CentOS系统的优化配置
1、修改网络配置文件,安装集成工具包“net-tools”,查看网络
1.编辑eth0的配置文件中“ONBOOT”项为“yes”,使eth0网络开启自动启动
[root@centos7 ~]# vi /etc/sysconfig/network-scripts/ifcfg-eth0
ONBOOT=yes
[root@centos7 ~]#
2.重启网络服务
[root@centos7 ~]# systemctl restart network
[root@centos7 ~]#
3.安装集成工具包“net-tools”
[root@centos7 ~]# yum -y install net-tools
2、查看网络IP地址,使用远程工具连接
查看IP地址
[root@centos7 ~]# ifconfig
3、永久关闭“防火墙、SElinux、NetworkManager”服务
1.永久关闭NetworkManager服务
[root@localhost ~]# systemctl stop NetworkManager
[root@localhost ~]# systemctl disable NetworkManager
2.永久关闭SElinux服务
[root@localhost ~]# vi /etc/sysconfig/selinux
“SELINUX=enforcing” 改为 “SELINUX=disabled”
[root@localhost ~]#
3.永久关闭防火墙服务
因为有时会用到防火墙,如WEB服务,所以先安装防火墙,在把防火墙永久关闭,需要时在启用
(1)安装防火墙
[root@localhost ~]# yum -y install firewalld
(2)永久关闭防火墙
[root@localhost ~]# systemctl disable firewalld
4.重启系统
[root@localhost ~]# reboot
4、修改yum源
系统默认yum源是CentOS官网,连接缓慢,所以要修改yum源。修改“/etc/yum.repos.d/CentOS-Base.repo”文件为公司的yum源,或网络上常用的yum源(如阿里等)
5、安装常用的基础命令
[root@localhost ~]# yum install vim iotop bc gcc gcc-c++ glibc glibc-devel pcre \
pcre-devel openssl openssl-devel zip unzip zlib-devel net-tools \
lrzsz tree ntpdate telnet lsof tcpdump wget libevent libevent-devel \
bc systemd-devel bash-completion traceroute psmisc -y
重要:
这里我没有安装epel源的包,如果此虚拟机用于安装Openstack,则不能安装epel源,因为会与Openstack的源冲突;
如果不用于Openstack,则可以安装epel源。
6、优化内核参数
1.查看优化文件
[root@localhost ~]# ll
-rw-r--r-- 1 root root 2895 Jun 18 18:51 limits.conf
-rw-r--r-- 1 root root 2232 Jun 18 18:51 sysctl.conf
[root@localhost ~]#
2.把centos系统内核文件替换为优化文件
[root@localhost ~]# mv sysctl.conf /etc/sysctl.conf
mv: overwrite ‘/etc/sysctl.conf’? y
[root@localhost ~]#
[root@localhost ~]# mv limits.conf /etc/security/limits.conf
mv: overwrite ‘/etc/security/limits.conf’? y
[root@localhost ~]#
3.查看优化文件“sysctl.conf”
[root@localhost ~]# cat /etc/sysctl.conf
# Controls source route verification
net.ipv4.conf.default.rp_filter = 1
net.ipv4.ip_nonlocal_bind = 1
net.ipv4.ip_forward = 1
# Do not accept source routing
net.ipv4.conf.default.accept_source_route = 0
# Controls the System Request debugging functionality of the kernel
kernel.sysrq = 0
# Controls whether core dumps will append the PID to the core filename.
# Useful for debugging multi-threaded applications.
kernel.core_uses_pid = 1
# Controls the use of TCP syncookies
net.ipv4.tcp_syncookies = 1
# Disable netfilter on bridges.
net.bridge.bridge-nf-call-ip6tables = 0
net.bridge.bridge-nf-call-iptables = 0
net.bridge.bridge-nf-call-arptables = 0
# Controls the default maxmimum size of a mesage queue
kernel.msgmnb = 65536
# # Controls the maximum size of a message, in bytes
kernel.msgmax = 65536
# Controls the maximum shared segment size, in bytes
kernel.shmmax = 68719476736
# # Controls the maximum number of shared memory segments, in pages
kernel.shmall = 4294967296
# TCP kernel paramater
net.ipv4.tcp_mem = 786432 1048576 1572864
net.ipv4.tcp_rmem = 4096 87380 4194304
net.ipv4.tcp_wmem = 4096 16384 4194304
net.ipv4.tcp_window_scaling = 1
net.ipv4.tcp_sack = 1
# socket buffer
net.core.wmem_default = 8388608
net.core.rmem_default = 8388608
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
net.core.netdev_max_backlog = 262144
net.core.somaxconn = 20480
net.core.optmem_max = 81920
# TCP conn
net.ipv4.tcp_max_syn_backlog = 262144
net.ipv4.tcp_syn_retries = 3
net.ipv4.tcp_retries1 = 3
net.ipv4.tcp_retries2 = 15
# tcp conn reuse
net.ipv4.tcp_tw_reuse = 1
net.ipv4.tcp_tw_recycle = 1
net.ipv4.tcp_fin_timeout = 1
net.ipv4.tcp_max_tw_buckets = 20000
net.ipv4.tcp_max_orphans = 3276800
net.ipv4.tcp_timestamps = 1 #?
net.ipv4.tcp_synack_retries = 1
net.ipv4.tcp_syncookies = 1
# keepalive conn
net.ipv4.tcp_keepalive_time = 300
net.ipv4.tcp_keepalive_intvl = 30
net.ipv4.tcp_keepalive_probes = 3
net.ipv4.ip_local_port_range = 10001 65000
# swap
vm.overcommit_memory = 0
vm.swappiness = 10
[root@localhost ~]#
4.查看优化文件“limits.conf”
[root@localhost ~]# cat /etc/security/limits.conf
* soft core unlimited
* hard core unlimited
* soft nproc 1000000
* hard nproc 1000000
* soft nofile 1000000
* hard nofile 1000000
* soft memlock 32000
* hard memlock 32000
* soft msgqueue 8192000
* hard msgqueue 8192000
[root@localhost ~]#
7、修改主机名
登录后复制
[root@localhost ~]# vim /etc/hostname
centos7
[root@localhost ~]#
重启系统生效以上配置:[root@localhost ~]# reboot