1。在内核中打开:
│ Symbol: SYN_COOKIES [=y] │
│ Prompt: IP: TCP syncookie support (disabled per default) │
│ Defined at net/ipv4/Kconfig:287 │
│ Depends on: NET && INET │
│ Location: │
│ -> Networking │
│ -> Networking support (NET [=y]) │
│ -> Networking options │
│ -> TCP/IP networking (INET [=y])
2。启动系统时增加下面选项:nano -w /etc/sysctl.conf
net.ipv4.tcp_syn_retries = 1
net.ipv4.tcp_synack_retries = 1
net.ipv4.tcp_syncookies = 1