先看一下文章解释:
http://jerrypeng.me/2014/12/08/dreadful-nf-conntrack-table-full-issue/
我处理方案如下:
稳妥的临时处理办法:
1
2
3
4
5
6
7
8
9
|
vi
/etc/sysctl
.conf
net.nf_conntrack_max = 2097152
net.netfilter.nf_conntrack_tcp_timeout_established = 300
net.netfilter.nf_conntrack_max = 1048576
net.netfilter.nf_conntrack_tcp_timeout_close_wait = 60
net.netfilter.nf_conntrack_tcp_timeout_fin_wait = 120
net.netfilter.nf_conntrack_tcp_timeout_time_wait = 120
net.ipv4.conf.default.forwarding = 1
sysctl -p
|
1
2
|
echo
50000 >
/sys/module/nf_conntrack/parameters/hashsize
echo
524288 >
/proc/sys/net/netfilter/nf_conntrack_max
|
1
2
|
vim
/etc/rc
.
local
echo
524288 >
/proc/sys/net/netfilter/nf_conntrack_max
|
问题解决
参考文档:
http://jerrypeng.me/2014/12/08/dreadful-nf-conntrack-table-full-issue/
本文转自crazy_charles 51CTO博客,原文链接:http://blog.51cto.com/douya/1960818,如需转载请自行联系原作者