The Two Best Pieces of Linux Tuning Advice I Have Ever Received
- Ensure that
sysctl net.netfilter.nf_conntrack_maxis greater thansysctl net.netfilter.nf_conntrack_count - Don’t forget
dmesg.
sysctl net.netfilter.nf_conntrack_max is greater than sysctl net.netfilter.nf_conntrack_countdmesg.