1# SPDX-License-Identifier: GPL-2.0-only 2# 3# Network configuration 4# 5 6menuconfig NET 7 bool "Networking support" 8 select NLATTR 9 select GENERIC_NET_UTILS 10 select BPF 11 help 12 Unless you really know what you are doing, you should say Y here. 13 The reason is that some programs need kernel networking support even 14 when running on a stand-alone machine that isn't connected to any 15 other computer. 16 17 If you are upgrading from an older kernel, you 18 should consider updating your networking tools too because changes 19 in the kernel and the tools often go hand in hand. The tools are 20 contained in the package net-tools, the location and version number 21 of which are given in <file:Documentation/Changes>. 22 23 For a general introduction to Linux networking, it is highly 24 recommended to read the NET-HOWTO, available from 25 <http://www.tldp.org/docs.html#howto>. 26 27if NET 28 29config WANT_COMPAT_NETLINK_MESSAGES 30 bool 31 help 32 This option can be selected by other options that need compat 33 netlink messages. 34 35config COMPAT_NETLINK_MESSAGES 36 def_bool y 37 depends on COMPAT 38 depends on WEXT_CORE || WANT_COMPAT_NETLINK_MESSAGES 39 help 40 This option makes it possible to send different netlink messages 41 to tasks depending on whether the task is a compat task or not. To 42 achieve this, you need to set skb_shinfo(skb)->frag_list to the 43 compat skb before sending the skb, the netlink code will sort out 44 which message to actually pass to the task. 45 46 Newly written code should NEVER need this option but do 47 compat-independent messages instead! 48 49config NET_INGRESS 50 bool 51 52config NET_EGRESS 53 bool 54 55config NET_REDIRECT 56 bool 57 58config SKB_EXTENSIONS 59 bool 60 61menu "Networking options" 62 63source "net/packet/Kconfig" 64source "net/unix/Kconfig" 65source "net/tls/Kconfig" 66source "net/xfrm/Kconfig" 67source "net/iucv/Kconfig" 68source "net/smc/Kconfig" 69source "net/xdp/Kconfig" 70 71config NET_HANDSHAKE 72 bool 73 depends on SUNRPC || NVME_TARGET_TCP || NVME_TCP 74 default y 75 76config INET 77 bool "TCP/IP networking" 78 help 79 These are the protocols used on the Internet and on most local 80 Ethernets. It is highly recommended to say Y here (this will enlarge 81 your kernel by about 400 KB), since some programs (e.g. the X window 82 system) use TCP/IP even if your machine is not connected to any 83 other computer. You will get the so-called loopback device which 84 allows you to ping yourself (great fun, that!). 85 86 For an excellent introduction to Linux networking, please read the 87 Linux Networking HOWTO, available from 88 <http://www.tldp.org/docs.html#howto>. 89 90 If you say Y here and also to "/proc file system support" and 91 "Sysctl support" below, you can change various aspects of the 92 behavior of the TCP/IP code by writing to the (virtual) files in 93 /proc/sys/net/ipv4/*; the options are explained in the file 94 <file:Documentation/networking/ip-sysctl.rst>. 95 96 Short answer: say Y. 97 98if INET 99source "net/ipv4/Kconfig" 100source "net/ipv6/Kconfig" 101source "net/netlabel/Kconfig" 102source "net/mptcp/Kconfig" 103 104endif # if INET 105 106config NETWORK_SECMARK 107 bool "Security Marking" 108 help 109 This enables security marking of network packets, similar 110 to nfmark, but designated for security purposes. 111 If you are unsure how to answer this question, answer N. 112 113config NET_PTP_CLASSIFY 114 def_bool n 115 116config NETWORK_PHY_TIMESTAMPING 117 bool "Timestamping in PHY devices" 118 select NET_PTP_CLASSIFY 119 help 120 This allows timestamping of network packets by PHYs (or 121 other MII bus snooping devices) with hardware timestamping 122 capabilities. This option adds some overhead in the transmit 123 and receive paths. 124 125 If you are unsure how to answer this question, answer N. 126 127menuconfig NETFILTER 128 bool "Network packet filtering framework (Netfilter)" 129 help 130 Netfilter is a framework for filtering and mangling network packets 131 that pass through your Linux box. 132 133 The most common use of packet filtering is to run your Linux box as 134 a firewall protecting a local network from the Internet. The type of 135 firewall provided by this kernel support is called a "packet 136 filter", which means that it can reject individual network packets 137 based on type, source, destination etc. The other kind of firewall, 138 a "proxy-based" one, is more secure but more intrusive and more 139 bothersome to set up; it inspects the network traffic much more 140 closely, modifies it and has knowledge about the higher level 141 protocols, which a packet filter lacks. Moreover, proxy-based 142 firewalls often require changes to the programs running on the local 143 clients. Proxy-based firewalls don't need support by the kernel, but 144 they are often combined with a packet filter, which only works if 145 you say Y here. 146 147 You should also say Y here if you intend to use your Linux box as 148 the gateway to the Internet for a local network of machines without 149 globally valid IP addresses. This is called "masquerading": if one 150 of the computers on your local network wants to send something to 151 the outside, your box can "masquerade" as that computer, i.e. it 152 forwards the traffic to the intended outside destination, but 153 modifies the packets to make it look like they came from the 154 firewall box itself. It works both ways: if the outside host 155 replies, the Linux box will silently forward the traffic to the 156 correct local computer. This way, the computers on your local net 157 are completely invisible to the outside world, even though they can 158 reach the outside and can receive replies. It is even possible to 159 run globally visible servers from within a masqueraded local network 160 using a mechanism called portforwarding. Masquerading is also often 161 called NAT (Network Address Translation). 162 163 Another use of Netfilter is in transparent proxying: if a machine on 164 the local network tries to connect to an outside host, your Linux 165 box can transparently forward the traffic to a local server, 166 typically a caching proxy server. 167 168 Yet another use of Netfilter is building a bridging firewall. Using 169 a bridge with Network packet filtering enabled makes iptables "see" 170 the bridged traffic. For filtering on the lower network and Ethernet 171 protocols over the bridge, use ebtables (under bridge netfilter 172 configuration). 173 174 Various modules exist for netfilter which replace the previous 175 masquerading (ipmasqadm), packet filtering (ipchains), transparent 176 proxying, and portforwarding mechanisms. Please see 177 <file:Documentation/Changes> under "iptables" for the location of 178 these packages. 179 180if NETFILTER 181 182config NETFILTER_ADVANCED 183 bool "Advanced netfilter configuration" 184 depends on NETFILTER 185 default y 186 help 187 If you say Y here you can select between all the netfilter modules. 188 If you say N the more unusual ones will not be shown and the 189 basic ones needed by most people will default to 'M'. 190 191 If unsure, say Y. 192 193config BRIDGE_NETFILTER 194 tristate "Bridged IP/ARP packets filtering" 195 depends on BRIDGE 196 depends on NETFILTER && INET 197 depends on NETFILTER_ADVANCED 198 select NETFILTER_FAMILY_BRIDGE 199 select SKB_EXTENSIONS 200 help 201 Enabling this option will let arptables resp. iptables see bridged 202 ARP resp. IP traffic. If you want a bridging firewall, you probably 203 want this option enabled. 204 Enabling or disabling this option doesn't enable or disable 205 ebtables. 206 207 If unsure, say N. 208 209source "net/netfilter/Kconfig" 210source "net/ipv4/netfilter/Kconfig" 211source "net/ipv6/netfilter/Kconfig" 212source "net/bridge/netfilter/Kconfig" 213 214endif 215 216source "net/bpfilter/Kconfig" 217 218source "net/dccp/Kconfig" 219source "net/sctp/Kconfig" 220source "net/rds/Kconfig" 221source "net/tipc/Kconfig" 222source "net/atm/Kconfig" 223source "net/l2tp/Kconfig" 224source "net/802/Kconfig" 225source "net/bridge/Kconfig" 226source "net/dsa/Kconfig" 227source "net/8021q/Kconfig" 228source "net/llc/Kconfig" 229source "drivers/net/appletalk/Kconfig" 230source "net/x25/Kconfig" 231source "net/lapb/Kconfig" 232source "net/phonet/Kconfig" 233source "net/6lowpan/Kconfig" 234source "net/ieee802154/Kconfig" 235source "net/mac802154/Kconfig" 236source "net/sched/Kconfig" 237source "net/dcb/Kconfig" 238source "net/dns_resolver/Kconfig" 239source "net/batman-adv/Kconfig" 240source "net/openvswitch/Kconfig" 241source "net/vmw_vsock/Kconfig" 242source "net/netlink/Kconfig" 243source "net/mpls/Kconfig" 244source "net/nsh/Kconfig" 245source "net/hsr/Kconfig" 246source "net/switchdev/Kconfig" 247source "net/l3mdev/Kconfig" 248source "net/qrtr/Kconfig" 249source "net/ncsi/Kconfig" 250 251config PCPU_DEV_REFCNT 252 bool "Use percpu variables to maintain network device refcount" 253 depends on SMP 254 default y 255 help 256 network device refcount are using per cpu variables if this option is set. 257 This can be forced to N to detect underflows (with a performance drop). 258 259config MAX_SKB_FRAGS 260 int "Maximum number of fragments per skb_shared_info" 261 range 17 45 262 default 17 263 help 264 Having more fragments per skb_shared_info can help GRO efficiency. 265 This helps BIG TCP workloads, but might expose bugs in some 266 legacy drivers. 267 This also increases memory overhead of small packets, 268 and in drivers using build_skb(). 269 If unsure, say 17. 270 271config RPS 272 bool 273 depends on SMP && SYSFS 274 default y 275 276config RFS_ACCEL 277 bool 278 depends on RPS 279 select CPU_RMAP 280 default y 281 282config SOCK_RX_QUEUE_MAPPING 283 bool 284 285config XPS 286 bool 287 depends on SMP 288 select SOCK_RX_QUEUE_MAPPING 289 default y 290 291config HWBM 292 bool 293 294config CGROUP_NET_PRIO 295 bool "Network priority cgroup" 296 depends on CGROUPS 297 select SOCK_CGROUP_DATA 298 help 299 Cgroup subsystem for use in assigning processes to network priorities on 300 a per-interface basis. 301 302config CGROUP_NET_CLASSID 303 bool "Network classid cgroup" 304 depends on CGROUPS 305 select SOCK_CGROUP_DATA 306 help 307 Cgroup subsystem for use as general purpose socket classid marker that is 308 being used in cls_cgroup and for netfilter matching. 309 310config NET_RX_BUSY_POLL 311 bool 312 default y if !PREEMPT_RT 313 314config BQL 315 bool 316 depends on SYSFS 317 select DQL 318 default y 319 320config BPF_STREAM_PARSER 321 bool "enable BPF STREAM_PARSER" 322 depends on INET 323 depends on BPF_SYSCALL 324 depends on CGROUP_BPF 325 select STREAM_PARSER 326 select NET_SOCK_MSG 327 help 328 Enabling this allows a TCP stream parser to be used with 329 BPF_MAP_TYPE_SOCKMAP. 330 331config NET_FLOW_LIMIT 332 bool 333 depends on RPS 334 default y 335 help 336 The network stack has to drop packets when a receive processing CPU's 337 backlog reaches netdev_max_backlog. If a few out of many active flows 338 generate the vast majority of load, drop their traffic earlier to 339 maintain capacity for the other flows. This feature provides servers 340 with many clients some protection against DoS by a single (spoofed) 341 flow that greatly exceeds average workload. 342 343menu "Network testing" 344 345config NET_PKTGEN 346 tristate "Packet Generator (USE WITH CAUTION)" 347 depends on INET && PROC_FS 348 help 349 This module will inject preconfigured packets, at a configurable 350 rate, out of a given interface. It is used for network interface 351 stress testing and performance analysis. If you don't understand 352 what was just said, you don't need it: say N. 353 354 Documentation on how to use the packet generator can be found 355 at <file:Documentation/networking/pktgen.rst>. 356 357 To compile this code as a module, choose M here: the 358 module will be called pktgen. 359 360config NET_DROP_MONITOR 361 tristate "Network packet drop alerting service" 362 depends on INET && TRACEPOINTS 363 help 364 This feature provides an alerting service to userspace in the 365 event that packets are discarded in the network stack. Alerts 366 are broadcast via netlink socket to any listening user space 367 process. If you don't need network drop alerts, or if you are ok 368 just checking the various proc files and other utilities for 369 drop statistics, say N here. 370 371endmenu 372 373endmenu 374 375source "net/ax25/Kconfig" 376source "net/can/Kconfig" 377source "net/bluetooth/Kconfig" 378source "net/rxrpc/Kconfig" 379source "net/kcm/Kconfig" 380source "net/strparser/Kconfig" 381source "net/mctp/Kconfig" 382 383config FIB_RULES 384 bool 385 386menuconfig WIRELESS 387 bool "Wireless" 388 depends on !S390 389 default y 390 391if WIRELESS 392 393source "net/wireless/Kconfig" 394source "net/mac80211/Kconfig" 395 396endif # WIRELESS 397 398source "net/rfkill/Kconfig" 399source "net/9p/Kconfig" 400source "net/caif/Kconfig" 401source "net/ceph/Kconfig" 402source "net/nfc/Kconfig" 403source "net/psample/Kconfig" 404source "net/ife/Kconfig" 405 406config LWTUNNEL 407 bool "Network light weight tunnels" 408 help 409 This feature provides an infrastructure to support light weight 410 tunnels like mpls. There is no netdevice associated with a light 411 weight tunnel endpoint. Tunnel encapsulation parameters are stored 412 with light weight tunnel state associated with fib routes. 413 414config LWTUNNEL_BPF 415 bool "Execute BPF program as route nexthop action" 416 depends on LWTUNNEL && INET 417 default y if LWTUNNEL=y 418 help 419 Allows to run BPF programs as a nexthop action following a route 420 lookup for incoming and outgoing packets. 421 422config DST_CACHE 423 bool 424 default n 425 426config GRO_CELLS 427 bool 428 default n 429 430config SOCK_VALIDATE_XMIT 431 bool 432 433config NET_SELFTESTS 434 def_tristate PHYLIB 435 depends on PHYLIB && INET 436 437config NET_SOCK_MSG 438 bool 439 default n 440 help 441 The NET_SOCK_MSG provides a framework for plain sockets (e.g. TCP) or 442 ULPs (upper layer modules, e.g. TLS) to process L7 application data 443 with the help of BPF programs. 444 445config NET_DEVLINK 446 bool 447 default n 448 449config PAGE_POOL 450 bool 451 452config PAGE_POOL_STATS 453 default n 454 bool "Page pool stats" 455 depends on PAGE_POOL 456 help 457 Enable page pool statistics to track page allocation and recycling 458 in page pools. This option incurs additional CPU cost in allocation 459 and recycle paths and additional memory cost to store the statistics. 460 These statistics are only available if this option is enabled and if 461 the driver using the page pool supports exporting this data. 462 463 If unsure, say N. 464 465config FAILOVER 466 tristate "Generic failover module" 467 help 468 The failover module provides a generic interface for paravirtual 469 drivers to register a netdev and a set of ops with a failover 470 instance. The ops are used as event handlers that get called to 471 handle netdev register/unregister/link change/name change events 472 on slave pci ethernet devices with the same mac address as the 473 failover netdev. This enables paravirtual drivers to use a 474 VF as an accelerated low latency datapath. It also allows live 475 migration of VMs with direct attached VFs by failing over to the 476 paravirtual datapath when the VF is unplugged. 477 478config ETHTOOL_NETLINK 479 bool "Netlink interface for ethtool" 480 default y 481 help 482 An alternative userspace interface for ethtool based on generic 483 netlink. It provides better extensibility and some new features, 484 e.g. notification messages. 485 486config NETDEV_ADDR_LIST_TEST 487 tristate "Unit tests for device address list" 488 default KUNIT_ALL_TESTS 489 depends on KUNIT 490 491endif # if NET 492