How to debug issue when in logs there are messages like 'nf_conntrack: table full, dropping packet.' ?

Solution Verified - Updated -

Issue

  • /var/log/messages/ has logs like nf_conntrack: table full, dropping packet. Which are seen when nf_conntrack table get full.
  • Increasing the value of parameter net.netfilter.nf_conntrack_max = <value> can increase the table size but at the cost of memory utilization.
  • So how to find out what exactly has caused to increase the number of connection ? Because of which connections the table has got full ?

Environment

  • Red Hat Enterprise Linux 6 (All Versions)
  • Red Hat Enterprise Linux 5 (All Versions)

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In