137 lines
3.7 KiB
Plaintext
137 lines
3.7 KiB
Plaintext
# $FreeBSD: releng/12.3/sbin/sysctl/sysctl.conf 337624 2018-08-11 13:28:03Z brd $
|
|
#
|
|
# This file is read when going to multi-user and its contents piped thru
|
|
# ``sysctl'' to adjust kernel values. ``man 5 sysctl.conf'' for details.
|
|
#
|
|
|
|
# Uncomment this to prevent users from seeing information about processes that
|
|
# are being run under another UID.
|
|
security.bsd.see_other_uids=0
|
|
security.bsd.see_other_gids=0
|
|
security.bsd.unprivileged_read_msgbuf=0
|
|
security.bsd.unprivileged_proc_debug=0
|
|
kern.randompid=1
|
|
vfs.zfs.min_auto_ashift=12
|
|
hw.acpi.cpu.cx_lowest=C6
|
|
|
|
kern.coredump=1
|
|
kern.sugid_coredump=1
|
|
kern.sched.interact=5
|
|
kern.sched.slice=3
|
|
vfs.read_max=128
|
|
vfs.timestamp_precision=3
|
|
net.link.tap.up_on_open=1
|
|
#net.link.lagg.lacp.default_strict_mode=0
|
|
net.link.ether.inet.log_arp_movements=0
|
|
net.inet.ip.fw.verbose_limit=5
|
|
|
|
dev.igb.0.fc=0
|
|
dev.igb.1.fc=0
|
|
#dev.igb.0.eee_control=0
|
|
#dev.igb.1.eee_control=0
|
|
# breaks the igb driver
|
|
hw.intr_storm_threshold=9000
|
|
kern.ipc.maxsockbuf=16777216
|
|
kern.ipc.shm_use_phys=1
|
|
kern.ipc.soacceptqueue=1024
|
|
|
|
kern.ipc.nmbclusters=24513148
|
|
kern.ipc.nmbjumbop=9192430
|
|
kern.ipc.nmbjumbo9=2723683
|
|
kern.ipc.nmbjumbo16=1532071
|
|
kern.ipc.nmbufs=117663120
|
|
|
|
kern.maxvnodes=4194304
|
|
kern.random.harvest.mask=351
|
|
kern.threads.max_threads_per_proc=9000
|
|
net.bpf.optimize_writers=1
|
|
net.inet.icmp.drop_redirect=1
|
|
net.inet.icmp.icmplim=512
|
|
net.inet.icmp.icmplim_output=0
|
|
net.inet.ip.forwarding=1
|
|
net.inet.ip.maxfragpackets=0
|
|
net.inet.ip.maxfragsperpacket=0
|
|
net.inet.ip.random_id=1
|
|
net.inet.ip.redirect=0
|
|
net.inet.raw.maxdgram=131072
|
|
net.inet.raw.recvspace=131072
|
|
net.inet.tcp.abc_l_var=44
|
|
net.inet.tcp.blackhole=2
|
|
net.inet.tcp.cc.abe=1
|
|
net.inet.tcp.cc.algorithm=cubic
|
|
#net.inet.tcp.cc.htcp.adaptive_backoff=1
|
|
#net.inet.tcp.cc.htcp.rtt_scaling=1
|
|
net.inet.tcp.delacktime=20
|
|
net.inet.tcp.drop_synfin=1
|
|
net.inet.tcp.initcwnd_segments=44
|
|
net.inet.tcp.keepidle=10000
|
|
net.inet.tcp.keepintvl=5000
|
|
net.inet.tcp.minmss=524
|
|
net.inet.tcp.msl=2500
|
|
net.inet.tcp.mssdflt=1448
|
|
net.inet.tcp.nolocaltimewait=1
|
|
net.inet.tcp.path_mtu_discovery=0
|
|
net.inet.tcp.reass.maxqueuelen=1448
|
|
net.inet.tcp.recvbuf_inc=65536
|
|
net.inet.tcp.recvbuf_max=16777216
|
|
net.inet.tcp.recvspace=262144
|
|
net.inet.tcp.rfc6675_pipe=1
|
|
net.inet.tcp.sendbuf_inc=65536
|
|
net.inet.tcp.sendbuf_max=16777216
|
|
net.inet.tcp.sendspace=262144
|
|
net.inet.tcp.syncache.rexmtlimit=0
|
|
net.inet.tcp.syncookies=0
|
|
net.inet.tcp.tso=0
|
|
net.inet.udp.blackhole=1
|
|
net.inet.udp.maxdgram=57344
|
|
net.inet6.icmp6.nodeinfo=0
|
|
net.inet6.ip6.accept_rtadv=1
|
|
net.inet6.ip6.use_tempaddr=1
|
|
net.inet6.ip6.prefer_tempaddr=1
|
|
net.inet6.ip6.forwarding=1
|
|
net.inet6.ip6.maxfragpackets=0
|
|
net.inet6.ip6.maxfrags=0
|
|
net.inet6.ip6.redirect=0
|
|
net.link.bridge.pfil_bridge=0
|
|
net.link.bridge.pfil_member=0
|
|
net.link.bridge.pfil_onlyip=0
|
|
net.local.stream.recvspace=164240
|
|
net.local.stream.sendspace=164240
|
|
net.route.netisr_maxqlen=2048
|
|
net.raw.recvspace=65536
|
|
net.raw.sendspace=65536
|
|
vfs.zfs.arc_max=51539607552
|
|
vfs.zfs.delay_min_dirty_percent=96
|
|
vfs.zfs.dirty_data_max=12884901888
|
|
vfs.zfs.prefetch_disable=0
|
|
#vfs.zfs.top_maxinflight=128
|
|
vfs.zfs.trim.txg_delay=2
|
|
vfs.zfs.txg.timeout=90
|
|
vfs.zfs.vdev.aggregation_limit=1048576
|
|
vfs.zfs.vdev.write_gap_limit=0
|
|
|
|
# no l2arc
|
|
#vfs.zfs.l2arc_write_boost=402653184
|
|
#vfs.zfs.l2arc_write_max=402653184
|
|
|
|
net.inet.tcp.functions_default=rack
|
|
net.inet.tcp.rack.tlpmethod=3
|
|
net.inet.tcp.rack.data_after_close=0
|
|
|
|
# Verify RACK
|
|
# sysctl net.inet.tcp.functions_available
|
|
# sysctl net.inet.tcp.rack.
|
|
|
|
#Cheap Disk Issues
|
|
kern.cam.ada.default_timeout=60
|
|
kern.cam.da.default_timeout=90
|
|
|
|
# best way to see misconfigured or non operational services
|
|
net.inet.tcp.log_in_vain: 1
|
|
net.inet.udp.log_in_vain: 1
|
|
|
|
# Disable File Handle Affinity for NFS write operations.
|
|
# It improves NFS write throughput with ZFS sync=always on ship/pxe
|
|
vfs.nfsd.fha.write=0
|
|
vfs.nfsd.fha.max_nfsds_per_fh=32
|