|
|
@ -4,7 +4,7 @@ net.ipv4.conf.all.arp_ignore=1 |
|
|
|
net.ipv4.ip_forward=1 |
|
|
|
net.ipv4.ip_forward=1 |
|
|
|
net.ipv4.icmp_echo_ignore_broadcasts=1 |
|
|
|
net.ipv4.icmp_echo_ignore_broadcasts=1 |
|
|
|
net.ipv4.icmp_ignore_bogus_error_responses=1 |
|
|
|
net.ipv4.icmp_ignore_bogus_error_responses=1 |
|
|
|
net.ipv4.tcp_ecn=0 |
|
|
|
net.ipv4.tcp_ecn=0 |
|
|
|
net.ipv4.tcp_fin_timeout=30 |
|
|
|
net.ipv4.tcp_fin_timeout=30 |
|
|
|
net.ipv4.tcp_keepalive_time=120 |
|
|
|
net.ipv4.tcp_keepalive_time=120 |
|
|
|
net.ipv4.tcp_syncookies=1 |
|
|
|
net.ipv4.tcp_syncookies=1 |
|
|
@ -17,3 +17,8 @@ net.ipv4.netfilter.ip_conntrack_tcp_timeout_established=3600 |
|
|
|
net.ipv4.netfilter.ip_conntrack_udp_timeout=60 |
|
|
|
net.ipv4.netfilter.ip_conntrack_udp_timeout=60 |
|
|
|
net.ipv4.netfilter.ip_conntrack_udp_timeout_stream=180 |
|
|
|
net.ipv4.netfilter.ip_conntrack_udp_timeout_stream=180 |
|
|
|
# net.ipv6.conf.all.forwarding=1 |
|
|
|
# net.ipv6.conf.all.forwarding=1 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# disable bridge firewalling by default |
|
|
|
|
|
|
|
net.bridge.bridge-nf-call-arptables=0 |
|
|
|
|
|
|
|
net.bridge.bridge-nf-call-ip6tables=0 |
|
|
|
|
|
|
|
net.bridge.bridge-nf-call-iptables=0 |
|
|
|