今天查看系統日誌發現大量的nf_conntrack: table full, dropping packet. 錯誤
cat /var/log/messages | more
Jun 7 09:52:05 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:05 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:05 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:05 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:05 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:05 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:05 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:05 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:10 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:10 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:10 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:10 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:10 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:10 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:10 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:10 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:10 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:10 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:15 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:15 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:15 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:15 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:15 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:15 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:15 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:15 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:15 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:15 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:23 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:23 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:23 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:23 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:23 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:23 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:23 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:23 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:23 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:23 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:30 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:30 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:30 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:30 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:30 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:30 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:30 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:30 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:30 localhost kernel: nf_conntrack: table full, dropping packet.
Jun 7 09:52:30 localhost kernel: nf_conntrack: table full, dropping packet.
解決辦法: vim /etc/sysctl.conf 加入: net.nf_conntrack_max = 655350 net.netfilter.nf_conntrack_tcp_timeout_established = 1200 CENTOS 6.1或以上版本使用: net.netfilter.nf_conntrack_max = 655350 net.netfilter.nf_conntrack_tcp_timeout_established = 1200 保存後執行 sysctl -p 使之生效,而後觀察該錯誤是否是沒有了。