2010年9月24日

Improve DDOS, TIME_WAIT and CLOSE_WAIT issue

net.ipv4.tcp_fin_timeout=30
net.ipv4.tcp_keepalive_time=120
net.ipv4.tcp_timestamps=0
net.ipv4.tcp_tw_reuse=1
net.ipv4.tcp_tw_recycle=1
net.ipv4.tcp_keepalive_intvl=15
net.ipv4.tcp_keepalive_probes=5
net.ipv4.tcp_synack_retries=3
net.ipv4.tcp_syn_retries=3
net.ipv4.tcp_max_syn_backlog=2048
net.ipv4.ip_local_port_range=5000 65000

Query status:
netstat -nat|awk '{print awk $NF}'|sort|uniq -c|sort -n

0 意見: