« A hard day | Home | 继续写blog »

October 19, 2005

Some sysctls

net.inet.tcp.sendspace=65536 net.inet.tcp.recvspace=65536 kern.ipc.somaxconn=4096 kern.ipc.maxsockbuf=2097152 net.inet.icmp.drop_redirect=1 net.inet.icmp.log_redirect=1 net.inet.ip.redirect=0 net.inet6.ip6.redirect=0 net.inet.icmp.icmplim=100 net.inet.tcp.always_keepalive=1 net.inet.tcp.delayed_ack=1 net.inet.udp.sendspace=65535 net.inet.udp.maxdgram=65535 net.local.stream.sendspace=65535 kern.maxfiles=65536 kern.securelevel=0 net.inet.tcp.log_in_vain=1 net.inet.udp.log_in_vain=1 net.inet.tcp.blackhole=2 net.inet.udp.blackhole=1 net.inet.udp.checksum=1 net.inet.icmp.bmcastecho=0 ######this new add 20041021########### net.inet.tcp.recvspace=65535 net.inet.tcp.sendspace=65535 net.inet.ip.forwarding=1 net.inet.tcp.strict_rfc1948=1 ########for sys flood attack###### net.inet.tcp.msl=7500 net.inet.tcp.blackhole=2 net.inet.udp.blackhole=1 net.inet.icmp.icmplim=50 kern.ipc.somaxconn=32768 net.inet.tcp.syncookies=1

sysctl -w net.inet.tcp.msl=7500
sysctl -w net.inet.tcp.blackhole=2
sysctl -w net.inet.udp.blackhole=1
sysctl -w net.inet.icmp.icmplim=50
sysctl -w kern.ipc.somaxconn=32768
sysctl -w net.inet.tcp.syncookies=1

Posted by Lifeng Shen on October 19, 2005 5:41 PM |

评论

添加评论







固定链接与引用