Stop your box from dumping connections when things get noisy

Performance Tuning & Kernel Parameters (Sysctl)

Stop your box from dumping connections when things get noisy

🧩 The Challenge

Dealing with a massive surge of concurrent connections and watching your server start dropping packets like it’s throwing a party for TCP resets. I’ve wasted way too many hours staring at dmesg seeing SYN flood alerts when the traffic was actually just legitimate spikes.

💡 The Fix

Increase the size of your TCP SYN backlog and the listen queue limit so the kernel actually holds onto those incoming handshakes instead of nuking them. It’s a quick win for any box handling a high volume of short-lived connections.

sysctl -w net.ipv4.tcp_max_syn_backlog=4096
sysctl -w net.core.somaxconn=1024

⚙️ Why It Works

Pumping these values up gives the kernel a bigger bucket to catch incoming connections before they get handed off to your application’s accept queue. Otherwise, you’re essentially telling the world to go away the moment your buffer hits capacity.

🚀 Pro-Tip: Check your application’s backlog setting too, because the kernel can only do so much if your app isn’t actually ready to take the connections off the queue.

Linux Tips & Tricks | © ngelinux.com | 7/21/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted