|
|
|
@ -10,7 +10,7 @@ net.ipv4.tcp_keepalive_time=120 |
|
|
|
|
net.ipv4.tcp_syncookies=1 |
|
|
|
|
net.ipv4.tcp_timestamps=0 |
|
|
|
|
net.core.netdev_max_backlog=30 |
|
|
|
|
net.netfilter.nf_conntrack_checksum=0 |
|
|
|
|
|
|
|
|
|
net.ipv4.netfilter.ip_conntrack_checksum=0 |
|
|
|
|
net.ipv4.netfilter.ip_conntrack_max=16384 |
|
|
|
|
net.ipv4.netfilter.ip_conntrack_tcp_timeout_established=3600 |
|
|
|
@ -18,6 +18,12 @@ net.ipv4.netfilter.ip_conntrack_udp_timeout=60 |
|
|
|
|
net.ipv4.netfilter.ip_conntrack_udp_timeout_stream=180 |
|
|
|
|
net.ipv6.conf.all.forwarding=1 |
|
|
|
|
|
|
|
|
|
net.netfilter.nf_conntrack_checksum=0 |
|
|
|
|
net.netfilter.nf_conntrack_max=16384 |
|
|
|
|
net.netfilter.nf_conntrack_tcp_timeout_established=3600 |
|
|
|
|
net.netfilter.nf_conntrack_udp_timeout=60 |
|
|
|
|
net.netfilter.nf_conntrack_udp_timeout_stream=180 |
|
|
|
|
|
|
|
|
|
# disable bridge firewalling by default |
|
|
|
|
net.bridge.bridge-nf-call-arptables=0 |
|
|
|
|
net.bridge.bridge-nf-call-ip6tables=0 |
|
|
|
|