Safely edit a NetworkManager profile with nmtui-edit
You will finish with one NetworkManager connection profile inspected and, if needed, edited through the text interface. You will also confirm which profile you opened and have a recovery path before changing anything.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes for a small edit, plus time to test the connection afterwards. You need a terminal, NetworkManager, and the profile name or ID. This guide uses the nmtui-edit binary from NetworkManager 1.46.0, packaged here as network-manager 1.46.0-1ubuntu2.8. The interface is curses-based, so use a real terminal rather than a command runner that cannot handle interactive screen applications.
Safety boundary
Editing a profile changes saved network configuration. A wrong address, route, DNS server or wireless setting can interrupt access. Keep an existing SSH session open, record the old values, and do not save a change you cannot explain. Most reads below are ordinary commands. Use elevated privileges only if your system refuses to read or save the profile; do not make sudo the first fix for an uncertain setting.
1. Confirm the installed command
Check the executable and its built-in help. These commands do not alter NetworkManager:
$ command -v nmtui-edit
/usr/bin/nmtui-edit
$ nmtui-edit --help
Usage:
nmtui-edit [OPTION...]
Help Options:
-h, --help Show help options
The separate nmtui-edit program skips nmtui's activity-selection screen. The installed manual documents the equivalent form nmtui edit NAME_OR_ID. There is no documented version flag in this build, so use the package query when you need the version:
$ dpkg-query -W -f='${Package} ${Version}\n' network-manager
network-manager 1.46.0-1ubuntu2.8
Checkpoint
Stop here if command -v finds a different binary from the one you intended to use, or if the package is missing.
2. Identify the profile before opening it
Use NetworkManager's read-only listing to find the exact connection name and UUID. Names are convenient, but a UUID avoids ambiguity when similar profiles exist:
$ nmcli -f NAME,UUID,TYPE,DEVICE connection show
NAME UUID TYPE DEVICE
Office wired 11111111-2222-3333-4444-555555555555 ethernet enp1s0
Backup Wi-Fi 66666666-7777-8888-9999-aaaaaaaaaaaa wifi --
Your output will differ. Replace PROFILE_ID below with the complete name or UUID of the profile you intend to edit. If a name contains spaces, quote it. If you are unsure which profile is active, check the DEVICE column and do not guess from a shortened name.
$ PROFILE_ID='Office wired'
$ nmcli -f NAME,UUID,TYPE,DEVICE connection show "$PROFILE_ID"
NAME UUID TYPE DEVICE
Office wired 11111111-2222-3333-4444-555555555555 ethernet enp1s0
Using a UUID is equally valid:
$ PROFILE_ID='11111111-2222-3333-4444-555555555555'
$ nmcli -f NAME,UUID connection show "$PROFILE_ID"
NAME UUID
Office wired 11111111-2222-3333-4444-555555555555
3. Save a record of the current state
Before opening an editor, capture the profile as text. This is a comparison record, not a file to paste blindly back into NetworkManager. The output can contain wireless or VPN secrets, so store it somewhere access-controlled and remove it when you no longer need it:
$ nmcli connection show "$PROFILE_ID" > "$HOME/network-profile-before.txt"
$ chmod 600 "$HOME/network-profile-before.txt"
$ grep -E '^(connection\.id|connection\.uuid|connection\.type|ipv4\.|ipv6\.|802-11-wireless\.ssid)' "$HOME/network-profile-before.txt"
connection.id: Office wired
connection.uuid: 11111111-2222-3333-4444-555555555555
connection.type: 802-3-ethernet
ipv4.method: auto
ipv6.method: auto
The exact fields depend on the connection type. Do not publish this record or paste it into a support ticket without checking for passwords, private keys and other secrets.
4. Open the profile in nmtui-edit
Launch the editor with the exact name or UUID:
$ nmtui-edit "$PROFILE_ID"
The screen opens the connection editor for that profile. Move between controls with the arrow keys or Tab, use Space to toggle a checkbox, and follow the on-screen key hints. The editor supports viewing and modifying an existing profile, and it can also add or delete profiles from its connection list. For this workflow, stay with the profile you identified and do not choose a delete action.
Change one setting at a time. For example, a wired profile may expose IPv4 configuration, DNS and routes; a Wi-Fi profile may expose its SSID, security and saved secrets. The available settings depend on the connection type. Do not copy an IPv4 address, gateway or DNS value from this example into your network. Use values supplied by your network administrator or documented by the service you are joining.
Checkpoint
Before saving, review the profile name, interface association, addressing method and any changed value. If the screen shows a setting you do not recognise, leave without saving and compare the profile with the record from step 3.
5. Save only after reviewing the change
Use the editor's on-screen save or OK action, then quit the editor. Saving writes the profile through NetworkManager. It does not mean that every change has already been applied to the active interface, and it does not prove that the new network values work.
Immediately compare the saved profile with the values you intended:
$ nmcli -f NAME,UUID,TYPE,DEVICE connection show "$PROFILE_ID"
NAME UUID TYPE DEVICE
Office wired 11111111-2222-3333-4444-555555555555 ethernet enp1s0
$ nmcli connection show "$PROFILE_ID" | grep -E '^(connection\.id|connection\.uuid|ipv4\.|ipv6\.)'
connection.id: Office wired
connection.uuid: 11111111-2222-3333-4444-555555555555
ipv4.method: auto
ipv6.method: auto
Use the before-and-after record to check the particular field you changed. If you saved an unwanted edit, reopen the profile and restore the old value from your private record, then save again. If the change made the active connection unusable, use a local console or another working connection before attempting a reconnect.
6. Test activation separately
Editing a profile and activating it are separate operations. First confirm that NetworkManager still sees the profile. Only activate it when you have a maintenance window or a fallback connection, because a reconnect can interrupt SSH and other traffic.
$ nmcli connection show "$PROFILE_ID"
NAME UUID TYPE DEVICE
Office wired 11111111-2222-3333-4444-555555555555 ethernet enp1s0
For an explicit test, use nmtui's connect activity or the separately documented nmcli connection up command. Do not run an activation command automatically as part of a remote edit. After a planned reconnect, verify the result with:
$ nmcli -f GENERAL.STATE,GENERAL.CONNECTION device show enp1s0
GENERAL.STATE: 100 (connected)
GENERAL.CONNECTION: Office wired
The device name and state depend on your host. A saved profile can be valid while activation still fails because a cable, access point, DHCP server or authentication service is unavailable.
7. Clean up the recovery record
Keep the before-state record until the connection has passed its real test. Once you are satisfied, remove it because it may contain secrets:
$ rm -- "$HOME/network-profile-before.txt"
This deletion is irreversible. If you still need the record for an approved change log, move it to an access-controlled location instead of leaving it in a shared home directory.
Done means
- You confirmed the NetworkManager package and the nmtui-edit help available on this host.
- You opened the intended profile by an exact name or UUID.
- You recorded the old settings before making a saved change.
- You reviewed the changed values and verified the profile after saving.
- You treated activation as a separate, potentially disruptive test.
- You can restore an unwanted edit from the before-state record, and you removed that record when it was no longer needed.