ulimit限制之nproc问题

在RHEL6.3中执行sysctl -p的时候发现输出出现以下错误

# sysctl -p
net.ipv4.ip_forward = 0
net.ipv4.conf.default.rp_filter = 1
net.ipv4.conf.default.accept_source_route = 0
kernel.sysrq = 0
kernel.core_uses_pid = 1
net.ipv4.tcp_syncookies = 1
error: "net.bridge.bridge-nf-call-ip6tables"is an unknown key
error: "net.bridge.bridge-nf-call-iptables"is an unknown key
error: "net.bridge.bridge-nf-call-arptables"is an unknown key
kernel.msgmnb = 65536
kernel.msgmax = 65536
kernel.shmmax = 68719476736
kernel.shmall = 4294967296

经过Google大神点击打开链接后来找到的了原因所在,原来以下3个参数依赖于bridge模块,该模块如果没有加载则会现上面的输出错误

error: "net.bridge.bridge-nf-call-ip6tables"is an unknown key
error: "net.bridge.bridge-nf-call-iptables"is an unknown key
error: "net.bridge.bridge-nf-call-arptables"is an unknown key

加载模块测试,发现问题解决

# modprobe bridge
# sysctl -p
net.ipv4.ip_forward = 0
net.ipv4.conf.default.rp_filter = 1
net.ipv4.conf.default.accept_source_route = 0
kernel.sysrq = 0
kernel.core_uses_pid = 1
net.ipv4.tcp_syncookies = 1
net.bridge.bridge-nf-call-ip6tables = 0
net.bridge.bridge-nf-call-iptables = 0
net.bridge.bridge-nf-call-arptables = 0
kernel.msgmnb = 65536
kernel.msgmax = 65536
kernel.shmmax = 68719476736
kernel.shmall = 4294967296

有人可能会好奇这三个值得意义所在,我在红帽官网找到了相关说明点击打开链接

以下大致的意思主要说使用以上3个选项阻止桥接流量获得通过主机iptables规则,Netfilter是默认情况下启用了桥梁,如果不阻止会导致严重的混乱。

ulimit限制之nproc问题_第1张图片


ulimit限制之nproc问题

http://blog.yufeng.info/archives/2568

http://weibo.com/1642466057/y3jM4cz3q

你可能感兴趣的:(ulimit)