Update the Ubuntu example configs
[kconfig-hardened-check.git] / kernel_hardening_checker / config_files / distros / example_sysctls.txt
1 abi.vsyscall32 = 1
2 debug.exception-trace = 1
3 debug.kprobes-optimization = 1
4 dev.cdrom.autoclose = 1
5 dev.cdrom.autoeject = 0
6 dev.cdrom.check_media = 0
7 dev.cdrom.debug = 0
8 dev.cdrom.info = CD-ROM information, Id: cdrom.c 3.20 2003/12/17
9 dev.cdrom.info = 
10 dev.cdrom.info = drive name:            sr0
11 dev.cdrom.info = drive speed:           1
12 dev.cdrom.info = drive # of slots:      1
13 dev.cdrom.info = Can close tray:                1
14 dev.cdrom.info = Can open tray:         1
15 dev.cdrom.info = Can lock tray:         1
16 dev.cdrom.info = Can change speed:      1
17 dev.cdrom.info = Can select disk:       0
18 dev.cdrom.info = Can read multisession: 1
19 dev.cdrom.info = Can read MCN:          1
20 dev.cdrom.info = Reports media changed: 1
21 dev.cdrom.info = Can play audio:                1
22 dev.cdrom.info = Can write CD-R:                1
23 dev.cdrom.info = Can write CD-RW:       1
24 dev.cdrom.info = Can read DVD:          1
25 dev.cdrom.info = Can write DVD-R:       1
26 dev.cdrom.info = Can write DVD-RAM:     1
27 dev.cdrom.info = Can read MRW:          1
28 dev.cdrom.info = Can write MRW:         1
29 dev.cdrom.info = Can write RAM:         1
30 dev.cdrom.info = 
31 dev.cdrom.info = 
32 dev.cdrom.lock = 0
33 dev.hpet.max-user-freq = 64
34 dev.mac_hid.mouse_button2_keycode = 97
35 dev.mac_hid.mouse_button3_keycode = 100
36 dev.mac_hid.mouse_button_emulation = 0
37 dev.raid.speed_limit_max = 200000
38 dev.raid.speed_limit_min = 1000
39 dev.scsi.logging_level = 0
40 dev.tty.ldisc_autoload = 1
41 fs.aio-max-nr = 65536
42 fs.aio-nr = 0
43 fs.binfmt_misc.status = enabled
44 fs.dentry-state = 371268        317893  45      0       59993   0
45 fs.dir-notify-enable = 1
46 fs.epoll.max_user_watches = 1779801
47 fs.fanotify.max_queued_events = 16384
48 fs.fanotify.max_user_groups = 128
49 fs.fanotify.max_user_marks = 64771
50 fs.file-max = 1000000
51 fs.file-nr = 3552       0       1000000
52 fs.inode-nr = 318298    27310
53 fs.inode-state = 318298 27310   0       0       0       0       0
54 fs.inotify.max_queued_events = 16384
55 fs.inotify.max_user_instances = 128
56 fs.inotify.max_user_watches = 60915
57 fs.lease-break-time = 45
58 fs.leases-enable = 1
59 fs.mount-max = 100000
60 fs.mqueue.msg_default = 10
61 fs.mqueue.msg_max = 10
62 fs.mqueue.msgsize_default = 8192
63 fs.mqueue.msgsize_max = 8192
64 fs.mqueue.queues_max = 256
65 fs.nr_open = 1048576
66 fs.overflowgid = 65534
67 fs.overflowuid = 65534
68 fs.pipe-max-size = 1048576
69 fs.pipe-user-pages-hard = 0
70 fs.pipe-user-pages-soft = 16384
71 fs.protected_fifos = 1
72 fs.protected_hardlinks = 1
73 fs.protected_regular = 2
74 fs.protected_symlinks = 1
75 fs.quota.allocated_dquots = 0
76 fs.quota.cache_hits = 0
77 fs.quota.drops = 0
78 fs.quota.free_dquots = 0
79 fs.quota.lookups = 0
80 fs.quota.reads = 0
81 fs.quota.syncs = 8
82 fs.quota.writes = 0
83 fs.suid_dumpable = 2
84 fs.verity.require_signatures = 0
85 kernel.acct = 4 2       30
86 kernel.acpi_video_flags = 0
87 kernel.apparmor_display_secid_mode = 0
88 kernel.auto_msgmni = 0
89 kernel.bootloader_type = 114
90 kernel.bootloader_version = 2
91 kernel.bpf_stats_enabled = 0
92 kernel.cad_pid = 1
93 kernel.cap_last_cap = 40
94 kernel.core_pattern = |/usr/share/apport/apport %p %s %c %d %P %E
95 kernel.core_pipe_limit = 0
96 kernel.core_uses_pid = 1
97 kernel.ctrl-alt-del = 0
98 kernel.dmesg_restrict = 1
99 kernel.domainname = (none)
100 kernel.firmware_config.force_sysfs_fallback = 0
101 kernel.firmware_config.ignore_sysfs_fallback = 0
102 kernel.ftrace_dump_on_oops = 0
103 kernel.ftrace_enabled = 1
104 kernel.hardlockup_all_cpu_backtrace = 0
105 kernel.hardlockup_panic = 0
106 kernel.hostname = u2204oval
107 kernel.hotplug = 
108 kernel.hung_task_all_cpu_backtrace = 0
109 kernel.hung_task_check_count = 4194304
110 kernel.hung_task_check_interval_secs = 0
111 kernel.hung_task_panic = 0
112 kernel.hung_task_timeout_secs = 120
113 kernel.hung_task_warnings = 10
114 kernel.io_delay_type = 1
115 kernel.kexec_load_disabled = 0
116 kernel.keys.gc_delay = 300
117 kernel.keys.maxbytes = 20000
118 kernel.keys.maxkeys = 200
119 kernel.keys.persistent_keyring_expiry = 259200
120 kernel.keys.root_maxbytes = 25000000
121 kernel.keys.root_maxkeys = 1000000
122 kernel.kptr_restrict = 1
123 kernel.max_lock_depth = 1024
124 kernel.max_rcu_stall_to_panic = 0
125 kernel.modprobe = /sbin/modprobe
126 kernel.modules_disabled = 0
127 kernel.msg_next_id = -1
128 kernel.msgmax = 8192
129 kernel.msgmnb = 16384
130 kernel.msgmni = 32000
131 kernel.ngroups_max = 65536
132 kernel.nmi_watchdog = 0
133 kernel.ns_last_pid = 2810585
134 kernel.numa_balancing = 0
135 kernel.oops_all_cpu_backtrace = 0
136 kernel.osrelease = 5.15.0-25-generic
137 kernel.ostype = Linux
138 kernel.overflowgid = 65534
139 kernel.overflowuid = 65534
140 kernel.panic = 0
141 kernel.panic_on_io_nmi = 0
142 kernel.panic_on_oops = 0
143 kernel.panic_on_rcu_stall = 0
144 kernel.panic_on_unrecovered_nmi = 0
145 kernel.panic_on_warn = 0
146 kernel.panic_print = 0
147 kernel.perf_cpu_time_max_percent = 25
148 kernel.perf_event_max_contexts_per_stack = 8
149 kernel.perf_event_max_sample_rate = 100000
150 kernel.perf_event_max_stack = 127
151 kernel.perf_event_mlock_kb = 516
152 kernel.perf_event_paranoid = 4
153 kernel.pid_max = 4194304
154 kernel.poweroff_cmd = /sbin/poweroff
155 kernel.print-fatal-signals = 0
156 kernel.printk = 4       4       1       7
157 kernel.printk_delay = 0
158 kernel.printk_devkmsg = on
159 kernel.printk_ratelimit = 5
160 kernel.printk_ratelimit_burst = 10
161 kernel.pty.max = 4096
162 kernel.pty.nr = 1
163 kernel.pty.reserve = 1024
164 kernel.random.boot_id = 22aedd89-1172-4dbf-8984-99343adac9be
165 kernel.random.entropy_avail = 3451
166 kernel.random.poolsize = 4096
167 kernel.random.urandom_min_reseed_secs = 60
168 kernel.random.uuid = 5dbb0c08-8fd4-4537-bc4b-339cd0830e85
169 kernel.random.write_wakeup_threshold = 896
170 kernel.randomize_va_space = 2
171 kernel.real-root-dev = 0
172 kernel.sched_autogroup_enabled = 1
173 kernel.sched_cfs_bandwidth_slice_us = 5000
174 kernel.sched_child_runs_first = 0
175 kernel.sched_deadline_period_max_us = 4194304
176 kernel.sched_deadline_period_min_us = 100
177 kernel.sched_energy_aware = 1
178 kernel.sched_rr_timeslice_ms = 100
179 kernel.sched_rt_period_us = 1000000
180 kernel.sched_rt_runtime_us = 950000
181 kernel.sched_schedstats = 0
182 kernel.sched_util_clamp_max = 1024
183 kernel.sched_util_clamp_min = 1024
184 kernel.sched_util_clamp_min_rt_default = 1024
185 kernel.seccomp.actions_avail = kill_process kill_thread trap errno user_notif trace log allow
186 kernel.seccomp.actions_logged = kill_process kill_thread trap errno user_notif trace log
187 kernel.sem = 250        32000   32      275
188 kernel.sem_next_id = -1
189 kernel.sg-big-buff = 32768
190 kernel.shm_next_id = -1
191 kernel.shm_rmid_forced = 0
192 kernel.shmall = 4194304
193 kernel.shmmax = 17179869184
194 kernel.shmmni = 4096
195 kernel.soft_watchdog = 1
196 kernel.softlockup_all_cpu_backtrace = 0
197 kernel.softlockup_panic = 0
198 kernel.stack_tracer_enabled = 0
199 kernel.sysctl_writes_strict = 1
200 kernel.sysrq = 176
201 kernel.tainted = 0
202 kernel.task_delayacct = 0
203 kernel.threads-max = 62462
204 kernel.timer_migration = 1
205 kernel.traceoff_on_warning = 0
206 kernel.tracepoint_printk = 0
207 kernel.unknown_nmi_panic = 0
208 kernel.unprivileged_bpf_disabled = 2
209 kernel.unprivileged_userns_apparmor_policy = 1
210 kernel.unprivileged_userns_clone = 1
211 kernel.usermodehelper.bset = 4294967295 511
212 kernel.usermodehelper.inheritable = 4294967295  511
213 kernel.version = #25-Ubuntu SMP Wed Mar 30 15:54:22 UTC 2022
214 kernel.watchdog = 1
215 kernel.watchdog_cpumask = 0-127
216 kernel.watchdog_thresh = 10
217 kernel.yama.ptrace_scope = 1
218 net.bridge.bridge-nf-call-arptables = 1
219 net.bridge.bridge-nf-call-ip6tables = 1
220 net.bridge.bridge-nf-call-iptables = 1
221 net.bridge.bridge-nf-filter-pppoe-tagged = 0
222 net.bridge.bridge-nf-filter-vlan-tagged = 0
223 net.bridge.bridge-nf-pass-vlan-input-dev = 0
224 net.core.bpf_jit_enable = 1
225 net.core.bpf_jit_harden = 0
226 net.core.bpf_jit_kallsyms = 1
227 net.core.bpf_jit_limit = 264241152
228 net.core.busy_poll = 0
229 net.core.busy_read = 0
230 net.core.default_qdisc = fq_codel
231 net.core.dev_weight = 64
232 net.core.dev_weight_rx_bias = 1
233 net.core.dev_weight_tx_bias = 1
234 net.core.devconf_inherit_init_net = 0
235 net.core.fb_tunnels_only_for_init_net = 0
236 net.core.flow_limit_cpu_bitmap = 00000000,00000000,00000000,00000000
237 net.core.flow_limit_table_len = 4096
238 net.core.gro_normal_batch = 8
239 net.core.high_order_alloc_disable = 0
240 net.core.max_skb_frags = 17
241 net.core.message_burst = 10
242 net.core.message_cost = 5
243 net.core.netdev_budget = 300
244 net.core.netdev_budget_usecs = 8000
245 net.core.netdev_max_backlog = 1000
246 net.core.netdev_rss_key = e1:ca:53:a8:12:b0:cc:46:ba:45:59:ad:99:fd:56:e3:0d:e3:d5:91:46:60:f8:3c:e0:7b:32:6a:00:ea:44:73:07:1e:2a:3f:9c:1d:32:3b:3e:12:ed:0b:5c:35:82:30:71:0c:69:73
247 net.core.netdev_tstamp_prequeue = 1
248 net.core.netdev_unregister_timeout_secs = 10
249 net.core.optmem_max = 20480
250 net.core.rmem_default = 212992
251 net.core.rmem_max = 212992
252 net.core.rps_sock_flow_entries = 0
253 net.core.somaxconn = 1024
254 net.core.tstamp_allow_data = 1
255 net.core.warnings = 0
256 net.core.wmem_default = 212992
257 net.core.wmem_max = 212992
258 net.core.xfrm_acq_expires = 30
259 net.core.xfrm_aevent_etime = 10
260 net.core.xfrm_aevent_rseqth = 2
261 net.core.xfrm_larval_drop = 1
262 net.ipv4.cipso_cache_bucket_size = 10
263 net.ipv4.cipso_cache_enable = 1
264 net.ipv4.cipso_rbm_optfmt = 0
265 net.ipv4.cipso_rbm_strictvalid = 1
266 net.ipv4.conf.all.accept_local = 0
267 net.ipv4.conf.all.accept_redirects = 0
268 net.ipv4.conf.all.accept_source_route = 0
269 net.ipv4.conf.all.arp_accept = 0
270 net.ipv4.conf.all.arp_announce = 0
271 net.ipv4.conf.all.arp_filter = 0
272 net.ipv4.conf.all.arp_ignore = 0
273 net.ipv4.conf.all.arp_notify = 0
274 net.ipv4.conf.all.bc_forwarding = 0
275 net.ipv4.conf.all.bootp_relay = 0
276 net.ipv4.conf.all.disable_policy = 0
277 net.ipv4.conf.all.disable_xfrm = 0
278 net.ipv4.conf.all.drop_gratuitous_arp = 0
279 net.ipv4.conf.all.drop_unicast_in_l2_multicast = 0
280 net.ipv4.conf.all.force_igmp_version = 0
281 net.ipv4.conf.all.forwarding = 1
282 net.ipv4.conf.all.igmpv2_unsolicited_report_interval = 10000
283 net.ipv4.conf.all.igmpv3_unsolicited_report_interval = 1000
284 net.ipv4.conf.all.ignore_routes_with_linkdown = 0
285 net.ipv4.conf.all.log_martians = 0
286 net.ipv4.conf.all.mc_forwarding = 0
287 net.ipv4.conf.all.medium_id = 0
288 net.ipv4.conf.all.promote_secondaries = 0
289 net.ipv4.conf.all.proxy_arp = 0
290 net.ipv4.conf.all.proxy_arp_pvlan = 0
291 net.ipv4.conf.all.route_localnet = 0
292 net.ipv4.conf.all.rp_filter = 2
293 net.ipv4.conf.all.secure_redirects = 1
294 net.ipv4.conf.all.send_redirects = 1
295 net.ipv4.conf.all.shared_media = 1
296 net.ipv4.conf.all.src_valid_mark = 0
297 net.ipv4.conf.all.tag = 0
298 net.ipv4.conf.default.accept_local = 0
299 net.ipv4.conf.default.accept_redirects = 1
300 net.ipv4.conf.default.accept_source_route = 0
301 net.ipv4.conf.default.arp_accept = 0
302 net.ipv4.conf.default.arp_announce = 0
303 net.ipv4.conf.default.arp_filter = 0
304 net.ipv4.conf.default.arp_ignore = 0
305 net.ipv4.conf.default.arp_notify = 0
306 net.ipv4.conf.default.bc_forwarding = 0
307 net.ipv4.conf.default.bootp_relay = 0
308 net.ipv4.conf.default.disable_policy = 0
309 net.ipv4.conf.default.disable_xfrm = 0
310 net.ipv4.conf.default.drop_gratuitous_arp = 0
311 net.ipv4.conf.default.drop_unicast_in_l2_multicast = 0
312 net.ipv4.conf.default.force_igmp_version = 0
313 net.ipv4.conf.default.forwarding = 1
314 net.ipv4.conf.default.igmpv2_unsolicited_report_interval = 10000
315 net.ipv4.conf.default.igmpv3_unsolicited_report_interval = 1000
316 net.ipv4.conf.default.ignore_routes_with_linkdown = 0
317 net.ipv4.conf.default.log_martians = 0
318 net.ipv4.conf.default.mc_forwarding = 0
319 net.ipv4.conf.default.medium_id = 0
320 net.ipv4.conf.default.promote_secondaries = 1
321 net.ipv4.conf.default.proxy_arp = 0
322 net.ipv4.conf.default.proxy_arp_pvlan = 0
323 net.ipv4.conf.default.route_localnet = 0
324 net.ipv4.conf.default.rp_filter = 2
325 net.ipv4.conf.default.secure_redirects = 1
326 net.ipv4.conf.default.send_redirects = 1
327 net.ipv4.conf.default.shared_media = 1
328 net.ipv4.conf.default.src_valid_mark = 0
329 net.ipv4.conf.default.tag = 0
330 net.ipv4.conf.docker0.accept_local = 0
331 net.ipv4.conf.docker0.accept_redirects = 1
332 net.ipv4.conf.docker0.accept_source_route = 0
333 net.ipv4.conf.docker0.arp_accept = 0
334 net.ipv4.conf.docker0.arp_announce = 0
335 net.ipv4.conf.docker0.arp_filter = 0
336 net.ipv4.conf.docker0.arp_ignore = 0
337 net.ipv4.conf.docker0.arp_notify = 0
338 net.ipv4.conf.docker0.bc_forwarding = 0
339 net.ipv4.conf.docker0.bootp_relay = 0
340 net.ipv4.conf.docker0.disable_policy = 0
341 net.ipv4.conf.docker0.disable_xfrm = 0
342 net.ipv4.conf.docker0.drop_gratuitous_arp = 0
343 net.ipv4.conf.docker0.drop_unicast_in_l2_multicast = 0
344 net.ipv4.conf.docker0.force_igmp_version = 0
345 net.ipv4.conf.docker0.forwarding = 1
346 net.ipv4.conf.docker0.igmpv2_unsolicited_report_interval = 10000
347 net.ipv4.conf.docker0.igmpv3_unsolicited_report_interval = 1000
348 net.ipv4.conf.docker0.ignore_routes_with_linkdown = 0
349 net.ipv4.conf.docker0.log_martians = 0
350 net.ipv4.conf.docker0.mc_forwarding = 0
351 net.ipv4.conf.docker0.medium_id = 0
352 net.ipv4.conf.docker0.promote_secondaries = 1
353 net.ipv4.conf.docker0.proxy_arp = 0
354 net.ipv4.conf.docker0.proxy_arp_pvlan = 0
355 net.ipv4.conf.docker0.route_localnet = 0
356 net.ipv4.conf.docker0.rp_filter = 2
357 net.ipv4.conf.docker0.secure_redirects = 1
358 net.ipv4.conf.docker0.send_redirects = 1
359 net.ipv4.conf.docker0.shared_media = 1
360 net.ipv4.conf.docker0.src_valid_mark = 0
361 net.ipv4.conf.docker0.tag = 0
362 net.ipv4.conf.ens160.accept_local = 0
363 net.ipv4.conf.ens160.accept_redirects = 1
364 net.ipv4.conf.ens160.accept_source_route = 0
365 net.ipv4.conf.ens160.arp_accept = 0
366 net.ipv4.conf.ens160.arp_announce = 0
367 net.ipv4.conf.ens160.arp_filter = 0
368 net.ipv4.conf.ens160.arp_ignore = 0
369 net.ipv4.conf.ens160.arp_notify = 0
370 net.ipv4.conf.ens160.bc_forwarding = 0
371 net.ipv4.conf.ens160.bootp_relay = 0
372 net.ipv4.conf.ens160.disable_policy = 0
373 net.ipv4.conf.ens160.disable_xfrm = 0
374 net.ipv4.conf.ens160.drop_gratuitous_arp = 0
375 net.ipv4.conf.ens160.drop_unicast_in_l2_multicast = 0
376 net.ipv4.conf.ens160.force_igmp_version = 0
377 net.ipv4.conf.ens160.forwarding = 1
378 net.ipv4.conf.ens160.igmpv2_unsolicited_report_interval = 10000
379 net.ipv4.conf.ens160.igmpv3_unsolicited_report_interval = 1000
380 net.ipv4.conf.ens160.ignore_routes_with_linkdown = 0
381 net.ipv4.conf.ens160.log_martians = 0
382 net.ipv4.conf.ens160.mc_forwarding = 0
383 net.ipv4.conf.ens160.medium_id = 0
384 net.ipv4.conf.ens160.promote_secondaries = 1
385 net.ipv4.conf.ens160.proxy_arp = 0
386 net.ipv4.conf.ens160.proxy_arp_pvlan = 0
387 net.ipv4.conf.ens160.route_localnet = 0
388 net.ipv4.conf.ens160.rp_filter = 2
389 net.ipv4.conf.ens160.secure_redirects = 1
390 net.ipv4.conf.ens160.send_redirects = 1
391 net.ipv4.conf.ens160.shared_media = 1
392 net.ipv4.conf.ens160.src_valid_mark = 0
393 net.ipv4.conf.ens160.tag = 0
394 net.ipv4.conf.lo.accept_local = 0
395 net.ipv4.conf.lo.accept_redirects = 1
396 net.ipv4.conf.lo.accept_source_route = 0
397 net.ipv4.conf.lo.arp_accept = 0
398 net.ipv4.conf.lo.arp_announce = 0
399 net.ipv4.conf.lo.arp_filter = 0
400 net.ipv4.conf.lo.arp_ignore = 0
401 net.ipv4.conf.lo.arp_notify = 0
402 net.ipv4.conf.lo.bc_forwarding = 0
403 net.ipv4.conf.lo.bootp_relay = 0
404 net.ipv4.conf.lo.disable_policy = 1
405 net.ipv4.conf.lo.disable_xfrm = 1
406 net.ipv4.conf.lo.drop_gratuitous_arp = 0
407 net.ipv4.conf.lo.drop_unicast_in_l2_multicast = 0
408 net.ipv4.conf.lo.force_igmp_version = 0
409 net.ipv4.conf.lo.forwarding = 1
410 net.ipv4.conf.lo.igmpv2_unsolicited_report_interval = 10000
411 net.ipv4.conf.lo.igmpv3_unsolicited_report_interval = 1000
412 net.ipv4.conf.lo.ignore_routes_with_linkdown = 0
413 net.ipv4.conf.lo.log_martians = 0
414 net.ipv4.conf.lo.mc_forwarding = 0
415 net.ipv4.conf.lo.medium_id = 0
416 net.ipv4.conf.lo.promote_secondaries = 1
417 net.ipv4.conf.lo.proxy_arp = 0
418 net.ipv4.conf.lo.proxy_arp_pvlan = 0
419 net.ipv4.conf.lo.route_localnet = 0
420 net.ipv4.conf.lo.rp_filter = 2
421 net.ipv4.conf.lo.secure_redirects = 1
422 net.ipv4.conf.lo.send_redirects = 1
423 net.ipv4.conf.lo.shared_media = 1
424 net.ipv4.conf.lo.src_valid_mark = 0
425 net.ipv4.conf.lo.tag = 0
426 net.ipv4.fib_multipath_hash_fields = 7
427 net.ipv4.fib_multipath_hash_policy = 0
428 net.ipv4.fib_multipath_use_neigh = 0
429 net.ipv4.fib_notify_on_flag_change = 0
430 net.ipv4.fib_sync_mem = 524288
431 net.ipv4.fwmark_reflect = 0
432 net.ipv4.icmp_echo_enable_probe = 0
433 net.ipv4.icmp_echo_ignore_all = 0
434 net.ipv4.icmp_echo_ignore_broadcasts = 1
435 net.ipv4.icmp_errors_use_inbound_ifaddr = 0
436 net.ipv4.icmp_ignore_bogus_error_responses = 1
437 net.ipv4.icmp_msgs_burst = 50
438 net.ipv4.icmp_msgs_per_sec = 1000
439 net.ipv4.icmp_ratelimit = 1000
440 net.ipv4.icmp_ratemask = 6168
441 net.ipv4.igmp_link_local_mcast_reports = 1
442 net.ipv4.igmp_max_memberships = 20
443 net.ipv4.igmp_max_msf = 10
444 net.ipv4.igmp_qrv = 2
445 net.ipv4.inet_peer_maxttl = 600
446 net.ipv4.inet_peer_minttl = 120
447 net.ipv4.inet_peer_threshold = 65664
448 net.ipv4.ip_autobind_reuse = 0
449 net.ipv4.ip_default_ttl = 64
450 net.ipv4.ip_dynaddr = 0
451 net.ipv4.ip_early_demux = 1
452 net.ipv4.ip_forward = 1
453 net.ipv4.ip_forward_update_priority = 1
454 net.ipv4.ip_forward_use_pmtu = 0
455 net.ipv4.ip_local_port_range = 32768    60999
456 net.ipv4.ip_local_reserved_ports = 
457 net.ipv4.ip_no_pmtu_disc = 0
458 net.ipv4.ip_nonlocal_bind = 0
459 net.ipv4.ip_unprivileged_port_start = 1024
460 net.ipv4.ipfrag_high_thresh = 4194304
461 net.ipv4.ipfrag_low_thresh = 3145728
462 net.ipv4.ipfrag_max_dist = 64
463 net.ipv4.ipfrag_secret_interval = 0
464 net.ipv4.ipfrag_time = 30
465 net.ipv4.neigh.default.anycast_delay = 100
466 net.ipv4.neigh.default.app_solicit = 0
467 net.ipv4.neigh.default.base_reachable_time_ms = 30000
468 net.ipv4.neigh.default.delay_first_probe_time = 5
469 net.ipv4.neigh.default.gc_interval = 30
470 net.ipv4.neigh.default.gc_stale_time = 60
471 net.ipv4.neigh.default.gc_thresh1 = 128
472 net.ipv4.neigh.default.gc_thresh2 = 512
473 net.ipv4.neigh.default.gc_thresh3 = 1024
474 net.ipv4.neigh.default.locktime = 100
475 net.ipv4.neigh.default.mcast_resolicit = 0
476 net.ipv4.neigh.default.mcast_solicit = 3
477 net.ipv4.neigh.default.proxy_delay = 80
478 net.ipv4.neigh.default.proxy_qlen = 64
479 net.ipv4.neigh.default.retrans_time_ms = 1000
480 net.ipv4.neigh.default.ucast_solicit = 3
481 net.ipv4.neigh.default.unres_qlen = 101
482 net.ipv4.neigh.default.unres_qlen_bytes = 212992
483 net.ipv4.neigh.docker0.anycast_delay = 100
484 net.ipv4.neigh.docker0.app_solicit = 0
485 net.ipv4.neigh.docker0.base_reachable_time_ms = 30000
486 net.ipv4.neigh.docker0.delay_first_probe_time = 5
487 net.ipv4.neigh.docker0.gc_stale_time = 60
488 net.ipv4.neigh.docker0.locktime = 100
489 net.ipv4.neigh.docker0.mcast_resolicit = 0
490 net.ipv4.neigh.docker0.mcast_solicit = 3
491 net.ipv4.neigh.docker0.proxy_delay = 80
492 net.ipv4.neigh.docker0.proxy_qlen = 64
493 net.ipv4.neigh.docker0.retrans_time_ms = 1000
494 net.ipv4.neigh.docker0.ucast_solicit = 3
495 net.ipv4.neigh.docker0.unres_qlen = 101
496 net.ipv4.neigh.docker0.unres_qlen_bytes = 212992
497 net.ipv4.neigh.ens160.anycast_delay = 100
498 net.ipv4.neigh.ens160.app_solicit = 0
499 net.ipv4.neigh.ens160.base_reachable_time_ms = 30000
500 net.ipv4.neigh.ens160.delay_first_probe_time = 5
501 net.ipv4.neigh.ens160.gc_stale_time = 60
502 net.ipv4.neigh.ens160.locktime = 100
503 net.ipv4.neigh.ens160.mcast_resolicit = 0
504 net.ipv4.neigh.ens160.mcast_solicit = 3
505 net.ipv4.neigh.ens160.proxy_delay = 80
506 net.ipv4.neigh.ens160.proxy_qlen = 64
507 net.ipv4.neigh.ens160.retrans_time_ms = 1000
508 net.ipv4.neigh.ens160.ucast_solicit = 3
509 net.ipv4.neigh.ens160.unres_qlen = 101
510 net.ipv4.neigh.ens160.unres_qlen_bytes = 212992
511 net.ipv4.neigh.lo.anycast_delay = 100
512 net.ipv4.neigh.lo.app_solicit = 0
513 net.ipv4.neigh.lo.base_reachable_time_ms = 30000
514 net.ipv4.neigh.lo.delay_first_probe_time = 5
515 net.ipv4.neigh.lo.gc_stale_time = 60
516 net.ipv4.neigh.lo.locktime = 100
517 net.ipv4.neigh.lo.mcast_resolicit = 0
518 net.ipv4.neigh.lo.mcast_solicit = 3
519 net.ipv4.neigh.lo.proxy_delay = 80
520 net.ipv4.neigh.lo.proxy_qlen = 64
521 net.ipv4.neigh.lo.retrans_time_ms = 1000
522 net.ipv4.neigh.lo.ucast_solicit = 3
523 net.ipv4.neigh.lo.unres_qlen = 101
524 net.ipv4.neigh.lo.unres_qlen_bytes = 212992
525 net.ipv4.nexthop_compat_mode = 1
526 net.ipv4.ping_group_range = 0   2147483647
527 net.ipv4.raw_l3mdev_accept = 1
528 net.ipv4.route.error_burst = 1250
529 net.ipv4.route.error_cost = 250
530 net.ipv4.route.gc_elasticity = 8
531 net.ipv4.route.gc_interval = 60
532 net.ipv4.route.gc_min_interval = 0
533 net.ipv4.route.gc_min_interval_ms = 500
534 net.ipv4.route.gc_thresh = -1
535 net.ipv4.route.gc_timeout = 300
536 net.ipv4.route.max_size = 2147483647
537 net.ipv4.route.min_adv_mss = 256
538 net.ipv4.route.min_pmtu = 552
539 net.ipv4.route.mtu_expires = 600
540 net.ipv4.route.redirect_load = 5
541 net.ipv4.route.redirect_number = 9
542 net.ipv4.route.redirect_silence = 5120
543 net.ipv4.tcp_abort_on_overflow = 0
544 net.ipv4.tcp_adv_win_scale = 1
545 net.ipv4.tcp_allowed_congestion_control = reno cubic
546 net.ipv4.tcp_app_win = 31
547 net.ipv4.tcp_autocorking = 1
548 net.ipv4.tcp_available_congestion_control = reno cubic
549 net.ipv4.tcp_available_ulp = espintcp mptcp tls
550 net.ipv4.tcp_base_mss = 1024
551 net.ipv4.tcp_challenge_ack_limit = 1000
552 net.ipv4.tcp_comp_sack_delay_ns = 1000000
553 net.ipv4.tcp_comp_sack_nr = 44
554 net.ipv4.tcp_comp_sack_slack_ns = 100000
555 net.ipv4.tcp_congestion_control = cubic
556 net.ipv4.tcp_dsack = 1
557 net.ipv4.tcp_early_demux = 1
558 net.ipv4.tcp_early_retrans = 3
559 net.ipv4.tcp_ecn = 2
560 net.ipv4.tcp_ecn_fallback = 1
561 net.ipv4.tcp_fack = 0
562 net.ipv4.tcp_fastopen = 1
563 net.ipv4.tcp_fastopen_blackhole_timeout_sec = 0
564 net.ipv4.tcp_fastopen_key = 23d4bc1a-67678cb7-969bbf8f-f04ed254
565 net.ipv4.tcp_fin_timeout = 60
566 net.ipv4.tcp_frto = 2
567 net.ipv4.tcp_fwmark_accept = 0
568 net.ipv4.tcp_invalid_ratelimit = 500
569 net.ipv4.tcp_keepalive_intvl = 75
570 net.ipv4.tcp_keepalive_probes = 9
571 net.ipv4.tcp_keepalive_time = 7200
572 net.ipv4.tcp_l3mdev_accept = 0
573 net.ipv4.tcp_limit_output_bytes = 1048576
574 net.ipv4.tcp_low_latency = 0
575 net.ipv4.tcp_max_orphans = 32768
576 net.ipv4.tcp_max_reordering = 300
577 net.ipv4.tcp_max_syn_backlog = 512
578 net.ipv4.tcp_max_tw_buckets = 32768
579 net.ipv4.tcp_mem = 92505        123341  185010
580 net.ipv4.tcp_migrate_req = 0
581 net.ipv4.tcp_min_rtt_wlen = 300
582 net.ipv4.tcp_min_snd_mss = 48
583 net.ipv4.tcp_min_tso_segs = 2
584 net.ipv4.tcp_moderate_rcvbuf = 1
585 net.ipv4.tcp_mtu_probe_floor = 48
586 net.ipv4.tcp_mtu_probing = 0
587 net.ipv4.tcp_no_metrics_save = 0
588 net.ipv4.tcp_no_ssthresh_metrics_save = 1
589 net.ipv4.tcp_notsent_lowat = 4294967295
590 net.ipv4.tcp_orphan_retries = 0
591 net.ipv4.tcp_pacing_ca_ratio = 120
592 net.ipv4.tcp_pacing_ss_ratio = 200
593 net.ipv4.tcp_probe_interval = 600
594 net.ipv4.tcp_probe_threshold = 8
595 net.ipv4.tcp_recovery = 1
596 net.ipv4.tcp_reflect_tos = 0
597 net.ipv4.tcp_reordering = 3
598 net.ipv4.tcp_retrans_collapse = 1
599 net.ipv4.tcp_retries1 = 3
600 net.ipv4.tcp_retries2 = 15
601 net.ipv4.tcp_rfc1337 = 0
602 net.ipv4.tcp_rmem = 4096        131072  6291456
603 net.ipv4.tcp_rx_skb_cache = 0
604 net.ipv4.tcp_sack = 1
605 net.ipv4.tcp_slow_start_after_idle = 1
606 net.ipv4.tcp_stdurg = 0
607 net.ipv4.tcp_syn_retries = 6
608 net.ipv4.tcp_synack_retries = 5
609 net.ipv4.tcp_syncookies = 1
610 net.ipv4.tcp_thin_linear_timeouts = 0
611 net.ipv4.tcp_timestamps = 1
612 net.ipv4.tcp_tso_win_divisor = 3
613 net.ipv4.tcp_tw_reuse = 2
614 net.ipv4.tcp_tx_skb_cache = 0
615 net.ipv4.tcp_window_scaling = 1
616 net.ipv4.tcp_wmem = 4096        16384   4194304
617 net.ipv4.tcp_workaround_signed_windows = 0
618 net.ipv4.udp_early_demux = 1
619 net.ipv4.udp_l3mdev_accept = 0
620 net.ipv4.udp_mem = 185010       246682  370020
621 net.ipv4.udp_rmem_min = 4096
622 net.ipv4.udp_wmem_min = 4096
623 net.ipv4.xfrm4_gc_thresh = 32768
624 net.ipv6.anycast_src_echo_reply = 0
625 net.ipv6.auto_flowlabels = 1
626 net.ipv6.bindv6only = 0
627 net.ipv6.calipso_cache_bucket_size = 10
628 net.ipv6.calipso_cache_enable = 1
629 net.ipv6.conf.all.accept_dad = 0
630 net.ipv6.conf.all.accept_ra = 1
631 net.ipv6.conf.all.accept_ra_defrtr = 1
632 net.ipv6.conf.all.accept_ra_from_local = 0
633 net.ipv6.conf.all.accept_ra_min_hop_limit = 1
634 net.ipv6.conf.all.accept_ra_mtu = 1
635 net.ipv6.conf.all.accept_ra_pinfo = 1
636 net.ipv6.conf.all.accept_ra_rt_info_max_plen = 0
637 net.ipv6.conf.all.accept_ra_rt_info_min_plen = 0
638 net.ipv6.conf.all.accept_ra_rtr_pref = 1
639 net.ipv6.conf.all.accept_redirects = 1
640 net.ipv6.conf.all.accept_source_route = 0
641 net.ipv6.conf.all.addr_gen_mode = 0
642 net.ipv6.conf.all.autoconf = 1
643 net.ipv6.conf.all.dad_transmits = 1
644 net.ipv6.conf.all.disable_ipv6 = 0
645 net.ipv6.conf.all.disable_policy = 0
646 net.ipv6.conf.all.drop_unicast_in_l2_multicast = 0
647 net.ipv6.conf.all.drop_unsolicited_na = 0
648 net.ipv6.conf.all.enhanced_dad = 1
649 net.ipv6.conf.all.force_mld_version = 0
650 net.ipv6.conf.all.force_tllao = 0
651 net.ipv6.conf.all.forwarding = 0
652 net.ipv6.conf.all.hop_limit = 64
653 net.ipv6.conf.all.ignore_routes_with_linkdown = 0
654 net.ipv6.conf.all.ioam6_enabled = 0
655 net.ipv6.conf.all.ioam6_id = 65535
656 net.ipv6.conf.all.ioam6_id_wide = 4294967295
657 net.ipv6.conf.all.keep_addr_on_down = 0
658 net.ipv6.conf.all.max_addresses = 16
659 net.ipv6.conf.all.max_desync_factor = 600
660 net.ipv6.conf.all.mc_forwarding = 0
661 net.ipv6.conf.all.mldv1_unsolicited_report_interval = 10000
662 net.ipv6.conf.all.mldv2_unsolicited_report_interval = 1000
663 net.ipv6.conf.all.mtu = 1280
664 net.ipv6.conf.all.ndisc_notify = 0
665 net.ipv6.conf.all.ndisc_tclass = 0
666 net.ipv6.conf.all.proxy_ndp = 0
667 net.ipv6.conf.all.ra_defrtr_metric = 1024
668 net.ipv6.conf.all.regen_max_retry = 3
669 net.ipv6.conf.all.router_probe_interval = 60
670 net.ipv6.conf.all.router_solicitation_delay = 1
671 net.ipv6.conf.all.router_solicitation_interval = 4
672 net.ipv6.conf.all.router_solicitation_max_interval = 3600
673 net.ipv6.conf.all.router_solicitations = -1
674 net.ipv6.conf.all.rpl_seg_enabled = 0
675 net.ipv6.conf.all.seg6_enabled = 0
676 net.ipv6.conf.all.seg6_require_hmac = 0
677 net.ipv6.conf.all.suppress_frag_ndisc = 1
678 net.ipv6.conf.all.temp_prefered_lft = 86400
679 net.ipv6.conf.all.temp_valid_lft = 604800
680 net.ipv6.conf.all.use_oif_addrs_only = 0
681 net.ipv6.conf.all.use_tempaddr = 2
682 net.ipv6.conf.default.accept_dad = 1
683 net.ipv6.conf.default.accept_ra = 1
684 net.ipv6.conf.default.accept_ra_defrtr = 1
685 net.ipv6.conf.default.accept_ra_from_local = 0
686 net.ipv6.conf.default.accept_ra_min_hop_limit = 1
687 net.ipv6.conf.default.accept_ra_mtu = 1
688 net.ipv6.conf.default.accept_ra_pinfo = 1
689 net.ipv6.conf.default.accept_ra_rt_info_max_plen = 0
690 net.ipv6.conf.default.accept_ra_rt_info_min_plen = 0
691 net.ipv6.conf.default.accept_ra_rtr_pref = 1
692 net.ipv6.conf.default.accept_redirects = 1
693 net.ipv6.conf.default.accept_source_route = 0
694 net.ipv6.conf.default.addr_gen_mode = 0
695 net.ipv6.conf.default.autoconf = 1
696 net.ipv6.conf.default.dad_transmits = 1
697 net.ipv6.conf.default.disable_ipv6 = 0
698 net.ipv6.conf.default.disable_policy = 0
699 net.ipv6.conf.default.drop_unicast_in_l2_multicast = 0
700 net.ipv6.conf.default.drop_unsolicited_na = 0
701 net.ipv6.conf.default.enhanced_dad = 1
702 net.ipv6.conf.default.force_mld_version = 0
703 net.ipv6.conf.default.force_tllao = 0
704 net.ipv6.conf.default.forwarding = 0
705 net.ipv6.conf.default.hop_limit = 64
706 net.ipv6.conf.default.ignore_routes_with_linkdown = 0
707 net.ipv6.conf.default.ioam6_enabled = 0
708 net.ipv6.conf.default.ioam6_id = 65535
709 net.ipv6.conf.default.ioam6_id_wide = 4294967295
710 net.ipv6.conf.default.keep_addr_on_down = 0
711 net.ipv6.conf.default.max_addresses = 16
712 net.ipv6.conf.default.max_desync_factor = 600
713 net.ipv6.conf.default.mc_forwarding = 0
714 net.ipv6.conf.default.mldv1_unsolicited_report_interval = 10000
715 net.ipv6.conf.default.mldv2_unsolicited_report_interval = 1000
716 net.ipv6.conf.default.mtu = 1280
717 net.ipv6.conf.default.ndisc_notify = 0
718 net.ipv6.conf.default.ndisc_tclass = 0
719 net.ipv6.conf.default.proxy_ndp = 0
720 net.ipv6.conf.default.ra_defrtr_metric = 1024
721 net.ipv6.conf.default.regen_max_retry = 3
722 net.ipv6.conf.default.router_probe_interval = 60
723 net.ipv6.conf.default.router_solicitation_delay = 1
724 net.ipv6.conf.default.router_solicitation_interval = 4
725 net.ipv6.conf.default.router_solicitation_max_interval = 3600
726 net.ipv6.conf.default.router_solicitations = -1
727 net.ipv6.conf.default.rpl_seg_enabled = 0
728 net.ipv6.conf.default.seg6_enabled = 0
729 net.ipv6.conf.default.seg6_require_hmac = 0
730 net.ipv6.conf.default.suppress_frag_ndisc = 1
731 net.ipv6.conf.default.temp_prefered_lft = 86400
732 net.ipv6.conf.default.temp_valid_lft = 604800
733 net.ipv6.conf.default.use_oif_addrs_only = 0
734 net.ipv6.conf.default.use_tempaddr = 2
735 net.ipv6.conf.docker0.accept_dad = 1
736 net.ipv6.conf.docker0.accept_ra = 0
737 net.ipv6.conf.docker0.accept_ra_defrtr = 1
738 net.ipv6.conf.docker0.accept_ra_from_local = 0
739 net.ipv6.conf.docker0.accept_ra_min_hop_limit = 1
740 net.ipv6.conf.docker0.accept_ra_mtu = 1
741 net.ipv6.conf.docker0.accept_ra_pinfo = 1
742 net.ipv6.conf.docker0.accept_ra_rt_info_max_plen = 0
743 net.ipv6.conf.docker0.accept_ra_rt_info_min_plen = 0
744 net.ipv6.conf.docker0.accept_ra_rtr_pref = 1
745 net.ipv6.conf.docker0.accept_redirects = 1
746 net.ipv6.conf.docker0.accept_source_route = 0
747 net.ipv6.conf.docker0.addr_gen_mode = 0
748 net.ipv6.conf.docker0.autoconf = 1
749 net.ipv6.conf.docker0.dad_transmits = 1
750 net.ipv6.conf.docker0.disable_ipv6 = 0
751 net.ipv6.conf.docker0.disable_policy = 0
752 net.ipv6.conf.docker0.drop_unicast_in_l2_multicast = 0
753 net.ipv6.conf.docker0.drop_unsolicited_na = 0
754 net.ipv6.conf.docker0.enhanced_dad = 1
755 net.ipv6.conf.docker0.force_mld_version = 0
756 net.ipv6.conf.docker0.force_tllao = 0
757 net.ipv6.conf.docker0.forwarding = 0
758 net.ipv6.conf.docker0.hop_limit = 64
759 net.ipv6.conf.docker0.ignore_routes_with_linkdown = 0
760 net.ipv6.conf.docker0.ioam6_enabled = 0
761 net.ipv6.conf.docker0.ioam6_id = 65535
762 net.ipv6.conf.docker0.ioam6_id_wide = 4294967295
763 net.ipv6.conf.docker0.keep_addr_on_down = 0
764 net.ipv6.conf.docker0.max_addresses = 16
765 net.ipv6.conf.docker0.max_desync_factor = 600
766 net.ipv6.conf.docker0.mc_forwarding = 0
767 net.ipv6.conf.docker0.mldv1_unsolicited_report_interval = 10000
768 net.ipv6.conf.docker0.mldv2_unsolicited_report_interval = 1000
769 net.ipv6.conf.docker0.mtu = 1500
770 net.ipv6.conf.docker0.ndisc_notify = 0
771 net.ipv6.conf.docker0.ndisc_tclass = 0
772 net.ipv6.conf.docker0.proxy_ndp = 0
773 net.ipv6.conf.docker0.ra_defrtr_metric = 1024
774 net.ipv6.conf.docker0.regen_max_retry = 3
775 net.ipv6.conf.docker0.router_probe_interval = 60
776 net.ipv6.conf.docker0.router_solicitation_delay = 1
777 net.ipv6.conf.docker0.router_solicitation_interval = 4
778 net.ipv6.conf.docker0.router_solicitation_max_interval = 3600
779 net.ipv6.conf.docker0.router_solicitations = -1
780 net.ipv6.conf.docker0.rpl_seg_enabled = 0
781 net.ipv6.conf.docker0.seg6_enabled = 0
782 net.ipv6.conf.docker0.seg6_require_hmac = 0
783 net.ipv6.conf.docker0.suppress_frag_ndisc = 1
784 net.ipv6.conf.docker0.temp_prefered_lft = 86400
785 net.ipv6.conf.docker0.temp_valid_lft = 604800
786 net.ipv6.conf.docker0.use_oif_addrs_only = 0
787 net.ipv6.conf.docker0.use_tempaddr = 2
788 net.ipv6.conf.ens160.accept_dad = 1
789 net.ipv6.conf.ens160.accept_ra = 0
790 net.ipv6.conf.ens160.accept_ra_defrtr = 1
791 net.ipv6.conf.ens160.accept_ra_from_local = 0
792 net.ipv6.conf.ens160.accept_ra_min_hop_limit = 1
793 net.ipv6.conf.ens160.accept_ra_mtu = 1
794 net.ipv6.conf.ens160.accept_ra_pinfo = 1
795 net.ipv6.conf.ens160.accept_ra_rt_info_max_plen = 0
796 net.ipv6.conf.ens160.accept_ra_rt_info_min_plen = 0
797 net.ipv6.conf.ens160.accept_ra_rtr_pref = 1
798 net.ipv6.conf.ens160.accept_redirects = 1
799 net.ipv6.conf.ens160.accept_source_route = 0
800 net.ipv6.conf.ens160.addr_gen_mode = 0
801 net.ipv6.conf.ens160.autoconf = 1
802 net.ipv6.conf.ens160.dad_transmits = 1
803 net.ipv6.conf.ens160.disable_ipv6 = 0
804 net.ipv6.conf.ens160.disable_policy = 0
805 net.ipv6.conf.ens160.drop_unicast_in_l2_multicast = 0
806 net.ipv6.conf.ens160.drop_unsolicited_na = 0
807 net.ipv6.conf.ens160.enhanced_dad = 1
808 net.ipv6.conf.ens160.force_mld_version = 0
809 net.ipv6.conf.ens160.force_tllao = 0
810 net.ipv6.conf.ens160.forwarding = 0
811 net.ipv6.conf.ens160.hop_limit = 64
812 net.ipv6.conf.ens160.ignore_routes_with_linkdown = 0
813 net.ipv6.conf.ens160.ioam6_enabled = 0
814 net.ipv6.conf.ens160.ioam6_id = 65535
815 net.ipv6.conf.ens160.ioam6_id_wide = 4294967295
816 net.ipv6.conf.ens160.keep_addr_on_down = 0
817 net.ipv6.conf.ens160.max_addresses = 16
818 net.ipv6.conf.ens160.max_desync_factor = 600
819 net.ipv6.conf.ens160.mc_forwarding = 0
820 net.ipv6.conf.ens160.mldv1_unsolicited_report_interval = 10000
821 net.ipv6.conf.ens160.mldv2_unsolicited_report_interval = 1000
822 net.ipv6.conf.ens160.mtu = 1500
823 net.ipv6.conf.ens160.ndisc_notify = 0
824 net.ipv6.conf.ens160.ndisc_tclass = 0
825 net.ipv6.conf.ens160.proxy_ndp = 0
826 net.ipv6.conf.ens160.ra_defrtr_metric = 1024
827 net.ipv6.conf.ens160.regen_max_retry = 3
828 net.ipv6.conf.ens160.router_probe_interval = 60
829 net.ipv6.conf.ens160.router_solicitation_delay = 1
830 net.ipv6.conf.ens160.router_solicitation_interval = 4
831 net.ipv6.conf.ens160.router_solicitation_max_interval = 3600
832 net.ipv6.conf.ens160.router_solicitations = -1
833 net.ipv6.conf.ens160.rpl_seg_enabled = 0
834 net.ipv6.conf.ens160.seg6_enabled = 0
835 net.ipv6.conf.ens160.seg6_require_hmac = 0
836 net.ipv6.conf.ens160.suppress_frag_ndisc = 1
837 net.ipv6.conf.ens160.temp_prefered_lft = 86400
838 net.ipv6.conf.ens160.temp_valid_lft = 604800
839 net.ipv6.conf.ens160.use_oif_addrs_only = 0
840 net.ipv6.conf.ens160.use_tempaddr = 0
841 net.ipv6.conf.lo.accept_dad = -1
842 net.ipv6.conf.lo.accept_ra = 1
843 net.ipv6.conf.lo.accept_ra_defrtr = 1
844 net.ipv6.conf.lo.accept_ra_from_local = 0
845 net.ipv6.conf.lo.accept_ra_min_hop_limit = 1
846 net.ipv6.conf.lo.accept_ra_mtu = 1
847 net.ipv6.conf.lo.accept_ra_pinfo = 1
848 net.ipv6.conf.lo.accept_ra_rt_info_max_plen = 0
849 net.ipv6.conf.lo.accept_ra_rt_info_min_plen = 0
850 net.ipv6.conf.lo.accept_ra_rtr_pref = 1
851 net.ipv6.conf.lo.accept_redirects = 1
852 net.ipv6.conf.lo.accept_source_route = 0
853 net.ipv6.conf.lo.addr_gen_mode = 0
854 net.ipv6.conf.lo.autoconf = 1
855 net.ipv6.conf.lo.dad_transmits = 1
856 net.ipv6.conf.lo.disable_ipv6 = 0
857 net.ipv6.conf.lo.disable_policy = 0
858 net.ipv6.conf.lo.drop_unicast_in_l2_multicast = 0
859 net.ipv6.conf.lo.drop_unsolicited_na = 0
860 net.ipv6.conf.lo.enhanced_dad = 1
861 net.ipv6.conf.lo.force_mld_version = 0
862 net.ipv6.conf.lo.force_tllao = 0
863 net.ipv6.conf.lo.forwarding = 0
864 net.ipv6.conf.lo.hop_limit = 64
865 net.ipv6.conf.lo.ignore_routes_with_linkdown = 0
866 net.ipv6.conf.lo.ioam6_enabled = 0
867 net.ipv6.conf.lo.ioam6_id = 65535
868 net.ipv6.conf.lo.ioam6_id_wide = 4294967295
869 net.ipv6.conf.lo.keep_addr_on_down = 0
870 net.ipv6.conf.lo.max_addresses = 16
871 net.ipv6.conf.lo.max_desync_factor = 600
872 net.ipv6.conf.lo.mc_forwarding = 0
873 net.ipv6.conf.lo.mldv1_unsolicited_report_interval = 10000
874 net.ipv6.conf.lo.mldv2_unsolicited_report_interval = 1000
875 net.ipv6.conf.lo.mtu = 65536
876 net.ipv6.conf.lo.ndisc_notify = 0
877 net.ipv6.conf.lo.ndisc_tclass = 0
878 net.ipv6.conf.lo.proxy_ndp = 0
879 net.ipv6.conf.lo.ra_defrtr_metric = 1024
880 net.ipv6.conf.lo.regen_max_retry = 3
881 net.ipv6.conf.lo.router_probe_interval = 60
882 net.ipv6.conf.lo.router_solicitation_delay = 1
883 net.ipv6.conf.lo.router_solicitation_interval = 4
884 net.ipv6.conf.lo.router_solicitation_max_interval = 3600
885 net.ipv6.conf.lo.router_solicitations = -1
886 net.ipv6.conf.lo.rpl_seg_enabled = 0
887 net.ipv6.conf.lo.seg6_enabled = 0
888 net.ipv6.conf.lo.seg6_require_hmac = 0
889 net.ipv6.conf.lo.suppress_frag_ndisc = 1
890 net.ipv6.conf.lo.temp_prefered_lft = 86400
891 net.ipv6.conf.lo.temp_valid_lft = 604800
892 net.ipv6.conf.lo.use_oif_addrs_only = 0
893 net.ipv6.conf.lo.use_tempaddr = -1
894 net.ipv6.fib_multipath_hash_fields = 7
895 net.ipv6.fib_multipath_hash_policy = 0
896 net.ipv6.fib_notify_on_flag_change = 0
897 net.ipv6.flowlabel_consistency = 1
898 net.ipv6.flowlabel_reflect = 0
899 net.ipv6.flowlabel_state_ranges = 0
900 net.ipv6.fwmark_reflect = 0
901 net.ipv6.icmp.echo_ignore_all = 0
902 net.ipv6.icmp.echo_ignore_anycast = 0
903 net.ipv6.icmp.echo_ignore_multicast = 0
904 net.ipv6.icmp.ratelimit = 1000
905 net.ipv6.icmp.ratemask = 0-1,3-127
906 net.ipv6.idgen_delay = 1
907 net.ipv6.idgen_retries = 3
908 net.ipv6.ioam6_id = 16777215
909 net.ipv6.ioam6_id_wide = 72057594037927935
910 net.ipv6.ip6frag_high_thresh = 4194304
911 net.ipv6.ip6frag_low_thresh = 3145728
912 net.ipv6.ip6frag_secret_interval = 0
913 net.ipv6.ip6frag_time = 60
914 net.ipv6.ip_nonlocal_bind = 0
915 net.ipv6.max_dst_opts_length = 2147483647
916 net.ipv6.max_dst_opts_number = 8
917 net.ipv6.max_hbh_length = 2147483647
918 net.ipv6.max_hbh_opts_number = 8
919 net.ipv6.mld_max_msf = 64
920 net.ipv6.mld_qrv = 2
921 net.ipv6.neigh.default.anycast_delay = 100
922 net.ipv6.neigh.default.app_solicit = 0
923 net.ipv6.neigh.default.base_reachable_time_ms = 30000
924 net.ipv6.neigh.default.delay_first_probe_time = 5
925 net.ipv6.neigh.default.gc_interval = 30
926 net.ipv6.neigh.default.gc_stale_time = 60
927 net.ipv6.neigh.default.gc_thresh1 = 128
928 net.ipv6.neigh.default.gc_thresh2 = 512
929 net.ipv6.neigh.default.gc_thresh3 = 1024
930 net.ipv6.neigh.default.locktime = 0
931 net.ipv6.neigh.default.mcast_resolicit = 0
932 net.ipv6.neigh.default.mcast_solicit = 3
933 net.ipv6.neigh.default.proxy_delay = 80
934 net.ipv6.neigh.default.proxy_qlen = 64
935 net.ipv6.neigh.default.retrans_time_ms = 1000
936 net.ipv6.neigh.default.ucast_solicit = 3
937 net.ipv6.neigh.default.unres_qlen = 101
938 net.ipv6.neigh.default.unres_qlen_bytes = 212992
939 net.ipv6.neigh.docker0.anycast_delay = 100
940 net.ipv6.neigh.docker0.app_solicit = 0
941 net.ipv6.neigh.docker0.base_reachable_time_ms = 30000
942 net.ipv6.neigh.docker0.delay_first_probe_time = 5
943 net.ipv6.neigh.docker0.gc_stale_time = 60
944 net.ipv6.neigh.docker0.locktime = 0
945 net.ipv6.neigh.docker0.mcast_resolicit = 0
946 net.ipv6.neigh.docker0.mcast_solicit = 3
947 net.ipv6.neigh.docker0.proxy_delay = 80
948 net.ipv6.neigh.docker0.proxy_qlen = 64
949 net.ipv6.neigh.docker0.retrans_time_ms = 1000
950 net.ipv6.neigh.docker0.ucast_solicit = 3
951 net.ipv6.neigh.docker0.unres_qlen = 101
952 net.ipv6.neigh.docker0.unres_qlen_bytes = 212992
953 net.ipv6.neigh.ens160.anycast_delay = 100
954 net.ipv6.neigh.ens160.app_solicit = 0
955 net.ipv6.neigh.ens160.base_reachable_time_ms = 30000
956 net.ipv6.neigh.ens160.delay_first_probe_time = 5
957 net.ipv6.neigh.ens160.gc_stale_time = 60
958 net.ipv6.neigh.ens160.locktime = 0
959 net.ipv6.neigh.ens160.mcast_resolicit = 0
960 net.ipv6.neigh.ens160.mcast_solicit = 3
961 net.ipv6.neigh.ens160.proxy_delay = 80
962 net.ipv6.neigh.ens160.proxy_qlen = 64
963 net.ipv6.neigh.ens160.retrans_time_ms = 1000
964 net.ipv6.neigh.ens160.ucast_solicit = 3
965 net.ipv6.neigh.ens160.unres_qlen = 101
966 net.ipv6.neigh.ens160.unres_qlen_bytes = 212992
967 net.ipv6.neigh.lo.anycast_delay = 100
968 net.ipv6.neigh.lo.app_solicit = 0
969 net.ipv6.neigh.lo.base_reachable_time_ms = 30000
970 net.ipv6.neigh.lo.delay_first_probe_time = 5
971 net.ipv6.neigh.lo.gc_stale_time = 60
972 net.ipv6.neigh.lo.locktime = 0
973 net.ipv6.neigh.lo.mcast_resolicit = 0
974 net.ipv6.neigh.lo.mcast_solicit = 3
975 net.ipv6.neigh.lo.proxy_delay = 80
976 net.ipv6.neigh.lo.proxy_qlen = 64
977 net.ipv6.neigh.lo.retrans_time_ms = 1000
978 net.ipv6.neigh.lo.ucast_solicit = 3
979 net.ipv6.neigh.lo.unres_qlen = 101
980 net.ipv6.neigh.lo.unres_qlen_bytes = 212992
981 net.ipv6.route.gc_elasticity = 9
982 net.ipv6.route.gc_interval = 30
983 net.ipv6.route.gc_min_interval = 0
984 net.ipv6.route.gc_min_interval_ms = 500
985 net.ipv6.route.gc_thresh = 1024
986 net.ipv6.route.gc_timeout = 60
987 net.ipv6.route.max_size = 4096
988 net.ipv6.route.min_adv_mss = 1220
989 net.ipv6.route.mtu_expires = 600
990 net.ipv6.route.skip_notify_on_dev_down = 0
991 net.ipv6.seg6_flowlabel = 0
992 net.ipv6.xfrm6_gc_thresh = 32768
993 net.iw_cm.default_backlog = 256
994 net.mptcp.add_addr_timeout = 120
995 net.mptcp.allow_join_initial_addr_port = 1
996 net.mptcp.checksum_enabled = 0
997 net.mptcp.enabled = 1
998 net.mptcp.stale_loss_cnt = 4
999 net.netfilter.nf_conntrack_acct = 0
1000 net.netfilter.nf_conntrack_buckets = 262144
1001 net.netfilter.nf_conntrack_checksum = 1
1002 net.netfilter.nf_conntrack_count = 105
1003 net.netfilter.nf_conntrack_dccp_loose = 1
1004 net.netfilter.nf_conntrack_dccp_timeout_closereq = 64
1005 net.netfilter.nf_conntrack_dccp_timeout_closing = 64
1006 net.netfilter.nf_conntrack_dccp_timeout_open = 43200
1007 net.netfilter.nf_conntrack_dccp_timeout_partopen = 480
1008 net.netfilter.nf_conntrack_dccp_timeout_request = 240
1009 net.netfilter.nf_conntrack_dccp_timeout_respond = 480
1010 net.netfilter.nf_conntrack_dccp_timeout_timewait = 240
1011 net.netfilter.nf_conntrack_events = 1
1012 net.netfilter.nf_conntrack_expect_max = 4096
1013 net.netfilter.nf_conntrack_frag6_high_thresh = 4194304
1014 net.netfilter.nf_conntrack_frag6_low_thresh = 3145728
1015 net.netfilter.nf_conntrack_frag6_timeout = 60
1016 net.netfilter.nf_conntrack_generic_timeout = 600
1017 net.netfilter.nf_conntrack_gre_timeout = 30
1018 net.netfilter.nf_conntrack_gre_timeout_stream = 180
1019 net.netfilter.nf_conntrack_helper = 0
1020 net.netfilter.nf_conntrack_icmp_timeout = 30
1021 net.netfilter.nf_conntrack_icmpv6_timeout = 30
1022 net.netfilter.nf_conntrack_log_invalid = 0
1023 net.netfilter.nf_conntrack_max = 262144
1024 net.netfilter.nf_conntrack_sctp_timeout_closed = 10
1025 net.netfilter.nf_conntrack_sctp_timeout_cookie_echoed = 3
1026 net.netfilter.nf_conntrack_sctp_timeout_cookie_wait = 3
1027 net.netfilter.nf_conntrack_sctp_timeout_established = 432000
1028 net.netfilter.nf_conntrack_sctp_timeout_heartbeat_acked = 210
1029 net.netfilter.nf_conntrack_sctp_timeout_heartbeat_sent = 30
1030 net.netfilter.nf_conntrack_sctp_timeout_shutdown_ack_sent = 3
1031 net.netfilter.nf_conntrack_sctp_timeout_shutdown_recd = 0
1032 net.netfilter.nf_conntrack_sctp_timeout_shutdown_sent = 0
1033 net.netfilter.nf_conntrack_tcp_be_liberal = 0
1034 net.netfilter.nf_conntrack_tcp_ignore_invalid_rst = 0
1035 net.netfilter.nf_conntrack_tcp_loose = 1
1036 net.netfilter.nf_conntrack_tcp_max_retrans = 3
1037 net.netfilter.nf_conntrack_tcp_timeout_close = 10
1038 net.netfilter.nf_conntrack_tcp_timeout_close_wait = 60
1039 net.netfilter.nf_conntrack_tcp_timeout_established = 432000
1040 net.netfilter.nf_conntrack_tcp_timeout_fin_wait = 120
1041 net.netfilter.nf_conntrack_tcp_timeout_last_ack = 30
1042 net.netfilter.nf_conntrack_tcp_timeout_max_retrans = 300
1043 net.netfilter.nf_conntrack_tcp_timeout_syn_recv = 60
1044 net.netfilter.nf_conntrack_tcp_timeout_syn_sent = 120
1045 net.netfilter.nf_conntrack_tcp_timeout_time_wait = 120
1046 net.netfilter.nf_conntrack_tcp_timeout_unacknowledged = 300
1047 net.netfilter.nf_conntrack_timestamp = 0
1048 net.netfilter.nf_conntrack_udp_timeout = 30
1049 net.netfilter.nf_conntrack_udp_timeout_stream = 120
1050 net.netfilter.nf_flowtable_tcp_timeout = 30
1051 net.netfilter.nf_flowtable_udp_timeout = 30
1052 net.netfilter.nf_hooks_lwtunnel = 0
1053 net.netfilter.nf_log.0 = NONE
1054 net.netfilter.nf_log.1 = NONE
1055 net.netfilter.nf_log.10 = NONE
1056 net.netfilter.nf_log.11 = NONE
1057 net.netfilter.nf_log.12 = NONE
1058 net.netfilter.nf_log.2 = NONE
1059 net.netfilter.nf_log.3 = NONE
1060 net.netfilter.nf_log.4 = NONE
1061 net.netfilter.nf_log.5 = NONE
1062 net.netfilter.nf_log.6 = NONE
1063 net.netfilter.nf_log.7 = NONE
1064 net.netfilter.nf_log.8 = NONE
1065 net.netfilter.nf_log.9 = NONE
1066 net.netfilter.nf_log_all_netns = 0
1067 net.nf_conntrack_max = 262144
1068 net.unix.max_dgram_qlen = 512
1069 user.max_cgroup_namespaces = 31231
1070 user.max_fanotify_groups = 128
1071 user.max_fanotify_marks = 64771
1072 user.max_inotify_instances = 128
1073 user.max_inotify_watches = 60915
1074 user.max_ipc_namespaces = 31231
1075 user.max_mnt_namespaces = 31231
1076 user.max_net_namespaces = 31231
1077 user.max_pid_namespaces = 31231
1078 user.max_time_namespaces = 31231
1079 user.max_user_namespaces = 31231
1080 user.max_uts_namespaces = 31231
1081 vm.admin_reserve_kbytes = 8192
1082 vm.compact_unevictable_allowed = 1
1083 vm.compaction_proactiveness = 20
1084 vm.dirty_background_bytes = 0
1085 vm.dirty_background_ratio = 10
1086 vm.dirty_bytes = 0
1087 vm.dirty_expire_centisecs = 3000
1088 vm.dirty_ratio = 20
1089 vm.dirty_writeback_centisecs = 500
1090 vm.dirtytime_expire_seconds = 43200
1091 vm.extfrag_threshold = 500
1092 vm.hugetlb_shm_group = 0
1093 vm.laptop_mode = 0
1094 vm.legacy_va_layout = 0
1095 vm.lowmem_reserve_ratio = 256   256     32      0       0
1096 vm.max_map_count = 65530
1097 vm.memory_failure_early_kill = 0
1098 vm.memory_failure_recovery = 1
1099 vm.min_free_kbytes = 67584
1100 vm.min_slab_ratio = 5
1101 vm.min_unmapped_ratio = 1
1102 vm.mmap_min_addr = 65536
1103 vm.mmap_rnd_bits = 28
1104 vm.mmap_rnd_compat_bits = 8
1105 vm.nr_hugepages = 0
1106 vm.nr_hugepages_mempolicy = 0
1107 vm.nr_overcommit_hugepages = 0
1108 vm.numa_stat = 1
1109 vm.numa_zonelist_order = Node
1110 vm.oom_dump_tasks = 1
1111 vm.oom_kill_allocating_task = 0
1112 vm.overcommit_kbytes = 0
1113 vm.overcommit_memory = 0
1114 vm.overcommit_ratio = 50
1115 vm.page-cluster = 3
1116 vm.page_lock_unfairness = 5
1117 vm.panic_on_oom = 0
1118 vm.percpu_pagelist_high_fraction = 0
1119 vm.stat_interval = 1
1120 vm.swappiness = 60
1121 vm.unprivileged_userfaultfd = 0
1122 vm.user_reserve_kbytes = 131072
1123 vm.vfs_cache_pressure = 100
1124 vm.watermark_boost_factor = 15000
1125 vm.watermark_scale_factor = 10
1126 vm.zone_reclaim_mode = 0