system: set net.pf.request_maxcount default value

While here also migrate the enc filter rules to our new style.
Useful for testing so tunables can be overwritten by users.

PR: https://github.com/opnsense/core/issues/3969
This commit is contained in:
Franco Fichtner 2020-03-13 14:28:53 +01:00
parent 116511910d
commit f09aceecb3

View File

@ -78,6 +78,10 @@ function get_default_sysctl_value($id)
'hw.syscons.kbd_reboot' => '0',
'kern.ipc.maxsockbuf' => '4262144',
'kern.randompid' => '347',
'net.enc.in.ipsec_bpf_mask' => '2', /* after processing */
'net.enc.in.ipsec_filter_mask' => '2', /* after processing */
'net.enc.out.ipsec_bpf_mask' => '1', /* before processing */
'net.enc.out.ipsec_filter_mask' => '1', /* before processing */
'net.inet.icmp.drop_redirect' => '0',
'net.inet.icmp.icmplim' => '0',
'net.inet.icmp.log_redirect' => '0',
@ -107,6 +111,7 @@ function get_default_sysctl_value($id)
'net.link.bridge.pfil_onlyip' => '0',
'net.link.tap.user_open' => '1',
'net.local.dgram.maxdgram' => '8192',
'net.pf.request_maxcount' => '500000',
'security.bsd.see_other_gids' => '0',
'security.bsd.see_other_uids' => '0',
'vfs.read_max' => '32',
@ -125,11 +130,12 @@ function system_sysctl_get()
global $config;
$sysctls = array(
'net.enc.in.ipsec_bpf_mask' => '2', /* after processing */
'net.enc.in.ipsec_filter_mask' => '2', /* after processing */
'net.enc.out.ipsec_bpf_mask' => '1', /* before processing */
'net.enc.out.ipsec_filter_mask' => '1', /* before processing */
'net.enc.in.ipsec_bpf_mask' => 'default',
'net.enc.in.ipsec_filter_mask' => 'default',
'net.enc.out.ipsec_bpf_mask' => 'default',
'net.enc.out.ipsec_filter_mask' => 'default',
'net.local.dgram.maxdgram' => 'default',
'net.pf.request_maxcount' => 'default',
);
foreach (config_read_array('sysctl', 'item') as $tunable) {