From: Felix Fietkau Date: Sat, 30 Jun 2007 02:59:09 +0000 (+0000) Subject: unify sysctl.conf, add extra netfilter options (#1996) X-Git-Tag: reboot~28803 X-Git-Url: http://git.openwrt.org/?p=openwrt%2Fopenwrt.git;a=commitdiff_plain;h=9bf6078866b29e9dc89374c79cc750390e73f95c;ds=sidebyside unify sysctl.conf, add extra netfilter options (#1996) SVN-Revision: 7784 --- diff --git a/package/base-files/files/etc/sysctl.conf b/package/base-files/files/etc/sysctl.conf new file mode 100644 index 0000000000..4ad2ab2c2f --- /dev/null +++ b/package/base-files/files/etc/sysctl.conf @@ -0,0 +1,13 @@ +kernel.panic=3 +net.ipv4.conf.default.arp_ignore=1 +net.ipv4.conf.all.arp_ignore=1 +net.ipv4.ip_forward=1 +net.ipv4.icmp_echo_ignore_broadcasts=1 +net.ipv4.icmp_ignore_bogus_error_responses=1 +net.ipv4.tcp_fin_timeout=30 +net.ipv4.tcp_keepalive_time=120 +net.ipv4.tcp_syncookies=1 +net.ipv4.tcp_timestamps=0 +net.ipv4.netfilter.ip_conntrack_tcp_timeout_established=3600 +net.ipv4.netfilter.ip_conntrack_udp_timeout=60 +net.ipv4.netfilter.ip_conntrack_udp_timeout_stream=180 diff --git a/target/linux/generic-2.4/base-files/etc/sysctl.conf b/target/linux/generic-2.4/base-files/etc/sysctl.conf deleted file mode 100644 index e60038cf35..0000000000 --- a/target/linux/generic-2.4/base-files/etc/sysctl.conf +++ /dev/null @@ -1,12 +0,0 @@ -kernel.panic=3 -net.ipv4.conf.default.arp_ignore=1 -net.ipv4.conf.all.arp_ignore=1 -net.ipv4.ip_forward=1 -net.ipv4.icmp_echo_ignore_broadcasts=1 -net.ipv4.icmp_ignore_bogus_error_responses=1 -net.ipv4.tcp_fin_timeout=30 -net.ipv4.tcp_keepalive_time=120 -net.ipv4.tcp_syncookies=1 -net.ipv4.tcp_timestamps=0 -net.ipv4.ip_conntrack_tcp_timeouts="300 43200 120 60 120 120 10 60 30 120" -net.ipv4.ip_conntrack_udp_timeouts="60 180" diff --git a/target/linux/generic-2.6/base-files/etc/sysctl.conf b/target/linux/generic-2.6/base-files/etc/sysctl.conf deleted file mode 100644 index a05498cd6c..0000000000 --- a/target/linux/generic-2.6/base-files/etc/sysctl.conf +++ /dev/null @@ -1,10 +0,0 @@ -kernel.panic=3 -net.ipv4.conf.default.arp_ignore=1 -net.ipv4.conf.all.arp_ignore=1 -net.ipv4.ip_forward=1 -net.ipv4.icmp_echo_ignore_broadcasts=1 -net.ipv4.icmp_ignore_bogus_error_responses=1 -net.ipv4.tcp_fin_timeout=30 -net.ipv4.tcp_keepalive_time=120 -net.ipv4.tcp_syncookies=1 -net.ipv4.tcp_timestamps=0