123456789101112131415161718192021222324252627282930313233343536 |
- # See sysctl.d(5) and core(5) for documentation.
- # To override settings in this file, create a local file in /etc
- # (e.g. /etc/sysctl.d/90-override.conf), and put any assignments
- # there.
- # System Request functionality of the kernel (SYNC)
- #
- # Use kernel.sysrq = 1 to allow all keys.
- # See https://www.kernel.org/doc/html/latest/admin-guide/sysrq.html for a list
- # of values and keys.
- # kernel.sysrq = 16
- # Source route verification
- net.ipv4.conf.all.rp_filter = 1
- # Do not accept source routing
- net.ipv4.conf.all.accept_source_route = 0
- # Promote secondary addresses when the primary address is removed
- net.ipv4.conf.all.promote_secondaries = 1
- # ping(8) without CAP_NET_ADMIN and CAP_NET_RAW
- # The upper limit is set to 2^31-1. Values greater than that get rejected by
- # the kernel because of this definition in linux/include/net/ping.h:
- # #define GID_T_MAX (((gid_t)~0U) >> 1)
- # That's not so bad because values between 2^31 and 2^32-1 are reserved on
- # systemd-based systems anyway: https://systemd.io/UIDS-GIDS.html#summary
- -net.ipv4.ping_group_range = 0 2147483647
- # Fair Queue CoDel packet scheduler to fight bufferbloat
- net.core.default_qdisc = fq_codel
- # Enable hard and soft link protection
- fs.protected_hardlinks = 1
- fs.protected_symlinks = 1
|