LINUXOR.SK ... open source notes ...

Vault - sysctl.conf (kernel parameters)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Linux hardening

The kernel parameter file of the Vault nodes as built in 2023, hardening and network tuning in one file. It is kept as the record of what ran. For a new build start from the two maintained profiles instead: Linux kernel hardening with sysctl and Linux kernel performance tuning with sysctl.

ItemValue
Path on the host/etc/sysctl.conf
Shown hereVault node
Deployed onevery server, with the differences listed below
Applied withsysctl -p

The file

ini
#------------------------------------------------------------------------------
# File: sysctl.conf
# Description: Hardened kernel configuration
# Author: admin01
# Date: 2023
#------------------------------------------------------------------------------

#------------------------------------------------------------------------------
# Tweak virtual memory
#------------------------------------------------------------------------------

# Default: 30
# 0 - Never swap under any circumstances.
# 1 - Do not swap unless there is an out-of-memory (OOM) condition.
vm.swappiness=0

# vm.dirty_background_ratio is used to adjust how the kernel handles dirty pages that must be flushed to disk.
# Default value is 10.
# The value is a percentage of the total amount of system memory, and setting this value to 5 is appropriate in many situations.
# This setting should not be set to zero.
vm.dirty_background_ratio=5

# The total number of dirty pages that are allowed before the kernel forces synchronous operations to flush them to disk
# can also be increased by changing the value of vm.dirty_ratio, increasing it to above the default of 30 (also a percentage of total system memory)
# vm.dirty_ratio value in-between 60 and 80 is a reasonable number.
vm.dirty_ratio=60

# vm.max_map_count will calculate the current number of memory-mapped files.
# The minimum value for mmap limit (vm.max_map_count) is the number of open files ulimit (cat /proc/sys/fs/file-max).
# map_count should be around 1 per 128 KB of system memory. Therefore, max_map_count will be 262144 on a 32 GB system.
# Reference: https://docs.confluent.io/current/kafka/deployment.html
# Default: 65530
vm.max_map_count=2097152

#------------------------------------------------------------------------------
# Tweak file descriptors
#------------------------------------------------------------------------------

# Increases the size of file descriptors and inode cache and restricts core dumps.
fs.file-max=2097152
fs.suid_dumpable=0

#------------------------------------------------------------------------------
# Tweak network settings
#------------------------------------------------------------------------------

# Default amount of memory allocated for the send and receive buffers for each socket.
# This will significantly increase performance for large transfers.
net.core.wmem_default=25165824
net.core.rmem_default=25165824

# Maximum amount of memory allocated for the send and receive buffers for each socket.
# This will significantly increase performance for large transfers.
net.core.wmem_max=25165824
net.core.rmem_max=25165824

# In addition to the socket settings, the send and receive buffer sizes for
# TCP sockets must be set separately using the net.ipv4.tcp_wmem and net.ipv4.tcp_rmem parameters.
# These are set using three space-separated integers that specify the minimum, default, and maximum sizes, respectively.
# The maximum size cannot be larger than the values specified for all sockets using net.core.wmem_max and net.core.rmem_max.
# A reasonable setting is a 4 KiB minimum, 64 KiB default, and 2 MiB maximum buffer.
net.ipv4.tcp_wmem=20480 12582912 25165824
net.ipv4.tcp_rmem=20480 12582912 25165824

# Increase the maximum total buffer-space allocatable
# This is measured in units of pages (4096 bytes)
net.ipv4.tcp_mem=65536 25165824 262144
net.ipv4.udp_mem=65536 25165824 262144

# Minimum amount of memory allocated for the send and receive buffers for each socket.
net.ipv4.udp_wmem_min=16384
net.ipv4.udp_rmem_min=16384

# Enabling TCP window scaling by setting net.ipv4.tcp_window_scaling to 1 will allow
# clients to transfer data more efficiently, and allow that data to be buffered on the broker side.
net.ipv4.tcp_window_scaling=1

# Increasing the value of net.ipv4.tcp_max_syn_backlog above the default of 1024 will allow
# a greater number of simultaneous connections to be accepted.
net.ipv4.tcp_max_syn_backlog=10240

# Increasing the value of net.core.netdev_max_backlog to greater than the default of 1000
# can assist with bursts of network traffic, specifically when using multigigabit network connection speeds,
# by allowing more packets to be queued for the kernel to process them.
net.core.netdev_max_backlog=65536

# Increase the maximum amount of option memory buffers
net.core.optmem_max=25165824

# Number of times SYNACKs for passive TCP connection.
net.ipv4.tcp_synack_retries=2

# Allowed local port range.
net.ipv4.ip_local_port_range=2048 65535

# Protect Against TCP Time-Wait
# Default: net.ipv4.tcp_rfc1337 = 0
net.ipv4.tcp_rfc1337=1

# Decrease the time default value for tcp_fin_timeout connection
net.ipv4.tcp_fin_timeout=15

# The maximum number of backlogged sockets.
# Default is 128.
net.core.somaxconn=4096

# Turn on syncookies for SYN flood attack protection.
net.ipv4.tcp_syncookies=1

# Avoid a smurf attack
net.ipv4.icmp_echo_ignore_broadcasts=1

# Turn on protection for bad icmp error messages
net.ipv4.icmp_ignore_bogus_error_responses=1

# Enable automatic window scaling.
# This will allow the TCP buffer to grow beyond its usual maximum of 64K if the latency justifies it.

# Turn on and log spoofed, source routed, and redirect packets
net.ipv4.conf.all.log_martians=1
net.ipv4.conf.default.log_martians=1

# Tells the kernel how many TCP sockets that are not attached to any
# user file handle to maintain. In case this number is exceeded,
# orphaned connections are immediately reset and a warning is printed.
# Default: net.ipv4.tcp_max_orphans = 65536
net.ipv4.tcp_max_orphans=65536

# Do not cache metrics on closing connections
net.ipv4.tcp_no_metrics_save=1

# Disable timestamps as defined in RFC1323:
# Default: net.ipv4.tcp_timestamps = 1
net.ipv4.tcp_timestamps=0

# Enable select acknowledgments.
# Default: net.ipv4.tcp_sack = 1
net.ipv4.tcp_sack=1

# Increase the tcp-time-wait buckets pool size to prevent simple DOS attacks.
# net.ipv4.tcp_tw_recycle has been removed from Linux?4.12. Use net.ipv4.tcp_tw_reuse instead.
net.ipv4.tcp_max_tw_buckets=1440000
net.ipv4.tcp_tw_reuse=1

# The accept_source_route option causes network interfaces to accept packets with the Strict Source Route (SSR) or Loose Source Routing (LSR) option set.
# The following setting will drop packets with the SSR or LSR option set.
net.ipv4.conf.all.accept_source_route=0
net.ipv6.conf.all.accept_source_route=0
net.ipv4.conf.default.accept_source_route=0
net.ipv6.conf.default.accept_source_route=0

# Turn on reverse path filtering
net.ipv4.conf.all.rp_filter=1
net.ipv4.conf.default.rp_filter=1

# Disable ICMP redirect acceptance
net.ipv4.conf.all.accept_redirects=0
net.ipv6.conf.all.accept_redirects=0
net.ipv4.conf.default.accept_redirects=0
net.ipv6.conf.default.accept_redirects=0
net.ipv4.conf.all.secure_redirects=0
net.ipv4.conf.default.secure_redirects=0

# Disables sending of all IPv4 ICMP redirected packets.
net.ipv4.conf.all.send_redirects=0
net.ipv4.conf.default.send_redirects=0

# Set ICMP ratemask
net.ipv4.icmp_ratemask=88089

# Disable IP forwarding.
# IP forwarding is the ability for an operating system to accept incoming network packets on one interface,
# recognize that it is not meant for the system itself, but that it should be passed on to another network, and then forwards it accordingly.
net.ipv4.ip_forward=0
net.ipv6.conf.all.forwarding=0

# Disable IPv6
net.ipv6.conf.all.disable_ipv6=1
net.ipv6.conf.default.disable_ipv6=1

# Disable acceptance of IPv6 router advertisements
net.ipv6.conf.all.accept_ra=0
net.ipv6.conf.default.accept_ra=0

# ARP related hardening
net.ipv4.conf.default.arp_announce=2
net.ipv4.conf.all.arp_announce=2
net.ipv4.conf.default.arp_ignore=2
net.ipv4.conf.all.arp_ignore=2

# Disable shared media
net.ipv4.conf.default.shared_media=0
net.ipv4.conf.all.shared_media=0

#------------------------------------------------------------------------------
# Tweak kernel parameters
#------------------------------------------------------------------------------

# Address Space Layout Randomization (ASLR) is a memory-protection process for operating systems that guards against buffer-overflow attacks.
# It helps to ensure that the memory addresses associated with running processes on systems are not predictable,
# thus flaws or vulnerabilities associated with these processes will be more difficult to exploit.
# Accepted values: 0 = Disabled, 1 = Conservative Randomization, 2 = Full Randomization
kernel.randomize_va_space=2

# Allow for more PIDs (to reduce rollover problems)
kernel.pid_max=65536

Per-role differences

RoleSettingValue
Vault node, bastionnet.ipv4.ip_forward0
Load balancernet.ipv4.ip_forward1
Load balancernet.ipv4.ip_nonlocal_bind1, in the separate file /etc/sysctl.d/haproxy.conf, so HAProxy can bind the virtual address on the node that does not hold it

Reading it today

← solutionz