Configure NetworkManager Safely with conf.d Overrides
You will create a small, reversible NetworkManager configuration snippet, confirm that NetworkManager reads it, and reload the daemon without editing the distribution-managed main file. This guide matches NetworkManager 1.46.0, installed here by Ubuntu's network-manager package. Allow about 10 minutes, plus a little longer if you need to recover a remote machine.
The route
Jump straight to the step you need, or tick off Done means at the end.
Before you change anything
You need a shell account with sudo access and NetworkManager running. Use a local console if the change might affect the only network path to the machine. The examples use a logging change because it is easy to observe and undo. Do not copy a device, DNS or unmanaged-device setting unless you understand which connections and interfaces it will affect.
First record the version and the configuration NetworkManager currently sees:
NetworkManager --version
NetworkManager --print-config
On this installation the version is 1.46.0. The printout shows the main file and the snippets that were loaded, followed by the merged sections. Treat that output as the checkpoint for the rest of the job.
1. Put your override in conf.d
NetworkManager reads the packaged snippets in /usr/lib/NetworkManager/conf.d, boot-time snippets in /run/NetworkManager/conf.d, the main file at /etc/NetworkManager/NetworkManager.conf, and administrator snippets in /etc/NetworkManager/conf.d. Files in a directory are read in asciibetical filename order. Later values override earlier values, and a same-named file in /etc can shadow one in /usr/lib or /run.
The old nm-system-settings.conf name is also installed as a manual-page alias here. The current configuration file is named NetworkManager.conf. Avoid changing the distribution's main file: a package update may replace it. Create a clearly named administrator file instead:
sudo install -d -m 0755 /etc/NetworkManager/conf.d
sudo tee /etc/NetworkManager/conf.d/95-local-logging.conf >/dev/null <<'EOF'
[logging]
level=INFO
domains=DEFAULT
EOF
The heredoc is quoted so the shell does not expand anything in the file. INFO and DEFAULT are deliberately modest values. For a short troubleshooting session, the upstream manual recommends level=TRACE and domains=ALL, but that produces much more journal data. Do not leave verbose logging enabled indefinitely on a busy system.
Checkpoint: confirm the file and merge order
Read back exactly what you wrote, then inspect the effective configuration:
sudo sed -n '1,40p' /etc/NetworkManager/conf.d/95-local-logging.conf
NetworkManager --print-config
Look for 95-local-logging.conf in the file list and for the resulting [logging] values. If a different later file sets the same key, the later definition wins. The internal file at /var/lib/NetworkManager/NetworkManager-intern.conf is read last and can override administrator settings; it is maintained by NetworkManager and should not be edited by hand.
2. Reload or restart deliberately
Some configuration can be reloaded with a SIGHUP or through D-Bus. The reliable operational choice after changing a file is to ask NetworkManager to reload its configuration:
sudo nmcli general reload conf
nmcli general logging
The first command normally prints no output when it succeeds. The second displays the active logging level and domains. If your change affects startup behaviour or is not reflected after reload, restart the service during a maintenance window:
sudo systemctl restart NetworkManager
systemctl is-active NetworkManager
NetworkManager --print-config
Restarting a network manager can briefly interrupt connections. On a remote host, keep an existing session open and have console access or an out-of-band route before doing this.
3. Use sections that match the job
The file is an INI-style key file. Every setting belongs inside a section, comments start with #, and list-valued settings can be extended with += or reduced with -=. The useful sections are not interchangeable.
[main]controls daemon-wide choices such as the settings plugins, DHCP client and DNS processing mode. On this machine,plugins=ifupdown,keyfileanddns=systemd-resolvedare active.[logging]controls daemon logging. Runtime options and command-line logging arguments can take precedence over this section.[connection]supplies defaults for connection profiles. A section such as[connection-wifi]can addmatch-device=type:wifiand apply defaults to matching devices.[device]supplies persistent per-device properties. For example,managed=1ormanaged=0can be restricted withmatch-device=interface-name:eth0.[keyfile]controls the keyfile settings plugin. Itsunmanaged-devicesoption is strict: a device excluded there cannot be made managed withnmcli device set.
For a device-specific change, prefer a matching section over a global wildcard. This example marks one interface unmanaged:
sudo tee /etc/NetworkManager/conf.d/95-local-device.conf >/dev/null <<'EOF'
[device-eth0]
match-device=interface-name:eth0
managed=0
EOF
sudo nmcli general reload conf
nmcli device status
That setting changes management state and can drop networking on eth0. It is included to show the pattern, not as a harmless default. Remove the file and reload if it was accidental:
sudo rm /etc/NetworkManager/conf.d/95-local-device.conf
sudo nmcli general reload conf
Common traps and recovery
Do not confuse daemon configuration with a connection profile. IP addresses, routes and Wi-Fi credentials normally belong in profiles managed by nmcli connection, not in a broad [main] setting. The keyfile plugin stores profiles under /etc/NetworkManager/system-connections; those files may contain secrets and are intended to be readable only by root.
Do not use monitor-connection-files expecting automatic profile reloads. The setting is deprecated and has no effect. Use nmcli connection reload when you have edited a connection profile, and use nmcli general reload conf for NetworkManager.conf changes.
If the daemon refuses a configuration, inspect the service journal:
systemctl status NetworkManager --no-pager
journalctl -u NetworkManager -b --no-pager -n 80
To undo an administrator override, remove or rename only the file you created, then reload or restart. Before deleting a pre-existing file, copy it to a root-readable backup in a controlled location. Never remove the whole configuration directory as a troubleshooting shortcut: packaged defaults and other administrator settings may be lost.
Done means
NetworkManager --print-configlists the intended snippet and effective values.- The setting is in
/etc/NetworkManager/conf.d, not an editable package file. - You reloaded or restarted NetworkManager and checked its active state.
- You know which file to remove to undo the change.
- Any verbose logging or device-management test has been returned to its previous state.