.RE
.SH OPTIONS
+.SS "Controller Discovery Options"
.TP
\fB--accept-vconn=\fIregex\fR
When \fBsecchan\fR performs controller discovery (see \fBCONTACTING
When controller discovery is not performed, this option has no effect.
+.SS "Networking Options"
.TP
\fB-F\fR, \fB--fail=\fR[\fBopen\fR|\fBclosed\fR]
The controller is, ordinarily, responsible for setting up all flows on
because bugs in the STP implementation are still being worked out.
The default will change to \fB--stp\fR at some point in the future.
+.TP
+\fB--netflow=\fIhost\fB:\fIport\fR
+When flows end on the switch, send NetFlow v5 messages to
+\fIhost\fR on UDP \fIport\fR.
+
+.SS "Remote Command Execution Options"
+
.TP
\fB--command-acl=\fR[\fB!\fR]\fIglob\fR[\fB,\fR[\fB!\fR]\fIglob\fR...]
Configures the commands that remote OpenFlow connections are allowed
\fBdirectory\fR. The default directory is
\fB@pkgdatadir@/commands\fR.
-.TP
-\fB--netflow=\fIhost\fB:\fIport\fR
-When flows end on the switch, send NetFlow v5 messages to
-\fIhost\fR on UDP \fIport\fR.
+.SS "Daemon Options"
+.so lib/daemon.man
+
+.SS "Public Key Infrastructure Options"
.TP
\fB-p\fR, \fB--private-key=\fIprivkey.pem\fR
\fBcontroller\fR(8) can be configured to do so with the
\fB--peer-ca-cert\fR option.
-.so lib/daemon.man
+.SS "Logging Options"
.so lib/vlog.man
+.SS "Other Options"
.so lib/common.man
.so lib/leak-checker.man