1.添加bond配置文件
cp /etc/sysconfig/network-scripts/ifcfg-em1/etc/sysconfig/network-scripts/ifcfg-bond60
2.编辑bond60配置文件
vi/etc/sysconfig/network-scripts/ifcfg-bond60
删除uuid和freedns两项,修改DEVICE=bond60
ONBOOT=yes
TYPE=Ethernet
NM_CONTROLLED=no
BOOTPROTO=static
IPADDR=X.X.X.X
NETMASK=X.X.X.X
GTAEWAY=X.X.X.X
ARPCHECK=no
BONDING_OPTS="mode=6miimon=100"
3.修改网卡1的配置文件
vi/etc/sysconfig/network-scripts/ifcfg-em1
删除uuid和FREEDNS两项,修改:DEVICE=em1
TYPE=Ethernet
ONBOOT=yes
NM_CONTROLLED=no
BOOTPROTO=none
MASTER=bond60
SLAVE=yes
4.用刚修改好的em1的配置文件覆盖em2的配置文件:catifcfg-em1 > ifcfg-em2。然后修改em2配置文件:vi ifcfg-em2
DEVICE=em2(只需将em1修改为em2)
TYPE=Ethernet
ONBOOT=yes
NM_CONTROLLED=no
BOOTPROTO=none
MASTER=bond60
SLAVE=yes
5.添加dns解析:echo "dnsnameserver 202.106.0.2" > /etc/resolv.conf
6.测试网络连通性:pingwww.baidu.com
7.重启网络:/etc/init.d/networkrestart
8.ssh到服务器
9.清理yum缓存:yum clean all
10.在系统中安装基本的支持包:
yum -y install vim iptrafsysstat lsof zlib-devel bind-utils telnet dmidecode wget openssl-devel tcpdumpntpdate gcc gcc-c++ make pcre-devel \
readline-develpciutils openssl-devel xinetd bc
11.新建优化脚本文件init.sh:vi init.sh
复制优化脚本到init.sh中:
#modify ulimit deny
cat << EOF >> /etc/security/limits.conf
* soft nofile 200000
* hard nofile 300000
EOF
sed -i 's/1024/unlimited/g' /etc/security/limits.d/90-nproc.conf
#add administrator system utils
yum -y install vim iptraf sysstat lsof zlib-devel bind-utilstelnet dmidecode wget openssl-devel tcpdump ntpdate gcc gcc-c++ make pcre-devel\
readline-devel pciutils openssl-devel xinetd bc
#shutdown selinux
sed -i 's/SELINUX=enforcing/SELINUX=disabled/g'/etc/sysconfig/selinux
/usr/sbin/setenforce 0
echo "/usr/sbin/setenforce 0" >> /etc/rc.local
#clean all rules
cat << EOF > /etc/sysconfig/iptables
# Generated by iptables-save v1.4.7 on Sat Dec 27 17:00:46 2014
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
COMMIT
# Completed on Sat Dec 27 17:00:46 2014
EOF
#shutdown DNS resolve
sed -i 's/#UseDNS yes/UseDNS no/g' /etc/ssh/sshd_config
#restart services
/etc/init.d/sshd restart
/etc/init.d/iptables restart
sed -i 's/net.ipv4.ip_forward = 0/net.ipv4.ip_forward = 1/g'/etc/sysctl.conf
sysctl -p
sed -i 's/#Port 22/Port 61440/g' /etc/ssh/sshd_config &&/etc/init.d/sshd restart
#ntpdate 10.128.64.121
chkconfig iptables off
12.执行优化脚本:sh -x init.sh
13.Tcpdump -I em1-nn icmp验证
(1) Ping www.baidu.com
(2) Tcpdump -I em1 -nn icmp
(3) Tcpdump -I em2 -nn icmp
Em1和em2两个端口均有数据包通过即双上连完成。
北京永联同创科技有限公司 北京IT外包部编制 http://www.bjyltc.com