linux内核防synflood

字体: | 打印

转贴:

前两天服务器给人搞了一把,查到这个配置,打开内核的syncookies 还是有用的

sysctl -a | grep syn 看到:

QUOTE:

net.ipv4.tcp_max_syn_backlog = 1024
net.ipv4.tcp_syncookies = 0
net.ipv4.tcp_synack_retries = 5
net.ipv4.tcp_syn_retries = 5
修改为:

QUOTE:

sysctl -w net.ipv4.tcp_max_syn_backlog=2048
sysctl -w net.ipv4.tcp_syncookies=1
sysctl -w net.ipv4.tcp_synack_retries=3
sysctl -w net.ipv4.tcp_syn_retries=3

我也来说两句 查看全部评论 相关评论

  • smallwl (2006-8-06 00:05:15)

    good