blob: 08d39e246656e5284d57ed799a4e3470e068c2ca [file] [log] [blame]
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -07001wpa_supplicant and Wi-Fi P2P
2============================
3
4This document describes how the Wi-Fi P2P implementation in
5wpa_supplicant can be configured and how an external component on the
6client (e.g., management GUI) is used to enable WPS enrollment and
7registrar registration.
8
9
10Introduction to Wi-Fi P2P
11-------------------------
12
13TODO
14
15More information about Wi-Fi P2P is available from Wi-Fi Alliance:
16http://www.wi-fi.org/Wi-Fi_Direct.php
17
18
19wpa_supplicant implementation
20-----------------------------
21
22TODO
23
24
25wpa_supplicant configuration
26----------------------------
27
28Wi-Fi P2P is an optional component that needs to be enabled in the
29wpa_supplicant build configuration (.config). Here is an example
30configuration that includes Wi-Fi P2P support and Linux nl80211
31-based driver interface:
32
33CONFIG_DRIVER_NL80211=y
34CONFIG_CTRL_IFACE=y
35CONFIG_P2P=y
36CONFIG_AP=y
37CONFIG_WPS=y
38
39
40In run-time configuration file (wpa_supplicant.conf), some parameters
41for P2P may be set. In order to make the devices easier to recognize,
42device_name and device_type should be specified. For example,
43something like this should be included:
44
45ctrl_interface=/var/run/wpa_supplicant
46device_name=My P2P Device
47device_type=1-0050F204-1
48
49
50wpa_cli
51-------
52
53Actual Wi-Fi P2P operations are requested during runtime. These can be
54done for example using wpa_cli (which is described below) or a GUI
55like wpa_gui-qt4.
56
57
58wpa_cli starts in interactive mode if no command string is included on
59the command line. By default, it will select the first network interface
60that it can find (and that wpa_supplicant controls). If more than one
61interface is in use, it may be necessary to select one of the explicitly
62by adding -i argument on the command line (e.g., 'wpa_cli -i wlan1').
63
64Most of the P2P operations are done on the main interface (e.g., the
65interface that is automatically added when the driver is loaded, e.g.,
66wlan0). When using a separate virtual interface for group operations
67(e.g., wlan1), the control interface for that group interface may need
68to be used for some operations (mainly WPS activation in GO). This may
69change in the future so that all the needed operations could be done
70over the main control interface.
71
72Device Discovery
73
Dmitry Shmidt61d9df32012-08-29 16:22:06 -070074p2p_find [timeout in seconds] [type=<social|progressive>] \
75 [dev_id=<addr>] [delay=<search delay in ms>]
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -070076
77The default behavior is to run a single full scan in the beginning and
78then scan only social channels. type=social will scan only social
79channels, i.e., it skips the initial full scan. type=progressive is
80like the default behavior, but it will scan through all the channels
81progressively one channel at the time in the Search state rounds. This
82will help in finding new groups or groups missed during the initial
83full scan.
84
Dmitry Shmidt61d9df32012-08-29 16:22:06 -070085The optional dev_id option can be used to specify a single P2P peer to
86search for. The optional delay parameter can be used to request an extra
87delay to be used between search iterations (e.g., to free up radio
88resources for concurrent operations).
89
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -070090p2p_listen [timeout in seconds]
91
92Start Listen-only state (become discoverable without searching for
93other devices). Optional parameter can be used to specify the duration
94for the Listen operation in seconds. This command may not be of that
95much use during normal operations and is mainly designed for
96testing. It can also be used to keep the device discoverable without
97having to maintain a group.
98
99p2p_stop_find
100
101Stop ongoing P2P device discovery or other operation (connect, listen
102mode).
103
104p2p_flush
105
106Flush P2P peer table and state.
107
108Group Formation
109
Dmitry Shmidt04949592012-07-19 12:16:46 -0700110p2p_prov_disc <peer device address> <display|keypad|pbc> [join|auto]
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700111
112Send P2P provision discovery request to the specified peer. The
113parameters for this command are the P2P device address of the peer and
114the desired configuration method. For example, "p2p_prov_disc
11502:01:02:03:04:05 display" would request the peer to display a PIN for
116us and "p2p_prov_disc 02:01:02:03:04:05 keypad" would request the peer
117to enter a PIN that we display.
118
Dmitry Shmidt1f69aa52012-01-24 16:10:04 -0800119The optional "join" parameter can be used to indicate that this command
120is requesting an already running GO to prepare for a new client. This is
Dmitry Shmidt04949592012-07-19 12:16:46 -0700121mainly used with "display" to request it to display a PIN. The "auto"
122parameter can be used to request wpa_supplicant to automatically figure
123out whether the peer device is operating as a GO and if so, use
124join-a-group style PD instead of GO Negotiation style PD.
Dmitry Shmidt1f69aa52012-01-24 16:10:04 -0800125
126p2p_connect <peer device address> <pbc|pin|PIN#> [display|keypad]
Dmitry Shmidt04949592012-07-19 12:16:46 -0700127 [persistent|persistent=<network id>] [join|auth]
Dmitry Shmidt68d0e3e2013-10-28 17:59:21 -0700128 [go_intent=<0..15>] [freq=<in MHz>] [ht40] [vht] [provdisc]
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700129
130Start P2P group formation with a discovered P2P peer. This includes
131optional group owner negotiation, group interface setup, provisioning,
132and establishing data connection.
133
134The <pbc|pin|PIN#> parameter specifies the WPS provisioning
135method. "pbc" string starts pushbutton method, "pin" string start PIN
136method using an automatically generated PIN (which will be returned as
137the command return code), PIN# means that a pre-selected PIN can be
Dmitry Shmidt1f69aa52012-01-24 16:10:04 -0800138used (e.g., 12345670). [display|keypad] is used with PIN method
139to specify which PIN is used (display=dynamically generated random PIN
140from local display, keypad=PIN entered from peer display). "persistent"
Dmitry Shmidt04949592012-07-19 12:16:46 -0700141parameter can be used to request a persistent group to be formed. The
142"persistent=<network id>" alternative can be used to pre-populate
143SSID/passphrase configuration based on a previously used persistent
144group where this device was the GO. The previously used parameters will
145then be used if the local end becomes the GO in GO Negotiation (which
146can be forced with go_intent=15).
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700147
148"join" indicates that this is a command to join an existing group as a
149client. It skips the GO Negotiation part. This will send a Provision
150Discovery Request message to the target GO before associating for WPS
151provisioning.
152
153"auth" indicates that the WPS parameters are authorized for the peer
154device without actually starting GO Negotiation (i.e., the peer is
155expected to initiate GO Negotiation). This is mainly for testing
156purposes.
157
158"go_intent" can be used to override the default GO Intent for this GO
159Negotiation.
160
161"freq" can be used to set a forced operating channel (e.g., freq=2412
162to select 2.4 GHz channel 1).
163
Dmitry Shmidt04949592012-07-19 12:16:46 -0700164"provdisc" can be used to request a Provision Discovery exchange to be
165used prior to starting GO Negotiation as a workaround with some deployed
166P2P implementations that require this to allow the user to accept the
167connection.
168
Dmitry Shmidt68d0e3e2013-10-28 17:59:21 -0700169p2p_group_add [persistent|persistent=<network id>] [freq=<freq in MHz>]
170 [ht40] [vht]
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700171
172Set up a P2P group owner manually (i.e., without group owner
173negotiation with a specific peer). This is also known as autonomous
174GO. Optional persistent=<network id> can be used to specify restart of
175a persistent group. Optional freq=<freq in MHz> can be used to force
176the GO to be started on a specific frequency. Special freq=2 or freq=5
177options can be used to request the best 2.4 GHz or 5 GHz band channel
178to be selected automatically.
179
180p2p_reject <peer device address>
181
182Reject connection attempt from a peer (specified with a device
183address). This is a mechanism to reject a pending GO Negotiation with
184a peer and request to automatically block any further connection or
185discovery of the peer.
186
187p2p_group_remove <group interface>
188
189Terminate a P2P group. If a new virtual network interface was used for
190the group, it will also be removed. The network interface name of the
191group interface is used as a parameter for this command.
192
193p2p_cancel
194
Dmitry Shmidta54fa5f2013-01-15 13:53:35 -0800195Cancel an ongoing P2P group formation and joining-a-group related
196operation. This operations unauthorizes the specific peer device (if any
197had been authorized to start group formation), stops P2P find (if in
198progress), stops pending operations for join-a-group, and removes the
199P2P group interface (if one was used) that is in the WPS provisioning
200step. If the WPS provisioning step has been completed, the group is not
201terminated.
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700202
Dmitry Shmidt391c59f2013-09-03 12:16:28 -0700203p2p_remove_client <peer's P2P Device Address|iface=<interface address>>
204
205This command can be used to remove the specified client from all groups
206(operating and persistent) from the local GO. Note that the peer device
207can rejoin the group if it is in possession of a valid key. See p2p_set
208per_sta_psk command below for more details on how the peer can be
209removed securely.
210
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700211Service Discovery
212
213p2p_serv_disc_req
214
215Schedule a P2P service discovery request. The parameters for this
216command are the device address of the peer device (or 00:00:00:00:00:00
217for wildcard query that is sent to every discovered P2P peer that
218supports service discovery) and P2P Service Query TLV(s) as hexdump. For
219example,
220
221p2p_serv_disc_req 00:00:00:00:00:00 02000001
222
223schedules a request for listing all available services of all service
224discovery protocols and requests this to be sent to all discovered
225peers (note: this can result in long response frames). The pending
226requests are sent during device discovery (see p2p_find).
227
228Only a single pending wildcard query is supported, but there can be
229multiple pending peer device specific queries (each will be sent in
230sequence whenever the peer is found).
231
232This command returns an identifier for the pending query (e.g.,
233"1f77628") that can be used to cancel the request. Directed requests
234will be automatically removed when the specified peer has replied to
235it.
236
Dmitry Shmidta54fa5f2013-01-15 13:53:35 -0800237Service Query TLV has following format:
238Length (2 octets, little endian) - length of following data
239Service Protocol Type (1 octet) - see the table below
240Service Transaction ID (1 octet) - nonzero identifier for the TLV
241Query Data (Length - 2 octets of data) - service protocol specific data
242
243Service Protocol Types:
2440 = All service protocols
2451 = Bonjour
2462 = UPnP
2473 = WS-Discovery
2484 = Wi-Fi Display
249
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700250For UPnP, an alternative command format can be used to specify a
251single query TLV (i.e., a service discovery for a specific UPnP
252service):
253
254p2p_serv_disc_req 00:00:00:00:00:00 upnp <version hex> <ST: from M-SEARCH>
255
256For example:
257
258p2p_serv_disc_req 00:00:00:00:00:00 upnp 10 urn:schemas-upnp-org:device:InternetGatewayDevice:1
259
260Additional examples for queries:
261
262# list of all Bonjour services
263p2p_serv_disc_req 00:00:00:00:00:00 02000101
264
265# list of all UPnP services
266p2p_serv_disc_req 00:00:00:00:00:00 02000201
267
268# list of all WS-Discovery services
269p2p_serv_disc_req 00:00:00:00:00:00 02000301
270
271# list of all Bonjour and UPnP services
272p2p_serv_disc_req 00:00:00:00:00:00 0200010102000202
273
274# Apple File Sharing over TCP
275p2p_serv_disc_req 00:00:00:00:00:00 130001010b5f6166706f766572746370c00c000c01
276
277# Bonjour SSTH (supported service type hash)
278p2p_serv_disc_req 00:00:00:00:00:00 05000101000000
279
280# UPnP examples
281p2p_serv_disc_req 00:00:00:00:00:00 upnp 10 ssdp:all
282p2p_serv_disc_req 00:00:00:00:00:00 upnp 10 upnp:rootdevice
283p2p_serv_disc_req 00:00:00:00:00:00 upnp 10 urn:schemas-upnp-org:service:ContentDirectory:2
284p2p_serv_disc_req 00:00:00:00:00:00 upnp 10 uuid:6859dede-8574-59ab-9332-123456789012
285p2p_serv_disc_req 00:00:00:00:00:00 upnp 10 urn:schemas-upnp-org:device:InternetGatewayDevice:1
286
Dmitry Shmidt61d9df32012-08-29 16:22:06 -0700287# Wi-Fi Display examples
288# format: wifi-display <list of roles> <list of subelements>
289p2p_serv_disc_req 00:00:00:00:00:00 wifi-display [source] 2,3,4,5
290p2p_serv_disc_req 02:01:02:03:04:05 wifi-display [pri-sink] 3
291p2p_serv_disc_req 00:00:00:00:00:00 wifi-display [sec-source] 2
292p2p_serv_disc_req 00:00:00:00:00:00 wifi-display [source+sink] 2,3,4,5
293p2p_serv_disc_req 00:00:00:00:00:00 wifi-display [source][pri-sink] 2,3,4,5
294
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700295p2p_serv_disc_cancel_req <query identifier>
296
297Cancel a pending P2P service discovery request. This command takes a
298single parameter: identifier for the pending query (the value returned
299by p2p_serv_disc_req, e.g., "p2p_serv_disc_cancel_req 1f77628".
300
301p2p_serv_disc_resp
302
303Reply to a service discovery query. This command takes following
304parameters: frequency in MHz, destination address, dialog token,
305response TLV(s). The first three parameters are copied from the
306request event. For example, "p2p_serv_disc_resp 2437 02:40:61:c2:f3:b7
3071 0300000101". This command is used only if external program is used
308to process the request (see p2p_serv_disc_external).
309
310p2p_service_update
311
312Indicate that local services have changed. This is used to increment
313the P2P service indicator value so that peers know when previously
314cached information may have changed. This is only needed when external
315service discovery processing is enabled since the commands to
316pre-configure services for internal processing will increment the
317indicator automatically.
318
319p2p_serv_disc_external <0|1>
320
321Configure external processing of P2P service requests: 0 (default) =
322no external processing of requests (i.e., internal code will process
323each request based on pre-configured services), 1 = external
324processing of requests (external program is responsible for replying
325to service discovery requests with p2p_serv_disc_resp). Please note
326that there is quite strict limit on how quickly the response needs to
327be transmitted, so use of the internal processing is strongly
328recommended.
329
330p2p_service_add bonjour <query hexdump> <RDATA hexdump>
331
332Add a local Bonjour service for internal SD query processing.
333
334Examples:
335
336# AFP Over TCP (PTR)
337p2p_service_add bonjour 0b5f6166706f766572746370c00c000c01 074578616d706c65c027
338# AFP Over TCP (TXT) (RDATA=null)
339p2p_service_add bonjour 076578616d706c650b5f6166706f766572746370c00c001001 00
340
341# IP Printing over TCP (PTR) (RDATA=MyPrinter._ipp._tcp.local.)
342p2p_service_add bonjour 045f697070c00c000c01 094d795072696e746572c027
343# IP Printing over TCP (TXT) (RDATA=txtvers=1,pdl=application/postscript)
344p2p_service_add bonjour 096d797072696e746572045f697070c00c001001 09747874766572733d311a70646c3d6170706c69636174696f6e2f706f7374736372797074
345
346# Supported Service Type Hash (SSTH)
347p2p_service_add bonjour 000000 <32-byte bitfield as hexdump>
348(note: see P2P spec Annex E.4 for information on how to construct the bitfield)
349
350p2p_service_del bonjour <query hexdump>
351
352Remove a local Bonjour service from internal SD query processing.
353
354p2p_service_add upnp <version hex> <service>
355
356Add a local UPnP service for internal SD query processing.
357
358Examples:
359
360p2p_service_add upnp 10 uuid:6859dede-8574-59ab-9332-123456789012::upnp:rootdevice
361p2p_service_add upnp 10 uuid:5566d33e-9774-09ab-4822-333456785632::upnp:rootdevice
362p2p_service_add upnp 10 uuid:1122de4e-8574-59ab-9322-333456789044::urn:schemas-upnp-org:service:ContentDirectory:2
363p2p_service_add upnp 10 uuid:5566d33e-9774-09ab-4822-333456785632::urn:schemas-upnp-org:service:ContentDirectory:2
364p2p_service_add upnp 10 uuid:6859dede-8574-59ab-9332-123456789012::urn:schemas-upnp-org:device:InternetGatewayDevice:1
365
366p2p_service_del upnp <version hex> <service>
367
368Remove a local UPnP service from internal SD query processing.
369
370p2p_service_flush
371
372Remove all local services from internal SD query processing.
373
374Invitation
375
376p2p_invite [persistent=<network id>|group=<group ifname>] [peer=address]
Dmitry Shmidt68d0e3e2013-10-28 17:59:21 -0700377 [go_dev_addr=address] [freq=<freq in MHz>] [ht40] [vht]
378 [pref=<MHz>]
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700379
380Invite a peer to join a group (e.g., group=wlan1) or to reinvoke a
381persistent group (e.g., persistent=4). If the peer device is the GO of
Dmitry Shmidt04949592012-07-19 12:16:46 -0700382the persistent group, the peer parameter is not needed. Otherwise it is
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700383used to specify which device to invite. go_dev_addr parameter can be
384used to override the GO device address for Invitation Request should
385it be not known for some reason (this should not be needed in most
Jouni Malinen31be0a42012-08-31 21:20:51 +0300386cases). When reinvoking a persistent group, the GO device can specify
Dmitry Shmidt7a5e50a2013-03-05 12:37:16 -0800387the frequency for the group with the freq parameter. When reinvoking a
388persistent group, the P2P client device can use freq parameter to force
389a specific operating channel (or invitation failure if GO rejects that)
390or pref parameter to request a specific channel (while allowing GO to
391select to use another channel, if needed).
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700392
393Group Operations
394
395(These are used on the group interface.)
396
397wps_pin <any|address> <PIN>
398
399Start WPS PIN method. This allows a single WPS Enrollee to connect to
400the AP/GO. This is used on the GO when a P2P client joins an existing
401group. The second parameter is the address of the Enrollee or a string
402"any" to allow any station to use the entered PIN (which will restrict
403the PIN for one-time-use). PIN is the Enrollee PIN read either from a
404label or display on the P2P Client/WPS Enrollee.
405
406wps_pbc
407
408Start WPS PBC method (i.e., push the button). This allows a single WPS
409Enrollee to connect to the AP/GO. This is used on the GO when a P2P
410client joins an existing group.
411
412p2p_get_passphrase
413
414Get the passphrase for a group (only available when acting as a GO).
415
416p2p_presence_req [<duration> <interval>] [<duration> <interval>]
417
418Send a P2P Presence Request to the GO (this is only available when
419acting as a P2P client). If no duration/interval pairs are given, the
420request indicates that this client has no special needs for GO
Dmitry Shmidtfb79edc2014-01-10 10:45:54 -0800421presence. The first parameter pair gives the preferred duration and
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700422interval values in microseconds. If the second pair is included, that
Dmitry Shmidtfb79edc2014-01-10 10:45:54 -0800423indicates which value would be acceptable. This command returns OK
424immediately and the response from the GO is indicated in a
425P2P-PRESENCE-RESPONSE event message.
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700426
427Parameters
428
429p2p_ext_listen [<period> <interval>]
430
431Configure Extended Listen Timing. If the parameters are omitted, this
432feature is disabled. If the parameters are included, Listen State will
433be entered every interval msec for at least period msec. Both values
434have acceptable range of 1-65535 (with interval obviously having to be
435larger than or equal to duration). If the P2P module is not idle at
436the time the Extended Listen Timing timeout occurs, the Listen State
437operation will be skipped.
438
439The configured values will also be advertised to other P2P Devices. The
440received values are available in the p2p_peer command output:
441
442ext_listen_period=100 ext_listen_interval=5000
443
444p2p_set <field> <value>
445
446Change dynamic P2P parameters
447
448p2p_set discoverability <0/1>
449
450Disable/enable advertisement of client discoverability. This is
451enabled by default and this parameter is mainly used to allow testing
452of device discoverability.
453
454p2p_set managed <0/1>
455
456Disable/enable managed P2P Device operations. This is disabled by
457default.
458
459p2p_set listen_channel <1/6/11>
460
461Set P2P Listen channel. This is mainly meant for testing purposes and
462changing the Listen channel during normal operations can result in
463protocol failures.
464
465p2p_set ssid_postfix <postfix>
466
467Set postfix string to be added to the automatically generated P2P SSID
468(DIRECT-<two random characters>). For example, postfix of "-testing"
469could result in the SSID becoming DIRECT-ab-testing.
470
Dmitry Shmidt391c59f2013-09-03 12:16:28 -0700471p2p_set per_sta_psk <0/1>
472
473Disabled(default)/enables use of per-client PSK in the P2P groups. This
474can be used to request GO to assign a unique PSK for each client during
475WPS provisioning. When enabled, this allow clients to be removed from
476the group securily with p2p_remove_client command since that client's
477PSK is removed at the same time to prevent it from connecting back using
478the old PSK. When per-client PSK is not used, the client can still be
479disconnected, but it will be able to re-join the group since the PSK it
480learned previously is still valid. It should be noted that the default
481passphrase on the GO that is normally used to allow legacy stations to
482connect through manual configuration does not change here, so if that is
483shared, devices with knowledge of that passphrase can still connect.
484
Dmitry Shmidt8d520ff2011-05-09 14:06:53 -0700485set <field> <value>
486
487Set global configuration parameters which may also affect P2P
488operations. The format on these parameters is same as is used in
489wpa_supplicant.conf. Only the parameters listen here should be
490changed. Modifying other parameters may result in incorrect behavior
491since not all existing users of the parameters are updated.
492
493set uuid <UUID>
494
495Set WPS UUID (by default, this is generated based on the MAC address).
496
497set device_name <device name>
498
499Set WPS Device Name (also included in some P2P messages).
500
501set manufacturer <manufacturer>
502
503Set WPS Manufacturer.
504
505set model_name <model name>
506
507Set WPS Model Name.
508
509set model_number <model number>
510
511Set WPS Model Number.
512
513set serial_number <serial number>
514
515Set WPS Serial Number.
516
517set device_type <device type>
518
519Set WPS Device Type.
520
521set os_version <OS version>
522
523Set WPS OS Version.
524
525set config_methods <config methods>
526
527Set WPS Configuration Methods.
528
529set sec_device_type <device type>
530
531Add a new Secondary Device Type.
532
533set p2p_go_intent <GO intent>
534
535Set the default P2P GO Intent. Note: This value can be overridden in
536p2p_connect command and as such, there should be no need to change the
537default value here during normal operations.
538
539set p2p_ssid_postfix <P2P SSID postfix>
540
541Set P2P SSID postfix.
542
543set persistent_reconnect <0/1>
544
545Disable/enabled persistent reconnect for reinvocation of persistent
546groups. If enabled, invitations to reinvoke a persistent group will be
547accepted without separate authorization (e.g., user interaction).
548
549set country <two character country code>
550
551Set country code (this is included in some P2P messages).
552
553Status
554
555p2p_peers [discovered]
556
557List P2P Device Addresses of all the P2P peers we know. The optional
558"discovered" parameter filters out the peers that we have not fully
559discovered, i.e., which we have only seen in a received Probe Request
560frame.
561
562p2p_peer <P2P Device Address>
563
564Fetch information about a known P2P peer.
565
566Group Status
567
568(These are used on the group interface.)
569
570status
571
572Show status information (connection state, role, use encryption
573parameters, IP address, etc.).
574
575sta
576
577Show information about an associated station (when acting in AP/GO role).
578
579all_sta
580
581Lists the currently associated stations.
582
583Configuration data
584
585list_networks
586
587Lists the configured networks, including stored information for
588persistent groups. The identifier in this list is used with
589p2p_group_add and p2p_invite to indicate which persistent group is to
590be reinvoked.
591
592remove_network <network id>
593
594Remove a network entry from configuration.
595
596
597wpa_cli action script
598---------------------
599
600See examples/p2p-action.sh
601
602TODO: describe DHCP/DNS setup
603TODO: cross-connection