13、內核參數優(yōu)化
說明:本優(yōu)化適合apache,nginx,squid多種等web應用,特殊的業(yè)務也可能需要略作調整。
1 [root@server ~]# vi /etc/sysctl.conf
2 #by sun in 20131001
3 net.ipv4.tcp_fin_timeout = 2
4 net.ipv4.tcp_tw_reuse = 1
5 net.ipv4.tcp_tw_recycle = 1
6 net.ipv4.tcp_syncookies = 1
7 net.ipv4.tcp_keepalive_time =600
8 net.ipv4.ip_local_port_range = 4000 65000
9 net.ipv4.tcp_max_syn_backlog = 16384
10 net.ipv4.tcp_max_tw_buckets = 36000
11 net.ipv4.route.gc_timeout = 100
12 net.ipv4.tcp_syn_retries = 1
13 net.ipv4.tcp_synack_retries = 1
14 net.core.somaxconn = 16384
15 net.core.netdev_max_backlog = 16384
16 net.ipv4.tcp_max_orphans = 16384
17 #一下參數是對iptables防火墻的優(yōu)化,防火墻不開會有提示,可以忽略不理。
18 net.ipv4.ip_conntrack_max = 25000000
19 net.ipv4.netfilter.ip_conntrack_max = 25000000
20 net.ipv4.netfilter.ip_conntrack_tcp_timeout_established = 180
21 net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait = 120
22 net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait = 60
23 net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait = 120
24 [root@localhost ~]# sysctl –p #使配置文件生效提示:由于CentOS6.X系統中的模塊名不是ip_conntrack,而是nf_conntrack,所以在/etc /sysctl.conf優(yōu)化時,需要把net.ipv4.netfilter.ip_conntrack_max 這種老的參數,改成net.netfilter.nf_conntrack_max這樣才可以。
即對防火墻的優(yōu)化,在5.8上是
1 net.ipv4.ip_conntrack_max = 25000000
2 net.ipv4.netfilter.ip_conntrack_max = 25000000
3 net.ipv4.netfilter.ip_conntrack_tcp_timeout_established = 180
4 net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait = 120
5 net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait = 60
6 net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait = 120
1 net.ipv4.tcp_syn_retries = 1
2 net.ipv4.tcp_synack_retries = 1
3 net.ipv4.tcp_keepalive_time = 600
4 net.ipv4.tcp_keepalive_probes = 3
5 net.ipv4.tcp_keepalive_intvl =15
6 net.ipv4.tcp_retries2 = 5
7 net.ipv4.tcp_fin_timeout = 2
8 net.ipv4.tcp_max_tw_buckets = 36000
9 net.ipv4.tcp_tw_recycle = 1
10 net.ipv4.tcp_tw_reuse = 1
11 net.ipv4.tcp_max_orphans = 32768
12 net.ipv4.tcp_syncookies = 1
13 net.ipv4.tcp_max_syn_backlog = 16384
14 net.ipv4.tcp_wmem = 8192 131072 16777216
15 net.ipv4.tcp_rmem = 32768 131072 16777216
16 net.ipv4.tcp_mem = 786432 1048576 1572864
17 net.ipv4.ip_local_port_range = 1024 65000
18 net.ipv4.ip_conntrack_max = 65536
19 net.ipv4.netfilter.ip_conntrack_max=65536
20 net.ipv4.netfilter.ip_conntrack_tcp_timeout_established=180
21 net.core.somaxconn = 16384
22 net.core.netdev_max_backlog = 16384另外,在此優(yōu)化過程中可能會有報錯:
1、5.8版本上
1 error: "net.ipv4.ip_conntrack_max"is an unknown key
2 error: "net.ipv4.netfilter.ip_conntrack_max"is an unknown key
3 error: "net.ipv4.netfilter.ip_conntrack_tcp_timeout_established"is an unknown key
4 error: "net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait"is an unknown key
5 error: "net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait"is an unknown key
6 error: "net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait"is an unknown key
2015職稱計算機考試書PowerPoint2007中 .. 定價:¥45 優(yōu)惠價:¥42 更多書籍 | |
2015年全國職稱計算機考試教材(2007模 .. 定價:¥225 優(yōu)惠價:¥213 更多書籍 |