1
|
# Do not send RSTs for packets to closed ports
|
2
|
net.inet.tcp.blackhole=2
|
3
|
# Do not send ICMP port unreach messages for closed ports
|
4
|
net.inet.udp.blackhole=1
|
5
|
# Generate random IP_ID's
|
6
|
net.inet.ip.random_id=1
|
7
|
# Breaks RFC1379, but nobody uses it anyway
|
8
|
net.inet.tcp.drop_synfin=1
|
9
|
net.inet.ip.redirect=0
|
10
|
kern.ipc.somaxconn=2048
|
11
|
net.inet.tcp.syncookies=1
|
12
|
net.inet.tcp.recvspace=65228
|
13
|
net.inet.tcp.sendspace=65228
|
14
|
net.inet.ip.fastforwarding=1
|
15
|
net.isr.enable=1
|
16
|
kern.maxfiles=16384
|
17
|
kern.maxfilesperproc=16384
|
18
|
net.inet.tcp.delayed_ack=0
|
19
|
kern.ipc.maxsockbuf=2097152
|
20
|
net.inet.udp.maxdgram=57344
|