FastHandle is fast operation tools for infrastructure configurations and tests.
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
os:linux:set:kernel:etc_sysctl.conf.html [2017/11/18 01:29] kurihara |
os:linux:set:kernel:etc_sysctl.conf.html [2018/02/17 01:43] (current) kurihara |
||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== | + | [[os: |
| + | ====== / | ||
| + | \\ | ||
| + | {{INLINETOC}} | ||
| + | \\ | ||
| - | ===== / | + | ===== My / |
| Line 30: | Line 34: | ||
| # Network | # Network | ||
| # | # | ||
| - | # keepalive | + | # TCP keepalive |
| net.ipv4.tcp_keepalive_time = 60 # defautl 7200 | net.ipv4.tcp_keepalive_time = 60 # defautl 7200 | ||
| net.ipv4.tcp_keepalive_intvl = 3 # default 75 | net.ipv4.tcp_keepalive_intvl = 3 # default 75 | ||
| Line 37: | Line 41: | ||
| # 60sec + 3sec * 9 = 567sec = 9.56min | # 60sec + 3sec * 9 = 567sec = 9.56min | ||
| - | + | # tcp connection | |
| - | # disable IPv6 | + | net.nf_conntrack_max |
| - | net.ipv6.conf.all.disable_ipv6 = 1 | + | |
| - | net.ipv6.conf.lo.disable_ipv6 = 1 | + | |
| - | net.ipv6.conf.default.disable_ipv6 | + | |
| # port exhaustion | # port exhaustion | ||
| Line 51: | Line 52: | ||
| net.ipv4.tcp_tw_reuse = 1 | net.ipv4.tcp_tw_reuse = 1 | ||
| + | |||
| + | # disable IPv6 (CentOS7) | ||
| + | net.ipv6.conf.all.disable_ipv6 = 1 | ||
| + | net.ipv6.conf.lo.disable_ipv6 = 1 | ||
| + | net.ipv6.conf.default.disable_ipv6 = 1 | ||
| Line 59: | Line 65: | ||
| kernel.pid_max = 131072 | kernel.pid_max = 131072 | ||
| + | </ | ||
| + | |||
| + | \\ | ||
| + | ===== CentOS7 Defautl / | ||
| + | |||
| + | <sxh bash toolbar: | ||
| + | # System default settings live in / | ||
| + | # To override those settings, enter new settings here, or in an / | ||
| + | # | ||
| + | # For more information, | ||
| + | </ | ||
| + | |||
| + | \\ | ||
| + | ===== Ubuntu16.0.4 Default / | ||
| + | |||
| + | <sxh bash toolbar: | ||
| + | # | ||
| + | # / | ||
| + | # See / | ||
| + | # See sysctl.conf (5) for information. | ||
| + | # | ||
| + | |||
| + | # | ||
| + | |||
| + | # Uncomment the following to stop low-level messages on console | ||
| + | # | ||
| + | |||
| + | ############################################################## | ||
| + | # Functions previously found in netbase | ||
| + | # | ||
| + | |||
| + | # Uncomment the next two lines to enable Spoof protection (reverse-path filter) | ||
| + | # Turn on Source Address Verification in all interfaces to | ||
| + | # prevent some spoofing attacks | ||
| + | # | ||
| + | # | ||
| + | |||
| + | # Uncomment the next line to enable TCP/IP SYN cookies | ||
| + | # See http:// | ||
| + | # Note: This may impact IPv6 TCP sessions too | ||
| + | # | ||
| + | |||
| + | # Uncomment the next line to enable packet forwarding for IPv4 | ||
| + | net.ipv4.ip_forward=1 | ||
| + | |||
| + | # Uncomment the next line to enable packet forwarding for IPv6 | ||
| + | # Enabling this option disables Stateless Address Autoconfiguration | ||
| + | # based on Router Advertisements for this host | ||
| + | # | ||
| + | |||
| + | |||
| + | ################################################################### | ||
| + | # Additional settings - these settings can improve the network | ||
| + | # security of the host and prevent against some network attacks | ||
| + | # including spoofing attacks and man in the middle attacks through | ||
| + | # redirection. Some network environments, | ||
| + | # settings are disabled so review and enable them as needed. | ||
| + | # | ||
| + | # Do not accept ICMP redirects (prevent MITM attacks) | ||
| + | # | ||
| + | # | ||
| + | # _or_ | ||
| + | # Accept ICMP redirects only for gateways listed in our default | ||
| + | # gateway list (enabled by default) | ||
| + | # net.ipv4.conf.all.secure_redirects = 1 | ||
| + | # | ||
| + | # Do not send ICMP redirects (we are not a router) | ||
| + | # | ||
| + | # | ||
| + | # Do not accept IP source route packets (we are not a router) | ||
| + | # | ||
| + | # | ||
| + | # | ||
| + | # Log Martian Packets | ||
| + | # | ||
| + | # | ||
| + | |||
| + | net.ipv6.conf.all.disable_ipv6 = 1 | ||
| + | net.ipv6.conf.default.disable_ipv6 = 1 | ||
| + | net.ipv6.conf.default.autoconf=0 | ||
| </ | </ | ||
| + | \\ | ||
| + | <WRAP box 90%> | ||
| + | <catlist ..: -noAddPageButton -smallHead> | ||
| + | </ | ||
| + | \\ | ||
| + | \\ | ||
| + | [[os: | ||
My Sites
SNS
Copyright (c) 2025 FastHandle - IT Operations Examples All Rights Reserved.