Stop your system from dropping packets because of tiny conntrack tables

Performance Tuning & Kernel Parameters (Sysctl)

Stop your system from dropping packets because of tiny conntrack tables

🧩 The Challenge

Dealing with a production web server that randomly started dropping connections, only to find the dmesg logs screaming about conntrack table full is a special kind of hell. It happens silently while your app throughput just falls off a cliff.

💡 The Fix

Increase your netfilter conntrack table size and reduce the timeout settings so old, stale entries don’t clog up your kernel memory.

sysctl -w net.netfilter.nf_conntrack_max=1048576
sysctl -w net.netfilter.nf_conntrack_tcp_timeout_established=86400

⚙️ Why It Works

By cranking up the max entries, you give the kernel breathing room for high-traffic spikes while the lower timeouts make sure dead connections get purged before they take up space.

🚀 Pro-Tip: Verify your actual usage with cat /proc/sys/net/netfilter/nf_conntrack_count before you panic and bump these numbers way too high.

Linux Tips & Tricks | © ngelinux.com | 8/27/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted