###ENABLE SECURITY
security.bsd.unprivileged_read_msgbuf=0 #1
security.bsd.unprivileged_proc_debug=0 #1
kern.randompid=1 #0
kern.sugid_coredump=1 #0 changed credential programs dump core
kern.corefile=/var/coredumps/%U/%N.core #%N.core
###KERN
kern.msgbuf_show_timestamp=1 #0 show timestamp in messagebuf
kern.shutdown.poweroff_delay=2000 #5000 : Delay before poweroff to write disk caches (msec)
kern.shutdown.kproc_shutdown_wait=20 #60 : Max wait time (sec) to stop for each process
kern.ipc.shm_use_phys=1 #0 : Enable locking of shared memory pages in core
kern.ipc.shmall=512000 #131072
kern.ipc.shmmax=1000000000 #536870912
###HW
hw.usb.no_shutdown_wait=1 #0 : No USB device waiting at system shutdown
###VFS
vfs.zfs.min_auto_ashift=12 #9
vfs.usermount=1 #0,Unprivileged users may mount and unmount file systems
##################987654321####
vfs.zfs.arc_min= 1500000000 #0
vfs.zfs.arc_max= 2500000000 #0
#################a987654321###
###NET##################################################################
net.inet6.ip6.temppltime=7200 # 86400 , Maximum preferred lifetime for temporary addresses
net.inet6.ip6.tempvltime=14400 # 604800 , Maximum valid lifetime for temporary addresses
net.inet.tcp.cc.algorithm=cubic #newreno #Congestion control newreno,CDG,CHD,CUBIC,DCTCP,HD,H-TCP,VEGAS
#
net.inet6.ip6.redirect=0 #1
net.inet6.icmp6.rediraccept=0 #1
net.inet.ip.redirect=0 #1
net.inet.icmp.drop_redirect=1 #0
#
net.inet.ip.maxfragpackets=0 #15762
net.inet.ip.maxfragsperpacket=0 #16
#
net.inet.tcp.blackhole=2 #0
net.inet.udp.blackhole=1 #0
#
net.inet.tcp.always_keepalive=0 #1
net.inet.tcp.nolocaltimewait=1 #0
net.inet.tcp.icmp_may_rst=0 #1
net.inet.ip.check_interface=1 #0
net.inet.ip.process_options=0 #1
net.inet.ip.random_id=1 #0
net.inet.icmp.icmplim=50 #200
#aslr
kern.elf64.aslr.enable=1 #0
#aslrpie
kern.elf64.aslr.pie_enable=1 #0
#
net.inet6.ip6.accept_rtadv=1 #0 Default value of per-interface flag for accepting ICMPv6 RA messages
#
kern.metadelay=4 #28
kern.dirdelay=5 #29
kern.filedelay=7 #30
#
security.bsd.unprivileged_idprio=1 #0
kern.sched.preempt_thresh=120 #80