[root@adc ~]# sysctl -p
net.ipv4.ip_forward = 0
net.ipv4.conf.default.rp_filter = 1
net.ipv4.conf.default.accept_source_route = 0
kernel.sysrq = 0
kernel.core_uses_pid = 1
fs.file-max = 2097152
net.core.rmem_default = 10000000
net.core.rmem_max = 10000000
net.core.wmem_default = 10000000
net.core.wmem_max = 10000000
net.core.optmem_max = 10000000
net.core.somaxconn = 1024
net.ipv4.tcp_max_orphans = 327680
net.ipv6.conf.default.dad_transmits = 0
net.ipv4.neigh.default.gc_thresh1 = 204800
net.ipv4.neigh.default.gc_thresh2 = 409600
net.ipv4.neigh.default.gc_thresh3 = 819200
net.ipv4.ip_local_port_range = 16384 65534
net.ipv4.tcp_max_syn_backlog = 8092
net.ipv4.tcp_max_tw_buckets = 1800000
net.ipv4.ip_forward = 1
error: "net.ipv4.netfilter.ip_conntrack_max" is an unknown key
error: "net.ipv4.netfilter.ip_conntrack_tcp_timeout_established" is an unknown key
net.ipv4.tcp_sack = 0
net.ipv4.tcp_syncookies = 0
net.ipv4.tcp_tw_reuse = 1
net.ipv4.tcp_tw_recycle = 1
net.ipv4.tcp_fin_timeout = 30
原文出处:Netkiller 系列 手札
本文作者:陈景峯
转载请与作者联系,同时请务必标明文章原始出处和作者信息及本声明。