掉包解决方法

echo “965535″ > /proc/sys/net/ipv4/ip_conntrack_max
echo 180>/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_established

echo 120   > /proc/sys/net/ipv4/neigh/default/gc_stale_time
echo 1024 > /proc/sys/net/ipv4/neigh/default/gc_thresh1
echo 4096 > /proc/sys/net/ipv4/neigh/default/gc_thresh2
echo 8192 > /proc/sys/net/ipv4/neigh/default/gc_thresh3

限制同一ip连接数:
iptables -I INPUT -m connlimit –connlimit-above 5 -p tcp –dport 80 -j REJECT

http://myeblog.3322.org/1184.html

https://bbs.et8.net/bbs/showthread.php?t=977006