centos 6.8模板机制作

前端之家收集整理的这篇文章主要介绍了centos 6.8模板机制作前端之家小编觉得挺不错的,现在分享给大家,也给大家做个参考。

第一章虚拟化NAT网络设置

使用DHCP自动获取IP地址

wKioL1nT1kbC76qdAAK2ml4dTs0370.jpg

wKiom1nT1p2BqyI1AASxjGdBX2k736.jpg

第二章创建虚拟机

wKioL1nTwi3jdzJ5AAIOZ5sVKZw459.jpg

wKiom1nTwnfz8smaAAEHMpc-bns967.jpg

wKioL1nTwjKxU6cAAADpto8xN4w500.jpg

wKiom1nTwnygKngKAADoa210L_8572.jpg

wKiom1nTwn-jKHGtAADtuqUThZk630.jpg

wKioL1nTwjnjD46uAADfGNNXgZ0586.jpg

wKioL1nTwjuwmQQkAAD0aYkzq50145.jpg

wKiom1nTwoaTgryHAAEjMwOqbrA885.jpg

wKioL1nTwkDAJAD7AAEDhr1kfn4562.jpg

wKiom1nTwouSolQZAADQXKV8PsA469.jpg

wKioL1nTwkSRfxeKAACqjUYjs48951.jpg

wKiom1nTwo_jHJICAAEDRhtZW1c278.jpg

wKiom1nTwpKxajpHAAEMg-ZfmPI046.jpg

wKioL1nTwkyw-ADAAADcbf3FKA0681.jpg

wKiom1nTwpbCRa62AAEh9kYiwbE557.jpg

wKioL1nTwlWQU02ZAAKicTweEM8123.jpg

wKiom1nTwqCwIex7AADnvs0NrjY863.jpg

wKioL1nTwlzwpATkAAGgV2_SEoU535.jpg

wKioL1nTwl7hJq3EAAESN2iq-mU546.jpg

wKioL1nTw32jbIDTAAKOJTcsL1Y786.jpg

第三章安装CentOS-6.8-x86_64-bin-DVD1操作系统

wKioL1nT0ruimZ3SAANoL0GMIyQ937.jpg

wKiom1nT0wrxMc72AALAw9fcYj8529.jpg

wKiom1nT0w7y8K9CAAELU9tmE_4226.jpg

wKioL1nT0siyzFtSAADmWw9LbJ4392.jpg

wKiom1nT0xKxoPjtAACwKlde7vU398.jpg

wKioL1nT0szC-HOHAAEPmECH914560.jpg

wKioL1nT0s_xXjrGAADmWSU29zs054.jpg

wKiom1nT0xrhKolXAAC9WNz-RSA208.jpg

wKiom1nT0xyCIZqDAAFKPuN3juc084.jpg

wKioL1nT0tWBNUbcAACShk2agrk070.jpg

wKiom1nT0yLhu-NLAAE8ScSCp4w403.jpg

wKioL1nT0tzCHxq-AACrTivgJP8635.jpg

wKiom1nT0yayLK-SAADIfEbhhQk320.jpg

wKioL1nT0uLw8veWAAF31hY2XV8735.jpg

wKioL1nT0uWg-ZStAAFyvEd68Gg445.jpg

wKiom1nT0zHzoIohAAFPRKFZZbo983.jpg

wKioL1nT0uzDedZQAAFAdvG96lo957.jpg

wKiom1nT0zeCacwAAAFI30iYzGM239.jpg

wKiom1nT0zrAj-HkAAE8Z-bOB48939.jpg

wKioL1nT0vXDEiBVAAFMAqGU45I212.jpg

wKioL1nT0vfzuj4DAADIvLMceQw439.jpg

wKiom1nT00LDJSo6AAD9_UYJ6hc455.jpg

wKiom1nT00Wir3PLAAEIg5kVJps538.jpg

wKioL1nT0v6S6vngAACzFzN7cpk562.jpg

wKiom1nT00uglA4gAAFVN1DRNjU132.jpg

wKioL1nT0waCJkZXAAGSgjU2Hes005.jpg

wKiom1nT01Hz1PsMAAE4VFjSv8k446.jpg

wKioL1nT0wvQJm0lAADpFFIfgGM856.jpg

wKioL1nT0w6zl5IsAADxkf9FZnk127.jpg

wKiom1nT01qyPrPdAAErxi0lMec532.jpg

wKiom1nT02PyRxX9AAN5_MQdekY009.jpg

wKioL1nT0yXTHjEVAAPigZkopwE008.jpg

第四章模板机优化

开机后使用命令ifup eth0获取到IP地址后。用SecureCRT连接。

4.1SecureCRT设置


wKiom1nT38bR5iVoAAHQxhHTKzU684.jpg

wKioL1nT347QDyR1AAGR53jJr68554.jpg

wKiom1nT3-6Ak_VqAAFN1IMiG6Q989.jpg

wKioL1nT36qg6z0aAAIsVqgw85E338.jpg


wKiom1nT4FyRoBbxAAE6bnKW6_c114.jpg

wKioL1nT4BvTh_ZrAAKG4Nt40J0050.jpg

wKiom1nT4GjDZjVnAAF6ATrt2Bc856.jpg

wKioL1nT4CPhLJwxAAFP5aHKZTE154.jpg


4.2安装linux系统后调优及安全设置

设置开机网卡自动启动

  1. sed-i's#ONBOOT=no#ONBOOT=yes#g'/etc/sysconfig/network-scripts/ifcfg-eth0

关闭selinux

  1. [root@mobanji~]#sed-i's#SELINUX=enforcing#SELINUX=disabled#g'/etc/sysconfig/selinux
  2. [root@mobanji~]#getenforce
  3. Enforcing
  4. [root@mobanji~]#setenforcePermissive
  5. [root@mobanji~]#getenforce
  6. Permissive

关闭防火墙

  1. [root@mobanji~]#/etc/init.d/iptablesstop##临时关闭
  2. [root@mobanji~]#chkconfigiptablesoff##永久关闭开机启动

可选择的:支持中文显示,防止中文出现乱码(CRT外观-字符编码也要设置UTF-8)此处一般不要设置成中文的。linux一切都是英文的比较好,如果想看中文的再开启即可。

  1. [root@mobanji~]#echo$LANG
  2. en_US.UTF-8
  3. [root@mobanji~]#sed-i's#en_US#zh_CN#g'/etc/sysconfig/i18n
  4. [root@mobanji~]#./etc/sysconfig/i18n##.或者source都可以
  5. [root@mobanji~]#echo$LANG
  6. zh_CN.UTF-8

Base源更改为阿里云,并打补丁到最新

  1. mv/etc/yum.repos.d/CentOS-Base.repo/etc/yum.repos.d/CentOS-Base.repo.backup
  2. wget-O/etc/yum.repos.d/CentOS-Base.repo
  3. rpm--import/etc/pki/rpm-gpg/RPM-GPG-KEY*
  4. yumupdate-y#执行此命令升级后centos6.8就自动升级成了6.9了,再重启如下图所示:

wKiom1nUiw2SMVqPAABYIsIWAps241.jpg

额外安装一些有用的软件包

  1. [root@mobanji~]#yuminstalltreetelnetdos2unixsysstatlrzszncnmap-y

精简开机系统自启动只保留5个服务。

  1. [root@mobanji~]#chkconfig--list|grep3:on|egrep-v"crond|sshd|network|rsyslog|sysstat"|awk'{print"chkconfig",$1,"off"}'|bash
  2. [root@mobanji~]#chkconfig--list|grep3:on
  3. crond0:off1:off2:on3:on4:on5:on6:off
  4. network0:off1:off2:on3:on4:on5:on6:off
  5. rsyslog0:off1:off2:on3:on4:on5:on6:off
  6. sshd0:off1:off2:on3:on4:on5:on6:off
  7. sysstat0:off1:on2:on3:on4:on5:on6:off

设置linux服务器时间同步

  1. [root@mobanji~]#/usr/sbin/ntpdatetime.nist.gov
  2. 4Oct12:23:24ntpdate[24685]:noserversuitableforsynchronizationfound
  3. [root@mobanji~]#echo'#timesyncbyoldboyat2017-10-04'>>/var/spool/cron/root
  4. [root@mobanji~]#echo'*/5****/usr/sbin/ntpdatetime.nist.gov>/dev/null2>&1'>>/var/spool/cron/root
  5. [root@mobanji~]#crontab-l
  6. #timesyncbyoldboyat2017-10-04
  7. */5****/usr/sbin/ntpdatetime.nist.gov>/dev/null2>&1

历史记录数及登录超时环境变量设置

  1. echo'exportTMOUT=300'>>/etc/profile#连接的超时时间控制时间为300秒
  2. echo'exportHISTSIZE=5'>>/etc/profile#命令行的历史记录数为5
  3. echo'exportHISTFILESIZE=5'>>/etc/profile#历史记录文件的命令数量
  4. tail-3/etc/profile

内核优化(本优化适合apache,Nginx,squid等多种web应用,特殊的业务有可能需要略做调整)

  1. net.ipv4.tcp_fin_timeout=2
  2. net.ipv4.tcp_tw_reuse=1
  3. net.ipv4.tcp_tw_recycle=1
  4. net.ipv4.tcp_syncookies=1
  5. net.ipv4.tcp_keepalive_time=600
  6. net.ipv4.ip_local_port_range=400065000
  7. net.ipv4.tcp_max_syn_backlog=16384
  8. net.ipv4.tcp_max_tw_buckets=36000
  9. net.ipv4.route.gc_timeout=100
  10. net.ipv4.tcp_syn_retries=1
  11. net.ipv4.tcp_synack_retries=1
  12. net.core.somaxconn=16384
  13. net.core.netdev_max_backlog=16384
  14. net.ipv4.tcp_max_orphans=16384
  15. #以下参数是对iptables防火墙的优化,防火墙不开会提示,可以忽略不理
  16. net.nf_conntrack_max=25000000
  17. net.netfilter.nf_conntrack_max=25000000
  18. net.netfilter.nf_conntrack_tcp_timeout_established=180
  19. net.netfilter.nf_conntrack_tcp_timeout_time_wait=120
  20. net.netfilter.nf_conntrack_tcp_timeout_close_wait=60
  21. net.netfilter.nf_conntrack_tcp_timeout_fin_wait=120

将上面的内核参数值加入vim /etc/sysctl.conf文件中,然后执行如下命令使之生效

  1. [root@oldboy~]#sysctl-p
  2. net.ipv4.ip_forward=0
  3. net.ipv4.conf.default.rp_filter=1
  4. net.ipv4.conf.default.accept_source_route=0
  5. kernel.sysrq=0
  6. kernel.core_uses_pid=1
  7. net.ipv4.tcp_syncookies=1
  8. kernel.msgmnb=65536
  9. kernel.msgmax=65536
  10. kernel.shmmax=68719476736
  11. kernel.shmall=4294967296
  12. net.ipv4.tcp_fin_timeout=2
  13. net.ipv4.tcp_tw_reuse=1
  14. net.ipv4.tcp_tw_recycle=1
  15. net.ipv4.tcp_syncookies=1
  16. net.ipv4.tcp_keepalive_time=600
  17. net.ipv4.ip_local_port_range=400065000
  18. net.ipv4.tcp_max_syn_backlog=16384
  19. net.ipv4.tcp_max_tw_buckets=36000
  20. net.ipv4.route.gc_timeout=100
  21. net.ipv4.tcp_syn_retries=1
  22. net.ipv4.tcp_synack_retries=1
  23. net.core.somaxconn=16384
  24. net.core.netdev_max_backlog=16384
  25. net.ipv4.tcp_max_orphans=16384
  26. error:"net.nf_conntrack_max"isanunknownkey
  27. error:"net.netfilter.nf_conntrack_max"isanunknownkey
  28. error:"net.netfilter.nf_conntrack_tcp_timeout_established"isanunknownkey
  29. error:"net.netfilter.nf_conntrack_tcp_timeout_time_wait"isanunknownkey
  30. error:"net.netfilter.nf_conntrack_tcp_timeout_close_wait"isanunknownkey
  31. error:"net.netfilter.nf_conntrack_tcp_timeout_fin_wait"isanunknownkey

4.3配置双网卡固定ip

设置完后如下配置后重启linux系统

wKiom1nUhvOyfRvoAAJ1BjWHuFs742.jpg

wKioL1nUhraQVrPzAASMMgnmVFk383.jpg

wKioL1nUhrqwD7PDAAHMHxvLFfM913.jpg

wKiom1nUhwfAapbdAAFZVTkaSHI898.jpg

wKiom1nUhwuj71hJAAEvyOh8Ljk960.jpg

设置完成后重启,然后直接用SecureCRT连接即可

wKioL1nUjkCDGaBPAAKEVYBWH28887.jpg


eth0网卡:删除mac地址和uuid

  1. [root@oldboy~]#cat/etc/sysconfig/network-scripts/ifcfg-eth0
  2. DEVICE=eth0
  3. HWADDR=00:0c:29:59:47:0f
  4. TYPE=Ethernet
  5. UUID=ee7d8a04-694b-4595-9e37-b759535e7c99
  6. ONBOOT=yes
  7. NM_CONTROLLED=yes
  8. BOOTPROTO=none
  9. IPADDR=10.0.0.100
  10. NETMASK=255.255.255.0
  11. DNS2=202.96.128.86
  12. GATEWAY=10.0.0.2
  13. DNS1=10.0.0.2
  14. USERCTL=no
  15. PEERDNS=yes
  16. IPV6INIT=no
  1. [root@oldboy~]#vi/etc/sysconfig/network-scripts/ifcfg-eth0
  2. 删除如下两行即可(MAC地址和UUID
  3. HWADDR=00:0c:29:59:47:0f
  4. UUID=ee7d8a04-694b-4595-9e37-b759535e7c99

eth1网卡:删除mac地址和uuid

  1. [root@oldboy~]#cat/etc/sysconfig/network-scripts/ifcfg-eth1
  2. DEVICE=eth1
  3. HWADDR=00:0c:29:59:47:19
  4. TYPE=Ethernet
  5. UUID=e082a412-3fee-42e6-96e5-ac05b4d38d5f
  6. ONBOOT=yes
  7. NM_CONTROLLED=yes
  8. BOOTPROTO=none
  9. IPADDR=172.16.1.100
  10. NETMASK=255.255.255.0
  11. USERCTL=no
  12. PEERDNS=yes
  13. IPV6INIT=no
  14. [root@oldboy~]#vi/etc/sysconfig/network-scripts/ifcfg-eth1
  15. 删除如下两行即可(MAC地址和UUID
  16. HWADDR=00:0c:29:59:47:19
  17. UUID=e082a412-3fee-42e6-96e5-ac05b4d38d5f

清空70-persistent-net.rules

  1. [root@oldboy~]#>/etc/udev/rules.d/70-persistent-net.rules
  2. [root@oldboy~]#echo">/etc/udev/rules.d/70-persistent-net.rules">>/etc/rc.local
  3. [root@oldboy~]#cat/etc/rc.local
  4. #!/bin/sh
  5. #
  6. #Thisscriptwillbeexecuted*after*alltheotherinitscripts.
  7. #Youcanputyourowninitializationstuffinhereifyoudon't
  8. #wanttodothefullSysVstyleinitstuff.
  9. touch/var/lock/subsys/local
  10. >/etc/udev/rules.d/70-persistent-net.rules

设置完后,关机。然后把这个模板机,做个快照,快照名为模板机CentOS 6.8 模板机即可。

后期需要克隆虚拟机直接用链接克隆即可

猜你在找的CentOS相关文章