Commit Graph

16 Commits

Author SHA1 Message Date
K4YT3X
445f1e4791 edited/reformatted SSR comments; updated dates 2021-10-12 16:36:27 +00:00
IceCodeNew
2ead2cea26 Disable TCP slow start after idle
Signed-off-by: IceCodeNew <32576256+IceCodeNew@users.noreply.github.com>
2021-10-12 21:16:55 +08:00
K4YT3X
3ea204497d tweaked perf restrictions, disallowed IPv6 SRR and redirects 2021-06-07 22:03:11 +00:00
Samuel FORESTIER
9a3fd6cf9c Fixed variables processing order issue related to perf subsystem
> https://bbs.archlinux.org/viewtopic.php?id=248926
2021-06-07 08:21:17 +00:00
Samuel FORESTIER
4eba426270 added recommendations from ANSSI (perf subsystem + vm low addr mapping)
> https://www.ssi.gouv.fr/uploads/2016/01/linux_configuration-fr-v1.2.pdf#section.6.2
2021-06-06 14:12:51 +02:00
K4YT3X
5eecf56b0a added more descriptions for TCP timestamps 2020-10-29 10:44:10 -04:00
K4YT3X
fbe72f187d added comments for rp_filter (BCP38) 2020-10-21 23:37:04 -04:00
K4YT3X
7ec9bd7ef5 increased fs.inotify.max_user_watches to 524288 2020-10-19 17:31:10 -04:00
K4YT3X
f173c2cafc added note for inode-max 2020-10-07 17:39:07 -04:00
K4YT3X
d45547b9c5 further increased ip port range 2020-10-07 17:31:14 -04:00
K4YT3X
2f4267a8d9 increased kernel.pix_max and fs.file-max values according to theoretical limits on 64-bit systems 2020-10-07 17:29:29 -04:00
IceCodeNew
fcdee62224 It is better if two numbers have different parity
Refer: https://www.kernel.org/doc/Documentation/networking/ip-sysctl.txt
Signed-off-by: IceCodeNew <32576256+IceCodeNew@users.noreply.github.com>
2020-10-07 23:57:00 +08:00
K4YT3X
abb9f9fc22 version 1.1: added more security options and tweaks 2020-10-06 14:20:18 -04:00
K4YT3X
2f7ba697fc added more descriptions into the README file 2020-10-05 18:03:38 -04:00
K4YT3X
13fb9e964a added version number 1.0 2020-10-05 17:52:47 -04:00
K4YT3X
5062ebcc05 added the first version of sysctl.conf 2020-10-05 17:52:08 -04:00