<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Archives des Cyber - CoffeeBreak Info</title>
	<atom:link href="https://coffeebreak.en-images.info/tag/cyber/feed/" rel="self" type="application/rss+xml" />
	<link>https://coffeebreak.en-images.info/tag/cyber/</link>
	<description>Une petite pause :)</description>
	<lastBuildDate>Sat, 19 Mar 2022 11:18:17 +0000</lastBuildDate>
	<language>fr-FR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://coffeebreak.en-images.info/wp-content/uploads/2021/07/cropped-Tasse_Cafe-scaled-1-32x32.jpg</url>
	<title>Archives des Cyber - CoffeeBreak Info</title>
	<link>https://coffeebreak.en-images.info/tag/cyber/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>MODOP – Tuning Linux kernel parameters</title>
		<link>https://coffeebreak.en-images.info/modop-tuning-linux-kernel-parameters/</link>
					<comments>https://coffeebreak.en-images.info/modop-tuning-linux-kernel-parameters/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Sat, 19 Mar 2022 11:18:15 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Securité]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6171</guid>

					<description><![CDATA[<p>MODOP – Configurer ou « tuner » son noyau linux est un besoin qui peut être nécessaire pour un administrateur système et surtout des spécificités d’un client. Le service le plus souvent utilisé est « sysctl » disponible sur toutes les types de Linux du marché. Sysctl permet de modifier les paramètres du kernel stockés dans /proc/sys dynamiquement, et donc très rapidement applicable à vos serveurs et clients.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-tuning-linux-kernel-parameters/">MODOP – Tuning Linux kernel parameters</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2></h2>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>1°) Paramètres KERNEL</strong></span></span></h3>
<pre><em># arrêter les messages de bas niveau sur la console</em>
<em><span style="color: #ff0000;">kernel.printk = 4 4 1 7</span> </em>

<em>#Evite un panic KERNEL brute , Redémarre le Kernel aprs 10sec </em>
<em><span style="color: #ff0000;">kernel.panic = 10</span> </em>

<em># Désactive la journalisation de la Magic SysRq key </em>
<span style="color: #ff0000;"><em>kernel.sysrq = 0 </em></span>

<em># Allocation maximale (bytes) autorisée d'un segment de mémoire partagée pour le Kernel</em>
<em><span style="color: #ff0000;">kernel.shmmax = 4294967296</span> </em>

<em># Allocation minimale (bytes) d'un segment de mémoire partagée pour le Kernel</em>
<em><span style="color: #ff0000;">kernel.shmall = 4194304</span> </em>

<em># Fixe comme PID le plus haut pour le fichier coredump</em>
<em><span style="color: #ff0000;">kernel.core_uses_pid = 1</span> </em>

<em># Allocation maximale (octets) d'un seul fichier en standby</em>
<em><span style="color: #ff0000;">kernel.msgmnb = 65536</span> </em>

<em># Allocation maximale (octets) autorisée d'un seul fichier en standby</em>
<span style="color: #ff0000;"><em>kernel.msgmax = 65536</em></span></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img fetchpriority="high" decoding="async" width="846" height="236" class="wp-image-6172" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-76.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-76.png 846w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-76-300x84.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-76-768x214.png 768w" sizes="(max-width: 846px) 100vw, 846px" /></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">sysctl -p</span>
<em><span style="color: #ff0000;">kernel.printk = 4 4 1 7</span></em>
<em><span style="color: #ff0000;">kernel.panic = 10</span></em>
<em><span style="color: #ff0000;">kernel.sysrq = 0</span></em>
<em><span style="color: #ff0000;">kernel.shmmax = 4294967296</span></em>
<em><span style="color: #ff0000;">kernel.shmall = 4194304</span></em>
<em><span style="color: #ff0000;">kernel.core_uses_pid = 1</span></em>
<em><span style="color: #ff0000;">kernel.msgmnb = 65536</span></em>
<em><span style="color: #ff0000;">kernel.msgmax = 65536</span></em></pre>
<h3><span style="text-decoration: underline; color: #000000;">2°) Contrôle SWAP au niveau KERNEL</span></h3>
<pre><em># Limitation basse pour le swap géré au niveau Kernel</em>
<em><span style="color: #ff0000;">vm.swappiness = 20</span> </em>

<em># Allocation maximale absolue de mémoire système avant d'écrire des données sur le disque</em>
<em><span style="color: #ff0000;">vm.dirty_ratio = 80</span> </em>

<em># Pourcentage de mémoire système qui amène à écrire des données sur le disque</em>
<span style="color: #ff0000;"><em>vm.dirty_background_ratio = 5</em></span></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img decoding="async" width="819" height="137" class="wp-image-6173" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-77.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-77.png 819w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-77-300x50.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-77-768x128.png 768w" sizes="(max-width: 819px) 100vw, 819px" /></pre>
<pre>[root@vps-e7276df3 chris]#<span style="color: #ff0000;"> sysctl -p</span>
<span style="color: #ff0000;"><em>vm.swappiness = 20</em></span>
<span style="color: #ff0000;"><em>vm.dirty_ratio = 80</em></span>
<span style="color: #ff0000;"><em>vm.dirty_background_ratio = 5</em></span></pre>
<h3><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">3°) Contrôle Fichier au niveau KERNEL</span></span></h3>
<pre><em># Limitation de fichier ouverts sous linux </em>
<em><span style="color: #ff0000;">fs.file-max = 2097152</span> </em></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img decoding="async" width="410" height="61" class="wp-image-6174" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-78.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-78.png 410w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-78-300x45.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-78-400x61.png 400w" sizes="(max-width: 410px) 100vw, 410px" /></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">sysctl -p</span>
<span style="color: #ff0000;"><em>fs.file-max = 2097152</em></span></pre>
<h3><span style="text-decoration: underline; color: #000000;">4°) Paramètres Socket Network au niveau KERNEL</span></h3>
<pre><em># Nombre maximum de paquets reçu par l'interface réseau </em>
<em><span style="color: #ff0000;">net.core.netdev_max_backlog = 262144</span> </em>

<em>#Tampon de réception de socket par défaut </em>
<em><span style="color: #ff0000;">net.core.rmem_default = 31457280</span> </em>

<em># Tampon de réception de socket maximal </em>
<em><span style="color: #ff0000;">net.core.rmem_max = 67108864</span> </em>

<em># Tampon d'envoi de socket par défaut </em>
<span style="color: #ff0000;"><em>net.core.wmem_default = 31457280 </em></span>

<em># Tampon d'envoi de socket maximal </em>
<em><span style="color: #ff0000;">net.core.wmem_max = 67108864</span> </em>

<em># Modifier le nombre de connexions entrantes </em>
<em><span style="color: #ff0000;">net.core.somaxconn = 65535</span> </em>

<em># Augmenter la quantité maximale de mémoire tampon </em>
<span style="color: #ff0000;"><em>net.core.optmem_max = 25165824</em></span></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img loading="lazy" decoding="async" width="866" height="246" class="wp-image-6175" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-79.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-79.png 866w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-79-300x85.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-79-768x218.png 768w" sizes="auto, (max-width: 866px) 100vw, 866px" /></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">sysctl -p</span>
<span style="color: #ff0000;"><em>net.core.netdev_max_backlog = 262144</em></span>
<span style="color: #ff0000;"><em>net.core.rmem_default = 31457280</em></span>
<span style="color: #ff0000;"><em>net.core.rmem_max = 67108864</em></span>
<span style="color: #ff0000;"><em>net.core.wmem_default = 31457280</em></span>
<span style="color: #ff0000;"><em>net.core.wmem_max = 67108864</em></span>
<span style="color: #ff0000;"><em>net.core.somaxconn = 65535</em></span>
<span style="color: #ff0000;"><em>net.core.optmem_max = 25165824</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_timestamps = 0</em></span></pre>
<h3><span style="text-decoration: underline; color: #000000;"><strong>5°) Paramètres ARP Network au niveau KERNEL</strong></span></h3>
<pre><em># taille du cache ARP interne du noyau</em>
<span style="color: #ff0000;"><em>net.ipv4.neigh.default.gc_thresh1 = 4096 </em></span>
<span style="color: #ff0000;"><em>net.ipv4.neigh.default.gc_thresh2 = 8192 </em></span>
<em><span style="color: #ff0000;">net.ipv4.neigh.default.gc_thresh3 = 16384</span> </em>

<em># Fréquence avec laquelle on vérifie les entrées ARP valides</em>
<em><span style="color: #ff0000;">net.ipv4.neigh.default.gc_interval = 5</span> </em>

<em>#Fréquence de vérification des entrées ARP périmées</em>
<span style="color: #ff0000;"><em>net.ipv4.neigh.default.gc_stale_time = 120</em></span></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img loading="lazy" decoding="async" width="655" height="165" class="wp-image-6176" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-80.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-80.png 655w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-80-300x76.png 300w" sizes="auto, (max-width: 655px) 100vw, 655px" /></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">sysctl -p</span>
<span style="color: #ff0000;"><em>net.ipv4.neigh.default.gc_thresh1 = 4096</em></span>
<span style="color: #ff0000;"><em>net.ipv4.neigh.default.gc_thresh2 = 8192</em></span>
<span style="color: #ff0000;"><em>net.ipv4.neigh.default.gc_thresh3 = 16384</em></span>
<span style="color: #ff0000;"><em>net.ipv4.neigh.default.gc_interval = 5</em></span>
<span style="color: #ff0000;"><em>net.ipv4.neigh.default.gc_stale_time = 120</em></span></pre>
<h3><span style="text-decoration: underline; color: #000000;"><strong>6°) Paramètres des messages Network au niveau KERNEL</strong></span></h3>
<pre><em>#Nombre maximal d'entrées de connexion autorisées</em>
<em><span style="color: #ff0000;">net.netfilter.nf_conntrack_max = 10000000</span> </em>

<em># désactivons la récupération des connexions</em>
<em><span style="color: #ff0000;">net.netfilter.nf_conntrack_tcp_loose = 0</span> </em>

<em># Délai (seconde) d'expiration de la connexion établie</em>
<em><span style="color: #ff0000;">net.netfilter.nf_conntrack_tcp_timeout_established = 1800</span> </em>

<em># Délai (seconde)d'expiration pour une requête</em>
<em><span style="color: #ff0000;">net.netfilter.nf_conntrack_tcp_timeout_close = 10</span> </em>

<em># Délai (seconde) d'attente avant l'expiration pour une requête</em>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_timeout_close_wait = 10</em></span>

<em># Délai (seconde) de fin d'attente pour une requête</em>
<em><span style="color: #ff0000;">net.netfilter.nf_conntrack_tcp_timeout_fin_wait = 20</span> </em>

<em># Délai (seconde) d'attente du dernier message</em>
<em><span style="color: #ff0000;">net.netfilter.nf_conntrack_tcp_timeout_last_ack = 20</span> </em>

<em># Délai (seconde) d'attente synchro réception d'un message</em>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_timeout_syn_recv = 20 </em></span>

<em># Délai (seconde) d'attente synchro envoi d'un message</em>
<em><span style="color: #ff0000;">net.netfilter.nf_conntrack_tcp_timeout_syn_sent = 20</span> </em>

<em># Délai (seconde) d'attente pour la fin d'un message</em>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_timeout_time_wait = 10</em></span></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img loading="lazy" decoding="async" width="775" height="344" class="wp-image-6177" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-81.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-81.png 775w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-81-300x133.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-81-768x341.png 768w" sizes="auto, (max-width: 775px) 100vw, 775px" /></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">sysctl -p</span>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_max = 10000000</em></span>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_loose = 0</em></span>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_timeout_established = 1800</em></span>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_timeout_close = 10</em></span>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_timeout_close_wait = 10</em></span>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_timeout_fin_wait = 20</em></span>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_timeout_last_ack = 20</em></span>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_timeout_syn_recv = 20</em></span>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_timeout_syn_sent = 20</em></span>
<span style="color: #ff0000;"><em>net.netfilter.nf_conntrack_tcp_timeout_time_wait = 10</em></span></pre>
<h3><span style="color: #000000;"><strong><span style="text-decoration: underline;">7°) Paramètres IPv4 Network au niveau KERNEL</span></strong></span></h3>
<pre><em>#définit le port min/max d'une connexion réseau utilisable comme port source</em>
<em><span style="color: #ff0000;">net.ipv4.ip_local_port_range = 1024 65000</span> </em>

<em># Désactivation de la fragmentation d'un message/packet IPv4</em>
<span style="color: #ff0000;"><em>net.ipv4.ip_no_pmtu_disc = 1</em></span></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img loading="lazy" decoding="async" width="738" height="80" class="wp-image-6178" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-82.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-82.png 738w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-82-300x33.png 300w" sizes="auto, (max-width: 738px) 100vw, 738px" /></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">sysctl -p</span>
<span style="color: #ff0000;"><em>net.ipv4.ip_local_port_range = 1024 65000</em></span>
<span style="color: #ff0000;"><em>net.ipv4.ip_no_pmtu_disc = 1</em></span></pre>
<p><strong>Partie Routage </strong></p>
<pre><em># Désactivation du routage IP IPv4</em>
<em><span style="color: #ff0000;">net.ipv4.ip_forward = 0</span> </em>

<em># Désactivation updates table de routage </em>
<em><span style="color: #ff0000;">net.ipv4.route.flush = 1</span> </em>

<em># Nombre maximum d'entrées dans le cache Route</em>
<em><span style="color: #ff0000;">net.ipv4.route.max_size = 8048576</span> </em></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img loading="lazy" decoding="async" width="592" height="118" class="wp-image-6179" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-83.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-83.png 592w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-83-300x60.png 300w" sizes="auto, (max-width: 592px) 100vw, 592px" /></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">sysctl -p</span>
<span style="color: #ff0000;"><em>net.ipv4.ip_forward = 0</em></span>
<span style="color: #ff0000;"><em>net.ipv4.route.flush = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.route.max_size = 8048576</em></span></pre>
<p><strong>Partie ICMP </strong></p>
<pre><em># Activer l'ignorance des requêtes ICMP </em>
<span style="color: #ff0000;"><em>net.ipv4.icmp_echo_ignore_all = 1</em></span>

<em># Activer l'ignorance des requêtes Brodcoast</em>
<em><span style="color: #ff0000;">net.ipv4.icmp_echo_ignore_broadcasts = 1</span> </em>

<em>#Activer le rejet des trames non RFC</em>
<span style="color: #ff0000;"><em>net.ipv4.icmp_ignore_bogus_error_responses = 1 </em></span></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img loading="lazy" decoding="async" width="515" height="120" class="wp-image-6180" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-84.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-84.png 515w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-84-300x70.png 300w" sizes="auto, (max-width: 515px) 100vw, 515px" /></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">sysctl -p</span>
<span style="color: #ff0000;"><em>net.ipv4.icmp_echo_ignore_all = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.icmp_echo_ignore_broadcasts = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.icmp_ignore_bogus_error_responses = 1</em></span></pre>
<p><strong>Partie TCP</strong></p>
<pre><em># Désactiver le démarrage lent TCP</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_slow_start_after_idle = 0</span> </em>

<em># Définir Algo du contrôle de gestion TCP</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_congestion_control = htcp</span> </em>

<em># Allocation total du buffer maximum allouable TCP</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_mem = 65536 131072 262144</span> </em>

<em># Allocation total du buffer en lecture maximum allouable TCP</em>
<span style="color: #ff0000;"><em>net.ipv4.tcp_rmem = 4096 87380 33554432</em></span>

<em># Allocation total du buffer en écriture maximum allouable TCP</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_wmem = 4096 87380 33554432</span> </em>

<em># Allocation du pool de buckets tcp-time-wait (attaques DOS simples)</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_max_tw_buckets = 1440000</span> </em>

<em># Activer les SOCKET time_wait Recycle</em>
<span style="color: #ff0000;"><em>net.ipv4.tcp_tw_recycle = 1</em></span>

<em># Activer les SOCKET time_wait REUSE</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_tw_reuse = 1</span> </em>

<em># Nombre maximal de sockets TCP pour les HANDLE</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_max_orphans = 400000</span> </em>

<em># Activer window scaling défini par la norme RFC1323.</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_window_scaling = 1</span> </em>

<em># Activer le contrôle de la pile TCP</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_rfc1337 = 1</span> </em>

<em># Activer la protection des cookies TCP SYN </em>
<em><span style="color: #ff0000;">net.ipv4.tcp_syncookies = 1</span> </em>

<em># Nombre de SYNACK pour une tentative de connexion TCP</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_synack_retries = 1</span> </em>

<em># Nombre de SYN pour une tentative de connexion TCP</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_syn_retries = 2</span> </em>

<em># Nombre max de demandes de connexion mémorisées sans accusé de réception du client </em>
<em><span style="color: #ff0000;">net.ipv4.tcp_max_syn_backlog = 16384</span> </em>

<em># Activation de timestamps</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_timestamps = 1</span> </em>

<em># Activation acknowledgments (SACKS)</em>
<span style="color: #ff0000;"><em>net.ipv4.tcp_sack = 1 </em></span>
<em><span style="color: #ff0000;">#net.ipv4.tcp_fack = 1</span> </em>

<em># Activation ECN lors de connexion entrante</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_ecn = 2</span> </em>

<em># Durée de timeout des connexions orphelines </em>
<em><span style="color: #ff0000;">net.ipv4.tcp_fin_timeout = 10</span> </em>

<em># Fréquence d'envoi des message KEEPALIVE </em>
<span style="color: #ff0000;"><em>net.ipv4.tcp_keepalive_time = 600 </em></span>

<em># Temps à laquelle les connexions sont KILL sans réponse</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_keepalive_intvl = 60</span> </em>

<em># Nombres de sondes keepalive TCP envoyé avant de KILL les connexions sans réponse</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_keepalive_probes = 10</span> </em>

<em># Active l'enregistrement des metrics TCP dans le cache route</em>
<em><span style="color: #ff0000;">net.ipv4.tcp_no_metrics_save = 1</span> </em></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img loading="lazy" decoding="async" width="1012" height="730" class="wp-image-6181" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-85.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-85.png 1012w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-85-300x216.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-85-768x554.png 768w" sizes="auto, (max-width: 1012px) 100vw, 1012px" /></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">sysctl -p</span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_slow_start_after_idle = 0</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_congestion_control = htcp</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_mem = 65536 131072 262144</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_rmem = 4096 87380 33554432</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_wmem = 4096 87380 33554432</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_max_tw_buckets = 1440000</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_tw_recycle = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_tw_reuse = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_max_orphans = 400000</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_window_scaling = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_rfc1337 = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_syncookies = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_synack_retries = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_syn_retries = 2</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_max_syn_backlog = 16384</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_timestamps = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_sack = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_ecn = 2</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_fin_timeout = 10</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_keepalive_time = 600</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_keepalive_intvl = 60</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_keepalive_probes = 10</em></span>
<span style="color: #ff0000;"><em>net.ipv4.tcp_no_metrics_save = 1</em></span></pre>
<p><strong>Partie UDP</strong></p>
<pre><em># Allocation total du buffer maximum allouable UDP</em>
<em><span style="color: #ff0000;">net.ipv4.udp_mem = 65536 131072 262144</span> </em>

<em># Allocation total du buffer en lecture maximum allouable UDP</em>
<span style="color: #ff0000;"><em>net.ipv4.udp_rmem_min = 16384</em></span>

<em># Allocation total du buffer en écriture maximum allouable UDP</em>
<em><span style="color: #ff0000;">net.ipv4.udp_wmem_min = 16384</span> </em></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img loading="lazy" decoding="async" width="644" height="119" class="wp-image-6182" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-86.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-86.png 644w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-86-300x55.png 300w" sizes="auto, (max-width: 644px) 100vw, 644px" /></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">sysctl -p</span>
<span style="color: #ff0000;"><em>net.ipv4.udp_mem = 65536 131072 262144</em></span>
<span style="color: #ff0000;"><em>net.ipv4.udp_rmem_min = 16384</em></span>
<span style="color: #ff0000;"><em>net.ipv4.udp_wmem_min = 16384</em></span></pre>
<p><strong><em>Partie Divers</em></strong></p>
<pre><em># Désactiver l'acceptation de la redirection des packets sur toutes les interfaces </em>
<em><span style="color: #ff0000;">net.ipv4.conf.all.send_redirects = 0</span> </em>

<em># Désactiver le routage source IP </em>
<em><span style="color: #ff0000;">net.ipv4.conf.all.accept_source_route = 0</span> </em>

<em># Activer la protection contre l'usurpation d'adresse IP</em>
<span style="color: #ff0000;"><em>net.ipv4.conf.all.rp_filter = 1</em></span>

<em># Activer la journalisation des paquets falsifiés, des paquets routés à la source et des paquets de redirection </em>
<span style="color: #ff0000;"><em>net.ipv4.conf.all.log_martians = 1</em></span>

<em># Désactiver l'acceptation de la redirection ICMP </em>
<span style="color: #ff0000;"><em>net.ipv4.conf.all.accept_redirects = 0</em></span></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">vi /etc/sysctl.conf</span>

<img loading="lazy" decoding="async" width="925" height="175" class="wp-image-6183" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-87.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-87.png 925w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-87-300x57.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-87-768x145.png 768w" sizes="auto, (max-width: 925px) 100vw, 925px" /></pre>
<pre>[root@vps-e7276df3 chris]# <span style="color: #ff0000;">sysctl -p</span>
<span style="color: #ff0000;"><em>net.ipv4.conf.all.send_redirects = 0</em></span>
<span style="color: #ff0000;"><em>net.ipv4.conf.all.accept_source_route = 0</em></span>
<span style="color: #ff0000;"><em>net.ipv4.conf.all.rp_filter = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.conf.all.log_martians = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv4.conf.all.accept_redirects = 0</em></span></pre>
<p>Views: 8</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-tuning-linux-kernel-parameters/">MODOP – Tuning Linux kernel parameters</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-tuning-linux-kernel-parameters/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
