for testing and not used for administrative communication
<<STATIC_CONNECTION>>example-staticName of the working connection profile to which the static IP configuration is applied
<<IPV4_CIDR>>192.0.2.10/24IPv4 address and prefix length to configure
<<GATEWAY_IPV4>>192.0.2.1IPv4 address of the default gateway
<<DNS_PRIMARY>>192.0.2.53IPv4 address of the primary DNS server
<<DNS_SECONDARY>>192.0.2.54IPv4 address of the secondary DNS server
<<ROUTE_METRIC>>60000Metric to assign to the new default route

Step 1: Check NetworkManager and the current routes

Section titled “Step 1: Check NetworkManager and the current routes”

First, confirm that NetworkManager is running, check the NIC status, and review the current IPv4 default route. The NIC used by the default route is excluded from automatic selection in this procedure.

Terminal window
set -euo pipefail
sudo systemctl is-active NetworkManager
sudo nmcli general status
sudo nmcli device status
sudo ip -4 route show default

Before continuing, confirm which NIC is carrying the current administrative connection. If your environment has only one connected Ethernet NIC, do not run this example as-is. First ensure that you have an alternative management path, such as console access.

Step 2: Create a working profile while keeping the original connection

Section titled “Step 2: Create a working profile while keeping the original connection”

The following commands explicitly specify in <<TEST_INTERFACE>> a connected Ethernet NIC that is not being used by the current IPv4 default route, and duplicate the active connection profile on that NIC as <<STATIC_CONNECTION>>. The original profile name and NIC name are saved under /var/tmp for rollback.

Before running the commands, confirm from the Step 1 output that the target is a connected Ethernet NIC and is not being used by the default route.

Terminal window
set -euo pipefail
DEFAULT_DEV=$(sudo env LC_ALL=C ip -4 route show default | awk 'NR==1 {print $5}')
DEVICE_NAME="<<TEST_INTERFACE>>"
test "$DEVICE_NAME" != "$DEFAULT_DEV"
sudo env LC_ALL=C nmcli -t -f DEVICE,TYPE,STATE device status | \
awk -F: -v device="$DEVICE_NAME" '$1==device && $2=="ethernet" && $3 ~ /^connected/ {found=1} END {exit !found}'
ORIGINAL_CONNECTION=$(sudo env LC_ALL=C nmcli -g GENERAL.CONNECTION device show "$DEVICE_NAME")
test -n "$ORIGINAL_CONNECTION"
test "$ORIGINAL_CONNECTION" != "--"
if sudo nmcli -g NAME connection show | grep -Fxq "<<STATIC_CONNECTION>>"; then
echo "指定した作業用接続プロファイル名は既に存在します。" >&2
exit 1
fi
printf '%s\n' "$DEVICE_NAME" | sudo tee /var/tmp/example-static-device >/dev/null
printf '%s\n' "$ORIGINAL_CONNECTION" | sudo tee /var/tmp/example-original-connection >/dev/null
sudo nmcli connection clone "$ORIGINAL_CONNECTION" "<<STATIC_CONNECTION>>"

The original connection profile is not modified. From this point onward, edit only the duplicated <<STATIC_CONNECTION>> profile.

Step 3: Configure the static IP, DNS, and default gateway

Section titled “Step 3: Configure the static IP, DNS, and default gateway”

Change the IPv4 method to manual, then configure the static IP address, gateway, and DNS servers. With ipv4.ignore-auto-dns yes, automatically obtained DNS servers are not used. With ipv4.never-default no, a default route can be generated from the specified gateway.

Set ipv4.route-metric to a relatively high value so that the existing administrative default route is more likely to retain priority. In production, adjust this value to match the existing routing and metric design.

Terminal window
set -euo pipefail
sudo nmcli connection modify "<<STATIC_CONNECTION>>" \
ipv4.method manual \
ipv4.addresses "<<IPV4_CIDR>>" \
ipv4.gateway "<<GATEWAY_IPV4>>" \
ipv4.dns "<<DNS_PRIMARY>> <<DNS_SECONDARY>>" \
ipv4.ignore-auto-dns yes \
ipv4.never-default no \
ipv4.route-metric "<<ROUTE_METRIC>>"

Step 4: Verify the connection profile settings

Section titled “Step 4: Verify the connection profile settings”

Before activating the profile, confirm that the intended values have been saved in the connection profile.

Terminal window
set -euo pipefail
sudo env LC_ALL=C nmcli -g ipv4.method,ipv4.addresses,ipv4.gateway,ipv4.dns,ipv4.ignore-auto-dns,ipv4.never-default,ipv4.route-metric connection show "<<STATIC_CONNECTION>>"

If ipv4.method is set to manual and the static IP address, gateway, DNS servers, and route metric match the specified values, proceed to the next step.

Step 5: Activate the static IP configuration

Section titled “Step 5: Activate the static IP configuration”

Activate the duplicated connection profile. Then confirm that the profile is connected on the target NIC.

Terminal window
set -euo pipefail
DEVICE_NAME=$(sudo cat /var/tmp/example-static-device)
sudo nmcli connection up "<<STATIC_CONNECTION>>"
sudo env LC_ALL=C nmcli -g GENERAL.CONNECTION,GENERAL.STATE device show "$DEVICE_NAME"

If the connection profile name is <<STATIC_CONNECTION>> and the NIC is connected, the configuration has been applied.

Step 6: Verify the active IP, routes, and DNS

Section titled “Step 6: Verify the active IP, routes, and DNS”

Do not check only the values saved in the connection profile. Also verify the IPv4 address, gateway, DNS servers, and routes actually applied to the target NIC.

Terminal window
set -euo pipefail
DEVICE_NAME=$(sudo cat /var/tmp/example-static-device)
sudo env LC_ALL=C nmcli -g IP4.ADDRESS,IP4.GATEWAY,IP4.DNS device show "$DEVICE_NAME"
sudo ip -4 address show dev "$DEVICE_NAME"
sudo ip -4 route show dev "$DEVICE_NAME"

Confirm that the static IP address is <<IPV4_CIDR>>, the gateway is <<GATEWAY_IPV4>>, and the DNS servers are <<DNS_PRIMARY>> and <<DNS_SECONDARY>>. If multiple default routes exist, also confirm that the intended route metric has been applied.

Step 7: Restore the original configuration if necessary

Section titled “Step 7: Restore the original configuration if necessary”

To remove the static IP configuration, reactivate the original connection profile saved earlier and delete the working profile. If you want to continue using the static IP configuration, do not run this step.

Terminal window
set -euo pipefail
ORIGINAL_CONNECTION=$(sudo cat /var/tmp/example-original-connection)
DEVICE_NAME=$(sudo cat /var/tmp/example-static-device)
sudo nmcli connection up "$ORIGINAL_CONNECTION"
sudo nmcli connection delete "<<STATIC_CONNECTION>>"
ACTIVE_CONNECTION=$(sudo env LC_ALL=C nmcli -g GENERAL.CONNECTION device show "$DEVICE_NAME")
test "$ACTIVE_CONNECTION" = "$ORIGINAL_CONNECTION"
if sudo nmcli connection show "<<STATIC_CONNECTION>>" >/dev/null 2>&1; then
exit 1
fi
sudo rm -f /var/tmp/example-original-connection /var/tmp/example-static-device

Because the original connection profile was not modified, reactivating it restores the network configuration from before the changes. In environments managed over SSH or another remote connection, connectivity may change immediately after the switch. If necessary, verify the system state through an alternative management path.

Category: Linux