/proc/sys/net/ipv4/* À» À§ÇÑ ¹®¼ kernel version 2.4.25
¹ø¿ª 2004.2.25 ±èÁ¤±Õ <http://oops.org>
* ¿ªÁÖ)
ÀÌ ÆäÀÌÁö¸¦ Àбâ Àü¿¡ ¾ÆÁÖ °·ÂÇÏ°Ô ÁÖÀǸ¦ ¿äÇÒ °ÍÀº sysctlÀ» ÀÌ¿ëÇÏ¿© ÀÌ °ªµéÀ»
º¯°æÇÒ °æ¿ì³ª Á÷Á¢ÀûÀ¸·Î º¯°æÀ» ÇÒ °æ¿ì ½Ã½ºÅÛÀÌ crash µÇ¾îÁú À§Çè¿ä¼Ò°¡ ¸¹ÀÌ ÀÖ
´Ù´Â °ÍÀ» ¸í½ÉÇØ ¾ß ÇÑ´Ù. Áï, ÀÚ±âÀÇ ½Ã½ºÅÛ¿¡ ¹«¸®ÇÑ °ªÀ» ³Ö¾úÀ» °æ¿ì ±× Áï½Ã ½Ã
½ºÅÛÀÌ ¸ØÃâ¼öµµ Àֱ⠶§¹®¿¡ ÃæºÐÇÑ Å×½ºÆ®¿Í ½Ã½ºÅÛÀÌ crash°¡ µÉ ¼ö ÀÖÀ½À» ¸í½ÉÇÏ
°í Ã¥ÀÓÀ» Áú¼ö ÀÖÀ» °æ¿ì¿¡¸¸ ¸¸Áö±â¸¦ ±ÇÀåÇÑ´Ù.
* ÂüÁ¶)
http://kldp.org/KoreanDoc/html/Kernel-KLDP/network.html
ip_forward - 01 ¿¬»ê
0 - »ç¿ë¾ÈÇÔ (±âº»°ª)
0 ÀÌ ¾Æ´Ò °æ¿ì - »ç¿ëÇÔ
interface µé »çÀÌ¿¡ ÆÐŶµéÀ» ±³È¯½ÃŰ´Â °ÍÀ» Çã¶ô.
ÀÌ º¯¼öÀÇ º¯°æÀº ±âº»ÀûÀÎ »óÅ·Π¸ðµç ¼³Á¤ ÆÄ¶ó¹ÌÅ͵éÀ» ¸®¼Â ½ÃŲ´Ù.
(RFC1122 for hosts, RFC1812 for routers)
ip_default_ttl - Á¤¼ö
±âº»°ª: 64
TTL (Time To Live) Àº IP ÆÐŶ ¾È¿¡ µé¾îÀÖ´Â (´ë°³ 0ºÎÅÍ 255 »çÀÌ) Á¤¼ö°ª
À¸·Î TTL À̶ó´Â ¸» ±×´ë·Î ÆÐŶÀÇ ¼ö¸íÀ» Ä«¿îÆ®ÇÑ´Ù. ¶ó¿ìÅÍ Çϳª¸¦ Áö³¯¶§
¸¶´Ù Ãʱ⠰ª¿¡¼ 1 (ȤÀº ±× ÀÌ»ó)À» »©´Âµ¥ °ªÀÌ 0 ÀÌ µÇ¸é ¶ó¿ìÅÍ´Â ±× ÆÐ
Ŷ À» ¹ö¸®°í ÀçÀü¼ÛÀ» ¿äûÇÏ´Â ICMP ¸Þ½ÃÁö¸¦ ¹ß½ÅÁö È£½ºÆ®¿¡ º¸³½´Ù. ¸®
´ª½º´Â ±× °ªÀÌ 255 À̳ª À©µµ¿ì 95 ³ª 98 ÀÇ TTL ±âº» °ªÀº 32 È©À¸·Î, ¿î¿µ
üÁ¦¸¶´Ù ´Ù¸¦ ¼ö ÀÖ´Ù.
ping °ú traceroute À¯Æ¿¸®Æ¼´Â TTL °ªÀ» »ç¿ëÇÏ´Â ´ëÇ¥ÀûÀÎ ÇÁ·Î±×·¥Àε¥ »ç
¿ëÀÚ°¡ TTL °ªÀ» Á¶Á¤ÇÒ ¼ö ÀÖÀ¸¸ç traceroute ´Â TTL ±âº»°ªÀ» 30 À¸·Î ³·Ãß
¾î ÆÐŶÀ» Àü¼ÛÇÑ´Ù.
¸ÖƼij½ºÆÃ¿¡¼´Â TTL °ªÀÌ ÆÐŶÀÌ Àü´ÞµÇ¾î¾ß ÇÏ´Â ¹üÀ§³ª ±¸¿ªÀ» °¡¸®Å²´Ù.
0 Àº °°Àº È£½ºÆ®·Î Á¦ÇѵȴÙ.
1 Àº °°Àº ¼ºê³ÝÀ¸·Î Á¦ÇѵȴÙ.
32 ´Â °°Àº »çÀÌÆ®·Î Á¦ÇѵȴÙ.
64 ´Â °°Àº Áö¿ªÀ¸·Î Á¦ÇѵȴÙ.
128 Àº °°Àº ´ë·úÀ¸·Î Á¦ÇѵȴÙ.
ip_no_pmtu_disc - 01 ¿¬»ê
MTU discorery °æ·Î¸¦ »ç¿ë¾ÈÇÔ
±âº»°ª FALSE (»ç¿ëÇÔÀ» ÀǹÌ)
MTU (Maximum Transmission Unit) ´Â ÇÁ·¹ÀÓÀ̳ª ÆÐŶÀÌ Çѹø¿¡ Çϳª ¾¿ Àü¼Û
µÉ ¶§ Åë°úÇÒ ¼ö ÀÖ´Â Å©±â·Î ÇÁ·ÎÅäÄݸ¶´Ù ±× Å©±â°¡ ´Ù¸£´Ù. ¿¹¸¦µé¾î ÀÌ´õ
³Ý¿¡¼´Â 1500 ÀÌÁö¸¸, X.25 ¿¡¼´Â 576 ÀÌ´Ù. Path MTU ´Â µÎ È£½ºÆ®»çÀÌ °æ
·Î (path) ¿¡¼ °¡Àå ÀÛÀº MTU °ªÀÌ´Ù.
È£½ºÆ®°¡ °°´õ¶óµµ ¶ó¿ìÆÃ °æ·Î³ª ÇÁ·ÎÅäÄÝÀº ¸Å¹ø ¹Ù²î¹Ç·Î, MTU °ªµµ °è¼Ó
´Þ¶óÁö°Ô µÈ´Ù. ÇöÀç ÆÐŶº¸´Ù ÀÛÀº MTU °ªÀ» °¡Áø ¶ó¿ìÅ͸¦ Åë°úÇÒ ¶§, ÆÐŶ
Àº ±× ¶ó¿ìÅÍ MTU ¿¡ ¸ÂÃç Àß°Ô Âɰ³Áø´Ù. ¼ö½ÅÇϴ ȣ½ºÆ®¿¡¼´Â ±×·¸°Ô ÂÉ
°³Áø Á¶°¢µéÀ» ¸ðµÎ ¹Þ¾Æ¼ ´Ù½Ã ÀçÁ¶¸³Çϴµ¥, ±× °¡¿îµ¥ ÇÑÁ¶°¢ÀÌ¶óµµ µå·Ó
µÇ¸é ¸ðµç Á¶°¢À» ´Ù½Ã Àü¼Û¹Þ¾Æ¾ß ÇÑ´Ù. ÀÌ °æ¿ì, ¶ó¿ìÅÍ´Â Á¶°¢À» ³ª´©´À¶ó
¹Ù»Ú°í, È£½ºÆ®´Â ÀçÁ¶¸³ÇÏ´À¶ó ¹ÙºüÁö¸ç, ÀçÀü¼ÛÀÌ ¸¹¾ÆÁö´Â µî ÆÛÆ÷¸Õ½º¸¦
¶³¾îÆ®¸®°Ô µÈ´Ù.
ÀÌ·² ¶§ pmtu discovery ¸¦ »ç¿ëÇÑ´Ù. ¸ÕÀú ÆÐŶ ¹ß¼Û ½Ã, Çì´õ¿¡ DF (Don't
Fragment) ºñÆ®¸¦ ¼³Á¤Çؼ Á¶°¢³»Áö ¸»¶ó°í ¾Ë¸°´Ù. DF ºñÆ®°¡ ¼³Á¤µÈ ÆÐŶ
À» ¹ÞÀº ¶ó¿ìÅÍ´Â ÀÚ½ÅÀÇ MTU º¸´Ù Å« °æ¿ì Á¶°¢ÈÇÏ´Â ´ë½Å, Can't Fragment
¿¡·¯¿Í MTU °ªÀ» µ¹·Áº¸³½´Ù. ±× °ªÀ» µ¹·Á¹Þ´Â È£½ºÆ®°¡ ¶ó¿ìÅÍÀÇ MTU °ª¿¡
¸ÂÃß¾î ÆÐŶÀ» ´Ù½Ã Àü¼ÛÇÑ´Ù. Á¶°¢³ª´Â °ÍÀ» ÇÇÇϸé¼, °¡Àå Å« ÆÐŶÀ» º¸³»
±â À§ÇØ pmtu discovery¸¦ »ç¿ëÇÏ´Â °ÍÀÌ´Ù.
´Ü, ÀÌ ±â´ÉÀ» »ç¿ëÇϱâ À§Çؼ´Â ICMP ¸Þ½ÃÁö ŸÀÔ 3 °¡¿îµ¥ code 4
(Fragmentation Needed and Don't fragment)¸¦ Çã¿ëÇØ¾ßÇÑ´Ù.
IP Fragmentation:
ipfrag_high_thresh - Á¤¼ö
Maximum memory ´Â IP Á¶°¢µéÀ» ÀçÁ¶ÇÕÀ» ÇÑ´Ù. ¸Þ¸ð¸®ÀÇ ipfrag_high_thresh
byte°¡ À̰á°ú¸¦ ÅëÇØ ÀçÇÒ´ç µÈ´Ù¸é, fragment handler´Â ipfrag_low_thresh
°¡ µµ´ÞÇϱâ Àü¿¡ ÆÐŶµéÀ» Àü´ÞÀ» ÇÒ°ÍÀÌ´Ù.
ipfrag_low_thresh - Á¤¼ö
ipfrag_high_thresh ¸¦ Âü°íÇ϶ó
ipfrag_time - Á¤¼ö
¸Þ¸ð¸®¿¡¼ IP fragment ¸¦ À¯ÁöÇÏ´Â ½Ã°£ (ÃÊ´ÜÀ§)
INET peer storage:
inet_peer_threshold - Á¤¼ö
½ºÅ丮ÁöÀÇ ´ë·«ÀûÀÎ Å©±âÀÌ´Ù. ÀÌ threshold¸ñ·Ïµé·Î ºÎÅÍ ½ÃÀÛÇÏ´Â °ÍÀº ħ
ÀÔÀÇ ¿ä¼Ò¸¦ ¾È°Ô µÉ °ÍÀÌ´Ù. ÀÌ threshold ´Â garbage collection passes »ç
ÀÌ¿¡¼ ¸ñ·ÏµéÀÇ time-to-live ¿Í time intervals¸¦ ÇÑÁ¤À» ÇÑ´Ù. ¶Ç ´Ù¸¥ Á¤
º¸¸¦ ¾ò°í ½Í´Ù¸é less time-to-live ³ª less GC interval À» Ç϶ó.
inet_peer_minttl - Á¤¼ö
Minimum time-to-live of entries. Should be enough to cover fragment
time-to-live on the reassembling side. This minimum time-to-live is
guaranteed if the pool size is less than inet_peer_threshold.
Measured in jiffies.
inet_peer_maxttl - Á¤¼ö
Maximum time-to-live of entries. Unused entries will expire after
this period of time if there is no memory pressure on the pool (i.e.
when the number of entries in the pool is very small).
Measured in jiffies.
inet_peer_gc_mintime - Á¤¼ö
Minimum interval between garbage collection passes. This interval is
in effect under high memory pressure on the pool.
Measured in jiffies.
inet_peer_gc_maxtime - Á¤¼ö
Minimum interval between garbage collection passes. This interval is
in effect under low (or absent) memory pressure on the pool.
Measured in jiffies.
TCP variables:
tcp_syn_retries - Á¤¼ö
Ȱ¼ºÈµÈ TCP Á¢¼ÓÀÌ ÀçÀü¼ÛÀ» ½ÃµµÇÏ°Ô Çϱâ À§ÇÑ ÃÖÃÊ SYN½Ã°£ÀÇ °ªÀ» Á¤ÇÑ
´Ù. 255 º¸´Ù ³ô¾Æ¼´Â ¾ÈµÈ´Ù. ±âº»°ªÀº 5À̸ç, 180 ÃÊ¿¡ ´ëÀÀÀÌ µÈ´Ù.
tcp_synack_retries - Á¤¼ö
passive TCP Á¢¼Ó ½Ãµµ°¡ ÀçÁ¢¼ÓÀ» Çϱâ À§ÇÑ SYNACKsÀÇ °ªÀ» Á¤ÇÑ´Ù. 255 º¸
´Ù ³ô°Ô ÁöÁ¤ÇÒ ¼ö ¾ø´Ù. ±âº»°ªÀº 5À̸ç, 180ÃÊ¿¡ ´ëÀÀÀÌ µÈ´Ù.
tcp_keepalive_time - Á¤¼ö
keepalive °¡ Ȱ¼ºµÇ µÇ¾î ÀÖÀ» °æ¿ì ¾ó¸¶³ª ÀÚÁÖ TCP °¡ keepalive ¸Þ¼¼Áö¸¦
º¸³»°Ô ÇÒ °ÍÀÎÁö¸¦ ¼³Á¤. ±âº»°ªÀº 2½Ã°£ ÀÌ´Ù.
KEEPALIVE ½Ã°£À» ÁÙÀÌ¸é ºñÁ¤»óÀûÀ¸·Î stable µÈ Á¢¼ÓÀ» ÇØÁ¦ÇÏ´Â ½Ã°£À» ÁÙ
Àϼö ÀÖÀ½.
tcp_keepalive_probes - Á¤¼ö
Á¢¼ÓÀÌ ²÷¾îÁö´Â °ÍÀ» °áÁ¤Çϱâ Àü±îÁö keepalive °¡ TCP send out À» ¾ó¸¶³ª
»ìÇÇ°Ô ÇÒÁö ÁöÁ¤ÇÑ´Ù. ±âº»°ªÀº 9 ÀÌ´Ù.
tcp_keepalive_intvl - Á¤¼ö
¾ó¸¶³ª ÀÚÁÖ send out À» üũÇÒÁö¸¦ Á¤ÇÑ´Ù. tcp_keepalive_probes ¿¡ ÀÇÇØ
Áõ°¡µÇ¾îÁø probes ´Â probes °¡ ½ÃÀÛµÈ ÈÄ¿¡´Â responding connection À» Á×
Àϼö ¾ø´Ù. ±âº»°ªÀº 75ÃÊ ÀÌ´Ù. ±âº» °ªÀÇ »ç¿ë½Ã 11ºÐ 15ÃÊ ÈÄ¿¡ ¿¬°áÀÌ ÇØ
Á¦µÈ °ÍÀ¸·Î °£ÁÖ µÈ´Ù.
tcp_retries1 - Á¤¼ö
¹«¾ð°¡ À߸øµÇ¾úÀ» °æ¿ì, network layer ·Î ÀÌ Çö»óÀ» reporting ÇϱâÀü ´Ù½Ã
È®ÀÎÀ» Çϱâ À§ÇÑ È½¼ö¸¦ ÁöÁ¤ÇÑ´Ù. ÃÖ¼Ò RPC °ªÀº 3 À̸ç, ÀÌ´Â RTO»ó¿¡¼ 3
ÃÊ¿¡¼ 8ºÐ »çÀÌ¿¡ ÀÀ´äÀ» Çϵµ·Ï ÇÏ´Â °ÍÀÌ ±âº»°ªÀÌ´Ù.
tcp_retries2 - Á¤¼ö
»ì¾ÆÀÖ´Â TCP ¿¬°áÀ» ²÷±â Àü¿¡ È®ÀÎÇϴ Ƚ¼ö¸¦ Á¤ÇÑ´Ù. RFC1122 ´Â 100Ãʺ¸
´Ù ±æ°Ô Á¦ÇÑÇ϶ó ÇÏÁö¸¸ ³Ê¹« ÀÛÀº °ªÀÌ´Ù. ±âº»°ªÀº 15·Î RTO 13-30ºÐ¿¡ ÇØ
´çÇÑ´Ù.
tcp_orphan_retries - Á¤¼ö
¿ì¸® ÂÊ¿¡¼ ´ÝÀº TCP ¿¬°áÀ» ²÷±â Àü¿¡ È®ÀÎÇϴ Ƚ¼ö¸¦ Á¤ÇÑ´Ù. ±âº»°ªÀº 7
·Î RTO 50 ÃÊ¿¡¼ 16 ºÐ »çÀÌ¿¡ ÇØ´çÇÑ´Ù. À¥ ¼¹ö°¡ ¿î¿µ Áß À̶ó¸é ÀÌ °ªÀ»
ÁÙ¿©¼ ¼ÒÄÏ µîÀÌ ±ÍÇÑ ¸®¼Ò½º¸¦ ¼ÒºñÇÏÁö ¾Êµµ·Ï ÇÒ ¼öµµ ÀÖ´Ù.
tcp_fin_timeout - Á¤¼ö
¼¹ö¿¡ ÀÇÇØ ´ÝÇôÁú¶§ FIN_WAIT-2 »óÅÂÀÇ ¼ÒÄÏÀ» À¯Áö ½Ãų ½Ã°£À» ÁöÁ¤ÇÑ´Ù.
peer´Â ÆÄ±«µÉ¼ö ÀÖÁö¸¸ °áÄÚ ½º½º·Î ´ÝÁö´Â ¾Ê°Å³ª, ¿¡»óÄ¡ ¸øÇÏ°Ô Á×À»¼ö´Â
ÀÖ´Ù. ±âº»°ª 60ÃÊ ÀÌ´Ù. º¸Åë Ä¿³Î 2.2 ¿¡¼´Â 180 Ãʸ¦ »ç¿ë ÇÏÁö¸¸ ¼öÁ¤À»
ÇÒ¼ö´Â ÀÖ´Ù. ÇÏÁö¸¸ ½Ã½ºÅÛÀÌ À¥¼¹öÀÇ ¿ëµµ¶ó¸é ¼ö¸¹Àº Á×Àº ¼ÒÄϵé·Î ÀÎÇØ
¸Þ¸ð¸®°¡ ÆøÁÖÇÒ À§Çèµµ ÀÖ´Ù. FIN-WAIT-2 ¼ÒÄϵéÀº ÃÖ°í 1.5K Á¤µµÀÇ ¸Þ¸ð¸®
¸¦ »ç¿ëÇϱ⠶§¹®¿¡ FIN_WAIT-1 º¸´Ù ´ú À§Çè ÇÏÁö¸¸ tcp_max_orphans °ªº¸´Ù
´õ ¿À·¡ À¯ÁöµÇ·Á´Â °æÇâÀÌ ÀÖ´Ù.
FIN_TIMEOUT ´ë±â ½Ã°£À» ÁÙÀÌ¸é ²÷¾îÁø ¼ÒÄÏÀÇ ¼Ò°Å ½Ã°£À» ÁÙÀÏ ¼ö ÀÖÀ½.
tcp_max_tw_buckets - Á¤¼ö
µ¿½Ã¿¡ À¯Áö °¡´ÉÇÑ timewait ¼ÒÄÏÀÇ ¼ö. ÁöÁ¤ ¼ýÀÚ¸¦ ÃʰúÇÒ °æ¿ì, timewait
¼ÒÄÏÀÌ ¾ø´Ù´Â °æ°í ¸Þ¼¼Áö Ãâ·ÂÇÑ´Ù. ÀÌ Á¦ÇÑÀº ´Ü¼øÇÑ DoS °ø°ÝÀ» ¹æ¾îÇϱâ
À§Çؼ¸¸ ÇÊ¿äÇϸç, ±âº»°ªº¸´Ù ÀÛ°ÔÇØ¼´Â Àý´ë ¾ÈµÈ´Ù. ³×Æ®¿öÅ© ȯ°æÀÌ ±â
º»°ªº¸´Ù Å« °ªÀ» ¿ä±¸ÇÑ´Ù¸é ´Ã·Áµµ µÈ´Ù. º¸Åë ·¥ 64M ´ç 180000 À¸·Î °è»ê
À» ÇÏ¸é µÈ´Ù.
tcp_tw_recycle - 01 ¿¬»ê
ºü¸¥ Àç»ý TIME-WAIT ¼ÒÄÏÀ» »ç¿ëÇÑ´Ù. ±âº»°ªÀº 1ÀÌ´Ù. Àü¹®°¡ÀÇ Á¶¾ð / ¿ä
ûÀÌ ¾ø´Ù¸é Àý´ë ¹Ù²ÙÁö ¸¶¶ó.
tcp_tw_reuse - 01 ¿¬»ê
ÇÁ·ÎÅäÄÝ °üÁ¡¿¡¼ ¾ÈÀüÇÏ´Ù°í ÆÇ´ÜµÉ ¶§ »õ·Î¿î ¿¬°á¿¡ ´ëÇÏ¿© TIME-WAIT ¼Ò
ÄÏÀ» Àç»ç¿ëÇÏ´Â °ÍÀ» Çã¶ôÇÑ´Ù. ±âº»°ªÀº 0 ÀÌ´Ù. ÀÌ °ªÀº ±â¼ú Àü¹®°¡ÀÇ Á¶
¾ðÀ̳ª ¿äûÀÌ ¾øÀÌ º¯°æÇÏÁö ¾Ê´Â °ÍÀÌ ÁÁ´Ù.
tcp_max_orphans - Á¤¼ö
½Ã½ºÅÛ¿¡ °íÁ¤ µÇ¾ú°Å³ª, »ç¿ëÀÚ ÆÄÀÏ Çڵ鿡 ¿¬°áµÇÁö ¾ÊÀº TCP ¼ÒÄÏÀÇ ÃÖ´ë
°ªÀ» ÁöÁ¤ÇÑ´Ù. °í¾Æ ¿¬°áÀÌ ÀÌ °ªÀ» ÃʰúÇϸé, Áï½Ã ¸®¼ÂµÇ°í °æ°í¸¦ Ãâ·ÂÇÑ
´Ù. ÀÌ Á¦ÇÑÀº ´Ü¼øÇÑ DoS °ø°ÝÀ» ¹æ¾îÇϱâ À§Çؼ¸¸ ÇÊ¿äÇϸç, ±âº» °ªº¸´Ù
ÀÛ°ÔÇØ¼´Â Àý´ë ¾ÈµÈ´Ù. ³×Æ®¿öÅ© ȯ°æÀÌ ±âº»°ªº¸´Ù Å« °ªÀ» ¿ä±¸Çϰųª ¿À
·¡ ¹öÅß¼ ±×·± ¹®Á¦µéÀº ´õ °ø°ÝÀûÀ¸·Î Á×À̱â À§ÇØ ³×Æ®¿öÅ©¸¦ Á¶À² ÇÑ´Ù¸é
´Ã·Áµµ µÈ´Ù (¾Æ¸¶, ¼³Ä¡µÈ ¸Þ¸ð¸®¸¦ Áõ¼³ÇÑ ´ÙÀ½) Çѹø ´õ ´çºÎÇÏÀÚ¸é: °í¾Æ
¿¬°áµéÀº ½º¿ÒÇÒ ¼ö ¾ø´Â ¸Þ¸ð¸®¸¦ °¢ÀÚ 64K ÀÌ»ó Â÷ÁöÇÏ°Ô µÈ´Ù..
tcp_abort_on_overflow - 01 ¿¬»ê
¸®½º´× ¼ºñ½º°¡ »õ·Î¿î ¿¬°áÀ» ¼ö¶ôÇϱ⿡ ³Ê¹« ´À¸®´Ù¸é, ±× ¼ºñ½º¸¦ ¸®¼Â
ÇÑ´Ù. ±âº»°ªÀº FALSE ÀÌ´Ù. ÀÌ °ÍÀº °©Àڱ⠿À¹öÇ÷ΰ¡ ¹ß»ýÇÏ´õ¶óµµ ¿¬°áÀÌ
º¹±¸µÈ´Ù´Â ¶æÀÌ´Ù. ¸®½º´× µ¥¸ðÀÌ ¿¬°áÀ» ´õ »¡¸® ¼ö¶ôÇϵµ·Ï ÀÚ¸®ÀâÁö ¸øÇÏ
´Â°Ô Á¤¸» È®½ÇÇÒ ¶§¿¡¸¸ ÀÌ ¿É¼ÇÀ» Ȱ¼ºÈ ÇÑ´Ù. ÀÌ ¿É¼ÇÀ» Ȱ¼ºÈÇÏ¸é ¼¹ö
¿¡¼ ¼Õ»óµÈ Ŭ¶óÀÌ¾ðÆ®¶óµµ ¸®½¼ ÇÏ°Ô µÈ´Ù.
tcp_syncookies - 01 ¿¬»ê
kernel À» CONFIG_SYNCOOKIES ¸¦ ¼³Á¤ÇÏ¿© »ý¼ºÀ» ÇÏ¿´À» ¶§¸¸ »ç¿ëÀÌ À¯È¿ÇÏ
´Ù. ¼ÒÄÏÀ¸·Î syn backlog queue °¡ ³ÑÄ¥¶§ syncookies ¸¦ º¸³½´Ù. À̰ÍÀº ÀÏ
¹ÝÀûÀÎ 'syn flood attack' À̶ó´Â °ø°ÝÀ» ¹æ¾î Çϱâ À§ÇØ »ç¿ëÀÌ µÈ´Ù. ±âº»
°ªÀº FALSE ÀÌ´Ù.
syncookies ´Â ´ëü ¹æ¹ýÀÏ »Ó À̶ó´Â °ÍÀ» ¸í½É ÇØ¾ß ÇÑ´Ù. À̰ÍÀº Á¤»óÀûÀÎ
Á¢¼Ó¿¡ ´ëÇØ ´õ ÁÁÀº ¼º´ÉÀ» ³»°ÔÇÏ´Â °Í¿¡ »ç¿ëÀÌ µÇ´Â°ÍÀº ¾Æ´Ï´Ù. ¸¸¾à ·Î
±×¿¡¼ synflood °æ°í¸¦ º¸°Ô µÈ´Ù¸é, ÇÏÁö¸¸ À̰͵éÀÌ Á¤»óÀûÀÎ Á¢¼ÓµéÀÌ ³Ñ
Ãļ ¹ß»ýÇÑ °ÍµéÀ̶ó¸é ÀÌ °æ°í°¡ »ç¶óÁö±â Àü¿¡ tcp_syncookies °¡ ¾Æ´Ñ ´Ù
¸¥ ÆÄ¶ó¹ÌÅ͵éÀ» Á¶ÀýÇØ¾ß ÇÑ´Ù. tcp_max_syn_backlog, tcp_synack_retries,
tcp_abort_on_overflow ¸¦ Âü°í¸¦ Ç϶ó.
syncookies ´Â TCP ÇÁ·ÎÅäÄÝ¿¡ ½É°¢ÇÏ°Ô ¾î±ß³ª¸ç, TCP È®ÀÞµéÀ» »ç¿ëÇÏ´Â °Í
À» Çã¶ôÇÏÁö ¾ÊÀ¸¸ç, (SMTP relaying °°Àº) ƯÁ¤¼ºñ½ºµéÀÇ ½É°¢ÇÑ ¼Õ»óÀÇ °á
°ú°¡ µÉ¼öÀÖ´Ù. ¸¸¾à ½ÇÁ¦ ³ÑÄ¡Áö ¾ÊÀ½¿¡µµ ºÒ±¸ÇÏ°í ·Î±×¿¡ synflood °æ°í°¡
°è¼Ó ¹ß»ýÇÑ´Ù¸é, ¼¹öÀÇ ¼³Á¤ÀÌ ½É°¢ÇÏ°Ô À߸øµÇ¾î ÀÖ´Â °ÍÀÌ´Ù.
tcp_stdurg - 01 ¿¬»ê
TCP urg Æ÷ÀÎÅÍ Çʵå ÇØ¼®±â°¡ ÇÊ¿äÇÒ ¶§¿¡ »ç¿ëÇÑ´Ù. ´ëºÎºÐ ¿À·¡µÈ BSD ÇØ
¼®±â¸¦ »ç¿ëÇϴµ¥, ¸®´ª½º°¡ ±×·± °Íµé°ú Á¦´ë·Î ¼ÒÅëÇÏÁö ¸øÇÑ´Ù°í ÆÇ´ÜµÉ
°æ¿ì Ȱ¼ºÈ¸¦ ÇØ º¼¸¸ÇÏ´Ù. ±âº»°ªÀº FALSE ÀÌ´Ù.
tcp_max_syn_backlog - Á¤¼ö
Á¢¼ÓÇÑ client µé Áß ½ÂÀÎÀ» ¹ÞÁö ¸øÇÏ´Â Á¢¼Ó ¿äûµéÀÇ ÃÖ´ë°ªÀ» ÁöÁ¤ ÇÑ´Ù.
¸¸¾à ½ÂÀÎÀ» ¹ÞÁö ¸øÇÏ°í ±â´Ù¸®´Â Á¢¼Ó ¿äûµéÀÌ ÀÌ ¼ö¸¦ ¹þ¾î³ª´Â °æ¿ì¿¡´Â
"´Ù½Ã ÀçÁ¢¼ÓÀ» ÇØ º¸¶ó" ¶ó´Â ¸Þ¼¼Áö¸¦ ¹Þ°Ô µÈ´Ù. 128MbÀÇ ¸Þ¸ð¸®¿¡¼´Â ±â
º»°ªÀ¸·Î 1024¸¦ »ç¿ëÇÒ¼ö ÀÖÀ¸¸ç, À̺¸´Ù ÀûÀº ¸Þ¸ð¸®¸¦ °¡Áö°í ÀÖÀ» °æ¿ì¿¡
´Â 128 À» »ç¿ëÇϱ⸦ ±ÇÀå ÇÑ´Ù. ¸¸¾à ¼¹ö¿¡ ºÎÇϰ¡ ¸¹ÀÌ °É¸®°Ô µÈ´Ù¸é ÀÌ
°ªÀ» Áõ°¡ÇØ º¸±â ¹Ù¶õ´Ù.
tcp_window_scaling - 01 ¿¬»ê
RFC1323 ¿¡ Á¤ÀÇµÈ window scaling À» °¡´ÉÇÏ°Ô ÇÑ´Ù.
tcp_timestamps - 01 ¿¬»ê
RFC1323 ¿¡ Á¤ÀÇµÈ timestamp µéÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù.
tcp_sack - 01 ¿¬»ê
SYN ÆÐŶÀ» Àü¼ÛÇÑ ÈÄ¿¡, ·Î½º°¡ ¹ß»ýÀ» ÇÏ¿© ACK ¸¦ ÀϺΠ¹ÞÁö ¸øÇßÀ» °æ¿ì,
¼±ÅÃÀûÀ¸·Î (selected) ¹ÞÁö ¸øÇÑ ACK ¸¸ ¹Þµµ·Ï ¿äûÇÏ´Â °ÍÀ» Çã¶ôÇÑ´Ù. ·Î
½º°¡ ¸¹Àº ³×Æ®¿öÅ©¿¡¼´Â »ó´çÈ÷ Áß¿äÇÑ ¿ªÇÒÀ» ÇÑ´Ù.
tcp_fack - 01 ¿¬»ê
FACK ¹ÐÁý ȸÇÇ¿Í ºü¸¥ ÀçÀü¼ÛÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù. tcp_sack ÀÌ È°¼ºÈ°¡ µÇ¾î
ÀÖÁö ¾ÊÀ¸¸é ÀÌ °ªÀº »ç¿ëµÇÁö ¾Ê´Â´Ù.
tcp_dsack - 01 ¿¬»ê
TCP°¡ Áߺ¹µÈ SACK µéÀ» º¸³»´Â °ÍÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù.
tcp_ecn - 01 ¿¬»ê
TCP ¿¡ ¸í¹éÇÑ È¥Àâ °øÁö(Explicit Congestion Notification) ¸¦ °¡´ÉÇÏ°Ô ÇÑ
´Ù.
tcp_reordering - Á¤¼ö
TCP stream ¿¡ ÆÐŶµéÀÇ ÃÖ´ë Àç ¿äûÀ» ¼³Á¤.
±âº»°ª: 3
tcp_retrans_collapse - 01 ¿¬»ê
¸Á°¡Áø ÇÁ¸°ÅÍ¿¡ Bug-to-bug ȣȯ. ´õ Å« ÆÐŶÀ» ÀçÀü¼ÛÇØ¼ ¾î¶² TCP ½ºÅÿ¡
ÀÖ´Â ¹ö±×¸¦ ÇÇÇØ°£´Ù.
tcp_wmem - vector of 3 INTEGERs: min, default, max
min: TCP ¼ÒÄÏ¿¡¼ send buffer ¿¡ ÇÒ´çµÉ ¸Þ¸ð¸® ¾ç. °¢ TCP ¼ÒÄϵéÀº ¿¬°á
ÀÌ À¯ÁöµÈ »óÅ¿¡¼´Â ÀÌ ¸Þ¸ð¸®¸¦ »ç¿ëÇÑ ±ÇÇÑÀ» °¡Áö°Ô µÈ´Ù. ±âº»°ªÀº 4K
default: TCP ¼ÒÄÏ¿¡¼ ±âº»À¸·Î ÇÒ´çÀÌ µÇ´Â send ¹öÆÛÀÇ ¸Þ¸ð¸® ¾ç. À̰ªÀº
´Ù¸¥ ÇÁ·ÎÅäÄÝ¿¡¼ ÀÇÇØ »ç¿ëµÇ´Â net.core.wmem_default °ª º¸´Ù ¿ì¼± ÇÑ´Ù.
±âº»°ªÀº 16K
max: TCP ¼ÒÄÏ¿¡¼ ÀÚµ¿À¸·Î ¼±ÅÃµÈ send ¹öÆÛ¸¦ À§ÇÑ ÃÖ´ë ¸Þ¸ð¸® Å©±â. ÀÌ
°ªº¸´Ù net.core.wmem_max °ªÀÌ ¿ì¼±ÇÑ´Ù. ±âº»°ªÀº 128K
tcp_rmem - vector of 3 INTEGERs: min, default, max
min: TCP ¼ÒÄÏ¿¡¼ receive buffer ¿¡ ÇÒ´çµÉ ¸Þ¸ð¸® ¾ç. °¢ TCP ¼ÒÄϵéÀº ¿¬
°áÀÌ À¯ÁöµÈ »óÅ¿¡¼´Â ÀÌ ¸Þ¸ð¸®¸¦ »ç¿ëÇÒ ±ÇÇÑÀ» °¡Áö°Ô µÈ´Ù. ±âº»°ªÀº 8K
default: TCP ¼ÒÄÏ¿¡¼ »ç¿ëµÇ¾î Áö´Â receive buffer ÀÇ ±âº»°ª. ÀÌ °ªÀº ´Ù
¸¥ ÇÁ·ÎÅäÄÝ¿¡ ÀÇÇØ »ç¿ëµÇ´Â net.core.rmem_default °ª º¸´Ù ¿ì¼±ÇÑ´Ù. ±âº»
°ªÀº 87380 byte ÀÌ´Ù. ÀÌ °ªÀº tcp_adv_win_Scale ÀÇ ±âº» ¼³Á¤°ú tcp_app_win:0
°ú ±âº» tcp_app_win À» À§ÇÑ bit less ¿Í ÇÔ²² 65535 ÀÇ window ¸¦ °¡Áö°ÔµÈ
´Ù.
max: TCP ¼ÒÄÏ¿¡ ´ëÇÏ¿©, ÀÚµ¿ÀûÀ¸·Î ÃÖ´ëÇÑ »ç¿ëÇÒ ¼ö ÀÖ´Â receive buffer
ÀÇ ÃÖ´ëÅ©±â ÀÌ °ªÀº net.core.rmem_max ÀÇ °ªÀ» µ¤¾î¾²Áö ¸øÇϸç, SO_RCVBUF
¸¦ ÅëÇÑ "Á¤Àû"ÀÎ ¿¬°áÀº ÀÌ °ªÀ» »ç¿ëÇÏÁö ¾Ê´Â´Ù. ±âº»°ªÀº 87380*2 byte.
tcp_mem - vector of 3 INTEGERs: min, pressure, max
low: below this number of pages TCP is not bothered about its
memory appetite.
pressure: when amount of memory allocated by TCP exceeds this number
of pages, TCP moderates its memory consumption and enters memory
pressure mode, which is exited when memory consumtion falls
under "low".
high: number of pages allowed for queueing by all TCP sockets.
Defaults are calculated at boot time from amount of available
memory.
tcp_app_win - Á¤¼ö
Reserve max(window/2^tcp_app_win, mss) of window for application
buffer. Value 0 is special, it means that nothing is reserved.
±âº»°ª: 31
tcp_adv_win_scale - Á¤¼ö
Count buffering overhead as bytes/2^tcp_adv_win_scale
(if tcp_adv_win_scale > 0) or bytes-bytes/2^(-tcp_adv_win_scale),
if it is <= 0.
±âº»°ª: 2
tcp_rfc1337 - BOOLEAN
¼¼ÆÃµÇ¸é TCP ½ºÅÃÀº RFC1337À» µû¸¥´Ù. ÇØÁ¦µÇ¸é RFC¸¦ µû¸£Áö ¾ÊÁö¸¸ TCP
TIME_WAIT asassinationÀº ¸·¾ÆÁØ´Ù.
Ŭ¶óÀ̾ðÆ®ÀÇ ¼ÒÄÏÀ¸·Î ºÎÅÍ RST¸¦ ¹Þ¾Æ TIME_WAIT »óÅ·Π°¡´Â °æ¿ì Áï½Ã ¼Ò
ÄÏÀ» Á¾·á ½ÃÅ´. À¥¼¹ö¿Í °°Àº À¯ÇüÀÇ ¼¹ö¿¡¼´Â ¼ÒÄÏÀ» ¿°í ´Ý´Â ȸ¼ö°¡
¸¹À¸¹Ç·Î, ÀÌ ¼³Á¤À» ÀûÀýÇÏ°Ô ¼³Á¤ÇÏ¿© »ç¿ëÇÏ´Â °ÍÀÌ ÁÁÀ½. ¶Ç´Â
net.ipv4.tcp_max_tw_buckets °ªÀ» ÁÙÀÌ´Â °ÍÀ¸·Îµµ °¡´ÉÇÔ
±âº»°ª: 0
tcp_low_latency - BOOLEAN
If set, the TCP stack makes decisions that prefer lower
latency as opposed to higher throughput. By default, this
option is not set meaning that higher throughput is preferred.
An example of an application where this default should be
changed would be a Beowulf compute cluster.
±âº»°ª: 0
ip_local_port_range - 2 Á¤¼ö°ª
TCP ¿Í UDP ¿¡ ÀÇÇØ »ç¿ëµÉ local Æ÷Æ® ¹üÀ§¸¦ Á¤ÀÇÇÑ´Ù. ù¹øÂ° ¼ýÀÚ´Â »ç¿ë
ÇÒ ¿µ¿ªÀÇ °¡Àå ¾ÕºÎºÐ Æ÷Æ® ¹øÈ£¸¦ ÁöÁ¤ÇÏ°í µÎ¹øÂ°´Â ¸¶Áö¸· Æ÷Æ®¹øÈ£¸¦ Áö
Á¤ÇÑ´Ù. ±âº»°ªÀº ½Ã½ºÅÛÀÇ »ç¿ë°¡´ÉÇÑ ¸Þ¸ð¸®ÀÇ ¾ç¿¡ ÀÇÇØ °áÁ¤ÀÌ µÈ´Ù:
¸Þ¸ð¸®°¡ 128Mb º¸´Ù ¸¹À» °æ¿ì 32768-61000
¸Þ¸ð¸®°¡ 128Mb º¸´Ù ÀûÀ» °æ¿ì 1024-4999 ¶Ç´Â À̺¸´Ù Àû°Ô..
ÀÌ °ªÀº TCP È®ÀåÀ» Áö¿øÇÏÁö ¾Ê´Â ½Ã½ºÅÛÀ¸·Î µ¿½Ã¿¡ ¹ß»ýÀÌ µÉ¼ö Àִ Ȱ¼º
ÈµÈ Á¢¼ÓµéÀÇ ¼ö¸¦ °áÁ¤ÇÑ´Ù. tcp_tw_recycle À» °¡´ÉÇÏ°Ô ÇÔÀ¸·Î¼ (±âº»Àû
À¸·Î) 1024-4999 ¿µ¿ªÀº timestamps¸¦ Áö¿øÇÏ´Â ½Ã½ºÅ۵鿡 ÃÊ´ç 2000°³ÀÇ Á¢
¼Ó Á¤µµ¸¦ °¡´ÉÇÏ°Ô ÇÏ ´Âµ¥ ÃæºÐÇÏ´Ù.
Á¤È®Ä¡´Â ¾ÊÁö¸¸ 2.4.20 ÀÌ ÈÄ ºÎÅÍ´Â Ä¿³Î¿¡¼ ÀÚµ¿À¸·Î °¨Áö¸¦ ÇÏ¿© ÀâÀ¸¹Ç
·Î ½Å°æÀ» ¾²Áö ¾Ê¾Æµµ »ó°üÀÌ ¾ø´Ù.
ip_nonlocal_bind - BOOLEAN
¼¼ÆÃµÇ¸é ÇÁ·Î¼¼½º°¡ ·ÎÄà IP °¡ ¾Æ´Ñ ÁÖ¼Ò¿¡ bind() ÇÒ¼ö ÀÖ´Ù. ¸Å¿ì À¯¿ëÇÑ
±â´ÉÀÌÁö¸¸ ¾î¶² ¾îÇø®ÄÉÀ̼ǿ¡¼´Â ³ª»Ü ¼ö ÀÖ´Ù.
±âº»°ª: 0
ip_dynaddr - BOOLEAN
0 ÀÌ ¾Æ´Ñ °ªÀ» ¼¼ÆÃÇÏ¸é µ¿Àû ÁÖ¼Ò¸¦ (dynamic addresses) Áö¿øÇÑ´Ù. 1 º¸´Ù
Å« °ªÀ» ¼¼ÆÃÇÏ¸é µ¿ÀûÁÖ¼Ò°¡ ´Ù½Ã ¾²¿©Áú ¶§¸¶´Ù ·Î±× ¸Þ½ÃÁö°¡ Ãâ·ÂµÉ °ÍÀÌ
´Ù.
±âº»°ª: 0
icmp_echo_ignore_all - 01 ¿¬»ê
ÀÌ °ªÀ» 1 ·Î ÇÒ °æ¿ì kernel Àº ¸ðµç ICMP ECHO ¿äûÀ» ¹«½ÃÇØ ¹ö¸°´Ù.
Áï ping ÀÌ ¾ÈµÇ°Ô ÇÑ´Ù.
icmp_echo_ignore_broadcasts - 01 ¿¬»ê
¸¸¾à ¸ðµç ICMP ECHO ¿äûÀ» Ä¿³ÎÀÌ ¹«½ÃÇÏ°Ô Çϰųª, ICMP ECHO ¿äû Áß
broadcast ¿Í multicast ÁÖ¼Ò¿¡¸¸ ¹«½ÃÇÏ°Ô ÇÒ¶§ 1ÀÇ °ªÀº ¹«½Ã, 0ÀÇ °ªÀº ¸®
ÅÏÀ» ÇÏ°Ô µÈ´Ù. ¸¸¾à boardcast/multicast ÁÖ¼ÒÀÇ ICMP ECHO ¿äûÀ» ¼ö¿ëÇÏ
°Ô ÇÑ´Ù¸é, network°¡ ´Ù¸¥È£½ºÆ®·Î denial of service(DOS) packet flooding
°ø°ÝÀ» Çϴµ¥ ÀÌ¿ëÀÌ µÉ¼ö°¡ ÀÖ´Ù.
icmp_ratelimit - Á¤¼ö
¾Æ·¡ÀÇ icmp_ratemask ¿¡ ÁöÁ¤µÈ BIT ¿Í ÀÏÄ¡Çϴ ŸÀÔÀÇ ICMP ÆÐŶÀ» º¸³»±â
À§ÇÑ ÃÖ´ë ºóµµ¸¦ Á¦ÇÑÇÑ´Ù.
0 Àº Á¦ÇÑÀ» ¾ø¾Ö¸ç ±× ¹ÛÀÇ °ªÀº jiffies(1) ÀÇ ÃÖ´ë ºóµµ¸¦ ÀǹÌÇÑ´Ù.
±âº»°ª: 100
icmp_ratemask - Á¤¼ö
Mask made of ICMP types for which rates are being limited.
Significant bits: IHGFEDCBA9876543210
Default mask: 0000001100000011000 (6168)
Bit Á¤ÀÇ (see include/linux/icmp.h):
0 Echo Reply
3 Destination Unreachable *
4 Source Quench *
5 Redirect
8 Echo Request
B Time Exceeded *
C Parameter Problem *
D Timestamp Request
E Timestamp Reply
F Info Request
G Info Reply
H Address Mask Request
I Address Mask Reply
* These are rate limited by default (see default mask above)
icmp_ignore_bogus_error_responses - 01 ¿¬»ê
¾î¶² router µéÀº broadcast frame µé·Î °ÅÁþ ÀÀ´äÀ» º¸³¿À¸·Î¼ RFC 1122 ¸¦
À§¹ÝÇÑ´Ù. ÀÌ·¯ÇÑ À§ÇѵéÀº º¸Åë Ä¿³Î °æ°í¸¦ ÅëÇØ ·Î±ëÀÌ µÈ´Ù. À̰ÍÀ» TRUE
·Î ¼³Á¤À» ÇÒ°æ¿ì Ä¿³ÎÀº ÀÌ·¯ÇÑ °æ°í¸¦ ÇÏÁö ¾ÊÀ» °ÍÀ̸ç, ·Î±× ÆÄÀÏÀÌ ÁöÀú
ºÐÇØ Áö´Â °ÍÀ» ÇÇÇÒ¼ö ÀÖ´Ù.
±âº»°ª: FALSE
igmp_max_memberships - Á¤¼ö
¸ÖƼij½ºÆ® ±×·ì¿¡ Âü¿©ÇÒ ¼ö ÀÖ´Â ÃÖ´ë°ªÀ» º¯°æÇÑ´Ù.
±âº»°ª: 20
conf/interface/* changes special settings per interface (where "interface" is
the name of your network interface)
conf/all/* is special, changes the settings for all interfaces
log_martians - 01 ¿¬»ê
ºÒ°¡´ÉÇÑ ÁÖ¼ÒµéÀ» Áö´Ñ ÆÐŶÀ» kerenl log ¿¡ ±â·ÏÇÑ´Ù. IP soppfing packet
À» üũÇϴµ¥ À¯¿ëÇÏ´Ù.
Log packets with impossible addresses to kernel log.
log_martians for the interface will be enabled if at least one of
conf/{all,interface}/log_martians is set to TRUE,
it will be disabled otherwise
accept_redirects - 01 ¿¬»ê
ICMP redirect message µéÀ» Çã¿ëÇÑ´Ù.
±âº»°ª TRUE (host)
FALSE (router)
Accept ICMP redirect messages.
accept_redirects for the interface will be enabled if:
- both conf/{all,interface}/accept_redirects are TRUE in the case forwarding
for the interface is enabled
or
- at least one of conf/{all,interface}/accept_redirects is TRUE in the case
forwarding for the interface is disabled
accept_redirects for the interface will be disabled otherwise
default TRUE (host)
FALSE (router)
forwarding - 01 ¿¬»ê
ÀÌ interface ·Î IP forwarding À» °¡´ÉÇÏ°Ô ÇÑ´Ù.
mc_forwarding - 01 ¿¬»ê
multicast routingÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù. ÀÌ °ªÀ» »ç¿ëÇϱâ À§Çؼ´Â Ä¿³Î config
¿¡¼ CONFIG_MROUTE ¸¦ ¼³Á¤Çؼ ºôµå¸¦ ÇØ¾ß Çϸç, multicast routing ÀÌ °¡
´ÉÇÑ µ¥¸óÀÌ ¿ä±¸µÇ¾î Áø´Ù.
medium_id - Á¤¼ö
Integer value used to differentiate the devices by the medium they
are attached to. Two devices can have different id values when
the broadcast packets are received only on one of them.
The default value 0 means that the device is the only interface
to its medium, value of -1 means that medium is not known.
Currently, it is used to change the proxy_arp behavior:
the proxy_arp feature is enabled for packets forwarded between
two devices attached to different media.
proxy_arp - 01 ¿¬»ê
ÇÁ·Ï½Ã ARP´Â ÁöÁ¤ÇÑ ÀÎÅÍÆäÀ̽º¿Í ¿¬°áµÈ ´Ù¸¥ È£½ºÆ®ÀÇ ARP ÁÖ¼Ò¸¦ ´ë½Å »Ñ
·ÁÁÖ°í, ¹Þ´Â´Ù. Åõ¸íÇÏ°Ô µ¿ÀÛÇÏ´Â ³×Æ®¿öÅ© Àåºñ¿¡ ¹Ýµå½Ã ÇÊ¿äÇÏ´Ù.
shared_media - 01 ¿¬»ê
RFC1620 ¹Ìµð¾î °øÀ¯ ¸®´ÙÀÌ·ºÆ®¸¦ º¸³»°Å³ª (¶ó¿ìÅÍ) ¼ö¶ô (È£½ºÆ®)ÇÑ´Ù. ÀÌ
¿É¼Ç °ªÀÌ 0 À̸é ÇÑ ÀåÄ¡¿¡ ¼³Á¤µÈ ¼·Î ´Ù¸¥ ¼ºê³ÝÀ» Á÷Á¢ Åë½ÅÇÒ ¼ö ¾ø´Ù.
±âº»°ª: TRUE
secure_redirects - 01 ¿¬»ê
µðÆúÆ® °ÔÀÌÆ®¿þÀÌ ¸ñ·Ï¿¡ ¿Ã¶óÀÖ´Â °ÔÀÌÆ®¿þÀÌ¿¡¸¸ ICMP ¸®´ÙÀÌ·ºÆ® ¸Þ½ÃÁö¸¦
Çã¿ëÇÑ´Ù. ±âº»°ªÀº TRUE
send_redirects - 01 ¿¬»ê
router ·Î »ç¿ëÀÌ µÈ´Ù¸é redirect ¸¦ º¸³½´Ù. ±âº»°ªÀº TRUE ÀÌ´Ù.
Accept ICMP redirect messages only for gateways,
listed in default gateway list.
secure_redirects for the interface will be enabled if at least one of
conf/{all,interface}/secure_redirects is set to TRUE,
it will be disabled otherwise
default TRUE
send_redirects - BOOLEAN
Send redirects, if router.
send_redirects for the interface will be enabled if at least one of
conf/{all,interface}/send_redirects is set to TRUE,
it will be disabled otherwise
±âº»°ª: TRUE
bootp_relay - 01 ¿¬»ê
Accept packets with source address 0.b.c.d destined
not to this host as local ones. It is supposed, that
BOOTP relay daemon will catch and forward such packets.
default FALSE
Not Implemented Yet.
accept_source_route - 01 ¿¬»ê
SRR ¿É¼ÇÀ¸·Î ÆÐŶµéÀ» ¼ö¿ëÇÑ´Ù. IP source routing À» Á¦¾îÇÑ´Ù. º¸Åë È£½º
Æ®·Î ÇâÇÏ°Ô ÇÏ´Â °ÍÀ» ±ÇÀåÇÑ´Ù. ÀÌ °ªÀÌ ÂüÀÌ¸é ÆÐŶ °æ·Î¸¦ Ãâ¹ßÁö¿¡¼ Á¶
ÀÛÀÌ °¡´ÉÇϹǷÎ, IP ½ºÇªÇο¡ ¾Ç¿ëµÉ ¼ÒÁö°¡ ÀÖ´Ù.
±âº»°ª TRUE (router)
FALSE (host)
rp_filter - 01 ¿¬»ê
1 - Áý¿¡¼ »ç¿ëÇÏ´Â ½Ì±Û È£½ºÆ®³ª ¸î°³ÀÇ ¼ºê³ÝÀ¸·Î ³ª´µ¾îÁø ³×Æ®¿öÅ© °°
ÀÌ RFC1812¿¡ ÁöÁ¤µÇ¾îÁø ¿ª°æ·Î¿¡ ÀÇÇÑ ¼Ò½º À¯È¿¼ºÀ» üũÇÑ´Ù. ºÐ¼®ÇÏ
±â ¾î·Á¿î ³×Æ®¿öÅ©¿¡¼ ´À¸®°í ½Å·ÚÇÒ ¼ö ¾ø´Â ÇÁ·ÎÅäÄÝ ¶Ç´Â Á¤ÀûÀÎ ³×
Æ®¿öÅ©¸¦ ÅëÇØ ¹®Á¦¸¦ ¾ß±âÇÒ¼öµµ ÀÖ´Ù.
º¸ÅëÀº IP spoofing À» ¹æÁöÇϱâ À§ÇØ ¸¹ÀÌ »ç¿ëÀ» ÇÑ´Ù.
0 - ¼Ò½º À¯È¿¼º üũ¸¦ ÇÏÁö ¾Ê´Â´Ù.
conf/all/rp_filter must also be set to TRUE to do source validation
on the interface
±âº»°ªÀº 0 ÀÌ´Ù. startip ½ºÅ©¸³Æ®¿¡¼ À̸¦ °¡´ÉÇÏ°Ô ÇØ ³õÀº ¹èÆ÷ÆÇµµ ÀÖ
À¸´Ï ÁÖÀÇÇØ¾ß ÇÑ´Ù.
arp_filter - BOOLEAN
1 - Allows you to have multiple network interfaces on the same
subnet, and have the ARPs for each interface be answered
based on whether or not the kernel would route a packet from
the ARP'd IP out that interface (therefore you must use source
based routing for this to work). In other words it allows control
of which cards (usually 1) will respond to an arp request.
0 - (default) The kernel can respond to arp requests with addresses
from other interfaces. This may seem wrong but it usually makes
sense, because it increases the chance of successful communication.
IP addresses are owned by the complete host on Linux, not by
particular interfaces. Only for more complex setups like load-
balancing, does this behaviour cause problems.
arp_filter for the interface will be enabled if at least one of
conf/{all,interface}/arp_filter is set to TRUE,
it will be disabled otherwise
tag - Á¤¼ö
Allows you to write a number, which can be used as required.
Default value is 0.
(1) Jiffie:
Ä¿³ÎÀ» À§ÇÑ ³»ºÎ ŸÀÓÀ¯´Ö. i386 ¿¡¼ 1/100 ÃÊ, ¾ËÆÄ¿¡¼ 1/1024 ÃÊÀÌ´Ù. ¾Ë¸ÂÀº °ª
ÀÌ ±Ã±ÝÇÏ´Ù¸é /usr/include/asm/param.h ¿¡¼ HZ defineÀ» Âü°íÇÑ´Ù.
Alexey Kuznetsov.
kuznet@ms2.inr.ac.ru
Updated by:
Andi Kleen
ak@muc.de
Nicolas Delon
delon.nicolas@wanadoo.fr
/proc/sys/net/ipv6/* Variables:
IPv6 has no global variables such as tcp_*. tcp_* settings under ipv4/ also
apply to IPv6 [XXX?].
bindv6only - BOOLEAN
Default value for IPV6_V6ONLY socket option,
which restricts use of the IPv6 socket to IPv6 communication
only.
TRUE: disable IPv4-mapped address feature
FALSE: enable IPv4-mapped address feature
±âº»°ª: FALSE (as specified in RFC2553bis)
conf/default/*:
Change the interface-specific default settings.
conf/all/*:
Change all the interface-specific settings.
[XXX: Other special features than forwarding?]
conf/all/forwarding - BOOLEAN
Enable global IPv6 forwarding between all interfaces.
IPv4 and IPv6 work differently here; e.g. netfilter must be used
to control which interfaces may forward packets and which not.
This also sets all interfaces' Host/Router setting
'forwarding' to the specified value. See below for details.
This referred to as global forwarding.
conf/interface/*:
Change special settings per interface.
The functional behaviour for certain settings is different
depending on whether local forwarding is enabled or not.
accept_ra - BOOLEAN
Accept Router Advertisements; autoconfigure using them.
Functional default: enabled if local forwarding is disabled.
disabled if local forwarding is enabled.
accept_redirects - BOOLEAN
Accept Redirects.
Functional default: enabled if local forwarding is disabled.
disabled if local forwarding is enabled.
autoconf - BOOLEAN
Configure link-local addresses using L2 hardware addresses.
±âº»°ª: TRUE
dad_transmits - Á¤¼ö
The amount of Duplicate Address Detection probes to send.
±âº»°ª: 1
forwarding - BOOLEAN
Configure interface-specific Host/Router behaviour.
Note: It is recommended to have the same setting on all
interfaces; mixed router/host scenarios are rather uncommon.
FALSE:
By default, Host behaviour is assumed. This means:
1. IsRouter flag is not set in Neighbour Advertisements.
2. Router Solicitations are being sent when necessary.
3. If accept_ra is TRUE (default), accept Router
Advertisements (and do autoconfiguration).
4. If accept_redirects is TRUE (default), accept Redirects.
TRUE:
If local forwarding is enabled, Router behaviour is assumed.
This means exactly the reverse from the above:
1. IsRouter flag is set in Neighbour Advertisements.
2. Router Solicitations are not sent.
3. Router Advertisements are ignored.
4. Redirects are ignored.
±âº»°ª: FALSE if global forwarding is disabled (default),
otherwise TRUE.
hop_limit - Á¤¼ö
Default Hop Limit to set.
±âº»°ª: 64
mtu - Á¤¼ö
Default Maximum Transfer Unit
±âº»°ª: 1280 (IPv6 required minimum)
router_solicitation_delay - Á¤¼ö
Number of seconds to wait after interface is brought up
before sending Router Solicitations.
±âº»°ª: 1
router_solicitation_interval - Á¤¼ö
Number of seconds to wait between Router Solicitations.
±âº»°ª: 4
router_solicitations - Á¤¼ö
Number of Router Solicitations to send until assuming no
routers are present.
±âº»°ª: 3
icmp/*:
ratelimit - Á¤¼ö
Limit the maximal rates for sending ICMPv6 packets.
0 to disable any limiting, otherwise the maximal rate in jiffies(1)
±âº»°ª: 100
IPv6 Update by:
Pekka Savola <pekkas AT netcore.fi>
YOSHIFUJI Hideaki / USAGI Project <yoshfuji AT linux-ipv6.org>
>> ÀÌÀü : Sysctl For Kernel Parameters in Kernel
|