Initial commit
This commit is contained in:
commit
7855df459d
|
@ -0,0 +1,4 @@
|
|||
vm.overcommit_memory = 2
|
||||
|
||||
vm.dirty_ratio = 30
|
||||
vm.dirty_background_ratio = 10
|
|
@ -0,0 +1,46 @@
|
|||
# IPV4
|
||||
net.ipv4.ip_forward = 0
|
||||
net.ipv4.conf.default.accept_source_route = 0
|
||||
|
||||
net.ipv4.tcp_syncookies = 1
|
||||
net.ipv4.tcp_synack_retries = 5
|
||||
|
||||
net.ipv4.conf.all.send_redirects = 0
|
||||
net.ipv4.conf.default.send_redirects = 0
|
||||
net.ipv4.conf.all.accept_redirects = 0
|
||||
net.ipv4.conf.all.secure_redirects = 0
|
||||
net.ipv4.conf.all.accept_source_route = 0
|
||||
|
||||
net.ipv4.conf.all.log_martians = 1
|
||||
net.ipv4.conf.default.accept_source_route = 0
|
||||
net.ipv4.conf.default.accept_redirects = 0
|
||||
net.ipv4.conf.default.secure_redirects = 0
|
||||
|
||||
net.ipv4.icmp_echo_ignore_broadcasts = 1
|
||||
|
||||
net.ipv4.conf.all.rp_filter = 1
|
||||
net.ipv4.conf.default.rp_filter = 1
|
||||
|
||||
net.ipv4.tcp_rfc1337 = 1
|
||||
|
||||
# TCP Tweaks
|
||||
net.ipv4.tcp_fastopen = 3
|
||||
net.ipv4.tcp_tw_reuse = 1
|
||||
net.ipv4.tcp_mtu_probing = 1
|
||||
|
||||
# IPV6
|
||||
net.ipv6.conf.default.router_solicitations = 0
|
||||
|
||||
net.ipv6.conf.default.accept_ra_rtr_pref = 0
|
||||
net.ipv6.conf.default.accept_ra_pinfo = 0
|
||||
net.ipv6.conf.default.accept_ra_defrtr = 0
|
||||
|
||||
net.ipv6.conf.default.autoconf = 0
|
||||
|
||||
net.ipv6.conf.default.dad_transmits = 0
|
||||
|
||||
net.ipv6.conf.default.max_addresses = 1
|
||||
|
||||
# Misc
|
||||
net.core.netdev_max_backlog = 16384
|
||||
net.core.somaxconn = 8192
|
|
@ -0,0 +1,10 @@
|
|||
kernel.sysrq = 0
|
||||
|
||||
# Memory execution prevention
|
||||
kernel.exec-shield = 2
|
||||
kernel.randomize_va_space=2
|
||||
|
||||
kernel.dmesg_restrict = 1
|
||||
kernel.kptr_restrict = 2
|
||||
|
||||
kernel.kexec_load_disabled = 1
|
Loading…
Reference in New Issue