Stop your system from dropping packets because of tiny conntrack tables
Performance Tuning & Kernel Parameters (Sysctl)
Stop your system from dropping packets because of tiny conntrack tables
🧩 The Challenge
Dealing with a production web server that randomly started dropping connections, only to find the dmesg logs screaming about conntrack table full is a special kind of hell. It happens silently while your app throughput just falls off a cliff.
💡 The Fix
Increase your netfilter conntrack table size and reduce the timeout settings so old, stale entries don’t clog up your kernel memory.
sysctl -w net.netfilter.nf_conntrack_max=1048576
sysctl -w net.netfilter.nf_conntrack_tcp_timeout_established=86400
⚙️ Why It Works
By cranking up the max entries, you give the kernel breathing room for high-traffic spikes while the lower timeouts make sure dead connections get purged before they take up space.
🚀 Pro-Tip: Verify your actual usage with cat /proc/sys/net/netfilter/nf_conntrack_count before you panic and bump these numbers way too high.
Linux Tips & Tricks | © ngelinux.com | 8/27/2026
