From 61994097f2eb2a14811bfbf2f5e3b4c4449021d7 Mon Sep 17 00:00:00 2001 From: nbd Date: Sat, 30 Jun 2007 02:59:09 +0000 Subject: unify sysctl.conf, add extra netfilter options (#1996) git-svn-id: svn://svn.openwrt.org/openwrt/trunk@7784 3c298f89-4303-0410-b956-a3cf2f4a3e73 --- package/base-files/files/etc/sysctl.conf | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 package/base-files/files/etc/sysctl.conf (limited to 'package/base-files/files/etc/sysctl.conf') diff --git a/package/base-files/files/etc/sysctl.conf b/package/base-files/files/etc/sysctl.conf new file mode 100644 index 000000000..4ad2ab2c2 --- /dev/null +++ b/package/base-files/files/etc/sysctl.conf @@ -0,0 +1,13 @@ +kernel.panic=3 +net.ipv4.conf.default.arp_ignore=1 +net.ipv4.conf.all.arp_ignore=1 +net.ipv4.ip_forward=1 +net.ipv4.icmp_echo_ignore_broadcasts=1 +net.ipv4.icmp_ignore_bogus_error_responses=1 +net.ipv4.tcp_fin_timeout=30 +net.ipv4.tcp_keepalive_time=120 +net.ipv4.tcp_syncookies=1 +net.ipv4.tcp_timestamps=0 +net.ipv4.netfilter.ip_conntrack_tcp_timeout_established=3600 +net.ipv4.netfilter.ip_conntrack_udp_timeout=60 +net.ipv4.netfilter.ip_conntrack_udp_timeout_stream=180 -- cgit v1.2.3