# dhcpcd.conf - dhcpcd configuration file - man(5) - [phpMan]

[_DHCPCD.CONF_(5)](https://www.chedong.com/phpMan.php/man/DHCPCD.CONF/5/markdown)                           File Formats Manual                          [_DHCPCD.CONF_(5)](https://www.chedong.com/phpMan.php/man/DHCPCD.CONF/5/markdown)

## NAME
       dhcpcd.conf — dhcpcd configuration file

## DESCRIPTION
       Although **dhcpcd **can do everything from the command line, there are cases where it's just eas‐
       ier  to  do  it  once in a configuration file.  Most of the options found in [_dhcpcd_(8)](https://www.chedong.com/phpMan.php/man/dhcpcd/8/markdown) can be
       used here.  The first word on the line is the option and the rest of the line is  the  value.
       Leading and trailing whitespace for the option and value are trimmed.  You can escape charac‐
       ters  in  the  value  using  the \ character.  Comments can be prefixed with the # character.
       String values should be quoted with the " character.

       Here's a list of available options:

       **allowinterfaces _**pattern_
               When discovering interfaces, the interface name must match _pattern_ which is  a  space
               or  comma  separated list of patterns passed to [_fnmatch_(3)](https://www.chedong.com/phpMan.php/man/fnmatch/3/markdown).  If the same interface is
               matched in **denyinterfaces **then it is still denied.

       **denyinterfaces _**pattern_
               When discovering interfaces, the interface name must not match  _pattern_  which  is  a
               space or comma separated list of patterns passed to [_fnmatch_(3)](https://www.chedong.com/phpMan.php/man/fnmatch/3/markdown).

### anonymous
               Enables  Anonymity  Profiles for DHCP, RFC 7844.  Any DUID is ignored and ClientID is
               set to LL only.  All non essential options are then masked at this  point,  but  they
               could  be  unmasked by explicitly requesting the option **after **the **anonymous **option is
               processed.  As such, the **anonymous **option **should **be the last option in the configura‐
               tion unless you really want to send something which could identify you.  **dhcpcd  **will
               not try and reboot an old lease, it will go straight into DISCOVER/SOLICIT.

### randomise_hwaddr
               Forces  a hardware address randomisation when the interface is brought up or when the
               carrier is lost.  This is generally used in tandem with the anonymous option.

       **arping _**address_ [address]
               **dhcpcd **will arping each address in order before attempting DHCP.  If  an  address  is
               found,  we will select the replying hardware address as the profile, otherwise the IP
               address.  Example:

                     interface bge0
                     arping 192.168.0.1

                     # My specific 192.168.0.1 network
                     profile dd:ee:aa:dd:bb:ee
                     static ip_address=192.168.0.10/24

                     # A generic 192.168.0.1 network
                     profile 192.168.0.1
                     static ip_address=192.168.0.98/24

       **authprotocol _**protocol_ [_algorithm_ [_rdm_]]
               Authenticate DHCP messages.  See the Supported Authentication Protocols section.   If
               _protocol_ is _token_ then _algorithm_ _is_ snd_secretid/rcv_secretid so you can send and re‐
               ceive different tokens.

       **authtoken _**secretid_ _realm_ _expire_ _key_
               Define  a  shared key for use in authentication.  _realm_ can be "" to for use with the
               _delayed_ protocol.  _expire_ is the date the token expires and should be formatted "yyy-
               mm-dd HH:MM".  You can use the keyword _forever_ or _0_ which means the token  never  ex‐
               pires.   For the token protocol, _secretid_ needs to be 0 and _realm_ needs to be "".  If
               **dhcpcd **has the error
                     dhcp_auth_encode: Invalid argument
               then it means that **dhcpcd **could not find the correct  authentication  token  in  your
               configuration.

### background
               Fork  to  the background immediately.  This is useful for startup scripts which don't
               disable link messages for carrier status.

       **blacklist _**address_[/cidr]
               Ignores all packets from _address_[/cidr].

       **whitelist _**address_[/cidr]
               Only accept packets from _address_[/cidr].  **blacklist **is ignored if **whitelist **is set.

       **bootp   **Be a BOOTP client.  Basically, this just doesn't send a DHCP Message Type option  and
               will only interact with a BOOTP server.  All other DHCP options still work.

### broadcast
               Instructs  the DHCP server to broadcast replies back to the client.  Normally this is
               only set for non-Ethernet interfaces, such  as  FireWire  and  InfiniBand.   In  most
               cases, **dhcpcd **will set this automatically.

       **controlgroup _**group_
               Sets  the  group ownership of _/run/dhcpcd/sock_ so that users other than root can con‐
               nect to **dhcpcd**.

       **debug   **Echo debug messages to the stderr and syslog.

       **dev _**value_
               Load the _value_ _/dev_ management module.  **dhcpcd **will load the first one found to work,
               if any.

       **env _**value_
               Push _value_ to the environment for use in [_dhcpcd-run-hooks_(8)](https://www.chedong.com/phpMan.php/man/dhcpcd-run-hooks/8/markdown).  For example,  you  can
               force  the  hostname hook to always set the hostname with **env _**force_hostname=YES_.  Or
               set which driver [_wpa_supplicant_(8)](https://www.chedong.com/phpMan.php/man/wpasupplicant/8/markdown) should use with **env _**wpa_supplicant_driver=nl80211_

               If the hostname is set, it will be will set to the FQDN if possible as per RFC  4702,
               section  3.1.   If  the  FQDN option is missing, **dhcpcd **will still try and set a FQDN
               from the hostname and domain options for consistency.   To  override  this,  set  **env**
               _hostname_fqdn=[YES|NO|SERVER]_.   A  value  of _SERVER_ means just what the server says,
               don't manipulate it.  This could lead to an inconsistent hostname  on  a  DHCPv4  and
               DHCPv6 network where the DHCPv4 hostname is short and the DHCPv6 has an FQDN.  DHCPv6
               has no hostname option.

       **clientid _**string_
               Send  the  _clientid_.   If  the string is of the format 01:02:03 then it is encoded as
               hex.  For interfaces whose hardware address  is  longer  than  8  bytes,  or  if  the
               _clientid_ is an empty string then **dhcpcd **sends a default _clientid_ of the hardware fam‐
               ily and the hardware address.

       **duid **[ll | lt | uuid | value]
               Use  a  DHCP  Unique Identifier.  If a system UUID is available, that will be used to
               create a DUID-UUID, otherwise if persistent storage  is  available  then  a  DUID-LLT
               (link  local address + time) is generated, otherwise DUID-LL is generated (link local
               address).  The DUID type  can  be  hinted  as  an  optional  parameter  if  the  file
               _/var/lib/dhcpcd/duid_  does  not exist.  If not _ll_, _lt_ or _uuid_ then _value_ will be con‐
               verted from 00:11:22:33 format.  This, plus the IAID will be used  as  the  **clientid**.
               The  DUID  generated will be held in _/var/lib/dhcpcd/duid_ and should not be copied to
               other hosts.  This file also takes precedence over the above rules except for setting
               a value.

       **iaid _**iaid_
               Set the Interface Association Identifier to _iaid_.  This option must  be  used  in  an
               **interface  **block.  This defaults to the VLANID (prefixed with 0xff) for the interface
               if set, otherwise the last 4 bytes of the hardware address assigned to the interface.
               Each instance of this should be unique within the scope  of  the  client  and  **dhcpcd**
               warns if a conflict is detected.  If there is a conflict, it is only a problem if the
               conflicted IAIDs are used on the same network.

       **dhcp    **Enable DHCP on the interface, on by default.

       **dhcp6   **Enable DHCPv6 on the interface, on by default.

       **ipv4    **Enable IPv4 on the interface, on by default.

       **ipv6    **Enable IPv6 on the interface, on by default.

       **request **[_address_]
               Request  the _address_ in the DHCP DISCOVER message.  There is no guarantee this is the
               address the DHCP server will actually give.  If no _address_ is given  then  the  first
               address currently assigned to the _interface_ is used.

       **inform **[_address_[_/cidr_[_/broadcast_address_]]]
               Behaves  like  **request **as above, but sends a DHCP INFORM instead of DISCOVER/REQUEST.
               This does not get a lease as such, just notifies the DHCP server of  the  _address_  in
               use.  You should also include the optional _cidr_ network number in case the address is
               not  already configured on the interface.  **dhcpcd **remains running and pretends it has
               an infinite lease.  **dhcpcd **will not de-configure the interface  when  it  exits.   If
               **dhcpcd  **fails  to  contact a DHCP server then it returns a failure instead of falling
               back on IPv4LL.

### inform6
               Performs a DHCPv6 Information Request.  No address is requested or specified, but all
               other DHCPv6 options are allowed.  This is normally performed automatically  when  an
               IPv6  Router  Advertisement  indicates that the client should perform this operation.
               This option is only needed when **dhcpcd **is not processing IPv6  RA  messages  and  the
               need for a DHCPv6 Information Request exists.

### persistent
               **dhcpcd  **normally  de-configures the interface and configuration when it exits.  Some‐
               times, this isn't desirable if, for example, you have root mounted over  NFS  or  SSH
               clients  connect to this host and they need to be notified of the host shutting down.
               You can use this option to stop this from happening.

       **fallback _**profile_
               Fall back to using this profile if DHCP fails.  This allows you to configure a static
               profile instead of using ZeroConf.

       **hostname _**name_
               Sends the hostname _name_ to the DHCP server so it can be registered in DNS.   If  _name_
               is  an  empty  string  then  the  current system hostname is sent.  If _name_ is a FQDN
               (i.e., contains a .) then it will be encoded as such.

### hostname_short
               Sends the short hostname to the DHCP server instead of the FQDN.  This is useful  be‐
               cause  DHCP  servers  will not register the FQDN in their DNS if the domain part does
               not match theirs.

               Also, see the **env **option above to control how the hostname is set on the host.

       **ia_na **[_iaid_ [/ address]]
               Request a DHCPv6 Normal Address for _iaid_.  _iaid_ defaults to the **iaid  **option  as  de‐
               scribed  above.   You can request more than one ia_na by specifying a unique _iaid_ for
               each one.

       **ia_ta **[_iaid_]
               Request a DHCPv6 Temporary Address for _iaid_.  You can request more than one ia_ta  by
               specifying a unique _iaid_ for each one.

       **ia_pd **[_iaid_ [/ _prefix_ _/_ _prefix_len_] [_interface_ [/ _sla_id_ [/ _prefix_len_ [/ _suffix_]]]]]
               Request a DHCPv6 Delegated Prefix for _iaid_.  This option must be used in an **interface**
               block.  Unless a _sla_id_ of 0 is assigned with the same resultant prefix length as the
               delegation,  a reject route is installed for the Delegated Prefix to stop unallocated
               addresses being resolved upstream.  If no _interface_ is given then we  will  assign  a
               prefix  to  every other interface with a _sla_id_ equivalent to the interface index as‐
               signed by the OS.  Otherwise addresses are  only  assigned  for  each  _interface_  and
               _sla_id_.   To  avoid delegating to any interface, use - as the invalid interface name.
               Each assigned address will have a _suffix_, defaulting to 1.  If the _suffix_ is 0 then a
               SLAAC address is assigned.  You cannot assign a prefix to  the  requesting  interface
               unless  the DHCPv6 server supports the **RFC 6603 **Prefix Exclude Option.  **dhcpcd **has to
               be running for all the interfaces it is delegating to.  A default _prefix_len_ of 64 is
               assumed, unless the maximum _sla_id_ does not fit.  In  this  case  _prefix_len_  is  in‐
               creased  to  the highest multiple of 8 that can accommodate the _sla_id_.  _sla_id_ is an
               integer which must be unique inside the _iaid_ and is added to the  prefix  which  must
               fit  inside _prefix_len_ less the length of the delegated prefix.  You can specify mul‐
               tiple _interface_ _/_ _sla_id_ _/_ _prefix_len_ per **ia_pd**, space separated.  IPv6RS  should  be
               disabled globally when requesting a Prefix Delegation.

               In the following example eth0 is the externally facing interface to be configured for
               both IPv4 and IPv6.  The DHCPv4 server will provide us with an IPv4 address and a de‐
               fault  route.   The  DHCPv6 server is going to provide us with an IPv6 address, a de‐
               fault route and a /64 subnet to be delegated to the internal interface.  The eth1 in‐
               terface will be automatically configured for IPv6 using the first address (::1)  from
               the  delegated prefix.  A second prefix is requested and assigned to two other inter‐
               faces.  [_rtadvd_(8)](https://www.chedong.com/phpMan.php/man/rtadvd/8/markdown) can be used with an empty configuration  file  on  eth1,  eth2  and
               eth3, to provide automatic IPv6 address configuration for the internal network.

               noipv6rs                 # disable routing solicitation
               denyinterfaces eth2      # Don't touch eth2 at all
               interface eth0
                 ipv6rs                 # enable routing solicitation for eth0
                 ia_na 1                # request an IPv6 address
                 ia_pd 2 eth1/0         # request a PD and assign it to eth1
                 ia_pd 3 eth2/1 eth3/2  # req a PD and assign it to eth2 and eth3
                 ia_pd 4 -              # request a PD but don't assign it

### ipv4only
               Only configure IPv4.

### ipv6only
               Only configure IPv6.

       **fqdn **[disable | none | ptr | both]
               _none_  will  not  ask the DHCP server to update DNS.  _ptr_ just asks the DHCP server to
               update the PTR record of the host in DNS, whereas _both_ also  updates  the  A  record.
               _disable_ will disable the FQDN option.  The default is _both_.  **dhcpcd **itself never does
               any DNS updates.  **dhcpcd **encodes the FQDN hostname as specified in **RFC 1035**.

       **interface _**interface_
               Subsequent options are only parsed for this _interface_.

### ipv6ra_autoconf
               Generate  SLAAC  addresses for each Prefix advertised by an IPv6 Router Advertisement
               message with the Auto flag set.  On by default.

### ipv6ra_noautoconf
               Disables the above option.

### ipv6ra_fork
               By default, when **dhcpcd **receives an IPv6 Router Advertisement, **dhcpcd **will only  fork
               to  the background if the RA contains at least one unexpired RDNSS option and a valid
               prefix or no DHCPv6 instruction.  Set this option so to make **dhcpcd **always fork on  a
               RA.

       **ipv6rs  **Enables  IPv6 Router Advertisement solicitation.  This is on by default, but is docu‐
               mented here in the case where it is disabled globally but needs to be enabled for one
               interface.

       **leasetime _**seconds_
               Request DHCP a lease time of _seconds_.  _-1_ represents an infinite lease time.  By  de‐
               fault  **dhcpcd  **does not request any lease time and leaves it in the hands of the DHCP
               server.  It is not possible to request a DHCPv6 lease time as this is not RFC compli‐
               ant.  See RFC 8415 21.4, 21.6, 21.21 and 21.22.

       **link_rcvbuf _**size_
               Override the size of the link receive buffer from the kernel default.   While  **dhcpcd**
               will  recover from link buffer overflows, this may not be desirable on heavily loaded
               systems.

       **logfile _**logfile_
               Writes to the specified _logfile_.  **dhcpcd **still writes to [_syslog_(3)](https://www.chedong.com/phpMan.php/man/syslog/3/markdown).  The  _logfile_  is
               reopened when **dhcpcd **receives the SIGUSR2 signal.

       **metric _**metric_
               Metrics  are  used to prefer an interface over another one, lowest wins.  **dhcpcd **will
               supply a default metric of 1000 + [_if_nametoindex_(3)](https://www.chedong.com/phpMan.php/man/ifnametoindex/3/markdown).  This will be offset by 2000 for
               wireless interfaces, with additional offsets of 1000000 for IPv4LL  and  2000000  for
               roaming interfaces.

       **mudurl _**url_
               Specifies  the  URL  for  a Manufacturer Usage Description (MUD).  The description is
               used by upstream network devices to instantiate any desired access lists.  See draft-
               ietf-opsawg-mud for more information.

### noalias
               Any pre-existing IPv4 addresses will be removed from the interface when adding a  new
               IPv4 address.

       **noarp   **Don't send any ARP requests.  This also disables IPv4LL.

### noauthrequired
               Don't require authentication even though we requested it.  Also allows FORCERENEW and
               RECONFIGURE messages without authentication.

### nodelay
               Don't delay for an initial randomised time when starting protocols.

       **nodev   **Don't load _/dev_ management modules.

       **nodhcp  **Don't  start  DHCP  or  listen  to  DHCP messages.  This is only useful when allowing
               IPv4LL.

### nodhcp6
               Don't start DHCPv6 or listen to DHCPv6 messages.  Normally DHCPv6 is  started  by  an
               IPv6 Router Advertisement instruction or configuration.

### nogateway
               Don't install any default routes.

### gateway
               Install a default route if available (default).

       **nohook _**script_
               Don't run this hook script.  Matches full name, or prefixed with 2 numbers optionally
               ending with _.sh_.

               So  to  stop  **dhcpcd  **from  touching your DNS settings or starting wpa_supplicant you
               would do:-
                     nohook resolv.conf, wpa_supplicant

       **noipv4  **Don't attempt to configure an IPv4 address.

### noipv4ll
               Don't attempt to obtain an IPv4LL address if we failed to get one via DHCP.  See  _RFC_
               _3927_.

       **noipv6  **Don't solicit or accept IPv6 Router Advertisements and DHCPv6.

### noipv6rs
               Don't solicit or accept IPv6 Router Advertisements.

       **nolink  **Don't receive link messages about carrier status.  You should only set this for buggy
               interface drivers.

       **noup    **Don't bring the interface up when in manager mode.

       **option _**option_
               Requests  the  _option_  from  the  server.   It  can  be  a  variable  to  be  used in
               [_dhcpcd-run-hooks_(8)](https://www.chedong.com/phpMan.php/man/dhcpcd-run-hooks/8/markdown) or the numerical value.  You can specify more  _option_s  separated
               by commas, spaces or more **option **lines.  Prepend dhcp6_ to _option_ to request a DHCPv6
               option.   If  no  DHCPv6  options  are  configured, then DHCPv4 options are mapped to
               equivalent DHCPv6 options.

               Prepend nd_ to _option_ to handle ND options, but this only  works  for  the  **nooption**,
               **reject **and **require **options.

               To see a list of options you can use, call **dhcpcd **with the **-V**, **--variables **argument.

       **nooption _**option_
               Remove the option from the message before it's processed.

       **require _**option_
               Requires  the _option_ to be present in all messages, otherwise the message is ignored.
               To enforce that **dhcpcd **only responds to DHCP servers and not BOOTP servers,  you  can
               **require _**dhcp_message_type_.  This isn't an exact science though because a BOOTP server
               can send DHCP-like options.

       **reject _**option_
               Reject  a  message  that  contains  the  _option_.   This is useful when you cannot use
               **require **to select / de-select BOOTP messages.

       **destination _**option_
               If **dhcpcd.conf **detects an address added to a point to point interface (PPP, TUN, etc)
               then it will set the listed DHCP options to the destination address of the interface.

       **profile _**name_
               Subsequent options are only parsed for this profile _name_.

       **quiet   **Suppress any dhcpcd output to the console, except for errors.

       **reboot _**seconds_
               Allow _reboot_ seconds before moving to the DISCOVER phase if we have an old  lease  to
               use.   Allow  _reboot_ seconds before starting fallback states from the DISCOVER phase.
               IPv4LL is started when the first _reboot_ timeout is reached.  The default  is  5  sec‐
               onds.   A  setting  of  0  seconds causes **dhcpcd.conf **to skip the reboot phase and go
               straight into DISCOVER.  This is desirable for mobile users  because  if  you  change
               from network A to network B and they use the same subnet and the address from network
               A isn't in use on network B, then the DHCP server will remain silent even if authori‐
               tative  which  means  **dhcpcd  **will  timeout before moving back to the DISCOVER phase.
               This has no effect on DHCPv6 other than skipping the reboot phase.

### release
               **dhcpcd **will release the lease prior to stopping the interface.

       **script _**script_
               Use _script_ instead of the default _/usr/lib/dhcpcd/dhcpcd-run-hooks_.

       **ssid _**ssid_
               Subsequent options are only parsed for this wireless _ssid_.

       **slaac hwaddr **| **private **| **token _**token_ [**temp **| **temporary**]
               Selects the interface identifier used for SLAAC generated IPv6 addresses.  If **private**
               is used, a RFC 7217 address is generated.  If **token _**token_ is used then the  token  is
               combined  with  the  prefix  to make the final address.  The **temporary **directive will
               create a temporary address for the prefix as well.

       **static _**value_
               Configures a static _value_.  If you set **ip_address **then **dhcpcd **will not attempt to ob‐
               tain a lease and will just use the value for the address with an infinite lease time.
               If you set an empty value this removes all  prior  static  allocations  to  the  same
               value.   This is useful when using profiles and in the case of **ip_address **it will re‐
               move the static allocation.  Note that setting 0.0.0.0 keeps  the  static  allocation
               but  waits  for  a 3rdparty to configure the address.  If you set **ip6_address**, **dhcpcd**
               will continue auto-configuration as normal.

               Here is an example which configures two static address, overriding the  default  IPv4
               broadcast  address,  an  IPv4  router, DNS and disables IPv6 auto-configuration.  You
               could also use the **inform6 **command here if you wished to obtain more information  via
               DHCPv6.   For  IPv4,  you should use the **inform _**ipaddress_ option instead of setting a
               static address.
                     interface eth0
                     noipv6rs
                     static ip_address=192.168.0.10/24
                     static broadcast_address=192.168.0.63
                     static ip6_address=fd51:42f8:caae:[d92e::ff](https://www.chedong.com/phpMan.php/perldoc/d92e%3A%3Aff/markdown)/64
                     static routers=192.168.0.1
                     static domain_name_servers=192.168.0.1 fd51:42f8:caae:[d92e::1](https://www.chedong.com/phpMan.php/perldoc/d92e%3A%3A1/markdown)

               Here is an example for PPP which gives the destination a default route.  It uses  the
               special _destination_ keyword to insert the destination address into the value.
                     interface ppp0
                     static ip_address=0.0.0.0
                     destination routers

       **timeout _**seconds_
               Time  out  after  _seconds_,  instead of the default 30.  A setting of 0 _seconds_ causes
               **dhcpcd **to wait forever to get a lease.  If **dhcpcd **is working on  a  single  interface
               then  **dhcpcd  **will  exit  when  a timeout occurs, otherwise **dhcpcd **will fork into the
               background.  If using IPv4LL then **dhcpcd **start the IPv4LL process after  the  timeout
               and then wait a little longer before really timing out.

       **userclass _**string_
               Tag the DHCPv4 message with the userclass.  You can specify more than one.

       **msuserclass _**string_
               Tag  the  DHCPv4  mesasge with the Microsoft userclass.  Unlike the **userclass **option,
               this one can only be added once.  It should only be used for Microsoft  DHCP  servers
               and  the  **vendorclassid **should be set to "MSFT 98" or "MSFT 5.0".  This option is not
               RFC compliant.

       **vendor _**code_,_value_
               Add an encapsulated vendor option.  _code_ should be between 1 and 254  inclusive.   To
               add a raw vendor string, omit _code_ but keep the comma.  Examples.

               Set the vendor option 01 with an IP address.
                     vendor 01,192.168.0.2
               Set the vendor option 02 with a hex code.
                     vendor 02,01:02:03:04:05
               Set the vendor option 03 with an IP address as a string.
                     vendor 03,\"192.168.0.2\"
               Set un-encapsulated vendor option to hello world.
                     vendor ,"hello world"

       **vendorclassid _**string_
               Set the DHCP Vendor Class.  DHCPv6 has its own option as shown below.  The default is
               dhcpcd-<version>:<os>:<machine>:<platform>.  For example
                     dhcpcd-5.5.6:NetBSD-6.99.5:i386:i386
               If not set then none is sent.  Some badly configured DHCP servers reject unknown ven‐
               dorclassids.   To  work around it, try and impersonate Windows by using the MSFT ven‐
               dorclassid.

       **vendclass _**en_ _data_
               Add the DHCPv6 Vendor Indetifying Vendor Class with the IANA assigned Enterprise Num‐
               ber _en_ with the _data_.  This option can be set more than once to add  more  data,  but
               the behaviour, as per RFC 3925 is undefined if the Enterprise Number differs.

       **waitip **[4 | 6]
               Wait  for  an  address to be assigned before forking to the background.  4 means wait
               for an IPv4 address to be assigned.  6 means wait for an IPv6 address to be assigned.
               If no argument is given, **dhcpcd.conf **will wait for any address  protocol  to  be  as‐
               signed.   It  is  possible to wait for more than one address protocol and **dhcpcd.conf**
               will only fork to the background when all waiting conditions are satisfied.

### xidhwaddr
               Use the last four bytes of the hardware address as the DHCP xid instead of a randomly
               generated number.

### Defining new options
       DHCP, ND and DHCPv6 allow for the use of custom options, and RFC 3925 vendor options for DHCP
       can also be supplied.  Each option needs to be started with the **define**, **definend**, **define6  **or
       **vendopt **directive.  This can optionally be followed by both **embed **or **encap **options.  Both can
       be specified more than once and **embed **must come before **encap**.

       **define _**code_ _type_ _variable_
               Defines  the  DHCP  option  _code_  of  _type_  with  a  name  of  _variable_  exported  to
               [_dhcpcd-run-hooks_(8)](https://www.chedong.com/phpMan.php/man/dhcpcd-run-hooks/8/markdown).

       **definend _**code_ _type_ _variable_
               Defines  the  ND  option  _code_  of  _type_  with  a  name  of  _variable_   exported   to
               [_dhcpcd-run-hooks_(8)](https://www.chedong.com/phpMan.php/man/dhcpcd-run-hooks/8/markdown), with a prefix of _nd__.

       **define6 _**code_ _type_ _variable_
               Defines  the  DHCPv6  option  _code_  of  _type_  with  a  name  of  _variable_ exported to
               [_dhcpcd-run-hooks_(8)](https://www.chedong.com/phpMan.php/man/dhcpcd-run-hooks/8/markdown), with a prefix of _dhcp6__.

       **vendopt _**code_ _type_ _variable_
               Defines the Vendor-Identifying Vendor Options.  The _code_ is the IANA Enterprise  Num‐
               ber  which  will uniquely describe the encapsulated options.  _type_ is normally _encap_.
               _variable_ names the Vendor option to be exported.

       **embed _**type_ _variable_
               Defines an embedded variable within the defined option.  The length is determined  by
               the  _type_.   If  the  _variable_ is not the same as defined in the parent option, it is
               prefixed with the parent _variable_ first with an underscore.  If the _variable_ has  the
               name of _reserved_ then it is not processed.

       **encap _**code_ _type_ _variable_
               Defines an encapsulated variable within the defined option.  The length is determined
               by  the _type_.  If the _variable_ is not the same as defined in the parent option, it is
               prefixed with the parent _variable_ first with an underscore.

### Type prefix
       These keywords come before the type itself, to describe it more fully.  You can use more than
       one, but they must appear in the order listed below.

       **request  **Requests the option by default without having to be specified in user configuration.

### norequest
                This option cannot be requested, regardless of user configuration.

### optional
                This option is optional.  Only makes sense for embedded options like the client FQDN
                option, where the FQDN string itself is optional.

       **index    **The option can appear more than once and will be indexed.

       **array    **The option data is split into a space separated array, each element being  the  same
                type.

### Types to define
       The  type directly affects the length of data consumed inside the option.  Any remaining data
       is normally discarded.  Lengths can be specified for string and binhex  types,  but  this  is
       generally with other data embedded afterwards in the same option.

### ipaddress
               An IPv4 address, 4 bytes.

### ip6address
               An IPv6 address, 16 bytes.

       **string **[: **length**]
               A NVT ASCII string of printable characters.

       **byte    **A byte.

       **bitflags**: **flags**
               A  byte  represented  as a string of flags, most significant bit first.  For example,
               using ABCDEFGH then A would equal 10000000, B 01000000, C 00100000, etc.  If the  bit
               is  not set, the flag is not printed.  A flag of 0 is not printed even if the bit po‐
               sition is set.  This is to allow reservation of the first bits  while  assigning  the
               last bits.

       **int16   **A signed 16bit integer, 2 bytes.

       **uint16  **An unsigned 16bit integer, 2 bytes.

       **int32   **A signed 32bit integer, 4 bytes.

       **uint32  **An unsigned 32bit integer, 4 bytes.

       **flag    **A fixed value (1) to indicate that the option is present, 0 bytes.

       **domain  **An RFC 3397 encoded string.

       **dname   **An RFC 1035 validated string.

       **uri     **If an array then the first two bytes are the URI length inside the option data.  Oth‐
               erwise,  the  whole option data is the URI.  As a space is not allowed in the URI en‐
               coding, the URIs are space separated.

       **binhex **[: **length**]
               Binary data expressed as hexadecimal.

       **embed   **Contains embedded options (implies encap as well).

       **encap   **Contains encapsulated options (implies embed as well).

       **option  **References an option from the global definition.

### Example definition
             # DHCP option 81, Fully Qualified Domain Name, RFC 4702
             define 81 embed fqdn
             embed byte flags
             embed byte rcode1
             embed byte rcode2
             embed domain fqdn

             # DHCP option 125, Vendor Specific Information Option, RFC 3925
             define 125 encap vsio
             embed uint32 enterprise_number
             # Options defined for the enterprise number
             encap 1 ipaddress ipaddress

### Supported Authentication Protocols
       **token    **Sends a plain text token the server expects and matches a token sent by the  server.
                The tokens do not have to be the same.  If unspecified, the token with a _secretid_ of
                0 will be used in sending messages and validating received messages.

### delayedrealm
                Delayed  Authentication.   **dhcpcd  **will send an authentication option with no key or
                MAC.  The server will see this option, and select a key for **dhcpcd.conf**, writing the
                _realm_ and _secretid_ in it.  **dhcpcd **will then look  for  an  unexpired  token  with  a
                matching _realm_ and _secretid_.  This token is used to authenticate all other messages.

       **delayed  **Same as above, but without a realm.

### Supported Authentication Algorithms
       If none specified, **hmac-md5 **is the default.

### hmac-md5

### Supported Replay Detection Mechanisms
       If  none  specified,  **monotonic  **is the default.  If this is changed from what was previously
       used, or the means of calculating or storing it is broken, then the DHCP server will probably
       have to have its notion of the client's Replay Detection Value reset.

### monocounter
                Read the number in the file _/var/lib/dhcpcd/dhcpcd-rdm.monotonic_ and add one to it.

### monotime
                Create an NTP timestamp from the system time.

### monotonic
                Same as **monotime**.

## SEE ALSO
       [_fnmatch_(3)](https://www.chedong.com/phpMan.php/man/fnmatch/3/markdown), [_if_nametoindex_(3)](https://www.chedong.com/phpMan.php/man/ifnametoindex/3/markdown), [_dhcpcd_(8)](https://www.chedong.com/phpMan.php/man/dhcpcd/8/markdown), [_dhcpcd-run-hooks_(8)](https://www.chedong.com/phpMan.php/man/dhcpcd-run-hooks/8/markdown)

## AUTHORS
       Roy Marples <<_roy@marples.name_>>

## BUGS
       Please report them to <https://roy.marples.name/projects/dhcpcd>

Debian                                    December 18, 2023                           [_DHCPCD.CONF_(5)](https://www.chedong.com/phpMan.php/man/DHCPCD.CONF/5/markdown)
