Stop letting your kernel drop packets before your app even sees them

Performance Tuning & Kernel Parameters (Sysctl)

Stop letting your kernel drop packets before your app even sees them

🧩 The Challenge

Dealing with a high-traffic API server that just starts shedding load for no apparent reason is infuriating. You check the app logs, but they’re silent because the kernel decided the incoming connection queue was full and just tossed the SYN packets into the abyss.

💡 The Fix

Bump up your net.core.somaxconn and tcp_max_syn_backlog values to give your listening sockets a bit more breathing room during sudden bursts. You’ll stop seeing those mysterious “connection refused” errors when your service is actually running fine.

sysctl -w net.core.somaxconn=4096
sysctl -w net.ipv4.tcp_max_syn_backlog=4096
sysctl -p

⚙️ Why It Works

By default, these buffers are often laughably small, like 128 or 1024, which get overwhelmed the second a load balancer sends a heavy surge of traffic. Boosting these numbers forces the kernel to hold onto those connection requests longer, giving your application worker threads time to actually pick them up.

🚀 Pro-Tip: Run ss -lnt to check your current Recv-Q; if it’s hitting the limit you set, you need to scale up the app, not just the kernel buffers.

Linux Tips & Tricks | © ngelinux.com | 9/18/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted