Stop your box from dumping connections when things get noisy
Performance Tuning & Kernel Parameters (Sysctl)
Stop your box from dumping connections when things get noisy
🧩 The Challenge
Dealing with a massive surge of concurrent connections and watching your server start dropping packets like it’s throwing a party for TCP resets. I’ve wasted way too many hours staring at dmesg seeing SYN flood alerts when the traffic was actually just legitimate spikes.
💡 The Fix
Increase the size of your TCP SYN backlog and the listen queue limit so the kernel actually holds onto those incoming handshakes instead of nuking them. It’s a quick win for any box handling a high volume of short-lived connections.
sysctl -w net.ipv4.tcp_max_syn_backlog=4096
sysctl -w net.core.somaxconn=1024
⚙️ Why It Works
Pumping these values up gives the kernel a bigger bucket to catch incoming connections before they get handed off to your application’s accept queue. Otherwise, you’re essentially telling the world to go away the moment your buffer hits capacity.
🚀 Pro-Tip: Check your application’s backlog setting too, because the kernel can only do so much if your app isn’t actually ready to take the connections off the queue.
Linux Tips & Tricks | © ngelinux.com | 7/21/2026
