Ted Unangst wrote:
Make no sense in the test and improving results, or make no sense in
setting them as such here?
net.inet.ip.redirect=0
Is to disable ICMP routing redirects. Otherwise, your system could have
its routing table misadjusted by an attacker. Wouldn't be wise to do so?
May be if PF is turn on, then there is no reason for this, but with PF
ON, I get drop and need to address that. Didn't pursue it yet as dead
however.
As for the net.bpf.bufsize, I am looking again in my notes and tests,
it's use for Berkeley Packet Filter (BPF), to maintains an internal
kernel buffer for storing packets received off the wire.
Yes in that case it make sense not to have that here. I redid the tests
with the default value and yes you are right! This one is wrong here.
May be lack of sleep. (;> Thanks for correcting me!
I also have the revise my statement on the net.inet.ip.portfirst=32768
effect. In a series of new tests, it doesn't have the impact noted the
first test runs. So, I would keep it as default value as well now. May
be it was when PF was enable that I have more of an impact then. But my
notes are not clear on that specific one.
Anything else you see that may be questionable in what I sent? I am
doing more tests with different hardware to be sure it's all sane value
in the end.
Other wise many thanks for having taken the time to look it over and
give me your feedback on it!
I sure appreciate it big time!
Best
Daniel
| Cliffe | Re: [RFC 0/5] [TALPA] Intro to a linux interface for on access scanning |
| Amit K. Arora | [RFC] Heads up on sys_fallocate() |
| Bart Van Assche | Integration of SCST in the mainstream Linux kernel |
| Andrew Morton | Re: [RFC/PATCH] Documentation of kernel messages |
| David Miller | [GIT]: Networking |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Radu Rendec | Endianness problem with u32 classifier hash masks |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
git: | |
