Home / Alt manpages / sysctl(8)

  • sysctl(8)
  • Admin command
  • linux

Apply Linux Kernel Tuning Safely with sysctl and sysctl.d

This guide shows you how to inspect a kernel parameter, make a temporary runtime change, verify it, and persist a deliberately chosen setting for future boots. The commands use the installed procps-ng 4.0.4 and systemd 255.4 interfaces described by the local sysctl(8), sysctl.conf(5) and sysctl.d(5) pages.

Allow about 15 minutes for a read-only inspection and one reversible test. Persistent tuning needs more care because a bad value can affect networking, memory pressure or process isolation. You need a shell, access to /proc/sys, and elevated privileges for writes to most keys and for editing /etc/sysctl.d/.

1. Inspect before changing anything

Start with a parameter whose meaning you understand. The name maps to a file below /proc/sys; dots are accepted as separators, and slashes are accepted too. The hostname is a harmless example that is easy to read:

$ sysctl kernel.hostname
kernel.hostname = server.dixon.cx
$ sysctl -n kernel.hostname
server.dixon.cx

The ordinary form prints both the key and value. Add -n when a script needs only the value. Add -N when you need only the name. Do not confuse -a with a focused query: it prints every parameter currently exposed by this kernel, which can be a large and machine-specific list.

Checkpoint: save the current value of any key you plan to alter. This gives you a practical undo value even when the setting is not documented in your distribution's defaults:

$ sysctl net.ipv4.ip_forward
net.ipv4.ip_forward = 0
$ OLD_FORWARDING=$(sysctl -n net.ipv4.ip_forward)

2. Query a narrow group of parameters

Use --pattern with -a when you need a family of keys. The pattern is an extended regular expression, so anchor it when you mean one exact name:

$ sysctl -a --pattern '^net\.ipv4\.ip_forward$'
net.ipv4.ip_forward = 0

For a broader investigation, sysctl -a --pattern 'forward' can return several keys. Treat that output as discovery, not as a ready-made change list. Kernel versions, loaded modules and network interfaces change which keys exist.

3. Make one temporary runtime change

Only do this when you know what the parameter controls. The following enables IPv4 forwarding until the next reboot or until you restore it. It is a system-wide networking change and normally needs root:

$ sudo sysctl -w net.ipv4.ip_forward=1
net.ipv4.ip_forward = 1
$ sysctl -n net.ipv4.ip_forward
1

Keep the assignment as one shell word. Quoting is needed when a value contains spaces or shell metacharacters, for example kernel.domainname="example.com". The -w option forces arguments to be treated as writes, which helps catch a command that was accidentally written as a read.

Warning: changing a sysctl can alter security or service behaviour immediately. Do not paste a hardening or performance recommendation without checking its kernel documentation and the workload it affects. A successful write proves only that the kernel accepted the value, not that your application is now configured correctly.

Undo the example with the value recorded earlier:

$ sudo sysctl -w net.ipv4.ip_forward="$OLD_FORWARDING"
net.ipv4.ip_forward = 0
$ sysctl -n net.ipv4.ip_forward
0

4. Persist a setting in sysctl.d

For a setting that should survive reboot, create a local administrator file in /etc/sysctl.d/. Use a numbered name so its ordering is visible. This example persists forwarding, but choose the value for your own host:

$ sudo install -m 0644 /dev/null /etc/sysctl.d/90-local-forwarding.conf
$ sudo sh -c 'printf "%s\n" "net.ipv4.ip_forward = 1" > /etc/sysctl.d/90-local-forwarding.conf'
$ sudo cat /etc/sysctl.d/90-local-forwarding.conf
net.ipv4.ip_forward = 1

Configuration files contain assignments, blank lines and comments beginning with # or ;. Values can contain whitespace. A leading single hyphen makes a failed assignment non-fatal, but use that only when failure is genuinely expected; hiding an unknown or mistyped key makes troubleshooting harder.

The 90- prefix is not magic. Files are sorted lexicographically, and a later filename can override an earlier assignment. Files in /etc/sysctl.d/ take precedence over same-named files in /run/sysctl.d/, /usr/local/lib/sysctl.d/ and /usr/lib/sysctl.d/. A same-named file in /etc replaces the lower-priority file; a differently named later file can override individual keys.

5. Load and verify the file now

Apply the file without rebooting. The file argument is explicit, so this test does not unexpectedly load every system configuration file:

$ sudo sysctl --load=/etc/sysctl.d/90-local-forwarding.conf
net.ipv4.ip_forward = 1
$ sysctl net.ipv4.ip_forward
net.ipv4.ip_forward = 1

At boot, systemd-sysctl.service reads the sysctl.d directories. You can inspect the complete ordered set that procps-ng would load with:

$ sudo sysctl --system
* Applying /etc/sysctl.d/90-local-forwarding.conf ...
net.ipv4.ip_forward = 1

Real output includes other files and may include permission-denied messages for keys the current environment cannot write. Do not treat every line as evidence that your file was ignored. Check the target value separately, then inspect the service status and journal if a boot-time application fails.

6. Remove or disable the persistent change

Persistent configuration is state. To undo this guide, remove the assignment from the file or move the file aside, then restore the runtime value explicitly:

$ sudo mv /etc/sysctl.d/90-local-forwarding.conf /etc/sysctl.d/90-local-forwarding.conf.disabled
$ sudo sysctl -w net.ipv4.ip_forward=0
$ sysctl -n net.ipv4.ip_forward
0

The .disabled suffix means systemd-sysctl will not treat the renamed file as a configuration file. If another file also sets the key, find it before assuming the setting will remain at zero:

$ sudo sysctl --system 2>&1 | grep 'ip_forward'
$ sysctl -a --pattern 'net\.ipv4\.ip_forward'

Some parameters appear only after a kernel module or network interface exists. A boot-time run can therefore happen before a key is available. The sysctl.d(5) guidance points to udev rules for settings that must be applied when a module or interface appears, rather than hiding the failure in a general configuration file.

Done means

  • You recorded the original value before changing a live key.
  • You verified the runtime value with a focused sysctl query.
  • Your persistent file uses a clear name under /etc/sysctl.d/.
  • You tested that file explicitly and understand its ordering and precedence.
  • You know how to remove the file and restore the previous runtime value.