unify sysctl.conf, add extra netfilter options (#1996)