ceph存储 CentOS内核优化示例sysctl.conf、iptables、limits.conf
2017-03-08 19:16
666 查看
不是老法师,具体参数请自己根据自己的系统需求等情况做适当修改
/etc/sysctl.conf
/etc/sysconfig/iptables
/etc/security/limits.conf
/etc/sysctl.conf
net.ipv4.ip_forward = 0 net.ipv4.conf.default.rp_filter = 1 net.ipv4.conf.default.accept_source_route = 0 kernel.sysrq = 0 kernel.core_uses_pid = 1 net.ipv4.tcp_syncookies = 1 kernel.msgmnb = 65536 kernel.msgmax = 65536 kernel.shmmax = 68719476736 kernel.shmall = 4294967296 net.ipv4.tcp_max_tw_buckets = 5000 net.ipv4.tcp_sack = 1 net.ipv4.tcp_window_scaling = 1 net.ipv4.tcp_rmem = 4096 87380 4194304 net.ipv4.tcp_wmem = 4096 16384 4194304 net.core.wmem_default = 8388608 net.core.rmem_default = 8388608 net.core.rmem_max = 16777216 net.core.wmem_max = 16777216 net.core.netdev_max_backlog = 262144 net.core.somaxconn = 262144 net.ipv4.tcp_max_orphans = 3276800 net.ipv4.tcp_max_syn_backlog = 8192 net.ipv4.tcp_timestamps = 0 net.ipv4.tcp_synack_retries = 1 net.ipv4.tcp_syn_retries = 1 net.ipv4.tcp_tw_recycle = 1 net.ipv4.tcp_tw_reuse = 1 net.ipv4.tcp_mem = 94500000 915000000 927000000 net.ipv4.tcp_fin_timeout = 30 net.ipv4.tcp_keepalive_time = 10 net.ipv4.tcp_keepalive_probes=5 net.ipv4.ip_local_port_range = 1024 65534 fs.file-max = 6553500 fs.inotify.max_user_instances = 10485760 fs.inotify.max_user_watches=10485760 net.netfilter.nf_conntrack_max = 6553500 net.netfilter.nf_conntrack_tcp_timeout_close_wait = 60 net.netfilter.nf_conntrack_tcp_timeout_fin_wait = 120 net.netfilter.nf_conntrack_tcp_timeout_time_wait = 120 net.netfilter.nf_conntrack_tcp_timeout_established = 3600
/etc/sysconfig/iptables
*filter :INPUT DROP [0:0] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [0:0] :syn-flood - [0:0] -A INPUT -i lo -j ACCEPT -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT -A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT -A INPUT -p icmp -m limit --limit 1/sec --limit-burst 10 -j ACCEPT -A INPUT -f -m limit --limit 100/sec --limit-burst 100 -j ACCEPT -A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j syn-flood -A INPUT -j REJECT --reject-with icmp-host-prohibited -A syn-flood -p tcp -m limit --limit 3/sec --limit-burst 6 -j RETURN -A syn-flood -j REJECT --reject-with icmp-port-unreachable COMMIT
/etc/security/limits.conf
* soft nproc 65535 * hard nproc 65535 * soft nofile 65535 * hard nofile 65535
相关文章推荐
- centos下limits.conf和sysctl.conf优化脚本
- centos下limits.conf和sysctl.conf优化脚本
- centos下limits.conf和sysctl.conf优化脚本
- CentOS5.x内核优化详细解析 (sysctl.conf)
- 通过/etc/sysctl.conf加固 内核优化
- /etc/sysctl.conf 调优 & 优化Linux内核参数
- 内核参数优化/etc/sysctl.conf
- Linux之sysctl.conf与limits.conf优化配置
- Linux内核优化sysctl.conf,生产环境需反复测试,找到最佳值
- ceph存储 centos下ulimit用法示例
- ceph存储 centos上搭建Ceph分布式文件系统集群示例一
- Linux 系统内核参数 sysctl.conf优化方案
- 内核参数sysctl.conf的优化
- CentOS5.x内核优化详细解析 (sysctl.conf)
- 设置Sysctl.conf用以提高Linux的性能(最完整的sysctl.conf优化方案)
- CentOS7 内核参数优化
- FreeBsd网络性能优化方案WEB sysctl.conf ,以及老大逐句解析
- 如何在 CentOS 7.0 上配置 Ceph 存储
- Centos5.3编译内核增加connlimit模块并升级Iptables
- centos7内核参数优化配置详解