2 Description=Network Configuration
3 Documentation=man:networkd.service(8)
5 ConditionCapability=CAP_NET_ADMIN
7 # systemd-udevd.service can be dropped once tuntap is moved to netlink
8 After=systemd-udevd.service network-pre.target systemd-sysusers.service systemd-sysctl.service
9 Before=network.target multi-user.target shutdown.target
10 Conflicts=shutdown.target
14 AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_NET_RAW
15 BusName=org.ipfire.network1
16 CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_NET_RAW
18 ExecStart=@networkdir@/networkd
19 FileDescriptorStoreMax=512
21 MemoryDenyWriteExecute=yes
25 ProtectControlGroups=yes
28 ProtectKernelModules=yes
32 RestrictAddressFamilies=AF_UNIX AF_NETLINK AF_INET AF_INET6 AF_PACKET
33 RestrictNamespaces=yes
36 SystemCallArchitectures=native
37 SystemCallErrorNumber=EPERM
38 SystemCallFilter=@system-service
44 WantedBy=multi-user.target
45 Alias=dbus-org.ipfire.network1.service