RHEL7: Use /proc/sys and sysctl to modify and set kernel runtime parameters.

Share this link

Note: This was a RHCE 7 exam objective until June 2016. It is now removed from the curriculum.

Presentation

When you want to improve the performance or the characteristics of your server, you need to set the kernel runtime parameters.

In order to do this, you’ve got three ways:

  • through the /proc filesystem,
  • with the sysctl command,
  • through the /etc/sysctl.conf file.

The /proc Filesystem

To get the value of a kernel runtime parameter (here /proc/sys/net/ipv4/ip_forward used for allowing a host to act as an router), type:

# cat /proc/sys/net/ipv4/ip_forward

To set the value of the same parameter, type:

# echo 1 > /proc/sys/net/ipv4/ip_forward

Note: 1 is used for On and 0 for off.

This change is instantaneously active but doesn’t persist a reboot. You have to write it into the /etc/rc.d/rc.local file to get it re-applied at each boot. See below for a better solution.

The sysctl Command

With the sysctl command, you can get all the available kernel runtime parameters with their current value.

# sysctl -a | grep vm.swappiness
vm.swappiness = 30

But you can also set a kernel runtime parameter with the -w option.

# sysctl -w vm.swappiness=20
vm.swappiness = 20

Still like the previous method, this change is instantaneously active but doesn’t persist a reboot. You have to write it into the /etc/rc.d/rc.local file to get it re-applied at each boot. See below for a better solution.

The /etc/sysctl.conf File

To permanently store kernel runtime parameters, you need to write them into the /etc/sysctl.conf file.

For example, edit the /etc/sysctl.conf file and paste the following line:

# allow IPv4 forwarding
net.ipv4.ip_forward = 1

Caution: Comments are only allowed on a separate line and not at the end of a line!
Note: It is not a coincidence if the net.ipv4.ip_forward kernel runtime parameter name matches the /proc/sys/net/ipv4/ip_forward path name.

Then, you need to apply the change:

# sysctl -p

Many kernel runtime parameters can be set this way. Here are only a few examples:

# don't respond to a ping
net.ipv4.icmp_echo_ignore_all = 1
# don't respond to a ping to the broadcast address
net.ipv4.icmp_echo_ignore_broadcasts = 1
# disable IPv6 for all network interfaces
net.ipv6.conf.all.disable_ipv6 = 1

Note: As seen before, the sysctl -a command gets all the kernel runtime parameters with their current value. By redirecting the output to a file, this is also a good way to back up your configuration before any change.

Default kernel runtime configuration is located in the /usr/lib/sysctl.d directory and is executed before anything else (see sysctl –system).

Caution: Kernel runtime parameters set in the /etc/sysctl.conf file can be overrided by the application of a tuned profile (see this example).

Additional Resources

Suse provides an interesting SLES 11/12 OS Tuning & Optimization Guide.
Fedora documentation‘s got a page about Suggested /etc/sysctl.conf config.
Kernel.org also provides documentation about sysctl configuration.
O’Reilly offers free videos about the proc filesystem (5min/2016), Modifying the /proc filesystem (4min/2016) and the sysctl command (4min/2016).

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading...

Leave a Reply

19 Comments on "RHEL7: Use /proc/sys and sysctl to modify and set kernel runtime parameters."

Notify of
Sort by:   newest | oldest
ak340
Member
ak340

Hi Certdepot, should we need to know how to tune kernel module parameters and kernel parameters for rhcsa exam?

ak340
Member
ak340

Hi mate,
sysctl -p is not working.
Should I include the configuration file? like sysctl -p changes.conf?

tom
Member
tom

One little trick from sysctl.d man page:

Note that both / and . are accepted as label separators within sysctl variable names. “kernel.domainname=foo” and “kernel/domainname=foo” hence are entirely equivalent.

ILMostro
Member
ILMostro

Instead of trying to navigate the maze of directories in the “/proc/…” subdirectories, why not use the `sysctl` tool entirely on its own?

For example,

# cat /proc/sys/net/ipv4/ip_forward

can be done with

# sysctl -a |grep ip_forward

To write/change values, do

# sysctl -w net.ipv4.ip_forward=1

ILMostro
Member
ILMostro

Take a look at the SYSCTL(8) man-page; here’s a useful note differences between sysctl commandline tool and /proc when dealing with deprecated params:

DEPRECATED PARAMETERS
The base_reachable_time and retrans_time are deprecated. The sysctl command does not allow changing values of these parameters. Users who insist to use deprecated kernel interfaces should push values to /proc file system by
other means. For example:

echo 256 > /proc/sys/net/ipv6/neigh/eth0/base_reachable_time

hunter86_bg
Member

You should bear in mind that in CentOS 7.2 some kernel runtime parameters (I’ve tested with vm.swappiness) can’t be set on boot, while they could in CentOS 7.0.

hunter86_bg
Member

By the way echo something > /proc/sys/ is not a recommended way. It’s better to use “sysctl -w (this switch is optional) =” with no spaces around the “=”.
Also, sysctl variable=new_setting is equal to sysctl -w variable=new_setting.
When I want to do it permanent, I write the conf file in /etc/sysctl.d/any_name.conf and then sysctl -p /etc/sysctl.d/any_name.conf

hunter86_bg
Member

Is it possible to add some way of editing, so we won’t need to do it this way? By the way, I really loved your website while I was preparing for my RHCSA, and I still think it is.
Happy New Year!

hunter86_bg
Member

I have received response for the issue with the vm.swappiness not set on boot. It seems that the tuned daemon is applying settings after the systemd-sysctl daemon. There are 2 approaches in resolving this : to disable the tuned profile or to edit the configuration of the tuned daemon.
I didn’t have enough time to review what tunables are affected by the tuned profiles.
The virtual-guest profile seems to change only 2 tunables: vm.dirty_ratio and vm.swappiness.

wpDiscuz

RHCSA7: Task of the day

Allowed time: 8 minutes.
Find all files bigger than 100MB and write their names into the /root/results.txt file.

RHCE7: Task of the day

Allowed time: 10 minutes.
Set up a default secure MariaDB database called maria and back up the database with mysqldump.

Poll for favorite RHEL 7 book

What is your favorite RHEL 7 book to prepare RHCSA & RHCE exams?

View Results

Loading ... Loading ...

Poll for most difficult RHCSA 7 topic

What do you think is the most difficult RHCSA 7 topic?

View Results

Loading ... Loading ...

Poll for most difficult RHCE 7 topic

What do you think is the most difficult RHCE 7 topic?

View Results

Loading ... Loading ...

Recent Comments