BBUWOO'S [ LIKE UNIX ] WORLD Home > Lecture > Kernel > Kernel-7  

HOME
WHAT's BBUWOO?
LInux AnNyung
DEVELOPMENT
LECTURE
MINI LECTURE
QnA BOARD
ENGLISH POEM
WEB LOG
RESOURCE USAGE
ÇöÀç ´ë¿ªÆø Ȱ¿ë:
0.06 Mbit/s
ÃÖ´ë ´ë¿ªÆø:
100.0 Mbit/s
Bandwidth utilization bar


WARNNING

°­ÁÂÀÇ ¸ðµç ±Ç¸®´Â º»ÀÎ ±èÁ¤±Õ¿¡°Ô ÀÖÀ¸¸ç ÀÌ °­Á¸¦ »ó¾÷Àû ¸ñÀû À¸·Î ÀÌ¿ë
Çϰųª ´Ù¸¥ °÷À¸·Î ¿Å±æ½Ã¿¡´Â º»ÀÎÀÇ Çã¶ôÀÌ ÀÖ¾î¾ß ÇÑ´Ù. À̱ÛÀÇ °¡Àå ÃֽűÛÀº
http://www.oops.org ¿¡¼­ È®ÀÎÇÒ¼ö ÀÖ´Ù.



7. Sysctl For Networking in Kernel

/proc/sys/net/ipv4/* À» À§ÇÑ ¹®¼­ kernel version 2.4.25 ¹ø¿ª 2004.2.25 ±èÁ¤±Õ <http://oops.org> * ¿ªÁÖ) ÀÌ ÆäÀÌÁö¸¦ Àбâ Àü¿¡ ¾ÆÁÖ °­·ÂÇÏ°Ô ÁÖÀǸ¦ ¿äÇÒ °ÍÀº sysctlÀ» ÀÌ¿ëÇÏ¿© ÀÌ °ªµéÀ» º¯°æÇÒ °æ¿ì³ª Á÷Á¢ÀûÀ¸·Î º¯°æÀ» ÇÒ °æ¿ì ½Ã½ºÅÛÀÌ crash µÇ¾îÁú À§Çè¿ä¼Ò°¡ ¸¹ÀÌ ÀÖ ´Ù´Â °ÍÀ» ¸í½ÉÇØ ¾ß ÇÑ´Ù. Áï, ÀÚ±âÀÇ ½Ã½ºÅÛ¿¡ ¹«¸®ÇÑ °ªÀ» ³Ö¾úÀ» °æ¿ì ±× Áï½Ã ½Ã ½ºÅÛÀÌ ¸ØÃâ¼öµµ Àֱ⠶§¹®¿¡ ÃæºÐÇÑ Å×½ºÆ®¿Í ½Ã½ºÅÛÀÌ crash°¡ µÉ ¼ö ÀÖÀ½À» ¸í½ÉÇÏ °í Ã¥ÀÓÀ» Áú¼ö ÀÖÀ» °æ¿ì¿¡¸¸ ¸¸Áö±â¸¦ ±ÇÀåÇÑ´Ù. * ÂüÁ¶) http://kldp.org/KoreanDoc/html/Kernel-KLDP/network.html ip_forward - 01 ¿¬»ê 0 - »ç¿ë¾ÈÇÔ (±âº»°ª) 0 ÀÌ ¾Æ´Ò °æ¿ì - »ç¿ëÇÔ interface µé »çÀÌ¿¡ ÆÐŶµéÀ» ±³È¯½ÃŰ´Â °ÍÀ» Çã¶ô. ÀÌ º¯¼öÀÇ º¯°æÀº ±âº»ÀûÀÎ »óÅ·Π¸ðµç ¼³Á¤ ÆÄ¶ó¹ÌÅ͵éÀ» ¸®¼Â ½ÃŲ´Ù. (RFC1122 for hosts, RFC1812 for routers) ip_default_ttl - Á¤¼ö ±âº»°ª: 64 TTL (Time To Live) Àº IP ÆÐŶ ¾È¿¡ µé¾îÀÖ´Â (´ë°³ 0ºÎÅÍ 255 »çÀÌ) Á¤¼ö°ª À¸·Î TTL À̶ó´Â ¸» ±×´ë·Î ÆÐŶÀÇ ¼ö¸íÀ» Ä«¿îÆ®ÇÑ´Ù. ¶ó¿ìÅÍ Çϳª¸¦ Áö³¯¶§ ¸¶´Ù Ãʱ⠰ª¿¡¼­ 1 (ȤÀº ±× ÀÌ»ó)À» »©´Âµ¥ °ªÀÌ 0 ÀÌ µÇ¸é ¶ó¿ìÅÍ´Â ±× ÆÐ Ŷ À» ¹ö¸®°í ÀçÀü¼ÛÀ» ¿äûÇÏ´Â ICMP ¸Þ½ÃÁö¸¦ ¹ß½ÅÁö È£½ºÆ®¿¡ º¸³½´Ù. ¸® ´ª½º´Â ±× °ªÀÌ 255 À̳ª À©µµ¿ì 95 ³ª 98 ÀÇ TTL ±âº» °ªÀº 32 È©À¸·Î, ¿î¿µ üÁ¦¸¶´Ù ´Ù¸¦ ¼ö ÀÖ´Ù. ping °ú traceroute À¯Æ¿¸®Æ¼´Â TTL °ªÀ» »ç¿ëÇÏ´Â ´ëÇ¥ÀûÀÎ ÇÁ·Î±×·¥Àε¥ »ç ¿ëÀÚ°¡ TTL °ªÀ» Á¶Á¤ÇÒ ¼ö ÀÖÀ¸¸ç traceroute ´Â TTL ±âº»°ªÀ» 30 À¸·Î ³·Ãß ¾î ÆÐŶÀ» Àü¼ÛÇÑ´Ù. ¸ÖƼij½ºÆÃ¿¡¼­´Â TTL °ªÀÌ ÆÐŶÀÌ Àü´ÞµÇ¾î¾ß ÇÏ´Â ¹üÀ§³ª ±¸¿ªÀ» °¡¸®Å²´Ù. 0 Àº °°Àº È£½ºÆ®·Î Á¦ÇѵȴÙ. 1 Àº °°Àº ¼­ºê³ÝÀ¸·Î Á¦ÇѵȴÙ. 32 ´Â °°Àº »çÀÌÆ®·Î Á¦ÇѵȴÙ. 64 ´Â °°Àº Áö¿ªÀ¸·Î Á¦ÇѵȴÙ. 128 Àº °°Àº ´ë·úÀ¸·Î Á¦ÇѵȴÙ. ip_no_pmtu_disc - 01 ¿¬»ê MTU discorery °æ·Î¸¦ »ç¿ë¾ÈÇÔ ±âº»°ª FALSE (»ç¿ëÇÔÀ» ÀǹÌ) MTU (Maximum Transmission Unit) ´Â ÇÁ·¹ÀÓÀ̳ª ÆÐŶÀÌ Çѹø¿¡ Çϳª ¾¿ Àü¼Û µÉ ¶§ Åë°úÇÒ ¼ö ÀÖ´Â Å©±â·Î ÇÁ·ÎÅäÄݸ¶´Ù ±× Å©±â°¡ ´Ù¸£´Ù. ¿¹¸¦µé¾î ÀÌ´õ ³Ý¿¡¼­´Â 1500 ÀÌÁö¸¸, X.25 ¿¡¼­´Â 576 ÀÌ´Ù. Path MTU ´Â µÎ È£½ºÆ®»çÀÌ °æ ·Î (path) ¿¡¼­ °¡Àå ÀÛÀº MTU °ªÀÌ´Ù. È£½ºÆ®°¡ °°´õ¶óµµ ¶ó¿ìÆÃ °æ·Î³ª ÇÁ·ÎÅäÄÝÀº ¸Å¹ø ¹Ù²î¹Ç·Î, MTU °ªµµ °è¼Ó ´Þ¶óÁö°Ô µÈ´Ù. ÇöÀç ÆÐŶº¸´Ù ÀÛÀº MTU °ªÀ» °¡Áø ¶ó¿ìÅ͸¦ Åë°úÇÒ ¶§, ÆÐŶ Àº ±× ¶ó¿ìÅÍ MTU ¿¡ ¸ÂÃç Àß°Ô Âɰ³Áø´Ù. ¼ö½ÅÇϴ ȣ½ºÆ®¿¡¼­´Â ±×·¸°Ô ÂÉ °³Áø Á¶°¢µéÀ» ¸ðµÎ ¹Þ¾Æ¼­ ´Ù½Ã ÀçÁ¶¸³Çϴµ¥, ±× °¡¿îµ¥ ÇÑÁ¶°¢ÀÌ¶óµµ µå·Ó µÇ¸é ¸ðµç Á¶°¢À» ´Ù½Ã Àü¼Û¹Þ¾Æ¾ß ÇÑ´Ù. ÀÌ °æ¿ì, ¶ó¿ìÅÍ´Â Á¶°¢À» ³ª´©´À¶ó ¹Ù»Ú°í, È£½ºÆ®´Â ÀçÁ¶¸³ÇÏ´À¶ó ¹ÙºüÁö¸ç, ÀçÀü¼ÛÀÌ ¸¹¾ÆÁö´Â µî ÆÛÆ÷¸Õ½º¸¦ ¶³¾îÆ®¸®°Ô µÈ´Ù. ÀÌ·² ¶§ pmtu discovery ¸¦ »ç¿ëÇÑ´Ù. ¸ÕÀú ÆÐŶ ¹ß¼Û ½Ã, Çì´õ¿¡ DF (Don't Fragment) ºñÆ®¸¦ ¼³Á¤Çؼ­ Á¶°¢³»Áö ¸»¶ó°í ¾Ë¸°´Ù. DF ºñÆ®°¡ ¼³Á¤µÈ ÆÐŶ À» ¹ÞÀº ¶ó¿ìÅÍ´Â ÀÚ½ÅÀÇ MTU º¸´Ù Å« °æ¿ì Á¶°¢È­ÇÏ´Â ´ë½Å, Can't Fragment ¿¡·¯¿Í MTU °ªÀ» µ¹·Áº¸³½´Ù. ±× °ªÀ» µ¹·Á¹Þ´Â È£½ºÆ®°¡ ¶ó¿ìÅÍÀÇ MTU °ª¿¡ ¸ÂÃß¾î ÆÐŶÀ» ´Ù½Ã Àü¼ÛÇÑ´Ù. Á¶°¢³ª´Â °ÍÀ» ÇÇÇϸ鼭, °¡Àå Å« ÆÐŶÀ» º¸³» ±â À§ÇØ pmtu discovery¸¦ »ç¿ëÇÏ´Â °ÍÀÌ´Ù. ´Ü, ÀÌ ±â´ÉÀ» »ç¿ëÇϱâ À§Çؼ­´Â ICMP ¸Þ½ÃÁö ŸÀÔ 3 °¡¿îµ¥ code 4 (Fragmentation Needed and Don't fragment)¸¦ Çã¿ëÇØ¾ßÇÑ´Ù. IP Fragmentation: ipfrag_high_thresh - Á¤¼ö Maximum memory ´Â IP Á¶°¢µéÀ» ÀçÁ¶ÇÕÀ» ÇÑ´Ù. ¸Þ¸ð¸®ÀÇ ipfrag_high_thresh byte°¡ À̰á°ú¸¦ ÅëÇØ ÀçÇÒ´ç µÈ´Ù¸é, fragment handler´Â ipfrag_low_thresh °¡ µµ´ÞÇϱâ Àü¿¡ ÆÐŶµéÀ» Àü´ÞÀ» ÇÒ°ÍÀÌ´Ù. ipfrag_low_thresh - Á¤¼ö ipfrag_high_thresh ¸¦ Âü°íÇ϶ó ipfrag_time - Á¤¼ö ¸Þ¸ð¸®¿¡¼­ IP fragment ¸¦ À¯ÁöÇÏ´Â ½Ã°£ (ÃÊ´ÜÀ§) INET peer storage: inet_peer_threshold - Á¤¼ö ½ºÅ丮ÁöÀÇ ´ë·«ÀûÀÎ Å©±âÀÌ´Ù. ÀÌ threshold¸ñ·Ïµé·Î ºÎÅÍ ½ÃÀÛÇÏ´Â °ÍÀº ħ ÀÔÀÇ ¿ä¼Ò¸¦ ¾È°Ô µÉ °ÍÀÌ´Ù. ÀÌ threshold ´Â garbage collection passes »ç ÀÌ¿¡¼­ ¸ñ·ÏµéÀÇ time-to-live ¿Í time intervals¸¦ ÇÑÁ¤À» ÇÑ´Ù. ¶Ç ´Ù¸¥ Á¤ º¸¸¦ ¾ò°í ½Í´Ù¸é less time-to-live ³ª less GC interval À» Ç϶ó. inet_peer_minttl - Á¤¼ö Minimum time-to-live of entries. Should be enough to cover fragment time-to-live on the reassembling side. This minimum time-to-live is guaranteed if the pool size is less than inet_peer_threshold. Measured in jiffies. inet_peer_maxttl - Á¤¼ö Maximum time-to-live of entries. Unused entries will expire after this period of time if there is no memory pressure on the pool (i.e. when the number of entries in the pool is very small). Measured in jiffies. inet_peer_gc_mintime - Á¤¼ö Minimum interval between garbage collection passes. This interval is in effect under high memory pressure on the pool. Measured in jiffies. inet_peer_gc_maxtime - Á¤¼ö Minimum interval between garbage collection passes. This interval is in effect under low (or absent) memory pressure on the pool. Measured in jiffies. TCP variables: tcp_syn_retries - Á¤¼ö Ȱ¼ºÈ­µÈ TCP Á¢¼ÓÀÌ ÀçÀü¼ÛÀ» ½ÃµµÇÏ°Ô Çϱâ À§ÇÑ ÃÖÃÊ SYN½Ã°£ÀÇ °ªÀ» Á¤ÇÑ ´Ù. 255 º¸´Ù ³ô¾Æ¼­´Â ¾ÈµÈ´Ù. ±âº»°ªÀº 5À̸ç, 180 ÃÊ¿¡ ´ëÀÀÀÌ µÈ´Ù. tcp_synack_retries - Á¤¼ö passive TCP Á¢¼Ó ½Ãµµ°¡ ÀçÁ¢¼ÓÀ» Çϱâ À§ÇÑ SYNACKsÀÇ °ªÀ» Á¤ÇÑ´Ù. 255 º¸ ´Ù ³ô°Ô ÁöÁ¤ÇÒ ¼ö ¾ø´Ù. ±âº»°ªÀº 5À̸ç, 180ÃÊ¿¡ ´ëÀÀÀÌ µÈ´Ù. tcp_keepalive_time - Á¤¼ö keepalive °¡ Ȱ¼ºµÇ µÇ¾î ÀÖÀ» °æ¿ì ¾ó¸¶³ª ÀÚÁÖ TCP °¡ keepalive ¸Þ¼¼Áö¸¦ º¸³»°Ô ÇÒ °ÍÀÎÁö¸¦ ¼³Á¤. ±âº»°ªÀº 2½Ã°£ ÀÌ´Ù. KEEPALIVE ½Ã°£À» ÁÙÀÌ¸é ºñÁ¤»óÀûÀ¸·Î stable µÈ Á¢¼ÓÀ» ÇØÁ¦ÇÏ´Â ½Ã°£À» ÁÙ Àϼö ÀÖÀ½. tcp_keepalive_probes - Á¤¼ö Á¢¼ÓÀÌ ²÷¾îÁö´Â °ÍÀ» °áÁ¤Çϱâ Àü±îÁö keepalive °¡ TCP send out À» ¾ó¸¶³ª »ìÇÇ°Ô ÇÒÁö ÁöÁ¤ÇÑ´Ù. ±âº»°ªÀº 9 ÀÌ´Ù. tcp_keepalive_intvl - Á¤¼ö ¾ó¸¶³ª ÀÚÁÖ send out À» üũÇÒÁö¸¦ Á¤ÇÑ´Ù. tcp_keepalive_probes ¿¡ ÀÇÇØ Áõ°¡µÇ¾îÁø probes ´Â probes °¡ ½ÃÀÛµÈ ÈÄ¿¡´Â responding connection À» Á× Àϼö ¾ø´Ù. ±âº»°ªÀº 75ÃÊ ÀÌ´Ù. ±âº» °ªÀÇ »ç¿ë½Ã 11ºÐ 15ÃÊ ÈÄ¿¡ ¿¬°áÀÌ ÇØ Á¦µÈ °ÍÀ¸·Î °£ÁÖ µÈ´Ù. tcp_retries1 - Á¤¼ö ¹«¾ð°¡ À߸øµÇ¾úÀ» °æ¿ì, network layer ·Î ÀÌ Çö»óÀ» reporting ÇϱâÀü ´Ù½Ã È®ÀÎÀ» Çϱâ À§ÇÑ È½¼ö¸¦ ÁöÁ¤ÇÑ´Ù. ÃÖ¼Ò RPC °ªÀº 3 À̸ç, ÀÌ´Â RTO»ó¿¡¼­ 3 ÃÊ¿¡¼­ 8ºÐ »çÀÌ¿¡ ÀÀ´äÀ» Çϵµ·Ï ÇÏ´Â °ÍÀÌ ±âº»°ªÀÌ´Ù. tcp_retries2 - Á¤¼ö »ì¾ÆÀÖ´Â TCP ¿¬°áÀ» ²÷±â Àü¿¡ È®ÀÎÇϴ Ƚ¼ö¸¦ Á¤ÇÑ´Ù. RFC1122 ´Â 100Ãʺ¸ ´Ù ±æ°Ô Á¦ÇÑÇ϶ó ÇÏÁö¸¸ ³Ê¹« ÀÛÀº °ªÀÌ´Ù. ±âº»°ªÀº 15·Î RTO 13-30ºÐ¿¡ ÇØ ´çÇÑ´Ù. tcp_orphan_retries - Á¤¼ö ¿ì¸® ÂÊ¿¡¼­ ´ÝÀº TCP ¿¬°áÀ» ²÷±â Àü¿¡ È®ÀÎÇϴ Ƚ¼ö¸¦ Á¤ÇÑ´Ù. ±âº»°ªÀº 7 ·Î RTO 50 ÃÊ¿¡¼­ 16 ºÐ »çÀÌ¿¡ ÇØ´çÇÑ´Ù. À¥ ¼­¹ö°¡ ¿î¿µ Áß À̶ó¸é ÀÌ °ªÀ» ÁÙ¿©¼­ ¼ÒÄÏ µîÀÌ ±ÍÇÑ ¸®¼Ò½º¸¦ ¼ÒºñÇÏÁö ¾Êµµ·Ï ÇÒ ¼öµµ ÀÖ´Ù. tcp_fin_timeout - Á¤¼ö ¼­¹ö¿¡ ÀÇÇØ ´ÝÇôÁú¶§ FIN_WAIT-2 »óÅÂÀÇ ¼ÒÄÏÀ» À¯Áö ½Ãų ½Ã°£À» ÁöÁ¤ÇÑ´Ù. peer´Â ÆÄ±«µÉ¼ö ÀÖÁö¸¸ °áÄÚ ½º½º·Î ´ÝÁö´Â ¾Ê°Å³ª, ¿¡»óÄ¡ ¸øÇÏ°Ô Á×À»¼ö´Â ÀÖ´Ù. ±âº»°ª 60ÃÊ ÀÌ´Ù. º¸Åë Ä¿³Î 2.2 ¿¡¼­´Â 180 Ãʸ¦ »ç¿ë ÇÏÁö¸¸ ¼öÁ¤À» ÇÒ¼ö´Â ÀÖ´Ù. ÇÏÁö¸¸ ½Ã½ºÅÛÀÌ À¥¼­¹öÀÇ ¿ëµµ¶ó¸é ¼ö¸¹Àº Á×Àº ¼ÒÄϵé·Î ÀÎÇØ ¸Þ¸ð¸®°¡ ÆøÁÖÇÒ À§Çèµµ ÀÖ´Ù. FIN-WAIT-2 ¼ÒÄϵéÀº ÃÖ°í 1.5K Á¤µµÀÇ ¸Þ¸ð¸® ¸¦ »ç¿ëÇϱ⠶§¹®¿¡ FIN_WAIT-1 º¸´Ù ´ú À§Çè ÇÏÁö¸¸ tcp_max_orphans °ªº¸´Ù ´õ ¿À·¡ À¯ÁöµÇ·Á´Â °æÇâÀÌ ÀÖ´Ù. FIN_TIMEOUT ´ë±â ½Ã°£À» ÁÙÀÌ¸é ²÷¾îÁø ¼ÒÄÏÀÇ ¼Ò°Å ½Ã°£À» ÁÙÀÏ ¼ö ÀÖÀ½. tcp_max_tw_buckets - Á¤¼ö µ¿½Ã¿¡ À¯Áö °¡´ÉÇÑ timewait ¼ÒÄÏÀÇ ¼ö. ÁöÁ¤ ¼ýÀÚ¸¦ ÃʰúÇÒ °æ¿ì, timewait ¼ÒÄÏÀÌ ¾ø´Ù´Â °æ°í ¸Þ¼¼Áö Ãâ·ÂÇÑ´Ù. ÀÌ Á¦ÇÑÀº ´Ü¼øÇÑ DoS °ø°ÝÀ» ¹æ¾îÇϱâ À§Çؼ­¸¸ ÇÊ¿äÇϸç, ±âº»°ªº¸´Ù ÀÛ°ÔÇØ¼­´Â Àý´ë ¾ÈµÈ´Ù. ³×Æ®¿öÅ© ȯ°æÀÌ ±â º»°ªº¸´Ù Å« °ªÀ» ¿ä±¸ÇÑ´Ù¸é ´Ã·Áµµ µÈ´Ù. º¸Åë ·¥ 64M ´ç 180000 À¸·Î °è»ê À» ÇÏ¸é µÈ´Ù. tcp_tw_recycle - 01 ¿¬»ê ºü¸¥ Àç»ý TIME-WAIT ¼ÒÄÏÀ» »ç¿ëÇÑ´Ù. ±âº»°ªÀº 1ÀÌ´Ù. Àü¹®°¡ÀÇ Á¶¾ð / ¿ä ûÀÌ ¾ø´Ù¸é Àý´ë ¹Ù²ÙÁö ¸¶¶ó. tcp_tw_reuse - 01 ¿¬»ê ÇÁ·ÎÅäÄÝ °üÁ¡¿¡¼­ ¾ÈÀüÇÏ´Ù°í ÆÇ´ÜµÉ ¶§ »õ·Î¿î ¿¬°á¿¡ ´ëÇÏ¿© TIME-WAIT ¼Ò ÄÏÀ» Àç»ç¿ëÇÏ´Â °ÍÀ» Çã¶ôÇÑ´Ù. ±âº»°ªÀº 0 ÀÌ´Ù. ÀÌ °ªÀº ±â¼ú Àü¹®°¡ÀÇ Á¶ ¾ðÀ̳ª ¿äûÀÌ ¾øÀÌ º¯°æÇÏÁö ¾Ê´Â °ÍÀÌ ÁÁ´Ù. tcp_max_orphans - Á¤¼ö ½Ã½ºÅÛ¿¡ °íÁ¤ µÇ¾ú°Å³ª, »ç¿ëÀÚ ÆÄÀÏ Çڵ鿡 ¿¬°áµÇÁö ¾ÊÀº TCP ¼ÒÄÏÀÇ ÃÖ´ë °ªÀ» ÁöÁ¤ÇÑ´Ù. °í¾Æ ¿¬°áÀÌ ÀÌ °ªÀ» ÃʰúÇϸé, Áï½Ã ¸®¼ÂµÇ°í °æ°í¸¦ Ãâ·ÂÇÑ ´Ù. ÀÌ Á¦ÇÑÀº ´Ü¼øÇÑ DoS °ø°ÝÀ» ¹æ¾îÇϱâ À§Çؼ­¸¸ ÇÊ¿äÇϸç, ±âº» °ªº¸´Ù ÀÛ°ÔÇØ¼­´Â Àý´ë ¾ÈµÈ´Ù. ³×Æ®¿öÅ© ȯ°æÀÌ ±âº»°ªº¸´Ù Å« °ªÀ» ¿ä±¸Çϰųª ¿À ·¡ ¹öÅß¼­ ±×·± ¹®Á¦µéÀº ´õ °ø°ÝÀûÀ¸·Î Á×À̱â À§ÇØ ³×Æ®¿öÅ©¸¦ Á¶À² ÇÑ´Ù¸é ´Ã·Áµµ µÈ´Ù (¾Æ¸¶, ¼³Ä¡µÈ ¸Þ¸ð¸®¸¦ Áõ¼³ÇÑ ´ÙÀ½) Çѹø ´õ ´çºÎÇÏÀÚ¸é: °í¾Æ ¿¬°áµéÀº ½º¿ÒÇÒ ¼ö ¾ø´Â ¸Þ¸ð¸®¸¦ °¢ÀÚ 64K ÀÌ»ó Â÷ÁöÇÏ°Ô µÈ´Ù.. tcp_abort_on_overflow - 01 ¿¬»ê ¸®½º´× ¼­ºñ½º°¡ »õ·Î¿î ¿¬°áÀ» ¼ö¶ôÇϱ⿡ ³Ê¹« ´À¸®´Ù¸é, ±× ¼­ºñ½º¸¦ ¸®¼Â ÇÑ´Ù. ±âº»°ªÀº FALSE ÀÌ´Ù. ÀÌ °ÍÀº °©Àڱ⠿À¹öÇ÷ΰ¡ ¹ß»ýÇÏ´õ¶óµµ ¿¬°áÀÌ º¹±¸µÈ´Ù´Â ¶æÀÌ´Ù. ¸®½º´× µ¥¸ðÀÌ ¿¬°áÀ» ´õ »¡¸® ¼ö¶ôÇϵµ·Ï ÀÚ¸®ÀâÁö ¸øÇÏ ´Â°Ô Á¤¸» È®½ÇÇÒ ¶§¿¡¸¸ ÀÌ ¿É¼ÇÀ» Ȱ¼ºÈ­ ÇÑ´Ù. ÀÌ ¿É¼ÇÀ» Ȱ¼ºÈ­ÇÏ¸é ¼­¹ö ¿¡¼­ ¼Õ»óµÈ Ŭ¶óÀÌ¾ðÆ®¶óµµ ¸®½¼ ÇÏ°Ô µÈ´Ù. tcp_syncookies - 01 ¿¬»ê kernel À» CONFIG_SYNCOOKIES ¸¦ ¼³Á¤ÇÏ¿© »ý¼ºÀ» ÇÏ¿´À» ¶§¸¸ »ç¿ëÀÌ À¯È¿ÇÏ ´Ù. ¼ÒÄÏÀ¸·Î syn backlog queue °¡ ³ÑÄ¥¶§ syncookies ¸¦ º¸³½´Ù. À̰ÍÀº ÀÏ ¹ÝÀûÀÎ 'syn flood attack' À̶ó´Â °ø°ÝÀ» ¹æ¾î Çϱâ À§ÇØ »ç¿ëÀÌ µÈ´Ù. ±âº» °ªÀº FALSE ÀÌ´Ù. syncookies ´Â ´ëü ¹æ¹ýÀÏ »Ó À̶ó´Â °ÍÀ» ¸í½É ÇØ¾ß ÇÑ´Ù. À̰ÍÀº Á¤»óÀûÀÎ Á¢¼Ó¿¡ ´ëÇØ ´õ ÁÁÀº ¼º´ÉÀ» ³»°ÔÇÏ´Â °Í¿¡ »ç¿ëÀÌ µÇ´Â°ÍÀº ¾Æ´Ï´Ù. ¸¸¾à ·Î ±×¿¡¼­ synflood °æ°í¸¦ º¸°Ô µÈ´Ù¸é, ÇÏÁö¸¸ À̰͵éÀÌ Á¤»óÀûÀÎ Á¢¼ÓµéÀÌ ³Ñ Ãļ­ ¹ß»ýÇÑ °ÍµéÀ̶ó¸é ÀÌ °æ°í°¡ »ç¶óÁö±â Àü¿¡ tcp_syncookies °¡ ¾Æ´Ñ ´Ù ¸¥ ÆÄ¶ó¹ÌÅ͵éÀ» Á¶ÀýÇØ¾ß ÇÑ´Ù. tcp_max_syn_backlog, tcp_synack_retries, tcp_abort_on_overflow ¸¦ Âü°í¸¦ Ç϶ó. syncookies ´Â TCP ÇÁ·ÎÅäÄÝ¿¡ ½É°¢ÇÏ°Ô ¾î±ß³ª¸ç, TCP È®ÀÞµéÀ» »ç¿ëÇÏ´Â °Í À» Çã¶ôÇÏÁö ¾ÊÀ¸¸ç, (SMTP relaying °°Àº) ƯÁ¤¼­ºñ½ºµéÀÇ ½É°¢ÇÑ ¼Õ»óÀÇ °á °ú°¡ µÉ¼öÀÖ´Ù. ¸¸¾à ½ÇÁ¦ ³ÑÄ¡Áö ¾ÊÀ½¿¡µµ ºÒ±¸ÇÏ°í ·Î±×¿¡ synflood °æ°í°¡ °è¼Ó ¹ß»ýÇÑ´Ù¸é, ¼­¹öÀÇ ¼³Á¤ÀÌ ½É°¢ÇÏ°Ô À߸øµÇ¾î ÀÖ´Â °ÍÀÌ´Ù. tcp_stdurg - 01 ¿¬»ê TCP urg Æ÷ÀÎÅÍ Çʵå ÇØ¼®±â°¡ ÇÊ¿äÇÒ ¶§¿¡ »ç¿ëÇÑ´Ù. ´ëºÎºÐ ¿À·¡µÈ BSD ÇØ ¼®±â¸¦ »ç¿ëÇϴµ¥, ¸®´ª½º°¡ ±×·± °Íµé°ú Á¦´ë·Î ¼ÒÅëÇÏÁö ¸øÇÑ´Ù°í ÆÇ´ÜµÉ °æ¿ì Ȱ¼ºÈ­¸¦ ÇØ º¼¸¸ÇÏ´Ù. ±âº»°ªÀº FALSE ÀÌ´Ù. tcp_max_syn_backlog - Á¤¼ö Á¢¼ÓÇÑ client µé Áß ½ÂÀÎÀ» ¹ÞÁö ¸øÇÏ´Â Á¢¼Ó ¿äûµéÀÇ ÃÖ´ë°ªÀ» ÁöÁ¤ ÇÑ´Ù. ¸¸¾à ½ÂÀÎÀ» ¹ÞÁö ¸øÇÏ°í ±â´Ù¸®´Â Á¢¼Ó ¿äûµéÀÌ ÀÌ ¼ö¸¦ ¹þ¾î³ª´Â °æ¿ì¿¡´Â "´Ù½Ã ÀçÁ¢¼ÓÀ» ÇØ º¸¶ó" ¶ó´Â ¸Þ¼¼Áö¸¦ ¹Þ°Ô µÈ´Ù. 128MbÀÇ ¸Þ¸ð¸®¿¡¼­´Â ±â º»°ªÀ¸·Î 1024¸¦ »ç¿ëÇÒ¼ö ÀÖÀ¸¸ç, À̺¸´Ù ÀûÀº ¸Þ¸ð¸®¸¦ °¡Áö°í ÀÖÀ» °æ¿ì¿¡ ´Â 128 À» »ç¿ëÇϱ⸦ ±ÇÀå ÇÑ´Ù. ¸¸¾à ¼­¹ö¿¡ ºÎÇϰ¡ ¸¹ÀÌ °É¸®°Ô µÈ´Ù¸é ÀÌ °ªÀ» Áõ°¡ÇØ º¸±â ¹Ù¶õ´Ù. tcp_window_scaling - 01 ¿¬»ê RFC1323 ¿¡ Á¤ÀÇµÈ window scaling À» °¡´ÉÇÏ°Ô ÇÑ´Ù. tcp_timestamps - 01 ¿¬»ê RFC1323 ¿¡ Á¤ÀÇµÈ timestamp µéÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù. tcp_sack - 01 ¿¬»ê SYN ÆÐŶÀ» Àü¼ÛÇÑ ÈÄ¿¡, ·Î½º°¡ ¹ß»ýÀ» ÇÏ¿© ACK ¸¦ ÀϺΠ¹ÞÁö ¸øÇßÀ» °æ¿ì, ¼±ÅÃÀûÀ¸·Î (selected) ¹ÞÁö ¸øÇÑ ACK ¸¸ ¹Þµµ·Ï ¿äûÇÏ´Â °ÍÀ» Çã¶ôÇÑ´Ù. ·Î ½º°¡ ¸¹Àº ³×Æ®¿öÅ©¿¡¼­´Â »ó´çÈ÷ Áß¿äÇÑ ¿ªÇÒÀ» ÇÑ´Ù. tcp_fack - 01 ¿¬»ê FACK ¹ÐÁý ȸÇÇ¿Í ºü¸¥ ÀçÀü¼ÛÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù. tcp_sack ÀÌ È°¼ºÈ­°¡ µÇ¾î ÀÖÁö ¾ÊÀ¸¸é ÀÌ °ªÀº »ç¿ëµÇÁö ¾Ê´Â´Ù. tcp_dsack - 01 ¿¬»ê TCP°¡ Áߺ¹µÈ SACK µéÀ» º¸³»´Â °ÍÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù. tcp_ecn - 01 ¿¬»ê TCP ¿¡ ¸í¹éÇÑ È¥Àâ °øÁö(Explicit Congestion Notification) ¸¦ °¡´ÉÇÏ°Ô ÇÑ ´Ù. tcp_reordering - Á¤¼ö TCP stream ¿¡ ÆÐŶµéÀÇ ÃÖ´ë Àç ¿äûÀ» ¼³Á¤. ±âº»°ª: 3 tcp_retrans_collapse - 01 ¿¬»ê ¸Á°¡Áø ÇÁ¸°ÅÍ¿¡ Bug-to-bug ȣȯ. ´õ Å« ÆÐŶÀ» ÀçÀü¼ÛÇØ¼­ ¾î¶² TCP ½ºÅÿ¡ ÀÖ´Â ¹ö±×¸¦ ÇÇÇØ°£´Ù. tcp_wmem - vector of 3 INTEGERs: min, default, max min: TCP ¼ÒÄÏ¿¡¼­ send buffer ¿¡ ÇÒ´çµÉ ¸Þ¸ð¸® ¾ç. °¢ TCP ¼ÒÄϵéÀº ¿¬°á ÀÌ À¯ÁöµÈ »óÅ¿¡¼­´Â ÀÌ ¸Þ¸ð¸®¸¦ »ç¿ëÇÑ ±ÇÇÑÀ» °¡Áö°Ô µÈ´Ù. ±âº»°ªÀº 4K default: TCP ¼ÒÄÏ¿¡¼­ ±âº»À¸·Î ÇÒ´çÀÌ µÇ´Â send ¹öÆÛÀÇ ¸Þ¸ð¸® ¾ç. À̰ªÀº ´Ù¸¥ ÇÁ·ÎÅäÄÝ¿¡¼­ ÀÇÇØ »ç¿ëµÇ´Â net.core.wmem_default °ª º¸´Ù ¿ì¼± ÇÑ´Ù. ±âº»°ªÀº 16K max: TCP ¼ÒÄÏ¿¡¼­ ÀÚµ¿À¸·Î ¼±ÅÃµÈ send ¹öÆÛ¸¦ À§ÇÑ ÃÖ´ë ¸Þ¸ð¸® Å©±â. ÀÌ °ªº¸´Ù net.core.wmem_max °ªÀÌ ¿ì¼±ÇÑ´Ù. ±âº»°ªÀº 128K tcp_rmem - vector of 3 INTEGERs: min, default, max min: TCP ¼ÒÄÏ¿¡¼­ receive buffer ¿¡ ÇÒ´çµÉ ¸Þ¸ð¸® ¾ç. °¢ TCP ¼ÒÄϵéÀº ¿¬ °áÀÌ À¯ÁöµÈ »óÅ¿¡¼­´Â ÀÌ ¸Þ¸ð¸®¸¦ »ç¿ëÇÒ ±ÇÇÑÀ» °¡Áö°Ô µÈ´Ù. ±âº»°ªÀº 8K default: TCP ¼ÒÄÏ¿¡¼­ »ç¿ëµÇ¾î Áö´Â receive buffer ÀÇ ±âº»°ª. ÀÌ °ªÀº ´Ù ¸¥ ÇÁ·ÎÅäÄÝ¿¡ ÀÇÇØ »ç¿ëµÇ´Â net.core.rmem_default °ª º¸´Ù ¿ì¼±ÇÑ´Ù. ±âº» °ªÀº 87380 byte ÀÌ´Ù. ÀÌ °ªÀº tcp_adv_win_Scale ÀÇ ±âº» ¼³Á¤°ú tcp_app_win:0 °ú ±âº» tcp_app_win À» À§ÇÑ bit less ¿Í ÇÔ²² 65535 ÀÇ window ¸¦ °¡Áö°ÔµÈ ´Ù. max: TCP ¼ÒÄÏ¿¡ ´ëÇÏ¿©, ÀÚµ¿ÀûÀ¸·Î ÃÖ´ëÇÑ »ç¿ëÇÒ ¼ö ÀÖ´Â receive buffer ÀÇ ÃÖ´ëÅ©±â ÀÌ °ªÀº net.core.rmem_max ÀÇ °ªÀ» µ¤¾î¾²Áö ¸øÇϸç, SO_RCVBUF ¸¦ ÅëÇÑ "Á¤Àû"ÀÎ ¿¬°áÀº ÀÌ °ªÀ» »ç¿ëÇÏÁö ¾Ê´Â´Ù. ±âº»°ªÀº 87380*2 byte. tcp_mem - vector of 3 INTEGERs: min, pressure, max low: below this number of pages TCP is not bothered about its memory appetite. pressure: when amount of memory allocated by TCP exceeds this number of pages, TCP moderates its memory consumption and enters memory pressure mode, which is exited when memory consumtion falls under "low". high: number of pages allowed for queueing by all TCP sockets. Defaults are calculated at boot time from amount of available memory. tcp_app_win - Á¤¼ö Reserve max(window/2^tcp_app_win, mss) of window for application buffer. Value 0 is special, it means that nothing is reserved. ±âº»°ª: 31 tcp_adv_win_scale - Á¤¼ö Count buffering overhead as bytes/2^tcp_adv_win_scale (if tcp_adv_win_scale > 0) or bytes-bytes/2^(-tcp_adv_win_scale), if it is <= 0. ±âº»°ª: 2 tcp_rfc1337 - BOOLEAN ¼¼ÆÃµÇ¸é TCP ½ºÅÃÀº RFC1337À» µû¸¥´Ù. ÇØÁ¦µÇ¸é RFC¸¦ µû¸£Áö ¾ÊÁö¸¸ TCP TIME_WAIT asassinationÀº ¸·¾ÆÁØ´Ù. Ŭ¶óÀ̾ðÆ®ÀÇ ¼ÒÄÏÀ¸·Î ºÎÅÍ RST¸¦ ¹Þ¾Æ TIME_WAIT »óÅ·Π°¡´Â °æ¿ì Áï½Ã ¼Ò ÄÏÀ» Á¾·á ½ÃÅ´. À¥¼­¹ö¿Í °°Àº À¯ÇüÀÇ ¼­¹ö¿¡¼­´Â ¼ÒÄÏÀ» ¿­°í ´Ý´Â ȸ¼ö°¡ ¸¹À¸¹Ç·Î, ÀÌ ¼³Á¤À» ÀûÀýÇÏ°Ô ¼³Á¤ÇÏ¿© »ç¿ëÇÏ´Â °ÍÀÌ ÁÁÀ½. ¶Ç´Â net.ipv4.tcp_max_tw_buckets °ªÀ» ÁÙÀÌ´Â °ÍÀ¸·Îµµ °¡´ÉÇÔ ±âº»°ª: 0 tcp_low_latency - BOOLEAN If set, the TCP stack makes decisions that prefer lower latency as opposed to higher throughput. By default, this option is not set meaning that higher throughput is preferred. An example of an application where this default should be changed would be a Beowulf compute cluster. ±âº»°ª: 0 ip_local_port_range - 2 Á¤¼ö°ª TCP ¿Í UDP ¿¡ ÀÇÇØ »ç¿ëµÉ local Æ÷Æ® ¹üÀ§¸¦ Á¤ÀÇÇÑ´Ù. ù¹øÂ° ¼ýÀÚ´Â »ç¿ë ÇÒ ¿µ¿ªÀÇ °¡Àå ¾ÕºÎºÐ Æ÷Æ® ¹øÈ£¸¦ ÁöÁ¤ÇÏ°í µÎ¹øÂ°´Â ¸¶Áö¸· Æ÷Æ®¹øÈ£¸¦ Áö Á¤ÇÑ´Ù. ±âº»°ªÀº ½Ã½ºÅÛÀÇ »ç¿ë°¡´ÉÇÑ ¸Þ¸ð¸®ÀÇ ¾ç¿¡ ÀÇÇØ °áÁ¤ÀÌ µÈ´Ù: ¸Þ¸ð¸®°¡ 128Mb º¸´Ù ¸¹À» °æ¿ì 32768-61000 ¸Þ¸ð¸®°¡ 128Mb º¸´Ù ÀûÀ» °æ¿ì 1024-4999 ¶Ç´Â À̺¸´Ù Àû°Ô.. ÀÌ °ªÀº TCP È®ÀåÀ» Áö¿øÇÏÁö ¾Ê´Â ½Ã½ºÅÛÀ¸·Î µ¿½Ã¿¡ ¹ß»ýÀÌ µÉ¼ö Àִ Ȱ¼º È­µÈ Á¢¼ÓµéÀÇ ¼ö¸¦ °áÁ¤ÇÑ´Ù. tcp_tw_recycle À» °¡´ÉÇÏ°Ô ÇÔÀ¸·Î¼­ (±âº»Àû À¸·Î) 1024-4999 ¿µ¿ªÀº timestamps¸¦ Áö¿øÇÏ´Â ½Ã½ºÅ۵鿡 ÃÊ´ç 2000°³ÀÇ Á¢ ¼Ó Á¤µµ¸¦ °¡´ÉÇÏ°Ô ÇÏ ´Âµ¥ ÃæºÐÇÏ´Ù. Á¤È®Ä¡´Â ¾ÊÁö¸¸ 2.4.20 ÀÌ ÈÄ ºÎÅÍ´Â Ä¿³Î¿¡¼­ ÀÚµ¿À¸·Î °¨Áö¸¦ ÇÏ¿© ÀâÀ¸¹Ç ·Î ½Å°æÀ» ¾²Áö ¾Ê¾Æµµ »ó°üÀÌ ¾ø´Ù. ip_nonlocal_bind - BOOLEAN ¼¼ÆÃµÇ¸é ÇÁ·Î¼¼½º°¡ ·ÎÄà IP °¡ ¾Æ´Ñ ÁÖ¼Ò¿¡ bind() ÇÒ¼ö ÀÖ´Ù. ¸Å¿ì À¯¿ëÇÑ ±â´ÉÀÌÁö¸¸ ¾î¶² ¾îÇø®ÄÉÀ̼ǿ¡¼­´Â ³ª»Ü ¼ö ÀÖ´Ù. ±âº»°ª: 0 ip_dynaddr - BOOLEAN 0 ÀÌ ¾Æ´Ñ °ªÀ» ¼¼ÆÃÇÏ¸é µ¿Àû ÁÖ¼Ò¸¦ (dynamic addresses) Áö¿øÇÑ´Ù. 1 º¸´Ù Å« °ªÀ» ¼¼ÆÃÇÏ¸é µ¿ÀûÁÖ¼Ò°¡ ´Ù½Ã ¾²¿©Áú ¶§¸¶´Ù ·Î±× ¸Þ½ÃÁö°¡ Ãâ·ÂµÉ °ÍÀÌ ´Ù. ±âº»°ª: 0 icmp_echo_ignore_all - 01 ¿¬»ê ÀÌ °ªÀ» 1 ·Î ÇÒ °æ¿ì kernel Àº ¸ðµç ICMP ECHO ¿äûÀ» ¹«½ÃÇØ ¹ö¸°´Ù. Áï ping ÀÌ ¾ÈµÇ°Ô ÇÑ´Ù. icmp_echo_ignore_broadcasts - 01 ¿¬»ê ¸¸¾à ¸ðµç ICMP ECHO ¿äûÀ» Ä¿³ÎÀÌ ¹«½ÃÇÏ°Ô Çϰųª, ICMP ECHO ¿äû Áß broadcast ¿Í multicast ÁÖ¼Ò¿¡¸¸ ¹«½ÃÇÏ°Ô ÇÒ¶§ 1ÀÇ °ªÀº ¹«½Ã, 0ÀÇ °ªÀº ¸® ÅÏÀ» ÇÏ°Ô µÈ´Ù. ¸¸¾à boardcast/multicast ÁÖ¼ÒÀÇ ICMP ECHO ¿äûÀ» ¼ö¿ëÇÏ °Ô ÇÑ´Ù¸é, network°¡ ´Ù¸¥È£½ºÆ®·Î denial of service(DOS) packet flooding °ø°ÝÀ» Çϴµ¥ ÀÌ¿ëÀÌ µÉ¼ö°¡ ÀÖ´Ù. icmp_ratelimit - Á¤¼ö ¾Æ·¡ÀÇ icmp_ratemask ¿¡ ÁöÁ¤µÈ BIT ¿Í ÀÏÄ¡Çϴ ŸÀÔÀÇ ICMP ÆÐŶÀ» º¸³»±â À§ÇÑ ÃÖ´ë ºóµµ¸¦ Á¦ÇÑÇÑ´Ù. 0 Àº Á¦ÇÑÀ» ¾ø¾Ö¸ç ±× ¹ÛÀÇ °ªÀº jiffies(1) ÀÇ ÃÖ´ë ºóµµ¸¦ ÀǹÌÇÑ´Ù. ±âº»°ª: 100 icmp_ratemask - Á¤¼ö Mask made of ICMP types for which rates are being limited. Significant bits: IHGFEDCBA9876543210 Default mask: 0000001100000011000 (6168) Bit Á¤ÀÇ (see include/linux/icmp.h): 0 Echo Reply 3 Destination Unreachable * 4 Source Quench * 5 Redirect 8 Echo Request B Time Exceeded * C Parameter Problem * D Timestamp Request E Timestamp Reply F Info Request G Info Reply H Address Mask Request I Address Mask Reply * These are rate limited by default (see default mask above) icmp_ignore_bogus_error_responses - 01 ¿¬»ê ¾î¶² router µéÀº broadcast frame µé·Î °ÅÁþ ÀÀ´äÀ» º¸³¿À¸·Î¼­ RFC 1122 ¸¦ À§¹ÝÇÑ´Ù. ÀÌ·¯ÇÑ À§ÇѵéÀº º¸Åë Ä¿³Î °æ°í¸¦ ÅëÇØ ·Î±ëÀÌ µÈ´Ù. À̰ÍÀ» TRUE ·Î ¼³Á¤À» ÇÒ°æ¿ì Ä¿³ÎÀº ÀÌ·¯ÇÑ °æ°í¸¦ ÇÏÁö ¾ÊÀ» °ÍÀ̸ç, ·Î±× ÆÄÀÏÀÌ ÁöÀú ºÐÇØ Áö´Â °ÍÀ» ÇÇÇÒ¼ö ÀÖ´Ù. ±âº»°ª: FALSE igmp_max_memberships - Á¤¼ö ¸ÖƼij½ºÆ® ±×·ì¿¡ Âü¿©ÇÒ ¼ö ÀÖ´Â ÃÖ´ë°ªÀ» º¯°æÇÑ´Ù. ±âº»°ª: 20 conf/interface/* changes special settings per interface (where "interface" is the name of your network interface) conf/all/* is special, changes the settings for all interfaces log_martians - 01 ¿¬»ê ºÒ°¡´ÉÇÑ ÁÖ¼ÒµéÀ» Áö´Ñ ÆÐŶÀ» kerenl log ¿¡ ±â·ÏÇÑ´Ù. IP soppfing packet À» üũÇϴµ¥ À¯¿ëÇÏ´Ù. Log packets with impossible addresses to kernel log. log_martians for the interface will be enabled if at least one of conf/{all,interface}/log_martians is set to TRUE, it will be disabled otherwise accept_redirects - 01 ¿¬»ê ICMP redirect message µéÀ» Çã¿ëÇÑ´Ù. ±âº»°ª TRUE (host) FALSE (router) Accept ICMP redirect messages. accept_redirects for the interface will be enabled if: - both conf/{all,interface}/accept_redirects are TRUE in the case forwarding for the interface is enabled or - at least one of conf/{all,interface}/accept_redirects is TRUE in the case forwarding for the interface is disabled accept_redirects for the interface will be disabled otherwise default TRUE (host) FALSE (router) forwarding - 01 ¿¬»ê ÀÌ interface ·Î IP forwarding À» °¡´ÉÇÏ°Ô ÇÑ´Ù. mc_forwarding - 01 ¿¬»ê multicast routingÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù. ÀÌ °ªÀ» »ç¿ëÇϱâ À§Çؼ­´Â Ä¿³Î config ¿¡¼­ CONFIG_MROUTE ¸¦ ¼³Á¤Çؼ­ ºôµå¸¦ ÇØ¾ß Çϸç, multicast routing ÀÌ °¡ ´ÉÇÑ µ¥¸óÀÌ ¿ä±¸µÇ¾î Áø´Ù. medium_id - Á¤¼ö Integer value used to differentiate the devices by the medium they are attached to. Two devices can have different id values when the broadcast packets are received only on one of them. The default value 0 means that the device is the only interface to its medium, value of -1 means that medium is not known. Currently, it is used to change the proxy_arp behavior: the proxy_arp feature is enabled for packets forwarded between two devices attached to different media. proxy_arp - 01 ¿¬»ê ÇÁ·Ï½Ã ARP´Â ÁöÁ¤ÇÑ ÀÎÅÍÆäÀ̽º¿Í ¿¬°áµÈ ´Ù¸¥ È£½ºÆ®ÀÇ ARP ÁÖ¼Ò¸¦ ´ë½Å »Ñ ·ÁÁÖ°í, ¹Þ´Â´Ù. Åõ¸íÇÏ°Ô µ¿ÀÛÇÏ´Â ³×Æ®¿öÅ© Àåºñ¿¡ ¹Ýµå½Ã ÇÊ¿äÇÏ´Ù. shared_media - 01 ¿¬»ê RFC1620 ¹Ìµð¾î °øÀ¯ ¸®´ÙÀÌ·ºÆ®¸¦ º¸³»°Å³ª (¶ó¿ìÅÍ) ¼ö¶ô (È£½ºÆ®)ÇÑ´Ù. ÀÌ ¿É¼Ç °ªÀÌ 0 À̸é ÇÑ ÀåÄ¡¿¡ ¼³Á¤µÈ ¼­·Î ´Ù¸¥ ¼­ºê³ÝÀ» Á÷Á¢ Åë½ÅÇÒ ¼ö ¾ø´Ù. ±âº»°ª: TRUE secure_redirects - 01 ¿¬»ê µðÆúÆ® °ÔÀÌÆ®¿þÀÌ ¸ñ·Ï¿¡ ¿Ã¶óÀÖ´Â °ÔÀÌÆ®¿þÀÌ¿¡¸¸ ICMP ¸®´ÙÀÌ·ºÆ® ¸Þ½ÃÁö¸¦ Çã¿ëÇÑ´Ù. ±âº»°ªÀº TRUE send_redirects - 01 ¿¬»ê router ·Î »ç¿ëÀÌ µÈ´Ù¸é redirect ¸¦ º¸³½´Ù. ±âº»°ªÀº TRUE ÀÌ´Ù. Accept ICMP redirect messages only for gateways, listed in default gateway list. secure_redirects for the interface will be enabled if at least one of conf/{all,interface}/secure_redirects is set to TRUE, it will be disabled otherwise default TRUE send_redirects - BOOLEAN Send redirects, if router. send_redirects for the interface will be enabled if at least one of conf/{all,interface}/send_redirects is set to TRUE, it will be disabled otherwise ±âº»°ª: TRUE bootp_relay - 01 ¿¬»ê Accept packets with source address 0.b.c.d destined not to this host as local ones. It is supposed, that BOOTP relay daemon will catch and forward such packets. default FALSE Not Implemented Yet. accept_source_route - 01 ¿¬»ê SRR ¿É¼ÇÀ¸·Î ÆÐŶµéÀ» ¼ö¿ëÇÑ´Ù. IP source routing À» Á¦¾îÇÑ´Ù. º¸Åë È£½º Æ®·Î ÇâÇÏ°Ô ÇÏ´Â °ÍÀ» ±ÇÀåÇÑ´Ù. ÀÌ °ªÀÌ ÂüÀÌ¸é ÆÐŶ °æ·Î¸¦ Ãâ¹ßÁö¿¡¼­ Á¶ ÀÛÀÌ °¡´ÉÇϹǷÎ, IP ½ºÇªÇο¡ ¾Ç¿ëµÉ ¼ÒÁö°¡ ÀÖ´Ù. ±âº»°ª TRUE (router) FALSE (host) rp_filter - 01 ¿¬»ê 1 - Áý¿¡¼­ »ç¿ëÇÏ´Â ½Ì±Û È£½ºÆ®³ª ¸î°³ÀÇ ¼­ºê³ÝÀ¸·Î ³ª´µ¾îÁø ³×Æ®¿öÅ© °° ÀÌ RFC1812¿¡ ÁöÁ¤µÇ¾îÁø ¿ª°æ·Î¿¡ ÀÇÇÑ ¼Ò½º À¯È¿¼ºÀ» üũÇÑ´Ù. ºÐ¼®ÇÏ ±â ¾î·Á¿î ³×Æ®¿öÅ©¿¡¼­ ´À¸®°í ½Å·ÚÇÒ ¼ö ¾ø´Â ÇÁ·ÎÅäÄÝ ¶Ç´Â Á¤ÀûÀÎ ³× Æ®¿öÅ©¸¦ ÅëÇØ ¹®Á¦¸¦ ¾ß±âÇÒ¼öµµ ÀÖ´Ù. º¸ÅëÀº IP spoofing À» ¹æÁöÇϱâ À§ÇØ ¸¹ÀÌ »ç¿ëÀ» ÇÑ´Ù. 0 - ¼Ò½º À¯È¿¼º üũ¸¦ ÇÏÁö ¾Ê´Â´Ù. conf/all/rp_filter must also be set to TRUE to do source validation on the interface ±âº»°ªÀº 0 ÀÌ´Ù. startip ½ºÅ©¸³Æ®¿¡¼­ À̸¦ °¡´ÉÇÏ°Ô ÇØ ³õÀº ¹èÆ÷ÆÇµµ ÀÖ À¸´Ï ÁÖÀÇÇØ¾ß ÇÑ´Ù. arp_filter - BOOLEAN 1 - Allows you to have multiple network interfaces on the same subnet, and have the ARPs for each interface be answered based on whether or not the kernel would route a packet from the ARP'd IP out that interface (therefore you must use source based routing for this to work). In other words it allows control of which cards (usually 1) will respond to an arp request. 0 - (default) The kernel can respond to arp requests with addresses from other interfaces. This may seem wrong but it usually makes sense, because it increases the chance of successful communication. IP addresses are owned by the complete host on Linux, not by particular interfaces. Only for more complex setups like load- balancing, does this behaviour cause problems. arp_filter for the interface will be enabled if at least one of conf/{all,interface}/arp_filter is set to TRUE, it will be disabled otherwise tag - Á¤¼ö Allows you to write a number, which can be used as required. Default value is 0. (1) Jiffie: Ä¿³ÎÀ» À§ÇÑ ³»ºÎ ŸÀÓÀ¯´Ö. i386 ¿¡¼­ 1/100 ÃÊ, ¾ËÆÄ¿¡¼­ 1/1024 ÃÊÀÌ´Ù. ¾Ë¸ÂÀº °ª ÀÌ ±Ã±ÝÇÏ´Ù¸é /usr/include/asm/param.h ¿¡¼­ HZ defineÀ» Âü°íÇÑ´Ù. Alexey Kuznetsov. kuznet@ms2.inr.ac.ru Updated by: Andi Kleen ak@muc.de Nicolas Delon delon.nicolas@wanadoo.fr /proc/sys/net/ipv6/* Variables: IPv6 has no global variables such as tcp_*. tcp_* settings under ipv4/ also apply to IPv6 [XXX?]. bindv6only - BOOLEAN Default value for IPV6_V6ONLY socket option, which restricts use of the IPv6 socket to IPv6 communication only. TRUE: disable IPv4-mapped address feature FALSE: enable IPv4-mapped address feature ±âº»°ª: FALSE (as specified in RFC2553bis) conf/default/*: Change the interface-specific default settings. conf/all/*: Change all the interface-specific settings. [XXX: Other special features than forwarding?] conf/all/forwarding - BOOLEAN Enable global IPv6 forwarding between all interfaces. IPv4 and IPv6 work differently here; e.g. netfilter must be used to control which interfaces may forward packets and which not. This also sets all interfaces' Host/Router setting 'forwarding' to the specified value. See below for details. This referred to as global forwarding. conf/interface/*: Change special settings per interface. The functional behaviour for certain settings is different depending on whether local forwarding is enabled or not. accept_ra - BOOLEAN Accept Router Advertisements; autoconfigure using them. Functional default: enabled if local forwarding is disabled. disabled if local forwarding is enabled. accept_redirects - BOOLEAN Accept Redirects. Functional default: enabled if local forwarding is disabled. disabled if local forwarding is enabled. autoconf - BOOLEAN Configure link-local addresses using L2 hardware addresses. ±âº»°ª: TRUE dad_transmits - Á¤¼ö The amount of Duplicate Address Detection probes to send. ±âº»°ª: 1 forwarding - BOOLEAN Configure interface-specific Host/Router behaviour. Note: It is recommended to have the same setting on all interfaces; mixed router/host scenarios are rather uncommon. FALSE: By default, Host behaviour is assumed. This means: 1. IsRouter flag is not set in Neighbour Advertisements. 2. Router Solicitations are being sent when necessary. 3. If accept_ra is TRUE (default), accept Router Advertisements (and do autoconfiguration). 4. If accept_redirects is TRUE (default), accept Redirects. TRUE: If local forwarding is enabled, Router behaviour is assumed. This means exactly the reverse from the above: 1. IsRouter flag is set in Neighbour Advertisements. 2. Router Solicitations are not sent. 3. Router Advertisements are ignored. 4. Redirects are ignored. ±âº»°ª: FALSE if global forwarding is disabled (default), otherwise TRUE. hop_limit - Á¤¼ö Default Hop Limit to set. ±âº»°ª: 64 mtu - Á¤¼ö Default Maximum Transfer Unit ±âº»°ª: 1280 (IPv6 required minimum) router_solicitation_delay - Á¤¼ö Number of seconds to wait after interface is brought up before sending Router Solicitations. ±âº»°ª: 1 router_solicitation_interval - Á¤¼ö Number of seconds to wait between Router Solicitations. ±âº»°ª: 4 router_solicitations - Á¤¼ö Number of Router Solicitations to send until assuming no routers are present. ±âº»°ª: 3 icmp/*: ratelimit - Á¤¼ö Limit the maximal rates for sending ICMPv6 packets. 0 to disable any limiting, otherwise the maximal rate in jiffies(1) ±âº»°ª: 100 IPv6 Update by: Pekka Savola <pekkas AT netcore.fi> YOSHIFUJI Hideaki / USAGI Project <yoshfuji AT linux-ipv6.org>



>> ÀÌÀü : Sysctl For Kernel Parameters in Kernel



    



 Home > Lecture > Kernel > Kernel-7

Copyright 1997-2010 JoungKyun Kim 
LAST MODIFIED: 2009/08/28