分享新vps装鸡流程

分享新vps装鸡流程

先DD个Debian9系统(不要直接运行,将密码2字改成root密码,以及将IP和网关和掩码改成vps的):

bash <(wget --no-check-certificate -qO- 'https://moeclub.org/attachment/LinuxShell/InstallNET.sh') -d 9 -v 64 -a -p 密码 --ip-addr 192.168.1.188 --ip-gate 192.168.1.1 --ip-mask 255.255.255.0 --mirror http://ftp.funet.fi/pub/linux/mirrors/debian/

D完后安装一些基本包:

apt-get install curl
apt-get install sudo

修改/etc/ssh/sshd_config更换SSH端口为自定义:

Port 25566

设置时区及时间:

tzselect

选择亚洲 Asia,然后选择北京或者香港

cp /usr/share/zoneinfo/Asia/Shanghai  /etc/localtime
sudo apt-get install ntpdate
ntpdate cn.pool.ntp.org
hwclock --systohc

crontab -e 添加定时校准

00 1 * * * /usr/sbin/ntpdate -u cn.pool.ntp.org > /dev/null 2>&1; /sbin/hwclock -w

锁定DNS(这样就不会因自动获取DNS而变成奇怪DNS而被劫持):

rm -rf /etc/resolv.conf

再新建/etc/resolv.conf添加:

nameserver 8.8.4.4

打开/etc/network/interfaces修改DNS

dns-nameservers 8.8.4.4

锁定DNS配置文件:

chattr +i /etc/resolv.conf
chattr +i /etc/network/interfaces

TCP加速(以下为 锐速+内核参数 方案):

安装内核:

wget https://debian.sipwise.com/debian-security/pool/main/l/linux/linux-image-4.9.0-4-amd64_4.9.65-3+deb9u1_amd64.deb
dpkg -i linux-image-4.9.0-4-amd64_4.9.65-3+deb9u1_amd64.deb

查看系统中已安装的内核:

dpkg -l|grep linux-image

卸载除 4.9.0-4 以外的所有内核:

apt purge  linux-image-4.9.0-13-amd64
update-grub

重启后安装锐速:

bash <(wget --no-check-certificate -qO- https://github.com/xidcn/LotServer_Vicer/raw/master/Install.sh) install

修改/appex/etc/config部分参数

advinacc="1"
wankbps="10000000"
waninkbps="10000000"
maxmode="1"
initialCwndWan="33"
retranWaitListMS="10"
halfCwndLossRateShift="30"
smBurstMS="14"
smBurstMin="14700"
httpCompEnable="0"

修改/etc/sysctl.conf参数

fs.file-max = 1048576
fs.nr_open = 1048576
net.ipv6.conf.all.disable_ipv6 = 1
net.ipv4.tcp_keepalive_time = 1
net.ipv4.tcp_keepalive_intvl = 1
net.ipv4.tcp_keepalive_probes = 147
net.ipv4.tcp_syn_retries = 2
net.ipv4.tcp_retries1 = 14
net.ipv4.tcp_retries2 = 14
net.ipv4.tcp_fin_timeout = 147
net.ipv4.tcp_window_scaling = 1
net.ipv4.tcp_sack = 1
net.ipv4.tcp_fack = 1
net.ipv4.tcp_bic = 1
net.ipv4.route.flush = 1

保存:

sysctl -p

重启一下让锐速配置生效就行了


关闭部分补丁释放10%性能占用仅适合非生产环境老Intel CPU

sed -i 's/GRUB_CMDLINE_LINUX_DEFAULT="/GRUB_CMDLINE_LINUX_DEFAULT="noibrs noibpb nopti nospectre_v2 nospectre_v1 l1tf=off nospec_store_bypass_disable no_stf_barrier mds=off mitigations=off /g' /etc/default/grub

主要内容是屏蔽spectre和meltdown漏洞补丁。漏洞的主要原理是通过虚拟机或者别的进程不停的探测缓存截取数据,成功率很感人,一般人没啥用可以禁用并释放被占用的性能

3 Comments

  1. Pingback: viagra 50 mg coupon
  2. Pingback: very cheap viagra

Comments are closed.